Defense Systems

Federal government is still in the dark on ransomware

Information on the majority of ransomware attacks targeting American companies and civilian agencies remains unreported to the Department of Homeland Security, a top cyber official told lawmakers.

Threats

China May Steal Encrypted Data Now to Decrypt In Years to Come, Report Warns

Quantum computers promise to render today's encryption largely obsolete. A Booz Allen report says it's time to start managing the risks.

Ideas

Waiting for Attribution in Cyberspace: A Tragicomedy

“We were so hopeful last March when the UN Open-Ended Working Group agreed to endorse all 11 of us voluntary, non-binding norms of responsible state behavior.”

Defense Systems

Homeland Security updates cyber workforce system

The Department of Homeland Security’s Cybersecurity Talent Management System updates the agency’s practices around hiring, compensating and developing employees.

Defense Systems

FBI wants input on cyber reporting legislation

A top FBI cyber official told lawmakers on Tuesday that the bureau could face significant challenges addressing cyberattacks and ransomware incidents if it was not included in breach disclosure requirements being considered in legislation.

Policy

DHS Launches Portal to Recruit—and Retain—Cybersecurity Talent

The moment of truth is here for a new hiring system that promises to address gaping cybersecurity shortages by redefining "merit."

Defense Systems

Who's ready to volunteer for the new CMMC?

The Defense Department is looking for contractors to test out its revamped cybersecurity standard to protect unclassified but sensitive data.

Defense Systems

Creating a cyber talent pipeline for DOD contractors

Old Dominion University’s School of Cybersecurity is training cyber experts to be fluent in the Defense Department’s cybersecurity requirements so they can help defense contractors stay secure.

Ideas

The Disinformation Business is Booming

Other nations can learn from South Korea, which has been on the forefront of online disinfo.

Defense Systems

CISA directive requires vulnerability fixes in 6 months

A new binding operational directive puts federal civilian agencies on a six-month clock to remediate known vulnerabilities.

Defense Systems

DOD revamps controversial CMMC program

After a nine-month review, the Defense Department is replacing its original cyber compliance program for the industrial base with CMMC 2.0, putting more emphasis on self-assessment.

Defense Systems

White House pick for DOD CIO eyes tweaks to CMMC

The Biden administration's pick to be the Pentagon's tech chief wants to make it easier for small businesses to adhere to the Defense Department's cybersecurity standards and expand network optimization across the entire enterprise.

Science & Tech

New White House Cyber Director Wants to Fight Like Cobra Kai

Chris Inglis says the government needs to hit would-be attackers where it hurts.

Defense Systems

The state of CMMC from an assessor perspective

The Cybersecurity Maturity Model Certification program is a step forward for DOD and its contractors to improve the nature and the operation of the DOD supply chain in today’s cybersecurity-focused world.

Defense Systems

State Department to get cyber bureau

The secretary of State named cybersecurity and emerging tech as critical areas for capacity building at State, alongside climate, global health and multilateral technology.

Defense Systems

New missions could present challenges for DODs cyber workforce

Mieke Eoyang, the deputy assistant secretary of defense for cyber policy said one of DOD's main cyber workforce challenges is being able to set expectations around policymakers' calls to step in and defend against cyberattacks.

Ideas

It’s Not About Submarines. It’s about Software

Important as AUKUS submarines are in the military balance, the new way of deterrence will be about the strength, speed, and resilience of software.

Defense Systems

DOD testing director nominee wants cyber assessments for commercial cloud systems

The Biden administration's pick to lead the Defense Department's operational testing, Nickolas Guertin, called the department's inability to conduct independent cyber assessments of commercial cloud systems "a severe limitation."

Defense Systems

CISA seeks 24-hour cyber incident reporting timeline

Two separate Senate bills set different deadlines for federal contractors, critical infrastructure providers and other covered companies to report cyber incidents to the federal government.

Science & Tech

Russian Corruption Makes It Harder to Crack Down on Ransomware

Hackers who learned skills in government service are branching out “for their own personal enrichment,” Pentagon cyber leader says.