The U.S. federal government has partnered with Google, Microsoft, Amazon Web Services (AWS), and six more private companies to fight cyberthreats.
“You’ve got to plan in peacetime so you're ready in wartime," Jen Easterly, a retired military officer and the newly sworn-in Director of the Cybersecurity and Infrastructure Security Agency (CISA) said during a virtual keynote session at this week’s Black Hat cybersecurity event. She also announced the launch of the Joint Cyber Defense Collaborative (JCDC).
Easterly explained that JCDC brings its public and private partners together to create a common operating picture of the current threat environment, develop the nation’s comprehensive cyberdefense plans to combat the most significant threats to the nation and its critical infrastructure, and implement these plans into actual operations to reduce cyberrisks.
As one of the initial launch partners, Google plans to offer its security resources to build a stronger and more resilient cyberdefense posture, Google Cloud CISO Phil Venables wrote in an email to SDxCentral. Venables added that “in order to bolster our nation’s cyberdefenses, it's essential that the public and private sectors work together to defend against evolving threats and shore up modern IT capabilities that will protect our federal, state, and local governments.”
Cybersecurity Workforce ShortageAccording to Easterly, there are 3.5 million unfilled cybersecurity jobs around the world, with 500,000 openings in the U.S. She laid out CISA’s plan to amplify a national effort to “build the cybersecurity workforce to deal with the highly digitized world that we live in.”
The agency works with the academic sector and provides scholarships to students for cybersecurity careers in exchange for government service. For K-12 education, it plans to build a cybersecurity curriculum to influence 3 million students next year. CISA also provides training programs to federal non-cybersecurity professionals. And last week it issued a grant to nonprofit organizations to identify cybersecurity talents in the underserved communities, as well as a cybersecurity workforce guide for private-sector employers.
CISA Asks for PartnershipsIn her keynote speech, Easterly highlighted the scope and scale of threats to the nation’s cyber infrastructure and emphasized the importance of transparency and information sharing.
She said the Biden administration has made cybersecurity a national security imperative, but more than 80% of critical infrastructure is in private hands. Easterly asked private companies to leverage collaboration to help secure the cyber ecosystem.
CISA issued a vulnerability disclosure platform to enable its partners and the public to identify vulnerabilities on the government’s websites and mobile applications.
“Collaboration is in CISA’s DNA,” Easterly said, and added that one of her priorities as the director is to cultivate and strengthen the partnerships with industry, academia, researcher, and hacker communities for the nation's collective defense.
She noted that there is a cyberattack roughly every 40 seconds targeting one-tenth of the total 1.8 billion websites, while leading to malware cybercrime damages in trillions of dollars.
Citing the growing threat of ransomware attacks on the health care services, she said, “we cannot allow avoidable cyber disruptions to cost human lives.”
Easterly previously served as the senior director for counterterrorism on the National Security Council in the Obama administration. She then joined Morgan Stanley as global head of the company's cybersecurity division before taking the job as the CISA director.
Everyday malicious attacks from nation-states and cybercriminals weaponize data and the vulnerabilities in our networks to threaten the confidentiality, integrity, and availability of our information, privacy, identity, security, and critical infrastructure, Easterly said, “that's what brings me back after four and a half years in the private sector to the U.S. government to lead CISA.”
Comments