Showing posts with label FCC. Show all posts
Showing posts with label FCC. Show all posts

Broadcasting as a Cyber Threat Vector: Ten Steps Broadcasters Need to Take Now


Cyber threats to financial institutions, electric utilities, broadband providers, government agencies, Hollywood studios and even emerging Web-connected household appliances get a lot of ink. But one major potential threat vector, television and radio broadcasting, doesn't conjure up the kind of concerns that these other avenues of cyber intrusion do.

That's changing, though, in the wake of a major cyber attack that took place last April when French broadcaster TV5Monde was hijacked, with eleven of its channels going dark and its social media outlets commandeered to display pro-ISIS messages. Although a group called the CyberCaliphate claimed credit for the damaging breach, the French government has lately cast some blame on Russian hackers who, the government suggests, was using the CyberCaliphate as a false flag.

Whatever the case may be, the TV5Monde attack was a wake-up call to the broadcasting sector that it too is vulnerable to the kinds of disruptive cyber intrusions and attacks that affect other critical aspects of society. That's why top broadcasting publication TVNewsCheck and I have joined hands to offer the first of its kind webinar, "Cybersecurity for Broadcasters: Ten Steps You Need to Take Right Now," aimed at helping broadcasters come up to speed on how to protect their assets from unwanted and potentially damaging cyber intrusions and how to become more resilient in the face of what will undoubtedly be more future cyber attacks.

Slated for July 22 from 2 pm to 3:30, the webinar features a top line-up of experts (with more to come) including:
  • Rear Admiral (ret) David Simpson, Bureau Chief, FCC Public Safety and Homeland Security
  • Kelly Williams, Engineering & Technology Policy, Senior Director, National Association of Broadcasters
  • Ed Czarnecki, Strategy & Global Government Affairs, Senior Director, Monroe Electronics
For more background on the array of cybersecurity concerns that broadcasters face, check out the piece I wrote for TVNewsCheck that I hope lays it all out fairly well and stayed tuned for more information as we update the speaker line-up. If you have any thoughts or questions, drop me an email. (As a personal aside, it's been nice to bring my two areas of professional experience, communications media and cybersecurity, together in an interesting project, something I hope to continue to explore).

And don't forget to check out Metacurity.com, a continuously updated source of cybersecurity intelligence and news aimed at solving the info-overload that increasingly bedevils most infosec professionals.

Rep. Mike Rogers Raps FCC's Stance on Cybersecurity, Challenges Funding Request


Rep. Mike Rogers (R-MI), Chairman of the House Intelligence Committee, yesterday issued a red flag against last week's move by Federal Communications Commission Chairman (FCC) Tom Wheeler to broaden the agency's involvement in communications companies' cybersecurity practices.  In a letter signed by fellow Republican panel member Mike Pompeo (R-KS), Rogers expressed concern that Wheeler's approach, while relying primarily on the market to manage cybersecurity issues, verges too close to increased regulation.

The letter states that a speech Wheeler gave last week, in which he outlined a "new paradigm" for cybersecurity, as well as statements by Commission staff, "lead us to be concerned that the Commission may be preparing to implement a new regulatory scheme that would significantly impact Internet service providers and other web service providers."  In his speech, Wheeler said that if the new paradigm doesn't work, "we must be ready" with "alternatives if it doesn't."

The letter also raised objections to little-noticed cybersecurity-related budget additions in the FCC's FY 2015 budget.  "We also question why the FCC's Fiscal 2015 budget requested a substantial funding increase for cybersecurity activities, including funding for 'Big Data Cybersecurity Analytics and a Cybersecurity Metrics' program. While we support efforts to ensure that the Commission's internal systems are secure from cyber-attack, these initiatives appear to be outward, or industry, facing."

