Stopping Data Breaches Will Require Help from Governments

3 min read
Curated from hbr.org →

When it comes to cybersecurity, companies are on their own. We need to work together with government to create more on systemic solutions.

Not a month goes by without a major corporation suffering a cyber attack.  Often state-sponsored, these breaches are insidious, difficult to detect, and may implicate personal information relating to millions of individuals. Clearly, the current approaches to safeguarding sensitive data are insufficient. We need to reorient expectations for the role of the private sector in cybersecurity.  As the risk of cyberattacks has become better appreciated, we see an increasingly punitive focus on holding corporate America solely responsible.

Multiple, overlapping laws at the national and state level require companies to have “reasonable” security, a concept that is largely undefined and elusive, especially given that threats and available defensive measures constantly evolve. And regulatory enforcement actions and lawsuits in the wake of cyberattacks declare any exploited security vulnerability to be de facto “unreasonable,” without a meaningful assessment of the company’s overall security program or acknowledgement that the company has been the victim of a crime.

This approach is premised on an unreasonable expectation that every company in the United States has the resources and capability to defend itself against even the most sophisticated cyber actor.  We should move away from laws that focus on finding companies at fault, rather than as victims of criminal cyber activity.  This framework is neither fair nor effective in improving our collective cybersecurity.

In our experience, despite increasing security spend, most companies face significant obstacles to successfully managing cyber risk.  Although some industry security standards have emerged, they are  vague, and available security solutions are seldom turnkey.  Rather, effective security requires application of significant judgment in the context of unique and complex corporate network architectures, as well as the ability to adapt as security solutions and threats evolve.  Unfortunately, the talent pool with the requisite cyber experience and knowledge is limited.  It is simply not possible, at present, for every company in America to have sufficient internal cyber expertise to manage the risk.

The challenge is compounded by the resources and sophistication that state and criminal cyber attackers can bring to bear.  In no other arena do we expect every business to defend itself from foreign intelligence and military agencies or sophisticated criminal threats.

Although there has been a significant focus on sharing threat information, both within the private sector and between the government and the private sector, such sharing remains incomplete at best, particularly when it comes to the techniques, tactics, and procedures that particular actors are employing.  As a result, companies often lack sufficient knowledge of the specific threats they face so they can best defend themselves.

Given these and other factors, companies that suffer cyberattacks are, and should be treated primarily as, victims.  When a bank suffers a physical robbery, we do not think of blaming and shaming it – even though there is almost always some additional precaution the bank could have taken that might have helped prevent the attack (such as a police officer stationed at every teller window or limiting customer access to tellers).  While banks are expected to implement some security measures, there is no expectation that those measures will prevent criminal attacks entirely, and banks are not vilified if they did not have every available precaution in place that might have prevented them.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at hbr.org →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.