Better CyberSecurity Coalition
We are a coalition of cross-industry leaders from around the world. You may already know many of us.
We are concerned about the rapidly deteriorating cybersecurity situation. So, we have written an open letter, and proposing a better cybersecurity blueprint.
Better cybersecurity coalition.
an Open letter.
Dear Policymakers, Industry Associations, Cross-Industry CxOs, and Deans of Educational Institutions,
The Cybersecurity situation is deteriorating. With rapid technological innovations, adoptions, and geopolitical developments, the situation is only going to get worse - much worse.
The math is simply against cybersecurity (threat-of-once) - cyber criminals only have to succeed once, whereas cybersecurity needs to succeed every time.
This requires urgent attention and collective action.
Given the concerns, some of us have gotten together under the umbrella of the better cybersecurity coalition, to put a spotlight on this deteriorating situation, and are proposing a better cybersecurity blueprint. This is the result of our learning not only from the cybersecurity field, but also from the automotive, aviation, and the building industry.
Our proposed better cybersecurity blueprint, which builds upon the existing frameworks and best practices, is as follows:
Better CyberSecurity = Security Pillar + Resiliency Pillar + DesignForCyberAttacks (Loss-Reduction) Foundation + Regulatory Oversight + Country CyberForce (aka fifth-domain force) Coverage + Education/Certification (+ International/UN CyberSecurity Cooperation)
Design For Cyber Attacks: Our first proposal is to take a holistic approach - bake-in Design-For-Cyber-Attacks (Loss Reduction) - in addition to Security-By-Design (better security), and Resiliency (quick recovery) - at the design stage itself. These are the three critical components in our new proposed blueprint.
Regulatory oversight: Our second proposition is to take a holistic risk-based approach to regulations - to regulate certain high-risk aspects of the better cybersecurity blueprint. Here we refer to the aircraft, building, and vehicle industries. Indeed, regulations should have enough teeth for them to be effective.
CyberForce coverage: Our third proposition is for the countries to provide active CyberForce (aka 5th domain force) coverage - a top country level (layered) security coverage.
Education/Certification: Our fourth proposition is to integrate (or run certification courses for digital system architects, security architects, and chip designers) this better cybersecurity blueprint in all computer science and related classes.
UN/International CyberSecurity Cooperation: Our final proposition is to expedite international cooperation, surrounding cybersecurity.
Cyber attacks are here to stay. So, we urge policy makers to initiate the debate on priority - to come-up with the required regulatory framework. We also urge cross-industry CxOs, to continue in the interim to improve our security posture - and prepare our organisations to face crises to come - our digital systems should be designed henceforth with the DesignForCyberAttacks doctrine (Loss-Reduction).
Let’s take the control of cybersecurity back from cyber criminals. Let Greta Thunberg’s generation not question us - how dare you - not take any action?
Endorsed and signed by
Better CyberSecurity Coalition
Dated October 3, 2019/Thursday
Attachment: White paper titled, “Better CyberSecurity - A New Blueprint” >>>
While cyber threats continue to pose challenges, the emerging technologies such as cognitive computing, data lake and deep learning will be key to combat them. Key to manage the cyber risk will be adherence to security by design principle.
Award-winning and accomplished CISO
better cybersecurity.
a New Blueprint
Cybersecurity needs a fundamental change in our approach. It’s time to shake the very foundation of existing and failing “Security” focused strategy. Yep, that’s true - there we said it.
We are writing this white paper under the backdrop of a rapidly deteriorating cybersecurity situation. In our collective opinion, cyber attacks are continuing to grow due to technological innovation & adoption, and changing global geopolitics. This opens new areas and vectors for abuse by cyber threats. Additionally the arc of impacts has driven a shift in public expectations. This will leap forward, as life-safety risks become apparent. In light of these developments, our current cybersecurity frameworks and practices are missing crucial components. In this paper, we are proposing a new blueprint for better cybersecurity and calling for action from various stakeholders…