<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet media="screen" type="text/xsl" href="https://one.sightlinemg.com/federaltimes/wp-content/themes/smg/assets/xslt/rss-xslt.xml"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
xmlns:news="http://www.pugpig.com/news"
>

<channel>
	<title>Federal Times - Federal Times</title>
	<atom:link href="https://one.sightlinemg.com/federaltimes/opinion/feed/" rel="self" type="application/rss+xml" />
	<link>https://one.sightlinemg.com/federaltimes/</link>
	<description>Federal Times</description>
	<lastBuildDate>Sat, 08 Aug 2026 18:31:03 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://one.sightlinemg.com/wp-content/uploads/2026/06/favicon-fed.png?w=32</url>
	<title>Federal Times - Federal Times</title>
	<link>https://one.sightlinemg.com/federaltimes/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">255331619</site><atom:link rel="next" type="application/rss+xml" href="https://one.sightlinemg.com/federaltimes/feed/?paged=2" />
	<item>
		<title>How to improve cyber training for critical infrastructure employees</title>
		<link>https://one.sightlinemg.com/federaltimes/home/2019/11/01/how-to-improve-cyber-training-for-critical-infrastructure-employees/</link>
					<comments>https://one.sightlinemg.com/federaltimes/home/2019/11/01/how-to-improve-cyber-training-for-critical-infrastructure-employees/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Fri, 01 Nov 2019 21:10:31 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Newsletters]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2019/11/01/how-to-improve-cyber-training-for-critical-infrastructure-employees/</guid>

					<description><![CDATA[Critical infrastructure organizations can no longer go through the motions of cybersecurity awareness training thinking their technology and security teams are enough to maintain control.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/home/2019/11/01/how-to-improve-cyber-training-for-critical-infrastructure-employees/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">28391</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/636038373369539633-052410ft-powerlines2jpg.jpg" width="3000" height="2000" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">A brief scan of the news reaffirms that cyberattacks targeting critical infrastructure organizations are on the rise. </p>



<p class="wp-block-paragraph">Daily headlines highlight the latest ransomware attacks, data breaches and new phishing techniques, bringing to light an epidemic that has resulted in financial, operational and reputational damage for businesses, governments and the general public alike.</p>



<p class="wp-block-paragraph">Today, cyberattacks put a lot more than just our personal data at risk – threat actors have increased the regularity at which they target the infrastructure that supports mission critical systems, such as power grids, water utilities, healthcare systems, nuclear facilities and emergency services.</p>



<p class="wp-block-paragraph">A report from the<a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Flookbook.tenable.com%2Fponemonotreport%2Fponemon-OT-report&#038;data=02%7C01%7Cmgruss%40mco.com%7Cb4ecaf98817b4e5bf01d08d75f065a2a%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C0%7C637082353229364659&#038;sdata=%2BOlAnB7p%2FEPYwoUDAdwxI30HV24RBR81pQdGjuX75y0%3D&#038;reserved=0"> Ponemon Institute</a> revealed a steady rise in cyberattacks against critical infrastructure, stating that “Nation-state attacks are especially concerning in the [original technology] sector because they’re typically conducted by well-funded, highly capable cyber criminals and are aimed at critical infrastructure.”</p>



<p class="wp-block-paragraph">These critical infrastructure sectors – of which there are 16 – ultimately impact how our daily lives function and when attacked could have lasting global effects.</p>



<p class="wp-block-paragraph">Just last month E&amp;E News reported on the<a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.eenews.net%2Fstories%2F1061111289&#038;data=02%7C01%7Cmgruss%40mco.com%7Cb4ecaf98817b4e5bf01d08d75f065a2a%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C0%7C637082353229374652&#038;sdata=X7VLlhMUobrQdKWSnyFY3vU%2B1gtHHnEMmFynbuWLv%2BA%3D&#038;reserved=0"> first cyberattack on the U.S. power grid</a> as identified by the North American Electric Reliability Corp (NERC). While nation state reconnaissance has occurred for years, this attack is unique in that it is the first to facilitate “minor impact.” In contrast, other critical infrastructure sectors like healthcare and financial services have suffered the consequences of cyberattacks for over a decade, as personally identifiable information regularly sought can rake in millions on the Dark Web in addition to the many benefits associated with intellectual property theft.</p>



<p class="wp-block-paragraph"><b>Critical infrastructure cybersecurity training today</b></p>



<p class="wp-block-paragraph">As mentioned, cybersecurity is not unknown to critical infrastructure sectors. In response to the integration of information technology systems with operational technology systems and the emergence of the industrial internet of things, an increased focus on risk mitigation and industry and federal regulatory compliance emerged. At the same time, a new challenge came to light &#8211; there simply aren’t enough cybersecurity workers to fill the number of open jobs.</p>



<p class="wp-block-paragraph">To limit risk, most critical infrastructure organizations provide some level of security awareness training company-wide, but it’s often limited to very basic information, such as how to identify and report a phishing email. Advanced training is not typically given to ordinary workers, and many critical infrastructure stakeholders are never properly briefed on how to handle suspected cyber threats.</p>



<p class="wp-block-paragraph">This is a serious problem in today’s connected world where vulnerabilities and cyberattacks can come from anywhere at any time including a remote worker, a contractor, a device or even technology that appears on its surface to be begin, like a smart thermostat.</p>



<p class="wp-block-paragraph">To put it into perspective, most of today’s CI organizations remotely monitor the status and location of trains, buses and trucks; they can adjust the flow of crude oil and natural gas through pipelines remotely; water and electricity consumption can be monitored and changed from a centralized location and medical devices can be monitored from half a world away. These conveniences cut costs, increase efficiency and overall make our lives easier – but as the number of interconnected systems continues to rise, so does the attack surface. As a result, more employees across a CI ecosystem are a threat, whether they know it or not.</p>



<p class="wp-block-paragraph"><b>Training needs to go beyond phishing</b></p>



<p class="wp-block-paragraph">Critical infrastructure organizations can no longer go through the motions of cybersecurity awareness training thinking their technology and security teams are enough to maintain control. Instead, all employees must begin to understand that any interaction with technology can play a role in a cyberattack. This represents a change to both culture and strategy &#8211; which is never easy to deploy despite its necessity.</p>



<p class="wp-block-paragraph">Ultimately, CI organizations must begin to teach every employee and stakeholder that every person – no matter their role – plays an important part in protecting mission critical infrastructure. And not just with scare tactics, but with the knowledge and understanding of how cyberattacks operate and how to handle them.</p>



<p class="wp-block-paragraph">Leaders should consider some of the following steps:</p>



<ul class="wp-block-list"><li>Prioritize practical, hands-on CIP cybersecurity workforce training rather than just relying on theories and concepts that are difficult to visualize.</li><li>Set up the right incentives, performance management, training, processes, procedures and other systems to ingrain the mindset and cultural changes needed.</li><li>Train OT professionals in technologies and processes that are valuable to making CI stronger and more resilient.&nbsp;</li><li>Lead by example – have all managers and leaders in CI take in-depth CIP cybersecurity training courses to become knowledgeable in cybersecurity for CI and to understand how to communicate that information to everyone involved.&nbsp;</li></ul>



<p class="wp-block-paragraph">Protecting critical infrastructure against cyberattacks is a two-part problem. We must put in place better protections, more advanced security protocols and better incident response plans, but that starts with better cybersecurity knowledge across the entire CI workforce. Ultimately, we need to change the way everyone in the CI ecosystem thinks about cybersecurity. The success of critical infrastructure protection relies on the steps taken by the workforce to mitigate risks – and that starts with the knowledge and understanding of the nuances that make up CIP cybersecurity. In today’s world, you cannot afford to not train every CIP stakeholder in cybersecurity. </p>



<p class="wp-block-paragraph"><i>Dan Lanir is vice president of customer success at OPSWAT, a San Francisco based software company. </i></p>
]]></content:encoded>
	</item>
		<item>
		<title>As Russians hack the US grid, a look at what’s needed to protect it</title>
		<link>https://one.sightlinemg.com/federaltimes/home/2018/08/08/as-russians-hack-the-us-grid-a-look-at-whats-needed-to-protect-it/</link>
					<comments>https://one.sightlinemg.com/federaltimes/home/2018/08/08/as-russians-hack-the-us-grid-a-look-at-whats-needed-to-protect-it/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Wed, 08 Aug 2018 16:12:03 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Newsletters]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2018/08/08/as-russians-hack-the-us-grid-a-look-at-whats-needed-to-protect-it/</guid>

					<description><![CDATA[The U.S. electricity grid is hard to defend because of its enormous size and heavy dependency on digital communication and computerized control software. The number of potential targets is growing as “internet of things” devices, such as smart meters, solar arrays and household batteries, connect to smart grid systems.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/home/2018/08/08/as-russians-hack-the-us-grid-a-look-at-whats-needed-to-protect-it/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">11581</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/AP_060927050025.jpg.jpg" width="1200" height="628" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph"><i>The Conversation is an independent and nonprofit source of news, analysis and commentary from academic experts.</i></p>



<p class="wp-block-paragraph">The U.S. electricity grid is hard to defend because of its enormous size and heavy dependency on digital communication and computerized control software. The number of potential targets is growing as “internet of things” devices, such as smart meters, solar arrays and household batteries, connect to smart grid systems.</p>



<p class="wp-block-paragraph">As <a href="https://scholar.google.com/citations?user=nGBlVWwAAAAJ&#038;hl=en">researchers of</a><a href="https://scholar.google.com/citations?user=vkOTo_EAAAAJ&#038;hl=en">grid security</a>, we believe that current security standards mandated by federal regulations provide sufficient protection against observed threats. But recent incidents demonstrate the ongoing challenge of ensuring everyone follows the guidelines, which themselves must change over time to keep up with technological shifts.</p>


