Slashdot Mirror


Report: Federal Workers, Contractors Behind Half of Government Cyber Breaches

schwit1 writes Federal employees and contractors are unwittingly undermining a $10 billion-per-year effort to protect sensitive government data from cyberattacks, according to a published report. The AP says that workers in more than a dozen agencies, from the Defense and Education departments to the National Weather Service, are responsible for at least half of the federal cyberincidents reported each year since 2010, according to an analysis of records.

61 comments

  1. Thank you... by Anonymous Coward · · Score: 0

    ...captain obvious!

  2. turn off autoplay by Anonymous Coward · · Score: 3, Informative

    If you don't want to watch 4 unrelated videos at once, turn off autoplay before visiting the sites in the summary.

    1. Re:turn off autoplay by ShanghaiBill · · Score: 4, Informative

      If you don't want to watch 4 unrelated videos at once, turn off autoplay before visiting the sites in the summary.

      Also, you don't need to click both links, since they are the exact same story, word for word. One is the AP report, the other is the Fox News verbatim repost of the AP report.

  3. About right by kilfarsnar · · Score: 4, Interesting

    The statistic I have always heard is that 60% of intrusions are internal. So 50% of breaches coming from employees sounds about right. It's a lot easier to steal stuff if you have a key. And as we have learned again over the past 6 years or so, the best way to rob a bank is to own one.

    --
    "What the American public doesn't know is what makes them the American public." -Ray Zalinsky (Tommy Boy)
    1. Re:About right by khasim · · Score: 3, Interesting

      It doesn't even have to be that intentional. From TFA:

      They have clicked links in bogus phishing emails, opened malware-laden websites and been tricked by scammers into sharing information.

      One was redirected to a hostile site after connecting to a video of tennis star Serena Williams.

      People are usually the weakest link in a security system.

      And it does not sound like that security system is very well designed in the first place.

    2. Re:About right by TWX · · Score: 2

      Plus it's getting harder to avoid those kind of masquerading link attacks while still enjoying the cross-site linking capabilities that the web was designed for. I attempt to keep Javascript, Flash, and other things turned off, but it's getting harder and harder to look at web content without those things.

      --
      Do not look into laser with remaining eye.
  4. is this really news? by Anonymous Coward · · Score: 0

    I believe that in almost all sectors, users are the primary entree into the protected network, either via phishing or other social engineering. You could probably replace the word Government in the phrase "government cyber breeches" with healthcare, financial services, social networking, retail, non-profit, etc.

    1. Re:is this really news? by plover · · Score: 1

      I believe that in almost all sectors, users are the primary entree into the protected network, either via phishing or other social engineering. You could probably replace the word Government in the phrase "government cyber breeches" with healthcare, financial services, social networking, retail, non-profit, etc.

      Social engineering will always work as long as humans have access to the data and systems. There are steps sys admins can take that can limit or mitigate the damage, but the bottom line is that if people need to access the data, then other people will be able to exploit them.

      Heavy handed security often isn't the panacea it's advertised as, because ordinary users will find ways to deal with it. Do you make them change passwords daily? They'll resort to keeping a file of daily passwords. Do you make them fill out a big form to request access to a system? They'll request access to a dozen, in hopes that they will stumble across the correct one, and so won't have to repeat the ordeal; out of the dozen departments they request access from, some may approve the inappropriate request. Or some department head will proclaim "grant everything to my department, because I don't want to waste our time with all these expensive little requests." All of these can be exploited even in the best of situations.

      --
      John
  5. It's a problem, but not just the feds: by Radical+Moderate · · Score: 3, Insightful

    From TFA: "Since 2006, there have been more than 87 million sensitive or private records exposed by breaches of federal networks, ..... By comparison, retail businesses lost 255 million records during that time, financial and insurance services lost 212 million and educational institutions lost 13 million."

    My bank is constantly sending out new credit cards because businesses (hey there Home Depot!) won't implement basic security measures to prevent data theft. Data security is a serious issue that needs to be addressed, but "Blame the incompetent gubmint!!!" isn't where we should start.

