In October of 2022, the US Cybersecurity and Infrastructure Security Agency (CISA) released a document titled “CPG - Cross Sector Cybersecurity Performance Goals” that lays out some guidelines for improving the cybersecurity posture and outlook of organizations. This document is intended to supplement the NIST Cybersecurity Framework created several years ago.
The CPG document discusses how many organizations, even today, still need to adopt fundamental cybersecurity protections. It also points out how small and medium-sized organizations are often “left behind” when implementing cybersecurity practices and investments. There is a “lack of consistent standards and cyber maturity across CI (Critical Infrastructure) sectors.”
I applaud efforts to bring such matters to our attention, no matter how often we repeat the same story. Parents and teachers know that repetition is the key to getting things to change and improve.
However, we also know that there are more effective and efficient ways to get things to change than simple repetition. It also requires simplifying difficult things, which is why this document is so important. From our perspective at Arctic Security, achieving baseline security should not be complicated.
Reading through this CPG list, I can see how Arctic EWS would help an organization to tackle a few of the baseline capabilities: Asset inventory (2.3), Mitigating known vulnerabilities (5.1), No exploitable services on the Internet (5.4), Third-Party Validation of Cybersecurity Control Effectiveness (5.6). It can also help you to make the case to your manager on why you should dedicate time to implementing all the other CPGs since we can tell you what kinds of problems are regularly visible in your company.
The problem I see is that this document states that everything is voluntary. We know how well voluntary requirements work in the real world. I’m not saying it is always a failure, but we can point to many instances where voluntary actions lead to success. It is woefully inefficient in a world where cybersecurity issues are constantly growing.
Ok, back to teaching and parenting for a moment. There are ways to get people to do things beyond voluntary adoption. Let’s start with the one everybody hates, penalizing people and organizations for non-compliance. It works well in the military, civilian world, and at home. However, it also leads to rebellion, anger, and a populace that is constantly trying to figure out ways to game the system and put an end to the man cracking the whip. In other words, it is not always the best solution.
The other method is through incentives, a reward system. We reward good behavior. Heck, people pay for points and fame on video games with no value other than the proverbial “atta boy pat on the back. Humans are easy sometimes.
Now, I am not saying the brownie points system is the way to get organizations to buck up and improve their cybersecurity posture. Still, it is possible to create incentive systems to get them to fall in line. Perhaps tax incentives for organizations that can show evidence of compliance? Tax planning is an industry in itself, and I can already imagine the hoops that the CFO would have the rest of the organization jump through to achieve 1% less tax at the end of the year. The best part is that tax planning is just as critical for small businesses as it is for large ones.
Finally, this brings me to the notion of “evidence.” To prevent people and organizations from gaming the system (at least not systematically), we need to consider what criteria can serve as conclusive evidence. Some of this can be determined by adherence to today's limited standards and are listed in the CPG document, but more is needed.
We also need to collect data from tools that track information, such as the existence of vulnerable systems and the ability of organizations to react to known attack vectors. In other words, we need to know how weak and resistant an organization is to digital diseases.
Okay, again, I want to applaud CISA for their efforts here. Let’s kick it up a notch and do better.