	<aside class="smg-interstitial-link wp-block-smg-interstitial-link">
		<a href="https://one.sightlinemg.com/c4isrnet/cyber/2018/08/07/hackers-targeted-a-fake-power-grid-is-the-real-one-next/" class="smg-interstitial-link__inner">
							<div class="smg-interstitial-link__media">
					<img decoding="async" width="300" height="200" src="https://one.sightlinemg.com/wp-content/uploads/2026/08/electric-grid.jpg.jpg?w=300" class="smg-interstitial-link__image wp-post-image" alt="" />				</div>
						<div class="smg-interstitial-link__content">
				<span class="smg-interstitial-link__kicker">Related</span>
				<h3 class="smg-interstitial-link__title">Hackers targeted a fake power grid. Is the real one next?</h3>
									<p class="smg-interstitial-link__excerpt">A honey pot experiment showed how suspected criminals may try to hack into America&#039;s electric grid.</p>
							</div>
		</a>
	</aside>
	


<p class="wp-block-paragraph">The threat is real: In late 2015 and again in 2016, Russian hackers <a href="https://theconversation.com/cybersecurity-of-the-power-grid-a-growing-challenge-73102">shut down parts of Ukraine’s power grid</a>. In March 2018, federal officials warned that Russians had <a href="https://www.us-cert.gov/ncas/alerts/TA18-074A">penetrated the computers of multiple U.S. electric utilities</a> and were able to gain access to critical control systems. Four months later, the Wall Street Journal reported that the hackers’ access had included <a href="https://www.wsj.com/articles/russian-hackers-reach-u-s-utility-control-rooms-homeland-security-officials-say-1532388110">privileges that were sufficient to cause power outages</a>.</p>



<p class="wp-block-paragraph">Specific technical details have not yet been made public, so it’s hard to know exactly what the hackers did or gained access to. What has been revealed is that these breaches were accomplished with common hacking techniques, such as sending <a href="https://arstechnica.com/information-technology/2017/07/dhs-fbi-warn-of-attempts-to-hack-nuclear-plants/">spearphishing emails to specific employees</a>. Apparently, and reassuringly, the U.S. attacks didn’t involve <a href="https://dragos.com/blog/crashoverride/CrashOverride-01.pdf">more advanced techniques seen in the Ukraine incidents</a>, including <a href="https://www.wired.com/2011/07/how-digital-detectives-deciphered-stuxnet/">custom-made software to target specific systems</a>.</p>



<p class="wp-block-paragraph">In addition, human errors will inevitably lead to mistakes that will weaken the security of some of the thousands of digital devices needed to protect the grid. And more sophisticated attackers may still find and exploit currently unknown vulnerabilities. Therefore, it’s important for electric utilities, grid operators and vendors to remain vigilant and deploy multiple layers of defense.</p>


	<aside class="smg-interstitial-link wp-block-smg-interstitial-link">
		<a href="https://one.sightlinemg.com/militarytimes/news/your-military/2018/08/07/mattis-says-russia-sanctioned-2016-election-meddling-outlines-protections-for-midterms/" class="smg-interstitial-link__inner">
							<div class="smg-interstitial-link__media">
					<img loading="lazy" decoding="async" width="300" height="157" src="https://one.sightlinemg.com/wp-content/uploads/2026/08/43911874851_4fc7916555_k.jpg.jpg?w=300" class="smg-interstitial-link__image wp-post-image" alt="" />				</div>
						<div class="smg-interstitial-link__content">
				<span class="smg-interstitial-link__kicker">Related</span>
				<h3 class="smg-interstitial-link__title">Mattis says Russia sanctioned 2016 election meddling, outlines protections for midterms</h3>
									<p class="smg-interstitial-link__excerpt">Mattis said troops have a part in defending the Constitution and US elections.</p>
							</div>
		</a>
	</aside>
	


<p class="wp-block-paragraph"><i>Major players have some protections</i></p>



<p class="wp-block-paragraph">There are two main aspects to grid architecture that need defending in different ways. The first element is the bulk power system, often referred to as the “transmission grid.” It connects high-capacity power plants, transmission wires and substations that collectively generate and transport huge quantities of electricity over hundreds or thousands of miles. The rest of the grid is made up of smaller distribution grids – connected with the bulk power system – delivering electricity to homes and businesses around the country. The strongest standards for protection apply only to the bulk power system; though many distribution systems follow the same guidelines, they remain optional.</p>



<p class="wp-block-paragraph">U.S. federal rules, as well as those set by the agency that governs the North American grid – which also includes large parts of Canada – require companies operating elements of the bulk power system to follow <a href="https://www.nerc.com/pa/Stand/Pages/CIPStandards.aspx">certain basic cybersecurity measures</a>, including monitoring their networks to detect intrusions and mandating <a href="https://theconversation.com/the-age-of-hacking-brings-a-return-to-the-physical-key-73094">two-factor authentication for user logins</a>.</p>



<p class="wp-block-paragraph">Many large utilities do even more, <a href="https://www.nist.gov/cyberframework">assessing their risks in standardized ways</a> and <a href="https://www.nerc.com/pa/CI/CIPOutreach/GridEX/GridEx%20IV%20Public%20Lessons%20Learned%20Report.pdf">practicing responses to computer intrusions</a>. These exercises often include hundreds of companies and organizations rehearsing how to collaborate to detect and confine attacks and restore service to customers.</p>



<p class="wp-block-paragraph"><i>Smaller companies are more vulnerable</i></p>



<p class="wp-block-paragraph">Because transmission grid utilities should already have some protections against network intrusions, it is likely that the Russian hackers looked elsewhere, infiltrating smaller distribution utilities. If that’s so, any potential power shutdown or other problems in those systems would be confined to smaller areas – like towns or cities. That, in turn, means fewer customers would be affected, with less work needed to get power back on.</p>



<p class="wp-block-paragraph">But it highlights a worrying reality: Smaller and midsized companies that operate electricity distribution systems often have inadequate resources to invest in full cybersecurity protections. The <a href="https://www.energy.gov/sites/prod/files/2015/12/f28/united-states-electricity-industry-primer.pdf">more than 3,000 utilities in the U.S.</a> have trouble finding sufficiently skilled workers who understand how the computerized and physical components of the grid work together and how to protect them.</p>



<p class="wp-block-paragraph">In addition, utilities rely on complex supply chains to provide equipment, software, maintenance and other business functions. These external contractors and vendors may not implement protections as rigorous as the utilities. And their computer systems often have connections to the utilities’ networks, which may be considered trusted and safe, rather than potential avenues of attack.</p>



<p class="wp-block-paragraph"><i>Stepping up defenses</i></p>



<p class="wp-block-paragraph">Fixing all these potential problems is complex. First, all utility companies – even the smallest – should adopt <a href="https://www.nerc.com/pa/Stand/Pages/CIPStandards.aspx">basic security protections</a> like those required of large utilities. <a href="https://www.forbes.com/sites/constancedouris/2018/01/16/as-cyber-threats-to-the-electric-grid-rise-utilities-regulators-seek-solutions/">Some states</a> are moving to require this of the power companies serving their residents, but many aren’t yet. Further, we recommend all companies that are part of the grid participate in coordinated grid exercises to improve cybersecurity preparedness and share best practices.</p>



<p class="wp-block-paragraph">In addition, all utility companies need to take steps to ensure the hardware and software they use are <a href="https://www.nerc.com/pa/Stand/CIP0103RD/Implementation_Plan_Clean_071117.pdf">from trustworthy sources</a> and <a href="https://ics-cert.us-cert.gov/advisories/ICSA-14-178-01">have not been tampered with or modified</a> to allow unauthorized users in.</p>



<p class="wp-block-paragraph">It won’t be enough to protect against today’s threats. Adversaries are likely to employ increasingly sophisticated techniques that exploit both computer and human vulnerabilities. Companies need to ensure they engage in what might be called sustainable cybersecurity – ongoing processes that let systems and staff adapt over time, to stay ahead of the threats.</p>



<p class="wp-block-paragraph">Researchers have an important role too, exploring ways that emerging technologies like cloud computing, blockchain and big-data analytics could help reduce risks without introducing any additional weaknesses. Further, researchers should identify more advanced ways to secure the grid, and reduce these systems’ complexity, which would limit both current risks and future unknowns.</p>



<p class="wp-block-paragraph"><i>This article was originally published on The Conversation. Read the original article here: </i><a href="http://theconversation.com/as-russians-hack-the-us-grid-a-look-at-whats-needed-to-protect-it-100489"><i>http://theconversation.com/as-russians-hack-the-us-grid-a-look-at-whats-needed-to-protect-it-100489</i></a><i>.</i></p>
]]></content:encoded>
	</item>
		<item>
		<title>How attackers used human error to hack the power grid [Commentary]</title>
		<link>https://one.sightlinemg.com/federaltimes/newsletters/2017/09/07/how-attackers-used-human-error-to-hack-the-power-grid-commentary/</link>
					<comments>https://one.sightlinemg.com/federaltimes/newsletters/2017/09/07/how-attackers-used-human-error-to-hack-the-power-grid-commentary/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Thu, 07 Sep 2017 19:31:42 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Newsletters]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2017/09/07/how-attackers-used-human-error-to-hack-the-power-grid-commentary/</guid>

					<description><![CDATA[A report that says hackers may now be able to shut down power grids in the United States, Turkey and Switzerland shows how easily human error can put critical computer networks at risk, security experts said.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/newsletters/2017/09/07/how-attackers-used-human-error-to-hack-the-power-grid-commentary/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">23898</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/cyber_image.jpg.jpg" width="694" height="463" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">The cybersecurity company <a href="https://www.symantec.com/connect/blogs/dragonfly-western-energy-sector-targeted-sophisticated-attack-group">Symantec reported</a> the attackers spent two years infiltrating, mapping out and possibly gaining control over power company systems, through a variety of techniques designed to trick people into activating malicious software.</p>



