Showing posts with label Cyber Security. Show all posts
Showing posts with label Cyber Security. Show all posts

Broadcasting as a Cyber Threat Vector: Ten Steps Broadcasters Need to Take Now


Cyber threats to financial institutions, electric utilities, broadband providers, government agencies, Hollywood studios and even emerging Web-connected household appliances get a lot of ink. But one major potential threat vector, television and radio broadcasting, doesn't conjure up the kind of concerns that these other avenues of cyber intrusion do.

That's changing, though, in the wake of a major cyber attack that took place last April when French broadcaster TV5Monde was hijacked, with eleven of its channels going dark and its social media outlets commandeered to display pro-ISIS messages. Although a group called the CyberCaliphate claimed credit for the damaging breach, the French government has lately cast some blame on Russian hackers who, the government suggests, was using the CyberCaliphate as a false flag.

Whatever the case may be, the TV5Monde attack was a wake-up call to the broadcasting sector that it too is vulnerable to the kinds of disruptive cyber intrusions and attacks that affect other critical aspects of society. That's why top broadcasting publication TVNewsCheck and I have joined hands to offer the first of its kind webinar, "Cybersecurity for Broadcasters: Ten Steps You Need to Take Right Now," aimed at helping broadcasters come up to speed on how to protect their assets from unwanted and potentially damaging cyber intrusions and how to become more resilient in the face of what will undoubtedly be more future cyber attacks.

Slated for July 22 from 2 pm to 3:30, the webinar features a top line-up of experts (with more to come) including:
  • Rear Admiral (ret) David Simpson, Bureau Chief, FCC Public Safety and Homeland Security
  • Kelly Williams, Engineering & Technology Policy, Senior Director, National Association of Broadcasters
  • Ed Czarnecki, Strategy & Global Government Affairs, Senior Director, Monroe Electronics
For more background on the array of cybersecurity concerns that broadcasters face, check out the piece I wrote for TVNewsCheck that I hope lays it all out fairly well and stayed tuned for more information as we update the speaker line-up. If you have any thoughts or questions, drop me an email. (As a personal aside, it's been nice to bring my two areas of professional experience, communications media and cybersecurity, together in an interesting project, something I hope to continue to explore).

And don't forget to check out Metacurity.com, a continuously updated source of cybersecurity intelligence and news aimed at solving the info-overload that increasingly bedevils most infosec professionals.

Top Cybersecurity Writers, By the Numbers


Last week I posted an analysis of how often various publications appeared during the first six weeks or so of active tracking on Metacurity, our new continuously updated resource on cybersecurity news and information. (For more on Metacurity and how we're selecting which articles and blog posts make the cut, see this post).

Now we turn to the actual journalists, bloggers, pundits and others who actually write the posts.  As the table below shows, 128 writers appeared more than once in approximately 1,220 posts from March 29 through mid-day on May 6 (links are to the writers' Twitter profiles, where they could be found).

Topping the list is Darren Pauli from The Register, not a surprise given that The Register also topped our list of publications, focused as it is on the nitty-gritty of IT technology. In fact, the vast majority of writers who top the list below are focused almost exclusively on matters related to information security -- again no surprise.

A word of caution though:  quantity does not necessarily equal quality. Many of the top writers working in the field appear lower down on the list presumably because they are not pressured to fill the hole each day and are given some latitude to spend time on bigger pieces or on related beats, such as privacy and national security.

In addition, some excellent writers are working for publications that put content behind paywalls and are not reflected here (Politico is the exception because some Politico pieces are available without paid subscriptions).

I was surprised at the amount of feedback I received on the first post detailing the publications by the numbers and welcome again feedback on this list.  As Metacurity evolves we will be adding additional publications, bloggers and sources and new features that make the site a more dynamic resource for cybersecurity news and information. Give us your feedback on the sources we rely upon and what additional information we should be incorporating into our system.

Metacurity Posts by Writer, 3/29/2015 to 5/6/2015
Writer# PostsPrimary Publication
Darren Pauli32 The Register
Waqas31 Hack Read
Eduard Kovacs27 Security Week
John Leyden24 The Register
Maria Korolov21 CSO Online
Dan Goodin20 Ars Technica
Michael Mimoso19 Threat Post
AFP17 Security Week
BrianPrince17 Security Week
Mike Lennon16 Security Week
Zack Whittaker16 ZDNet
Lorenzo Franceschi-Bicchierai15 Motherboard
Adam Greenberg15 SC Magazine
Brian Krebs15 Krebs on Security
Ashley Carman12 SC Magazine
Lucian Constantin12 CSO Online
Dennis Fisher12 Threat Post
Aliya Sternstein12 NextGov
Thomas Fox-Brewster11 Forbes
Andy Greenberg11 Wired
Kelly Jackson Higgins11 Dark Reading
Charlie Osborne11 ZDNet
Sara Peters11 Dark Reading
Cory Bennett10 The Hill
Graham Cluley10 Graham Cluley
ERICKA CHICKOWSKI9 Passcode
Richard Chirgwin9 The Register
Jeremy Kirk9 CSO Online
Steven Ragan9 CSO Online
Iain Thomson9 The Register
Danielle Walker9 SC Magazine
Kim Zetter9 Wired
Dustin Volz8 National Journal via Next Gov
Robert Abel7 SC Magazine
Kyle Ellison7 We Live Security
Julian Hattem7 The Hill
Alexander Martin7 The Register
JAIKUMAR VIJAYAN7 Passcode
Stewart Baker6 Lawfare
Cyrus Farivar6 Ars Technica
Grant Gross6 Computer World
Shaun Nichols6 The Register
Mohana Ravindranath6 Next Gov
Bruce Schneier6 Lawfare
Sara Sorcher6 Passcode
Leon Spencer6 ZDNet
Taylor Armerding5 CSO Online
Chris Brook5 Threat Post
Joseph Cox5 Motherboard
Brian Donohue5 Threat Post
Sean Gallagher5 Ars Technica
Frank Konkel5 NextGov
Dave Lewis5 Forbes
Mario Trujillo5 The Hill
DAN FROOMKIN4 The Intercept
Hallie Golden4 NextGov
Robert Graham4 Errata Security
Swati Khandelwal4 The Hacker News
Rachel King4 ZDNet
Glyn Moody4 Ars Technica
Jordan Pearson4 Motherboard
Nicole Perlroth4 New York Times
Elise Viebeck4 The Hill
Wang Wei4 Hacker News
Paul Farrell3 The Guardian
Samuel Gibbs3 The Guardian
Roger Grimes3 Info World
Shane Harris3 The Daily Beast
Michael Heller3 TechTarget
Ben Kepes3 Forbes
Jason Koebler3 Motherboard
David Kravets3 Ars Technica
Mohit Kumar3 The Hacker News
Tony Morbin3 SC Magazine
Paolo Passeri3 Hackmageddon
Steve Ranger3 ZDNet
Teri Robinson3 SC Magazine
Jack Schofield3 ZDNet
Evan Selinger3 Passcode
Darlene Storm3 Computer World
Lee Suster3 SC Magazine
Kevin Tofel3 ZDNet
Joe Uchill3 Passcode
David Auerbach2 Slate
Violet Blue2 ZDNet
Tony Bradley2 CSO Online
Steve Cobb2 We Live Security
Kenneth Corbin2 CSO Online
Chris Duckett2 ZDNet
Kristen Eichensehr2 Just Security
Lee Fang2 The Intercept
Kelly Fiveash2 The Register
John Fontana2 ZDNet
Natalie Gagliordi2 ZDNet
Megan Geuss2 Ars Technica
Alexandra Gheorghe2 Hot for Security
Stephen Glasskeys2 Computer World
Jack Goldsmith2 Lawfare
Matthew Goldstein2 New York Times
Tim Greene2 Computer World
Wendy Grossman2 ZDNet
Robert Hackett2 Fortune
Kat Hall2 The Register
David Harley2 WeLiveSecurity
Alex Hern2 The Guardian
Michael Horowitz2 ComputerWorld
Patrick Howell O'Neill2 Daily Dot
Gregg Keizer2 Computer World
Herb Lin2 Lawfare
Rafal Los2 Security Week
Alan Martin2 We Live Security
Tony Martin-Vegue2 CSO Online
Joseph Menn2 Reuters
Jack Moore2 Next Gov
Joe Mullin2 Ars Technica
Ellen Nakashima2 Washington Post
David Perera2 Politico
Jason Polancich2 Security Week
Fahmida Rashid2 Security Week
Paul Roberts2 Passcode
Paul Rosenzweig2 Lawfare
Simon Sharwood2 The Register
Marc Solomon2 Security Week
Patrick Tucker2 Defense One
Camille Tuutti2 NextGov
Bob Violino2 CSO Online
Martyn Williams2 Computer World
Eileen Yu2 ZDNet

