Blog
Contact Us

BREAKING NEWS

CiaC



 

Posted by on in Crisis Communication
How do we survive surviving? By Ann SanCartier for Firestorm

Imagine.  You head to pick up your child from school and abruptly, the only thing separating you, your daughter and your sister from 200 mile per hour winds are two collapsed walls supporting each other in a triangular formation. You hold your daughter with adrenaline-induced strength while you scream and pray as the realistic fear of being sucked up into a monster overwhelms you. That’s what happened to a family I spoke with who survived the Moore, Oklahoma Tornado. As they cowered for protection at Briarwood Elementary, what we now know to be an E5 tornado, whipped them with flying debris leaving their feet, arms, and heads lacerated by its ferocity. As this mother shared her traumatic experience with me, she related that her sister was waiting in their van parked outside the school. When the school advised her that a...

 

 


 

Need help now?

Harry Rhulen:  This email address is being protected from spambots. You need JavaScript enabled to view it.            

Jim Satterfield:  This email address is being protected from spambots. You need JavaScript enabled to view it.

Suzy Loughlin:  This email address is being protected from spambots. You need JavaScript enabled to view it.
(800) 321-2219

 

CLICK HERE FOR BREAKING NEWS & ANALYSES

The Team at Firestorm

Firestorm has a globally recognized group of contributors to this blog - Expert Speakers, Authors and Presenters, all highly credentialed and experienced in the field of crisis preparedness and crisis management.

  • Home
    Home This is where you can find all the blog posts throughout the site.
  • Categories
    Categories Displays a list of categories from this blog.
  • Tags
    Tags Displays a list of tags that has been used in the blog.
  • Login

Cybersecurity - Critical Computer Infrastructure Should Extend Beyond Cyberspace

Posted by on in Data Security
  • Font size: Larger Smaller
  • Hits: 4982
  • 1 Comment
  • Subscribe to this entry
  • Print

Cybersecurity


Cybersecurity Commentary by Security Management Expert Ed Levy, Firestorm Expert Council Member

Edward M. Levy is a senior security executive with nearly 30-years in the corporate and government sectors. Mr. Levy was the VP & Global Head of Security for Thomson Reuters. He served in other corporate security positions with Pfizer, CIT Group, and the Empire State Building. Mr. Levy is also a retired Lieutenant Colonel from the US Army and former Assistant Professor at the United States Military Academy at West Point.

Critical Computer Infrastructure Should Extend Beyond Cyberspace


Recently, in an article in Homeland Security News Wire, it was detailed that the current Administration announced it is "exploring whether to issue an executive order to protect the U.S. critical computer infrastructure from cyber attacks."

As stated in the article:

"White House sources say an executive order is being considered after a 2 August procedural vote in the Senate that all but




[caption id="attachment_2394" align="alignright" width="269"] Ed Levy will present "Duty Of Care: What's The Security Director's Role" along with Jason Dury and Robert Martin at ASIS

doomed a cyber-security bill endorsed by Obama as well as current and former national security officials from both Republican and Democratic administrations

 

President Barack Obama is exploring whether to issue an executive order to protect the U.S. critical computer infrastructure from cyber attacks; White House sources say an executive order is being considered after a 2 August procedural vote in the Senate that all but doomed a cyber-security bill endorsed by Obama as well as current and former national security officials from both Republican and Democratic administrations."


The Administration details that "Our Nation’s cybersecurity strategy is twofold:  (1) improve our resilience to cyber incidents and (2) reduce the cyber threat."

While I see this as a great initiative on infrastructure protection legislation for the private sector, I believe that language surrounding the “critical computer infrastructure” should extend beyond the cyber-space.

Threats to companies and the DHS designated critical infrastructure sectorsDHS designated critical infrastructure sectors are quite credible, determined, and persistent, especially when it comes to attacks and protection requirements for intellectual capital and key resources.  A discussion point is that “the threat” extends beyond a faceless cyber-attack which transverses networks to penetrate, disrupt, disable, vandalize, or loot companies externally, but an equating threat that originates as permissible, to gain access and resonate internally to companies.

I am a believer in regulation for security.  As a profession that is indiscriminately still looked upon as a cost center and financial burden for doing business and delivering services, regulation and legislation help reinforce the case of security under an enterprise risk management construct.


