<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet media="screen" type="text/xsl" href="https://one.sightlinemg.com/federaltimes/wp-content/themes/smg/assets/xslt/rss-xslt.xml"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
xmlns:news="http://www.pugpig.com/news"
>

<channel>
	<title>Cyber - Federal Times</title>
	<atom:link href="https://one.sightlinemg.com/federaltimes/cyber/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>Federal Times</description>
	<lastBuildDate>Sat, 08 Aug 2026 18:35:20 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://one.sightlinemg.com/wp-content/uploads/2026/06/favicon-fed.png?w=32</url>
	<title>Cyber - Federal Times</title>
	<link></link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">255331619</site><atom:link rel="next" type="application/rss+xml" href="https://one.sightlinemg.com/federaltimes/feed/?paged=2" />
	<item>
		<title>QinetiQ’s American unit agrees to buy software specialist Avantus</title>
		<link>https://one.sightlinemg.com/federaltimes/acquisition/2022/08/09/qinetiqs-american-unit-makes-deal-to-buy-software-specialist-avantus/</link>
					<comments>https://one.sightlinemg.com/federaltimes/acquisition/2022/08/09/qinetiqs-american-unit-makes-deal-to-buy-software-specialist-avantus/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Tue, 09 Aug 2022 18:32:39 +0000</pubDate>
				<category><![CDATA[Cyber]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Procurement]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2022/08/09/qinetiqs-american-unit-makes-deal-to-buy-software-specialist-avantus/</guid>

					<description><![CDATA[“This acquisition is an important step in the execution of QinetiQ’s five-year ambitions to expand our presence in the US,” according to the company’s CEO.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/acquisition/2022/08/09/qinetiqs-american-unit-makes-deal-to-buy-software-specialist-avantus/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">19268</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/5373156.jpg.jpg" width="6720" height="4480" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">WASHINGTON — The U.S. arm of British defense technology company QinetiQ struck a deal to acquire software provider Avantus Federal from NewSpring Holdings for $590 million.</p>



<p class="wp-block-paragraph">“This acquisition is an important step in the execution of QinetiQ’s five-year ambitions to expand our presence in the US, the largest security and defence market in the world,” the company’s CEO, Steve Wadey, said in a statement Aug. 5.</p>



<p class="wp-block-paragraph">The deal would double QinetiQ’s U.S. business, according to the release, and is to be completed by the end of this year, subject to regulatory approvals. A combination of existing cash and new debt facilities are expected to finance the acquisition.</p>



<p class="wp-block-paragraph">QinetiQ was the 64th largest defense firm in 2021, per <a href="https://people.defensenews.com/top-100/" target="_blank">Defense News’ Top 100 list, which ranks companies according to defense revenue</a>. Its total revenue for the fiscal year that ended March 31, 2022, was about £1.32 billion, or $1.8 billion, per the list. According to the company, its revenue has grown for the last five years.</p>



<p class="wp-block-paragraph">Avantus, which was not on the list, brought in $298 million in total revenue in the fiscal year that ended June 30, 2022, and its revenue has grown by double-digit rates over the last three years, according to the release.</p>



<p class="wp-block-paragraph">Founded in 2016 and based in McLean, Virginia, Avantus provides data and cyber services to the departments of Defense and Homeland Security, among other American military and government entities. QinetiQ also provides products and services to the U.S. government.</p>
]]></content:encoded>
	</item>
		<item>
		<title>As US struggles to fill cyber defense jobs, Australia works to keep talent at home</title>
		<link>https://one.sightlinemg.com/federaltimes/cyber/2022/07/20/as-us-struggles-to-fill-cyber-defense-jobs-australia-works-to-keep-talent-at-home/</link>
					<comments>https://one.sightlinemg.com/federaltimes/cyber/2022/07/20/as-us-struggles-to-fill-cyber-defense-jobs-australia-works-to-keep-talent-at-home/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Wed, 20 Jul 2022 21:51:29 +0000</pubDate>
				<category><![CDATA[Cyber]]></category>
		<category><![CDATA[IT & Networks]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2022/07/20/as-us-struggles-to-fill-cyber-defense-jobs-australia-works-to-keep-talent-at-home/</guid>

					<description><![CDATA[Australia's artificial intelligence industry leaders point to a gap in the defense workforce at July 20 summit.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/cyber/2022/07/20/as-us-struggles-to-fill-cyber-defense-jobs-australia-works-to-keep-talent-at-home/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">18945</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/GettyImages-173010176.jpg.jpg" width="4400" height="4000" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">WASHINGTON — While U.S. companies struggle to fill cybersecurity and artificial intelligence positions, Australia has too few jobs to keep its talent at home, leaving it vulnerable in an increasingly hostile cyber environment, defense industry leaders said.</p>



<p class="wp-block-paragraph">Australia is investing millions of dollars into research and development to close gaps in the country’s cyber defense apparatus, they told the Australian Defence Science, Technology and Research Summit in Sydney on June 20.</p>



<p class="wp-block-paragraph">And while the talent pool for workers with for AI and machine learning in Australia is deep, Anton van den Hengel, director of the Centre for Augmented Reasoning at the Australian Institute for Machine Learning, said their are simply not enough jobs and career opportunities in the country to keep them at home.</p>



<p class="wp-block-paragraph">“We’ve made very little — very little — progress towards artificial intelligence,” he said.</p>



<p class="wp-block-paragraph">The U.S. faces a critical cyber labor shortage, with some 700,000 cybersecurity positions open nationwide, according to <a href="https://www.whitehouse.gov/briefing-room/statements-releases/2022/07/18/announcement-of-white-house-national-cyber-workforce-and-education-summit/" target="_blank">estimates</a> from the White House. More than 35,000 job openings are currently posted on the Indeed hiring wesbite using the search term “Artificial Intelligence.”</p>



<p class="wp-block-paragraph">Van den Hengel, who also works as a director of applied science at Amazon, and other industry leaders at the summit pointed to the government’s inability to compete with tech companies as a major issue when expanding the country’s AI abilities. In both the U.S. and Australia, governments come up against the draw of private industry, creating high salary costs and other the hurdles to attracting and retaining talent.</p>



<p class="wp-block-paragraph">“Defense no longer has the best tech,” he said, noting that private companies have committed billions of dollars to develop technologies and have the open positions to attract workers in the AI field.</p>



<p class="wp-block-paragraph">The Defence Science and Technology Group, a part of the Australian defense department aimed at providing science and technology support to national security interests, hosted the summit.</p>



<h1 class="wp-block-heading">Private-sector competition intensifies for AI talent</h1>



<p class="wp-block-paragraph">With high salaries and access to breaking-edge technologies, the private AI field has become increasingly lucrative. In recent years, many western counties, including the U.S., have turned to the private sector to compete with investments made by China.</p>



