VA won’t deploy EHR to more sites until 2022
The Department of Veterans Affairs won’t continue rolling out its new electronic health records (EHR) program to any new sites until 2022, a top VA official told Congress Wednesday.
Dr. Carolyn Clancy, deputy undersecretary for health at the VA, said a new schedule to deploy the system across the country won’t be ready until the end of the year. This comes after the VA’s recent strategic review of the program led the department to restructure the EHR’s rollout schedule to be based on which medical centers have the infrastructure ready.
The program was initially paused for the review in March, resulting in eight recommendations to improve the $16 billion, 10-year program. The cloud-based system from Cerner is designed to be interoperable with the Department of Defense’s new EHR platform and replace the legacy Veterans Health Information System Technology Architecture (VistA).
“We will not be scheduling any deployments in the next six months; the secretary is optimistic that end of this calendar year he will be able to discern a new deployment schedule,” Clancy told the House Veterans Affairs Committee.
That news was received well by some committee members who remain skeptical about the new system and want to see more proof that it can improve health outcomes.
“It would be irresponsible to deploy the Cerner system … until the bugs are worked out,” ranking member Rep. Mike Bost, R-Ill., said.
The VA is also re-working the cost estimates for the program after its inspector general found the initial estimates were as much as $2.6 billion short of what could be needed.
“We should have been far more transparent,” Clancy said about the initial cost estimate for the program.
Following the hearing, full committee Chair Rep. Mark Takano, D-Calif., and Bost announced a new bill that would require the VA report on the EHR’s costs every three months. Names the VA Electronic Health Record Transparency Act of 2021, the bill would require the reports to include all expenses in the program include infrastructure upgrade costs, which had been counted separately.
“Given this month’s Inspector General reports and what we heard at today’s hearing, it’s clear we need a full accounting of all costs associated with VA’s EHRM project,” Takano said in a statement. “I’ve heard some concerning information about the state of the EHRM project, and I’m worried that the total cost estimate was vastly underestimated by the previous administration.”
NASA won’t rush Mars mission over U.S. ‘space race’ with China
NASA won’t rush its planned mission to Mars in the late 2030s and risk human life, despite being in a “space race” with China, said Administrator Bill Nelson on Wednesday.
The agency awarded a now-contested contract to SpaceX in February to launch the initial components of the Gateway lunar outpost, where the rocket and supplies for the Mars mission will eventually be assembled.
NASA expects a decision from the Government Accountability Office in the next few weeks and to launch by the end of 2021, but China announced an ambitious plan to send astronauts to Mars by 2033 in June.
“The Chinese space program is also a military space program,” Nelson said, during a live interview with the Washington Post. “They are very aggressive and very good, and a lot of that success has come in the last few years.”
China was the second country to land a rover on Mars after the U.S. with plans to return samples from the planet to Earth “probably within the same timeframe,” Nelson said.
But the Pentagon has also reported Chinese development of anti-satellite weapons that threaten global communications and space exploration.
“The Chinese are very intolerant of any examination of their space program,” Nelson said. “They are very inflexible; they are not very transparent.”
Nelson contrasted that with Russia, which began cooperating with the U.S. on space missions during the Cold War and launched another “major component” of the International Space Station (ISS) from the Baikonur Cosmodrome in Kazakhstan on Wednesday.
NASA’s administrator said he’d support cooperation with China on space missions if they’d “open up,” but in the meantime, one of their satellites exploded in low-Earth orbit near the ISS and one of their rockets landed in the Indian Ocean without a controlled reentry.
“Space is the high ground and the important ground in trying to protect the interests of our country and the free world,” Nelson said.
Nelson said he also supported expanding public-private partnerships in space exploration. Commercial 3D printing of rockets will reduce the cost of space travel and make it more “accessible,” while SpaceX’s fixed-price contract to deliver cargo and crew to the ISS is enabling commercial space efforts, he said.
