Biden promises tough response to cyber attacks
President-elect promises that he "won't stand idly by" when nation-states hack US


President-elect Joe Biden has taken a stance on the recently discovered hack of US government and private sector systems, promising to hold adversaries accountable. In a statement issued by his transition team, Biden said he had already been briefed by government officials on the attack and would make dealing with it a priority when it took office.
Biden promised to strengthen partnerships with the private sector and expand investments in cyber security infrastructure, but he also hinted at a more hawkish cyber security approach.
"A good defense isn’t enough; we need to disrupt and deter our adversaries from undertaking significant cyber attacks in the first place," Biden said. "We will do that by, among other things, imposing substantial costs on those responsible for such malicious attacks, including in coordination with our allies and partners. Our adversaries should know that, as President, I will not stand idly by in the face of cyber assaults on our nation."
In the last few days, government officials and private sector companies have discovered the scope of a massive cyber attack on US government and private sector systems. The attack, delivered via malicious code injected into SolarWinds' IT monitoring software, is ongoing, officials warned. In an update, Microsoft president Brad Smith called the incident, believed now to have been engineered by Russia, "an attack on the United States and its government and other critical institutions."
Biden has a tough job ahead of him. "This is big," said Sue Gordon, who served as principal deputy director of national intelligence in the Office of the Director of National Intelligence (DNI) until resigning from the position in August 2019, likening it to the Office of Personnel Management hack revealed in 2015. "Even bigger than that because this is public and private, and global," Gordon said, pointing out that the problem is ongoing. "This is not only problematic in terms of the information, but problematic in terms of getting rid of it."
President Trump remained silent on the hack this week. During his term as president, more than a third of his National Infrastructure Advisory Council members quit, citing "insufficient attention to the growing threats to the cybersecurity of the critical systems upon which all Americans depend."
Trump appointed Bush-era security advisor Tom Bossert to head up the administration's cyber security efforts, but the White House's John Bolton removed him in April 2018, leaving the position vacant.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
In 2018, senators announced the bipartisan Cyber Deterrence and Response Act that would have forced the president to act against overseas hackers found targeting the US or explain why he hadn't. However, lawmakers failed to pass the bill.
Danny Bradbury has been a print journalist specialising in technology since 1989 and a freelance writer since 1994. He has written for national publications on both sides of the Atlantic and has won awards for his investigative cybersecurity journalism work and his arts and culture writing.
Danny writes about many different technology issues for audiences ranging from consumers through to software developers and CIOs. He also ghostwrites articles for many C-suite business executives in the technology sector and has worked as a presenter for multiple webinars and podcasts.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
UK cyber experts on red alert after Salt Typhoon attacks on US telcos
Analysis The UK could be next in a spate of state-sponsored attacks on telecoms infrastructure
By Solomon Klappholz Published
-
Healthcare data breaches are out of control – here's how the US plans to beef up security standards
News Changes to HIPAA security rules will require organizations to implement MFA, network segmentation, and more
By Solomon Klappholz Published
-
The US could be set to ban TP-Link routers
News US authorities could be lining up the largest equipment proscription since the 2019 ban on Huawei networking infrastructure
By Solomon Klappholz Published
-
Three ways to evolve your security operations
Whitepaper Why current approaches aren’t working
By ITPro Published
-
Beat cyber criminals at their own game
Whitepaper A guide to winning the vulnerability race and protection your organization
By ITPro Published
-
Quantifying the public vulnerability market: 2022 edition
Whitepaper An analysis of vulnerability disclosures, impact severity, and product analysis
By ITPro Published
-
Same cyberthreat, different story
Whitepaper How security, risk, and technology asset management teams collaborate to easily manage vulnerabilities
By ITPro Published
-
US government IT contractor could face death penalty over espionage charges
News The IT pro faces two espionage charges, each of which could lead to a death sentence or life imprisonment, prosecutors said
By Ross Kelly Published