<p class="wp-block-paragraph">Van den Hengel said outsourcing to the private sector only goes so far. Governments have to try and keep track of the technologies coming out of companies while also trying to understand them deeply enough to figure out their defense applications, he said.</p>



<p class="wp-block-paragraph">In November, the Australian government <a href="https://www.minister.defence.gov.au/minister/melissa-price/media-releases/10-million-build-defences-ai-capability-and-support-critical#:~:text=%2410%20MILLION%20TO%20BUILD%20DEFENCE'S%20AI%20CAPABILITY%20AND%20SUPPORT%20CRITICAL%20TECH%20FOR%20AUSTRALIA,-18%20November%202021&#038;text=The%20Morrison%20Government%20is%20investing,jobs%20in%20Australia's%20defence%20industry." target="_blank">said</a> it would invest $10 million in innovative AI tech. The move followed the September <a href="https://www.defensenews.com/global/asia-pacific/2021/09/17/what-are-the-regional-reactions-to-the-new-us-uk-australia-security-pact/" target="_blank">announcement</a> that Australia would partner with Britain and U.S. in a new working group, known by the acronym AUKUS, to share advanced technologies, including AI.</p>



<p class="wp-block-paragraph">Kate Devitt, the chief scientist of Trusted Autonomous Systems, said Australia specifically needs experts in the field of deep learning and natural language processing compared to companies such as Google and Meta as well as specialists in reinforcement learning.</p>



<p class="wp-block-paragraph">“We lack the digital infrastructure and investment required to enable the human capital with these skills to flourish in universities,” she said. “These gaps make Australia vulnerable and dependent on the choices of our allies and our rivals.”</p>



<p class="wp-block-paragraph">Trusted Autonomous Systems is Australia’s first defense cooperative research center. It partners the country’s defense industry and research organizations with Australia’s defense department to develop autonomous and robotic technology.</p>



<p class="wp-block-paragraph">While Devitt said the “obvious” answer is more investment in technical AI capabilities and infrastructure, she said that Australia needs to be decisive in its investments. As a medium-sized country, the government must use its limited resources to make “scrappy” decisions that yield outsized impacts, she said.</p>
]]></content:encoded>
	</item>
		<item>
		<title>Cybersecurity for critical infrastructure approved in $840 billion defense bill</title>
		<link>https://one.sightlinemg.com/federaltimes/federal-oversight/2022/07/19/cyber-defense-for-critical-infrastructure-approved-by-house/</link>
					<comments>https://one.sightlinemg.com/federaltimes/federal-oversight/2022/07/19/cyber-defense-for-critical-infrastructure-approved-by-house/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Tue, 19 Jul 2022 13:32:22 +0000</pubDate>
				<category><![CDATA[Cyber]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[IT & Networks]]></category>
		<category><![CDATA[Oversight]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2022/07/19/cyber-defense-for-critical-infrastructure-approved-by-house/</guid>

					<description><![CDATA[“In the nearly 22 years that I’ve served in Congress, we have come a long way in cyberspace,” said Rep. Jim Langevin, D-R.I.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/federal-oversight/2022/07/19/cyber-defense-for-critical-infrastructure-approved-by-house/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">26560</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/AP21130690330119.jpg.jpg" width="6000" height="4000" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">WASHINGTON — The U.S. House passed its $840 billion version of the annual defense policy bill, including a provision to identify and better secure critical infrastructure at most risk of cyberattack.</p>



<p class="wp-block-paragraph">The measure, championed by <a href="https://www.c4isrnet.com/battlefield-tech/c2-comms/2022/06/08/house-cyber-panel-seeks-review-of-delayed-air-force-link-16-upgrade/" target="_blank">retiring Rep. Jim Langevin</a>, a Rhode Island Democrat, would designate certain critical infrastructure entities as “systemically important” for the wellbeing of the U.S. and establish new avenues for information sharing, risk management disclosures and rapid responses to digital intrusions, among other steps.</p>



<p class="wp-block-paragraph">“In the nearly 22 years that I’ve served in Congress, we have come a long way in cyberspace,” Langevin said in a statement following the 329-101 House vote. “When I was elected in 2000, nobody was talking about cybersecurity.”</p>



<p class="wp-block-paragraph">As many as 200 entities could initially be named, <a href="https://armedservices.house.gov/_cache/files/e/5/e50a0100-521c-4e1b-8817-faa3e64b110b/0DF5D2AD1AA2D0B33ACB6B51CE88566C.fy23ndaaamendmenttracker-12-20220714-1823.pdf" target="_blank">according to the language of the measure</a>, with room for 150% more in four years. Entities could appeal placement on the list.</p>



<p class="wp-block-paragraph">The vast majority of stateside critical infrastructure is stewarded by the private sector, with assets ranging from communications to chemicals, dams to the defense industrial base. Their destruction would debilitate U.S. economic security, public health and safety, according to the Cybersecurity and Infrastructure Security Agency.</p>



<p class="wp-block-paragraph">Russia’s February <a href="https://www.c4isrnet.com/electronic-warfare/2022/05/19/ukrainian-troops-training-with-us-electronic-jamming-kit/" target="_blank">invasion of Ukraine</a> trained a spotlight on critical infrastructure and related digital vulnerabilities.</p>



<p class="wp-block-paragraph">Lawmakers and analysts warned of potential cyberattacks on American assets — physical and virtual — and CISA issued a so-called Shields Up notice, urging heightened online awareness. The longer the Russia-Ukraine war grinds on, the more likely Moscow will act belligerently in cyberspace, according to<a href="https://www.airforcetimes.com/cyber/2022/06/17/prolonged-war-may-make-russia-more-cyber-aggressive-us-official-says/?contentQuery=%7B%22section%22%3A%22%2Fhome%22%2C%22exclude%22%3A%22%2Fcyber%22%2C%22from%22%3A285%2C%22size%22%3A10%7D&#038;contentFeatureId=f0fmoahPVC2AbfL-2-1-8" target="_blank"> Neal Higgins</a>, deputy national cyber director for national cybersecurity.</p>



<p class="wp-block-paragraph">The measure included in the House’s defense policy package is an offshoot of work done by the Cyberspace Solarium Commission, a bipartisan group assembled to analyze and improve U.S. cybersecurity. Its flagship report, published in 2020, included a recommendation that Congress codify systemically important critical infrastructure, also known as SICI.</p>



<p class="wp-block-paragraph">“Both the private sector and the U.S. government have a vested interest in protecting these systems and assets and have unique responsibilities for their security and resilience,” <a href="https://www.solarium.gov/report" target="_blank">the report stated</a>.</p>