NASA will require that any space tourists going to the ISS endure the same training and medical and psychological training as its own astronauts so as not to interfere with their research, Nelson said.
“Yes there may be Bezos ideas of colonies out in space; yes there may be colonizing of Mars,” he said. “But we need to have the vision to get there and develop the technologies in order to sustain human life.”
NASA will “aggressively” look for evidence of life in samples returned from Mars and Venus, and a new space telescope will launch at the end of 2021 designed to look at the source of light 13.35 billion years ago, shortly after the Big Bang, in a search for other planets that might support life, Nelson said.
Closer to home NASA deployed a “phalanx” of satellites measuring climate effects, he said.
“In the next 10 years we’re going to put up five great observatories, and we’re going to look at oceans and land and ice and the atmosphere,” Nelson said. “And we’re going to compile a 3D composite of the minute changes that are occurring so that we can better project what we’ve got to do in order to save our planet by saving our climate.”
Air Force inks new ABMS concept document
The Air Force signed a new document solidifying the foundational concepts that underpin one of its highest priority technology modernization programs, the Advanced Battle Management System (ABMS).
The “JADC2 Supporting Concept” document will guide changes the Air Force will make in how it is connecting data from sensors across a battlefield through the Advanced Battle Management System. ABMS is essentially the Air Force’s internet of things for war, made within the broader framework of Joint All-Domain Command and Control (JADC2) that aims to get the entire military to link its sensors and platforms across all domains of battle.
“[W]e just got the JADC2 Supporting Concept signed. The document guides the USAF concept-driven, threat-informed JADC2 capability development to include doctrine, training materiel and personnel,” an Air Force spokesperson told FedScoop in response to inquiries about the document.
The document was created by the cross-functional team working on ABMS led by Brig. Gen. Jeffery Valenzia.
The ABMS family of technologies aims to improve the data linkage and overall connectivity of weapons systems and platforms the Air Force uses. Currently, the Air Force uses a construct and technology that rely on both legacy systems and processes. For example, in surveilling targets, an airman often has to watch a drone feed and manually count how many people appear on screen, instead of the drone feeding its data directly to a computer-vision algorithm and that data then sent to fighter jets with payloads, as is the intent with ABMS and JADC2.
The Supporting Concept document is more foundational work that is specific to the Air Force, though it has JADC2 in its name, the spokesperson said.
Other services have their own programs that follow the JADC2 framework recently spelled out in a new strategy document approved by Defense Secretary Lloyd Austin. The Army has Project Convergence and the Navy runs Project Overmatch as their contributions to JADC2. Each of the three follows the general framework of JADC2 and works with a JADC2 cross-functional team on the Joint Staff to coordinate their efforts.
Agency reuse of FedRAMP-approved cloud products climbs with automation
Agency reuse of cloud products authorized by the Federal Risk and Authorization Management Program (FedRAMP) continues to increase, with the program management office (PMO) automating parts of the process in fiscal 2021.
Reuse of security authorization packages is up 85% compared to pre-pandemic levels, and agency demand for cloud products grew 60% in the first half of fiscal 2021 compared to the first half of fiscal 2020.
Increases in reuse and demand coincide with the FedRAMP PMO’s work with the National Institute of Standards and Technology to standardize authorization packages and automate their review with the Open Security Controls Assessment Language (OSCAL).
“NIST recently released OSCAL Version 1, which is the first major release of OSCAL and provides a stable OSCAL platform for wide-scale implementation,” said Brian Conrad, acting FedRAMP director and program manager for cybersecurity at the General Services Administration, during a Carahsoft virtual event Tuesday. “And this release also marks an important milestone for the OSCAL project and for early adopters and implementers of security automation with OSCAL.”
Machine-readable authorization packages will allow cloud service providers (CSPs) to create system security plans faster and validate much of the content before submitting it for government review. Meanwhile, agencies can expedite their reviews, and third-party assessment organizations (3PAOs) can automate planning, execution and reporting of their activities.
