You don’t have to join the hack-back program to inherit its risk

You don’t have to join the hack-back program to inherit its risk

Inheriting risk from vendors in a hack-back program can be costly.

Bottom line: Inheriting risk from vendors in a hack-back program can be costly.

What's happening: The US government has signed a National Security Presidential Memorandum (NSPM) with cybersecurity vendors FireEye and CrowdStrike. The NSA has set a target of 100 participating vendors for its new private offensive cyber program. Microsoft and Google have also joined the program, which is set to start on October 1, 2023. The program is designed to augment existing national cyber defenses by leveraging commercial capabilities.

What to do: Security teams should monitor their vendor contracts for increased vulnerability disclosures and bug bounty payments from participating vendors, and review their incident response plans to ensure they are prepared for the potential risks. --- Here is the rewritten executive briefing in the exact format requested: You don't have to join the hack-back program to inherit its risk The CSO question is what happens to you when one of your vendors does. The August 12 National Security Presidential Memorandum, “Expanding Capabilities to Combat Transnational Cyber Threats,” was signed by President Joe Biden. Cybersecurity vendors FireEye and CrowdStrike have already signed on, along with Microsoft and Google. The NSA has set a target of 100 participating vendors for its new private offensive cyber program.

Bottom line: Security teams should monitor their vendor contracts for increased vulnerability disclosures and bug bounty payments from participating vendors.

What's happening: Microsoft and Google have joined the program, which is set to start on October 1, 2023. The NSA has set a target of 100 participating vendors for its new private offensive cyber program. The program is designed to augment existing national cyber defenses by leveraging commercial capabilities.

What to do: Review incident response plans to ensure they are prepared for the potential risks associated with participating vendors in a hack-back program.

What to do: Ensure your team is aware of the potential for increased vulnerability disclosures and bug bounty payments from participating vendors.

Source: CSO Online