Top Cybersecurity News and Information Sources, By The Numbers - UPDATE


(Update:  Astute reader and topic maps (semantic integration) maven Patrick Durusau pointed out to me that I had the New York Times listed twice in an earlier version of this list, once as The New York Times and once as simply New York Times. The new list corrects this glitch.  Not only that but he also pointed out that National Journal and NextGov are different publications, which they indeed are.  But because NextGov publishes so many National Journal pieces, I'm not 100% certain from the data alone which came from which, so I merged the two.  He also kindly went out of his way to put hyperlinks to the relevant publications in my table!)

Starting on March 29, I began to systematically sift through voluminous news articles, blog posts and other sources to pick the most relevant, timely and knowledgeable items on cybersecurity matters to post on Metacurity.com. (See previous post for an introduction to Metacurity and an explanation of the criteria used for selection.) From that date through mid-day on May 6, Metacurity featured 1,220 posts from across well over 100 different publications, mostly traditional consumer interest and trade publications, as well as specialized blogs.

In an effort to better improve the selection and publication process, we’re currently analyzing the data to develop better filters and formulas.  One slice of interesting information is the frequency with which various publications appear across the still-nascent data set – obviously over time the data will change as the database gets bigger, more sources are added and newsworthy developments shift.

Articles Posted in Metacurity, 3/29/2015 to 5/6/2015
Source# Posts% Total
The Register1008.2%
SecurityWeek907.4%
CSOOnline685.6%
ZDNet625.1%
SC Magazine594.8%
Ars Technica483.9%
DarkReading483.9%
ThreatPost*413.4%
NextGov and National Journal413.4%
ComputerWorld322.6%
Hack Read322.6%
The Hill322.6%
Forbes312.5%
Motherboard302.5%
Passcode272.2%
Wired221.8%
WeLiveSecurity211.7%
The Guardian191.6%
New York Times171.4%
Krebs on Security151.2%
The Hackers News110.9%
Hot for Security100.8%
Lawfare Blog100.8%
The Intercept90.7%
Wall Street Journal90.7%
IT World70.6%
Slate60.5%
Just Security50.4%
Politico50.4%
Reuters50.4%
Schneier on Security50.4%
BBC News40.3%
Errata Security40.3%
Network World40.3%
TechTarget40.3%
The Daily Beast40.3%
The Diplomat40.3%
Washington Post40.3%
Bloomberg30.2%
Business Insider30.2%
DailyDot30.2%
Fortune30.2%
Google Security**30.2%
Hackmageddon30.2%
International Business Times30.2%
Telegraph30.2%
USA Today30.2%
FCW***30.2%
Financial Times20.2%
Freedom to Tinker20.2%
Harvard Business Review20.2%
Info World20.2%
Medium20.2%
MIT Technology Review20.2%
Quartz20.2%
The Security Ledger20.2%
Associated Press20.2%
Total99381.4%
*Technically a corporate blog by Kaspersky but features many newsworthy, journalistic-type posts.
**Technically a corporate blog by Google but important because of the nature of the posts.
***Recent resource added.

Of the sources published, 57 or 58 publications (I merged National Journal and NextGov)  received two or more posts, excluding posts from vendor blogs. Of these 57 or 58  sources, The Register grabbed more of the screen time than any other publication, no surprise given its focus on the nitty-gritty reality of IT technology. Likewise, all but one of the other top ten resources have as their main focus information security, IT technology or other specialized subjects where cybersecurity is a main concern.

The appearance of inside-politics publications such as the National Journal (which cross-publishes with NextGov) and The Hill is likewise no surprise given the ascendancy of cybersecurity in Washington and the pendency of cybersecurity legislation. A good deal of excellent coverage of Washington-related cybersecurity matters appears in paid-access-only publications such as Politico, which launched last year its own cybersecurity publication and makes some articles available outside its paywall. Paid-access publications don’t appear on Metacurity because, well, that would be too frustrating for casual visitors.  This may change over time.

For now, this list is interesting but definitely subject to change as time moves on, as more publications beef up their cybersecurity beats and as we refine our methods for pinpointing the best sources and items of information.

Stay tuned and please talk to us. Tell us what resources we're missing that you rely on and what additional types of information you'd like to see in the mix.

