<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet media="screen" type="text/xsl" href="https://one.sightlinemg.com/federaltimes/wp-content/themes/smg/assets/xslt/rss-xslt.xml"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
xmlns:news="http://www.pugpig.com/news"
>

<channel>
	<title>Federal Times - Federal Times</title>
	<atom:link href="https://one.sightlinemg.com/federaltimes/smr/rsa/feed/" rel="self" type="application/rss+xml" />
	<link>https://one.sightlinemg.com/federaltimes/</link>
	<description>Federal Times</description>
	<lastBuildDate>Sat, 08 Aug 2026 04:58:48 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://one.sightlinemg.com/wp-content/uploads/2026/06/favicon-fed.png?w=32</url>
	<title>Federal Times - Federal Times</title>
	<link>https://one.sightlinemg.com/federaltimes/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">255331619</site><atom:link rel="next" type="application/rss+xml" href="https://one.sightlinemg.com/federaltimes/feed/?paged=2" />
	<item>
		<title>RSA takeaway: Defenders are (over) confident</title>
		<link>https://one.sightlinemg.com/federaltimes/management/2016/03/09/rsa-takeaway-defenders-are-over-confident/</link>
					<comments>https://one.sightlinemg.com/federaltimes/management/2016/03/09/rsa-takeaway-defenders-are-over-confident/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Wed, 09 Mar 2016 16:46:07 +0000</pubDate>
				<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[Show Reporters]]></category>
		<category><![CDATA[Special Multimedia Reports]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/03/09/rsa-takeaway-defenders-are-over-confident/</guid>

					<description><![CDATA[In cybersecurity, both the attackers and defenders think they have an edge. They can't both be right.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/management/2016/03/09/rsa-takeaway-defenders-are-over-confident/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">12776</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635931206284902578-1200px-cole-thomas-the-course-of-empire-destruction-1836jpg.jpg" width="1200" height="744" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">It&#8217;s not that either side lacks it. But the difference in the overall message at Black Hat — a conference for hackers — and RSA — an event for defenders — illustrates the disconnect between the two halves of the cybersecurity community: both believe they&#8217;re winning.</p>



<p class="wp-block-paragraph">That&#8217;s not to say the defenders don&#8217;t see the enormity of the challenge they face.</p>



<p class="wp-block-paragraph">Phyllis Schneck, deputy undersecretary for cybersecurity and communications for Homeland Security&#8217;s National Protection and Programs Directorate, said one of the hardest problems is clearing &#8220;some of the ridiculous noise out of the Internet,&#8221; separating the run-of-the-mill attacks from the advanced threats.</p>



<p class="wp-block-paragraph">The first goal of the defender is &#8220;to make it less easy for the adversary so that we can start to hunt and find the really sophisticated stuff,&#8221; <a href="http://www.federaltimes.com/story/government/show-reporter/rsa2016/2016/03/03/dhs-malware-provenance/81268928/">she said</a>. This was immediately followed with, &#8220;Game on.&#8221;</p>



<p class="wp-block-paragraph">Similarly, Defense Secretary Ash Carter announced a new bug bounty program for the Pentagon, opening its networks to white hat hackers. While this is becoming an industry standard, for the Department of Defense — which, by its nature tends to take a more conservative position on these sorts of things — inviting this level of scrutiny feels like a bold move. (One I applaud them for making.)</p>





<p class="wp-block-paragraph">During a <a href="http://www.federaltimes.com/story/government/show-reporter/rsa2016/2016/03/03/nsa-automating-cybersecurity/81276640/">panel espousing the effectiveness of automation</a> — another worthy endeavor — National Security Agency Special Assistant to the Director for Cyber Philip Quade cited an agency facing a billion incidents each day. By automating significant parts of the detection and mitigation process, the agency was able to go from resolving a few dozen incidents a day to tens of thousands. That&#8217;s a huge leap, for sure, but &#8220;tens of thousands&#8221; still doesn&#8217;t come close to &#8220;a billion.&#8221; <a href="https://en.wikipedia.org/wiki/Cassandra#Family_and_gift_of_prophecy">Cassandras</a>&#8220;The barbarians are at the gates,&#8221; he said. Though what&#8217;s worse, today, &#8220;There aren&#8217;t any gates.&#8221;</p>



<p class="wp-block-paragraph">But everyone at the conference recognized the threat is real. And maybe some over-confidence — a little swagger — isn&#8217;t such a bad thing, so long as you can face down the horde when it comes knocking.</p>
]]></content:encoded>
	</item>
		<item>
		<title>5 cybersecurity lessons from ancient battles</title>
		<link>https://one.sightlinemg.com/federaltimes/smr/rsa/2016/03/04/5-cybersecurity-lessons-from-ancient-battles/</link>
					<comments>https://one.sightlinemg.com/federaltimes/smr/rsa/2016/03/04/5-cybersecurity-lessons-from-ancient-battles/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Fri, 04 Mar 2016 21:08:50 +0000</pubDate>
				<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[Show Reporters]]></category>
		<category><![CDATA[Special Multimedia Reports]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/03/04/5-cybersecurity-lessons-from-ancient-battles/</guid>

					<description><![CDATA[Tips gleaned from the great generals and battles of the ancient world.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/smr/rsa/2016/03/04/5-cybersecurity-lessons-from-ancient-battles/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">14560</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635927044400971412-geersjpg.jpg" width="3264" height="2448" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Cybersecurity is the freshest thing out there. Few fully understand it but everyone now knows how important it is. But just because it&#8217;s new doesn&#8217;t mean lessons from the past can&#8217;t be applied.</p>



<p class="wp-block-paragraph">That was the thrust of a presentation by ZeroFOX head security writer Spencer Wolfe and NATO Ambassador to the Cooperative Cyber Defense Centre of Excellence Kenneth Geers at this year&#8217;s RSA Conference in San Francisco.</p>



<p class="wp-block-paragraph">Wolfe set up the conversation, offering five important lessons from the major battles that shaped the ancient western world, from the rise of Greece to the fall of Rome. Geers followed up each lesson with how it applies to the modern world of cybersecurity.</p>



<p class="wp-block-paragraph"><strong>Lesson 1: Choose your battlefield.</strong></p>



<p class="wp-block-paragraph">The first lesson was taken from two of the most iconic and important battles of all time: the Grecian defense against the Persians at Thermopylae and Salamis.</p>



<p class="wp-block-paragraph">In both battles, Greek forces held off significantly larger and better resources attackers by picking the best locations available. The Greeks knew their home turf and led the Persians into traps.</p>



<p class="wp-block-paragraph">Similarly, an adversary might make initial inroads in an attack but a smart defense will leave them chasing their tails.</p>



<p class="wp-block-paragraph">&#8220;As you architect your cyber defense, you should think in terms of traps, in terms of tricks, in terms of a unique style that no one has ever seen before,&#8221; Geers said. &#8220;Present the hacker with something that is a challenge because from the hacker perspective, your network is a black box.&#8221;</p>



<p class="wp-block-paragraph"><strong>Lesson 2: Be original.</strong></p>



<p class="wp-block-paragraph">Later in Grecian history, the city-states often warred with each other, often using the same phalanx battle technique, with thin lines and the strongest troops positioned on the right side of the formation. However, during the battle of Leuctra, Theban general Epaminondas turned that tactic upside down, putting his best troops head-to-head with the strongest Spartan units on the field.</p>



<p class="wp-block-paragraph">&#8220;The left side goes forward, meets the Spartans best troops and are able to break them … and of course when you see your best troops defeated and fleeing, the rest of the army folds,&#8221; Wolfe explained.</p>



<p class="wp-block-paragraph">&#8220;Pitched battles and cybersecurity are games of wit,&#8221; he said. &#8220;Originality is your ace in the hole.&#8221;</p>



<p class="wp-block-paragraph"><strong>Lesson 3: Know thy enemy.</strong></p>



<p class="wp-block-paragraph">Wolfe broke from the western-theme briefly to quote Sun Tzu, the famous Chinese philosopher who wrote &#8220;The Art of War.&#8221;</p>



<p class="wp-block-paragraph">&#8220;If you know your enemies and yourself, you will not be imperiled in a hundred battles,&#8221; Sun Tzu wrote. &#8220;If you neither know your enemies nor yourself, you will be imperiled in every single battle.&#8221;</p>



<p class="wp-block-paragraph">Wolfe pointed to Phillip II, father of Alexander the Great, as a perfect example of this tactic.</p>



<p class="wp-block-paragraph">Phillip faced four major powers in his quest to conquer and unite the Greeks: the Paionians, Thracians, Dardanians and Athenians. Knowing he couldn&#8217;t take on all four at once, Phillip bought off the first two and married a Dardanian princess, enabling him to focus on defeating Athens.</p>



<p class="wp-block-paragraph">Today, Geers said understanding the common thread in major cyber incidents can help defenders understand the enemy.</p>



<p class="wp-block-paragraph">He pointed to Russia as the one to watch, as the country has been at the center of most major incidents since the 1980s. Knowing the kind of attack vectors and intent of the attackers will help defenders anticipate the next incident and mitigate the effects.</p>



<p class="wp-block-paragraph"><strong>Lesson 4: Lead from the front.</strong></p>



<p class="wp-block-paragraph">Phillip&#8217;s son, Alexander the Great, surpassed even his father to become one of the greatest generals of all time. One of the reasons for his success was the unwavering support from his troops, largely due to his prowess as a general but also because he led them into battle from the front lines.</p>



<p class="wp-block-paragraph">In modern times, we&#8217;ve gone from &#8220;Alexander the Great to Alexander the Geek,&#8221; Geers said, referring to former NSA and CyberCOM Director Gen. Keith Alexander.</p>



<p class="wp-block-paragraph">Under his tenure, U.S. warfare took on a cyber element as never before.</p>



<p class="wp-block-paragraph">&#8220;He oversaw the rapid expansion of cyber integration into signals intelligence,&#8221; Geers said. &#8220;Such that now if Seal Team Six goes into Libya, they not only have air cover but they have cyber cover taking them in and protecting them.&#8221;</p>



<p class="wp-block-paragraph"><strong>Lesson 5: Fight fire with fire.</strong></p>



<p class="wp-block-paragraph">The final lesson was taken from one of Rome&#8217;s greatest defeats: the Battle of Cannae, in which the Carthaginians slaughtered the Roman army. Carthage used advanced maneurvering to flank the Romans on both sides, enveloping the army and closing off their retreat, Wolfe explained.</p>



<p class="wp-block-paragraph">As the Punic Wars raged on, Roman general Scipio learned from that defeat and used the same tactics against the Carthaginians in the Battle of Ilipa 12 years later to great effect.</p>



<p class="wp-block-paragraph">&#8220;The lesson here is not only to think like the enemy but also to act like them,&#8221; Wolfe said. &#8220;Act like a hacker. You have to both think and act like the adversary to understand the threat that&#8217;s coming in.&#8221;</p>



<p class="wp-block-paragraph"><strong>Conclusion: The modern perimeter.</strong></p>



<p class="wp-block-paragraph">Wolfe wrapped up the presentation with a look ahead — namely the security issues posed by the widening perimeter caused by the spread of BYOD and the Internet of Things.</p>



<p class="wp-block-paragraph">&#8220;The barbarians are at the gates and, unfortunately, there aren&#8217;t any gates,&#8221; he said. &#8220;The perimeter is that thin.&#8221;</p>
]]></content:encoded>
	</item>
		<item>
		<title>Suzanne Spaulding on why DHS is at RSA</title>
		<link>https://one.sightlinemg.com/federaltimes/smr/rsa/2016/03/04/suzanne-spaulding-on-why-dhs-is-at-rsa/</link>
					<comments>https://one.sightlinemg.com/federaltimes/smr/rsa/2016/03/04/suzanne-spaulding-on-why-dhs-is-at-rsa/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Fri, 04 Mar 2016 01:09:25 +0000</pubDate>
				<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[Show Reporters]]></category>
		<category><![CDATA[Special Multimedia Reports]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/03/04/suzanne-spaulding-on-why-dhs-is-at-rsa/</guid>

					<description><![CDATA[Homeland Security's head of NPPD explains why the agency goes to conferences like RSA and what she's learned this year's event.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/smr/rsa/2016/03/04/suzanne-spaulding-on-why-dhs-is-at-rsa/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">23056</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635926324390625327-dhs-suzanne-spaulding-synced-sequence00-00-53-25still001jpg.jpg" width="1920" height="1080" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph"><em>Federal Times caught up with Suzanne Spaulding, Homeland Security undersecretary for the National Protection and Programs Directorate, while at the 2016 RSA Conference to talk about why she and other feds made the trek out to San Francisco, what they&#8217;re learning at the show and what they want to say to industry.</em></p>



<iframe allowfullscreen="true" frameborder="0" src="/embed/player?filmId=00000155-ee7d-d761-a955-efff05350000&amp;autoplay=false"></iframe>



<p class="wp-block-paragraph"><strong>Why does DHS go to big cybersecurity conferences like RSA?</strong></p>



<p class="wp-block-paragraph">We thought it was really important for the Department of Homeland Security to be here. For a number of years now we&#8217;ve been coming to this conference and we do so for a number of reasons.</p>



<p class="wp-block-paragraph">One is to make sure we understand the innovation and the trends that are happening in this very important area of cybersecurity solutions and cybersecurity technology because we need to benefit from that innovation and that technology.</p>



<p class="wp-block-paragraph">It&#8217;s also important to us that the folks out here and across the country that are working in that innovative field understand what we do and the role of the department in protecting particularly the .gov space but also working to protect critical infrastructure and private sector cybersecurity.</p>



<p class="wp-block-paragraph">And then, third, we&#8217;d like to recruit some more of the best and the brightest to fill our ranks.</p>





<p class="wp-block-paragraph"><strong>What trends have you seen at the conference so far that have piqued your interest?</strong></p>



<p class="wp-block-paragraph">There are all kinds of things that are happening out here that are very interesting to us and important to us. We have developed for the .gov space an important platform called Einstein that we hope to continue to build by adding innovation, innovative products and developments from the private sector.</p>



<p class="wp-block-paragraph">Similarly, out Continuous Diagnostics and Mitigation program, which looks at the health of the network and who&#8217;s on the network from the inside is really bringing into the government technologies and products produced by the private sector.</p>



<p class="wp-block-paragraph">So the kinds of things folks are talking about out here — the innovative approaches to achieving scale, for example, how do we make sure the things we&#8217;re doing we can do on a scale that matches our adversary; the speed with which our adversary is moving; the ways in which we have to be able to learn, do machine learning; be able to recognize things we&#8217;ve never seen before. This is work that we&#8217;re undertaking at the department and we&#8217;re benefiting from some of the innovation out in the public sector.</p>



<p class="wp-block-paragraph"><strong>What are you telling industry while you&#8217;re here?</strong></p>



<p class="wp-block-paragraph">We want industry to know that we are very interested in not competing with the private sector. But in collaborating with the private sector — mostly in benefiting from the kinds of innovation and technology that&#8217;s being developed out here.</p>



<p class="wp-block-paragraph">We want to make sure they understand the challenges we&#8217;re seeing in trying to bring both tools and techniques to the civilian government space but also in helping the private sector do better risk management.</p>



<p class="wp-block-paragraph">And I&#8217;m pleased to see out here that there&#8217;s a lot of talk about the recognition of the need to move to a risk approach and a mission-based approach to cybersecurity.</p>



<p class="wp-block-paragraph"><strong>How do you motivate people to join the government when the private sector offers much higher salaries?</strong></p>



<p class="wp-block-paragraph">In terms of building the cyber workforce, I&#8217;ve been talking for some time now with my colleagues in the private sector about working together to both put resources into building that pipeline. Going to colleges and universities to make sure that we&#8217;re appealing to students to go into cybersecurity but also providing some resources to help there.</p>



<p class="wp-block-paragraph">The deal that I make with the private sector is: I&#8217;ll hire them right out of school and we&#8217;ll give them on-the-job training for a few years, then you lure them away with a bigger salary, more money. And then when they&#8217;ve put their kids through college, they&#8217;ll miss the mission and they&#8217;ll come back to us.</p>



<p class="wp-block-paragraph">That&#8217;s the way we&#8217;re going to have to begin to think about our workforce, which is different for the government. Not getting someone in and keeping them for an entire 30- or 40-year career.</p>
]]></content:encoded>
	</item>
		<item>
		<title>Infographic: Evolution of info sharing</title>
		<link>https://one.sightlinemg.com/federaltimes/smr/rsa/2016/03/03/infographic-evolution-of-info-sharing/</link>
					<comments>https://one.sightlinemg.com/federaltimes/smr/rsa/2016/03/03/infographic-evolution-of-info-sharing/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Thu, 03 Mar 2016 23:53:47 +0000</pubDate>
				<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[Show Reporters]]></category>
		<category><![CDATA[Special Multimedia Reports]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/03/03/infographic-evolution-of-info-sharing/</guid>

					<description><![CDATA[Infographic depicts how cyber information sharing has developed over time and where it's going.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/smr/rsa/2016/03/03/infographic-evolution-of-info-sharing/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">14441</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635926278948141391-evolution-of-info-sharingjpg.jpg" width="960" height="539" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">During a discussion with NSA and Homeland Security officials on the importance of automating cybersecurity, Philip Quade, special assistant to the director of NSA for cyber, offered an infographic showing the evolution of information sharing.</p>



<p class="wp-block-paragraph">It starts with sharing information about an incident — just that it took place — and progresses to how the breach was detected, how the damage was mitigated and so on.</p>



<p class="wp-block-paragraph">&#8220;It&#8217;s not just good enough to understand what to look for but what actions you take based on that,&#8221; Quade said.</p>



<p class="wp-block-paragraph">Sharing information about threat vectors, signatures and new malware is an important aspect of a robust cybersecurity posture for any organization. But too much information is almost as useless as none at all.</p>



<p class="wp-block-paragraph">Adding automation to the process — letting computers do the heavy lifting at machine speed — is the answer, according to Quade.</p>



<p class="wp-block-paragraph">&#8220;What we&#8217;re trying to get to is automated decision making with a human above the loop,&#8221; he said. &#8220;It&#8217;s a robot that&#8217;s making the decisions, to take the burden of the minutia off the human being.&#8221;</p>



<p class="wp-block-paragraph">The vendor space hasn&#8217;t quite caught up to that need, he added.</p>



<p class="wp-block-paragraph">&#8220;There are lots of pitchers but not a lot of catchers,&#8221; Quade said, with plenty of tools to transmit threat data but few capable of high-level intake and processing.</p>
]]></content:encoded>
	</item>
		<item>
		<title>4 lessons from NSA on automating cybersecurity</title>
		<link>https://one.sightlinemg.com/federaltimes/smr/rsa/2016/03/03/4-lessons-from-nsa-on-automating-cybersecurity/</link>
					<comments>https://one.sightlinemg.com/federaltimes/smr/rsa/2016/03/03/4-lessons-from-nsa-on-automating-cybersecurity/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Thu, 03 Mar 2016 20:12:44 +0000</pubDate>
				<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[Show Reporters]]></category>
		<category><![CDATA[Special Multimedia Reports]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/03/03/4-lessons-from-nsa-on-automating-cybersecurity/</guid>

					<description><![CDATA[NSA special assistant to the director on cyber Philip Quade offers some lessons-learned to make sure automating incident reporting is a boon instead of a bear.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/smr/rsa/2016/03/03/4-lessons-from-nsa-on-automating-cybersecurity/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">14673</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635926146706405693-quadejpg.jpg" width="3264" height="2448" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Agencies are getting more data on cybersecurity incidents than ever before. But if they can&#8217;t manage the deluge of information coming in, all those tools are useless.</p>



<p class="wp-block-paragraph">Bringing together multiple data sources in a unified system is a lot like conducting a symphony where everyone is using different sheet music. The keys to making it work are automation and orchestration.</p>



<p class="wp-block-paragraph">&#8220;We rely very, very heavily on automation and integration,&#8221; said Philip Quade, special assistant to the director of NSA for cyber.</p>



<p class="wp-block-paragraph">He pointed to a federal agency that was getting hit with more than a billion incidents a day. Prior to automating its security operations, the agency was only able to handle approximately 65 of those a day through manual processes. Additionally, manually reviewing an incident took anywhere from 11 minutes to 11 hours.</p>



<p class="wp-block-paragraph">&#8220;They turned on the COTS [commercial off-the-shelf] secure orchestration and instead of doing 65 events a day, they started doing tens of thousands of them simultaneously,&#8221; Quade said. &#8220;And they were doing that in anywhere from 0.1 seconds and 1 second. They were able to increase security and increase efficiency at the same time.&#8221;</p>



<p class="wp-block-paragraph">Quade offer four lessons the NSA has learned from its efforts to automate its threat identification systems.</p>



<p class="wp-block-paragraph"><strong>Cyber defense means protecting networks inside and out</strong></p>



<p class="wp-block-paragraph">&#8220;We need to have active cyber defenses at the boundaries of our networks,&#8221; Quade said. &#8220;However, boundary defense alone is not sufficient.&#8221;</p>



<p class="wp-block-paragraph">Quade equated it to only focusing on cyber hygiene, which is important but only one aspect of cybersecurity. To have a truly robust security system, defensive tools need to focus on protecting the perimeter as well as the data flowing inside the network.</p>



<p class="wp-block-paragraph"><strong>Orchestrate, don&#8217;t replace</strong></p>



<p class="wp-block-paragraph">Quade noted it isn&#8217;t practical to expect organizations — whether federal agencies or private companies — to replace their entire enterprise architecture just to automate threat detection. Rather, organizations should be looking for orchestration products that can be bolted on to boost security monitoring on existing systems.</p>



<p class="wp-block-paragraph">For NSA, that means having a &#8220;bring your own security enterprise approach,&#8221; he said.</p>



<p class="wp-block-paragraph">&#8220;Whatever products you already have … you need to embrace existing COTS products on your network and get them to work as a team,&#8221; he said.</p>



<p class="wp-block-paragraph"><strong>Products should act as one</strong></p>



<p class="wp-block-paragraph">&#8220;One-off solutions have proven unwieldy,&#8221; Quade said. &#8220;You can&#8217;t expect customers to buy three or four or five, six, twelve different products, each with its own dashboard and figure out a way to manage all those on the enterprise.&#8221;</p>



<p class="wp-block-paragraph">Instead, organizations should look to integrate as many products as possible.</p>



<p class="wp-block-paragraph">&#8220;It&#8217;s all about integration and automation to accommodate security at speed and scale,&#8221; he said.</p>



<p class="wp-block-paragraph"><strong>COTS, meet GOTS</strong></p>



<p class="wp-block-paragraph">Finally, Quade noted the immediate depreciation of products as soon as they&#8217;re developed, a problem that is perhaps most stark when it comes to government off-the-shelf solutions (GOTS).</p>



<p class="wp-block-paragraph">&#8220;GOTS products that the NSA or someone else might advocate … their shelf-life starts ticking down the second they&#8217;re conceived,&#8221; he said. &#8220;What we really need are COTS-based solutions that use standards — an open standards based approach,&#8221; so they can be integrated with new tools as those become available.</p>



<p class="wp-block-paragraph">&#8220;Secure orchestration is a game-changing approach,&#8221; Quade said, so long as it&#8217;s done correctly.</p>



<p class="wp-block-paragraph"><em>Editor&#8217;s Note: A previous version of this story quoted Quade speaking about a specific agency. He actually referred to an unnamed agency CIO. The story has been updated to reflect this.</em></p>
]]></content:encoded>
	</item>
		<item>
		<title>Twitter Tracker: RSA talks IoT, privacy</title>
		<link>https://one.sightlinemg.com/federaltimes/smr/rsa/2016/03/03/twitter-tracker-rsa-talks-iot-privacy/</link>
					<comments>https://one.sightlinemg.com/federaltimes/smr/rsa/2016/03/03/twitter-tracker-rsa-talks-iot-privacy/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Thu, 03 Mar 2016 20:01:25 +0000</pubDate>
				<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[Show Reporters]]></category>
		<category><![CDATA[Special Multimedia Reports]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/03/03/twitter-tracker-rsa-talks-iot-privacy/</guid>

					<description><![CDATA[Meaty panels and insightful keynotes continue at RSA.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/smr/rsa/2016/03/03/twitter-tracker-rsa-talks-iot-privacy/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">20443</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635926139577277862-spauldingjpg.jpg" width="520" height="520" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">As day four of the RSA Conference continues, attendees found still more to talk about on Twitter. Among the topics:</p>



<p class="wp-block-paragraph">1. The Internet of Things is opening a whole new set of complications.</p>



<p class="wp-block-paragraph">2. Medical devices are part of it.</p>





<p class="wp-block-paragraph">3. Why hacking back is a bad idea. (Hint: Legalities.)</p>





<p class="wp-block-paragraph">4. Sometimes you pull one string and unravel a whole ball of twine.</p>





<p class="wp-block-paragraph">5. Divine intervention is a two-edged sword.</p>





<p class="wp-block-paragraph"><em>Want more from RSA? <a href="http://www.federaltimes.com/rsa2016/">See all of our coverage</a>.</em></p>



<figure class="wp-block-embed"><div class="wp-block-embed__wrapper">
<blockquote class="twitter-tweet" data-width="500" data-dnt="true"><p lang="en" dir="ltr">S. Spaulding of <a href="https://x.com/Cyber?ref_src=twsrc%5Etfw">@Cyber</a> would liks to see liability for these <a href="https://x.com/hashtag/IoT?src=hash&amp;ref_src=twsrc%5Etfw">#IoT</a> devices in court. <a href="https://x.com/hashtag/RSAC?src=hash&amp;ref_src=twsrc%5Etfw">#RSAC</a></p>&mdash; National Cybersecurity Alliance (@StaySafeOnline) <a href="https://x.com/StaySafeOnline/status/705428365252161536?ref_src=twsrc%5Etfw">March 3, 2016</a></blockquote><script async src="https://platform.x.com/widgets.js" charset="utf-8"></script>
</div></figure>



<figure class="wp-block-embed"><div class="wp-block-embed__wrapper">
<blockquote class="twitter-tweet" data-width="500" data-dnt="true"><p lang="en" dir="ltr">Medical devices are a risky business. Today at <a href="https://x.com/hashtag/RSAC?src=hash&amp;ref_src=twsrc%5Etfw">#RSAC</a> <a href="https://x.com/ChrisShermanFR?ref_src=twsrc%5Etfw">@ChrisShermanFR</a> will discuss fact from fiction: <a href="https://t.co/tKsniSQcGK">https://t.co/tKsniSQcGK</a></p>&mdash; Forrester (@forrester) <a href="https://x.com/forrester/status/705422616979501056?ref_src=twsrc%5Etfw">March 3, 2016</a></blockquote><script async src="https://platform.x.com/widgets.js" charset="utf-8"></script>
</div></figure>



<figure class="wp-block-embed"><div class="wp-block-embed__wrapper">
<blockquote class="twitter-tweet" data-width="500" data-dnt="true"><p lang="en" dir="ltr">A gentle reminder at <a href="https://x.com/hashtag/RSAC?src=hash&amp;ref_src=twsrc%5Etfw">#RSAC</a>: Hacking back is a bad idea <a href="https://t.co/9M4t9vmUf8">https://t.co/9M4t9vmUf8</a></p>&mdash; Threatpost (@threatpost) <a href="https://x.com/threatpost/status/705180374708654080?ref_src=twsrc%5Etfw">March 2, 2016</a></blockquote><script async src="https://platform.x.com/widgets.js" charset="utf-8"></script>
</div></figure>



<figure class="wp-block-embed"><div class="wp-block-embed__wrapper">
<blockquote class="twitter-tweet" data-width="500" data-dnt="true"><p lang="en" dir="ltr">Tracking one <a href="https://x.com/hashtag/cybercriminal?src=hash&amp;ref_src=twsrc%5Etfw">#cybercriminal</a> led to the discovery of 220K+ more: <a href="https://t.co/vayrbEAR7P">https://t.co/vayrbEAR7P</a>  <a href="https://x.com/hashtag/RSAC?src=hash&amp;ref_src=twsrc%5Etfw">#RSAC</a> <a href="https://t.co/vQEwSw8i4T">pic.twitter.com/vQEwSw8i4T</a></p>&mdash; RSA (@RSAsecurity) <a href="https://x.com/RSAsecurity/status/705455706087006208?ref_src=twsrc%5Etfw">March 3, 2016</a></blockquote><script async src="https://platform.x.com/widgets.js" charset="utf-8"></script>
</div></figure>



<figure class="wp-block-embed"><div class="wp-block-embed__wrapper"><blockquote class="twitter-tweet"><a href="https://twitter.com/sayers_doug/status/705472111704281088">https://twitter.com/sayers_doug/status/705472111704281088</a></blockquote></div></figure>
]]></content:encoded>
	</item>
		<item>
		<title>How big data, info sharing make hackers&#8217; lives harder</title>
		<link>https://one.sightlinemg.com/federaltimes/management/2016/03/03/how-big-data-info-sharing-make-hackers-lives-harder/</link>
					<comments>https://one.sightlinemg.com/federaltimes/management/2016/03/03/how-big-data-info-sharing-make-hackers-lives-harder/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Thu, 03 Mar 2016 17:42:47 +0000</pubDate>
				<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[Show Reporters]]></category>
		<category><![CDATA[Special Multimedia Reports]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/03/03/how-big-data-info-sharing-make-hackers-lives-harder/</guid>

					<description><![CDATA[Top Homeland Security cybersecurity officials explain how understanding where malware comes from can disrupt the attack cycle.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/management/2016/03/03/how-big-data-info-sharing-make-hackers-lives-harder/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">18608</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635884490778814035-phyllis-schneckjpg.jpg" width="640" height="566" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Creating a new piece of malware is easy: Find something that suits your needs, then tweak the code to bypass firewalls and trick anti-virus software. Hackers are doing this everywhere but by analyzing the provenance of code — a broader look at style rather than just substance — defenders are disrupting the reuse cycle and making the adversary&#8217;s life harder.</p>



<p>Thomas Ruoff, director of technology innovation and mission integration for the Department of Homeland Security, likened provenance to a professor trying to determine whether a student actually wrote a paper or <span class="rte rte-comment">whether it was </span>plagiarized it.</p>



<p>By breaking down the code and comparing certain attributes to other forms of known malware<span class="rte rte-comment"> that have been seen before</span>, defenders can identify <span class="rte rte-comment">see </span>patterns<span class="rte rte-comment"> that tell them the signs to watch for</span>. From there, through statistical analysis, they can assign a trust score to the traffic coming from certain sources or bearing certain signatures of malicious intent.</p>



<p class="wp-block-paragraph">While this tactic isn&#8217;t perfect — true zero-days pop up all the time — it is a fast and efficient tool DHS and others are using to identify and block a large swath of attacks, Ruoff said during a panel discussion at the 2016 RSA Conference in San Francisco.</p>



<p class="wp-block-paragraph">&#8220;It enables us to rapidly make a probability [determination] of authorship, probability of intent,&#8221; he said. Furthermore, &#8220;it also allows us to think about the reuse of code and how the actors readily reuse malware, change it a little bit — therefore change the hash — that approach is somewhat nullified if you have to change a tremendous amount of the object to make it not attributable … It means the economics and the sweat equity of the bad guy are changing.&#8221;</p>



<p class="wp-block-paragraph">DHS is working with the FBI, Justice Department, National Security Agency and others to pull in and analyze more code to build better provenance profiles. But, as the private-sector work in this area continues to grow, the government is also looking to industry to provide additional data.</p>



<p>Some of that will come through information sharing — the framework of which is just being established — while other data will be purchased directly from companies trading in threat intelligence, according to Phyllis Schneck, deputy undersecretary for cybersecurity and communications within the DHS National Protection and Programs Directorate<span class="rte rte-comment"> (NPPD)</span>.</p>



<p class="wp-block-paragraph">Using multiple sources of information enables analysts to build a more comprehensive trust score, adding in indicators and knowledge from all angles.</p>



<p class="wp-block-paragraph">Even then, the system is far from perfect. But it is effective at identifying software at the far ends of the spectrum, Schneck said.</p>



<p class="wp-block-paragraph">&#8220;Probabilities on this tend to be very reliable on the good end and on the really bad end and that&#8217;s what we&#8217;re most concerned with. The middle is a science project that we&#8217;re looking at,&#8221; she explained. &#8220;But it&#8217;s the ability to clear some of the ridiculous noise out of the Internet; to make it less easy for the adversary so that we can start to hunt and find the really sophisticated stuff.&#8221;</p>



<p class="wp-block-paragraph">Schneck compared it to a bank robber making a slight costume change and then attempting to rob the same bank. He might not be the smartest robber out there, but he needs to be stopped and this is one way to do it.</p>



<p class="wp-block-paragraph">&#8220;To truly cause pain to this adversary we have to cut the business model and make sure they stop reusing and just tweaking software and they get right back at us and get in,&#8221; she said. Creating a robust provenance and attribution system gives agencies &#8220;the ability to absolutely destroy the model where the adversary simple takes a piece of software and sends it back out again.&#8221;</p>
]]></content:encoded>
	</item>
		<item>
		<title>Carter plugs collaboration between DoD, private sector at RSA</title>
		<link>https://one.sightlinemg.com/federaltimes/management/2016/03/02/carter-plugs-collaboration-between-dod-private-sector-at-rsa/</link>
					<comments>https://one.sightlinemg.com/federaltimes/management/2016/03/02/carter-plugs-collaboration-between-dod-private-sector-at-rsa/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Wed, 02 Mar 2016 22:04:05 +0000</pubDate>
				<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[Show Reporters]]></category>
		<category><![CDATA[Special Multimedia Reports]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/03/02/carter-plugs-collaboration-between-dod-private-sector-at-rsa/</guid>

					<description><![CDATA[Defense Secretary Ash Carter outlined several new paths for Silicon Valley to work with DoD and help the latter become more agile.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/management/2016/03/02/carter-plugs-collaboration-between-dod-private-sector-at-rsa/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">12150</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635925297731571370-carterrsajpg.jpg" width="1024" height="768" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Defense Secretary Ash Carter was at the RSA Conference in San Francisco this week to tout the Defense Department&#8217;s new initiatives meant to spur innovation within the department through collaboration with the private sector.</p>



<p class="wp-block-paragraph">During a fireside chat with Ted Schlein, a general partner at Kleiner Perkins, Caufield &#038; Byers, titled, &#8220;A Conversation on Collaboration Between Silicon Valley and the Department of Defense,&#8221; Carter cited the department&#8217;s new Defense Digital Service, the brand-new Defense Innovation Advisory Board and a satellite office that recently opened in Silicon Valley.</p>



<p class="wp-block-paragraph">All these are intended to bridge the divide between DoD and the private sector and help the former innovate more like the latter.</p>



<p class="wp-block-paragraph">&#8220;Reach out to us,&#8221; Carter said. &#8220;Whether you&#8217;re looking at our problems and offering us a solution; whether you&#8217;re offering your own commitment for a year, six months. We have lots of avenues for you to connect with us and we&#8217;re trying to create more every day.&#8221;</p>



<p class="wp-block-paragraph"><strong>Defense Digital Service</strong></p>



<p class="wp-block-paragraph">The Defense Digital Service — modeled off the U.S. Digital Service and similar teams on the civilian side — is a great way for individuals to test the waters of working at DoD without having to jump all the way in, Carter said.</p>



<p class="wp-block-paragraph">The DDS is designed to be a way for private sector cyber and IT experts to do tours of duty with the DoD for one or two years at a time.</p>



<p class="wp-block-paragraph">&#8220;Come in, work with us … no strings attached,&#8221; Carter said, adding that he would have loved an opportunity like this when he was starting out in the private sector. &#8220;You don&#8217;t have to become part of the government. Come in, try it out, work on an important problem for a year or two, see how you like it.&#8221;</p>



<p class="wp-block-paragraph">After the tour is up, those people can leave to do something new or sign up for public service and continue their work.</p>



<p class="wp-block-paragraph">&#8220;That&#8217;s an example of a people bridge between the innovative sector and the government,&#8221; he said.</p>



<p class="wp-block-paragraph"><strong>Defense Innovation Advisory Board</strong></p>



<p class="wp-block-paragraph">Earlier in the day, news broke that DoD would be establishing an advisory board of tech experts to help advise the secretary and the department.</p>



<p class="wp-block-paragraph">&#8220;This is going to be some people who are the best technical minds who come in and spend some time telling me how we can be more innovative,&#8221; Carter said.</p>



<p class="wp-block-paragraph">That effort will be led by Eric Schmidt, executive chairman of Alphabet (formerly known as Google), who will also be tasked with filling out the board&#8217;s ranks. Carter said he plans to give Schmidt &#8220;substantial latitude&#8221; in those appointments.</p>



<p class="wp-block-paragraph">Once the board is fleshed out, the members will travel to bases and installations around the world to get a sense of how the DoD works and the inherent challenges to innovation.</p>



<p class="wp-block-paragraph">Then, the board will &#8220;tell me how we can do better,&#8221; Carter said.</p>



<p class="wp-block-paragraph"><strong>Silicon Valley Office</strong></p>



<p class="wp-block-paragraph">Carter said the DoD bureau stationed in Silicon Valley is just getting off the ground but he hopes it will be a place where private sector experts can come meet the department one-on-one and find out where they can work together.</p>



<p class="wp-block-paragraph">&#8220;It&#8217;s a place to connect,&#8221; he explained. &#8220;I&#8217;ve given it a very open charter: Just make connections. Make money connections — that is, help people understand the places in the department where they can secure funding for ideas they think are relevant for defense — where they can get to know the programs I&#8217;ve described — like if they want to take a tour of duty — it&#8217;s a place where our people can be and connect with all of you.&#8221;</p>



<p class="wp-block-paragraph">Carter said DoD is still experimenting with the best structure for this office but encouraged anyone with an interest to visit.</p>



<p class="wp-block-paragraph">Ultimately, the branch will be successful so long as it fosters conversations between the sectors.</p>



<p class="wp-block-paragraph">&#8220;Our job is to protect you and we&#8217;d love your help,&#8221; he told the crowd.</p>
]]></content:encoded>
	</item>
		<item>
		<title>Defense Secretary: No backdoors</title>
		<link>https://one.sightlinemg.com/federaltimes/management/2016/03/02/defense-secretary-no-backdoors/</link>
					<comments>https://one.sightlinemg.com/federaltimes/management/2016/03/02/defense-secretary-no-backdoors/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Wed, 02 Mar 2016 21:23:09 +0000</pubDate>
				<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[Show Reporters]]></category>
		<category><![CDATA[Special Multimedia Reports]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/03/02/defense-secretary-no-backdoors/</guid>

					<description><![CDATA[The government’s top defense official told RSA Conference attendees he doesn’t think building backdoors to encryption is the right way forward.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/management/2016/03/02/defense-secretary-no-backdoors/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">15170</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635863794311892536-arm-ausa-carter02jpg.jpg" width="2701" height="1956" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p>People across the U.S. are getting interested in cybersecurity <span class="rte rte-comment">these days </span>as the battle between the FBI and Apple over developing software to crack an iPhone used by a terrorist in the San Bernardino shooting wages on.</p>



<p class="wp-block-paragraph">While the Justice Department and other law enforcement agencies are fully behind the FBI&#8217;s efforts, some in government — like Defense Secretary Ash Carter — aren&#8217;t sure building &#8220;backdoors&#8221; to encryption is a good idea on the whole.</p>



<p class="wp-block-paragraph">While speaking at the RSA Conference in San Francisco, Carter said he wouldn&#8217;t comment on the specific case before the courts. However, in general he said he&#8217;s &#8220;not a believer in backdoors or a single technical approach&#8221; to breaking encryption.</p>



<p class="wp-block-paragraph">The line got a big round of applause from the cybersecurity professionals in the room.</p>





<p class="wp-block-paragraph">For the Department of Defense, &#8220;Data security — including encryption — is absolutely essential for us,&#8221; he said. &#8220;None of our stuff works unless it&#8217;s connected … So we&#8217;re four-square behind strong data security and strong encryption.&#8221;</p>



<p class="wp-block-paragraph">To ensure that this fight doesn&#8217;t lead to problems between the private sector and the government, Carter suggested keeping the lines of communication open and trying to find a way forward in unison.</p>



<p class="wp-block-paragraph">&#8220;It&#8217;s much better if we do it together. That&#8217;s the path we need to be on,&#8221; he said. &#8220;Let&#8217;s be collaborative, let&#8217;s be technical … and innovate our way&#8221; to a solution.</p>



<p class="wp-block-paragraph">If that doesn&#8217;t happen, then the norms might be decided by another country that doesn&#8217;t have American ideals or our best intentions in mind, he added.</p>



<p class="wp-block-paragraph">No matter where the debate goes, however, Carter said the Apple/FBI case shouldn&#8217;t dominate the entire discussion.</p>



<p class="wp-block-paragraph">&#8220;Let&#8217;s recognize that [the encryption debate] is not one case, it&#8217;s many,&#8221; he said.</p>
]]></content:encoded>
	</item>
		<item>
		<title>Explaining cyber to execs: Use fire</title>
		<link>https://one.sightlinemg.com/federaltimes/smr/rsa/2016/03/01/explaining-cyber-to-execs-use-fire/</link>
					<comments>https://one.sightlinemg.com/federaltimes/smr/rsa/2016/03/01/explaining-cyber-to-execs-use-fire/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Tue, 01 Mar 2016 21:50:02 +0000</pubDate>
				<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[Show Reporters]]></category>
		<category><![CDATA[Special Multimedia Reports]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/03/01/explaining-cyber-to-execs-use-fire/</guid>

					<description><![CDATA[Why don’t fires grow out of control and burn down entire cities anymore?]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/smr/rsa/2016/03/01/explaining-cyber-to-execs-use-fire/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">23755</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635924476856024725-john-elliottjpg.jpg" width="520" height="520" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Why don&#8217;t fires grow out of control and burn down entire cities anymore?</p>



<p class="wp-block-paragraph">The question has an answer, and it provides a helpful metaphor to explain core cybersecurity concepts to executives and decision-makers who might not otherwise grasp the technological complexities, said John Elliott, head of information security at the Principality Building Society.</p>



<p class="wp-block-paragraph">Speaking at the RSA Conference, Elliott said that modern firefighting strategy takes a holistic view of the kill chain, creating the ability contain a fire rather than having it blaze from one building to the next — much as effective cybersecurity contains a threat.</p>



<p class="wp-block-paragraph">Elliott said the inspiration for the metaphor was a conversation with a manager who was complaining about the never-ending requests from the information security team to buy new technology that was seemingly unnecessary. When Elliott asked him why the building has fire extinguishers when there hadn&#8217;t been a fire in years, the manager got it.</p>



<p class="wp-block-paragraph">In 1666, the city of London was only about a square mile in area. A fire started in a bakery in the pre-dawn hours, and burned down most of the city. Houses made of wood and straw burned quickly, and the narrow streets and closely packed houses enabled rapid spread.</p>



<p class="wp-block-paragraph">Two hundred years later, much of Chicago burned down, despite having more stone buildings and a greater area. In that case, high winds, blew burning materials into flammable areas.</p>



<p class="wp-block-paragraph">Today though, fire control begins with prevention; when prevention fails, detection systems alert responders to the fire so that response and recovery can happen fast.</p>



<p class="wp-block-paragraph">&#8220;By using fire and people&#8217;s common knowledge of how fire works and spreads, it works really well as a metaphor,&#8221; he said.</p>



<p class="wp-block-paragraph"><em>See all of our <a href="http://www.federaltimes.com/rsa2016/" target="_blank">RSA 2016 coverage here</a>.</em></p>


]]></content:encoded>
	</item>
	</channel>
</rss>
