Cybersecurity

  • Both the White House and Congress have asserted that protecting the nation's resources from cyber-attacks is a top priority. Techworld is reporting enacting legislation designed to enhance security for critical infrastructure components such as water, power, telecom and transport facilities that is acceptable to both political parties has been a struggle. The problem political differences. But Cyber industry leaders have started to work on a voluntary standards and best practices platform to provide some level of security.

    August 05, 2013
  • Howard Schmidt, the former cybersecurity coordinator for the Obama administration, joined In Depth with Francis Rose to discuss the growing market in zero-day detection

    August 01, 2013
  • The FBI hopes a new portal, iGuardian, will enable the FBI to help companies protect themselves against malware by creating a repository of cybersecurity breaches.

    July 31, 2013
  • A recent IG report said the State Department's Bureau of Information Resource Management's Office of Information Assurance lacks organization and lags in performance. The report made 32 recommendations for the office.

    July 25, 2013
  • Brendan Goode, the director of network security deployment in the National Protection and Programs Directorate in DHS, said 15 out of the initial 23 agencies expected to implement Einstein 3 have signed memorandums of agreements with the department. E3A will use both unclassified and classified indicators to understand risks and vulnerabilities of federal networks.

    July 22, 2013
  • Bruce McConnell announced today his intention to leave the Homeland Security Department in August after spending more than four years in an assortment of senior cybersecurity positions. He will be third senior ranking cyber official at DHS to leave since January.

    July 18, 2013
  • Cyber-attacks on banks are growing more frequent. Wall Street has just conducted a cyber-defense exercise called "Quantum Dawn 2,". During the drill, bank employees were stationed at their normal offices, and were emailed throughout the day with bits of information that could indicate an encroaching hacker attack. They monitored a simulated stock exchange for irregular trading and were pressed to figure out what was going on and how to react while sharing information with regulators and each other.

    July 18, 2013
  • Ever hear of the Multi-State Information Security and Analysis Center? It's a division of the Center for Internet Security. Their focus is cyber threat prevention, protection, response and recovery for state, local territory and tribal governments. Their objectives iclude providing two-way sharing of information and early warnings on cyber security threats, dissemination of information on cyber security incidents, to promote awareness and coordinate training.

    July 18, 2013
  • Will exploit developers become potential targets of state-sponsored assassinations in the future -like the nuclear scientists in recent times? There's been some discussion in the "Tech" community regarding the legitimacy of using lethal force against civilian hackers. As a result some are wondering what the future might hold for exploit developers and other members of the cyber supply chain who are facilitating state-funded, offensive cyber operations.

    July 18, 2013
  • We hear a lot about zero-day attacks and system vulnerabilities, but most hackers look for easier enterprises like the application used to access the Web. That's the one most online attackers will target. Why? Because most attackers and online exploit kit designers realize that the common browser is usually an endpoint's weakest link. Not only are enterprises generally slow to keep up with browser patching, they're downright sluggish at updating plug-ins and extensions.

    July 18, 2013
  • While leaders at CMS said the hub connecting personal information stored in the health insurance marketplace to multiple agencies will be ready by the Oct. 1 deadline, legislators are concerned with how well CMS is securing individuals' personal information from cyber threats.

    July 17, 2013
  • Dan Doney, the new chief innovation officer at the Defense Intelligence Agency, talks about the agency's plan to change the way it interacts with industry and brings innovation to government.

    July 17, 2013
  • NIST and the National Cybersecurity Center of Excellece (NCCoE) want to facilitate public-private collaborations surrounding cybersecurity solutions by creating a new research-and-development center.

    July 16, 2013
  • All agencies are fighting cyber-attacks. The FBI Director of Cyber Security believes there are two groups of organizations: those whose systems have been attacked and those who do not know they have been attacked. In the federal space, the velocity and variety of attacks has dramatically increased. With Advanced Persistent Threats (APT), the time it can take to comprise a system ranges from hours to days, yet the time it takes for its discovery averages 6 months. The cyber security solution has shifted from the perimeter (firewall) or how to stop the attacks to how to deal with the attacks after they occur. The emphasis is now on the controls and minimizing what the attacker is doing once he gets in. The cost of the attacks is down time and data loss. With a 200% to 300% increase in attacks on agency's systems, it is imperative the federal government implements a holistic solution including hardware, software, training and compliance.

    July 16, 2013