Federal panel says agencies need to focus on harmonizing cyber regulations

Federal panel says agencies need to focus on harmonizing cyber regulations

Comment

Welcome to The Cybersecurity 202! Why am I obsessed with eating mass-manufactured cherry pies and orange cupcakes of late? (I won’t name the brand.) It’s unhealthy and I get grossed out right after doing it, then, bam, next day, I’m ready for more of them.

Reading this online? Sign up for The Cybersecurity 202 to get scoops and sharp analysis in your inbox each morning.

Below: The Defense Department says it secured a previously exposed server that leaked sensitive military emails, and gaming giant Activision falls victim to a phishing scheme. First: 

An advisory committee recommended the creation of an office to deconflict cyber rules

The Biden administration needs to take numerous steps to deconflict and organize the proliferation of cybersecurity regulations, according to a report that a presidential advisory committee approved Tuesday.

That includes things like creating an office within the Cybersecurity and Infrastructure Security Agency to harmonize cybersecurity rules across the federal government, or directing a trio of federal agencies to coordinate with foreign governments to develop consensus cybersecurity standards.

The recommendations arrive as the U.S. cyber scene awaits publication of the Biden administration’s national cybersecurity strategy, the White House pushes for mandates on numerous industries, and CISA writes a rule to require critical infrastructure owners and operators to report major cyber incidents to the agency.

The advisory panel, named the National Security Telecommunications Advisory Committee (NSTAC), voted Tuesday to send the report to Biden for his consideration.

The committee draws its membership from the business community, with a heavy emphasis on cybersecurity companies. Many industry groups have indicated opposition to the Biden administration pushing a more muscular federal role for cyber mandates.

But an official with the Office of the National Cyber Director, which led the writing of the national cybersecurity strategy, saw overlap between that strategy and the NSTAC report.

“The recommendations regarding regulatory harmonization align very well with the strategic goals of the strategy,” said Rob Knake, the acting principal deputy at the cyber director’s office.

One such recommendation is for CISA to establish an Office of Cybersecurity Regulatory Harmonization. There are already some federal initiatives with a similar mission, such as the Cyber Incident Reporting Council, and the Cybersecurity Forum for Independent and Executive Branch Regulators. But the new office would have the job of building expertise on cybersecurity regulation and assisting other federal agencies during the cybersecurity rulemaking process.

The report recommended housing the office in CISA for a few reasons, as incoming NSTAC chair Scott Charney, vice president for security policy at Microsoft, explained:

  • “The primary advantage of housing this effort in CISA is that most other departments, such as Treasury or [Health and Human Services], are primarily concerned” with the industries they regulate, Charney said. “By contrast, CISA’s focus on protecting critical infrastructures gives it a broader, cross-vertical perspective.”
  • “The proposed office would act in an advisory capacity to other regulators,” Charney said, “which is consistent with CISA’s existing interactions with regulators.”
  • Furthermore, he said, CISA’s parent agency, the Department of Homeland Security, is home to the aforementioned Cyber Incident Reporting Council. That council was formed as part of legislation Congress passed last year that directed CISA to write a rule requiring critical infrastructure owners and operators to report major cyberattacks within 72 hours.

Agencies writing cyber rules would have to report how their regulations align with the new office’s guidelines. 

Separate from the recommendations about the new office and how agencies would interact with it, the report calls on agencies to review their rules at least every five years and update them as needed. 

And “the Department of State and Department of Commerce, in coordination with the Department of Homeland Security, shall develop and execute a strategy to encourage more foreign government participation in the development and adoption of specific consensus standards,” the report states.

Recommendations that aren’t about harmonization

The report isn’t only about harmonizing regulations.

Among its other recommendations:

  • CISA and the General Services Administration should “draft core, universally applicable procurement language that clearly defines the government’s requirements and preferences” on secure software and services.
  • CISA should expand and enhance a federal program focused on scanning and monitoring services to help federal agencies better protect their networks.
  • CISA and the National Institute of Standards and Technology should form a partnership “focusing on transition to post quantum cryptography” — in other words, making computers safe against quantum computers that could break current encryption.

Private U.S. military emails were exposed online

The Defense Department on Monday afternoon said it secured a server that was left online without a password for two weeks, exposing internal military emails to anyone on the internet, TechCrunch’s Zack Whittaker reports.

