Feeds

Tom Ridge: Private sector lagging in cybersecurity

Former US Homeland Security boss scorns enterprise security efforts

Internet Security Threat Report 2014

Poor communications, weak management and a lack of communications with government agencies is leaving many large enterprises vulnerable to targeted cyberattacks, according to former US Homeland Security boss Tom Ridge.

Speaking at a press event in San Francisco, Ridge said that the growth in security threats targeting government and military targets along with critical infrastructure has driven the US government to pour resources into both defensive and offensive efforts, many companies within the private sector have lagged behind.

"The warfighters are presently laser-focused on the risk associated with the cyber world," Ridge said. "I dare say the private enterprise does not bring the same acuity to the risk in the digital forevermore."

Now the CEO of his own security consulting firm, Ridge rose to the national stage first as governor of Pennsylvania and then as the first secretary of the Department of Homeland Security under the George W. Bush Administration.

Ridge said that in his security work, he has found that firms often fall behind on security for a number of reasons. In doing so, he notes that contractors and private firms which handle critical infrastructure could be leaving citizens vulnerable to attacks.

In some cases, he notes, executives fail to put adequate security policies in place, or offload the responsibility for cybersecurity as an IT issue rather than a larger corporate policy problem. In other instances, he sees firms settling for filling out a checklist of compliance requirements and ignoring the broader security concerns behind those points.

While much has been said of the upstream flow of data from private companies to government organizations, the flow of intelligence information back down from the government to CSOs and security providers remains wanting.

Among the most glaring holes, says Ridge, remains the gap that exists between government agencies and the private sector in regards to sharing data. While critical of the security work being done by large enterprises, Ridge noted that due to government practices such as restricting data with overly restrictive classifications and over regulating the flow of data to private firms, the government is withholding potentially valuable intelligence from private firms.

"You have to go from a 'need to know' mindset to a 'need to share' mindset," Ridge said.

"You can not secure the country from inside the Beltway." ®

Internet Security Threat Report 2014

More from The Register

next story
George Clooney, WikiLeaks' lawyer wife hand out burner phones to wedding guests
Day 4: 'News'-papers STILL rammed with Clooney nuptials
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
PEAK IPV4? Global IPv6 traffic is growing, DDoS dying, says Akamai
First time the cache network has seen drop in use of 32-bit-wide IP addresses
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
Stunned by Shellshock Bash bug? Patch all you can – or be punished
UK data watchdog rolls up its sleeves, polishes truncheon
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.