Cybersecurity

Cybersecurity isn't just about money, OPM adviser says

Shutterstock image (by MaximP): network defense.

Cybersecurity might actually come relatively cheap.

Clifton Triplett, the special outside-of-government senior adviser hired in November by the Office of Personnel Management, made the case for using what agencies already have instead of buying new tools.

"I get a little bit frustrated that we're constantly striving for more money," Triplett said at a Bloomberg Government event on Dec. 14. "We have to get past, 'Cyber is more expensive.'"

Agencies could get a lot of bang for very few bucks just by changing behaviors -- for example, internal culture and access management -- and making better use of the tools they already have, he said.

Triplett was hired to advise Acting OPM Director Beth Cobert on cybersecurity in the wake of the massive breach that resulted in the theft of databases containing records on more than 22 million government workers, contractors and individuals included as references or sources in background checks.

"I just get concerned that we think buying a technology's a silver bullet," he said. "We have a lot of stuff already."

One place where there is a need for purchasing: modernization of antiquated legacy systems. But don't file those costs under the "cybersecurity" tab.

"That will cause harm," Triplett said, adding that modernizing legacy systems will streamline business processes, improve customer experiences and enhance government in myriad ways.

His argument that cybersecurity does not have to be expensive stands apart from modernization that needs to be happening anyway, he added.

Triplett touted the merits of two-factor authentication, keeping critical systems off the Internet and sharing information, noting that the private and public sectors must be willing to "share on suspicion, not fact" of compromises. That willingness has been tough to come by, he said, because companies fear that telling the government about a suspected breach could undermine the public's trust.

When asked about good cybersecurity metrics, Triplett said, "I often see metrics driving bad behaviors." If, say, "mean time to resolution" is a preferred metric, people might try to game it by delaying the reporting of an incident, which would ultimately damage the whole enterprise.

He also stressed that although cybersecurity does not have to be expensive, it is a never-ending battle.

"Our goal should not be zero" cybersecurity incidents reported, Triplett said. "It should be to find them at a more refined level every year."

About the Author

Zach Noble is a staff writer covering digital citizen services, workforce issues and a range of civilian federal agencies.

Before joining FCW in 2015, Noble served as assistant editor at the viral news site TheBlaze, where he wrote a mix of business, political and breaking news stories and managed weekend news coverage. He has also written for online and print publications including The Washington Free Beacon, The Santa Barbara News-Press, The Federalist and Washington Technology.

Noble is a graduate of Saint Vincent College, where he studied English, economics and mathematics.

Click here for previous articles by Noble, or connect with him on Twitter: @thezachnoble.


Featured

  • Cybersecurity

    DHS floats 'collective defense' model for cybersecurity

    Homeland Security Secretary Kirstjen Nielsen wants her department to have a more direct role in defending the private sector and critical infrastructure entities from cyberthreats.

  • Defense
    Defense Secretary James Mattis testifies at an April 12 hearing of the House Armed Services Committee.

    Mattis: Cloud deal not tailored for Amazon

    On Capitol Hill, Defense Secretary Jim Mattis sought to quell "rumors" that the Pentagon's planned single-award cloud acquisition was designed with Amazon Web Services in mind.

  • Census
    shutterstock image

    2020 Census to include citizenship question

    The Department of Commerce is breaking with recent practice and restoring a question about respondent citizenship last used in 1950, despite being urged not to by former Census directors and outside experts.

Stay Connected

FCW Update

Sign up for our newsletter.

I agree to this site's Privacy Policy.