    --
    Never let a lack of data get in the way of a good rant.
    1. Re:It's a problem, but not just the feds: by mysidia · · Score: 3, Interesting

      Businesses (hey there Home Depot!) won't implement basic security measures to prevent data theft. Data security is a serious issue that needs to be addressed

      Yes... PCI was a start, but we need new regulations; first of all, Businesses should be liable for costs to consumers resulting from breaches. There should also be a statutory liability for not being able to prove to within certain standards to consumers and independent auditors that their information is secure and has not been leaked.

      In the event a customer's information gets leaked; the burden of proof should rest on the business.

      And companies that collect SSNs or other PII that can be used to conduct ID theft should be required to take out an insurance policy to cover at least a portion of their potential liability.

      They should be required to have 3rd party independent oversight, and there should be a fine for failures to comply, money which should be distributed to the affected customers, AND there should be a bounty for the company overseeing them spotting an error.

    2. Re:It's a problem, but not just the feds: by Jawnn · · Score: 1

      And companies that collect SSNs or other PII that can be used to conduct ID theft should be required to take out an insurance policy to cover at least a portion of their potential liability.

      That's probably not going to solve the problem. There's already a land-rush business in such policies for "covered entities" and "business associates" encumbered by HIPAA, and the general consensus is that they are not worth the paper they're written on. All include (not surprisingly) clauses that require the insured to have "implemented all required safeguards..." (or words to that effect). The problem is that there is no "standard requirement". The clause is just weasel-wording to ensure that no matter who diligent the policy holder may have been, a breach will have been "not adequately prevented". The net effect of this insurance push will be to lean on that rather than proper security, with predictable results.

    3. Re:It's a problem, but not just the feds: by mysidia · · Score: 1

      All include (not surprisingly) clauses that require the insured to have "implemented all required safeguards..."

      If such a clause exists, then the feds' view should be that the insurance policy is not compliant with the requirement, because the purpose of the insurance requirement is to help protect consumers against insolvency of the business, as such, the insurance policy should be required to payout to a trust sufficient amounts which can only be redeemed by those whose information was leaked or who suffered ID theft.

    4. Re: It's a problem, but not just the feds: by WindBourne · · Score: 1

      Wrong. They have basic security.

      What is really the cause is running windows combined with outsourcing to locations that have NO vested interest in the company and are paid very low relative to other nations.
      For example, nearly all of the companies that have been cracked of late (target, neiman Marcus, home depot, etc) had ( and most still do) outsourced production admin to India. In India, they pay these ppl less than $10,000 due to exchange rate manipulation. Others in China and Russia simply offer a person 100k to release a backdoor on the network. From there, these crackers will then leave false traces while massively stealing. Since both target and home depot have retained the offshore admins, there is little doubt that they are already cracked.

      What is sad is that companies like Boeing have actually outsourced to places like India, but also Russia and china. All 3 nations are finding loads of useful information.

      --
      I prefer the "u" in honour as it seems to be missing these days.
  6. Re:The solution by BVis · · Score: 1

    Always one, isn't there.

    --
    Never underestimate the power of stupid people in large groups.
  7. Blame the victim ... by CaptainDork · · Score: 2

    ... instead of fixing the goddam problem.

    FTFA:

    "No matter what we do with the technology ... we'll always be vulnerable to the phishing attack and ... human-factor attacks unless we educate the overall workforce," said Eric Rosenbach, Assistant Secretary of Defense for Homeland Defense and Global Security.

    Bold is mine.

    So much for AI in doing anything useful in protecting systems, and it's not the overall workforce that needs educating ... it's the fucking gate keepers -- IT and software/hardware manufacturers.

    It's a bitch that we send people to schools to be experts in their craft and then we have to educate the consumers of our craft because we are so fucking incompetent.

