2025-01-23
DHS Fires Advisory Committees, Including Cyber Safety Board
An internal memo issued January 20, 2025, from Acting Department of Homeland Security (DHS) Secretary Benjamine Huffman, terminated all advisory committee positions. Among those dismissed were the Cyber Safety Review Board (CSRB), a committee responsible for "study[ing] major cyber incidents and recommend[ing] improvements," comprising private sector experts and government cybersecurity officials. Since its establishment in 2022 by President Biden's executive order, the CSRB investigated the Log4Shell security crisis, attacks by Lapsus$, and the Microsoft Exchange Online Breach, and at the time of Huffman's memo was in the process of investigating the massive 2024 breach of US telecommunications networks by the Chinese state-sponsored hacking group, Salt Typhoon.
Editor's Note
This action and the new administration revoking a previous Executive Order on AI safety are certainly not positive signs that the federal government will play a major role in raising the bar on cybersecurity. But, it is too soon to pronounce judgment until until some concrete new directions are seen from the new administration.

John Pescatore
This one hurts. One of the biggest challenges we have in cybersecurity is data, especially from real world incidents. When an airplane crashes in North America, the National Transportation Safety Board (NTSB) investigates the accident and makes recommendations aimed at preventing future ones. It's extremely effective and has helped dramatically reduce aviation incidents over the decades. THE CSRB had the potential to do the same for cybersecurity. Their first big publication in 2024 was on Microsoft and shared a wealth of intelligence and lessons learned. I sincerely hope for the security of this country and others that the CSRB is reinstated.

Lance Spitzner
I will take a contrarian view here for the sake of argument. While I know many will claim terminating the review board harms national security, there may be a bit of hubris at play. In the past 2+ years the CSRB has investigated three incidents. It's not clear to me that any of the findings have resulted in substantive change to better protect the nation. As far as investigating Salt Typhoon and the attack on US telecommunications networks, that can still be continued by Congress and the Executive Branch.

Curtis Dukes
I'm unsure what to make of this. I don't recall seeing an 'NTSB Board' being fired during the middle of a plane crash investigation. At this point, it's very hard to tell what is happening since it is occurring very quickly. I can say that the attackers in the phone companies will not stop because the review board has gone away. We do need to figure out how these attacks occurred, and CISA did appear to be doing some good for the vast majority of the federal systems. Will a new set of individuals be appointed? I think this story will change day-by-day and we will have to wait to see.

Moses Frost
With the change in administration, expect changes in advisory and similar capabilities as new administrators work to implement their vision. Regrettably we still have an urgent need to address telecommunications security. For now, continue to follow CISAÕs guidelines on secure communications.

Lee Neely
Read more in
NextGov: DHS cyber review board cleaned out in Trump move to eliminate 'misuse of resources'
Ars Technica: Trump admin fires security board investigating Chinese hack of large ISPs
TechCrunch: Trump administration fires members of cybersecurity review board in 'horribly shortsighted' decision
SecurityWeek: DHS Disbands Cyber Safety Review Board, Ending One of CISA's Few Bright Spots
The Record: Trump administration dismisses members of all DHS advisory panels, including CSRB
CyberScoop: Removal of Cyber Safety Review Board members sparks alarm from cyber pros, key lawmaker