U.S. to work with Big Tech, finance sector on new cybersecurity guidelines
21–30 of 59 posts
Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines
#22Checklists are not the answer. Some kind of liability framework seems like the answer. And perhaps through such a lens we'll discover that some businesses simply shouldn't exist.
None of the three had any clue if what we were saying was even true. Or what it would mean if it weren't.
To make myself more clear: checklists might be ok, if the checker can scour the code and prove such things. I've never met one that does or even seems to have the ability to.
Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines
#23We're getting closer and closer to cyber and kinetic warfare intermingling regularly. Attacking a US company may become akin to attacking a US citizen. State backed or State sanctioned actors will be looked at as an agent of the state itself. Hacks will lead to proportional responses from governments against governments. It's not much different than our military and contractors protecting domestic oil company interes…
What do you do in the case the actor is using a weak state as cover? Send a surgical strike into a country that aside from having the presence of the bad actor had nothing to do with it?
Work with law enforcement agencies in those countries to apprehend the person. If the country won't cooperate or shields the attackers, then sure, a drone strike could work.
Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines
#24Doesn't sound so nice when you put it like that.
Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines
#25A huge joke. If you have ever had to work with the DoD you may have had to deal with CMMC. It's totally ridiculous. At least it will boost the economy by adding thousands of security officer jobs and pad the pockets of any security vendor, and drive system administrators nuts by having to deal with shit like Microsoft Azure GCC High
Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines
#26We're getting closer and closer to cyber and kinetic warfare intermingling regularly. Attacking a US company may become akin to attacking a US citizen. State backed or State sanctioned actors will be looked at as an agent of the state itself. Hacks will lead to proportional responses from governments against governments. It's not much different than our military and contractors protecting domestic oil company interes…
What do you do in the case the actor is using a weak state as cover? Send a surgical strike into a country that aside from having the presence of the bad actor had nothing to do with it?
Here's the plan: invade Afganistan, and eventually find the guy years later in a compound in Pakistan.
Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines
#27Checklists are not the answer. Some kind of liability framework seems like the answer. And perhaps through such a lens we'll discover that some businesses simply shouldn't exist.
The only way to have liability is ... show people didn't follow a checklist. The main way to show a restaurant is liable for getting people sick is to show they didn't follow the health code, the main way to show a company is liable for fire is to show they violated various codes, etc.
For computer security, I'd want to see liability on results, and not just on the methods and the checklists. If a company has a data breach, then that's something for which they can be held liable. That might mean that it becomes much more expensive to maintain large databases on users, which would be a good change.
Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines
#28What systems can do that?
Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines
#29Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines
#30What good can come from this? "We want to improve our cybersecurity - lets engage the biggest technology companies in the country." If we invite them all to a luncheon, their collective knowledge of "cyber" must lead to something good, right? Except all of these executives likely have limited understanding of cybersecurity at best. At worst, they or their team already thought up regulations to help crush early compan…