<p class="wp-block-paragraph">The methods exploited what cybersecurity experts call the <a href="https://www.forcepoint.com/solutions/need/insider-threat-data-protection">“insider threat,”</a> a term for the various ways authorized users can let an attacker inside a network, either by mistake or malice.</p>



<p class="wp-block-paragraph">“They’re basically playing on things that influence the weakest link inside your enterprise – people,” said Josh Douglas, chief strategy officer for Raytheon Cyber Services. “Their desires and their will their social interaction, their reading habits, etcetera. The behavioral aspects of employees are a direct link to the weakness of the security of an organization.”</p>



<p class="wp-block-paragraph">The methods were common and well-documented, suggesting the attackers focused less on technological sophistication and more on knowing what energy company employees were likely to do – a hacking principle known as “social engineering.”</p>



<p class="wp-block-paragraph">For example, Symantec reported, the attackers:</p>



<ul class="wp-block-list"><li>Disguised malware as an invitation to a New Year&#8217;s Eve party – a method known as &#8220;spearphishing,&#8221; then followed up with messages containing &#8220;very specific content related to the energy sector;&#8221;</li><li>Planted malware on websites frequented by utility employees, a technique known as a &#8220;watering hole&#8221; attack;<br></li><li>Hid malware inside what appeared to be a legitimate software update, or &#8220;Trojanization.&#8221;<br></li></ul>



<p class="wp-block-paragraph">Symantec attributed the attack to a group known as Dragonfly 2.0, the same party responsible for a cyber-spying operation on energy companies uncovered in 2014. It did not speculate on the group’s origins, but did call it “an accomplished attack group” and said it used one piece of what appeared to be custom-built malware.</p>



<p class="wp-block-paragraph">Just as the attackers used human behavior to build their offensive, companies can use it to design their defense, said Richard Ford, chief scientist for Forcepoint, a commercial cybersecurity company jointly owned by Raytheon.</p>



<p class="wp-block-paragraph">For example, he said, the company found that while people going to a website commonly click out of pop-up security warnings, they respond better to an intermediary webpage that tells them clicking through might be a bad idea.</p>



<p class="wp-block-paragraph">“By changing the context of the interaction, the overall click-through rate was dramatically lowered,” he said.</p>



<p class="wp-block-paragraph">The trick, Ford said, is “to steer people, as opposed to direct them,” and close the same types of security gaps the power-grid hackers exploited.</p>



<p class="wp-block-paragraph">“People are great. We’re awesome. And we’re also very focused on what we’re doing, and we don’t think about the consequences for that,” Ford said. “There’s no patch for people. At least, if there is, I’m not sure I want to install it.”</p>



<p class="wp-block-paragraph"><i>Josh Douglas is the chief strategy officer for Raytheon’s cyber services business. Richard Ford is the chief scientist for Forcepoint, a commercial cybersecurity company jointly owned by Raytheon.</i></p>
]]></content:encoded>
	</item>
		<item>
		<title>Putting the problem first: 3 lessons from Georgetown Hacking for Defense course [Commentary]</title>
		<link>https://one.sightlinemg.com/federaltimes/newsletters/2017/07/24/putting-the-problem-first-3-lessons-from-georgetown-hacking-for-defense-course-commentary/</link>
					<comments>https://one.sightlinemg.com/federaltimes/newsletters/2017/07/24/putting-the-problem-first-3-lessons-from-georgetown-hacking-for-defense-course-commentary/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Mon, 24 Jul 2017 16:58:21 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Newsletters]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2017/07/24/putting-the-problem-first-3-lessons-from-georgetown-hacking-for-defense-course-commentary/</guid>

					<description><![CDATA[School is out, and at most universities that means final exams have given way to fun and sun. While the semester wrap-up at Georgetown University had its share of parties, students in Washington’s first-ever Hacking for Defense course prepared for perhaps their biggest challenge yet: reshaping the American military.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/newsletters/2017/07/24/putting-the-problem-first-3-lessons-from-georgetown-hacking-for-defense-course-commentary/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">31903</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635749142231757220-000-par7505649jpg.jpg" width="1500" height="1000" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">School is out, and at most universities that means final exams have given way to fun and sun. While the semester wrap-up at Georgetown University had its share of parties, students in Washington’s <a href="http://www.hacking4defensegu.com/">first-ever Hacking for Defense course</a> prepared for perhaps their biggest challenge yet: reshaping the American military. As entrepreneur and Stanford University professor Steve Blank, the founder of the Hacking for Defense initiative, wrote on his blog introducing the movement: <a href="https://steveblank.com/2016/01/26/hacking-for-defense-stanford/">“We will not lose because we had the wrong technology.&nbsp;We will lose because we couldn’t adopt, adapt and deploy technology&nbsp;<i>at speed and in sufficient quantities</i>&nbsp;to overcome our enemies.”</a></p>



<p class="wp-block-paragraph">Accepting that mission, these resourceful undergraduates spent 10 weeks painstakingly working to intimately understand and respond to the U.S. government’s toughest national security challenges. Using Silicon Valley innovation methods based on the premise that true innovation comes from grasping a customer’s problem better than they do, the students iterated threat-busting artificial intelligence algorithms, hunter drones, and augmented reality glasses, among other products.</p>



<p class="wp-block-paragraph">Merging lessons learned from leading technology engineers, entrepreneurs, executives and investors, the Hacking for Defense movement is gaining momentum on campuses nationwide amid a growing recognition that status quo defense acquisitions are increasingly being outpaced by new national security challenges. After kicking off last year at Stanford University, the class has now expanded to seven universities. With support from the Defense Department’s MD5 tech accelerator, the Georgetown students applied Silicon Valley-style lean startup methods to acute (and unclassified) national security challenges put forth by government agencies keen for a fresh perspective. The problem statements and results aren’t academic exercises; these are real-world problems. As course mentors, we expected students to develop actual prototypes for “minimum viable products” (or MVPs as they’re often called) over the 16-week class. Think of it as show-and-tell from a future battlefield, all broadcast live on social media.</p>



<p class="wp-block-paragraph">Each “product” is more than the sum of its parts. It starts with government sponsors pitching students on their problems. The students then conduct hundreds of sponsor and expert interviews, countless product iterations, and many late nights. Just like a real-world startup would, students received “relentlessly direct” feedback from their instructors and “customers” (problem sponsors) and “investors” (instructors). This forged their approach into an entrepreneurial mindset. Survival depended on real-time technological and business-plan adaptation as well as acceptance of failures along the way. Along with other mentors from across the national security community, our role was to give advice and otherwise support students along the way. This could mean helping to structure problems, understand market developments, and identify potential partners.</p>



<p class="wp-block-paragraph">What the four student teams ultimately produced was impressive. For example, working a problem posed by the Army’s Asymmetric Warfare Group (AWG), Team Spyglass developed an AI algorithm that in real-time identifies threats – including images – posted on social media. To their credit, the students recognized that identifying the threats alone wasn’t enough. They then created a messaging service that within seconds notifies relevant military users that a threat exists.</p>



<p class="wp-block-paragraph">The Hacking for Defense approach is about more than technology, something that can be overlooked given its Silicon Valley origins. The students discovered that what truly mattered was solving the right problems. While AWG originally asked for a way to monitor broad trends on social media that could indicate unrest, after several dozen interviews the team had its a-ha moment. They realized the Army’s real problem was actually protecting individuals and units from being photographed and geotagged for potential ambushes or flash-mob style attacks. With that revelation, Team Spyglass rapidly adapted its approach.</p>



<p class="wp-block-paragraph">This type of ongoing discovery is essential to Hacking for Defense. And it applies to more than students.</p>



<p class="wp-block-paragraph">The broad lessons are applicable to pretty much anyone in the public and private defense sector, from executive-level leadership to strategic planning groups and technology development organizations. For DoD, one of the most important benefits is a process that hones in on placing innovation where it matters most: in the hands of warfighters. From a defense industry perspective, we believe these approaches can help large corporations stay nimble and truly understand a customer’s often unspoken priorities.</p>



<p class="wp-block-paragraph">Consider these takeaways from the course:</p>



<p class="wp-block-paragraph">1.&nbsp;<b><i>Start with the mission problem</i>.</b> It’s not uncommon for us to see people build technology solutions first and then try to figure out mission applications.&nbsp; A more effective approach is to invest in deeply understanding the operator (or customer) and the mission problems these people face. Only then does it make sense to develop a technology solution that addresses their needs. Even better, identify the problems they didn’t even know existed. Deeply understanding mission problems, however, is not a casual endeavor. Follow the lead of Hacking for Defense students: conduct scores of interviews and collect in-depth data about technology beneficiaries and partners. Then integrate this ongoing, detailed discovery into development planning. When mission challenges are clearly understood, it’s far more likely the solutions created will be the correct ones. </p>



<p class="wp-block-paragraph">2.&nbsp;<b><i>Live your vision</i>.</b> Too often – but not always – strategy in the defense sector is the result of periodic process, perhaps annually or every three to five years. The reality is that technologies and threats are evolving too quickly for a rigid planning process alone to be a highly effective approach. Instead, turn strategic planning into a real-time activity. &nbsp;Hacking for Defense students do this by constantly iterating a “Mission Model Canvas” throughout the semester as they collect new information on beneficiaries and partners. For those involved in crafting industry or government strategy, build this type of living dashboard to augment or supplant a strategic plan. Constantly revisit customer or operator knowledge, market data, internal portfolios, and goals. </p>



<p class="wp-block-paragraph">3.&nbsp;<b><i>Ditch the static roadmap.</i></b> Like highways, technology roadmaps can accelerate progress, but they also give people fewer choices to exit when it makes the most sense rather than what a planner once envisioned as the optimal outcome. Hacking for Defense teams recognize this reality by presenting weekly updates on their MVPs that reflect their daily inputs. Therefore keep planning dynamic by conducting real-time research into beneficiary needs and the broader marketplace. Based on findings, quickly update roadmaps – even before milestone reviews if possible. Some organizations should even consider setting up small rapid innovation cells propelling development efforts outside normal R&amp;D procedures. </p>



