Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Incident Response

Delay in Creating New Cybersecurity Board Prompts Concern

This is not the first time lawmakers have been unhappy with the pace of progress under Biden

This is not the first time lawmakers have been unhappy with the pace of progress under Biden

It’s a key part of President Joe Biden’s plans to fight major ransomware attacks and digital espionage campaigns: creating a board of experts that would investigate major incidents to see what went wrong and try to prevent the problems from happening again — much like a transportation safety board does with plane crashes.

But eight months after Biden signed an executive order creating the Cyber Safety Review Board it still hasn’t been set up. That means critical tasks haven’t been completed, including an investigation of the massive SolarWinds espionage campaign first discovered more than a year ago. Russian hackers stole data from several federal agencies and private companies.

Some supporters of the new board say the delay could hurt national security and comes amid growing concerns of a potential conflict with Russia over Ukraine that could involve nation-state cyberattacks. The FBI and other federal agencies recently released an advisory — aimed particularly at critical infrastructure like utilities — on Russian state hackers’ methods and techniques.

“We will never get ahead of these threats if it takes us nearly a year to simply organize a group to investigate major breaches like SolarWinds,” said Sen. Mark Warner, a Virginia Democrat who leads the Senate Intelligence Committee. “Such a delay is detrimental to our national security and I urge the administration to expedite its process.”

Biden’s order, signed in May, gives the board 90 days to investigate the SolarWinds hack once it’s established. But there’s no timeline for creating the board itself, a job designated to Department of Homeland Security Secretary Alejandro Mayorkas.

In response to questions from The Associated Press, DHS said in a statement it was far along in setting it up and anticipated a “near-term announcement,” but did not address why the process has taken so long.

Scott Shackelford, the cybersecurity program chair at Indiana University and an advocate for creating a cyber review board, said having a rigorous study about what happened in a past hack like SolarWinds is a way of helping prevent similar attacks.

Advertisement. Scroll to continue reading.

“It sure is taking, my goodness, quite a while to get it going,” Shackelford said. ”It’s certainly past time where we could see some positive benefits from having it stood up.”

The Biden administration has made improving cybersecurity a top priority and taken steps to bolster defenses, but this is not the first time lawmakers have been unhappy with the pace of progress. Last year several lawmakers complained it took the administration too long to name a national cyber director, a new position created by Congress.

The SolarWinds hack exploited vulnerabilities in the software supply-chain system and went undetected for most of 2020 despite compromises at a broad swath of federal agencies and dozens of companies, primarily telecommunications and information technology providers. The hacking campaign is named SolarWinds after the U.S. software company whose product was exploited in the first-stage infection of that effort.

The hack highlighted the Russians’ skill at getting to high-level targets. The AP previously reported that SolarWinds hackers had gained access to emails belonging to the then-acting Homeland Security Secretary Chad Wolf.

The Biden administration has kept many of the details about the cyberespionage campaign hidden.

The Justice Department, for instance, said in July that 27 U.S. attorney offices around the country had at least one employee’s email account compromised during the hacking campaign. It did not provide details about what kind of information was taken and what impact such a hack may have had on ongoing cases.

The New York-based staff of the DOJ Antitrust Division also had files stolen by the SolarWinds hackers, according to one former senior official briefed on the hack who was not authorized to speak about it publicly and requested anonymity. That breach has not previously been reported. The Antitrust Division investigates private companies and has access to highly sensitive corporate data.

The federal government has undertaken reviews of the SolarWinds hack. The Government Accountability Office issued a report this month on the SolarWinds hack and another major hacking incident that found there was sometimes a slow and difficult process for sharing information between government agencies and the private sector, The National Security Council also conducted a review of the SolarWinds hack last year, according to the GAO report.

But having the new board conduct an independent, thorough examination of the SolarWinds hack could identify inconspicuous security gaps and issues that others may have missed, said Christopher Hart, a former National Transportation Safety Board chairman who has advocated for the creation of a cyber review board.

“Most of the crashes that the NTSB really goes after … are ones that are a surprise even to the security experts,” Hart said. “They weren’t really obvious things, they were things that really took some deep digging to figure out what went wrong.”

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

Shaun Khalfan has joined payments giant PayPal as SVP, CISO.

UK cybersecurity agency NCSC announced Richard Horne as its new CEO.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

CISO Strategy

SecurityWeek spoke with more than 300 cybersecurity experts to see what is bubbling beneath the surface, and examine how those evolving threats will present...

CISO Conversations

Joanna Burkey, CISO at HP, and Kevin Cross, CISO at Dell, discuss how the role of a CISO is different for a multinational corporation...

CISO Conversations

In this issue of CISO Conversations we talk to two CISOs about solving the CISO/CIO conflict by combining the roles under one person.

CISO Strategy

Security professionals understand the need for resilience in their company’s security posture, but often fail to build their own psychological resilience to stress.

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...