As the nation struggles to come to terms with the coronavirus and questions linger around our readiness for such a pandemic, government leaders are already grappling with the next potential catastrophe — a major cyberattack against the U.S.
A new report issued by the federal Cyberspace Solarium Commission, a congressional body chaired by Sen. Angus King and Rep. Mike Gallagher, opens with a dire warning: that the country is “dangerously insecure in cyber” and “…is at risk, not only from a catastrophic cyberattack but from millions of daily intrusions disrupting everything from financial transactions to the inner workings of our elections,” reports Dark Reading.
In response to this threat, the Commission published more than 75 recommendations to lawmakers on ways in which public and private entities can strengthen their security posture to reduce the probability and impact of cyberattacks.
Lack of clarity hampers cybersecurity risk reduction
Yet even as cyber incidents are increasing in frequency and severity, the report acknowledges a major roadblock to achieving this goal: that both the U.S. government and broader marketplace “lack sufficient clarity about the nature and scope of these attacks to develop nuanced and effective policy responses.”
Much of the problem lies in the fact that official data sets are incomplete and provide only a superficial or cursory understanding of evolving trends in cybersecurity. The Department of Justice gathers data on cyber-crime, but the data is woefully out-of-date. Meanwhile, the FBI Cyber Crime division collects statistics on the monetary cost of cybercrime, but only on cases that it deals with. And while many industry titans in the cybersecurity sector assemble vast amounts of data about the true state of cybersecurity in the U.S., they are not obligated to disclose it.
This makes it hard for government and private companies to model and understand cyber risk and tell if they’re making progress defending their systems.
How a proposed Bureau of Cyber Statistics could help
In response to these data gaps, the report calls on Congress to establish a Bureau of Cyber Statistics within the Department of Commerce. The Bureau would collect, process, analyze, and disseminate essential data on cybersecurity, cyber incidents, and the cyber ecosystem. In partnership with NIST, the Bureau would use this data to help inform Americans of risk, drive greater risk reduction, and assist the government in crafting more effective cyber policy and programs.
But the responsibility for measuring cyber risk shouldn’t lie with the government alone. Whether or not these recommendations become law, the Cybersecurity Solarium Commission has identified serious shortcomings in the nation’s cybersecurity posture. Considering this, every organization has an obligation — to their customers, partners, investors, and employees – to apply meaningful metrics to cybersecurity performance.