Introducing Metacurity – An Answer to Cybersecurity Information Overload


It’s been a long time since I blogged here – about a half a year actually.  In that time I’ve been working on various projects that pushed blogging to the back seat.  One of those projects was to redesign this blog into a more professional look and integrate the blog into a redesigned corporate website, with a common look-and-feel.

Along the way, I decided to incorporate into the new integrated sites a “news feed” that addresses a problem plaguing the digital and network security sector:  information overload. Fairly soon, that redesign project took a back seat to figuring out how to sift through the escalating number of news stories, journal articles and other sources of cybersecurity information and present it in a way that is the most helpful to overworked cybersecurity practitioners and other professionals interested in the subject.

For at least the past five months I’ve increasingly focused on that challenge to the point that it’s almost become a more than full-time job. The result of that work is a stand-alone website, Metacurity. Relying on over fifty (and growing) standard sources of cybersecurity news, plus dozens of other sources, Metacurity is an evolving site that presents sifted, breaking and other news in a clean, easy-to-scan format.
I’ve worked out a system for selecting the most timely, useful and relevant articles, blog posts, and other sources and publishing them in summary form, with links directly back to the sources themselves. Although still wholly subjective and imperfect, I use a rough set of criteria for what gets published. These criteria generally are:
  1. Timeliness: Although articles that break news aren’t necessarily always the most informative or best, being first does matter, if for no other reason than it shapes the conversation.
  2. Level of Skill: Well-written articles and posts that do justice to the subject catch more attention. Articles that are nothing more than a couple of paragraphs, gloss over or fail to point out important distinctions or are extremely late to the game don’t appear that frequently.
  3. Originality: A related criteria is originality. Items that are typically rewrites of press releases or rewrites of major news stories with very little additional reporting or analyses are low on the priority list.
  4. Pure-Play: The topic of cybersecurity overlaps with so many other topics – privacy, cloud computing, national security, criminal justice, diplomacy and other major concerns. It’s difficult to parse out articles, reports, blog posts and studies that are solely focused on how to maintain secure reliable networks. But, those articles that do deal mostly or exclusively with cybersecurity get higher priority.
  5. Impact:  Some “scoops” have major impact on discussions surrounding cybersecurity. Some headline-breaking articles in the cybersecurity arena do not necessarily hold up under further analysis but nonetheless create a stir. Although rare, these kinds of reports are higher on the priority list.
In the middle of the site, or further down the screen on mobile devices, appear blog posts produced by cybersecurity vendors labeled as “Corporate Posts.” These items are useful and often news-making posts produced by the dozens of vendors in the IT and information security arena.  (Although the Corporate Posts are selected based on editorial judgment, we are offering vendors the opportunity to spotlight their posts at the top of this section via sponsorships. We are also offering companies the ability to promote their employment opportunities and conference organizers to promote their events via highlighted entries in our events section.)

Metacurity also features a table that encapsulates cybersecurity events around the globe and a handy box for employers to promote their cybersecurity openings to the tiny available pool of available and qualified cybersecurity professionals.

Ultimately Metacurity will become much more efficient at picking out what’s important based on data analysis.  As Metacurity evolves, we’ll add more and different types of information. I want feedback on how to make the site better and more informative. Please contact us and share your thoughts.  Happy reading!

And yeah…I’m finally getting around to the redesign of this blog.  Stay tuned.

Four Key Take-Aways from the Sixth NIST Cybersecurity Framework Workshop


Last week, the National Institute of Standards and Technology (NIST) held in Tampa, FL its sixth workshop on the landmark critical infrastructure cybersecurity framework mandated by President Obama in February 2013 and issued by NIST in February 2014. As was true of the five previous workshops NIST held prior to the framework's release, hundreds of cybersecurity specialists gathered for two days to listen to government and industry experts and to hash out the framework's details across multiple, specialized working sessions.

While the event covered a lot of ground, tackling a range of technical and detailed topics from relatively specialized matters such as authentication issues in industrial control security to broader overviews of how various sectors are dealing with the framework, a few themes emerged from the sessions and conversations with the attendees. Here are the top four take-aways from the latest workshop:

1. Everyone Likes the Framework: Almost everyone said the framework is a good thing, although, as noted below, there are some issues that specialists still have with the framework's ongoing development. Not surprisingly, representatives from industry, UK and EU governments invited to speak on the plenary session panels offered almost uniformly positive views of the framework. "We began using the framework essentially the day it came out," Tim Casey, a senior information risk analyst at Intel said. "It gave us purpose and direction that we didn't have previously," Jefferson England, an executive at small telco Silverstar Communications, said.

Conversations with attendees yielded more of the same. "This is a good force multiplier. It's a common unified framework for managing security risks," Robert Brown, Manager of Assurance at PWC, said. "People have seemed to really embrace it," according to Phil Agcaoili, VP and Chief CISO at Evalon. "There are all sorts of ways this could have gone wrong and it didn't," Chris Blask, ‎Chair at Industrial Control System Information Sharing and Analysis Center (ICS-ISAC), said.

Much of the good vibes flowed from the sense of collegial community that has cropped up over the course of the multiple workshops among the many hundreds of cybersecurity specialists. (Frequent jokes were made about the T-shirts given to people who had attended every workshop). The framework process has really "put trust across the sectors," Jack Whitsitt, Senior Analyst of cybersecurity consortium EnergySec, said, highlighting the fact that cyber specialists in different industries now share information outside their sectors because of the relationships forged during the NIST framework process.

2. The Framework's Primary Value To Date Seems to Be as a Communications Tool:  The jury's out in terms of whether the framework has actually achieved its intended goal of reducing cybersecurity risks, but it's clear that the subject matter experts who were at the workshop think it's a good device for trying to communicate the arcane subject of cybersecurity to managers, regulators, vendors, partners and other audiences. "One of the largest benefits of the framework is that it provided a framework of discussion, as much as anything else," Silverstar's England said.

"We're using it as an engagement tool for our regulators," Karl Schimmeck of the Securities Industry and Financial Markets Association, said. "We're hoping that it becomes the common language when you're talking to suppliers, vendors, joint ventures," a senior oil and gas industry representative said. "I'm using it to inform my board and executives," Evalon's  Agcaoili said.

3. Otherwise the Framework Is Still Kind of Difficult to Use:  Despite being built on the notion of simplicity, the NIST framework is a 41-page document that features core sets of activities, multiple tiers and intricate mapping to hundreds of detailed cybersecurity standards developed by a welter of standards-setting bodies. Most of the practitioners in attendance at the workshop said that the framework, despite its communication value, can at times be quite a challenge to use. "These frameworks are alphabet soup," PWC's Brown said.

