Week in Review: CISA officials furloughed, DeepSeek’s weak security, Cairncross as cyberdirector
Feb 14, 2025
auto_awesome
Doug Mayer, VP and CISO at WCG, shares his expertise on pivotal cybersecurity developments. He delves into the leadership changes at CISA and their implications for election security amidst the rise of AI technologies. The discussion highlights vulnerabilities in DeepSeek's security and the unsettling trend of collaboration between state-sponsored actors and cyber criminals. Mayer emphasizes the need for rigorous testing and responsible AI use while advocating for enhanced compliance measures to navigate the dynamic threats faced by the industry.
The furlough of CISA's election security officials may elevate the risk of misinformation and weaken electoral safety across the nation.
DeepSeek's alarming security flaws highlight the critical need for robust measures as AI technologies increasingly integrate into business applications.
Deep dives
CISA Officials on Leave Amid Policy Changes
Several officials from CISA's election security team have been placed on administrative leave as part of a policy shift under the new administration. This decision particularly affects those involved in countering misinformation and disinformation related to elections, raising concerns about the vulnerabilities of smaller jurisdictions. Former election secretary Kim Wyman cautions that this change may leave local areas more susceptible to misinformation, as CISA's past efforts have been crucial in mitigating foreign influence. The rollback of these initiatives could potentially weaken the security of electoral processes across the nation.
DeepSeek's Security Vulnerabilities in AI
Research on DeepSeek's large language model has revealed a propensity for significant security oversights, notably in its inability to effectively mitigate the creation of malware. Findings suggest that the model failed to prevent malicious activity 93% of the time and allowed for the circumvention of system safeguards in 91% of attempts. While it did show improved results in leaking training data, the overall security risks associated with DeepSeek raise concerns about its readiness for business applications. The lack of comprehensive guardrails highlights the importance of robust security measures as AI technologies continue to evolve.
RNC Executive Appointed as National Cyber Director
Sean Cairncross, previously the RNC's COO, has been nominated as the national cyber director, a role aimed at advising the president on cybersecurity issues. Despite lacking a background in cybersecurity, his experience in political administration raises questions about the appropriateness of appointing someone from outside the industry for this sensitive position. Experts argue that seasoned professionals with deep cybersecurity knowledge are essential in navigating complex security scenarios swiftly. While support staff with expertise may assist him, the need for immediate, informed decision-making in cybersecurity crises remains critical.
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Doug Mayer, vp, CISO, WCG
Thanks to our show sponsor, Vanta
Do you know the status of your compliance controls right now? Like…right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines
All links and the video of this episode can be found on CISO Series.com
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode