Archive for White House

White House & Texas Government launch Texas pilot to find and fix cyber weaknesses in water systems

Posted in Commentary with tags on September 1, 2026 by itnerd

The White House along with the Texas Government has launched Project Watershed 250, a six-month cybersecurity pilot that will provide Texas water and wastewater utilities with private-sector cybersecurity and AI resources at no cost.

The program will use red teaming to test utilities’ existing defenses, identify vulnerabilities and harden systems, with a particular focus on smaller and rural water providers that often lack dedicated cybersecurity resources.

The initiative will be overseen by the Office of the National Cyber Director and Texas Cyber Command, with companies including Microsoft, Google Cloud, AWS, Cloudflare, Palo Alto Networks, Fortinet, Forescout and Dragos contributing technology and expertise.

The pilot follows a wave of attacks against U.S. water infrastructure, including a recent campaign affecting 30 water systems across 12 states. Officials said the goal is to determine which defenses are effective during the six-month test and then scale successful approaches to water and wastewater systems across the country.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

   “You can’t harden what you don’t know is connected. Incomplete asset inventories are one of the most common findings I see across engagements, and critical infrastructure environments have some of the worst visibility gaps. Forescout, one of Watershed 250’s twelve participating vendors, recently found 4,400 internet-exposed Rockwell and Allen-Bradley controllers. Twenty-two sit in cities already hit by the recent water attacks, and 19 of those run firmware vulnerable to a flaw Rockwell patched many years ago.

   “Twelve companies are contributing technology and expertise at no cost, but bringing more tools into environments that lack staff to configure and maintain them just grows the unmanaged attack surface. A firewall with default rules or a monitoring console nobody watches becomes another blind spot in an inventory that was already incomplete. These utilities need governance and dedicated security personnel before they need enterprise-grade technology.

   “Month seven is the real test. Iranian campaigns against U.S. water systems and FBI-documented Chinese access to critical infrastructure are persistent threats, not six-month engagements. Replacing an exposed Programmable Logic Controller (PLC) might mean swapping a 15-year-old controller that was never designed to be networked, and the utility that can’t fund a dedicated security hire can’t fund that replacement either. If “scale what works” is the exit plan, it needs to include who pays for ongoing staffing and governance after the pilot ends.”

Damon Small, Board of Directors, Xcape, Inc.:

   “Federal support for critical infrastructure represents a welcome partnership between the public and private sectors, offering underfunded municipal utilities a no-cost opportunity to reduce operational technology risk. While Project Watershed 250 establishes an important first step, utility executives must question who benefits most over time: whether this effort drives long-term resilience or simply lines vendor pockets with short-lived service agreements. Temporary tool donations and red teaming cannot fix legacy hardware and deficient network architecture design without sustained capital investment. The broader challenge remains defending the entirety of the nation’s critical infrastructure beyond rural water systems.

   “To turn this initial momentum into permanent defense, security leaders must isolate control networks from the public Internet, enforce multi-factor authentication on remote access gateways, and baseline legacy environments before deploying complex artificial intelligence tools.

   “Critical Takeaways

  • Federal support and private-sector partnerships provide essential temporary coverage, but pilot programs cannot substitute for long-term capital investments in legacy hardware.
  • Utility executives must evaluate whether vendor-backed initiatives drive systemic resilience or merely create vendor lock-in.
  • Immediate operational technology defense requires foundational controls, including network isolation from the public Internet and enforced multi-factor authentication, before layering on advanced tools.

   “Upgrading national security requires durable capital allocation, not just a six-month software trial with big-tech name drops.”

Hopefully this isn’t just a one time investment because quite honestly, that’s not what the US needs. Now more than ever.

White House order targets foreign-made equipment and software in U.S. power grid 

Posted in Commentary with tags on August 27, 2026 by itnerd

Yesterday, the President Of The United States signed an executive order declaring a national emergency to secure the U.S. bulk-power system, citing cybersecurity and operational risks associated with foreign-produced energy equipment.

The order can prohibit the acquisition, importation, transfer or installation of foreign-made bulk-power equipment, including associated software and digital capabilities, when it is determined to pose a significant national security risk.

The order specifically warns that foreign-made equipment could contain vulnerabilities or digital backdoors capable of providing remote access to U.S. energy infrastructure.

The restrictions could affect equipment such as power transformers and components used in solar infrastructure. China currently accounts for 85% of global solar supply-chain production capacity.

The Department of Energy has 120 days to develop rules implementing the order in coordination with other federal agencies.

Doc McConnell, Head of Policy and Compliance, Finite State:

   “On August 26, the President declared a national emergency over foreign-made equipment in the United States electric grid. Executive Order 14420 is the latest in a series of supply chain actions from this administration, and it includes a now-familiar assumption: equipment manufactured in a foreign country poses a national security risk.

   “The order points to two reasons. First, where equipment incorporates software, firmware, or other digital components, an adversary could build in remote access for surveillance or sabotage. Second, an adversary could cut off the supply of critical equipment at a moment of its own choosing, and do real damage that way.

   “Supply chain risk is real, and it is appropriate for the federal government to act on it. But for software and firmware, I don’t agree that foreign development is inherently risky, or that requiring development to happen within our borders keeps us safe.

   “A better way to secure our critical infrastructure is to test the equipment we install. For example, analyzing the compiled firmware binary of bulk-power system equipment can identify vulnerabilities, surface insecure configurations, and allow us to mitigate specific risks to better secure our energy infrastructure, regardless of where that equipment was manufactured.

   “The Department of Energy has 120 days to write the implementing rule. I hope that we see an evidence-based approach to evaluating the security of the equipment in our energy grid.”

John Strand, Owner, Black Hills Information Security, Inc.:

   “This has been a concern for a large number of people in the computer security industry for a very, very, very long time. If you go back to concerns raised around Super Micro Computer Incorporated, the bigger issue has always been the same. Where are the components that make up our critical infrastructure actually coming from, and how much do we really know about that supply chain?

   “It’s nice to finally see this being acknowledged at a serious level. But acknowledgment is the easy part.

   “The details of how this gets implemented are going to be much more interesting. This isn’t a situation where we can simply decide we don’t trust a supplier and buy the equipment somewhere else. China dominates the production of many of the components and materials that modern technology and critical infrastructure depend on. In some areas, there simply aren’t enough alternative suppliers to make an immediate transition realistic.

   “So yes, I’m glad this is being looked at. It should have been looked at much more seriously years ago. But the real question isn’t whether we recognize the supply chain risk. We do.

