#cyberpolicy — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cyberpolicy, aggregated by home.social.
-
📰 Fragmented Federal Rules Divert Resources from Cyber Incident Response
New report warns fragmented US federal cyber reporting rules are diverting resources from incident response. With 117 regulations across 27 agencies, experts call for a streamlined 'report once' model led by CISA. #CyberPolicy #IncidentResponse
-
With the new hack-back memo, the US has shot itself in the foot again. And most of the initial online discussions miss how far the damage reaches. For the US.
Quick summary. On August 12 the President signed a memorandum letting vetted American companies break into foreign systems used by criminal groups and disrupt or destroy them. It is not vigilantism: the companies act under federal direction, and two officials approve every operation in writing.
Americans lost more than $20 billion to this fraud last year, so the motivation is real. I am not against acting. I am against this approach, and I know the arguments because I spent years making them to governments that wanted the same thing.
The debate so far has been about whether private firms should do this, and whether innocent foreigners get hurt. However I analyze it, the first casualty is American:
- Why would anyone share threat intel with Americans, when it could now be used to attack infrastructure in their own country?
- Why would a non-US CISO keep American EDR and XDR agents deep in their stack, when nobody can tell them whether that vendor also runs surveillance and offensive operations for the state?
- Why would anyone outside the US let an American vendor build the map of their weakest cryptography, in the PQC discovery and inventory work their own regulator is forcing them to do?
- Why would a European buyer accept "we cannot comment" as a tender answer?
- Why would an American firm disclose the flaw it just found, when its other contract values that flaw unpatched?
- Why would a sovereign wealth fund hold a listed US security vendor it has no way to assess?
- Why would an allied service share access with a partner whose contractors may be on the same box?
- How does a US prosecutor explain the next indictment of a Chinese contractor hacker?
- What does Washington say when Beijing runs the same program and calls it law enforcement?
Procedures are due October 11 and need not be published. Which means these questions may never get a public answer, and every one of them will get answered by assumption instead. None of those assumptions will favor the American cybersecurity industry.
https://postquantum.com/cyber-kinetic-security/cyber-privateers-what-breaks/
#Cybersecurity #CISO #CyberPolicy #ThreatIntel #NationalSecurity #InfoSec #VendorRisk #PQC
-
Back in 2018 I got to interview the inagural Cybersecurity Ambassador for Australia and this year, in Melbourne, we got to meet and interview Brendan Dowling, Australia’s Ambassador for Cyber Affairs and Critical Technology.
You do not want to miss this conversation, trust me 😬
🎙️✨Australia's Global Opportunity and Responsibility: Shaping a More Secure Region and a Safer Digital World
On Location Coverage with Sean Martin and Marco Ciappelli on ITSPmagazine Podcasts
An Australian Cyber Conference 2024 in Melbourne Conversation with Ambassador Brendan Dowling
Australian Information Security Association (AISA)
At the Australian Cyber Conference Melbourne 2024, On Location with Sean Martin and Marco Ciappelli welcomed Brendan Dowling, Australia’s Ambassador for Cyber Affairs and Critical Technology. In this thought-provoking conversation, Dowling shared his insights on the evolving role of cyber diplomacy, the ethical implications of #AI, and the importance of international collaboration in securing the digital world.
📺 Watch the episode video on YouTube & subscribe to ITSPmagazine Channel here 👇
📻 If you prefer to listen to the audio podcast, enjoy it here 👉 https://on-location-with-sean-martin-and-marco-ciappelli.simplecast.com/episodes/australias-global-opportunity-and-responsibility-shaping-a-more-secure-region-and-a-safer-digital-world-an-australian-cyber-conference-2024-in-melbourne-conversation-with-ambassador-brendan-dowling-on-location-coverage
🖥️ More about our Australian Cyber Conference 2024 Coverage👇
🌟Sponsor of ITSPmagazine's Australian Cyber Conference 2024 Coverage at the time of publishing: ThreatLocker 👉 https://itspm.ag/threatlocker-r974
#AustralianCyberConference2024
#CyeberCon2024
#CyberSecurity
#infosecurity
#infosec #cyberpolicy
#technology #politicalscience #internatinalrelationship #cyber #cyberdiplomacy