<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet media="screen" type="text/xsl" href="https://one.sightlinemg.com/federaltimes/wp-content/themes/smg/assets/xslt/rss-xslt.xml"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
xmlns:news="http://www.pugpig.com/news"
>

<channel>
	<title>Mark Pomerleau, Author at Federal Times</title>
	<atom:link href="https://one.sightlinemg.com/federaltimes/author/mark-pomerleau/feed/" rel="self" type="application/rss+xml" />
	<link>https://one.sightlinemg.com/federaltimes</link>
	<description>Federal Times</description>
	<lastBuildDate>Sat, 08 Aug 2026 18:23:40 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://one.sightlinemg.com/wp-content/uploads/2026/06/favicon-fed.png?w=32</url>
	<title>Mark Pomerleau, Author at Federal Times</title>
	<link>https://one.sightlinemg.com/federaltimes</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">255331619</site><atom:link rel="next" type="application/rss+xml" href="https://one.sightlinemg.com/federaltimes/feed/?paged=2" />
	<item>
		<title>Online survey finds hacking to be the number one concern of government IT workers</title>
		<link>https://one.sightlinemg.com/federaltimes/it-networks/2022/01/11/online-survey-finds-hacking-to-be-the-number-one-concern-of-government-it/</link>
					<comments>https://one.sightlinemg.com/federaltimes/it-networks/2022/01/11/online-survey-finds-hacking-to-be-the-number-one-concern-of-government-it/#respond</comments>
		
		<dc:creator><![CDATA[Mark Pomerleau]]></dc:creator>
		<pubDate>Tue, 11 Jan 2022 11:35:00 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[IT & Networks]]></category>
		<category><![CDATA[Newsletters]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2022/01/11/online-survey-finds-hacking-to-be-the-number-one-concern-of-government-it/</guid>

					<description><![CDATA[Public sector survey respondents no longer believe insiders are the greatest threat.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/it-networks/2022/01/11/online-survey-finds-hacking-to-be-the-number-one-concern-of-government-it/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">14621</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/Fed-feature-2.jpg.jpg" width="6720" height="4480" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">WASHINGTON — Hacking is the largest source of security threats to the public sector, surpassing insiders for the first time in five years, according to a new survey released today.</p>



<p class="wp-block-paragraph">In a report released by SolarWinds — an IT management and software company who contracted Market Connections to conduct the survey — 56% of respondents said the general hacking community was one of the largest source of security threats at public sector organizations, followed by careless or untrained insiders at 52% and foreign governments at 47%.</p>



<p class="wp-block-paragraph">400 IT decision makers responded to the online survey conducted in Oct. 2021 — 200 from the federal level, 100 from the state and local level, and 100 more from the education level. A majority of the respondents worked at civilian federal agencies, with the next highest cadre coming from the Department of Defense. Nearly half of the participants were IT staff, with IT director/manager the second largest portion of respondents and security staff making up a distant third. Others included chief information and technology officers, chief security and information security officers.</p>



<p class="wp-block-paragraph">According to the report, participants from state and local governments were significantly more likely to be concerned about the threat from the general hacking community than those working for federal civilian agencies, who were more likely to indicate careless insiders as a top threat.</p>



<p class="wp-block-paragraph">DoD employees, however, were more likely to list foreign governments as the top threat.</p>



<p class="wp-block-paragraph">“Public sector organizations are increasingly concerned about the threats from foreign governments,” said Tim Brown, CISO and Vice President of Security at SolarWinds. “In looking at the survey data, it’s encouraging that a majority of the public sector is actively seeking to follow the roadmap outlined in the <a href="https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/" target="_blank">[Biden] Administration’s Cybersecurity Executive Order</a>, including enhanced data sharing between public and private sectors.”</p>



<p class="wp-block-paragraph">Public sector respondents’ concern over ransomware, malware and phishing increased the most over the last year.</p>



<p class="wp-block-paragraph">A plurality of respondents, 30%, listed budget constraints as the biggest obstacles to maintaining or improving IT security. Insufficient training of IT staff, shortage of funding and resources and the expanded security perimeter created by remote or hybrid work were the top three impediments listed to detection and remediation of security issues.</p>
]]></content:encoded>
	</item>
		<item>
		<title>Inspector: DoD may struggle to recruit needed cyber workers because it failed to track open jobs</title>
		<link>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/08/02/inspector-dod-may-struggle-to-recruit-needed-cyber-workers-because-it-failed-to-track-open-jobs/</link>
					<comments>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/08/02/inspector-dod-may-struggle-to-recruit-needed-cyber-workers-because-it-failed-to-track-open-jobs/#respond</comments>
		
		<dc:creator><![CDATA[Mark Pomerleau]]></dc:creator>
		<pubDate>Mon, 02 Aug 2021 18:11:54 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[HR]]></category>
		<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[Newsletters]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2021/08/02/inspector-dod-may-struggle-to-recruit-needed-cyber-workers-because-it-failed-to-track-open-jobs/</guid>

					<description><![CDATA[Only one military branch met the federal requirement to code its filled and unfilled cyber jobs.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/08/02/inspector-dod-may-struggle-to-recruit-needed-cyber-workers-because-it-failed-to-track-open-jobs/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">24171</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/48081086122_28526a182f_o.jpg.jpg" width="2250" height="1500" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">WASHINGTON — The Department of Defense has not properly tracked its open civilian cyber jobs and risks missing goals to recruit more skilled cyber employees without a clear picture of workforce needs, a watchdog report released Aug. 2 said.</p>



<p class="wp-block-paragraph">Leaders at the DoD and across the larger federal government have long called for filling a cyber skills gap by speeding up recruitment and ensuring competitive salaries with private sector. That need is only growing with increasing cyberattacks. All U.S. agencies had to implement a job-coding plan to document filled and unfilled cyber jobs, many for highly qualified personnel who perform information technology and cybersecurity.</p>



<p class="wp-block-paragraph">The DoD was supposed to have started logging its jobs starting in 2018, but the Army was the only component with an automated quality assurance process to code its cyber workforce, according to the DoD inspector general report.</p>



<p class="wp-block-paragraph">While the DoD established work role codes as required, many components did not code or incorrectly coded civilian workforce positions.</p>



<p class="wp-block-paragraph">“Until the DoD Components’ application of work role codes is complete and accurate, the DoD may not have the information needed to identify and target the recruitment and retention programs to meet its greatest cyber workforce needs,” the inspector general said.</p>



<p class="wp-block-paragraph">The report blacked out many mentions of specific positions and percentages of filled and unfilled positions. “With [REDACTED] percent of its filled and [REDACTED] percent of unfilled core positions not coded or coded incorrectly, the DoD may be unable to accurately determine the skill set and size of its civilian cyber workforce, which may hinder workforce planning activities, such as recruitment and retention strategies and determining the work roles of critical need.”</p>



