• COVID-19
  • About Us
  • Contact Us
  • Events
  • Industries
  • Partners
  • Products & Services
  • Contribute
  • Webinars

Aerospace

  • Québec’s CloudOps Will Build Telesat LightSpeed’s Cloud Network
  • Myriota and Goanna Ag Team Up on IoT Agriculture Solutions
  • Fleet Picks Swissto12 to Deliver Additively Manufactured All-Metal Patch Antennas

Chemical

  • POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
  • Evonik deepens partnership with IBM to accelerate AI implementation
  • Achieving Plant Efficiency – the Digital Way

Cybersecurity

  • House Passes Eight Bipartisan Cyber, Homeland Security Bills
  • Biden Administration Targets Electric Utilities For Cybersecurity Protections
  • White House Attributes SolarWinds Hack To Russian Agency

Healthcare

  • CISA Services In High Demand Related To COVID Vaccine Response
  • AI tool detects COVID-19 by listening to patients’ coughs
  • Printing Wearable Sensors Directly onto Skin

Oil & Gas

  • Globalstar Wins Asset Tracking Order from Brazilian Oil and Gas Company
  • Cybersecurity: Continuous Vigilance Required
  • Repsol and Microsoft renew partnership developing AI-powered digital solutions

Power

  • POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
  • Self-Tuning Artificial Intelligence Improves Plant Efficiency and Flexibility
  • How to Put the Power Grid to Work to Prevent Wildfires

Transportation

  • Swarm CEO Sara Spangelo Sets Disruptive Pricing on New Satellite IoT Service
  • Trump Issues Cyber Security Plan For Maritime Transportation System
  • Sabic Launches New Compounds for Automotive Radar Sensors

Webinars

  • Anticipating the Unknowns: Accelerating Incident Response Without Losing Control
  • Industrial Endpoint Protection in Operational Technology
  • Known and Unknown: Putting a Stop to OT and IT Threats Before they Act

Sign up today for our free weekly e-letter

sign up
CONNECTING INNOVATIONS
WITH INSIGHT
SIGN UP
LOG IN
  • Aerospace
    Québec's CloudOps Will Build Telesat LightSpeed's Cloud Network
    Read story View all articles
  • Chemical
    POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
    Read story View all articles
  • Cybersecurity
    House Passes Eight Bipartisan Cyber, Homeland Security Bills
    Read story View all articles
  • Healthcare
    CISA Services In High Demand Related To COVID Vaccine Response
    Read story View all articles
  • Oil & Gas
    Globalstar Wins Asset Tracking Order from Brazilian Oil and Gas Company
    Read story View all articles
  • Power
    POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
    Read story View all articles
  • Transportation
    Swarm CEO Sara Spangelo Sets Disruptive Pricing on New Satellite IoT Service
    Read story View all articles
Cybersecurity
February 23 2021 10:09 pm

Time For Government To Mandate Cyber Breach Notification, Tech Heads Say

C

Cal Biesecker

In the wake of the recently disclosed breach of some federal and private sector networks likely by a Russian intelligence organization, the U.S. government needs to mandate that private sector entities whose networks have been breached notify the government of an incident, executives from Microsoft [MSFT] and FireEye [FEYE] said on Tuesday.

Current information about cyber hacks and breaches is "too often" siloed within the government and the private sector, said Brad Smith, president of Microsoft.

The information "doesn't come together," he said. "Because of that need, it is time, not only to talk about, but to find a way to take action to impose in an appropriate manner some kind of notification obligation on entities in the private sector."

Testifying before the Senate Intelligence Committee, which is examining the recent hack, Smith said that while it's "not a typical step" for a company to tell Congress to "place a new law on me…I think it's the only way we're going to protect the country and I think it's the only way we're going to protect the world."

