The U.S. government has been very public about its concern for national cybersecurity. There have been grandiose speeches, presidential declarations and several attempts by the legislature to pass new cybersecurity laws. But the problem with America's national cybersecurity strategy is bigger than one-off hacks or data thefts. Crimes perpetrated by the likes of Edward Snowden, Chelsea Manning and the individual(s) who committed the alleged leak of the CIA's highly sensitive cyber warfare tools have resulted in mind-blowing losses.
Beyond those headline grabbers is a problem that gets less attention but poses a significant risk to critical national assets: the fact that private sector businesses operate -- but do not adequately protect -- a vast majority of the nation's critical infrastructure and data.
The federal government, and even the largest private sector enterprises, spend billions on cybersecurity investment but fail to extend those efforts into the SMBs that do much of the legwork. Laws are passed that promise to protect sensitive government information and "critical" systems, but the regulations are fine-tuned to work for the business community, effectively neutering enforcement mechanisms. Until there are real ramifications for cybersecurity failures in government and private sector entities that support the government, we will continue to see national security erode.
Private companies should be responsible for the public interest and implement precautions to minimize security failures that potentially undermine national defense.
Consider, for example, the fallout from a 2013 report that found designs for some of the most sensitive, advanced U.S. weapons systems were hacked by a foreign country. Although it is a serious issue that those weapons systems are now compromised and have likely been duplicated by at least one foreign military, there is no sign of any punishment for the private companies that allowed the theft in the first place. In fact, the companies and their subcontractors that made the stolen systems will ultimately benefit from the espionage: There are a limited number of prime contractors that can perform this work, so the companies from which the systems were stolen will most likely build any replacement systems, if they have not already done so. There is no evidence that the contractors have lost work or otherwise paid for their failure. Until the cost of failure is higher than implementing real security technology, we will continue to see poor choices that lead us to cybersecurity failure.
I first wrote about the potential for a digital D-Day in 2005, then again in 2012. In the years since, we have sadly not come very far in advancing cyber protection of our most important systems. We are still allowing the private sector to decide what assets are critical and how they should protect them. This is true even where their product, service or infrastructure has a direct role in our national cybersecurity strategy and the U.S. government's operational continuity.
Private companies should be responsible for the public interest and implement precautions to minimize security failures that potentially undermine national defense. Cybersecurity professionals who falsely attest to security should be held accountable in the same way business executives are held accountable when their companies violate financial regulations.
But the reality is that the lack of resources within private companies, combined with no serious government enforcement, lead to little constructive action. As long as the U.S. continues to accept the lowest bids and/or sole-source providers in government contracting without serious consideration for their cyber hygiene, we will not see change.
In defense of the contractors, I do believe companies should be able to include burdensome security expenses when submitting bids. Security should be rewarded as a competitive advantage and in the interest of national security.
But if a bidder is found to have not initiated the protections they attested to, they should be penalized. How is a failure to protect U.S. national secrets by not meeting minimum cybersecurity requirements, and, in some cases, committing blatant willful neglect, not considered criminal negligence?
Under International Traffic in Arms Regulations (ITAR) one can get a decade in prison for unlawfully exporting defense technology. Punishments for export violations range from criminal penalties of "up to $1 million per violation and up to 10 years in prison" and for civil violations "seizure and forfeiture of articles, revocation of exporting privileges" with fines of up to $500,000 per violation. One Tennessee professor received 14 months in prison for "exporting military technology" when he taught foreign students about information that the professor didn't even know was protected. In his case, the prosecuting Assistant U.S. Attorney said, "Prison time is appropriate to avoid the appearance of a mere slap on the wrist for so serious of an offense involving national security." A mere accident on the part of this professor is a severe crime in the eyes of the government, but a cyber breach that results in dozens of our most important weapons system being stolen results in no action? We should treat willful neglect of cybersecurity hygiene that results in national security breaches by foreign countries as export violations as well.
