Experts call for US Cyber Safety Review Board rethink The Register

As the US mulls legislation that would see the Cyber Safety Review Board become a permanent fixture in the government's cyber defense armory, experts are calling for substantial changes in the way it's organized.
Discussions were held at a US Senate hearing on January 17 on how the CSRB could be improved.
The board was established in 2021 via an Executive Order and is tasked with investigating some of the most pressing cybersecurity challenges facing the US, but has only produced two reports so far: One on Log4J [PDF] and another on the LAPSUS$ group [PDF].
All three senior industry figures in attendance agreed that a greater degree of independence was required to ensure the reports produced by the board were as richly detailed as possible, answering the questions that those in the private sector typically haven't in the past.
Tarah Wheeler, CEO at Red Queen Dynamics, said the current makeup of the CSRB needs a serious rethink and the way investigations are carried out at present is like asking Boeing's leadership to write the sole report on what happened with last week's 737 MAX 9 disaster.
Currently, the CSRB comprises 15 cybersecurity leaders from both the public and private sectors, but this is viewed as a potential blockade for open, transparent reporting on major incidents.
A private organization isn't expected to be completely and wholly transparent about a security incident, so to elect a representative of an organization subject to a CSRB investigation to the CSRB could result in findings omitted for legal and profitability reasons.
The board's upcoming third report, looking into the Microsoft Exchange snafu that saw 60,000 State Department emails flutter off to China, is one such example of where private sector members from or with ties to Microsoft have no place.
To avoid a duplication of efforts, the CSRB should be an independent body wielding the power to fully probe an incident and include every detail in an open report so the wider industry can benefit from the lessons, she argued.
The goal of the CSRB should be to offer reports filled with actionable information that's free to be published without fear of lawyers hushing certain sections or risking a dip in stock prices.
The sentiment was shared by Trey Herr, director of the Cyber Statecraft Initiative at the Atlantic Council, who also agreed that the proposed independence of the CSRB should be seen as a key strength and an argument in favor of introducing the board on a permanent basis.
In terms of the board's membership, Herr said the CSRB should have a handful of core members but also have the power to bring in and recuse members on an ad-hoc basis, depending on the perceived conflict of interest on any given investigation.
John Miller, senior veep of policy, trust, data, and technology and general counsel at the Information Technology Industry Council, said private sector board members should be independent and the election process should also be transparent.
It's a sentiment that was met with unanimous agreement, but there is somewhat of an unease around the conflicts of interest that arise with the private sector's involvement.
In addition to its independence and primary function, discussions were held about whether the board should have the power to subpoena organizations to obtain key information that may otherwise stay within a company's walls.
Wheeler, on one hand, appeared vehemently in favor of affording the CSRB subpoena powers, but not in its current makeup, which she argued could be seen as anti-competitive.
Herr agreed, with a slight addendum: The subpoena power should not be tied to a criminal investigation - something that may impede the board's access to information.
He said it should exist within a specific authority like the National Transportation Safety Board - a similar body that investigates major transport accidents and inspired the formation of the CSRB - and shouldn't be punitive in any way.
Miller opposed the idea, saying it was too early to think about affording the CSRB powers of this caliber until the Cybersecurity and Infrastructure Security Agency has finalized the scope of the incidents and covered entities of the Cyber Incident Reporting for Critical Infrastructure Act of 2022.
Following the hearing, Senator Gary Peters said the committee was not endorsing any of the testimony given before it this week and is still in the research stages of deciding whether to codify the board.


This Cyber News was published on go.theregister.com. Publication date: Thu, 18 Jan 2024 19:13:05 +0000


Cyber News related to Experts call for US Cyber Safety Review Board rethink The Register