<p class="wp-block-paragraph">The acting DoD chief information officer agreed with the IG’s recommendations for components to complete work role coding by the end of 2021. The CIO is developing an automated dashboard to show components’ cyber workforce status.</p>
]]></content:encoded>
	</item>
		<item>
		<title>US Cyber Command wants more money for network defense</title>
		<link>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/06/10/us-cyber-command-wants-more-money-for-network-defense/</link>
					<comments>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/06/10/us-cyber-command-wants-more-money-for-network-defense/#respond</comments>
		
		<dc:creator><![CDATA[Mark Pomerleau]]></dc:creator>
		<pubDate>Thu, 10 Jun 2021 14:44:30 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Newsletters]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2021/06/10/us-cyber-command-wants-more-money-for-network-defense/</guid>

					<description><![CDATA[U.S. Cyber Command is asking Congress for an additional $62.1 million in its unfunded priority list to harden networks from malicious cyberattacks.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/06/10/us-cyber-command-wants-more-money-for-network-defense/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">23912</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/Pic-5.JPG.jpg" width="1800" height="1200" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">WASHINGTON — U.S. Cyber Command asked Congress for an additional $62 million to harden Department of Defense networks as part of its <a href="https://www.defensenews.com/dod/cybercom/2020/02/21/which-cyber-priorities-didnt-appear-in-the-pentagons-budget/" target="_blank">unfunded priorities</a> that didn’t make it into the command’s fiscal 2022 budget request.</p>



<p class="wp-block-paragraph">A copy of the list obtained by C4ISRNET showed that Cyber Command noted the recent SolarWinds intrusion of various government networks in its request for money to help the DoD secure its own networks and respond to malicious cyber actions. The item topped a list of four unfunded priorities totaling $93.4 million.</p>



<p class="wp-block-paragraph">The DoD has said that the vast SolarWinds breach of federal and business networks, attributed to the Russian foreign intelligence service, did not affect its own systems.</p>



<p class="wp-block-paragraph">“I ask your committee to support these priorities … to help us strengthen military readiness and alliances, secure the homeland from cyberspace attack and advance national interests,” Gen. Paul Nakasone, commander of Cyber Command wrote in the proposal.</p>



<p class="wp-block-paragraph">Cyber intrusions and ransomware incidents are rising to epidemic status, according to some cybersecurity analysts, leading the federal government to prioritize response efforts.</p>



<p class="wp-block-paragraph">In fact, the largest slice of the Pentagon’s $10 billion cyber request asked for <a href="https://www.c4isrnet.com/cyber/2021/05/28/after-years-of-flat-cybersecurity-budgets-dod-asks-for-more-money-and-cyber-mission-force-personnel/" target="_blank">$5.6 billion to protect IT systems</a>.</p>



<p class="wp-block-paragraph">Cyber Command’s No. 2 unfunded priority is $23.3 million for cyber training. The command, through service acquisition executives, is building an online training system called the <a href="https://www.c4isrnet.com/cyber/2021/01/28/latest-version-of-cyber-training-to-roll-out-in-coming-months/" target="_blank">Persistent Cyber Training Environment</a>, which allows forces to conduct individual and collective training as well as mission rehearsal.</p>



<p class="wp-block-paragraph">The other two items listed are $3.2 million for human intelligence to help the command build an organic intelligence capability to access strategic targets and $4.8 million for acquisition personnel.</p>



<p class="wp-block-paragraph">Cyber Command has worked for several years to establish an acquisition structure with Congress, which in 2016 authorized limited purchasing authority described as a <a href="https://www.c4isrnet.com/dod/cybercom/2018/09/07/cyber-commands-acquisition-authority-still-in-its-infancy/" target="_blank">crawl, walk, run approach</a> to ensure the young command could get the plan up and running.</p>



<p class="wp-block-paragraph">In the most recent annual defense bill, Congress eliminated the $75 million acquisition cap on Cyber Command and enhanced the commander’s authority to oversee programs and priorities. However, the services still run major programs on behalf of the command and joint cyber mission force.</p>



<p class="wp-block-paragraph">The $4.8 million would go toward integrating the command’s <a href="https://www.c4isrnet.com/cyber/2021/06/04/cyber-command-plans-bigger-budget-for-mission-planning-tool/" target="_blank">Joint Cyber Warfighting Architecture</a>, which guides its acquisition priorities. Congress and the nonpartisan Government Accountability Office <a href="https://www.c4isrnet.com/cyber/2020/11/19/us-cyber-commands-capability-efforts-lack-clarity-says-government-watchdog/" target="_blank">gave the command poor marks for the architecture</a>, citing integration and oversight problems. The command has <a href="https://www.c4isrnet.com/cyber/2021/03/12/cyber-command-works-to-address-criticism-over-how-it-integrates-tools-challenges-remain/" target="_blank">since sought to assuage those concerns</a>.</p>



<p class="wp-block-paragraph"><i>Defense News reporter Joe Gould contributed to this report</i>.</p>
]]></content:encoded>
	</item>
		<item>
		<title>Will the cyber mission force soon receive more personnel?</title>
		<link>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/05/14/will-the-cyber-mission-force-soon-receive-more-personnel/</link>
					<comments>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/05/14/will-the-cyber-mission-force-soon-receive-more-personnel/#respond</comments>
		
		<dc:creator><![CDATA[Mark Pomerleau]]></dc:creator>
		<pubDate>Fri, 14 May 2021 19:38:25 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Newsletters]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2021/05/14/will-the-cyber-mission-force-soon-receive-more-personnel/</guid>

					<description><![CDATA[The head of U.S. Cyber Command hinted that the cyber mission force could soon receive a bump in staffing.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/05/14/will-the-cyber-mission-force-soon-receive-more-personnel/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">28462</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/200619-N-KT462-6060.JPG.jpg" width="4760" height="3384" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">WASHINGTON — The commander of U.S. Cyber Command hinted Friday that his cyber force could soon see a growth in personnel.</p>



<p class="wp-block-paragraph">“I would anticipate that as we lay out the case, we have to look at some critical elements that will influence the future size of the cyber mission force, now 133 teams,” Gen. Paul Nakasone said at a House Armed Services Cyber, Innovative Technologies and Information Systems Subcommittee hearing.</p>



<p class="wp-block-paragraph">Some members of Congress are worried that the cyber mission force — designed and built almost 10 years ago — <a href="https://www.c4isrnet.com/dod/cybercom/2020/03/05/house-members-worry-if-the-cyber-force-is-the-right-size/" target="_blank">does not reflect the current dynamic state of cyberspace</a>.</p>



<p class="wp-block-paragraph">Members questioned Nakasone last year on the topic, and he said Cyber Command would gather information for Pentagon leaders to make appropriate staffing decisions.</p>



<p class="wp-block-paragraph">In fact, the congressionally mandated <a href="https://www.c4isrnet.com/dod/2020/01/07/congressional-commission-wants-more-cyberwarriors-for-the-military/" target="_blank">Cyberspace Solarium Commission recommended the Department of Defense create more cyberwarriors</a>. That provision made it into last year’s National Defense Authorization Act in the form of <a href="https://www.c4isrnet.com/cyber/2020/12/22/which-ndaa-cyber-provisions-have-the-most-impact-for-dod/" target="_blank">providing a comprehensive assessment cyber operations forces</a> as part of changes to the department’s quadrennial cyber posture review.</p>



