Let’s Prioritize Cyber Security as a Crucial Concern

We need a robust investigative body for cyber incidents, not the ineffective one we have today.

Just as aviation disasters prompt rigorous, law-empowered investigations to uncover the truth, we require a similar approach for cyber incidents. Currently, there is no dedicated body to scrutinize failures like CrowdStrike’s recent problematic update, which has wreaked havoc on banks, airlines, and emergency services, costing billions. This gap needs to be addressed.

The White House’s Cyber Safety Review Board (CSRB) was established on March 20, 2021, through an executive order, to offer independent evaluations of major cyberattacks against the U.S. Its purpose is to penetrate the veil of corporate secrecy surrounding these attacks and to provide valuable lessons and recommendations for the security community. This approach mirrors the rationale behind creating the National Transportation Safety Board, but focused on cyber incidents rather than aviation.

However, the CSRB has yet to fulfill its mission effectively. It was created in response to the SolarWinds attack but failed to investigate it comprehensively for reasons that remain unclear. To date, the CSRB has released three reports, each with basic recommendations. The first, on Log4J, urged companies to update their systems more frequently. The second, concerning Lapsus$, advised against SMS-based two-factor authentication due to vulnerabilities. These are fundamental cybersecurity practices that don’t require in-depth investigations to identify.

The latest report on China’s breach of Microsoft’s cloud environment is more thorough, providing an in-depth analysis of Microsoft’s security shortcomings. It criticizes Microsoft for not rotating cryptographic keys and suggests that such a measure might have thwarted the attack. While this report is more detailed and offers specific guidance, it still has shortcomings. It relies heavily on anonymous sources and does not provide clear standards or recommendations applicable across the industry.

The CSRB’s lack of subpoena power significantly hampers its effectiveness. Unlike the NTSB, which can compel testimony and documents, the CSRB must depend on voluntary cooperation, which may not always be forthcoming. This limitation means the board cannot always get a complete picture, and transparency suffers.

Tarah Wheeler recently addressed the U.S. Senate’s Homeland Security and Governmental Affairs Committee about these issues. The senators expressed genuine concern over the CSRB’s slow pace and lack of transparency in its reports.

Addressing these problems requires legislative action. Congress needs to formally codify the CSRB and grant it subpoena authority to ensure it can perform its duties effectively. Additionally, the CSRB’s reports should offer clear, actionable standards and align with established frameworks like those from NIST. Currently, the recommendations often lack concrete, industry-wide guidelines, leaving companies to rely on fragmented and subjective interpretations.

Cybersecurity should be treated with the same seriousness as public safety. We need comprehensive, standardized guidance rather than isolated anecdotes about individual companies’ failures. Real progress in cybersecurity requires establishing clear, evidence-based standards and practices.

Bruce Schneier is a Lecturer at Harvard Kennedy School and a leading cybersecurity expert.

Tarah Wheeler is the Senior Fellow for Global Cyber Policy at the Council on Foreign Relations and CEO of Red Queen Dynamics.

More Articles & Posts