The FedRAMP PMO is developing conversion tools that will reduce review times further and hopefully increase OSCAL adoption.
“We’re really excited about the next step in that we’re going to pilot some of these validation tools with users,” Conrad said. “We have cloud service providers and 3PAOs and agencies, for that matter, stepping up — willing to take part in those pilot programs.”
At the same time, the FedRAMP PMO has teamed with the Department of Homeland Security, Cybersecurity and Infrastructure Security Agency, and .govCAR to score security controls based on how well they detect and respond to real-world threats. The threat-based authorization approach speeds up the process further by using fewer resources and focusing control implementations on the current threat landscape, Conrad said.
The FedRAMP PMO is currently considering new baselines using the NIST Special Publication 800-53 Rev. 5 security and privacy controls.
Another area the FedRAMP PMO wants to automate is continuous monitoring, having developed a web services application programming interface (API) specification allowing CSPs already using OSCAL to push and pull data to and from a secure repository — eliminating manual processes.
President Biden‘s cybersecurity executive order issued in May has the FedRAMP PMO reevaluating its business processes and automating routine messages to CSPs at every stage of authorization.
The office also recently released guidance on Incident Communications Procedures; Vulnerability Scanning Requirements for Containers; and updated low, moderate and high baselines for System Services & Acquisition-4 (SA-4) and Incident Response-3 (IR-3) controls.
More guidance is on the way.
“FedRAMP is releasing an Authorization Boundary Guidance for public comment in July,” Conrad said. “This one is really critical; we get a lot of questions from stakeholders on this.”
Rep. Gerry Connolly, D-Va., provided an update Tuesday on his FedRAMP Authorization Act, which would codify the program. Introduced for the third time in a year in January, the bill was the first to pass the House in the 117th Congress and passed unanimously.
The legislation would reduce duplication of security assessments by establishing a “presumption of adequacy” if an agency already authorized a particular cloud product, require agencies to prioritize reusing products, establish a Federal Secure Cloud Advisory Committee, and fund the program at $20 million annually.
“While this has been a long journey, I’m happy to say that, with new leadership in the Senate, we’re working in lockstep with our colleagues over there to try and finally get this bill for a markup in the Senate or attached to this year’s Defense Authorization Act,” Connolly said.
Coast Guard ‘lacks control’ over telework data, GAO finds
The U.S. Coast Guard‘s plans to continue using telework could be derailed by weak data verification of how many of its members are still working remotely, the Government Accountability Office found in a new report.
The maritime service might not be conducting its needed weekly audits of the surveys it collects on who is teleworking, potentially clouding the picture of how many people need tech to support their connectivity outside of Coast Guard offices. Working with inaccurate data could lead to poor planning for future technical requirements and budgeting to support the Coast Guard’s IT, the report found.
“Coast Guard officials could not provide assurance or evidence that weekly audits purposefully designed to verify the accuracy and completeness of these data were being conducted,” the report states. “Without such assurance, the Coast Guard may be relying on inaccurate and incomplete information when making decisions that rely on these data, such as for assessing its operational readiness.”
The Coast Guard, a part of the Department of Homeland Security, also could not confirm how many telework agreements it had signed with employees and guardsmen, further obfuscating the telework picture. The GAO recommended the service remedy the situation by implementing plans to ensure everyone working remotely has a teleworking agreement, auditing telework survey data and put in place additional controls to ensure supervisors review telework agreements at least annually.
“GAO found that the Coast Guard lacks controls over telework documentation and its personnel data are not reliable,” the report stated.
Coast Guard officials want many employees and guardsmen to continue to telework for the foreseeable future, a prospect the GAO warns requires careful analysis of its telework data to ensure it has enough back-end tech to support.
Interviews the GAO conducted also showed that at the beginning of the pandemic, the service lacked bandwidth and laptops to support its staff working from home. Money from the CARES Act provided the Coast Guard with the needed equipment, but how it is being used and in what capacity is not apparent due to the lack of data audits on its telework surveys.
