Wednesday, October 6, 2021

Secretary Mayorkas Delivers Remarks at the 12th Annual Billington CyberSecurity Summit

U.S. DEPARTMENT OF HOMELAND SECURITY

Office of Public Affairs


Secretary Mayorkas Delivers Remarks at the 12th Annual Billington CyberSecurity Summit

On October 6, 2021, Secretary of Homeland Security Alejandro N. Mayorkas delivered a keynote address at the 12th Annual Billington CyberSecurity Summit. His remarks are below:

Thank you very much for the introduction and for the invitation to speak at the Billington Cybersecurity Summit.  Thank you all for joining us today.

As you know, cybersecurity poses one of the greatest challenges facing our Nation. The last year and a half has powerfully demonstrated what's at stake.

Last March, schools and students, stores and consumers, companies and employees, houses of worship and congregants had to shift their operations online in almost an instant.

The internet became essential, allowing us stay in touch with loved ones, enabling remote work, and ensuring continued innovation across industries.

At the same time, ransomware attacks disrupted already-strained hospitals, schools, food suppliers, and pipelines in addition to many other organizations that provide critical services.  These attacks revealed that what is at stake is not simply the way we communicate or the way we work, but the way we live.

A couple of weeks ago, at the BlackHat conference, I talked about how cybersecurity is now a central piece of our geopolitics, shaping our future online and offline and generating repercussions that impact our economy, our security, our democracy, and the exercise of fundamental rights for decades to come.

That's why cybersecurity has been a top priority for the Biden-Harris Administration from the start.  Together with partners from across every level of government and the private sector, we are working to defend a digital future that is free and secure.

Over the course of my eight months in office, DHS has taken a series of bold actions to lead the charge on this front.  I'll describe a few of them today.

First, we are strengthening the Department's Cybersecurity and Infrastructure Security Agency, or CISA as it is commonly known, as the nation's cybersecurity quarterback.   Jen Easterly, who is the new Director of CISA, has had a distinguished career in government and the U.S. military, as well as in the private sector.  She exemplifies the impressive talent we have brought to DHS to advance many of our key cybersecurity priorities and tackle related challenges.  You will hear more from Jen and about CISA tomorrow.

Second, we are breaking out of cyber silos to strengthen national cybersecurity resilience.

We are doing this by elevating and integrating cybersecurity across agencies, sectors, and within DHS, leveraging CISA's expertise and experience wherever possible.

At DHS, this work also includes TSA, the Coast Guard, FEMA, the Secret Service, and ICE.

To move from vision to action, DHS has undertaken a series of 60-day sprints.  The idea is straightforward: let's turbocharge our leadership on cybersecurity by issuing a series of challenges to ourselves – and commit to hard deadlines for results.

We launched the first sprint in March, focused on elevating the fight against ransomware at home and around the world.  We now have an entire whole-of-government effort dedicated to this challenge and we developed StopRansomware.gov, which is the first website that pools federal resources to help individuals and organizations of all sizes mitigate their risk against this threat.    

The second sprint focused on ensuring DHS can recruit, retain, and develop a diverse, top-tier cybersecurity workforce.  This resulted in the largest and most successful cybersecurity hiring effort in our Department's history and paved the way for the near-term launch of the DHS Cybersecurity Service on November 15th, which will increase access to public service careers in cybersecurity.

The third sprint centered on increasing the cybersecurity of our Industrial Control Systems, including pipelines and the electricity sector, a necessity driven home by the Colonial Pipeline ransomware attack.  Along every step of the way, the Department has been working hand-in-glove with the White House, other federal partners, and the private sector to increase adoption of CISA's guidance and services to protect critical infrastructure.

The fourth sprint focuses on the cybersecurity of the transportation sector.  It launched in September and is ongoing so I will briefly highlight our activities in greater detail.

Whether by air, land, or sea, our transportation systems are of utmost strategic importance to our national and economic security. 

The maritime transportation system is comprised of hundreds of ports and shipyards, 25,000 miles of waterways, and 20,000 bridges, pipelines, and undersea cables.  Roughly a quarter of America's GDP flows through it – that amounts to approximately $5.4 trillion annually.

This network is the connective tissue between consumers, manufacturers, farmers, and domestic and international markets – and the Coast Guard is responsible for protecting it against cyber threats.

Over the summer, the Coast Guard released a new Cyber Strategic Outlook, its first update since 2015, and it is now integrating cyber risk management into vessel and facility safety, and security planning and operations.

