Security

CSO

I tried hard, but didn't fix all of cybersecurity, admits outgoing US National Cyber Director

In colossal surprise, ONCD boss Harry Coker says more work is needed


The outgoing leader of the United States' Office of the National Cyber Director has a clear message for whomever President-elect Trump picks to be his successor: There's a lot of work still to do.

Speaking to the Foundation for the Defense of Democracies yesterday, outgoing director National Cyber Director Harry Coker praised the work his office’s team has done in the past four years, while also noting that America is yet to implement all necessary defenses for critical systems.

"In the last four years we have: Fought fires; taken a proactive posture to defending cyberspace; brought greater coherence to Federal and global efforts; gotten key tech companies to step up on cybersecurity; and taken on some of the hardest problems that have long crippled our ability to stay secure," said Coker, the second person confirmed by the US Senate to hold his role.

"We've made progress," the outgoing director added, while noting "there's still a long way to go."

Coker called particular attention to the White House national cybersecurity strategy enacted in 2023, which his office played a key part in developing, as a success during his time in the role. Efforts to shore up security holes in the Border Gateway Protocol were also cited as a success.

The director also pointed to the Service for America campaign he led last year, which pitched cybersecurity work as national service as another success despite it also being an item of unfinished business as hundreds of thousands of infosec jobs remain unfilled.

"Everywhere I go, whether I'm talking to state or local government leaders, small or large businesses, or anyone leading critical infrastructure – they all tell me that they need more cyber talent," Coker said.

Coker hopes the second Trump administration will give the Office of the National Cyber Director more say in cybersecurity budgeting across the federal government.

"I would love for the incoming administration, or any administration, to recognize the priority of cybersecurity," Coker told reporters at yesterday's event. "It's a responsibility that every department and agency needs to stand up to. We need to give more than guidance when it comes to cybersecurity budgets."

He didn't mince words on the state of cybersecurity in the US, highlighting concerns about recent reports of cyber intrusions targeting US telecommunications systems.

How well that message is being received is unclear. Verizon - one of the group of US telecom providers breached by the Beijing-linked Salt Typhoon crew - has been handed a deal to upgrade cellular networks on 35 US Air Force bases.

Moreover, Microsoft, which supplies myriad government agencies, has been slammed by US cyber officials for lax security that allowed a China-linked group to breach Exchange Online and access the emails of senior government officials, but contract cash keeps flowing to Redmond, too.

President-elect Trump is yet to name the next ONCD Director. Whoever gets the gig will be busy. ®

Send us news
12 Comments

Trump’s DoD CISO pick previously faced security clearance suspension

Hey, at least Katie Arrington brings a solid resume

Trump’s cyber chief pick has little experience in The Cyber

GOP lawyer Sean Cairncross will be learning on the fly, as we also say hi to new intelligence boss Tulsi Gabbard

Rather than add a backdoor, Apple decides to kill iCloud encryption for UK peeps

Plus: SEC launches new crypto crime unit; Phishing toolkit upgraded; and more

Harassment allegations against DEF CON veteran detailed in court filing

More than a dozen women came forward with accusations

Probe finds US Coast Guard has left maritime cybersecurity adrift

Numerous systemic vulnerabilities could scuttle $5.4T industry

Polish space agency confirms cyberattack

Officials vow to uncover who was behind it

Ransomware criminals love CISA's KEV list – and that's a bug, not a feature

1 in 3 entries are used to extort civilians, says new paper

Wallbleed vulnerability unearths secrets of China's Great Firewall 125 bytes at a time

Boffins poked around inside censorship engines – here's what they found

Signal will withdraw from Sweden if encryption-busting laws take effect

Experts warned the UK’s recent 'victory' over Apple would kickstart something of a domino effect

Incoming deputy boss of Homeland Security says America's top cyber-agency needs to be reined in

Plus: New figurehead of DOGE emerges and they aren't called Elon

MITRE Caldera security suite scores perfect 10 for insecurity

Is a trivial remote-code execution hole in every version part of the training, or?

US Dept of Housing screens sabotaged to show deepfake of Trump sucking Elon's toes

'Appropriate action will be taken,' we're told – as federal HR email sparks uproar, ax falls on CISA staff