Cybersecurity Needs Its Own CDC

How to understand your data
Aug. 28 2014 3:30 PM

Unreadiness Team

Let’s start treating cybersecurity like we treat public health.

(Continued from Page 1)

In February, a Senate report described a number of security breaches that pose a threat to American citizens. Hackers stole data on our weakest dams, including those that could kill someone if they failed. They used the Emergency Broadcast System to broadcast zombie attack warnings—which might be funny if it didn’t underscore how vulnerable that system is to intruders. Even the National Institute of Standards and Technology got hacked, and its database of known software vulnerabilities was offline for days.

All of these agencies have their own internal auditors and inspectors general investigating their systems. In October 2012, the Department of Energy’s inspector general reviewed the Western Area Power Administration, which has oversight for 15 central and western states. The audit found that “nearly all” of the 105 computers tested needed to be patched. One of the servers was still using a default name and password, which “could have allowed an attacker with an Internet connection to obtain unauthorized access to an internal database supporting the electricity scheduling system.” Just a few months ago, hackers infiltrated the DOE and stole data on 100,000 people. The IG blamed that theft on outdated software. It turns out that an upgrade had been purchased; it was just never installed.

The DOE is just one agency. There are audits that reveal similarly troubling findings for other groups, including the IRS, the Nuclear Regulatory Commission, and the Department of Education.

Advertisement

My point is that government administrators in cybersecurity aren’t as effective if they haven’t been in the trenches fighting hackers. Maybe those DOE patches weren’t made because they seemed like those run-of-the-mill Windows updates on our home computers that we like to ignore. Leaders without technical experience and knowledge aren’t equipped to ask their staff important questions or make good proactive decisions. There’s just too much changing every day for a non-expert to be at the helm. As hackers poke holes in our existing tools, they reveal new vulnerabilities in our operating systems, our Internet browsers, our databases and servers. Rarely does any digital tool operate completely independently, which means that when one company releases an update, it may cause problems for the ancillary services it uses. An example: A browser might change its settings, causing a few lines of code on a banking website to behave differently. If left unchecked, that could potentially expose a user’s account information to hackers.  

Consumers are buying and using technology at an unprecedented rate, and they don’t fully understand how the new digital equipment and tools they’re using can be compromised. At some point, there were government employees assigned to write, edit, approve, and post the 48 PDFs on US-CERT’s website. If someone thought it was important enough to create those documents, shouldn’t it be just as important to make sure that content is current? Maintaining a bunch of PDFs isn’t US-CERT’s main function, of course, but part of its charge is to keep the public informed—and if US-CERT can’t help consumers learn how to fend off cyberattacks, some other agency should take the helm and wage a comprehensive publicity campaign.

It’s time to treat our digital ecosystem the way we do public health. The solution is an agency staffed by cybersecurity experts who understand the delicate balance between national security and personal privacy. They must create protocol that’s proactive and have the authority to enact it. There should be a unified process in place for threats to critical infrastructure, one for which all private contractors receive ongoing training. Currently, there is no single organization that’s aware of all the cyber-related research and development work being funded by the government. An agency should be responsible for coordinating that research, making sure it’s not redundant across agencies and can actually be used.

Some of these ideas have already been articulated as part of the White House’s Comprehensive National Cybersecurity Initiative. It’s a well-crafted government report, with a lot of acronyms and official names. But the layers of offices and task forces and teams involved are a tangled mess compared with how hackers operate. In their world, they operate alone or in clusters. They’re nimble and fast. And they can cause havoc in an instant.

Amy Webb writes a column about data for Slate. She's the head of Webbmedia Group, a digital strategy agency, the author of Data, A Love Story and the co-founder of Spark Camp.

TODAY IN SLATE

Politics

Blacks Don’t Have a Corporal Punishment Problem

Americans do. But when blacks exhibit the same behaviors as others, it becomes part of a greater black pathology. 

I Bought the Huge iPhone. I’m Already Thinking of Returning It.

Scotland Is Just the Beginning. Expect More Political Earthquakes in Europe.

Lifetime Didn’t Think the Steubenville Rape Case Was Dramatic Enough

So they added a little self-immolation.

Two Damn Good, Very Different Movies About Soldiers Returning From War

Medical Examiner

The Most Terrifying Thing About Ebola 

The disease threatens humanity by preying on humanity.

Students Aren’t Going to College Football Games as Much Anymore, and Schools Are Getting Worried

The Good Wife Is Cynical, Thrilling, and Grown-Up. It’s Also TV’s Best Drama.

  News & Politics
Weigel
Sept. 19 2014 9:15 PM Chris Christie, Better Than Ever
  Business
Business Insider
Sept. 20 2014 6:30 AM The Man Making Bill Gates Richer
  Life
Inside Higher Ed
Sept. 19 2014 1:34 PM Empty Seats, Fewer Donors? College football isn’t attracting the audience it used to.
  Double X
The XX Factor
Sept. 19 2014 4:58 PM Steubenville Gets the Lifetime Treatment (And a Cheerleader Erupts Into Flames)
  Slate Plus
Slate Picks
Sept. 19 2014 12:00 PM What Happened at Slate This Week? The Slatest editor tells us to read well-informed skepticism, media criticism, and more.
  Arts
Brow Beat
Sept. 19 2014 4:48 PM You Should Be Listening to Sbtrkt
  Technology
Future Tense
Sept. 19 2014 6:31 PM The One Big Problem With the Enormous New iPhone
  Health & Science
Medical Examiner
Sept. 19 2014 5:09 PM Did America Get Fat by Drinking Diet Soda?   A high-profile study points the finger at artificial sweeteners.
  Sports
Sports Nut
Sept. 18 2014 11:42 AM Grandmaster Clash One of the most amazing feats in chess history just happened, and no one noticed.