<p class="wp-block-paragraph">Nakasone told the committee today that he does have the data available to make such a determination.</p>



<p class="wp-block-paragraph">“To prepare for the approved growth in the CMF, we will enhance our control over resources for the force, improve its readiness (including the metrics we require in doing so), and consolidate CMF training,” Nakasone wrote in congressional testimony provided to the Senate Armed Serves Committee in March and to the House Armed Services Committee on Friday. “Recent demand across DoD has demonstrated that the original 133 teams in the CMF are not enough. The strategic environment has changed since the original CMF was designated in 2012. Added forces will ensure USCYBERCOM can fulfill its responsibility as both a supported and a supporting command.”</p>



<p class="wp-block-paragraph">A Department of Defense spokesperson told C4ISRNET that those specific numbers have not been released publicly.</p>



<p class="wp-block-paragraph">Currently, there are 6,187 authorized positions for the cyber mission force with 238,000 personnel in the DoD’s cyberspace operations forces, which includes the cyber mission force, Cyber Command subordinate command elements, cybersecurity service providers, special capability providers, and specialty units, Nakasone said, drawing from the 2018 cyber posture review.</p>



<p class="wp-block-paragraph">Those cyber mission force teams have <a href="https://www.c4isrnet.com/dod/cybercom/2019/05/16/cyber-command-is-decoding-how-to-best-reorganize-teams/" target="_blank">undergone changes over the years</a> to adapt to threats, allowing the freedom for commanders to task organize their teams as necessary. For example, in Nakasone’s written testimony, he noted how several teams were initially aligned to the counterterrorism fight, but with the department’s shift toward state actors, Cyber Command has realigned some units to focus on key nations.</p>



<p class="wp-block-paragraph">One such example is its counter-Islamic State group task force, <a href="https://www.c4isrnet.com/cyber/2021/05/04/cyber-command-shifts-counterterrorism-task-force-to-focus-on-higher-priority-threats/" target="_blank">Joint Task Force-Ares</a>. Cyber Command shifted the majority of the task force to focus more on nation-state actors, particularly in the Indo-Pacific region.</p>



<p class="wp-block-paragraph">Nakasone told representatives that there are a few other factors that will affect the growth of the cyber mission force; chief among them is the <a href="https://www.c4isrnet.com/cyber/2020/07/24/where-do-space-force-and-space-command-fit-into-the-pentagons-cyber-plans/" target="_blank">growing importance of space</a>.</p>



<p class="wp-block-paragraph">The creation of the Space Force and Space Command adds more ground for Cyber Command to cover. The way the cyber force is staffed within the DoD is that each of the services are responsible for providing a set number of teams — offensive, defensive and intelligence/support teams — to the joint cyber mission force.</p>



<p class="wp-block-paragraph">In turn, these teams are led by a Joint Force Headquarters-Cyber, which are headed by each of the service cyber component commanders, who them plan, synchronize and conduct operations for the combatant commands to which they’re assigned. The 16th Air Force and its Joint Force Headquarters-Cyber component takes responsibility for Space Command, which is in the process of creating its own <a href="https://fcw.com/articles/2021/04/21/space-command-cyber-zero-trust.aspx" target="_blank">Joint Cyber Center</a> to create a tighter linkage with Cyber Command.</p>



<p class="wp-block-paragraph">While all the services provide an allotted number of forces to Cyber Command through the cyber mission force, officials to date have said there are <a href="https://www.c4isrnet.com/cyber/2021/02/12/space-force-begins-adding-cyber-warriors/" target="_blank">no plans for Space Force to provide cyber mission force contributions</a>. Instead, officials have noted that they need specialized, serviced-retained cyber personnel to defend their critical assets, such as ground stations, from cyberattacks.</p>



<p class="wp-block-paragraph">Adversaries are now using cyberspace in ways that weren’t necessarily imagined when the force was initially conceived. Namely, they’ve discovered they can conduct operations below the threshold of war to undermine U.S. national security and not draw a significant response.</p>



<p class="wp-block-paragraph">“We have to have that balance of not only, what we are going to support our fellow combatant commands if conflict was to break out, but also if our adversaries are operating below the level of armed conflict every single day, what type of force do we need to be able to ensure that we can counteract that,” Nakasone said.</p>
]]></content:encoded>
	</item>
		<item>
		<title>Biden orders wide cybersecurity changes for government, contractors</title>
		<link>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/05/13/biden-orders-wide-cybersecurity-changes-for-government-contractors/</link>
					<comments>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/05/13/biden-orders-wide-cybersecurity-changes-for-government-contractors/#respond</comments>
		
		<dc:creator><![CDATA[Mark Pomerleau]]></dc:creator>
		<pubDate>Thu, 13 May 2021 17:44:17 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Newsletters]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2021/05/13/biden-orders-wide-cybersecurity-changes-for-government-contractors/</guid>

					<description><![CDATA[A new executive order aims to improve detection of malicious cyber activity on federal networks.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/05/13/biden-orders-wide-cybersecurity-changes-for-government-contractors/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">24109</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/AP21107030907949.jpg.jpg" width="2000" height="1333" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">WASHINGTON — Following government cyber breaches, the Biden administration issued a cybersecurity order requiring improved protections at government agencies and prompt breach reports from federal computer network and cloud service suppliers.</p>



<p class="wp-block-paragraph">The executive order signed Wednesday touches on many issues that the Defense Department is weighing to ensure adequate protections among its vast information technology supplier network, an effort driven in large part by lawmakers’ alarm over recent high-profile government network compromises. For example, lawmakers ordered the DoD to assess programs to share cybersecurity information with the defense industrial base and to consider the possibility of a threat-hunting program on vendors’ networks.</p>



<p class="wp-block-paragraph">The security of the military’s most sensitive information, such as weapon controls and service members’ locations, rides on its cyber protections.</p>



<p class="wp-block-paragraph">The Biden administration is trying to eliminate any hesitation or contractual barriers that might prevent IT providers from sharing cyber threat information with the government.</p>



<p class="wp-block-paragraph">“Federal agencies can’t defend what they can’t see,” a senior administration official said during a call with reporters the day Biden approved the plan. “Removing barriers to information sharing regarding threats and incidents is a fundamental first step to preventing breaches in the first place and empowering the federal government to respond when they do occur.”</p>



<p class="wp-block-paragraph">The order follows a raft of major cyber breaches and compromises over the last year, including the wide-ranging, Russian-orchestrated <a href="https://www.c4isrnet.com/cyber/2021/01/29/hand-to-hand-combat-on-computer-networks-how-cyber-threat-hunters-work/" target="_blank">Solar Winds intrusion of federal systems</a> that compromised the supply chain; a Chinese-orchestrated operation that compromised Microsoft Exchange servers globally; and a ransomware attack against Colonial Pipeline that is affecting gas supplies. Officials said the order would help detect some of these problems much faster in the future.</p>