The Coast Guard is also deploying cybersecurity specialists to major U.S. ports to oversee assessments, evaluate plans, and lead preparedness and response activities.

Starting this month, more than 2,300 maritime entities must submit a dedicated cyber plan to the Coast Guard; address any cybersecurity vulnerabilities identified in their Facility Security Assessments; and outline the owner or operator's cybersecurity mitigation measures.

These facilities and vessels are required to report cyber incidents.  The Coast Guard and CISA work closely together to respond to cyber incident reports, assess and mitigate risks to critical infrastructure, and provide oversight and technical support to industry.

At the same time, with most global trade transported on foreign ships, the Coast Guard is working with the International Maritime Organization and member countries to ensure that global cargo and passenger vessels conduct cyber risk assessments and develop mitigation plans under their existing safety management system.

These rules came into effect earlier this year, and they are now being implemented onboard ships calling at every American port.

As we combat cyber threats on our seas, we are also focusing on what is happening by land and air.

TSA's broad responsibilities cover security at our airports, highways and traffic management systems, pipelines, mass transit terminals and hubs, and subways and metros that carry billions of passengers every year.

Our freight rail system is essential not only to our economic well-being, but also to the ability of our military to move equipment from "Fort to Port" when needed.

In the aftermath of the Colonial attack, TSA issued two new security directives designed to strengthen the security of our nation's pipelines, requiring pipeline owners and operators to designate a cybersecurity coordinator, report cyber incidents to CISA within 12 hours, implement a number of basic hygiene measures, develop contingency plans in the event of a cyber attack, and subject their systems to robust vulnerability testing.

Applying lessons learned from that experience, TSA is now laying the foundation for a more secure and resilient aviation and surface transportation sector.

To strengthen the cybersecurity of our railroads and rail transit, TSA will issue a new security directive this year that will cover higher-risk railroad and rail transit entities and require them to identify a cybersecurity point person; report incidents to CISA; and put together a contingency and recovery plan in case they become a victim of malicious cyber activity.  We are coordinating and consulting with industry as we develop all of these plans.

For lower-risk surface entities, TSA will issue separate guidance that encourages, rather than requires, these entities to take the same measures.  Reducing cybersecurity risk is in every organization's self-interest, especially considering the indiscriminate nature of ransomware. 

Beyond the most urgent and important measures required by the security directive, TSA is initiating a rulemaking process to develop a longer-term regime to strengthen cybersecurity and resilience in the transportation sector.

To maximize industry input and inform this rulemaking process, TSA will issue an information circular recommending the completion of a cybersecurity self-assessment.

Mirroring these steps, TSA has begun updating its aviation security program.  By the close of this sprint, TSA will require critical U.S. airport operators, passenger aircraft operators, and all-cargo aircraft operators to designate a cybersecurity coordinator and report cyber incidents to CISA.  TSA will expand the covered entities gradually to other relevant entities and consider additional measures over time.

Taken together, these elements – a dedicated point of contact, cyber incident reporting, and contingency planning – represent the bare minimum of today's cybersecurity best practices.

We are also advancing initiatives like CISA's CyberSentry program, a voluntary partnership between government and business that helps us spot sophisticated threats early, understand how far they reach, share critical guidance, and collaborate with network defenders on responding swiftly and effectively.

Further, cybersecurity will be a top priority in the next cycle of FEMA's transportation-related grant programs to ensure we are driving funding toward key efforts.  A new working group with CISA, FEMA, TSA, and the Coast Guard is driving this forward.  In my first month in office, we already increased the required minimum spent on cybersecurity through FEMA grant awards to 7.5%, a significant increase across the country.

Throughout this process, we will continue working closely with the private sector to identify additional opportunities to work together and increase our collective cybersecurity baseline.

In many respects, our transportation sprint – and our Department-wide efforts – are a microcosm of our Administration's whole-of-government approach to cybersecurity.  And I have only just scratched the surface of what we are doing, as a Department and as an Administration, to meet this moment.  Every day, we dive deeper into new and innovative ways to up our cyber game. 

Before I finish, let me reiterate one more point: we can't do this alone.  As I have said before, the Department of Homeland Security is fundamentally a department of partnerships.  Our ability to execute our critical mission relies on the strength of our partnerships.  We need your expertise, perspective, and strategic guidance.  We need your partnership.

