CIOs are still lukewarm to the idea of sharing the cybersecurity threat information the U.S. government is requesting in its Cybersecurity Information Sharing Act. Department of Homeland Security official Andy Ozment reassures IT executives that the feds just want to ‘help you.’ Credit: Thinkstock Despite a new law encouraging companies to share more information about cybersecurity attacks, only 58 percent of CIOs polled say the new law would make it more likely they would cooperate with the government in the event of a data breach. The results, collected in a live audience poll at the Wall Street Journal’s CIO Network show Tuesday, suggest the U.S. government has a ways to go to fostering trust with the corporate sector.Companies are generally willing to share threat “indicators,” such as the IP address of a phishing scam making the rounds, rather than report specific incidents, said Andy Ozment, the Department of Homeland Security’s assistant secretary of the office of cybersecurity and communications, who took the poll in stride as a guest speaker. “The legislation will make that more clear.”The U.S. Senate in October passed the Cybersecurity Information Sharing Act, a well-intentioned band-aid for the rash of data breaches that have buffeted the corporate sector. Ideally, companies would share with DHS more information about threats they are seeing in their networks, which would contextualize the data and share it with other companies and federal agencies. The law seeks to protect companies from private lawsuits, a major stumbling block to information sharing. Ozment said the DHS would begin sharing cybersecurity threat information with private companies later this month.Uncle Sam wants you to trust it with your dataOzment, who oversees a $930 million budget and workforce created to bolster the nation’s cyber and communications infrastructure defense, says companies can relay threat indicator information from their intrusion detection system to one of their servers. Companies then relay it to DHS, which has created a “giant mixing bowl of indicators,” which are stripped of information about employees. He also said cybersecurity vendors would be able to use the data to build their own products. While he allowed that companies are much more reticent to report hacks, Ozment encouraged companies to communicate incidents to law enforcement or DHS, which would grant statutory protections where the data can’t be used for regulatory purposes, civil litigation or Freedom of Information Sharing Act requests. “The bill says that if you’re sharing information for cybersecurity purposes, then you’re protected against this liability,” Ozment says.Companies are contemplating how to share not only information, but talent. Jim Motes, CISO of Rockwell Automation, has proposed a cooperative staffed by the best engineers from member companies, which he says would be better positioned to protect corporate networks than most managed security service providers (MSSP). No shortage of skeptics Although Ozment attempted to put a friendly face on the government’s information-sharing efforts, he faced a skeptical crowd of CIOs from Lockheed Martin, American International Group, Allstate and other Fortune 500 companies.NuStar Energy CIO Manish Kapoor noted that his CISO was “freaking out” after the company received an addendum request for a commercial contractor to comply with National Institute of Standards and Technology (NIST) standard for protecting critical infrastructure within 90 days. He said this was a tall task because “NIST standards are really complicated.”Ozment, whose agency provides support for the NIST standards, said that this is happening in every industry, adding that a singular standard is better than too many standards. “The benefit of the NIST cybersecurity framework is at least we can all agree on it because the worst case for everybody is a tower of Babel … competing regulations, competing contractual demands … nobody wants to live in that world and that is why we did the NIST cybersecurity framework.”Ultimately, Ozment said: “We’re there to help you, we want to find the bad guys on your network, kick them out and get you back up on your feet again,” he says. Despite those good intentions, the DHS must overcome the perception problem it has among some CIOs. As NuStar Energy’s Kapoor puts it, “Whenever I hear somebody say ‘I’m from the government and I’m here to help you’ I get nervous.” Related content news UK government plans 2,500 new tech recruits by 2025 with focus on cybersecurity New apprenticeships and talent programmes will support recruitment for in-demand roles such as cybersecurity technologists and software developers By Michael Hill Sep 29, 2023 4 mins Education Industry Education Industry Education Industry news UK data regulator orders end to spreadsheet FOI requests after serious data breaches The Information Commissioner’s Office says alternative approaches should be used to publish freedom of information data to mitigate risks to personal information By Michael Hill Sep 29, 2023 3 mins Government Cybercrime Data and Information Security feature Cybersecurity startups to watch for in 2023 These startups are jumping in where most established security vendors have yet to go. By CSO Staff Sep 29, 2023 19 mins CSO and CISO Security news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Data Breach Financial Services Industry Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe