
A dearth of advocacy
In my experience working for the
US G
government, I had many opportunities to evaluate agencies’ counterintelligence and insider threat programs. I also created, in partnership with other very talented and dedicated individuals, one of the most successful insider threat programs at a major U.S. agency.
Our success came after observing many failed or ineffective programs. The problems I experienced firsthand across the government usually included a failure of political appointees and their senior staff members to advocate for the programs. This lack of advocacy severely hampered the efforts of the professionals who were working to protect valuable information assets from theft and misuse.
“It’s not that hard”
Leadership responses like “this should not be a heavy lift,” “do less work,” or “you are blowing this out of proportion” were commonplace. They were all laughable if you knew the number of insider threats and successful attacks these agencies faced.
The professional staff, in turn, would invariably roll their eyes, chuckle, and complain about how appointees and senior staff ignored or scoffed at the problem. It became a sort of gallows humor for the staff that underscored a serious problem that was easy, in theory, to correct.
Even more humorous was the fact that these appointees and senior staff members didn’t want the professionals presenting to the heads of the agencies. They reserved that very visible and important work for themselves.
Here’s where the comedy turns dark. It was obvious that most senior staff did not take the time to listen to what the professionals were trying to tell them. They did not understand the importance of countering the threats so their interpretations of what was actually happening were wildly unrealistic. Perhaps they felt the reality of the problems they were facing might dampen their careers or advancement potential and the only option was to discount the significance of the threat.
Every time I observed this phenomenon, I would always think of two classic comedy routines. (If you haven’t seen these before, check them out — you’ll understand what I’m talking about more and get a good laugh in the process.) One routine is “What It Was, Was Football” by Andy Griffith and the other is the classic Abbott and Costello routine “Who’s On First.”
In each of these routines, the masters of comedy showcase how inexperience, naiveté
,
and ignorance can have a disastrous effect when a neophyte attempts to describe something totally outside their experience. They are true artists in describing a bumbling caricature. However, I believe these routines serve a purpose for our discussion. They underscore the direction that agency heads and senior executives
should not
follow when dealing with insider and cybersecurity threats.
Give your professionals — and your program — a chance
If you preside over insider threat or cybersecurity for your agency, the first thing you can do is wake up to the current threat environment. You are entrusted to protect critical value data from those who wish to exploit, steal
,
or extort it. The threats are real. You are the gatekeepers and without your advocacy, you and your agency will be exploited. It’s just a question of when.
Second, listen to your skilled professionals. Listen to those who are informed about current threats, the best methods to protect your organization, and the data you need to protect. You listen when a licensed mechanic tells you what’s wrong with your car — do the same with your security professionals when they talk about what’s wrong with your network and data protections.
Third, learn to trust. Trust in your team. Trust that they are there to protect you and the agency from threats. Let them speak to the agency’s leadership. Only an expert who is used to answering questions about the process, problems
,
and threat can deliver a clear message.
Last, advocate for the program. Advocacy means more than merely giving a nod or politely holding meetings with your team. Openly state your position of support to the entire agency and staff. Give your team the resources and time necessary to fulfill their work. Above all else, don’t shoot the messenger. Attacks are going to happen — to counter them, we must all work as a team.
Real protection requires you to understand that you are countering a real, not imaginary, threat. It also means trusting and leading. Don’t be seen as a caricature of a comedic bumbling bureaucrat.
In other words, advocate!
Keith Lowry is Nuix’s senior vice president for business threat intelligence and analysis. He served as chief of staff to the deputy undersecretary of Defense for human intelligence, counterintelligence and security at the Pentagon, and as an information security consultant in the private sector.




