• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechCybersecurity

SolarWinds tries to rebuild its reputation a year after its huge hack was discovered

By
Jonathan Vanian
Jonathan Vanian
Down Arrow Button Icon
By
Jonathan Vanian
Jonathan Vanian
Down Arrow Button Icon
December 20, 2021, 12:01 PM ET

It took a catastrophic hack to put cybersecurity front and center at business software maker SolarWinds.

In the year since suffering one of the biggest cyberattacks in recent history, SolarWinds has had to completely reorient itself around security, says CEO Sudhakar Ramakrishna.

That meant creating a cybersecurity executive committee, which includes Ramakrishna and two board members, to ensure top management is aware of security risks. It also involved giving more authority and resources to the company’s security chief. And it led to upending how the company creates software so that the process is more deliberate, which provides more time and opportunities to discover vulnerabilities.

Ramakrishna became SolarWinds CEO in January, a month after the company was found to have been attacked by Russian hackers. Criminals were able to exploit flaws within SolarWinds’ little-known but widely-used product for managing corporate IT systems that thousands of the company’s customers downloaded. The hackers were then able use the software bugs to covertly penetrate and conduct espionage on the networks of less than one hundred organizations.

Ramakrishna, who was previously the CEO of security firm Pulse Secure, replaced former chief Kevin Thompson, who the company announced in October would leave the company as part of a leadership transition plan. Ramakrishna says he only learned about the SolarWinds hack a few days after he was named CEO in December. He would have a challenging first year on the job, fielding questions from members of Congress about the hack, and overhauling the business, which took a hit as some customers stopped using its technology.

Since then, the tech world has been rocked by several more similar hacks that were unrelated to SolarWinds. The hacks are known as supply chain attacks because they leave users of the software vulnerable rather than the developer that created it.

Earlier this month, researchers discovered a bug in the open-source software tool Log4j used by software developers. It has caused thousands of security teams to scramble to secure their corporate IT infrastructure. Meanwhile in March, Microsoft disclosed its own supply-chain attack in which Chinese hackers exploited a coding bug in its popular Exchange email software. Microsoft has since released patches so customers can fix the flaw. 

Ramakrishna says that he’s spent the past year talking with government agencies worldwide that specialize in cybersecurity and that are “actively investigating several supply-chain attacks simultaneously.” Such investigations underscore the extent to which criminals are attempting to replicate SolarWinds-like attacks.

When news of the SolarWinds hack first emerged last year, Ramakrishna acknowledges that “some customers were downright upset and angry.” To repair relationships with clients, he has been meeting with executives to describe the cybersecurity steps his company has taken and has been speaking more publicly about the hack to build trust with the broader business community. It’s better to be transparent rather than distance the company from the hack, he explains. 

The more “we put our head in the sand and hope the problem goes away, the more and more the problem actually magnifies,” Ramakrishna says about rebuilding trust. “It shouldn’t be looked at as a shameful thing as much as what do you learn from it.”

Still, SolarWinds’s revenue declined 1.9% year-over-year to $181.3 million in its most recent quarter. In corporate filings, the company said that the hack “is expected to negatively impact revenue, profitability and cash flows in 2021 and beyond.”

But Ramakrishna is hopeful that SolarWinds will rebound. Customer renewal and retention rates, he says, “are almost back to our historical levels, and it’s not even been a year since the incident happened.”

Some of the cybersecurity steps SolarWinds has taken over the past year include setting up a program in which it invites developers to discover flaws in its products so it can fix them before criminals exploit them. The company has held two so-called bug-bounty programs and paid the helpful hackers tens of thousands of dollars to spot problems, Ramakrishna says.

“It’s much better to do that than pay ransom on a ransomware,” he says. 

When SolarWinds creates new software products, it essentially makes three different versions of the tools that each require their own security checks and authorizations to access. Doing so makes it more difficult for hackers to break into and perform so-called man-in-the middle attacks, in which they could covertly tamper with the software, he explains. SolarWinds won’t make the tools officially available until all three versions are free of any security holes, Ramakrishna says.

He estimates that changing software development and related IT processes has increased the company’s expenses by 10% to 15%, but he says the extra cost is well worth it.

SolarWinds also regularly runs fake phishing attacks against employees to teach workers to recognize scam emails, one of the most common strategies hackers use to break into companies.

“As you know, it takes one targeted spear phishing attack for an attacker to gain access,” Ramakrishna says. 

SolarWinds inevitably faces the risk of being hacked again, but Ramakrishna believes that the extra precautions will probably avoid it.

“My belief is that if you’re applying some of these secure by design principles that we have implemented, the likelihood of something like this goes down significantly,” Ramakrishna says. 

Clarification, Dec. 22, 2021 at 2:30 PM ET.: This article has been updated to clarify the number of customers who downloaded the software that the hackers compromised versus the customers who the criminals were able to ultimately hack.

Never miss a story: Follow your favorite topics and authors to get a personalized email with the journalism that matters most to you.

About the Author
By Jonathan Vanian
LinkedIn iconTwitter icon

Jonathan Vanian is a former Fortune reporter. He covered business technology, cybersecurity, artificial intelligence, data privacy, and other topics.

See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Meta's Hyperion data-center site in Northeastern Louisiana.
EnergyMeta
Meta orders 10 gas-fired power plants for its Hyperion AI campus in rural Louisiana—more than triple the initial plan
By Jordan BlumMarch 27, 2026
16 minutes ago
LawMeta
Meta promised it wouldn’t spy on you with its AI smart glasses. A lawsuit says humans are watching you, actually
By Catherina GioinoMarch 27, 2026
1 hour ago
Steve Wozniak speaks into a microphone, raising his palm in the air.
Big TechApple
Apple cofounder Steve Wozniak admits he’s ‘disappointed a lot’ by AI and hardly uses it: ‘They just sound too dry and too perfect’
By Sasha RogelbergMarch 27, 2026
1 hour ago
AIData centers
Microsoft is picking up a Texas data center project OpenAI didn’t want, in a telling sign of how far they’ve drifted apart
By Matt O'Brien and The Associated PressMarch 27, 2026
3 hours ago
InnovationDrones
The Army and Amazon are creating an online storefront to buy drones as the technology transforms the battlefield
By Jason MaMarch 27, 2026
4 hours ago
kid on laptop with parent blindfolding them
PoliticsSocial Media
Americans want kids shielded from the internet. They don’t trust websites or the government to do anything about it
By Catherina GioinoMarch 27, 2026
5 hours ago

Most Popular

C-Suite
'I didn’t want anybody shooting me': Five Guys CEO gave away $1.5 million bonus to employees over botched BOGO burger birthday celebration
By Fortune EditorsMarch 25, 2026
2 days ago
AI
Exclusive: Anthropic acknowledges testing new AI model representing ‘step change’ in capabilities, after accidental data leak reveals its existence
By Fortune EditorsMarch 26, 2026
20 hours ago
Environment
Vail Resorts CEO says it’s time to think beyond the $1,000 ski pass that helped build the empire
By Fortune EditorsMarch 26, 2026
2 days ago
Success
Meetings are not work, says Southwest Airlines CEO—and he’s taking action by blocking his calendar every afternoon from Wednesday to Friday 
By Fortune EditorsMarch 27, 2026
12 hours ago
Success
Palantir’s billionaire CEO says only two kinds of people will succeed in the AI era: trade workers — ‘or you’re neurodivergent’
By Fortune EditorsMarch 24, 2026
3 days ago
Commentary
The Treasury just declared the U.S. insolvent. The media missed it
By Fortune EditorsMarch 23, 2026
4 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.