Showing posts with label Cyber Risks. Show all posts
Showing posts with label Cyber Risks. Show all posts

Wednesday, July 15, 2015

Good Grief, Isn’t Anyone Responsible Here?

We have all seen the news of the massive theft of information from the Office of Personnel Management (OPM).  In a nutshell, with extremely high probability just about anyone that does work for the government (or from one estimate over 21 million people), which includes yours truly, had very personal information stolen.  In my case, this could mean that the last 35 years of my life, everywhere I lived, everywhere I worked, the names and contact information of my close relatives and closest friends, and virtually everywhere I traveled outside of the United States of America is in the hands of what is speculated to be the Chinese government.  In some cases, of course other than myself, the information will include self-disclosed arrest information, drug and alcohol abuse disclosures, and whether bankruptcy was declared.  Good Grief! And, what do we get from those in charge of OPM? Well to my mind it is exactly what the Peanuts characters hear when the adults talk: "waa waa waa.".  Translated for your benefit: The (now former) Director of OPM says she does not believe "anyone is personally responsible".  It is just this lack of personal responsibility as well as other Cyber security failures that needs to motivate us to a new approach – one that recognizes that every business relationship today has its implementation foundation built on Information Technology (IT).

Although the director of OPM has now resigned, there is still no real accountability or responsibility.  Dozens of OPM government employees and contractors knew the state of their system and lack of protection.  The problem is that these people know, with certainty, that there is no accountability and there is no responsibility.  The Chief Information Office (CIO) has not resigned, and that person is directly accountable to Congress to represent that their systems are FISMA compliant.  Here is a link to the OPM Office of the Inspector General Report for 2014.  Just read the summary page under "What Did We Find?" and you will be appalled.  There is some glimmer of hope on the trail to real responsibility.  As reported in the Wall Street Journal CIO Report by Kim S. Nash, the OPM CIO better get some lawyers as she is being sued.  The legal threshold is high, but this is at least a step away from zero responsibility.  Of course, let’s say that she loses in court, what exactly is going to be the remedy for the people impacted (she most likely has no money, even if that is a potential judgement)?  Would this actually change the environment to get some real focus on Cyber security?

Of course it is easy to be a Monday Morning Quarterback and to Beat A Dead Horse, so let's move to a more constructive set of observations and advice.  The old adage is that you "get what you pay for".  In the business world it transforms into "you get what you measure", and I will contend that in the Cyber Security world "you get what someone is liable for".  In fact, the government gets precisely what is measures, preferring to award Lowest Cost Technically Acceptable (LCTA) contracts where in general there is no significant liability for Cyber failure and more importantly no emphasis on actually grading the contractors during source selection against Cyber security performance.  In the OPM case, the government hired a contractor to perform background checks and submit data.  This contractor’s system became entangled in the government’s system.  Because there was little emphasis on the Cyber security posture of the contractor as part of the performance of the contract, the contractor’s system was apparently not well managed or secured, and when the attackers found a hole, it ran all the way into the government and enabled the theft of massive amounts of data.  Most likely, the system was built by a contractor many years ago (of course this is speculation) and is still in place because budgets and priorities are always about maintaining status quo and "working on" new solutions.  In general, the government finds it significantly difficult to "abandon" outdated or obsolete systems, where industry does - it invests in the new modern methods and either sells of or disposes of the old.

Let me explain.  In the business environment companies have to directly address the risk of doing business.  This is represented by insurance for fire and theft, as well as in many cases for other business related issues such as product liability.  In the commercial world, poor business practices translate into higher business losses (for example product related liabilities) and an increase in costs due to rising insurance rates as well as potentially large expenses due to punitive damages imposed by a court decision.  In addition, business executives are directly accountable legally (e.g., Sarbanes-Oxley, HIPPA, etc.) and from their Boards and Stockholders - that is they lose their jobs and even can go to prison.  Business leaders are also responsible for the entirety of their business - accounting, hiring, delivery, liability, and profit to shareholders and owners.  Hence, they know how it all works together and they make decisions with the overall goal of sustaining the business and enabling growth as primary focus elements.

In the current government environment, and almost surely at OPM, none of the normal commercial business pressures are at play, especially in light of comments that "no one is personally responsible". The problem is that when the government takes on the responsibility directly, in general, there is virtually no administrative or legal repercussions for a massive failure.  Assuming good faith of effort, organizations such as OPM grow their government supervised internal Cyber Security operation setting-up processes, buying tools, and then trying to keep-up with the quickly morphing Cyber threat landscape.  Miss one step in this activity, and we get a massive Cyber failure.  Cyber security technology is not the culprit here - it is the lack of understanding by leadership as to how to apply Cyber security as an enterprise core competency where agency heads are not dazzled by the latest buzz words, but see the enterprise as a single architecture that includes its partners.

