Axios Codebook

October 14, 2022
😎 TGIF, everyone. Welcome back to Codebook.
- Thanks to everyone who showed up to last night's packed D.C. event with the White House's Anne Neuberger and former homeland security adviser Tom Bossert. It was so much fun seeing everyone!
- 📬 Have thoughts, scoops or other feedback to share? [email protected].
Today's newsletter is 1,387 words, a 5.5-minute read.
1 big thing: Making Cybersecurity Awareness Month better
Illustration: Sarah Grillo/Axios
Cybersecurity Awareness Month’s educational impact could be getting drowned out by companies cranking up their marketing volume.
The big picture: Every October, the Cybersecurity and Infrastructure Security Agency and the National Cybersecurity Alliance host Cybersecurity Awareness Month to educate individuals about basic cyber hygiene practices and encourage security professionals to re-evaluate their organizations' cyber strategies.
- For the government, this month means social media campaigns and White House meetings, including one focused on ransomware and another on the security of Internet of Things devices.
- In the private sector, IT security teams launch awareness campaigns for their employees, and companies host events about the threat landscape.
But many cybersecurity vendors have overrun the month with sales pitches for their own products, making it difficult for government and nonprofit-run awareness campaigns to get traction.
- "It’s almost become a scenario where if you’re not doing messaging, you’re the one left out," says Brandon Pugh, policy counsel on the R Street Institute's cyber team. "If you’re not planning an event, you’re not writing an article on it, you’re not trying to sell a product around October, people are wondering why you’re not."
Several companies — including Norton and Trend Micro — published Cybersecurity Awareness Month blog posts on initiatives launching this month. However, many of them plugged their own products at the end.
- IT management software company Kaseya published a blog post right before the month started titled, "How to Win More Business During Cybersecurity Awareness Month."
- Multiple companies have also used social media to bring awareness to their products while mentioning the initiative.
Between the lines: Cybersecurity Awareness Month still has plenty of room to better cut through the noise, experts tell Axios.
- Oz Alashe, founder and CEO of CybSafe, tells Axios a lot of security professionals struggle to simplify their messages and get everyday people engaged in cyber — especially after years of vendors, IT staffs and others telling them to use tough passwords and not click on malicious links.
- One way companies can combat that fatigue is to focus on just three lessons they want to teach people during the month, says Lance Spitzner, director of the SANS Institute's security awareness team. "Try to make those three things as simple as possible," he says.
- Governments and organizations shouldn't be afraid to advance their education beyond the basics, Alashe adds, especially as more people become aware of tools like multifactor authentication and best password practices.
The intrigue: Despite the marketing noise, consultants who advise companies to establish their own cyber awareness and training programs say having a dedicated month-long campaign actually does help.
- Alashe says he's seen C-suite executives be more inclined to spearhead company cybersecurity initiatives in October.
- Pugh says that when he was on a local school board in New Jersey, the board often used Cybersecurity Awareness Month as a time to focus on its cybersecurity priorities.
Yes, but: Measuring Cybersecurity Awareness Month's effectiveness depends on who people say the campaign's target audience is.
- "What I can't work out is if people feel generally bombarded," Alashe says. "If you're not in the security space, maybe, actually, you're not paying attention as much as we are because it's not your everyday life."
2. White House cyber regs enter a new phase
Anne Neuberger speaks during a news conference in February 2022. Photo: Oliver Contreras/Sipa/Bloomberg via Getty Images
Critical infrastructure sectors should start preparing for the next phase in the Biden administration's cyber regulatory plan after a pair of announcements from a top White House adviser on Thursday.
Driving the news: Anne Neuberger, deputy national security adviser for cybersecurity and emerging technology, shared updates during two public interviews Thursday — including one with your Codebook host — on the White House's work to stand up new cyber regulatory structures for critical infrastructure sectors.
- Neuberger said during a Washington Post event in the morning that the communications, water and health care sectors are next on the administration's list for new cyber rules.
- Neuberger also told an audience at an Axios event in Washington last night that the Cybersecurity and Infrastructure Security Agency (CISA) is planning to release its highly anticipated, but voluntary, cybersecurity performance goals before the end of the month.
