LARRY CLINTON'S OPENING STATEMENT: WORLD ECONOMIC FORUM 2024 ANNUAL MEETING ON CYBERSECURITY

The following is the opening statement of Larry Clinton of ISA at the World Economic Forum’s Annual Meeting on Cybersecurity in Geneva on November 12:


ARE REGULATORS THE NEW THREAT ACTORS? 


Good afternoon and welcome to today’s session. I’m Larry Clinton, President of the Internet Security Alliance, and I’m honored to lead today’s session on “Are Regulators the New Threat Actors?” 


To paraphrase Shakespeare, we come here not to bury the regulators but to praise their sincere efforts to enhance cybersecurity, but to also to recognize that many of their activities are hampering our security efforts and need to be significantly rethought and reformed. 


As the old saying goes, when you find yourself in a hole, the first thing to do is stop digging. 


The first question we need to ask is if the massive regulatory infrastructure built over the last two decades is working? 


The apparent answer is no, we have had cyber regulation for decades and the threat has only continued to get worse. Regulatory structures are not only wasteful but ineffective. In the US studies – including from the Federal Government Accounting Office – found that redundant cyber regulations waste between 40-70% of cybersecurity budgets. This means that the more cyber regulations we have the less cybersecurity we get.  


The empirical answer is also no. I cite perhaps the best, serious study of cyber regulation in existence; Douglass Hubbard’s book How to Measure Anything in Cybersecurity. Hubbard provides an exhaustive review of the literature and concludes there is no evidence that any of the regulatory models has ever been demonstrated to improve security.   


No cyber regulations should be permitted to remain in force unless they have been systematically assessed and found to be cost effective. 


If regulations are not cost effective, then need to be modified or sunsetted — just as the private sector would do routinely with any program that was not cost effective. 


But not only are cyber regulations not effective from a security perspective, they are actually harmful. Multiple studies – from industry and government – have demonstrated that the weed-like uncoordinated regulatory structures waste resources. 


We all know we don’t have adequate resources to fend off the increasingly well-financed attack community so we can’t afford to waste these resources. And let’s be clear the attackers didn’t do this to us, this is a government created problem. 


But it’s not just the waste, we are now seeing attackers actually using the regulations to make their attacks more painful and blackmail attack victims into complying with Ransomware demands by threatening disclosers to increase pressure on the victims to comply. 


In the US SEC regulations are actually being used to manipulate stocks. Attackers will lodge an attack and short the stock of the company they are attacking forcing disclose to trigger reductions in value of the stocks thus making a killing in the market while stealing valuable data. 


Some regulators are seeking to hold CISOs personally liable – threatening massive personal fines and even jail for attacks the CISO had no practical ability to prevent. This is driving security professionals out of the field. Gartner is predicting we will lose as much as 20% of our current CISOs in the next few years just from the pressures of the job. 


We are at the point where we need to realize that traditional regulation is a 20th century approach to a 21st century problem. We must find a better, modern way. 


This needs to begin with cost-benefit studies of proposed methods to enhance security. There are non-regulatory cost-effective methods to improve cybersecurity. . I offer you the Cyber Risk Oversight Handbooks created through a true partnership process including the US CISA, the German Federal Office of Information Security, the OAS in conjunction with the National Association of Corporate Directors, the European Conference of Director Associations, the Japanese Federation of Business, and others. 


Independent verification of these best practices from PWC and MIT in collaboration with the Forum has shown use of these handbooks generate better cyber risk management, closer alignment of security with business goals promoting a culture of security and up to an 80% reduction in negative cyber events. No regulation can make that claim. 


The traditional regulatory model is geared to stop corporate malfeasance. That is not the main problem in cybersecurity. The main problem is that the economics of the digital age are upside down. Attack methods are cheap and easy to acquire; they generate massive profits with a great business model.  


We on the defender side are largely in a reactive posture, defending an inherently vulnerable perimeter and getting virtually no help from law enforcement – we successfully prosecute less than 1% of cyber criminals. 


Government needs to focus less on adversary regulations and penalizing security practitioners and more on true collaboration providing incentives for security innovation. 

 

Select the link below for ISA’s Fixing American Cybersecurity, a cyber resource for Boards of Directors; available now from Amazon and everywhere fine books are sold.

Internet Security Alliance | Website
Twitter  Linkedin