IT security teams at federal government agencies and their cleared industrial contractors face a daunting series of challenges in securing their networks against modern malware intrusions, including advanced persistent threats (APTs) and advanced targeted attacks (ATAs). Their networks are prime targets for individual, political, nation-state and other hackers eager for access to truly critical content. They are also subject to a myriad of regulations from oversight and standards-setting organizations, both U.S. and international, the most prominent coming from FISMA/NIST.
Ironically and somewhat counter-intuitively, time and effort spent ensuring that an agency’s network is in compliance with all regulations often competes with – and sometimes even takes time away from – attention to providing actual data protection using the very best tools, systems, and methods available.
In a new Norman Shark white paper, “The Last Line of Defense: The Role of Malware Collection and Analysis in Securing Federal IT Systems,” I discuss how government compliance requirements frequently fall short of industry best practices, due to the fast-changing nature of the malware threat environment combined with the slow, grinding pace of the legislative and regulatory processes. The paper differentiates compliance from best practices by noting that IT security teams are often forced to focus their compliance efforts on meeting regulatory requirements – often just enough to pass annual compliance audits under strict time constraints – not on protecting critical information with all of the urgency and resources that the organization’s various stakeholders deserve. Best practices include implementing the most current strategies, and hardware and software suited to the task, all designed to secure agency, employee, and customer information against exfiltration and misuse.
The paper identifies the motivations of malware authors and their sponsors and highlights the many ways that malware can enter a federal or contractor network, including spear-phishing, bring your own device (BYOD), USB drives, zero-day exploits and many others. Focusing on the especially thorny topic of BYOD, I note that 51 percent of U.K. businesses have already been compromised as a result of malicious software entering enterprise networks via difficult to monitor user-owned mobile devices.
As part of a strategy to assist federal IT security teams to move beyond compliance and towards a true best practices approach, Norman Shark is offering a no-cost advanced malware risk analysis to all government agencies and qualified contractors. Call for yours today!
Do you manage security for a federal government or cleared contractor network? What have been your experiences with malware intrusions and defenses? What keeps you up at night? Share your concerns, strategies and successes so we all can sleep better!
Read more about advanced malware risks and defenses. Download the white paper and join the discussion! [Click Here]

