Army says it’s mitigated ‘critical’ cybersecurity deficiencies in early NGC2 prototype
The US Army says it has mitigated several cybersecurity risks discovered in an early iteration of its nascent Next Generation Command and Control (NGC2) platform, as detailed in a blunt memo obtained by Breaking Defense.
Penned on Sept. 5 and signed by Army Chief Information Office Chief Technology Officer Gabriele Chiulli, the document said the NGC2 platform “in its current state, exhibits critical deficiencies in fundamental security controls, processes, and governance.”
“These issues collectively create a significant risk to data, mission operations, and personnel by rendering the system vulnerable to insider threats, external attacks, and data spillage,” the document said. Chiulli wrote at the time that the Army “lack[s] the visibility and controls necessary to ensure the security and integrity of the platform. There seems to be a rush to get capabilities into the system without actual oversight or process to do it, putting greater risk as this system further increases this risk.”
Read more at Breaking Defense