<p class="wp-block-paragraph">“Companies need to share information about the incident, the vulnerability, what occurred. We’re really focused on information that’s important to be used to get out information to better help other entities defend themselves,” the senior administration official said. “We’re really creating a common threshold across the federal government to say let’s make sure that info is shared so all can defend themselves and all can get at information to private sector stakeholders and others to enable them to defend themselves as well.”</p>



<p class="wp-block-paragraph">The order requires, within six months for some agencies, advanced protections including multifactor authentication of users’ identities and endpoint detection systems that constantly monitor for malicious activity and block it.</p>



<p class="wp-block-paragraph">“Fundamentally what we saw in SolarWinds was that federal government cybersecurity was not at the level needed to detect attempts to intrude and to rapidly find those that are successful,” the administration official said.</p>



<p class="wp-block-paragraph">Additionally, the new order pushes the federal government to move to secure cloud services and a<a href="https://www.c4isrnet.com/cyber/2021/04/15/the-pentagons-next-move-in-expanding-zero-trust/" target="_blank"> zero-trust architecture</a> and mandates encryption to secure data.</p>



<p class="wp-block-paragraph">In the event of a breach or lesser network problem, the order creates a “playbook” or a standard set of definitions for cyber response by federal agencies.</p>



<p class="wp-block-paragraph">Software suppliers also must provide federal buyers with a “software bill of materials,” essentially a list of ingredients of what’s inside the software. John Cofrancesco, vice president of government business for Fortress Information Security, told C4ISRNET that the bill of materials was “huge.”</p>



<p class="wp-block-paragraph">“Weapon systems and platforms were once thought to be disconnected standalone systems, because they were not consistently connected to a network,” Cofrancesco said. “That belief has been dispelled in large part due to the heavily reliance on software that must be updated, refreshed, loaded, downloaded and patched. Each of these present unique touch points and access points for adversaries and criminals to corrupt our systems.”</p>



<p class="wp-block-paragraph">This executive order is the first step in helping to secure supply chains and add greater transparency and accountability.</p>



<p class="wp-block-paragraph">Officials acknowledge that the order is limited given the authorities afforded to executive orders. While it is a welcome stride, some argue that more needs to be done to protect the federal government from sophisticated intrusions.</p>



<p class="wp-block-paragraph">“This executive order is a good first step, but executive orders can only go so far. Congress is going to have to step up and do more to address our cyber vulnerabilities, and I look forward to working with the administration and my colleagues on both sides of the aisle to close those gaps,” Sen. Mark Warner, D-Virginia, chairman of the Intelligence Committee, said in a statement.</p>



<p class="wp-block-paragraph"><i>Andrew Eversden contributed to this report.</i></p>
]]></content:encoded>
	</item>
		<item>
		<title>Air Force cyber school will add online training tool</title>
		<link>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/05/05/air-force-cyber-school-will-add-online-training-tool/</link>
					<comments>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/05/05/air-force-cyber-school-will-add-online-training-tool/#respond</comments>
		
		<dc:creator><![CDATA[Mark Pomerleau]]></dc:creator>
		<pubDate>Wed, 05 May 2021 18:40:39 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Newsletters]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2021/05/05/air-force-cyber-school-will-add-online-training-tool/</guid>

					<description><![CDATA[U.S. Cyber Command has mandated that all the services must adopt the Persistent Cyber Training Environment at schoolhouses.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/05/05/air-force-cyber-school-will-add-online-training-tool/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">14158</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/190625-A-JP545-2152.JPG.jpg" width="1800" height="1200" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph"><i>This version of the story includes corrected information that Cyber Command has made it a goal, not a mandate, that the Persistent Cyber Training Environment becomes the training platform for the cyber mission force.</i></p>



<p class="wp-block-paragraph">WASHINGTON — The Air Force school to prepare airmen to become high-end cyber defenders will introduce an online training tool in its upcoming curriculum.</p>



<p class="wp-block-paragraph">Designed as the <a href="https://www.c4isrnet.com/cyber/2021/01/28/latest-version-of-cyber-training-to-roll-out-in-coming-months/" target="_blank">premier training tool</a> for the Department of Defense cyber force, the Persistent Cyber Training Environment (PCTE) allows U.S. Cyber Command’s warriors to log on from anywhere in the world for individual or group training and mission rehearsals. The goal for PCTE is that it will be the training platform for the cyber mission force in the future.</p>



<p class="wp-block-paragraph">To date, the services have used PCTE mostly for <a href="https://www.c4isrnet.com/cyber/2021/01/08/cyber-valhalla-air-force-trains-offensive-warriors-with-unclassified-exercise/" target="_blank">active duty units</a>’ training and <a href="https://www.c4isrnet.com/dod/cybercom/2020/06/15/for-the-first-time-cyber-commands-major-exercise-will-use-new-training-platform/" target="_blank">exercises</a>. </p>



<p class="wp-block-paragraph">Cyber Command sets training standards for its cyber mission force, fed by the military branches. The command selected the Navy as the joint curriculum lead for defensive cyber operations, and. the Army is manages the PCTE program on behalf of Cyber Command.</p>



<p class="wp-block-paragraph">Officials at the <a href="https://www.c4isrnet.com/dod/air-force/2018/06/20/the-air-forces-flight-school-but-for-cyber/" target="_blank">39th Information Operations Squadron</a>, which provides airmen initial qualification training for defensive weapon systems before they join cyber protection teams, have worked with the Navy as it finalizes those joint standards. The schoolhouse at the 39th IOS is in the beginning stages of migrating to PCTE, inputting modules from the operational force, lab assignments and even practice ranges.</p>



<p class="wp-block-paragraph">“The sooner everyone gets on board and moving in that direction is the sooner that we’ll start seeing the benefits from” PCTE, Lt. Col. Jonathan Williams, commander of the 39th IOS, told C4ISRNET.</p>



<p class="wp-block-paragraph">Overall, training of defensive cyber warriors won’t change a whole lot given they have always used online tools and ranges in the classroom, officials said. What does change with the inclusion of PCTE in the schoolhouse is the variety and complexity of the training ranges, said Capt. Jerrelle Marshall, chief of weapons and tactics at the 39th IOS.</p>



<p class="wp-block-paragraph">“Having a common set of training goals across the services provides a better opportunity for inter-changeability on cyber missions for the joint cyber operations force,” he said.</p>



<p class="wp-block-paragraph">Officials said using PCTE will create a more ready force — from better training at the schoolhouse level to more realistic and on-demand training for operational forces — all to a greater benefit to taxpayers.</p>



<p class="wp-block-paragraph">“From the budget perspective, [uploading operational lessons for students] saves us a heck of a lot of time and money and makes us much better stewards of your taxpayer dollars,” Runyan said.</p>



