There is allot of Of the many things you can say about the cyber domain, but saying it’s “static” is not one of them. As always, things are changing when it comes to cyber. Once again cyber threats dramatically increased this year and are expected to soar in 2016. One of the unique aspects of the changes in this domain is that there is no agreement whether the developments changes are for the good or bad. Two of the more recent changes that havehas created a great divide on the good versus bad discussion are the passage of the cybersecurity bill and the elevation of the cyber risks to the board level.
Congressional passage of cybersecurity bill – In case you missed it, the Cybersecurity Information Sharing Act, known as CISA, it was hidden within the on the $1.1 trillion spending package that Congress passed in December was passed on December 18th. Some have commented that it is better than nothing, . That is hardly a ringing endorsement. Wwhile others feel it is a well-struck balance between the nation’s need for cyber intelligence and defense, and privacy. One recent posting referred to the bill as the worst anti-privacy bill since the PATRIOT Act was signed into law on Oct.ober 26, 2001 by President George W. Bush. Perhaps the best comment about the bill’s passage was cast in the context of Star Wars. At a conference one individual artfully asked, “When will the force awaken?” Talk about politically correct: – yYou can take that comment as pro or con when looking at the passage of the cybersecurity bill. Clearly, that individual has a bright future in politics.
Cyber Security Biggest Board Issue – In a recent online poll conducted by a management consulting firm, 42 percent of those that responded stated that in 2016 cyber security was the top issue for the Board of Directors.Cybersecurity will also be a top priority for boards of directors, according to 42 percent of respondents to a recent online poll conducted by a management consulting firm. The cyber threat environment continues to grow virtually uncontrolled. As I previously discussed, corporate losses are mounting due to theft of sensitive, confidential and proprietary information. Two recent court rulings have laid the foundation to increase the overall costs to many companies. One allows banks and credit card companies to recover costs from the source of a data breaches. The second allows individuals who that had their data stolen to get compensation for all the work they do to protect themselves from identity theft or for in their efforts to clean up their identity and finances after their identity has been stolen.
As always, anything to do with the legal aspects of cyber is highly controversial, and both of these topics certainly fit that category for sure. What has become so interesting is the amount of legal interaction that senior level cybersecurity professionals are experiencing. One has to wonder, what we will see next in the legal aspects of cyber. As it stands with compliance requirements, new legal aspects associated with data breaches and privacy laws has gotten to the point where a fair portion of the chief information security officer’s (CISO) time is spent addressing these complex regulatory and legal demands. A fair portion of a chief information security officer’s time is spent addressing data breach and privacy law compliance requirements. One individual recently commented that these aspects have gotten so bad that the CISO now needs to have a law degree. We wouldn’t put the commanding general involved in a heated battle in this place, so why are we putting the CISO?
Somehow we need to find a way to reduce the demands on the CISO’s time due to legal and regulatory demands. When I addressed this issue, one CISO said, “Yeah, good luck – Good Luck,” but Obviously he does not hold much hope of that happening. Wwhat he followed up with shocked me. He said in many cyber-related instances in-house legal staff are not equipped to handle these complex regulatory/legal issues. They have to go outside the firm and seek outside specialists in this aspect of the legal and regulatory environments.
Now consider this issue in the military and intelligence environment: It is far more complicated and time-consuming for those on the cyber front lines and the decision-makers who that support them. With things moving as fast as they do when a cyberattack occurs, this is unacceptable. Just think about how much more damage that could be done during when a 5-minute delay occurs. So wWe are impeded from rapid response. Our adversaries are not impaired in this way.