The server, which was left without a password due to a misconfiguration, was hosted on Microsoft’s Azure government cloud for Defense Department customers. That platform is typically used to share sensitive but unclassified government data, but in this case it stored about three terabytes of internal military emails, including those related to the U.S. Special Operations Command. 

Anurag Sen, a security researcher who discovered the breach, said the exposed server contained military emails dating back years, with at least one file in particular including a completed SF-86 questionnaire full of highly sensitive personal and health information. 

The server is now inaccessible. U.S. Special Operations Command spokesperson Ken McGraw said in an email to TechCrunch on Tuesday that an investigation into the leak began Monday and is still underway.

“We can confirm at this point is no one hacked U.S. Special Operations Command’s information systems,” McGraw said. It’s not clear if anyone besides Sen found the server during the two weeks that it was exposed.

Supreme Court knocks down Wikipedia operator’s bid to challenge NSA oversight

The Supreme Court on Tuesday denied a request from the operator of Wikipedia to reopen a lawsuit against the National Security Agency challenging broad internet surveillance, Reuters’s Andrew Chung reports.

In 2015, the Wikimedia Foundation, represented by the American Civil Liberties Union, sought to confront the legality of NSA’s “upstream” program used to surveil foreign targets through the collection and searching of internet traffic on data transmission lines flowing into and out of the United States. The lawsuit alleges that the practice violates Americans’ right to privacy and freedom of speech.

The NSA has defended the surveillance by pointing to the Foreign Intelligence Surveillance Act of 2008. Its existence was leaked in 2013 by former NSA contractor Edward Snowden, who later fled to Russia. 

Tuesday’s decision upholds a lower court’s previous dismissal of the lawsuit because of the state secrets privilege, or a legal doctrine that can shut down litigation if disclosure of certain information, like details about the surveillance, would damage national security. 

Hacker gains access to Activision Slack, steals Call of Duty info

A hacker was able to breach a Slack channel of the game publishing giant Activision after convincing an employee to give them a two-factor authentication token, Motherboard’s Joseph Cox reports.

After the breach, the bad actor posted offensive messages from the targeted staff account and apparently stole information related to upcoming Call of Duty release dates, according to screenshots posted online by the cybersecurity collective vx-underground. 

Activision told Motherboard in a statement: “The security of our data is paramount, and we have comprehensive information security protocols in place to ensure its confidentiality. On Dec. 4, 2022, our information security team swiftly addressed an SMS phishing attempt and quickly resolved it.”

“Following a thorough investigation, we determined that no sensitive employee data, game code, or player data was accessed,” the statement added. Activision did not respond when asked specifically by Motherboard about the data that the hacker seemingly did access, such as the Call of Duty scheduling. 

The attack comes as the gaming sector is increasingly facing cyberthreats, with the industry seeing a 167 percent increase in web application attacks in 2021, and last year becoming the most targeted industry for distributed denial of service (DDoS) attacks. Last month, hackers broke into Riot Games, another gaming giant. In 2021, hackers breached Electronic Arts and CD Projekt.

White House mulls scaling up Login-dot-gov to reach every American (Federal Computer Week)

House Dems call for info on racially-motivated cyberattacks (NextGov)

Tor Project moves away from infrastructure ran by internet monitoring firm (Motherboard)

Hackers extort less money, are laid off as new tactics thwart more ransomware attacks (Wall Street Journal)

Ukraine’s volunteer cyber army could be model for other nations, experts say (Newsweek)

Hackers scored corporate giants’ logins for Asian data centers (Bloomberg News)

Civil liberties groups call for EU-wide ban on spyware (The Record)

Ukraine’s largest charity wants to raise $1.3 million for ‘cyber offensive’ (The Record)

  • The Atlantic Council holds a discussion with the authors of two new reports on Russian narratives to justify the war in Ukraine today at 9 a.m. 
  • The R Street Institute holds a webinar on the state of cybersecurity careers for Black professionals on Thursday at noon.
  • Former U.S. national security adviser John Bolton will join The Washington Post for a conversation about the war in Ukraine and rising tensions with China on Friday at 11 a.m. 

Thanks for reading. See you tomorrow.

Is Your Board Prepared for New Cybersecurity Regulations?

Is Your Board Prepared for New Cybersecurity Regulations?

