Axios Codebook

January 17, 2025
π TGIF, everyone. Welcome back to Codebook.
- πΊπΈ That concludes the last week of the Biden administration β and man, did they give us a lot to talk about! Let's dig in.
- π¬ Next week, I want to feature your cybersecurity wish list for the Trump administration. Have snappy thoughts? Hit reply.
Today's newsletter is 1,521 words, a 5.5-minute read.
1 big thing: Biden's Day 1 cyber adviser says farewell
Biden's right-hand cyber adviser, Anne Neuberger, says her team's tenure can be defined by creative thinking, its partnerships with the private sector, and the continuing push to fully implement the new programs they created to help critical infrastructure.
Why it matters: Even if President-elect Trump decides to erase all of the cyber regulations President Biden and his team put in place, the administration's work permanently changed how executives, government officials and security professionals approach security.
Driving the news: Neuberger, deputy national security adviser for cyber and emerging tech in the White House, is leaving her role today ahead of the inauguration.
- Her last few weeks have been busy: She spearheaded the administration's second cyber executive order, which was signed yesterday; traveled to CES last week for the launch of the U.S. Cyber Trust Mark program; and published a Foreign Affairs piece Wednesday about artificial intelligence's influence on global espionage.
The big picture: In one of her final interviews as a Biden official, Neuberger told Axios that China, AI and software liability were the three tentpoles of her office's work over the last four years.
- The discovery that China has been lurking inside U.S. power utilities, water systems, online communications and more for years forced the Biden administration to double down on creating minimum cyber requirements for companies, she said.
- Neuberger also pointed to the administration's work to tap AI for cyber defenses, as seen in the 2023 AI executive order (which Trump has promised to rescind) and this week's cybersecurity order.
- The Biden administration introduced the idea of holding software providers liable for the security flaws in their products β a project that officials admittedly knew would take nearly a decade to fully implement.
Flashback: Neuberger is the only senior cyber official who has been on the job since Day 1 of the Biden administration.
- When Biden took office, his team also took over the response to the Russia-backed intrusion of SolarWinds, which affected at least nine federal agencies and 100 companies.
- Then, Russian ransomware gangs went on a summer rampage through U.S. infrastructure, targeting the country's largest refined products pipeline, a meat production facility and a widely used IT vendor.
- The only time Biden and Russian President Vladimir Putin ever met in person was primarily to discuss ransomware.
Now, the new Trump administration is coming in as the U.S. government is responding to a range of China-backed cyberattacks on government networks.
- Neuberger is one of only a handful of people in the world who understands that feeling.
- Her advice to those replacing her: "Use the power of procurement, use the rules around what we buy," she said, and "keep [the products we buy] regularly updated because adversaries' offensive techniques evolve and our defenses have to continuously be updated."
By the numbers: The Biden administration made a lot of strides in bringing certain critical infrastructure sectors up to speed, Neuberger said.
- 100% of U.S. pipelines now meet baseline cybersecurity requirements that were put in place following the 2021 Colonial Pipeline attack.
- 70% of railways now comply with their own new baseline requirements.
- 60% of airports also are following new requirements as of this week, she added.
Reality check: The Biden administration still hit a few legal hurdles when trying to implement its agenda.
- To avoid this, Neuberger said, the incoming administration and new congressional leaders should take the time to ask each agency what it needs to make securing its sector easier β "whether that's resources, whether that's ways to attract or retain top talent, whether that's deeper ties to the intelligence community," she said.
The bottom line: Neuberger is hopeful that much of her team's work will remain intact, since cybersecurity has mostly remained a nonpartisan issue.
- "We've got to continue to do more to make defense continuously, rapidly evolving and never rest on our laurels," Neuberger said. "We know attackers are never resting."
2. Trump inches closer on CISA nominations
Two former Trump cyber officials are the likely choices to take the top roles at the lead U.S. cyber agency, according to two people familiar with the matter.
Why it matters: The new leaders of the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency will play a key role in helping the president-elect respond to recent China-backed cyberattacks on U.S. government networks.
Zoom in: The Trump transition team is zeroing in on Sean Plankey to run CISA and Nicholas Andersen to be No. 2 as deputy director, according to the people familiar with ongoing discussions.
- Both Plankey and Andersen held several top cyber roles during the first Trump administration: They each had top roles in the Energy Department's cyber office and at the White House overseeing cyber policy.
