US State Department to establish cyber bureau
This comes as the country has experienced a number of high profile cyber attacks on its critical infrastructure in the last year


The US State Department is set to establish a cyber bureau after the country experienced a surge of cyber attacks on its critical infrastructure.
The Bureau of Cyberspace and Digital Policy will be led by a Senate-confirmed ambassador and will focus on three key areas: cyberspace security, international digital policy, and digital freedom.
The department hopes this will integrate the core security, economic, and values components of its cyber agenda. It also revealed its plans to establish a new special envoy for critical and emerging technology to lead the immediate technology diplomacy agenda with its allies and partners.
“The Bureau of Cyberspace and Digital Policy, that will include three sub-units focused on international cyberspace security – that’s cyber policy and negotiations, cyber deterrence, cyber operations, and capacity building – international digital policy – and so that includes, for example, engagement with the ITU, standard-setting bodies, promotion of trusted telecom systems, digital technology tracks and multilateral agenda – and digital freedom,” said Ned Price, State Department spokesperson.
The move comes as the US recovers from a number of high-profile cyber attacks, like the Colonial Pipeline attack in May which led to the shutdown of the US fuel pipeline. The company manages around 45% of the US east coast’s fuel supplies and was forced to suspend 5,500 miles of pipeline between Texas and New York after falling victim to ransomware from the DarkSide group.
RELATED RESOURCE
HP Wolf Security: Threat insights report
Equipping security teams with the knowledge to combat emerging threats
The following month, JBS Foods paid an $11 million ransom to hackers who compromised its IT systems. The company, the largest processor of meat in the world and produces close to a quarter of the US’s beef, fell victim to an attack at the end of May. The company confirmed it made the $11 million ransom payment in Bitcoin.
As part of its response to the growing threat, the US Treasury has also imposed sanctions on virtual currency exchange Suex for its alleged role in facilitating transactions for ransomware actors. The Treasury said in September that Suex facilitated transactions involving illicit proceeds from at least eight ransomware variants, underlining that over 40% of its transaction history is associated with illicit actors.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Zach Marzouk is a former ITPro, CloudPro, and ChannelPro staff writer, covering topics like security, privacy, worker rights, and startups, primarily in the Asia Pacific and the US regions. Zach joined ITPro in 2017 where he was introduced to the world of B2B technology as a junior staff writer, before he returned to Argentina in 2018, working in communications and as a copywriter. In 2021, he made his way back to ITPro as a staff writer during the pandemic, before joining the world of freelance in 2022.
-
Prolific ransomware operator added to Europe’s Most Wanted list as US dangles $10 million reward
News The US Department of Justice is offering a reward of up to $10 million for information leading to the arrest of Volodymyr Viktorovych Tymoshchuk, an alleged ransomware criminal.
-
Jaguar Land Rover “did the right thing” shutting down systems to thwart cyber attack
News The attack on Jaguar Land Rover highlights the growing attractiveness of the automotive sector
-
Ransomware attack on IT supplier disrupts hundreds of Swedish municipalities
News The attack on IT systems supplier Miljödata has impacted public sector services across the country
-
A notorious hacker group is ramping up cloud-based ransomware attacks
News The Storm-0501 threat group is refining its tactics, according to Microsoft, shifting away from traditional endpoint-based attacks and toward cloud-based ransomware.
-
Security researchers have just identified what could be the first ‘AI-powered’ ransomware strain – and it uses OpenAI’s gpt-oss-20b model
News Using OpenAI's gpt-oss:20b model, ‘PromptLock’ generates malicious Lua scripts via the Ollama API.
-
Data I/O shuts down systems in wake of ransomware attack
News Regulatory filings by Data I/O suggest the costs of dealing with the attack could be significant
-
Average ransom payment doubles in a single quarter
News Targeted social engineering and data exfiltration have become the biggest tactics as three major ransomware groups dominate
-
BlackSuit ransomware gang taken down in latest law enforcement sting – but members have already formed a new group
News The notorious gang has seen its servers taken down and bitcoin seized, but may have morphed into a new group called Chaos