Boards are now shelling out interest to the need to take part in cybersecurity oversight. Not only are the implications sparking concern, but the new rules are upping the ante and changing the game.

Boards have a specifically essential role to make certain acceptable administration of cyber danger as aspect of their fiduciary and oversight purpose. As cyber threats enhance and organizations around the world bolster their cybersecurity budgets, the regulatory group, together with the SEC, is advancing new prerequisites providers will will need to know about as they enhance their cyber strategy.

Most organizations we’ve analyzed focus on cyber defense alternatively than cyber resilience, and we consider that is a blunder. Resiliency is additional than just protection it’s a system for restoration and business continuation. Being resilient suggests that you’ve done as a lot as you can to defend and detect a cyber incident, and you have also finished as a great deal as you can to make certain you can proceed to operate when an incident takes place. A business who invests only in defense is not taking care of the danger connected with acquiring up and running yet again in the function of a cyber incident.

Our analysis implies that most board associates consider it’s not a matter of if, but when their firm will knowledge a cyber occasion. The top aim of a cyber-resilient firm would be zero disruption from a cyber breach. That will make the focus on resilience far more essential.

New SEC Rules Will Change the Board’s Part

In March 2022, the SEC issued a proposed rule titled Cybersecurity Danger Management, Technique, Governance, and Incident Disclosure.  In it, the SEC describes its intention to demand general public corporations to disclose no matter if their boards have users with cybersecurity experience: “Cybersecurity is by now amongst the prime priorities of lots of boards of directors and cybersecurity incidents and other challenges are regarded as a single of the greatest threats to providers. Accordingly, investors may locate disclosure of no matter whether any board members have cybersecurity skills to be crucial as they contemplate their investment in the registrant as nicely as their votes on the election of administrators of the registrant.”

The SEC will shortly need corporations to disclose their cybersecurity governance abilities, together with the board’s oversight of cyber chance, a description of management’s role in evaluating and running cyber hazards, the applicable knowledge of these kinds of administration, and management’s purpose in implementing the registrant’s cybersecurity procedures, strategies, and procedures. Exclusively, wherever pertinent to board oversight, registrants will be needed to disclose:

  • regardless of whether the complete board, a specific board member, or a board committee is dependable for the oversight of cyber pitfalls,
  • the processes by which the board is informed about cyber hazards, and the frequency of its discussions on this topic,
  • regardless of whether and how the board or specified board committee considers cyber threats as section of its small business tactic, possibility administration, and fiscal oversight.

The fantastic information is that boards are creating progress in this area. Recent study we conducted with analysis lover Proofpoint confirmed that just about two thirds of board customers consider the organization is at threat of a material cyber assault. Almost 3 quarters of respondents felt the investment decision their business has created in cybersecurity is ample, and about the same volume come to feel cybersecurity is a top rated priority.  Seventy-6 {b7c9e2c88beb1a84f22d94ab877a147f4adc4b3519717f3f957a0f34e16918d1} reported that cybersecurity matters are mentioned at every single board meeting, or extra often than that.

Nevertheless, our investigation also uncovered attitudes and beliefs that have to alter. Only 23{b7c9e2c88beb1a84f22d94ab877a147f4adc4b3519717f3f957a0f34e16918d1} of board associates assume the danger of an attack on their firm is extremely probable. About 47{b7c9e2c88beb1a84f22d94ab877a147f4adc4b3519717f3f957a0f34e16918d1} believe that their business is unprepared for a cyber assault, begging the issue “what are they carrying out about this?”  And about a single 3rd of board customers say they interact with the CISO only when he/she is presenting to the board. There is plainly home for improvement in aligning board members with the companies cybersecurity priorities.

Board Member Cybersecurity Attitude Adjustment

To give proper oversight and comply with the regulatory ecosystem, board members are going to have to up their cybersecurity recreation. It’s no extended suitable to just listen to about the protections set in put, or the effects of the most recent phishing workout. Board members ought to get the place that cyber assaults are probably, and training their oversight role to make sure that executives and administrators have built suitable and ideal preparations to reply and recover. Soon after all, if we believe just about every group has a possible chance of becoming breached or attacked, and it is not probable to be 100{b7c9e2c88beb1a84f22d94ab877a147f4adc4b3519717f3f957a0f34e16918d1} protected from each and every assault, the most rational solution is to make sure the business can get better with minimal or no harm to operations, to the economical bottom line, and to the organization’s reputation.