   “The question is how we actually reduce that risk when much of the supply chain we’re worried about is also the supply chain we currently depend on.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

   “The cybersecurity issue here isn’t limited to finding a secret backdoor soldered into a foreign-made transformer. A legitimate vendor update mechanism or remote maintenance service becomes a national-security dependency when the infrastructure behind it is controlled by an entity the U.S. considers adversarial. Modern grid equipment increasingly relies on vendor-maintained update channels, remote diagnostics, firmware management, and other lifecycle services. That control-plane dependency is the threat surface this order actually reaches.

   “The order’s definitions acknowledge this more clearly than its preamble. Section 2(a) expressly covers software, firmware, digital services, maintenance services, and remote-access capabilities. Section 5(b) separately tells agencies to consider “remote access capabilities, lifecycle maintenance and update mechanisms, and other supply chain dependencies.” That operative language goes well beyond hypothetical malicious implants.

   “Section 2(b) creates the harder enforcement challenge, authorizing DOE to order identification, isolation, monitoring, disconnection, or replacement of foreign equipment already installed. This is rip-and-replace authority dressed in “phased compliance” language. Traditional asset inventories may tell a utility who manufactured a device, but not who controls its firmware, update infrastructure, remote maintenance services, or other lifecycle dependencies. The 2020 version of this policy ran into the same implementation problem, with some utilities struggling to determine what equipment fell within scope.

   “The 120-day rulemaking window will determine whether this becomes enforceable policy or another unfunded mandate. If DOE applies the “Covered Foreign Entity” definition narrowly and provides a realistic pre-qualification pathway, utilities can plan around it. If the rules function as a blanket ban without realistic transition guidance, the order risks creating the same grid-reliability problem it is intended to prevent. You can’t rip out a 345kV transformer on a regulatory deadline when a compliant replacement may have a multi-year lead time.”


Donald McFarlane, Advisory Board Member, 
Xcape, Inc.

   “EO14420 is a balanced executive order.  It recognizes that supply-chain provenance is a legitimate national security issue without treating every piece of foreign-made equipment as inherently compromised.  DOE has to identify a connection to a covered foreign entity and make a risk determination, and the order expressly requires consideration of reliability, replacement availability and continuity of service before existing equipment is disconnected or removed.

   “The cyber concern goes well beyond transformers. The order specifically reaches inverters, battery-storage systems, protective relays, PLCs, intelligent electronic devices, software, firmware, maintenance services and remote-access capabilities. The electric grid is increasingly a distributed network of computers, and that is before considering the possibility of undocumented or deliberately concealed capabilities and covert communications channels. Whenever equipment can receive an update or a remote command, who built it, who maintains it and who ultimately retains access to it are important security questions.

   “One interesting feature is what the order leaves out. It reaches transmission down to 69 kV but specifically excludes local distribution. I would not interpret that to mean distribution is safe or unimportant. It looks more like deliberate risk prioritization: generation and transmission are where a successful attack is most likely to create cascading, nationally significant consequences, while distribution is vastly larger, more heterogeneous, subject to different regulatory authorities and potentially much harder to remediate given existing supply-chain dependencies. The exclusion of distribution shouldn’t be read to mean distribution is secure. It means the government is starting with the part of the grid where compromise can most readily become a national event.

   “But that boundary is becoming less comfortable as distributed energy resources proliferate. One compromised residential inverter is not a threat to the grid; coordinated control of thousands or tens of thousands of installations and their inverters, batteries, EV chargers or other distributed resources is a very different proposition. A large fleet of individually modest devices can become a systemically important grid asset if an adversary can command them together. That is why the security of aggregated distributed resources increasingly has to be considered alongside the traditional generation-and-transmission security perimeter.

   “So, I view this EO as an important first step rather than a complete solution.  Cheap infrastructure isn’t cheap if a foreign adversary may retain a control path into it.  The test should be straightforward: do we know what the equipment contains, what and how it communicates with, and who can update or remotely control it?  The next challenge is making sure we eventually apply that same security thinking below the traditional bulk-power boundary, without imposing requirements that utilities and domestic supply chains simply cannot meet.

   “Engineers deliberately build margin into systems, for safety, for growth, and for resilience. In too many parts of the country, rapid load growth and constrained generation and transmission growth are consuming that headroom.  Sophisticated controls and grid-enhancing technologies can help us extract more capacity from existing infrastructure, but they are no substitute for building sufficient physical generation and transmission.  Cybersecurity, supply-chain security and adequate capacity are all parts of the same operational resilience problem.  The United States needs this EO, and it needs substantially more investment in generation and transmission.  It is very encouraging to see this administration treating those issues with the seriousness they deserve.”

Critical Infrastructure needs to be protected. The power system is critical infrastructure and hopefully organizations of all sizes pay attention to this and take whatever action is required to make themselves secure.

How Does the White House Privatizing US Cybersecurity Help It Defend Against AI-Driven Attacks?

Posted in Commentary with tags on August 13, 2026 by itnerd

The White House has a new memo on involving private cybersecurity companies in US defense against AI-driven hacks, vishing, and other attacks:

Transnational Criminal Organizations (TCOs) pose a growing threat to American citizens, businesses, and national security. These organizations conduct sustained cyber campaigns to perpetrate frauds that undermine American prosperity, security, and freedom. Through Executive Order 14390 of March 6, 2026 (Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens), I directed the Federal Government to take various actions to combat cyber‑enabled crime harming American citizens. This memorandum expands the fight against TCO-perpetrated cybercrime by incorporating the ingenuity of the private sector.

Chris Nyhuis, CEO of Vigilant, released the following comments that all organizations should follow:

It’s the right move. But it quietly changes the role of private cybersecurity companies in American national security. The biggest question isn’t whether America has the technical capability to fight back. It’s whether we establish the doctrine necessary to do it without making a cyber incident worse.

I support this. America has extraordinary cyber capability sitting in the private sector, and we should be putting some of that capability into the fight. But offensive capability without disciplined rules creates its own risk. Before America acts, we need to prove who we’re dealing with, contain the original intrusion, understand the escalation risk, and then decide what action actually accomplishes the mission.

The forthcoming federal operating rules need to establish a simple doctrine:

PROVE > CONTAIN > DECONFLICT > ACT > PROTECT

1. PROVE: “EVERYBODY WANTS TO KICK THE DOOR DOWN. SOMEBODY STILL HAS TO PROVE IT’S THE RIGHT DOOR.”

Cyber attribution has always been difficult. But the consequences of getting attribution wrong are about to become significantly greater.

