- Cybersecurity Docket
- Posts
- Secret Service Official: Cybersecurity Areas That Need More Attention
Secret Service Official: Cybersecurity Areas That Need More Attention
Plus, FBI launches new cybersecurity initiative; and more

Good morning! Here’s what’s up.

People
Anand Sha has joined KPMG US as Privacy & Confidentiality Program Officer.

Clips ✂️
The internet domain registration system is a major weakness that malicious hackers can exploit, but is often being overlooked, a senior Secret Service official said Thursday.
“It is staggering to me that we live in a world where domain registrars and registrars will do bulk registration of various spellings of a major institution’s brand name to create URLs to then use in phishing campaigns or in fraudulent advertising,” the official, Matt Noyes, said at a conference in Washington, D.C.
It was one of two areas Noyes identified as attack vectors that aren’t adequately being addressed during a panel at the 2026 Identity, Authentication and the Road Ahead Policy Forum, along with susceptibility to business email compromise scams.
US FBI Launches “Operation Winter Shield” to counter escalating Cyber Threats
The United States Federal Bureau of Investigation (FBI) has launched a new cybersecurity initiative, titled “Operation Winter Shield,” aimed at strengthening the protection of information technology (IT) and operational technology (OT) infrastructure across both public and private sector organizations. The operation is designed to counter increasingly sophisticated cyber threats originating from adversary nation-states and their affiliated actors.
Operation Winter Shield focuses on identifying, tracking, and disrupting cyberattacks that target critical infrastructure within the United States. According to the FBI, the initiative emphasizes not only detection and response, but also active deterrence and retaliation against malicious cyber activities. A key pillar of the program is enhanced collaboration between government agencies and private sector organizations, recognizing that effective cyber defense requires shared intelligence, coordinated action, and collective resilience.
In recent years, U.S. businesses have faced a surge in cyber incidents, including ransomware attacks, supply-chain compromises, fraud, and intrusions linked to state-sponsored threat groups.
Standardizing Cyber Analytics to Secure Critical Infrastructure
A team at the Johns Hopkins Applied Physics Laboratory (APL) in Laurel, Maryland, has developed a framework for standardizing alerts generated by cybersecurity systems defending critical infrastructure, dramatically improving the efficiency with which they respond to potential attacks.
Known as BAS/CS — short for Behavioral Alerting Sets for Control Systems and pronounced “basics” — the capability is already in use by military control system operators.
Control systems for essential services — including electricity, water and natural gas — remain high-priority hacking targets. Defending these systems is complicated by the sheer variety of technologies, protocols and available cybersecurity solutions in use, which makes it extremely challenging to share information and identify threats.
…
Remapping the Cyber Threat Landscape
The BAS/CS framework addresses the variability problem on multiple levels. First, every event flagged by a sensor — for instance, an attempt to remotely log into a system or a new protocol seen on the network — is tagged with a common identification number that works across different sensors and vendor offerings.
Global Cybersecurity Market to Reach $578.2Bn by 2033 at 10.4% CAGR
According to a new report … [t]he global cybersecurity market size was valued at USD 219 billion in 2023 and is projected to reach USD 578.2 billion by 2033, growing at a [Compound Annual Growth Rate] of 10.4% from 2024 to 2033.
…
Cybersecurity encompasses technologies, processes, and services designed to protect networks, devices, applications, and data from cyber threats such as malware, ransomware, phishing, and advanced persistent attacks.
…
Growing digitization, remote and hybrid work models, and the rapid adoption of emerging technologies such as AI, IoT, and 5G are expanding the attack surface for cybercriminals. This has led to a surge in demand for comprehensive security solutions, including endpoint protection, identity and access management, cloud security, and security analytics. Organizations are shifting toward proactive and integrated security strategies, making cybersecurity a foundational component of modern enterprise infrastructure.
The Cybersecurity Consequences Of The Latest Government Shutdown
Washington entered a partial government shutdown at midnight on Jan. 31, 2026, after funding lapsed for dozens of federal agencies. The Senate advanced a bipartisan funding package late Friday to fund most of the government, but the House had not approved it when funding expired. Many agencies are expected to return to normal once the House votes, but the current impasse highlights structural fractures in federal governance that matter to every executive responsible for risk and technology.
…
What Actually Happens To Cyber Operations During A Shutdown
Federal cyber operations do not stop during a shutdown, but they do narrow.
Agencies such as the Cybersecurity and Infrastructure Security Agency remain operational and focused on incident response and protection of critical infrastructure. What slows or pauses is the work designed to prevent incidents in the first place. Proactive threat hunting, system hardening, cross-sector exercises, contractor-supported initiatives and forward-looking analysis are all reduced.
US wants to push its view of AI cybersecurity standards to the rest of the world
The U.S. government wants the rest of the world to adopt its artificial intelligence cybersecurity standards, a top official with the Office of the National Cyber Director said Thursday.
As part of an effort to advance American AI, the administration will be “undertaking diplomacy efforts to promote American AI cybersecurity standards and norms, establishing industry best practices for secure AI deployment and harnessing the full potential of AI tools,” said Alexandra Seymour, principal deputy assistant national cyber director for policy.
Seymour’s comments at the 2026 Identity, Authentication, and the Road Ahead Policy Forum in Washington, D.C. partially reflect the Trump administration’s AI Action Plan released last summer, which said the departments of Commerce and State would “vigorously advocate for international AI governance approaches that promote innovation, reflect American values, and counter authoritarian influence,” but doesn’t explicitly mention international promotion of cybersecurity standards.
