Six Information Security Tips to Mitigate the Risk of a SolarWinds-Like Breach
Privacy, Cyber & AI Decoded Alert | 1 min read
Jan 13, 2021
The impacts and implications of the recent SolarWinds breach are widespread and on-going. SolarWinds' network-monitoring and management software was used by customers worldwide—including the U.S. military, Fortune 500 companies, government agencies, and educational institutions—to manage their own computer systems. The apparent expert consensus is that Russia used SolarWinds' hacked program to infiltrate roughly 18,000 government and private networks.
Microsoft and FireEye, both victims of the hack, have issued reports detailing the malware specs that hackers added to the SolarWinds' monitoring product updates that were uploaded to customer computers. The Cybersecurity & Infrastructure Security Agency, the New York State Department of Financial Services, and other cyber agencies and regulators have issued advisories requiring immediate action by entities using the affected SolarWinds products or usage by third parties with access to regulated entities' networks and data. There are also increasingly pointed news reports concerning SolarWinds' management and security practices.
Even for organizations not directly impacted, this incident provides incentive to revisit basic security hygiene. In particular, it is important to manage the security risks associated with third-party service providers to ensure that the security of information and information assets is not reduced when: (1) exchanging information with the third party, or (2) introducing their products and services into your environment.
Complacency with respect to third parties is unwise. Organizations can take a few critical steps to improve their security:
- Confirm that you and your third-party vendors are not implicated by the SolarWinds breach
- Re-risk assess your data and information system assets and current security posture
- Revisit your due diligence process for third-party service providers and your procurement of technology
- Revisit employee security education and training
- Enhance your protocols for data and information systems access, including authorizations, network segmentation, and backups
- Test your security incident response plan, including, in particular, new reporting and notification requirements to regulators and government agencies
Related Capabilities
Featured Insights

Healthcare Alert
Aug 3, 2026
Fixing the Emergency Refill Trap: What California’s AB 1587 Means for Pharmacies

Consumer Crossroads: Where Financial Services and Litigation Intersect
Jul 30, 2026
Should Text Messages be Considered “Calls” Under the TCPA? The Seventh Circuit Says No

Healthcare Alert
Jul 30, 2026
California Courts Sharply Curtail the MICRA Damages Cap in Nursing Home Litigation

Insights for Insurers Alert
Jul 30, 2026
Analyzing a Couple of Cases Involving Exclusions in D&O Policies

In The News
Jul 29, 2026
Hinshaw Authors Contribute Two Articles in Latest Edition of the CCFL Quarterly Report

Webinar
Jul 28, 2026
Cathy Mulrow-Peattie and Sabrina Janeiro Present on Legal AI Technology

In The News
Jul 27, 2026
Scott Seaman Discusses How the Insurance Industry Contributed to the 2026 FIFA World Cup

Privacy, Cyber & AI Decoded Alert
Jul 27, 2026
Compliance Guidance for the New Vermont Data Privacy and Online Surveillance Act (VDPOSA)

Healthcare Alert
Jul 24, 2026
Q&A: Right to Electronic Monitoring Extended to Illinois Assisted and Shared Living Facilities

Press Release
Jul 23, 2026
Insurance Partner Christophe Burusco Joins Hinshaw in Los Angeles

In The News
Jul 16, 2026
Jennifer Driscoll Anticipates Epic Battle Between “Titans of the Antitrust Bar”