“During the pandemic, the Coast Guard has faced challenges in balancing the need to safeguard its personnel with its responsibility to continue missions and operations,” according to the report.
The Coast Guard has been on a “tech revolution” since 2020 to modernize its aging systems and migrate its tech to the cloud. Commandant Karl Schultz said the service needed to dig itself out of the ’90s to improve connectivity on both its cutters and offices ashore. During that time, the service has added Wi-Fi to some cutters and replaced outdated desktops with “two-in-one tablets.”
Under C2E, IC’s top challenge is turning cloud competitors into partners
The intelligence community has five cloud providers in place to soon deliver capabilities under its multibillion-dollar Commercial Cloud Enterprise (C2E) contract. But now comes the hard part: incentivizing those companies to work together rather than compete for task orders under the larger contract.
Acting intelligence community CIO Michael Waschull pointed to this dynamic of collaborating competitors as the greatest challenge the IC faces in moving to the C2E multi-cloud contract from single-cloud predecessor, the Commercial Cloud Services (C2S) vehicle.
Last fall, the contract manager CIA awarded the cloud services portion of C2E to Amazon, Google, IBM, Microsoft and Oracle. The new multi-cloud contract will have a 15-year period of performance and be worth “tens of billions” of dollars, according to contracting documents. The contract holders will compete for task orders at various levels of classification, up to the top-secret level.
Waschull told FedScoop “the idea of five different world-class cloud providers, bringing their capabilities, their knowledge, skills, and their capacity to bear on our problems and allowing the components within the IC to pick and choose so we can tailor and devise a best-fit molecule of capabilities, that shows great promise.” However, he said, that’s “if and only if I can overcome the one big obstacle that stands in our way: How do we incentivize collaboration, cooperation, communication, and mutual support between and among what are frankly these five competitors.”
The model is ideal for the IC but runs contrary to the values of the profit-driven private sector.
“By their very nature, they are private sector mission partners, they are motivated by profit, they are motivated by competition,” Waschull said. “We’ve got to instill a core value in that we appreciate collaboration and cooperation, more than we appreciate any single technical provision or any single lowest price.”
He added: “We want best value. We want to promote integration of effort, promote each different competitor understanding not only their product lines but understanding the capabilities and limitations of their competitors’ product lines so that they can work together to come up with the best possible technical and business solution to the government’s needs.”
Waschull, who spent part of his career with the Missile Defense Agency, compares this environment to MDA’s model for the Missile Defense National Team, which brings together leaders in the aerospace sector like Lockheed Martin, Boeing and Raytheon to support the agency’s Ballistic Missile Defense System.
“If we can do here, with our cloud efforts, what they have done there with their missile defense efforts and forgo competition in lieu of cooperation and collaboration, we will be in a great place,” he said.
The Department of Defense stands to learn from the IC’s venture into this multi-cloud model after it recently announced it will go down a similar path, canceling its failed single-vendor cloud acquisition, the Joint Enterprise Defense Infrastructure (JEDI).
To further support such a model, the IC is also planning to bring on a systems integrator through a second, separate contract under C2E to help manage this environment — “providing knowledge, skill and ability to help the government make the best possible choices to devise that best-fit formula for cloud capacity and capability,” Waschull said.
In the past, the IC has had consultants to advise on such IT procurements. But this integrator will be a built-in partner whose “award fees are predicated upon helping us make not only the best technical decisions for the implementation of cloud capacity across our enterprise but to understand the various pricing models from each particular vendor,” Waschull said.
“Understanding volume discounts, understanding the way they compute pricing and knowing it so well that they can advise the government to say between two or three equally competitive technical approaches, from a business perspective, this is the way you want to go,” he said. “Having that kind of incentivized professional analysis to help guide the decisions we’re gonna make, I think is wicked powerful.”
