Cybersecurity Experts Caution Congress About ‘Global Emergency’ from Hackers

February 11, 2021 by Tom Ramstack
Cybersecurity Experts Caution Congress About ‘Global Emergency’ from Hackers
This Aug. 4, 2009, photo shows the United States Chamber of Commerce building in Washington. The White House says a senior national security official is leading the U.S. response to a massive breach of government departments and private corporations discovered late last year. The announcement that the deputy national security adviser for cyber and emergency technology, Anne Neuberger, has been in charge of the response to the SolarWinds hack follows congressional criticism of the government effort so far as “disorganized.” (AP Photo/Manuel Balce Ceneta)

WASHINGTON — Cybersecurity experts suggested to a congressional committee Wednesday that lawmakers act quickly to address growing threats from hackers.

They mentioned the SolarWinds computer infiltration by the Russians last year and a hacker’s attempt to poison a Florida municipal water supply last week as examples.

“These attacks in my opinion for all intents and purposes should be considered an attack on the United States,” said Rep. Lou Correa, D-Calif.

The cybersecurity witnesses told the House Homeland Security Committee there is no easy solution to cyberattacks.

“We keep hooking more and more devices up to the internet,” said Michael Daniel, president of the Cyber Threat Alliance, a non-profit advocacy organization for cybersecurity.

A few decades ago, internet connectivity consisted almost completely of computers. Now it includes cars, water systems and other equipment, he said. 

As a result, hacking attacks can be more devastating, Daniel said.

SolarWinds refers to a 2020 cyber-attack backed by the Russian government that penetrated thousands of organizations globally, including U.S. government agencies that handle national security and financial issues.

The Russian hackers gained access to the agencies’ computers for about nine months, making it the most devastating cyberattack in U.S. history. Other organizations affected included NATO, the European Parliament and Microsoft Corp.

Last Friday, a hacker tapped remotely into the Oldsmar, Fla., water treatment plant to try to fill the city’s water supply with potentially deadly levels of sodium hydroxide, also known as lye. The unknown hacker briefly increased the level of lye but it was detected before it threatened anyone’s health.

About 54,000 water systems are operated in the United States by local governments or private contractors.

“I think we’re on the verge of a global emergency,” said Chris Krebs, former director of the U.S. Cybersecurity and Infrastructure Security Agency.

Sue Gordon, a former deputy director at the U.S. Office of the Director of National Intelligence, suggested a multi-layered approach to cybersecurity.

“There’s no technology magic bullet,” she said.

Instead, she suggested more public-private ventures dedicated to security. In addition, leadership of the effort should not be controlled by a single agency but spread among several organizations that can double-check each other, she said.

Dmitri Alperovitch, chairman of the Silverado Policy Accelerator, a non-profit organization for advancing economic prosperity, said a purely defensive posture against cyberattacks will offer only limited security.

“We need to go on the offense,” he said.

Only when the cost to hackers is so great that it acts as a deterrent will cybersecurity become more effective, he said. Disrupting the infrastructure of the hackers — such as launching computer viruses and attacks against the attackers — were examples Alperovitch and other experts mentioned.

He also recommended against overlooking the international threat against the United States.

“We do not have a cyber problem,” he said. “We have a China, Russia, Iran and North Korea problem.”

He added, “I really believe that SolarWinds is the new normal for the Russians.”

A+
a-
  • Chris Krebs
  • cybersecurity
  • Dmitri Alperovitch
  • Lou Correa
  • Michael Daniel
  • Russia
  • Solarwinds
  • In The News

    Health

    Voting

    Cybersecurity

    Americans Reporting Nationwide Cellular Outages From AT&T, Cricket Wireless and Others

    A number of Americans are dealing with cellular outages on AT&T, Cricket Wireless, Verizon, T-Mobile and other service providers, according... Read More

    A number of Americans are dealing with cellular outages on AT&T, Cricket Wireless, Verizon, T-Mobile and other service providers, according to data from Downdetector. AT&T had more than 73,000 outages around 9:30 a.m. ET, in locations including Houston, Atlanta and Chicago. The outages began at approximately... Read More

    States and Congress Wrestle With Cybersecurity at Water Utilities Amid Renewed Federal Warnings

    HARRISBURG, Pa. (AP) — The tiny Aliquippa water authority in western Pennsylvania was perhaps the least-suspecting victim of an international... Read More

    HARRISBURG, Pa. (AP) — The tiny Aliquippa water authority in western Pennsylvania was perhaps the least-suspecting victim of an international cyberattack. It had never had outside help in protecting its systems from a cyberattack, either at its existing plant that dates to the 1930s or the... Read More

    December 6, 2023
    by Dan McCue
    HHS Unveils Next Steps to Enhance Cybersecurity of Health Care Records

    WASHINGTON — The bad guys in cyberspace want your health care records.  Between 2018 and 2022, there was a 93%... Read More

    WASHINGTON — The bad guys in cyberspace want your health care records.  Between 2018 and 2022, there was a 93% increase in large breaches in the health care sector, with a 278% increase in large breaches involving ransomware, according to the Department of Health and Human... Read More

    Insider Q&A: Pentagon AI Chief on Network-Centric Warfare, Generative AI Challenges

    The Pentagon's chief digital and artificial intelligence offer, Craig Martell, is alarmed by the potential for generative artificial intelligence systems... Read More

    The Pentagon's chief digital and artificial intelligence offer, Craig Martell, is alarmed by the potential for generative artificial intelligence systems like ChatGPT to deceive and sow disinformation. His talk on the technology at the DefCon hacker convention in August was a huge hit. But he's anything... Read More

    October 31, 2023
    by Tom Ramstack
    US Workforce Unprepared for AI, Technology Experts Tell Senate

    WASHINGTON — President Joe Biden’s executive order Monday setting regulatory standards for artificial intelligence prompted witnesses at a Senate hearing... Read More

    WASHINGTON — President Joe Biden’s executive order Monday setting regulatory standards for artificial intelligence prompted witnesses at a Senate hearing Tuesday to say it is only a first step in a process likely to transform American workplaces. “Artificial intelligence will not only disrupt lives, it will... Read More

    July 18, 2023
    by Tom Ramstack
    Congress Told AI Holds Great Risks and Benefits for US Military

    WASHINGTON — Artificial intelligence experts warned Tuesday during a congressional hearing of ominous dangers for the United States if it... Read More

    WASHINGTON — Artificial intelligence experts warned Tuesday during a congressional hearing of ominous dangers for the United States if it falls behind in developing the technology but a bright future by taking the lead. One of the greatest risks would be defending against a foreign enemy... Read More

    News From The Well
    scroll top