The issue with this piece of legislation is that it is only a partial view of infrastructure protection; it does not fully encompass the full threat profile of how intellectual and capital losses are truly accessed from networks and computers, or easily available for the taking through the physical space.

Losses seem to amount by the processes (or lack thereof), where companies actually invite and accept nefarious activity into the logical infrastructure through physical means resulting from:


  • inadequate background checks

  • open access to contractors and vendors

  • antiquated visitor controls

  • poor employee and contractor on-boarding and termination procedures

  • non-existent document controls

  • narrow due diligence processes during mergers and acquisitions

  • lack of meaningful training and awareness


An executive order or legislation for infrastructure protection is excellent, but needs to be complete.  There are several domains of security that require specific levels of expertise for a process management approach, associated for infrastructure protection – cyber is only one domain.

Ultimately, security should be converged under a single unifying framework for governance and operations to manage the full spectrum of security risks and protective strategies to reduce exposure.

So again, great initiative, but the question begs, why the cyber-threat only – why not a complete baseline policy to truly outline infrastructure protection measures companies should comply with to protect financial, reputational, fiduciary, and operational well-being?

Join Ed Levy and Firestorm on Wednesday, August 22 at 2-3PM EDT for Threat Management: Navigating the Obvious

Ed will address "Do you really know what’s walking out of your door?"

According to results of ID management provider Cyber-Ark's sixth annual global "Trust, Security and Passwords Survey," just under half of 820 respondents admitted if they were fired tomorrow, they'd walk out with proprietary data such as privileged password lists, company databases, R&D plans and financial reports -- even though they know they are not entitled to it.

The report reveals that “while insiders continue to be perceived as the biggest risk organizations face in securing against data breaches, a majority of respondents agree that all recent security breaches – internal and external – involved the exploitation of privileged accounts. The continued exploitation of these accounts in some of the industry’s most notorious data breaches is a significant factor in the growing recognition of the “privileged connection.” Businesses need to continue to be vigilant in securing and managing these high value targets.”

Join Ed Levy - a Firestorm Expert Council Member and senior security executive - to discuss strategies for minimizing risk due to data and intellectual capital losses.

 



Rate this blog entry:
0

Comments

Leave your comment

Guest Wednesday, 19 June 2013

Newsletter Sign Up

newsletter signup
Firestorm believes that crisis preparedness is predicated on recognition of imminent threats. Our weekly newsletter is an invaluable tool that reports on current conditions and issues, and includes original commentary and analysis from our Expert Council, Senior Leadership, and Guest Contributors. Valuable, insightful commentary analysis each week - and it's FREE! Sign up to receive these critical alerts

Download our Toolbar! Get our toolbar!

Register for an Event

Crisis CalendarFirestorm Events

Firestorm presents a variety of topical webinars each month for the business community presented by leading experts in their fields.  Our Leadership Team and Expert Council present as Keynote Speakers, Program Presenters, and Panel Members at events across the country. Keep up to date and Join us!
View our Upcoming Events...

 

Read Our Latest Analysis

Disaster Ready People

Firestorm founders Harry Rhulen and Jim Satterfield wrote Disaster Ready People for a Disaster Ready America specifically to address the need for crisis and disaster preparedness at home, and the book has become a cornerstone of many personal and corporate preparedness programs.

Download the eBook..

Who We Are

What We Do

How We Do It

Contact Firestorm

Newsroom

Biography

Every Crisis is a Human CrisisFirestorm has a globally recognized group of...

Calendar

Loading ...
Our Address:
1000 Holcomb Woods Parkway Suite 130
Roswell, GA USA 30076

Information

Firestorm® is a national leader in crisis management, vulnerability analysis/threat assessment, and business continuity. Firestorm’s Predict. Plan. Perform.® process leverages next-generation consulting services, tools and software creating resilient organizations.  We are the Crisis Coach™ for Crisis Management, Critical Decision Support, Crisis Communications, Crisis Public Relations, and Consequence Management (800) 321-2219

Firestorm Solutions transforms crisis into value, and is a recognized leader in crisis management, critical decision support, crisis communications, crisis public relations, and consequence management. Learn More...

Meet Our Management Team
Facebook
Google
Twitter