New Executive Order Takes Aim at Improving Cybersecurity
Time 2 Minute Read

On May 12, 2021, President Biden signed an Executive Order on Improving the Nation’s Cybersecurity. The Order outlines a number of initiatives intended to improve cybersecurity in the U.S. and protect federal government networks, including:

  • Removing barriers to information sharing between the government and private sector, such as contractual obligations that otherwise would prohibit IT service providers from sharing certain breach information;
  • Modernizing and implementing stronger cybersecurity standards in the federal government, for example, by mandating the deployment of multi-factor authentication and encryption;
  • Improving software supply chain security by establishing baseline security standards for the development of software sold to the government and requiring developers to make security data publicly available;
  • Establishing a Cybersecurity Safety Review Board (to be co-chaired by government and private sector leads) that may convene following a significant cyber incident to analyze what happened and make concrete recommendations for improving cybersecurity;
  • Creating a standard playbook for responding to cyber incidents to ensure all federal agencies are prepared to take uniform steps to identify and mitigate a threat; and
  • Improving the detection of cybersecurity incidents on federal government networks by enabling a government-wide endpoint detection and response system and improved information sharing within the federal government; and
  • Improving investigative and remediation capabilities by creating robust cybersecurity event log requirements for federal departments and agencies.
Recognizing that much of the critical infrastructure in the U.S. is owned and operated by the private sector, a White House statement encourages private sector companies to “follow the Federal government’s lead and take ambitious measures to augment and align cybersecurity investments with the goal of minimizing future incidents.”

You May Also Be Interested In

Time 1 Minute Read

On February 6, 2026, the Federal Trade Commission announced its second report to Congress on its efforts to combat ransomware and other cyber attacks.

Time 2 Minute Read

Congress has extended the Cybersecurity Information Sharing Act of 2015 through September 30, 2026 as part of the Consolidated Appropriations Act, a government funding package enacted in early February 2026.

Time 2 Minute Read

On November 20, 2025, the U.S. Securities and Exchange Commission issued a brief announcement that it filed a joint stipulation with defendants SolarWinds Corporation and its Chief Information Security Officer to dismiss, with prejudice, the SEC’s ongoing civil enforcement action against them.

Time 3 Minute Read

Ace American Insurance Company (“Ace”) recently filed a subrogation lawsuit against two technology and cybersecurity providers, following a cybersecurity incident suffered by an insured policyholder that had engaged the providers. This case highlights the growing risk of subrogation lawsuits following a cybersecurity incident.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page