News: 1611612036

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Biden said to be assembling cyber dream team to sort out US govt computer security

(2021/01/25)


President Biden is preparing to assemble a crack US government cybersecurity team, and has pledged $10bn in funding to shore up the defenses of Uncle Sam's computer networks.

Former NSA and National Security Council official Jen Easterly will [1]reportedly be put forward as National Cyber Director, a role that will oversee the federal government's cybersecurity activities. Easterly was part of the team that set up US Cyber Command at the Dept of Defense, she served in Iraq in 2006 using signals intelligence to track down targets, and is right now Head of Firm Resilience at global financial giant Morgan Stanley.

[2]

The National Cyber Director (NCD) is an entirely new post that was created by this year's must-pass [3]military budget bill .

In addition, former assistant secretary for cyber policy at Homeland Security Rob Silvers is expected to be put forward as director of the Cybersecurity and Infrastructure Security Agency (CISA), which advises the public and private sector on computer security. He is thus set to replace Chris Krebs who [4]was fired by President Trump in November after he not only refused to say that the presidential election results were fraudulent but said that the election had been “the most secure in American history.” Silvers held the aforementioned Homeland Security post during Obama's final year as president.

[5]

And Eric Goldstein, another former Homeland Security official, is expected to be tapped for the executive assistant director of CISA’s Cyber Division. Goldstein, who served under the Obama administration, was the head of engagement at Homeland Security's Office of Cybersecurity and Communications.

All the above are rumors; there is no official word yet from the top.

Who's down with NCD?

The NCD will “serve as the principal advisor to the President on cybersecurity policy and strategy” and be the point man in the US government for all things cyber, including offering “advice and consultation to the National Security Council and its staff, the Homeland Security Council and its staff, and relevant Federal departments and agencies.”

SolarWinds: Hey, only as many as 18,000 customers installed backdoored software linked to US govt hacks [6]READ MORE

Most importantly, given the recent [7]SolarWinds backdoor – in which it appears the Russian government gained access to the email systems of several key US government departments via tainted network-monitoring software – the NCD will be responsible for “preparing the response by the federal government to cyberattacks and cyber campaigns of significant consequence across Federal departments and agencies.”

In a speech in December, Biden described the [8]SolarWinds compromise as a “grave threat to national security,” and later said the United States needed to “innovate and reimagine our defenses against growing threats in new realms like cyberspace.”

The rumored quick hires are welcome after President Trump had seemingly gone out of his way to diminish the issue of cybersecurity during his presidency, including [9]allegedly shifting funds away to instead build a Mexican border wall.

If there's one criticism of the approach taken by Biden so far it's that all his picks have been primarily public-sector people with relatively limited experience in the corporate world. The internet remains a network run almost entirely over private networks.

The president has [10]ring-fenced about $10bn in funding in his upcoming COVID-19 pandemic relief plan to improve the US government's cybersecurity efforts. The vast majority of funding will go to CISA and the General Services Administration (GSA): $9bn for new cybersecurity services split between them; $200m will go to hiring tech experts for the US Digital Service; $300m to funding new GSA programs; and $690m to CISA for better security monitoring and incident response.

[11]

However, the funding is only at the proposal stage and there's no sign yet that Congress is in a mood to play along any time soon. ®

Get our [12]Tech Resources



[1] https://www.reuters.com/article/us-usa-biden-cyber/after-big-hack-of-u-s-government-biden-enlists-world-class-cybersecurity-team-idUSKBN29R18I

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YA9NhWdAqh2AOQUURh1jfAAAAAI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.congress.gov/bill/116th-congress/house-bill/6395/text/enr

[4] https://www.theregister.com/2020/11/18/trump_fires_krebs/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YA9NhWdAqh2AOQUURh1jfAAAAAI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2020/12/15/solar_winds_update/

[7] https://www.theregister.com/2021/01/19/fireeye_solarwinds_code/

[8] https://www.theregister.com/2021/01/21/microsoft_solarwinds_deep_dive/

[9] https://www.reuters.com/article/us-usa-immigration-funds/trump-administration-taps-disaster-cyber-funds-to-cover-immigration-idUSKCN1VH2F7

[10] https://mailchi.mp/bidentransition/ascertainment-news-statement-3589994?e=9df75180c1

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YA9NhWdAqh2AOQUURh1jfAAAAAI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://whitepapers.theregister.com/

About time

martinusher

We spend a fortune on network snooping, its pretty much all the NSA does. Given this you'd think that they'd have not only been actively developing exploits for offense but also actively researching defensive measures. They haven't, and as a result everyone's been left to more or less fend for themselves for decades. Its business for some, certainly, but the threat to national security and the losses through crime are intolerable, a huge burden on the economy.

It always annoys me to read of someone losing money through a scam with the banks in particular throwing up their hands and saying "What can we do?", especially when we know that government monitors transactions for illegal activity all the time in the name of 'sanctions'. I think government has a warped set of priorities -- its so busy fighting Cold War 2 that they can't be bothered to deal with real threats. We see things through a very narrow geopolitical lens, its all about twarting "the Russians" or "the Chinese" that it never occurs to us that there are criminals all over the place -- sure, governments may well be in there someplace but where there's money to be made there's plenty of others trying their luck.

It is enough to make one sympathize with a tyrant for the determination
of his courtiers to deceive him for their own personal ends...
-- Russell Baker and Charles Peters