5 Ways Agencies Can Prepare for Cyberattacks

cjgphotography/Shutterstock.com

Agencies are under great pressure to protect personal data.

Ger Daly is Accenture’s managing director for Defense & Public Safety.

Governments face an increasingly complex security landscape, with new technology ushering in enormous benefits for citizens, as well as new threats. At the same time, agencies are under greater pressure to protect personal data, resulting in unprecedented investments in information security.

A recent U.S. federal budget proposal, which would go into effect in early 2017, increases cybersecurity spending by 35 percent. This decision is part of a broader White House-led initiative to modernize and protect IT across the public sector, known as the National Cybersecurity Action Plan. Announced in February, this plan has led to the establishment of a Commission on Enhancing National Cybersecurity and the appointment of a federal chief information security officer.

But how serious is the risk posed to the public sector by data breaches and other cyber threats?

According to estimates, cyberattacks cost the global economy $400 billion each year. Some industries have it worse than others: According to the Brookings Institution, one in four cyberattacks affect health care organizations.

» Get the best federal technology news and ideas delivered right to your inbox. Sign up here.

The public sector is another primary target, as evidenced by last year’s attack on the Office of Personnel Management, in which more than 21 million current, former and prospective federal employees’ employment records were hacked.

So how can public-sector organizations—large and smallmanage digital risks? Here are five key steps for gauging the cybersecurity “health” of an organization:

Undertake Risk Assessment

According to Accenture research, 43 percent of enterprise security professionals believe their company’s brand reputation is most susceptible to attack, while 37 percent feel the same about their customer support business functions.

But every organization is different, and modern threats can manifest in myriad ways.

To prepare for a cyberattack, government agencies should conduct a risk assessment to determine where they are most vulnerable and what the consequences of such an attack might be. By understanding both the worst and most likely scenarios, governments will be able to engineer defenses that address their unique vulnerabilities.

Open dialogue between security experts and business stakeholders is also crucial, to ensure that everyoneacross all levels of an agency or organizationunderstands how data is utilized and what safeguards exist to keep information secure.

Devise a Cybersecurity Strategy

Many organizations have crisis plans in place to help them respond to and mitigate the impact of cyberattacks. But as digital threats become more common and sophisticated, leaders must develop a more proactive approach to data security.

Prioritization is an important element of any security strategy. Once an agency has conducted a risk assessment, they can build systems that protect what’s most vulnerable and essential. Because breaches can happen at all levels of government, it’s also important for agencies to develop protocols that can be leveraged by federal, state and local officials.

Further adoption of the National Institute of Standards and Technology Cybersecurity Framework would help provide robust protection for public-sector organizations and citizens alike, while also reducing the administrative burden and uncertainty for smaller agencies.

Take an Intelligence-led, Analytics-based Approach

Effective cybersecurity can no longer rely on a passive “gates and guards” approach and using endpoint detection systems that can only identify known malicious activities. By employing advanced analytics systems that incorporate cyber threat identification and intelligence garnered from suspect behavior within networks, government agencies will be able to respond swiftly and proactively to digital threats.

Likewise, advanced analytics will empower public-sector organizations to effectively use and manage large volumes of data, rather than suffer from data overload. Such an approach will also make it easier to integrate intelligence-led cybersecurity with new and emerging technologies such as cloud, mobile and social media while protecting confidential data. In fact, half of enterprise security professionals say digital initiativesincluding analyticsare critical to data security.

Increase Stakeholder Collaboration

In the digital age, the role of the individual in cybersecurity has become more important. This is especially true considering the volume of data citizens generate on a daily basis on tablets, smartphones and wearable fitness or health-monitoring devices. Government employees, in particular, need to understand the risks and security protocols when using mobile devices or operating in the cloud.

A recent survey of more than 200 enterprise security professionals showed two-thirds had experienced data theft or corruption within their organization. Educating employees and citizens about cybersecurity risks will allow them to play their part in keeping sensitive data safe from threatsinternal and externalwhile building digital trust.

Cross-sector collaboration is also crucial. Governments should build upon existing relationships with peer organizations, academia and the private sector when developing security procedures and systemsparticularly in the context of cybersecurity R&D and intelligence gathering. As the majority of security infrastructure is owned and/or managed by private-sector companies, their involvement is essential.

Invest in Cybersecurity Talent

No cybersecurity initiative can succeed without the proper talent to back it up. Unfortunately, many public-sector organizations are finding themselves short on the skills and competencies required to stave off digital threats.

According to Accenture research, 42 percent of enterprise security professionals believe they have insufficient budget to recruit and train security talent, and 76 percent say they aren’t adequately equipped to conduct threat and vulnerability assessments.

To prepare for the next wave of digital threats, all public-sector leaders must allocate resources to build a strong cybersecurity team. The federal Cybersecurity National Action Plan has already taken steps to address the skills gap through strategic investments ($62 million in 2017) in cybersecurity education and training, but change must happen on an agency level. Those deterred by the idea of additional spending should consider the potential cost of a data breach.

In today’s data-driven world, a reactive approach to cybersecurity won’t cut it. By developing a robust, proactive cybersecurity strategy, government agencies will be better equipped to prepare for, prevent and resolve digital threats into the future.

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.