With the proliferation of cyber-related solutions flooding the market, it can be a challenge for government leaders and corporate boards to know where to best place limited resources. In 2016, I expect these leaders to demand greater accountability from the cyber professionals in their organizations.
After working on these issues for 25 years as a state senator, state CIO, a senior official at the Department of Homeland Security and now as a corporate consultant, I believe the coming year will mark a turning point for how government and business approach cyber expenditures.
No one wants to be in the headlines as the next Office of Personnel Management or Target, but where should the focus be in acquiring cybersecurity tools to limit risk and enhance return on investment? Here are five areas where cyber outlays in 2016 can help move the needle in the right direction.
Know what you have
The first step is to know what you have in terms of cyber protection capabilities. This sounds fairly fundamental, yet many leaders in organizations have little idea what kind of protections the CIO and CISO are deploying. This is why the top of the list in developing a sound cyber strategy on the Center for Internet Security’s 20 Critical Security Controls focuses on creating inventories of software and devices, authorized and unauthorized.
Developed by government Red Teams, a principle benefit of the controls is that they prioritize and focus a smaller number of actions with high pay-off results. For the full list of controls, follow this link.
Protect your data
In the wake of the OPM debacle, Federal CIO Tony Scott took two major actions. First, he initiated a 30 Day “cyber sprint” to close immediate holes in the government’s authentication and access control systems. Second, he convened leaders in government and industry to create a roadmap for “identifying and addressing critical cybersecurity gaps and emerging priorities, while making specific recommendations to address those gaps and priorities.”
At the top of the priority list in the resulting Cybersecurity Strategy and Implementation Plan (CSIP) is data protection. This is a particularly important with the proliferation of mobile technology. One successful strategy for protecting key data is to deploy an enterprise digital rights management (E-DRM) system as part of your security stack. Effective E-DRM solutions have the benefit of delivering advanced encryption that follows the file regardless of whether the data is at rest or in transit to other end user devices. In the age of mobility, this is a must.
Enhance perimeter defenses
While perimeter network defenses won’t solve all your problems, there is no denying that having strong blocking and detection capabilities should continue to be a part of a robust, layered cybersecurity approach. When combined with analytics and intelligence tools, this approach can prove partially effective. The caution is that many of these systems rely on signature-based technologies that require knowledge of the threat in advance. The Federal government’s National Cybersecurity Protection System (NCPS), commonly referred to as Einstein, is a good example of this strategy. In its latest iteration, Einstein 3 Accelerated (E3A), the Department of Homeland Security seeks to utilize a managed security services approach, using Internet Service Providers to aggregate traffic and block malicious activity. It is increasingly apparent that the most sophisticated nation states, criminal syndicates and lone hackers are able to circumvent some of these protections.
Deploy continuous diagnostics and mitigation
A term that is getting a great deal of attention these days is cyber resilience. Generally, this refers to the notion that organizations need to be able to swiftly bounce back from aggressive cyber-attacks. Part of the strategy in 2016 will remain the focus on the ability to continuously monitor and mitigate persistent and emerging threats on networks. The Federal government calls this program Continuous Diagnostics and Mitigation (CDM). This major acquisition has had its challenges, but it is fundamentally sound in attempting to deploy network sensor and dashboard technologies that can provide cyber professional with the tools to see malicious activity and move swiftly to mitigate and bounce back from any damage that is caused.
Build the cyber workforce of the future
Many of the recommendations for improving government and corporate cybersecurity in the future will be moot if we don’t get serious about creating a qualified cybersecurity workforce. It is clear that nationally we need to be more determined in creating a cyber talent pipeline. There are some very good ad hoc efforts underway, yet scale and coordination are lacking. With the demand so high and the mission so important, we must find a more comprehensive way to work with community colleges and universities to set standards and curriculum that will train the next generation of cyber professionals in the mission critical skillsets. The DHS CyberSkills Task Force recommendations are a good roadmap to make this happen (CyberSkills Task Force Report – Homeland Security).
It is often observed that there is no magic bullet that will guarantee your organization won’t fall victim to a cyber-attack in the coming year. It largely becomes a factor of effective risk management. The question for leaders in both the public and private sector is “Have you taken the necessary steps to limit your cyber exposure by deploying an effective, layered approach to data and network security?” Let’s hope the answer is yes in 2016.
Chris Cummiskey is the CEO of MarkAny Cyber, a former acting under secretary for management at DHS and a senior fellow with the George Washington University Center for Cyber and Homeland Security.
Moving the needle on cyber in 2016