<p class="wp-block-paragraph">Langevin was a member of the commission.</p>
]]></content:encoded>
	</item>
		<item>
		<title>Troops’ use of TikTok may be national security threat, FCC commissioner says</title>
		<link>https://one.sightlinemg.com/federaltimes/it-networks/2022/07/14/troops-use-of-tiktok-may-be-national-security-threat-fcc-commissioner-says/</link>
					<comments>https://one.sightlinemg.com/federaltimes/it-networks/2022/07/14/troops-use-of-tiktok-may-be-national-security-threat-fcc-commissioner-says/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Thu, 14 Jul 2022 21:22:08 +0000</pubDate>
				<category><![CDATA[Cyber]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[IT & Networks]]></category>
		<category><![CDATA[Oversight]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2022/07/14/troops-use-of-tiktok-may-be-national-security-threat-fcc-commissioner-says/</guid>

					<description><![CDATA[A U.S. regulator says troops' and families' use of TikTok on personal devices could pose a national security threat.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/it-networks/2022/07/14/troops-use-of-tiktok-may-be-national-security-threat-fcc-commissioner-says/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">29659</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/Tik1.jpg.jpg" width="1500" height="1052" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Troops and family members could be jeopardizing national security with their use of the TikTok video-sharing app, a U.S. regulator told lawmakers.</p>



<p class="wp-block-paragraph">While the military services have banned the use of TikTok from government devices, troops and family members do use the app on personal devices.</p>



<p class="wp-block-paragraph">TikTok is owned by the Beijing-based ByteDance, said Brendan Carr, the senior Republican on the Federal Communications Commission. And he’s concerned about the amount of non-public sensitive data Americans upload that could be <a href="https://www.militarytimes.com/news/your-military/2019/11/04/concerns-rise-over-possibility-chinese-could-use-tiktok-to-collect-troops-data/" target="_blank">flowing into the hands of the Chinese government. </a></p>



<p class="wp-block-paragraph">TikTok has grown in popularity in the military community. For example, troops often upload videos of barracks, military equipment and maneuvers, Carr said in testimony Wednesday before the House Oversight Committee’s panel on national security.</p>



<p class="wp-block-paragraph">“With TikTok, this is a device right in your pocket. It’s going inside the military installation, looking at location data, which can give people information on troop movements,” Carr said. “There’s a range of ways that that sensitive data going back to Beijing with their sophisticated [artificial intelligence] can ultimately be used to harm U.S. national security.”</p>



<p class="wp-block-paragraph">The hearing was held to explore financial fraud targeting service members and veterans. The threats to active duty and veterans come from a variety of sources, according to Carr, and many of the frauds seen on other online platforms are also perpetrated on TikTok. But there are unique national security concerns when it comes to this video-sharing app.</p>



<p class="wp-block-paragraph">“TikTok has engaged in a pattern of misrepresentation regarding both the amount and extent of data it’s collected as well as how much has been accessed from inside China,” Carr said.</p>



<p class="wp-block-paragraph">He cited a recent <a href="https://www.buzzfeednews.com/article/emilybakerwhite/tiktok-tapes-us-user-data-china-bytedance-access" target="_blank">BuzzFeed News report of leaked audio from 80 internal TikTok meetings</a> that showed China has repeatedly accessed Americans’ user data.</p>



<p class="wp-block-paragraph">“The flow of this non-public sensitive data into China is particularly troubling given the [People’s Republic of China’s] track record of engaging in espionage and other nefarious acts,” Carr said.</p>



<p class="wp-block-paragraph">“At its core, TikTok functions as a sophisticated surveillance tool that harvests extensive amounts of sensitive data from search and browsing history, keystroke patterns, location data, and biometrics including face prints and voice prints,” Carr added. “All of the concerns with TikTok are heightened in the military context.”</p>



<p class="wp-block-paragraph">Rep. Glenn Grothman, R-Wisc., proposed that the military should be proactively urging troops to not use the app.</p>



<p class="wp-block-paragraph">“Should the military be doing more to tell our members to stay off of TikTok?” he asked.</p>



<p class="wp-block-paragraph">The federal government should be doing more, Carr said. The government “should address the continued use of TikTok on military installations, as well as any use that depicts U.S. military operations,” he added.</p>



<p class="wp-block-paragraph">Ongoing national security reviews of TikTok, currently being conducted by officials in the Treasure and Commerce departments, should be finished soon, according to Carr.</p>



<p class="wp-block-paragraph">Leaders of the Senate Select Committee on Intelligence, chairman Sen. Mark Warner, D-Va., and vice chairman Sen. Marco Rubio, R-Fl., called on the Federal Trade Commission in a July 5 letter to initiate an investigation of TikTok.</p>



<p class="wp-block-paragraph">In light of reports about the Chinese government’s access to the data, they wrote, the FTC should immediately launch an investigation “on the basis of apparent deception by TikTok, and coordinate this work with any national security or counter-intelligence investigation that may be initiated by the U.S. Department of Justice.”</p>



<p class="wp-block-paragraph">Carr has also called on Google and Apple to remove TikTok from their app stores. In a July 5 blog, a TikTok official addressed the company’s approach to keeping U.S. data secure.</p>



<p class="wp-block-paragraph">“The security of the data our community entrusts us with is a top priority at TikTok, despite recent reports questioning that commitment,” wrote Michael Beckerman, TikTok’s head of public policy for the Americas.</p>



<p class="wp-block-paragraph">TikTok recently stood up a new U.S. data security division “to bring heightened focus and governance to our ongoing efforts to strengthen our data protection policies and protocols, further protect our users, and build confidence in our systems and controls in the United States,” he stated.</p>



<p class="wp-block-paragraph">The creation of that division was an important milestone in the goals they previously laid out, he said: “minimizing access to U.S. user data and minimizing data transfers across regions – including to China.”</p>
]]></content:encoded>
	</item>
		<item>
		<title>UN stresses strategic communications to combat disinformation ‘weapon of war’</title>
		<link>https://one.sightlinemg.com/federaltimes/cyber/2022/07/13/un-stresses-strategic-communications-to-combat-disinformation-weapon-of-war/</link>
					<comments>https://one.sightlinemg.com/federaltimes/cyber/2022/07/13/un-stresses-strategic-communications-to-combat-disinformation-weapon-of-war/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Wed, 13 Jul 2022 14:13:29 +0000</pubDate>
				<category><![CDATA[Cyber]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[IT & Networks]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2022/07/13/un-stresses-strategic-communications-to-combat-disinformation-weapon-of-war/</guid>

					<description><![CDATA[U.N. Secretary-General Antonio Guterres told the council that the world in which peacekeepers operate "is more hazardous today than any time in recent memory," with geopolitical tensions reverberating locally and conflicts "more complex and multi-layered."]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/cyber/2022/07/13/un-stresses-strategic-communications-to-combat-disinformation-weapon-of-war/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">23946</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/AP22031558740921.jpg.jpg" width="5760" height="3840" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">The U.N. Security Council said Tuesday that more needs to be done to counter disinformation and misinformation about the U.N.’s 12 peacekeeping operations, which have faced growing attacks especially on social media.</p>



