Bigger Government Role Expected to Protect Industry From Hackers

October 26, 2021 by Tom Ramstack
Bigger Government Role Expected to Protect Industry From Hackers

WASHINGTON — Large-scale cyberattacks continued this week in the United States and abroad as computer security experts told a congressional panel Tuesday that more government intervention is needed.

On Monday, Microsoft announced that Russia-backed hackers were trying to steal information technology to disrupt the global supply chain.

On Tuesday, cyberattackers shut down gas stations across Iran. In Germany, a major auto components supplier was hacked, possibly interfering with automobile production throughout the country.

Other attacks were reported this week at schools in Colorado and Wisconsin.

“The threat is evolving much more quickly than our defense,” said Suzanne Spaulding, a Homeland Security International Security Program senior advisor.

She testified to the House Homeland Security subcommittee on cybersecurity as it considers proposals to require transportation companies to meet minimum requirements for protecting their computer systems that operate the nation’s transit systems, airlines, pipelines and railroads.

The Transportation Security Administration is close to finalizing the requirements. They come with a huge controversy for private industry.

Corporations have traditionally relied upon voluntary guidelines to protect their businesses and customers. They argue against the heavy hand of government regulation, along with the fines and court orders that could accompany it.

Witnesses at the congressional hearing said recent events show voluntary guidelines are too weak to adequately protect the public and the nation’s economy.

Spaulding said that until recently she also favored voluntary private market compliance with cybersecurity guidelines.

“Markets are generally more efficient and, important for such a dynamic area as cyber, nimbler,” she said. “However, over the last couple of years, I have reluctantly had to conclude that we cannot rely upon markets alone to ensure the continuity of nationally critical functions upon which the American public relies.”

Lawmakers and witnesses discussed the May 2021 Colonial Pipeline ransomware attack as a prime example of the damage cyberattackers can cause.

Gasoline and jet fuel deliveries along the 5,500-mile pipeline from Houston, Texas, to the East Coast were shut down for five days while the attackers demanded a $4.4 million bitcoin ransom.

Colonial Pipeline officials paid the ransom but also generated disputes that continued this week about whether anyone should need to respond to demands of thieves who use software to extort money.

“Time is not on our side,” Spaulding said.

Rep. Yvette Clarke, D-N.Y., chairwoman of the cybersecurity subcommittee, said lawmakers were “shocked” by weaknesses in Colonial Pipeline’s cybersecurity.

She also said cyberattacks and ransomware are a special threat for her constituents in New York, which is a major hub for airports, rail systems and transit. Six months ago, Chinese hackers infiltrated computers of the New York Metropolitan Transportation Authority.

“Fortunately, they did not gain access to operational systems that control rail cars, but I remain concerned about the cybersecurity of mass transit systems generally and MTA’s network in particular,” Clarke said. “Given the degree to which middle- and low-income people rely on public transportation, a cyberattack affecting mass transit could have a disproportionate impact on these populations.”

She welcomed the Transportation Security Administration’s upcoming cybersecurity standards for transportation companies and agencies.

“They mark a pivotal transition in the federal government’s approach to cybersecurity,” Clarke said.

The new standards could not come soon enough, according to respondents in a survey released last week by Texas-based cloud computing company Rackspace Technology.

The survey of 1,420 government information technology decision-makers showed that less than half believe their personnel are prepared to mitigate or understand all cyber threats.

Tom can be reached at [email protected]

A+
a-
  • Congress
  • Hackers
  • House Homeland Seuity Subcommittee
  • Microsoft
  • In The News

    Health

    Voting

    Cybersecurity

    Americans Reporting Nationwide Cellular Outages From AT&T, Cricket Wireless and Others

    A number of Americans are dealing with cellular outages on AT&T, Cricket Wireless, Verizon, T-Mobile and other service providers, according... Read More

    A number of Americans are dealing with cellular outages on AT&T, Cricket Wireless, Verizon, T-Mobile and other service providers, according to data from Downdetector. AT&T had more than 73,000 outages around 9:30 a.m. ET, in locations including Houston, Atlanta and Chicago. The outages began at approximately... Read More

    States and Congress Wrestle With Cybersecurity at Water Utilities Amid Renewed Federal Warnings

    HARRISBURG, Pa. (AP) — The tiny Aliquippa water authority in western Pennsylvania was perhaps the least-suspecting victim of an international... Read More

    HARRISBURG, Pa. (AP) — The tiny Aliquippa water authority in western Pennsylvania was perhaps the least-suspecting victim of an international cyberattack. It had never had outside help in protecting its systems from a cyberattack, either at its existing plant that dates to the 1930s or the... Read More

    December 6, 2023
    by Dan McCue
    HHS Unveils Next Steps to Enhance Cybersecurity of Health Care Records

    WASHINGTON — The bad guys in cyberspace want your health care records.  Between 2018 and 2022, there was a 93%... Read More

    WASHINGTON — The bad guys in cyberspace want your health care records.  Between 2018 and 2022, there was a 93% increase in large breaches in the health care sector, with a 278% increase in large breaches involving ransomware, according to the Department of Health and Human... Read More

    Insider Q&A: Pentagon AI Chief on Network-Centric Warfare, Generative AI Challenges

    The Pentagon's chief digital and artificial intelligence offer, Craig Martell, is alarmed by the potential for generative artificial intelligence systems... Read More

    The Pentagon's chief digital and artificial intelligence offer, Craig Martell, is alarmed by the potential for generative artificial intelligence systems like ChatGPT to deceive and sow disinformation. His talk on the technology at the DefCon hacker convention in August was a huge hit. But he's anything... Read More

    October 31, 2023
    by Tom Ramstack
    US Workforce Unprepared for AI, Technology Experts Tell Senate

    WASHINGTON — President Joe Biden’s executive order Monday setting regulatory standards for artificial intelligence prompted witnesses at a Senate hearing... Read More

    WASHINGTON — President Joe Biden’s executive order Monday setting regulatory standards for artificial intelligence prompted witnesses at a Senate hearing Tuesday to say it is only a first step in a process likely to transform American workplaces. “Artificial intelligence will not only disrupt lives, it will... Read More

    July 18, 2023
    by Tom Ramstack
    Congress Told AI Holds Great Risks and Benefits for US Military

    WASHINGTON — Artificial intelligence experts warned Tuesday during a congressional hearing of ominous dangers for the United States if it... Read More

    WASHINGTON — Artificial intelligence experts warned Tuesday during a congressional hearing of ominous dangers for the United States if it falls behind in developing the technology but a bright future by taking the lead. One of the greatest risks would be defending against a foreign enemy... Read More

    News From The Well
    scroll top