How Did Cybersecurity Change in November 2020?

184 views
November 25, 2020
by
RSAC Cybersecurity
YouTube video player
How Did Cybersecurity Change in November 2020?

TL;DR

Election security depended on transparent communication, coordinated government action, and clear separation of verified facts from misinformation. Organizations also needed resilience through post-incident reviews, tabletop exercises, and continuous penetration testing, while the expanding cybersecurity workforce showed that education and outreach could help narrow the skills gap.

Transcript

Hello, listeners. We are so excited to be back for another live stream monthly news roundup with RSAConference.com. Given the week we just had, I think one of the greatest challenges is going to be actually looking back on the entire month with the same level of intense interest. But when we started the month of November, we had great concerns abou... Read More

Key Insights

  • CISA’s rumor-control reporting was a transparent way to distinguish verified election-security facts from misinformation. The initiative paired an executive summary of objectives and goals with video communication, demonstrating how security organizations can give their missions a visible, accessible public face.
  • The November 3 election was described in a November 12 joint statement as the most secure in American history. Election officials across the country were still reviewing and double-checking the process before finalizing results, showing that verification continued after voting ended.
  • Federal election-security work involved several organizations operating toward a shared objective. One cited example was the Department of Justice’s October shutdown of 92 websites described as being surreptitiously controlled by the Iranian government and used for foreign influence.
  • Security leadership benefits from transparency about missions, objectives, goals, and evidence. The discussion praised Chris Krebs and Bryan Ware for their work and treated CISA’s public communication as a practical example for CISOs and other security practitioners.
  • Organizational resilience requires post-incident reviews and tabletop exercises. These activities help teams identify lessons, determine what could have been handled better, and share useful information about attacks and preventive mechanisms with industry partners and neighboring organizations.
  • Annual penetration tests provide only a point-in-time assessment. A test completed in the first quarter may no longer represent fourth-quarter conditions after organizations deploy new VPNs, software, servers, computers, and applications in response to major operational changes.
  • Crowdsourced penetration testing supports ongoing examination by strategic thinkers who may approach systems differently. The discussion presented it as a way to discover current vulnerabilities and obtain practical information for improving applications and business security beyond an annual compliance exercise.
  • The cybersecurity workforce estimate reached around 3.5 million after approximately 700,000 additional professionals entered the industry, a 25 percent increase over the previous estimate. Further narrowing the skills gap depends on education, outreach, and earlier exposure to cybersecurity, information security, and intelligence careers.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How did CISA respond to election misinformation in 2020?

CISA used rumor-control updates to distinguish verified facts from misinformation about election security. Its public materials included an executive summary describing the mission, objectives, and goals, along with video communication. The approach gave security work a recognizable public face and provided citizens with an attributed source for evaluating claims about the November 3 election.

Q: Why was CISA’s election-security communication considered effective?

CISA’s communication was considered effective because it combined transparency, clear objectives, factual attribution, and accessible formats. Its rumor-control report explained what misinformation could look like and directed people toward reliable information. The discussion presented this approach as a useful leadership lesson for CISOs and security practitioners responsible for communicating risk to the public or their organizations.

Q: What government action addressed foreign influence before the election?

The Department of Justice shut down 92 websites in October that were described as being surreptitiously controlled by the Iranian government. Visitors to those sites could see a government seizure banner explaining that the domains had been taken over because of foreign influence. The discussion connected this action to the broader multi-agency effort supporting a safe and secure election.

Q: Why are post-incident reviews important for cybersecurity teams?

Post-incident reviews help organizations identify lessons after a security event, examine what could have been handled better, and improve preventive mechanisms. They can also produce information worth sharing with industry partners and neighboring organizations. Although executives may view reviews and tabletop exercises as additional expenditures, the discussion described them as essential tools for strengthening future responses.

Q: Why is annual penetration testing insufficient by itself?

An annual penetration test measures security at one point in time, so its findings can become outdated as technology and operations change. During the pandemic, organizations introduced VPNs, software, servers, computers, and applications. A test performed in the first quarter therefore might not represent the environment in the fourth quarter, even if it satisfied an annual requirement.

Q: How does crowdsourced penetration testing improve security?

Crowdsourced penetration testing enables ongoing testing by strategic thinkers who may examine applications and systems from different perspectives. According to the discussion, these testers can identify vulnerabilities that a periodic assessment may miss and provide practical insight into how an organization can improve its application and business security as technology changes throughout the year.

Q: What did the 2020 cybersecurity workforce study report?

The 2020 cybersecurity workforce study reported that approximately 700,000 additional professionals had joined the industry. That represented a 25 percent increase over the previous workforce estimate and expanded the estimated global workforce to around 3.5 million. The findings suggested that the skills gap had narrowed, although continued education and outreach remained important.

Q: How can education help reduce the cybersecurity skills gap?

Education can reduce the skills gap by introducing cybersecurity, information security, and intelligence careers during formative years rather than after people have already chosen other paths. Outreach can include both young people and seniors. The discussion also noted that youths who find vulnerabilities or create backdoors in games may already possess resilient, relevant problem-solving abilities.

Summary & Key Takeaways

  • CISA’s election-security work emphasized transparency, attribution, and public rumor control. Chris Krebs and Bryan Ware were credited with helping address fears about foreign hackers and misinformation surrounding the November 3 election. The discussion presented visible leadership and coordination among government organizations as important parts of maintaining confidence in election systems.

  • ISC2 Security Congress sessions focused on building systems that can withstand disruption. Juliet Kayyem acknowledged that even extensive national-security experience could not fully prepare leaders for the global pandemic. Recommended sessions examined post-incident reviews, tabletop exercises, and the differences among crowdsourced, traditional, and automated penetration testing approaches.

  • The 2020 cybersecurity workforce study estimated that approximately 700,000 additional professionals had joined the industry, increasing the workforce estimate by 25 percent to around 3.5 million. The discussion connected further progress to earlier cybersecurity education, outreach to young people and seniors, and recognition of transferable technical problem-solving skills.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