Cybersecurity companies use terms like ‘high confidence’ all the time. That’s one thing when the result is a threat-intelligence report. It’s something entirely different when that assessment becomes the basis for an operation against somebody else’s infrastructure.”

Attackers also understand how attribution works and can attempt to manipulate the evidence defenders rely upon. Infrastructure can be shared or compromised. Tools can be copied. Malware can be planted. Indicators can be manufactured. That creates a potentially dangerous scenario:

“Imagine you’re a foreign adversary and you can make America believe your enemy attacked us. If our attribution process isn’t strong enough, you don’t have to attack your enemy yourself. You try to manipulate us into doing it for you.”

Nyhuis believes the program should therefore establish one forensic attribution standard for every participating company.

“One company’s telemetry cannot become America’s definition of truth.”

Attribution should be independently corroborated and then subjected to an adversarial review in which another team actively attempts to prove the attribution wrong.

Before you ask, ‘Why do we believe it’s them?’ put somebody in the room whose job is to prove that it isn’t.”

2. CONTAIN: “NEVER OPEN A SECOND FRONT WHILE THE ATTACKER IS STILL INSIDE YOUR PERIMETER.”

Correct attribution isn’t enough. Before an offensive operation begins, Nyhuis believes there is another question that has to be answered: Have we actually contained the original intrusion?

Removing malware, restoring a compromised server or blocking the attacker’s known access does not necessarily mean the attacker is gone. The adversary may still possess valid credentials, persistence mechanisms, undiscovered access paths or other footholds inside the victim’s environment.

“Before you start talking about going after somebody, you’d better know whether you’ve actually contained the original intrusion.”

Launching an offensive operation before containment has been established could turn one cyber incident into a two-front fight.

“Never open a second front while the attacker is still inside your perimeter.”

If the attacker retains access when their infrastructure is disrupted, they may already possess everything necessary to retaliate from inside the victim’s environment.

“Think about the position you’ve just created. You’re attacking outward while the adversary may still be operating inward. They don’t have to break back into your network to retaliate — they may already be there.”

The attacker could destroy evidence, steal additional information, establish new persistence, disrupt operations, or deploy destructive malware using access they already possess. That is why containment status and retaliation risk should be part of the government’s operational approval process.

Offensive cyber doesn’t make incident response less important. It makes disciplined incident response more important.”

Containment also does not necessarily mean immediate eradication. There may be legitimate investigative or intelligence reasons to knowingly maintain visibility into an adversary. The critical distinction is whether continued adversary access is known and intentional or simply undiscovered.

“You can make a deliberate decision to observe an attacker who’s still inside. That’s very different from launching an offensive operation because everybody incorrectly assumed the attacker was gone.”

3. DECONFLICT: “THE TECHNICALLY CORRECT ACTION CAN STILL BE THE OPERATIONALLY WRONG ACTION.”

A cyber target rarely exists in isolation. The same infrastructure could be part of a corporate incident response, federal criminal investigation, intelligence operation, foreign-partner investigation or an active case involving victims.

Before private operators act, they need to know who else may already be operating in that environment, and what could be damaged by taking action.

Cyberspace doesn’t put up a sign telling you that somebody else is already working the case.”

Nyhuis believes government deconfliction should therefore be a mandatory gate before offensive action. That becomes particularly important when an investigation involves live victims.

“If taking down a server destroys an evidence chain, alerts an offender or puts a victim at greater risk, you’ve won the technical battle and potentially lost the actual mission.”

The question cannot simply be whether an operator can disrupt the target. It has to be whether disrupting the target at that moment advances the larger mission.

“The technically correct action can still be the operationally wrong action.”

4. ACT: “OFFENSE NEEDS AN OBJECTIVE, NOT JUST A TARGET.”

Once attribution, containment, and deconfliction have been established, there is still one more question before action: What exactly are we trying to accomplish? Surveillance, intelligence collection, disruption, denial, degradation and destruction can produce very different consequences.

“The objective can’t simply be, ‘We found the bad guy, now hit him.’ What outcome are we trying to create? What happens when they respond? And what does success actually look like?”

An operation designed to collect intelligence should be evaluated differently from one intended to disrupt infrastructure. An operation intended to temporarily deny capability is different from one intended to permanently destroy it. And every action creates the possibility of a reaction.

Nyhuis believes escalation therefore needs to be evaluated as part of the operational decision—not after the operation has already begun.

“America absolutely needs the capability to go after foreign cybercriminals. But capability needs doctrine. Prove who did it. Contain the original intrusion. Understand the escalation risk. Then decide whether and how to act.”

Offensive cyber capability is ultimately a tool. The mission should determine how—and whether—that tool is used.

5. PROTECT: “IF AMERICA AUTHORIZES PRIVATE CITIZENS TO ENTER THE FIGHT, WHAT HAPPENS WHEN THE FIGHT FOLLOWS THEM HOME?”

There is another side of this program that Nyhuis believes cannot be an afterthought: Who protects the private-sector people conducting these operations? The individuals carrying out authorized operations may be private-sector cybersecurity professionals—not military personnel, federal law-enforcement officers, or diplomats.

That distinction matters.

If the United States authorizes a private cybersecurity professional to disrupt a foreign criminal organization on America’s behalf, we need to think seriously about what happens to that person afterward.”

The United States may view the individual as an authorized participant in a lawful government-directed operation. The organization being targeted may see something much simpler: The person who attacked them. And the risk may not end when the operation does.

“Cyber operations don’t necessarily end when somebody closes the laptop.”

An operator who helps disrupt a sophisticated foreign criminal organization could potentially become a target for retaliation, identification, doxxing, intimidation, or other threats.

International travel raises another set of questions. What happens when that private-sector operator travels overseas months or years later? Could a foreign jurisdiction investigate or seek to detain the operator based on its own laws? What assistance would the United States provide? What happens if the criminal organization identifies the operator or their family?

These are questions the program should answer before the first operation is authorized, not after something goes wrong.

“We shouldn’t discover the government’s responsibility to these people when the first American cyber operator gets detained at a foreign airport or targeted because of an operation our government asked them to conduct.”

Nyhuis believes the framework should explicitly address operator identity protection, operational security, physical-security risk, foreign legal exposure, international travel, threat monitoring, and government assistance if an authorized operator is threatened or detained.