<p class="wp-block-paragraph">Because training is conducted in the same environment at the schoolhouse and in operational units, there are resource efficiencies gained from standardization, simplification and automation of the training management processes, Marshall said.</p>



<p class="wp-block-paragraph">“Instead of reinventing the wheel each time the field requests new training requirements, the schoolhouse has a direct link to entire communities’ worth of lessons learned and best practices, significantly shortening the timeline to go from need to implementation,” he said. “This link also enables tremendous cost savings to the joint community as we scale down the number of fielded independently operated and managed cyber training ranges to a consolidated model.”</p>



<p class="wp-block-paragraph">The tool comes with a variety of additional benefits. It allows students to rerun practicals or replay scenarios they might have struggled on. They can get hands-on experience with the real tools and environments they’ll encounter in operations against actual threats.</p>



<p class="wp-block-paragraph">Officials hope that experience will help the Air Force students, who at this level are focused heavily on individual training, more ready to integrate with their units and conduct mission qualification training.</p>



<p class="wp-block-paragraph">“My personal opinion is that’s going to pay off in spades at the unit level at the mission qual [qualification] training, at the exercises and upgrade team certification for our CPTs out in the field,” said Skip Runyan, a tech adviser at the 39th IOS. “The possibilities that PCTE brings to the fight are enormous.”</p>



<p class="wp-block-paragraph">This approach differs from traditional training for the broader military, which has limited training times and ranges because people have to practice on the tanks, fighter jets or other equipment they use in missions. What’s more, while the military does its best to replicate threats, it can only go so far. In cyberspace, these units can play against actual strains of malware or networks seen in operations.</p>



<p class="wp-block-paragraph">“If we’re using the fighter analogy, they’ve got the ability to hop in the F-15 cockpit and do some training when there is a need to do that training. [Airmen] don’t have to schedule themselves for training sorties. The training will always be available,” Williams said. “I think that’s the true power with this new environment.”</p>



<p class="wp-block-paragraph">Professors’ workload is lightened because PCTE grades students’ lessons.</p>



<p class="wp-block-paragraph">“The grading aspect takes up a lot of time for the instructors, and if we have the ability to not only grade them with a little bit of the automation built into PCTE but also do some replays from what they’re doing in there, we can actually show them where they went wrong or where they went right in the system,” Runyan said. “That saves a lot of time and effort on the part of the instructor and saves a lot of frustration on the part of the student.”</p>



<p class="wp-block-paragraph">Marshall explained that instead of instructors spending time thinking up how ranges should be configured, they can now focus their efforts on developing threat-representative scenarios.</p>


	<aside class="smg-interstitial-link wp-block-smg-interstitial-link">
		<a href="https://one.sightlinemg.com/c4isrnet/newsletters/daily-brief/2020/11/06/the-us-air-force-is-using-a-new-cyber-training-platform-to-evolve-defensive-teams/" class="smg-interstitial-link__inner">
							<div class="smg-interstitial-link__media">
					<img decoding="async" width="300" height="216" src="https://one.sightlinemg.com/wp-content/uploads/2026/08/4077384.jpg.jpg?w=300" class="smg-interstitial-link__image wp-post-image" alt="" />				</div>
						<div class="smg-interstitial-link__content">
				<span class="smg-interstitial-link__kicker">Related</span>
				<h3 class="smg-interstitial-link__title">The US Air Force is using a new cyber training platform to evolve defensive teams</h3>
									<p class="smg-interstitial-link__excerpt">The Persistent Cyber Training Environment is being used to mature new designs for defensive cyber teams.</p>
							</div>
		</a>
	</aside>
	]]></content:encoded>
	</item>
		<item>
		<title>White House names leader for SolarWinds hack response after criticism</title>
		<link>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/02/11/white-house-names-leader-for-solarwinds-hack-response-after-criticism/</link>
					<comments>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/02/11/white-house-names-leader-for-solarwinds-hack-response-after-criticism/#respond</comments>
		
		<dc:creator><![CDATA[Mark Pomerleau]]></dc:creator>
		<pubDate>Thu, 11 Feb 2021 16:50:54 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Newsletters]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2021/02/11/white-house-names-leader-for-solarwinds-hack-response-after-criticism/</guid>

					<description><![CDATA[The Biden administration named a top National Security Council official as the leader following lawmakers' complaints of a disjointed response.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/02/11/white-house-names-leader-for-solarwinds-hack-response-after-criticism/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">26556</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/DataBreach.jpg.jpg" width="9431" height="5301" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">WASHINGTON — Reacting to senators’ criticism of a disorganized response to a massive government hack, the White House said a top cybersecurity adviser is leading the recovery.</p>



<p class="wp-block-paragraph">The news Wednesday that Anne Neuberger, deputy national security adviser for cyber, is in charge of responding to the Russian breach pleased Senate Intelligence Committee leaders, who <a href="https://www.c4isrnet.com/cyber/2021/02/09/unhappy-with-response-senators-ask-for-a-leader-to-head-up-cyber-breach-cleanup/" target=_blank>called the effort disjointed</a> a day earlier and have pushed for more information about federal cybersecurity.</p>



<p class="wp-block-paragraph">“The federal government’s response to date to the SolarWinds breach has lacked the leadership and coordination warranted by a significant cyber event, so it is welcome news that the Biden administration has selected Anne Neuberger to lead the response,” said Sens. Mark Warner, D-Virginia, and Marco Rubio, R-Florida, the committee chairman and vice chairman, respectively. “The committee looks forward to getting regular briefings from Ms. Neuberger and working with her to ensure we fully confront and mitigate this incident as quickly as possible.”</p>



<p class="wp-block-paragraph">Before moving to a new cybersecurity-focused role on the National Security Council, Neuberger was the first director of the National Security Agency’s Cybersecurity Directorate, created in 2019 to provide the private sector key intelligence to bolster national cybersecurity.</p>



<p class="wp-block-paragraph">Media reports noted that the Biden administration said Neuberger has been the point person on the federal response all along, but that role had not been known publicly.</p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="4815" height="3322" src="/wp-content/uploads/2026/08/GettyImages-1186386275.jpg.jpg" alt="" class="wp-image-75686" srcset="https://one.sightlinemg.com/wp-content/uploads/2026/08/GettyImages-1186386275.jpg.jpg 4815w, https://one.sightlinemg.com/wp-content/uploads/2026/08/GettyImages-1186386275.jpg.jpg?resize=300,207 300w, https://one.sightlinemg.com/wp-content/uploads/2026/08/GettyImages-1186386275.jpg.jpg?resize=768,530 768w, https://one.sightlinemg.com/wp-content/uploads/2026/08/GettyImages-1186386275.jpg.jpg?resize=1024,706 1024w, https://one.sightlinemg.com/wp-content/uploads/2026/08/GettyImages-1186386275.jpg.jpg?resize=1536,1060 1536w, https://one.sightlinemg.com/wp-content/uploads/2026/08/GettyImages-1186386275.jpg.jpg?resize=2048,1413 2048w" sizes="(max-width: 4815px) 100vw, 4815px" /><figcaption class="wp-element-caption">SAN FRANCISCO, CALIFORNIA &#8211; NOVEMBER 08: Anne Neuberger speaks onstage at the WIRED25 Summit 2019 &#8211; Day 1 at Commonwealth Club on November 08, 2019 in San Francisco, California. (Photo by Phillip Faraone/Getty Images for WIRED)</figcaption></figure>