"The mapping process is nuts," Dorian Cougia, Compliance Scientist at Unified Compliance said. Part of the problem is that the intricate standards that are mapped to the framework can run dozens and even hundreds of pages long and it's not always clear which parts of the standards apply to what. "There were times when we did not exactly understand what the framework meant," one top energy cybersecurity specialist said.

"The content of the framework really doesn't matter," EnergySec's Whitsitt said. "Organizations that don’t know how to do security already will have a hard time with it."

The difficulty in using the framework can be greater for smaller and mid-sized organizations that don't have cybersecurity experts on staff, a topic much discussed during the framework's development. "The big guys do this already," one communications industry representative said. "They wouldn't be in business if they weren't protecting their networks for financial reasons." The smaller guys, however, are struggling to come up to speed with what the framework demands, she noted, because they may have at most only one IT person on staff assigned to implement security measures.

The right way to view the challenge of using the framework isn't big versus small, according to Adam Sedgewick, who spearheads the project for NIST, clarifying that it's more about how serious the company is about cybersecurity, regardless of size. "I think it's a mistake to think that small and medium companies do not have good cybersecurity practice as a rule.  I think it's more appropriate to say companies that do not have robust cybersecurity programs" face greater challenges.

4. There Won't Be a Framework 2.0 Any Time Soon:  Two mantras emerged from the government and NIST speakers at the workshop.  The first is that "it's still early days" for the framework and too soon to gauge its effectiveness.  The second, related concept is that no basic changes to the framework are in the offing anytime soon.

"We want to make sure that people understand we don't expect changes to the framework in the future," Ari Schwartz of the National Security Council said. "We are in no rush to make changes without knowing or understanding what effect those changes might have," Matt Scholl, Deputy Division Chief at NIST said.

Cybersecurity is already shaped by endless organizations, government agencies, schemas, frameworks and evolving standards, NIST's Sedgewick said. "We have to be careful when we think about the next phase of this effort to reduce that complexity and not increase it."

That view was embraced by most of the workshop attendees. However, some of the industry specialists who are implementing the framework think changes are needed sooner rather than later. "It is useful but it still needs more work," one big electric utility representative said. "If something is missing, they don't know something is missing.  They should not wait too long to update the core."

Cybersecurity Should Scale Faster than the Information Revolution, DARPA Head Says

Mary Jordan, Arati Prabhakar

(Washington, DC) In the face of cybersecurity threats that seem to breed like bacteria, a conceptual fix is to speed up cybersecurity development to outpace the rapid-fire evolution in technology, the head of the Defense Advanced Research Projects Agency (DARPA) said today. Speaking at a cybersecurity summit hosted by the Washington Post, Arati Prabhakar, Director of DARPA, said "we are trying to wrangle this problem while the information revolution is exploding. The moonshot for cybersecurity in my view is to find techniques that scale faster than this revolution."

One key problem is that the Internet was developed--under DARPA's auspices-- at a time when the current kinds of security threats were unimaginable. If DARPA had a clean slate to rebuild the Internet to make it more secure, one concept would be to apply a biological model to network security, she said. "Under the hood there is a lot of diversity among individuals [s]o one attack cannot wipe out the human race," drawing parallels between the efforts DARPA spearheads to help the public health community outpace infectious diseases and its simultaneous efforts to develop automated cyberdefense systems.

The scariest cybersecurity threat is a potential take-down of the power grid. But that's an unlikely prospect for the typical IT hacker, Andy Bochman, Senior Cyber and Energy Security Strategist at Idaho National Laboratory, said. "The communication protocols and the types of processors and the amount of memory is often wholly different" for the energy sector's industrial control systems. "For the standard hacker, it would be a strange place."

Still, to the extent that power companies are putting into place new technology, there is a "tremendous opportunity" to minimize risk. "The more that electric utilities and stakeholders include security requirements into their RFPs, [t]hat gives signals to the manufacturers that what wasn't important before is suddenly something they should pay attention to," Bochman said.

It's unlikely that Congress will step in with its own solution during the upcoming lame duck session, Rep. Mike Rogers (R-MI), retiring Chairman of the House Intelligence Committee, indicated. "We have a very small window to get this done [pass a cybersecurity bill]," he said. "The political challenges in the Senate make the odds pretty high," with Rogers blaming the failure to pass a bill on "political tantrums."

Only 15% of networks are owned by the U.S. government and thus benefit from the cybersecurity protection of the military and various federal agencies. "By doing nothing in Congress, we are telling these 85% of private networks 'you are on your own,'" mainly due to the difficulties in sharing information between public and private groups, a knowledge gap that most cybersecurity bills aimed to minimize.

Meanwhile, the federal government is doing what it can to help raise the level of cybersecurity practices around the globe. Federal agencies are increasingly coming together to work with other nations in securing the necessary infrastructure against the "less deterrable" threat actors, such as Iran and Korea as well as terrorist organizations. "The good thing is that more and more countries are taking this seriously," Christopher Painter, Coordinator, Cyber Issues at the State Department, said.

Around 60 countries are looking to build cyber command operations, Eric Rosenbach, Assistant Secretary of Defense for Homeland Defense and Global Security for the Defense Department, said. The U.S. government is helping some of those countries, particularly in Europe and Asia, build that capacity. "There are a small group of countries that we are advising. [W]e only do it with our very closest partners, mostly because we want to make sure it's being done right."

NIST Cybersecurity Framework is Good and Bad, Experts Say

Source:  AWWA.
Six months after its release, the cybersecurity framework issued by the National Institute of Standards and Technology (NIST) received mixed reviews from a group of cybersecurity specialists who've now had time to give the landmark system a closer look. Speaking at a webinar hosted yesterday by both the Industrial Control System Information Sharing and Analysis Center (ISC ISAC) and my own firm DCT Associates, the early assessment of the framework ranged from "pleased" to "failed," with a general sense that the framework doesn't replace the hard work of implementing adequate cybersecurity controls.

"I'm relatively pleased," Chris Blask, Chair of the ICS ISAC said. "What we want to achieve from all these sorts of things, rather than force people to comply with specific activities, is encourage all the relevant players to take steps that result in a more secure infrastructure."

"From an operator perspective, a document like this [the framework itself] is quite intimidating," Kevin Morley, Security and Preparedness Program Manager, American Water Works Association (AWWA), said. "This is a little bit abstract and we felt we needed a different approach," which is why the AWWA developed it's own security guidance for the water sector. Nevertheless, AWWA mapped its separate guidance to the NIST framework and found that the two are 100% aligned, Morley said.

