Cyber Security Exchange

A vertical community of Federal cyber security leaders, project managers, industry, and government IT community stakeholders focused on public-private collaboration and best-practice exchange.

Ban on Ransom Payments Needs More Work, Walden Tells Hill

While a total ban on ransom payments to hackers remains “the ultimate goal” for cybersecurity experts, critical infrastructure organizations need stronger cybersecurity resilience before that happens, former acting National Cyber Director Kemba Walden told lawmakers on April 16. […]

Tagged , , , | Leave a comment

Easterly Pitches Procurement Power to Enforce Cybersecurity

The head of the Cybersecurity and Infrastructure Security Agency (CISA) said today that the Federal government has a “powerful” ability to mandate security standards for software vendors through its procurement process. […]

Tagged , , , , | Leave a comment

Congress Urged to Enforce Minimum Healthcare Cyber Standards

A group of industry experts called on Congress this week to enforce minimum cybersecurity standards among healthcare organizations in light of the February ransomware attack on UnitedHealth subsidiary Change Healthcare. […]

Tagged , , | Leave a comment

Axonius Adapt: Feds Looking to Upskill AI Workforce

As artificial intelligence technologies continue to rapidly evolve, Federal agencies are looking to upskill their AI workforce to keep pace with emerging cybersecurity threats. […]

Tagged , , , , , | Leave a comment

Flournoy: NCS Lacks Teeth to Regulate Secure-by-Design

The former policy lead for the Department of Defense (DoD) under President Barack Obama said Tuesday that while the Biden administration’s National Cybersecurity Strategy (NCS) calls for secure-by-design technology principles, the White House doesn’t actually have the authority to regulate that. […]

Tagged , , | Leave a comment

DeRusha Credits Quick SASE ‘Flip’ to Meet Ivanti Vulnerability

Federal Chief Information Security Officer (CISO) Chris DeRusha gave broad credit today to Federal agencies for making marked improvements in cybersecurity over the past few years, and cited the ability of one larger agency – which he did not name – with being able to take particularly quick action in the face of the Ivanti vulnerabilities that the government began warning about in January. […]

Tagged , , | Leave a comment

CSRB Slams Microsoft for ‘Inadequate’ Security Culture, Calls for Overhaul

The Department of Homeland Security’s (DHS) Cyber Safety Review Board (CSRB) released findings late Tuesday following its independent review of the summer 2023 Microsoft Exchange Online intrusion that attributed the success of the China-based hack to “a cascade of security failures at Microsoft” and an “inadequate” security culture at the company. […]

Tagged , , | Leave a comment

FAR Updated With Cyber, Supply Chain Security

The Defense Department, General Services Administration, and NASA have issued a final rule amending the Federal Acquisition Regulation (FAR) to add the framework for a new FAR part 40 covering information security and supply chain security. […]

Tagged , , | Leave a comment

Subscribe

Want the latest on the Cyber Security Exchange? Sign up today.

  • This field is for validation purposes and should be left unchanged.

Subscribe

Want the latest on the Cloud Computing Exchange? Sign up today.

  • This field is for validation purposes and should be left unchanged.