Democratic presidential nominee, Joe Biden, speaks in Durham, North Carolina. (Adam Schultz/Biden for President)
Even among those who have worked with him, Joe Biden is not known as a tech policy wonk.
So, its not surprising that today, during a pandemic, cybersecurity doesnt come near to the top of the list of topics Bidens campaign is prioritizing for the sake of the election.Russias election meddling may get a mention, but nothing tied to any substantive cybersecurity policy.
That said, any presidents potential influence on cybersecurity policies are manifold, with legislation, trade philosophy, and even military actions all playing a role. And as the cybersecurity community assesses a potential Biden White House, privacy regulations, global internet surveillance practices, and supply chain security are all at play.
Those topics matter to practitioners like Michael Daly, chief technology officer for cybersecurity, special missions, training and services at Raytheon Technologies. But what he says matters most is whether the government prioritizes cybersecurity in the first place.
Its just a question of how much focus it gets how much energy anything can get in the time of COVID-19, he said. There isnt a lot of oxygen left. But Im hoping that cybersecurity will see a resurgence in importance.
SC Media spoke to numerous sources, many who worked with the former vice president or his running mate Kamala Harris, about how cybersecurity might enter the conversation in the White House.
What new leadership can and cant change
Much of the government cyber posture is handled by agencies, including the departments of Homeland Security and Justice. And while there are often brash changes to leadership, the cybersecurity priorities remain very similar and long-term plans remain in effect.
I dont think whos in office changes many of the goals, but theres a change in focus and energy, said Daly.
Former DoJ employees note that many of the prosecutions of Chinese hackers for economic espionage that we see today, for example, are the result of strategies and investigations put in place in prior administrations, sharpened by Chinese actions and new lessons learned. The same is true for much of DHSs work through the Cybersecurity and infrastructure Security Agency, or CISA. And just as strategies need time to develop, successes and failures can often be attributed to career officials, not changes at the top.
For day-to-day work, several former government employees say, agencies adapt more to changing threats than changes in leadership.
The Obama administration built on some really great work that was done during the Bush Administration, which built on some good work that was done during the Clinton administration, Obama-era Federal Chief Information Security Officer Greg Touhill and current president at AppGate Federal told SC Media. And Grant [Schneider, Touhills successor appointed by Trump] went from being my deputy to carrying the same message into President Trumps executive order as well as the national cybersecurity strategy.
But leadership changes have a more profound effect on how information gets to the president and how the president weighs the different priorities of different agencies and of industry partners. A potential Biden pivot back towards a more traditional, full collection of White House advisers, including restoring dedicated cybersecurity staff, could ensure that the issue doesnt get lost during a presidential term dominated by recovery from a COVID-19 shattered economy and several national disasters.
Any administration will tell you one of the single most precious commodities that it has is time, said Michael Daniel, former Obama cybersecurity coordinator and current chief executive of the Cyber Threat Alliance. To the extent that you can count on people whose job it is to continue making progress on policy issues, even in the midst of other stuff going on is very important; to say, hey, if we want to avoid the next crisis over here, lets take five minutes to talk about this.
During the tenure of John Bolton as national security advisor in the Trump Administration, the National Security Council dramatically reduced staff in the hopes of streamlining decisions. Many government officials of both parties see value in a president reintroducing and utilizing something akin to the cybersecurity coordinator position that was eliminated that is, someone to make sure all agencies are rowing in the same direction and to coordinate with the private sector.Biden may be inclined to do that, considering a cybersecurity coordinator existed under the Obama administration.
One thing I learned in the military as a cadet, is the best way to get a bunch of people from over here to over there is to have somebody call cadence, said Touhill, who served to the rank of brigadier general. You need to have that coordinator whos making sure that we are in sync, for example, with offense and defense. If Ive got Cyber Command firing cyber shots down range, you know what? Theyre going to shoot back. Agencies and businesses need to be prepared when that happens.
That could also serve well what many expect to be a more deliberative and measured approach to government that would come from Biden, much like Obama. That approach relies heavily on both public and private sector stakeholder input. It means, for example, that someone from the Department of Transportation may be aware of U.S. action that could lead to a counterattack on airports. More thorough legal review could ensure better outcomes in court cases.
But it all comes at the cost of expediency. And cybersecurity decisions aimed at any one sector including government often have broad impacts on other sectors.
Its frustrating and its sometimes slower than you would like, but I firmly believe you end up making better policy, said Daniel. They can stand the test of time that way for both government and the businesses community.
Privacy policy
Privacy policy in America is a patchwork of several legislative efforts siloed by industry. Its a key issue where the government, and not an industry group, creates the standards that industries have to abide by.
The biggest and most obvious focus is in compliance, especially around privacy, said Raytheons Daly.
