Back to news

March 6, 2020 | Local, C4ISR, Security

Pentagon push to boost cybersecurity could affect Canadian suppliers

We're at cyberwar every day' - Ellen Lord, the U.S. undersecretary of defence for acquisition

Murray Brewster ·

The Pentagon has been engaged in a quiet, deliberate effort to plug all of the cyber-holes in its high-tech systems and among its defence contractors — an operation that will soon spill across the border into Canada.

Ellen Lord, the U.S. undersecretary of defence for acquisition and sustainment, said today cybersecurity has been one of her biggest concerns since being appointed by the Trump administration two and a half years ago.

Increasingly, major defence contractors have found themselves targeted by hackers from China and Russia who have stolen troves of sensitive data on new and existing weapons systems.

"Bottom line is, I don't think the average American citizen understands that we're at cyberwar every day," Lord told the Conference of Defence Associations Institute's annual meeting in Ottawa today.

The burden of keeping data secure is being placed on the companies themselves, she added.

After consulting with the National Security Agency (NSA), the U.S. electronic spy service and the military's Cyber Command, the Pentagon rolled out a new program in January aimed at forcing defence contractors to deal with points of vulnerability.

"We have written new cyber security standards that we are putting in all of our new contracts," said Lord. "We are looking at the defence industrial base and how they need to address cyber security and how we as a government can hold them accountable."

The initiative includes a cyber security "certification and accreditation" system, similar to the International Organization for Standardization.

Lord said it's not a one-size fits all solution and that companies looking to do business with the Pentagon will have to meet one of five levels of certification, depending upon the contract.

The defence industrial complexes of Canada, Britain and Australia are tightly stitched into the U.S. system. Lord said allies are looking at a similar measures which she hopes to see coordinated with American efforts.

"This is something we're talking with Canada about, with allies and partners, because a lot of us are doing the same thing," she said.

The problems with existing systems — software already in the field — is being dealt with aggressively. Contractors who are responsible for maintaining complex systems on warships and aircraft are being told by the Pentagon to close their potential security gaps.

"We are going to start shutting equipment down if they are not brought up to standard because every day we see [intelligence], we see how much has been compromised," Lord said.

Troy Crosby, head of the Canadian Department of National Defence's materiel branch, said Innovation, Science and Economic Development Canada has launched a "cyber secure program" and there's a hope that the two countries can find a way to align their efforts.

Some analysts and critics in the U.S. have argued that contractors — even those that make cyber security a priority — will find the cost of meeting uniform standards prohibitive.

Beyond that, many major contractors have complex supply chains with many smaller companies that also would be required to spend substantial sums of money to keep up with evolving threats.

https://www.cbc.ca/news/politics/pentagon-contractors-cyber-security-1.5487452

On the same subject

  • New fighter jets ‘can’t arrive quickly enough,’ Canada’s top military commander says

    December 31, 2018 | Local, Aerospace

    New fighter jets ‘can’t arrive quickly enough,’ Canada’s top military commander says