    --
    It little behooves the best of us to comment on the rest of us.
    1. Re:Blame the victim ... by Anonymous Coward · · Score: 0

      Ho no sir, he his right IT need to police the entire system. I hope you don't mind sir but once I'm done typing this text I will cut internet access so peoples stop clicking on everything they are presented.

    2. Re:Blame the victim ... by Anonymous Coward · · Score: 0

      It's a bitch when end users are so incompetent, oh hell with it, I'll just say what I really mean "when end users are just FUCKING STUPID"

      You can't fix stupid.
      You can fire them though.

      I bet captdork has paid the "fine" to the "Hi, I'm with the IRS and you owe back taxes plus fines, please buy a pre-paid CC and send me the card details or someone will be over to arrest you shortly" scamsters twice by now.

      He's also probably waiting upon the twelve inheritances that he's gotten from 411/419 scammers as well.
       

    3. Re:Blame the victim ... by Anonymous Coward · · Score: 0

      > we have to educate the consumers
      No, we don't. Explaining common sense like "don't talk to strangers" is a hand-holding courtesy, not an obligation.

      The AI is doing exactly and correctly as you demand, when you green light a stranger.

      Needs to be smarter and slap the user's wrist for them when they do? Users say it's already too restrictive. All the "Are you SURE you wish to authorize him?" barriers and security checkpoints and "Only admins can authorize guests"s.

      "I can't click the link."
      "Oh, it's an antiphising feature of the site. Check the path bar, and if you're sure it's a safe link? The override is to hold shift."
      "Yep, I'll be sure to remember that. The last part anyway."
      Congratulations, improved AI accomplished nothing when the "victim" is the instigator, when they authorize it. Leave the victim shit back on the SJW blogs. Don't blame Gmail when you send money to a Nigerian prince.

      Gmail can't tell whether that's REALLY your cousin asking for money. Your cell phone can't tell whether that's REALLY your wife texting 'what's the bank PIN again', or if her phone was swiped off a desk. You're up against intelligent humans, not monkeys peddling snake oil, and they're going to pick the venues that are hardest to coddle. The hardest to foolproof. It's only natural they choose to strike where you can't be babied.

    4. Re: Blame the victim ... by Anonymous Coward · · Score: 0

      Still not going far enough. A system without any outside lines is only as secure as physical security can get it, which requires at the absolute bare minimum some sort of access control system and at least two guards at all entrances to make sure people aren't "just helping that one guy" or tailgating their way through the gate, unfortunately those guards are a "cost center" and generally not included in security. And you do need two, because no one can stay awake watching a door for eight hours without coffee, which means bathroom breaks.

    5. Re:Blame the victim ... by xaotikdesigns · · Score: 1
      Obviously, you need to have a security personel sitting at the door checking ID's.

      Which means that the obvious answer is to have IT working directly with each user. When a user needs to log in, they call IT, IT checks their credentials to ensure they have the right person sitting at the computer, then logs them in. You'll need another couple IT people to make sure that workstsations are locked with people get up, and of course, you'll need someone available to log the users back in when they get back from the bathroom or where ever they go.

      The solution isn't education, it's more gatekeepers. Just think about the number of IT professionals that would be employed with the demand that this type of security would require.

      --
      XDInd
    6. Re:Blame the victim ... by gmhowell · · Score: 1

      You can't fix stupid.
      You can fire them though.

      Not if they're a GS employee.

      --
      Jesus was all right but his disciples were thick and ordinary. -John Lennon
  8. I should hope so by Anonymous Coward · · Score: 0

    Actually, I would hope that it would be even higher, as the alternative is that most of your data breaches are from external attacks.

    A "data breach" could be anything from unwittingly clicking on a malware link in a phishing attack (although those are pretty well filtered) to the more common data-spill, where information is transmitted on a system that is not certified for the information, like emailing home a phone listing that contains PII.

  9. But but but th-the Chinese! by Rujiel · · Score: 0

    And the Russians! Aren't they the chief troublemakers? How can we push our pre-emptive cyberwarfare withouth a boogeyman foreigner?

