Michael Sulmeyer, who held cyber posts under Trump and Obama, gets Biden White House gig

Michael Sulmeyer, a senior adviser to National Security Agency and U.S. Cyber Command leader Gen. Paul Nakasone, will take the position of senior director for cyber in the Biden White House. Sulmeyer’s selection came with no formal announcement. Instead, the transition website posted his position Monday evening. Sulmeyer is a cybersecurity veteran with broad experience, one of many to join the Biden administration. He’s also one of several whose tenures have included roles in the Trump administration. Beyond serving under Nakasone, he also served in the Obama administration at the Defense Department, where he was director for plans and operations for cyber policy. Between roles in the Trump and Obama administrations, he was director of the Belfer Center’s Cyber Security Project at the Harvard Kennedy School. He also wrote extensively for Lawfare on subjects like election security, federal cybersecurity strategy and DOD-related cybersecurity issues. In the past, the National Security […]

The post Michael Sulmeyer, who held cyber posts under Trump and Obama, gets Biden White House gig appeared first on CyberScoop.

Continue reading Michael Sulmeyer, who held cyber posts under Trump and Obama, gets Biden White House gig

Grant Schneider steps down as federal CISO, heads to private sector

Grant Schneider, who has spent nearly three decades in the federal government, is leaving his post as the Trump administration’s chief information security officer for the private sector. Schneider is joining the Washington, D.C., office of law firm Venable as a senior director of cybersecurity services, the firm said in a statement Tuesday. Ari Schwartz, a Venable executive who worked in the Obama administration, lauded Schneider’s work as a federal official on supply chain security and encryption. Schneider spent more than 20 years at the Defense Intelligence Agency, the Pentagon’s spying arm, culminating in a multi-year tenure as chief information officer. He was also a senior official at the Office of Personnel Management in 2015 and 2016 as the agency continued to cope with the fallout of its massive 2014 data breach. At the National Security Council, Schneider was influential in cybersecurity policymaking. He headed the Vulnerabilities Equities Process, the […]

The post Grant Schneider steps down as federal CISO, heads to private sector appeared first on CyberScoop.

Continue reading Grant Schneider steps down as federal CISO, heads to private sector

Classified data key to new acquisition approach, Federal CISO says

The strength of a new federal acquisition council on supply-chain security lies in its ability to directly involve classified information in agencies’ decisions to buy products and services, according to a senior White House official. The new regime contrasts from previous “whack-a-mole” approaches that were confined to the unclassified space, Federal Chief Information Officer Grant Schneider said Thursday at the 2019 Security Through Innovation Summit, presented by McAfee. He chairs the nascent interagency Federal Acquisition Security Council, which was established by a law signed by President Donald Trump in December. The law allows classified information to be used to support risk assessments while assuring the intelligence community that data is protected, Schneider added. “The Binding Operational Directive on Kaspersky was completely through open-source [information],” Schneider said, referring to a 2017 federal order that, due to security concerns, banned civilian agencies from using products made by Moscow-based Kaspersky Lab. “If we […]

The post Classified data key to new acquisition approach, Federal CISO says appeared first on CyberScoop.

Continue reading Classified data key to new acquisition approach, Federal CISO says

National Security Council cyber chief: Criminals are closing the gap with nation-state hackers

Cybercriminals are catching up to nation-states’ hacking capabilities, and it’s making attribution more difficult, the National Security Council’s senior director for cybersecurity policy said Thursday. “They’re not five years behind nation-states anymore, because the tools have become more ubiquitous,” said Grant Schneider, who also holds the title of federal CISO, at the Security Through Innovation Summit presented by McAfee and produced by CyberScoop and FedScoop. Schneider told CyberScoop that he thinks the implants cybercriminals are using in their cyberattacks have been improving. “The actual sophistication of the tool … is better with criminals than we saw in the past.” Steve Grobman, the chief technology officer for McAfee, told CyberScoop that advanced crooks are behaving more corporately, which means they are able to proliferate higher-quality hacking tools. “One of the things we’re seeing on the business-model side is cybercriminals are starting to use innovative processes like franchises — affiliate groups where a cybercriminal will develop technology [and] make it […]

The post National Security Council cyber chief: Criminals are closing the gap with nation-state hackers appeared first on CyberScoop.

Continue reading National Security Council cyber chief: Criminals are closing the gap with nation-state hackers

U.S. Cyber Command has shifted its definition of success

U.S. Cyber Command is shifting the way it measures success from solely military outcomes to how the command enables other government agencies to defend against foreign offensive cyber threats. Brig. Gen. Timothy Haugh, who is in charge of Cyber Command’s Cyber National Mission Force, said on Tuesday at an event hosted by the Atlantic Council that success is “not necessarily [about] the department’s outcome,” but is instead about “how can we enable our international partners [and] our domestic partners in industry to be able to defend those things that are critical to our nation’s success.” Haugh said Cyber Command is doing its job right if agencies are taking their own actions: State Department issuing démarches, Department of Homeland Security releasing alerts, and Treasury Department announcing sanctions “based off of information that is derived from our operations.” In the past, Haugh said he believes that these outcomes may not have been considered as wins. […]

The post U.S. Cyber Command has shifted its definition of success appeared first on CyberScoop.

