Panel
Lunch Program | High Stakes in Cyber-Security
Cyber Threat Landscape and Strategic Shifts
- Cyber threats have evolved from financial theft to intentional disruption and destruction, as evidenced by the 2012 Saudi Aramco attack which wiped 30,000 computers and destroyed all data without stealing a single dime.
- Denial-of-service attacks against the U.S. financial infrastructure in late 2012–2013 involved up to 100 incidents globally, where a single nation-state (widely conjectured to be Iran) leveraged borrowed, unauthorized infrastructure to amplify attacks to over 80 gigabits per second.
- 90% of the critical infrastructure essential to U.S. national security, including logistics and supply chains like those used by U.S. Transportation Command, is owned and operated by the private sector.
- The U.S. Department of Justice indicates that companies generally fall into two categories: those that know they have been hacked and those that have been hacked but remain unaware of the breach.
- According to the Poneman Institute, companies detect cyber intrusions on average 253 days after the initial breach, during which time intellectual property, R&D data, and capital are systematically exfiltrated.
- Former National Security Agency official Chris Inglis notes that the vast majority of successful cyber attacks originate from inside the network perimeter, invalidating traditional "perimeter defense" strategies.
- Former Secretary of Defense Leon Panetta identifies "cyber Pearl Harbor" as a looming, tangible threat capable of paralyzing the electrical grid, water systems, and transportation networks via sophisticated viruses similar to the Shamoon malware.
- International tensions, specifically regarding Russian sanctions over Ukraine, raise the likelihood of covert, unattributable cyber retaliations against U.S. financial institutions and infrastructure.
- The NSA's decision to leak information via Edward Snowden was achieved by abusing the trust placed in a system administrator with access to administrative data, highlighting the vulnerability of "trusted insiders."
- The White House has recently issued a policy framework to govern the disclosure of discovered cybersecurity vulnerabilities, weighing the public benefit of patching flaws against the intelligence value of retaining access capabilities.
- Regulatory pressure is increasing, with the SEC recently demanding 50 Wall Street firms to disclose their cybersecurity strategies, policies, and technologies, signaling a shift toward mandatory federal oversight.
Executive and Board-Level Directives
- Acknowledge Inevitability: CEOs and Boards must accept that network breaches are inevitable and that the primary goal should be resilience and protecting "crown jewels" rather than preventing all intrusion.
- Prioritize Leadership: Cybersecurity must be elevated from an IT issue to a top-tier board and CEO responsibility, increasingly managed by Chief Risk Officers rather than just CIOs.
- Re-architect Networks: Organizations must stop relying on static perimeter defenses and instead implement "defense in depth" strategies that assume adversaries are already inside the network.
- Develop Breach Protocols: Companies must create and regularly exercise specific breach response plans involving real personnel to ensure effective reaction during an actual crisis.
- Enhance Due Diligence: Investors and acquirers must conduct rigorous cyber-security due diligence on M&A targets to assess the risk of stolen intellectual property and hidden liabilities.
- Align Risk Strategy: Boards must approve a defined cyber risk strategy that identifies specific organizational pain points and acceptable risk tolerances before capital is allocated to security tools.
- Public-Private Collaboration: While essential for national defense, information sharing between the private sector and government remains hindered by a lack of legislation providing protection from litigation.
- Cloud and Mobile Caution: The adoption of cloud services and mobile devices (BYOD) requires specific contractual stipulations for security levels; rushing to market often results in deploying insecure technologies.