    By BRUCE CAMPION-SMITH Ottawa Bureau OTTAWA—A new fighter jet “can't arrive quickly enough” for Canada's Air Force as it deals with aging CF-18s that are approaching the end of their useful life, the country's top military commander says. Gen. Jonathan Vance, the chief of defence staff, acknowledged that an old fighter and personnel shortages present challenges for the Air Force. “The F-18 is clearly an aircraft that is one that is coming to the end of its useful life. But it's not at the end,” Vance told the Star in a year-end interview. “I'm real keen to get the future fighter in place as quickly as possible. Until then we've got the F-18. We're going to have to invest in it to ensure that our aircrew, the RCAF, can continue to ... protect Canada and Canadians and be valued in operations,” he said. A recent report by the federal auditor general's office put the challenges facing the Air Force into stark focus with its findings that the CF-18s, first delivered in 1982, are increasingly obsolete. But more critically, the report said the bigger challenge was a shortage of technicians to maintain the 76 existing jets and pilots to fly them. Vance said the military is moving to address its personnel shortages. On the pilot front, the problem isn't attracting new recruits, he said. It's training them and then keeping them in uniform at a time when civilian airlines are dangling the promise of big paycheques and better quality of life. “I'm not going to lie to you. It's not going to be easy,” Vance said. “There's no way we're ever going to be able to compete with private industry. We never have. You don't join the military for the paycheque,” he said. But he said the Air Force is considering a number of measures, from better compensation and benefits to addressing complaints about postings and desk jobs that contribute to drive pilots from the ranks. Lt.-Gen. Al Meinzinger, RCAF commander, told the Commons public accounts committee in December that pilots quit because of family challenges, tempo of operations, work-life balance and geographic postings. “My assessment is that it's going to take us approximately five to seven years to grow the crew force. Again, a lot of the considerations are in the future. We have to stave off the attrition we're experiencing today. We're getting at that as a priority in terms of some of the retention ideas we have,” Meinzinger told the committee. A tortured procurement stretching over several governments, with several false starts, has delayed the purchase of new fighters, leaving the Air Force with the CF-18s, which require 24 hours of maintenance for every hour they fly. Jody Thomas, the deputy minister of defence, told the Commons public accounts committee in December the government now expects to release a request for proposals next spring with bids submitted in 2020 and a contract award in 2022. Under that timeline, deliveries of 88 new fighters would occur between 2025 and 2032. “We expect to achieve initial operating capability by 2026 with nine advanced fighters ready to fulfil the NORAD mission,” Thomas said. That still means the CF-18s have to remain airworthy and combat capable for up to 12 more years to help bridge the transition, a tall order for jets that are already three decades old. To help augment the fleet and spread the flying hours, the federal government has purchased 18 used F-18s from Australia. The first of those aircraft is expected to arrive late winter. They will require maintenance checks and some upgrades to make them compatible with existing fleet. National Defence expects to spend almost $3 billion to extend the life of its current fleet and to buy, operate and maintain the interim aircraft. The auditor general's report noted the CF-18 has not undergone any significant upgrade to its combat capabilities since 2008. That's because the Air Force thought they would be replaced. Now, analysis is underway on how best to upgrade some of the CF-18s as early as 2020 in the areas of sensors, weapons, self-protection and mission support capabilities. “Those capability upgrades are sufficient ... to keep the aircraft at an acceptable level of combat capability until the future fleet arrives,” Vance said. Bruce Campion-Smith is an Ottawa-based reporter covering national politics. Follow him on Twitter: @yowflier https://www.thestar.com/politics/federal/2018/12/21/new-fighter-jets-cant-arrive-quickly-enough-canadas-top-military-commander-says.html