As a cybersecurity professional, I know there is no such thing as foolproof cybersecurity: Perfection is not achievable, and even a great defensive posture may not be enough against a determined actor. Organizations are all challenged with the cost and distraction of cybersecurity requirements, but may not be doing enough because, frankly, they just do not feel compelled to make a real effort when it comes to cybersecurity.
For example, some organizations are under such tight pricing constraints that realistic security measures are just not possible. In order to survive, these organizations must gamble on this lack of security and hope they are never a target for hacking, or even audited. Other organizations are simply woefully uneducated on their security obligations, and still others sincerely try to understand these obligations but still do not succeed.
By design, U.S. cybersecurity laws and regulations are ambiguous and flexible. This flexibility, while intended to make it easier for organizations to comply, really makes it that much harder by not spelling out, in clear terms, what private sector organizations actually must do. We must insist that private sector companies work toward becoming secure, and then assist them when taking the necessary steps to help further the national cybersecurity strategy.
While I do not propose rushing into actions haphazardly, we must not just keep planning. We should start by:
With each administration there is a renewed commitment and refreshed cybersecurity directives that result in nothing of consequence. There has been a renewed cybersecurity focus as foreign actors show their cards, so it is time that we do something impactful. The bottom line is we are running out of time before cybersecurity threats to our critical infrastructure result in an actual catastrophic attack. The time for action is now.
More on national cybersecurity strategy:
Ask the Expert: How has the FITARA law influenced U.S. cybersecurity?
After government breaches, Pentagon cybersecurity under fire
Secret Service audit reveals cybersecurity flaws
Read more:
Private sector's national cybersecurity strategy contributions lacking - TechTarget
- The Skanner Newspaper - Jailed Chelsea Manning Gets Intelligence Ethics Award [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Chelsea Manning | Thanksgiving Gratitude With Michelle ... [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Private Manning Support Network [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Chelsea Manning awarded 2014 Sam Adams Prize for Integrity ... [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Chelsea Manning - Wikipedia, the free encyclopedia [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Chelsea Manning We three Spies - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- » About PVT. Manning Private Manning Support Network [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- @CassandraRules - Fullerton City Council about Kelly Thomas - Video [Last Updated On: January 28th, 2014] [Originally Added On: January 28th, 2014]
- Report puts Snowden-like leaks as the No. 2 threat to U.S. security [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Germany: Poitras praises courage of whistleblowers - Video [Last Updated On: February 3rd, 2014] [Originally Added On: February 3rd, 2014]
- What not to say to a transgender person [Last Updated On: February 5th, 2014] [Originally Added On: February 5th, 2014]
- Chelsea Manning and the Law - Outside The Beltway [Last Updated On: February 5th, 2014] [Originally Added On: February 5th, 2014]
- UK spy agency launched cyber attack on hacktivist group Anonymous [Last Updated On: February 6th, 2014] [Originally Added On: February 6th, 2014]
- chelsea manning trio - there's trouble until - Video [Last Updated On: February 6th, 2014] [Originally Added On: February 6th, 2014]
- Pirates jointly nominate Manning and Snowden for Nobel ... [Last Updated On: February 7th, 2014] [Originally Added On: February 7th, 2014]
