Commentary

Michael Hickins
 

Expert: Cyber-Czar Will Be 'Underwhelming' Choice

The Obama Administration is set to introduce a "cybersecurity coordinator" to help the United States craft policies that will beat back hostile incursions into public and private databases and systems, but hasn't made his pick known yet.

The Obama Administration is set to introduce a "cybersecurity coordinator" to help the United States craft policies that will beat back hostile incursions into public and private databases and systems, but hasn't made his pick known yet.Saddled with enormous responsibilities, many experts fear that the so-called czar's power will be undercut by bureaucratic turf battles because the position is supposed to report to both the U.S. National Security Council and the National Economic Council.

But if the Administration's track record so far is any indication, Obama is likely to pick a pragmatic manager rather than a thought-leader for this position -- in other words, someone who won't butt heads with others because they think they know better.


More Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

Jack Thomas Tomarchio, former Deputy Under Secretary for Intelligence and Analysis Operations at the Department of Homeland Security, told me that Obama "is governing as a pragmatist" and is likely to pick someone in a similar vein. "There's going to be a lot of bureaucratic rice bowls overturned, so you're going to need someone to navigate that," he said. (As an early member of a a new bureaucracy himself, Tomarchio has first-hand experience navigating those overturned rice bowls.)

Tomarchio told me the choice will likely be "underwhelming... maybe some retread military guy."

So in other words, don't expect an expert from Silicon Valley or academia to fill those shoes. Whoever this person is, they're more likely to be conciliatory than commandeering; not only will he or she have to report to those two departments, but will have to play nicely with private sector utilities, local government agencies, security vendors and various branches of the military and intelligence community as well.

Mind you, this isn't part of the typical virus hype cycle. Tomarchio assured me the risk to national security is real and growing. "We're under consistent and pervasive attack around the clock, and it runs the gamut of nations, organized crime activities, terrorist groups, and what I'd call your run of the mill hackers," he said.

Public and private sector organizations are being consistently invaded by adversaries, and "a staggering number of countries are engaged in active cyber-collection against our government systems," Tomarchio said.

The Administration isn't standing still while awaiting the new czar. Tomarchio told me that he recently participated in a cyber-warfare exercise sponsored by the CIA, with around 150 participants from private, public and not-for-profit organizations. He said the exercise was "valuable to learn our strengths and weaknesses."

The so-called "after-action" report is still to come.

One question with which the cyber-czar will have to grapple is how much security the government can build in without invading the privacy of its citizens. Many security experts believe that identity management is the only way to protect systems efficiently, but Americans have little appetite for being tracked, even when the cookies are for their own good. That may end up being the messiest rice bowl of them all.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links