The Grill: Patricia Titus

News
Jun 21, 20106 mins

The security maven wants criteria for acts of cyberwar.

As the first chief information security officer at the Transportation Security Administration, Patricia Titus got a rare opportunity to build an information security organization from scratch. Titus, who is now CISO at Unisys Corp., talks about the advantages and disadvantages of such an opportunity, and the broader challenges involved in defending U.S. interests in cyberspace.

Patricia Titus

Title: CISO, Unisys Corp.

Most interesting thing people don’t know about you: I used to copy Morse code for the U.S. Air Force in the early ’80s and can still remember much of it.

Favorite nonwork pastime: Gardening. I love to dig my hands into the dirt, plant something and watch it grow. My favorite is growing herbs and flowers that attract bugs, butterflies and birds to our backyard.

Recent good read: I like to read for pleasure, and right now I’m stuck on The Twilight Saga by Stephenie Meyer.

Favorite movie: My favorite movie still is Independence Day with Will Smith. Remember they wiped out the aliens by injecting the mother ship with a computer virus?

What was it like heading up IT security at the TSA? The challenge in the early days was getting leadership to recognize that even though we were deploying very rapidly, we needed to keep security in the forefront. When I started at the TSA, I was actually a wireless program manager. When I complained that there was no one doing security, they promptly assigned that to me. I was given security as a collateral duty, and eventually, after about six months, the CIO said, “You are going to be our new CISO.” The challenge was in coming up with a brand-new operation and coming up with policies that were not based on old, antiquated legacy concepts. What we clearly understood was, our environment was so different from the other agencies that we really needed to start completely from ground up with new technologies and with new policies based on a set of standards where you really didn’t have to worry about legacy systems.

Was starting from scratch an advantage or a disadvantage? It was a benefit for me to be able to look at things differently and to form an organization the way it needed to be formed. It was very different from the way security offices were in government departments that have been around for years and years. But it was also a challenge trying to change the culture and mind-set of several people and executives who had been in government a long time and had always done things [a particular] way.

We keep hearing about cyberwar, state-sponsored attacks and intrusions into government networks and systems. What’s happening? First of all, it’s not just government, it’s also the agencies and corporations that support the government. What needs to be looked at is critical infrastructure in general. We are constantly doing tactical firefighting, and I think more offensive capabilities need to be built that give us early warning and allow us to respond when these attacks happen.

Respond how? As Americans, we have a tendency to respond to attacks versus putting up preventive capabilities. When it comes to any sort of cyberattack, we still have the old mind-set: Where they have a nuclear weapon, we have a nuclear weapon. They push a button; we push a button. I think we need to have a different mind-set. With technology, we need to have innovation that allows us to have offensive capabilities. I don’t think that the U.S. has taken that stance before. It is a very difficult stance to take, just in general, looking at cyberspace and how it works.

Does cyberwar merit a military response? We need to be able to take immediate steps, and in some instances, we need to be the first. In a cyberwar, the nation-state that hits first is going to win. It’s not like a traditional war where you send some troops and guns — you might lose a little bit of ground sometimes but end up winning the war. In cyberspace, if your systems are taken offline, you are offline, period. The downside to launching first is that it is a declaration of war. That’s something this administration is going to have to define clearly. What constitutes an act of war, what constitutes a threat, and what constitutes intent? Those things have to be clearly defined.

What’s your assessment of the Obama administration’s handling of cybersecurity affairs? I think they have done a good job. It’s hard to assess all that’s being done behind the scenes, because I am not inside the government anymore. But I do think they are making tremendous progress. They are reaching out through public-private partnerships. They have asked for feedback from industry on writing the strategies that need to be implemented. That’s something that industry has not had as much input into in the past, with previous administrations.

There aren’t too many women in the information security arena. Why do you think that’s the case? I think women have a tendency to be more risk-averse than men, and the IT security field is a very risk-ripe career field. I think we could encourage more women, more individuals, to go into the IT security field just based on executive leadership. So the same leadership I had at TSA, where the assistant secretary was very aware and very strongly supportive of my office — I have that same commitment here at Unisys from our CEO. So I don’t feel like I’m at risk like I would in an organization where I didn’t have that kind of executive sponsorship.

Do you see more women in the IT security field than when you started your career? I absolutely do. I think the community of women in the IT security field is coming together, and we are supporting each other much the same as people in other fields.

You were voted Woman of Influence by the Executive Women’s Forum last year. What did it mean to you? That was amazing to me to be recognized by my peers as a leader and as someone who is influencing direction. That was a great honor. I hope that I continue to live up to that award and continue to influence other women to go into this field.

jvijayan

Jaikumar Vijayan is a freelance technology writer specializing in computer security and privacy topics. He writes for CSO Online, Dark Reading and Security Boulevard, among other outlets. He has also written for eWEEK, InformationWeek, TechTarget, Security Intelligence, Government Computer News, Datamation, and Information Security Magazine.

Jai was previously as senior editor at Computerworld, where he covered information security topics targeted at an enterprise IT audience. In addition to breaking news stories, he wrote features and analysis based on commentary and interviews with technical experts, security executives and other IT leaders. While at Computerworld, he won several awards for excellence in technology journalism.

Prior to Computerworld, Jai covered technology issues for The Economic Times in Bangalore, India. He has a Master's degree in Statistics and lives in Naperville, Ill.

More from this author