Keeping a competitive edge in the cybersecurity ‘game’

Instead of thinking of cybersecurity as a problem, IT leaders should look at it through the lens of a game — and threat intelligence gives your team the competitive edge.

The post Keeping a competitive edge in the cybersecurity ‘game’ appeared first on CyberScoop.

Continue reading Keeping a competitive edge in the cybersecurity ‘game’

CrowdStrike: Attackers focusing on cloud exploits, data theft

CrowdStrike’s new threat report sees a big increase in data theft activity, as attackers move away from ransomware and other malware attacks, as defense gets better, and the value of data increases.
The post CrowdStrike: Attackers focusing on cloud exp… Continue reading CrowdStrike: Attackers focusing on cloud exploits, data theft

US National Cyber Director plans Japan trip to bolster digital cooperation

Inglis’s trip reflects Japan’s status as an increasingly important ally on cybersecurity, particularly as the administration focuses more on China.

The post US National Cyber Director plans Japan trip to bolster digital cooperation appeared first on CyberScoop.

Continue reading US National Cyber Director plans Japan trip to bolster digital cooperation

How purple team operations helped defend the Pentagon — and can help your security team today.

The purple team construct is changing cybersecurity for the better. Here is how you build, lead, and manage effective purple team operations.
The post How purple team operations helped defend the Pentagon — and can help your security team today. appea… Continue reading How purple team operations helped defend the Pentagon — and can help your security team today.

NSA cyber director explains why US missed suspected Russian espionage operation

When Russia’s Foreign Intelligence Service staged a sweeping espionage campaign targeting hundreds of U.S. companies and federal government agencies last year, it was a private sector cybersecurity firm that first uncovered the operation, not the U.S. government. Lawmakers have asked in recent weeks why the U.S. intelligence community appears to have gaps in its visibility into foreign hacking, and whether the National Security Agency needs new surveillance authorities. But the NSA’s cybersecurity director, Rob Joyce, suggested that that may not be the best solution. “Inside the U.S. you would expect us to have the best tools and capabilities, but instead what we’re finding — in General Nakasone’s words — is we don’t even see the dots, let alone connect the dots,” Joyce said at CyberTalks, a summit presented by CyberScoop. The NSA Cybersecurity Directorate, which Joyce leads, is responsible for preventing and eradicating threats from foreign hackers targeting U.S. entities. […]

The post NSA cyber director explains why US missed suspected Russian espionage operation appeared first on CyberScoop.

Continue reading NSA cyber director explains why US missed suspected Russian espionage operation

Lawmakers want DOD to share more info with Americans on deterring hacks

Lawmakers on Capitol Hill are clamoring for the U.S. government to better communicate what it’s doing to fend off foreign hackers, a concern that has come front and center in recent days as Americans have queued up at gas stations following a ransomware attack against a major U.S. pipeline company. Colonial Pipeline, the largest pipeline in the country, temporarily had to shut down operations earlier this month in response to a ransomware attack impacting its IT networks. The company shut down operations to prevent the malicious software from spreading to its operational networks. The incident has raised questions about the fragility of U.S. critical infrastructure cybersecurity, and Rep. Elissa Slotkin, D-Mich., indicated Friday she wants the U.S. government to tell the American people more about what it’s doing to try to prevent these kinds of attacks in the first place. ”It is so hard to explain to the American public […]

The post Lawmakers want DOD to share more info with Americans on deterring hacks appeared first on CyberScoop.

Continue reading Lawmakers want DOD to share more info with Americans on deterring hacks

GAO Finds Gaps in DoD Cyberdefenses, Highlights Importance of Breach and Attack Simulation Tools

AttackIQ’s Security Optimization Platform gives an agency a proactive—rather than a reactive—security posture. It enables continuous validation of security controls to definitively establish the effectiveness of key initiatives, to include zero-trust c… Continue reading GAO Finds Gaps in DoD Cyberdefenses, Highlights Importance of Breach and Attack Simulation Tools

The NSA has a new interim cybersecurity director

Dave Luber is serving as the National Security Agency’s cybersecurity director in an interim manner as the agency transitions in new leadership in the Biden administration, CyberScoop has learned. The Biden administration this month tapped the most recent director, Anne Neuberger, to join the White House National Security Council. And while the NSA Cybersecurity Directorate recently selected Rob Joyce, the NSA’s top intelligence liaison in the U.K., to take on the role as NSA cybersecurity director, he has not yet taken up the reins. Luber, a longtime NSA and Cyber Command employee, previously served as the executive director of Cyber Command, the Department of Defense’s offensive and defensive cyber-operations arm. In that role, as the third-in-command and highest-ranking civilian post at Cyber Command, Luber led approximately 12,000 personnel, including those who work to defend Pentagon networks from intruders and those who run military cyber-operations in support of the U.S. military’s […]

The post The NSA has a new interim cybersecurity director appeared first on CyberScoop.

Continue reading The NSA has a new interim cybersecurity director

White House to release maritime cybersecurity update

The National Security Council is planning to issue a cybersecurity update to the U.S. government’s national maritime security strategy Tuesday, multiple senior administration officials tell CyberScoop. The update, which administration officials first teased last September, will prompt federal agencies to develop more streamlined cybersecurity standards for organizations in the maritime transportation system (MTS), which includes seaports, vessel owners and operators and terminal operators, according to administration strategy documents obtained by CyberScoop. The update from the White House also is aimed at promoting more information-sharing on maritime cyberthreats with the private sector, streamlining the information-sharing process and prompting the U.S. government to establish maritime cybersecurity-focused workforce programs. The NSC is releasing the National Maritime Cybersecurity Plan as part of a recognition that there are gaps in U.S. maritime security, officials said. A chief concern is that disruptions to ports and shipping could send shockwaves through the U.S. economy. More directly for […]

The post White House to release maritime cybersecurity update appeared first on CyberScoop.

Continue reading White House to release maritime cybersecurity update

CISA Alert: Sophisticated, Ongoing Cyberattacks Go Beyond SolarWinds

CISA warns government agencies & critical infrastructure providers about sophisticated APT cyberattacks that go beyond breaching the SolarWinds Orion platform.
The post CISA Alert: Sophisticated, Ongoing Cyberattacks Go Beyond SolarWinds appeared f… Continue reading CISA Alert: Sophisticated, Ongoing Cyberattacks Go Beyond SolarWinds