- Assange story: Media watchdog dismisses complaint against Four Corners [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- BRADLEY MANNING versus CHELSEA MANNING! | shootthescribe [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- Defending Chelsea Manning - Video [Last Updated On: February 18th, 2014] [Originally Added On: February 18th, 2014]
- Snowden Congratulates Chelsea Manning [Last Updated On: February 20th, 2014] [Originally Added On: February 20th, 2014]
- Snowden Pays Homage to Sam Adams Awardee Chelsea Manning | Oxford Union - Video [Last Updated On: February 20th, 2014] [Originally Added On: February 20th, 2014]
- Free Chelsea Manning! -- LGBT Wikileaker - Video [Last Updated On: February 20th, 2014] [Originally Added On: February 20th, 2014]
- Whistleblowers refuse to be hounded, form alliance [Last Updated On: February 22nd, 2014] [Originally Added On: February 22nd, 2014]
- Whistleblowers unite in London [Last Updated On: February 22nd, 2014] [Originally Added On: February 22nd, 2014]
- Snowden: Geheimhaltung, Kriege, Kriegsverbrechen, Folter - Chelsea Manning/Sam Adams Award - Video [Last Updated On: February 25th, 2014] [Originally Added On: February 25th, 2014]
- Snowden: Geheimhaltung, Kriegsverbrechen, Folter - Chelsea Manning/Sam Adams Award - Video [Last Updated On: February 25th, 2014] [Originally Added On: February 25th, 2014]
- News from Leavenworth: Chelsea Manning receives a family ... [Last Updated On: February 25th, 2014] [Originally Added On: February 25th, 2014]
- Chelsea Manning: US secrecy breeds unilateralism that ... [Last Updated On: February 25th, 2014] [Originally Added On: February 25th, 2014]
- US Press Freedom Ranking Fail - Video [Last Updated On: March 2nd, 2014] [Originally Added On: March 2nd, 2014]
- Nobel Shortlist: Putin, Snowden, Manning [Last Updated On: March 5th, 2014] [Originally Added On: March 5th, 2014]
- Putin Nominated for Nobel Peace Prize [Last Updated On: March 5th, 2014] [Originally Added On: March 5th, 2014]
- Drawing the Chelsea Manning Trial--Part 2 - Video [Last Updated On: March 9th, 2014] [Originally Added On: March 9th, 2014]
- Drawing the Chelsea Manning Trial--Part 1 - Video [Last Updated On: March 10th, 2014] [Originally Added On: March 10th, 2014]
- Pvt. Manning seeks formal name change to Chelsea - Quincy Herald-Whig | Illinois & Missouri News, Sports [Last Updated On: March 20th, 2014] [Originally Added On: March 20th, 2014]
- Chelsea Manning petitions for formal name change [Last Updated On: March 20th, 2014] [Originally Added On: March 20th, 2014]
- Manning seeks to change name to Chelsea [Last Updated On: March 20th, 2014] [Originally Added On: March 20th, 2014]
- Chelsea Manning Formally Requests Name Change [Last Updated On: March 20th, 2014] [Originally Added On: March 20th, 2014]
- Chelsea Manning Seeks Legal Name Change [Last Updated On: March 20th, 2014] [Originally Added On: March 20th, 2014]
- Chelsea Manning I m not a pacifist - Video [Last Updated On: March 20th, 2014] [Originally Added On: March 20th, 2014]
- Chelsea Manning Support Network [Last Updated On: March 22nd, 2014] [Originally Added On: March 22nd, 2014]
- » About Chelsea Manning Chelsea Manning Support Network [Last Updated On: March 22nd, 2014] [Originally Added On: March 22nd, 2014]
- Chelsea Manning petitions court for name change [Last Updated On: March 27th, 2014] [Originally Added On: March 27th, 2014]
- Chelsea Manning’s Attorney: She Didn’t Get a Fair Trial [Last Updated On: March 28th, 2014] [Originally Added On: March 28th, 2014]
- U.S. vs. Private Chelsea Manning: A Graphic Account from Inside the Courtroom - Video [Last Updated On: April 2nd, 2014] [Originally Added On: April 2nd, 2014]
- Chelsea Manning Sentence Harsher Than Others For Similar ... [Last Updated On: April 4th, 2014] [Originally Added On: April 4th, 2014]
- ABQ attorney to represent Chelsea Manning - Video [Last Updated On: April 4th, 2014] [Originally Added On: April 4th, 2014]
- CHELSEA MANNING TALKS ABOUT NINJUTSU? OH I MEAN THE OTHER GUY - Video [Last Updated On: April 6th, 2014] [Originally Added On: April 6th, 2014]
- San Francisco Pride Apologizes, Honors Chelsea Manning [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- Manning sentence approved by Washington military district commander [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- Army general denies Chelsea Manning clemency over WikiLeaks case [Last Updated On: April 15th, 2014] [Originally Added On: April 15th, 2014]
