• COVID-19
  • About Us
  • Contact Us
  • Events
  • Industries
  • Partners
  • Products & Services
  • Contribute
  • Webinars

Aerospace

  • Québec’s CloudOps Will Build Telesat LightSpeed’s Cloud Network
  • Myriota and Goanna Ag Team Up on IoT Agriculture Solutions
  • Fleet Picks Swissto12 to Deliver Additively Manufactured All-Metal Patch Antennas

Chemical

  • POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
  • Evonik deepens partnership with IBM to accelerate AI implementation
  • Achieving Plant Efficiency – the Digital Way

Cybersecurity

  • House Passes Eight Bipartisan Cyber, Homeland Security Bills
  • Biden Administration Targets Electric Utilities For Cybersecurity Protections
  • White House Attributes SolarWinds Hack To Russian Agency

Healthcare

  • CISA Services In High Demand Related To COVID Vaccine Response
  • AI tool detects COVID-19 by listening to patients’ coughs
  • Printing Wearable Sensors Directly onto Skin

Oil & Gas

  • Globalstar Wins Asset Tracking Order from Brazilian Oil and Gas Company
  • Cybersecurity: Continuous Vigilance Required
  • Repsol and Microsoft renew partnership developing AI-powered digital solutions

Power

  • POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
  • Self-Tuning Artificial Intelligence Improves Plant Efficiency and Flexibility
  • How to Put the Power Grid to Work to Prevent Wildfires

Transportation

  • Swarm CEO Sara Spangelo Sets Disruptive Pricing on New Satellite IoT Service
  • Trump Issues Cyber Security Plan For Maritime Transportation System
  • Sabic Launches New Compounds for Automotive Radar Sensors

Webinars

  • Anticipating the Unknowns: Accelerating Incident Response Without Losing Control
  • Industrial Endpoint Protection in Operational Technology
  • Known and Unknown: Putting a Stop to OT and IT Threats Before they Act

Sign up today for our free weekly e-letter

sign up
CONNECTING INNOVATIONS
WITH INSIGHT
SIGN UP
LOG IN
  • Aerospace
    Québec's CloudOps Will Build Telesat LightSpeed's Cloud Network
    Read story View all articles
  • Chemical
    POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
    Read story View all articles
  • Cybersecurity
    House Passes Eight Bipartisan Cyber, Homeland Security Bills
    Read story View all articles
  • Healthcare
    CISA Services In High Demand Related To COVID Vaccine Response
    Read story View all articles
  • Oil & Gas
    Globalstar Wins Asset Tracking Order from Brazilian Oil and Gas Company
    Read story View all articles
  • Power
    POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
    Read story View all articles
  • Transportation
    Swarm CEO Sara Spangelo Sets Disruptive Pricing on New Satellite IoT Service
    Read story View all articles
Cybersecurity
February 22 2021 10:14 pm

Mayorkas Announces Initial Plans To Bolster U.S. Cyber Security; SolarWinds CEO Has Ideas Too

C

Cal Biesecker

Homeland Security Secretary Alejandro Mayorkas on Monday announced his department's initial steps to further strengthen the nation's cyber security posture in line with the Biden administration's commitment to prioritize cyber security, including requiring recipients of federal emergency grants to spend more of the funds on cyber security.

"Cyber security is more important than ever, and we will build on the department's excellent work as we transform our whole-of-government approach to tackle the challenge we face as a nation," Mayorkas said in a statement. "This week is just the beginning of a series of actions DHS will pursue nationally and international to improve cyber security at all levels."

The steps outlined by Mayorkas include raising the minimum requirement for recipients of Federal Emergency Management Agency grants to spend on cyber security, and directing the Cybersecurity and Infrastructure Security Agency (CISA) to examine new grant programs to help state and local governments bolster their cyber security.

This Thursday, Mayorkas also will "issue a call to action to build a diverse cyber security workforce and leverage DHS's partnerships to tackle the growing risk from ransomware," DHS said. The secretary will also push CISA's new "Reduce the Risk of Ransomware" effort launched in January to work with, and encourage, the private and public sector to reduce ransomware risk. DHS will also leverage the Secret Service's Cyber Fraud Task Forces to response to ransomware incidents and arrest perpetrators of this activity.

"Ransomware is a cyber pandemic that paralyzes cities, companies, and hospitals across the country," DHS said. It added that "Tackling ransomware will require partnering with private organization, state, local, tribal and territorial entities–the hallmark of DHS's approach to cyber security."

In the coming weeks, Mayorkas will also further discuss how DHS will support its partners in better managing their cyber risks and security, and engage with foreign partners to strengthen international collaboration on cyber security.

