Cybersecurity

Cybersecurity isn't just about money, OPM adviser says

Shutterstock image (by MaximP): network defense.

Cybersecurity might actually come relatively cheap.

Clifton Triplett, the special outside-of-government senior adviser hired in November by the Office of Personnel Management, made the case for using what agencies already have instead of buying new tools.

"I get a little bit frustrated that we're constantly striving for more money," Triplett said at a Bloomberg Government event on Dec. 14. "We have to get past, 'Cyber is more expensive.'"

Agencies could get a lot of bang for very few bucks just by changing behaviors -- for example, internal culture and access management -- and making better use of the tools they already have, he said.

Triplett was hired to advise Acting OPM Director Beth Cobert on cybersecurity in the wake of the massive breach that resulted in the theft of databases containing records on more than 22 million government workers, contractors and individuals included as references or sources in background checks.

"I just get concerned that we think buying a technology's a silver bullet," he said. "We have a lot of stuff already."

One place where there is a need for purchasing: modernization of antiquated legacy systems. But don't file those costs under the "cybersecurity" tab.

"That will cause harm," Triplett said, adding that modernizing legacy systems will streamline business processes, improve customer experiences and enhance government in myriad ways.

His argument that cybersecurity does not have to be expensive stands apart from modernization that needs to be happening anyway, he added.

Triplett touted the merits of two-factor authentication, keeping critical systems off the Internet and sharing information, noting that the private and public sectors must be willing to "share on suspicion, not fact" of compromises. That willingness has been tough to come by, he said, because companies fear that telling the government about a suspected breach could undermine the public's trust.

When asked about good cybersecurity metrics, Triplett said, "I often see metrics driving bad behaviors." If, say, "mean time to resolution" is a preferred metric, people might try to game it by delaying the reporting of an incident, which would ultimately damage the whole enterprise.

He also stressed that although cybersecurity does not have to be expensive, it is a never-ending battle.

"Our goal should not be zero" cybersecurity incidents reported, Triplett said. "It should be to find them at a more refined level every year."

About the Author

Zach Noble is a staff writer covering digital citizen services, workforce issues and a range of civilian federal agencies.

Before joining FCW in 2015, Noble served as assistant editor at the viral news site TheBlaze, where he wrote a mix of business, political and breaking news stories and managed weekend news coverage. He has also written for online and print publications including The Washington Free Beacon, The Santa Barbara News-Press, The Federalist and Washington Technology.

Noble is a graduate of Saint Vincent College, where he studied English, economics and mathematics.

Click here for previous articles by Noble, or connect with him on Twitter: @thezachnoble.


Featured

  • Telecommunications
    Stock photo ID: 658810513 By asharkyu

    GSA extends EIS deadline to 2023

    Agencies are getting up to three more years on existing telecom contracts before having to shift to the $50 billion Enterprise Infrastructure Solutions vehicle.

  • Workforce
    Shutterstock image ID: 569172169 By Zenzen

    OMB looks to retrain feds to fill cyber needs

    The federal government is taking steps to fill high-demand, skills-gap positions in tech by retraining employees already working within agencies without a cyber or IT background.

  • Acquisition
    GSA Headquarters (Photo by Rena Schild/Shutterstock)

    GSA to consolidate multiple award schedules

    The General Services Administration plans to consolidate dozens of its buying schedules across product areas including IT and services to reduce duplication.

Stay Connected

FCW Update

Sign up for our newsletter.

I agree to this site's Privacy Policy.