About this site

Previous work

Projects

   

   

   

   

   

   

   

   

   

   

Strategy for overall remediaton and long term view

Retrieved 2021-06-01

  • The Line in the Sand: How We Respond Today Impacts Our Security Tomorrow (secblvd)
  • Cybersecurity for U.S. critical infrastructure a ‘national (security imperative,’ NSC official says – Urgent Comms)
  • FireEye CEO: 'We are getting sucker (punched in cyberspace')
  • Retrieved 2021-05-26

  • Biden’s Cybersecurity EO: The Wrong Issues (tpost)
  • Retrieved 2021-05-18

  • #RSAC: Anne Neuberger Sets Out Biden Administration’s Plan to Modernize US Cyber-defenses (Infosecurity Magazine)
  • Retrieved 2021-04-22

  • HAFNIUM Exploits Live On (secblvd)
  • Retrieved 2021-04-20

  • House passes legislation to elevate cybersecurity at the State Department (hill)
  • Retrieved 2021-04-19

  • SolarWinds: A Catalyst for Change & a Cry for ...
  • Retrieved 2021-04-16

  • NATO to improve cyber defense in bid to boost alliance resilience
  • Retrieved 2021-04-15

  • SolarWinds Sanctions Far From Last Word On Russian Hacks (Law360)
  • Retrieved 2021-04-13

  • STRATEGIC THREAT INTELLIGENCE: PREPARING FOR THE NEXT “SOLARWINDS” EVENT
  • Retrieved 2021-04-12

  • Biden's cybersecurity dream team takes shape
  • SolarWinds and Microsoft Exchange: Hacks Wrapped in a Cybersecurity Dilemma Inside a Cyberspace Crisis (Georgetown Journal of International Affairs)
  • Retrieved 2021-04-11

  • Biden Seeks to Boost CISA's Budget by $110 Million
  • Fed Chairman Jerome Powell: The 2021 60 Minutes Interview (CBS News)
  • Retrieved 2021-04-09

  • The U.S. Government Needs to Overhaul Cybersecurity. Here’s How. (Lawfare)
  • Biden budget request calls for major investments in cybersecurity, emerging technologies (hill)
  • White House asks for additional $110 million in CISA funding to address cyber threats (CyberScoop)
  • The U.S. Government Needs to Overhaul Cybersecurity. Here’s How. (secblvd)
  • Retrieved 2021-04-08

  • Federal watchdog investigating State Department cybersecurity pr (WENY News)
  • Retrieved 2021-04-02

  • DOE Watchdog Detailed Its Cybersecurity State Amid SolarWinds Hack (Nextgov)
  • Retrieved 2021-04-01

  • SolarWinds Hack Shows Why We Need a National Cyber Director
  • Analysts expect the worst if Biden doesn't turn his focus toward protecting the grid (WCTI)
  • Biden's cyber executive order to include new rules for federal agencies, contractors
  • DHS Secretary Previews Six ‘Sprints’ to Improve Federal Cybersecurity (MeriTalk)
  • The Cybersecurity 202: DHS head seeks to quickly solve some major cybersecurity problems (wapo)
  • DHS Secretary Outlines Biden Administration’s Cybersecurity Vision (Infosecurity Magazine)
  • After hack, officials draw attention to supply chain threats - U.S. (Stripes)
  • After hack, officials draw attention to supply chain threats
  • Retrieved 2021-03-31

  • Atlantic Council: SolarWinds, Microsoft Hacks Reveal ‘Strategic Failure’ (MeriTalk)
  • Zero Trust Security Is Essential for Neutralizing Supply Chain Attacks (TechBullion)
  • U.S. Launches Cyber ‘Sprints’ in the Wake of Nation-State Hacks (Bloomberg)
  • Mayorkas pledges to modernize US cyber-defenses after their failure to detect alleged Russian spies (CyberScoop)
  • Retrieved 2021-03-30

  • SolarWinds Breach Exposed 'Climate Change' Level of Threat to U.S. Cybersecurity: Experts (The Crime Report)
  • Retrieved 2021-03-29

  • NIST Seeks Small Business to Help Develop Cybersecurity Standards (Nextgov)
  • DHS Secretary Outlines 60 (Day Cybersecurity Recovery Plan)
  • Broken trust: Lessons from Sunburst (Atlantic Council)
  • In wake of giant software hacks, defenders & dev teams must fix AppSec
  • Retrieved 2021-03-27

  • Opinion (The United States has a major hole in its cyberdefense. Here’s how to fix it. - The Washington Post)
  • Retrieved 2021-03-26

  • Time for cyber teams, not stovepipes: Telos' CEO tells Wall Street - (Washington Technology)
  • Boards still aren’t taking cybersecurity seriously, warns new NCSC boss. That means everyone is at risk (Bestgamingpro)
  • Retrieved 2021-03-25

  • Senators urge Energy chief to prioritize cybersecurity amid growing threats (hill)
  • Retrieved 2021-03-23

  • ‘Accelerate change or lose’: Applying Gen. Brown’s action orders to cyberspace education and training
  • US Response to SolarWinds Cyber Penetrations: A Good Defense Is the Best Offense (Russia Matters)
  • Retrieved 2021-03-22

  • The cybersecurity problem we should really worry about (hill)
  • Retrieved 2021-03-17

  • Senators press for federal agency accountability over SolarWinds - (FCW)
  • House Energy Committee Requests SolarWinds Update from Agencies
  • Senate Security Leaders Eye FISMA Revamp, SolarWinds Accountability
  • Senator Hassan Presses Top Administration Officials on Strengthening Cybersecurity Across All Levels of Government Following SolarWinds & Microsoft Exchange Breaches (U.S. Senator Maggie Hassan of New Hampshire)
  • Retrieved 2021-03-16

  • White House considers cybersecurity ratings to boost visibility - (GCN)
  • For US cyber defense, helpful hackers are only half the battle (hill)
  • Retrieved 2021-03-11

  • Evolving Cybersecurity Takes More Than Money
  • Why 'Layered Security' Should Be Your New Mantra
  • Retrieved 2021-03-10

  • SolarWinds Unlikely to Be an Isolated Event as Attackers Become More Sophisticated (Infosecurity Magazine)
  • What the Quad Must Learn From the SolarWinds Hack (The National Interest)
  • Retrieved 2021-03-09

  • Understanding Third (Party Hacks, Learning from SolarWinds Hack)
  • Beazley on the implications of the Solar Winds hacking incident (Insurance Business)
  • How the SolarWinds attack may affect your organization's cybersecurity (TechRepublic)
  • New survey examines the impact of SolarWinds breach on cybersecurity | 2021-03-08 (Security Magazine)
  • Was SolarWinds a Different Type of Cyber Espionage? (Lawfare)
  • Why the SolarWinds Hack Is a Wake-Up Call (CoFR)
  • Retrieved 2021-03-08

  • Is it time to adopt an ‘assumed breach’ cyber policy? (BIC Magazine)
  • What to Do About Cybersecurity (Law, Policy -- and IT?)
  • Retrieved 2021-03-05

  • U.S. Weapons Programs Lack 'Key' Cybersecurity Measures (tpost)
  • Retrieved 2021-03-04

  • SolarWinds hack a wake-up call to the tech sector (GZERO Media)
  • Biden makes cybersecurity ‘top priority’ in national security guidance (FRN)
  • Retrieved 2021-03-03

  • Will the SolarWinds hack make us tighten security in the tech industry?
  • Okta CEO: After SolarWinds hack, leaders must think about 4 points
  • How SolarWinds Busted Up Our Assumptions About Code ...
  • Retrieved 2021-03-02

  • Cybersecurity Journalist says SolarWinds Hack is a “Harbinger” of Threats to Come — Fraud Conference News
  • Retrieved 2021-03-01

  • National Security Risks of Late-Stage Capitalism (secblvd)
  • Retrieved 2021-02-28

  • Buy Palo Alto Networks (PANW) On Weakness; Unlocking Value Of Cloud Business (Seeking Alpha)
  • FireEye cyber CEO: American internet users will be targeted in next war
  • Retrieved 2021-02-27

  • Kamala Harris To Prioritize Cybersecurity And Global Health In Foreign Policy Platform (MITechNews)
  • Retrieved 2021-02-26

  • Miller-Meeks says 'SolarWinds' hack a wake up call for all (Radio Iowa)
  • Basic cybersecurity standards must start with procurements, experts say
  • Oversight and Homeland Security Committees Discussed Next Steps for Government and Private Tech Following SolarWinds Breach (House Committee on Homeland Security)
  • Retrieved 2021-02-25

  • Katko Calls on Administration to Fully Leverage CISA Capabilities in SolarWinds Response - Committee on Homeland Security (Republicans)
  • More Money Won’t Prevent the Next SolarWinds - But Better Detection Strategies Will (secblvd)
  • SolarWinds To Spend Up To $25M On Security Following Attack
  • Krebs Lays Out CISA Bite-Back at Health (Sector Hackers – MeriTalk)
  • Our Dire Need for a National Cybersecurity Agency
  • Retrieved 2021-02-24

  • A digital strategy to defend the nation (Microsoft On the Issues)
  • Guest post: Kurt Sanger on “The ‘SolarWinds’ Hack and the Need to Reframe U.S. Cybersecurity Information Sharing” (Lawfire)
  • More Money Won’t Prevent the Next SolarWinds (But Better Detection Strategies Will)
  • Retrieved 2021-02-23

  • Best Practices for Strengthening Your Organization’s Overall Security Posture (Manufacturing Business Technology)
  • After SolarWinds hack, the U.S. must prioritize cybersecurity (Idaho Business Review)
  • Network security relies on careful scrutiny
  • Retrieved 2021-02-22

  • N-able: The Path Forward for the Former SolarWinds MSP (ChannelE2E)
  • SolarWinds CEO talks hack, remaining questions before Capitol Hill hearings
  • Chinese Hackers Hijacked NSA-Linked Hacking Tool: Report (tpost)
  • Mayorkas Announces Initial Plans To Bolster U.S. Cyber Security; SolarWinds CEO Has Ideas Too
  • Retrieved 2021-02-20

  • Neuberger: Private (Sector Partnership ‘Core’ in Fixing Huge Hack, Building Better Defenses – Homeland Security Today)
  • Retrieved 2021-02-19

  • Massive breach fuels calls for US action on cybersecurity (WAVY.com)
  • 5 minutes with Michael Bahar - The aftermath of the SolarWinds Orion breach | 2021-02-19 (Security Magazine)
  • SolarWinds cyberhack is a blow. The US must prioritize cybersecurity now | Columns (idahostatejournal.com)
  • Retrieved 2021-02-18

  • The SolarWinds hackers could be in US government computers for a long time. Here’s our next move (Bulletin of the Atomic Scientists)
  • Occam’s Razor — A SolarWinds Perspective for Law Firms (Legal Talk Network)
  • Digital Offense Capabilities Are Currently Net Negative for the Security Ecosystem
  • Hiding in Plain Sight: What the SolarWinds Attack ...
  • Retrieved 2021-02-17

  • Press Briefing by Press Secretary Jen Psaki and Deputy National Security Advisor for Cyber and Emerging Technology Anne Neuberger, February 17, 2021 (The White House)
  • The U.S. Needs a Cyber State of Distress to Withstand the Next SolarWinds (Lawfare)
  • Retrieved 2021-02-11

  • White House Names SolarWinds Response Leader Amid Criticism (SecurityWeek.Com)
  • The Hack Roundup: White House Says Neuberger Leading Federal Response (Nextgov)
  • Retrieved 2021-02-10

  • Supply chain security is actually worse than we think (ZDNet)
  • White House Names Cybersecurity Expert to Lead Response to SolarWinds Hack (WSJ)
  • Retrieved 2021-02-09

  • SolarWinds security to-do list post hack (Utility Dive)
  • SolarWinds Recovery May Require Extreme Actions
  • Senate Select Committee on Intelligence letter to DNI
  • Retrieved 2021-02-08

  • A Key Step in Preventing a Future SolarWinds (Just Security)
  • The Right Response to SolarWinds (CoFR)
  • Retrieved 2021-02-03

  • Mimecast To Lay Off 80 Workers Weeks After Disclosing Hack
  • Retrieved 2021-02-02

  • Kevin Mandia: Discovering SolarWinds Hack ‘Validates Our Intelligence and Expertise’
  • Retrieved 2021-01-29

  • SolarWinds attack is not an outlier, but a moment of reckoning for security industry, says Microsoft exec (ZDNet)
  • Retrieved 2021-01-20

  • President Biden Announces American Rescue Plan (The White House)
  • Retrieved 2021-01-19

  • The aftermath of the SolarWinds breach: Organizations need to be more vigilant (TechRepublic)
  • After SolarWinds, the U.S. can trust no one (Fortune)
  • Incoming Biden administration looks to shake up US cybersecurity policy (The Daily Swig)
  • Defense nominee favors proactive cyber posture
  • Retrieved 2021-01-16

  • American Public Reticent to Retaliate Against SolarWinds Hack (The National Interest)
  • Retrieved 2021-01-14

  • SolarWinds defense: How to stop similar attacks (ZDNet)
  • What the SolarWinds hack really tells us (TechBeacon)
  • Increasing resilience against Solorigate and other sophisticated attacks with Microsoft Defender (MS Security)
  • Retrieved 2021-01-13

  • Expect more SolarWinds victims, national security official says - (GCN)
  • Retrieved 2021-01-12

  • SolarWinds: What Hit Us Could Hit Others — Krebs on Security
  • Lessons from the SolarWinds Hack: Robust Cybersecurity Requires Leadership (Toka)
  • OODA Loop - If SolarWinds Is a Wake (Up Call, Who’s Really Listening?)
  • Retrieved 2021-01-11

  • SolarWinds CEO: Attack Was ‘One Of The Most Complex And Sophisticated’ In History
  • SolarWinds Hack Lessons Learned: Finding the Next ...
  • SolarWinds Hack Lessons Learned: Finding the Next ...
  • Retrieved 2021-01-09

  • Industry urges agencies to accelerate zero trust adoption after SolarWinds hack (FedScoop)
  • Retrieved 2021-01-08

  • SolarWinds Hires Chris Krebs and Alex Stamos for ...
  • Retrieved 2021-01-07

  • Krebs Stamos Group
  • Hacking victim SolarWinds hires ex-Homeland Security official Krebs as consultant (Reuters)
  • Retrieved 2021-01-06

  • Life After the SolarWinds Supply Chain Attack
  • Retrieved 2021-01-05

  • SolarWinds Breach is the Rule, Not an Exception (secblvd)
  • Retrieved 2021-01-01

  • Gossamer: Supply Chain Security for Open (Source Software)
  • Retrieved 2020-12-29

  • National cyber director role in the spotlight after SolarWinds hack
  • Retrieved 2020-12-28

  • In wake of SolarWinds and Vietnam, more supply chain attacks expected 2021 (scmedia)
  • Retrieved 2020-12-23

  • Opinion (With Hacking, the United States Needs to Stop Playing the Victim - The New York Times)
  • Retrieved 2020-12-22

  • How SolarWinds could’ve been prevented (FRN)
  • The SolarWinds hack, and the danger of arrogance (scmedia)
  • Coast Guard releases bulletin on SolarWinds hack (WorkBoat)
  • Retrieved 2020-12-21

  • SolarWinds incident should be a catalyst to rethink federal cybersecurity (FRN)
  • The Solarwinds breach — What do CIOs need to do now?
  • After the FireEye and SolarWinds breaches, what’s your failsafe? (TechCrunch)
  • Retrieved 2020-12-20

  • SolarWinds/SUNBURST Backdoor, Third-Party and Supply Chain Security (YouTube)
  • Retrieved 2020-12-19

  • SolarWinds hack shows we need a 'whole of society' national cyber strategy (hill)
  • It’s A Twister! Will SolarWinds Blow Cybersecurity Governance Reform Into The Boardroom?
  • Retrieved 2020-12-18

  • Alex Stamos on Twitter: "There is a long history of "trickle down" effects in cyber, where a technique honed by a major player becomes commonplace. China's 2000s APTs -> Iran/DPRK/teenagers in the 2010s. Stuxnet ->smart ransomware. If supply (chain a)
  • The Strategic Implications of SolarWinds (Lawfare)
  • FireEye, SolarWinds Breaches: Implications and Protections (eSecurityPlanet)
  • Retrieved 2020-12-17

  • A moment of reckoning: the need for a strong and global cybersecurity response (Microsoft On the Issues)
  • Feds: SolarWinds Attack ‘Poses a Grave Risk’ To Government, Business
  • Retrieved 2020-12-15

  • What We Know (And Don’t) About The SolarWinds Orion Hack So Far
  • Retrieved 2020-12-13

  • Top Democrat: 'Critical' that Pompeo brief senators on SolarWinds hack at State Dept. (hill)
  • Retrieved 2020-11-02

  • U.S. Cyber Command Expands Operations to Hunt Hackers From Russia, Iran and China (nyt)