Skip to main content

CISA’s got a plan to strengthen corporate cybersecurity

Delivered every Monday by 10 a.m., Weekly Cybersecurity examines the latest news in cybersecurity policy and politics.
Jan 30, 2023 View in browser
 
POLITICO's Weekly Cybersecurity newsletter logo

By John Sakellariadis

With help from Maggie Miller

Driving the Day

CISA is starting the year laser-focused on enhancing cybersecurity at the corporate level, a top agency official tells MC.

HAPPY MONDAY, and welcome to Morning Cybersecurity! Between the Sixers, the Phillies and the Eagles, the City of Brotherly Love is having a moment.

… Which should infuriate me as a New Yorker. But between my editor (Philly native) and my in-laws (ditto), I’m ready to praise the Birds now so I don’t have to eat crow later. Fly, Eagles fly!

Got tips, feedback or other commentary? Send them my way at jsakellariadis@politico.com. You can also follow @POLITICOPro and @MorningCybersec on Twitter. Full team contact info is below.

 

JOIN POLITICO ON 2/9 TO HEAR FROM AMERICA’S GOVERNORS: In a divided Congress, more legislative and policy enforcement will shift to the states, meaning governors will take a leading role in setting the agenda for the nation. Join POLITICO on Thursday, Feb. 9 at World Wide Technology's D.C. Innovation Center for The Fifty: America's Governors, where we will examine where innovations are taking shape and new regulatory red lines, the future of reproductive health, and how climate change is being addressed across a series of one-on-one interviews. REGISTER HERE.

 
 

Want to receive this newsletter every weekday? Subscribe to POLITICO Pro. You’ll also receive daily policy news and other intelligence you need to act on the day’s biggest stories.

Today's Agenda

Nothing terabyte-sized on the agenda.

At the Agencies

AT THE BOARD LEVEL — A top priority for the Cybersecurity and Infrastructure Security Agency in 2023: cajoling corporations into better safeguarding their networks — including a potential laundry list of what that should include, Maggie reports in a story out this morning.

Companies need to embrace the idea of “corporate cyber responsibility,” CISA chief of staff Kiersten Todt told POLITICO in an interview Friday at the agency’s headquarters in Arlington, Va.

“The innovation of the car was a great asset, and with that though came this responsibility to take care of the car, to make sure it was safe and secure,” Todt said. “Similarly, cyber represents technology, represents innovation that every company benefits from.”

— No orders here: Todt stressed that she’s talking about voluntary actions by companies and said CISA is exploring putting out guidelines to help them do that. That could include CISA creating a “series of best practices” on cybersecurity for boards and senior officials, she said.

“What we're doing right now is exploring and examining and researching what makes the most sense to be able to put it in a straightforward, accessible way and that is something off of which we can build,” Todt said. She stressed that “this isn't intended to be ‘thou shalt,’ it's much more of the ‘we've got to work together.’”

Todt said CISA would involve industry in any crafting of guidelines, and that there are no specific deadlines at the moment for the initiative.

— Teamwork makes the dream work: CISA could work with other agencies in prioritizing corporate cybersecurity, such as with the Small Business Administration to help get smaller organizations involved, Todt said. More formally, the Internet Security Alliance and the National Association of Corporate Directors will be jointly involved in the program alongside CISA.

— A silver lining: Companies have been more fixated on cybersecurity after a year in which CISA worked to ensure critical infrastructure groups were alert to potential threats from Russia as part of its “Shields Up” campaign. Todt noted the effort served as a “catalyst” for boards to invest more in cybersecurity, and that industry has made clear to CISA that it doesn’t want to go “shields down,” particularly due to ongoing ransomware attacks that have made cybersecurity a major concern for Americans.

“People now accept this heightened level of vigilance without real fatigue because this is what's part of what we need to do,” Todt said. “That is an element of this corporate cyber responsibility, and being able to work more collaboratively with industry to help them demystify what we know.”

Read the full story (for Pros!) here.

On the Hill

GOP DRAWS STRAWS FOR HOUSE HOMELAND — An up-and-coming cyber lawmaker is set to lead an influential House committee with jurisdiction over CISA and the nation’s critical infrastructure protection efforts.

Republican Rep. Andrew Garbarino (R-N.Y.) will take the gavel in the House Homeland Security Committee’s subcommittee on Cybersecurity and Infrastructure Protection, Republican leadership announced Friday.

Building a resume — The second-term congressman has been vocal on cybersecurity issues since he entered Congress, sponsoring or co-sponsoring 14 pieces of legislation on the topic.

