Cybersecurity, Privacy, & AI

Trending Now
Cyber Leaders Wary of Giving Agentic AI Too Much Authority • New ‘Water Watch Center’ Launched to Help Small Utilities Stop Cyberattacks • TikTok Can Be on Government Phones. Managing It Comes Next. • CISA, FBI and Partners Detail Gunra Ransomware Tactics • NIST Wants to Overhaul Its Vulnerability Database for the AI Age

Colonial Pipeline CEO Defends Shutdown and Ransom Payment in Congressional Hearing

Mike Mareen | Shutterstock

Colonial Pipeline CEO Joseph Blount told the Senate Homeland Security and Governmental Affairs Committee that his decision following last month’s ransomware attack – to shut down the company’s distribution network then to secretly pay the $4.3 million ransom demand – was made to “put the interests of the country first” by restoring the flow of fuel for essential uses. “I believe with all my heart it was the right choice to make,” Blount said. He declined to speculate about what would have happened otherwise.

When asked whether TSA should build on new requirements it has issued since, Blount suggested that established industry standards would be beneficial. Blount also addressed the company’s failure to contact CISA, stating that the FBI – whom they contacted “almost immediately” – had said they would do so, making another contact redundant.

Questioned about how the attackers were able to access their network, Blount explained that the company’s system’s were breached through a “legacy VPN” – of which Colonial’s IT staff was unaware – with only single-factor authentication, consisting of a strong, but compromised password.

Sources:

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.