Saturday, February 28, 2015

Final Thoughts

This is my last day of classes for the Cyber Security program, and I’m excited to finally be here.  I have worked really hard these last 2 years, and I’ve learned so much.  I currently work in general tech support at work, but I hope to use my degree to transition into the information security department at some point.  I think my company does a good job of doing what it can to protect itself, and out clients.  Other companies not so much.  If they were, I don’t think we would keep hearing the monthly news report that some large company was hacked, and now X number of people have to worry about whether or not their information has been compromised.  I’ve made several previous posts about this topic, so I’m not going to rehash it here.  I just think there is so much more we can do. 

Friday, November 14, 2014

What I've learned

 Like most classes I’ve taken towards my cyber security degree, I’ve learned a lot throughout the term. It’s always difficult for me to come up with the one thing that stands above the others, but in this case it was a little easier. Instead of a class that just teaches us the information, this one also provided instruction in how to use the information we were taught.  I think the most important thing I’m taking away from this class is the process of transforming my knowledge into a usable product. Not only did I learn new information, but I learned what to do with it. Writing papers to satisfy a class requirement is one thing; however, gathering that information and presenting it into a report for management is an entirely different matter. This class was especially helpful in taking what I’ve learned and assembling it into a useful document that could be presented to others. Going a further step Is taking that report and then reformatting it into a visual presentation.

Friday, October 31, 2014

Enforcement

 I saw the below article on CNN this morning while I was bored at work, and felt like I needed to share some thoughts about it. As cybercrime evolves and grows, law-enforcement continues to make corresponding adjustments to fight it. Although the Secret Service may have prevented 1 billion in cyber crime fraud last year, the estimated cost annual cost of cybercrime is about 400 billion (CNN). Needless to say, we have a long way to go before we get a handle on it. Ed Lowery is a special agent with the US Secret Service, who acknowledges that there has been a marked increase in the level of sophistication in both the nature and accomplishment of cybercrimes.

 Cyber criminals are no longer the lone hacker looking to make a quick buck, now they are organized cartels and governments targeting the US and other countries. According to Lowery, the US is an especially appealing target for infiltration. Adding to the problem is the fact that they often operate from locations were enforcement is particularly difficult, which may be due to lack of cooperation and geographic tensions.   These regions make ideal stopping grounds for cyber criminals.

 Even when policing is possible, there is still the critical elements of detecting and hunting these criminals. Lowery believes that the skill sets of law-enforcement must mirror (or exceed) those possessed by the cyber criminals. In addition to cyber skills, law-enforcement also needs to have investigative skills, which is not a common combination. Both take years to develop and they don’t often occur simultaneously.

 In my opinion, the biggest problem facing cyber security is not the skill set of the investigators, or even the laws in place. The larger issue is enforcement, and the ability  to police in regions with little or no cooperation. This is going to be the greatest hurdle in the feeding an annual fraud bill of 400 billion.



Lake, M. (2014). Police vs Cartels In The High-Tech Battle To Stop Cybercrime.  Retrieved from http://www.cnn.com/2014/10/30/tech/web/police-vs-cartelscybercrime/inde.html.


Saturday, October 25, 2014

I was initially going to write about something else this week, but  I couldn’t resist this headline: “China Is Hacking Its Own Citizens' iCloud Accounts.”   

The attack coincides with the iPhone 6 and 6 plus release in China.  China has previously launched attacks against their citizens’ Google and Yahoo accounts, but those attacks only resulted in the government being able to see what was accessed.  This new attack on Apple  is different though. Instead of just seeing what was access, the Chinese government is attempting to gain  the username and password for individuals utilizing iCloud. It wasn’t the idea of a government hacking its own citizens that caught my attention, it was the fact that I am absolutely not at all surprised that China is doing this. What does surprise me is that this headline didn’t show up before now. I would have guessed China was trying to crack into the iCloud years ago.   (I still suspect that this might be the case, and I doubt they are the only company involved in this kind of activity)

If they are successful in their attack, it will give them access to people’s pictures, documents, messages, etc. It  would be quite possible for the government to use this kind of information to build a case against an individual.  

It could be a criminal who successfully launches an attack against a company who acquires personal information, or it could be a government.  The bottom line here is that there really is no such thing as privacy anymore.



O’Toole, J. (2014). China Is Hacking Its Own Citizens' iCloud Accounts. Retrieved from http://
money.cnn.com/2014/10/21/technology/security/china-icloud/index.html.