    1. Re:But but but th-the Chinese! by Anonymous Coward · · Score: 0

      Do you think the Russians and Chinese aren't trying to hack the U.S. Gov, or was that just a snide sarcastic jab at the government?

    2. Re:But but but th-the Chinese! by jc42 · · Score: 1

      And the Russians! Aren't they the chief troublemakers? How can we push our pre-emptive cyberwarfare withouth a boogeyman foreigner?

      Nah; today the term is "terrist". ;-) And them terrists can live nearly anywhere. There are lots of them in China, India, Malaysia, Nigeria, Brazil, and all those Muslim countries that are our current Enemies of Choice. And you can even find them in Canada.

      In Russia, "cyberwarfare" (aka "hacking" to the MSM) is becoming a public, respectable industry. They're into it as a way to systematically make a lot of money, putting them in essentially the same class as most of management in the corporate world. But in other parts of the world, it's more often a case of causing trouble for your victim, rather than just making money off them.

      --
      Those who do study history are doomed to stand helplessly by while everyone else repeats it.
    3. Re: But but but th-the Chinese! by Anonymous Coward · · Score: 0

      Russians, Chinese, Coatians, Bugarians... you notice 'They' are never from allied countries or those we like to do big business with. No Indians, even though they seem to be a huge source for outsourcing and recruiting. No cyber attacks from New Zealand, Australia, France or Britain.... the Germans always play nice,too. And what of the Italian mob?

      hmmmm really makes you wonder, doesn't it.

  10. Blame the victim ... by Anonymous Coward · · Score: 0, Flamebait

    You don't work in IT do you? Users are fucking idiots, when you can ask a random employee in the street to allow you into their building because you're working on floor X and have forgotten your pass, and they let you in how the fuck do you blame IT?

  11. Sounds like a criteria to cull the herd by Anonymous Coward · · Score: 0

    "You clicked on what?"
    "Don't let the door hit you on the way to the unemployment office."

    1. Re:Sounds like a criteria to cull the herd by sumdumass · · Score: 0

      Welcome to the world of unions.

      To finish your one sided connversation a month later, it would be-

      "What? He filed a grievance with the union"
      "What do you mean he gets his job back with back pay?"
      "So hard hard will it be to get that into the next contract?"
      "So it won't happen. Expect more of the same- we cannot do anything unless we get competent users who follow rules unless we lock everything down, but then they cannot get any work done"

    2. Re:Sounds like a criteria to cull the herd by xaotikdesigns · · Score: 1
      Fun story; CIO caught someone writing their password on a post-it note attached to the monitor. He took it down and told them not to do it again. Next time he walked past the desk, he saw the username and password on a post-it not stuck to the monitor, so he took it and wrote the guy up. When he saw it a third time, he boxed up the guys computer while he was away from his desk. He then told the guy that he was still expected to perform his job, but was nolonger allowed to use a computer due to violations of the companies IT policies.

      He quit before the end of the day.

      --
      XDInd
    3. Re:Sounds like a criteria to cull the herd by sumdumass · · Score: 1

      Lol.. what is flamebait about that. Everyone knows public employees are in the union and you cannot fire them for reasons not outlined in the conteact.

  12. Wow by Anonymous Coward · · Score: 1

    And here I thought those guys didn't do anything all day...

  13. If education could have worked ... by khasim · · Score: 3, Insightful

    If education could have worked, it would have worked by now.

    So much for AI in doing anything useful in protecting systems, and it's not the overall workforce that needs educating ... it's the fucking gate keepers -- IT and software/hardware manufacturers.

    The problem is that even if the IT people are competent they have to be MORE competent than everyone who can attack them. Why does everything have to be connected to the Internet?

    And they have to that competent with the software/hardware that they're using. How many times has the purchasing decision been made before you've even been aware of the issue?

    Which leads to the issues that the software/hardware vendors have within their own companies. Ship today and we'll patch tomorrow. Got to get to market before the competition.

