- Product
Product Overview
Sophisticated security with unmatched simplicityCloud SIEM
Pre-configured detections across your environmentHoneypots
Deception technology to detect lateral movementEndpoint Visibility
Real-time monitoring with added detection & responseSecurity Reports
Data visualizations, compliance reports, and executive summariesAutomated Response
Detect, prioritize, and neutralize threats around the clockIntegrations
Cloud, on-prem, and open API connectionsXDR Platform
A complete view to identify risk, and things operational
- Pricing
- Why Blumira
Why Blumira
The Security Operations platform IT teams loveWatch A Demo
See Blumira in action and how it builds operational resilienceUse Cases
A unified security solution for every challengePricing
Unlimited data and predictable pricing structureCompany
Our human-centered approach to cybersecurityCompare Blumira
Find out how Blumira stacks up to similar security toolsIntegrations
Cloud, on-prem, and open API connectionsCustomer Stories
Learn how others like you found success with Blumira
- Solutions
- Partners
- Resources
The Biden administration signed an executive order on Wednesday that aims to bolster cybersecurity defenses.
The executive order follows a wake of major cyberattacks, including the Colonial Pipeline ransomware attack that began on Thursday, May 6 that caused the operator to shut down 5,500 miles of pipeline across the United States.
“This ransomware attack does rise to the level of the Biden administration taking a hard look at ransomware and treating it like a true national security threat,” said Mike Behrmann, Director of Security at Blumira. “These threats need to be taken even more seriously because of the probability of which they can happen.”
Why Is It Important?
The initiative requires organizations to report certain information about cyber breaches, attempting to break down contractual barriers that limit information sharing.
The report reads, “Removing these contractual barriers and increasing the sharing of information about such threats, incidents, and risks are necessary steps to accelerating incident deterrence, prevention, and response efforts and to enabling more effective defense of agencies’ systems and of information collected, processed, and maintained by or for the Federal Government.”
There must be strong public-private partnerships that make it easier for companies to report a cybersecurity incident, said Behrmann, who has prior experience in the National Security Agency and the FBI.
The National Cyber Forensics and Training Alliance, for example, brought together law enforcement, cybersecurity academics, and the commercial sector in a safe place where they could exchange ideas.
“What’s most important is being able to quietly but helpfully report cyber incidents,” he said. “Corporations don’t necessarily want a lot of publicity when something like this happens.”
The White House order also requires that federal agencies, including cloud service providers, “provide logs to the Secretary of Homeland Security through the Director of CISA and to the FBI.”
The Biden Administration’s decision to empower the CISA is particularly noteworthy, Behrmann said.
“Not only will the CISA now essentially carry the flag for other agencies to follow suit, but they are also part of the Department of Homeland Security, which has been very slow to be given any real juice within the federal government framework.”
“To me, this speaks to the CISA’s public efforts providing public guidance on major threats such as the Russian SVR and SolarWinds in their capacity as US-CERT,” he continued.
The initiative also orders FCEB (federal civilian executive branch) agencies to deploy an EDR (endpoint detection and response) initiative to “support proactive detection of cybersecurity incidents within Federal Government infrastructure, active cyber hunting, containment and remediation, and incident response.”
“Explicitly recognizing proactive detection is something that we prescribe to all of our clients at Blumira,” Behrmann said. “Mandating this across federal agencies is just plain smart, and should only bolster each agency’s cybersecurity posture away from a purely reactive model.”
“The EDR initiative is a good example of why Sysmon is so useful and powerful on the host,” added Matt Warner, CTO of Blumira. “Continuing that pattern will only help.”
Erica Mixon
Erica is an award-winning writer, editor and journalist with over ten years of experience in the digital publishing industry. She holds a Bachelor’s degree in writing, literature and publishing from Emerson College. Her foray into technology began at TechTarget, where she provided editorial coverage on a wide variety...
More from the blog
View All Posts
Security Trends and Info
3 min read
| February 1, 2021
Blumira's Security Advisor Series: Cost of Ransomware vs. Cloud SIEM
Read More
Security How-To
2 min read
| September 28, 2021
Stay Ahead in Ransomware Crisis
Read More
Conferences and Events
7 min read
| May 12, 2021
Top 10 RSA Conference Sessions To Add To Your Schedule
Read MoreSubscribe to email updates
Stay up-to-date on what's happening at this blog and get additional content about the benefits of subscribing.