CONGRESS MUST REAUTHORIZE CISA 2015

The Cybersecurity Information Sharing Act (CISA) of 2015 is arguably the most successful cybersecurity legislation ever enacted. It uses market incentives (liability protection) to incentivize critical information sharing between industry and the government. It is currently scheduled to expire in three months. Disabling our most fundamental cybersecurity mechanism would take place at a time of […]

THOUGHTS FROM THE WORLD ECONOMIC FORUM – REIMAGINING CYBER REGULATIONS

Last week, I was honored to be asked to lead the session on reimagining cyber regulations at the World Economic Forum event in Paris. The Forum relies on the Chatham House Rule, so I will await their report on the meeting; however, below is the text from which I drew the opening statement for the […]

ISA Workforce Development Specific Recommendations and the Presidential Commission on Enhancing National Cybersecurity

ISA Workforce Development Recommendations Source: Chapter 9 of The Cybersecurity Social Contract: Implementing a Market-Based Model for Cybersecurity Presidential Commission on Enhancing National Cybersecurity Focus A National Initiative On Building the Talent Pipeline “Attracting students into the federal government must be augmented by an aggressive strategy to build the pipeline of interest in earlier grade […]

ISA Utilities Sector Specific Recommendations and the Presidential Commission on Enhancing National Cybersecurity

ISA Telecom Sector Recommendations Source: Chapter 8 of The Cybersecurity Social Contract: Implementing a Market-Based Model for Cybersecurity Presidential Commission on Enhancing National Cybersecurity Enhance Information Sharing Between Utilities and The Federal Government “Utilities, as highly regulated entities, have a long history of collaborating with government. But there are obvious caveats. They require a better […]

ISA Telecom Sector Specific Recommendations and the Presidential Commission on Enhancing National Cybersecurity

ISA Telecom Sector Recommendations Source: Chapter 8 of The Cybersecurity Social Contract: Implementing a Market-Based Model for Cybersecurity Presidential Commission on Enhancing National Cybersecurity Incident Reporting and Information Sharing “Governments can do more to set the framework and do more to incentivize and reward good behavior. Following an incident, everyone needs to be clear and […]

ISA Information Technology Sector Specific Recommendations and the Presidential Commission on Enhancing National Cybersecurity

ISA Information Technology Sector Recommendations Source: Chapter 7 of The Cybersecurity Social Contract: Implementing a Market-Based Model for Cybersecurity Presidential Commission on Enhancing National Cybersecurity Create a Cabinet-like Position to Upgrade Civilian IT and Security Infrastructure “Attempts to build [a bureaucratic power base] through the position of cybersecurity coordinator were well intentioned, but a White […]

ISA Manufacturing Sector Specific Recommendations and the Presidential Commission on Enhancing National Cybersecurity

ISA Manufacturing Sector Recommendations Source: Chapter 10 of The Cybersecurity Social Contract: Implementing a Market-Based Model for Cybersecurity Presidential Commission on Enhancing National Cybersecurity Incentives for Improving Cybersecurity “The government should complete the task begun with creation of the National Institute of Standards and Technology Cybersecurity Framework in determining what the most cost-effective elements of […]

ISA Insurance Sector Specific Recommendations and the Presidential Commission on Enhancing National Cybersecurity

ISA Insurance Sector Recommendations Source: Chapter 14 of The Cybersecurity Social Contract: Implementing a Market-Based Model for Cybersecurity Presidential Commission on Enhancing National Cybersecurity Tax Incentives for Cybersecurity Investment “Companies should be incentivized to invest in cybersecurity. Investments will benefit all citizens—they will ensure that data and networked physical assets are kept safe and secure. […]

ISA Healthcare Sector Specific Recommendations and the Presidential Commission on Enhancing National Cybersecurity

ISA Healthcare Sector Recommendations Source: Chapter 4 of The Cybersecurity Social Contract: Implementing a Market-Based Model for Cybersecurity Presidential Commission on Enhancing National Cybersecurity Incentivize Healthcare to Implement Best Cybersecurity Practices “A course shift away from prescriptive regulation and to regulation that encourages security best practices is desperately needed. That encouragement would best be achieved […]

ISA Financial Sector Specific Recommendations and the Presidential Commission on Enhancing National Cybersecurity

ISA Financial Sector Recommendations Source: Chapter 5 of The Cybersecurity Social Contract: Implementing a Market-Based Model for Cybersecurity Presidential Commission on Enhancing National Cybersecurity Harmonize, Streamline, and Improve Regulations “Regulations should encourage banks to take a risk-based approach, which is customized to the threats they face and takes into account the bank’s business model and […]