Doubts abound over US action on cybersecurity

States may have to take the lead as the federal government lags on cybersecurity, a governor said

IDG

IDG

How should the U.S. respond to cyber attacks? That’s been a major question at this year’s RSA security conference, following Russia’s suspected attempt to influence last year’s election.

Clearly, the government should be doing more on cybersecurity, said U.S. lawmakers and officials at the show, but they admit that politics and policy conflicts have hampered the government's approach. 

“I wish the federal government could do this, but it’s very hard, unfortunately, due to partisan politics,” said Virginia State Governor Terry McAuliffe, during a speech at the show. “They haven’t been able to take the lead on this issue as they should have.”

Instead, it might be up to the states to assume a larger role in promoting cybersecurity, given that divisive U.S. politics at the federal level have been stalling government action, McAuliffe said on Tuesday.

RSA conference 2017 Michael Kan

The RSA conference 2017.

Collectively, state governments store more data than the federal government, including residents' tax returns, healthcare records and drivers’ licenses, he said. That can make them targets of hackers, so McAuliffe has been urging other states to make cybersecurity a priority.

“It’s up to the governors of this country to lean in and take the lead,” he said.

At the RSA show, U.S. Representative Michael McCaul also spoke and said the U.S. is falling behind on cybersecurity, pointing to the numerous hacks from state-sponsored hackers. “We are in the fight of our digital lives and we are not winning,” he said.

McCaul, who also chairs the House committee on Homeland Security, said Russia’s suspected involvement in influencing last year’s election was a “wake up call.” But he was disappointed with the responses from the  administration of President Barack Obama and Donald Trump, then a presidential candidate,  to the Kremlin’s alleged meddling.

“If there are no consequences for bad behavior, the bad behavior will continue,” he said. “Unfortunately, we still do not have a clear proportionate response, policies for striking back.”

However, actually coming up with a U.S. doctrine on stopping serious cyber attacks is easier said than done.

“One of the big questions out there is what is an act of war in cyberspace?” said Daniel Lerner, a staff member at the U.S. Senate committee on Armed Services, who also spoke at the show.

Currently, the U.S. treats every serious cyberattack on a case-by-case basis, which does little to dissuade the state-sponsored hackers from attacking in the first place, he said.  

“That’s no way to project deterrence. And it really undermines our overall security posture, if every instance is a crisis,” Lerner said.

It doesn’t help that trying to accurately prove a foreign country was behind a cyberattack can be incredibly hard and might involve sensitive intelligence.

For instance, U.S. intelligence agencies have declined to share publicly classified evidence showing why they suspect Russia was behind last year’s election-related hacks. In addition, the Kremlin has denied any involvement.

Nevertheless, more officials in the U.S. government want to see the country take action in the event of another cyberattack, said Brendan Shields, staff director at the House committee of Homeland Security.

“The fuse is getting shorter and shorter,” he said at a panel discussion at RSA. “I think there is a growing desire for making sure deterrence is real.”

terry Michael Kan

Virginia state governor Terry McAuliffe (left) speaking at the RSA conference.

However, going after state-sponsored hackers is only one aspect of the problem. Much more of it has to do with defense, and protecting users from hacking threats that are coming over consumer-made products or websites.

It’s an area where the private sector also needs to play a crucial role, given that IT vendors have most of the cybersecurity talent, said the Virginia governor.

“We need your ideas. We need the private sector,” McAuliffe said. “We at the state government cannot drive this. The federal government cannot drive this.”

Join the PC World newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Michael Kan

IDG News Service
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Armand Abogado

HP OfficeJet 250 Mobile Printer

Wireless printing from my iPhone was also a handy feature, the whole experience was quick and seamless with no setup requirements - accessed through the default iOS printing menu options.

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?