The FCC's FY 2015 budget asks for $700,000 for a big data cybersecurity analytics program.  In the budget the Commission states that "Big Data Cybersecurity Analytics will be a disruptive technology in the 
Cybersecurity arena, as traditional analysis and forensics techniques will be superseded by 
automation conveniences that reduce the burden of work on the analyst." The $700,000 is aimed at helping the FCC conduct root cause analysis, such as reverse engineering of malware on computer networks.

The FY 2015 budget also asks for $575,000 for the metrics program referenced in the letter.  The budget states that "FCC has initiated planning efforts to collect and analyze monthly metrics related to the cybersecurity threats addressed using data obtained from commercial sources," with the metrics to be provided to the Commission's newly formed Cybersecurity and Communications Reliability Division for analysis and baseline tracking.

Once that's done, the metrics program will be used to create a "Cybersecurity Dashboard" to "help the FCC track the ongoing progress of cybersecurity initiatives."

The appearance of the letter from Rogers and Pompeo indicates some level of concern among certain affected communications providers over Wheeler's new paradigm.  Following last week's speech by Wheeler, some telco industry representatives expressed unhappiness over some statements in the speech, presumably those that indicated the FCC would need to see "demonstrably effective" results and metrics under the new paradigm, perceived to be code for quasi-official monitoring and a possible precursor to regulatory action.

However, cable companies seemed warmer to the idea of the new cybersecurity paradigm.  Comcast issued a statement supporting Wheeler's new approach.  "Comcast will continue working with the Chairman, his fellow Commissioners, and the dedicated staff at the FCC to help achieve these important goals," Myrna Soto, senior VP and chief information and infrastructure security officer, for Comcast Cable, said.

FCC Chairman Unveils New Paradigm for Cybersecurity; Must Be "Demonstrably Effective"


(Washington, DC)  The Chairman of the Federal Communications Commission (FCC) Tom Wheeler today unveiled a new program for communications cybersecurity that relies on industry-driven initiatives for "proactive, accountable cyber risk management for the communications sector" in lieu of a "prescriptive, regulatory approach."  Nonetheless, the "new paradigm," as he called it, needs to be more "demonstrably effective than blindly trusting the market" to provide adequate cybersecurity risk management.

The goal is to spur greater cybersecurity activity by communications companies while stopping short of implementing official FCC rules or policies. Many communications companies have feared regulatory action by the FCC as a means of mandating the voluntary cybersecurity framework issued by the National Institute of Standards and Technology (NIST) last February or in the wake of a high-profile cyber incident 

Speaking at an event hosted here by the American Enterprise Institute, Wheeler laid out some central pillars of the approach. The first pillar is for the FCC and communications companies to promote greater "privacy-protective" information sharing of cyber threats and attacks, along the lines of the best-in-class information sharing that the financial sector has demonstrated in its ISAC (Information Sharing and Analysis Center). The communications sector already has its own ISAC in the National Coordinating Center for Telecommunications (NCC) under the Department of Homeland Security.

The second pillar is for the FCC to measure best cybersecurity practices already developed under the Commission's auspices and to tailor risk management processes to NIST's framework. The FCC's industry-led Communications Security, Reliability and Interoperability Council (CSRIC) has already formed a working group for this task, "working group 4," which met last week to begin tailoring the NIST framework. CISRIC will host its fourth meeting on June 18, while the working group 4 is expected to meet again in late-July.

Wheeler has asked the Commission’s Technological Advisory Council (TAC) to explore specific opportunities where R&D activity beyond a single company might result in positive cybersecurity benefit for the entire industry, an effort that forms the third pillar.

It's crucial that communications companies conduct some internal reviews of their cyber risk exposure, assess how they are managing their risks and develop better metrics, Wheeler said. "Companies must have the capacity to assure themselves, their shareholders and boards – and their nation – of the sufficiency of their own cyber risk management practices."