Harris has a more robust tech policy lineage than Biden, particularly around privacy policy. In 2012, as attorney general of California, Harris set up the Privacy Enforcement and Protection Unit, helping thestate become a national leader in regulating consumer privacy.
Her potential vice presidency comes at a time when corporations and civil liberties groups alike are asking for a national privacy policy on the scale of the General Data Protection Regulation (GDPR) the regulation governing data protection and privacy in the European Union. For businesses, the alternative is 50 different and potentially contradictory state laws for chief information security officers to juggle.
In the words of Daly, its far cheaper to have one set of rules.
Harris would also bring some experience to the delicate negotiations with tech companies.
During a time when mega breaches impacted consumers at a very personal level, her office took the lead on several of those investigations, said Kathleen McGee, an attorney for Lowenstein Sandler who handles cybersecurity and tech issues. She formerly worked with Harriss California attorney general office as chief of the Bureau of Internet & Technology for the New York State Attorney Generals Office.
Along with several other states, California entered into what were groundbreaking agreements with companies that paved the way for a greater level of expectation from customers, she said.
Privacy policies affect what data companies can save about consumers, how it must be stored, when consumers must be explicitly notified about a data incident and how data can be sold on a lucrative secondary market.
Democrats have traditionally been the party most in support of bringing U.S. positions on privacy in line with those around the globe. The EU, for example, views personal data as personal property even when its stored on a commercial site. That dramatically impacts the data economy that keeps sites like Google and Facebook in business. As emerging technologies like biometrics work their way into storefronts, like Amazons cashierless store concept, those concerns can heighten.
Harris comes from California and has represented Silicon Valley in the Senate, McGee noted. It may give Harris a unique credibility for both sides of the debate. And credibility might be a key, missing factor in getting a privacy bill passed. National privacy policy was at times a priority of both the Obama and Trump administrations, but got little traction.
Larry Clinton, president and CEO of the Internet Security Alliance, which lobbies for cybersecurity policy on behalf of a broad swath of companies, expects federal agencies to take back regulatory power the Trump administration abandoned in a new administration. And, he said, that might not be a bad thing.
Industry is more risk tolerant than the government. Why does 10 percent of product walk out the door? Because cameras and security guards cost 11 percent, he said. But commercial insecurity creates a national security threat.
International considerations
The Obama-Biden administration and, most politicians before Trump typically approached multilateral global agreements so as to benefit all parties. Should Biden win, attempts will likely be made early on to repair some of the relationships fractured during four years of an America First philosophy.
But why might that matter? While global relations may seem more a matter of diplomacy, they can often influence cyber activity for both the government and the business community.
When I advise companies, I say dont just read the science and technology pages, said Michael Bahar, an attorney for Eversheds Sutherland with a focus on cybersecurity and technology policy. Read the front page, because often when geopolitical tensions rise your work is going to be hard and vice versa.
By promoting the idea of sovereignty over international cooperation, the United States has lost some of its influence to combat global shifts in internet governance. There has been a slide toward the Russian and Chinese ideal of a nationally siloed internet: less open, more surveillance and fewer global cloud offerings. All of those policies are less attractive to global businesses that depend upon the availability of such services to support operations.
I would hope to see the U.S. regain some of its standing as a leader internationally in developing good cybersecurity policies, said Daniel. Biden would move against some of the balkanization that China and Russia have made in the past few past four years.
A coalition of allies could influence the world away from the Russian and Chinese version of Walled Gardens, he continued, where the government gets to decide who sees what, who gets what, what kind of information moves. That would swing the pendulum back to a more comfortable position for businesses, which must track global data and surveillance policies that could impact supply chains.
Notably, Chinas international dominance of supply chains with equipment embedded in everything from computers to the telecommunications equipment to emerging social media platforms like TikTok creates massive uncertainties in the business community. It also introduces an array of security concerns.
Daniel offers that a unified crackdown among allies on China might mean, in part, offering alternatives to Chinese products, and may mean building a domestic 5G equipment industry to counter Huawei.
The Internet Security Associations Clinton believes China has pushed the U.S. to an inflection point, which will force cybersecurity and general technology policy to be reconsidered. The White House will be compelled toward collaboration with companies, and toward funding of domestic research into fields like machine learning and quantum technologies those areas where he feels the next Huawei skirmishes will happen.
It matters who the leader is, he said. The perception of the threats will be the same. But if Biden won, we would likely see a broader approach to cybersecurity.
