The Baker-Polito administration filed their FY 2023 Budget proposal at the end of last month, which includes $164.1 million to be used by the Executive Office of Technology Services and Security for a multitude of cybersecurity and infrastructure updates.
Governor Files FY2023 Massachusetts Budget Proposal
US Government “Initiates the widest empowerment and expansion of CISA through legislation since the SolarWinds incident”
The next step in critical infrastructure cybersecurity defense now begins as Joe Biden, like modern presidents before him, signed the National Defense Authorization Act of 2022 into law at the end of last month.
Sections 861-867 focus on Small Businesses, including committing the Department of Defense to analyze and review how their Cybersecurity Maturity Model Certification (CMMC) can work for small businesses.
2021 Sees More Scam Calls Than Ever Before
Almost a quarter of Americans (23%) have reported losing money to a phone scam in the past year, according to Truecaller Insights US Spam & Scam Report 2021. The actual percentage of people who have fallen for a scam, whether or not they've given money, is 31%.
Truecaller estimates that in total, Americans lost $29.8 billion, with an average of $502. Expanding, Truecaller says that 60% of these calls were robocalls instead of actual humans.
Movie Pirates Discover Their Systems Hijacked
While you may not be a pirate yourself, chances are you know someone who gets their entertainment from less-than-legal means. If this is being done on your network, you might be at risk too. It's no surprise that the top pirated movie of 2021 was the latest Spider-Man film, which has even broken pre-2020 records at the box office.
GoDaddy Breach Affects Millions
On Monday, Nov. 22, popular domain registrar GoDaddy revealed in a public SEC filing that "an unauthorized third party" hacked into its systems back in early September and had access until mid-November.
According to GoDaddy, "Using a compromised password, an unauthorized third party accessed the provisioning system in our legacy code base for Managed WordPress.
FBI Email Servers Hacked; Fake Warnings Sent
The nonprofit SpamHaus, which tracks spam e-mails, noticed tens of thousands of urgent FBI bulletins going out the morning of November 13. These bulletins, warning of a "sophisticated chain attack," were sent by the FBI's servers. In actuality, a hacker had been able to get into the Bureau's e-mail notification system to distribute the false warnings.
House Passes SBA Cyber Security Act
The House unanimously passed H.R. 3462, the SBA Cyber Security Awareness Act, in early November, sending it to the Senate for approval.
"The SBA will be required to conduct an annual assessment of IT equipment and cybersecurity capabilities, and provide Congress a detailed account of any cyber security risk," said Rep.
Direct IT News Update, November 2021
Tentative Conclusions About CMMC 2.0 From a Small Business Focused MSP/MSSP
The DoD’s announcement of CMMC 2.0 has the defense industrial base buzzing with questions. For some smaller parts manufacturers or service providers who work directly or indirectly for the department of defense, shifting standards and unclear deadlines are making it hard to prioritize investing in CMMC compliance.
CMMC is dead! Long Live CMMC 2.0!
CMMC is dead! Long Live CMMC 2.0! There was a major security-related announcement from the Office of the Under Secretary of Defense for Acquisition and Sustainment of the Department of Defense (DoD) today. The DoD released an overview of its plans moving forward for the CMMC program.