EU Cyber Resilience Act (CRA) Clears Penultimate Step
5 min read
EU Cyber Resilience Act (CRA) Clears Penultimate Step
By Eric Byres on December 8, 2023

On December 3rd, the EU's new Cyber Resilience Act (CRA) got a big step closer to being adopted when the European Parliament and the EU Council reached an agreement on the legislation. It...

Continue Reading
A Flurry of Regulatory Action and the Need for SBOMs
5 min read
A Flurry of Regulatory Action and the Need for SBOMs
By Eric Byres on October 12, 2022

Executive Order 14028 on Improving the Nation's Cybersecurity was issued in May of 2021 and provided a roadmap for a series of regulatory initiatives that government agencies (and anyone...

Continue Reading
Sorry Blackberry: You Are Part of the Supply Chain
2 min read
Sorry Blackberry: You Are Part of the Supply Chain
By Eric Byres on November 2, 2021

Today, reporters Betsy Woodruff Swan and Eric Geller at Politico published a story: “BlackBerry resisted announcing major flaw in software powering cars, hospital equipment.” They outline...

Continue Reading
NTIA Publishes Minimum Components of an SBOM
4 min read
NTIA Publishes Minimum Components of an SBOM
By Derek Kruszewski on July 15, 2021

In today’s blog post I’d like to recognize all the hard work done by NTIA (National Telecommunications and Information Administration) and congratulate them on publishing the minimum...

Continue Reading
Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 4
5 min read
Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 4
By Eric Byres on May 26, 2021

Section 3 - Less Fog, More Cloud Section 3: Modernizing Federal Government Cybersecurity of the Executive Order is all about government agencies moving to the cloud and doing it right. If...

Continue Reading
Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 3
3 min read
Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 3
By Eric Byres on May 21, 2021

So you don’t sell to the Feds… Today’s blog is going to take a break from analyzing a specific section of the Executive Order on Improving the Nation’s Cybersecurity and focus on who will...

Continue Reading
Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 2
3 min read
Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 2
By Eric Byres on May 18, 2021

Removing Barriers to Sharing Threat Information On Friday we dissected Section 4: Enhancing Software Supply Chain Security of the new Executive Order on Improving the Nation’s Cybersecurity...

Continue Reading
Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 1
4 min read
Unpacking EO14028: Improving the Nation's Cybersecurity - Pt. 1
By Eric Byres on May 14, 2021

Late Wednesday night President Biden signed the Executive Order on Improving the Nation’s Cybersecurity. Compared to any Executive Order (EO) I’ve seen, this is a massive and complex...

Continue Reading
Wrapping Up 2020 with Dale Peterson
2 min read
Wrapping Up 2020 with Dale Peterson
By Eric Byres on January 7, 2021

Wrapping up my year on December 31, I was delighted to join ICS cybersecurity luminary Dale Peterson for his December: ICS Security Month in Review episode of the Unsolicited Response...

Continue Reading
Three Things the SolarWinds Supply Chain Attack Can Teach Us
4 min read
Three Things the SolarWinds Supply Chain Attack Can Teach Us
By Eric Byres on December 18, 2020

Just in case you missed it, a software supply chain attack on the US government and industries is consuming the waking hours of everyone involved in cyber security this week. The attack...

Continue Reading
Loading more posts
No more posts to load
1 2

Stay up to date