Showing posts with label united states. Show all posts
Showing posts with label united states. Show all posts

Monday, April 12, 2010

Increased Espionage against US Defense Contractors

The Counterintelligence Directorate of the U.S. Defense Security Office recently released a report on espionage against the U.S. defense industry. The study identified four broad methods of information gathering including the use and misuse of technology:
  1. Direct Request - Email requests for information, webcard purchase requests, price quote requests, phone calls, or marketing surveys
  2. Suspicious Internet Activity - Confirmed intrusion, attempted intrusion, computer network attack, potential pre-attack, or spam
  3. Solicitation and Seeking Employment - Offering technical and business services..., resume submissions, or sales offers
  4. Foreign Visits and Targeting - Suspicious activity at a convention, unannounced visit..., solicitations to attend a convention, offers of paid travel to a seminar, targeting of travelers, questions beyond scope, or overt search and seizure
The alleged sources of attacks are world wide including:
  • "East Asia and the Pacific and Near East entities remaining the most prolific collectors of United States technology or information"; and,
  • Europe and Eurasia
The largest growth in cyber activity was from East Asia and the Pacific:
"Suspicious Internet activity with IP addresses originating in the East Asia and the Pacific region represented 79 percent of the regional cyber collection effort, a significant increase over last year’s 52 percent. These apparent cyber operations mainly targeted cleared defense contractor networks used for research and development documentation, especially those related to information systems technology."
The report noted an interesting trend between Asian and Near East activity and that of Europe and Eurasia [emphasis added]:
"Europe and Eurasia collectors do not need to use high-profile collection techniques because their covert collection methodologies are already efficient and effective as to render the more blatant, overt requests largely supplemental to other collection competencies. It is noteworthy that even though their overt collection efforts have declined, European and Eurasian cyber actors remain some of the most active targeters of United States technology."
The report contains in-depth analysis of the types of information targets and regional statistics and analysis of activity. The report forecasts increased cyber activity in the future:
"Government and commercial collection entities worldwide are highly likely to continue the use of cyber collection activities against United States government and its CDCs. Cyber intrusion offers a relatively low-risk, high-gain technique giving illicit collectors the opportunity to acquire sensitive and proprietary information stored on United States computer networks. Cyber targeting may also be utilized as a collection planning tool to identify targets of opportunity not readily apparent to traditional collectors. This cyber reconnaissance allows foreign elements to design targeting plans employing the full range of collection techniques on focused targets."

TARGETING U.S. TECHNOLOGIES: A TREND ANALYSIS OF REPORTING FROM DEFENSE INDUSTRY

Tuesday, April 06, 2010

Fine Line between Criminal Activity and National Security

NPR ran a lengthy report on cyber war centered around last month's congressional testimony by the Director of National Intelligence Dennis Blair citing cyber attacks as a top threat to U.S. security.

One important factor noted in the broadcast is the fine line between criminal activity and national security threats. The difference is not so much technique as motive:
"The difference between cybercrime, cyber-espionage, and cyberwar is a couple of keystrokes," says [Richard] Clarke [former Presidential cyber security adviser]. "The same technique that gets you in to steal money, patented blueprint information or chemical formulas is the same technique that a nation-state would use to get in and destroy things."

Cyber Insecurity: U.S. Struggles To Confront Threat

Sunday, February 07, 2010

US Faces "Significant" Threat from Cyber Espionage

John Brennan, Deputy National Security Adviser for Homeland Security and Counterterrorism, stated during a television interview that the United States faced a "serious and significant" threat from cyberspace:

"We're looking at these issues from the standpoint of espionage, from governments, from different individuals, whether they be hackers or terrorist organizations," Brennan said.

"National security is something that is at risk. That's why what we're trying to do is to ensure that our networks, our government networks, our private sector networks have the ability to withstand these attempts to hack in."


US faces 'serious' cyberspace threats: advisor

Friday, January 15, 2010

Attempted Cyberattack on Law Firm that Sued China

The U.S. law firm Gipson Hoffman & Pancione has received email with malicious code they belive originated from China. Gipson Hoffman & Pancione is the firm representing Solid Oak Software Inc., a maker of Internet filtering software that they alleged was stolen and used by Chinese companies to create the "Green Dam Youth Escort" filtering software required by the Chinese government. The lawsuit named various Chinese companies and the Chinese government.

After analyzing the malicious code, a company spokesperson said:
"We have every reason to believe they're coming out of China... We have solid indications. We can say the payloads of these Trojan e-mails were located within China and the ISP routing bears out the connections with China. But what we don't know is specifically who they were sent by, where they were sent from, and why they were sent."
The spokesperson also noted the timing of the attack in relation to Google's announcement to stop censoring Internet searches in China:
"It is difficult to believe that the timing is merely coincidental."

U.S. Law Firm That Sued China Reports Cyberattack

Thursday, December 17, 2009

U.S. Predator Drones Compromised

In a stunning admission, the U.S. military confirmed that Iraqi insurgents have intercepted video streams from Predator Drones [emphasis added]:
"Shiite fighters in Iraq used off-the-shelf software programs ... available for as little as $25.95 on the Internet — to regularly capture drone video feeds, the Wall Street Journal reported Thursday. The hacking was possible because the remotely flown planes have an unprotected communications link."

"...in December 2008, the military apprehended a Shiite militant in Iraq whose laptop contained files of intercepted drone video feeds, the Journal reported. In July, they found pirated feeds on other militant laptops, leading some officials to conclude that groups trained and funded by Iran were regularly intercepting feeds and sharing them with multiple extremist groups."
Even more incredulous is the admission that the system was not originally designed to encrypt transmissions:
"The military has known about the vulnerability for more than a decade, but assumed adversaries would not be able to exploit it."
This is a classic, textbook example of inadequate security design and risk assessments - the root causes of most security issues in both the public and private sector.

What should be more alarming is, if this vulnerability has been there for more than a decade, who else (with better resources) had access to the feeds and what other vulnerabilities exist in other systems that are not being addressed?

Pentagon: Insurgents intercepted drone spy videos

Wednesday, April 08, 2009

U.S. Electrical Grid Intrusions

The Wall Street Journal reheated the debate of infrastructure vulnerability with an article concerning intrusions into and mapping of the U.S. electrical grid. The report points to China and Russia as the source, but provides almost no details beyond the generalized comments of anonymous sources to substantiate the claims.

One interesting note is the lack of detection of the intrusions by the companies themselves:

"Many of the intrusions were detected not by the companies in charge of the infrastructure but by U.S. intelligence agencies, officials said. Intelligence officials worry about cyber attackers taking control of electrical facilities, a nuclear power plant or financial networks via the Internet.

"Authorities investigating the intrusions have found software tools left behind that could be used to destroy infrastructure components, the senior intelligence official said. He added, "If we go to war with them, they will try to turn them on."

Of course, the story is spawning many other reports and analysis including the suggestion that the power grid should be disconnected from the Internet:
"The onetime Counter Terrorism Czar, who famously criticized the Bush Administration for doing little to combat al Qaeda early in his first term before 9/11, chided the Obama Administration for not moving fast enough to decide upon the best defense strategy to counter cyber attacks on key infrastructure.

"One thing you can do is disconnect the power grid control system from the internet," Clarke said. "There's no reason for it to be connected."
This could be said of many critical systems. One such system that is rarely discussed is emergency communications including 911 systems that have slowly been connecting to the Internet despite security issues.

Electricity Grid in U.S. Penetrated By Spies
Disconnect electrical grid from Internet, former terror czar Clarke warns

Friday, March 13, 2009

U.S. Legal Issues on Cyber War

The Congressional Research Service has published a report on the legal and policy issues related to cyber warfare and defense in the United States. The paper summarizes the issues in terms of the three branches of the Federal government:
"Given that cyber threats originate from various sources, it is difficult to determine whether actions to prevent cyber attacks fit within the traditional scope of executive power to conduct war and foreign affairs. Nonetheless, under the Supreme Court jurisprudence, it appears that the President is not prevented from taking action in the cybersecurity arena, at least until Congress takes further action. Regardless, Congress has a continuing oversight and appropriations role. In addition, potential government responses could be limited by individuals’ constitutional rights or international laws of war."
One of the key problems with the Comprehensive National Cybersecurity Initiative (CNCI) is that originated in a classified Presidential Directive. This immediately causes conflict with the private sector on which the government is dependent:
"Given the secretive nature of the CNCI, one of the common concerns voiced by many security experts is the extent to which non-federal entities should have a role in understanding the threat to the nation’s telecommunications and cyber infrastructure and assist with providing advice, assistance, and coordination in preparation and response for ongoing and future intrusions and attacks."
The report provides background and discussion on the various roles and responsibilities of the three governmental branches and recommends the following Congressional actions to clarify and strengthen the legal basis for government action:
  • determine the most appropriate and effective organizational entity in which the nation’s principal cybersecurity prevention, response, and recovery responsibilities should reside;

  • require the senior U.S. government official in charge of all CNCI related activities be a Senate confirmable position to facilitate ongoing information exchange regarding Initiative plans and areas of progress and difficulty;

  • enact legislative language recognizing and defining the classified and unclassified aspects of the CNCI and the need for greater transparency and inclusiveness;

  • require the new Administration to develop and revise annually a classified and unclassified national cyber security strategy and intelligence community generated National Intelligence Estimate that provides Congress, the telecommunications industry, and the American public information related to the CNCI, the current and strategic cyber threats facing the nation, and programs being implemented to prepare for evolving technological risks;

  • define the privacy and civil liberty considerations that should accompany all aspects of the CNCI;

  • include legislative language in applicable authorizations bills to establish a programmatic foundation for CNCI related programs and suggest funding for current and future year’s activities; or

  • identify and codify relevant laws defining a national security related cyber offense against the United States, offensive versus defensive cyber activities, and the situations in which the Congress should be notified prior to the United States undertaking an offensive or counteroffensive cyber act.
The full report is available through the Washington Post:

Comprehensive National Cybersecurity Initiative: Legal Authorities and Policy Considerations

Thursday, March 05, 2009

California May Censor Google Earth

Following reports that terrorists in India and Israel were using Google Earth in planning attacks, California lawmaker Joel Anderson has introduced a bill (AB 255) in the California Assembly to force censorship of potential targets:
"(a) An operator of a commercial Internet Web site or online service that makes a virtual globe browser available to members of the public shall not provide aerial or satellite photographs or imagery of a building or facility in this state that is identified on the Internet Web site by the operator as a school or place of worship, or a government or medical building or facility, unless those photographs or images have been blurred.

"(b) An operator of a commercial Internet Web site or online service that makes a virtual globe browser available to members of the public shall not provide street view photographs or images of the buildings and facilities described in subdivision (a)."


ASSEMBLY BILL No. 255

Wednesday, February 25, 2009

A New Military Branch for Cyber Warfare?

IANewsletter has published an article (starting on page 14) looking at the need for a separate cyber branch of the U.S. military on par with the Army, Navy, Marines and Air Force.

The authors review the historical context of the existing branches and the unique nature of cyber warfare:
"...occasionally, a new technology is so significant that it creates a discontinuity in the conduct of war that necessitates creation of an entirely new military service. This situation occurred in the United States, resulting in the formation of the Air Force in 1947. The advent of air power fundamentally altered the conduct of warfighting and drove the transformation of the Army Air Corps into the United States Air Force.

"The revolution in cyberwarfare places today’s militaries at a similar cusp in history and necessitates the formation of a cyberwarfare branch of the military, on equal footing with the Army, Navy, and Air Force."
...
"Cyberwarfare is fundamentally different from traditional kinetic warfare. National boundaries in cyberspace are difficult, if not impossible, to define. Lawyers and pundits are still debating the
formal definition of an “act of war.” Asymmetries abound and defenders must block all possible avenues of cyber attack. An attacker need only exploit a single vulnerability to be successful."
The article then discusses why it would be better to have a separate military branch rather than trying to integrate cyber capabilities into each existing branch:
"The cultures of today’s military services are fundamentally incompatible with the culture required to conduct cyberwarfare. This assertion in no way denigrates either culture. Today’s militaries excel at their respective missions of fighting and winning in ground, sea, and air conflict; however, the core skills each institution values are intrinsically different from those skills required to engage in cyberwarfare. Cyber requires a deep understanding of software, hardware, operating systems, and networks at both the technical and policy levels."

Army, Navy, Air Force, and Cyber—Is it Time for a Cyberwarfare Branch of Military?

Friday, February 13, 2009

DNI: Cyber Security a Top U.S. National Security Issue

The U.S. Director of National Intelligence, Dennis Blair, has provided his annual threat assessment to Congress. His Statement for the Record has been published and cyber security issues are defined as a major threat to the United States. Mr. Blair's statement includes the following summary of the threat (emphasis has been added):

"A growing array of state and non-state adversaries are increasingly targeting—for exploitation and potentially disruption or destruction—our information infrastructure, including the Internet, telecommunications networks, computer systems, and embedded processors and controllers in critical industries. Over the past year, cyber exploitation activity has grown more sophisticated, more targeted, and more serious. The Intelligence Community expects these trends to continue in the coming year.

"We assess that a number of nations, including Russia and China, have the technical capabilities to target and disrupt elements of the US information infrastructure and for intelligence collection. Nation states and criminals target our government and private sector information networks to gain competitive advantage in the commercial sector. Terrorist groups, including al-Qa’ida, HAMAS, and Hizballah, have expressed the desire to use cyber means to target the United States. Criminal elements continue to show growing sophistication in technical capability and targeting and today operate a pervasive, mature on-line service economy in illicit cyber capabilities and services available to anyone willing to pay. Each of these actors has different levels of skill and different intentions; therefore, we must develop flexible capabilities to counter each. We must take proactive measures to detect and prevent intrusions from whatever source, as they happen, and before they can do significant damage.

"We expect disruptive cyber activities to be the norm in future political or military conflicts. The Distributed Denial of Service (DDoS) attacks and Web defacements that targeted Georgia in 2008 and Estonia in 2007 disrupted government, media, and banking Web sites. DDoS attacks and Web defacements targeted Georgian government Web sites, including that of Georgian President Saakishvili, intermittently disrupting online access to the official Georgian perspective of the conflict and some Georgian Government functions but did not affect military action. Such attacks have been a common outlet for hackers during political disputes over the past decade, including Israel’s military conflicts with Hizballah and HAMAS in 2006 and 2008, the aftermath of the terrorist attacks in Mumbai last year, the publication of cartoons caricaturing the Prophet Mohammed in 2005, and the Chinese downing of a US Navy aircraft in 2001."
The report also discusses online activity by organized crime.

Annual Threat Assessment of the Intelligence Community for the Senate Select Committee on Intelligence

Chinese Cyber Attacks Back in the News

Attacks from China have resurfaces in the news although its difficult to determine from the coverage if these are new attacks. In a recent interview, Rep. Bennie Thompson, Chairman of the House Homeland Security Committee, provided a few details concerning attack targets:

"Currency trading is among the financial networks targeted by hackers, Thompson said. An attack would be particularly damaging in light of the financial system’s troubled state, he said.

"He said electric utilities’ networks also have several points of weakness.

“We were provided alarming data on the vulnerability of our electrical grid in this country,” he said."

China strongly denies the allegations:

“Allegations that the Chinese government is behind cyber attacks against the U.S. computer networks are totally unwarranted and misleading for the America public,” Wang [Baodong, a spokesman for the Chinese Embassy in the U.S.] said in an e-mailed statement.

Wang said the Chinese government is “cracking down” on computer hacking and other cyber crimes.


Chinese Hackers Attack U.S. Computers, Thompson Says

Thursday, February 05, 2009

Convergence of Electronic and Network Warfare

The Fort Leavenworth Lamp discusses the convergence of traditional electronic warfare (EW) with computer network operations (CNO):
"In the operational environment, the lines between CNO and EW are blurred," [Lt. Col. John] Bircher said. "We can use EW to disable our enemies' cellular phone device or we can use CNO to deny the device's access to its network."

"Do we use CNO or EW to deny our adversary, and does it matter to the tactical commander?" Bircher continued, "and in our conceptual research we found that it didn't matter. What's important is controlling the data, the bandwidth and the electromagnetic spectrum."

Electronic Warfare Proponent: Changes by adversaries, advances in technology drive EW's operational importance

Wednesday, February 04, 2009

Cyber Security Is a National Security Problem for the United States

Vice Adm. Carl Mauney, deputy commander for the U.S. Strategic Command told the 2009 Network Centric Warfare conference that "cyber security is a national security problem".

During his presentation he told the audience some of the problems the DoD is facing and that cyber defense required better coordination of effort:
"Also complicating cyber sleuths’ lives is the world’s billions of eye-blink-fast interconnected computers. But keeping up is vital. “Cyberspace has become a warfighting domain like land, sea, air, space,” Mauney told attendees. “And in light of growingly astute cyber enemies, it’s in our interest to maintain freedom of action,” he said.

"However, he cautioned, “It can’t be done in isolation.” There’s a “compelling need to integrate all elements of cyberspace operation and to [move] at net speed.” This is because the DOD on a daily basis faces millions of denial-of-service attacks, hacking, malware, bot-nets, viruses and other ruinous intrusions, some of which are associated with nations and nation-states, he said."
More importantly, Admiral Mauney stressed the need for individual accountability:
"What is needed is “a focus on accountability, from leadership to the user level. Our mindset needs to reflect the way we treat other military systems,” he said. “We don’t accept substandard performance in maritime, air and ground ops — and this is no different.” [emphasis added]

Hear Hear!


Greater cooperation needed to defeat cyber enemies

Friday, January 23, 2009

Obama Adminstration Releases National Security Agenda Including Cyber Security

The new Obama Administration has posted their strategy for national security on the White House website. The document specifies a number of agenda items including terrorism, nuclear weapons and... information security.

The agenda is broad and encompasses many areas of information security that historically have been neglected, drowned in red tape and infighting or handed over to technical PhDs that can't see beyond the length of an encryption key to develop "solutions" that can't be implemented.

It remains to be seen if the new Administration can implement real change. However, if even a few of these initiatives were properly implemented it would be a major step forward.

Here is the full text of the cyber security section:

"Protect Our Information Networks

"Barack Obama and Joe Biden -- working with private industry, the research community and our citizens -- will lead an effort to build a trustworthy and accountable cyber infrastructure that is resilient, protects America's competitive advantage, and advances our national and homeland security. They will:

  • Strengthen Federal Leadership on Cyber Security: Declare the cyber infrastructure a strategic asset and establish the position of national cyber advisor who will report directly to the president and will be responsible for coordinating federal agency efforts and development of national cyber policy.

  • Initiate a Safe Computing R&D Effort and Harden our Nation's Cyber Infrastructure: Support an initiative to develop next-generation secure computers and networking for national security applications. Work with industry and academia to develop and deploy a new generation of secure hardware and software for our critical cyber infrastructure.

  • Protect the IT Infrastructure That Keeps America's Economy Safe: Work with the private sector to establish tough new standards for cyber security and physical resilience.

  • Prevent Corporate Cyber-Espionage: Work with industry to develop the systems necessary to protect our nation's trade secrets and our research and development. Innovations in software, engineering, pharmaceuticals and other fields are being stolen online from U.S. businesses at an alarming rate.

  • Develop a Cyber Crime Strategy to Minimize the Opportunities for Criminal Profit: Shut down the mechanisms used to transmit criminal profits by shutting down untraceable Internet payment schemes. Initiate a grant and training program to provide federal, state, and local law enforcement agencies the tools they need to detect and prosecute cyber crime.

  • Mandate Standards for Securing Personal Data and Require Companies to Disclose Personal Information Data Breaches: Partner with industry and our citizens to secure personal data stored on government and private systems. Institute a common standard for securing such data across industries and protect the rights of individuals in the information age."


THE AGENDA • HOMELAND SECURITY

Information Security Makes GAO High Risk Report for the 12th Year

The U.S. Government Accountability Office (GAO) has updated its list of governmental projects that are at risk "due to their greater vulnerabilities to fraud, waste, abuse, and mismanagement. GAO also identifies high-risk areas needing broad-based transformation to address major economy, efficiency, or effectiveness challenges."

Information security continues to make the list - for the 12th year. In the section titled: "Protecting the Federal Government’s Information Systems and the Nation’s Critical Infrastructures", the report makes note that the Department of Homeland Security (DHS) has made some progress but still falls short:
"Federal information security has been on GAO’s list of high-risk areas since 1997; in 2003, GAO expanded this high-risk area to include cyber CIP [Critical Infrastructure Protection]. The continued risks to information systems include escalating and emerging threats; the ease of obtaining and using hacking tools; the steady advance in the sophistication of attack technology; and the emergence of new and more destructive attacks."
Specifically, the report refers to numerous detailed past GAO reports and summarizes several areas requiring attention:
"Since 2006, GAO has made numerous recommendations in the following key areas:
  • bolstering cyber analysis and warning capabilities.
  • reducing organizational inefficiencies.
  • completing actions identified during cyber exercises.
  • developing sector-specific plans that fully address all cyber-related criteria.
  • improving cyber security of infrastructure control systems.
  • strengthening DHS’s ability to help recover from Internet disruptions.
"Until these and other key cyber security areas are effectively addressed, the nation’s cyber critical infrastructure is at risk of increasing threats posed by terrorists, nation-states, and others."
HIGH-RISK SERIES: An Update

Monday, January 19, 2009

A Look at the Future of U.S. Cyberwar

Aviation week takes a look at the future (and convergence) of cyber and other electronic warfare. Some of the more notable quotes from the article include:
"In a few years, the U.S. Army, Navy and Marine Corps expect to be delivering airborne electronic fires and cyber-attacks for ground troops with a fusion of radio battalions, EA-6B Prowlers, EA-18G Growlers and a range of UAVs."

"...As cyber- and electronic attack technologies emerge, it is becoming harder to distinguish between cyberwarfare, directed energy and electronic attack, intelligence gathering and information operations. Rationalization of all these elements also is complicated by shrinking manpower and funding."

"...However, researchers are worried that pieces of the digital puzzle are still missing - in particular, projection of new threats that foes may throw at the U.S."

Cyber-Attack Operations Near

Monday, January 12, 2009

NATO and US Army Systems Targeted by Palistinian Supports

Supports of Palestine have defaced several US Army, NATO and UN websites in the continuing escalation of cyber attacks related to the current situation in the Gaza Strip:
"Four websites belonging to the United States Army's Military District of Washington... have been defaced by a Turkish hacker affiliated with a group called “Peace Crew.” The attacker, who identified himself as Agd_Scorp, has posted threatening messages in English. “Stop attacks u Israel and USA! You cursed nations! One day Muslims will clean the world from you!,” the pages displayed.
"The website of the Joint Force Headquarters, National Capital Region... of the Northern Command has also been defaced by Agd_Scorp, and the same message has been posted along with the image of a Palestinian throwing a rock at a tank. In addition, the same attacker also hacked the websites of the NATO Parliamentary Assembly... and UNICEF Italy, in order to express his support for Palestine."

Palestinian Supporters Hack NATO and U.S. Army Sites

Friday, December 19, 2008

U.S. Unprepared for Cyber Attacks

Reuters reported on the results of a two-day "cyber war game" and concluded that the U.S. still is not prepared for a significant attack.
"Billions of dollars must be spent by both government and industry to improve security, said U.S. Rep. Dutch Ruppersberger of Maryland, the Democratic chairman of the intelligence subcommittee on technical intelligence."

This is unlikely without serious legislation and government regulation (see Commentary: U.S. CEOs to Assist in Critical Infrastructure Protection? - Not Likely).

The article goes on to quote U.S. Homeland Security Secretary Michael Chertoff:
"International law and military doctrines need to be updated to deal with computer attacks, Chertoff said.

"We know that if someone shoots missiles at us, they're going to get a certain kind of response. What happens if it comes over the Internet?," he said."


U.S. not ready for cyber attack

Wednesday, December 17, 2008

U.S. Nuclear Regulatory Commission Issues New Cyber Security Rules

The U.S. Nuclear Regulatory Commission (NRC) issued a press release concerning new security requirements for nuclear power plants. The release had one line referring to increased cyber security. No other details were provided:
"Additionally, there are new sections requiring a comprehensive cyber security program at nuclear power plants..."

NRC APPROVES FINAL RULE EXPANDING SECURITY REQUIREMENTS FOR NUCLEAR POWER PLANTS

Monday, December 15, 2008

Commentary: U.S. CEOs to Assist in Critical Infrastructure Protection? - Not Likely

Coverage and analysis of the report "Securing Cyberspace for the 44th Presidency" released by the Center for Strategic and International Studies continues.




A recent article from NetworkWorld discusses the recommendation to create a C-level panel of advisers called The President’s Committee for Secure Cyberspace. This panel would represent four key industries: Energy, finance, information technology/communications and government.
"The four industries were chosen for the committee because they “form the backbone of cyberspace. … Keep these sectors running and cyberspace will continue to deliver services in a crisis. Bring them down, and all other sectors will be damaged.”

There will be no problem getting CEOs to sit on a highly visible presidential committee where they can be seen to be doing something for little or no cost. However, expecting for-profit corporations to voluntarily make costly security changes and investments, especially during an economic down-turn, is wishful thinking at best. It will never happen. Remember, these are the same CEOs that require extensive ROIs for the most mundane security investment.

Therefore, the report also recommends new regulatory powers to force security changes:
"The report also seeks new regulations with the teeth to enforce standards that would establish a more secure infrastructure."

The article discusses several possible forms these regulations could take. Unfortunately, if past behavior provides any insight of future behavior, these regulations will be passed with little forethought or, if there is open discussion and debate, will be significantly weakened via lobbying when corporations realize the cost of compliance.

Top execs would roll up sleeves to fight cyber war, according to think tank study