Cybersecurity

NSS Labs CEO: U.S. has unilaterally disarmed in cyberspace

Vikram Phatak

NSS Labs' Vikram Phatak said the government's fundamental misunderstanding of cybersecurity hampers its ability to fight adversaries in cyberspace.

The United States is fighting adversaries in cyberspace with one hand tied behind its back, according to the CEO of NSS Labs, an IT security testing firm.

"Unilateral disarmament is a folly, and that's effectively what [the United States has] done," Vikram Phatak told FCW in a recent interview. "We've taken anybody who knows how to operate a [cyber weapon] and thrown them in jail.

The U.S. government is worse off for keeping hackers with operational knowledge at arm's length, he added.

By contrast, the Russian government has reportedly had close ties to organized cybercrime. Although U.S. military and intelligence agencies have talented personnel, Phatak said, they don't have "the kind of operational experience that the Russian mob has or the Chinese mob has."

National Security Agency Director Adm. Michael Rogers has said he wants to make it easier to recruit private-sector talent and rotate NSA personnel in and out of the private sector.

"I think, fundamentally, there's a misunderstanding of cyber in Washington," Phatak said. He later added that "either you're working for the government or you're a bad guy...and it's very much a law enforcement-centric view as opposed to a national security view."

Phatak was one of the thousands of IT security professionals who descended on San Francisco in early March for the RSA Conference. His Austin, Texas-based firm tests cybersecurity products for a range of purposes, including endpoint security and distributed denial-of-service attacks.

Phatak believes that NSS Labs' reputation as a testing firm positions him well to dispense impartial analysis to lawmakers. "When we go to the Hill, we don't go to sell anything," he said. "My customers are everyone from Disney to JPMorgan Chase, and if government policy goes sideways, then they're all affected."

Tribal vs. institutional knowledge

A federal court order to compel Apple to help the FBI unlock the iPhone of one of the San Bernardino, Calif., shooters cast a pall over the RSA Conference.

Phatak, a former CTO at cybersecurity firm Trustwave, called the FBI's pressure on Apple "ham-fisted" and expressed concern that mandating backdoors into U.S. products would undercut the country's economic interests.

Encryption is math, after all, and he asked what sense it made to stop people from doing math.

The RSA Conference offers IT industry gurus a chance to strut their stuff, but there might be an over-reliance on such gurus in the public and private sectors, according to Phatak. "You've got tribal knowledge or institutional knowledge, and right now you've got a lot of tribal knowledge when it comes to cybersecurity," he said.

One way to create a baseline understanding of government IT assets and their vulnerabilities is through the Continuous Diagnostics and Mitigation program run by the Department of Homeland Security and the General Services Administration.

Phatak praised CDM for its proactive approach to detecting vulnerabilities. The government's recognition of the need to continuously evaluate IT assets is a good thing, he said.

About the Author

Sean Lyngaas is an FCW staff writer covering defense, cybersecurity and intelligence issues. Prior to joining FCW, he was a reporter and editor at Smart Grid Today, where he covered everything from cyber vulnerabilities in the U.S. electric grid to the national energy policies of Britain and Mexico. His reporting on a range of global issues has appeared in publications such as The Atlantic, The Economist, The Washington Diplomat and The Washington Post.

Lyngaas is an active member of the National Press Club, where he served as chairman of the Young Members Committee. He earned his M.A. in international affairs from The Fletcher School of Law and Diplomacy at Tufts University, and his B.A. in public policy from Duke University.

Click here for previous articles by Lyngaas, or connect with him on Twitter: @snlyngaas.


Featured

  • FCW PERSPECTIVES
    sensor network (agsandrew/Shutterstock.com)

    Are agencies really ready for EIS?

    The telecom contract has the potential to reinvent IT infrastructure, but finding the bandwidth to take full advantage could prove difficult.

  • People
    Dave Powner, GAO

    Dave Powner audits the state of federal IT

    The GAO director of information technology issues is leaving government after 16 years. On his way out the door, Dave Powner details how far govtech has come in the past two decades and flags the most critical issues he sees facing federal IT leaders.

  • FCW Illustration.  Original Images: Shutterstock, Airbnb

    Should federal contracting be more like Airbnb?

    Steve Kelman believes a lighter touch and a bit more trust could transform today's compliance culture.

Stay Connected

FCW Update

Sign up for our newsletter.

I agree to this site's Privacy Policy.