Creating resiliency in an business requires right oversight from the boardroom dependent on a obvious strategy crafted on business enterprise and economic evaluation. Below are a number of tales about how providers we studied have carried out this.

A monetary companies business CEO realized his board was not well versed in the enterprise context or fiscal exposure possibility from a cyber attack. He hired a third-bash consulting organization to perform a cybersecurity maturity evaluation. The enterprise CISO offered the effects of the report to the business hazard administration subcommittee, producing a effective dialogue all over the small business and economical effect of various investments in cybersecurity. What-ifs about investing in diverse amounts of maturity assisted the board have an understanding of the economical/threat tradeoffs and presented them with both a language and viewpoint required to perform the required oversight of cybersecurity strategies supplied by the government staff.

Another group targeted their board on the alignment of their cybersecurity method and operational risk. The CISO, in collaboration with the main chance officer, leverage fiscal analytics to aid with bridging the hole among the cyber exposures to operational losses. The board was able to recognize the publicity of the corporation from a hazard point of view, resulting in optimizing their cyber insurance plan as a way to mitigate the recently recognized possibility.

By working with the language of risk, resiliency and status in cybersecurity discussions with board customers, operational executives are capable to bridge the gaps that generally manifest amongst the technical requires witnessed to fulfill cybersecurity wants, and the oversight obligations executed by boards. Perhaps this was greatest articulated by Peter R. Gleason, the president and CEO of the National Association of Corporate Directors (NACD), when he mentioned, “We have listened to from many administrators the require to realize the financial publicity ensuing from cyber possibility, heading further than the menace-targeted, complex cyber presentations most boards receive.”

As we significantly rely on boards to prolong their fiduciary duties to cybersecurity designs, operational professionals should also just take a function by presenting individuals programs in a way that align with the way boards ideal add.  Conference the new regulatory prerequisites can be greater achieved by aligning how operational leaders talk about cybersecurity with their boards.

Raise Cybersecurity Knowledge in your Boardroom

In this article are some actionable insights to start currently so your board fulfills (or exceeds) the new SEC recommendations, and provides the ideal amount of oversight to cybersecurity ideas:

1. Establish a frequent language for discussing the sophisticated issues of cyber threat and resilience.

Boards want to simplify bewildering, technical discussions loaded with nuanced safety phrases. It’s not that these are unimportant, it is just not as efficient for the board as an economic investigation that demonstrates how cyberattacks endanger businesses financially in the brief and long term and how the organization will be back again up and jogging, i.e. resilient. Our research displays that insurance firms are taking the direct here, as they shifting the cyber discussion from a hugely technological and ambiguous safety just one to a single exactly where enterprises can fully grasp and effectively handle their fiscal exposure.

2. Retain cyber resiliency on the board’s agenda and in conversations with management.

Our exploration implies that boards are listening to about cybersecurity from administration but the discussions ought to take location extra normally. It’s not a “one and done” kind of choice it is a continually changing and relocating goal.  The far more typically the board is exposed to the cyber-circumstance of their business, the a lot more relaxed and far more pro they grow to be.

3. Build broader bridges amongst cybersecurity executives and board members.

Board associates need to have obtain to, and interactions with, cybersecurity authorities inside the business. Although inviting CISOs to report to the board can help with identification, it does not build robust connections among board associates and protection executives. Come across strategies to facilitate this romantic relationship.

In our investigation, we have noticed board associates reaching out to CISOs in involving board meetings to go over cybersecurity headlines, to share individual incidents that may possibly take place, and just to get superior acquainted. That way, when there is an urgent need to have for the board to weigh in on a cybersecurity situation, the partnership is by now in position and the conversations are much more related and clear.  A cyber incident is not the time to build the bridge that must happen very long in advance of the challenging discussions have to choose put.

Board training to meet up with the SEC prerequisites can take place organically if both the board and running executives just somewhat tweak their technique.  Wondering in terms of resiliency as an alternative of safety, balancing the business and specialized risks, speaking about cybersecurity in terms of financial exposures, and expanding the frequency of dialogue of the cybersecurity landscape confronted by the firm, will assistance directors on boards get ready for and satisfy the SEC policies probable to come.  And that will go a extended way in direction of growing organizational resiliency.