Actionable Intelligence for Malware Defense.

Blog » Sometimes Legislation is Just Irrelevant
Blog
Sometimes Legislation is Just Irrelevant
2013.01.15 | By John Dennis | 0 comments

As the year and congressional session closed without the passage of a comprehensive cyber security bill, the CEO of a non-profit cyber security intelligence organization weighs in on the role of legislation. Although he’s unauthorized to comment on the most recent efforts, the executive challenges the relevance of past legislation based on lengthy lead times.

In the twelfth episode of our video series, our guest explains how a recent rude awakening, in the form of high-profile hacks, confirmed to lawmakers that cyber threats are real and inevitable. Many publicly-traded corporations have opened up, reporting security breaches and taking responsibility for warning others. The executive applauds congressional and executive efforts to prioritize our nation’s network security, but initiatives are often more reactive than proactive.

Even a proactive approach to regulation involves an extensive process, with debates and approvals spanning over as many as three years. The executive explains this Catch 22: “So much badness can happen between that three-year window that legislation, unfortunately, when it hits the streets, is not relevant.”

To accelerate action, he insists on getting the correct people involved in debates and congressional testimonies. More informed discussions led by cyber security experts will lead to more beneficial and applicable legislation. There’s been a lot of buzz about the reintroduction of cyber security standard discussions in 2013, with new iterations of the failed bill. Hopefully this year will finally bring new cyber protection laws to encourage cooperation among government and enterprise organizations.

What are your predictions for cyber security legislation?

“In today’s climate of persistent threats, network defense alone is no longer enough. In order to protect networks from the proliferation of targeted attacks and unknown threats, analysts need dynamic malware intelligence capabilities that allow them to respond quickly in the event of an incursion.”