(WASHINGTON, D.C.) – The Internet Security Alliance today released a “Cyber Regulation Fact Sheet,” demonstrating multiple examples of how the tremendous growth in cybersecurity rules and regulations is diverting scarce security resources and actually undermining our nation’s cyber defenses.

“One of the unintended consequences for organizations, like ISA who has been raising awareness of the cyber threat for 15 years, is that we now have cyber mandates springing up like weeds as virtually every governmental entity, federal state and local, fight to be the ‘cyber guy’. The result is an uncoordinated, inconsistent and often counterproductive set of requirements that actually hurts, not helping, increased security,” said ISA President Larry Clinton.

“Research tells us we are experiencing more than a million cyber-attacks a year and we don’t have nearly enough cyber professionals to help protect us. We need to use our scarce resources efficiently and effectively,” Clinton said. “Yet some firms are now spending 30 percent of their budgets and 40 percent of their time of various compliance regimes, none of which have been shown to empirically aid in securing our cyber systems.”

ISA’s fact sheet offered numerous examples from multiple industry sectors of the growth of cyber regulations often inconsistent with the risk management philosophy that professionals overwhelmingly suggest is a more effective approach to cyber defense. Among the statistics cited are:

“No one, certainly not ISA, is saying we ought not to have cyber controls or assessments. But, we need to have a rational and well-thought out system or we will waste vital resources and undermine our security,” said Clinton

 About ISA: The Internet Security Alliance (ISA) is a trade association with members from virtually every critical industry sector. ISA’s mission is to integrate advanced technology with economics and public policy to create a sustainable system of cybersecurity. ISA pursues three goals: thought leadership, policy advocacy and promoting sound security practices. ISA’s “Cybersecurity Social Contract” has been embraced as the model for government policy by both Republicans and Democrats. ISA also developed the Cyber Risk Handbook for the National Association of Corporate Directors. For more information about ISA, please visit www.isalliance.org or 703-907-7090.