As hackers and other malicious actors become more sophisticated and agile in their attacks, the governmentfederal agencies needs to be proactive about cybersecurity.
“Don’t wait to be hunted,” Linus Barloon, IT security branch manager for the U.S. Senate Office of the Sergeant at Arms, told attendees at the Public Sector Cybersecurity Summit hosted by Raytheon | Websense on Dec. 1. “Start hunting,” he said.
Barloon told agency CISOs and other security professionals they need to be on the offense, going beyond check-the-box compliance.
“I can’t wait for threat data to tell me that three months ago I was hacked,” he said, speaking in the hypothetical. “Now we’re starting to operationalize cybersecurity. It’s not a sit-back/goal-line-defense game anymore. It’s more about getting out front and being offensive.”
While compliance with a checklist of security controls and best practices is useful, it shouldn’t be the entirety of an agency’s cybersecurity efforts, Barloon warned. Rather, cyber professionals should be concerned with identifying the gaps in their systems and procedures and actively working to prepare for the next attack vector.
“There’s nothing wrong with check-the-box — the checklist is still needed to understand, ‘Do you have these programs in place.’ But there are other components that factor in,” he said. “If I’m checklist-oriented, I’m waiting for something bad to happen.”
Barloon compared this way of thinking to having a fire alarm and suppression system but never testing it to ensure everything works or running fire drills so everyone knows what to do in an emergency. The alarms might sound but if no one knows that means to leave the building, the safety of everyone inside is compromised.
One method for being proactive is hiring private contractors to run penetration tests (pen tests) on federal systems.
Pen tests “are a perfect way for me to fly scenarios in the face of my security operations center,” Barloon said. “If my SOC can’t catch somebody I’ve paid to go after them, I don’t have a chance with anybody else.”
Similarly, cybersecurity shops should be running phishing stings on their own employees and provide regular training about proper cyber hygiene.
This kind of training and testing mixed with implementation of the latest security tools is the only way to build a resilient system that can meet the mission no matter the threat, Barloon said.
“How do I know what those gaps are and how do I test those gaps to understand that resilient approach?” he said. “Because when a senator wants to travel, when the staff wants to travel to pick-your-place across the globe, they need to go and ‘no’ isn’t going to be the answer.”
FREE WEBCAST DEC. 10: Satcom for secure voice, video and data on the battlefield with Army WIN-T’s LTC Mark Henderson.




