DHS to unveil National Risk Management Center
Full article600 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
DHS plans to unveil a new interagency center to help critical infrastructure firms assess the risk that a ceaseless stream of cyberthreats pose to their networks.
The Department of Homeland Security will unveil on Tuesday a new interagency center to help critical-infrastructure firms assess the risk that a ceaseless stream of cyberthreats pose to their networks.
The National Risk Management Center is meant to be a one-stop shop for helping private companies manage their cybersecurity risk – and develop ways to mitigate it. Officials are expected to announce the center at a conference in New York City that will feature Vice President Mike Pence, Homeland Security Secretary Kirstjen Nielsen and other Cabinet officials.
The new initiative follows months of public statements from DHS officials about the need to better understand cyber risk spread across sectors. Effectively assessing risk requires “visibility into an often-opaque supply-chain process and a clear understanding of the threat,” Jeanette Manfra, DHS’s top cybersecurity official, said in April.
With the private sector telling DHS it needs more actionable threat data, the department has long looked to revamp its approach to helping protect banks, power companies, and other critical infrastructure firms from hackers.
The job is complicated by the expanding definition of critical infrastructure, as well as the fact that the vast majority of critical infrastructure in the United States is privately owned. The department designated voting systems as critical infrastructure in January 2017 following the probing of state systems by Russian hackers before the 2016 election, adding to a tally of 16 critical infrastructure sectors.
Reacting to the new risk management center, Bruce Potter, chief information security officer at cybersecurity company Expel, said that public-private collaboration was challenging in the current environment and that DHS should focus on incentivizing the private sector to build technology that is “secure by default.”
“Giving users systems that don’t require complex security know-how but rather are secure out of the box will go a long way to making our infrastructure and the country more secure,” Potter said.
DHS has repeatedly warned about the threats that advanced hacking groups pose to U.S. critical infrastructure, including through a March 2018 advisory that detailed Russian government hackers’ collection of information on the control systems used by power plants.
The Wall Street Journal was first to report on the new risk management center.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/dhs-risk-management-center/