Biden administration wants to hold companies liable for bad cybersecurity
arstechnica.com
arstechnica.com
It really should not go without mentioning the cause of the Colonial Pipeline attack: a leak of the NSA’s hacking weapons. The attack was collateral damage of the US government’s offensive capabilities.
How about instead of simply pen testing adversaries, the NSA also pen tests critical American infrastructure. This infrastructure would need to first be identified and then given a special designation. The US already does this with banks and solvency. The NSA can start with the lowest hanging fruit: OWASP vulnerabilities.
We are long past the point where these groups had any accountability to any elected official or judge etc...