<p class="wp-block-paragraph">A Brazilian-drafted presidential statement approved by all 15 council members said the U.N. must “improve the culture of strategic communications across civilian, military and police components” of peacekeeping missions in order to protect civilians — a key mandate for the U.N.’s 90,000 peacekeepers in Africa, the Middle East, Asia and Europe.</p>



<p class="wp-block-paragraph">The council noted “with great concern the increasing amount of disinformation and misinformation directed against United Nations peacekeeping operations, which may negatively impact missions and peacekeepers.”</p>



<p class="wp-block-paragraph">Brazilian Foreign Minister Carlos França, whose country holds the council presidency this month and chaired Tuesday’s meeting, said that “strategic communications are essential for a successful peacekeeping operation.”</p>



<p class="wp-block-paragraph">U.N. Secretary-General Antonio Guterres told the council that the world in which peacekeepers operate “is more hazardous today than any time in recent memory,” with geopolitical tensions reverberating locally and conflicts “more complex and multi-layered.”</p>



<p class="wp-block-paragraph">“Peacekeepers are facing terrorists, criminals, armed groups and their allies — many with access to powerful modern weapons, and many with a vested interest in perpetuating the chaos in which they thrive,” the U.N. chief said.</p>



<p class="wp-block-paragraph">But, he added, “The weapons they wield are not just guns and explosives. Misinformation, disinformation, and hate speech are increasingly being used as a weapon of war.”</p>



<p class="wp-block-paragraph">Guterres said a recent survey found that nearly half of all U.N. peacekeepers feel misinformation and disinformation severely affect their work and threaten their safety and security.</p>



<p class="wp-block-paragraph">As an example of false information spreading “like wildfire,” Guterres said a fake letter alleging that U.N. peacekeepers in Mali were collaborating with armed groups “went viral on WhatsApp and was picked up by national media.” It stirred up hostility and resentment against peacekeepers and made their efforts to protect civilians even harder, he said.</p>



<p class="wp-block-paragraph">Lt. Gen. Marcos Da Costa, commander of the peacekeeping force in Congo, told the council that it operates in a country where successive surveys find “an overall poor perception” among the population about the mission’s relevance in improving their security.</p>



<p class="wp-block-paragraph">“Anti-mission sentiment prevails in certain parts of the country that even prevent some of our deployments,” he said. “Unfair speeches by several actors against the mission put in risk the safety of our peacekeepers. The extensive use of social media by armed groups and other spoilers undermines the confidence in the U.N.”</p>



<p class="wp-block-paragraph">He said these armed militias “use regular information warfare techniques” and their fake news diffusing through messaging and social media is difficult to distinguish from reality.</p>



<p class="wp-block-paragraph">“These emerging technologies are driving a fundamental change to the character of the war, and peace operations are already being affected,” Da Costa said.</p>



<p class="wp-block-paragraph">Guterres said the U.N. is moving to improve communications in peacekeeping operations between uniformed and civilian personnel, seek military and police officers skilled in communicating, and work with tech and media companies and member states to collect and share best practices.</p>
]]></content:encoded>
	</item>
		<item>
		<title>National Guardsmen may soon use personal electronics in deployments</title>
		<link>https://one.sightlinemg.com/federaltimes/it-networks/2022/06/28/national-guardsmen-may-soon-use-personal-electronics-in-deployments/</link>
					<comments>https://one.sightlinemg.com/federaltimes/it-networks/2022/06/28/national-guardsmen-may-soon-use-personal-electronics-in-deployments/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Tue, 28 Jun 2022 20:20:54 +0000</pubDate>
				<category><![CDATA[Cyber]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[IT & Networks]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2022/06/28/national-guardsmen-may-soon-use-personal-electronics-in-deployments/</guid>

					<description><![CDATA[“Bring Your Own Approved Device” initiative would allow guardsmen to use personal mobile equipment to perform the same functions in the field that they would otherwise carry out at a desktop in their offices.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/it-networks/2022/06/28/national-guardsmen-may-soon-use-personal-electronics-in-deployments/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">32260</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/AP21116836146190.jpg.jpg" width="5062" height="3375" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">WASHINGTON — National Guardsmen may soon be able to use their personal electronic devices for official functions during domestic deployments to help fill a resources gap and reduce mobilization time, according to the service’s chief information officer.</p>



<p class="wp-block-paragraph">Speaking during a <a href="https://events.c4isrnet.com/office-hours-crisis-communications/" target="_blank">C4ISRNET </a>webcast, Kenneth McNeill said an initiative called “Bring Your Own Approved Device” would allow guardsmen to use personal mobile equipment to perform the same functions in the field that they would otherwise carry out at a desktop in their offices.</p>



<p class="wp-block-paragraph">“In a typical state, all of our guardsmen, unfortunately, they may not have government-furnished devices — mobile cellphones, iPads,” McNeill said. “It cuts down on time when we’re planning for a mobilization.”</p>



<p class="wp-block-paragraph">The initiative, which is a collaboration with the Department of the Army and the Pentagon’s cybersecurity office, is in its third phase of a pilot program consisting of a yearlong trial with the largest sample size to date. After this trial, if deemed successful, the initiative will be enacted, McNeill said.</p>



<p class="wp-block-paragraph">Work began on the initiative before the pandemic, which drove a transition to remote work. The realities of the situation forced the Guard to accelerate its efforts.</p>



<p class="wp-block-paragraph">“This is another tool in the toolkit that will give us an opportunity to allow our workforce, even after the pandemic, to continue to telework and [perform] remote work that is critical in the National Guard,” McNeill said. “I don’t think we’re going back [to] everyone in the office. I think this is the future of how we’re going to operate here in the government and in the Department of Defense.”</p>



<p class="wp-block-paragraph">While deployed to the streets of Washington, D.C., following the Jan. 6 insurrection on the Capitol, the National Guard employed a similar capability called Commercial Virtual Remote to carry out the mission that was limited in scope and time.</p>



<p class="wp-block-paragraph">“Now we will have a capability that really links our force, even before they are called up for deployment,” he said. “This will be a game-changer.”</p>



<h2 class="wp-block-heading">JADC2</h2>



<p class="wp-block-paragraph">McNeill also discussed an addition to the Joint All-Domain Command and Control concept being implemented by the DoD that would focus on the needs of the National Guard’s mission set. Called “Project Homeland,” the initiative would apply the same capabilities of JADC2 to the domestic front.</p>



