Montreal Gazette

Government urged to set cyber standards

- JORDAN PRESS

OTTAWA — Gover nments should move to secure private networks in the name of national security — possibly even forcing standards upon the industry, two experts in cyber-security said Thursday.

The end of that road could require Canada and other government­s to legislate cybersecur­ity standards, according to the former chief of Canada’s ultra-secretive cyberspy agency, because voluntary standards can be ignored.

The Harper government has rejected legislatin­g basic standards for cyber-security, opting instead to share best practices with industry. A recently released research paper for Canada’s spy agency, CSIS, suggested funding cyber-security for critical infrastruc­ture, such as water systems and electrical grids, in the name of national security. The Obama administra­tion trod lightly on this in a recent executive order, announcing only voluntary security standards for companies that run critical infrastruc­ture in the U.S.

Top U.S. politician­s and defence officials have suggested the threat in cyberspace is so great that an attack on critical infrastruc­ture could cripple countries, a scenario American officials have repeatedly dubbed a “cyber Pearl Harbor.”

The number of attacks on U.S. systems has grown as the number of users and devices connected to the Internet continues to grow. Online disruption­s successful­ly targeted Estonian networks in 2007, and last year a malicious program rendered 30,000 computers at the Saudi Arabian state oil company unusable.

Much of the concern over government involvemen­t in cyber-security, such as having Internet service providers tell federal security agencies about potential attacks or disruption­s to systems, comes down to worries over the loss of civil liberties.

A report this week from IT security firm Mandiant alleged a specialize­d Chinese military unit was behind the hacking of 141 companies in the last six years, stealing corporate secrets from enterprise­s including Canadian company Televent, which creates the computer systems that operate pipelines. China has denied the accusation­s.

Worldwide, cyber-criminals are estimated to have stolen $4 trillion annually, Adams said, while companies spent about $15 trillion fighting such losses.

The White House announced Wednesday it would move to punish countries that don’t do enough to crack down on hackers stealing corporate secrets, naming China, India and Russia as possible culprits.

A spokesman for Public Safety Minister Vic Toews didn’t directly respond to the U.S. strategy Wednesday, saying only that through the government’s cyber-security strategy government agencies would “work with the private sector and our allies to guard against these threats.”

Gen. Keith Alexander, the head of U.S. Cyber Command, said no network will be completely safe from hackers and the best defences can always be compromise­d. He said government­s should move to a secure cloud network to limit the number of vulnerabil­ities in a traditiona­l network, an option the Harper government has been considerin­g.

 ?? SEAN KILPATRICK/ THE CANADIAN PRESS ?? Gen. Keith Alexander, head of U.S. Cyber Command, said no network is completely safe from hackers.
SEAN KILPATRICK/ THE CANADIAN PRESS Gen. Keith Alexander, head of U.S. Cyber Command, said no network is completely safe from hackers.

Newspapers in English

Newspapers from Canada