Threats Are Increasing, but Security Budgets, Staff Aren’t

The age-old problem of misaligned security budgets and staffing continues, but they may not be the answer to solving the most pressing security issues. I didn’t go to Black Hat USA this year, but I’ve heard some chatter about the show. One person told… Continue reading Threats Are Increasing, but Security Budgets, Staff Aren’t

New Zealand budget details leaked due to website sloppiness, not hackers

Earlier this week, the New Zealand government was claiming that it had suffered a “deliberate and systematic” hacking attack that resulted in budget details ending up in the hands of its political opponents.
But that’s not what had re… Continue reading New Zealand budget details leaked due to website sloppiness, not hackers

How to Buy a Security Awareness Training Program

Are you in search of a security awareness training program to help educate your employees on cyber security best practices? There are lots of options and you may even be deciding on developing one yourself vs. choosing a vendor. Most organizations face… Continue reading How to Buy a Security Awareness Training Program

OMB slams agencies on cyber risk, calls for ‘bold’ new approaches

Nearly three quarters of 96 agencies reviewed by federal officials have cybersecurity programs that are either “at risk” or at “high risk,” meaning “bold approaches” are needed to secure federal networks, according to the Office of Management and Budget. Risk assessments carried out by OMB show that a lack of threat information available to agencies “results in ineffective allocations” of their limited budgets, OMB said in a report released last week. “This situation creates enterprise-wide gaps in network visibility, IT tool and capability standardization, and common operating procedures, all of which negatively impact federal cybersecurity.” In the report, a “high risk” designation means that key cybersecurity policies and tools are either absent or insufficiently deployed, while an “at risk” rating means some key policies are in place to lessen cyber risk, “but significant gaps remain.” An executive order that President Donald Trump signed last year mandated the governmentwide survey of […]

The post OMB slams agencies on cyber risk, calls for ‘bold’ new approaches appeared first on Cyberscoop.

Continue reading OMB slams agencies on cyber risk, calls for ‘bold’ new approaches

U.S. Cyber Command chief calls for debate around hacking unit’s authorities

Lawmakers and Pentagon leadership are considering plans that could one day provide U.S. Cyber Command with additional authorities to more easily operate outside declared war zones, two senior U.S. officials acknowledged Wednesday during an open congressional hearing. The testimony confirms aspects of a story CyberScoop published Wednesday about a push inside the government to give more authority to the military’s top hacking unit. That story described concerns shared in the intelligence community about the potential impact of a spike in cyber warfare operations. Such a shift in policy may allow Cyber Command to offer more protection to private companies, including those that own and operate what the U.S. government considers “critical infrastructure.” When it comes to offensive measures, the shift could also open the door for soldiers to hack a much wider array of targets; beyond the Middle East, where the military is already engaged in firefights. Under existing authorities, U.S. […]

The post U.S. Cyber Command chief calls for debate around hacking unit’s authorities appeared first on Cyberscoop.

Continue reading U.S. Cyber Command chief calls for debate around hacking unit’s authorities