More aggressive oversight — While in the minority, Garbarino frequently nudged DHS and White House cyber officials to provide more transparency about the administration’s cyber work or to giddy up on congressional priorities.

For example, late last year, Garbarino and Rep. Mike Gallagher (R-Wisc.) pressed the White House to follow through on a new law directing CISA to draft a plan for how the government would maintain “economic continuity” in the event of a massive cyberattack.

GOP depth problems? — None of the other four Republicans named to the subcommittee has a background in cyber policy, and with the exception of Garbarino and Rep. Carlos Giménez (R-Fla.), also a second-term congressman, all are freshmen on Capitol Hill.

Likewise, while Chair Mark Green (R-Tenn.) has cited securing the “cyber border” as one of his top priorities for the committee, neither Green nor vice chair Michael Guest (R-Miss.) has previously been active on cybersecurity issues.

Cyber Diplomacy

TRANSATLANTIC CYBER COLLAB — The U.S. and European Union are eyeing tighter cooperation on cybersecurity governance, even as both pave the way for new — and likely inconsistent — regulatory regimes.

In a joint statement released late Thursday, DHS and the European Commission's Directorate-General for Communications Networks, Content and Technology announced the launch of three cyber policy “workstreams” organized around information sharing and crisis response, critical infrastructure protection, and the security of hardware and software.

Next steps — The statement highlighted a number of projects EU and U.S. officials would prioritize ahead of the next EU-U.S. cyber dialogue, expected in the second half of 2023.

Those projects include examining ways to secure civilian space systems, finalizing a “working arrangement” between CISA and its EU equivalent, ENISA, harmonizing incident reporting regimes and developing more robust transatlantic threat sharing programs, among others.

Tough road ahead? — The EU is moving more aggressively than the U.S. when it comes to cyber regulation, raising questions about whether some of those initiatives could quickly run into transatlantic headwinds.

For example, the EU’s newly revised Network and Information Security Directive, or NIS2, designates cloud providers as essential entities, something U.S. lawmakers have thus far avoided. It also sets stricter and more robust incident reporting, corporate governance and vulnerability disclosure rules than equivalents that have gained traction in the U.S.

Hold your horses, MC! — NIS2 will not bear real teeth until a member-state implementation deadline of fall 2024. In the meantime, the White House is gearing up to release its new national cyber strategy, which should help close the transatlantic regulatory gap by calling for tighter oversight of U.S. companies.

Tweet of the Weekend

Russia blocking access to the State Department’s Rewards for Justice website, hours after it asked for information on the operators of the Hive ransomware group? No, not suspicious at all.

@mathew_d_green

Twitter

Quick Bytes

— The Atlantic Council has a new blog post out this morning on China’s cyber operations.

— Ukraine blames a notorious Russian hacking group for another disruptive wiper attack. (CyberScoop)

— Russia blocks access to the website of the State Department’s Rewards for Justice program. (The Record)

— Inside TikTok’s plans to address U.S. national security concerns. (CyberScoop)

Chat soon. 

