The Times Australia
The Times World News

.
The Times Real Estate

.

Trump has fired a major cyber security investigations body. It’s a risky move

  • Written by Toby Murray, Professor of Cybersecurity, School of Computing and Information Systems, The University of Melbourne



Before the end of its first full day of operations, the new Trump administration gutted all advisory panels for the Department of Homeland Security. Among these was the well-respected Cyber Safety Review Board, or CSRB.

While this change hasn’t received as much notice as Trump’s massive announcement about AI[1], it has potentially significant implications for cyber security. The CSRB is an important source of information for governments and businesses trying to protect themselves from cyber threats.

This change also throws into doubt the board’s current activities. These include an ongoing investigation into the Salt Typhoon cyber attacks which began as early as 2022[2] and are still keeping cyber defenders busy[3], attributed to hackers in China.

Salt Typhoon has been described as the “worst telecommunications hack[4]” in US history. Among other activities, the hackers obtained call records data made by high-profile individuals and even the contents of phone calls and text messages[5]. The phones of then presidential nominee Donald Trump were reportedly among those targeted[6].

What does the Cyber Safety Review Board do?

The board was established three years ago by the Biden administration. Roughly speaking, its job is the cyberspace equivalent of government air traffic investigation bodies such as the US National Transportation Safety Board, or the Australian Transport Safety Bureau.

The CSRB investigates major cyber security incidents. Its job is to determine their causes and recommend ways government and businesses can better protect themselves, including on how to prevent similar incidents in future.

Its members include global cyber security luminaries from industry, such as cyber executives from Google and Microsoft, and US government leaders from several departments and agencies concerned with security.

The US CSRB has previously published three major reports. Its first covered the infamous 2021 Log4j vulnerability[7], described at the time[8] as the “single biggest, most critical vulnerability ever”. (A vulnerability is a weakness in a computer system that cyber criminals can exploit.)

The board’s most recent published investigation involved a very sophisticated hacking campaign[9] that targeted Microsoft’s cloud email services in 2023. As a result, hackers even gained access to the emails of various US government agencies.

Cyber security experts widely consider the CSRB as a positive thing. Late last year, Australia even committed to establish its own version, the Cyber Incident Review Board[10].

At the time of writing, it’s unclear whether the CSRB will continue – perhaps with different membership – or whether its activities will cease entirely.

Either way, the decision to fire the board’s members[11] has significant security implications. It comes at a moment in history when cyber threats have never been more severe.

What is Salt Typhoon?

The CSRB has been investigating the Salt Typhoon hacking campaign. Salt Typhoon is the name Microsoft assigned to a sophisticated group of hackers believed to be operated by China’s Ministry of State Security. The ministry is somewhat like a combination of an intelligence agency and a secret police service.

Salt Typhoon is best known for hacking into several US telecommunication companies, first reported in August 2024[12]. In December, it came to light Salt Typhoon’s telco hacks may also have impacted countries beyond the US. American, Australian, Canadian and New Zealand authorities also jointly issued public guidance[13] to organisations to help defend against Salt Typhoon.

Salt Typhoon reportedly targeted prominent figures, including political leaders. The hackers’ goal appears to have been to collect intelligence, rather than cause damage.

For example, it has been reported[14] Salt Typhoon collected a list of all phone calls made near Washington DC, which could help them determine who was talking to whom in the US capital.

Salt Typhoon also reportedly[15] obtained a list of phone numbers wiretapped by the US Justice Department. This confirmed the fears of many people opposed to the government’s powers to lawfully wiretap citizens’ phones.

It is unclear why the hackers obtained that information. Some have speculated[16] it would identify which of their own operatives were being monitored by US law enforcement.

To say the Salt Typhoon revelations created waves[17] in government and cyber security circles is putting it mildly. Telecommunications are critical infrastructure, as well as highly valuable targets for intelligence collection.

The idea that foreign spies could burrow so deeply into the communication fabric of the US was unprecedented and disturbing.

In October 2024 the CSRB was tasked[18] with investigating Salt Typhoon’s activities.

Street view of a building with big verizon logo in New York.
Verizon was one of the telcos affected by Salt Typhoon attacks. Tada Images/Shutterstock[19]

An uncertain future

With the board now fired, the future of the Salt Typhoon investigation remains unclear.

A thorough and impartial investigation of the Salt Typhoon hacks, had it been allowed to run, was likely to have delivered highly valuable cyber security lessons. Those lessons are important for both US companies and those in Australia, which have also been the targets[20] of Chinese intelligence collection.

The future of the CSRB itself is now also in question. The board and its overseas equivalents serve a vital role in promoting cyber information-sharing that helps to improve best practices.

It is imperative these bodies are staffed with a diverse collection of impartial experts, able to carry out their work free from government and corporate interference.

