President Biden outlines new software policy following recent cyberattacks

watch biden inauguration day 2021 live stream
(Image credit: Chip Somodevilla/Getty Images)

US President Joe Biden has signed an executive order outlining new steps for software vendors engaging with the government in order to prevent possible future cyberattacks. 

Rumors about the order first surfaced in March, on the heels of the SolarWinds cyberattacks directed against multiple government organisations, with the recent ransomware attack on the Colonial Pipeline seemingly the final straw.

Reports quoting an unnamed senior administration official say that the new executive order “reflects a fundamental shift in our mindset from incident response to prevention, from talking about security to doing security.” 

The executive order calls for establishing baseline cybersecurity standards for all software sold to the federal government. It also mandates software vendors to notify their government customers of any cybersecurity breaches.

Wrong approach?

The move has generated a mixed response from the software industry. While the software vendors that TechRadar Pro spoke to welcomed the move, they voiced concerns about the prescriptive nature of the order.

“The new executive order is a swing and a miss from the government. Prescriptive regulations for the software industry simply will not work -- the federal government cannot move quickly enough to effectively regulate how software is built,” said Jeff Hudson, CEO of identity management company Venafi.

Hudson noted that the order fails to address the threat from machine to machine communication. A better approach is for the government to incentivize the software industry to build better, secure software, he added. 

Jyoti Bansal, CEO of Traceable and Harness, which develops tools to secure the application development pipeline agrees that prescriptive regulation alone is insufficient.

“The industry as a whole needs to shift security left — ensuring that security is implemented in the software development life cycle instead of waiting to add in security after products are deployed into production,” said Bansal.

“This order, as it stands, will slow down software companies and give attackers the opportunity to innovate faster,” warns Hudson.

Via The Hill

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Digital US flag
Biden orders review, new rules governing US national cybersecurity
A hand reaching out to touch a futuristic rendering of an AI processor.
Trump revokes AI risk regulation in day one executive order
Security
Removing software supply chain blind spots that put public sector organizations at risk
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
US government urges federal agencies to patch Microsoft 365 now
watch biden inauguration day 2021
US Government Defense bill waters down creation of US Cyber Force, allocates billions to "rip and replace" Chinese tech
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
The US privacy nightmare? What's changed after 30 days of President Trump's new administration
Latest in Security
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
ransomware avast
One of the most powerful ransomware hacks around has been cracked using some serious GPU power
person at a computer
Infamous ransomware hackers reveal new tool to brute-force VPNs
person at a computer
Many workers are overconfident at spotting phishing attacks
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Data Breach
Thousands of healthcare records exposed online, including private patient information
Latest in News
Panos Panay and Alexa Plus
Amazon's Panos Panay teases future Alexa+ devices from speakers to possible wearables
Metroid Prime 4
I reckon the Nintendo Switch 2 could launch with Metroid Prime 4 – here’s why
Samsung Galaxy Z Fold 6
New rumors predict a foldable iPhone will launch next year – and cost almost twice as much as the iPhone 16 Pro Max
Pebble smartwatch countdown
Pebble confirms its smartwatch announcement is just hours away
Logo of YouTube Shorts
Is YouTube auto-playing Shorts when you open the app? Well, you’re not alone - here’s how to fix it
Google DeepMind panel discussion
“More sovereignty and protection” - Google goes all-in on UK AI with data residency, upskilling projects, and startup investments