<p class="wp-block-paragraph">JADC2 is a project by the Department of Defense to connect all the sensors from the individual services and compile data collected into a single information network. Previously, each service had their own tactical networks that were unable to interface with each other.</p>



<p class="wp-block-paragraph">“JADC2 is a warfighting necessity to keep pace with the volume and complexity of data in modern warfare and to defeat adversaries decisively,” the department said in a statement. “JADC2 enables the Joint Force to ‘sense,’ ‘make sense,’ and ‘act’ on information across the battle-space quickly using automation, artificial intelligence (AI), predictive analytics, and machine learning to deliver informed solutions via a resilient and robust network environment.”</p>



<p class="wp-block-paragraph">Project Homeland would apply those same capabilities during domestic deployments across the 54 states and territories National Guard units and their civilian interagency partners as opposed to the military services and their coalition forces.</p>



<p class="wp-block-paragraph">McNeill spoke to the challenges the National Guard faced during their humanitarian relief operations post Hurricane Katrina. On the ground, the Guard was unable to talk with the local first responders because they did not have cross-banding communication systems.</p>



<p class="wp-block-paragraph">“We learned from that experience that we’ve got to think out of the box,” McNeill said. “We’ve got to look at capabilities that can talk to first responders and focus on what we do in the homeland.”</p>
]]></content:encoded>
	</item>
		<item>
		<title>Six proven steps to Zero Trust</title>
		<link>https://one.sightlinemg.com/federaltimes/opinions/2022/06/28/six-proven-steps-to-zero-trust/</link>
					<comments>https://one.sightlinemg.com/federaltimes/opinions/2022/06/28/six-proven-steps-to-zero-trust/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Tue, 28 Jun 2022 18:38:51 +0000</pubDate>
				<category><![CDATA[Cyber]]></category>
		<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[IT & Networks]]></category>
		<category><![CDATA[Newsletters]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2022/06/28/six-proven-steps-to-zero-trust/</guid>

					<description><![CDATA[Agency leaders are working to adopt the mindset of trust nothing and verify everything to prioritize the transformation of legacy systems.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/opinions/2022/06/28/six-proven-steps-to-zero-trust/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">16551</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/Cybersecurity-shield.jpg.jpg" width="5833" height="4167" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">First, it was the attack on SolarWinds, then the Colonial Pipeline, and most recently, Log4j. Unfortunately, these successful and very public cyber exploits weren’t the first, and they certainly won’t be the last.</p>



<p class="wp-block-paragraph">Federal leaders are no longer surprised when attackers identify the next crack in the dam. That doesn’t mean they can sit complacently by and wait.</p>



<p class="wp-block-paragraph">The onset of COVID-19 and the shift to hybrid work expedited the need for government agencies to reevaluate how best to utilize their limited resources to plug the unfilled holes. The need to fast-track remote access has led to the recent adoption, emphasis on, and implementation of Zero Trust innovations.</p>



<p class="wp-block-paragraph">White House <a href="https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/">Executive Order 14028</a> on May 12, 2021, made ZT architecture central to the federal security landscape, required agencies to develop new standards that could better prevent cyber incidents, and mandated the transformation of government systems into more secure digital infrastructures.</p>



<p class="wp-block-paragraph">Since then, the Office of Management and Budget released its <a href="https://www.whitehouse.gov/omb/briefing-room/2022/01/26/office-of-management-and-budget-releases-federal-strategy-to-move-the-u-s-government-towards-a-zero-trust-architecture/">federal strategy</a> in January, and the Cybersecurity and Infrastructure Security Agency issued its latest <a href="https://www.cisa.gov/sites/default/files/publications/Zero_Trust_Principles_Enterprise_Mobility_For_Public_Comment_508C.pdf">ZT guidance</a> for agencies this March.</p>



<p class="wp-block-paragraph">While guidance abounds, there are many steps required to implement federal efforts to identify, detect, deter, prevent and respond to these ever-evolving threats. Agency leaders are working to adopt the mindset of trust nothing and verify everything to prioritize the transformation of legacy systems.</p>



<p class="wp-block-paragraph">The General Service Administration is supporting the implementation phase with plans to issue ZT <a href="https://www.meritalk.com/articles/gsa-sees-zero-trust-implementation-playbooks-coming-soon/">playbooks </a>this year. These roadmaps will help operationalize the ZT strategies required by the EO and recently submitted by each federal agency.</p>



<p class="wp-block-paragraph">So, what should these playbooks contain? First, they should define the key tenets of ZT. Second, playbooks need actionable and proven guidelines that go beyond top-line EO-driven agency strategies to guide adoption in six key steps.</p>



<h2 class="wp-block-heading">Define Key Tenets of ZT</h2>



<p class="wp-block-paragraph">For starters, ZT is not a destination but rather an ongoing journey. It optimizes and improves security by increasing levels of automation, refining access to data and making sound decisions based on policies and risk. It includes six key tenets that leaders must fully understand to drive implementation. These key tenets include:</p>



<p class="wp-block-paragraph"><b>Identities</b>: people, services and internet-of-things components</p>



<p class="wp-block-paragraph"><b>Devices</b>: monitoring and enforcing device health and compliance</p>



<p class="wp-block-paragraph"><b>Apps and Services</b>: ensuring appropriate permissions and secure configurations</p>



<p class="wp-block-paragraph"><b>Data</b>: giving the necessary attributes and encryption to safeguard out in the open</p>



<p class="wp-block-paragraph"><b>Infrastructure</b>: hardening against attacks on-premises or in the cloud</p>



<p class="wp-block-paragraph"><b>Networks</b>: establishing controls to segment, monitor, analyze and encrypt end-to-end traffic</p>



<h2 class="wp-block-heading"><b>Implementing Trust Resilience</b></h2>



<p class="wp-block-paragraph">Agencies can benefit from proven strategies poised to tackle EO ZT requirements in actionable bites and implement a “trust resilience framework” in six key steps.</p>



<ul class="wp-block-list"><li><u><b>Establish a ZT Accelerator.</b></u><b> </b>Assess current plans to understand the operating environment of basic ZT tenets and create a strategic roadmap.</li><li><u><b>Build a Risk Management Framework (RMF).</b></u><b> </b>RMF as a service coupled with continuous authorization to operate (ATO) can be pre-packaged to meet the National Institute of Standards and Technology (NIST) framework.</li><li><u><b>Ensure Continuous ATO.</b></u><b> </b>Give the highest level of assurance for existing systems to pass annual audits.</li><li><u><b>Secure Cloud Infrastructure.</b></u><b> </b>Ensure the technology stack is designed on ZT principles.</li><li><u><b>Secure Access Service Edge (SASE</b></u><b>). </b> Ensures authorized users have access anytime anywhere</li><li><u><b>Enterprise IT Support</b></u><b>: </b>Provide as-a-service delivery of the previous four items (2-5)</li></ul>



