Contributor

Could a small business cyber security task force do some good?

Opinion
Jun 11, 20082 mins

Knowing my usual reaction to government involvement in cyber security most of my readers will be surprised to learn that I actually support this proposed bill. Typically, forming a “task force” involves the trading of political favors and the establishment of more bureaucracy. But this bill, as proposed today by Senators Kerry et. al. is simple and to the point: create an advisory task force to the SBA (Small Business Administration) to help suggest ways that small businesses can protect themselves from cyber threats.

Since most of my blogging and writing has the same purpose as the proposed task force I cannot complain about the goal of this legislation. And, I really approve of the budget, $200K/year for three years, with nothing going to the task force members.

While you could argue that the task force will not uncover anything new, as a matter of fact will come up with some pretty obvious recommendations (firewalls, passwords, defense in depth, encryption of critical data), you have to admit that the SBA is pretty good at messaging to its constituency. I could see the SBA engaging in education programs, web based tools, even working through banks and its loan programs to influence the adaption of good security practices at small businesses.

————

Follow me on Twitter 

Join the LinkedIn Security Leaders Group 

Richard Stiennon is chief research analyst at IT-Harvest, the firm he founded in 2005 to cover the 1,600 vendors that make up the IT security industry. He is the author of Surviving Cyberwar (Government Institutes, 2010) and There Will Be Cyberwar: How the Move to Network-Centric Warfighting Set the Stage for Cyberwar. He is a member of the advisory board at the Information Governance Initiative and principal of TrueBit Cyber Partners. He also serves on the R2-TAC, the technical advisory committee for the Responsible Recycling standard for e-waste.

Stiennon was chief marketing officer for Fortinet Inc. and vice president of threat research at Webroot Software. Prior to that, he was vice president of research at Gartner Inc. He has a B.S. in aerospace engineering and an M.A. in war in the modern world from King’s College, London.

The opinions expressed in this blog are those of Richard Stiennon and do not necessarily represent those of IDG Communications Inc. or its parent, subsidiary or affiliated companies.

More from this author