Biden Administration Issues Another Stark Warning on Cybersecurity

Mar 22, 2022

Reading Time : 2 min

He notes that the Biden administration “will continue to use every tool to deter, disrupt, and if necessary, respond to cyberattacks against critical infrastructure,” but that the government “can’t defend against this threat alone” and needs “the private sector and critical infrastructure owners and operators [to] accelerate efforts to lock their digital doors.”

He further urged “private sector partners to harden . . . cyber defenses immediately by implementing the best practices [the administration and partners] have developed together over the last year.” This “Shields Up” guidance is available here.

A related Fact Sheet “urge[s] companies to execute [various] steps with urgency,” including:

  • Mandating multi-factor authentication to make it harder for attackers to access systems.
  • Deploying modern security tools to continuously look for and mitigate threats.
  • Patching and protecting systems against known vulnerabilities and changing passwords to make “previously stolen credentials . . . useless to malicious actors.”
  • Backing up data and making sure offline back-ups are “beyond the reach of malicious actors.”
  • Practicing emergency plans to ensure quick response to and recovery from an attack.
  • Encrypting data so it cannot be used if stolen.
  • Educating staff on common tactics attackers use and encouraging reporting of “unusual behavior” on systems, such as “unusual crashes or operating very slowly.”
  • Engaging proactively with the FBI and/or Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) “to establish relationships in advance of any cyber incidents.”

Together, Biden notes, companies in the private sector “have the power, the capacity, and the responsibility to strengthen the cybersecurity and resilience of the critical services and technologies on which Americans rely.” He urges “everyone to do their part to meet one of the defining threats of our time,” noting that “vigilance and urgency today can prevent or mitigate attacks tomorrow.”

CISA Director Jen Easterly added that President Biden’s statement “reinforces the urgent need for all organizations, large and small, to act now to protect themselves against malicious cyber activity.” She said that CISA, “[a]s the nation’s cyber defense agency, . . . has been actively working with critical infrastructure entities to rapidly share information and mitigation guidance that will help them protect their systems” and “will continue working closely with . . . federal and industry partners to monitor the threat environment 24/7 and . . . stand ready to help organizations respond to and recover from cyberattacks.”

Share This Insight

Previous Entries

Speaking Energy

July 8, 2026

On June 18, 2026, the Federal Energy Regulatory Commission (FERC or the Commission) issued an order to ISO New England Inc. (ISO-NE) directing ISO-NE and ISO-NE participating transmission owners to show cause as to why ISO-NE’s tariff should not be found to be unjust and unreasonable (ISO New England Inc., 195 FERC ¶ 61,215 (2026) (Order)) because it fails to sufficiently:

...

Read More

Speaking Energy

July 7, 2026

On June 29, 2026, the Supreme Court granted a petition for certiorari in Leonard Hoffmann v. WBI Energy Transmission, Inc. (Hoffmann), which presents the question whether section 7 of the Natural Gas Act (NGA) requires pipeline companies using federal eminent domain authority to pay landowners’ attorney’s fees in states where landowners can recover those fees under state law. In the decision giving rise to the Supreme Court’s review, the U.S. Court of Appeals for the Eighth Circuit held that a group of ranchers were not entitled to recover their $383,300 in attorney’s fees incurred while negotiating their compensation—creating a circuit split with four other courts of appeals. Hoffmann will be heard during the Court’s October 2026 Term, and marks the second time in five years that the Court has agreed to interpret NGA section 7.

...

Read More

Speaking Energy

July 6, 2026

On June 29, 2026, the United States Supreme Court issued Trump v. Slaughter, fundamentally reshaping presidential removal authority over independent regulatory agencies. The decision overruled a 90-year-old precedent established in Humphrey’s Executor v. United States, which had upheld the constitutionality of commissioner removal protections in the Federal Trade Commission Act (FTC Act). As written, the FTC Act permits a commissioner’s removal “only for inefficiency, neglect of duty, or malfeasance in office.” In Slaughter, the Court was asked to reevaluate this standard following the President’s removal of a Democratic-appointed FTC commissioner from office in 2025 without cause. Finding for the President, the Court held that removal was permissible because the FTC Act’s for-cause removal protections for commissioners violate the separation of powers, specifically, the President’s removal power under Article II. The Court explained that the FTC exercises executive power because it promulgates binding rules, investigates and enforces those rules through administrative adjudications, and brings civil enforcement actions in federal court. It found that because it exercises these executive powers, its commissioners “must therefore be controlled by the Chief Executive, in whom such power is vested.” While previous recent cases addressing the scope of the Removal Power, Seila Law LLC v. Consumer Financial Protection Bureau and Collins v. Yellen purported to preserve some kernel of Humphrey’s, the Court made clear that “[i]f anything more is left of Humphrey’s, we overrule it.”

...

Read More

Speaking Energy

June 25, 2026

On June 18, 2026, the Federal Energy Regulatory Commission (FERC or the Commission) issued an order to the California Independent System Operator Corporation (CAISO) directing CAISO and CAISO transmission owners to show cause as to why CAISO’s tariff should not be found to be unjust and unreasonable (California Indep. Sys. Operator Corp., 195 FERC ¶ 61,214 (2026) (the Order)) because it fails to sufficiently:

...

Read More

© 2026 Akin Gump Strauss Hauer & Feld LLP. All rights reserved. Attorney advertising. This document is distributed for informational use only; it does not constitute legal advice and should not be used as such. Prior results do not guarantee a similar outcome. Akin is the practicing name of Akin Gump LLP, a New York limited liability partnership authorized and regulated by the Solicitors Regulation Authority under number 267321. A list of the partners is available for inspection at Eighth Floor, Ten Bishops Square, London E1 6EG. For more information about Akin Gump LLP, Akin Gump Strauss Hauer & Feld LLP and other associated entities under which the Akin Gump network operates worldwide, please see our Legal Notices page.