- CISA helps federal agencies shore up their cybersecurity strategies and coordinates several partnerships between the federal government and the private sector to better fight major cyberattacks.
- Plankey's role would need Senate confirmation.
- Politico first reported on Plankey's momentum.
Yes, but: Trump has been known to change his mind at the last minute.
The big picture: CISA's mission is likely to face intense scrutiny once Trump takes office next week following years of Republican criticism over its election security work.
- Some officials have called to eliminate the office altogether.
What we're watching: Trump has yet to nominate new leadership at the Office of the National Cyber Director or appoint people to leading cyber roles in the White House's National Security Council.
3. Cyber influencers will miss TikTok, too
Even some cybersecurity professionals are upset about TikTok's potential shutdown in the U.S. this weekend.
Why it matters: Lawmakers passed the "divest or sell" law because of national security and data collection concerns.
- No one understands those concerns better than cybersecurity influencers who use their platform to educate the masses about data security and privacy issues.
State of play: As of now, TikTok is planning to turn off services in the U.S. on Sunday, the deadline for ByteDance to divest its stake in TikTok.
- The U.S. Supreme Court has decided to uphold the law, but President Biden doesn't plan to enforce it Sunday β leaving President-elect Trump's team in charge of finding options to bring it back online next week.
Zoom in: Caitlin Sarian β an influencer who posts as Cybersecurity Girl and has more than 456,000 TikTok followers β told Axios that the short-form video app is the best platform to reach a wide-ranging audience, rather than just her followers.
- Sarian said she's preparing to migrate her focus over to Instagram, where her following has swelled to 907,000 followers, and LinkedIn if TikTok fully shuts down.
Other influencers have been posting on TikTok throughout the week about how much they've gained from the platform.
- "I don't see how TikTok being banned is going to be a net positive on my life," said cybersecurity influencer Moshe, who posts under the handle ChiefGyk3D, in a video this week.
- He has around 370,000 TikTok followers and also posts on Discord, YouTube, Twitch and BlueSky.
The intrigue: Sarian, the former global lead of cyber advocacy at TikTok, also said she doesn't think the ban will do much to help protect Americans' data.
- "I understand people's sentiment around the China situation because we are in cyber warfare," she said.
- "But if I'm looking at it from my perspective, there's a lot bigger fish to fry than banning this app totally."
Yes, but: Don't expect cybersecurity influencers to flock to Red Note alongside everyone else.
- Sarian joked she would consider it only if she had a burner phone dedicated solely to using the China-based social media app.
4. Catch up quick
@ D.C.
π‘ The Federal Communications Commission issued a proposed rule that would require telecom providers to submit a cybersecurity risk management plan to the agency for review each year, following the Salt Typhoon intrusions. (FCC)
π Nathaniel Fick, the outgoing U.S. cyber ambassador, urged his successor to remain engaged in global tech and digital security debates or risk having Russia and China take a leading role in filling the gap. (Wired)
π The Salt Typhoon intrusions were first spotted on federal networks, before telcos detected them, CISA Director Jen Easterly said this week. (Nextgov)
@ Industry
π General Motors is banned from providing drivers' behavior and geolocation data to consumer reporting agencies for five years under a new Federal Trade Commission settlement. (New York Times)
@ Hackers and hacks
β οΈ Chinese government hackers gained access to more than 3,000 unclassified U.S. Treasury Department files during a recent breach, including those belonging to Treasury Secretary Janet Yellen, according to a person who participated in a classified briefing on Capitol Hill this week. (Politico)
π¨ FBI leaders believe hackers who broke into AT&T's systems last year stole months' worth of their agents' call and text logs. (Bloomberg)
π« The PowerSchool hackers stole "all" historical data about students and teachers at some school districts. (TechCrunch)
5. 1 fun thing
πΈ Spotted on San Francisco's Nextdoor page: Someone fully believing this AI-generated photo of a so-called butterfly begonia, which doesn't exist and appears to be just an image of a begonia covered in butterflies.
- β οΈ Even those of us in the tech capital of the world are falling for AI-generated fake images.
- π«‘ H/t to our editor, Meg, for coming across this.
βοΈ See y'all Tuesday!
Thanks to Megan Morrone for editing and Khalid Adad for copy editing this newsletter.
If you like Axios Codebook, spread the word.