- Chelsea Manning's 35-year sentence, conviction upheld [Last Updated On: April 15th, 2014] [Originally Added On: April 15th, 2014]
- OurHD.Tv FDL 10@10 4/15/2014 - Video [Last Updated On: April 17th, 2014] [Originally Added On: April 17th, 2014]
- USA: Chelsea Manning's punishment 'outrageous' says attorney - Video [Last Updated On: April 17th, 2014] [Originally Added On: April 17th, 2014]
- Manning Determined to Fight Back After Army Upholds 35-Year Sentence - Video [Last Updated On: April 23rd, 2014] [Originally Added On: April 23rd, 2014]
- Defending Democracy: Government Whistleblowing in the Digital Age - Video [Last Updated On: April 23rd, 2014] [Originally Added On: April 23rd, 2014]
- Chelsea Manning allowed to legally change name from Bradley Manning [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- Chelsea Manning Allowed to Formally Change Name [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- Chelsea Manning gets name change [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- Kansas judge to consider Chelsea Manning's petition to legally change name from Bradley [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- Fox News Calls Chelsea Manning a 'Gender-Bender' [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Chelsea Manning Announces Legal Name Change in Optimistic Letter [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- Chelsea Manning Allowed to Formally Change Name - NBC News [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- 2014 05 02 Robin Hooding w/Chalk 5/10 - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- The FBI Was Never the Same: 1971 Screening and Discussion - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- Chelsea Manning - Video [Last Updated On: May 6th, 2014] [Originally Added On: May 6th, 2014]
- Exclusive Interview: NSA whistleblower on what he'd do differently now [Last Updated On: May 9th, 2014] [Originally Added On: May 9th, 2014]
- Speaking out - Deb Van Poolen - Video [Last Updated On: May 9th, 2014] [Originally Added On: May 9th, 2014]
- FREEDOM for CHELSEA MANNING! Solidarity music session, Dublin. - Video [Last Updated On: May 12th, 2014] [Originally Added On: May 12th, 2014]
- German hacker club offers Snowden, Manning honorary membership [Last Updated On: May 13th, 2014] [Originally Added On: May 13th, 2014]
- Pentagon reportedly trying to transfer Manning to civilian prison for gender treatment [Last Updated On: May 14th, 2014] [Originally Added On: May 14th, 2014]
- Pentagon OKs Chelsea Manning Transfer for Gender Treatment [Last Updated On: May 14th, 2014] [Originally Added On: May 14th, 2014]
- Chelsea Manning Could Be Getting a Transfer to Civilian Prison [Last Updated On: May 14th, 2014] [Originally Added On: May 14th, 2014]
- Leaker Chelsea Manning may get jail transfer for gender treatment [Last Updated On: May 14th, 2014] [Originally Added On: May 14th, 2014]
- Manning Could Move To Civilian Prison For Hormone Therapy [Last Updated On: May 14th, 2014] [Originally Added On: May 14th, 2014]
- Chelsea Manning might be moved to civilian prison [Last Updated On: May 14th, 2014] [Originally Added On: May 14th, 2014]
- Chelsea Manning transfer for gender treatment is backed by Pentagon [Last Updated On: May 15th, 2014] [Originally Added On: May 15th, 2014]
- Pentagon weighs sending Manning to civilian prison for gender treatment [Last Updated On: May 15th, 2014] [Originally Added On: May 15th, 2014]
- Chelsea Manning Could Be Moved To Civilian Prison - Video [Last Updated On: May 16th, 2014] [Originally Added On: May 16th, 2014]
- Chelsea Manning Biography - Video [Last Updated On: May 16th, 2014] [Originally Added On: May 16th, 2014]
- Pentagon May Grant Chelsea Manning's Request for Gender Transition - Video [Last Updated On: May 21st, 2014] [Originally Added On: May 21st, 2014]
- [383] Internet Freedom, Sociopathic Cop Executes Boston Bombing Associate, Manning Denied Safety - Video [Last Updated On: May 21st, 2014] [Originally Added On: May 21st, 2014]