Saturday, October 18, 2014

Cash Payments

 For some reason I had a hard time coming up with a topic for this week’s post. I figured if I just started typing, something would come to me eventually – and it finally did (I’ll spare you the rambling that got me to the final topic). Our assignments have focused on the restaurant chain of Harry and Mae’s and the breach they experienced in their payment processing system. Even though this is a fictional company, the situation could very well be real. I got to thinking about the protection of my information whenever I pay after eating in a restaurant. I generally tend to fall on the side of paranoid, which means I never pay with my debit card when the waitstaff takes the card from the table to go pay at a terminal. I just use my credit card or pay in cash in the situations because I refuse to let someone walk away with access to my checking account. However, I willingly handover my debit card whenever I’m paying at the register. Because of our Harry and Mae’s case study, I’m starting to rethink this habit. Granted, the person behind the counter that I’m handing my card to isn’t going to have time to steal my information while I’m watching them, but I really don’t know what their payment processing system is like or how well protected my information is. Going forward I think I’m going to start using my credit card or cash in these instances as well. It’s not that I really want my credit card information taken, but with the ever increasing number of breaches lately, I expect it is likely at some point. No loss of information is pleasant to deal with, but I really don’t want  my checking account compromised along with everything else. This happened to a friend of mine, and it was months before she got everything straightened out. I just don’t have the patience to deal with that kind of a mess.

Saturday, October 11, 2014

Simon Says...

In one of the chapters assigned for this week’s reading assignment, our book talks about social engineering.  I find this aspect of cyber security especially interesting -probably not surprising given the fact that I have a bachelor's in psychology.  Naturally, this is a topic towards which I would gravitate.  It’s also something I deal with every day at work.  My company has very strict privacy rules regarding client information where we have to verify very specific pieces of information before we can provide any client account data.   Sometimes just the fact that we ask the information upsets people, even after we point out that this is to protect their information. They just like to complain that this is their account they should be able to have their account information.

But what really surprises me is when other companies call for client account information, and argue with me that I should be able to talk to them about the account.  For example, a client’s  account is transferring to another company, and they call us to check the status of the transfer. We can provide limited information about the transfer: if it’s been received, if it’s in process it’s been completed etc. If there is something wrong with the request that we can’t process it, we ask the receiving company to instruct the client to call us.  At least once a day one of these companies will start yelling that I should be able to provide this information to them. When this happens, I usually ask them if their company has rules regarding client privacy, and they always reply yes but in this situation I should be able to give them what they’re asking for. They try various social engineering techniques, such as creating a sense of urgency, attempting to put themselves in a position of authority,  anything to make me feel like I should give them this information.   It’s frustrating, but it’s a factor in protecting client information.





Thursday, October 2, 2014

I think I might have learned something

I’ve decided to comment on my assignments for this week’s blog post.  Last week was the initial design of the current system arrangement for Harry and Mae’s restaurants.  Much of the assignment was similar to the analysis we had done for a previous class, but I feel like I understood the assignment so much better this time around.  The purpose behind college and homework is to learn (obviously), but I’m starting to realize just how much I have learned.  I’ve understood all along that there is a learning curve with every class as I’m introduced to new topics and processes; however, for the first time in the program the assignments are requiring the prior knowledge learned in the previous classes. Each of my classes prior to this term, while enjoyable and informative, were pretty independent of one another.  Now they have begun to build on each other, which is interesting to me.  I don’t mean just the assignments, just the way the past has informed my current classwork.  I’m sure I would have been able to complete the assignments this week and last week if I hadn’t had the prior coursework, but it would have been much more difficult, if not overwhelming.  Fortunately I had the previous work that I could reference to complete these assignments.  I’m finally seeing the light at the end of the graduate work tunnel, and am happy to know that I have leaned not only the subject matter, but how to incorporate what I’ve that learning into my new projects.  




Friday, September 26, 2014

New York agrees with me



During a discussion of cyber security, the superintendent for the New York Department of Financial Services (DFS), Benjamin Lawsky, said, “It is impossible to take it seriously enough” (Lopez &  Friefeld ).  The importance of cyber security cannot be understated. Last week I posted specifically about the Home Depot breach, but there are so many more. Just yesterday, the Channel 7 news in Omaha had a story that Jimmy John’s experienced a breach.  J.P. Morgan has also recently reported that they are investigating a potential breach. In fact, the DFS issued a report earlier in the year that the majority of financial institutions have experienced at least one attack in the last three years. Exact numbers were not provided in the article, but this still seems like a significant number of attacks. This doesn’t even include the number experienced by retailers.

