Government Hiring Practices Hamper Cybersecurity Efforts - InformationWeek
Government // Cybersecurity
12:45 PM
Moving UEBA Beyond the Ground Floor
Sep 20, 2017
This webinar will provide the details you need about UEBA so you can make the decisions on how bes ...Read More>>

Government Hiring Practices Hamper Cybersecurity Efforts

Federal agencies find it difficult to hire unconventional but well-qualified talent to battle cyberattacks, experts say.

by former NSA contractor Edward Snowden is the harm done to agencies' ability to hire "non-standard" people, who may not have college degrees but who have superior computer skills.

And, of course, there's the pay issue. David Bray, CIO of the Federal Communications Commission, said that when he's trying to recruit someone in IT, he tells them, "We can't pay what the private sector does," but that they will have a compelling mission they can find fulfilling.

Bray said his agency is using its ambassadors program, which brings in contractors from outside Washington, D.C., for a maximum of 120 days, to get new perspectives and fresh ideas. He suggested that perhaps the government could have a "reserve corps" of cybersecurity professionals, former ambassadors who have returned to the private sector, on call for cyber emergencies.

Robert Childs, former chancellor of the National Defense University's Information Resources Management College, said that Singapore could be a model for US practices. Children "learn cyber hygiene in elementary schools," he said. Here, though, "children, Millennials, don't care about cyber... the young people have the skills," but not the knowledge of sound policy and governance.

Bucci added that just getting employees to follow the cybersecurity policies already on the books would help -- and that has to include the bosses.

"If the boss isn't doing it, no one else will," he said.

Wilshusen said many federal agency leaders are starting to understand the importance of recruiting better talent. "The incidents reported to US-CERT have more than doubled in the past four years." But it's going to take more than just agency leaders recognizing the problem.

Childs pointed to previous cyberattacks, including when attackers shut down much of Estonia's electronic infrastructure in 2007 and another on the Saudi national oil company Aramco in 2012, as acts of cyber warfare. The war between Russia and Georgia in 2008 was the first demonstration of "cyber (attacks) combined with kinetic attacks," he said.

Bucci said the US military comes closest to understanding and preparing for these kinds of orchestrated attacks. "But in a [military] exercise, add the cyber component and the exercise comes crashing to a halt within a couple of hours," he said. The leaders of the exercise will usually insist on shutting down the cyber component so they can continue, even though they won't be able to do that on a real battlefield, he said.

NIST's cyber-security framework gives critical-infrastructure operators a new tool to assess readiness. But will operators put this voluntary framework to work? Read the Protecting Critical Infrastructure issue of InformationWeek Government today.

Washington-based Patience Wait contributes articles about government IT to InformationWeek. View Full Bio

2 of 2
Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Drew Conry-Murray
Drew Conry-Murray,
User Rank: Ninja
5/21/2014 | 2:56:57 PM
Re: Tough Job
I'd say Sillicon Valley and Wall Street have pretty good front row seats. But I agree that if you want to be part of a team that gets to kick down doors or fight terrorists and drug lords, that's not an opportunity you'll get in the private sector.
User Rank: Author
5/21/2014 | 1:54:08 PM
Re: Tough Job
On the other hand, where else is someone with the right skills likely to get the kind of front row seat and training the government offers -- it's a little like getting to fly an f-35 Joint Strike Fighter. Can't find those kinds of jobs in the private sector.  But it does take someone willling to give it all for his/her country.
User Rank: Ninja
5/21/2014 | 1:30:23 PM
Re: Tough Job
Cyber and kinetic attacks are going to be a huge issue for defense in the future. I am sure that the US government has a handle on the offensive side of these types of vectors.

But I question whether or not we are properly prepared to defend these sort of attacks on a large scale. I hope that we are. 
Drew Conry-Murray
Drew Conry-Murray,
User Rank: Ninja
5/21/2014 | 10:50:31 AM
Tough Job
I don't envy government recruiters. They've got a difficult needle to thread on hiring for cybersecurity, especially post-Snowden.
How Enterprises Are Attacking the IT Security Enterprise
How Enterprises Are Attacking the IT Security Enterprise
To learn more about what organizations are doing to tackle attacks and threats we surveyed a group of 300 IT and infosec professionals to find out what their biggest IT security challenges are and what they're doing to defend against today's threats. Download the report to see what they're saying.
Register for InformationWeek Newsletters
White Papers
Current Issue
IT Strategies to Conquer the Cloud
Chances are your organization is adopting cloud computing in one way or another -- or in multiple ways. Understanding the skills you need and how cloud affects IT operations and networking will help you adapt.
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Flash Poll