Experts call for US Cyber Safety Review Board rethink The Register - As the US mulls legislation that would see the Cyber Safety Review Board become a permanent fixture in the government's cyber defense armory, experts are calling for substantial changes in the way it's organized. Discussions were held at a US Senate ...
10 months ago Go.theregister.com
OpenAI's board might have been dysfunctional-but they made the right choice. Their defeat shows that in the battle between AI profits and ethics, it's no contest - The drama around OpenAI, its board, and Sam Altman has been a fascinating story that raises a number of ethical leadership issues. What are the responsibilities that OpenAI's board, Sam Altman, and Microsoft held during these quickly moving events? ...
11 months ago Fortune.com
Fighting ransomware: A guide to getting the right cybersecurity insurance - While the cybersecurity risk insurance market has been around for more than 20 years, the rapidly changing nature of attacks and the rise in the ransomware epidemic has markedly changed the nature of cyber insurance in recent years. It's more ...
10 months ago Scmagazine.com
Cyber Insurance for Businesses: Navigating Coverage - To mitigate these risks, many businesses opt for cyber insurance. With the wide range of policies available, navigating the world of cyber insurance can be overwhelming. In this article, we will delve into the complexities of cyber insurance and ...
9 months ago Securityzap.com
Cyber Insurance: A Smart Investment to Protect Your Business from Cyber Threats in 2023 - Don't wait until it's too late - get cyber insurance today and secure your business for tomorrow. According to the U.S. Federal Trade Commission, cyber insurance is a particular type of insurance that helps businesses mitigate financial losses ...
9 months ago Cyberdefensemagazine.com
Teaching Digital Literacy and Online Safety - It is crucial for educators to prioritize teaching online safety to ensure that students are equipped with the necessary skills to protect themselves online. This article aims to explore the importance of teaching digital literacy and online safety, ...
11 months ago Securityzap.com
Why Virtual Board Portals are the Key to Better Collaboration and Decision-Making - A digital meeting refers to a business gathering conducted electronically, eliminating the need for traditional paper documents. Embracing paperless council meetings contributes to sustainability by reducing paper waste and diminishing the energy ...
10 months ago Hackread.com
Three Key Threats Fueling the Future of Cyber Attacks - Improvements in cyber security and business continuity are helping to combat encryption-based ransomware attacks, yet the cyber threat landscape is continually evolving. Protecting an organization against intrusion remains a cat and mouse game, in ...
7 months ago Cyberdefensemagazine.com
Wargames director Jackie Schneider on why cyber is one of 'the most interesting scholarly puzzles' - In other games, we had people from Silicon Valley who were leading AI companies or cyber companies. What we found is those who had expertise in cyber operations were more likely to be more nuanced about how they used the cyber capability. On a larger ...
5 months ago Therecord.media
Meet Your New Cybersecurity Auditor: Your Insurer - As businesses deal with the fallout of massive ransomware waves, from Lapsus$ to Cl0p/MOVEit, an unlikely new entity is joining the regulatory bodies to raise the bar for cybersecurity: the cyber insurer. Their coverage requirements and ...
11 months ago Darkreading.com
Role of Parents in Teaching Online Safety - In today's digital landscape, where children are increasingly exposed to the vast world of the internet, the role of parents in teaching online safety has become paramount. Parents should have regular conversations with their kids about the ...
11 months ago Securityzap.com
Does Pentesting Actually Save You Money On Cyber Insurance Premiums? - Way back in the cyber dark ages of the early 1990s as many households were buying their first candy-colored Macintoshes and using them to play Oregon Trail and visit AOL chat rooms, many businesses started venturing into the digital realm as well by ...
11 months ago Securityboulevard.com
Cyber Insights 2023: The Geopolitical Effect - The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs. The Russia/Ukraine war that started in early 2022 has been mirrored by a ...
1 year ago Securityweek.com
IT Professionals in ASEAN Confronting Rising Cyber Security Risks - The ASEAN region is seeing more cyber attacks as digitisation advances. In July 2023, the Association of Southeast Asian Nations officially opened a joint cyber security information sharing and research centre, or Cybersecurity and Information Centre ...
11 months ago Techrepublic.com
Uncertainty Is the Biggest Challenge to Australia's Cyber Security Strategy - Political shifts could lead to changes in Australia's cyber security strategy. Early in 2023, as the Australian government started to craft its cyber security vision, it met with opposition at both ends of the political spectrum. On the right wing, ...
10 months ago Techrepublic.com
Online safety laws: What's in store for children's digital playgrounds? - As children's safety and privacy online becomes a matter of increasing urgency, lawmakers around the world push ahead on new regulations in the digital realm. Tomorrow is Safer Internet Day, an annual awareness campaign that started in Europe in 2004 ...
1 year ago Welivesecurity.com
CVE-2022-48998 - In the Linux kernel, the following vulnerability has been resolved: powerpc/bpf/32: Fix Oops on tail call tests test_bpf tail call tests end up as: test_bpf: #0 Tail call leaf jited:1 85 PASS test_bpf: #1 Tail call 2 jited:1 111 PASS test_bpf: #2 ...
4 weeks ago Tenable.com
The Evolution of Cyber Threats: Past, Present, and Future - Cyber threats have evolved significantly over time, posing increasing risks to individuals, organizations, and governments in our interconnected world. Let's explore the past, present, and future of cyber threats to better understand how to protect ...
9 months ago Securityzap.com
Cyber Insights 2023: Cyberinsurance - The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs. In 2022, Russia invaded Ukraine with the potential for more serious and more ...
1 year ago Securityweek.com
5 Ways to Counteract Increasing Cyber Insurance Rates - Despite this threat, only 55% of organizations have some form of cyber insurance, and only 19% have coverage for cyber events beyond $600,000. As the cybersecurity landscape continues to evolve, businesses must carefully evaluate their risk exposure ...
9 months ago Cybersecurity-insiders.com
Cybersecurity Tops 2024 Global Business Risks - The newly released Allianz Risk Barometer revealed that Cyber incidents such as ransomware attacks, data breaches, and IT disruptions are the biggest worry for companies globally, as well as in the United States, in 2024. The 13th annual business ...
9 months ago Cybersecurity-insiders.com
CVE-2013-0135 - Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) addressbook/register/delete_user.php, (2) addressbook/register/edit_user.php, or (3) ...
7 years ago
What CIRCIA Means for Critical Infrastructure Providers and How Breach and Attack Simulation Can Help - Cyber Defense Magazine - To prepare themselves for future attacks, organizations can utilize BAS to simulate real-world attacks against their security ecosystem, recreating attack scenarios specific to their critical infrastructure sector and function within that sector, ...
1 month ago Cyberdefensemagazine.com
Student Cybersecurity Clubs: Fostering Online Safety - Student cybersecurity clubs are playing a crucial role in promoting online safety among students. Student cybersecurity clubs play a vital role in this regard, as they provide a platform for students to learn about the latest threats, share best ...
10 months ago Securityzap.com
Smashing Security Podcast Episode 306: What is the State of Cyber Security in 2020? - The recent pandemic has created a need for businesses to invest in cybersecurity more than ever. The popularity of digital communication and remote access has exposed organizations to more cybersecurity threats than ever before. Graham Cluley’s ...
1 year ago Grahamcluley.com

Latest Cyber News


Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)