News

DHS Cyber Safety Review Board blames corporate culture for 2023 Microsoft Exchange Online incident

Following an independent review of the Microsoft Exchange Online intrusion in summer 2023, the U.S. Department of Homeland Security (DHS) Cyber Safety Review Board (CSRB) announced that the attack had been preventable, and steps should be taken to do so in the future.

Last summer, Microsoft Exchange Online was hit by several intrusions from Storm-0558, a hacking group CSRB judged to be affiliated with China. That group secured access to numerous organizations’ mailboxes through this breach, in turn compromising hundreds of governmental as well as private accounts. While hackers will always be an issue, their crimes are often built on opportunity, and such was the case here, as the CSRB chided Microsoft for decisions that failed to emphasize security investments and risk management, despite its central role in the modern technology sector.

“Individuals and organizations across the country rely on cloud services every day, and the security of this technology has never been more important,” Secretary of Homeland Security Alejandro Mayorkas said. “Nation-state actors continue to grow more sophisticated in their ability to compromise cloud service systems. Public-private partnerships like the CSRB are critical in our efforts to mitigate the serious cyber threat these nation-state actors pose. The Department of Homeland Security appreciates the Board’s comprehensive review and report of the Storm-0558 incident. Implementation of the Board’s recommendations will enhance our cybersecurity for years to come.”

CSRB’s findings stemmed from data, as well as interviews with 20 organizations, industry experts and affected organizations. This marked the third completed review by the Board since its founding in 2022, and in addition to its findings, it also pushed recommendations for the industry to follow going forward.

“Cloud computing is some of the most critical infrastructure we have, as it hosts sensitive data and powers business operations across our economy,” Robert Silvers, DHS Under Secretary of Policy and CSRB chair, said. “It is imperative that cloud service providers prioritize security and build it in by design. The Board has become the authoritative organization for conducting fact-finding and issuing recommendations in the wake of major cyber incidents, receiving extensive industry and expert input in each of its three reviews to date. We appreciate Microsoft’s full cooperation in the course of the Board’s seven-month, independent review.”

This prioritization included calling on Microsoft to develop and make public a plan for security-focused reforms among it and its products. CSRB also recommended that cloud service providers undertake modern control mechanisms and baseline practices to reduce risks of system-level compromises, adopt minimum standards for default audit logging in cloud services and provide notices to victims, among others.

Chris Galford

Recent Posts

DoD challenge brings opportunities for nine new ideas in talent management

A Department of Defense (DoD) 2040 Task Force (D2T) challenge on talent management innovation drew…

2 days ago

TSA publishes final rule on Flight Training Security Program improvements

For the first time since its creation in 2004, the Transportation Security Administration’s (TSA) Flight…

2 days ago

FEMA launches new hurricane season campaign with multicultural messaging on flood risks

The 2024 Hurricane Season Campaign began for the Federal Emergency Management Agency (FEMA) this week,…

3 days ago

SERVICE Act of 2024 seeks DOJ pilot program, grants for local veteran response teams

As a way to support veterans, U.S. Reps. Maria Elvira Salazar (R-FL), Dale Strong (R-AL),…

3 days ago

DHS publishes guidelines for securing critical infrastructure and weapons against AI threats

Mere days after the Department of Homeland Security formed a new Artificial Intelligence (AI) Safety…

4 days ago

U.S. Army and European Command awards KBR $771M contract

KBR will continue to provide life support, equipment readiness, training and supply chain solutions for…

4 days ago

This website uses cookies.