<p class="wp-block-paragraph">The first Hacking for Defense classes in Washington may be over, but the work of some students continues as they look to get their ideas into the hands of warfighters. Given the speed and intensity with which the students worked, and the eagerness of their sponsoring agencies, that could even be sooner than they ever believed possible when they first signed up for the class.</p>



<p class="wp-block-paragraph"><i>Joshua Pavluk is a principal at Avascent, where he advises clients across the global aerospace and defense technology sector. His commentary has appeared in TechCrunch, VentureBeat, and War on the Rocks.</i></p>



<p class="wp-block-paragraph"><i>Jim Tinsley is a managing director at Avascent, specializing in major defense platforms and subsystems.</i></p>



<p class="wp-block-paragraph"><br/></p>
]]></content:encoded>
	</item>
		<item>
		<title>How tax agencies can fight back against insider threats [Commentary]</title>
		<link>https://one.sightlinemg.com/federaltimes/home/2017/07/19/how-tax-agencies-can-fight-back-against-insider-threats-commentary/</link>
					<comments>https://one.sightlinemg.com/federaltimes/home/2017/07/19/how-tax-agencies-can-fight-back-against-insider-threats-commentary/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Wed, 19 Jul 2017 08:48:55 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Newsletters]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2017/07/19/how-tax-agencies-can-fight-back-against-insider-threats-commentary/</guid>

					<description><![CDATA[The IRS is never going to earn the title of most popular agency with U.S. citizens. But it serves an important role, and insider threats can jeopardize that.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/home/2017/07/19/how-tax-agencies-can-fight-back-against-insider-threats-commentary/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">28423</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/Capture-6.jpg.jpg" width="1102" height="650" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">There is an old episode of &#8220;The Simpsons&#8221; where Lisa wins the family a trip to Washington, D.C. to take part in a national speechwriting competition. On their way from the airport to the hotel the family&#8217;s cab stops at a red light with Marge pointing out to Homer the headquarters of the Internal Revenue Service (IRS). &#8220;Booooooo!&#8221; Homer yells out the car&#8217;s window, expressing his displeasure with the tax agency.
</p>



<p class="wp-block-paragraph">Needless to say, the IRS is never going to earn the title of most popular agency with U.S. citizens. As the nation&#8217;s lead tax collector, the agency has the difficult job of processing the tax returns, payments and collections of tax-filing businesses and individuals across the country. While this leads to pop culture jokes like the one referenced above, it is a very important role as those funds go to pay for government services like defense, education and healthcare.
</p>



<p class="wp-block-paragraph">Those funds, as we know, are under constant attack from fraudsters looking to penetrate the system. But these attacks aren&#8217;t always coming from the outside … insider threats are becoming more commonplace.
</p>



<h2 class="wp-block-heading">The Insider Threat for Tax Agencies</h2>



<p class="wp-block-paragraph">According to a <a href="https://insights.sei.cmu.edu/insider-threat/2017/01/2016-us-state-of-cybercrime-highlights.html" rel="noopener noreferrer" target="_blank">survey</a> from the CERT Division of the Carnegie Mellon Software Engineering Institute (SEI), 47 percent of respondents reported an insider incident has been committed against their organization. They also said 27 percent of all cyberattacks come from insiders.
</p>



<p class="wp-block-paragraph">While these numbers look at the private sector, they surely translate to the government environment as well. Government agencies are incredibly prone to insider threats, especially employees that may have become unhappy with political changes or are approached with a lucrative opportunity from an outside source. This is especially true at tax agencies that have access to large amounts of financial and personal information – information that can generate significant financial and personal gain.
</p>



<h2 class="wp-block-heading">What Should Tax Agencies Do?</h2>



<p class="wp-block-paragraph">First and foremost, leaders at tax agencies must familiarize themselves with the insider threat industry, including considering the most modern insider threat detection solutions. For instance, advanced analytics that can reveal threats automatically.
</p>



<p class="wp-block-paragraph">Advanced analytics provide agencies with visibility into their networks that they did not have before. This enables administrators to have a better understanding of how, and where, data is being used, allowing them to establish baselines that can lead to easily identifying suspicious behavior. Analytics can work without human intervention as well, constantly monitoring networks for suspicious activity and then automatically sending alerts. This type of insight can allow administrators to learn about potential issues and pick up on patterns that human analysts miss.
</p>



<p class="wp-block-paragraph">Advanced analytics systems can use data already available to identify:
</p>



<ul class="wp-block-list"><li>File downloads which are excessive for the employees peer group.</li><li>Atypical privileged account access (e.g. VIP taxpayers).</li><li>Abnormal viewing/modification of taxpayer accounts.</li><li>Excessive web activity.</li><li>Sentiments (i.e. feelings) expressed in work email that are highly correlated with insider threat.</li><li>Unusual time-of-day access.</li><li>Employees connections and sphere of influence in the organization.</li></ul>



<p class="wp-block-paragraph">Advanced analytics, more than anything, can identify out-of-the-norm behavior. Most employees are hired to fill certain tasks, so their work tends to follow certain patterns. When those patterns are disrupted, that&#8217;s when the analytics engine can raise a red flag. Sometimes those activities might be nothing more than a mistake by an employee, but other times they can signal nefarious behavior.
</p>



<h2 class="wp-block-heading">Its Not Always Malicious</h2>



<p class="wp-block-paragraph">Fighting insider threats has been one of the government&#8217;s top priorities, but also one of the most difficult to achieve. To succeed, the government needs to have both a trust that employees are doing the work they were hired to do with the best intent, but also enough caution to monitor their work.
</p>



<p class="wp-block-paragraph">That is, of course, for insider threats that are intentionally malicious. There is another category of insider threats made up of employees that mean well, but do not follow information security best practices. These types of employees are not trying to put information at risk, but end up doing so. Advanced analytics can track the behavior of all employees and how they use data, flagging potential risks and dangerous behavior.
</p>



<p class="wp-block-paragraph">Tax agencies already face a difficult job. They must collect trillions of dollars each year in taxes, process returns and watch for fraud, waste and abuse in the process. Insider threats make this difficult job that much harder. With a proper analytics program, though, federal technology leaders can minimize the impact of insider threats and keep data, and important financial information, safe at all times.
</p>



<p class="wp-block-paragraph"><em>Deborah Pianko has 20 years of experience building technology solutions for tax and revenue agencies. As a systems engineer, Deborah helped build the systems used by many tax agencies, including D.C., Tennessee, Arizona, Maryland, Ohio, Nevada, Puerto Rico, Detroit, Australia and others.</em></p>
]]></content:encoded>
	</item>
		<item>
		<title>What an artificial intelligence researcher fears about AI [Commentary]</title>
		<link>https://one.sightlinemg.com/federaltimes/home/2017/07/14/what-an-artificial-intelligence-researcher-fears-about-ai/</link>
					<comments>https://one.sightlinemg.com/federaltimes/home/2017/07/14/what-an-artificial-intelligence-researcher-fears-about-ai/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Fri, 14 Jul 2017 09:00:44 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Newsletters]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2017/07/14/what-an-artificial-intelligence-researcher-fears-about-ai/</guid>

					<description><![CDATA[As an artificial intelligence researcher, I often come across the idea that many people are afraid of what AI might bring. As an AI expert, what do I fear about artificial intelligence?]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/home/2017/07/14/what-an-artificial-intelligence-researcher-fears-about-ai/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">32016</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/Capture-5.jpg.jpg" width="952" height="634" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">As an artificial intelligence researcher, I often come across the idea that many </p>



<a href="https://www.vox.com/conversations/2017/3/8/14712286/artificial-intelligence-science-technology-robots-singularity-automation" rel="noopener noreferrer" target="_blank">people are afraid of what AI might bring</a>



<p class="wp-block-paragraph">. It&#8217;s perhaps unsurprising, given both history and the entertainment industry, that </p>



<a href="https://www.vox.com/conversations/2017/3/8/14712286/artificial-intelligence-science-technology-robots-singularity-automation" rel="noopener noreferrer" target="_blank">we might be afraid</a>



<p class="wp-block-paragraph"> of a cybernetic takeover that forces us to live locked away, &#8220;Matrix&#8221;-like, as </p>



<a href="https://filmschoolrejects.com/was-the-matrix-even-necessary-in-the-matrix-c64070985674/" rel="noopener noreferrer" target="_blank">some sort of human battery</a>



<p class="wp-block-paragraph">.
</p>



<p class="wp-block-paragraph">And yet it is hard for me to look up from the <a href="https://theconversation.com/evolving-our-way-to-artificial-intelligence-54100" rel="noopener noreferrer" target="_blank">evolutionary computer models I use to develop AI</a>, to think about how the innocent virtual creatures on my screen might become the monsters of the future. Might I become &#8220;<a href="https://www.wired.co.uk/article/manhattan-project-robert-oppenheimer" rel="noopener noreferrer" target="_blank">the destroyer of worlds</a>,&#8221; as Oppenheimer lamented after spearheading the construction of the first nuclear bomb?
</p>



<p class="wp-block-paragraph">I would take the fame, I suppose, but perhaps the critics are right. Maybe I shouldn&#8217;t avoid asking: As an AI expert, what do I fear about artificial intelligence?
</p>



<h2 class="wp-block-heading">Fear of the unforeseen</h2>



<p class="wp-block-paragraph">The HAL 9000 computer, dreamed up by <a href="https://en.wikipedia.org/wiki/2001:_A_Space_Odyssey_(novel)" rel="noopener noreferrer" target="_blank">science fiction author Arthur C. Clarke</a> and brought to life by <a href="http://www.imdb.com/title/tt0062622/" rel="noopener noreferrer" target="_blank">movie director Stanley Kubrick</a> in &#8220;2001: A Space Odyssey,&#8221; is a good example of a system that fails because of unintended consequences. In many complex systems – the RMS Titanic, NASA&#8217;s space shuttle, the Chernobyl nuclear power plant – engineers layer many different components together. The designers may have known well how each element worked individually, but didn&#8217;t know enough about how they all worked together.
</p>