In my post last week, I stated that it seems retailers are taking the required extra steps only AFTER an attack has occurred, instead of learning from others and taking steps now. Lawsky points out that lawmakers are in a position to enforce requirements, but I think any policies they put into place to address this specific topic would be to general or too outdated by the time the bills were approved. Technology tends to move faster than Congress (especially of late).

The article ends with Lawsky saying, “Once there is a major event, everyone suffers. We are going to pay for it either now or then” (Lopez &  Friefeld ).  This is my belief to an extent, but I would suggest that it actually costs more to wait for something to happen. Aside from the expense of review and upgrading the system to prevent a breach, the company would have to cover the cost of identity protection and any required reparations after a breach.  In the long run it is cheaper to make changes now instead of waiting for shit hit the fan and have people scrambling to resolve what should happen fix initially. By focusing attention on the importance of cyber security now, Lawsky is positioning New York in a better position to protect the financial institutions.


Lopez, L. &  Friefeld, K. (2014). N.Y. Financial Regulator Says to Focus on Cyber Security. 




Saturday, September 20, 2014

Thoughts on Home Depot

CNN posted a short little article about the hack into Home Depot that has been recently reported in the news. This latest breach, involving over 56 million credit/debit cards, only serves to highlight the need for strong security measures. In addition to that, it also raises some questions. How did it happen? Why was it able to happen for such a long time? What’s going to happen in the future?

According to Home Depot, the breach resulted from “a custom strain its security team had never seen before.”  Unfortunately, this is likely to be the future of these kinds of attacks. With changes in technology, and improved methods from the attacker community, this will also be a more common occurrence. Home Depot has said that they are seeking to increase their encryption and security methods, but why did it take a major hack to make those changes? Granted, I don’t know all the facts in the case yet, and it’s easy to judge, but does it really take a 56 million card lost to instigate changes? Target reported a breach of 40 million cards last year, and this should have been a wake up call to any retailer. Instead, the attack was found on September 2, but is believed to have been around since April. This is a long time to be losing information.

There are some lessons that can be taken away from this. We shouldn’t rely on what is in place. Instead, it should be regularly reviewed, tested, and updated. Improvements are constantly made in regards to technology and this should also apply to our defenses. Anytime a client’s information is at risk, companies need to ensure it is protected. Having an effective security plan in place has got to be cheaper then supplying identity protection services for millions of cardholders.



Backman, M. (2014). Home Depot: 56 Million Cards Exposed in Breach.  Retrieved from http://

Saturday, September 13, 2014

Patience and Planning

I’m going to write about something that happened at work recently. I apologize for some of the generalities in this post, but I am not going to discuss any company specific technologies in a public forum.  In our cyber-security courses we learn about Confidentiality Integrity and Availability being the cornerstones for protecting information.  This also applies to new systems in development.  My company prides itself on our technology and often uses it as an incentive when we are inviting new agents to join us.  While our agents do think about the Confidentiality and Integrity legs of the triangle, their primary concern is Availability.   

A new program was recently implemented that completely replaced one of the primary services we provide to our agents.  Testing had been done to ensure it worked as designed; however, it couldn’t talk to the agent facing system that is used to view the service.  The new program was security tested, and passed.  Information remained remained secure, but the Availability failed once the program went live.  Because of this the entire Information Security team had to give up their weekend so they could find the problem, fix it, and test it by Monday morning.  

In my opinion, this comes down to planning and patience. I saw this happen at my previous employer, but never to the scale as what happened at my current company.  Management was excited about the new program, and rushed to put it in place.  Once it passed initial testing, it should have gone through a secondary phase of a limited rollout to test it in the live environment.  This wasn’t done, and resulted in a pretty big failure.  Planning and patience could have avoided this. 



Sunday, September 7, 2014

Websites for managing threats and vulnerabilities

Establishing a list of reliable sources for breast and bone abilities is important for managing them. Below is a list of the sites I like best with a little bit of a description and why I like them. I’ve also included a link to each one so that you can also visit the site and give me your thoughts.

The National Vulnerability Database (NVD), which is a government sponsored database for vulnerability management.  They provide links to additional websites dedicated to threat and vulnerability management.  Having these additional links all in one place is easy.  

I especially like the link the NVD provide to The National Checklist Program.  These lists provide guidance for setting up security configurations to defeat known threats.

