Federal report warns U.S. is unready for a cyberattack
The U.S. should take a slew of steps today to prevent a major cyberattack that could wreak wide-scale devastation on the U.S., a year-long study mandated by Congress reported Wednesday.
Why it matters: "A major cyberattack on the nation's critical infrastructure and economic system would create chaos and lasting damage exceeding that wreaked by fires in California, floods in the Midwest, and hurricanes in the Southeast," the report predicts.
What they're saying: "This is like doing the 9/11 Commission before 9/11 happens. We want to avoid that situation," Rep. Mike Gallagher (R-Wis.), a co-chair of the panel, said at an Axios event Monday.
- At the same event, Sen. Angus King (I-Maine), the other co-chair, said the U.S. does not currently have an effective deterrence policy in place to discourage hostile cyberattacks. "We are getting killed by a thousand cuts," he said.
Details: The Cyberspace Solarium Commission was established by the 2019 defense appropriations law and named for a Cold War-era project that offered recommendations for forestalling nuclear war.
- Its report proposes a broad strategy of "layered cyber deterrence" pursued by a reorganized federal cyber defense framework with new permanent select cybersecurity committees in both houses of Congress, a Senate-confirmed National Cyber Director, and a Cyber Bureau at the State Department.
- The report also calls for establishing a Cyber Response and Recovery Fund, a National Cybersecurity Certification and Labeling Authority, a Bureau of Cyber Statistics, a national privacy and data security law, enhanced election security measures, and formal classifications for "systemically important critical infrastructure."
What's next: President Trump has shown little enthusiasm for long-term planning and risk mitigation efforts in this realm, and his administration eliminated its top cybersecurity coordinator position in 2018. But bipartisan interest in Congress remains high, and the Cyberspace Solarium report gives future executives a template for action.
Go deeper: Read the executive summary or the full report.