<p class="wp-block-paragraph">That resulted in systems that could never be completely understood, and could fail in unpredictable ways. In each disaster – sinking a ship, blowing up two shuttles and spreading radioactive contamination across Europe and Asia – a set of relatively small failures combined together to create a catastrophe.
</p>



<p class="wp-block-paragraph">I can see how we could fall into the same trap in AI research. We look at the latest research from cognitive science, translate that into an algorithm and add it to an existing system. We try to engineer AI without understanding intelligence or cognition first.
</p>



<p class="wp-block-paragraph">Systems like IBM&#8217;s Watson and Google&#8217;s Alpha equip artificial neural networks with enormous computing power, and accomplish impressive feats. But if these machines make mistakes, <a href="http://www.techrepublic.com/article/ibm-watson-the-inside-story-of-how-the-jeopardy-winning-supercomputer-was-born-and-what-it-wants-to-do-next/" rel="noopener noreferrer" target="_blank">they lose on &#8220;Jeopardy!&#8221;</a> or don&#8217;t <a href="https://techcrunch.com/2017/05/27/googles-alphago-ai-is-retiring/" rel="noopener noreferrer" target="_blank">defeat a Go master</a>. These are not world-changing consequences; indeed, the worst that might happen to a regular person as a result is losing some money betting on their success.
</p>



<p class="wp-block-paragraph">But as AI designs get even more complex and computer processors even faster, their skills will improve. That will lead us to give them more responsibility, even as the risk of unintended consequences rises. We know that &#8220;to err is human,&#8221; so it is likely impossible for us to create a truly safe system.
</p>



<h2 class="wp-block-heading">Fear of misuse</h2>



<p class="wp-block-paragraph">I&#8217;m not very concerned about unintended consequences in the types of AI I am developing, using an approach called <a href="https://theconversation.com/evolving-our-way-to-artificial-intelligence-54100" rel="noopener noreferrer" target="_blank">neuroevolution</a>. I create virtual environments and evolve digital creatures and their brains to solve increasingly complex tasks. The creatures&#8217; performance is evaluated; those that perform the best are selected to reproduce, making the next generation. Over many generations these machine-creatures evolve cognitive abilities.
</p>



<p class="wp-block-paragraph">Right now we are taking baby steps to evolve machines that can do simple navigation tasks, make simple decisions, or remember a couple of bits. But soon we will evolve machines that can execute more complex tasks and have much better general intelligence. Ultimately we hope to create human-level intelligence.
</p>



<p class="wp-block-paragraph">Along the way, we will find and eliminate errors and problems through the process of evolution. With each generation, the machines get better at handling the errors that occurred in previous generations. That increases the chances that we&#8217;ll find unintended consequences in simulation, which can be eliminated before they ever enter the real world.
</p>



<p class="wp-block-paragraph">Another possibility that&#8217;s farther down the line is using evolution to influence the ethics of artificial intelligence systems. It&#8217;s likely that human ethics and morals, such as <a href="http://dx.doi.org/10.1080/19390459.2014.935173" rel="noopener noreferrer" target="_blank">trustworthiness</a> and <a href="https://doi.org/10.1146/annurev-psych-010814-015355" rel="noopener noreferrer" target="_blank">altruism</a>, are a result of our evolution – and factor in its continuation. We could set up our virtual environments to give evolutionary advantages to machines that demonstrate kindness, honesty and empathy. This might be a way to ensure that we develop more obedient servants or trustworthy companions and fewer ruthless killer robots.
</p>



<p class="wp-block-paragraph">While neuroevolution might reduce the likelihood of unintended consequences, it doesn&#8217;t prevent misuse. But that is a moral question, not a scientific one. As a scientist, I must follow my obligation to the truth, reporting what I find in my experiments, whether I like the results or not. My focus is not on determining whether I like or approve of something; it matters only that I can unveil it.
</p>



<h2 class="wp-block-heading">Fear of wrong social priorities</h2>



<p class="wp-block-paragraph">Being a scientist doesn&#8217;t absolve me of my humanity, though. I must, at some level, reconnect with my hopes and fears. As a moral and political being, I have to consider the potential implications of my work and its potential effects on society.
</p>



<p class="wp-block-paragraph">As researchers, and as a society, we have not yet come up with a clear idea of what we want AI to do or become. In part, of course, this is because we don&#8217;t yet know what it&#8217;s capable of. But we do need to decide what the desired outcome of advanced AI is.
</p>



<p class="wp-block-paragraph">One big area people are paying attention to is employment. Robots are already doing physical work like <a href="http://www.assemblymag.com/articles/93555-new-technology-for-robotic-welding" rel="noopener noreferrer" target="_blank">welding car parts together</a>. One day soon they may also do cognitive tasks we once thought were uniquely human. <a href="https://www.theverge.com/2017/1/2/14147286/mit-research-nyc-taxi-carpool-uber-lyft" rel="noopener noreferrer" target="_blank">Self-driving cars could replace taxi drivers</a>; self-flying planes could replace pilots.
</p>



<p class="wp-block-paragraph">Instead of getting medical aid in an emergency room <a href="https://www.theatlantic.com/business/archive/2017/02/doctors-long-hours-schedules/516639/" rel="noopener noreferrer" target="_blank">staffed by potentially overtired doctors</a>, patients could get an examination and diagnosis from an expert system with <a href="https://www.engadget.com/2017/04/16/ai-can-predict-heart-attacks-more-accurately-than-doctors/" rel="noopener noreferrer" target="_blank">instant access to all medical knowledge</a> ever collected – and get <a href="http://spectrum.ieee.org/the-human-os/robotics/medical-robots/autonomous-robot-surgeon-bests-human-surgeons-in-world-first" rel="noopener noreferrer" target="_blank">surgery performed by a tireless robot</a> with a perfectly steady &#8220;hand.&#8221; Legal advice could come from an all-knowing <a href="https://law.duke.edu/lib/lresources/" rel="noopener noreferrer" target="_blank">legal database</a>; investment advice could come from a <a href="https://www.bloomberg.com/news/articles/2017-06-20/robots-are-eating-money-managers-lunch" rel="noopener noreferrer" target="_blank">market-prediction system</a>.
</p>



<p class="wp-block-paragraph">Perhaps one day, all human jobs will be done by machines. Even my own job could be done faster, by a large number of <a href="https://www.engadget.com/2017/05/17/google-launched-a-massive-open-ai-division/" rel="noopener noreferrer" target="_blank">machines tirelessly researching how to make even smarter machines</a>.
</p>



<p class="wp-block-paragraph">In our current society, automation pushes people out of jobs, <a href="https://theconversation.com/basic-income-after-automation-thats-not-how-capitalism-works-65023" rel="noopener noreferrer" target="_blank">making the people who own the machines richer and everyone else poorer</a>. That is not a scientific issue; it is a political and socioeconomic problem that <a href="https://theconversation.com/inequality-is-getting-worse-but-fewer-people-than-ever-are-aware-of-it-76642" rel="noopener noreferrer" target="_blank">we as a society must solve</a>. My research will not change that, though my political self – together with the rest of humanity – may be able to create circumstances in which AI becomes broadly beneficial instead of increasing the discrepancy between the one percent and the rest of us.
</p>



<h2 class="wp-block-heading">Fear of the nightmare scenario</h2>



<p class="wp-block-paragraph">There is one last fear, embodied by HAL 9000, the Terminator and any number of other fictional superintelligences: If AI keeps improving until it surpasses human intelligence, will a superintelligence system (or more than one of them) find it no longer needs humans? How will we justify our existence in the face of a superintelligence that can do things humans could never do? Can we avoid being wiped off the face of the Earth by machines we helped create?
</p>



<p class="wp-block-paragraph">The key question in this scenario is: Why should a superintelligence keep us around?
</p>



<p class="wp-block-paragraph">I would argue that I am a good person who might have even helped to bring about the superintelligence itself. I would appeal to the compassion and empathy that the superintelligence has to keep me, a compassionate and empathetic person, alive. I would also argue that diversity has a value all in itself, and that the universe is so ridiculously large that humankind&#8217;s existence in it probably doesn&#8217;t matter at all.
</p>



<p class="wp-block-paragraph">But I do not speak for all humankind, and I find it hard to make a compelling argument for all of us. When I take a sharp look at us all together, there is a lot wrong: We hate each other. We wage war on each other. We do not distribute food, knowledge or medical aid equally. We pollute the planet. There are many good things in the world, but all the bad weakens our argument for being allowed to exist.
</p>



<p class="wp-block-paragraph">Fortunately, we need not justify our existence quite yet. We have some time – <a href="http://fortune.com/2017/02/27/computers-smarter-than-people-masayoshi-son/" rel="noopener noreferrer" target="_blank">somewhere between 50</a> and 250 years, <a href="https://www.technologyreview.com/s/607970/experts-predict-when-artificial-intelligence-will-exceed-human-performance/" rel="noopener noreferrer" target="_blank">depending on how fast AI develops</a>. As a species we can come together and come up with a good answer for why a superintelligence shouldn&#8217;t just wipe us out. But that will be hard: Saying we embrace diversity and actually doing it are two different things – as are saying we want to save the planet and successfully doing so.
</p>



<p class="wp-block-paragraph">We all, individually and as a society, need to prepare for that nightmare scenario, using the time we have left to demonstrate why our creations should let us continue to exist. Or we can decide to believe that it will never happen, and stop worrying altogether. But regardless of the physical threats superintelligences may present, they also pose a political and economic danger. If we don&#8217;t find a way to <a href="https://www.nature.com/articles/ncomms3193" rel="noopener noreferrer" target="_blank">distribute our wealth better</a>, we will have <a href="https://www.technologyreview.com/s/428920/the-emerging-revolution-in-game-theory/" rel="noopener noreferrer" target="_blank">fueled capitalism</a> with artificial intelligence laborers serving only very few who possess all the means of production.
</p>