"You can look at the NIST CSF as a success and you could say it’s not a bad outcome.  I believe you could only say that if you have very low expectations," Perry Pederson, Co-Founder and Managing Principal at The Langner Group said. "Compliance with the NIST CSF only requires adopting the terminology.  If you speak in those terms and talk in those terms you can be compliant with the framework without changing anything you have to do. It’s really a business-friendly framework because it allows the business to decide based on its needs and resources to simply cherry pick what it wants."

Japp Schekkerman, Director of Global Cyber Security at CGI Group, agreed with Pederson. The framework is "addressing all kinds of questions [b]ut it doesn’t tell you how to do it," he said. "If you’re not familiar with the standards [referenced in the framework], you don’t know what to do."

The framework wasn't intended to provide a technical blueprint telling cybersecurity specialists what to do, Greg Witte, Program Manager, Security Standards Team, G2, countered. "It really is about communication and awareness," he said. "We should not be directing people and making it mandatory."

"The framework is a way to have a discussion about managing risk," Adam Sedgewick, who spearheads the framework initiative for NIST, said during an interview earlier in the week. Still, NIST welcomes criticism and hopes to solicit a wide range of opinions on the framework's effectiveness through a request for information issued today in preparation for a framework workshop NIST will host in October. "We really do want a healthy debate, we welcome criticism."

NIST's Cybersecurity Framework at the Six-Month Mark: Are We More Secure?


On February 12th the National Institute of Standards and Technology (NIST) released its comprehensive cybersecurity framework, the culmination of an intense 12-month drafting process ordered by President Obama in an effort to ward off what former Defense Secretary Leon Panetta feared would be an imminent "cyber Pearl Harbor." This framework of frameworks was intended to lay down some ground rules to improve the security and resilience of all industries, but particularly the critical ones upon which stable society depends, such as energy, communications, transportation and food and agriculture.

So, what's happened since the framework's release? Find out tomorrow when I will be moderating a webinar for the Industrial Control Information System Sharing and Analysis Center (ICS ISAC), one of the key groups assigned the all-important information-sharing task among industrial system control operators to ensure that cyber threats are identified and managed in a timely fashion.

Join ICS ISAC Chair Chris Blask and me to find out what top security specialists think about the framework six-months in and the benefits and challenges they've experienced in putting the framework into place. Among the experts we've lined up are:
  • Kevin Morley, Security and Preparedness Program Manager, American Water Works Association
  • Perry Pederson, Co-Founder and Managing Principal at The Langner Group, LLC
  • Greg Witte, Program Manager, Security Standards Team, G2, Inc.
Based on my conversations with some of the speakers, this webinar promises to be a lively one, complete with frank assessments of both the good and not-so-good aspects of the framework. I'll check back in here later with a write-up of the key points, but register for the webinar today so you can hear first-hand what they have to say and ask your own questions.

Cybersecurity Information Overload: Is There a Solution?

Sign Up for the Cybersecurity Magazine 
For at least the past two years, I've been fascinated by the highly fractured nature of information in the cybersecurity world, which is in a state of overwhelming onslaught of constant developments, studies, reports, meetings, breaking news, standards developments and government activity.  I've spent my entire career creating information products, conferences and advisory services focused on technology-related industries and corresponding complex policy topics (albeit in the comparatively easy-to-grasp media, communications, consumer electronics and, more recently, energy sectors).

But nothing beats cybersecurity as a tough topic, an issue that few people feel, deep down inside, they adequately grasp.  This vague sense of not-knowing is true for both the technology professionals responsible for implementing cybersecurity within their organizations and, most emphatically, the non-technologists who run organizations, government agencies and corporations and who are increasingly held responsible for the cyber breaches that occur on their watches.  Part of the problem is that there is just too much stuff  bombarding all of us and the information overload is accelerating.

Hundreds of good (and not so good) journalists crank out important cybersecurity news pieces every day across at least several dozen, if not hundreds, of bona fide publications (My slightly outdated must-read list is here).  Hundreds of consulting, engineering and law firms release reports, updates, advisories and white papers.  Endless meetings with thousands of participants are held across government and affiliated working groups, centers and labs of all stripes and sizes and all industry sectors. A day doesn't go by without at least a dozen important webinars, conferences or hearings on some important cybersecurity topic.

Trying to keep track of the day's developments is alone a herculean challenge.  A while back, I launched a Twitter feed and a corresponding nifty online Flipboard magazine (best seen on tablets and smartphones) that seeks to sift through the day's endless streams of information for only the most important, most interesting and most useful information.  Unlike some people who have brilliantly developed scripts to sift useful information from the repetitive, derivative and not-so-valuable gunk, I manually go through news feeds, emails, LinkedIn group reports and other sources and pick what to put in these curated resources. This process can consume many hours of my day if I don't watch it.

A few years back I interviewed over a dozen utility cybersecurity executives about the problems they faced. Information overload was consistently ranked among the top impediments to getting their jobs done. Typical of the responses I received was one top cybersecurity technologist. “A lot of stuff comes into our email inbox," he said. "There is a huge quantity of information out there saying 'we know what’s best.' Quite honestly, for me it’s fairly overwhelming to see that much information come in,”

And the situation has only deteriorated in the three years since I conducted that project. So, what's the solution? Is there a solution or is cybersecurity just too vast, just too endemic to everything in the world now that it's impossible to develop a comprehensive resource that hits the high-points and pulls it all together as best as possible in a reasonable time-frame?

These are the questions in the back of my mind as I work on a plan that proposes to do precisely that. Pull it all together and produce ongoing reports, data and analysis in a way that makes sense and reflects expertise and high-caliber thinking.

But if any of you have any answers to the question about information overload - is there a solution and what is it? -- or if there is a key piece of data or aggregated information that you wish you could see, drop me a line and share your thoughts.

Tanium Pushes 2014 Cybersecurity Venture Funding to $329M, Five Times 2013 Level


San Francisco-based cybersecurity-focused start-up Tanium announced yesterday a $90 mil. venture cash infusion from Andreessen Horowitz, a Silicon Valley powerhouse known for backing a long list of Internet and technology winners. The $90 mil. investment is the venture funding titan's second largest investment ever and continues a string of the firm's investments in cybersecurity companies, including Bluebox Security, Ciphercloud and Bromium.