Mayorkas' announcement coincided with comments made by the new chief executive of the network management software company SolarWinds [SWI] on how the government can better work with the private sector to improve national cyber security. A key reason for President Joe Biden's prioritization of cyber security was the discovery in December of a significant breach of federal, state and local, and private sector networks likely by sophisticated Russian hackers using novel techniques that allowed the perpetrators to move around undetected for at least a year.

At least one of the vectors for the breach is a network management platform supplied by SolarWinds called Orion. It was through patches or updates to Orion that the hackers were able to exploit some of the company's customers' networks.

Sudhakar Ramakrishna, president and CEO of SolarWinds, outlined three areas the government can improve, including having a single point of contact in the government for industry to report cyber incidents. That government organization can then share the incident data with other federal agencies, he said during a discussion with him hosted by Suzanne Spaulding, a senior adviser with the Center for Strategic and International Studies and the head of CISA's predecessor agency during the Obama administration.

Having a simpler reporting structure for industry will help, Ramakrishna said. Currently, SolarWinds deals with "multiple government agencies," which is time consuming "in fighting these attacks," he said.

"What is clear with these attacks is that no single enterprise, how large or how many resources you may have, or a single government can completely identify and protect and kill these attacks that continue to emanate," he said. "So, there's a need for a tighter public-private partnership."

Since joining SolarWinds on Jan. 4, Ramakrishna said the company's engagements with the government on the hacking incident have been "broadly constructive if not always completely informational," adding that the company has been very proactive in sharing information with "national defenders."

So far, the hack is largely thought of to be for espionage purposes but the Biden administration and cyber security experts have warned that the intrusion could become disruptive.

A second area of action that could be improved by the federal government is collaboration with the private sector to enhance existing standards and best practices for cyber security.

The need is for "excellence focused versus compliance focused," he said, "because a lot of us can pass through the check boxes of, ‘Did you do this? Did you do that?' But obviously the results prove that we need to do more."

The third area is around government incentives and protections for companies to share when their networks have been compromised, Ramakrishna said. Regulations to limit liability and punitive concerns will "comfort" companies to quickly alert authorities that they've been hacked, he said.

Ramakrishna pointed to last year's Cyberspace Solarium Commission report on the need for "speed and agility" in responding to network breaches as a key ingredient for a more fruitful response.

Regarding liability concerns, Ramakrishna said that SolarWinds has discussed the topic but it isn't "top of mind." More important is the need to share information so that the threat is understood and lessons can be learned, he said.

Ramakrishna will have plenty of opportunities this week to impress on Congress how the federal government can better work with the private sector. On Tuesday he will appear before the Senate Intelligence Committee and again on Friday before the House Homeland Security Committee to discuss the ongoing breach.

Reps. Bennie Thompson (D-Miss.) and Yvette Clarke (D-N.Y.), the chairs of the House Homeland Security Committee and its Cybersecurity Subcommittee, respectively, on Monday issued a statement saying they are "encouraged" with the initial steps that Mayorkas is planning to help state and local governments with their cyber security needs.

The two Democrats said they are planning to reintroduce the State and Local Cybersecurity Improvement Act, which would establish within DHS a grant program for state, local, tribal and territorial governments to address cyber security risks and states.

Sign up today for our free weekly e-letter

sign up

Aerospace

Chemical

Cybersecurity

Healthcare

Oil & Gas

Power

Quiz

Transportation

Webinars

About Us

IIoT Connection delivers the latest news, trends, insights, events and research surrounding the dynamic and disruptive Industrial Internet of Things (IIoT) marketplace. Brought to you by the publisher of must-read publications Defense Daily, OR Manager, POWER and Chemical Engineering, as well as the conference producers of SATELLITE, Global Connected Aircraft Summit, Connected Plant Conference and ELECTRIC POWER, IIoT Connection is committed to providing the most comprehensive compilation of products and services dedicated to the Industrial Internet of Things. Key verticals with associated products and services include: aerospace, chemical, cybersecurity, healthcare, oil & gas, power, and transportation.


Advertise

  • Privacy Policy
© 2021 Access Intelligence, LLC - All Rights Reserved.
  • × UPS Partners with Wingcopter to Develop, Certify Drone Delivery Fleet
    Read story View all articles
  • × How Industrial Managers Can Identify and Prevent Failures in Facilities
    Read story View all articles
  • × Federal Agencies Partner To Improve Cyber Security Cooperation In Energy Sector
    Read story View all articles
  • × New service lines can create opportunities for ORs
    Read story View all articles
  • × Equinor and Shell to collaborate on digital solutions
    Read story View all articles
  • × Dobroflot to Manage Fuel Savings With IOT Solution By Orange Business Services
    Read story View all articles
  • × The Future of 5G & IoT Technologies in the Transportation Industry
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles