U.S. needs to publicly attribute cyberattacks, former House intel chair says
Full article582 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The U.S. government needs to publicly attribute cyber attacks, or it will be impossible for a private sector cybersecurity insurance market to develop, the former chairman of the House Intelligence Committee said Thursday.
The U.S. government needs to publicly attribute cyberattacks, or it will be impossible for a private sector cybersecurity insurance market to develop, the former chairman of the House Intelligence Committee said Thursday.
‘I believe that we’re going to have to have the U.S. government do attribution on attacks here if we’re going to get the insurance market to work properly,’ former Michigan GOP Rep. Michael Rogers told a forum at the Stimson Center.
Rogers raised the case of a company he didn’t name, but which he said had suffered a ‘significant’ cyber penetration ‘and voluntarily disclosed it, mainly because they believed and I believe as a former government official that it was the government of China that did it and stole it, now they have 109 lawsuits, and if they all win they’re in trouble. they’re going away.’
He described the victim as a ‘major insurance company,’ but decline to elaborate.
Last year several large health insurers who cover federal employees were breached, with Chinese hackers as the main suspects and — significantly — none of the data showing up for sale on the criminal marketplaces on the dark web.
One former official who worked the insurance issue for the Department of Homeland Security noted that cyber insurance, like other policies, contains exclusions.
‘Chairman Rogers oversimplifies,’ said former DHS Deputy Undersecretary Bruce McConnell, now at the EastWest Institute. ‘Insurance companies are well aware of the threat landscape and write their coverage accordingly.’
Rogers suggested that attribution by the government might also provide some kind of legal shield for the victimized insurance company.
‘If the government had publicly come out and attributed who the attacker was, it would help the defense on those lawsuits,’ he noted.
‘[It’s] Pretty hard for a single company to defend against a nation state that according to the U.S. Naval Academy has 800,000 cyber warriors looking at trying to get into your network,’ said Rogers, who left the House of Representatives last year after a decade and half.
He was chairman of the House Intelligence Committee from 2011 to 2015.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/u-s-needs-to-publicly-attribute-cyberattacks-former-house-intel-chair-says/