This article appeared in Cybersecurity Law & Strategy, an ALM publication for privacy and security professionals, Chief Information Security Officers, Chief Information Officers, Chief Technology Officers, Corporate Counsel, Internet and Tech Practitioners, In-House Counsel. Visit the website to learn more.

It is difficult, if not impossible to think of a comparable cyber event to the one that effectively shut down the fuel pipeline that feeds over a third of the United States. The incident is unprecedented, and it is almost unfathomable that it occurred — despite warnings and longstanding fears about this very type of critical infrastructure incident. As the reports roll in of yet another critical widespread security incident, we are in the midst of a national cyber crisis, in addition to a border crisis, an economic crisis, and a winding pandemic. While we may have blueprints for the resolution of these other crises, things must urgently change on the cybersecurity front.

Over the last several months, major cyberattacks have been all too common mercilessly sparing no one including hospitals and schools, and even more recently an attack on JBS, the world's largest beef supplier, who was forced to close its meat processing plants in the United States and Australia. Many organizations are also still reeling from the effects of the widespread Microsoft Exchange vulnerability exploit known as "Hafnium". Affecting an untold number of companies at the core of their communications, this exploit was designed to silently steal data and it has been traced back to Chinese hacking collectives. A little further back, we found out about the SolarWinds attack, which ultimately affected thousands of companies, blinding them from their environments, injecting code and leaking data, this time tracing back to Russian sources. (For more on the SolarWinds attack, see, "How Should Directors Respond to the SolarWinds Attack," in the May 2021 issue of Cybersecurity Law & Strategy.) There is also the continual feed of ransomware incidents and a few months ago, a cyber-attack attempted to poison a water-treatment plant in Florida.