    And that isn't considering the problems that "management" at the company you work for keeps introducing. I cannot tell you how many times some executive simply had to have admin access on his laptop which resulted in massive infections being brought onto the network.

    Security is easy --- in theory.
    But it depends upon hundreds or thousands of decisions being made correctly. By people who have no incentive to protect the security of the systems you support.

    1. Re:If education could have worked ... by Reason58 · · Score: 2

      I do federal government InfoSec. When there is a conflict between the mission and security the manager will overrule the system administrator every time. Even in the military where lives are potentially at risk.

      Sure, there is a lot of less-than-competent admins out there, but a lot more of the problem is political rather than technical than most people realize.

    2. Re:If education could have worked ... by khasim · · Score: 1

      Sure, there is a lot of less-than-competent admins out there, but a lot more of the problem is political rather than technical than most people realize.

      Yes. I think it is because the political issues stem from status battles. If you can overrule IT then you have more status.

      If you cannot overrule IT then you have less status than the nerds.

      And YOUR status, today, is worth more than the risk of someone else's life, possibly, sometime in the nebulous future.

      Particularly because you can still blame IT for not being able to deal with the situation. After all, isn't that their job. That's if they can even prove that it was your demands that caused a problem. Because all the other managers had the same demands.

      Anyone fired from Home Depot? Target? Any of the others?

    3. Re:If education could have worked ... by Anonymous Coward · · Score: 1

      I do federal government InfoSec. When there is a conflict between the mission and security the manager will overrule the system administrator every time. Even in the military where lives are potentially at risk.

      Sure, there is a lot of less-than-competent admins out there, but a lot more of the problem is political rather than technical than most people realize.

      Definitely not true in the agency I'm in: Security rules, to the detriment of the mission. We're grinding to a halt under new security rules that have been implemented without accompanying processes in place. "We used to do X, but we can't any more for security reasons." "Okay, what's the new way?" "Y, and it'll be in place next year." "But, uh...we need to get work done NOW." "Well, you can't do X or Y." I want to keep our data safe, too, but we also need to get our projects done...it'd be nice if (when possible) implementation of the new security rule was delayed until the new method is up and running, or helping us find a way we can still accomplish our mission, securely, until Y is ready to go.

    4. Re:If education could have worked ... by SeaFox · · Score: 1

      The problem is that even if the IT people are competent they have to be MORE competent than everyone who can attack them. Why does everything have to be connected to the Internet?

      Because there is always someone who thinks they need to be able to access the system from wherever they are in the world. Either a big-wig who wants access to data, or an IT person who wants to be able to work on system issues from his home when things happen in the middle of the night.

      Security suffers at the hands of the human penchant for laziness.

  14. CyberThis, CyberThat, CyberCommand by Cid+Highwind · · Score: 5, Insightful

    Dear US military and federal contracting wanker-sphere,
    I know you were 30 years late discovering this whole internet thing, so imagery and phrases from 1980s cyberpunk still sound super-duper-cutting-edge to you, but can you please stop using "cyber" as a catch-all for everything connected to computers? Thanks.

    PS: When you leave a laptop full of citizen's private information on the bus, and a million people's social security numbers turn up on pastebin the next day, that's called "negligence" not "a cyberattack".

    --
    0 1 - just my two bits
    1. Re:CyberThis, CyberThat, CyberCommand by Anonymous Coward · · Score: 0

      CYBERATTACK!

      Sound the iAlarm!

      Rouse out the e-troops!

      Defend the GATEWAY ROUTERS.

    2. Re:CyberThis, CyberThat, CyberCommand by Anonymous Coward · · Score: 0

      These days all cyber means is a method for mutual masturbation...

      WTG U.S. Government, setting up the Masturbation Command structure. Let us know when you start going blind and growing hair on your palms.

    3. Re:CyberThis, CyberThat, CyberCommand by Anonymous Coward · · Score: 0

      It performs a useful service, as soon as I see Cyberanything or even Cybermen I can assume no useful technical content.