Tanium, which describes itself as an "enterprise-scale real-time security and systems management company," has developed an approach to security management that it says collects and processes billions of metrics -- hardware configuration, software inventory, network usage, patch and update status and more -- across an organization's endpoints in real-time, providing instant visibility into operational issues to ward off security attacks.

Andreessen's big investment is the latest in a string of high-profile investment rounds across the growing ranks of cybersecurity technology start-ups.  According to our tally, thus far in 2014, cybersecurity firms have snagged $392 mil. in venture capital, over five times the level of the estimated $70 mil. in cybersecurity related venture deals in 2013.  (See table below).

At this point, total recent venture funding for cybersecurity tech providers is coming close to the $1 bil. mark. As the table below shows, since April 2012, venture funding for cybersecurity start-ups has totaled at least $818 mil.  At this rate, and with five months left in the year, that $1 bil. mark seems to be easily within reach.

Rep. Mike Rogers Raps FCC's Stance on Cybersecurity, Challenges Funding Request


Rep. Mike Rogers (R-MI), Chairman of the House Intelligence Committee, yesterday issued a red flag against last week's move by Federal Communications Commission Chairman (FCC) Tom Wheeler to broaden the agency's involvement in communications companies' cybersecurity practices.  In a letter signed by fellow Republican panel member Mike Pompeo (R-KS), Rogers expressed concern that Wheeler's approach, while relying primarily on the market to manage cybersecurity issues, verges too close to increased regulation.

The letter states that a speech Wheeler gave last week, in which he outlined a "new paradigm" for cybersecurity, as well as statements by Commission staff, "lead us to be concerned that the Commission may be preparing to implement a new regulatory scheme that would significantly impact Internet service providers and other web service providers."  In his speech, Wheeler said that if the new paradigm doesn't work, "we must be ready" with "alternatives if it doesn't."

The letter also raised objections to little-noticed cybersecurity-related budget additions in the FCC's FY 2015 budget.  "We also question why the FCC's Fiscal 2015 budget requested a substantial funding increase for cybersecurity activities, including funding for 'Big Data Cybersecurity Analytics and a Cybersecurity Metrics' program. While we support efforts to ensure that the Commission's internal systems are secure from cyber-attack, these initiatives appear to be outward, or industry, facing."

The FCC's FY 2015 budget asks for $700,000 for a big data cybersecurity analytics program.  In the budget the Commission states that "Big Data Cybersecurity Analytics will be a disruptive technology in the 
Cybersecurity arena, as traditional analysis and forensics techniques will be superseded by 
automation conveniences that reduce the burden of work on the analyst." The $700,000 is aimed at helping the FCC conduct root cause analysis, such as reverse engineering of malware on computer networks.

The FY 2015 budget also asks for $575,000 for the metrics program referenced in the letter.  The budget states that "FCC has initiated planning efforts to collect and analyze monthly metrics related to the cybersecurity threats addressed using data obtained from commercial sources," with the metrics to be provided to the Commission's newly formed Cybersecurity and Communications Reliability Division for analysis and baseline tracking.

Once that's done, the metrics program will be used to create a "Cybersecurity Dashboard" to "help the FCC track the ongoing progress of cybersecurity initiatives."

The appearance of the letter from Rogers and Pompeo indicates some level of concern among certain affected communications providers over Wheeler's new paradigm.  Following last week's speech by Wheeler, some telco industry representatives expressed unhappiness over some statements in the speech, presumably those that indicated the FCC would need to see "demonstrably effective" results and metrics under the new paradigm, perceived to be code for quasi-official monitoring and a possible precursor to regulatory action.

However, cable companies seemed warmer to the idea of the new cybersecurity paradigm.  Comcast issued a statement supporting Wheeler's new approach.  "Comcast will continue working with the Chairman, his fellow Commissioners, and the dedicated staff at the FCC to help achieve these important goals," Myrna Soto, senior VP and chief information and infrastructure security officer, for Comcast Cable, said.

FCC Chairman Unveils New Paradigm for Cybersecurity; Must Be "Demonstrably Effective"


(Washington, DC)  The Chairman of the Federal Communications Commission (FCC) Tom Wheeler today unveiled a new program for communications cybersecurity that relies on industry-driven initiatives for "proactive, accountable cyber risk management for the communications sector" in lieu of a "prescriptive, regulatory approach."  Nonetheless, the "new paradigm," as he called it, needs to be more "demonstrably effective than blindly trusting the market" to provide adequate cybersecurity risk management.

The goal is to spur greater cybersecurity activity by communications companies while stopping short of implementing official FCC rules or policies. Many communications companies have feared regulatory action by the FCC as a means of mandating the voluntary cybersecurity framework issued by the National Institute of Standards and Technology (NIST) last February or in the wake of a high-profile cyber incident 

Speaking at an event hosted here by the American Enterprise Institute, Wheeler laid out some central pillars of the approach. The first pillar is for the FCC and communications companies to promote greater "privacy-protective" information sharing of cyber threats and attacks, along the lines of the best-in-class information sharing that the financial sector has demonstrated in its ISAC (Information Sharing and Analysis Center). The communications sector already has its own ISAC in the National Coordinating Center for Telecommunications (NCC) under the Department of Homeland Security.

The second pillar is for the FCC to measure best cybersecurity practices already developed under the Commission's auspices and to tailor risk management processes to NIST's framework. The FCC's industry-led Communications Security, Reliability and Interoperability Council (CSRIC) has already formed a working group for this task, "working group 4," which met last week to begin tailoring the NIST framework. CISRIC will host its fourth meeting on June 18, while the working group 4 is expected to meet again in late-July.

Wheeler has asked the Commission’s Technological Advisory Council (TAC) to explore specific opportunities where R&D activity beyond a single company might result in positive cybersecurity benefit for the entire industry, an effort that forms the third pillar.

It's crucial that communications companies conduct some internal reviews of their cyber risk exposure, assess how they are managing their risks and develop better metrics, Wheeler said. "Companies must have the capacity to assure themselves, their shareholders and boards – and their nation – of the sufficiency of their own cyber risk management practices."

Some companies could take time adjusting to the "demonstrably effective" aspect of the new paradigm, Wheeler noted, because it "will require a level of transparency that may make take some time to get used to, but the bottom line is that this new paradigm can’t be happy talk about good ideas – it has to work in the real world. We need market accountability on cybersecurity that doesn’t exist today, so that appropriately predictive and proactive investment is made to improve cyber readiness."