Continue reading U.S. Cyber Command has shifted its definition of success

PPD-20 successor has yielded ‘operational success,’ Federal CISO says

A revamped policy framework for offensive U.S. cyber operations is much quicker than its predecessor and has yielded “operational success,” a top White House cybersecurity official said Tuesday. Last August, President Donald Trump rescinded the Obama-era policy, known as Presidential Policy Directive 20, which governed U.S. hacking operations, and replaced it with the new framework. Critics said PPD-20’s intricate interagency process unnecessarily delayed offensive operations, while advocates called it an important mechanism for accounting for all of the potential repercussions of a cyberattack. The new structure “gives more authority to the people who need to actually make those decisions” about offensive operations, Grant Schneider, the federal information security officer, said at an event hosted by the nonprofit Intelligence and National Security Alliance. U.S. officials are focused on ensuring that the Pentagon “has the tools available to leverage offensive cyber capabilities,” he added. The remarks from Schneider, the National Security Council’s top defensive-focused […]

The post PPD-20 successor has yielded ‘operational success,’ Federal CISO says appeared first on CyberScoop.

Continue reading PPD-20 successor has yielded ‘operational success,’ Federal CISO says

White House makes Grant Schneider the top cybersecurity official in government

Veteran government IT official Grant Schneider will serve as federal chief information security officer, an influential policy role charged with implementing cybersecurity practices across the executive branch, the Office of Management and Budget announced Thursday. “Grant Schneider brings extensive cybersecurity experience well aligned to lead efforts in securing government systems from cyberattacks,” Margaret Weichert, OMB’s deputy director for management, said in a statement. “As chief information security officer, Grant will play a key role in making sure the federal government’s technology networks are safe and secure,” she added. The federal CISO chairs the CISO Council, which allows collaboration across agencies on issues like identity management and vulnerability response. Schneider had been serving as federal CISO on an acting basis until today. He is also a senior director for cybersecurity at the National Security Council (NSC), where he helps manage the government’s cyber defense strategy. In June, the White House tapped […]

The post White House makes Grant Schneider the top cybersecurity official in government appeared first on Cyberscoop.

Continue reading White House makes Grant Schneider the top cybersecurity official in government

DHS won’t reverse ban on Kaspersky products, court docs show

The Department of Homeland Security refuses to reverse the ban on Kaspersky products after the Russian anti-virus company sued the agency for its September 2017 directive, according to new court documents. Last month, Kaspersky Lab filed a preliminary injunction in U.S. federal court to overturn the Binding Operational Directive (BOD) that bans the company’s anti- virus software on federal computers. In a response to the court Tuesday, DHS is requesting the court to deny the request from Kaspersky Lab, stating that even if the BOD is overturned, the congressional ban on Kaspersky products still stands. Aside from the directive, the 2018 National Defense Authorization Act prohibits federal agencies from using Kaspersky products. That ban goes into effect on Oct. 1, 2018. “Any new investment in Kaspersky software would frustrate agency efforts to bring their information systems in compliance with the NDAA,” acting Federal Chief Information Security Officer (CISO) Grant Schneider said in a accompanying […]

The post DHS won’t reverse ban on Kaspersky products, court docs show appeared first on Cyberscoop.

Continue reading DHS won’t reverse ban on Kaspersky products, court docs show

Double role for White House cyber aide shows challenges for new administration

The remarkable decision to have a single official fill two key White House cybersecurity posts has highlighted both the Trump administration’s commitment to securing federal IT networks as a national security priority and its inability to fill key cyber jobs. Grant Schneider, the current deputy federal CISO, who has been acting CISO since his boss left mid-January, will also begin doing the job of senior director within the cybersecurity directorate of the National Security Council staff, the White House let slip this week. The federal CISO job is based in the Office and Management and Budget, which, like the NSC, is within the Executive Office of the President. Several former NSC staffers told CyberScoop the dual-hatting arrangement makes sense in the short term, but they questioned its viability in the long run. The administration made fixing federal government IT systems a priority under the cybersecurity executive order President Trump signed in May. The CISO’s office is operationally responsible for […]

The post Double role for White House cyber aide shows challenges for new administration appeared first on Cyberscoop.

Continue reading Double role for White House cyber aide shows challenges for new administration

Federal CISO to get second hat as National Security Council’s cyber director

Grant Schneider, the acting federal CISO who has been running the shop since his boss left just before the inauguration, is getting a second hat within the White House as a senior director for cybersecurity at the National Security Council, an administration official tells CyberScoop. Schneider will take over one of the “recently vacated senior director positions within the Cybersecurity Directorate on the NSC led by Rob Joyce,” the official said in an email. Schneider is the deputy CISO, but has been acting up since federal CISO Gregory Touhill departed in mid-January. “In order to increase synergy and alignment of national and federal cybersecurity strategy, policy, and guidance,” Schneider will continue to do his job at the Office of Management and Budget, the official added. “He will continue to lead and manage the Federal CISO team at OMB as well as the ‘Homeland’ portfolio within the NSC Cybersecurity Directorate.” That position was most recently filled […]

The post Federal CISO to get second hat as National Security Council’s cyber director appeared first on Cyberscoop.

Continue reading Federal CISO to get second hat as National Security Council’s cyber director