    4. Re:CyberThis, CyberThat, CyberCommand by allquixotic · · Score: 1

      Actually, the "US military and federal contracting wanker-sphere" were among the few organizations that spent big bucks on the foundational concepts of networking that eventually led to the Internet. Look up the history of DARPA sometimes. The first letter in the acronym, D, stands for Defense.

      Their reasons for using "Cyber" in front of everything are for completely different reasons. Beancounters in the massive federal bureaucracy system need distinctive search keywords for disparate efforts. If they just called everything "security", you would end up with hiring security guards with pistols who've never touched a computer, whose job description says they're supposed to do penetration testing on mainframes.

      Sure, their terminology seems a little out there (especially because much of the world doesn't feel the need to assign such specific, clumsy terms to everything), and I'm not defending their practice, nor am I claiming that they're up to date with the latest trends and technologies now that the Internet has flourished.

      But it is a complete fabrication to say that the military-industrial complex / the US DoD / the US military is "30 years late discovering this whole internet thing". They BUILT it.

      Al Gore didn't invent the Internet. DARPA did.

    5. Re:CyberThis, CyberThat, CyberCommand by Chris453 · · Score: 1

      Do you know who created the internet? Hint: it wasn't Al Gore. What does DARPA stand for again?

  15. There is just no way... by Anonymous Coward · · Score: 0

    ....the average person can keep track of the latest and greatest threats/ patches /updates etc and still have time to do their job.

    IMHO the current state of affairs is due to senior management in all industries/government because IT departments are seen as cost centers to be minimized at all cost.

    #1 They refuse to spend the $$$ to implement things correctly. Everything must be done on the quick and CHEAP.
    #2 They refuse to spend the $$$ to train their personnel correctly on the basics of using a computer.
    #3 They refuse to listen to advice and policies implemented by IT. Often times if one senior vp or somebody of sufficient status complains that something is too difficult, time consuming or troublesome, the policy is dropped/ignored.
    #4 They refuse to hire enough IT staff and pay the market price for their expertise. Often times every IT department I have worked for has been understaffed and barely able to keep up with the daily support requests......And by keeping them close to 110% load 100% of the time, you end up burning out your most skilled personnel who leave for greener pastures....or change fields altogether.....
    #5 They refuse to spend $$$ to train their IT personnel for an ever evolving industry. They somehow expect him to keep up to date on his own time (after of course putting in a 90 hour work week).

    All off the above leads to the clusterfuck mess we have today....

    Quite honestly there is not easy solution to all of this...

  16. No thanks. by Anonymous Coward · · Score: 0

    Sorry, but I don't believe any story where the source is Fox News, even if it is stating the obvious.

    They have misstated the truth too many times for me to credit them.

    In any case, I'm puzzled. Since they're saying that if a site is attacked, the person responsible is the victim, for having been vulnerable, surely the correct statistic is that 100% of the breaches are due to employees or contractors.

    All attacks are because somebody, somewhere, left a vulnerability. Not half: all. A hundred percent.

  17. I blame the sysadmins/IT staff by duke_cheetah2003 · · Score: 1

    They need to be taking proactive steps to securing their systems not only against outside threats, but from the idiots using their systems/networks. Isn't this like common knowledge, your users are your worst enemy?

    Oh wait, its the guberment. All bets are all, I guess. Common sense need not apply.

    1. Re:I blame the sysadmins/IT staff by duke_cheetah2003 · · Score: 1

      correction: all bets are off

  18. The media and govermment blame russia by Rujiel · · Score: 1

    at every opportunity, often to shine light away from the NSA's own global malfeasance.

  19. Which is why corporate security is a joke. by gestalt_n_pepper · · Score: 4, Insightful

    All of it can be overcome by a janitor with a USB drive with penetration software.

    Security culture is worse. Elaborate passwords. Two or three factor identification. Putting the security burden on the user in general. All you do is:

    1) Inconvenience users and make productivity next to impossible.

