
Since the early 1990s, the US government has been aware of the dangers of cyber threats and has taken various measures to address them. Though the attempts at security governance have been sincere, they have not been as successful as expected.
Since 2015, the federal government has experienced various cyber incidents because of ineffective risk management programs and a lack of accountability frameworks. Notably, in 2020, the SolarWinds hack revealed vulnerabilities in all national systems, leaving them open to malicious actors. These cybersecurity risks demonstrate how vulnerable the US is to malicious activity and how easily it can control the country’s fuel and food supplies.
Why Are Governments Being Targeted?
Cybercriminals target local governments for multiple reasons. For starters, the United States has more than 90,000 unique local governments, making it almost impossible to design and implement a unified approach to cybersecurity. It also does not help that local and state governments hold a significant amount of sensitive data and intellectual property, including people's Social Security numbers, driver's license information, and medical records.
Moreover, local government systems often lack a strategic view of cybersecurity strategies. This is partly due to financial constraints, with several agencies unable to match the competitive compensation in hiring employees with skills needed for cybersecurity.
Cybersecurity in Critical Infrastructure
Cybersecurity is vital in keeping critical infrastructure operational. Critical infrastructure includes telecommunications, electricity distribution, water supply, and transportation, which are all essential in maintaining a functional society. These networks are often managed by an IT system, making it crucial to assign 24/7 support teams for consistent monitoring and controlling.
Some agencies invest in remote vendor support to increase efficiency and reduce costs, but it also leaves their systems open to more vulnerabilities and potential information leaks. Devising a resilient cybersecurity strategy is essential in maintaining operational uptime while protecting information systems.
How Are State and Local Governments Responding to Cyber Threats?
Both state and local governments are responding to cyber threats on multiple fronts. President Biden's administration is treating ransomware with the same gravity as terrorism, with a proposed spending bill that includes infrastructure resilience, artificial intelligence (AI), and quantum computing funding. Moreover, the President asked Congress to allot $9.8 billion for strengthening cybersecurity governance programs.
The federal government has employed thousands of people in cybersecurity roles to mitigate massive security risks. CISA (Cybersecurity and Infrastructure Security Agency) functions as the prominent cyber risk consultant of the country, focusing on protecting the federal network and digital critical infrastructure like power plants and dams.
CISA also helps private companies, primarily critical infrastructure corporations like power utilities, by providing substantial coordination and guidance regarding the latest threats.
Laws and Standards for Cybersecurity in Government
Government agencies and private companies work together to craft laws and policies to improve national cybersecurity. Federal cybersecurity regulations include HIPPA, Gramm-Leach-Bliley, and FISMA, which was initially part of the Homeland Security Act of 2002.
Unfortunately, different government agencies have reached varying levels of progress in keeping information secure, with some lagging considerably. For instance, a 2019 audit showed that the Office of Personnel Management (OPM), a victim of a significant data breach in 2015, still had not addressed the vulnerabilities that caused the attack. Reports also found that OPM didn't appropriately manage user access based on their work roles, allowing hackers to penetrate its network.
Top Risk Management Strategies for Governments
Governments have adopted several risk assessment and security management strategies to mitigate cyber threats and reduce disruptions in the supply chain. Here are some examples:
- Adoption of 5G Technologies
5G technology continuously provides new capabilities and services to transform business operations while improving cybersecurity. While 5G solutions are primarily used in the private sector, multiple agencies are adopting modern systems to address gaps in their cybersecurity.
CISA and the Department of Homeland Security's Science and Technology Directorate submitted a five-step 5G Security Evaluation Process to improve security assessment guidance and create better standards in 5G technologies.
- Threat Sharing
Information-sharing remains one of the most effective ways to combat crime. The government and private industry continue to improve at sharing threat intelligence, with many Information Sharing and Analysis Centers (ISACs) established nationwide. ISACs are created to share relevant threat information with concerned entities, enabling better protection for everyone involved.
- Secure Cloud Business Application (SCuBA) Project
CISA established the Secure Cloud Business Applications (SCuBA) project to build cybersecurity guidance for Microsoft 365 (M365) and Google Workspace (GWS) services. The project aims to leverage vendor native capacities and third-party solutions to provide security configurations that can offer foundational protection for cloud applications, including giving CISA added visibility to identify and detect suspicious activities in the cloud.
Cybersecurity Employment in Government
The United States federal government is possibly the world's largest employer of cybersecurity professionals, with the exact number being unknown or undisclosed.
These jobs include security officers and personnel from agencies such as the CISA, the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI). Even divisions of the armed forces are now heavily investing in their cyber operations.
A Final Word on Cybersecurity Governance
Top government officials must make cyber risk management a primary concern, as the results of a security breach, including those involving national security, can be catastrophic. Leaders should collaborate with cybersecurity professionals to develop comprehensive cybersecurity frameworks and strategies.
To achieve effective cybersecurity governance, agencies must create an overarching plan that includes multiple security layers, from solid perimeter defense and enterprise risk management to improved threat monitoring and cybersecurity awareness. Keeping up with the latest cybersecurity trends in the public sector is an excellent first step in identifying which threats your system should be ready for.