Common Vulnerabilities and Exposures provides information about know vulnerabilities and exposures.   This is helpful for the use of vulnerability management, patch management, alerting, and intrusion detection.  

Symantec has two pages that I like for current threats and vulnerabilities.  First is their Threats page, which lists the name, severity, height, and discovery date.   Each threat name has a link that provides additional information about it.

Symantec’s vulnerabilities page, lists the name of the threat, it’s severity, and the date discovered. Each name is hyperlinked to a description page that details the problem, and provides recommendations. 














Saturday, August 30, 2014

A New Introduction

 This is my blog. There are many blogs like it, but this blog is mine. The bulk of my posts will focus on issues surrounding cybersecurity. Dull? Not likely. In an effort to make these posts more interesting, I am going to attempt to link each security related entry to something in pop culture. How my going to do this? I'm not exactly sure yet, but it should be fun to try. Please read along with me and let me know what you think.

Sunday, February 24, 2013

The obvious entry would be to discuss the recent news about China and their hacking activities, but I haven’t decided what I think about that yet.  On one hand, I’m surprised that people are so surprised about it.  On the other, I think it takes a lot of balls for a country to sponsor hacking activities (and there is no convincing me the government wasn’t aware).  Bt then on the other hand, is this really that different from the espionage activities that were conducted between us and the Soviet Union during he Cold War.  The targets are different, but the goals are similar.  Instead of spying on the military to better defend the home country, China is hacking to better develop the home country.  This doesn’t excuse the activity, but this thought process is at the core of why it doesn’t surprise me that it happened.  I guess what does surprise me about all this is that it took ten years for it to come out.  How is this news going to affect businesses?  Well, I assume there will be many internal investigations to determine exactly who was hacked and what data was compromised.  How is this going to affect individual people?  I don’t know that it will alter the behavior of too many people.  Last night Jimmy Fallon had a joke bout the China hacking situation by announcing that he still isn’t going to change his email password from “jimmy.”  I think this is probably going to be the case for most people -they aren’t going to give it any thought other than “Oh, China hacked businesses.”  Hopefully I’m wrong. 

Friday, November 9, 2012

The paranormal side of privacy and security


I struggled to come up with something to write about for this week’s blog. I did several searches online for information security and related topics, but nothing jumped out at me. So, I decided to write about something that came up last night I got to think about everyday personal security and privacy. I am co-founder of local ghost hunting group and we just accepted three new members into our organization last night. We take what we do seriously because we going to people’s private homes and wander around in the dark unsupervised. There is a high level of trust these individuals are placing us when they let us into their homes to do this. This means we have to choose new members carefully because they are going to be representing us. We need people who are going to respect the homeowners policy regarding what we see in the house (not just paranormal – we seen some really hot stuff that people have).

The most important thing is safeguarding the person’s privacy. Most of our clients are genuinely scared of whatever activity is going on in their home, and we are often their final attempt at a resolution. The very last thing they want is someone blabbing about the fact that they think they have ghosts in their house or business. Fortunately, we are able to debunk probably 75 – 80% of activity as everyday stuff like doors don’t latch properly or plumbing noises, et cetera. Even though that is the case, it still doesn’t mean that they want word to get out. The reason it’s so important to them is that it can affect how they are perceived by others. In the case of a business, it can cost the money customers believe you hear that the place is haunted, or that the owner is a little “off” for thinking that might be haunted.

So, we teach our new members to speak generically when telling investigation stories. Instead of saying something like Bob’s house in Central Omaha, we would just say a house in Omaha. It may seem like a small thing, but it really matters to our clients. The case files and pictures because our website are labeled in the same generic way (unless the home or business owner has given us permission to use their names, like Mystery Manner or the Squirrel Cage Jail in Council Bluffs).

Friday, November 2, 2012

Disaster Planning


I was initially going to do a post about Mac versus Windows and the ease of establishing VPNs for this weeks post. It’s a topic that would have tied into the general theme that is kind of present in my previous post, but hurricane Sandy got me thinking about disaster recovery from a business aspect. After I read the article in the link below, I was especially interested in this topic. So, join me on my deviation, won’t you?

