ARTICLE
21 January 2022

GAO Examines Federal Response To Cybersecurity Incidents

HL
Hogan Lovells Cadwalader

Contributor

Hogan Lovells Cadwalader is a global law firm trusted by clients to deliver on complex, high-stakes matters.

Operating at the intersection of business, finance, and government, we bring an unwavering commitment to client service and the decisive counsel that helps clients achieve exceptional results.

Consistently recognized for innovation across legal services, we combine sharp judgment with deep commercial perspective and intellectual rigor to address critical, cutting-edge challenges.

With 3,100 lawyers worldwide, we offer global scale with strong local insight in the markets that matter most. Our commitment extends beyond client work through pro bono activities, community investment, and responsible business practices.

In a new report, the GAO examined federal responses to two cybersecurity breaches: the hack of SolarWinds and the exploitation of a vulnerability in Microsoft Exchange.
United States Technology

In a new report, the GAO examined federal responses to two cybersecurity breaches: the hack of SolarWinds and the exploitation of a vulnerability in Microsoft Exchange.

The GAO stated that both incidents were caused by foreign government actors: the SolarWinds breach was by the Russian Foreign Intelligence Service and the Microsoft Exchange breach was by the Chinese Ministry of State Security. The report (1) provided a summary of the incidents, (2) described steps that federal agencies have taken in response to these incidents, and (3) identified lessons learned by federal agencies from these incidents.

GAO noted that federal agencies (i) formed two Cyber Unified Coordinated Groups (or "UCGs"), one for each incident, whose efforts included issuing directives and providing guidance and tools to agencies, and (ii) reported to the Cybersecurity and Infrastructure Security Agency the actions they took to mitigate the threats from these incidents. GAO said that federal agency officials believed that coordinating with private sector partners and other agencies led to more desirable outcomes in the responses to these incidents.

GAO also cited the National Security Council's review of the SolarWinds incident, which identified ways to address challenges that federal agencies faced during their response to the incident. These include:

  1. aligning technology investments with operational priorities;
  2. improving public/private engagement; and
  3. improving threat intelligence acquisition, sharing and use among federal agencies.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More