{"id":56016,"date":"2024-05-08T16:00:13","date_gmt":"2024-05-08T16:00:13","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\/"},"modified":"2024-05-08T16:00:13","modified_gmt":"2024-05-08T16:00:13","slug":"cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\/","title":{"rendered":"CISA boss: Secure code is the &#8216;only way to make ransomware a shocking anomaly&#8217;"},"content":{"rendered":"<p><span class=\"label\">RSAC<\/span> There&#8217;s a way to vastly reduce the scale and scope of ransomware attacks plaguing critical infrastructure, according to CISA director Jen Easterly: Make software secure by design.<\/p>\n<p>&#8220;It is the only way we can make ransomware and cyberattacks a shocking anomaly,&#8221; Easterly said during an RSA Conference keynote <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/www.rsaconference.com\/USA\/agenda\/session\/A%20World%20On%20Fire%20Playing%20Defense%20in%20a%20DigitizedWorldand%20Winning\">panel<\/a> this week in San Francisco. &#8220;And that is to make sure the technology is much more secure.&#8221;<\/p>\n<div class=\"promo_article\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2023\/02\/28\/handout_jen_easterley.jpg?x=174&amp;amp;y=115&amp;amp;crop=1\" width=\"174\" height=\"115\" alt=\"CISA director Jen Easterley standing in front of some binary code\"><\/p>\n<h2 title=\"Who apart from Microsoft is happy with the ship now, oh just fix it later approach?\">US cybersecurity chief: Software makers shouldn&#8217;t lawyer their way out of security responsibilities<\/h2>\n<p><a href=\"https:\/\/www.theregister.com\/2023\/02\/28\/cisa_easterly_secure_software\/\"><span>EARLIER&#8230;<\/span><\/a><\/div>\n<p>The CISA boss has been beating this drum throughout her tenure at America&#8217;s lead government cybersecurity agency, after she took over from the inaugural CISA chief Chris Krebs \u2013 who joined Easterly on stage during the aptly titled session, World on Fire, which was moderated by Washington Post super-journo Joseph Menn.<\/p>\n<p>As the two CISA bods noted, it does seem as though the digital world is on fire these days, with the &#8220;scourge of ransomware we&#8217;ve been dealing with,&#8221; Easterly said.<\/p>\n<p>A week ago, UnitedHealth CEO Andrew Witty confirmed to US senators that his corporation <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2024\/04\/30\/unitedhealth_ceo_ransom\/\" rel=\"noopener\">paid $22 million<\/a> to the extortionists responsible for the Change Healthcare IT breach in February.&nbsp;<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"condor\" data-xsm=\",fluid,mpu,\" data-sm=\",fluid,mpu,\" data-md=\",fluid,mpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_specialfeatures\/spotlightonrsa&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Zjvcreo3j04Mv9JTRkjs0gAAANM&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_specialfeatures\/spotlightonrsa&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Zjvcreo3j04Mv9JTRkjs0gAAANM&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>And this week, timed to coincide with the RSA Conference one suspects, the Feds charged and sanctioned suspected <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2024\/05\/07\/alleged_lockbit_kingpin_charged_sanctioned\/\" rel=\"noopener\">LockBit kingpin<\/a> Dmitry Yuryevich Khoroshev, whose ransomware affiliates targeted more than 100 hospitals and healthcare companies, it&#8217;s alleged.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"falcon\" data-xmd=\",fluid,mpu,leaderboard,\" data-lg=\",fluid,mpu,leaderboard,\" data-xlg=\",fluid,billboard,superleaderboard,mpu,leaderboard,\" data-xxlg=\",fluid,billboard,superleaderboard,brandwidth,brandimpact,leaderboard,mpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_specialfeatures\/spotlightonrsa&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44Zjvcreo3j04Mv9JTRkjs0gAAANM&amp;t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_specialfeatures\/spotlightonrsa&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44Zjvcreo3j04Mv9JTRkjs0gAAANM&amp;t=ct%3Dns%26unitnum%3D426raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<div class=\"adun_eagle_desktop_story_wrapper\">\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"mid\" data-raptor=\"eagle\" data-xxlg=\",mpu,dmpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_specialfeatures\/spotlightonrsa&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33Zjvcreo3j04Mv9JTRkjs0gAAANM&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_specialfeatures\/spotlightonrsa&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33Zjvcreo3j04Mv9JTRkjs0gAAANM&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<\/p><\/div>\n<p>In addition to ransomware criminals extorting organizations to the tune of billions, there are also government-backed groups like China&#8217;s Volt Typhoon. This particular crew, Easterly said &#8211; echoing her January testimony before Congress &#8211; is &#8220;burrowing into our critical infrastructure, not for espionage, not for intellectual property, but specifically for disruptive and destructive attacks in the event of a major conflict in the Taiwan Straits.