RSA Conference 2023: Firms hit by cyber attacks should work with government, says U.S. official

Share post:

The U.S. government needs the private sector to work with it to blunt cyber attacks, a senior justice department official told infosec pros at RSA Conference 2023.

“We want to work hand in glove with the private sector and give as much information as we can about what we’re seeing to alert folks,” Lisa Monaco, U.S. deputy attorney general and former Homeland Security advisor to President Barak Obama, told the San Francisco conference on its opening day Monday.

That’s what the U.S. did in 2021 when it helped alert Microsoft customers that a China-based group dubbed Halfnium was attacking Exchange servers, she said.

Photo of US Deputy AG Lisa Monaco, right, with interviewer Chris Krebs at RSA Conference 2023
U.S. Deputy AG Lisa Monaco, right, with interviewer Chris Krebs at RSA Conference 2023

“But then, when entities don’t take as much self-remedial action as maybe they should, we are going to take action … pursuant with court processes.”

For example, she said, in 2022 when the U.S. saw Russia’s GRU military intelligence group taking over a group of zombie routers and firewall devices made by WatchGuard and ASUS in a botnet dubbed Cyclops Blink, it worked with the U.K., other countries, and WatchGuard to fight back. Through newly-granted federal civil powers the U.S. was able not only to access the botnet’s infrastructure but issue commands to delete that malware from customers’ devices.

Another example of the U.S. government working with the private sector, she said, was when Colonial Pipeline asked for help after it suffered a ransomware attack in 2021. The U.S. traced the ransomware payment and was able to return half of the US$4.4 million Colonial paid in bitcoin.

Monaco’s call for U.S. firms to work with the government is not the first call of this kind. But it is one that can be repeated by other nations.

Monaco said she has given orders to U.S. federal prosecutors to think about how they can disrupt threat actors and minimize the harm of cyber attacks. “Doing so will not always get a prosecution,” she said, “but that’s fine. We don’t always measure our success with courtroom victories. This is about preventing and disrupting and putting victims at the centre.”

An example she cited was the January closing of the Hive ransomware gang’s infrastructure. No one was arrested, but a big threat was — at least temporarily — taken off the table.

“We have to be willing to put our tools on the table, to let people into the tent and help them see what we’re seeing, and then work together to take that action,” she said, “not meet with you once or twice a year and promise some more product.”

The U.S. is also watching how nation-states are going after new and disruptive technologies, data sets and algorithms, Monaco said. Her office, the Commerce Department and Homeland Security have created the U.S. Disruptive Technology Strikeforce “to strike back against adversaries trying to siphon our best technology,” she said at the time.

Referring to Colonial Pipeline’s willingness to go to the FBI, she said, “Do that because it’s good for business — and you see that in terms of the ransomware payment — and it’s good for America, because you are helping us to prevent the next attack”

“We are in this together. It should not be an adversarial thing.”

The post RSA Conference 2023: Firms hit by cyber attacks should work with government, says U.S. official first appeared on IT World Canada.
Howard Solomon
Howard Solomonhttps://www.itworldcanada.com
Currently a freelance writer, I'm the former editor of ITWorldCanada.com and Computing Canada. An IT journalist since 1997, I've written for ITBusiness.ca and Computer Dealer News. Before that I was a staff reporter at the Calgary Herald and the Brampton (Ont.) Daily Times.

SUBSCRIBE NOW

Related articles

Microsoft reveals critical security flaw affecting Android apps

Microsoft has identified a serious vulnerability in Android apps that could allow malicious software to hijack legitimate apps...

Chinese government websites “Riddled with security flaws” say researchers

A recent study conducted by researchers from the Harbin Institute of Technology reveals significant security issues plaguing Chinese...

Cyber Security Today, May 3, 2024 – North Korea exploits weak email DMARC settings, and the latest Verizon analysis of thousands of data breaches

This episode reports on warnings about threats from China, Russia and North Korea, the hack of Dropbox Sign's infrastructure

Hashtag Trending for World Password Day, Thursday, May 2nd, 2024

Security firm Okta warns of an unprecendented password stuffing attack that is piggybacking on regular user’s mobile and...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways