Top Qs
Timeline
Chat
Perspective

Cyber Safety Review Board

Public-private review board From Wikipedia, the free encyclopedia

Remove ads
Remove ads

The Cyber Safety Review Board (also called the CSRB) was established by United States Secretary of Homeland Security Alejandro Mayorkas on February 3, 2022.[1][2][3][4] Modeled after the National Transportation Safety Board, the Board reviews significant cybersecurity incidents and issues reports.[5][6] President Joe Biden directed the Board's creation through Section 5 of Executive Order 14028, issued on May 12, 2021.[7][8]

On January 21, 2025, it was reported that the Trump administration fired all members of the CSRB.[9] At the time it was still investigating Salt Typhoon, an intrusion believed to allow the Chinese government to access phone and broadband networks and spy on the communications of over a million Americans, including presidential candidates.[10]

Remove ads

Overview

When it was operating, the Board reviewed and assesses significant cyber incidents and provides findings and recommendations to the United States Secretary of Homeland Security. It is unusual in that is a collaboration between government and the private sector.

Executive Order 14028 provides that the Board is composed of up to twenty members, chosen by the Director of the Cybersecurity and Infrastructure Security Agency.[11] Those members must include representatives from various federal agencies, as well as individuals employed by the private sector.[11] The CSRB lacks subpoena power and instead relies on voluntary cooperation from organizations with relevant information, though the Biden Administration has published a legislative proposal requesting that Congress grant the CSRB subpoena power.[12]

Remove ads

Reports

Summarize
Perspective

As of 2024, the CSRB has issued three substantive reports.

Review of the December 2021 Log4j Event

On July 11, 2022, the CSRB published its first report, reviewing the Log4Shell vulnerability and associated incidents.[13]

On July 24, 2023, the CSRB published a report reviewing the Lapsus$ international hacker group.[14]

Review of the Summer 2023 Microsoft Exchange Online Intrusion

On March 20, 2024, the CSRB published a report detailing how in May 2023, a cyber threat actor classified by Microsoft as STORM-0558 compromised the mailboxes of a broad range of victims in the United States and United Kingdom, including email accounts in the U.S. Department of State, U.S. Department of Commerce, and U.S. House of Representatives.[15] The CSRB reported that STORM-0558 was able to compromise Microsoft's corporate network using unknown means and steal a Microsoft Services Account (MSA) key, which STORM-0558 then used to sign forged authentication tokens granting it access to specific mail accounts.[15] This malicious cyber activity was eventually detected by the U.S. Department of State, rather than by Microsoft itself.

The CSRB concluded that "Microsoft’s security culture was inadequate and requires an overhaul," noting that Microsoft "failed to detect the compromise of its cryptographic crown jewels on its own, relying instead of a customer."[15] This report was widely covered by traditional media and cybersecurity trade press.[16][17][18][19]

Following the publication of the report, Microsoft CEO Satya Nadalla released a blog post acknowledging the CSRB's report and pledging to prioritize security in the future.[20]

Remove ads

2024 members

Summarize
Perspective

At the time of dissolution, the CSRB was composed of 15 cybersecurity leaders from the federal government and the private sector:[3]

Previous members

Private sector CSRB members serve for a term of two years, which may be renewed up to three times.[11][21]

Remove ads

References

Loading content...
Loading related searches...

Wikiwand - on

Seamless Wikipedia browsing. On steroids.

Remove ads