National security should trump politics Earlier this week, the Senate Homeland Security and Government Affairs Committee (HSGAC) introduced a cybersecurity bill that would outline the Department of Homeland Security’s responsibilities for overseeing cybersecurity at privately-owned critical infrastructure organizations. Unfortunately, some members of the Senate believe that this legislation is being rushed through congress without the appropriate level of vetting. One Senator released the following statement: “Rather than rush into a massive bill that could have unintended consequences and may not address the problems it is supposed to, the American people would be better served by holding hearings and a markup so that members of both parties can make informed decisions about cybersecurity legislation.”Here we go again! Before our eyes, Congress is prioritizing politics over a pressing issue with national security implications. Of course this legislation isn’t perfect, but: 1. No one is rushing this bill anywhere. The statement above gives the impression that this bill came out of nowhere but that’s completely erroneous and somewhat deceptive. In truth, the roots of this bill have been debated for at least 4 or 5 years now. Congress had an opportunity for deliberation; it is now time to act.2. The bill had bipartisan support in committee. Okay, let’s suppose that there are legitimate differences of opinion about cybersecurity along party lines. A likely assumption but this bill has already passed through the partisan ringer and exited committee with bipartisan support from people (from all sides of the political spectrum) who’ve studied the issues at hand. Isn’t that what committee members are supposed to do BEFORE introducing legislation to the Senate?3. Security professionals working at critical infrastructure organizations want Federal action. At the end of 2010, ESG surveyed security professionals working at critical infrastructure organizations and asked them if they thought that the U.S. Federal Government should be more involved with cybersecurity. Thirty-one percent said that the feds, “should be significantly more active with cybersecurity strategies and defenses,” while 40% indicated that the Federal Government should be, “somewhat more active with cybersecurity strategies and defenses” (note: This report is available for download on the ESG site). If the most knowledge cybersecurity practitioners from critical infrastructure organizations believe that the government should act, doesn’t that tell you something?In speaking to Congress about cybersecurity risks to the U.S. critical infrastructure, Deputy Defense Secretary warned Congress about a potential “digital Pearl Harbor.” That was in 1998. Yes, we’ve made some progress but not nearly enough – especially in light of the ever more ominous cybersecurity threats we face. I know I am being dogmatic here but I’ve read the bill and know the topic quite well. The bill is far from ideal but I think the American public can live with it and of course we can fine-tune the provisions over time. Therefore, I believe that it is time for Senators (who really don’t understand this issue) to stop using the public as a political/digital sacrificial lamb, and pass legislation. Related content analysis 5 things security pros want from XDR platforms New research shows that while extended detection and response (XDR) remains a nebulous topic, security pros know what they want from an XDR platform. By Jon Oltsik Jul 07, 2022 3 mins Intrusion Detection Software Incident Response opinion Bye-bye best-of-breed? ESG research finds that organizations are increasingly integrating security technologies and purchasing multi-product security platforms, changing the industry in the process. By Jon Oltsik Jun 14, 2022 4 mins Security Software opinion SOC modernization: 8 key considerations Organizations need SOC transformation for security efficacy and operational efficiency. Technology vendors should come to this year’s RSA Conference with clear messages and plans, not industry hyperbole. By Jon Oltsik Apr 27, 2022 6 mins RSA Conference Security Operations Center opinion 5 ways to improve security hygiene and posture management Security professionals suggest continuous controls validation, process automation, and integrating security and IT technologies. By Jon Oltsik Apr 05, 2022 4 mins Security Practices Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe