CISA Chief: Tackling Cybersecurity Challenges is Achievable

LAS VEGAS — Despite a series of severe cyberattacks and disruptions that have impacted major sectors of the economy, Jen Easterly, the head of the Cybersecurity and Infrastructure Security Agency (CISA), asserts that the fight against cyber threats is far from over.

According to Easterly, organizations can still enhance their defense mechanisms and shift more responsibility to technology vendors. Speaking at a media session during Black Hat, she emphasized, “We’ve created this problem ourselves, and it’s up to us to solve it.”

Her optimism is grounded in tangible progress. “We’ve made significant strides, particularly in recent years,” Easterly noted. The U.S. government has strengthened its partnerships with businesses and global allies, and a growing number of CEOs and board members are integrating cyber risk management into their core business strategies. Corporate cyber responsibility is increasingly seen as a governance issue, not just a technical one.

Easterly highlighted CISA’s “secure by design” initiative as a crucial component in combating cyber threats. Since her appointment in 2021, this initiative has aimed to shift security responsibilities from end users to vendors. “Winning this battle relies on our ability to implement secure by design software. This is a critical focus and a challenging task,” she stated.

Introduced in April 2023, the secure by design principles began as a voluntary pledge, with 68 tech companies committing to these practices. To date, nearly 200 companies have endorsed the pledge.

Easterly believes that building secure software from the ground up is essential for creating a durable and scalable cybersecurity strategy.

Reflecting on a Year of High-Profile Cyber Incidents

The year has been marked by significant attacks that highlight the ongoing challenges for defenders and federal authorities.

In February, a ransomware attack severely disrupted healthcare billing operations for several months, and in April, over 100 businesses were affected by attacks on Snowflake customer environments. Last month, a problematic CrowdStrike software update caused one of the largest IT outages in history.

Despite these setbacks, Easterly remains confident that improvements are on the horizon. Federal agencies and international partners are working to address the root causes by encouraging technology vendors to design, develop, test, and deploy more robust software solutions.

More Articles & Posts