DTCC is a company I have worked closely with for years, and their location in lower Manhattan was directly in Sandy’s path. The wall to their vault where they store the stock certificates borders the East River, so their lower levels are underwater and they are still unable to go in and assess the damage. Here is the first sentence from the article, “trillions of dollars worth of stock certificates and other paper securities that were stored in a vault in lower Manhattan may have suffered water damage from superstorm Sandy.” As of Friday, they have been able to reopen and now except physical security deposits at an alternate location in Brooklyn. This means that clients will be able to trade on the physical securities that has been deposited to their brokerage accounts, this is important because clearing firms can once again contact this business as normal. Unfortunately DTCC is still unable to process settlements, which means clearing firms are unable to settle trades based on the physical certificates already in DTCC’s custody. This was runs into regulatory and delivery issues, that at this point, I’m not sure how we will work around. I assume FINRA is going to grant exceptions and waive the extension fees that would normally apply, but something that will take a lot of planning and communication to all the broker/dealers.

My point to all this rambling is this. While DTCC’s disaster planning and recovery plan has obviously gone into effect, there has been a trickle-down effect that has created an immediate consequences on businesses here in the Midwest for very far from any kind of physical storm damage. There is no primary disaster plan for the company to put into place in this situation, but we still have to react and create new policies based on the East Coast conditions. There are workarounds to using DTCC as the primary certificate processing facility, but it is a lengthy and sometimes more expensive alternative.  I guess the purpose to this writing is to bring up the fact that just because the company does not directly suffer any kind of disaster or damage, the planning team still needs to take outside factors into consideration. They need to plan for alternative ways to conduct business if one of our primary partnerships loses the ability to operate.



Thursday, October 25, 2012


I don’t have an article to reference for this weeks blog post because I want to talk about something that happened at work this week. It turned out to be I’m not even, but the level of awareness (or lack of) has me concerned. Here’s what happened:

I start work later than most of my department, so by the time I come in everyone is usually busy and getting things done. When I got in the other day, everyone was milling about and talking so I knew something was up. They told me the phones were down so we couldn’t do anything. Shortly after that the network went down as well. My first thought was, “could this be the result of some kind of an attack?” When I asked this question of my co-workers, I received a range of looks from confusion to disbelief. I don’t work in the technology department, so I understand that an attack might not be the first thought people have. But, what I found surprising is the fact that they wouldn’t even consider it as a possibility. Some people thought no one would be interested in attacking us, others not an attack wouldn’t affect our internal network. I pointed out that neither of those things were necessarily true, but no one was interested in discussing it. 

Like I said earlier, this turned out to be a non-event, but I’m disturbed by the fact that no one even considered the idea that we could have been attacked. I think it comes down to a training issue. Even though we aren’t a tech department, I think we would benefit from a training program that would address threats  and the fact that the company could be a target. I don’t mean to sound like I’m judging my coworkers – I’m not – but I think there needs to be a higher level of security awareness. It comes down to if employees think a company wouldn’t be a likely target attack, how can you expect them to follow the security rules in place?

Friday, October 19, 2012

Access Control and Training





In the chapter we rent this week, the book referred to access controls. There are two sides of this: the electronic and the physical. Naturally, the electronic access controls are going to address what systems and information can be accessed by which users. While that is a topic that would sustain its own lengthy conversation, I want to focus on the physical side of access control, specifically some of the dumb reasons why people I work with think it should apply to them. I know that sounds like a negative statement, but seriously it’s one of my pet peeves. Physical access control has been a factor in most of my adult working life. First in the military, then my career within the financial industry. Maybe it’s due to my time in the service that doesn’t bother me now, but it really seems to be a hassle for some people to grasp the importance of it.

I work in a building which requires that we have badge access not only for the building itself, but to get into my specific department. The entry points and key areas within my office are monitored with security camera, and there are additional measures that I’m not going to discuss for security reasons. All of this security is because we work with a lot of high-value and very portable assets. If someone were to run off with one of them, it could literally cost the company millions of dollars. All of these controls make sense to me, and I understand the reasoning behind the need for them, but I’ve heard people complain about them daily. Here are some examples of the complaints from just this week, “Do I really need to wear my badge everywhere?”  “I should be able to have people visit me in the office if I want to – other departments allow it.”  “It’s a violation of my rights for them to record me coming in and out of the office.”  

First, is it really that much of a hassle to put a badge on your belt loop, or to talk to the friend over chat instead of having to come to your desk. That one I understand can be a little bit frustrating when you can just walk into other departments, but the no visitor policy does reduce the risk of lost assets. And lastly, a violation of your rights? Seriously? How do you survive going into a mall? or a gas station?

