New York's cyber chief on keeping cities and states safe from cyberattacks | The Record from Recorded Future News

And so we think that that'll continue to evolve the security posture of New York State in a way that first and foremost provides the public good, which is, if a government service is not secure, it can't be considered reliable. We're in the process of rolling out over the next year or two — in addition to our endpoint detection and response shared service — attack service management, so providing the counties at no cost an enterprise-grade attack service management platform which will complement our endpoint [detection service] insofar as that, we'll have now a view of what is exploitable within the networks that are owned and controlled and managed that provide those services so we can assist local governments in triaging important findings, health checks, addressing issues before they occur. Three years ago, Colin Ahern became New York state’s first ever chief cyber officer — a role he took on after serving as first deputy director of New York City Cyber Command and acting CISO for the city. Then the governor called, and said ‘do you want to be the first chief cyber officer of New York State?’ And obviously you say yes to that. In fiscal year 2022-23, the governor doubled the size of the New York State Police Cyber Analysis Unit, Computer Crimes Unit and Internet Crimes Against Children's Center. I would also add that the New York State Intelligence Center, our federally chartered multi-agency fusion center does work very, very closely with the private sector because they have a statewide mission to advance counter terrorism and other topics across the state. So New York, over the last several years, the state Education Department has done a tremendous job in organizing, promulgating and now requiring a broad spectrum computer science curriculum which has several elements, one of which is cyber. One of the things we've been working on very closely the last couple years with our partners in the legislature, in particular in the Assembly and the State Education Department, is the Computer Science for All curriculum. After that, I was asked by [former New York City] Mayor Bill de Blasio, First Deputy Mayor Tony Shorris and the first Director of New York City Cyber Command Geoff Brown, to help stand up New York City Cyber Command. With K-12 in New York State, your son or daughter probably has a technology class, and now they're going to be learning about cyber bullying. Government is a service provider, so our public comment outlines a couple of specific areas in which federal rule making and federal processes can do even more to collaborate across the levels of the government, by not just sharing information in an anonymized form, but working collaboratively with up-to-date threat-centric information, really in the model of the Counter Terrorism Fusion Task Forces, the Joint Task Forces. As cyber threats targeting government agencies surged during the COVID-19 pandemic, he took steps to move state systems to the cloud and tighten security measures. But the governor in last year's budget worked with our partners in the legislature to put forward a multi-$100 million dollar technology and cybersecurity grant program, which provides up to $500 million for these facilities to upgrade their technology and cyber. We continue to work with our state and local partners to expand the kind of shared services we're providing. Our primary focus is on county and local governments, but additionally other critical infrastructure partners do work very closely with the Division of Homeland Security Emergency Services. Has there been a threat assessment done? A risk assessment? Is there multi-factor authentication? So we respect the rules within HIPAA but we focus on the larger healthcare ecosystem landscape and on critical services, because New York's a big state, it is the fourth largest state by population. Additionally, the governor in December of 2022 signed first in the nation legislation to enable the Public Service Commission to prescriptively regulate cybersecurity for energy distribution. CA: We have one of the country's leading cyber analysis units within the New York State Police. It’s been a wild ride but the support that the governor has given us, the priority that she's really put on this to level up cyber has been obviously a big challenge, but I’m proud of the important successes and opportunities up to this point. I wasn't really sure what I was gonna do, but I decided I would stick with cyber, so I worked in cybersecurity in financial services for a little bit. Unfortunately, now the convergence we've seen in cybercriminals and their capabilities, some of the Russians, the Chinese, the Iranians in particular, their use of cybercriminals and the proliferation of cyber tools across the industry — you can find advanced cyber tools on GitHub. The Department of Financial Services (DFS) in 2017 had one of the first prescriptive cybersecurity regulations, which covered not just state-chartered banks, but also insurance companies and other financial institutions. We're pairing regulations, which we believe address critical, absolutely essential elements of a cyber posture. Starting in ‘07 and ‘08 and then accelerating since 2010 and kind of really supercharged in the last five years, you've seen this convergence where no longer are there just one set of groups with these bespoke tools, zero-day attacks, malware which can evade detection, command and control. Because we think that what New York, with the federal government, with the New York Field Office of the FBI, really pioneered after 9/11 is that we're all on the same team.

This Cyber News was published on therecord.media. Publication date: Wed, 26 Mar 2025 16:20:04 +0000


Cyber News related to New York's cyber chief on keeping cities and states safe from cyberattacks | The Record from Recorded Future News

New York's cyber chief on keeping cities and states safe from cyberattacks | The Record from Recorded Future News - And so we think that that'll continue to evolve the security posture of New York State in a way that first and foremost provides the public good, which is, if a government service is not secure, it can't be considered reliable. We're ...
3 days ago Therecord.media
What CIRCIA Means for Critical Infrastructure Providers and How Breach and Attack Simulation Can Help - Cyber Defense Magazine - To prepare themselves for future attacks, organizations can utilize BAS to simulate real-world attacks against their security ecosystem, recreating attack scenarios specific to their critical infrastructure sector and function within that sector, ...
5 months ago Cyberdefensemagazine.com Akira
How Public & Private Sectors Can Better Align Cyber Defense - Over the past 25 years, organizations like the FBI's Internet Crime Complaint Center (IC3), the National Cyber Investigative Joint Task Force (NCIJTF), and the Cybersecurity and Infrastructure Security Agency (CISA) have been created. Uncovering ...
1 month ago Darkreading.com
North Korea's Kimsuky Attacks Rivals' Trusted Platforms - North Korea-linked threat groups are increasingly using living-off-the-land (LotL) techniques and trusted services to evade detection, with a recent Kimsuky campaign showcasing the use of PowerShell scripts and storing data in Dropbox folders, along ...
1 month ago Darkreading.com Andariel Kimsuky
Trump to Nominate Ex-RNC Official as National Cyber Director - President Donald Trump reportedly will nominate Sean Cairncross, former chief operating officer of the Republican National Committee (RNC), as the new head of the Office of the National Cyber Director (ONCD), according to multiple reports. If ...
1 month ago Darkreading.com
IT Professionals in ASEAN Confronting Rising Cyber Security Risks - The ASEAN region is seeing more cyber attacks as digitisation advances. In July 2023, the Association of Southeast Asian Nations officially opened a joint cyber security information sharing and research centre, or Cybersecurity and Information Centre ...
1 year ago Techrepublic.com
Cyber Insurance: A Smart Investment to Protect Your Business from Cyber Threats in 2023 - Don't wait until it's too late - get cyber insurance today and secure your business for tomorrow. According to the U.S. Federal Trade Commission, cyber insurance is a particular type of insurance that helps businesses mitigate financial losses ...
1 year ago Cyberdefensemagazine.com
Three Key Threats Fueling the Future of Cyber Attacks - Improvements in cyber security and business continuity are helping to combat encryption-based ransomware attacks, yet the cyber threat landscape is continually evolving. Protecting an organization against intrusion remains a cat and mouse game, in ...
11 months ago Cyberdefensemagazine.com
Cyber Insurance for Businesses: Navigating Coverage - To mitigate these risks, many businesses opt for cyber insurance. With the wide range of policies available, navigating the world of cyber insurance can be overwhelming. In this article, we will delve into the complexities of cyber insurance and ...
1 year ago Securityzap.com
Cyber Insights 2023: The Geopolitical Effect - The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs. The Russia/Ukraine war that started in early 2022 has been mirrored by a ...
2 years ago Securityweek.com
Fighting ransomware: A guide to getting the right cybersecurity insurance - While the cybersecurity risk insurance market has been around for more than 20 years, the rapidly changing nature of attacks and the rise in the ransomware epidemic has markedly changed the nature of cyber insurance in recent years. It's more ...
1 year ago Scmagazine.com
'Sex life data' stolen from UK government among record number of ransomware attacks - Data on the sex lives of up to 10,000 people was stolen from a British government department in one of the record number of ransomware attacks to have hit Westminster in the first half of this year. It is not known which department the information ...
1 year ago Therecord.media
