Some thoughts:
1) Certain infrastructure should be off the net automatically - pipelines, water treatment plants and similar things (or online with hardware guaranteed one ways connections).
2) Standards for testing backups.
3) Standards for IoS devices (a million insecure Internet light bulbs, what could possibly go wrong).
4) Standards for not having a hundred companies auto-updating onto the systems of critical infrastructure companies.
For backups, not only do they need to have it, they need to be tested, kept offline and encrypted - this doesnt apply to all its split by revenue bands/industry/mix of other logic.
IoT devices - they get notified in Control if we find any on the internet and told to not have them directly exposed
* Do you know if there are any follow up meetings planned? Did they discuss some kind of process?
* what were the main concerns discussed?
* interesting to find out about the coalition (I was briefly involved in a similar insurance setup in my home country). Is your ‘baseline’ derived from some standard? Can I find it online?
Yes the group will continue to meet and I believe more will come out overtime as we start to better define how we as private entities can help the gov.
Ransomware and attacks on critical infra were the big ones - Joshua our CEO wrote a bit about it here https://www.coalitioninc.com/blog/coalition-meets-with-presi...
- our baseline is internal. We are with our customers end to end. From selling the policy to scanning them, notifying them and we have our own incident response team which means that we learn a lot with every claim. So when we add a vulnerability in critical state in Control you can assume it came from learnings of losses combined with our cybersecurity expertise.
I look forward to a summary report on incidents somewhere in the future ;)