Some companies could take time adjusting to the "demonstrably effective" aspect of the new paradigm, Wheeler noted, because it "will require a level of transparency that may make take some time to get used to, but the bottom line is that this new paradigm can’t be happy talk about good ideas – it has to work in the real world. We need market accountability on cybersecurity that doesn’t exist today, so that appropriately predictive and proactive investment is made to improve cyber readiness."

Another potential issue is the level of commitment to the FCC's program, one key communications company representative said.  "There needs to be true commitment to this new paradigm.  When we actively hit bumps in the road, there has to be commitment," he said, adding that the commitment has to be on the part of not only the communications companies, but also the FCC itself.  "Providing there is a true will to make it work, it will work."

Communications companies aren't completely out of the regulatory woods yet. "We are not Pollyannas" Wheeler said. "We will implement this approach and measure results. It is those results that will tell us what, if any, next steps must be taken."

FCC Chairman: Implement NIST Cybersecurity Framework So That We Don't Have To


(Los Angeles, CA) The Chairman of the Federal Communications Commission (FCC) Tom Wheeler today urged the cable industry to get moving on the implementation of the cybersecurity framework released by the National Institute of Standards and Technology (NIST) earlier this year.  Speaking at the National Cable and Telecommunications Association (NCTA) annual conference here, Wheeler said that broadband networks are at a critical cybersecurity juncture and that the "more we learn about the challenges of cybersecurity and the costs of failure, the more apparent the importance of addressing it with best efforts, including yours."

Pointing to the work of the Communications, Security, Reliability and Interoperability Council (CSRIC) of the FCC, Wheeler said that the outcome of the industry-led CISRIC should be done "in such a way that those charged with oversight across the regulatory tapestry, recognize and understand the accepted cyber risk."

CISRIC is leveraging the NIST framework for its work and "over the course of the year we will need to see this translate into actual implementation," he said.  "We’re intending this to be a new regulatory paradigm, and we’re giving you the opportunity to write it. I urge you to step up, so we don’t have to."

Although both the telecom and cable industries have embraced the NIST framework, many communications sector representatives have expressed fear that the voluntary nature of the framework could become mandatory at the Commission over time.  The FCC offered no further information on Wheeler's speech to the cable attendees, instead pointing to archived video of the last CISRIC meeting for more context.

The big news out of Wheeler's speech was his further clarification on where he is headed with the FCC's upcoming net neutrality rulemaking.  Leaked outlines of the controversial regulatory action have stirred public interest advocates and Silicon Valley companies to decry what they perceive to be forthcoming FCC-sanctioned creation of pay-for-play "fast lanes" on the Internet, whereby broadband providers (with cable companies serving as the "principal" broadband providers in the U.S.) can charge content and application providers more for quicker delivery to end Internet users.

In impassioned tones, Wheeler rejected the idea that the FCC would effectively kill net neutrality by sanctioning the creation of Internet fast lanes.  "Any new rule will assure an open pathway that is sufficiently robust to enable consumers to access the content, services and applications they demand and innovators and edge providers the ability to offer new products and services," he said.

Wheeler, who headed the NCTA himself thirty years ago, rebutted charges that as a former cable lobbyist he is predisposed to do the industry a favor in the net neutrality debate.  "Now, as Chairman of the FCC, I do not intend to allow innovation to be strangled by the manipulation of the most important network of our time, the Internet."

FCC's Wheeler: We Can't Sit Around and Suck Eggs


Federal Communications Commission (FCC) Chairman Tom Wheeler today reiterated his view that the Commission must work quickly to assess the impact of radical changes in the communications landscape due to the rapid adoption of  Internet Protocol (IP) technology by communication network providers. Speaking at an event hosted by the National Journal following the FCC's launch of a series of trials aimed at measuring the impact of that transition, Wheeler said "if we sit around and suck eggs as the FCC did when it was sitting around saying 'should we use spectrum for cellular?' we will have incredibly adverse results for our economy."

Collecting real world data through research and trials before sanctioning the end of the old twisted copper-pair, analog-based public telephone network is crucial because "the thing I learned is that you get one shot," he said, referring to his long history in dealing with FCC policies. "The trials are going to give us the opportunity to collect the information that will help us to put together the components on that one shot.  You can’t do a Gilda Radner on this [and say] 'oh never mind.'

Wheeler also made a case that the current state of communications competition, in which most markets are served by only two dominant network providers, leaves a lot of room for improvement.  "IP means choices…vast choices in services.  There needs to be competition in the infrastructure that delivers those services," he said.

"While building IP networks is a highly capital intensive activity, operating IP networks [is] essentially cost-less. How do we make sure there is competition out there?  By having multiple choices for consumers [in] terms of facilities-based infrastructure."

Fostering competition in communications is a crucial economic issue as well as a consumer choice matter. "In order to have choice and competition in services it really helps to have choice and competition in the networks.  You can’t have an opportunity economy without having opportunity networks," he said.

AT&T CEO: FCC is Getting Better But Spectrum Situation Must Be Addressed


(Note:  We've added to our curated content collection with a new curated content page on spectrum issues. Take a look and send us your feedback.)

(Washington, DC)  The spectrum crunch in the U.S. is real and the Federal Communications Commission (FCC) is stepping up its game by speeding the pace of spectrum transfers AT&T Chairman and CEO Randall Stephenson said today.  Speaking at a Brookings Institution event here. Stephenson said "over the last three months, the pace for moving spectrum has been 60 to 90 days," referring to the FCC's ability to process and approve individual spectrum purchase deals AT&T has made.

The quicker pace in turning around the requested transfers "should be the norm and not the exception," Stephenson said, highlighting the sluggish rate at which AT&T contends the regulatory agency has handled these transactions in the past.  "We're trying to encourage the FCC to bring predictability to the industry.  I've commended the FCC here this morning because what we've seen is a stepped-up pace."

AT&T no doubt is still stinging from the Commission's refusal to approve the company's merger with T-Mobile, a deal driven by the need for spectrum.  The soft praise for the FCC signals a softer approach than AT&T has displayed since that deal was scuttled.

A more conciliatory tone toward the FCC could help AT&T as it goes about finding more spectrum.  The company will bid on 700 MHz spectrum that Verizon will sell off once its deal to purchase spectrum from a group of cable companies (SpectrumCo) goes through, Stephenson confirmed.  "It [Verizon's spectrum] pairs perfectly with ours.  If we were to have access to that spectrum, we would put it to work in 60 days."

AT&T hopes that the FCC's handling of the Verizon-SpectrumCo deal will yield some clues about what "the rules of the road" are regarding spectrum purchases.  "We are all waiting for the Verizon-Cableco deal to get approved because of the expectations we can glean from that deal," he said.

The meteoric rise of mobile devices will continue to strain AT&T's capacity, Stephenson said. "We're in a position today where we see exhaust in key markets."  Mobile data is the culprit, with voice and text services mere commodities, he said.  Addressing rival Verizon's announcement this morning that its phone service plans are shifting to data-centric options, Stephenson said "the value is in the data, and the voice and the texting are commoditized.  We've become a mobile data business.  Voice and texting are just apps that ride on top of this."

The dimensions of mobile communication are "mind-boggling," Glenn Hutchins, co-founder of investment firm Silver Lake said during the same event. "Today there are a billion devices that are handheld.  There are six billion mobile service subscriptions worldwide," which exceeds the total world population.

With most annual growth estimates hovering around 100% for mobile communications, "this is the biggest opportunity in the history of technology," Hutchins said.  But the fly in the ointment is not money to build the networks:  it's spectrum.

"This is not an industry that is lacking for capital investment.  The thing that will cause it to slow is lack of availability of spectrum," Hutchins said.

(Note:  We've added to our curated content collection with a new curated content page on spectrum issues. Take a look and send us your feedback.)

Twitter Delicious Facebook Digg Stumbleupon Favorites More