Federal agencies have been dealing with a number of key developments and challenges in cybersecurity throughout 2023. One of the most significant developments was the release of a new national cyber strategy by the Biden administration in March. This strategy aims to shift the responsibility for managing cyber risks from customers to manufacturers and includes efforts to establish cybersecurity regulations for critical infrastructure. In addition to the strategy, there have been other significant developments in cybersecurity, including the emergence of artificial intelligence (AI) and game-changing cyber attacks.
Threats to critical infrastructure and federal agencies have been a major concern in cybersecurity. In May, it was revealed that People’s Republic of China-related cyber actors had infiltrated the networks of U.S. critical infrastructure and were using built-in network administration tools to evade detection. This discovery has important implications for government and the private sector, particularly in terms of improving public-private partnerships and implementing secure by design initiatives.
Several high-profile cyber attacks also occurred in 2023, including the MOVEit breach and the infiltration of Microsoft cloud-based email accounts by suspected Chinese hackers. These incidents highlight the increasing severity of nation-state cyber threats and the need for federal government support in defending against them.
The Securities and Exchange Commission (SEC) has been leading the push for more cyber regulations, particularly for critical infrastructure. The SEC issued new cyber rules for publicly traded companies and brought legal action against SolarWinds and its CISO over alleged fraud and internal control failures related to the 2020 hack. These developments have implications for the role of CISOs and their relationship with boards and executive leadership teams.
The emergence of AI has both exciting potential and cyber threats. The introduction of large language models like ChatGPT has sparked concerns about the security and safety of AI technology, as it is reportedly being leveraged by hackers. However, AI also has the potential to help defend against cyber attacks and improve cybersecurity awareness and training.
Overall, the key developments in cybersecurity in 2023 include the new national cyber strategy, the emergence of AI and related cyber threats, the threats to critical infrastructure and federal agencies, and the push for more cyber regulations by the SEC.