As hackers and other malicious actors become more sophisticated and agile in their attacks, federal agencies need to be proactive about cybersecurity.
“Don’t wait to be hunted,” Linus Barloon, IT security branch manager for the U.S. Senate Office of the Sergeant at Arms, told attendees at the Public Sector Cybersecurity Summit hosted by Raytheon | Websense on Dec. 1. “Start hunting,” he said.
“I can’t wait for threat data to tell me that three months ago I was hacked,” he said, speaking in the hypothetical. “Now we’re starting to operationalize cybersecurity. It’s not a sit-back/goal-line-defense game anymore. It’s more about getting out front and being offensive.”
While compliance with a checklist of security controls and best practices is useful, it shouldn’t be the entirety of an agency’s cybersecurity efforts, Barloon warned. Rather, cyber professionals should be concerned with identifying the gaps in their systems and procedures and actively working to prepare for the next attack vector.
Barloon compared this way of thinking to having a fire alarm and suppression system but never testing it to ensure everything works or running fire drills so everyone knows what to do in an emergency. The alarms might sound but if no one knows that means to leave the building, the safety of everyone inside is compromised.
Pen tests “are a perfect way for me to fly scenarios in the face of my security operations center,” Barloon said. “If my SOC can’t catch somebody I’ve paid to go after them, I don’t have a chance with anybody else.”
Similarly, cybersecurity shops should be running phishing stings on their own employees and provide regular training about proper cyber hygiene.
“How do I know what those gaps are and how do I test those gaps to understand that resilient approach?” he said. “Because when a senator wants to travel, when the staff wants to travel to pick-your-place across the globe, they need to go and ‘no’ isn’t going to be the answer.”




