A report that Democrats on the Senate Homeland Security and Governmental Affairs Committee issued on Tuesday asserts that ransomware attacks are surging even as federal efforts to respond to them are not up to the task. This is pulled from CyberScoop, citing that the report concludes that the government is struggling to keep up with the problem in part because data reporting and collection on ransomware attacks and payments is “fragmented and incomplete.”
The Washington Post covers comments by Rep. Elissa Slotkin (D-Mich.), citing a need for broader options to push back on nations that violate the norms online, which could include blocking nations from the international financial system or dramatically restricting trade with them. During the same discussion, Rep. Michael McCaul (R-Tex.) urged more robust work with U.S. allies to establish rules of the road in cyberspace and the consequences for nations that violate them.
The Post also covers the deployment of new monitoring tools at CISA to give broad visibility to hacking threats across the civilian government and newly expanded authority to force agencies to fix digital vulnerabilities before hackers exploit them.
Legislation is gaining traction, too – Politico noted both the Better Cybercrime Metrics Act and the National Cybersecurity Preparedness Consortium Act earlier this month, and the House passed around half a dozen cyber-related bills in the last two weeks, including measures to provide cyber funding to state and local governments and to strengthen the federal cyber workforce. The pace is deliberate – and intentional. There are more on the horizon, as the Hose reviews ones passed by the Senate and the bipartisan intragovernmental Cybersecurity Information Sharing Act, which would require the DHS to enter into cyber information sharing agreements with the House and Senate.
You can’t manage what you don’t measure, right? Well, the US government is starting to measure. This much activity is going to end up with results. On Monday, I noted how many providers think the current level of regulation is too much. And we have a wave more coming.
It’s a rather fundamental shift going on here. “Regulation is coming” was the mantra… but rather than a light at the end of a long tunnel, now we can make out the details on the front of the train.
I’m confident there is money to be made here… I worry about those providers who aren’t geared, or gearing, up with a process to monitor and manage the legal landscape. How’s that complaining about too much regulation working out for you?

