As China hacking threat builds, Biden to order tougher cybersecurity standards

Published 01/10/2025, 04:16 PM
Updated 01/10/2025, 05:52 PM
© Reuters. U.S. President Joe Biden speaks at a media briefing in the Oval Office at the White House in Washington, U.S., January 10, 2025. REUTERS/Elizabeth Frantz
MSFT
-
S
-

By AJ Vicens

DETROIT (Reuters) - President Joe Biden is calling for tighter cybersecurity standards for federal agencies and contractors in a new executive order due to be published in the coming days, pushing reforms designed to address repeated Chinese-linked cyber operations and cybercriminal operations, according to a draft of the order seen by Reuters.

The order is set to land in the waning days of Biden’s presidency, during which several high-profile, Chinese-linked hacks occurred, according to the U.S. government and cybersecurity research groups. The alleged activity targeted critical infrastructure, government emails, major telecom firms and, most recently, the U.S. Treasury Department. Beijing has rejected the allegations.

Biden's proposal calls for tougher standards for secure software development, the ability to verify that those standards have been met, and a process for the Cybersecurity and Infrastructure Security Agency (CISA) to evaluate the process, according to the draft.

Vendors will have to provide secure software development documentation to be evaluated and validated by CISA through the agency's software attestation program. Attestations that "fail validation" could be referred to the attorney general for “action as appropriate,” according to the draft.

Tom Kellermann, senior vice president of cyber strategy at cybersecurity company Contrast Security, said the attestation provisions do not go far enough but that he “applauds” the efforts to push more secure software development. The timelines for implementation laid out by the order seem “arbitrary,” he said, given the immediacy of the threats from China, Russia and powerful cybercriminal syndicates.

“They’re already here,” Kellermann said. “We are dealing with literally an insurgency across critical infrastructure and U.S. government agencies that has been stoked by the Russians and Chinese.”

The order also mandates the development of guidelines to securely manage access tokens and cryptographic keys used by cloud providers. Chinese-linked hackers abused this method to access email accounts used by top U.S. government officials in May of 2023, Microsoft (NASDAQ:MSFT) said at the time.

Brandon Wales, vice president of cybersecurity strategy at cybersecurity company SentinelOne (NYSE:S) and formerly a top CISA official, told Reuters the order builds on ongoing work over the last five years to develop capabilities, get the right authorities, and funding. While the threat from China looms large – a “pacing threat” that is “driving the urgency and focus across the government” – the U.S. government and the private sector face a plethora of threats that need to be addressed.

© Reuters. U.S. President Joe Biden speaks at a media briefing in the Oval Office at the White House in Washington, U.S., January 10, 2025. REUTERS/Elizabeth Frantz

“It makes sense to continue to look for ways to get the most value out of capabilities that have been built over the past two administrations,” Wales said. 

The White House declined to comment and CISA did not respond to a request for comment.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2025 - Fusion Media Limited. All Rights Reserved.