Last week, ADM Mike Rogers—head of the NSA and U.S. Cyber Command—said cyber attacks attributed to China could shut down the US infrastructure. He went on to say one or two other countries could also achieve this level of disruption. Warning after warning has been issued with little action.
Rogers made these remarks while testifying before the House Intelligence Committee.
Internationally, there have been a few pieces of legislation that target technology suppliers for ‘security negligence.’ There are concerns about the rapidly rising threat and impact of successful cyber attacks, and that an increase in IT security budgets have not resulted. Some question if private sector security is keeping pace with advanced cyber threats.
One CISO at a critical infrastructure provider recently told me his cyber security budget was about 3 percent of the IT budget. Now in comparison, PWC reported that security spending as a percentage of the overall IT budget has remained about the same, 4 percent, for the past five years. To put that into context, one cyber security analysis unit disclosed there was a 48 percent increase in attacks last year. Could that critical infrastructure provider face criminal consequences – negligence – when they know the threat and their efforts do not even meet the average level of funding? God forbid if someone lost their life as a result of an outage – think about how that might play out in the courts. The Wall Street Journal recently reported that Wells Fargo spends roughly $250 million a year on cyber security and has increased staffing in the area by 50 percent. How many organizations do you know that are being proactive when it comes to cyber defense?
Warning after warning has been made and the situation continues to get worse. It is time for less talk and more action on the part of government and the private sector. We should take action before it is too late.