Please consider partnering with us, collaborating with us, or joining our team for a meaningful and challenging and fulfilling career in public service.  We want your voice at the table and we encourage differing views.  That's a hallmark of good government.

Tackling the cybersecurity challenges facing our Nation, our democracy, and our future requires our collective time, energy, expertise, and resources.  We are keen to team up with you.  Thank you so very much.

No comments:


Watch "Passion - How Great Is Our God (World Edition) [feat. Chris Tomlin]" on YouTube



43,748,905 views
Apr 12, 2013


I'm just a nobody
720,280 views • Sep 3, 2020


Christian Music CDs In Music on Christianbook.com




Make-A-Fort Snapwize Inc.

Free Logos Training Videos

About Me

My photo
Jesus Christ is alive and living in the hearts and lives of billions of Christians. I am interested in what He is saying and doing in the lives of those who know and love Him and interested in being a familiar and trusted blogger about Him

Dallas Theological Seminary Fighting Human Trafficking video on youtube

Human Trafficking Victims Program Introduction


She said two urls that are no longer the urls to use.
The first one, www.dhs.gov/humantrafficking automatically becomes www.dhs.gov/blue-campaign
The facebook site was the old site which does not automatically update to the following, the new facebook site is http://facebook.com/dhsbluecampaign
Click this link to search all of the DHS site for mentions of the Blue Campaign


The Ultimate Summary of C.S. Lewis

Kevin Livermore embedded Podcast Till We Have Faces. CS Lewis’ favorite book that he wrote

Intro image for Special Ops Feed widget

U.S. Army Special Operations Command RSS Feed

95.9 The Fish - Concerts RSS

Justice News

National Terrorism Advisory System Widget



Sky Spills Over


2,140,727 views May 27, 2015 This song is on the album "Sovereign" From Michael W. Smith
Sky Spills Over · Michael W. Smith
Sovereign
℗ 2014 The MWS Group, under exclusive license to Sparrow Records
Released on: 2014-01-01
Producer: Christopher Stevens
Composer Lyricist: Michael W. Smith
Composer Lyricist: Christopher Stevens
Composer Lyricist: Ryan Smith

MICHAEL W SMITH Twitter Widget
List of blog posts on this blog that are Twitter Widgets

Greg Laurie Harvest Podcast List Scrolling Widget



Greg Laurie Podcast





Greg Laurie Twitter Widget

LLC or Corp? Incorporate online at incorporate.com

Chemical Guys News Release

Training for Azure

The list of training opportunities below are similar to the example youtube videos above

Edureka Text Ads




Cyber Monday-Flat 30% OFF On All Live Courses -Coupon Code - CYB30
Weekend Offer - Flat 30% OFF On Live Courses, Coupon Code - EDUREKA30
Black Friday OFFER - Flat 20% OFF On Masters Courses - Coupon Code - BLACK20
Thanks Giving Day Offer -Flat 30% OFF On All Live Courses, coupon Code - THANKS30
Weekend Offer - Flat 30% OFF On Live Courses, Coupon Code - EDUREKA30
Flat 20% OFF On All Live Courses - Coupon Code - EDUREKA20
Flat 10% OFF on Any Masters Course - Coupon Code- MASTERS10
Be a Certified Big Data Expert Master Big Data, Hadoop, Spark, Cassandra, Talend and Kafka and become an unchallenged big data expert. Know more!
Be a Certified Cloud Architect Master Cloud Computing, AWS, DevOps and become an unchallenged cloud expert. Know more!
Be a Certified DevOps Engineer Master DevOps, Python, Docker, Splunk, AWS and Linux and become an unchallenged DevOps expert. Know more!
Be a Certified Data Scientist Master Data Science, Python, Spark, Tensorflow and Tableau and become an unchallenged data science expert. Know more!
MySQL DBA Live Online Training by Edureka
MySQL DBA Online Training by Edureka Gain expertise in MySQL Workbench, MySQL Server, Data Modeling, MySQL Connector, Database Design, MySQL Command line, MySQL Functions etc.
Flat 20% OFF
Flat 15% OFF
Flat 10% OFF
Become an Expert in Big Data and Analytics . View all courses!
Big Data and Analytics Live Online Training by Edureka
Become an Expert in Cloud Computing . View all courses!
Cloud Computing Live Online Training by Edureka
Become an Expert in Business Intelligence & Visualization . View all courses!
Business Intelligence & Visualization Live Online Training by Edureka
Become an Expert in DevOps. View all courses!
DevOps Live Online Training by Edureka
Become an Expert in Programming and Web Development.View all courses!
Become an Expert in Software Testing.View all courses!
Software Testing Live Online Training by Edureka
Become an Expert in Project Management.View all courses!
Become an Expert in Mobile App Development.View all courses!
Mobile App Development Live Online Training by Edureka
Become an Expert in Finance & Marketing.View all courses!
Finance & Marketing Live Online Training by Edureka
Become an Expert in Power BI.View upcoming batches!
Power BI Live Online Training by Edureka
Become an Expert in Docker.View upcoming batches!
Docker Live Online Training by Edureka
Become an Expert in AI and Deep Learning with TensorFlow.View upcoming batches!
AI & Deep Learning with TensorFlow Live Online Training
Become an Expert in Microsoft Azure.View upcoming batches!
Microsoft Azure Live Online Training
Become an Expert in ReactJS with Redux.View upcoming batches!
ReactJS with Redux Live Online Training
Become an Expert in Blockchain.View upcoming batches!
Blockchain Live Online Training
DevOps Live Online Training by Edureka
Top PMP exam preparation online course Crack PMP exam and get the pre-requisite 35 contact hours of project management education.
Linux Live Online Training Learn Installation, User Admin, Initialization, Server Config, Shell Scrip, Kerberos, Database Config. Know More
Node.js Online Training ExpressJS,EJS,Jade,Handlebars, Template,Gulp. Work on 5 Real-life Projects using Node JS
Web Developer Live Online Training by Edureka
Web Developer Online Training Learn HTML5, CSS3, JavaScript, jQuery,Twitter Bootstrap, Social Media Plugins. Know More!
Node.js Live Online Training by Edureka
Linux Admin Live Online Training by Edureka
Become an Expert in using Spring Framework. View Upcoming Batches!
Spring Live Online Training by Edureka
Talend Online Training Learn Talend Architecture, TOS, Hive in Talend, Pig in Talend. Work on Real-life Project, Get Certified.
Talend Live Online Training by Edureka
AWS Architect Live Online Training by Edureka
Informatica Live Online Training by Edureka
Java Live Online Training by Edureka
Python Live Online Training by Edureka
Openstack Live Online Training by Edureka
AngularJS Live Online Training by Edureka
Teradata Live Online Training by Edureka
Selenium Live Online Training by Edureka
Android Live Online Training by Edureka
Kafka Live Online Training by Edureka
Splunk Live Online Training by Edureka
Data Analytics Live Online Training by Edureka
Hadoop Admin Live Online Training by Edureka
Spark Live Online Training by Edureka
Big Data and Hadoop Live Online Training by Edureka
Data Science Live Online Training by Edureka
PMP Live Online Training by Edureka
Top online course certified by Project Management Institute (PMI) Get in-depth knowledge and understanding in various Agile Tool & Techniques.
Data Science Training by Edureka Drive Business Insights from Massive Data Sets Utilizing the Power of R Programming, Hadoop, and Machine Learning.
Big Data and Hadoop - Training by Edureka Become a Hadoop Expert by mastering MapReduce, Yarn, Pig, Hive, HBase, Oozie, Flume and Sqoop while working on industry based Use-cases and Projects. Know More!
Apache Spark and Scala - Training by Edureka Learn large-scale data processing by mastering the concepts of Scala, RDD, Spark Streaming, Spark SQL, MLlib and GraphX. Know More!
Hadoop Administration - Training by Edureka Become Hadoop Administrator by Planning, Deployment, Management, Monitoring & Tuning in Hadoop Cluster. Know More!
Analytics Training with R Master Regression, Data Mining, Predictive Analytics. Know More!
Splunk Certification Training Become an expert in searching, monitoring, analyzing and visualizing machine data in Splunk. Learn Splunk and get certified.
Financial Modeling with Advanced Valuation Techniques - Training by Edureka Become an expert in financial modeling by live online training conducted by industry experts. Know More!
Apache Kafka- Training by Edureka Become an expert in high throughput publish-subscribe distributed messaging system by mastering Kafka Cluster, Producers and Consumers, Kafka API, Kafka Integration with Hadoop, Storm and Spark. Know More!
Edureka - Live Online Training
Android Development- Training by Edureka Create Android apps, integrate them with Social Media, Google drive, Google maps, SQLite, etc. while working on Android Studio. Know More!
Testing With Selenium WebDriver- Training by Edureka Master the software automation testing framework for web applications using TDD, TestNG, Sikuli, JaCoCo. Know More!
Teradata Training by Edureka Become an expert in developing Data Warehousing applications using Teradata while working on real time use cases and projects. Get trained for TEO-141 and TEO-142 certifications. Know More!
AngularJS Training by Edureka Boost your web application development skills and become an invaluable SPA (single page application) developer. Know More!
SAS Certification Training by Edureka Become a Base SAS Expert by mastering the various concepts of SAS Language while working on real-life use cases and projects. Know More!
Openstack Training by Edureka Become an OpenStack expert by mastering concepts like Nova, Glance, Keystone, Neutron, Cinder, Trove, Heat, Celiometer and other OpenStack services. Know More!
Python Training by Edureka Learn Python the Big data way with integration of Machine learning, Hadoop, Pig, Hive and Web Scraping. Know More!
Java/J2EE and SOA - Training by Edureka Get a head start into Advance Java programming and get trained for both core and advanced Java concepts along with various Java frameworks like Hibernate & Spring. Know More!
Informatica PowerCenter 9.X Developer & Admin - Training by Edureka Master ETL and data mining using Informatica PowerCenter Designer. Know More!
DevOps Training by Edureka Gain expertise in various Devops processes and tools like Puppet, Jenkins, Nagios, GIT for automating multiple steps in SDLC, Ansible, SaltStack, Chef. Know More!
AWS Architect Certification Training by Edureka Master the skills to design cloud-based applications with Amazon Web Services. Know More!
Power BI Certification Training by Edureka Master the concepts about Power BI Desktop, Power BI Embedded, Power BI Map, Power BI DAX, Power BI SSRS. Know More!
Docker Certification Training by Edureka Master the Docker Hub, Docker Compose, Docker Swarm, Dockerfile, Docker Containers, Docker Engine, Docker Images. Know More!
Microsoft Azure Certification Training by Edureka Master the concepts like Azure Ad, Azure Storage, Azure SDK, Azure Cloud Services, Azure SQL Database, Azure Web App. Know More!
Tensorflow Certification Training by Edureka Master the concepts such as SoftMax function, Autoencoder Neural Networks, Restricted Boltzmann Machine (RBM). Know More!
Data Warehousing Live Online Training by Edureka
Data Warehousing & BI Live Online Training by Edureka

