Critical infrastructure security tech needs to be as good as our smartphones, top NSC cyber official says
The top cyber official at the National Security Council said Tuesday that heβs dismayed by the lag in security technology embedded in critical infrastructure, saying it pales in comparison to the tech in modern smartphones.
βI worry a lot about critical infrastructure cybersecurity,β Alexei Bulazel said at the Billington Cybersecurity Summit. βI also think about the technology thatβs deployed in critical infrastructure contexts. This is not the best-in-class software or hardware.β
Bulazel mentioned the energy sector in particular, given the potential for hackers to turn off the power in the United States. Itβs a sector that relies in large measure on supervisory control and data acquisition (SCADA) systems to monitor and control industrial processes.
βI think about the phones in our pockets β Android, iPhone, doesnβt matter β really amazing feats of engineering,β he said. βImagine if our critical infrastructure, if the SCADA system that ran the power or the water or whatever, was as secure as the phone in your pocket. I think a lot of these threats are mitigated; only the absolute apex predator, top-tier actors can get in.β
As a βWhite House policymaker,β Bulazel said, many of the questions he deals with go away if the technical mark is raised in critical infrastructure. Itβs one of the reasons the Trump administration β despite frequently discussing the need to go on offense in cyberspace β is focused on defensive strategies like secure-by-design, he said.
βWe are unapologetically unafraid to do offensive cyber,β he said. βItβs an important tool in the toolbox. Itβs not the only tool.β
The Trump administration is trying to shift away from βvictimsβ and more to βvillains,β Bulazel said. His comments echoed earlier remarks Tuesday from National Cyber Director Sean Cairncross about shifting the cyber risk burden to adversaries.
Itβs important to deter hackers, who arenβt like floods or lightning strikes in that they are intentional and deliberate, he said: βThis is because a motivated bad actor is trying to give you a bad day.β
The post Critical infrastructure security tech needs to be as good as our smartphones, top NSC cyber official says appeared first on CyberScoop.