&#8221;<\/p>\n<blockquote class=\"pullquote\" readability=\"5\">\n<p>How do we make up for decades and decades of no technology minimum standards for cybersecurity?<\/p>\n<\/blockquote>\n<p>Plus, there&#8217;s the ongoing problem of <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2024\/04\/03\/cisa_microsoft_exchange_online_china_report\/\" rel=\"noopener\">Chinese<\/a> and <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2024\/01\/24\/microsoft_latest_breach_cozy_bear\/\" rel=\"noopener\">Russian cyberspies<\/a> breaking into Microsoft&#8217;s cloud, including email accounts belonging to <a href=\"https:\/\/www.theregister.com\/2024\/04\/05\/microsoft_government_contracts\/\">US government officials<\/a>.<\/p>\n<p>&#8220;How do we make up for decades and decades of no technology minimum standards for cybersecurity? Well, it has to be a recognition across the entire ecosystem, that we need to do this together for the collective defense of the nation,&#8221; Easterly said.<\/p>\n<p>The federal government can use its technology procurement power to encourage providers to sell more secure software, she added. &#8220;And frankly, it&#8217;s a lever that anybody who buys technology should use. Demand that what we get from technology manufacturers is as safe and secure as possible.&#8221;<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"falcon\" data-xsm=\",fluid,mpu,\" data-sm=\",fluid,mpu,\" data-md=\",fluid,mpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_specialfeatures\/spotlightonrsa&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44Zjvcreo3j04Mv9JTRkjs0gAAANM&amp;t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_specialfeatures\/spotlightonrsa&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44Zjvcreo3j04Mv9JTRkjs0gAAANM&amp;t=ct%3Dns%26unitnum%3D426raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>On Wednesday at the conference, some 60-plus tech companies will sign a pledge to develop more secure technology, according to Easterly. The signatories are expected to include Microsoft, Google, AWS, IBM, Palo Alto Networks, and Cisco.<\/p>\n<p>&#8220;There&#8217;s an awakening \u2026 this is really going to start driving customers away, because they don&#8217;t have confidence in our products,&#8221; Krebs said, speaking from the point of view of a vendor.<\/p>\n<p>In addition to CISA&#8217;s voluntary efforts, such as the secure software pledge, there are four more levers that can be used to make technology products more secure, Krebs added.&nbsp;<\/p>\n<p>One is litigation, he said, noting the <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2024\/01\/29\/solarwinds_sec_lawsuit\/\" rel=\"noopener\">SEC lawsuit<\/a> against SolarWinds and its CISO Tim Brown over the 2020 digital intrusion.<\/p>\n<p>&#8220;You also have regulatory action,&#8221; Krebs said, adding there are challenges with this stemming from trying to get watchdogs created and empowered before the modern internet came about to scrutinize today&#8217;s cybersecurity practices. This is why we see things like the EPA establishing an <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2024\/03\/20\/us_water_sector_cybersecurity\/\" rel=\"noopener\">Water Sector Cybersecurity Task Force<\/a> to push for &#8220;immediate&#8221; fixes in critical infrastructure. Regulators will struggle to take yesteryear rules and apply them in this digital age without some form of change or evolution.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" id=\"story_eagle_xsm_sm_md_xmd_lg_xlg\" data-pos=\"mid\" data-raptor=\"eagle\" data-xsm=\",mpu,dmpu,\" data-sm=\",mpu,dmpu,\" data-md=\",mpu,dmpu,\" data-xmd=\",mpu,dmpu,\" data-lg=\",mpu,dmpu,\" data-xlg=\",mpu,dmpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_specialfeatures\/spotlightonrsa&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33Zjvcreo3j04Mv9JTRkjs0gAAANM&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_specialfeatures\/spotlightonrsa&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33Zjvcreo3j04Mv9JTRkjs0gAAANM&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>&#8220;And then ultimately, that last piece is legislative action,&#8221; Krebs said. &#8220;That&#8217;s where, I think, the spigot&#8217;s smaller.