Contributor

A plea to McCain and Obama: No Cyber Security Boondoggles

Opinion
Jul 18, 20081 min

It is great that Barack Obama has taken notice of the woeful state of “cyber security” within the government. So far his rhetoric is spot on.

I just want to point out that huge initiatives are NOT needed to address the problem. In these pages I have enumerated many of the steps needed to start to lock down government networks and operations. The Bush administration’s $30 billion price tag is totally ridiculous (for perspective, the world wide total of all software, hardware, and services in security is half that number). I am not a Washington insider so I can’t tell if that proposal is just a huge pork barrel hidden from public scrutiny under the mantel of “security”.

So, my plea to both candidates: Yes, raise the cyber security issue, OK hire a specialist to advise you, or better yet a bunch of specialists, but, do NOT create huge spending programs. Do NOT create laws and regulations requiring industry to “be secure”. They just are not needed. And please, no more talk about industry-government cooperation. Just get the government to start applying some simple security practices. We need leadership.

Richard Stiennon is chief research analyst at IT-Harvest, the firm he founded in 2005 to cover the 1,600 vendors that make up the IT security industry. He is the author of Surviving Cyberwar (Government Institutes, 2010) and There Will Be Cyberwar: How the Move to Network-Centric Warfighting Set the Stage for Cyberwar. He is a member of the advisory board at the Information Governance Initiative and principal of TrueBit Cyber Partners. He also serves on the R2-TAC, the technical advisory committee for the Responsible Recycling standard for e-waste.

Stiennon was chief marketing officer for Fortinet Inc. and vice president of threat research at Webroot Software. Prior to that, he was vice president of research at Gartner Inc. He has a B.S. in aerospace engineering and an M.A. in war in the modern world from King’s College, London.

The opinions expressed in this blog are those of Richard Stiennon and do not necessarily represent those of IDG Communications Inc. or its parent, subsidiary or affiliated companies.

More from this author