Russia’s invasion kicks Senate into cybersecurity law mode
- Reference: 1646440819
- News link: https://www.theregister.co.uk/2022/03/05/senate-cyber-bill/
- Source link:
This draft law would, among other steps, force critical infrastructure companies to report attacks and ransomware payments.
The [1]Strengthening American Cybersecurity Act of 2022 , which now goes to the House, would put into law some of the regulations the Biden Administration and some members of Congress have been advocating for since the onslaught of high-profile ransomware attacks last year, including those on such companies as Colonial Pipeline and meat processor JBS Foods.
[2]
Both attacks were made by cybercriminal groups – DarkSide and [3]REvil – with links to Russia.
[4]
[5]
The bill passed by the Senate this week would require civilian federal agencies and the owners of US critical infrastructure organizations – such as power plants, hospitals and shipping ports – to report cyberattacks to Homeland Security within 72 hours. In addition, they would have to report a ransomware payment within 24 hours.
While the White House has given its support to the bill – though an official there has said administration staff will work with the House to ensure all the necessary provisions are in it – the Department of Justice (DOJ) [6]reportedly pushed back on it, saying the FBI should also be on the list of agencies contacted by companies that have been attacked. The bill currently requires companies to notify the Cybersecurity and Infrastructure Security Agency (CISA), part of the Department of Homeland Security.
[7]
Deputy Attorney General Lisa Monaco told Politico the "bill as drafted leaves one of our best tools, the FBI, on the sidelines and makes us less safe at a time when we face unprecedented threats." FBI Director Christopher Wray agreed, adding that it would hurt the agency's response to attacks.
[8]FISMA's a fizzer, says Cisco, and calls on Congress to get cyber security policy right – pronto
[9]Microsoft president asks Congress to force private-sector orgs to admit when they've been hacked
[10]DEF CON offers beginner-level Spot the Fed this year: He'll be on stage giving a keynote
[11]New UK product security law won't be undercut by rogue traders upping and vanishing, government boasts
In addition, some in the cybersecurity field have questions about the proposed law, including the requirement to alert Homeland Security of a ransomware payment.
"Reporting ransomware payments can be immensely useful if there is immunity for making the payments," John Bambenek, principal threat hunter at cybersecurity firm Netenrich, told The Register .
"There is no, nor ever has been, any evidence that banning ransomware payments will work or be successful. Creating a reporting mechanism to report one's own 'wrongdoing' hasn't worked in the past. If – and only if – the government stops its saber rattling towards victims who make payments, then this policy has a chance at success."
Horse, meet stable door
The Biden Administration has made cybersecurity a priority. The President has signed executive orders and a memorandum pushing to improve the cybersecurity posture of the government and US businesses.
The National Security Council in June 2021 sent a memo urging them to take the ransomware threat seriously and in October ran out several initiatives that included going after the criminals orchestrating these attacks and requiring the reporting of incidents and ransomware payments.
In January, the FBI, NSA, and CISA [12]warned US businesses about the threat of Russian state-sponsored gangs as tensions rose between Russia, the United States, and European nations over President Putin's intentions for Ukraine.
[13]
Government agencies and cybersecurity companies have urged ransomware victims not to pay the demanded ransom to get their scrambled or deleted data restored, arguing that doing so pays for future attacks, makes companies more likely to be attacked and attacked again, and doesn't guarantee they will get back control of all their data.
A [14]study in October 2021 by cybersecurity firm ThycoticCentrify – now known as Delinea – claimed 83 per cent of ransomware victims in its survey paid their extortionists.
Spokespeople for Senators Gary Peters (D-MI) and Rob Portman (R-OH) said the cybersecurity bill included many changes both the DOJ and FBI pushed for and disagreed it would make the country less safe.
The escalating war in Ukraine and the ongoing [15]threat of Russian cyberattacks seems to have helped accelerate the Senate's passage of the legislation, which was taken out of the defense budget appropriation in December.
The requirements included, which go beyond just reporting incidents, are largely common-sense measures to protect organizations
"It's no surprise with recent incidents and an increased threat of cyberattacks that this bill has gained bipartisan support," Tim Erlin, vice president of strategy at cybersecurity company Tripwire, told The Register . "The requirements included, which go beyond just reporting incidents, are largely common-sense measures to protect organizations. Making progress on cybersecurity has been a clear objective for the administration and the passage of this legislation in the Senate is evidence of that progress."
That said, some cybersecurity experts said more needs to be done. Erlin noted that the "scope of this legislation is limited to civilian federal agencies and critical infrastructure. The vast majority of commercial organizations won't be directly impacted."
Netenrich's Bambenek said that those that will be most affected are federal government vendors that are required to use FedRAMP, a government program designed to address security assessment and monitoring of cloud products and services.
"The new legislation, and whatever implementing regulations are passed to support it, will start to tackle, among other things, software supply-chain issues," he said.
"How organizations begin to tackle that will also impact the B2B ecosystem as well. It will, by no means, solve the problem of supply-chain compromises, but it is definitely a step down the road to visibility and risk management."
Alex Ondrick, director of security operations at incident response specialist BreachQuest, told The Register that the legislation is well intentioned but doesn't define specifics.
"This seems to be a good first step towards formalizing cybersecurity policy at the national level, but this is only the beginning of the journey," Ondrick said. "In an ideal world, further policy developments would 'nest' considerations at the director [and] C-level, with further-developed and fully-defined technical next steps at the analyst level." ®
Get our [16]Tech Resources
[1] https://www.congress.gov/bill/117th-congress/senate-bill/3600/all-info
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YiLviojCpB1OVnBrulhsKQAAAM0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.theregister.com/2021/06/23/revil_ransomware_lv/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YiLviojCpB1OVnBrulhsKQAAAM0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YiLviojCpB1OVnBrulhsKQAAAM0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.politico.com/news/2022/03/02/doj-hack-reporting-bill-fbi-less-safe-00013420
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YiLviojCpB1OVnBrulhsKQAAAM0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2021/08/13/cisco_ciso_advisor_calls_on/
[9] https://www.theregister.com/2021/02/24/microsoft_solarwinds_congress_disclosure_law/
[10] https://www.theregister.com/2021/07/26/in_brief_security/
[11] https://www.theregister.com/2021/12/02/psti_bill_phoenixing_dcms_response/
[12] https://www.theregister.com/2022/01/19/us_cisa_ukraine_cross_infection_warning/
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YiLviojCpB1OVnBrulhsKQAAAM0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://thycotic.com/resources/ransomware-survey-and-report-2021/
[15] https://www.theregister.com/2022/02/24/cyberwarfare_russia_ukraine/
[16] https://whitepapers.theregister.com/
Air gaps don't work
Sanctions will be quickly lifted and Putin obviously knows this. Tucker Carlson and his comrades at Fox may be "anti-Putin" right now, but they'll turn on a dime to be back to pumping Russian interests soon enough. Watch the "Russia as Victim" stories out of Tucker's mouth, as he seeks to get the sanctions lifted.
"Cyber-security" is nothing, if you cannot physically protect your countries from invaders and Putin-puppets. There is no air-gapped system, if Putin controls that air.
Canada's Trudeau says NATO must avoid war with Russia at all cost. Trudeau would say the same when Russia attacks Germany. NATO will *never* defend any NATO member's soil, there will always be nay-sayers among the group, as long as the interests of everyone in the group is not fully aligned. Here Trudeau does not feel threatened, so he does not back NATO action in Europe. The weakest link is the break point.
Suppose Putin puts another puppet in the USA, a Trump Mk II, and attacks Canada. NATO's European partners would not help Canada. Their interests are not totally aligned with Canada's, and US would be blocked by the Trump Mk II Puppet. The lack of NATO consensus, would be used as an excuse not to help Canada by other NATO members.
"One for all and all for one"? No, "100% consensus or 100% inaction".
Trudeau would scream "help us help us, just some air support, something" as Canadian cities are bombed and charred Canadian bodies litter the streets, and Europe would say "well we're focussed on NATO an there isn't a NATO consensus to help you, so our hands are tied".
A Trump Mk II would feed Putin the location of Trudeau and his family, so Putin can have them killed, and a puppet government installed. The exact thing, they keep attempting to do to Zelenskyy and Ukraine. Think of all that US intel that made its way to Russia under Trump Mk I. Trudeau and his family's GPS location would be lived streamed to Moscow.
The more partners in NATO, the weaker it is, because the interests of each partner are not sufficiently closely aligned, the more they can find a reason to shrug their shoulders and do nothing.
France's Macron has the right idea, there has to be a new security mechanism for Europe. One that will actually defend Europe from Russia. If there's one clear thing out of this, it's that NATO cannot defend Europe and the only thing protecting Europe is mud and poorly maintained Russian tyres.
Oh, but air-gap your systems, that'll help right?
Report ransomware payments? Seriously?
It's past time to ban ransomware payments, complete with prison terms for anyone who authorizes them.