    2) Create an entire culture of employees who must, in order to get any work done, know how to hack their way into corporate systems from outside (I know of two ways. My IT guy knows about 6 entirely different ways), and frequently, inside.

    The problem is that security guys get bonuses for reducing intrusions (as they count them). Everyone else gets bonuses for getting their work done and being productive, which frequently isn't something that ever gets on a spreadsheet.

    And upper management, as usual, is too stupid, distracted with power politics and just plain pig-ignorant to understand this.

    --
    Please do not read this sig. Thank you.
  20. Web Surfing by ISoldat53 · · Score: 1

    Why are government employees web surfing. Don't the have anything better to do?

    1. Re:Web Surfing by Anonymous Coward · · Score: 0

      I mean, I guess I could get this workload done today but then I'd be downsized by Friday

    2. Re:Web Surfing by SeaFox · · Score: 1

      Why are government employees web surfing. Don't the have anything better to do?

      Don't you love it when people complain about government workers/contractors doing non-work related activities, but then they turn around and complain about their own boss treating them like a machine and expecting them to be productive every minute they're on the clock?

    3. Re:Web Surfing by Anonymous Coward · · Score: 0

      Yea, read SlashDot!

  21. I want to be.. by Anonymous Coward · · Score: 0

    I want to be a cyber ranger
    remote controlling all the danger
    cyber ranger
    remote danger

    captcha: ferocity

    1. Re:I want to be.. by jep77 · · Score: 1

      Sound off!

  22. Yep, Gov InfoSec by AF_Cheddar_Head · · Score: 1

    If you IA types understood how a network actually maybe we could talk but get your CISSP and make big bucks saying NO.

    Example:
    Backup program needs Port X open to initiate backups on remote servers (remember we are an Enterprise, Remote Management and all). Vendor did not adequately document port but our firewall logs and sniffer clearly indicate this message originates from the control server and goes to the Media server to initiate the backup.

    What does IA do? Stops all backups until paperwork is finished, six months without backups and guess what once the vendor documents turn it back on. No thought about the data risk just turn it off.

    Further details if you want but why not allow us a firewall rule from control server to destination server locked to IP addresses and maybe only during a defined time window to allow the backups.

    But IA has the hammer and enjoys using it.

  23. Remember when the perpetrator was responsible? by Dcnjoe60 · · Score: 1

    Workers are responsible for half of cyber incidents? Well, if opening an email or clicking a link as described in the article makes the worker responsible, then so be it. But, in the days before the internet, when corporate (or government) espionage was the issue, it wasn't the worker who created the report that was responsible for it being stolen, but the actual thief. So, other than another attempt to denigrate government workers, why if somebody sends a malicious link is it not the person who sent the link responsible versus the unknowing end user?

    Saying the government workers are the cause of the problem is like saying the woman wearing a short skirt was the cause of the rape. Blaming the victim just diverts attention from the real problem.

  24. I'll make this easy on all of us ... by CaptainDork · · Score: 1

    ... a person in the workforce asks me if an email is safe.

    I grab their email.

    The sender is apparently UPS, and the package ain't going nowhere until I click on the attached invoice and correct the ship-to address and stuff.

    NOW PAY ATTENTION:

    I look at the attachment and it's a .zip file. I double-click the .zip and, inside, there's a goddam .exe.

    UPS isn't going to send an attachment in the first place, and it damn sure isn't going to be an .exe, right?

    Why in Sam Hill can't a small, fast AI scrubber do this simple task?

    Why can't AI follow a link, intercept a download (either with or without the operator's permission), let the code execute in a sandbox to see what it WOULD do and say, "I don't think so?"

    We don't need to educate the workforce.

    We just need to do our jobs.

    --
    It little behooves the best of us to comment on the rest of us.
  25. seems about right by GrimShady · · Score: 1

    "Report: Federal Workers, Contractors Behind Half of Government Cyber Breaches"

    Since the government employs about half of the people in the US this is probably statistically correct for anything :)