I’m starting to appreciate what a special breed of person it takes to be a federal chief information security officer. It’s clearly not a job for the faint of heart.
Take the Energy Department, for example. USA Today obtained a redacted summary of cybersecurity incidents reported by the Energy Department over a 48-month period between October 2010 and October 2014. According to these documents, there were 1,131 major cyber incidents reported during that period. They include successful intrusions into DoE networks and user accounts, installations of malicious code, unauthorized access to networks, denial-of-service (DOS) attacks, and defacements of departmental websites.
That’s a lot. In fact, that translates to roughly 1.12 major cybersecurity incidents per workday.
A few nuggets that I took away from the DoE report:
Don’t Miss CYBERCON 2015, a cybersecurity conference coming Nov. 18, featuring DISA Director Lt. Gen. Alan Lynn and more government leaders. Get details here.
■Malicious code — defined as successful or persistent attempts to insert viruses — remains the big gorilla percentage-wise. Roughly 76 percent of all incidents reported were of this variety.
■There were 159 intrusions into the DoE network. Especially troubling was that 51 of those intrusions — roughly 5 percent of all reported incidents and a third of all intrusions — were root account compromises, which are particularly alarming because an intruder who gets root privileges to a server has the ability to do anything a systems administrator could do, including copying files or installing software. The remainder were user account intrusions.
■There were 72 “unauthorized use” incidents, or roughly 6 percent of all reported incidents. These are cases in which an individual gains access without permission to a network, system, application, data or other resource.
■There were 17 successful DOS attacks (plus a few unsuccessful DOS attempts, which are also reported). These render a network unusable for some period of time. There was even a two-month stretch between January and March 2014 where various DoE agencies were the targets of seven DOS attacks, three of which were successful.
Web defacements are not insignificant: There were 19.
DoE is no aberration. In fact, there are plenty of federal agencies who report significantly more cybersecurity incidents than DoE, including the Defense, Health and Human Services, Treasury, Justice and Homeland Security departments. And even agencies that report relatively fewer numbers of cyber incidents can’t relax (think Office of Personnel Management).
This cyber battle intensifies every year: Federal agencies reported 5,503 cyber incidents to the U.S. Computer Emergency Readiness Team in 2006. Within eight years, in 2014, that figure exploded to 67,168, more than 12 times the 2006 number.
This creates another problem: Data overload. There’s no effective mechanism in place to prioritize these incidents. The White House and DHS are working to develop agency-specific and federal-wide cybersecurity dashboards through the Continuous Diagnostics and Mitigation program that will prioritize this onslaught. But, realistically, that deployed capability is years away.
And, sorry to say, there’s something else for federal CISOs to worry about: The impact and severity of the cyber threat is evolving as well. Top U.S. intelligence officials are now warning that federal cyber breaches intended to manipulate or destroy data are likely to come soon. The implications of that are scary.
So even as we hear from the White House and others about the many steps being taken across the federal government to fortify federal network defenses, reports like this one remind us that there’s a long, long way to go.
It’s a wonder federal CISOs get any sleep at all.
Steve Watkins is a contributing editor.
The cyber onslaught gets worse




