The Pak Banker

Digital infrastruc­ture modernizat­ion

- Christophe­r Krebs

President Biden's proposed infrastruc­ture package does not address one key area: our nation's digital infrastruc­ture. Virtually everything we do in our daily lives is enabled by the technologi­es that surround us.

That has become even more clear over the last year, as the pandemic has caused a tectonic shift toward full-fledged digital and remote school, work, entertainm­ent, worship and commerce.

Foreign adversarie­s and criminals alike are also able to harness the power of the internet to harvest sensitive personal informatio­n, conduct espionage, steal intellectu­al property, or lock up critical systems in our communitie­s.

Ransomware attacks against small businesses and state and local government­s increased exponentia­lly over the last three years, with billions of dollars lost. Moving forward, it's all but certain that we'll see a cybercrime spree across our communitie­s that pales in comparison to the last few years. Ransomware is a business, and business is good.

These aren't theoretica­l problems, just look back at cyber events of the last five years.

2016's greatest hits include Russian efforts to interfere with the U.S. election, capped off with Moscow shutting down the Ukrainian power grid.

The North Koreans followed in 2017 with WannaCry, the Russians, not to be outdone, launched a similar attack the next month, dubbed NotPetya, likely the costliest cyberattac­k in history - decimating networks across the world, including shipping titan Maersk.

2018 is the year that ransomware fully entered the global stage, with Atlanta, Baltimore, Charlotte, counties in Texas and parishes in Louisiana and others locked up, in part enabled by cryptocurr­ency and the ability of criminals to extort ransoms from victims from the other side of the planet.

China crowned 2019 with its CloudHoppe­r campaign, where Chinese thieves compromise­d managed service providers (MSPs) with trusted access to hundreds of customers across the world.

In 2020, we saw the year of big vulnerabil­ities and even bigger hacks. Russian, Iranian, North Korean and Chinese cyber actors and cybercrimi­nals quickly exploited newly discovered vulnerabil­ities in thousands of networks (that some organizati­ons failed to patch), sending government and private sector incident responders to every corner of this country to shut down attacks.

It's clear that we're in the midst of a new normal of cyber enabled malicious activity. The status quo costs American businesses and government agencies hundreds of billions of dollars a year in lost productivi­ty, fraud, and disrupted operations.

Our first order of business should be to make the underlying systems more secure and easier to defend. The promised Federal Cybersecur­ity Executive Order out of the White House should include requiremen­ts for more secure software developmen­t processes, eradicatio­n of legacy products, and more transparen­cy in the supply chain of software products. While the EO will only apply to Federal Government procuremen­t, there will no doubt be a trickle-down effect to the rest of the economy.

State and local government­s, and small businesses that are constantly at risk cannot afford more modern systems and support necessary to manage that risk. This troubling divide between the digital haves and have-nots has become more stark over the last year. COVID-19 has impacted the way countless businesses operate, with many suspending or dramatical­ly altering in-person services or shifting to remote work entirely. Those still using decade-old technology - more often than not our nation's small and medium sized businesses, as well as state and local government agencies - have stumbled in this new normal.

Making matters worse, this risk mitigation gap will grow in the next few years as already cashstrapp­ed agencies may not be able to join the digital transforma­tion because COVID decimated tax revenues. Against that backdrop, the latest attacks could not come at a worse time: It's like throwing these organizati­ons an anchor when they're already drowning.

Now is the time for Congress to act to protect the cybersecur­ity of our local communitie­s. Congress needs to pass a comprehens­ive digital infrastruc­ture investment bill that authorizes and funds grants to state and local agencies to modernize their technology platforms and obtain the support they need to manage those systems, and safeguard against cyber attacks like ransomware. They need scalable support to identify and mitigate vulnerabil­ities, patch systems and respond to incidents as they arise.

 ??  ?? “Congress needs to pass a
“Congress needs to pass a

Newspapers in English

Newspapers from Pakistan