  • exactEarth and MarineTraffic Announce Channel Partner Agreement

    June 13, 2019 | Local, C4ISR

    exactEarth and MarineTraffic Announce Channel Partner Agreement

    CAMBRIDGE, ON and ATHENS, Greece, June 13, 2019 /CNW/ - exactEarth Ltd. ("exactEarth") (XCT:TSX), a leading provider of Satellite-AIS data services, and MarineTraffic, a leading global provider of ship tracking and maritime intelligence, announce that they have entered into a three-year channel partner agreement (the "Agreement"). Under terms of the Agreement, MarineTraffic will deploy exactEarth's exactView RT data into its online maritime services products to help bring real-time, business-critical and actionable vessel information to maritime industry participants. exactView RT consists of 58 operational payloads and seven orbital spares that were designed and built by Harris Corporation and that are hosted onboard the Iridium NEXT constellation of satellites, which is owned and operated by Iridium Communications Inc. exactView RT's advanced maritime payloads cover the entire maritime VHF radio band and leverage the unique cross-linked architecture of the Iridium NEXT satellite constellation to deliver AIS and other vessel-based VHF data services from more than 500,000 vessels, anywhere on the globe, relaying that data securely to customers in real-time. MarineTraffic owns the world's preeminent ship-tracking website, which attracts approximately six million unique visitors per month. The company operates 2,000 AIS stations in more than 165 countries around-the-world, delivering the most comprehensive AIS coastal tracking facility available today. For companies in the maritime sector, MarineTraffic is a preferred tool for fleet management, alert and notification systems, vessel particulars, port statistics and actionable intelligence through API. "MarineTraffic is a leading provider of vessel movement information services and we look forward to contributing to their ongoing efforts to enhance their customer experience," said Peter Mabson, President & CEO of exactEarth. "This Agreement opens-up another channel for our Satellite-AIS data services and is a further positive indication of the response we have received from customers, prospects and partners regarding the real-time functionality of exactView RT. With its superior vessel detection, rapid update rate and reliability, exactView RT is becoming a "must-have" data source on major data platforms throughout the maritime industry." Argyris Stasinakis, Partner Business Development, MarineTraffic said, "The addition of exactEarth's high resolution, real-time AIS data means that MarineTraffic is now the go-to source for any professional seeking the most comprehensive view of shipping movements. Users of our platform exploiting our ocean coverage services will see enhanced functionality thanks to the higher frequency, coverage and less than one-minute latency delivered by the exactView RT satellite constellation. This means that our popular predictive services will be more accurate than ever before, allowing our customers to monitor and plan more precisely." About MarineTraffic With headquarters in Athens and international offices in the UK and Singapore, MarineTraffic is the global ship tracking and maritime intelligence provider. Leveraging AIS technology, MarineTraffic is at the forefront of a movement taking shipping into a new digital era. The company's range of services deliver increased transparency to the shipping markets through the provision of high-quality data for analysis, which supports forecasting and informed decision making. MarineTraffic receives analyses and stores millions of vessel positions every day. This data is collected through the world's most extensive network of AIS stations before being enriched to deliver business-critical information. Current positions and vessel's tracks are displayed on a Live Map, with historical positions, vessel details, port conditions and statistics being made available throughout the website. www.marinetraffic.com About exactEarth Ltd. exactEarth is a leading provider of global maritime vessel data for ship tracking and maritime situational awareness solutions. Since its establishment in 2009, exactEarth has pioneered a powerful new method of maritime surveillance called Satellite-AIS and has delivered to its clients a view of maritime behaviours across all regions of the world's oceans unrestricted by terrestrial limitations. exactEarth has deployed an operational data processing supply chain involving a constellation of satellites, receiving ground stations, patented decoding algorithms and advanced "big data" processing and distribution facilities. This ground-breaking system provides a comprehensive picture of the location of AIS equipped maritime vessels throughout the world and allows exactEarth to deliver data and information services characterized by high performance, reliability, security and simplicity to large international markets. For more information, visit www.exactearth.com Forward-Looking Statements This news release contains statements that, to the extent they are not recitations of historical fact, may constitute "forward-looking statements" within the meaning of applicable Canadian securities laws. Forward-looking statements may include financial and other projections, as well as statements regarding exactEarth's future plans, our ability to continue as a going concern, objectives or economic performance, or the assumptions underlying any of the foregoing, including statements regarding, among other things, expectations of our exactView RT offering relative to competitors, timing of the achievement of real-time global vessel tracking via our second-generation constellation, timing expectations with respect to launch of satellites, expectations of the exactView RT capabilities driving growth, growth opportunities for the Company in the maritime information services market and the cost and revenue share in connection with the Harris Agreement. exactEarth uses words such as "may", "would", "could", "will", "likely", "expect", "anticipate", "believe", "intend", "plan", "forecast", "project", "estimate" and similar expressions to identify forward-looking statements. Any such forward-looking statements are based on assumptions and analyses made by exactEarth in light of its experience and its perception of historical trends, current conditions and expected future developments, as well as other factors exactEarth believes are appropriate under the relevant circumstances. However, whether actual results and developments will conform to exactEarth's expectations and predictions is subject to any number of risks, assumptions and uncertainties. Many factors could cause exactEarth's actual results, historical financial statements, or future events to differ materially from those expressed or implied by the forward-looking statements contained in this news release. These factors include, without limitation: uncertainty in the global economic environment; fluctuations in currency exchange rates; delays in the purchasing decisions of exactEarth's customers; the competition exactEarth faces in its industry and/or marketplace; the further delayed launch of satellites; the reduced scope of significant existing contracts; and the possibility of technical, logistical or planning issues in connection with the deployment of exactEarth's products or services. https://www.newswire.ca/news-releases/exactearth-and-marinetraffic-announce-channel-partner-agreement-865863568.html

