Biden administration wants to hold companies liable for bad cybersecurity

Aerial view of the White House at 1600 Pennsylvania Avenue and Lafayette Square, Washington DC, USA.

Getty Images

The Biden administration on Thursday called for new mandatory regulations and responsibilities on software makers and service providers to shift the burden of protecting America’s cyberspace away from smaller organizations and individuals.

“The most capable and highest-ranking actors in cyberspace must be the better stewards of the digital ecosystem,” said a long-awaited administrative official documenting the latest national cybersecurity strategy. written in the document. Individuals, small businesses, state and local governments, infrastructure His operators have limited resources and competing priorities, but the choices these actors make have a significant impact on national cybersecurity. There is a possibility. ”

Increased regulation and liability

The 39-page document cites recent ransomware attacks that have disrupted hospitals, schools, government services, pipeline operations, and other critical infrastructure and essential services. In 2021, we saw a ransomware attack against the Colonial pipelines that will supply much of the southeastern United States with gasoline and jet fuel. The attack shut down huge pipelines for days and caused fuel shortages in some states.

In the wake of that attack, the administration imposed new regulations on energy pipelines. Thursday’s strategy document suggests that similar frameworks are likely to be rolled out to other industries.

“Our strategic environment includes a modern and agile cybersecurity landscape that is tailored to each sector’s risk profile, harmonized to reduce duplication, complements public-private partnerships, and is cost-aware of implementation. We need a more robust regulatory framework,” the document said. “New and updated cybersecurity regulations to meet national security and public safety needs, in addition to the security and safety of individuals, regulated entities, and their employees, customers, operations, and data. We need to adjust.”

Another key focus of this strategy is to “strike a careful balance between protecting ourselves from today’s urgent threats while simultaneously strategically planning and investing in a resilient future. By supporting long-term investment.

One of the most controversial initiatives in the technology industry is holding companies accountable for vulnerabilities in software and services. Under the existing legal framework, even if the vulnerability stems from insecure default settings or known vulnerabilities, the legal consequences these companies face if their products or services are exploited are, even if Very few.

“While recognizing that even the most sophisticated software security programs cannot prevent all vulnerabilities, we must begin to shift the blame to entities that do not take reasonable precautions to protect their software. No,” the document said. “A company that creates software should have the freedom to innovate, but not be held accountable if it fails to meet the duty of care it owes to consumers, businesses, or its providers of critical infrastructure. I have to.”

five pillars

This document lists five “pillars” of these objectives. they are:

1. Protect your critical infrastructure. The plan not only expands regulation of critical sectors, but also protects critical infrastructure and public safety, and enables public-private sector cooperation in defending and modernizing federal networks and federal incident response. is required.

2. Disruption and Dismantling of Threat Actors to blunt their threat to national security and public safety. The means to achieve this include adopting “all the tools of national power” to deter threat actors, having the private sector do the same, and comprehensive This includes addressing the ransomware threat through a federal approach.

3. Shaping market forces to increase security and resilience. This includes giving responsibility to those best positioned to mitigate risk within the digital ecosystem. This pillar emphasizes promoting personal data privacy and security, shifting responsibility for software and services, and ensuring that federal grant programs encourage investment in new, more secure infrastructure. increase.

Four. Investing in a resilient future Through “strategic investments and coordinated joint actions”. This includes reducing vulnerability across the digital ecosystem, increasing resilience to cross-border repression, prioritizing cybersecurity research and development, and creating a stronger national cybersecurity workforce. increase.

Five. Forge international partnerships to achieve common goals. Some of the means to this end are implementing or leveraging United Nations and partnerships to counter threats, enhancing partners’ cybersecurity defense capabilities, and working with allies.

The last time a president presented a national cybersecurity blueprint was in 2018 under President Donald Trump. In the five years since, he’s had a series of damaging cyberattacks in the United States. Aside from the Colonial Pipeline, this includes the Solar Winds supply he chain attack that was revealed in December 2020. By compromising SolarWinds’ software distribution system, threat actors acting on behalf of the Kremlin delivered malware to approximately 18,000 customers using network management products. The hacker then sent his follow-up payloads to about 10 US federal agencies and about 100 private organizations.

Ransomware attacks are more common than they were five years ago. In the strategy, administrative officials wrote:

Given the impact of ransomware on key critical infrastructure services, the United States will use all elements of national power to combat the threat along four lines of effort: (2) investigate ransomware crimes and use law enforcement and other authorities to disrupt ransomware infrastructure and actors; (3) increase the resilience of critical infrastructure to withstand ransomware attacks; (4) address the abuse of virtual currency to launder ransom payments;

The document also reclassifies ransomware as a national security threat, previously considered a criminal threat.

The plan will be coordinated by the National Security Council, the White House Office of Management and Budget, and the Office of the Director of National Cyber ​​Affairs. These agencies provide annual reports to the President and Congress to update the plan’s implementation and effectiveness. These agencies also provide annual guidance to federal agencies. The White House provided this factsheet outlining the plan.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *