The New Era of Cyber Risk Governance

The New Era of Cyber Risk Governance

What's next for agencies under the new executive order?

Over the past few years, the U.S. has seen a devastating wave of high-profile security breaches, both in the government and corporate sectors. A report by Privacy Rights Clearinghouse revealed that federal and state government agencies publicly disclosed a total of 203 data breaches over the past five years.

In all, the breaches resulted in nearly 47 million records being stolen, exposed or otherwise compromised. While these figures are significantly less than those reported in the private sector, the issue lies in the type of sensitive information involved in government breaches, and the critical implications of that information falling into the wrong hands. The Justice Department’s recent announcement that Russian cyber terrorists were responsible for the Yahoo breach also sheds new light on the growing magnitude of cyber terrorist activity in the U.S.— and the harsh financial and legal impacts it can have on agency heads and stakeholders.

The growing concerns on cybersecurity haven’t fallen from focus in the executive branch, who, since the Obama Administration, has been casting light on the underlying issues behind the increased cyber vulnerability in the federal realm. The Trump Administration feels, “the executive branch has for too long accepted antiquated and difficult to defend IT and information systems.” Last week, President Trump signed the long-awaited Cybersecurity of Federal Networks Executive Order, which requires all federal government agencies to begin running risk management, reporting, and recovery programs under the NIST Cyber Security Framework (CSF) in hopes to better protect the government from cyber attacks. Under the mandates, agency heads will now be held responsible for damaging data loss during future cyber attacks to their departments.

This executive order marks a dramatic cultural shift in way the federal government looks at cyber security. The key differences between this EO and the actions that the Obama administration took fall in two categories: 1) never has an executive order required all federal agencies to apply NIST’s CSF to their entire organization, and 2) there has never been a mandate that requires agencies to build a comprehensive risk and mitigation report for their organization and then report to the president of the Department of Homeland Security and the director of the Office of Management and Budget. Currently, all federal agencies have their own cybersecurity processes in place to protect their own systems. However, critical information is leaking on a constant basis, and it’s becoming more and more apparent that this is an internal failure and the fault of a serious disconnect between risk assessment at an IT level and the ability to translate the highly technical insights to overall business risk.

Trump’s order mandates that the security of federal agencies has to be controlled on an enterprise level. Instead of building security protocols for specific systems, all people, processes, and policies within the agency must be analyzed and reported. As cybersecurity continues its shift from a strictly IT function to a business function, the federal government is facing conflicting opinions on how best to standardize risk management and reporting processes. The problem is, there is no “one size fits all” solution to preventing cyber risk, which begs the question of whether or not this order will be enough to set a successful framework that can be applied across all agencies – and to adequately protect the entire government network as an autonomous unit.

One of the main critiques against the order is it it may not be comprehensive enough to incite any notable changes and improvements in risk management practices in the government sector. But the executive order’s requirements that agencies meet the hundreds of control points of the NIST CSF means that cyber risk governance is the goal, rather than IT compliance. Drilling down too deep into the choices of technologies and compliance with technical standards is not what is being demanded, and doing so would miss the stated goal of providing an overview of each agency’s cyber risk. But how can the government ensure that agencies are implementing a cyber-conscious culture that encourages the mitigation of risk from the top-down?

The EO directs government action in three key areas under a mandated 90-day deadline: (1) assessing and improving each federal department’s cybersecurity posture; (2) enhancing the nation’s critical infrastructure; and (3) ensuring sure that “the Internet remains open, interoperable, reliable, and secure.” Meeting these criteria is a massive undertaking for federal agencies, who also have an incredible number of third-party networks, contractors/vendors, and employees that now require examination. Not to mention that the stringent deadline is a huge lift for an order that requires a cultural shift down to the DNA level of how agencies view cyber risk.

An undertaking this substantial means significant amounts of automation will be mandatory in order to be compliant, and do so fast. Getting the job done within this timeframe using traditional means of risk assessment and governance will undoubtedly prove challenging. Gone are the days where checking off protocols on a spreadsheet and presenting convoluted statistics and recommendations to agency heads will be enough to effectively mitigate cyber risk. Agencies must now be able to report on their risk in a manner that can be understood by all stakeholders and used to assess the cyber maturity of the government network on a portfolio view – and do so in a timeframe that was once thought impossible. Investing in automated tools that will streamline cyber risk governance and mandatory reporting processes will be an advantage for agencies that do not wish to incur the penalties associated with non-compliance of this new EO. But achieving these mandates will also be an agency-wide effort that requires involvement at all levels to ensure that everyone at an agency – from entry-level to the C-suite – is equipped to identify, assess, and mitigate risk.

The executive order is a step in the right direction for combatting the outbreak of detrimental breaches in the government sector, and points to a positive shift in the way we as a nation are addressing cybersecurity, but that does not mean it will be an easy adjustment. The impacts of the order await to be seen, but one thing we know for certain is that federal agencies will be fighting an uphill battle if they fail to acknowledge risk governance as a team sport and integral piece of an agency’s overall culture and business function.

Featured

  • 91 Percent of Security Leaders Believe AI Set to Outpace Security Teams

    Bugcrowd recently released its “Inside the Mind of a CISO” report, which surveyed hundreds of security leaders around the globe to uncover their perception on AI threats, their top priorities and evolving roles, and common myths directed towards the CISO. Among the findings, 1 in 3 respondents (33%) believed that at least half of companies are willing to sacrifice their customers’ long-term privacy or security to save money. Read Now

  • Milestone Announces Merger With Arcules

    Global video technology company Milestone Systems is pleased to announce that effective July 1, 2024, it will merge with the cloud-based video surveillance solutions provider, Arcules. Read Now

  • Organizations Struggle with Outdated Security Approaches, While Online Threats Increase

    Cloudflare Inc, recently published its State of Application Security 2024 Report. Findings from this year's report reveal that security teams are struggling to keep pace with the risks posed by organizations’ dependency on modern applications—the technology that underpins all of today’s most used sites. The report underscores that the volume of threats stemming from issues in the software supply chain, increasing number of distributed denial of service (DDoS) attacks and malicious bots, often exceed the resources of dedicated application security teams. Read Now

  • Cloud Resources Have Become Biggest Targets for Cyberattacks According to New Research

    Thales recently announced the release of the 2024 Thales Cloud Security Study, its annual assessment on the latest cloud security threats, trends and emerging risks based on a survey of nearly 3000 IT and security professionals across 18 countries in 37 industries. As the use of the cloud continues to be strategically vital to many organizations, cloud resources have become the biggest targets for cyber-attacks, with SaaS applications (31%), Cloud Storage (30%) and Cloud Management Infrastructure (26%) cited as the leading categories of attack. As a result, protecting cloud environments has risen as the top security priority ahead of all other security disciplines. Read Now

Featured Cybersecurity

Webinars

Whitepapers

New Products

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols. 3

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file. 3

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings. 3