Risk

7/14/2017
11:27 AM
Dark Reading
Dark Reading
Products and Releases
50%
50%

States Pledge to Meet Cyber Threats

Outgoing National Governors Association Chair Gov. McAuliffe Sunsets his Initiative, 38 Governors Sign Compact

PROVIDENCE, RI—Today National Governors Association (NGA) Chair Virginia Gov. Terry McAuliffe kicked off the 2017 NGA Summer Meeting with a discussion on how states continue to develop strategies to thwart cyber threats.

Over the last year, Gov. McAuliffe has spearheaded an effort to strengthen state cybersecurity through Meet the Threat: States Confront the Cyber Challenge, his NGA chair’s initiative.

“The goal of my initiative as NGA chair was to elevate the importance of cybersecurity on every governor’s agenda. To do that, we had to highlight why cybersecurity was more than just an information technology issue. I am proud that, throughout the last year, we have successfully engaged governors and their states on strengthening their cyber protocols and recognizing that cybersecurity is a technology issue, but it’s also a health issue, an education issue, a public safety issue, an economic issue and a democracy issue,” Gov. McAuliffe said.

Among the speakers joining him for the session were Matt Spence, partner at venture capital firm Andreesen Horowitz; Chris Bream, chief technology officer at IT company Tanium; and Wes Kremer, vice president of defense contractor Raytheon and president of Raytheon Integrated Defense Systems.

Gov. McAuliffe highlighted governors’ actions to boost cybersecurity defenses throughout the past year. “In New Mexico, Gov. Martinez signed legislation clarifying when the National Guard can be used during cyber events,” he said. “In Oregon, Gov. Brown signed an executive order to unify all cybersecurity efforts into one agency. Lastly, our incoming [NGA] chair, Gov. Sandoval, recently signed a bill to create a cyber defense center to lead all their cyber projects in Nevada.

“Since the launch of my initiative, more than 30 governors have signed an executive order, legislation or announced a cybersecurity initiative,” he continued, adding, “This has resulted in a dozen executive orders, 14 signed bills and 17 initiatives.”

Gov. McAuliffe also announced at the session that 38 governors across the country had signed on to a compact to improve state cybersecurity in which they pledged to enhance cybersecurity governance, prepare and defend their states from cybersecurity events and help grow the nation’s cyber workforce.

The work of Meet the Threat will live on, both in the Governor’s Guide to Cybersecurity, a comprehensive resource for state officials that outlines concrete steps they can take to bolster cybersecurity practices, and NGA’s Resource Center for State Cybersecurity, which Gov. McAuliffe co-chairs with Michigan Gov. Rick Snyder

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Understanding Evil Twin AP Attacks and How to Prevent Them
Ryan Orsi, Director of Product Management for Wi-Fi at WatchGuard Technologies,  11/14/2018
Veterans Find New Roles in Enterprise Cybersecurity
Kelly Sheridan, Staff Editor, Dark Reading,  11/12/2018
To Click or Not to Click: The Answer Is Easy
Kowsik Guruswamy, Chief Technology Officer at Menlo Security,  11/14/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Online Malware and Threats: A Profile of Today's Security Posture
Online Malware and Threats: A Profile of Today's Security Posture
This report offers insight on how security professionals plan to invest in cybersecurity, and how they are prioritizing their resources. Find out what your peers have planned today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-19301
PUBLISHED: 2018-11-15
tp4a TELEPORT 3.1.0 allows XSS via the login page because a crafted username is mishandled when an administrator later views the system log.
CVE-2018-5407
PUBLISHED: 2018-11-15
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
CVE-2018-14934
PUBLISHED: 2018-11-15
The Bluetooth subsystem on Polycom Trio devices with software before 5.5.4 has Incorrect Access Control. An attacker can connect without authentication and subsequently record audio from the device microphone.
CVE-2018-14935
PUBLISHED: 2018-11-15
The Web administration console on Polycom Trio devices with software before 5.5.4 has XSS.
CVE-2018-16619
PUBLISHED: 2018-11-15
Sonatype Nexus Repository Manager before 3.14 allows XSS.