Looking ahead at federal cybersecurity and what Howard Schmidt will leave in his wake.
A number of pieces about the legacy of President Obama’s Cybersecurity Coordinator CIO Howard Schmidt have already been written, but none that I’ve read talk about what I believe every enterprise technology and security executive can learn from his time in that critical role. Many of the articles about his tenure have revolved around the challenges he faced: a perceived “limited mandate,” living in the shadow of the more media-friendly General Keith Alexander at the NSA, and his apparent unwillingness to work directly with other federal agencies – the latter was the source of a considerable amount of negative press during his two and a half year tenure as the president’s cybersecurity chief.
The truth is, establishing cybersecurity policy at the federal level is great – after all, sharing best practices is a valuable and admirable endeavor. But, as I believe Howard Schmidt understood, security policy is ultimately pointless if an organization fails to implement the appropriate processes and controls defined by that very policy within its own environment. Schmidt’s legacy will, I believe, be his focus on ensuring the success of a more outwardly-focused primary objective: protecting our sensitive national data and infrastructure from foreign nation-states, hacktivists and others who would us it against us.
MORE FROM THIS AUTHOR: What a Psychopath Can Teach Us About Information Security
Flame Malware Blurs the Line Between Fiction and Reality
This mandate that Howard shepherded over the past few years is not particularly sexy, sensational, or (if we’re honest) that exciting, but it is the bread and butter of what we in the security industry do. If proof of this is needed, you need only to look at the pages of the 2012 Verizon Data Breach Investigations Report (which I’ve been quoting liberally over the past few weeks): 97% discovered data breaches discovered in 2011 could have been avoided with only basic of moderate controls. I’ll argue that, in many cases, the controls were in place, but simply were not reviewed. Don’t get me wrong, this isn’t intended to be a criticism of my fellow security professionals; it’s simply the fact that as networks grow increasingly complex, data volumes continue to increase exponentially and the requirement for security to feed into other operational- and risk-related business activities grows, things can get overlooked.
Howard Schmidt’s apparent diligence to the job of protecting our country’s most sensitive data has, I have no doubt, contributed to safeguarding federal data and systems from experiencing some avoidable and embarrassing incidents, quite possibly including major data breaches. It’s a challenge that every organization faces, and in Howard’s case, both the likelihood and value of compromised data would have been many times greater than in many organizations outside the scope of federal government. The environments under Schmidt’s management would have been at the very top of the list for hackers, state-sponsored cyber-terrorists (although he rejected the idea of a “Cyber War”) and signature-less advanced persistent threats.
Some corners of the media have commented on Schmidt’s replacement, and specifically, his age. Michael Daniel, the current chief of the White House Budget Office’s intelligence branch, is 16 years the junior of his predecessor. Some have described him as a ‘young gun’ – the insinuation being that his approach will differ substantially from Howard’s since he represents a different generation in the era of technology. I’m not sure that his age matters much, but I do hope that he follows the example set by Howard Schmidt: unless you get the basics right, all the latest technology and innovative approaches in the world won’t help you.
So, while the politicians will, I have no doubt, take care of the policy-making, perhaps we should all learn from the example set by Howard Schmidt. Implement effective systems and processes alongside the right technologies that help you to do the basics right; understand the risk profile of your organization and take steps to minimize them; continuously monitor your network and ensure continual compliance with regulatory mandates and your own organizational policies. As the volume of security data grows – as it has done and will continue to do over the coming months and years – getting your security house in order will become increasingly difficult. Perhaps this is Howard’s retirement gift to us all.