<p class="wp-block-paragraph">The breach, believed to have started in last spring, was executed through a variety of vectors, according to experts, most notably by inserting malicious code in software updates provided by government supplier SolarWinds.</p>



<p class="wp-block-paragraph">Hackers targeting the government’s supply chain could be the new normal, a top cyber expert warned members of Congress.</p>



<p class="wp-block-paragraph">“SolarWinds really represents a new normal for Russian intelligence. If you look at what they were doing prior to SolarWinds, they were trying to be very noisy when they were breaking in and being detected very, very quickly,” Dmitri Alperovitch, executive chairman, Silverado Policy Accelerator, said in a Feb. 10 hearing before the House Committee on Homeland Security. “I believe that they reevaluated post their original compromises of the White House, State Department and the Joint Chiefs of Staff back in 2014 and 2015 and realized that the supply chain vector — being able to comprise these high-risk software like SolarWinds and using that to gain access to high value networks is really the way to go if you want to have long term access to these networks and remain undetected for months if not years.”</p>



<p class="wp-block-paragraph">Other cybersecurity experts have noted changes in Russia’s tradecraft throughout the last decade. Kevin Mandia, CEO at cybersecurity firm FireEye, has said if Russian hackers were caught in U.S. networks a decade ago, they would leave to prevent any observation of their behavior. This changed around 2014-2015 when, if caught, they would <a href="https://www.c4isrnet.com/show-reporter/dodiis/2017/08/16/a-rundown-of-americas-top-cyberspace-foes/" target=_blank>persist on the network</a> even though they knew they were being watched.</p>



<p class="wp-block-paragraph">Alperovitch, who co-founded CrowdStrike and left in 2020, has followed Russian intelligence and cyber activities for years. He indicated the country’s efforts in cyberspace mirror its activities in human intelligence, sending spies to implant themselves in society over decades to steal secrets.</p>



<p class="wp-block-paragraph">China is also likely taking note of these Russian tactics, he said.</p>



<p class="wp-block-paragraph">In fact, China discovered several years back that it can hack contractors working on sensitive Department of Defense and national security programs to steal information and intellectual property, even use the information to build similar systems such as its J-31, which closely resembles the F-35.</p>



<p class="wp-block-paragraph">Adversaries have realized they can <a href="https://www.c4isrnet.com/dod/2019/07/18/is-industry-cyberinsecurity-dods-achilles-heel/" target=_blank>target small to medium-sized manufacturing companies with crippling cyberattacks</a> because, in many cases, these companies provide the Department of Defense critical services but often are so small that they don’t have the wherewithal to institute enough cyber defenses against intrusions.</p>



<p class="wp-block-paragraph">A key role for the NSA’s cybersecurity directorate is <a href="https://www.c4isrnet.com/dod/2019/10/09/new-nsa-cyber-directorate-to-focus-on-industrial-base/" target=_blank>helping secure the defense industrial base and defense weapons systems</a>.</p>



<p class="wp-block-paragraph">One way the government has sought to bolster the supply chain and defense industrial base is the <a href="https://www.c4isrnet.com/cyber/2020/12/16/dod-announces-cybersecurity-certification-pilots" target=_blank>Cybersecurity Maturity Model Certification</a>, a tiered cybersecurity framework that grades companies on a scale of one to five. A score of one designates basic cyber hygiene and a five represents advanced hygiene.</p>



<p class="wp-block-paragraph">Another way to improve supply chain vulnerabilities, Alperovitch offered, is to elevate standards for providers and require them to provide annual audits of their source code and networks.</p>
]]></content:encoded>
	</item>
		<item>
		<title>Unhappy with response, senators ask for a leader to head up cyber breach cleanup</title>
		<link>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/02/09/unhappy-with-response-senators-ask-for-a-leader-to-head-up-cyber-breach-cleanup/</link>
					<comments>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/02/09/unhappy-with-response-senators-ask-for-a-leader-to-head-up-cyber-breach-cleanup/#respond</comments>
		
		<dc:creator><![CDATA[Mark Pomerleau]]></dc:creator>
		<pubDate>Tue, 09 Feb 2021 22:08:06 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Newsletters]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2021/02/09/unhappy-with-response-senators-ask-for-a-leader-to-head-up-cyber-breach-cleanup/</guid>

					<description><![CDATA[The heads of the Senate Intelligence Committee urged the federal government to name a singular leader to run the response to a widespread hack attributed to Russian cyber actors.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/02/09/unhappy-with-response-senators-ask-for-a-leader-to-head-up-cyber-breach-cleanup/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">16550</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/GettyImages-1197629873.jpg.jpg" width="6000" height="4000" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">WASHINGTON — Worried about a “disjointed” response to what some <a href="https://www.c4isrnet.com/cyber/2021/01/29/hand-to-hand-combat-on-computer-networks-how-cyber-threat-hunters-work/" target=_blank>experts say could be the biggest hack in American history</a>, two congressional leaders urged the government to name a person to head the cleanup.</p>



<p class="wp-block-paragraph">In a <a href="https://www.warner.senate.gov/public/_cache/files/f/2/f26e92ba-2b05-4e65-bbda-10d3a8dc1c81/0CE82FCBF5172B642C7B6F9C2440B778.hainesnakasonewraywales-ssci-09feb21.pdf" target=_blank>Feb. 9 letter</a>, Sens. Mark Warner, D-Virginia, and Marco Rubio, R-Florida ― the chairman and vice chairman of the Senate Intelligence Committee, respectively — expressed their concern with the federal response to date.</p>



<p class="wp-block-paragraph">“The federal government’s response so far has lacked the leadership and coordination warranted by a significant cyber event, and we have little confidence that we are on the shortest path to recovery,” they wrote to the director of national intelligence, director of the National Security Agency, director of the FBI, and acting head of the Department of Homeland Security’s cyber arm.</p>



<p class="wp-block-paragraph">The U.S. government has blamed Russia for <a href="https://www.c4isrnet.com/battlefield-tech/it-networks/2020/12/27/very-difficult-to-defend-what-happens-if-hackers-are-inside-the-pentagons-networks/" target=_blank>widespread breach of federal agencies and private companies</a>. The hacking campaign, believed to have started in the spring, was executed through a variety of vectors, according to experts, but most notably by inserting malicious code in software updates provided by government supplier SolarWinds.</p>



<p class="wp-block-paragraph">The senators urged the government to establish a single leader who can unify the response.</p>



