Policy & Regulation: Page 10
-
CISA’s top 10 misconfigurations reveal ‘systemic weaknesses’
Common mistakes including poor credential management, weak MFA and lackluster patching continue to harm large enterprises.
By Matt Kapko • Oct. 16, 2023 -
Federal agencies press OT/ICS providers on open-source security
The U.S. is scrutinizing the security of critical infrastructure providers, which are becoming more dependent on connected infrastructure.
By David Jones • Oct. 12, 2023 -
Progress Software’s financial hit from MOVEit cuts deeper
With insurance coverage dwindling, and class-action lawsuits and financial restitution claims piling up, more trouble could be on the way for the software company.
By Matt Kapko • Oct. 11, 2023 -
CISA pivots focus to China-linked threats against critical infrastructure
The agency now considers China the top nation-state threat, after a heavy emphasis on risks related to the Russia-Ukraine war.
By David Jones • Oct. 5, 2023 -
CISA furloughs will cut deep if government shuts down
The agency will have to operate with a skeleton staff, which will reduce assessments and other programs for underserved critical infrastructure sectors and private industry partners.
By David Jones • Sept. 29, 2023 -
Cisco routers abused by China-linked hackers against US, Japan companies
A longstanding group, identified as BlackTech, uses custom malware to evade detection and hack into international subsidiaries of U.S. and Japanese firms.
By David Jones • Sept. 28, 2023 -
CISA rolls dice on public service campaign to raise cyber awareness
The agency is hoping to get families and small businesses to adopt MFA, use stronger passwords and recognize phishing attacks.
By David Jones • Sept. 27, 2023 -
CISA urges use of memory safe code in software development
Unsafe programming languages, like C and C++, account for more than 70% of security vulnerabilities.
By David Jones • Sept. 22, 2023 -
US is making headway on securing cyber infrastructure, commission says
While Cyberspace Solarium Commission leaders praised U.S. cybersecurity improvements, they said more work is needed to secure critical infrastructure.
By David Jones • Sept. 20, 2023 -
FBI director urges private sector to work with the agency on cyber threats
Christopher Wray told attendees at Mandiant’s mWISE 2023 private sector assistance contributed to the success of several recent operations.
By David Jones • Sept. 19, 2023 -
SEC cyber disclosure rules: What’s the role of the CIO?
CIOs are on the front lines of managing the IT estate, making them a critical part of rapid incident response.
By Roberto Torres • Sept. 19, 2023 -
6 stories on how SEC’s cyber rules are changing security response
As enforcement of the rules takes effect later this year, themes around how and when businesses will disclose security incidents will emerge.
By Naomi Eide • Sept. 15, 2023 -
White House, federal cyber leaders pledge renewed support for open source security
CISA released a roadmap for open source software security as industry officials convened to map out additional steps to protect federal agencies and the larger ecosystem.
By David Jones • Sept. 13, 2023 -
MGM Resorts discloses cyber incident in filing with SEC
Moody’s Investors Service called the cyber incident credit negative, and MGM is still taking steps to protect data and fully secure business operations.
By David Jones • Sept. 13, 2023 -
White House mulls rating system to boost cybersecurity for critical infrastructure
Anne Neuberger, deputy national security advisor for cyber, told the Billington Cybersecurity Summit that a new ransomware summit is set and updated a consumer labeling push for IoT.
By David Jones • Sept. 11, 2023 -
CISA director: Critical infrastructure cyber incident reporting rules almost ready
The Cybersecurity and Infrastructure Security Agency is in the final stages of work on the reporting requirements included in a March 2022 law.
By David Jones • Sept. 8, 2023 -
Cybersecurity investments boost profitability, resilience: White House
Expenditures on resilience will help companies reduce downtime, Acting National Cyber Director Kemba Walden said at the Billington Cybersecurity Summit.
By David Jones • Sept. 6, 2023 -
Photo illustration by Danielle Ternes/Cybersecurity Dive; photograph by yucelyilmaz via Getty Images
CISA creates voluntary ed tech pledge to boost K-12 cybersecurity
Companies signing the agreement are urged to commit to encouraging the use of multifactor authentication and public vulnerability disclosure.
By Anna Merod • Sept. 6, 2023 -
SEC cyber disclosure rules put CISO liability under the spotlight
Security executives find themselves in the eye of the needle as governance and incident response come into focus.
By David Jones • Sept. 5, 2023 -
SEC cyber disclosure rules are taking effect: Here’s what to expect
With enforcement on the horizon, much of the SEC's rules for material disclosures are subject to interpretation.
By Naomi Eide • Aug. 31, 2023 -
US leads takedown of Qakbot malware, which automated initial infections
The botnet and malware had infected more than 700,000 computers worldwide and was linked to the abuse of OneNote files.
By David Jones • Aug. 30, 2023 -
Software industry urged to assume risk on open source security
The Open Source Security Foundation called on commercial and non-commercial organizations that use open source software components to adopt better security practices.
By David Jones • Aug. 25, 2023 -
Opinion
Government investigation puts spotlight on password insecurity
A team working for the Department of Interior’s inspector general successfully cracked 1 in 5 active user passwords, a ratio that highlights traps in cybersecurity standards, Mike Kosask from LastPass writes.
By Michael Kosak • Aug. 24, 2023 -
Photo illustration by Danielle Ternes/Cybersecurity Dive; photograph by yucelyilmaz via Getty Images
Cyber authorities have a plan to defend remote monitoring tools
Threat actors can turn one point of attack into many by targeting remote management services that lack security controls.
By Matt Kapko • Aug. 18, 2023 -
SEC cyber rules ignite tension between reputation and security risk
The rules, which take effect Sept. 5, encountered mixed reactions. Some champion board-level cyber accountability. Others say the rules are too big of a lift.
By David Jones • Aug. 15, 2023