60 Minutes Report about Cyber War, but Still No Cyber Czar

Probably everyone who watched the recent 60 Minutes story entitled “Cyber War: Sabotaging the System” was not surprised by any aspect of the story. The report is old news, but unsettling particularly following President Obama’s presentation of his “Cyber Policy Review.” The White House vowed to take the lead in protecting the US. However apparently no one will take the new job of Cyber Czar. Senator Susan Collins recommends that the Cyber Czar be at the Department of Homeland Security rather than the White House where she speculates that the Cyber Czar would be ineffective.

Alarming Headline: Eight indicted for $9 million hack

No one is really surprised by this recent headline that 8 individuals (at least three of whom were in Estonia, Russia, and Moldova) were indicted in a $9 million hack within 12 hours after breaking into a computer network operated by credit-card processing vendor RBS WorldPlay. Allegedly counterfeit debit “cards were used to withdraw more than $9 million from more than 2,100 ATMs in about 280 cities worldwide, including cities in the U.S., Russia, Ukraine, Estonia, Italy, Hong Kong, Japan and Canada.”

Daily Computer and Internet Threats

In the meantime headline after headline show how vulnerable our computer networks and the Internet are, but to add more complications the federal government also has budget restraints. Clearly we have to improve the protection our financial and defense systems. Without question the public deserves better than what’s going on now. Something has to change otherwise everyone is at risk. However just appointing a person as Cyber Czar is not enough, as it will take commitments from governments around the world. Computer and Internet crime is not new, but it's time to get control over it because it seems we are more vulnerable than ever!

 

 

 

Cyber Security Is Critical - But No One Wants to be Cyber Czar!

In May when President Obama released a 40 page “Cyberspace Policy Review” it seemed pretty clear that the appointment of a Cyber Czar was imminent, however recent reports are that no one wants the job! In spite of three-year study report from the National Academy of Sciences that stated that the US was not Cybersafe released a few weeks before the President released his “Review”, we still cannot find a Cyber Czar. Without question Cyber Czar is a great title, but the individuals who turned down the job had good reasons which include a lack of clarity about how much power the new job would really have and to whom the Cyber Czar would report.

Shortage of Cyber Experts

While Cyber attacks persist we just got a report from the US government that there is a shortage of Cyber experts which only makes things worse. Because many of the Cyber expert jobs in the US government are classified and what job titles these people vary, it is not clear how many individuals are employed in this arena. However the Pentagon claims to have more than 90,000 individuals involved with Cyber security, and there are estimates of up to 45,000 other non-defense Cyber security workers. But yet there is a shortage given of the scope of these cyber attacks.

Our Future’s At Stake

In May the President stated that “America economic prosperity in the 21st century will depend on cybersecurity,” but not much progress has been made. Clearly it’s time the President to give the new Cyber Czar clarity on the job’s power and reporting authority. The US needs a Cyber Czar to take a leadership role. The world has become dependent on the Internet and as a result it is essential that we have adequate Cyber security to protect the economy now and in the future.
 

 

 
 

 

Privacy - More Congressional Questions

The US Congress is asking more questions about consumer privacy and email collection/surveillance at a time when President Obama is highlighting cybersecurity. So when asked about consumer’s opt-out from personal data collection, Yahoo! privacy chief’s admitted that fewer than 1% opted-out and Google’s deputy general counsel didn’t even know how many users opted-out. Of course the primary reason virtually no one chooses the opt-out is a lack of understanding about much privacy individuals actually have on the Internet and a false sense of security and privacy.
 

Behavior Advertising

A recent privacy blog discussed the February 2009 Federal Trade Commission Staff Report entitled “Self-Regulatory Principles For Online Behavioral Advertising,” and the opt-out questions posed by Congress are at the heart of whether new Internet privacy laws are required. The Internet economy, and certainly Google is chief example, are dependent upon the current behavioral advertising model and surely will be impacted by a change in the privacy laws in the US.

eMail Surveillance

Most US citizens believe that their emails are private. However employee privacy regarding emails in the workplace (not personal webmail) may be misplaced since in the US emails are private to employers and in the EU, Canada, and other countries emails are private to the employees. Nevertheless there are more questions being asked in Congress about how many e-mails are being collected in the name of security. The recent report that National Security Agency exceed its authority by intercepting emails and phone calls continues to be debated in Congress. Given President Obama’s cybersecurity agenda it will be interesting to see how the US congress can reconcile the expectation of personal privacy and need for Internet security. These debates will continue as the Internet evolves. Stay tuned for more.
 

President Obama: "America's economic prosperity in the 21st century will depend on cybersecurity"

When President Obama spoke about cybersecurity last week the Whitehouse also released a 40 page “Cyberspace Policy Review” that included a thorough analysis concluding that the world’s economy is dependence on the Internet. The Cyberspace Policy Review reinforced my Five Big Bang Theory of the Internet and is detailed in an Appendix (see chart below) which includes a reminder to the US about the October 1957 launch of Sputnik got the US started on its space race. Sputnik led President Kennedy to his 1961 promise to put a person 'on the moon by the end of the decade.’ President Kennedy’s promise directly led to funding of DARPA in 1962 that started to the Internet.

 

 

How Secure is the Internet?

Recent blogs questioning the state of Internet security and how well the US manages cybersecurity reinforce the need for an improvement in cybersecurity not only by the US, but other countries around the world. To improve cybersecurity countries around the world will have to unite, it is not possible for the US to succeed without partnerships with its allies which is stressed in the Cyberspace Policy Review. Last year there were reports that the Russian Business Network hijacked the websites of the Georgian government, and there continue to be headlines in that vein with militants and countries with political unrest.

Partnerships Required

The Cyberspace Policy Review makes the point that partnerships of all sorts are required between federal, state, and local governments, as well as private enterprise. Ironically enough the Cyberspace Policy Review points out that most of the Internet infrastructure is owned by private enterprise for commercial reasons. Accordingly if the new cybersecurity plans are to be successful surely all the players will have to work together as partners. Appointing a Cybersecurity Czar will not solve the problems identified in the Cyberspace Policy Review, rather hopefully the Cybersecurity Czar will allow the US to focus energies to help protect the Internet and its infrastructure.