Details: Neuberger said the EPA, the FCC and the Department of Health and Human Services (HHS) will each release their own cyber guidelines and rules.
- The FCC will issue a notice of proposed rulemaking for emergency and public warning systems, HHS is working on guidelines for hospitals, and the EPA is reviewing ways to regulate water systems' cybersecurity, Neuberger said.
- CISA is releasing performance goals, as required in a Biden national security memo issued last year, that will suggest baseline security practices for operators.
The big picture: Each announcement represents the Biden administration's strong desire to expand cybersecurity regulations into the private sector.
- So far, the White House has had a piecemeal approach, taking one critical infrastructure sector at a time, such as pipelines, railroads and aviation.
- As for CISA, industry groups have expressed concerns that the new performance goals will be a precursor for mandatory requirements.
Meanwhile, Neuberger's office also announced plans earlier this week to host a meeting on Wednesday with industry groups to discuss a new initiative to create a cybersecurity label for Internet of Things devices.
What they're saying: "Many of our peer governments, whether the European Union or Koreans or others, have over the years put in place minimum cybersecurity standards for critical infrastructure," Neuberger said during the Axios event.
- "We're now recognizing we very much need to do that in the U.S."
3. Former GOP official backs planned FCC order
Illustration: Sarah Grillo/Axios
A former U.S. homeland security adviser in the Bush and Trump administrations said a reported plan at the FCC to crack down on Chinese telecommunications providers is a step in the right direction during an Axios event Thursday.
What they're saying: "The U.S. intelligence services have it right now," said Tom Bossert, now president of Trinity Cyber, during the event.
- "With respect to microchips and certain hardware, there is no way to mitigate appropriately against an adversary that's producing those things. They now understand the firmware in every one of our devices."
Driving the news: On Thursday, Axios broke the news that the FCC is circulating a draft order that would ban all sales of new technologies from Chinese telecommunications providers Huawei and ZTE.
- If it went into effect, it would mark the first time the FCC has banned any electronics equipment based on national security concerns.
- The ban would not apply to old technologies the FCC has previously approved, Axios reported.
The big picture: The FCC's potential move could be one of the most consequential a U.S. agency has made against Huawei and ZTE.
- Intelligence agencies and security researchers have warned for years that the Chinese government could tap Chinese-made telecommunications equipment to spy on Americans.
Between the lines: Bossert cautioned that questioning the security controls on Chinese tech vendors is just the first step.
- "It seems like we're only halfway there right now," he said. "We're not trusting those markets, but we're still doing a heck of a lot of business there with a lot of technology companies."
- Many major U.S. tech companies have started to slowly move their businesses out of China, according to the New York Times.
4. Catch up quick
@ D.C.
📝 The Biden administration’s new national security strategy is light on information about where cybersecurity fits in. (The Record)
🔏 The Cybersecurity and Infrastructure Security Agency doesn't plan to release the public comments it received for its soon-to-be-released performance goals. (Nextgov)
@ Industry
❓ Questions linger after Thoma Bravo announced its buyout of identity management company ForgeRock. (Axios)
💰 Private equity firm Vista Equity Partners is acquiring security awareness training vendor KnowBe4 for $4.6 billion. (Dark Reading)
🦊 Firefox is expanding its Relay program — which gives people pseudo-emails so they don't need to hand out their real ones — to phone numbers. (The Verge)
@ Hackers and hacks
🗳 Researchers at cyber firm Trellix have observed an influx of phishing emails targeting election administrators ahead of next month's midterms. (Trellix)
👾 Fast Company notified board members that their personal information was not affected in a Sept. 27 hack. (BleepingComputer)
📲 Researchers at WithSecure said they've uncovered an unpatched vulnerability in Microsoft Office 365's message encryption, warning it could lead to "partial or full message disclosure." (WithSecure)
5. 1 fun thing
Screenshot: @NSA_CSDirector/Twitter
If you aren't following the cyber memes that Rob Joyce, director of cybersecurity at the National Security Agency, has been tweeting out this month, you're missing out.
☀️ See y'all on Tuesday!
Thanks to Peter Allen Clark for editing and Khalid Adad for copy editing this newsletter.
If you like Axios Codebook, spread the word.