<p class="wp-block-paragraph">The transition to, and implementation of, ZT across the federal government will be challenging, but is of the utmost importance. Transformation will require experienced people who know how to interpret the technologies implemented and understand that every arm of government operates at a different pace.</p>



<p class="wp-block-paragraph">Enhanced collaboration with private industry will go a long way in supporting the federal government throughout the adoption process and into the future. Best practices stand ready to support agencies as they build the tailored, specialized and playbook-aligned approaches necessary to meet the nation’s cyber threats.</p>



<p class="wp-block-paragraph"><i>Shawn Kingsberry is Vice President, Cybersecurity at SAIC</i></p>



<h2 class="wp-block-heading">Have an opinion?</h2>



<p class="wp-block-paragraph"><i>This article is an Op-Ed and as such, the opinions expressed are those of the authors. If you would like to respond, or have an editorial of your own you would like to submit, please </i><a href="https://mail.google.com/mail/?view=cm&#038;fs=1&#038;tf=1&#038;to=cary.oreilly@C4ISRNET.com"><i>email C4ISRNET Senior Managing Editor Cary O’Reilly</i></a><i>.</i></p>



<p class="wp-block-paragraph"><i>Want more perspectives like this sent straight to you? </i><a href="https://link.militarytimes.com/join/5b9/sign-up-opinion"><i>Subscribe to get our Commentary &amp; Opinion newsletter</i></a><i> once a week.</i></p>
]]></content:encoded>
	</item>
		<item>
		<title>US must prepare for proliferation of cyber warfare</title>
		<link>https://one.sightlinemg.com/federaltimes/it-networks/2022/06/24/us-must-prepare-for-proliferation-of-cyber-warfare/</link>
					<comments>https://one.sightlinemg.com/federaltimes/it-networks/2022/06/24/us-must-prepare-for-proliferation-of-cyber-warfare/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Fri, 24 Jun 2022 11:51:10 +0000</pubDate>
				<category><![CDATA[Cyber]]></category>
		<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[IT & Networks]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2022/06/24/us-must-prepare-for-proliferation-of-cyber-warfare/</guid>

					<description><![CDATA[To build cyber resilience in this heightened threat environment, agencies must work closely with both international counterparts and industry to align on a proactive, global approach to all cyber threats –– not just state-sponsored attacks.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/it-networks/2022/06/24/us-must-prepare-for-proliferation-of-cyber-warfare/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">19318</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/63801881.jpg.jpg" width="6000" height="4000" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Urgent calls from the Biden administration to strengthen cyber defenses amid the Ukraine crisis and overall heightened threat environment underscore the growing concern over the impact a cyber incident would have on U.S. networks and critical infrastructure.</p>



<p class="wp-block-paragraph">This year’s <a href="https://www.whitehouse.gov/briefing-room/legislation/2022/03/15/bill-signed-h-r-2471/">$1.5 trillion omnibus spending package</a> includes an <a href="https://www.cisa.gov/news/2022/03/11/statement-cisa-director-easterly-passage-cyber-incident-reporting-legislation">unprecedented budget increase</a> for the Cybersecurity and Infrastructure Security Agency, as well as tightened cyber incident reporting requirements for sectors like transportation and energy.</p>



<p class="wp-block-paragraph">To build cyber resilience in this heightened threat environment, agencies must work closely with both international counterparts and industry to align on a proactive, global approach to all cyber threats –– not just state-sponsored attacks. That means understanding the threat landscape, shoring up critical infrastructure and developing a plan to coordinate well before attacks happen.</p>



<p class="wp-block-paragraph"><b>Understanding an increasingly turbulent cyber threat landscape</b></p>



<p class="wp-block-paragraph">In general, the massive state-sponsored cyberattacks many analysts expected on critical infrastructure in Ukraine and elsewhere have yet to materialize. Still, the conflict has given rise to a <a href="https://www.nbcnews.com/tech/security/hacktivists-new-veteran-target-russia-one-cybers-oldest-tools-rcna20652">complex and shadowy landscape</a> of citizen cyber hacktivists, vigilantes and criminal groups taking advantage of the crisis to steal money and working as potential proxies for state actors.</p>



<p class="wp-block-paragraph"><a href="https://www.fortinet.com/blog/threat-research/bad-actors-capitalize-current-events-email-scams">Chatter within ransomware groups</a> indicates some threat actors are siding with Russia, some with the West and some are simply using the theater of war as a smokescreen to facilitate cybercrime. FortiGuard Labs researchers also identified email <a href="https://www.fortinet.com/blog/threat-research/bad-actors-capitalize-current-events-email-scams">phishing scams</a> perpetrated by opportunistic criminals posing as trusted organizations like the United Nations to fraudulently solicit donations and potentially infect devices.</p>



<p class="wp-block-paragraph">History shows the potential for outsized impact when the tools of cyber conflict inevitably proliferate. In 2017, for example, the <a href="https://www.fortinet.com/blog/industry-trends/analyzing-the-history-of-ransomware-across-industries">NotPetya</a> ransomware initially was launched in the update servers for accounting software in Ukraine but quickly and predictably spread worldwide, affecting even large and well-prepared firms and causing an estimated <a href="https://www.apextechservices.com/topics/articles/435235-notpetya-worlds-first-10-billion-malware.htm">$10 billion</a> in damage.</p>



<p class="wp-block-paragraph">Many analysts believe that despite having some of the surface charactaristics of ransomware, NotPetya was intended from the outset to be destructive, rather than a tool for criminal profit. And as the conflict in Ukraine continues, threat researchers are encountering increasing amounts of “wiperware”––malicious software designed to disrupt operations or delete data.</p>



<p class="wp-block-paragraph"><b>Shoring up critical infrastructure</b></p>



<p class="wp-block-paragraph">Within the United States, new investments in cybersecurity from both the omnibus bill and the <a href="https://www.whitehouse.gov/briefing-room/statements-releases/2021/08/02/updated-fact-sheet-bipartisan-infrastructure-investment-and-jobs-act/">Infrastructure Investment and Job Act</a> offer a unique opportunity to help mitigate the risk of both state-sponsored and criminal cyberattacks on critical infrastructure.</p>



<p class="wp-block-paragraph">Recent <a href="https://www.cisa.gov/control-systems-goals-and-objectives">CISA guidance</a> emphasizes the vital importance of including cybersecurity in the design of new infrastructure projects, regardless of the sector or the size of the organization. This is where national cybersecurity becomes a state and local issue as well. <a href="https://statescoop.com/state-local-cyber-grant-program-summer-cisa/">This summer,</a> CISA is expected to issue guidelines to help mayors and governors utilize the law’s $1 billion cyber grant program dedicated to building cyber maturity at the state and local level. However, if we spent only $1 billion on cybersecurity out of a $1.2 trillion total, we would be woefully underinvesting in cybersecurity and resilience.</p>



