The Director of the U.S. Defense Information Security Agency (DISA), Lieutenant General Robert J. Skinner, told a Senate committee on Wednesday that foreign actors are targeting third-party government contractors to access sensitive data and breach the Department of Defense (DOD).
According to Lt. Gen. Skinner, foreign adversaries see the defense industrial base as a “soft underbelly” and are “really targeting” industries in this space. The U.S. defense industrial base refers to the worldwide network of industries and institutions that contribute to the country’s military requirements.
He said threat actors are not only trying to steal highly sensitive information from their targets but are also trying to find ways to infiltrate the Pentagon’s systems.
Pentagon’s Network is the Third Largest Attack Surface in the World, Says Skinner
Lt. Gen. Skinner’s made the comments in response to questions at a U.S. Senate Committee on Armed Services hearing, which focused on the enterprise cybersecurity of the Department of Defense’s information networks.
The committee questioned Lt. Gen. Skinner and John B. Sherman, the Pentagon’s Chief Information Officer, about the status of specific programs, including the DISA Thunderdome prototype — a pilot program to develop and implement a zero-trust network architecture across the DOD.
“As I talk in the open forums, the Department of Defense information network attack surface is the third largest in the world, behind the United States and China,” said Lt. Gen. Skinner.
“We are continually upgrading our capabilities at the boundary to protect and secure, as well as continually scanning the boundary from the outside to make sure that what an adversary may see, we’ll see before them,” he added.
While he didn’t name any specific perpetrators of these attacks, hackers sponsored by U.S. adversaries like Russia and China are known to target critical government infrastructure.
Partnership with Private Parties and CMMC 2.0 Critical for Security
When asked about measures and initiatives to improve the security of the Pentagon’s private partners, Lt. Gen. Skinner said the continued partnership with the defense industrial base would play a pivotal role.
“As we work with them to understand the threat vector and their security posture is, I think is first and foremost,” Skinner stated. “In order to protect you have to understand, so the ability for them to sense and see what their environment is, I think is the most important thing we can continue to do as a partner.”
Skinner also said working with the Cybersecurity Maturity Model Certification (CMMC)2.0 is critical to protect the Pentagon. CMMC 2.0 is a framework launched by the Department of Defense to protect the defense industrial base from cyberattacks.
Cybercriminals also target third-party contractors of private companies to breach their networks. In recent years, DoorDash, Snap, and Uber have suffered data leaks due to third-party breaches.
