Feds need to play bigger role in cybersecurity
[Commentary] I think about security risks a bit like I think about transportation. If you're driving your own car, there is a lot you can do to increase your safety. You don't have complete control -- another driver could slam into you -- but there are plenty of things you can do. But if you're on a plane, you're pretty much at the mercy of the airline and the various government agencies that regulate air travel. Sure, it's up to you to put on your seat belt and stow your objects during takeoff and landing, but other than that, there's not much you can do.
Airline safety is regulated by the Federal Aviation Administration, but Web and app security is pretty much up to the individual company you're doing business with. While I'm reluctant to propose federal regulation, I do think government should play some role in protecting consumers, given the risk and consequences of these breaches. The trick is to avoid government micromanagement of how companies protect their infrastructure while encouraging companies to improve their security. It's a tough balance because there will always be forces trying to get government to put the hammer down on companies with lax security, and there always will be forces arguing that the government should keep its hands off industry for fear that it can stifle innovation. The answer lies somewhere in between, where government holds industry accountable while at the same time allowing industry to use its own talents and resources to find solutions.
Feds need to play bigger role in cybersecurity