facebook linkedin twitter

Cybersecurity Experts Caution Congress About ‘Global Emergency’ from Hackers

February 11, 2021 by Tom Ramstack
This Aug. 4, 2009, photo shows the United States Chamber of Commerce building in Washington. The White House says a senior national security official is leading the U.S. response to a massive breach of government departments and private corporations discovered late last year. The announcement that the deputy national security adviser for cyber and emergency technology, Anne Neuberger, has been in charge of the response to the SolarWinds hack follows congressional criticism of the government effort so far as “disorganized.” (AP Photo/Manuel Balce Ceneta)

WASHINGTON — Cybersecurity experts suggested to a congressional committee Wednesday that lawmakers act quickly to address growing threats from hackers.

They mentioned the SolarWinds computer infiltration by the Russians last year and a hacker’s attempt to poison a Florida municipal water supply last week as examples.

“These attacks in my opinion for all intents and purposes should be considered an attack on the United States,” said Rep. Lou Correa, D-Calif.

The cybersecurity witnesses told the House Homeland Security Committee there is no easy solution to cyberattacks.

“We keep hooking more and more devices up to the internet,” said Michael Daniel, president of the Cyber Threat Alliance, a non-profit advocacy organization for cybersecurity.

A few decades ago, internet connectivity consisted almost completely of computers. Now it includes cars, water systems and other equipment, he said. 

As a result, hacking attacks can be more devastating, Daniel said.

SolarWinds refers to a 2020 cyber-attack backed by the Russian government that penetrated thousands of organizations globally, including U.S. government agencies that handle national security and financial issues.

The Russian hackers gained access to the agencies’ computers for about nine months, making it the most devastating cyberattack in U.S. history. Other organizations affected included NATO, the European Parliament and Microsoft Corp.

Last Friday, a hacker tapped remotely into the Oldsmar, Fla., water treatment plant to try to fill the city’s water supply with potentially deadly levels of sodium hydroxide, also known as lye. The unknown hacker briefly increased the level of lye but it was detected before it threatened anyone’s health.

About 54,000 water systems are operated in the United States by local governments or private contractors.

“I think we’re on the verge of a global emergency,” said Chris Krebs, former director of the U.S. Cybersecurity and Infrastructure Security Agency.

Sue Gordon, a former deputy director at the U.S. Office of the Director of National Intelligence, suggested a multi-layered approach to cybersecurity.

“There’s no technology magic bullet,” she said.

Instead, she suggested more public-private ventures dedicated to security. In addition, leadership of the effort should not be controlled by a single agency but spread among several organizations that can double-check each other, she said.

Dmitri Alperovitch, chairman of the Silverado Policy Accelerator, a non-profit organization for advancing economic prosperity, said a purely defensive posture against cyberattacks will offer only limited security.

“We need to go on the offense,” he said.

Only when the cost to hackers is so great that it acts as a deterrent will cybersecurity become more effective, he said. Disrupting the infrastructure of the hackers — such as launching computer viruses and attacks against the attackers — were examples Alperovitch and other experts mentioned.

He also recommended against overlooking the international threat against the United States.

“We do not have a cyber problem,” he said. “We have a China, Russia, Iran and North Korea problem.”

He added, “I really believe that SolarWinds is the new normal for the Russians.”

Cybersecurity

October 14, 2021
by Victoria Turner
Cybersecurity Experts Point to More Investment Needed in Detection, Response

WASHINGTON -- If everyone were to employ proper cyber hygiene like multi-factor authentication or not clicking on links in phishing... Read More

WASHINGTON -- If everyone were to employ proper cyber hygiene like multi-factor authentication or not clicking on links in phishing emails, more than 85% of cyberattacks would be prevented, said Sen. Angus King, I-Maine, Thursday.  “The best hack is the one that doesn’t happen,” King said... Read More

October 5, 2021
by Victoria Turner
Cybersecurity Minimum Standards Needed to Keep North America Secure

North American governments should come together to create a trilateral strategy to assess and address threats in a holistic risk-based... Read More

North American governments should come together to create a trilateral strategy to assess and address threats in a holistic risk-based approach to cybersecurity that includes a minimum set of standards, said three experts yesterday. As much as the pandemic has accelerated the rate in which governments... Read More

September 29, 2021
by Victoria Turner
Aspen Cyber Summit Explores Collective Defense in a Digital World

WASHINGTON -- The Cybersecurity Infrastructure and Security Agency has met President Biden’s cybersecurity executive order’s “highly aggressive deadlines so far,”... Read More

WASHINGTON -- The Cybersecurity Infrastructure and Security Agency has met President Biden’s cybersecurity executive order’s “highly aggressive deadlines so far,” but there is “still a lot of work to do,” said CISA Director Jen Easterly Wednesday.  Kicking off the 6th annual Aspen Cyber Summit, Exploring Collective... Read More

September 22, 2021
by Victoria Turner
Identity Authentication Key Piece of Cybersecurity Puzzle

WASHINGTON -- Identity authentication is taking a front-and-center role in the administration's approach to ensuring robust cybersecurity across the U.S.... Read More

WASHINGTON -- Identity authentication is taking a front-and-center role in the administration's approach to ensuring robust cybersecurity across the U.S. government, according to Carole House, director of cybersecurity and secure digital Innovation at the White House National Security Council.  It “sits at the heart of zero... Read More

September 1, 2021
by Tom Ramstack
Executives Advocate for Legislation to Unite Government and Private Cybersecurity

WASHINGTON -- A cybersecurity expert told a congressional panel Wednesday that private industry alone cannot be expected to effectively confront... Read More

WASHINGTON -- A cybersecurity expert told a congressional panel Wednesday that private industry alone cannot be expected to effectively confront the kinds of cyberattacks that have wreaked havoc on U.S. computer networks in recent years. He testified to a House Homeland Security subcommittee as it considers... Read More

August 27, 2021
by Reece Nations
FBI Warns of New Hive Ransomware Threat

WASHINGTON — The Federal Bureau of Investigation distributed a Flash report on Friday warning of indicators of compromise from the... Read More

WASHINGTON — The Federal Bureau of Investigation distributed a Flash report on Friday warning of indicators of compromise from the Hive ransomware known to have infiltrated business networks. The ransomware utilizes multiple mechanisms as attachments to gain access and “Remote Desktop Protocol” to operate once embedded,... Read More

News From The Well
scroll top