Link:
Cybersecurity and a potential Biden White House: Past tech priorities resurrected - SC Magazine
- Google researchers have cracked a key internet security tool - Recode [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- Letter: Internet security is in jeopardy - INFORUM [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- New internet security device launched to safeguard schools against child abuse - Phys.Org [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- Everything You Need to Know About Cloudbleed, the Latest Internet Security Disaster - Gizmodo [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- Data from internet-connected teddy bears held ransom, security expert says - Fox News [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- Emsisoft Internet Security 2017.2.0.7219 - TechCentral.ie [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- What you need to know about 'Cloudbleed,' the latest internet security bug - Globalnews.ca [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- Google cracks longtime pillar of internet security - MarketWatch [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- BullGuard | Internet Security and Antivirus protection ... [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- Internet Storm Center - SANS Internet Storm Center [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- Internet-connected 'smart' devices are dunces about security - ABC News [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Derry internet security expert warns that advanced internet technology 'a risk to us all' - Derry Now [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Firewall Test, Web Tools and Free Internet Security Audit ... [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Internet security in the spotlight: How is the internet safer today than it was 20 years ago? - Mobile Business Insights (blog) [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Jim Mullen: Unsocial internet security | Columnists | auburnpub.com - Auburn Citizen [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Internet security company launches a perfume line to promote cybersecurity - Mashable [Last Updated On: March 12th, 2017] [Originally Added On: March 12th, 2017]
- Internet security - Wikipedia [Last Updated On: March 12th, 2017] [Originally Added On: March 12th, 2017]
- Are you undermining your web security by checking on it with the wrong tools? - The Register [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Bruce Schneier on New Security Threats from the Internet of Things - Linux.com (blog) [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Carpe Diem: home internet security - KFOX El Paso [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Motivation Monday: home internet security - KFOX El Paso [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Medical records of 26m patients at risk because of GP surgeries' failing internet security - The Sun [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Free Internet Security | Why Comodo Internet Security Suite ... [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Internet Security Software | Trend Micro USA [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Fix crap Internet of Things security, booms Internet daddy Cerf - The Register [Last Updated On: March 21st, 2017] [Originally Added On: March 21st, 2017]
- Internet of Things security: What happens when every device is smart and you don't even know it? - ZDNet [Last Updated On: March 21st, 2017] [Originally Added On: March 21st, 2017]
- CUJO is cuter than Wall-E, and it's the only internet security device you'll ever need - Yahoo News [Last Updated On: March 21st, 2017] [Originally Added On: March 21st, 2017]
- The Senate just voted to undo landmark rules covering your Internet privacy - Washington Post [Last Updated On: March 25th, 2017] [Originally Added On: March 25th, 2017]
- What the Cloudbleed disaster says about the state of internet security - Information Age [Last Updated On: March 25th, 2017] [Originally Added On: March 25th, 2017]
- Google Has Declared Symantec Harmful To Internet Security - UPROXX [Last Updated On: March 25th, 2017] [Originally Added On: March 25th, 2017]
- Internet Security Analysts: North Korea Is Planning a Global Bank Heist - Breitbart News [Last Updated On: March 28th, 2017] [Originally Added On: March 28th, 2017]
- Internet Security Firm Confirms WikiLeaks 'Vault 7' At Least 40 Cyberattacks Tied to the CIA - The Ring of Fire Network [Last Updated On: April 14th, 2017] [Originally Added On: April 14th, 2017]
- Homeland Security warns of 'BrickerBot' malware that destroys unsecured internet-connected devices - ZDNet [Last Updated On: April 20th, 2017] [Originally Added On: April 20th, 2017]
- A Global Industry First: Industrial Internet Consortium and Plattform Industrie 4.0 to Host Joint IIoT Security ... - Business Wire (press release) [Last Updated On: April 20th, 2017] [Originally Added On: April 20th, 2017]
- Mucheru urges private sector to boost investment in internet security - The Standard (press release) [Last Updated On: April 25th, 2017] [Originally Added On: April 25th, 2017]
- Cloudflare debuts a security solution for IoT - TechCrunch [Last Updated On: April 28th, 2017] [Originally Added On: April 28th, 2017]
- Russian-controlled telecom hijacks financial services' Internet traffic - Ars Technica [Last Updated On: April 28th, 2017] [Originally Added On: April 28th, 2017]
- Avira Internet Security Suite v15.0.26 - TechCentral.ie [Last Updated On: April 28th, 2017] [Originally Added On: April 28th, 2017]
- NSA To Limit Some Collection Of Internet Communication - NPR [Last Updated On: April 29th, 2017] [Originally Added On: April 29th, 2017]
