The Biden administration has announced a 100-day plan aimed at rapid improvement of US power grid cybersecurity. The administration made reference to "bold" moves and laid out some of its general proposals.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Much of the new cybersecurity strategy addresses critical infrastructure companies, which were already in the administration's crosshairs, but software creators are also facing the prospect of a much greater degree of liability than in the past.
The Biden administration is examining the possible national security risks of having thousands of Chinese smart cars on US roadways. One possibility is that all of these cars could be remotely disabled at once, but there are also data privacy concerns.
While the Executive Order primarily focuses on concrete steps the federal government must take to adopt cybersecurity best practices, there are several provisions that will also significantly impact government contractors, subcontractors and other private sector entities.
As ransomware attacks surge and hackers become increasingly bold, the Biden administration is forging ahead with a package of new measures that includes up to $10 million for information that leads to the identification of attackers that hit critical infrastructure.
Biden's Executive Order 14110 of Oct. 30, 2023 was aimed at developers of "the most powerful" AI systems. It required reporting of potential AI risks and sharing of results of their red-team safety tests with federal agencies.
The Biden administration will sign an executive order to bolster port cybersecurity with additional actions to enhance maritime cybersecurity, secure supply chains, and strengthen the US industrial base.
President Joe Biden warned Vladimir Putin that there would be consequences for ransomware attacks launched from Russia even if they were not sanctioned by the Kremlin.
Setting the direction towards leading standards in authentication, encryption and data compliance will yield great benefits as these approaches begin to be increasingly implemented across public and private areas.
The number of cyberattacks continues to rise and organisations need to come to terms with the fact that traditional approaches to mitigating the effects of malicious attacks may no longer be viable. One of these approaches is to harness the power of big data technology to help companies improve their proactive and reactive cyber-defence capabilities. David White and Annie Tu examine how old approaches may be found wanting and a paradigm based on new defence models can help companies not only stop hackers, but also help to better identify and respond to malicious activities.