<p class="wp-block-paragraph">“The briefings we have received convey a disjointed and disorganized response to confronting the breach. Taking a federated rather than a unified approach means that critical tasks that are outside the central roles of your respective agencies are likely to fall through the cracks,” they wrote. “The threat our country still faces from this incident needs clear leadership to develop and guide a unified strategy for recovery, in particular a leader who has the authority to coordinate the response, set priorities, and direct resources to where they are needed.”</p>



<p class="wp-block-paragraph">In her Jan. 19 confirmation hearing to become director of national intelligence, Avril Haines committed to providing open channels of communication with the committee to keep members abreast of new developments.</p>



<p class="wp-block-paragraph">The Trump administration created a Unified Coordination Group at the National Security Council to respond to the infiltration.</p>



<p class="wp-block-paragraph">President Joe Biden has tasked the intelligence community to develop a full assessment of the breach.</p>
]]></content:encoded>
	</item>
		<item>
		<title>Hand-to-hand combat on computer networks: How cyber threat hunters work</title>
		<link>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/01/29/hand-to-hand-combat-on-computer-networks-how-cyber-threat-hunters-work/</link>
					<comments>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/01/29/hand-to-hand-combat-on-computer-networks-how-cyber-threat-hunters-work/#respond</comments>
		
		<dc:creator><![CDATA[Mark Pomerleau]]></dc:creator>
		<pubDate>Fri, 29 Jan 2021 18:59:45 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Newsletters]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2021/01/29/hand-to-hand-combat-on-computer-networks-how-cyber-threat-hunters-work/</guid>

					<description><![CDATA[During a major breach, the Department of Defense tasks its elite cyber protection teams to root out hackers.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/newsletters/daily-brief/2021/01/29/hand-to-hand-combat-on-computer-networks-how-cyber-threat-hunters-work/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">24008</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/200521-D-IM742-2001.JPG.jpg" width="1240" height="826" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">WASHINGTON — When hackers break through the Pentagon’s cyber defenses, it’s the job of elite threat-hunting teams to find intruders or damage.</p>



<p class="wp-block-paragraph">Most recently, U.S. Cyber Command deployed cyber teams to check military networks for any signs of a compromise following what some experts and Congress members say is potentially the biggest hack and cyber espionage campaign in U.S. history.</p>



<p class="wp-block-paragraph">The Pentagon has found no evidence thus far that the susceptibility affected Department of Defense’s networks. “Parts of our software supply chain source have disclosed a vulnerability within their systems, but we have no indication that the DoD has been compromised,” said Capt. Katrina Cheesman, a U.S. Cyber Command spokesperson.</p>



<p class="wp-block-paragraph">But the teams are looking for damage nonetheless.</p>



<p class="wp-block-paragraph">While the department doesn’t share many details about how defensive <a href="https://www.c4isrnet.com/cyber/2020/11/06/the-us-air-force-is-using-a-new-cyber-training-platform-to-evolve-defensive-teams/" target=_blank>cyber protection teams</a> do their jobs, one common tactic that threat hunters employ is monitoring networks closely for any strange behavior or actions, such as odd login times or use of unusual software.</p>



<p class="wp-block-paragraph">A network user who takes actions outside of normal daily activity could be a hacker that the defensive team must block out of computer systems, sometimes confronting active trespassers directly to deny access through a kind of virtual hand-to-hand combat.</p>



<p class="wp-block-paragraph">In the latest breach, the U.S. blames Russia for implanting malicious code in software updates provided by government supplier SolarWinds, allowing unprecedented access for months across federal networks.</p>



<p class="wp-block-paragraph">The infiltration went beyond the software vendor, with hackers accessing networks in a variety of ways, The Wall Street Journal reported in a Jan. 29 <a href="https://www.wsj.com/articles/suspected-russian-hack-extends-far-beyond-solarwinds-software-investigators-say-11611921601" target=_blank>article</a> that included a Cybersecurity and Infrastructure Security Agency estimate that 30 percent of affected businesses and government offices did not have a direct link to SolarWinds.</p>



<p class="wp-block-paragraph">To date, Cyber Command’s teams have not been asked to assist breached federal agencies but would do so if authorized, Cheesman said.</p>



<p class="wp-block-paragraph">Cyber protection teams — 68 in total — make up the majority of the Pentagon’s cyber troops, and they’re always in high demand to help with suspicious activity throughout the vast DoD information network. Staff throughout the world use DODIN, a complex collection of thousands of local networks, for everything from sending real-time information to war fighters to storing basic personnel data.</p>



<p class="wp-block-paragraph">While cyber protection teams are the DoD’s defensive frontline, they primarily act as a response force and don’t get involved until an adversary breaches networks, according to a December presentation during an Army conference by one of its cyber units.</p>



<p class="wp-block-paragraph">When a breach occurs, the teams go to the site of the problem with specialized kits including a mix of laptops, small servers, passive and active sensors, analytic capability and software tools.</p>



<p class="wp-block-paragraph">They work with the local IT staff who run networks to understand the unique qualities of a particular network’s day-to-day operations. The teams help search for malicious activity, eradicate any lingering interlopers, and recommend to the local personnel how to rebuild stronger network defenses.</p>



<p class="wp-block-paragraph">Each team has 39 members, but they <a href="https://www.c4isrnet.com/digital-show-dailies/air-force-association/2020/09/17/the-air-force-is-working-on-better-intelligence-integration-for-defensive-cyber/" target=_blank>deploy in smaller elements</a> to spread their expertise and rotate through active operations, regrouping and training.</p>



<p class="wp-block-paragraph">Cyber experts familiar with cyber protection teams’ work described for C4ISRNET how the units would respond to a hypothetical breach, with some experts sharing insights anonymously because they are not authorized to speak publicly about the issue.</p>



<p class="wp-block-paragraph">If CPTs see the actor is still on the network, they will work to kick the hacker off by changing credentials and blocking methods of access like backdoors and then determine what information the actor reached. The teams might have to set up deliberate defense within the network, putting up blockades to disrupt adversaries and force them into certain portions of the network. That improves their ability see hackers’ activity or confront them directly.</p>



<p class="wp-block-paragraph">A team’s first action would likely be to get a handle on the attack vector, determining what machines or network segments run malicious software. From there, commanders prioritize hunting on the highest and most sensitive assets or portions of the network. For example, a system that works with the nuclear command and control infrastructure would be a top priority.</p>



<p class="wp-block-paragraph">Sophisticated network hunters are needed because high-end actors will obfuscate their activity with a variety of tools, such as using credentials and privileges to look like an administrator or legitimate user. CPTs will try to lock out the actors by changing credentials and passwords, a painstaking process of looking at all corners of the network, all legitimate users and credentials.</p>



<p class="wp-block-paragraph">With the latest breach, the actors were so stealthy they succeeded in masking their activity to look like a legitimate user. This is where a hunter has to know network processes inside and out, including what servers are running and what level of system is running those processes. Their forensics process might take them deep into network logs to analyze.</p>



<p class="wp-block-paragraph">These hunters carefully look for the slightest anomalous behavior. That skill is the benefit, many sources said, of training cyber warriors to joint standards to learn offense and defense.</p>