- Report Indicates '10 Concerts' Facebook Trend Could Compromise Your Internet Security - Complex [Last Updated On: April 29th, 2017] [Originally Added On: April 29th, 2017]
- "Improving the World" through Internet Security: Chatting with David Gorodyansky, CEO of AnchorFree - Huffington Post [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Don't Fall For This Tech Support Scam Targeting PC Users - KTLA [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Yikes! Antivirus Software Fails Basic Security Tests - Tom's Guide [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Watch Hackers Sabotage an Industrial Robot Arm - WIRED [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Decoding Internet Security: Spear phishing - Washington Post [Last Updated On: May 5th, 2017] [Originally Added On: May 5th, 2017]
- From the Desk of Jay Fallis: To internet vote, or not to internet vote - BarrieToday [Last Updated On: May 7th, 2017] [Originally Added On: May 7th, 2017]
- Crippling cyberattack continues to spread around the world - Los Angeles Times [Last Updated On: May 14th, 2017] [Originally Added On: May 14th, 2017]
- Cyber Security Experts: Russia Disproportionately Targeted by Malware - Voice of America [Last Updated On: May 14th, 2017] [Originally Added On: May 14th, 2017]
- The Latest: 29000 Chinese institutions hit by cyberattack - ABC News [Last Updated On: May 15th, 2017] [Originally Added On: May 15th, 2017]
- Cyberattack Aftershock Feared as US Warns of Its Complexity - New York Times [Last Updated On: May 15th, 2017] [Originally Added On: May 15th, 2017]
- This week's poll: Priorities for improving internet security - The Engineer [Last Updated On: May 18th, 2017] [Originally Added On: May 18th, 2017]
- Akamai Releases First Quarter 2017 State of the Internet / Security Report - PR Newswire (press release) [Last Updated On: May 18th, 2017] [Originally Added On: May 18th, 2017]
- Do Macs get viruses? - PC Advisor [Last Updated On: May 18th, 2017] [Originally Added On: May 18th, 2017]
- Massive Ransomware Attack Underscores Threats To Internet Security - Benzinga [Last Updated On: May 19th, 2017] [Originally Added On: May 19th, 2017]
- Security News This Week: Hoo-Boy, Mar-a-Lago's Internet Is Insecure - WIRED [Last Updated On: May 20th, 2017] [Originally Added On: May 20th, 2017]
- Internet security firm calls for law to compel information sharing to ... - The Star, Kenya [Last Updated On: May 22nd, 2017] [Originally Added On: May 22nd, 2017]
- Check It Out: No need to unplug after reading books on internet security - The Columbian [Last Updated On: May 22nd, 2017] [Originally Added On: May 22nd, 2017]
- How to beat security threats to 'internet of things' - BBC News - BBC News [Last Updated On: May 25th, 2017] [Originally Added On: May 25th, 2017]
- Best Mac antivirus 2017 - Macworld UK [Last Updated On: May 25th, 2017] [Originally Added On: May 25th, 2017]
- Avira, Kaspersky Top Windows 10 Antivirus Tests - Tom's Guide [Last Updated On: May 25th, 2017] [Originally Added On: May 25th, 2017]
- Paranoid about internet security? Here are the most secure OS options - The American Genius [Last Updated On: May 28th, 2017] [Originally Added On: May 28th, 2017]
- Blockchain Offers Hope for the Broken Internet - Fortune [Last Updated On: May 28th, 2017] [Originally Added On: May 28th, 2017]
- New uses for RFID and security for the internet of things - Phys.Org [Last Updated On: May 31st, 2017] [Originally Added On: May 31st, 2017]
- Security Best Practices for the Internet of Things - Web Host Industry Review [Last Updated On: May 31st, 2017] [Originally Added On: May 31st, 2017]
- Internet infrastructure security guidelines for Africa unveiled - Premium Times [Last Updated On: May 31st, 2017] [Originally Added On: May 31st, 2017]
- In addressing internet security issues, make sure to provide solutions - Minneapolis Star Tribune [Last Updated On: May 31st, 2017] [Originally Added On: May 31st, 2017]
- Whistic Partners with the Center for Internet Security to Extend the ... - PR Web (press release) [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Internet Security Alliance: NIST framework metrics should focus on threats - Inside Cybersecurity (subscription) [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- China cyber-security law will keep citizens' data within the Great Firewall - The Register [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Cyber security: Africa gets Internet security guidelines - TheNewsGuru [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- China to Implement Its First Law on Internet Security After Ransomware Attack - Sputnik International [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Decoding Internet Security: Ransomware - Washington Post [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Internet security upgrade on course - Business Daily (press release) (blog) [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- What's the Safest Laptop For Internet Security? - HuffPost [Last Updated On: June 2nd, 2017] [Originally Added On: June 2nd, 2017]
- Every Day Is Internet Security Day - The Chief-Leader [Last Updated On: June 3rd, 2017] [Originally Added On: June 3rd, 2017]
- 5 Reasons why internet security is crucial in 2017 - Techworm [Last Updated On: June 3rd, 2017] [Originally Added On: June 3rd, 2017]
- Are Pop-Ups An Internet Security Threat? - Good Herald [Last Updated On: June 4th, 2017] [Originally Added On: June 4th, 2017]
- 3 Ways Software Programs Can Help With Internet Security in 2017 - Geek Snack [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Inside Social Security: Make every day your internet security day - Santa Ynez Valley News [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- SOCIAL SECURITY: Every day is internet security day - Palm Beach Post [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]