Cyber times are changing and not for the better! In traditional warfare the United States has enjoyed top marks for capabilities for decades, but that is not the case when it comes to the cyber domain. Just consider all of the U.S. cyber assets (public and privately owned/operated), the level of protection ranges from barely protected to being extremely well fortified.That range needs to be severely narrowed.
James Clapper, the director of national intelligence testifying before the Senate Armed Services Committee said, “Rather than a ‘Cyber Armageddon’ scenario that debilitates the entire U.S. infrastructure, we envision something different. We foresee an ongoing series of low-to-moderate level cyber attacks from a variety of sources over time, which will impose cumulative costs on U.S. economic competitiveness and national security.” That message is loud and clear and we must listen to it and take action to address those risks.
One concept being floated to accomplish that critical task would require all producers of equipment/devices that connect to, are used by or attach to the Internet, to meet some minimal security standard. Those cries are getting louder after the Sony incident and the recent Lenovo Superfish adware revelations. This latest issue comes years after several spy agencies in the Unites States, UK and Australia were reported to have initiated a ban on Lenovo PCs due to backdoor vulnerabilities that allow cyber attackers to remotely access those computers.
When you realize the extremely low level investment needed to enter into the cyber weapons arms race, it is no wonder we are severely outnumbered when you consider that rogue nation-states, terrorists, criminals, extremists who all pose threats in cyber space. This time we had better not wait for something to happen that pushes us to take action!
To borrow a line from Nike – JUST DO IT!