<p class="wp-block-paragraph">“The time that you spent trying to work on a network as an offensive person is going to help you understand where you might want to look defensively,” said Andrew Hall, a retired Army colonel who directed the Army Cyber Institute and teaches cybersecurity at Marymount University. “Now, they might use different techniques than you, so you’re probably not going to find the exact same thing as you, but you think of it from both sides. You think of it as a defender, you think of it as an offensive person.”</p>



<p class="wp-block-paragraph">However, the reach of the recent hack makes it difficult for hunters to know where to look. Given the wide use of the vulnerable software within the government and DoD — and how well the actor stayed hidden — experts have said uncovering the extent of the any damage could take months.</p>
]]></content:encoded>
	</item>
		<item>
		<title>Why create more cyber units when talent might be lacking, wonders senator</title>
		<link>https://one.sightlinemg.com/federaltimes/management/2020/08/05/why-create-more-cyber-units-when-talent-might-be-lacking-wonders-senator/</link>
					<comments>https://one.sightlinemg.com/federaltimes/management/2020/08/05/why-create-more-cyber-units-when-talent-might-be-lacking-wonders-senator/#respond</comments>
		
		<dc:creator><![CDATA[Mark Pomerleau]]></dc:creator>
		<pubDate>Wed, 05 Aug 2020 17:04:32 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[Newsletters]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2020/08/05/why-create-more-cyber-units-when-talent-might-be-lacking-wonders-senator/</guid>

					<description><![CDATA[One senator is concerned that unless the Pentagon retains its top cyber talent, adding more needed cyber teams might not make a difference.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/management/2020/08/05/why-create-more-cyber-units-when-talent-might-be-lacking-wonders-senator/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">16619</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/200619-N-KT462-6060.JPG.jpg" width="4760" height="3384" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">WASHINGTON — Lawmakers and a congressionally mandated commission agree that the Pentagon’s cyber operations force will likely need to <a href="https://www.fifthdomain.com/dod/cybercom/2020/03/05/house-members-worry-if-the-cyber-force-is-the-right-size/" target=_blank>grow to meet burgeoning threats</a>. But one senator is concerned that if the Defense Department can’t attract and retain the necessary talent, then creating more cyber teams will be an exercise in futility.</p>



<p class="wp-block-paragraph">“If you don’t have the access to military targets, adding more cyber units [isn’t] going to accomplish much,” Sen. Joe Manchin, D-W.Va., said during an Aug. 4 hearing with members of the Cyberspace Solarium Commission at the Senate Armed Services Subcommittee on Cybersecurity.</p>



<p class="wp-block-paragraph">The commission is a bipartisan organization created by Congress in the 2019 to develop a multipronged U.S. cyber strategy. Manchin asked the witnesses if they have examined whether U.S. Cyber Command has difficulties recruiting, training and retaining its forces.</p>



<p class="wp-block-paragraph">“Our sense of United States Cyber Command is they’ve done a great job within the authorities that they have of recruiting, training and developing for careers the people necessary to do the work that they do,” responded Chris Inglis, a commission member and a former deputy director of the National Security Agency.</p>



<p class="wp-block-paragraph">Gen. Paul Nakasone, the head of Cyber Command, said during a discussion at an Association of the U.S. Army event in mid-July that the real issue isn’t necessarily training personnel, but “being able to retain our best, not everyone, but our best.”</p>



<p class="wp-block-paragraph">There are a few initiatives in place to accomplish this, the commander added.</p>



<p class="wp-block-paragraph">“First of all, it begins with the mission. If you like to work hard problems, if you like to be in the middle of ensuring the defense of our nation, if you like to work with incredible people and superb technology, being in a place like Cyber Command and NSA is critical,” he said. “But we’ve also been the beneficiaries of a number of different initiatives both by Congress and by our services to make sure that we have a significant amount of enumeration for those forces.”</p>



<p class="wp-block-paragraph">The Senate has backed this approach in its defense policy bill, which <a href="https://www.fifthdomain.com/congress/2020/06/11/senate-committee-wants-more-cyber-pilot-programs/" target=_blank>sought to give Cyber Command the same hiring authority</a> for technical talent as the Defense Advanced Research Projects Agency, the Strategic Capabilities Office and the Joint Artificial Intelligence Center. This would allow Cyber Command to offer more competitive pay.</p>



<p class="wp-block-paragraph">Nakasone also outlined a hiring boom on the civilian side.</p>



<p class="wp-block-paragraph">“Last year we hired over 2,000 people at the National Security Agency,” he explained. “What was interesting: There were a number of different programs upon which we were able to balance that. Whether or not it was developmental programs, whether or not it was outreach to colleges, we were able to fill all of those 2,000 spaces.”</p>



<p class="wp-block-paragraph"><b>Rightsizing the force</b></p>



<p class="wp-block-paragraph">There is broad support for a fresh assessment of Cyber Command’s cyber mission force, which makes up the offensive, defensive, and intelligence/support personnel that perform cyber operations.</p>



<p class="wp-block-paragraph">Designed in late 2012, key members of government are concerned it was designed prior to modern cyberthreats and a rapidly evolving landscape.</p>



<p class="wp-block-paragraph">The Cyberspace Solarium Commission recommended an assessment of this force, which made it into the defense policy bill that must still be reconciled with both houses of Congress.</p>



<p class="wp-block-paragraph">“I am a believer that <a href="https://www.fifthdomain.com/dod/cybercom/2019/05/16/cyber-command-is-decoding-how-to-best-reorganize-teams/" target=_blank>that force needs to grow</a>, and that’s one of the things that we’re involved in right now, is we take a look at the budget and one of the things I’ll be advocating for with the secretary. That’s a work in progress,” Nakasone said last month. “I will certainly be an advocate for looking at broader growth, obviously within the context of what our nation and what our department can afford.”</p>



<p class="wp-block-paragraph">Other commissioners of the solarium project said this assessment will strengthen the nation in cyberspace.</p>



<p class="wp-block-paragraph">“I think over time we will realize that the force structure assessment of the cyber mission force will end up having perhaps the biggest impact on DoD over the next decade if we come back with a finding that suggests that we do not have enough personnel,” Rep. Mike Gallagher, R-Wis., the commission’s co-chair, said before the House Armed Services Committee last week.</p>



<p class="wp-block-paragraph">Former Rep. Patrick Murphy, a commissioner and formerly the undersecretary of the Army, also told the committee last week that the assessment “is the first step to make sure that we get it right to ensure that the [cyber mission force] has appropriately sized forces and is sufficiently capable to achieve its objectives.”</p>



<p class="wp-block-paragraph">Inglis, before the Senate Armed Services Committee on Thursday, also agreed with the need for the assessment, but acknowledged that “we need to also at the same time make sure that we’ve done everything necessary to create a bigger pie from which we can recruit, and once we recruit to focus hard on how do you retain those people.”</p>
]]></content:encoded>
	</item>
	</channel>
</rss>