<p class="wp-block-paragraph"><a href="http://theconversation.com/what-an-artificial-intelligence-researcher-fears-about-ai-78655" rel="noopener noreferrer" target="_blank"><em>This article was originally published on The Conversation.</em></a></p>
]]></content:encoded>
	</item>
		<item>
		<title>&#8216;NotPetya&#8217; ransomware attack shows corporate social responsibility should include cybersecurity [Commentary]</title>
		<link>https://one.sightlinemg.com/federaltimes/home/2017/06/28/notpetya-ransomware-attack-shows-corporate-social-responsibility-should-include-cybersecurity-commentary/</link>
					<comments>https://one.sightlinemg.com/federaltimes/home/2017/06/28/notpetya-ransomware-attack-shows-corporate-social-responsibility-should-include-cybersecurity-commentary/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Wed, 28 Jun 2017 09:21:48 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Newsletters]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2017/06/28/notpetya-ransomware-attack-shows-corporate-social-responsibility-should-include-cybersecurity-commentary/</guid>

					<description><![CDATA[As the NotPetya ransomware attack spreads around the world, its making clear how important it is for everyone  and particularly corporations  to take cybersecurity seriously. ]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/home/2017/06/28/notpetya-ransomware-attack-shows-corporate-social-responsibility-should-include-cybersecurity-commentary/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">11527</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/file-20170627-24798-plfh1a.jpg.jpg" width="754" height="503" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">As the &#8220;</p>



<a href="http://fifthdomain.com/2017/06/27/new-cyberattack-causes-mass-disruption-in-europe/" rel="noopener noreferrer" target="_blank">NotPetya</a>



<p class="wp-block-paragraph">&#8221; ransomware attack </p>



<a href="http://fifthdomain.com/2017/06/27/us-drugmaker-health-care-system-hit-by-cyberattack/" rel="noopener noreferrer" target="_blank">spreads around the world</a>



<p class="wp-block-paragraph">, it&#8217;s making clear how important it is for everyone – and particularly corporations – to take cybersecurity seriously. The </p>



<a href="https://www.forbes.com/sites/thomasbrewster/2017/06/27/petya-notpetya-ransomware-is-more-powerful-than-wannacry/" rel="noopener noreferrer" target="_blank">companies affected by this malware</a>



<p class="wp-block-paragraph"> include </p>



<a href="https://www.usatoday.com/story/tech/news/2017/06/27/large-cyberattack-hits-europe-disrupts-power-grid-banks/103226268/" rel="noopener noreferrer" target="_blank">power utilities, banks and technology firms</a>



<p class="wp-block-paragraph">. Their customers are now left without power and other crucial services, in part because the companies did not take action and make the investments necessary to better protect themselves from these cyberattacks.
</p>



<p class="wp-block-paragraph">Cybersecurity is becoming another facet of the growing movement demanding <a href="http://csr-asia.com/csr-asia-weekly-news-detail.php?id=12692" rel="noopener noreferrer" target="_blank">corporate social responsibility</a>. This broad effort has already made progress toward getting workers paid a <a href="https://www.ecotextile.com/2016051922130/social-compliance-csr-news/living-wage-from-clothing-premium.html">living wage</a>, encouraging companies to operate <a href="http://www.triplepundit.com/2017/01/10-companies-zero-waste-to-landfill/" rel="noopener noreferrer" target="_blank">zero-waste production plants</a> and practice <a href="http://greenlivingideas.com/2015/08/31/cradle-to-cradle-manufacturing/" rel="noopener noreferrer" target="_blank">cradle-to-cradle manufacturing</a> – and even getting them to <a href="http://www.cnbc.com/2017/06/16/toms-founder-blake-mycoskie-shares-his-favorite-book-of-all-time.html" rel="noopener noreferrer" target="_blank">donate products</a> to people in need.
</p>



<p class="wp-block-paragraph">The overall idea is that companies should make corporate decisions that reflect obligations not just to owners and shareholders, customers and employees, but to society at large and the natural environment. As a scholar of cybersecurity law and policy and chair of Indiana University&#8217;s new integrated program on <a href="https://cybersecurityprograms.indiana.edu/" rel="noopener noreferrer" target="_blank">cybersecurity risk management</a>, I say it&#8217;s time to add cyberspace to that list.
</p>



<h2 class="wp-block-heading">Online security affects everyone</h2>



<p class="wp-block-paragraph">The recent <a href="http://www.bbc.com/news/technology-40085241" rel="noopener noreferrer" target="_blank">WannaCry ransomware attack</a> affected more than 200,000 computers in <a href="https://www.bleepingcomputer.com/news/security/new-data-shows-most-wannacry-victims-are-from-china-not-russia/" rel="noopener noreferrer" target="_blank">150 nations</a>. The results of the attack made clear that computers whose <a href="https://theconversation.com/why-installing-software-updates-makes-us-wannacry-77667" rel="noopener noreferrer" target="_blank">software is not kept up to date</a> can hurt not only the computers&#8217; owners, but ultimately all internet users. The companies hit by the NotPetya attack didn&#8217;t heed that warning, and got caught by an attack <a href="https://www.wired.com/story/petya-ransomware-outbreak-eternal-blue/" rel="noopener noreferrer" target="_blank">using the same vulnerability as WannaCry</a>, because they still haven&#8217;t updated their systems.
</p>



<p class="wp-block-paragraph">Some policymakers and managers are taking notice <a href="http://www.chinadailyasia.com/opinion/2016-09/11/content_15493388.html" rel="noopener noreferrer" target="_blank">around the world</a>. In the U.S., the Department of Homeland Security, the <a href="https://www.dhs.gov/topic/cybersecurity" rel="noopener noreferrer" target="_blank">chief federal agency dealing with cybersecurity</a>, has highlighted businesses&#8217; &#8220;<a href="https://www.dhs.gov/blog/2013/10/18/cybersecurity-shared-responsibility" rel="noopener noreferrer" target="_blank">shared responsibility</a>&#8221; to <a href="https://www.dhs.gov/blog/2013/10/18/cybersecurity-shared-responsibility" rel="noopener noreferrer" target="_blank">protect themselves</a> against cyberattacks. Consumers can&#8217;t protect their utility services, banking systems or even their personal data on their own, and must depend on companies to handle that security.
</p>



<p class="wp-block-paragraph">Cybersecurity is an effort that not only protects – and even benefits – a company&#8217;s bottom line but also contributes to overall <a href="http://www.huffingtonpost.com/scott-j-shackelford/sustainable-cybersecurity_b_6988050.html" rel="noopener noreferrer" target="_blank">corporate and societal sustainability</a>. In addition, by protecting privacy, free expression and the exchange of information, cybersecurity helps support people&#8217;s <a href="https://theconversation.com/should-cybersecurity-be-a-human-right-72342" rel="noopener noreferrer" target="_blank">human rights</a>, both online and offline.
</p>



<h2 class="wp-block-heading">Vaccinating cyberspace</h2>



<p class="wp-block-paragraph">If more companies get serious about cybersecurity, the internet ecosystem will be safer for everyone. The concept is much like vaccinating people against disease: <a href="https://www.vaccines.gov/basics/protection/index.html" rel="noopener noreferrer" target="_blank">If enough people are protected, the others benefit too</a>, through what is called &#8220;<a href="https://theconversation.com/herd-immunity-and-measles-why-we-should-aim-for-100-vaccination-coverage-36868" rel="noopener noreferrer" target="_blank">herd immunity</a>.&#8221;
</p>



<p class="wp-block-paragraph">In terms of deterring hackers, the number of vulnerable targets will drop, making it harder for hackers to find them, and less worthwhile to even look. And more companies will have defenses ready when cyber attackers come calling. This isn&#8217;t a perfect solution: With enough time and resources, any system is vulnerable. But this change in corporate perception is an important step in developing a global <a href="http://www.cambridge.org/us/academic/subjects/law/e-commerce-law/managing-cyber-attacks-international-law-business-and-relations-search-cyber-peace?format=HB&amp;isbn=9781107004375" rel="noopener noreferrer" target="_blank">culture of cybersecurity</a>.
</p>



<p class="wp-block-paragraph">Customers can get involved in this effort, demanding better cybersecurity from companies they do business with. These can include online retailers, whether small specialized sellers or giants like Amazon. But local bricks-and-mortar stores with customer loyalty programs that have built their brands on trust can also be susceptible to consumer pressure.
</p>



<p class="wp-block-paragraph">To date, it&#8217;s been hard to know which companies have the best cybersecurity practices. The product and service reviewers at Consumer Reports have made a start: In March they started <a href="http://www.consumerreports.org/privacy/consumer-reports-to-begin-evaluating-products-services-for-privacy-and-data-security/" rel="noopener noreferrer" target="_blank">evaluating devices, software and mobile apps</a> for privacy and cybersecurity.
</p>



<p class="wp-block-paragraph">Advocacy groups like the <a href="http://www.internetsociety.org/" rel="noopener noreferrer" target="_blank">Internet Society</a> <a href="http://www.cyberpeacefoundation.org/" rel="noopener noreferrer" target="_blank">and</a> <a href="https://staysafeonline.org/" rel="noopener noreferrer" target="_blank">many</a> <a href="https://www.comptia.org/advocacy" rel="noopener noreferrer" target="_blank">others</a> should ask companies to discuss cybersecurity efforts in their reports to shareholders. And they should urge government agencies to develop voluntary programs like the <a href="https://www.energystar.gov/" rel="noopener noreferrer" target="_blank">U.S. Environmental Protection Agency&#8217;s Energy Star</a> appliance-efficiency rating system. The U.K. has a certification like this for cybersecurity, called <a href="https://www.cyberessentials.org/" rel="noopener noreferrer" target="_blank">Cyber Essentials</a>. These efforts don&#8217;t require executives or managers to make different decisions, but help inform them – and the public – about how the choices they make affect consumers.
</p>



