![Chris Cummiskey [ID=20859201]](http://www.gannett-cdn.com/-mm-/bb9c441c9e17037375f63a738cedddac91ee9d40/r=297x400/local/-/media/2014/12/24/FederalTimes/FederalTimes/635550183344130337-Chris-Cummiskey.jpg)
Chris Cummiskey is a former acting under secretary for management and former chief acquisition officer at DHS.
It seems that every day we wake up to the news of yet another major cyber breach in industry or government.
One of the areas hardest hit in the last six months are the companies who handle the background investigations for individuals seeking employment and a security clearance with the federal government.
It is estimated that upwards of 75,000 individuals may have had their personally identifiable information (PII) compromised as part of these breaches. And as anyone who has filled out an SF86 knows, you are turning over the keys to the kingdom when you fill out those forms.
As someone who had to help come up with a plan for moving forward after these breaches were detected, I can tell you there are things we can do to make sure the government and vendors are better prepared for attacks from nation-states, criminal syndicates or others seeking to disrupt or gain financially.
While it is debatable as to whether or not companies like USIS or Keypoint had sufficient internal cybersecurity controls in place to mitigate the breaches, what’s clear is that most contracting vehicles are outdated and ill-suited for the cyber challenges of today.
To ensure better cyber hygiene and the use of best practices, departments like DHS are beginning the arduous process of updating contracts to include specific cyber requirements. Other departments in the federal government should follow their lead. This is not an easy process, but one that should involve the contracting/procurement shops as well as the CIO/CISO communities to get the best results.
One of the lessons of the USIS data breach, and others like it, is the fact that most of these contracts have been in place for years and just didn’t envision the kinds of scenarios we presently face from cyber criminals.
Groups like the Council on CyberSecurity, SANS and the Center for Internet Security are all promoting best practices in the use of critical controls and sound cyber hygiene that should be adopted by policy makers and operators alike.
We may not be able to stop these incidents from occurring, but by adopting better approaches to contracting and enhanced cyber hygiene we have a chance to minimize the damage.
Breaches should reignite push for better cyber hygeine




