Ideas

Look to the Roman Empire to Truly Understand Zero Trust

With the network border blurry at best, we no longer have a single and convenient point of telemetry collection to force the attacker in the open.

Cybersecurity

US, UK Agencies Warn Russian Hackers Are Adapting Based on Government Advisories

The adversary is changing its tools to avoid detection while attacking the vulnerabilities governments issue warnings about. 

Cybersecurity

Biden Administration Likely Retaining Trump Doctrine on Cybersecurity in Space

Vice President Kamala Harris is prioritizing cybersecurity as chair of the National Space Council, an official said.

Cybersecurity

State Department Needs a Tool to Scan Its Worldwide Network for Vulnerabilities

The department is exploring a “lifecycle refresh” for its Enterprise Vulnerability Scanning Solution program.

Cybersecurity

House Solarium Commission Members Press for More CISA Funding

“Congress was right to give the agency new authorities that allow it to better defend our interests in cyberspace, but without requisite funding, we’re setting CISA up for failure," the lawmakers wrote.

Cybersecurity

Senators Introduce Fresh Slate of Cybersecurity-Centered Bills

A couple would codify recommendations made by the Cyberspace Solarium Commission.

Cybersecurity

Federal Agencies Detail Russian Tactics Used in Recent Cyber Intrusions

The FBI, Homeland Security Department and Cybersecurity and Infrastructure Security Agency issued an alert on Russian government cyber tradecraft and mitigation techniques for targets.

Cybersecurity

How the Federal CISO Views Zero Trust

Federal Chief Information Security Officer Chris DeRusha and other federal officials also advocated moving away from siloed cybersecurity budgeting for agencies.

Cybersecurity

Existing Agency Threat Hunters Welcome CISA’s New Authorities 

For the Department of Education, proactive threat hunting means not just taking down questionable URLs but buying them up.

Cybersecurity

DOD’s Cybersecurity Accreditation Partner Working to Address Conflict of Interest Issues

Multiple members of the Accreditation Body’s board of directors also serve as consultants in the cybersecurity space, which critics say gives them an unfair advantage to cash in on the program.

Cybersecurity

Energy Department Announces 100-Day Sprint to Shore Up Power Grid Cybersecurity

The department will partner with the Cybersecurity and Infrastructure Security Agency and utilities to improve visibility, detection and response to cyber threats.

Cybersecurity

Agencies Have Till Midnight April 15 to Apply New Microsoft Exchange Patches

Four of the 95 vulnerabilities Microsoft released as part of its monthly “patch Tuesday” were identified by the National Security Agency.

Cybersecurity

White House Names National Cyber Director, CISA Chief

The administration also announced nominees for other Homeland Security Department leaders. 

Cybersecurity

Experts Torn on Role of National Cyber Director

Former officials agree someone needs to coordinate the work of various government entities but weighed pros and cons to the position being located within the National Security Council.

Cybersecurity

DOD’s Cybersecurity Accreditation Body Open to Pursuing Grants as a Nonprofit 

Once the organization gains non-profit status from the IRS, the board’s chairman sees new funding opportunities opening up that he says could benefit industry.

Cybersecurity

Top Homeland Security Senators Want Details on Agencies Hit in SolarWinds, Microsoft Intrusions

Sens. Gary Peters and Rob Portman also request more information on key defensive programs and federal cyber leadership.

Cybersecurity

DOD’s Vulnerability Disclosure Program for Contractors Is in Demand

The Defense Cyber Crime Center launched a pilot with “a few dozen” companies participating.

Ideas

Getting and Growing the Cyber Workforce You Need for 2021—and Beyond

It’s no secret that the competition for cyber talent is stiff. With a 0% unemployment rate and nearly 400K open positions across the U.S., federal agencies must reinvent their cyber employee experience.