Microsoft Could Reap Over $150 Million in New US Cybersecurity Spending Despite Recent Hacks

Author - Sunil Parashar
16 March 2021

⚫ Microsoft stands to receive nearly a quarter of Covid relief funds destined for US cybersecurity defenders, sources told Reuters, angering some lawmakers who don't want to increase funding for a company whose software was recently at the heart of two big hacks. Congress allocated the funds at issue in the COVID relief bill signed on Thursday after two enormous cyberattacks leveraged weaknesses in Microsoft products to reach into computer networks at federal and local agencies and tens of thousands of companies. One breach attributed to Russia in December grabbed emails from the Justice Department, Commerce Department, and Treasury Department.


⚫ The hacks pose a significant national security threat, frustrating lawmakers who say Microsoft's faulty software is making it more profitable.


⚫ "If the only solution to a major breach in which hackers exploited a design flaw long ignored by Microsoft is to give Microsoft more money, the government needs to re-evaluate its dependence on Microsoft,” said Oregon Senator Ron Wyden, a leading Democrat on the intelligence committee.


⚫ "The government should not be rewarding a company that sold it insecure software with even bigger government contracts."


⚫ Microsoft previously said it prioritises fixing attacks that it sees in wide use. A draft spending plan by the Cybersecurity Infrastructure Security Agency allocates more than $150 million of their new $650 million funding for a "secure cloud platform," according to documents seen by Reuters and people familiar with the matter.


⚫ More precisely, the money has been budgeted for Microsoft, according to four people briefed on the choice, largely to help other federal agencies upgrade their existing Microsoft deals to improve the security of their cloud systems. A CISA spokesman declined to comment.


⚫ A key service Microsoft provides, known as activity logging, allows its clients to keep watch on data traffic within their part of the cloud and spot inconsistencies that could reveal hackers at work. Officials have sought access to Microsoft's premium tracking capability after discovering the lack of logs made it much harder to investigate recent hacks tied to nation-states. Microsoft said Sunday that while all its cloud products have security features, "larger organizations may require more advanced capabilities such as a greater depth of security logs and the ability to investigate those logs and take action." It did not address the fairness issues raised by lawmakers.


⚫ Microsoft has turned security offerings into a significant source of revenue, with the business generating $10 billion annually, up 40 percent from the previous year. Representative Dutch Ruppersberger of the House appropriations committee said Congress must look into "why security is an afterthought in the procurement process" and move away from approving only the lowest bidders. The government could impose new regulations, said Curtis Dukes, a former head of the defensive mission at the National Security Agency now at the nonprofit Center for Internet Security, which works closely with CISA. “Maybe with additional size, vendors should have to do more.”


Click here to add comment

Hey viewer!


This feature is only available for subscribers.

Be a part of community of thousand of tech-enthusiast like you.


Subscribe to Techbuzz !!!




People who read this also read

article

OnePlus 9 Pro Display Details Revealed, Fluid Display 2.0 With Dynamic 120Hz Refresh Rate on Board

Jagmeet Singh
15 March 2021
article

Google Lens for Android Gets Gallery Mode for Quicker Access to Screenshots: Report

Satvik Khare
14 March 2021
article

GoPro Quik App Gets New Video Editing Tools, ‘Mural’ Private Feed for Users

Sourabh Kulesh
13 March 2021