Archive for White House

WH Proposes Budget Seeking To Boost Cybersecurity

Posted in Commentary with tags on March 13, 2024 by itnerd

On Monday, the White House’s proposed a budget for fiscal year 2025 calling for $13 billion of the $1.67 trillion discretionary spending to go to cybersecurity funding for civilian agencies, including additional investments to the DOJ, Homeland Security and Health and Human Services to bolster digital defenses.

The White House’s proposal seeks $3 billion for CISA, which is a $103 million increase from the 2023 enacted budget. The funding would include:

  • $470 million to deploy network tools like endpoint detection and response capabilities for federal assets
  • $394 million for its internal cybersecurity and analytical efforts
  • $116 million to oversee the implementation of the Cyber Incident Reporting for Critical Infrastructure Act of 2022
  • $41 million for “critical infrastructure security coordination”  

Also notable is the proposed funding for healthcare cybersecurity efforts:

  • $800 million to help “high need, low-resourced hospitals” cover the initial costs of implementing basic cybersecurity practices 
  • $500 million incentive program for more robust digital defenses
  • $141 million for HHS’s own security, including $11 million to better protect health information

The budget also includes a handful of other proposals aimed at improving cybersecurity including:

  • The National Highway Traffic Safety Administration’s Office of Automation Safety to “address vehicle cyber security risks,” as well as AI risks
  • The Department of Energy would receive $455 million “to extend the frontiers of AI”, in addition to its cybersecurity efforts
  • Military cybersecurity spending would be $7.4 billion, with another $6.4 billion for activities such as cyberspace operations and $630 million for R&D
  • The Department of Defense total would be $14.5 billion which is an increase from $13.5 billion since last year

The budget would also add additional funding to address workforce challenges via minority-serving institutions.

The next immediate deadline for government spending is March 22, when the continuing resolution funding DHS, DOD and other agencies expire. 

Emily Phelps, VP, Cyware had this to say:

   “The White House’s emphasis on cybersecurity in the 2025 budget reflects a strong commitment to national and economic security. This significant investment reinforces the importance of collaborative efforts between public and private sectors to combat sophisticated and persistent cyber threats. By focusing on key areas such as healthcare cybersecurity and leveraging advancements in AI and military defenses, the budget aims to fortify the resilience of our critical infrastructure, economy, and the protection of citizens and industries against the concerted efforts of threat actors.”

This is a good move by The White House to keep cyber assets safe. Hopefully this is a budget that can get through The House and Senate as this is something that the nation needs.

The White House Makes An Announcement On How They’re Going To Promote Responsible AI Development

Posted in Commentary with tags , on May 4, 2023 by itnerd

The White House today has announced what they are going to do to promote responsible AI innovations. This is timely as this is a top of mind issue at the moment. Here’s what the goal is:

AI is one of the most powerful technologies of our time, but in order to seize the opportunities it presents, we must first mitigate its risks. President Biden has been clear that when it comes to AI, we must place people and communities at the center by supporting responsible innovation that serves the public good, while protecting our society, security, and economy. Importantly, this means that companies have a fundamental responsibility to make sure their products are safe before they are deployed or made public.

There’s a lot more to this and I encourage you to read the full details at the link above.

I have two comments on this. Starting with Ani Chaudhuri, CEO, Dasera 

In light of the recent announcement made by the Biden-Harris Administration, it is evident that the US government has taken some essential steps to promote responsible AI innovation while protecting Americans’ rights and safety. While these actions are commendable, it is crucial to emphasize that data security plays a vital role in ensuring AI’s responsible and ethical use.

As the Administration engages with CEOs of leading AI companies, it is essential to remember that responsible and ethical AI development requires robust security measures. Data security companies play a significant part in this landscape, working diligently to protect sensitive information and mitigate risks associated with AI technologies.

The new investments in AI research and development, public assessments of generative AI systems, and policies to ensure responsible AI use by the US government are all necessary steps to create a safer AI ecosystem. However, investing in data security infrastructure and prioritizing collaboration with data security companies is vital. In doing so, the government and AI industry can ensure comprehensive protection against risks and potential harm to individuals and society.

