Following a Series of Government Hacks, Biden Closes Out His Administration With New Cybersecurity Order
Summary
The action follows an onslaught of cyberattacks in recent years in which hackers linked to Russia, China and other adversaries have exploited software vulnerabilities to steal sensitive documents from federal agencies. In the so-called SolarWinds attack, which was discovered shortly before Biden took office, Russian state-sponsored hackers exploited a weakness in a Microsoft product to steal sensitive data from the National Nuclear Security Administration and other agencies. The company told ProPublica that its offer was a direct response to “an urgent request by the Administration to enhance the security posture of federal agencies.” In his executive order, Biden addressed the fallout of that 2021 request, directing the federal government to mitigate the risks presented by the “concentration of IT vendors and services,” a veiled reference to Washington’s increased dependence on Microsoft, which some lawmakers have referred to as a “cybersecurity monoculture.” Though the order marks a firmer stance with the technology companies supplying the government, enforcement will fall to the Trump administration. FTC attorneys have been conducting interviews and setting up meetings with Microsoft competitors, and one key area of interest is how the company packages popular Office products together with cybersecurity and cloud computing services. The FTC views the fact that Microsoft has won more federal business even as it left the government vulnerable to hacks as an example of the company’s problematic power over the market, a person familiar with the probe told ProPublica.