After two years at #CISA, my term-limited appointment has expired. A necessary mission, a ton of potential, and loads of talent.
-I hope I left the role with as much as I took away
-I know there’s more to do
-I call on others to pick up the challenge
-I wish @CISAjen and her team all the best
In 2020, at the request of @Chris, I joined to help the Agency get better at understanding and engaging with companies and security researchers. Sadly, his last day came prior to my first. Even more sadly, the world was tightly in the grip of the #COVID pandemic.
I’ve worked on fun and meaningful projects and bridging the US Government to the independent security research community who can be among its greatest assets. While there’s certainly more to do, I’m proud of all we were able to accomplish together.
In my first week, I had the great honor to be drafted into the CISA COVID Task Force, alongside highly tenacious, clever, and motivated people across Gov and industry. The challenges were myriad, including our own exhaustion. Fantastic work that I hope to be able to talk more about soon.
Also in my first week I also began working to nudge CISA to do more about Ransomware, particularly targeting health institutions, elevating publicly reported events to leadership, catalyzing assessment frameworks, and building guidance. There’s a lot more still to do.
In addition, I’m especially proud to have contributed to:
-#Bad Practices: https://www.cisa.gov/BadPractices
-#Log4J Response: https://www.cisa.gov/uscert/apache-log4j-vulnerability-guidance
-Stuff off Search: https://www.cisa.gov/publication/stuff-off-search
-Expanding #Crossfeed: https://www.cisa.gov/crossfeed
-CISA CSAC TAC: https://www.cisa.gov/cisa-cybersecurity-advisory-committee
CISA has become THE trusted cybersecurity partner for US agencies, critical infrastructure, and foreign governments. With a reputation for innovation and collaboration, they’ve shown sparks of brilliance and foreshadowed what will work in the decades to come.
CISA will continue doing this by learning from feedback, building on what has worked, changing what’s lackluster, and taking bold steps to lead on cybersecurity and infrastructure security policy, strategy, and operations.
I strongly believe in the CISA mission. With their incredible potential, talent, and authorities from Congress, CISA is limited only by their willingness to be bold and ability to execute. Each passionate, bright person who allies with them can empower that. I urge you to help!
Several ways to engage with CISA.
-Cyber Innovation Fellows: https://www.cisa.gov/cyber-fellows
-Apply for a job: https://www.cisa.gov/careers
-Report issues/vulns: https://www.cisa.gov/report
-Sign up for alerts: https://public.govdelivery.com/accounts/USDHSCISA/subscriber/new?topic_id=USDHSCISA_138
-Meet Regional Contacts: https://www.cisa.gov/contact-us
While we’ve used this Margaret Mead quote many times in #IAmTheCavalry, it also bears mention here: “Never doubt that a small group of thoughtful, committed, citizens can change the world. Indeed, it is the only thing that ever has.”
My stint at CISA was incredibly humbling, educational, and rewarding. I plan to take my time to figure out where I can make the most difference next. No matter what, I will continue to work pushing industries and governments forward.