“Look, if the Russians and the Chinese want to break into our networks, we know they are going to at the end of the day,” -Jen Easterly, Director, Cybersecurity and Infrastructure Security Agency (CISA)
Out of the dozens of conversations I had and keynote and panel discussions I attended at the recent RSA Conference, that statement from Jen Easterly during a keynote panel stuck out to me as the most inciteful, impactful, and soul crushing because of the real truth it highlights: Yes, we should do as much as we can to prevent cyberattacks, but our real ally is chance.
Easterly made that statement almost off-handedly during the “Building Trust in a Zero-Trust World to Confront Tomorrow’s Cyber Threats” keynote panel on Wednesday afternoon at the event. She was responding to panel moderator Niloofar Razi Howe asking what the “general American public” should “be doing differently to protect themselves” from cyberattacks.
The meat of Easterly’s answer was to plug CISA’s “Shields Up” program that provides guidance to organizations on how they can protect themselves from cyberattacks. She also cited that program’s advice to individuals, which includes the use of multi-factor authentication, updated device software, being mindful of phishing scams, and using strong passwords.
But I forgot all of that following Easterly’s honest admission that despite everything that organizations, corporations, or individuals do, it’s not enough.
In talking with different people at the event following that keynote session, most agreed with Easterly’s eventuality statement. But they also added that despite that ultimate answer, everyone needs to do as much as they can to mitigate risks. Not every hacker or hacking group has the depth of resources that a China or Russia is going to have, so we should all do as much as we can to reduce our attack surfaces.
This model is similar to why we lock our home or automobile doors, despite both of those items being partly constructed with a clear material – glass – that can be easily defeated with one of the most plentiful objects on earth – rocks. We are basically just leaving our security to chance and hoping we get overlooked by those that will get in no matter what we do.
And that’s the notion from the RSA Conference that sticks with me.
The Reality of Cybersecurity Chance
As someone who believes in the randomness of the universe, I get that we are all really just at the whim of chance. Sure, we can sort of tweak that level of chance by making personal decisions. For instance, if I never go in water, I will reduce my chance of drowning. But, water is fun, so I will learn to swim and might even wear a floatation device when I go into a body of water.
By that notion, I could drastically reduce my chance of being the victim of a cyberattack by living completely off the grid. But, that’s too late at this point and some of the stuff on the grid can make life more fun. Thus, I might take steps to mitigate my chance of being attacked by following proper security hygiene and maybe even paying an outside firm to watch my back in case I forget something.
But, at the end of the day, my chance of being hit by a cyberattack comes down to whether a resource-rich entity decides they really want my information. And if they do, well, all bets are off.
I have toyed in the past with the idea of writing an opinion piece that just says: “I Give Up” followed by my social security number. The reasoning was that maybe if I just gave out my social security number a hacker would ignore it because there was no challenge in obtaining those digits.
I have not quite stepped over that line, but the daily deluge of information I receive from cybersecurity companies on various cyberattacks, breaches, and leaks keeps that idea on my mind. Which is sad, right?
Thus, I will continue to do all I can to limit the amount of my personal information that is hacked on a daily basis and just hope chance has my back. Or at least I will until I really get the crap scared out of me at the upcoming Black Hat event.
Comments