And on the policy front, two federal agencies are looking at reporting rules for cyber attacks: The SEC and CISA. The SEC is getting significant pushback, while CISA’s early work appears to be more embraced by the industry.
In fact, at Black Hat, former CISA director Chris Krebs even called for a reorganization of the government’s cyber response, proposing a “U.S. Digital Agency,” which would incorporate elements of CISA, the National Institute of Standards and Technology, the National Telecommunications and Information Administration, the Department of Energy as well as parts of the Federal Trade Commission and the Federal Communications Commission.
“I think it’s time to rethink the way government interacts with technology. We have to make an agency that’s focused on empowering better digital risk management services,” Krebs said. “I’m not just talking about security. I’m talking about privacy. I’m talking about trust and safety issues. We’re not where we need to be and we’re falling behind and Americans are suffering as a result.”
There’s logic to Krebs’s assessment here, and I’d agree we have responsibility spread into too many areas now. It’s popular to diss the government, which ignores the fact that they get a lot done. A US Digital Agency makes sense to me. Just take that SEC / CISA tension – a central ownership o the issue helps resolve it.
Watch this space.
