There was an interesting article in Wired.com, the magazine, recently that put a new twist on an old topic: What’s the best way to make sure the internet, and all of the information that travels on it every day, is safe? How do you really make cybersecurity, secure? After all, the safer the information, the more secure people will feel, and the use of the web, for everything from e-commerce to portable electronic healthcare records, will grow. The flip-side is just as true: the more hacks, hackers and data-breaches, the slower the pace of progress. The good will be harder to come by if the bad is hard to avoid.
Peter W. Singer, who wrote the article, entitled, “How to Save the Net: A CDC for Cybercrime,” which was posted on 08.19.14, 6:30 a.m., proposes an interesting idea.
The CDC, otherwise known as the Centers for Disease Control, is much in the news recently. Chances are, if you’ve seen news stories about the Ebola outbreak in West Africa, or the MERS outbreak earlier this year, the CDC has come up in more than just passing. It’s the clearinghouse for health related information, combating communicable diseases, the world over. There was just an article, by Betsy McKay, Nicholas Bariyo, and Drew Hinshaw, that appeared in the August 23-24, 2014 Weekend Edition of the Wall Street Journal in the Review Section, which talks about the invaluable help the CDC gave to another country that used to be at risk of virulent Ebola outbreaks. Uganda used to send blood samples to the CDC’s facilities in Atlanta, to be screened for Ebola. Now, thanks to technology and training the CDC provided, Ugandans do the same for themselves, in country, which lets them detect outbreaks of the deadly virus sooner, respond to them quicker, and stop them before they do large scale damage.
A central clearinghouse for ideas, both proven and proposed, to safeguard digital information seems like a good idea. Having a one size fits all approach, in which the government entity is the one upon whom everyone fighting the problem relies, may not be. That’s not really even the job the CDC is doing with Ebola.
Look at how the Federal Trade Commission is policing cybersecurity: the whole point of the its Reasonable Precautions cybersecurity standard, and its enforcement, and codification, on a case by case basis, is that “Reasonable Precautions” become reasonable, or not, based on the particular facts of a given situation. What might be the right protection for digital information exchanged between wholesale distributors and retailers, might not be sufficient to protect information between retailers and consumers, and that in turn might not be enough to safeguard patients’ healthcare histories when they are exchanged among medical providers. What might be a commercially reasonable effort to safeguard information in one industry, might not be in another.
The FTC encourages individual companies, and the industries in which they compete, to voluntarily join together to ensure data security. By making the terms Industry Standard Practices and Commercially Reasonable Efforts mean something substantive, companies can protect themselves against FTC enforcement actions for lax data security, as we’ve previously noted. Look no further than the April 7, 2014 decision of U.S.D.J. Esther Salas, in The Federal Trade Commission, Plaintiff, v. Wyndham Worldwide Corp., et al., Defendants, Civil Action No. 13-1887 (ES), United States District Court, D. New Jersey, to see why. If a company can’t figure out what the FTC wants it to do to protect its customers’ data, then it should create, and live by, Industry Standard Practices which will become Commercially Reasonable Efforts if all the major companies in the industry implement them. Many companies already say they do this anyway, right in their privacy policies. Instead of meaningless legal verbiage, make the terms mean something concrete; show they can work, and the FTC will have little to complain about, even if those efforts occasionally fail. Some of the most vulnerable industries, including retail, are banding together to do just that.
The Retail Industries Leaders Association, or RILA, as we previously noted, formed a voluntary clearinghouse, known as the Retail Cyber Intelligence Sharing Center, or R-CISC, to develop and share industry leading practices in cybersecurity, by communicating amongst themselves information they learn regarding threats and defenses. The reported backers of the initiative have put in a lot of effort: they’ve conferred with cybersecurity experts and involved interested government agencies. They also have a lot at stake: credit cards and financial information are common targets; just ask the RILA members.
One main benefit of a CDC for the wired world, according to Peter W. Singer, is the trust and confidence it will bring to all those who rely on it. By bringing the best and brightest together under one centralized government-funded roof, it would allow users to know that independent experts, with their best interests in mind, were on the job, fighting off the bad guys. That’s a good thing; but is that the only way to achieve it?
What if the businesses which hold their customers’ information on line were held accountable for not doing enough to protect that data? What if they faced the loss of business, and profits, as well as a government enforcement action, if they didn’t do enough? What lengths would they go to in order to keep their customers’ trust?
If you look at some quotes in the RILA press release, from the people involved in forming the R-CISC, you’ll see that trust is a recurring theme there, too:
“We are highly focused on protecting our customers and maintaining their trust. That’s why we have joined the R-CISC and are committed to sharing best practices and information with our peers and other stakeholders in order to strengthen our collective defenses against potential threats,” said Greg Wasson, President and CEO of Walgreen Company and vice chairman of RILA.
“The retail industry is already going to great lengths to minimize risk and stay ahead of cyber criminals. The reality is, cyber-criminals work non-stop and are becoming increasingly sophisticated in their methods of attack and by sharing information and leading practices and working together, the industry will be better positioned to combat these criminals,” states Ken Athanasiou, Global Information Security Director, American Eagle Outfitters, Inc.
“Our top priority is protecting our customers and maintaining the trust they place in us every time they make a purchase,” said Warren Steytler, vice president of information security at Lowe’s Companies, Inc. “We are confident that by sharing with our peers and industry stakeholders through the R-CISC, our industry will collectively strengthen its ability to protect critical customer information.”
So, which approach is better? The government funding and operating a centralized research facility dedicated to cybersecurity, or the government telling individual companies to adequately protect their customers’ sensitive private digital information? The first focuses on the recommendations: do what the cyber-CDC recommends and, even if something bad happens, at least it’s not your fault; you did what you were told. The second cares much more about the end results than the specifics of how you get there. Protect your customers’ information and, if you don’t, you better have a good reason why what you did was good enough. No one knows the answer for certain; only time will tell.
Go raibh maith agat.