Government at high risk of economic espionage

An evolving range of cyber threats, techniques and dependencies are brewing a perfect storm for economic espionage, and will require an accelerated, multi-pronged approach, according to a new Government Accountability Office report.

Better security through access management and data encryption, combined with risk management and strategic planning, are critical to defending U.S. public and private networks from an array of adversaries, including criminal groups, hackers, terrorists and insiders. But perhaps most important are key partnerships that coordinate agencies, companies and other stakeholders, according to the report.

“Cyberspace – where much business activity and the development of new ideas often take place – amplifies these threats by making it possible for malicious actors to quickly steal and transfer massive quantities of data while remaining anonymous and difficult to detect,” the report noted.

GAO designated federal information security as a government-wide high-risk area back in 1997, expanding that classification in 2003 to include critical infrastructure. The new report underscores the gravity of the threat and the importance of agencies following through with the hundreds of recommendations for protecting federal interests GAO has issued over the years.

According to the report, the U.S. Computer Emergency Readiness Team (US-CERT) – which receives computer security incident reports from government agencies, commercial enterprises, U.S. citizens, and international computer security incident response teams – fielded more than 100,000 incident reports in fiscal year 2011. More than half were phishing exploits; other types included viruses, Trojan horses, worms and logic bombs; malicious websites; policy violations; equipment theft or loss; suspicious network activity; attempted access; and social engineering.

The report also highlighted a number of alarming cyber crimes in the private sector in recent years, including security breaches that resulted in hundreds of millions of people’s sensitive data and billions of dollars in loss of intellectual property.

GAO recommended that agencies and companies alike employ a full suite of defenses: technological access controls including boundary protection, authentication and authorization; system integrity methods like antivirus software; cryptography; configuration management and assurance.

The report also called for better cybersecurity framework, risk assessments and especially collaboration, highlighting interagency efforts in Congress and the White House for protecting intellectual property.

“To address this threat, federal agencies have a key role to play in law enforcement, deterrence and information sharing,” the report noted. “Ensuring effective coordination will be critical for better protecting the economic security of America’s businesses.”

About the Author

Amber Corrin is a former staff writer for FCW and Defense Systems.

Rising Stars

Meet 21 early-career leaders who are doing great things in federal IT.

Featured

  • SEC Chairman Jay Clayton

    SEC owns up to 2016 breach

    A key database of financial information was breached in 2016, possibly in support of insider trading, said the Securities and Exchange Commission.

  • Image from Shutterstock.com

    DOD looks to get aggressive about cloud adoption

    Defense leaders and Congress are looking to encourage more aggressive cloud policies and prod reluctant agencies to embrace experimentation and risk-taking.

  • Shutterstock / Pictofigo

    The next big thing in IT procurement

    Steve Kelman talks to the agencies that have embraced tech demos in their acquisition efforts -- and urges others in government to give it a try.

  • broken lock

    DHS bans Kaspersky from federal systems

    The Department of Homeland Security banned the Russian cybersecurity company Kaspersky Lab’s products from federal agencies in a new binding operational directive.

  • man planning layoffs

    USDA looks to cut CIOs as part of reorg

    The Department of Agriculture is looking to cut down on the number of agency CIOs in the name of efficiency and better communication across mission areas.

  • What's next for agency cyber efforts?

    Ninety days after the Trump administration's executive order, FCW sat down with agency cyber leaders to discuss what’s changing.

Reader comments

Please post your comments here. Comments are moderated, so they may not appear immediately after submitting. We will not post comments that we consider abusive or off-topic.

Please type the letters/numbers you see above

More from 1105 Public Sector Media Group