This isn’t an argument against using private-sector operators. It’s an argument for recognizing what America is asking them to do.

“If America asks private citizens to accept personal risk while conducting a U.S.-authorized cyber operation, then America needs to define what protection follows that authorization.”

Because bringing private cybersecurity professionals into national-security operations creates responsibilities in both directions.

We need rules protecting America from a bad operation. But we also need rules protecting the Americans we’re asking to conduct a good one.”

THE DOCTRINE

The framework Nyhuis believes should govern private-sector offensive cyber operations can be reduced to five principles:

  1. PROVE

Do we have forensic evidence that identifies the right adversary?

  1. CONTAIN

Is the original attacker still inside — and what could they do if we escalate?

  1. DECONFLICT

Who else is operating, investigating or potentially at risk if we act?

  1. ACT

What outcome are we trying to achieve, what response should we anticipate, and is offensive action the right tool?

  1. PROTECT

What responsibility does the United States assume for the private citizens it authorizes to conduct these operations?

“America absolutely needs the capability to go after foreign cybercriminals. But capability needs doctrine. Prove who did it. Contain the original intrusion. Understand the escalation risk. Then decide whether and how to act — and protect the Americans we authorize to do it.”

UPDATE: John Strand, Owner, Black Hills Information Security, Inc. had this comment:

   “This article is both exciting and concerning at the exact same time. It genuinely feels like the cyber equivalent of letters of marque, where private industry is authorized to conduct specific, targeted operations on behalf of the United States government.

There are a number of questions that immediately come to mind. How will oversight work? What are the limits of these authorities? Who is responsible for ensuring those limits aren’t exceeded? How does this fit within international law? Those are all critical issues that need to be answered before a program like this reaches full maturity.

   “That said, it’s also important to acknowledge the strategic reality. Our adversaries are already operating this way. We’ve seen multiple reports of China leveraging private cybersecurity companies to conduct offensive cyber operations. Russia has long relied on so-called private hackers who carry out activities that align with government objectives. When our adversaries embrace a model that we refuse to consider, it can leave the United States at a strategic disadvantage.

   “For that reason, I think this is a positive step, particularly for strengthening U.S. offensive cyber capabilities. At the same time, it has to be implemented carefully. Strong oversight and clearly defined legal boundaries are essential if this model is going to be successful.

   “There’s another issue that deserves attention as well. If private security companies are going to participate in these operations, what level of legal protection and indemnification will they receive? Before any company signs a contract to perform offensive cyber activities on behalf of the U.S. government, those questions need clear answers.

   “There’s a lot to unpack here, and I expect the next 60 to 90 days will determine not only how this proposal evolves, but also how the relationship between government and private industry develops in the offensive cyber space.”

Jeremiah Fowler, Researcher for Black Hills Information Security, Inc.:

   “I personally see this as a positive step in combating cybercrime because it recognizes that some of the best technical expertise is outside of the government.

   “The private sector cybersecurity community brings a wide range of skill sets and many have dealt with the aftermath and active defense from these threats on a daily basis. Cybercriminals and state sponsored groups have been attacking US companies and assets for years causing billions of dollars in damages and it’s good to see the gloves come off. Cybercriminals have benefited for years from jurisdictional boundaries and the difficulty of pursuing threat actors operating overseas and this program could be a game changer.

   “Speed important in terms of cybersecurity and the perception is that government processes can be slowed down by bureaucracy. Criminal infrastructure can appear, move, and disappear in hours so a public-private model could help bridge that gap of speed and efficiency. Another benefit is information sharing. Private companies often see pieces of an attack that government agencies may not see, while law enforcement and intelligence agencies possess information unavailable to the private sector.”


Donald McFarlane, Advisory Board Member, Xcape, Inc.:

   “This is not cyber vigilantism. It connects private-sector visibility and capability to lawful federal authority and oversight.

   “This is a significant evolution of the public-private cyber partnership. We’re moving beyond simply sharing threat intelligence to creating a pathway by which threat information acquired through normal business activities, along with threats identified by state and local government, can feed proposed operations for federal approval.

   “Capability is not going to be the scarce resource. Target validation, competing intelligence equities and deconfliction will be. The NCC is going to be busy. The secret’s in the deconfliction.”

Corey Ham, Director of Continuous Pentesting, Black Hills Information Security, Inc.:

   “My primary concern is the security of these contractors. Giving more entities access to sensitive information increases the likelihood that it can be compromised. Most of the information we have on Chinese state-sponsored hacking similar to this is from data leaks and breaches affecting contractors like I-Soon, for example. I worry that both nation states and crime groups will compromise the contractors who are targeting them, and access information they should not be able to access, like forensic data from other targets or classified data.”

The White House Has Lots Of AI Related News For You

Posted in Commentary with tags on August 5, 2026 by itnerd

The White House has finalized its voluntary cybersecurity framework for frontier AI models, giving leading AI developers a process to submit advanced models for government security evaluations before public release. The framework is intended to address the growing cybersecurity risks posed by increasingly capable AI systems (after recent testing incidents involving frontier models).

Zach Wasserman, co-founder, Fleet Device Management (and one of the creators of OSquery) had this to say:

“The White House is focused on whether frontier AI models are safe. Enterprises must consider whether AI can safely operate inside their own environments. A model can perform well in testing but still create risk if it’s connected to production systems without the right controls. Before AI is managing thousands of endpoints, organizations need an operating model where every change is version controlled, auditable and easy to roll back.

The takeaway from the recent OpenAI and Anthropic testing incidents is that autonomous systems need guardrails. We’ve spent years building software development processes around code review, version control and rollback. AI making infrastructure changes should follow the same principles. Infrastructure as code gives AI a safe, structured way to make changes while keeping people in control.

Our recent research found that almost half of organizations are prioritizing AI automation, but fewer than a third are prioritizing infrastructure as code. That’s a problem because AI is only as safe as the systems it’s allowed to change. AI also shortens the time between finding a vulnerability and acting on it, whether that’s patching it or exploiting it. Organizations relying on manual processes simply won’t keep up.”

Also with The White Houre, they have told AI developers it will not include open-weight AI models in its new voluntary cybersecurity testing program, according to Reuters.

The policy was discussed during a White House meeting with representatives from Meta, Google, Nvidia, OpenAI and Anthropic, according to sources familiar with the discussions. Open-weight models, such as Meta’s Llama and Nvidia’s Nemotron, make their core model weights publicly available, unlike closed models from OpenAI and Anthropic.