The notion of government regulation requiring private sector entities to disclose breaches of their networks in some way to the federal government was argued vigorously in Congress a decade ago and found proponents in Sen. Susan Collins (R-Maine) and then Sen. Joe Lieberman (I/D-Conn.), but ultimately Congress and the Obama administration opted for voluntary disclosures incentivized by liability protections. However, companies that have been breached still remain wary of notifying the government and even their customers for fear of costly liabilities and reputational damage.

In the most recent hack, the perpetrators compromised software upgrades developed by network management supplier SolarWinds [SWI] for one of their software platforms that is widely used on government and private sector networks. The U.S. government believes the hackers are based in Russia but formal attribution specifically identifying the group hasn't been made.

President Joe Biden's Press Secretary Jen Psaki said on Tuesday that the White House has "asked the intelligence community to do further work to sharpen the attribution" and to better understand the damage, scope and scale of the breach.

"But it will be weeks, not months, before we respond, but I'm not going to get ahead of the conclusion of that process," she said in response to a reporter's question during the daily White House press briefing.

Sen. John Cornyn (R-Texas) asked the witnesses at the committee's hearing about requiring notification coupled with liability protections.

Smith replied that the country can "find a way to move forward this year" on such a regulation, adding that liability protection will make companies "more comfortable" with notifying they've been breached.

Kevin Mandia, CEO of FireEye, the company that first discovered the hack, said he agrees but that notification needs to be "confidential or you don't give organizations the capability to prepare for those liabilities." The benefit from notifying about a compromise is that it rapidly gets information about the threat out to those that need to know, he said.

Mandia pointed out that there's a lag between having data about the threat and then having a fuller understanding of the incident months later.

Disclosure, he said, is a legal requirement to inform impacted parties.

"And you don't know that day one," Mandia said.

Both Mandia and Smith said that the threat information should be shared with the appropriate government agency. On Monday, SolarWinds CEO Sudhakar Ramakrishna said that there needs to be a single point of contact in government for the private sector to engage to share information about cyber threats.

Currently, SolarWinds has to deal with multiple agencies, which is time consuming for responding to attacks, Ramakrishna said.

Sen. Mark Warner (D-Va.), chairman of the committee, asked at the outset of the hearing "Why shouldn't we have mandatory reporting systems even if those reporting systems require some liability protection so we can better understand and better mitigate future attacks?" He said that Sen. Collins "was way ahead of all of us on this issue."

Sign up today for our free weekly e-letter

sign up

Aerospace

Chemical

Cybersecurity

Healthcare

Oil & Gas

Power

Quiz

Transportation

Webinars

About Us

IIoT Connection delivers the latest news, trends, insights, events and research surrounding the dynamic and disruptive Industrial Internet of Things (IIoT) marketplace. Brought to you by the publisher of must-read publications Defense Daily, OR Manager, POWER and Chemical Engineering, as well as the conference producers of SATELLITE, Global Connected Aircraft Summit, Connected Plant Conference and ELECTRIC POWER, IIoT Connection is committed to providing the most comprehensive compilation of products and services dedicated to the Industrial Internet of Things. Key verticals with associated products and services include: aerospace, chemical, cybersecurity, healthcare, oil & gas, power, and transportation.


Advertise

  • Privacy Policy
© 2021 Access Intelligence, LLC - All Rights Reserved.
  • × UPS Partners with Wingcopter to Develop, Certify Drone Delivery Fleet
    Read story View all articles
  • × How Industrial Managers Can Identify and Prevent Failures in Facilities
    Read story View all articles
  • × Federal Agencies Partner To Improve Cyber Security Cooperation In Energy Sector
    Read story View all articles
  • × New service lines can create opportunities for ORs
    Read story View all articles
  • × Equinor and Shell to collaborate on digital solutions
    Read story View all articles
  • × Dobroflot to Manage Fuel Savings With IOT Solution By Orange Business Services
    Read story View all articles
  • × The Future of 5G & IoT Technologies in the Transportation Industry
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles