This is why the government keeps getting hacked
[Commentary] The Office of Personnel Managmenet breach exemplifies the cultural problem that besets the cybersecurity of the government and the private sector -- the failure to recognize that cybersecurity is a challenge that must be owned by the entire enterprise. Everyone -- CIO, CISO, CFO, COO, communications, human resources – must be part of plans and programs necessary for effective cybersecurity. It is a massive technology challenge that requires the best tools and talent. At the same time we are using the best available security tools, we must also address the culture issues that contribute to vulnerabilities or the technology cannot protect us. This culture reduces cybersecurity to “merely” a technical challenge.
No technologist can solve this problem -- everyone in an enterprise must own it. It is much harder to hold employees accountable when agencies invest so little time in training them. From inadequate annual refresher training to placing people in roles for which they have inadequate training, agencies are not providing their employees with they skills they need to do their parts. Given the potential harm that breaches can cause, more in-depth training, tailored to the employee’s role, is critical.
[Jeffrey Neal is the former personnel chief at the Department of Homeland Security and is now a senior vice president for ICF International]
This is why the government keeps getting hacked