Stay in touch with the whole team: Maggie Miller (mmiller@politico.com); John Sakellariadis (jsakellariadis@politico.com); and Heidi Vogt (hvogt@politico.com).

~~~~~

 

DOWNLOAD THE POLITICO MOBILE APP: Stay up to speed with the newly updated POLITICO mobile app, featuring timely political news, insights and analysis from the best journalists in the business. The sleek and navigable design offers a convenient way to access POLITICO's scoops and groundbreaking reporting. Don’t miss out on the app you can rely on for the news you need, reimagined. DOWNLOAD FOR iOSDOWNLOAD FOR ANDROID.

 
 
 

Follow us on Twitter

Heidi Vogt @HeidiVogt

Maggie Miller @magmill95

John Sakellariadis @johnnysaks130

 

Follow us

Follow us on Facebook Follow us on Twitter Follow us on Instagram Listen on Apple Podcast
 

To change your alert settings, please log in at https://www.politico.com/_login?base=https%3A%2F%2Fwww.politico.com/settings

This email was sent to rouf@idiot.cloudns.cc by: POLITICO, LLC 1000 Wilson Blvd. Arlington, VA, 22209, USA

Please click here and follow the steps to unsubscribe.

Comments

Popular Posts

💡The most innovative iPhone trick of the year.

Watch the performance: The ULTIMATE every-day carry. Make the physical light on the back of your iPhone come to life and move around. Then hand everything out for examination. This is a wildly innovative idea you have to see to believe.   ...

Breaking News: Top lawmakers strike funding deal, potentially averting weekend shutdown

Breaking News Alert Top lawmakers strike funding deal, potentially averting week...

Google Alert - Swift

Swift Daily update ⋅ November 28, 2017 NEWS The World's Best Driver's Car Under $18000 Is A Suzuki Swift Sport Forbes What better way to regain the interest of a generation that has fallen out of love with the car than to give it a super hot hatch like the Suzuki Swift Sport? Flag as irrelevant Taylor Swift tops Billboard chart for second week in a row... after breaking record with Reputation ... Daily Mail She broke a personal best record by selling 1.29 million copies of Reputation in the first week of it's release last week. And Taylor Swift has kept the success train running. The 27-year-old singer's latest album has topped the charts for the second week in a row according to Billboard. According to the ... Taylor Swift's 'Reputation' Is No. 1 Again, but Will It Maintain Its Momentum? - New York Times Chart Watch: Ta...

The GOP popularity contest

Presented by New Jersey Coalition of Automotive Retailers: Matt Friedman's must-read briefing on the Garden State's important news of the day Mar 06, 2025 View in browser   By Matt Friedman Presented by  ...

3 new tricks that will fool you... even when you know the secret.

Watch full performances of each trick here, and get fooled 3 times! ! (there are 3 separate videos) https://www.penguinmagic.com/p/16584 "Strong, really fooling ... there is no way it can be reconstructed." - Nique Tan I love these 3 tricks so much. 1. They're virtually impossible to figure out! They're so hard to figure out in fact, that even when you know the secret it's fun to perform, because it feels magical. 2. No sleight of hand . These tricks are super easy to perform. You can comb...

New today: The #1 best selling mind-reading wallet of the year

"This is the best mentalism device I've seen in many years! Bar none." - Steven Palmer TL;DR:  Our most requested upgrade from pros. The best selling mind-reading wallet is now available for the first time in genuine leather for only $59.95 .  It's also available in a new color, midnight blue for only $39.95 We only have 150 genuine leather Razor Wallets, so they'll go fast. No more will arrive before Christmas. Genuine Leather Razor Wallet (only 150 available) https://www.penguinmagic.com/p/16650 ...

"I NEVER would have thought of this!" -Doug Henderson

"Impressive, deceptive and entertaining" - Joe Rindfleisch A straw visually changes from one color to another and your hands are completely empty! Watch it performed here: https://www.penguinmagic.com/p/9085 "I never would have thought of this technique! I had no idea straws had these properties! Very simple gimmick to make. No crafting skills required." - Doug Henderson This brand new trick uses a prop you find at your local fast food joint, and is PURE eye candy. Just when you think you know wh...

Market Outlook 🚀 - Markets on Pace for Worst Month Since March 2020

Wages increase 1% in Q4 2021 Inside.com Part of   Network January 31, 2022 Presented by US Markets Stock Market futures are down slightly  on the last trading day of January, which is on track to be the worst month for U.S. equities since March 2020.  The S&P 500 is down 7% in January and down 8% from its highest point this month.  The Nasdaq is down 12% this month and 15% from its November high.  The current 10 Year U.S. Treasury yield is set at 1.79400% Dow Jones  34,725.47 1.65% S&P 500  4,431.85 2.43% Nasdaq  13,770.57 3.13% Russell 2000 1,968.51 1.93% *Stock Market data as of the last closing bell. Data received directly from the references indexes through ICE Data Services. Do you not understand any of these figures? Check out our explainer.   ...

Ludo, you have 2 new friends

    A lot has happened on Facebook since you last logged in. Here are some notifications you've missed from your friends.       Ludo Maallam             2 new friends               You have new notifications.             A lot has happened on Facebook since you last logged in. Here are some notifications you've missed from your friends.       Ludo Maallam             2 new friends               Go to Facebook     View Notifications             This message was sent to ludomallam@idiot.cloudns.cc . If you don't want to receive these emails from Facebook in the future, please unsubscribe . Facebook, Inc., Attention: Community Support, 1 Facebook Way, Menlo Park, CA 94025         To help k...

📷 Naveed Hussain shared Vijy Kumar's photo

  Ludo, see the post that he shared.           Facebook                 📷 Naveed Hussain shared Vijy Kumar 's photo. 4 June at 21:05   View               This message was sent to ludomallam@idiot.cloudns.cc . If you don't want to receive these emails from Facebook in the future, please unsubscribe . Facebook, Inc., Attention: Community Support, 1 Facebook Way, Menlo Park, CA 94025         To help keep your account secure, please don't forward this email. Learn more.