newsfilter.io
Conference Presentation, Panel, Fireside Chat

Cyber-Security: Protecting Companies and Citizens From Assault

  • Current Context & Panelists
    • The discussion addresses timely cybersecurity issues including new U.S. legislation, Department of Defense strategies, and the recent penetration of President Obama's emails by Russian hackers.
    • Panelists include Eli Sugarman (Hewlett Foundation), Alex Stamos (Yahoo CISO), Undersecretary Suzanne Spaulding (DHS), Ray Rothrock (Red Seal CEO/Investor), and Susan Gilchrist (Brunswick Group CEO).
    • Stamos notes that top U.S. tech companies already voluntarily share threat intelligence via groups like the Bay Area CISO Council and Facebook's Threat Exchange, rendering some new legislation redundant for them.
    • Rothrock highlights that small companies, which lack internal talent and resources, rely heavily on information sharing and network effects (e.g., Cloudflare's global monitoring) to prevent attacks.
    • Spaulding defines the DHS mission as strengthening the security and resilience of 16 critical infrastructure sectors, often intervening only upon request or when incidents are identified via intelligence partners.
    • Spaulding clarifies that the Department of Defense is engaged only when the President determines civilian resources are insufficient to address a cyber threat, mirroring protocols for physical attacks.
    • DHS legislative strategy focuses on incremental, bipartisan consensus rather than comprehensive bills, seeking targeted liability protections to encourage voluntary information sharing.
    • Susan Gilchrist observes that cybersecurity has risen to the top of board agendas globally, driven by the realization that threats are increasing and CEOs must now own the issue.
    • Gilchrist notes significant cultural and regulatory differences regarding privacy and security between the U.S., Europe, China, and Germany, creating navigation challenges for multinational corporations.
    • Stamos provides the Yahoo example of requiring mobile phone verification for account access to prevent password reuse, noting this creates conflicts for activists in countries where local governments control phone networks.
    • Spaulding emphasizes the need for international collaboration through the National Cybersecurity Communications Integration Center (NKIC) and bilateral CERT interactions, noting that "we are only as strong as our weakest link."
    • Rothrock cites $455 billion in annual U.S. cyber losses (3% of GDP) versus only $71 billion spent on defense, arguing the economics overwhelmingly favor security investment.
    • Rothrock advocates for standardized cybersecurity metrics (similar to credit scores) to help CEOs assess risk and for companies to conduct regular crisis drills to test response plans.
    • Gilchrist warns that breach responses should focus on reputational impact and customer trust rather than purely legal obligations, as customers will ultimately choose companies they trust.
    • Spaulding suggests that the NIST Cybersecurity Framework could eventually help establish a legal "standard of care," potentially increasing tort liability for companies that fail to implement reasonable security measures.
    • Stamos argues against rigid, prescriptive security standards like PCI DSS, noting they create fragile systems where companies aim only for compliance checks rather than actual resilience against dynamic threats.
    • Rothrock points out that static security standards are ill-suited for dynamic networks, suggesting a need for continuous monitoring and automation to detect changes in network topology.
    • Gilchrist notes that 90% of crisis simulations now focus on cyber incidents, with successful responses often characterized by senior leadership involvement and a customer-centric communication strategy.
    • Stamos rejects the feasibility of government-mandated "back doors" in encryption, stating no respected cryptographer supports the ability to build secure systems with intentional vulnerabilities.
    • Stamos argues that creating backdoors would cede the global competitive and moral high ground to foreign adversaries and that bad actors will simply use alternative technologies if U.S. products are compromised.
    • Spaulding counters that the post-Snowden world has not changed existing legal authorities (e.g., FISA Section 702, EO 12333) for metadata collection, and the encryption debate must consider the impact on law enforcement's ability to protect children and investigate crimes.
    • Rothrock proposes a "cyber credit score" to standardize risk communication for investors and consumers, criticizing the current lack of encryption training in computer science curricula.
    • Gilchrist observes a growing investor interest in the positive "data narrative," where monetization of data drives valuation, creating a need to balance this opportunity against security risks.
    • Stamos identifies the shift to mobile operating systems (iOS/Android) and the adoption of the FIDO standard for biometric authentication as the two most significant near-term security improvements for general users.
    • Yahoo is rolling out on-demand one-time passwords and open-source end-to-end encryption projects (in partnership with Google) to move users away from traditional password management.
    • Rothrock identifies a major investment shift from prevention (firewalls) to detection and incident response, driven by startups led by former NSA engineers capable of spotting offensive malware.
    • Spaulding highlights a trend where major security providers are voluntarily sharing threat indicators, creating near real-time situational awareness that could theoretically allow adversaries to succeed only once.
    • Gilchrist notes the emergence of cybersecurity committees within corporate boards, signaling a recognition of the issue's strategic importance, and speculates on the future possibility of a cyber expert becoming a CEO.