Another potential issue is the level of commitment to the FCC's program, one key communications company representative said.  "There needs to be true commitment to this new paradigm.  When we actively hit bumps in the road, there has to be commitment," he said, adding that the commitment has to be on the part of not only the communications companies, but also the FCC itself.  "Providing there is a true will to make it work, it will work."

Communications companies aren't completely out of the regulatory woods yet. "We are not Pollyannas" Wheeler said. "We will implement this approach and measure results. It is those results that will tell us what, if any, next steps must be taken."

NIST Framework Could Become a Useful Tool for Regulators (and Litigators), Cyber Lawyers Say


(Washington, DC)  The voluntary comprehensive cybersecurity framework issued by the National Institute of Standards and Technology (NIST) last February is already proving helpful to companies and could become a tool used by regulators. But it could also become a de facto requirement for organizations once it starts being cited by plaintiffs attorneys, a group of top cybersecurity law specialists said yesterday.

Speaking at a cybersecurity event hosted here by Bloomberg Government, Stewart Baker of Steptoe & Johnson said that the NIST framework could come into play with the impending wave of lawsuits surrounding cyber breaches.  "It’s a no-brainer for plaintiffs lawyers to say 'what do you mean you didn't even follow the government’s cybersecurity framework?'"

As expected (and feared by some industries) regulators could more heavily rely on the framework as a benchmark for good cybersecurity practices. "The other place we’re going to see the NIST framework used is as regulators [u]se the framework as a way of asking questions about what kind of security you have," Baker said, adding that it could become a kind of test as regulators implement various policies and rules.

"The thought of the SEC [Securities and Exchange Commission] becoming a regulator [in cybersecurity] is quite chilling," Donald Fagan of Covington & Burling said. It's probably more accurate to label it as a "precursor to a test," he said. "The framework can be used to determine whether we are acting reasonably," Ben Powell of WilmerHale said.

Right now few signals are coming out of government agencies that the NIST framework might morph from voluntary to mandatory. "The White House announced that they're happy with where the voluntary process is going…which surprised us a little bit," Jeff Greene, Senior Policy Counsel for Symantec said. "The framework at least for the foreseeable future will stay pretty much as voluntary as it can."

Symantec has already adopted the framework, albeit in a tailored fashion, Greene said. "We're actually using the NIST framework. We have found it useful internally."

Small businesses, though, have a difficult time adapting to the framework, according to Greene. "At the small business end [t]hey don’t have the in-house IT staff.  We have found that we have to talk to them in a one-pager document. We’re trying to distill it down in a way that we can talk to them about it."

Top Experts: C-Suite Execs Have 'Caught Religion' in Wake of Target Breach


(Washington, DC)  Given the high-profile ouster of Target's CEO in the wake of the retailer's massive data breach, cybersecurity has been--and should be--elevated to executive suites across corporate America, a string of top security experts said yesterday. Speaking at a day-long cybersecurity conference hosted by Bloomberg Government here, current and former top government and industry cyber specialists issued a wake-up call to business and critical infrastructure leaders that cybersecurity can no longer be relegated to the purely technical realm.

"Cybersecurity is foundational," Admiral Mike Rogers, Commander of U.S. Cyber Command and Director of the National Security Agency said. "You must own this problem. This is just not your IT and computer people. You have to own this problem as a leader."

"This is becoming a CEO issue," Lou Von Thaer, President of the National Security Sector of Leidos, said. "We are being asked by directors all the time to be briefed," Steven Chabinsky, General Counsel and Chief Risk Officer of CrowdStrike said. "I hear all the time from the board members…they actually think the IT people are purposively speaking in gibberish so they cannot be subjected to oversight."

Although litigation and liabilities are the primary outcome of Target-like breaches, the challenge of handling a huge, complex crisis might be the bigger reason that executives are suddenly paying attention. "In some respects the greatest liability risk is not a legal one but a crisis management one," Donald Fagan of Covington and Burling said. "It is the Target issue…that has caught the attention of many businesses out there. They’ve caught religion"

Target may be the poster child for the massive damage that can ensue from a cybersecurity breach, but the company did most things right when it came to cybersecurity. Target would have received a high grade in terms of how well it followed the cybersecurity framework issued by the National Institute of Standards and Technology earlier this year, Stewart Baker of Steptoe & Johnson said.  "They just didn't respond to the overwhelming number of alerts they got."

"People have to understand how good a company Target is when it comes to cybersecurity," Michael Leiter, Senior Counselor to the CEO of Palantir Technologies said. "That means there really is no company that doesn't face this as a business risk."

Rep. Mike Rogers: Chinese Indictments Are 'Glitz and Glamour' But Legislation More Important


(Washington, DC)  House Intelligence Committee Chairman Mike Rogers (R-MI) said yesterday that the Justice Department's high-profile indictment of Chinese military officials for cyber theft of U.S. business secrets is "great for glitz and glamour" but it's more important that Congress act on cyber legislation by August if the government wants to ensure true cybersecurity. Speaking at an event hosted by the George Washington University Cybersecurity Initiative, Rogers said "I agree with the indictments and I agree with certain visa restrictions [b]ut it can't be done in isolation."

The Obama administration's largely symbolic move is "great for glitz and glamour but nothing followed," Rogers said. "It's the right idea but the wrong execution.  If only we could get the second piece of this, which allows the private sector to defend itself," Rogers said, referring to the Cyber Intelligence Sharing and Protection Act, which would facilitate the sharing of cybersecurity information between the private sector and the government.

Although the House has passed the bill, it's stalled in the Senate, a situation that Rogers thinks is improving and believes has to be resolved by August or else prospects for near-term cybersecurity legislation will die. "I think we've made tremendous progress in the last few months. I hate to say it but if we don't get something moving in August, it will get lost in the haze."

Rogers is cautiously optimistic that a bill could move in the next thirty days, with the contentious issues narrowed down to a "few short issues," particularly the question of how a portal for sharing information with the government gets structured. "We've narrowed down the issues on the portal," Rogers said.

Speaking at the same event, Toomas Hendrik Ilves, President of Estonia, a country widely considered to be home to the first true cyber warfare attack, said that new intellectual concepts are needed to successfully battle cyber threats given the radically novel dangers posed by the modern connected era. "We have major intellectual tasks ahead of us," he said. We are facing the modern equivalent of Thomas Hobbes' "war of all against all"  and "we need our Jeffersons, our Voltaires in this area."

Estonia is at the forefront of protecting individual online identities as a key strategy for ensuring security, with everyone using two-factor public key infrastructure using RSA 2048 encryption. "We have come to the conclusion that you cannot have any genuine security without a secure online identity," Hendrik said.  "That is the dilemma of all Internet relations.  You don't know who's who."