  • Online 'phishing' attacks expected to target housebound staffers as COVID-19 spreads

    March 17, 2020 | Local, C4ISR, Security

    Online 'phishing' attacks expected to target housebound staffers as COVID-19 spreads

    It's a 'huge opportunity' for online crime, one expert warns The number of "phishing" attacks meant to steal the online credentials of public servants and corporate sector employees now housebound due to the COVID-19 pandemic is on the rise, one cyber security expert warns. Many attempts are being made against employees who are working from home on virtual private works (VPNs). Cyber experts are still gathering data to establish a direct correlation between the pandemic crisis and the increase in malicious activity. But Rafal Rohozinski, chief executive officer of the SecDev Group of Companies, said this pandemic moment — when large numbers of employees are at home and receiving instructions from their workplaces on how to connect to internal networks — offers online thieves a "huge opportunity." Federal government and corporate sector systems were never designed to support a sudden, mass migration of employees from offices to their homes, he said. "The opening that creates for those who want to wreak havoc through ransomware and malware is really, really significant," said Rohozinski. "And I don't think we're anywhere near prepared for that. "What we're seeing is an increase in phishing being used as a means to get people's credentials." U.S. Health Department attacked The U.S. Health and Human Services Department's website was hit by a cyber attack over several hours on Sunday, an incident which involved overloading its servers with millions of hits. Officials said the system was not penetrated, although media reports in Washington described it as an attempt to undermine the U.S. government's response to the coronavirus pandemic — and may have been the work of a foreign actor. Rohozinski said that while the facts are not all in yet, his "professional guess" is that there's a link between the attack and the COVID-19 crisis. Last week, Canada's top military commander warned that he'd seen recent indications the country's adversaries intend to exploit the uncertainty, confusion and fear generated by the pandemic. Send in the trolls: Canada braces for an online disinformation assault on COVID-19 Gen. Jonathan Vance, chief of the defence staff, was not specific about the potential threats — but experts say they could range from hacking to online disinformation campaigns aimed at discrediting the federal government's response. Rohozinski said he's concerned about the federal government's technical capacity to support thousands of employees on private networks. "Everybody's moving on to VPNs. Everybody," he said. "This is an enormous pinpoint and an enormous vulnerability." Federal Digital Government Minister Joyce Murray's office was asked for a response Monday, but was unable to provide an immediate comment. Many of the country's leading information technology companies are part of the Canadian Cyber Threat Exchange (CCTE), a nonprofit centre where companies can swap information and insights. A CCTE spokeswoman said the corporate sector is better prepared to face the challenges posed by the mass movement of employees to home networks. Canada to bar entry to travellers who are not citizens, permanent residents or Americans Canadian military bans international travel in response to COVID-19 Still, there is reason for concern. "Given we are moving people to work from home now, companies need to ensure that the work from home environment is as safe as the corporate environment and that people are trained to notice these phishing campaigns, just like they were in the corporate environment," said Mary Jane Couldridge, director of business development at the CCTE. "It's a matter of keeping our community aware of what is impacting Canada daily so we know how to react to it and prevent it from spreading — and not chase rainbows." Most corporations have plans they'll activate now to cover the wholesale movement of employees to networks outside of the office, she added. https://www.cbc.ca/news/politics/online-hacking-phishing-covid-19-coronavirus-1.5499725

All news