Security

CSO

I tried hard, but didn't fix all of cybersecurity, admits outgoing US National Cyber Director

In colossal surprise, ONCD boss Harry Coker says more work is needed


The outgoing leader of the United States' Office of the National Cyber Director has a clear message for whomever President-elect Trump picks to be his successor: There's a lot of work still to do.

Speaking to the Foundation for the Defense of Democracies yesterday, outgoing director National Cyber Director Harry Coker praised the work his office’s team has done in the past four years, while also noting that America is yet to implement all necessary defenses for critical systems.

"In the last four years we have: Fought fires; taken a proactive posture to defending cyberspace; brought greater coherence to Federal and global efforts; gotten key tech companies to step up on cybersecurity; and taken on some of the hardest problems that have long crippled our ability to stay secure," said Coker, the second person confirmed by the US Senate to hold his role.

"We've made progress," the outgoing director added, while noting "there's still a long way to go."

Coker called particular attention to the White House national cybersecurity strategy enacted in 2023, which his office played a key part in developing, as a success during his time in the role. Efforts to shore up security holes in the Border Gateway Protocol were also cited as a success.

The director also pointed to the Service for America campaign he led last year, which pitched cybersecurity work as national service as another success despite it also being an item of unfinished business as hundreds of thousands of infosec jobs remain unfilled.

"Everywhere I go, whether I'm talking to state or local government leaders, small or large businesses, or anyone leading critical infrastructure – they all tell me that they need more cyber talent," Coker said.

Coker hopes the second Trump administration will give the Office of the National Cyber Director more say in cybersecurity budgeting across the federal government.

"I would love for the incoming administration, or any administration, to recognize the priority of cybersecurity," Coker told reporters at yesterday's event. "It's a responsibility that every department and agency needs to stand up to. We need to give more than guidance when it comes to cybersecurity budgets."

He didn't mince words on the state of cybersecurity in the US, highlighting concerns about recent reports of cyber intrusions targeting US telecommunications systems.

How well that message is being received is unclear. Verizon - one of the group of US telecom providers breached by the Beijing-linked Salt Typhoon crew - has been handed a deal to upgrade cellular networks on 35 US Air Force bases.

Moreover, Microsoft, which supplies myriad government agencies, has been slammed by US cyber officials for lax security that allowed a China-linked group to breach Exchange Online and access the emails of senior government officials, but contract cash keeps flowing to Redmond, too.

President-elect Trump is yet to name the next ONCD Director. Whoever gets the gig will be busy. ®

Send us news
12 Comments

DEF CON's hacker-in-chief faces fortune in medical bills after paralyzing neck injury

Marc Rogers is 'lucky to be alive'

Datacus extractus: Harry Potter publisher breached without resorting to magic

PLUS: Allstate sued for allegedly tracking drivers; Dutch DDoS; More fake jobs from Pyongyang; and more

Feds sue Southwest for chronic delays, unrealistic schedules

Department of Transportation wants in on last-minute Biden administration action too

Infoseccer: Private security biz let guard down, exposed 120K+ files

Assist Security’s client list includes fashion icons, critical infrastructure orgs

Four plead guilty in US government tech procurement fraud case

Scheme involving bribes, bid rigging and insider info may have cost US taxpayers $1.3M

Snyk appears to deploy 'malicious' packages targeting Cursor for unknown reason

Packages removed, vendor said to have apologized to AI code editor as onlookers say it could have been a test

Cryptojacking, backdoors abound as fiends abuse Aviatrix Controller bug

This is what happens when you publish PoCs immediately, hm?

Nvidia snaps back at Biden's 'innovation-killing' AI chip export restrictions

'New rule threatens to squander America's hard-won technological advantage' says GPU supremo

Nominet probes network intrusion linked to Ivanti zero-day exploit

Unauthorized activity detected, but no backdoors found

Europe coughs up €400 to punter after breaking its own GDPR data protection rules

PLUS: Data broker leak reveals extent of info trading; Hot new ransomware gang might be all AI, no bark; and more

Drug addiction treatment service admits attackers stole sensitive patient data

Details of afflictions and care plastered online

Zero-day exploits plague Ivanti Connect Secure appliances for second year running

Factory resets and apply patches is the advice amid fortnight delay for other appliances