<p class="wp-block-paragraph">Ultimately, companies will play a huge role in shaping the future of our shared experience online. Cybersecurity and data privacy are key elements of this, and it&#8217;s time consumers demand corporations treat them as the 21st-century social responsibilities they are.
</p>



<p class="wp-block-paragraph"><a href="http://theconversation.com/notpetya-ransomware-attack-shows-corporate-social-responsibility-should-include-cybersecurity-79810" rel="noopener noreferrer" target="_blank"><em>This article was originally published on The Conversation.</em></a></p>
]]></content:encoded>
	</item>
		<item>
		<title>What not to do after a data breach</title>
		<link>https://one.sightlinemg.com/federaltimes/home/2017/06/22/what-not-to-do-after-a-data-breach/</link>
					<comments>https://one.sightlinemg.com/federaltimes/home/2017/06/22/what-not-to-do-after-a-data-breach/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Thu, 22 Jun 2017 10:00:42 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Newsletters]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2017/06/22/what-not-to-do-after-a-data-breach/</guid>

					<description><![CDATA[Thousands of words have been written about how to prevent cyberattacks and what to do if you've been targeted. Unfortunately, there's no standard playbook for a data breach and your actions during a disaster could be as harmful as they are helpful.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/home/2017/06/22/what-not-to-do-after-a-data-breach/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">9904</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/ThinkstockPhotos-526767097.jpg.jpg" width="4352" height="2896" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Thousands of words have been written about how to prevent cyberattacks and what to do if you&#8217;ve been targeted. You&#8217;re probably already familiar with terms such as endpoint protection and data backup and recovery. These solutions and services are great for protecting you and helping you get back up and running once an attack has been resolved. Unfortunately, there&#8217;s no standard playbook for a data breach and your actions during a disaster could be as harmful as they are helpful.
</p>



<p class="wp-block-paragraph">In this article, I will discuss what companies should avoid doing once they realize their systems have been breached. I spoke to several experts from security companies and industry analysis firms to better understand the potential pitfalls and disaster scenarios that develop in the wake of cyberattacks.
</p>



<h2 class="wp-block-heading">1. Do Not Improvise</h2>



<p class="wp-block-paragraph">In the event of an attack, your first instinct will tell you to begin the process of rectifying the situation. This may include protecting the endpoints that have been targeted or reverting to previous backups to close up the entry point used by your attackers. Unfortunately, if you hadn&#8217;t previous developed a strategy, then whatever hasty decisions you make after an attack could worsen the situation.
</p>



<p class="wp-block-paragraph">&#8220;The first thing you should not do after a breach is create your response on the fly,&#8221; said Mark Nunnikhoven, Vice President of Cloud Research at cyber security solution provider Trend Micro . &#8220;A critical part of your incident response plan is preparation. Key contacts should be mapped out ahead of time and stored digitally. It should also be available in hard copy in case of a catastrophic breach. When responding to a breach, the last thing you need to be doing is trying to figure out who is responsible for what actions and who can authorize various responses.&#8221;
</p>



<p class="wp-block-paragraph">Ermis Sfakiyanudis, President and CEO of data protection services company <a href="https://www.trivalent.co/" rel="noopener noreferrer" target="_blank">Trivalent</a>, agrees with this approach. He said it&#8217;s critical that companies &#8220;do not freak out&#8221; after they&#8217;ve been hit by a breach. &#8220;While unpreparedness in the face of a data breach can cause irreparable damage to a company, panic and disorganization can also be extremely detrimental,&#8221; he explained. &#8220;It is critical that a breached company not stray from its incident response plan, which should include identifying the suspected cause of the incident as a first step. For example, was the breach caused by a successful ransomware attack, malware on the system, a firewall with an open port, outdated software, or unintentional insider threat? Next, isolate the effected system and eradicate the cause of the breach to ensure your system is out of danger.&#8221;
</p>



<p class="wp-block-paragraph">Sfakiyanudis said it&#8217;s vital that companies ask for help when they&#8217;re in over their heads. &#8220;If you determine that a breach has indeed occurred following your internal investigation, bring in third-party expertise to help handle and mitigate the fallout,&#8221; he said. &#8220;This includes legal counsel, outside investigators who can conduct a thorough forensic investigation, and public relations and communication experts who can create strategy and communicate to the media on your behalf.
</p>



<p class="wp-block-paragraph">&#8220;With this combined expert guidance, organizations can remain calm through the chaos, identifying what vulnerabilities caused the data breach, remediating so the issue doesn&#8217;t happen again in the future, and ensuring their response to affected customers is appropriate and timely. They can also work with their legal counsel to determine if and when law enforcement should be notified.&#8221;
</p>



<h2 class="wp-block-heading">2. Do Not Go Silent</h2>



<p class="wp-block-paragraph">Once you&#8217;ve been attacked, it&#8217;s comforting to think that no one outside of your inner circle knows what just happened. Unfortunately, the risk here isn&#8217;t worth the reward. You&#8217;ll want to communicate with staffers, vendors, and customers to let everyone know what has been accessed, what you did to remedy the situation, and what plans you intend to take to ensure no similar attacks occur in the future. &#8220;Don&#8217;t ignore your own employees,&#8221; advised Heidi Shey, Senior Analyst of Security &#038; Risk at <a href="https://go.forrester.com/">Forrester Research</a>. &#8220;You need to communicate with your employees about the event, and provide guidance for your employees about what to do or say if they asked about the breach.&#8221;
</p>



<p class="wp-block-paragraph">Shey, like Sfakiyanudis, said you may want to look into hiring a public relations team to help control the messaging behind your response. This is especially true for large and expensive consumer-facing data breaches. &#8220;Ideally, you&#8217;d want such a provider identified in advance as a part of your incident response planning so you can be ready to kick off your response,&#8221; she explained.
</p>



<p class="wp-block-paragraph">Just because you&#8217;re being proactive about notifying the public that you&#8217;ve been breached, it doesn&#8217;t mean that you can start issuing wild statements and proclamations. For example, when toymaker VTech was breached, photos of children and chat logs were accessed by a hacker. After the situation had died down, the toymaker changed its Terms of Service to relinquish its responsibility in the event of a breach. Needless to say, <a href="http://www.csoonline.com/article/3035021/security/vtech-not-backing-down-on-terms-change-after-data-breach.html" rel="noopener noreferrer" target="_blank">customers were not happy</a>. &#8220;You don&#8217;t want to look like you&#8217;re resorting to hiding behind legal means, whether that&#8217;s in avoiding liability or controlling the narrative,&#8221; said Shey. &#8220;Better to have a breach response and crisis management plan in place to help with breach-related communications.&#8221;
</p>



<h2 class="wp-block-heading">3. Do Not Make False or Misleading Statements</h2>



<p class="wp-block-paragraph">This is an obvious one but you&#8217;ll want to be as accurate and honest as possible when addressing the public. This is beneficial to your brand, but it&#8217;s also beneficial to how much money you&#8217;ll recoup from your cyber-insurance policy should you have one. &#8220;Don&#8217;t issue public statements without consideration for the implications of what you&#8217;re saying and how you sound,&#8221; said Nunnikoven.
</p>



<p class="wp-block-paragraph">&#8220;Was it really a &#8216;sophisticated&#8217; attack? Labeling it as such doesn&#8217;t necessarily make it true,&#8221; he continued. &#8220;Does your CEO really need to call this an &#8216;act of terrorism&#8217;? Have you read the fine print of your cyber-insurance policy to understand exclusions?&#8221;
</p>



<p class="wp-block-paragraph">Nunnikhoven recommends crafting messages that are &#8220;no-bull, frequent, and which clearly state actions that are being taken and those that need to be taken.&#8221; Trying to spin the situation, he said, tends to make things worse. &#8220;When users hear about a breach from a third party, it immediately erodes hard-won trust,&#8221; he explained. &#8220;Get out in front of the situation and stay in front, with a steady stream of concise communications in all channels where you&#8217;re already active.&#8221;
</p>



<h2 class="wp-block-heading">4. Do Not Close Incidents Too Soon</h2>



<p class="wp-block-paragraph">You&#8217;ve closed your corrupted endpoints. You&#8217;ve contacted your employees and customers. You&#8217;ve recovered all of your data. The clouds have parted and a ray of sunshine has cascaded onto your desk. Not so fast. Although it may seem as if your crisis has ended, you&#8217;ll want to continue to aggressively and proactively monitor your network to ensure there are no follow-up attacks.
</p>



<p class="wp-block-paragraph">&#8220;There is a huge amount of pressure to restore services and recover after a breach,&#8221; said Nunnikhoven. &#8220;Attackers move quickly through networks once they gain a foothold, so it&#8217;s hard to make a concrete determination that you&#8217;ve addressed the entire issue. Staying diligent and monitoring more aggressively is an important step until you&#8217;re sure the organization is in the clear.&#8221;
</p>



<p class="wp-block-paragraph">Sfakiyanudis agrees with this assessment. &#8220;After a data breach is resolved and regular business operations resume, do not assume the same technology and plans you had in place pre-breach will be sufficient,&#8221; he said. &#8220;There are gaps in your security strategy that were exploited and, even after these gaps are addressed, it doesn&#8217;t mean there won&#8217;t be more in the future. In order to take a more proactive approach to data protection moving forward, treat your data breach response plan as a living document. As individuals change roles and the organization evolves via mergers, acquisitions, etc., the plan needs to change as well.&#8221;
</p>



