Attend CSC13
Title Talk: Sunburst -- The Attack, the Charges, and Five Years to Vindication
Abstract
In December 2020, the Russian SVR successfully compromised SolarWinds' Orion platform, tainting trusted software that was downloaded by roughly 18,000 customers. Tim Brown, former CISO of SolarWinds, shares his first-person account of leading the technical response — and the five-year journey that followed.
This talk traces that full arc:
The Breach — how a nation-state actor infiltrated the build pipeline and turned trusted software into a weapon
Discovery and Initial Response — the early hours and days of finding out, containing the threat, and coordinating disclosure
Recovery and Rebuilding Trust — the long work of restoring customer confidence and hardening the company from the inside out
The SEC Charges — a second front opens, as regulatory scrutiny puts the response itself on trial
Vindication — what five years, and the outcome, taught the industry about crisis leadership, transparency, and resilience
Attendees will leave with hard-won lessons on incident response, executive communication under pressure, and what it really takes for a CISO to lead through — and beyond — a career-defining crisis.
Keynote Speaker Bio
Tim Brown is one of the most credible and experienced voices in cybersecurity today. As the CA TECHNOLOGIES, he guided the company through the aftermath of the 2020 supply chain attack — one of the most sophisticated and consequential cyberattacks in history, attributed to a nation-state threat actor. His leadership during that period, and the hard-won lessons that came from it, form the foundation of his work as a speaker and advisor.
In February 2026, Tim joined Team8 as a Partner and CISO in Residence. Team8 is one of the world's leading cybersecurity venture groups, known for building companies from the ground up alongside elite founders. In this role, Tim works with security companies at every stage of the lifecycle — from initial ideation and problem validation, through early funding rounds, to scaling product and go-to-market strategy.
Tim is one of only six Dell Fellows worldwide — a distinction reserved for the most exceptional technical contributors in the Dell Technologies ecosystem. He is also a Distinguished Engineer, a recognition of sustained technical excellence and industry impact. These honors reflect a career that has always been grounded in deep technical credibility, not just executive leadership.
Before his time as CISO, Tim served as Chief Technology Officer and as Chief Product Officer — giving him a rare, multi-dimensional view of how security intersects with product development, engineering, and business strategy. This breadth of experience is what makes his perspective uniquely valuable to boards, security teams, and technology leaders.
Tim is an active advisor to multiple security companies across the funding lifecycle. He brings not just strategic guidance, but the kind of operational credibility that comes from having built, led, and defended complex security programs at scale — and from having navigated the legal, regulatory, and reputational consequences of a major incident in the full glare of public scrutiny.
He speaks regularly at major industry events including RSA Conference, Black Hat, and DEF CON, as well as to boards, audit committees, and executive teams at Fortune 500 companies. His talks are known for their candor, depth, and the kind of insight that only comes from lived experience.