<p class="wp-block-paragraph">For those state and local governments, it’s better to build in cyber protocols now as the infrastructure upgrades are being planned and implemented than trying to chase down vulnerabilities as they’re being exploited.</p>



<p class="wp-block-paragraph"><b>Coordinating across borders and sectors</b></p>



<p class="wp-block-paragraph">In addition to fortifying our defenses domestically, slowing the success of malicious cyber actors will require robust cooperation beyond our borders, as well collaboration with the private sector.</p>



<p class="wp-block-paragraph">That means more information sharing before, during and after attacks. President Biden even went so far as to write guidelines into his 2021 cyber <a href="https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/">executive order</a>, ensuring that IT services providers be able to share information with the government as a whole and require them to share certain breach information. And the recently enacted <a href="https://www.cisa.gov/circia">Cyber Incident Reporting for Critical Infrastructure Act</a> requires that critical infrastructure providers notify CISA of any significant cyber incident within 72 hours or any ransomware payment within 24 hours.</p>



<p class="wp-block-paragraph">Internationally, governments and the private sector should be aligning cyber defense and mitigation playbooks among NATO allies—a critical first step to mitigate the risk of burgeoning threats. Beyond that, multilateral organizations such as the <a href="https://www.fortinet.com/ru/corporate/about-us/newsroom/press-releases/2019/fortinet-serves-as-a-founding-partner-of-world-economic-forum-s-">World Economic Forum Centre for Cybersecurity</a> could convene global public-private partnerships to encourage information-sharing and the development of cyber norms.</p>



<p class="wp-block-paragraph">This is just a taste of what we’ll need to do in the coming months and years, but it’s a good start.</p>



<p class="wp-block-paragraph">Delivering more effective cybersecurity to protect our nation’s networks is a complex challenge –– one that will require governments and industry to work together effectively to confront. Progress is necessary and it will take an effort of allies. No single government or organization or cybersecurity vendor can take this on alone.</p>



<p class="wp-block-paragraph"><i>Jim Richberg is public sector field CISO at Fortinet. He formerly served as the national intelligence manager for cyber in the Office of the Director of National Intelligence, where he set national cyber intelligence priorities.</i></p>
]]></content:encoded>
	</item>
		<item>
		<title>What the Cyber Workforce bill means for federal IT professionals</title>
		<link>https://one.sightlinemg.com/federaltimes/opinions/2022/06/24/what-the-cyber-workforce-bill-means-for-federal-it-professionals/</link>
					<comments>https://one.sightlinemg.com/federaltimes/opinions/2022/06/24/what-the-cyber-workforce-bill-means-for-federal-it-professionals/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Fri, 24 Jun 2022 10:46:34 +0000</pubDate>
				<category><![CDATA[Cyber]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[IT & Networks]]></category>
		<category><![CDATA[Newsletters]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2022/06/24/what-the-cyber-workforce-bill-means-for-federal-it-professionals/</guid>

					<description><![CDATA[President Biden signed the Federal Rotational Cyber Workforce Program Act into law, offering agencies a practical solution to the cyber staffing crisis—if they act proactively.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/opinions/2022/06/24/what-the-cyber-workforce-bill-means-for-federal-it-professionals/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">24547</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/GettyImages-903456766.jpg.jpg" width="1200" height="592" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Following the invasion of Ukraine and the sanctions imposed against Russian interests by NATO allies, <a href="https://www.whitehouse.gov/briefing-room/statements-releases/2022/03/21/statement-by-president-biden-on-our-nations-cybersecurity/">the U.S. is on heightened cyber alert</a>.</p>



<p class="wp-block-paragraph">Concerns about cybersecurity threats posed by foreign adversaries were on the rise even before the conflict. According to the <a href="https://investors.solarwinds.com/news/news-details/2022/For-the-First-Time-in-Five-Years-External-Threats-Overshadow-Internal-Threats-as-the-Greatest-Cybersecurity-Concern-for-the-Public-Sector/default.aspx">2022 SolarWinds Public Sector Cybersecurity Survey Report</a>, 56% of federal IT operations and security decision-makers state foreign governments are now one of the top security threats, along with the general hacking community and untrained insiders.</p>



<p class="wp-block-paragraph">To combat these threats, protect American critical infrastructure and safeguard personal information, the federal government is actively seeking to strengthen its cybersecurity workforce. Agencies must find innovative ways to compete with lucrative private sector positions to do so, but it’s a perpetual challenge. In recent years, many federal agencies have seen their <a href="https://www.washingtonpost.com/politics/2021/08/02/cybersecurity-202-governments-facing-severe-shortage-cyber-workers-when-it-needs-them-most/">pool of cyber talent shrink</a>.</p>



<p class="wp-block-paragraph">Here are some best practices federal agencies can implement to better attract and retain a federal cybersecurity workforce.</p>



<p class="wp-block-paragraph"><b>Make a Case for a Rotational Cyber Workforce Program</b></p>



<p class="wp-block-paragraph">On June 21, President Joe Biden signed the <a href="https://www.congress.gov/bill/117th-congress/senate-bill/1097?r=1&#038;s=1">Federal Rotational Cyber Workforce Program Act</a> into law, offering agencies a practical solution to the cyber staffing crisis—if they act proactively.</p>



<p class="wp-block-paragraph">Under this new law, the Office of Personnel Management must establish a cross-agency rotational workforce development program allowing employees to work outside a single position within a single public office. The idea is that as cybersecurity professionals move across departments, agencies will benefit from knowledge transfer and collaborative efforts to address advanced threats.</p>



<p class="wp-block-paragraph">The program could also be used as a recruitment and retention tool. In theory, cybersecurity professionals will gain substantial experience across different departments, enhancing career opportunities and facilitating the expansion of each person’s professional network.</p>



<p class="wp-block-paragraph">The program will be open to IT, cybersecurity, and cyber-related functions. The OPM will be charged with developing policies, processes, and procedures for detailing employees among rotational positions.</p>



<p class="wp-block-paragraph">Therefore, it behooves IT and security leaders to make a case for their agencies’ participation and eligibility for the program sooner rather than later.</p>



<p class="wp-block-paragraph"><b>Address the Soft Skills Gap</b></p>



<p class="wp-block-paragraph">Today’s cybersecurity professionals have a broad range of responsibilities. In addition to technical ability, they’re often called on to display nontechnical skills. For instance, they may be required to make a business case for IT investments, resource allocation, and new risk reduction strategies. They must also collaborate and share best practices within the federal government and industry.</p>