The voluntary testing program is intended for advanced AI models with sophisticated cyber capabilities and follows recent disclosures that AI systems from OpenAI and Anthropic breached other organizations during controlled security evaluations.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“The US government already knows how to test open-weight models for cyber capability. Before Moonshot released Kimi K3’s weights on July 27, AISI and NIST ran a joint evaluation of its offensive capabilities, measuring exploit development, code execution, and network intrusion performance. That methodology works. The White House chose not to apply it.

“Publicly disclosed incidents that prompted this framework all involved closed-model companies. OpenAI’s models exploited Artifactory vulnerabilities to escape a test environment, then compromised Hugging Face through a separate attack path. Claude models gained unauthorized access to three companies during security evaluations. Under these guidelines, Meta and Nvidia walked out of the August 4 briefing with zero obligations while OpenAI and Anthropic accepted a voluntary pre-release review of up to 30 days.

“Kimi K3 trails US frontier models on cyber tasks today, but in a simulated enterprise attack it completed a full intrusion chain in one of ten attempts, against an intentionally vulnerable network, with initial access provided. China has made open-weight release a strategic priority, and each generation closes ground on the previous one. A framework that categorically exempts open weights has no mechanism to adapt when that gap narrows.”

I would give everything a read because if you use AI related anything, you are affected.

White House cites quantum supply chain as major challenge 

Posted in Commentary with tags on July 30, 2026 by itnerd

A White House official said fragmented and underfunded supply chains remain one of the biggest obstacles to advancing U.S. quantum technologies. 

Speaking during an industry webinar, Brad Blakestad, director of the National Quantum Coordination Office, said quantum computing, sensing and networking each rely on different hardware platforms and components, creating multiple interconnected supply chains that are difficult to secure and scale. 

Blakestad said the quantum industry is nearing broader commercialization but lacks sufficient private-sector funding to build resilient supply chains. He pointed to the Trump administration’s recent quantum executive order, which calls for strengthening domestic quantum supply chains through research, manufacturing and private-sector collaboration, while warning that securing future quantum encryption capabilities remains another key challenge. 

Donald McFarlane, Advisory Board Member, Xcape, Inc. had this comment: 

“The national security implications extend well beyond today’s research pipeline. If a cryptographically relevant quantum computer becomes practical, strategicadvantage won’t come from building the first one: it will come from being able to manufacture, deploy, sustain, and improve them at scale. This is as much about surge capacity as it is about supply chains. 

“The administration’s emphasis on domestic quantum manufacturing reflects that reality. The United States has long excelled at fundamental research, but technological leadership ultimately depends on the ability to translate breakthroughs into resilient domestic production. The relevant question isn’t simply whether we can build a sufficiently capable quantum computer, it’s whether we can rapidly build many of them, along with the cryogenic infrastructure, control electronics, specialized manufacturing, and skilled workforce needed to support them. 

This planning should already be well under way. Building surge capacity for quantum technologies can’t begin after a breakthrough has occurred. The industrial base, manufacturing capability, and supporting infrastructure must be developed in parallel so they are ready when they’re needed, not years later. 

“Leadership in quantum won’t be determined solely by scientific discovery; it will also be determined by who can industrialize, scale production, and sustain operational capability when national security demands it. 

Aaron Colclough, VP of Operations, Suzu Labs adds this comment: 

“Blakestad’s right that this isn’t one supply chain. Computing, sensing, and networking pull different parts, and even within computing the machines are built different ways, with different parts. That means several intertwined bills of materials to secure and scale, not a single national stack. 

 “The June order tries to fix that by mapping the supply chains, cutting manufacturing friction, and incentivizing the buying of parts. But that only works if there’s money and the order doesn’t invent a budget by itself. 

“Encryption is the part most companies can act on now. You don’t need a working quantum computer to start swapping out today’s public-key crypto for NIST’s post-quantum algorithms. Find where you encrypt and sign today, then plan the cutover. Waiting for “Q-day” is how you leave old traffic sitting around for someone to decrypt later.” 

Resilient supply chains are a today problem. Thus every organization needs to treat them as such today.

WH launches AI cybersecurity clearinghouse to coordinate vulnerability disclosures 

Posted in Commentary with tags on July 15, 2026 by itnerd

Tuesday on a call with reporters, the White House said it launched ‘Gold Eagle’, a cybersecurity clearinghouse that brings together leading AI developers and operators of critical infrastructure to share software and infrastructure vulnerabilities identified by advanced AI systems.

The initiative is intended to help organizations coordinate the discovery, validation, and remediation of security flaws before they can be exploited.

The clearinghouse includes AI companies and providers of essential services across sectors such as finance, healthcare, and energy.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“Gold Eagle is directionally right, but it risks optimizing the wrong bottleneck. Every security team I have worked with was already carrying more remediation and hardening work than it had the capacity to complete before AI entered the picture. AI-accelerated discovery can pour more findings into a pipeline that is already backed up.

“A White House official described AI vulnerability discovery as a “step function change” in scale. That should make defenders uneasy. CISA’s Known Exploited Vulnerabilities catalog now contains more than 1,600 entries with mandatory federal remediation deadlines, yet federal audits continue to find exploited vulnerabilities remaining open past those deadlines. Gold Eagle may improve validation, deduplication and prioritization, but coordination does not create the engineers, maintenance windows or vendor resources required to deploy fixes.

“Treasury’s leadership suggests the administration views this primarily as an economic and systemic-risk coordination problem. CISA and the Department of War bring the operational capabilities, but policy coordination and vulnerability remediation move at very different speeds.

“Using Carnegie Mellon’s VINCE platform for intake is a logical choice, given the Software Engineering Institute’s decades of experience with coordinated vulnerability disclosure. The unresolved question is whether the government and participating vendors can remediate findings at anything approaching the rate at which advanced AI systems generate them.

“Gold Eagle should be paired with funded remediation programs, additional support for open-source maintainers and direct technical assistance for critical-infrastructure operators. Otherwise, it creates a faster funnel into the same clogged pipe.”

Seemant Sehgal, Founder & CEO, BreachLock:

“Gold Eagle is a signal that the gap between vulnerability discovery and remediation, which most practitioners have been acutely aware of for a long time, has become too wide to ignore at the national level.

