Preparing New York for evolving cyber threats

Michaela Lee is the deputy chief cyber officer for operations at the state Cyber Office.

Michaela Lee is the deputy chief cyber officer for operations at the state Cyber Office. Courtesy of Michaela Lee

An interview with New York State Deputy Chief Cyber Officer for Operations Michaela Lee.

New York is one of the few states in the nation to have a dedicated Cyber Office, which centralizes cybersecurity management efforts. The office, led by New York’s first Chief Cyber Officer Colin Ahern, works to protect the state’s critical infrastructure, digital assets and individuals’ information from cyber threats.

Ahern and Deputy Chief Cyber Officer for Operations Michaela Lee will be speaking at City & State’s “Information Security Summit” on Oct. 7. Ahead of the event, Lee spoke about what her office does and how the state is preparing for evolving cyber threats. This interview has been edited for length and clarity.

What are currently the biggest concerns for New York state regarding cyber threats and cybersecurity? 

We know that adversaries are targeting critical infrastructure and are looking to exploit vulnerabilities that we might have in our system, so thinking about ways in which we can better protect New York state systems as well as critical infrastructure, local governments, and municipalities and small businesses has been really top of mind for us. A big part of that is raising the baseline and making sure that people are doing the industry-standard practices that we know to work against common adversarial attacks, whether that’s criminal groups, ransomware groups or nation-state adversaries. That’s things like multifactor authentication, ensuring that there’s good segmentation, that there’s endpoint detection and response – those types of things that make sure that businesses and critical infrastructure owners and operators have a good handle on their cybersecurity.

As technology is evolving rapidly, how can government prevent cyber threats before they happen? 

Much of what our office does is split between two modalities. One is thinking about responding to incidents and ensuring that critical infrastructure entities and state entities can get back up and operational as soon as possible. There are great teams within the state of New York that focus on incident response and making sure that we have the tools and capabilities that we need to get people back up and working. 

But then, we also have to think about the longer-term strategic resilience of our systems, whether that means doing assessments and prioritization with New York state agencies (or) building cyber resilience and preparedness by building up those cyber muscles at each agency, and that requires resources and tools and capabilities. We want to take that longer-term view as well, and a lot of the tools that we have at our disposal, including the Joint Security Operations Center, help us create and maintain a state-wide picture of our risk, and that’s really helpful as well. 

What policy and legislative initiatives is the state looking at now in regard to cybersecurity? 

One of the things that we’re implementing right now is legislation that Gov. Hochul passed on requiring the timely notification of cybersecurity incidents and ransomware payments that impact local government. This is really essential to ensure that the state has situational awareness of statewide cyber threat activity, and it helps us create that more comprehensive threat picture that I was talking about that defends government services and protects New Yorkers. 

The other thing that we have been working on is draft cybersecurity regulations for water and wastewater utilities. This follows regulations that we’ve released for hospitals last year to shore up sectors that are disproportionately hit by ransomware and cyber attacks. We’re undergoing analysis of the public comments that have been submitted recently, and we’re also pairing that with a forthcoming multimillion-dollar grant and technical assistance program that the Environmental Facilities Corporation will develop in collaboration with the regulators. That’s to help the critical infrastructure owners and operators have the resources that they need to comply with the regulations that are currently drafting.

What can New York learn from other states in terms of cybersecurity policy? 

One of the things that we are collaborating with other states on is ensuring that we have the federal resources that we need to continue protecting critical infrastructure and central services. That means working with entities like the Multi-State Information Sharing and Analysis Center and sharing best practices and cyberthreat intelligence so that we can learn from some of the threats that other states are facing, share some of the things that we have identified and make sure that we’re all learning from what each other are seeing in their environments. A ransomware actor that’s targeting a state on the other side of the country might be using the same tactics to target New York entities, and that information sharing is really helpful to ensure that we are learning best practices from others.

What is New York doing really well in this space? What does it need to improve on?

New York is doing a lot on the economic development and research side of AI, especially with Empire AI and launching a new high-performance computing facility in upstate New York, but we’re also very aware of the impact that it will have, and is already having, on cybersecurity. It’s a tool that is increasingly being used by cyber adversaries to increase the scope and scale of their attacks, but it is also being increasingly used by defenders, and we want to make sure we are keeping up with the changes there.

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.