Federal Cyber Security: Are We Winning or Losing?

At the current Safety Innovation Network (SINET) occasion held in Washington D.C not too long ago a sober assessment of our nation’s capacity to maintain an adequate cyber defense emerged.

The state of our cyber defense was summarized by Michael Chertoff, former Secretary of the Division of Homeland Safety when he concluded that it may perhaps take “a digital 9-11” to get business, buyers and governments to fortify their cyber security defenses. In effect we are fighting an asymmetrical war and, at present, we seem to be losing.

Echoing this theme, Mr. Vivek Wadhwa, a respected cyber safety analyst, argues, “Government basically can’t innovate rapid adequate to keep pace with the threats and dynamics of the Web or Silicon Valley’s rapidly altering technologies.”

Wadhwa goes on to point out that innovative entrepreneurial technology advancements are needed but the government, because of it overwhelming dependencies on significant contractors, is not equipped to take benefit of new and powerful cyber defense technologies.

Wadhwa concludes that accurate innovation developed through smaller entrepreneurial firms is becoming stifled by Federal Government procurement practices.

The Federal Government Acquisition Technique is Inadequate:

Though Wadhwa’s argument is focused on technologies improvement only it also applies equally to service providers who adapt new technology to new and enhancing defensive techniques such as vulnerability assessment, analysis of threats and remedial action.

Considering the fact that successful defense against cyber attacks is an on going method of monitoring and taking coercive action, the function of solutions and the cyber warrior is also important and outdated Federal purchasing patterns are equally dangerous.

Substantially of the issue stems from the present getting and acquisition patterns of the government. For years now the government has preferred to bundle specifications in to substantial “omnibus” or IDIQ contracts (with negotiated process orders) that favor the largest contractors but stifle innovation and flexibility. Cyber security requirements are treated on a like basis with Information technology specifications and this is a error.

In addition, current Congressional contracting “reforms” have encouraged protest actions on new contracts and process orders for each new and current contracts, resulting in a substantial delay of the procurement method. In the fast evolving planet of cyber security, delayed deployment of frequently obsolete technologies solutions increases the danger of a profitable attack.

Since these contracts are particularly massive, they demand numerous levels of approval-usually by Congress or senior administration officials. It ordinarily takes 3-4 years for government to award these and profitable bidders regularly have to go via a grueling “certification” approach to get authorized to bid. Proposal efforts for big bundled contracts expense millions of dollars to prepare and to lobby government officials and political leaders in order to win.

Because of obtaining patterns that are slanted toward huge, slower moving contractors new technology necessary to meet the multitude of cyber threats will be ignored in the coming years. This puts the nation at danger.

Small contractors are normally overlooked in favor of big contractors who regularly use contract cars to deliver solutions and options that are often out of date in the quickly altering cyber planet.

Startups can not wait this extended or afford the cost of bidding. But it is not enough to demonize big contractors when the root result in lies is how the government procures technology.

In order to remedy this challenge an overhaul of the acquisition and procurement procedure is required to level the playing field for modest cyber safety organizations: it ought to be made less difficult for startups and smaller service providers to bid for government contracts.

1 helpful way to do this is to unbundle the cyber needs for IT acquisitions and use more smaller company set asides for contract awards. In web app pen test at the General Accounting Workplace have to be discouraged and reserved only for obvious abuses of the contracting approach.

Procurement instances ought to be reduced to months rather than years some projects should really be performed in smaller sized actions so that the significant contractors, whose aim is normally income maximization and putting unqualified bench staff, are not the only ones certified to complete them.

Cyber attacks on our sensitive infrastructure and government agencies have elevated substantially. We want the most up-to-date technology and very best tools in order to win the cyber war.

Leave a Reply

Your email address will not be published. Required fields are marked *