“When AI can surface flaws faster than organizations can act on them, validation is critical. The sectors included here, finance, healthcare, energy, are exactly where adversaries have been patient and deliberate for years. The real measure of this initiative will be whether the remediation side keeps pace with the discovery side. Sharing intelligence is the easier half. Acting on it, consistently and at scale, is where most programs lose ground.”

Donald McFarlane, Advisory Board Member, Xcape, Inc.:

“Public-private partnerships for national cybersecurity, like Gold Eagle, are directionally the right model. Execution will determine whether it becomes transformative or merely another information-sharing program.

“Frontier AI is already changing the scale and speed of vulnerability discovery while accelerating offensive cyber operations. The real challenges are shifting toward coordination, prioritization, elimination of duplicate effort, and maintaining a defensive advantage when adversaries have access to many of the same capabilities.

“Gold Eagle offers a glimpse of how AI will reshape collective defense. The imperative is to move beyond human-speed workflows toward machine-speed, machine-scale detection, analysis, and coordinated response. Defenders cannot expect to compete if AI accelerates the offense while critical defensive processes remain measured in days or weeks.

“To succeed, Gold Eagle must earn the trust of its public and private partners, particularly in critical infrastructure where organizations depend on common hardware, software, and open-source supply chains. Participants need confidence that vulnerability discoveries will be protected appropriately, prioritized reliably, and translated into timely remediation. As AI makes vulnerability discovery increasingly abundant, the limiting factor will be the speed and effectiveness of coordinated response.”

I for one am skeptical of this program. But I am free to be proven wrong in terms of how effective this is.

Biden administration’s drops a cybersecurity executive order on America

Posted in Commentary with tags on January 16, 2025 by itnerd

Today, President Biden laid out an executive order that proposes to strengthen and promote Innovation in the nation’s cybersecurity efforts. This builds on previous executive orders and I encourage you to give this one a read.

Dr. Marc Manzano, general manager for cybersecurity at SandboxAQ had this comment:

“The Biden administration’s emphasis on requiring software vendors to provide proof of security is a significant step toward strengthening the software supply chain and ensuring greater accountability. This focus on security aligns with the critical need for improved compliance, auditing, observability, and agility in managing modern cybersecurity challenges. With this new EO, I am delighted to see additional efforts to push the current status quo and establish a more regulated framework, as this will ultimately improve IT resilience and safeguard critical systems across industries.”

Roger Grimes, Data-Driven Defense Evangelist at KnowBe4 adds this comment:

“This is a huge, widely varying cybersecurity EO that covers dozens of technologies and initiatives. There is a lot to love in it. Here’s what I like:

  • It focuses on software security (although not firmware, strangely), stating that vendors to the US government must prove they are following secure development practices and secure software chain procedures.
  • It’s going to add how to secure deploy patches and updates to NIST SP 800-53.
  • It promotes strong open-source security practices.
  • It is prioritizing investment in PHISHING-RESISTANT MFA.
  • It is increasing the focus on threat hunting and threat identification, empowering CISA to do more of it.
  • It is creating working groups around supported Endpoint Detection and Response (EDR) products to improve them.
  • It is requiring the encryption of civilian space-related commands.
  • It is creating new policies for cloud vendors in the FedRAMP program.
  • It is increasing the security of Border Gateway Protocol (BGP) and the government’s IP address space (decades overdue).
  • Promotes encrypted DNS.
  • Requires email to be encrypted.
  • Requires end-to-end encryption on email and other messaging apps (this is HUGE!!!).
  • Promotes post-quantum cryptography protections.
  • Sets aggressive 90-, 180-, and 270-day deadlines for each.”

Paul Bischoff, Consumer Privacy Advocate at Comparitech follows with this comment: 

“I suspect the federal government was already vetting the security of its software in this way to some extent, but this executive order codifies the process and makes the results of that vetting available to everyone. Many of Biden’s efforts to strengthen cybersecurity have been about improving threat intelligence and transparency, and this EO is in line with those efforts.”

Chris Hauk, Consumer Privacy Champion at Pixel Privacy concludes with this:

“I am particularly happy to see that cloud providers will be required to publish information to clients on how to operate securely. Too many data breaches have been due to misconfigured data buckets, many times leaving the data stored in those buckets open to anyone with an internet connection and a little bit of knowledge. While it is not certain whether incoming U.S. President Donald Trump’s new administration will uphold the executive order, we can hope that they see the value in this executive order. Software companies should be required to demonstrate the security protections of their software.”

As one of the commenters above said, this is a big deal. My only question is if this will actually get carried out or will it be killed by the incoming Trump administration. Hopefully not.

UPDATE: Christian Geyer, CEO and founder of Actfore adds these comments:

“The US needs to remain at the forefront of AI adoption and innovation because that will significantly strengthen national security. While it’s crucial to recognize the expanding attack surface that AI may bring, we can be optimistic about the incredible potential it holds for enhancing security and efficiency. The main challenge lies in navigating the complexities of government processes, but with the right approach, these challenges can be overcome, ensuring that technology initiatives are both effective and secure. For example, international data transfer laws in the EU are way ahead compared to the US. One thing we need to be cautious about is stepping on the gas too hard to accelerate AI adoption before we have our legislative foundation settled. That could do more harm and be more of a national security threat.

The growing focus on AI integration is a positive sign of progress, but it’s essential to approach this with a clear commitment to cybersecurity and robust legislative protections. With careful planning and due diligence, we can ensure that AI adoption is not only rapid but also responsible, safeguarding against vulnerabilities and data risks for US-based companies and the government. Although the pace of technological advancement may sometimes outstrip current legislation, this presents an opportunity for the US to strengthen its regulatory frameworks and stay ahead of potential threats.

These executive orders signal a forward-thinking, proactive strategy for incorporating AI into national security. The focus must remain on integrating AI securely, with ongoing vigilance and the development of strong safeguards. The long-term success of these initiatives will depend on the ability of future policymakers to adapt swiftly to technological changes and prioritize both implementation and legal protections for the American people and their sensitive data. It will be very interesting to see what the incoming administration does with these executive orders from President Biden.”

UPDATE #2: Saviynt Chief Trust Officer, Jim Routh provided this comment:

“Today’s Executive Order on Cybersecurity provides additive guidance to the previous Executive Order primarily for federal agencies, those that provide product & services to federal agencies, and also includes guidance for the private sector. There is greater emphasis on resilience in cloud computing, which is timely as enterprises in the federal sector and private sector dedicate more resources to the consumption of SaaS and PaaS. Digital identity management is also a dominant theme in the Order with a clear direction toward the maturity of interoperability standards for easier management of digital identities with less dependence on storing credentials. This is more of a 10-year view on the maturity of digital identity standards but important nonetheless. 