Government Cybersec Leaders: Just Patch Your System, Do Strong Passwords


(Washington, DC)  Despite vulnerabilities such as Heartbleed grabbing headlines, the best methods for ensuring adequate system security are often the most basic forms of cyber hygiene, such as patching systems and ensuring strong passwords, a group of government cybersecurity experts agreed today. Speaking at the GovSec conference here, Ron Layton, Deputy Chief Information Officer, U.S. Secret Service said "what's the best investment for our resource dollar?  Patch your system.  The vast majority of successful breaches use very low-level techniques."

"We are still at the precipice of one of the most disruptive forces in our society [b]ut just do a strong password and you're good," he added.

"You don't necessarily need to worry about the most recent APT [advanced persistent threat] if you have 20% of your computers that are unpatched that can be had by a hacker with no skill whatsoever," Patrick Morrissey, Former Director of Investigations and Protective Operations, Blackberry, and Former CISO, U.S. Secret Service, said. "That is where the bad guys are going to come in. The sophisticated hacker is not going to waste his technique on you.  Don't worry so much about being exploited by the latest and greatest.  Just stay up to date on your patches."

The best method for ensuring adequate cybersecurity within the federal government is information sharing and collaboration, something that is bolstered by trust but hampered when no crisis is pressing on the nation. "Trust and relationships is what it’s all about," Dave Pekoske, Chairman of the FBI-private sector partnership InfraGard National, said.

However, "the agencies are not going to be giving up the keys to the kingdom" to other agencies, Morrissey said, particularly if a truly collaborative relationship is absent. "People are going to be reluctant to share information with those agencies if they don't believe the agencies are going to protect them as they should."

Information sharing among government agencies is problematic for a number of reasons, not the least of which are the varying definitions of  security clearance and "need to know" statuses across agencies.  But agencies do collaborate better in the midst of a crisis.  "The government does work well in crises but the farther we get away from 9/11 it becomes a problem," Morrissey said.

Another perennial problem that hampers work across agencies is the lack of qualified cybersecurity personnel, who tend to steer clear of the government or bolt for the higher paid private sector after relatively short stints.  "It's a huge challenge for us right now," Eric Strom, Unit Chief, Cyber Initiative and Resource Fusion, NCFTA, FBI, said. "It's hard to take an investigator and teach them cyber skills."

GE Acquires Wurldtech as Cybersecurity Acquisition Deals Hum Along


GE announced today a deal to buy privately-held Vancouver-based cybersecurity firm Wurldtech, underscoring the increasingly hot market for cybersecurity tech firm acquisitions.  Wurldtech specializes in cybersecurity technologies for critical infrastructure industries and big industrial concerns including power plants, oil refineries and other key providers.

This deal follows FireEye's $70 mil. announced acuqisition of nPulse technologies earlier this week and caps a string of at least 26 cybersecurity acquisition deals over the past year.  (See table below.)  Clearly it's a good time to be a cybersecurity tech start-up or well-respected small solutions supplier.


FTC to Snapchat: If You Promise Security, You'd Better Deliver It


(Washington, DC)  In a move that could have wide-ranging effects on how Internet and mobile application providers approach both privacy and data security, the Federal Trade Commission (FTC) today entered into a consent order with mobile messaging app provider Snapchat, subjecting the company to a series of requirements aimed at ensuring that Snapchat maintains and protects the privacy, security and confidentiality of any consumer information.  The action, which officials labeled as a "significant" move by the agency, follows a complaint issued by the FTC that despite Snapchat's claims, images and videos transmitted via the application did not completely self-destruct and that adequate security of the service was not in place.

In announcing the consent order here at a Media Institute luncheon, FTC Chairwoman Edith Ramirez stressed not only the deceptive claims regarding content self-destruction (recipients could use tools outside of the application to save both photo and video messages), but also the need to maintain strict security practices, particularly when those practices are promoted as part of a product's appeal.  "The Snapchat case vividly illustrates that there is no data privacy without data security," she said.

Pointing to the high-profile data breaches over the past year, Ramirez said "despite the threats posed by data breaches, I am concerned that many companies continue to underinvest in data security and make fundamental mistakes when it comes to protecting sensitive consumer information."  Hinting at increased action by the FTC when promoted security fails to materialize, Ramirez noted that "the FTC’s enforcement work in this area has shown that some companies fail to take even the most basic security precautions, such  as failing to update antivirus software or to require network administrators to use strong passwords."

In making its original complaint against Snapchat, the FTC alleged that despite its claims of implementing adequate security measures, SnapChat "did not employ reasonable security measures to protect personal information from misuse and unauthorized disclosure." It alleged that Snapchat failed to implement proper identity verification upon sign-up, allowing users to send personal images to complete strangers who had registered with false phone numbers.  Moreover, the complaint alleges, Snapchat failed to secure its "Find Friends" feature, which resulted in a security breach permitting attackers to compile a database of 4.6 million Snapchat usernames and phone numbers.

In discussing the order with reporters following its release, Chris Olsen, Assistant Director, Division of Privacy and Identity Protection at the FTC said the case is a "new statement in our body of cases" because it tackles "a major player on many platforms with many users" and because Snapchat made "unequivocal express claims about the privacy of its service."

Although the FTC has brought a number of cases against individual apps for deceptive privacy practices and last year sued HTC America for negligently injecting security vulnerabilities in its devices that put sensitive consumer information at risk, the Snapchat case appears to reflect a new direction by the agency in holding companies responsible for failing to meet promised security protections.  "If you are making promises about security, privacy or anonymity, you have to keep those promises," Olsen said.

In its complaint, the FTC pointed to specific security promises that it contends Snapchat did not uphold, including "boilerplate" statements in its privacy policy.  For example, in its policy Snapchat said "[Parent company] Toyopa Group, LLC is dedicated to securing customer data and, to that end, employs the best security practices to keep your data protected" and "We take reasonable measures to help protect information about you from loss, theft, misuse and unauthorized access, disclosure, alteration and destruction."

Under the order, which will be put out for 30 days for public comment before it becomes final, Snapchat will have to cease any misrepresentation, establish, implement and maintain a comprehensive privacy program and conduct initial and biennial assessments of and reports on that program from a qualified, objective, independent third-party professional, who uses procedures and standards generally accepted in the profession.  Those assessments and reports will continue for twenty years. Any violation of the order will cost Snapchat $16,000 per day per new violation or $16,000 per day for a continuing violation.

Twitter Delicious Facebook Digg Stumbleupon Favorites More