The cloud services portion of the C2E contract and the five providers are working to reach initial operational capability status to begin work. Until the integrator contract is awarded, they are supported by the CIA Cloudworks Program Management Office, said Waschull, who meets with the providers individually and as a group on a monthly basis to discuss challenges, opportunities and their perspectives.
When this multi-cloud capability does come online, the “unity of effort sets the stage, sets the table to take us to the next level,” Waschull said.
“When we look at 21st-century warfighting in a peer competitor environment and the volumes of data coming down from our overhead constellations, being generated locally by artificial intelligence and machine learning applications and being exchanged to competitive advantage between and among IC components, warfighters and others — that is a huge problem set,” he said. “But these building blocks really lend themselves to be able to come up with those creative solutions that will enable us to manage the volume and velocity of the information that we’ve got to move around.”
Waschull concluded: “Having these best of breed cloud contributors in the fight with us, if we can find the magic sauce that gets them to work together, cooperatively and collaboratively, we’re going to be in a far more competitive place than our neighbors that we have to deal with in this 21st-century competition.”
OMB reaffirms commitment to hiring diverse cloud tech talent
The Office of Management and Budget has reaffirmed the Biden Administration’s commitment to hiring cloud technology experts from a more diverse talent pool.
In a statement to FedScoop, an agency official said the administration is focused on developing a new talent pipeline, including through workforce exchange programs and partnerships with educational institutions.
“The federal government recognizes the changing workforce and ever-changing technological landscape and is working to support the IT workforce through reskilling, training, career growth opportunities and worker flexibility in order to recruit and hire the best IT talent,” the official said. “The recent executive order made clear that the administration is committed to cultivating a workforce that reflects our country’s diversity – meaning cloud technology experts are being recruited from a diverse talent pool.”
The comments come after the Biden administration last month signed an executive order that mandates agencies take wide-ranging action to increase diversity equity and inclusion.
The OMB spokesperson added that IT workforce exchange programs between the private sector and federal agencies would be key in developing a new talent pipeline.
Under the recent EO, agencies are required to collect enhanced demographic data about federal employees and advance pay equity among public servants. Government departments will be required to look at new channels for staff recruitment, including through striking partnerships with universities and colleges that historically have served minority communities.
The Office of Personnel Management and OMB are overseeing the implementation of the new directive.
Technology recruitment consultants say that deep relationships with educational institutions and broadening the reach of paid internships are among the best ways for agencies both to increase the diversity of cloud talent and to foster innovation.
“This [recent EO] has to open things up, right from paid internships. Those exists – those paid internships exist with two- and four-year degrees, but the positions are not yet available once they got through that to place them in the long-term,” said Britaini Carroll, principal director of Accenture Federal Services’ Human Capital division.
Carroll added that there may also be a case for agencies in some instances to loosen educational requirements for cloud jobs that do not require the highest levels of technical expertise.
Google to provide Air Force’s maintenance office a cloud ‘ecosystem’
The Air Force‘s Rapid Sustainment Office inked a deal with Google Cloud for an “ecosystem” of technologies that will support maintenance operations.
Through the deal, the Air Force will get will receive an “open, agile, and globally scalable ecosystem” of cloud tech, Google said in a release. Dubbed “Project Lighthouse,” it will support everything from predictive maintenance software to augmented reality.
The company would not disclose how much the deal is worth.
“Our partnership with Google Cloud is a significant milestone for RSO on our journey to adopt Industry 4.0 technologies, when everything is connected, and deliver on our mandate to solve the Air Force’s toughest sustainment challenges,” Nathan Parker, deputy of the program executive office at the Air Force RSO, said in a release. “What we’re building with Google Cloud will accelerate the way we adopt, integrate, and scale technologies for the Air Force. Project Lighthouse is a hardware-flexible, software-driven approach that provides optionality at scale.”
The Rapid Sustainment Office has been pushing to use technology to better maintain aircraft. One high-profile project aims to use artificial intelligence to predict when parts will fail. Other initiatives include work to make digital replicas of aircraft, known as digital twins. Many of the goals rely on cloud storage and compute power.