&#8221;<\/p>\n<p>There&#8217;s the upcoming <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2024\/03\/28\/critical_infrastructure_cyberattack_reporting\/\" rel=\"noopener\">cyber attack reporting rules<\/a> for critical infrastructure operators, required under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA).&nbsp;<\/p>\n<p>&#8220;But beyond that, I just don&#8217;t see a lot of additional authorities in part because there aren&#8217;t a lot of legislative days in this session,&#8221; Krebs said, referring to the US election year, and adding that European Union regulations like the <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2024\/03\/13\/eu_ai_act\/\" rel=\"noopener\">AI Act<\/a> and Cyber Resilience Act may have a &#8220;cascading effect&#8221; on improving tech security in America. \u00ae<\/p>\n<p> READ MORE <a href=\"https:\/\/go.theregister.com\/feed\/www.theregister.com\/2024\/05\/08\/cisa_ransomware_rsac\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>And it would seriously inconvenience the Chinese and Russians, too RSAC\u00a0 There&#8217;s a way to vastly reduce the scale and scope of ransomware attacks plaguing critical infrastructure, according to CISA director Jen Easterly: Make software secure by design.\u2026 READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":56017,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-56016","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CISA boss: Secure code is the &#039;only way to make ransomware a shocking anomaly&#039; 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CISA boss: Secure code is the &#039;only way to make ransomware a shocking anomaly&#039; 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2024-05-08T16:00:13+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/regmedia.co.uk\/2023\/02\/28\/handout_jen_easterley.jpg?x=174&amp;amp;y=115&amp;amp;crop=1\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"CISA boss: Secure code is the &#8216;only way to make ransomware a shocking anomaly&#8217;\",\"datePublished\":\"2024-05-08T16:00:13+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\\\/\"},\"wordCount\":746,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly.jpg\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\\\/\",\"name\":\"CISA boss: Secure code is the 'only way to make ransomware a shocking anomaly' 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly.jpg\",\"datePublished\":\"2024-05-08T16:00:13+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly.jpg\",\"width\":174,\"height\":115},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CISA boss: Secure code is the &#8216;only way to make ransomware a shocking anomaly&#8217;\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CISA boss: Secure code is the 'only way to make ransomware a shocking anomaly' 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\/","og_locale":"en_US","og_type":"article","og_title":"CISA boss: Secure code is the 'only way to make ransomware a shocking anomaly' 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2024-05-08T16:00:13+00:00","og_image":[{"url":"https:\/\/regmedia.co.uk\/2023\/02\/28\/handout_jen_easterley.jpg?x=174&amp;amp;y=115&amp;amp;crop=1","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"CISA boss: Secure code is the &#8216;only way to make ransomware a shocking anomaly&#8217;","datePublished":"2024-05-08T16:00:13+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\/"},"wordCount":746,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/05\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly.jpg","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\/","url":"https:\/\/www.threatshub.org\/blog\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\/","name":"CISA boss: Secure code is the 'only way to make ransomware a shocking anomaly' 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/05\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly.jpg","datePublished":"2024-05-08T16:00:13+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/05\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/05\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly.jpg","width":174,"height":115},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/cisa-boss-secure-code-is-the-only-way-to-make-ransomware-a-shocking-anomaly\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"CISA boss: Secure code is the &#8216;only way to make ransomware a shocking anomaly&#8217;"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/56016","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=56016"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/56016\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/56017"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=56016"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=56016"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=56016"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}