“Third-party risk management is another dominant theme in the Order and appropriately so. My blunt assessment is that existing third-party risk management functions are woefully insufficient to meet today’s needs for all types of enterprises. Conventional third-party risk management (TPRM) practices evolved from the creation of an annual cyber security risk assessment originating from a response to a security questionnaire updated annually for high risk vendors. Regulatory requirements and compliance activities promote the continued use of this obsolete framework. 

The right approach for TPRM is to conduct vendor risk assessments daily through the aggregation of data derived from near real time sources/feeds across multiple domains such as:

1.      cyber resilience

2.      financial resilience

3.      geographic/political risk

4.      extreme weather events

5.      supply chain disruption

6.      environmental sustainability

7.      legal liability

Limited resources dedicated to TPRM can and should focus on the highest risk third parties on any particular day based on real data vs. self-attestations produced annually. Managing third-party risk should include the establishment of digital identities for third parties requiring access to cloud and on prem systems essential to perform their function reducing the risk of credentials being harvested and used maliciously. 

Another threat vector covered in the Order is the increased threat of a ransomware attack. Ransomware as a service has increased the probability of extortion through the exfiltration and dissemination of sensitive data. Nation state sponsored threat actors are using this attack vector to fund third-party resources to perform cyber espionage. Sanctions have been used as a tool to combat the spread of ransomware, but the results are mixed. Authoritative regimes continue to proliferate the use of extortion for funding purposes of other cyber-criminal activity.  Enterprises are forced to make extortion payments when existing recovery methods fail to restore core business functions in a timely manner. 

How impactful the Order will be remains to be seen in addition to its shelf life as an Executive Order given the new administration taking over the Executive Branch. The role of CISA will likely evolve as will the security requirements for federal agencies. The private sector will continue to be prodded toward a more effective model of building resilience into the delivery of IT products and services for all enterprises and consumers in addition to federal agencies.” 

UPDATE #3: Jonathan Gill, CEO at Panaseer provided me with this comment:

“It’s great to see such a detailed executive order relating to cybersecurity. This reflects the importance of cybersecurity at the highest levels – it is an issue of national security and should be treated as such. One of the big themes coming out of the order is the need to implement the right controls, and being able to provide evidence. Section two really underscores the need for secure software development. If it is followed through, software publishers will need to open their kimonos to show they have the right controls in place and that these are working effectively. It is also interesting to see in section seven that NIST will be issuing guidance on “minimum cybersecurity practices”, considering common cybersecurity practices and security controls.”

“Moving forward, we can expect to see even greater emphasis not just on encouraging companies to implement controls, but on providing evidence of such. However, many companies will struggle here. IT infrastructures and ecosystems have become incredibly complex. Most large organizations do not even have visibility of what assets they have, let alone the status of their security controls across those assets. This isn’t due to a lack of effort or care from cybersecurity professionals. The challenge lies in the fact that most large organizations rely on 50+ cybersecurity tools to protect their fast-moving IT environments. These tools operate in silos, disconnected from one another and informed by incomplete configuration management databases (CMDB). As we move into an era of ‘trust, but verify’, organizations will be under increasing pressure not only to outline what controls they have, but to demonstrate their effectiveness. Most large organizations already possess the data they need to understand their assets, controls coverage, and controls effectiveness, but it’s scattered and inaccessible. This data must be transformed into actionable, trusted intel, enabling security leaders to identify gaps, enforce accountability, and ensure stakeholders meet agreed-upon standards of controls.”

White House Launches “U.S. Cyber Trust Mark” for Internet Connected Devices 

Posted in Commentary with tags on January 8, 2025 by itnerd

Yesterday, the White House announced the launch of a cybersecurity label for internet-connected devices, known as the U.S. Cyber Trust Mark, completing public notice and input over the last 18 months.

You can get more details here:  https://www.whitehouse.gov/briefing-room/statements-releases/2025/01/07/white-house-launches-u-s-cyber-trust-mark-providing-american-consumers-an-easy-label-to-see-if-connected-devices-are-cybersecure/

Roger Grimes, data-driven defense evangelist at KnowBe4, commented:

“There are a lot of things to like about this program, especially the focus on IoT cybersecurity basics, such as changing default passwords, patching, data protection, and a software/hardware bill of materials. Allowing consumers to scan a QR code and get information from a decentralized IoT registry is a terrific idea. Those reasons alone are reasons enough for the program. But the devil is in the details and many of the security requirements are really just recommendations, such as the entire program itself (i.e., vendors do not need to participate), are voluntary and only suggestions. I wish many basic cybersecurity defenses such as the customer being forced to change the default password and automatic patching were required to be in the program. It would make the program much more valuable. 

“As another example, vendors participating in the program must tell consumers if they have a hard-coded default password instead of just preventing any vendor from having a hard-coded default password. The way I read the current requirements, a vendor could apply the mark if they simply told the consumer they only patched once a year, never automatically, and that the consumer had to manually remember and go out of their way to look for and apply a patch, if any are ever available. What percentage of consumers are going to do that? It would be far better to automatically patch your product without consumer involvement.

“But now, the way the program is written, a vendor simply disclosing that they purposefully have included very dangerous substandard cybersecurity practices seems still sufficient for using the mark. So, you could have some IoT vendors really going out of their way to make very secure products that require very little attention from the consumer and other IoT vendors not applying the same high cybersecurity practices and getting to use the same mark simply for telling the consumer they use substandard cybersecurity practices, assuming the consumer actually scans the QR code and reads the information. Wouldn’t it be better if the mark actually meant the vendor was using generally accepted safe cybersecurity practices?

“When I see an FCC safety mark on an electrical cord or lamp, I know it’s safe. I don’t have to scan a code and read information to find out if it is actually safe. I wish the Cyber Trust Mark label meant the same thing…that the device was actually safe as designed. I think the problem is that consumers will see the mark and automatically assume the device meets expected cybersecurity standards and maybe it does and maybe it doesn’t.”

This is a good move because consumers need to know that the gear that they buy is safe and secure. Because right now it’s kind of the Wild West out there with gear that might have vulnerabilities that are just waiting to be exploited. Which is not a good situation for anyone.