It remains to be seen whether dissolving the current CSRB will be a gift to Chinese hackers (as some have claimed[21]), or simply a speed bump in the evolution of the board.

References

  1. ^ massive announcement about AI (theconversation.com)
  2. ^ began as early as 2022 (theconversation.com)
  3. ^ are still keeping cyber defenders busy (www.cybersecuritydive.com)
  4. ^ worst telecommunications hack (www.washingtonpost.com)
  5. ^ even the contents of phone calls and text messages (www.wsj.com)
  6. ^ reportedly among those targeted (www.nytimes.com)
  7. ^ Log4j vulnerability (en.wikipedia.org)
  8. ^ described at the time (www.wired.com)
  9. ^ very sophisticated hacking campaign (www.cisa.gov)
  10. ^ Cyber Incident Review Board (www.homeaffairs.gov.au)
  11. ^ fire the board’s members (www.darkreading.com)
  12. ^ first reported in August 2024 (www.washingtonpost.com)
  13. ^ public guidance (www.cisa.gov)
  14. ^ it has been reported (techcrunch.com)
  15. ^ reportedly (www.wsj.com)
  16. ^ Some have speculated (theconversation.com)
  17. ^ created waves (foreignpolicy.com)
  18. ^ tasked (federalnewsnetwork.com)
  19. ^ Tada Images/Shutterstock (www.shutterstock.com)
  20. ^ targets (www.abc.net.au)
  21. ^ some have claimed (www.theregister.com)

Read more https://theconversation.com/trump-has-fired-a-major-cyber-security-investigations-body-its-a-risky-move-248106

The Times Features

An Introduction to Complete Hip Replacement Surgery

Hip replacement or total hip arthroplasty is a relatively common medical procedure to regain mobility and bring an end to incessant pain in victims of extreme pain in the hip joi...

2 in 3 Melbourne Families Are Downsizing—But Not for the Reason You Think, Says Big Stuff Movers

MELBOURNE, AUSTRALIA — [16-05-25] — In a city known for its vibrant culture and sprawling suburbs, a quiet revolution is underway. According to recent internal data from Big Stuf...

Runway With a Hug: Gary Bigeni’s Colourful Comeback

By Cesar Ocampo Photographer | AFW 2025 Some designers you photograph once, admire from afar, and move on. But others — like Gary Bigeni — pull you in and never let go. Not becaus...

Tassie’s best pie enters NSW with the launch National Pies’ new fresh range

Fresh from Tasmanian Bakeries in Hobart, National Pies has just delivered Tassie’s best-selling pie to the ready meals aisles of Woolworths stores across NSW.  The delicious roll o...

IORDANES SPYRIDON GOGOS RUNWAY | AFW 2025

Fifth Collection by ISG | Words + Photography by Cesar Ocampo Some runway shows are about the clothes. Others are about the culture they carry. With Iordanes Spyridon Gogos, it’s ...

AJE Resort ‘26 — “IMPRESSION”

Photographed by Cesar Ocampo | AFW 2025 Day 3, Barangaroo Pier Pavilion There are runways, and then there are moments. Aje’s Resort ‘26 collection, IMPRESSION, wasn’t just a fashi...

Times Magazine

Senior of the Year Nominations Open

The Allan Labor Government is encouraging all Victorians to recognise the valuable contributions of older members of our community by nominating them for the 2025 Victorian Senior of the Year Awards.  Minister for Ageing Ingrid Stitt today annou...

CNC Machining Meets Stage Design - Black Swan State Theatre Company & Tommotek

When artistry meets precision engineering, incredible things happen. That’s exactly what unfolded when Tommotek worked alongside the Black Swan State Theatre Company on several of their innovative stage productions. With tight deadlines and intrica...

Uniden Baby Video Monitor Review

Uniden has released another award-winning product as part of their ‘Baby Watch’ series. The BW4501 Baby Monitor is an easy to use camera for keeping eyes and ears on your little one. The camera is easy to set up and can be mounted to the wall or a...

Top Benefits of Hiring Commercial Electricians for Your Business

When it comes to business success, there are no two ways about it: qualified professionals are critical. While many specialists are needed, commercial electricians are among the most important to have on hand. They are directly involved in upholdin...

The Essential Guide to Transforming Office Spaces for Maximum Efficiency

Why Office Fitouts MatterA well-designed office can make all the difference in productivity, employee satisfaction, and client impressions. Businesses of all sizes are investing in updated office spaces to create environments that foster collaborat...

The A/B Testing Revolution: How AI Optimized Landing Pages Without Human Input

A/B testing was always integral to the web-based marketing world. Was there a button that converted better? Marketing could pit one against the other and see which option worked better. This was always through human observation, and over time, as d...

LayBy Shopping