CISA says it will continue to monitor Russian cyber threats | The Record from Recorded Future News - Both The Guardian and Washington Post bolstered the claims about CISA by saying a recent speech on critical infrastructure cyber threats by a senior State Department official did not mention Russia. The story emerged on Friday around the same time as ...
3 weeks ago Therecord.media
US cities warn of wave of unpaid parking phishing texts - While parking scams have been around for years, a massive wave of phishing text messages has caused numerous cities throughout the US to issue warnings, including from Annapolis, Boston, Greenwich, Denver, Detroit, ...
2 weeks ago Bleepingcomputer.com
Wargames director Jackie Schneider on why cyber is one of 'the most interesting scholarly puzzles' - In other games, we had people from Silicon Valley who were leading AI companies or cyber companies. What we found is those who had expertise in cyber operations were more likely to be more nuanced about how they used the cyber capability. On a larger ...
10 months ago Therecord.media
The Evolution of Cyber Threats: Past, Present, and Future - Cyber threats have evolved significantly over time, posing increasing risks to individuals, organizations, and governments in our interconnected world. Let's explore the past, present, and future of cyber threats to better understand how to protect ...
1 year ago Securityzap.com
Does Pentesting Actually Save You Money On Cyber Insurance Premiums? - Way back in the cyber dark ages of the early 1990s as many households were buying their first candy-colored Macintoshes and using them to play Oregon Trail and visit AOL chat rooms, many businesses started venturing into the digital realm as well by ...
1 year ago Securityboulevard.com Rocke
Japan Goes on Offense With New 'Active Cyber Defense' Bill - Most notably, the government introduced what it called "active" cyber defense, "for eliminating in advance the possibility of serious cyberattacks that may cause national security concerns to the Government and critical infrastructures ...
1 month ago Darkreading.com
Russian Groups Target Signal Messenger in Spy Campaign - But the tactics the threat actors are using in the campaign could well serve as a blueprint for other groups to follow in broader attacks on Signal, WhatsApp, Telegram, and other popular messaging apps, GTIG warned in a blog post this week. The other ...
1 month ago Darkreading.com Turla
Malware Takedowns Show Progress, But Fight Against Cybercrime Not Over - Takedown of malware infrastructure by law enforcement has proven to have an impact, albeit limited, on cybercriminal activity, according to threat intelligence provider Recorded Future. The Emotet takedown, led by Europol and Eurojust in 2021. The ...
1 year ago Infosecurity-magazine.com
Worried about job security, cyber teams hide security incidents - Between a growing talent shortage, alert fatigue, and new sophisticated attack methods, companies are more susceptible than ever. The research reveals that 40% of cyber teams have not reported a cyber incident out of fear of losing their jobs - a ...
10 months ago Helpnetsecurity.com
The Future of AI Safety: What California's Vetoed Bill Means - Although the veto was a setback for the bill, it highlights key debates in the emerging field of AI governance and the potential for California to shape the future of AI regulation. With the rapid advancement of AI technology, California's ...
5 months ago Darkreading.com
Dragos Expands ICS Platform with New Acquisition - "We grew pretty fast to become the de facto solution in the electric industry as the OT network visibility and segmentation analysis solution, which is extremely important in the case of compliance for the regulation in this industry," ...
5 months ago Darkreading.com
Mississippi Creates New Cyber Unit and Names First Director - The state of Mississippi has recently announced the creation of a new dedicated cyber security unit, as well as the naming of its first director. The Mississippi Cyber Security Unit, headed by Director Kelly Hurst and backed by the Mississippi Office ...
2 years ago Securityweek.com
UAE, Saudi Arabia Become Plum Cyberattack Targets - Hacktivism-related DDoS attacks have risen 70% in the region, most often targeting the public sector, while stolen data and access offers dominate the Dark Web. With the UAE and Saudi Arabia increasingly invested in digitization, AI development, and ...
5 months ago Darkreading.com

Latest Cyber News


Cyber Trends (last 7 days)