Concerns mount over Biden's new cybersecurity executive order following Colonial Pipeline hack
Cybersecurity,Energy,Colonial Pipeline Hack,Technology
Senior government officials are privately sounding the alarm over a new cybersecurity executive order President Joe Biden is poised to sign.
Biden vowed in April to take steps toward securing U.S. cyber-infrastructure and preventing future security breaches like the 2020 SolarWinds hack. The New York Times reported Sunday night, however, that some officials and lawmakers involved in the drafting of the order have expressed concerns about its ability to prevent breaches like the ransomware attack that shuttered the Colonial Pipeline over the weekend.
According to a draft reviewed by the newspaper, the order standardizes basic cybersecurity practices, such as two-factor authentication, at all federal agencies and contracted software vendors. The order also imposes a zero-tolerance policy for vendors and would block those who do not comply from receiving federal contracts.
“That is the stick,” James Lewis, a cybersecurity expert at the Center for Strategic and International Studies in Washington, told the Times. “Companies will be held liable if they’re not telling the truth.”
It remains unclear what effect the order would have had in preventing the Colonial Pipeline attack since it is a private company. Colonial Pipeline has not yet disclosed how the group of Russian hackers known as "DarkSide" compromised its system.
The company itself is responsible for transporting nearly half of the East Coast's fuel supply. Similarly, the New York Times estimated that 85% of the country's energy installations, water treatment plants, and other pieces of critical infrastructure are managed by private companies.
The Biden administration is carrying out a separate initiative to secure the power grid in the form of a 100-day review launched in April.