The Discontinued New Rick Livermore Site Rss Feed

powered by Surfing Waves

Christian Music Videos

NT Resources

Apologetics315

The Briefing - AlbertMohler.com

Daily Radio Program with Charles Stanley - In Touch Ministries

Boundaries Books

The Washington Times stories: Security

Judson Cornwall YouTube Video

YouTube Bible Gateway Basics Tutorial

Christian Bible Studies

In Touch TV Broadcast featuring Dr. Charles Stanley - In Touch Ministries

Spurgeon’s Morning and Evening

Answers with Ken Ham

Children Missing From CA

Renewing Your Mind with R.C. Sproul

Jim Daly

Bible.org Blogs

Crosswalk.com

Staff Picks

ICE Headline News Feed by Category - Human Smuggling/Trafficking

Something Good with Dr. Ron Jones

Justice News

Verse of the day Bible Gateway Widget










Contributions Welcome

The following request applies to any of the christian ministries that are currently getting visitors from my blog:

I am currently blogging: https://webmaster220.blogspot.com
I would like to place a banner on the right side of my home page that promotes your ministry
If I do that and it helps your ministry grow and expand do you have a suggestion as to what type of commission or contribution could be paid to my ministry. The reason I am saying that is there are a lot of ministries out there that are buying advertising space online and yours could be one of them for all I know. I have been an affiliate marketer for years on my blog but no commissions have ever been earned even though I am doing everything required to be done to earn the commissions. My blog readers are just not interested in spending any money on any of the goods or services discussed in my banner ads and text links. To reply, use the contact form below this paragraph Thanks, Rick Livermore - Webmaster220

Contact Form to contribute or pay the blog a commission

Name

Email *

Message *

Contact Form Introduction

Notice to authors:
I would like to add like minded authors to my blogger.com site. If you would like to be added email me a sample of what your writing is like to the "contact us" form here on this site. I will invite you as long as your example is suitable. Take a look at what type of a blog it is here

Contact Form

Name

Email *

Message *