<p class="wp-block-paragraph">Unfortunately, these “soft” or “people” skills are rarely sought or fostered within the federal cybersecurity workforce. As agencies enter a new paradigm of cyber risk, they must do everything they can to address this gap and ensure employees have the soft skills to adapt quickly and easily to the future of cybersecurity and succeed in a federal career. Indeed, strengthening and empowering the high-tech federal workforce is a key goal of the Biden administration’s management agenda.</p>



<p class="wp-block-paragraph">For instance, strong communication skills are essential to ensuring teams understand the criticality of a project. Each stakeholder must appreciate the technical goals of any cybersecurity initiative and how it relates to the agency’s mission and convey all this in nontechnical terms (i.e., speak “the language of the business”). This is especially important if a project impacts many staffers and cyber professionals are called on to gain broader buy-in from the rest of the agency.</p>



<p class="wp-block-paragraph">Collaboration is also vital. No agency works in a vacuum, and different groups must work together to share intelligence and accelerate efforts to lock their digital doors.</p>



<p class="wp-block-paragraph">Adaptability is another crucial soft skill. Change is constant in today’s world, and the pressures on federal cyber pros have been unrelenting over the past few years. After successfully helping the federal government pivot to ensure secure remote work policies, many are hoping for a return to normal. But once again, society is at an inflection point, and there’s no room for overconfidence or security apathy.</p>



<p class="wp-block-paragraph">The ability to function in this ever-changing environment is becoming increasingly important. Federal cyber pros must be able to shift their thinking quickly and be willing to embrace—and thrive through—change.</p>



<p class="wp-block-paragraph">Communication, collaboration and adaptability will take on new significance with the recent implementation of the Federal Rotational Cyber Workforce Program Act. As such, IT and security leaders must revisit their job requirements (even for the most technical staffers) and prioritize skills development with strategic training opportunities capable of bringing value to the organization and the workforce—and time is of the essence.</p>



<p class="wp-block-paragraph"><i>Brandon Shopp is Group Vice President, Product Strategy, at SolarWinds, a supplier of network and systems management software.</i></p>
]]></content:encoded>
	</item>
		<item>
		<title>CISA warns of potential Russian cyberattacks as invasion fears mount</title>
		<link>https://one.sightlinemg.com/federaltimes/cyber/2022/02/14/cisa-warns-of-potential-russian-cyberattacks-as-invasion-fears-mount/</link>
					<comments>https://one.sightlinemg.com/federaltimes/cyber/2022/02/14/cisa-warns-of-potential-russian-cyberattacks-as-invasion-fears-mount/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Mon, 14 Feb 2022 19:50:29 +0000</pubDate>
				<category><![CDATA[Cyber]]></category>
		<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Newsletters]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2022/02/14/cisa-warns-of-potential-russian-cyberattacks-as-invasion-fears-mount/</guid>

					<description><![CDATA[CISA said no credible cyber threats against the U.S. homeland are known at this time, but cautioned Russia could choose to escalate the situation.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/cyber/2022/02/14/cisa-warns-of-potential-russian-cyberattacks-as-invasion-fears-mount/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">28956</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/GettyImages-1078726270.jpg.jpg" width="6407" height="4271" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">WASHINGTON — As Ukraine braces for a possible Russian invasion that may come within days, the U.S. government is warning agencies, businesses and other critical organizations to be on their <a href="https://www.defensenews.com/cyber/2022/02/01/nsas-cybersecurity-directorate-looks-to-scale-up-this-year/" target="_blank">guard against cyberattacks</a>.</p>



<p class="wp-block-paragraph">The Cybersecurity and Infrastructure Security Agency has <a href="https://www.cisa.gov/shields-up" target="_blank">posted a “Shields Up” warning</a>, which the Pentagon emailed to members of the defense industry Monday morning, alerting organizations to the potential for cyberattacks.</p>



<p class="wp-block-paragraph">Cyberattacks have been a central part of <a href="https://www.defensenews.com/international/2020/02/21/why-the-us-chose-to-name-and-shame-russia-over-cyberattacks/" target="_blank">Russia’s playbook in the past</a>, CISA said, particularly in Ukraine in 2015. And while CISA said the U.S. homeland is not now facing any specific, credible threats, Russia could “consider escalating its destabilizing actions in ways that may impact others outside of Ukraine.”</p>



<p class="wp-block-paragraph">“The Russian government understands that disabling or destroying critical infrastructure — including power and communications — can augment pressure on a country’s government, military and population and accelerate their acceding to Russian objectives,” CISA wrote.</p>



<p class="wp-block-paragraph">CISA, which is part of the Homeland Security Department, helps organize the nation’s efforts to prevent and respond to cyberattack. Its mission includes connecting government and industry members with one another and help them find the tools and other resources they need to strengthen cybersecurity.</p>



<p class="wp-block-paragraph">CISA said it’s been working with partners in critical infrastructure in recent months to make them aware of what threats could be out there and to prepare in advance, instead of just responding after something happens.</p>



<p class="wp-block-paragraph">CISA advised organizations of all sizes to ensure personnel use multi-factor authentication when logging on remotely to their networks or for privileged and administrative access, and to ensure their software is up to date to lessen the chances of a cyber intrusion. They should also make sure their IT departments have turned off any ports or protocols that aren’t needed to conduct business, and put strong controls in place if using cloud services.</p>



<p class="wp-block-paragraph">If an organization becomes aware it may have been breached, CISA said their cybersecurity or IT personnel should quickly spot and assess anything out of the ordinary on their network, and make sure their network has the right software to protect against viruses or malware.</p>



<p class="wp-block-paragraph">Organizations that work with Ukrainian organizations should take particular caution to monitor, inspect and isolate that traffic, and closely review the access controls, CISA said.</p>



<p class="wp-block-paragraph">And organizations need to be prepared to respond if a cyberattack does occur, CISA said, such as by designating in advance a crisis response team. That team should designate the main points of contact and spell out the roles and responsibilities people within the organization — such as in the technology, communications or legal departments — should take if something happens. They should also make sure key personnel would be available if something happens and have a plan to surge support to respond when a cyber intrusion happens, CISA said.  Organizations should hold tabletop exercises to make sure all personnel know what they should do if a cyber intrusion happens.</p>



<p class="wp-block-paragraph">Organizations also need to test their backup procedures to make sure they can quickly restore critical data if it is hit by a destructive cyberattack such as ransomware, CISA said. They should also make sure their backups are isolated from network connections.</p>



<p class="wp-block-paragraph">CISA said any incidents or suspicious activity should be reported to them or the FBI at the FBI’s CyWatch line, at 855-292-3937, or <a href="mailto:CyWatch@fbi.gov" target="_blank">CyWatch@fbi.gov</a>.</p>
]]></content:encoded>
	</item>
	</channel>
</rss>
