How Should Government Strengthen Cybersecurity?

30.1K views
•
March 3, 2016
by
RSAC Cybersecurity
YouTube video player
How Should Government Strengthen Cybersecurity?

TL;DR

Cybersecurity improves when defensible systems, protected data, trained people, accountable leadership, and private-sector partnerships are treated as one integrated effort. Government cannot solve the threat alone, and technical defenses are insufficient unless every network user understands how phishing, configuration changes, and other routine choices can create vulnerabilities.

Transcript

Ladies and gentlemen, please welcome US Navy Commander, US Cyber Command Director, NSA/CSS, Admiral Michael S. Rogers. Thanks. Wish I'd set him up somehow. Well, certainly an interesting panel to follow as the director of the National Security Agency. So, can you hear me all the way in the back? Can you raise your hand? Perfect. Good over there? Pe... Read More

Key Insights

  • Cybersecurity is a shared responsibility across government, industry, academia, technical communities, product and service providers, and policymakers. The increasing complexity of cyber threats and changing adversary behavior require these groups to combine their expertise through sustained partnerships and innovative work.
  • United States Cyber Command has three primary missions: defending Department of Defense networks, developing a dedicated cyber workforce for defensive and offensive capabilities, and helping defend critical infrastructure when directed by the President or the Secretary of Defense.
  • Defensible networks are built by making security, redundancy, and reliability core design characteristics. Many existing networks and systems originated when aggressive external penetration was not a primary design concern, so their structures must be adapted to a fundamentally different threat environment.
  • Data is a valuable target that requires deliberate protection. The Department of Defense is examining where information is stored and whether suitable tripwires and protocols are present, using major breaches mentioned in the remarks as evidence that stored data attracts determined adversaries.
  • The cyber workforce includes both specialized mission teams and every person granted access to a keyboard. Specialized personnel supply advanced operational capability, while ordinary users can become either defensive assets or points of vulnerability through their everyday decisions and behavior.
  • User behavior is a fundamental part of cybersecurity because even strong technical defenses can be undermined by human choices. Training must address spear-phishing messages, unauthorized configuration changes, and attempts to make systems more convenient without considering their broader security consequences.
  • Cybersecurity culture depends on accountability, responsibility, and leadership education. Rogers compares the desired approach with the Navy's nuclear culture, where special processes and requirements help participants recognize serious risks and consistently work to reduce them.
  • Private-sector integration is necessary because government and the Department of Defense cannot solve cybersecurity challenges alone. Cyber Command's Point of Partnership seeks to connect with the technology ecosystem by drawing heavily on reservists who already work within that sector.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What are the primary missions of United States Cyber Command?

United States Cyber Command operates and defends Department of Defense networks, including associated weapon systems and platforms. It also works with the military services and acquisition community to develop a dedicated workforce that can apply defensive and offensive cyber capabilities. When directed by the President or the Secretary of Defense, it can also use its capabilities to help defend critical infrastructure in the United States.

Q: How can organizations design networks to withstand cyber threats?

Organizations can improve resilience by treating defensibility, redundancy, and reliability as essential design characteristics rather than later additions. Many networks were built when aggressive penetration by external actors was not a central concern, making their original assumptions unsuitable for the present environment. Cyber Command therefore emphasizes stronger network structures and shared security capabilities intended to embed better protection into the underlying architecture.

Q: Why is data storage central to cybersecurity strategy?

Data storage matters because information has become a valuable target for actors seeking to steal it. A sound strategy begins by mapping where important data is held and examining the protections surrounding each location. Rogers specifically emphasizes tripwires and security protocols that can help determine whether stored information is adequately defended, drawing attention to major breaches as warnings about the consequences of weak data protection.

Q: Why does cybersecurity require more than technical defenses?

Cybersecurity requires more than technology because every person with keyboard access can create either an opportunity or a vulnerability. A sophisticated defensive system can still be weakened when users respond poorly to spear-phishing messages or alter configurations for convenience. Effective protection therefore combines technical controls with user training, informed leadership, responsible behavior, and an organizational culture that recognizes the security consequences of routine choices.

Q: How should organizations train ordinary network users?

Organizations should teach every authorized user to understand how personal decisions affect the wider network. Training should cover the risks of spear-phishing emails and explain why changing settings or configurations for convenience can produce broader vulnerabilities. The goal is not limited to creating specialist knowledge. It is to ensure that everyone with access recognizes personal responsibility and makes choices consistent with the security of the entire system.

Q: What role does leadership play in cybersecurity?

Leadership must understand how the cyber threat environment changes operations, risk, and future planning. Rogers says this understanding cannot be taken for granted, so Cyber Command spends time working directly with leaders on the implications of operating under persistent cyber threats. Educated leaders are better positioned to establish accountability, support workforce preparation, reinforce secure behavior, and shape a culture that treats cybersecurity as a foundational mission concern.

Q: How can an organization build a strong cybersecurity culture?

A strong cybersecurity culture makes accountability and responsibility part of normal operations. Rogers compares this objective with the Navy's nuclear culture, where recognized risks led to special processes, requirements, and shared expectations designed to keep danger to a minimum. Applying that principle to cybersecurity means ensuring that leaders, specialists, and ordinary users understand the risks and consistently follow practices intended to mitigate them.

Q: Why are private-sector partnerships important for government cybersecurity?

Private-sector partnerships matter because government and the Department of Defense do not possess all the knowledge and innovation needed to address cyber threats alone. Rogers argues that better outcomes depend on partnership and integration. Cyber Command's Point of Partnership reflects this approach by establishing a presence in the technology ecosystem and relying largely on reservists who already have direct experience working in that sector.

Summary & Key Takeaways

  • Admiral Michael S. Rogers describes cybersecurity as a shared mission involving government, industry, academia, technical specialists, service providers, and policymakers. Because adversaries and their behavior continue to change, addressing the threat requires sustained innovation, collaboration, and an integrated approach rather than action by any single organization or professional community.

  • United States Cyber Command operates and defends Department of Defense networks, develops a dedicated workforce capable of defensive and offensive cyber operations, and can support the defense of critical infrastructure when directed by national leadership. Its broader strategy combines secure system design, data protection, workforce development, leadership education, and organizational accountability.

  • Rogers argues that technology cannot resolve cybersecurity problems by itself because people can create either opportunities or vulnerabilities. Users require practical security training, leaders must understand the operational implications of cyber threats, and institutions need a culture of responsibility. Partnerships with technology companies can add knowledge, innovation, and relevant experience.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