Alle leverandører

Vendor lineage

SolarWinds

Sold the software that watches everything, which is exactly why somebody wanted it.

SolarWinds was founded in 1999 in Tulsa, Oklahoma by two brothers, Donald Yonce - a former Walmart executive - and David Yonce. The business was unglamorous and very good: affordable network monitoring for the people who actually run networks, sold without the enterprise sales apparatus that made competitors expensive. It moved to Austin, and by 2020 its Orion platform sat inside a very large share of the organisations that matter.

The commercial insight was that monitoring was overpriced and oversold. A network engineer who needed to know whether a link was saturated did not want a six-month procurement cycle, and SolarWinds built a catalogue of tools that could be downloaded, trialled and bought on a card. That model took it from Tulsa to a public listing in October 2018, and it bought its way into adjacent categories along the way: Pingdom for external uptime checks, Papertrail for log aggregation, Loggly, AppOptics.

And then the thing that makes this page worth reading. In October 2019, attackers who had already been inside SolarWinds began testing whether they could inject code into the Orion build. Roughly four months later they succeeded, and from 26 March 2020 SolarWinds itself distributed the result - a backdoor the industry named SUNBURST - inside signed, legitimate updates to Orion versions 2019.4 through 2020.2.1.

It was not discovered until December 2020, and not by SolarWinds. FireEye found it while investigating its own compromise, which is worth noting because FireEye appears on this timeline too: a security company found the largest supply chain attack in history by looking into how it had itself been broken into. In April 2021 the US and UK governments attributed the operation to Russia's foreign intelligence service, the SVR - the group tracked as APT29 or Cozy Bear.

The number everyone quotes needs its caveat. Around 18,000 customers received the backdoored update. The US government's own assessment was that a much smaller number were actually compromised by follow-on activity, because the backdoor was a door rather than an occupation - the attackers chose where to walk through it, and they were extremely selective. Repeating 18,000 as a count of victims overstates it, and the distinction between having the malware and being exploited by it is precisely the distinction a security professional is paid to understand.

The response detail that stays with people: SolarWinds could not use its own email to coordinate the investigation, because the attackers were reading it. Staff worked by telephone and outside accounts, during a pandemic, from home. The chief executive later joked that every comma in the initial regulatory filing cost the company $20,000 in legal fees.

Then the argument about blame, which is not settled and is presented here as unsettled. In October 2023 the SEC charged SolarWinds and its chief information security officer, Timothy Brown, with fraud - alleging that from the 2018 listing onward the company disclosed only generic risks while internally knowing about specific deficiencies. SolarWinds called the action an attempt to "revictimise the victim" and said its disclosures were accurate. In July 2024 a federal judge dismissed most of the case, including everything relating to disclosures made after the attack, while allowing the claim based on the company's published security statement to proceed.

That outcome is the part with teeth for anyone who works in this field. A named individual was personally charged over how a breach was described, and while most of the case did not survive, the surviving part concerns a marketing page about security practices. What a company says about its own posture became a matter of securities law, and every CISO reading this now writes differently because of it.

The lesson for practitioners is architectural rather than moral, and this site already carries its twin. CrowdStrike's July 2024 outage broke 8.5 million machines because a trusted agent with deep access is updated centrally and rapidly. SUNBURST compromised thousands of networks for the same structural reason. One was an accident and one was an intelligence operation, and the property they exploited was identical: we have built an industry on software that updates itself from a single source, and the trust in that channel is load-bearing.

Founding stories

1999

SolarWinds

Tulsa, Oklahoma · Founders: Donald Yonce, David Yonce

Two brothers, one a former Walmart executive, building network monitoring for the people who run networks rather than for the people who sign for them. The company later moved to Austin, where it remains.

The timeline

  1. Founded in Tulsa

    Affordable monitoring sold without an enterprise sales apparatus.

  2. Taken private

    Thoma Bravo and Silver Lake bought the company for approximately $4.5B.

  3. Return to public markets

    Listed in October, raising $375M at a $4.6B valuation, with the two private equity firms retaining roughly 65% of the voting stock.

  4. The intrusion begins

    October: the first test injections into the Orion build.

  5. SUNBURST distributed, then found

    26 March to December, from first backdoored update to discovery.

  6. Attribution

    In April the United States and United Kingdom attributed the operation to Russia's SVR.

  7. Private again, at roughly the price it started

    Turn/River Capital agreed to buy the company on 7 February at $18.50 a share, about $4.4B, and closed on 16 April; the stock left the New York Stock Exchange. Nine years earlier the same company had been taken private at approximately $4.5B. It went through a public listing and the largest software supply chain attack on record, and came out roughly where it went in.

  8. The SEC case largely ends

    The remaining claims were dismissed in November, closing an action that had run since October 2023.

Flagship products and solutions

  • Orion, and the SolarWinds PlatformThe monitoring platform - network performance, server and application monitoring, configuration management - and the product whose build system was compromised.
  • SolarWinds ObservabilityThe current platform, offered both as a hosted service and self-hosted, which for a substantial part of this customer base is not a preference but a requirement.
  • Database Performance Analyzer and SQL SentryDatabase monitoring, sold under a combined licence - an unglamorous specialism with a loyal following among the people who actually tune queries.
  • Service DeskIT service management, added to put the ticket beside the alert.
  • Pingdom, Papertrail, Loggly and AppOpticsAcquired external monitoring, log aggregation and application performance tools, bought rather than built - the pattern that took the company into adjacent categories quickly.

Key innovations

  • The procurement bypass, and its second edgeSoftware bought without a procurement cycle is also software bought without a security review, an architecture board or an inventory entry. The model that made the company was the model that made its customers unable to answer, in December 2020, the only question that mattered: where is this installed.
  • Breadth at a price the mid-market paysA catalogue of narrow tools rather than one expensive platform let a customer buy exactly the piece they needed. The commercial model and the install base are the same fact.
  • Rebuilding the build process in publicAfter 2020 the company reconstructed its software build to run the same source through multiple independent pipelines and compare results, so that a single compromised environment cannot produce a trusted artefact. It published the approach rather than keeping it, which is the useful response to having been the case study.

Main markets

IT operations teams across enterprise, mid-market and government, with a footprint that includes a large share of the Fortune 500 and, in 2020, much of the United States federal government - which is what made the compromise a national security event rather than a commercial one.

It competes now against cloud-native observability vendors that grew up after its model was established, and its distinguishing position is the same as it always was: broad, affordable, and deployable on premises for customers who cannot use anything else.

Analyst standing

  • Assessed as a substantial incumbent in network monitoring and IT operations management, with a customer base whose size is its principal asset and, in 2020, its principal liability.
  • The commercial verdict is in the numbers: taken private at about $4.5B in 2016 and sold at about $4.4B in 2025. A company can survive the worst supply chain attack yet recorded and still be worth what it was - which says something about the durability of installed software that neither the attack nor the recovery narrative captures.

Acquisitions

  1. 2014 Pingdom

    External uptime and performance monitoring, checked from outside the network rather than within it.

    The SolarWinds cloud monitoring line.

  2. 2015 Papertrail

    Hosted log aggregation and live tail, popular with small engineering teams for being immediately useful.

    Part of the same cloud portfolio, kept under its own name.

  3. 2015 Librato and TraceView

    Metrics and application tracing, bought from AppNeta.

    AppOptics, which merged both into one product.