Enough of the rant. I think a lot of the issues in access control compliance come down to training. A company can deploy risk management policies all day long, but if employees are trained in how the procedures related them into their daily work, we are going to understand why it’s so important.  According to DiversifiedRiskManagement.com, “probably the simplest and most cost-effective precaution one can take is to see that every employee is involved in maintaining a safe and secure work force and work area, and through employee awareness training and empowerment of the workforce to get involved in daily security at work, even the most skilled intruder can be stopped in his tracks.” I think this statement meals the solution to the problem of getting employees to follow risk management procedures.



http://www.diversifiedriskmanagement.com/articles/access-control.html

Saturday, October 13, 2012

Career Thoughts


I had a weird week. I spent some time in the hospital, and whenever I was trying to do homework someone would come into the room and asked me what I was studying. This resulted in my having the same conversation several different times with different people.  I would explain that I am enrolled in a cyber security program degree program.  This would invariably would get the reaction, “I didn’t know that was a job.” I told them it is and what the program was about, and that I hope to get a job as a civilian contractor once I graduate.  If I’m lucky enough to do this, it means I can apply my active-duty time towards a government retirement. Even though this has been my plan all along, I got to thinking about other possibilities for a career in cyber security. Since there’s nothing else to do in the hospital other than daytime TV, I did some research on the web and came across an article in which the interviewees complained about the lack of inspiration of their government jobs.

The article interviewed a couple different individuals who work in cyber security capacity for the government, and both called the boring and unimaginative. They talked about how regulated the environment is, and the lack of access to the computers they are actually protecting. They went on to talk about the restrictions they face when it comes to the type of security programs that can be applied.  In the article said that individuals working in cyber security for the government were essentially acting as a gate keeper who spent their time explaining to people what they can or cannot do ensuring that they either do or don’t do it.  There was nothing in this article that the sweets me from my original goals.  

After my years of working in Air Force Intel, I’m very well aware of government bureaucracy and what kinds of restrictions the place on various points of access.  For example, I remember the IT guys coming into our secured work space , and every time they did, we had to secure the classified and bring everything down to zero before they could be escorted in.  It was an Airman’s duty to watch them like hawks in case they found any kind loose paper, or anything that could potentially be classified.  if they did come across something, we were actually instructed to grab it out of their hands before they could look at it.  So yeah, I think I am prepared to face restrictions over what I can or cannot access.


Saturday, October 6, 2012

Poster Thoughts



Even though it’s off-topic from previous post I’ve made to this blog, I decided to just do a Google search for information security posters to see what comes up. And, there were a lot of examples.  Some of them were quite clever, and got their point across using just visuals with very little commentary.  

For example the “Take it From Red” poster raises awareness about social engineering, and the different forms the threat can take. It uses figures that are immediately familiar to us, and places them into a security conscious context.


Another poster I thought was very effective raised wet awareness of emails and attachments. It’s simple, grabs your attention, and gets the point across through a combination of graphics and few words. It is something that you can read on the go, and immediately understand the message.


Then there were others like the, “only the strong survive,” which initially grabs your attention.  But then I was so busy trying to figure out what cheese has to do with the message, that I really didn’t pay attention to anything else in the poster. sometimes being too clever get in the way of your message.


Generally speaking, I’m in favor of using animals to make a point, but I didn’t understand this one at all. It asks “is your identity in safe hands?” and then says “security is everyone’s responsibility.” Good question at the top, but the following statement is a non sequitur. And where does the dog in the pink wig come in? It makes no sense to me.


Of course this is all just my opinion because different graphics are going to stand out in different ways different people. These are some examples of what either did or didn't appeal to me.


Sunday, September 30, 2012


The article I chose for this week’s blog is called “Taking the cyber attacks threats seriously,” and it talks about some of the large-scale dangers that hackers pose to the united states.  In the op-ed piece, President Obama specifically talked about the dangers to our infrastructure. He talks about the need for legislation that strengthens cyber security practices, and makes it easier for governments to communicate with companies or vice versa regarding specific threats.  I think this is a good idea. It would require industries to meet a certain minimum, and establish protocols for threats. Once the new policies are put in place, it would eliminate confusion over how to proceed in the event of an attack. The forward planning would potentially reduce the damage inflicted, and create a shorter timeframe or recovery.

Not only would companies be better prepared in the event of an attack, they would be better prepared to prevent an attack. If there was some kind of legislation that require a minimum standard, some companies may not have to do anything, but others may have to adjust their procedures to conform with the new policies. Even if a hacker overrides what ever the new protocols are, the companies will be better prepared to manage the situation.