So, what can be done? A good friend of mine loves to quote Peter Drucker: "There is nothing so useless as doing efficiently that which should not be done at all".  In this case, doing more efficiently the internal Cyber efforts of a government organization nearly a waste, and the reason is simple.  Adding processes, tools, and oversight does not make anyone actually truly responsible or liable in the legal sense of the word.  What needs to be done is a complete shift of activity to an approach that selects providers that offer a warranty or service level agreement for not only the performance of the direct work (e.g., performing background checks) but also for all necessary associated IT components.  This is not just a selection by reputation, but a selection that is based on the company's willingness to "put their money where their mouth is".

The vision is that an organization like OPM will select a responsible party with a track record of performance that demonstrates that they can do the job and stand by their work when there is a Cyber event.  Sign them up for real metrics, for example on the time between discovery and reporting and for the number of days between major Cyber events.  Don't take their word for it, hire an independent auditor, review the Cyber performance every month (or week) and hold them to their agreements and hit them with penalties and even legal action for failure.  However, liability just is one element.  We must not perpetuate the "security is a separate function", so we need to do more.  We have to get away from escape clauses that boil down to the contractors "just doing what the government wants them to”, and where the government supervises or even performs the Assessment and Authorization (A&A) process for the systems.  Without these additional changes, the liability melts away into the political morass and standard government CYA.

The solution to our problem is that we need the system provider, and their subcontractors, to provide the "warranty" just as they do today for their financial systems.  Just as a company or the government may hire an accounting or financial firm today, they need to hire their Cyber firm - both need to be accepted and certified.  Then the government needs to focus on monitoring and spot checks, and not interfere in the contractor’s activities because when they do, the liability goes back to the unaccountable.

Of supreme importance, this needs to expand to include when the government contracts for virtually any service.  In OPM’s case the apparent root-cause system that enable the breach was associated with a contracted personnel background investigations company.  The fact that the performance of the contract came with an IT system that electronically interacted with the government's system is the point.  It does not matter what service or product you buy, you are buying into that company’s Cyber posture and how they manage their IT and how it interacts into agency’s IT.  This is what the CIO needs to understand and address.

You might ask whether anyone would take on such an activity, but it happens every day.  Certified Public Accountants and Professional Engineers have to sign their work.  Maybe it will scare away some of the "Johnny come lately" Cyber "expert" companies that give advice but take no responsibility for the actual result.  Companies that have their act together, that genuinely understand the risks and technology will rise to the occasion.

Using this method, there will never be a time when someone is not responsible.  True risk equals good reward for Cyber companies and other providers that actually stand up for their work combined with IT security results.  Maybe “doing efficiently” our current approach should “not be done at all” – after all it does not seem to be working.

Wednesday, September 18, 2013

Cyber Risks: If we don't care, they don't care?

This is a follow-up to my previous posts.  In Creating Cyber Risks which discusses the pervasiveness of  computer related security risks and our headlong charge of adding to these risks.  Later, in Who is Responsible for Internet Security, I discussed the landscape of the various technical areas of potential Cyber weaknesses and who is responsible for keeping the things up-to-date.

Almost at the same time, two different articles came to my attention.  Microsoft has released released a report that tracks the trends of whether home computer users are applying good practice security measures.


There is a disturbing trend in the above graphic which shows a steep decline in the number of users that are are using the basic security capabilities of their computers and networks or keeping their applications software up-to-date.  If this is the case, what are the odds that they are keeping the more hidden elements current (e.g., device drivers, BIOS, etc.)?

Although this is disturbing, the presumption here is that the updates provided by a vendor actually improve the stability and security of an operating system or application.  However, as described in this report, Microsoft Update Quality Issues, this may not be true.  These updates are related not just to functionality improvements but also security improvements.  Pushed automatically to millions of machines at a time, these patches can cause virtually immediate new zero-day vulnerabilities that hackers are staged ready to exploit based on the known vendor path schedule.

So, we really have two problems and in each there really is no party other than the user that suffers.  If a user does not care to take best-practice measures to secure their systems, then an attack is more likely to be successful in either disabling computers or stealing information.  As discussed in Creating Cyber Risks, could enable a hacker to steal your money as well as enter your home.   Problem 1: User is responsible.

The second is that even if we do take care and score a perfect Microsoft Computing Safety Index (MCSI) score, the actual vendor provided updates can cause vulnerabilities.  Problem 2: Vendor takes no responsibility or liability - User is responsible.

So, if we don't care, will the vendors care to put our their best effort for Cyber-related issues?  And, if we do care, will marketplace embarrassment and corporate user agitation make the vendors care?

Monday, June 3, 2013

Creating Cyber-Related Risks - We are getting good at it!



There is not a day that goes by that there is not some discussion of Cyber or computer risks. For the largest part, it seems that the discussion is focused on the risk of information being hacked from government and government contractor systems. For example:

However, risks are more than hacking. There are other risks in the use of computers that we are adding on a day-to-day basis. Examples include:
  • Personal information shared both overtly and unknowingly on Social Networking sites such as Twitter, Facebook, Google+, etc.
  • Use of feature-rich business productivity services such as Google Apps for business.
  • Vehicle "telematics" systems such as OnStar.
  • Web accessible home security and energy management systems.
  • The nascent start of autonomous vehicles for consumers
Each of these risks alone are interesting, but taken together they form a comprehensive set of vulnerabilities that means an attack can come from just about anywhere in the world and strike at just about any time.

Let’s take them in order from above:

People are putting a tremendous amount of information into services such as Facebook, LinkedIn, Google+, etc. Much of this is personal information such as birthdays, home locations (current and past), education, contact information, presence and location information. These systems are now starting to include so call “two-factor” authentication to prevent unauthorized access to a person’s account - which should be a positive step in security. So, what are the risks:
  • This does absolutely nothing to stop the use of the information the user has already and continues to place in the system.
  • It also does not stop criminals who target and “social engineer” the user into “friending”, exposing the personal information to essentially the world.
  • I’m apparently on vacation or at a restaurant or bar, so come rob my house.
  • I placed enough information for the criminal to social engineer their way into other systems the victim may use. It may even be enough information to do a complete “Identity Theft” operation.


Business are moving in drive to the “Cloud”. In fact, I am writing this using Google Docs on my corporate Google Apps for Business account. The environment holds our email, calendars, selected documents, and messaging environment. Again, two-factor authentication can be used to secure access to the system, for a user or especially those that are administrators. Google constantly works to make their service more useful, attractive, and “sticky” to their customers. For example, the Google Now service, fully integrated into our employee’s smartphones (for those that use Android), searches their calendars, knows where they are, tells them when they should leave where they are to get to their next appointment, check them in for an upcoming airplane flight, as well as information based other items of interest to the employee. There are several risks again:

  • Unsurprisingly, for a user that is exploiting all the features of Google Apps, a compromised account provides a treasure trove of business and personal information, as well as essentially near-real time information of their location
  • Potential for access, on demand, by government investigators, such as the ominous (in my opinion) demands on Google to provide warrant-less access to customer accounts (see, Judge Tells Google To Five the FBI Customer Data)
  • In fact, just one account may not be compromised as the controls put into place by the Cloud service providers are apparently not all they need to be (see, BT Moves From Cloud Provider Based on Hacking Vulnerabilities)

The evolution of remote capabilities being embedded in the common car is transforming the relationship between car owner, their car, and the car manufacturer. No longer is the car just a sale to the customer with the potential of after sale service, the sale is now one that contains a growing list of services. Enabled by virtually continuous access to 3G and soon 4G wireless, there are services that:
  • Provide vehicle service information back to the manufacturer
  • Provides GPS and Cell Tower information to a services provider for navigation and traffic information
  • Enables a car that is reported stolen to be disabled
  • Enables an owner via a smartphone or tablet to open the car’s doors, start the car, and other functions
The risks here are profound. Insider threats, backdoors in the service provider’s systems, vulnerabilities in smartphone security, means that virtually any car can be stolen, tracked, or disabled remotely. In addition, as with the use of Cloud-based business services, information on a car’s travels may be demanded from the service provider by the government. Combined with your Cloud business information, someone is always able to track where you have been, where you are, and where you are going.

The more recent “oh my goodness” is the use of Internet-based home management systems. These systems, which are now being packaged by Cable and Telecom companies, as well as the traditional home security services, not only control the whether a home’s alarm system is active or turned-off, but also the heating and cooling system, cameras, and some can even open door locks. With the convenience of a mobile App, with a few swipes or presses you are in control. Of course, so it anyone that is able to take control of your smartphone, your security account, and certainly staff at the service providers operation centers (which makes me think of where these may be located). Again, like other well publicized cases, attacks on service providers have yielded access to thousands of user accounts.

A couple of scenarios:
  • You may think it is cool that you can make sure the lights are on in your house and the air conditioning is turned back on to prepare for your arrival from a long vacation, but what you may find is that the doors of the house are open and your valuables gone
  • You may think that you have the privacy of your own home, but what you really have is the government, a robber, a spy on your personal or business life, doing a bit of snooping without your knowledge.
Finally, I end on talking about autonomous cars. Lately, we have been entertained in the news on how far this technology has gone. Just a decade ago, these were lumbering vehicles moving only a few miles-an-hour on a course safely tucked away from the potential to harm anything or anyone. Now, these are moving through cities and highways navigating around work zones and what would appear to be difficult driving situations. In light of the progress, the Federal Government wants States to be a bit apprehensive (see, Caution Urged in Allowing Autonomous Cars).

In this case, it probably does not take a Cyber attack to gum-up the works. With a little ingenuity, paint, signs, and fake barriers, I wonder how hard it would be to fake the car into deciding that the road is under construction and the detour leads directly through my house.  Think of the damage that a "terrorist" could do on the D.C. Capitol Beltway (all without a firearm, fertilizer, or other items normally associated with an "act of terror").

All combined, we are creating a Cyber and Computer risk environment that is all around us. It is not clear how to even begin to deal with the combination business risk, U.S. Constitutional issues, business risk, personal property risks, national security risks that may become a security whack-a-mole - especially if being directed by a foreign (or domestic) adversary for money or power.