Furthermore, AI developers must be held accountable for the security of their products, emphasizing their responsibility to make their technology safe before deployment or public use. This includes proper data management, secure storage, and measures to prevent unauthorized access to sensitive information.

The Biden-Harris Administration’s actions to promote responsible AI innovation are crucial for a safer future. However, it is equally important to acknowledge the role of data security companies in this landscape and foster partnerships to ensure a comprehensive and cohesive approach to AI-related risks and opportunities.

This is followed up by a comment from Craig Burland, CISO, Inversion6:

There’s no putting the AI genie back in the bottle. Two years ago, if your product didn’t have AI it was considered last-generation.  From SIEM to EDR, products had to have AI / ML.  Now, ChatGPT is evoking fears pulled from science fiction movies.  

Generative AI (GAI) is an evolution of technology that started when we jumped into Big Data. GAI has tremendous potential and troubling downsides. But, the government will be hard-pressed to curtail building new models, slow expanding capabilities, or ban addressing new use cases. These models could proliferate anywhere on the globe.  Clever humans will find new ways to use this tool – for good and bad.  Any regulation will largely be ceremonial and practically unenforceable.  

I think that this is a good initiative by the White House. But as always, I await meaningful results as I feel that we’re currently at a tipping point in terms of where we are with AI. Which in my mind implies that things can go in a great direction, or things could go off the rails when it comes to AI. And in either case, there would be no way back.

White House OMB Announces “Zero Trust” Strategy

Posted in Commentary with tags , on January 26, 2022 by itnerd

That White House’s Office of Management and Budget (OMB) has released a Federal strategy today to move the U.S. Government toward a “zero trust” approach to cybersecurity. This report has more digestible details. But here’s the key point:

The U.S will adopt a “zero trust” approach, meaning the federal government will assume no actor, system, network, or service operating outside or within the security is trusted, according to a memo from the acting director of the Office of Management and Budget, Shalanda Young.

In a statement, the White House said that the “growing threat of sophisticated cyber attacks has underscored that the Federal Government can no longer depend on conventional perimeter-based defenses to protect critical systems and data.”

Anurag Gurtu, CPO, StrikeReady had this to say:

“As part of any digital transformation, Zero Trust networks should be a key initiative that focuses on securing resources (data, identities, and services), rather than securing physical networks.

By focusing on tailored controls around sensitive data stores, applications, systems, and networks, the Zero Trust model shifts the focus away from varying types of authentication and access controls.

The Zero Trust initiative should be supported by other key initiatives such as modernizing the security operations as well as uniting and empowering cyberdefenders. Without one of these, an organization’s security will be shaky at best.”

I like the fact that The White House is putting their influence behind this. That will hopefully encourage companies to do the same thing.

UPDATE: I have additional commentary from Lucas Budman, CEO, TruU:

“Securing only endpoints, firewalls, and networks provide little protection against identity and credential-based threats. Users should be authenticated continuously, from the time they try to login to the moment they log out. Until organizations start implementing identity-centric security measures, account compromise attacks will continue to provide a perfect camouflage for data breaches. The initial step in any successful Zero Trust strategy should focus on granting access by verifying the person requesting access, understanding the context of the request, and determining the risk of the access environment. This never trust, always verify, enforce least privilege approach provides the greatest security for organizations.

It’s also important in a Zero Trust construct to recognize that devices that access data (laptops, desktops, mobile devices) have identities, as well. You have to understand the device’s posture when accessing the network in order to provide proper device level authentication and authorization. If the user only has access to non-sensitive or public information, the enterprise may not care that their device might have malware; however, if the user is trying to access sensitive financial or customer data, access should only be given to those devices that are managed, trusted and protected. In any case, simultaneous device risk data and identity authentication allow customers to implement policies that respond to potential threats as they happen by stepping up identity verification on compromised endpoints and limiting access to high-value assets associated with those endpoints.”