Tighter cybersecurity regulations that have already come for certain critical infrastructure industries are now being applied to rail and aviation, as the Biden administration continues a general program of hardening the country's cyber defenses.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
The UK has experienced a long string of disruptive cyber incidents, but the announcement of the cyber resilience bill cites attacks on managed service providers as a particular impetus for the overhaul of existing laws.
Huawei has made “no material progress” on addressing Huawei cybersecurity flaws discovered a year ago. Recent HCSEC study shows Huawei cybersecurity practices are untrustworthy and present high risk to the UK for large 5G network build-outs.
As part of the Biden administration's ongoing infrastructure bill project, which looks to commit trillions of dollars to addressing longtime issues with the country's vital utilities, $1.9 billion has been proposed for cybersecurity funding.
New US National Security Directive: Foreign Internet Routers Require Special FCC Approval to be Sold
Consumer-grade internet routers have been added as a category to the FCC's Covered List, which establishes communications equipment and services deemed to be an unacceptable national security risk. Some individual manufacturers, such as Huawei and ZTE, have already been added to this list in years past.
The executive order instructs the National Security Agency, Department of Defense and other agencies to create a benchmarking standard to determine the degree to which AI models are a cyber risk that may impact national security, but stresses that it is not a "mandatory governmental licensing, preclearance, or permitting requirement" for developers.
With tens of thousands of contractors serving the Defense Department, the new vendor cyber security certificate aims to improve supply chain security by assessing contractors before allowing them to bid.
Latest 2019 Verizon data breach report highlights absence of foundation-level and layered security controls, internal security discipline, and general security awareness as the common denominators in the data breach dilemma.
Billions of devices may be affected by a UPnP vulnerability that allows hackers to conduct a DDoS attack and perform data exfiltration on the local network.
A bill establishing a new vulnerability disclosure program for federal contractors has passed the House, and will now move on to the Senate to be reviewed by the Committee on Homeland Security and Governmental Affairs.