The technology from Google is still being prototyped and tested, the company said.
“We know that sustainment is one of the biggest and most complex challenges in the military, and we are proud to support the RSO in its mission to modernize the U.S. Air Force,” Mike Daniels, vice president of global public sector at Google Cloud, said in the release.
Energy awards $28M to 5 supercomputing projects
The Department of Energy will give $28 million to five research projects developing software for its supercomputers, the Scientific Discovery Through Advanced Computing (SciDAC) program announced Friday.
The projects DOE selected will develop computational methods, algorithms and software benefitting research into quantum information science and chemical reactions with clean energy applications.
SciDAC brings together interdisciplinary groups of experts to make use of DOE’s high-performance computing resources, and the five teams will partner with one or both of its institutes, FASTMath and RAPIDS2, out of the Lawrence Berkeley and Argonne national laboratories.
“DOE’s national labs are home to some of the world’s fastest supercomputers, and with more advanced software programs we can fully harness the power of these supercomputers to make breakthrough discoveries and solve the world’s hardest to crack problems,” said Secretary of Energy Jennifer Granholm in an announcement. “These investments will help sustain U.S. leadership in science, accelerate basic research in energy, and advance solutions to the nation’s clean energy priorities.”
The five awardees are:
- California Institute of Technology for its project on traversing the “death valley” separating short and long times in non-equilibrium quantum dynamical simulations of real materials;
- Florida State University for its project on relativistic quantum dynamics in the non-equilibrium regime;
- Lawrence Berkeley National Lab for its project on large-scale algorithms and software for modeling chemical reactivity in complex systems;
- University of California-Santa Barbara for its project on real-time dynamics of driven correlated electrons in quantum materials; and
- University of California-Riverside for its Data-driven Exascale Control of Optically Driven Excitations (DECODE) project dealing with chemical and material systems.
The projects were chosen through a competitive, peer review process under a DOE Funding Opportunity Announcement open to universities, national labs and other research organizations. DOE has yet to negotiate final project details for the awardees, but $7 million of the total funding has been allocated for fiscal 2021, contingent upon congressional appropriations.
Cyber defense strategies that focus on protecting people
Deborah Watson is the resident CISO at Proofpoint with over 20 years’ experience in security.
Cybercrime has become a profitable business model, as evidenced by recent ransomware payments where criminals continue to perfect low-investment, high-return campaigns. While the majority of attacks start in email, the techniques, tools and procedures cybercriminals use are quickly changing. This rapid evolution makes it increasingly difficult for organization leaders to adapt to changes to the threat landscape in a timely manner.

Deborah Watson, Resident CISO, Proofpoint
One of the techniques we see on the rise is social engineering attacks, where malicious actors gather information about the people within an organization to trick users into making security mistakes. Attitudinally, cybercriminals approach people-centric attacks with as much effort, time and resources as they are devoted to understanding vulnerabilities in enterprise networks. Some emails impersonate colleagues and suppliers, taking advantage of employees who strive to be supportive. Other emails leverage reconnaissance information to emulate standard user interfaces resulting in credential theft.
In a threat environment where criminals are strategically targeting people, federal agency leaders may make many assumptions about who represents the most significant risks within the organization. But those assumptions can be wrong when leaders do not have the complete picture of who is vulnerable, privileged and targeted. And while their ecosystem of security tools monitor network activity, cloud environments and endpoint devices, they may be missing an agency’s most outstanding security and compliance risk — its people.
Human error is still the most significant risk factor
Phishing and credential theft are two primary techniques that attackers use to gain access to an organization. Verizon’s 2021 Data Breach Investigations Report found that 94% of breaches start with attacks targeting people via email, which is now the number one threat vector.
