Federal Cyber Safety: Are We Winning or Losing?

At the recent Safety Innovation Network (SINET) event held in Washington D.C recently a sober assessment of our nation’s capacity to maintain an adequate cyber defense emerged.

The state of our cyber defense was summarized by Michael Chertoff, former Secretary of the Division of Homeland Safety when he concluded that it may possibly take “a digital 9-11” to get organization, customers and governments to fortify their cyber safety defenses. In impact we are fighting an asymmetrical war and, at present, we appear to be losing.

Echoing this theme, Mr. Vivek Wadhwa, a respected cyber safety analyst, argues, “Government just cannot innovate rapid sufficient to maintain pace with the threats and dynamics of the World-wide-web or Silicon Valley’s swiftly altering technologies.”

Wadhwa goes on to point out that revolutionary entrepreneurial technologies advancements are needed but the government, for the reason that of it overwhelming dependencies on substantial contractors, is not equipped to take advantage of new and powerful cyber defense technology.

Wadhwa concludes that true innovation developed by means of smaller entrepreneurial firms is becoming stifled by Federal Government procurement practices.

The Federal Government Acquisition Approach is Inadequate:

Even though Wadhwa’s argument is focused on technologies development only it also applies equally to service providers who adapt new technologies to new and improving defensive techniques such as vulnerability assessment, evaluation of threats and remedial action.

Considering that successful defense against cyber attacks is an on going procedure of monitoring and taking coercive action, the role of solutions and the cyber warrior is also critical and outdated Federal acquiring patterns are equally harmful.

Substantially of the problem stems from the present buying and acquisition patterns of the government. For years now the government has preferred to bundle needs in to big “omnibus” or IDIQ contracts (with negotiated task orders) that favor the biggest contractors but stifle innovation and flexibility. Cyber security needs are treated on a like basis with Info technologies specifications and this is a error.

In addition, recent Congressional contracting “reforms” have encouraged protest actions on new contracts and task orders for each new and existing contracts, resulting in a significant delay of the procurement course of action. In the quickly evolving world of cyber safety, delayed deployment of normally obsolete technologies options increases the risk of a prosperous attack.

For the reason that these contracts are extremely large, they demand lots of levels of approval-usually by Congress or senior administration officials. It normally requires three-four years for government to award these and thriving bidders regularly have to go via a grueling “certification” method to get approved to bid. Proposal efforts for big bundled contracts price millions of dollars to prepare and to lobby government officials and political leaders in order to win.

For the reason that of buying patterns that are slanted toward big, slower moving contractors new technology expected to meet the multitude of cyber threats will be ignored in the coming years. This puts the nation at risk.

Compact contractors are typically overlooked in favor of substantial contractors who frequently use contract vehicles to provide services and solutions that are frequently out of date in the swiftly altering cyber planet.

Startups can’t wait this extended or afford the price of bidding. But it is not sufficient to demonize significant contractors when the root bring about lies is how the government procures technologies.

In cloud solutions to remedy this trouble an overhaul of the acquisition and procurement process is required to level the playing field for compact cyber security firms: it should be made much easier for startups and little service providers to bid for government contracts.

One particular efficient way to do this is to unbundle the cyber needs for IT acquisitions and use extra tiny enterprise set asides for contract awards. In addition protests at the Basic Accounting Office should be discouraged and reserved only for obvious abuses of the contracting procedure.

Procurement times need to be reduced to months rather than years some projects should be performed in smaller sized actions so that the main contractors, whose target is generally income maximization and placing unqualified bench employees, are not the only ones certified to full them.

Cyber attacks on our sensitive infrastructure and government agencies have increased substantially. We want the latest technology and very best tools in order to win the cyber war.