UPDATE: Andrew Obadiaru, CISO, Cobalt:

     “The FCC’s launch of the US Cyber Trust Mark is a crucial step toward improving IoT security. In our work testing IoT devices and embedded systems, we frequently uncover hardcoded credentials, exposed debug ports, and misconfigurations – vulnerabilities that give attackers easy access to networks. Once inside, adversaries can move laterally, disrupt operations, steal sensitive data, or launch ransomware attacks.

We recommend manufacturers prioritize regular penetration testing and firmware reviews to catch and fix these issues early. Addressing vulnerabilities before products reach the market reduces the risk of exploitation, safeguarding both consumers and enterprises while strengthening overall trust in connected devices.”

The White House Announces New Rules For The Use Of AI In Federal Agencies

Posted in Commentary with tags on March 29, 2024 by itnerd

The White House has announced new AI rules, stating U.S. federal agencies must show that their AI tools aren’t harming the public, or stop using them:

By December 1, 2024, Federal agencies will be required to implement concrete safeguards when using AI in a way that could impact Americans’ rights or safety. These safeguards include a range of mandatory actions to reliably assess, test, and monitor AI’s impacts on the public, mitigate the risks of algorithmic discrimination, and provide the public with transparency into how the government uses AI. These safeguards apply to a wide range of AI applications from health and education to employment and housing.

For example, by adopting these safeguards, agencies can ensure that:

  • When at the airport, travelers will continue to have the ability to opt out from the use of TSA facial recognition without any delay or losing their place in line.
  • When AI is used in the Federal healthcare system to support critical diagnostics decisions, a human being is overseeing the process to verify the tools’ results and avoids disparities in healthcare access.
  • When AI is used to detect fraud in government services there is human oversight of impactful decisions and affected individuals have the opportunity to seek remedy for AI harms.

If an agency cannot apply these safeguards, the agency must cease using the AI system, unless agency leadership justifies why doing so would increase risks to safety or rights overall or would create an unacceptable impediment to critical agency operations.   

To protect the federal workforce as the government adopts AI, OMB’s policy encourages agencies to consult federal employee unions and adopt the Department of Labor’s forthcoming principles on mitigating AI’s potential harms to employees. The Department is also leading by example, consulting with federal employees and labor unions both in the development of those principles and its own governance and use of AI.

Craig Burland, CISO, Inversion6 had this comment:

The administration continues to demonstrate vigilant leadership in cybersecurity domains, modeling what they want (and maybe expect) to see from the private sector. It’s clear that AI poses both a compelling opportunity and significant threat to how people use and interact with technology. The government’s commitment to human oversight of AI for highly personal and highly impactful decisions is both sensible and prudent given the immaturity of AI. ChatGPT burst into the public consciousness just over a year ago. AIs and LLMs are not ready to make decisions about healthcare or government services. In human terms, these tools are barely toddlers! At the same time, the administration adds friction to AI advancement with requirements about oversight and transparency, and it is lowering barriers for agencies where that friction is no longer warranted like FEMA, the CDC, and the FAA. This demonstration of balance speaks highly of their approach to harness the disrupting of AI without unleashing it on an unsuspecting public. 

A cautious approach to AI is warranted seeing as AI has had a few “misfires” over the years. And the worst thing that can possibly happen is that one of those “misfires” turns into a catastrophic event.

White House And EPA Warn Governors Of Cyberattacks Hitting US Water Systems

Posted in Commentary with tags , on March 21, 2024 by itnerd

On Tuesday, the White House and Environmental Protection Agency warned US governors in a letter that cyberattacks are hitting water and wastewater systems “throughout the United States”, and state governments and water facilities must improve their defenses against the threat.

   “We need your support to ensure that all water systems in your state comprehensively assess their current cybersecurity practices,” said the letter to the governors from EPA Administrator Michael Regan and national security adviser Jake Sullivan.

The US water sector spans 150,000 public water systems and, in many cases, Regan and Sullivan said, “even basic cybersecurity precautions” are not in place at water facilities and “can mean the difference between business as usual and a disruptive cyberattack.”

The EPA also announced it will set up a “task force” to “identify the most significant vulnerabilities of water systems to cyberattacks,” among other pressing issues. White House officials invited state homeland security and environmental officials to a meeting to discuss cybersecurity improvements needed in the water sector.

Emily Phelps, Director, Cyware had this comment:

   “The recent warnings from the White House and the EPA highlight a critical and growing threat to our nation’s infrastructure: cyberattacks targeting water and wastewater systems. This underscores the urgent need for investment in modern security capabilities to safeguard these essential services. The lack of fundamental cybersecurity precautions in many facilities poses a significant risk, potentially turning a minor breach into a major disruption. Ensuring the resilience of our water infrastructure against cyber threats is not just a matter of national security, but also of public health and safety, requiring collaborative efforts at all levels of government and between the public and private sectors.”

Dave Ratner, CEO, HYAS follows with this comment:

   “The impact of a cyber attack on critical infrastructure, such as water systems, could be devastating and even life-impacting.  It’s critical that everyone who provides critical infrastructure and services, not just water and wastewater systems, augment their security stack with resiliency-based approaches, such as Protective DNS, so they can detect in real-time any and all anomalous activity, render it inert before it causes damage, and ensure the safety of their services and the people who rely on them.”

John Gunn, CEO, Token adds this comment:

The biggest risk is the successful attacks on critical infrastructure that we have not yet detected. These are ticking time bombs. Imagine China invades Taiwan and we support our ally, or another scenario that leads to a broader conflict, China could then activate their earlier compromises and potentially cut off water, power, and other critical services for tens of millions of American citizens. 

We’re all in this together. Thus we need to start acting like it or critical infrastructure will simply become the “go to” attack point for threat actors with citizens paying the price.

UPDATE: Mark B. Cooper, President & Founder, PKI Solutions supplied this comment:

 

“The recent communication from the White House and the EPA to US governors underscores the urgent need for cybersecurity in the water sector. With 150,000 public systems at risk and many lacking basic safeguards, the call for access to comprehensive security evaluations is critical. The formation of a task force to pinpoint vulnerabilities, along with planned strategic discussions and the appropriate funding it takes to implement the strategic plans, highlights the concerted effort needed to safeguard this critical infrastructure from cyber threats.

   “Digital Certificates and the Public Key Infrastructure (PKI) that manages the digital certificates play a crucial role in providing advanced encryption methods that secures access and secures data, yet they are frequently underestimated and not managed properly.  Posture Management for the Digital Certificates and the PKI needs to be a core requirement in the cybersecurity plans implemented to protect our water sector.”