Civic News

Will Biden’s guidance on improving the nation’s cybersecurity impact you?

The order will affect Microsoft the most, at least at first. Long term, it should make all levels of the supply chain more secure.

Cybersecurity. By frederickmaheux
A piece of guidance that President Biden issued on Sept. 14 requires companies that do business with the US government to comply with stronger government-specified secure software development practices.

What does that guidance — which builds on a May 2021 executive order — mean for you?

First, we’ll get what Roger Cressey, former United States National Security Council member, calls the 400-pound gorilla out of the way: 85% of US government productivity and collaboration software is owned by Microsoft, with Cisco coming in a far second. There are few smaller companies landing contracts in this area — but this fact also puts a much higher level of responsibility for security squarely on Microsoft.

“Vendors must now step up and deliver more secure IT products, with fewer vulnerabilities,” AJ Grotto, the founding director of the Program on Geopolitics, Technology and Governance at the Stanford Cyber Policy Center, told Technical.ly. “And if they don’t, agencies should fire them and purchase products from a different vendor.”

The origin

Experts we spoke to said that the 2020 SolarWinds cyber attack was a catalyst for the order, known as the Executive Order on Improving the Nation’s Cybersecurity. The Tulsa, Oklahoma software company provides infrastructure and network monitoring tools for thousands of companies and organizations around the world – including local, state and federal agencies in the US. SolarWinds’ Orion platform suffered what is called a supply chain hack, threatening to compromise the data of over 30,000 public and private organizations that used the platform at the time. SolarWinds in 2021 estimated that the attack, known as SUNBURST, impacted “fewer than 100” customers.

“That’s the origin,” Cressey told Technical.ly. “In a nutshell, for too long the government has been buying crappy software from a wide variety of interests. And we need to start putting in place rules to ensure that the integrity of the software is at a higher level.”

Meeting new guidelines

The expectation isn’t perfectly secure, bug-free software, but software that consistently conforms to the guidelines issued by the National Institute of Standards and Technology (NIST), as per the 2021 EO.  If it doesn’t, the company has the opportunity to come up with a plan to get its security up to the level it needs to be.

For massive, highly resourced companies like Microsoft, meeting the security requirements (requirements it should arguably already be meeting to protect its everyday customers) should be achievable.

There’s a chance that another company could move in if Microsoft doesn’t meet the order’s security requirements, however.

“If [Microsoft does] not do this the right way, a number of agencies are going to have a really interesting challenge on their hands to just rip and replace all the embedded Microsoft infrastructure,” Cressey said.

If Microsoft is able to comply, while that would mean fewer contracts for other companies, it would also mean more security across the board — not just for government agencies, but for businesses that use Microsoft and everyday consumers.

And that, Cressey says, would be good for the economy.

“This certainly has an impact on others up and down the supply chain,” he said. “It’s about extending a better understanding.”

What to expect if you’re a contractor

Now that the guidelines have been set, government agencies have 90 days to inventory all software subject to the requirements, and within 120 days to set up a consistent communication system with vendors.

For the full timeline, read the new guidance in full
Update: This article has been updated after initial publication to clarify, upon a SolarWinds press representative’s prompting, the number of customers it estimated in 2021 were impacted by the SUNBURST attack. (9/22/22, 1:11 p.m.)
Companies: Microsoft

Before you go...

Please consider supporting Technical.ly to keep our independent journalism strong. Unlike most business-focused media outlets, we don’t have a paywall. Instead, we count on your personal and organizational support.

3 ways to support our work:
  • Contribute to the Journalism Fund. Charitable giving ensures our information remains free and accessible for residents to discover workforce programs and entrepreneurship pathways. This includes philanthropic grants and individual tax-deductible donations from readers like you.
  • Use our Preferred Partners. Our directory of vetted providers offers high-quality recommendations for services our readers need, and each referral supports our journalism.
  • Use our services. If you need entrepreneurs and tech leaders to buy your services, are seeking technologists to hire or want more professionals to know about your ecosystem, Technical.ly has the biggest and most engaged audience in the mid-Atlantic. We help companies tell their stories and answer big questions to meet and serve our community.
The journalism fund Preferred partners Our services
Engagement

Join our growing Slack community

Join 5,000 tech professionals and entrepreneurs in our community Slack today!

Trending

A new model for thinking about how to grow regional economies: the Innovation Ecosystem Stack

Delaware’s next governor will be an entrepreneur. Here’s why Matt Meyer thinks it matters. 

Can the nation’s biggest cyber hub even handle Craiglist founder’s $100M security pledge?

Penn dean is a startup founder and ‘engineer at heart’ who loves the connection between education and business

Technically Media