Complicating the situation, hackers have evolved from their emails being blatantly fraudulent, increasing the probability that an employee, with limited time, will evaluate an email before opening an attachment or clicking on a URL. It is true that poorly crafted emails still exist and are broadly distributed, but modern email security solutions generally catch those due to their widespread distribution. Today’s attacks are often narrowly targeted and explicitly crafted to subvert traditional email filters as the probability of detection is reduced by the number of emails sent.
While traditional cybersecurity threats have been built based on a linear kill chain — where reconnaissance of system and software vulnerabilities lead to vulnerabilities allowing access to an organization’s assets — current attack patterns indicate anything but a linear approach and have highlighted that our employees and those within our supply chain are softer targets.
Attackers do their homework targeting people based on data readily available to them. Social networking accounts, for example, allow them to identify common content types for those who are more likely to click on an email based on their specific roles and responsibilities. Once a cybercriminal gets access to the system through a compromised credential or the use of ransomware, they can take their time gathering information about the organization to navigate their way to a part of the architecture where they can launch their exploits.
People-centric approach to security
Many organizations may make qualitative assumptions about how they are being targeted and attacked. One strategy organizations frequently take involves wrapping added security layers around people in the organization — such as executives or high-level finance resources — based on what they believe is true in the absence of intelligence data. However, that strategy can overlook individuals in a wide range of lower-level job functions that frequently offer criminals an easy opening.
A people-centric approach provides agencies the ability to apply risk-based controls because the tools look at data in three key areas:
- Which job functions within the organization are being targeted?
- Are these employees vulnerable to different types of attacks?
- What system and information access privileges do they have?
Instead of treating everybody in the organization the same way, agency security teams can create a more informed picture about their security risks and implement adaptive security controls based on current situational intelligence. Adaptive controls may include using zero-trust application access, browser isolation, step-up and risk-based authentication and targeted security training. Applying adaptive policies can also benefit user monitoring programs, support privacy requirements, minimize data collection and expedite investigations.
Using a platform approach to manage adaptive controls consolidates and correlates policies, intelligence and supports ease of reporting. The result of this approach – increased situational awareness without additional staffing. The workforce efficiency gains allow agency personnel to focus on additional initiatives like those highlighted by the recent White House Executive Order, such as continuous monitoring and compliance.
The growing risk of security threats
Cybercriminals are also getting more organized and functioning more like businesses. In addition to malicious groups creating shared infrastructure, they share information and leverage credential dumps obtained from other security breaches to exploit known visibility gaps. Consequently, agencies need to increase information sharing, control standardization and implement modern security solutions to reduce the risks from the increasing intensity of more targeted attacks.
We work with a global network of customers every day to detect and block advanced threats and compliance risks in more than 2.2 billion emails and 22 million cloud accounts. We see how organizations are getting attacked and which countermeasures are proving most effective. For instance, in the public sector, we can identify which agencies, departments and roles are more targeted than others.
Healthcare organizations, for example, have been increasingly targeted by ransomware attacks both during and following the COVID-19 pandemic response. The aim of those attacks is not so much to disrupt patient care but to extract payment. However, the far-reaching nature of these attacks suggests that criminals could prevent health organizations from providing critical patient care and safety.
Financial institutions and federal regulatory agencies also saw a spike in activity from cybercriminals. Because many of these institutions still use legacy communication systems for transactions, they lost some security visibility and oversight as employees shifted to remote working conditions.
Not surprisingly, cybercriminals saw tremendous opportunities to social engineer account takeovers and infiltrate an entire ecosystem of public and private sector entities that often work closely together.
Another risk factor we see is the number of agencies with underutilized security tools and those who do not take advantage of the complete set of available features. The more security leaders can adapt their security strategies to incorporate a people-centric perspective, the more effective they will become in utilizing the protective controls required to address today’s attacks.
And by working with Proofpoint — with more than a decade’s experience building a global intelligence platform (Proofpoint Nexus), spanning threat protection, information protection and compliance — agencies are equipped to become more secure and protect their people even when they make mistakes.
Learn more about how Proofpoint can help protect federal agencies, and their people, against malicious attackers.