Tag Archive for: regulations

Hack prompts new security regulations for US pipelines


WASHINGTON — The federal government will issue cybersecurity regulations in the coming days for U.S. pipeline operators following a ransomware attack that led to fuel shortages across much of the Eastern Seaboard.

The directive will include a requirement that pipeline companies report cyber incidents to the federal government, said the official, speaking on condition of anonymity because the proposal has not yet been publicly released.

It addresses, to an extent, the ransomware attack that led to the shutdown of the pipeline this month, but it also reflects a broader Biden administration focus on cybersecurity after a series of damaging intrusions by overseas hackers.

The Department of Homeland Security declined to confirm any specifics of the pending directive, issuing a statement that said TSA and another component of the agency, the Cybersecurity and Infrastructure Agency, are working with private companies to address cyber threats. “The Biden Administration is taking further action to better secure our nation’s critical infrastructure,” it said.

The directive, first reported by The Washington Post, is expected to prompt concern, if not outright opposition, from private operators wary of increased government regulation.

The American Petroleum Institute, which represents the oil and gas industry, said in a statement that its members are working with the administration to develop reporting policies and that any new regulations should include “reciprocal information sharing and liability protections.”

Mark Montgomery, a senior fellow at the Foundation for the Defense of Democracies and former executive director of the congressionally mandated Cyberspace Solarium Commission, said federal officials have told him the pipeline order will have two stages.

The first will immediately mandate that any cybersecurity incidents are reported to the federal government, while the second, coming later, would require that pipeline companies…

Source…

Twitter hack shows need for cybersecurity regulations, govt. report says


In the eyes of government regulators, critical services and lax cybersecurity don’t mix — especially when those services support the online accounts of former president Barack Obama, former vice president Joe Biden, and current president Donald Trump.



Twitter hack shows need for cybersecurity regulations, govt. report says


© Provided by Mashable
Twitter hack shows need for cybersecurity regulations, govt. report says

The embarrassing and costly Twitter hack this past July served as more than just a wake-up call for the scores of public figures who trusted the social media giant to keep their accounts safe. In a comprehensive report released Tuesday, New York State’s Department of Financial Services argues that the hack proved that, left unregulated, “systemically important institutions” such as Twitter pose a “risk to society.”

The report breaks down, in detail, both how Twitter was hacked and the security lapses which allowed a Florida teenager to (allegedly) mastermind the entire thing. Notably, it doesn’t exactly paint Twitter’s executive team in a favorable light. 

“The problems started at the top: Twitter had not had a chief information security officer (“CISO”) since December 2019, seven months before the Twitter Hack,” reads the report. “A lack of strong leadership and senior-level engagement is a common source of cybersecurity weaknesses.”

According to the report, Twitter’s security “problems” were only exacerbated by the push to remote work necessitated by the coronavirus pandemic. Like many other newly remote workers, Twitter’s employees experienced tech problems working from home. Hackers were able to capitalize on this, tricking at least one Twitter employee into believing the hacker was a member of Twitter’s IT team.

The Twitter hack, notes the report, shows why antitrust regulation is only one part of the regulatory puzzle when it comes to social media companies. Without some form of basic cybersecurity standards, and the power to enforce them, we set ourselves up for more breaches, data leaks, and hacks of prominent figures. If the hackers are after more than just bitcoin, that could spell all kinds of disaster

That argument becomes only more timely as social media continues to serve as a conduit for misinformation

Source…

Data Privacy Regulations: Ensuring Mobile Data Protection in Light of Increasing Regulations

  1. Data Privacy Regulations: Ensuring Mobile Data Protection in Light of Increasing Regulations  Security Intelligence (blog)
  2. Full coverage

mobile security news – read more

Regulations and Threats: Adapting to the Landscape – BankInfoSecurity.com


BankInfoSecurity.com

Regulations and Threats: Adapting to the Landscape
BankInfoSecurity.com
From zeroday exploits to IoT vulnerabilities to the sheer number of prospective adversaries, the threat landscape is ever-shifting. And global regulatory pressures are only mounting. How must security leaders respond? Symantec's Renault Ross offers

and more »

zero day – read more