As the year and congressional session closed without the passage of a comprehensive cyber security bill, the CEO of a non-profit cyber security intelligence organization weighs in on the role of legislation. Although he’s unauthorized to comment on the most recent efforts, the executive challenges the relevance of past legislation based on lengthy lead times.
In the twelfth episode of our video series, our guest explains how a recent rude awakening, in the form of high-profile hacks, confirmed to lawmakers that cyber threats are real and inevitable. Many publicly-traded corporations have opened up, reporting security breaches and taking responsibility for warning others. The executive applauds congressional and executive efforts to prioritize our nation’s network security, but initiatives are often more reactive than proactive.
Even a proactive approach to regulation involves an extensive process, with debates and approvals spanning over as many as three years. The executive explains this Catch 22: “So much badness can happen between that three-year window that legislation, unfortunately, when it hits the streets, is not relevant.”
To accelerate action, he insists on getting the correct people involved in debates and congressional testimonies. More informed discussions led by cyber security experts will lead to more beneficial and applicable legislation. There’s been a lot of buzz about the reintroduction of cyber security standard discussions in 2013, with new iterations of the failed bill. Hopefully this year will finally bring new cyber protection laws to encourage cooperation among government and enterprise organizations.
What are your predictions for cyber security legislation?