<h2 class="wp-block-heading">5. Do Not Forget to Investigate</h2>



<p class="wp-block-paragraph">&#8220;When investigating a breach, document everything,&#8221; said Sfakiyanudis. &#8220;Gathering information on an incident is critical in validating that a breach occurred, what systems and data were impacted, and how mitigation or remediation was addressed. Log results of investigations through data capture and analysis so they are available for review post-mortem.
</p>



<p class="wp-block-paragraph">&#8220;Be sure to also interview anyone involved and carefully document their responses,&#8221; he continued. &#8220;Creating detailed reports with disk images, as well as details on who, what, where, and when the incident occurred, will help you implement any new or missing risk mitigation or data protection measures.&#8221;
</p>



<p class="wp-block-paragraph">If your company is too analog to conduct this analysis on its own, you&#8217;ll probably want to hire an external team to conduct this investigation for you (as Sfakiyanudis mentioned earlier). Take notes on the search process as well. Note what services you were offered, which vendors you spoke to, and whether or not you were happy with the investigation process. This information will help you determine whether or not to stick with your vendor, choose a new vendor, or hire in-house staff who&#8217;s capable of conducting these processes should your company be unlucky enough to suffer a second breach.
</p>



<p class="wp-block-paragraph"><em>This article <a href="http://www.pcmag.com/article/354410/what-not-to-do-after-a-data-breach" rel="noopener noreferrer" target="_blank">originally appeared</a> on <a href="http://www.pcmag.com/" rel="noopener noreferrer" target="_blank">PCMag.com</a>.</em></p>
]]></content:encoded>
	</item>
		<item>
		<title>Cryptocurrencies — a growing issue for military, intel agencies and law enforcement</title>
		<link>https://one.sightlinemg.com/federaltimes/cyber/2017/06/19/cryptocurrencies-a-growing-issue-for-military-intel-agencies-and-law-enforcement/</link>
					<comments>https://one.sightlinemg.com/federaltimes/cyber/2017/06/19/cryptocurrencies-a-growing-issue-for-military-intel-agencies-and-law-enforcement/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Mon, 19 Jun 2017 07:00:00 +0000</pubDate>
				<category><![CDATA[Cyber]]></category>
		<category><![CDATA[Net Defense Blogs]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[The Compass]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2017/06/19/cryptocurrencies-a-growing-issue-for-military-intel-agencies-and-law-enforcement/</guid>

					<description><![CDATA[While many have not heard of or understand cryptocurrencies, you had better take notice — that is for sure! This is a powerful technology whose ramifications mandate that military, intelligence organizations and law enforcement must monitor and understand it.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/cyber/2017/06/19/cryptocurrencies-a-growing-issue-for-military-intel-agencies-and-law-enforcement/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">14130</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/cryptocurrency.jpg.jpg" width="4966" height="3501" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">If you have not heard of or understand cryptocurrencies, you are not alone; but that had better change. Cryptocurrencies — a technology whose time seems to have come — has grown significantly as of late. The total dollar value of all cryptocurrencies exceed the gross domestic product of all but 84 countries in the world, according to the CIA World Factbook. That means the total value of all cryptocurrencies exceed the GDP of 145 individual countries, based on the CIA World Factbook! While many have not heard of or understand cryptocurrencies, you had better take notice — that is for sure! This is a powerful technology whose ramifications mandate that military, intelligence organizations and law enforcement must monitor and understand it.</p>



<p class="wp-block-paragraph">According to  <a class="" href="http://www.investopedia.com/" target="_blank">Investopedia</a>, a cryptocurrency is a digital or virtual currency that uses cryptography for security. A cryptocurrency is difficult to counterfeit because of this security feature. A defining feature of a cryptocurrency, and arguably its most endearing allure, is its organic nature; it is not issued by any central authority, rendering it theoretically immune to government interference or manipulation. <br/> <br/></p>





<p class="wp-block-paragraph">You can track the cumulative total U.S. dollar value of each individual cryptocurrency and the sum of all 863 individual cryptocurrencies using  <a class="" href="https://coinmarketcap.com/all/views/all/" target="_blank" title="Link: https://coinmarketcap.com/all/views/all/">this online source</a>. <br/> <br/></p>



<p class="wp-block-paragraph">About six weeks ago, the delivery of a cryptocurrency training webinar attracted a few thousand professional participants worldwide and was highly rated. That is a clear indicator of the interest in this subject matter, for sure. It is extremely difficult to calculate the military and intelligence ramifications.That being said, one has to wonder how much human trafficking, illegal drugs sales, arms sales, militia financing and terrorist activity support is represented in the figures above. One has to wonder about the cryptocurrency dollar value on the dark web. It is surely a national security issue! <br/> <br/></p>


]]></content:encoded>
	</item>
		<item>
		<title>Complexity of developing a cyber defense strategy [Commentary]</title>
		<link>https://one.sightlinemg.com/federaltimes/home/2017/06/07/complexity-of-developing-a-cyber-defense-strategy-commentary/</link>
					<comments>https://one.sightlinemg.com/federaltimes/home/2017/06/07/complexity-of-developing-a-cyber-defense-strategy-commentary/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Wed, 07 Jun 2017 10:30:00 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Newsletters]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2017/06/07/complexity-of-developing-a-cyber-defense-strategy-commentary/</guid>

					<description><![CDATA[For decades, our adversaries have been and continue to constantly seek new ways to compete with the United States on a much more level battlefield. Cyber has much, if not all, of what they have been looking for.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/home/2017/06/07/complexity-of-developing-a-cyber-defense-strategy-commentary/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">21603</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/snagfilms-a.akamaihd.netethernet-cords-barbed-wir-568a6571668a063e4f1c54d095d07768eb827cd1-1.jpg.jpg" width="2000" height="1500" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Creating a cyber defense strategy is an extremely difficult undertaking to be sure. Given all that is at stake, it is essential to ensure it serves the needs of the United States today and for years to come. The last thing any of us want is to have to change the strategy every time there is a new actor-led or technological threat, or when some new aspect of the internet and associated technology is implemented.
</p>



<p class="wp-block-paragraph">Let&#8217;s face it, there are not too many things that are as ever-changing as the internet and all the devices and equipment that gets connected to it! It is worth noting that several commercial and research organizations are hard at work integrating artificial intelligence into cyber defense. While that is an indicator of the complexities of the environment, it should also be worth noting the complexities that come with most cyber defense solution sets.
</p>



<p class="wp-block-paragraph">Estimates suggest that each month, 328 million new devices get connected to the internet. Each one of those devices could be a new sensor or other information-gathering mechanism. Now for the dark side: Each one of those devices becomes a potential point of attack; and worse, they become a potential weapon in a distributed denial-of-service attack. Another important aspect of the complexity of this topic is the segmentation of the environment. Analysis of this problem set produced the following segments, each with its own unique characteristics that add to the complexity and require somewhat of a different cyber defense strategy.
</p>



<p class="wp-block-paragraph"><strong>The private sector business side</strong> </p>



<ul class="wp-block-list"><li>Small businesses</li><li>Midsize businesses</li><li>Large businesses</li></ul>



<p class="wp-block-paragraph">The complexity of dealing with private sector aspects of complexity are due primarily to their role in critical infrastructure and their influence on other essential service/contributions.
</p>



<p class="wp-block-paragraph"><strong>The private sector not-for-profit organizations</strong> </p>



<ul class="wp-block-list"><li>Small</li><li>Medium</li><li>Large</li></ul>



<p class="wp-block-paragraph">The complexity of dealing with not-for-profit organizations&#8217; aspects of complexity are due primarily to their role in influential aspects of our country, such as political parties as a recent example.
</p>



<p class="wp-block-paragraph"><strong>Government organizations</strong> </p>



<ul class="wp-block-list"><li>Federal</li><li>State</li><li>Local</li></ul>



<p class="wp-block-paragraph"><strong>Defense Department</strong> </p>



<ul class="wp-block-list"><li>Combat units: offensive and defensive</li><li>Support services</li><li>Intelligence</li></ul>



<div> <p> </p><p>In order for the nations cyber defense strategy to be effective, it has to address aspects and attributes of each of area. This is why during one April presentation at a corporate risk briefing, one of the attendees said that defending the cyber environment is like trying to change a flat tire on a vehicle going down the road at 70 mph. That opinion is shared by many!</p><p> </p><p>This takes the best and brightest and most creative minds the nation has in a concerted effort to address this critical need. It is my belief that we should not use the models from the past, but look to create a new, sustainable model that addresses the needs of today as well as what is believed to be a model of the environment in the next three to five years. I should note that I am not alone in that thinking.</p><p> </p><p>There is an interesting piece on IEEE titled  <a class="" href="http://ieeexplore.ieee.org/document/7896576/" rel="noopener noreferrer" target="_blank" title="Link: http://ieeexplore.ieee.org/document/7896576/">The Unfitness of Traditional Military Thinking in Cyber</a>. While this is an interesting piece, one thing should be added: The cyber environment is continuously and rapidly changing and far different from what we see in the traditional military setting. New offensive, defensive and intelligence strategies must be developed. While starting with a blank sheet of paper is a daunting undertaking to be sure, it is necessary to address the complexities of this environment.</p><p> </p><p>For decades, our adversaries have been and continue to constantly seek new ways to compete with the United States on a much more level battlefield. Cyber has much, if not all, of what they have been looking for. A cyber weapon does not require significant amounts of money such as a weapon like the B-21 Long Range Strike Bomber. Cyber provides an environment where military capabilities can be compromised, stolen and reproduced by our adversaries. Cyber also provides an environment where you can easily outsource the execution of an adversary&#8217;s hostile intention toward the United States. Those are just a few of the many differences that require the nations cyber defense strategy to be wide-ranging and depart from traditional models.</p><p> </p><p>The cyber domain is a highly contested area, and we cannot afford to get wrong our nation&#8217;s cyber defense strategy.</p><p> </p><p></p></div>
]]></content:encoded>
	</item>
	</channel>
</rss>
