GAO criticizes rollout of two key Trump administration cyber initiatives

In September 2018, the White House announced a new federal cybersecurity strategy to make critical infrastructure more resilient to hacking, shore up supply chains and “identify, counter, disrupt, degrade and deter behavior in cyberspace.” The ambitious document, which the White House described as the United States’ “first fully articulated cyber strategy” in 15 years, aimed to reduce the occurrence of damaging cyberattacks on U.S. interests. Two years later, a review of the strategy by the Government Accountability Office, a nonpartisan congressional agency, has found key gaps in the way the White House is trying to execute that plan. In the face of persistent cyber-threats from foreign powers, the Trump administration’s effort to mobilize resources to fix important U.S. security weaknesses risks coming up short without a better plan to execute the strategy, GAO said in a report published Tuesday. The National Security Council’s implementation plan for the strategy does not include […]

The post GAO criticizes rollout of two key Trump administration cyber initiatives appeared first on CyberScoop.

Continue reading GAO criticizes rollout of two key Trump administration cyber initiatives

Senior Department of Energy cyber official to step down

Bruce Walker, who has served as a senior Department of Energy official focused on cybersecurity since 2017, is leaving his post later this month to work at a security nonprofit, CyberScoop has learned. As an assistant Energy secretary, Walker has been a key player in the department’s efforts to protect U.S. utilities from state-sponsored hacking threats. He also has helped implement a White House executive order in May that keeps federal agencies and companies from installing risky foreign-owned equipment in the electric sector. Walker confirmed to CyberScoop that he will continue some of this work in the nonprofit sector by joining a new resiliency organization — dubbed the Analysis & Resilience Center — that helps financial and energy companies protect themselves from cyberthreats. Walker previous spent nearly two decades at New York utility Con Edison. At the Department of Energy, Walker has worked closely with Alexander Gates, a National Security Agency veteran who was […]

The post Senior Department of Energy cyber official to step down appeared first on CyberScoop.

Continue reading Senior Department of Energy cyber official to step down

The Connection Between Cloud Service Providers and Cyber Resilience

Cloud service providers offer great performance and resilience, but ultimately it is up to individual organizations to determine whether these long-known advantages outweigh the possible downsides.

The post The Connection Between Cloud Service Providers and Cyber Resilience appeared first on Security Intelligence.

Continue reading The Connection Between Cloud Service Providers and Cyber Resilience

Stick the Landing: 6 Steps to Broaden Your Cyber Resilience Web

Cyber resilience is now critical to speeding remediation and boosting recovery after a security event. To stick the landing, enterprises must move beyond funnels and embrace web-based design.

The post Stick the Landing: 6 Steps to Broaden Your Cyber Resilience Web appeared first on Security Intelligence.

Continue reading Stick the Landing: 6 Steps to Broaden Your Cyber Resilience Web

Increase Automation to Overcome Cyber Resilience Challenges

Orchestration and automation capabilities are a core pillar of a comprehensive approach to cyber resilience.

The post Increase Automation to Overcome Cyber Resilience Challenges appeared first on Security Intelligence.

Continue reading Increase Automation to Overcome Cyber Resilience Challenges

10 Tenets for Cyber Resilience in a Digital World

Companies are facing increased and complex cybersecurity challenges in today’s interconnected digital economy. The cyber threats have become more sophisticated and may harm a company via innovative new forms of malware, through the compromise of … Continue reading 10 Tenets for Cyber Resilience in a Digital World

5 Cloud Security Considerations to Ensure a Successful Migration

While there is no single method for all sizes and types of cloud migration, you can significantly bolster your chances of cloud security success by leveraging best practices and a well-executed plan.

The post 5 Cloud Security Considerations to Ensure a Successful Migration appeared first on Security Intelligence.

Continue reading 5 Cloud Security Considerations to Ensure a Successful Migration

Cyber Storm 2020 could be DHS’s most rigorous drill for critical infrastructure yet

Every two years, the Department of Homeland Security hosts a large-scale exercise to test critical infrastructure companies’  ability to respond to a disruptive, hypothetical cyberattack. With more threat data to draw on than ever, DHS officials hope next spring’s Cyber Storm exercise will be the most rigorous test of participants’ response plans to date, driving home the interdependence of critical infrastructure sectors in new ways. Cyber Storm 2020 will focus more on collaborating with state and local officials to recover from an incident than previous drills, according to Brian Harrell, assistant director for infrastructure security at DHS’s Cybersecurity and Infrastructure Security Agency (CISA). In another twist, planners are looking to incorporate insider threats into the scenario, he said. Participants, which are expected to include representatives of the energy, financial and communications sectors, cyberthreat information-sharing organizations, and other federal agencies, will have to “bring a [hypothetical] cyber incident to resolution as quickly as possible… [to] restore some of these key services as quickly as […]

The post Cyber Storm 2020 could be DHS’s most rigorous drill for critical infrastructure yet appeared first on CyberScoop.

Continue reading Cyber Storm 2020 could be DHS’s most rigorous drill for critical infrastructure yet

Microsoft, Hewlett Foundation preparing to launch nonprofit that calls out cyberattacks

Microsoft and the Hewlett Foundation are preparing to launch a nonprofit organization dedicated to exposing the details of harmful cyberattacks and providing assistance to victims in an effort to highlight their costs, CyberScoop has learned. Known to its organizers as the “Cyber Peace Institute,” the nonprofit is expected to debut in the coming weeks, according to multiple sources who have discussed it with the organizers. The institute aims to investigate and provide analytical information on large-scale attacks against civilian targets, assess the costs of these attacks and give security tools to both individuals and organizations that will help them become more resilient, according to a description of the nonprofit provided during a session at the 2019 B-Sides Las Vegas cybersecurity conference. “We have a shared global responsibility to prevent the Internet from becoming ‘weaponized’ by increasing attacks by criminal groups and state actors alike,” the description reads. “We already have global organizations to tackle […]

The post Microsoft, Hewlett Foundation preparing to launch nonprofit that calls out cyberattacks appeared first on CyberScoop.

Continue reading Microsoft, Hewlett Foundation preparing to launch nonprofit that calls out cyberattacks