CyberSecurity SEE

Wyden Advocates for Elimination of Edge Devices in US Government

Wyden Advocates for Elimination of Edge Devices in US Government

US Senator Advocates for Zero Trust Architecture to Replace Outdated Edge Devices by 2028

In a bold move to enhance national cybersecurity, U.S. Senator Ron Wyden has advocated for the federal government to transition from legacy public-facing remote access systems to a more robust zero trust architecture by 2028. This call to action comes in the wake of alarming security breaches that have showcased the vulnerabilities associated with outdated network devices.

Senator Wyden’s proposal highlights the increasing threat posed by nation-state hackers, who have increasingly targeted these aging systems as their preferred means of gaining access to sensitive information. In his recent correspondence, Wyden enumerated a series of significant cyber-attacks, including the notorious "Arcane Door" campaign that targeted Cisco devices, as well as a credential-harvesting incident known as "FortiBleed," which compromised Fortinet devices. Additionally, he cited breaches involving legacy Ivanti VPN systems and Check Point devices, effectively underscoring the danger associated with reliance on outdated security technology.

Security experts have long considered network edge devices a significant risk. These devices typically lack the protective measures found in modern endpoint security solutions, receive updates sporadically, and often host exploitable vulnerabilities. The necessity for reform in this area has never been more pressing.

In his letter, addressed to key federal entities such as the Office of Management and Budget (OMB), the Cybersecurity and Infrastructure Security Agency (CISA), and the National Institute of Standards and Technology (NIST), Wyden proposed giving federal agencies a two-year window to phase out legacy remote access gateways and perimeter entry points. Emphasizing urgency, Wyden wrote, “The federal government has become trapped in an endless game of ‘whack-a-mole’ in responding to widespread compromises of legacy remote access technologies.” He further indicated that it is no longer tenable for agencies to rely on insecure, decades-old technologies that do not meet the current cybersecurity landscape’s demands.

Moreover, Wyden also called for NIST to devise and publish comprehensive zero trust implementation standards. These standards would necessitate certain safeguards, such as an outbound-only remote access architecture and the usage of software developed in memory-safe programming languages. One of the more critical aspects of his proposals was the decentralization of encryption key management, aimed at isolating government agencies from third-party breaches.

With the push for a more stringent cybersecurity framework, Wyden highlighted the detrimental effects of these security breaches, stating that foreign adversaries have gained administrative access to target networks, leading to the theft of sensitive data from various U.S. government agencies and private companies. This insight underscores the dire consequences of underestimating the risks posed by outdated technological infrastructure.

Supporting Wyden’s assertions, a March report from VulnCheck revealed that approximately 42% of last year’s exploited vulnerabilities pertained to devices deemed end-of-life or nearing that status. Notably, an additional percentage of vulnerabilities affected products that had already ceased to be sold. Such alarming statistics paint a grim picture of the current security landscape regarding network edge devices.

As the call for modern cybersecurity measures intensifies, stakeholders across government and the private sector must unify to act on these recommendations. The foreshadowing of further cyber threats, coupled with the growing dependence on outdated technology, emphasizes the necessity for strategic planning and swift action to transition to a zero trust architecture.

Indeed, adopting this modern approach may not only mitigate the risks associated with existing vulnerabilities but may also pave the way for innovative solutions that secure the nation’s future against ever-evolving cyber threats. The imperative for this transformation is clear: without decisive action, the security breaches capable of compromising sensitive governmental and corporate data will only escalate in frequency and severity.

Source link

Exit mobile version