Panel
Lunch Program | High Stakes in Cyber-Security
- Cyber threats have evolved from financial theft to intentional disruption and destruction, establishing a new "old normal" that necessitates CEO and board-level engagement rather than reliance on IT oversight alone.
- The 2012-2013 attempts to attack U.S. financial infrastructure succeeded largely due to adversary restraint rather than active defense measures, while attacks like Iran's utilized global telecommunications infrastructure to generate denial-of-service loads exceeding three times service provider capacity.
- U.S. Transportation Command estimates that 90% of logistical flow would cease overnight following a loss of confidence in cyberspace logistics, as manual backups have been eliminated for just-in-time efficiency.
- Approximately 90% of critical infrastructure is privately held, creating an urgent need for improved public-private collaboration and information sharing, which is currently hindered by stalled legislation protecting companies from litigation.
- Adversaries are actively developing capabilities to attack the U.S. electrical, chemical, water, transportation, and financial systems using sophisticated viruses similar to the 2012 Shamoon attack on Saudi Aramco.
- Major cyber incidents may go unnoticed until recently, despite parallels between the paralysis caused by Hurricane Sandy and the potential for a sophisticated virus to replicate such disruption.
- Companies face daily hacking with attacks often lasting an average of 253 days before detection, resulting in the loss of intellectual property, research, business intelligence, and money regardless of IT spending levels.
- Current strategies require leaders to admit to breaches and re-architect networks to protect "crown jewels," as assuming attackers can be entirely kept out is no longer viable given that only a small percentage of companies operate with the assumption that adversaries are already inside.
- Regulatory bodies including the SEC are demanding detailed information on cybersecurity strategies from Wall Street firms, with expectations that other federal agencies will mandate similar disclosures from various industries.
- The White House has established a policy to weigh the disclosure of vulnerabilities against intelligence gathering needs, involving the Treasury and Homeland Security Departments in these decisions.
- Cyber vulnerabilities frequently stem from poor implementation and composition of security mechanisms rather than inherent device flaws.
- Russia is expected to integrate cyber elements into military operations in eastern Ukraine to disrupt communications and missile systems, with the U.S. and NATO developing defensive capabilities against such attacks.
- Heavy sanctions on Russia are predicted to provoke covert cyber retaliations against U.S. financial institutions that may be unprovable by the U.S. government.
- The Snowden leaks have impaired U.S. intelligence capabilities developed since 9/11, leaving the country vulnerable as adversaries analyze released information.
- U.S. defense planning involves using cyber as a battlefield for aggressive operations to avoid physical force mobilization, given the sophistication and potential for "hellish damage" from these weapons.
- A primary obstacle remains a lack of awareness among the public, Congress, and corporate leadership regarding the severity of cyber threats, which impedes necessary action.
- Corporate boards must approve risk strategies identifying specific pain points and develop tested breach plans with real people, rather than prioritizing spending over strategy.
- Investors and companies conducting mergers and acquisitions must perform rigorous due diligence on cyber posture to determine if asset value has been compromised by foreign entities.
- If attacks occur against Ukraine or U.S. allies, the U.S. will engage in defense planning and information exchange with NATO to develop necessary defensive capabilities.