New rule would give electric utilities incentives for investing in cybersecurity
federalregister.gov
federalregister.gov
You can't just purchase a "deluxe cybersecurity firewall appliance" and plug it into your network, even if it costs $50,000. I bet that a lot of people believe that's what it takes, though.
Compare this to, say, education funding. It's good to spend more money on schools, right? I mean, teachers gotta be paid, students need (Chrome)books. But I always vote "no" on municipal school bond measures. I believe that money isn't everything, and I believe that it funds the wrong kind of things. The measures always pass, though, so don't worry, I'm not oppressing all the little kids in town.
Time and money spent working with cybersecurity professionals writing SOG/SOPs which map the business practices to the standard. Money spent buying and setting up some of the necessary equipment to handle CUI properly. Time (indirectly money) spent redoing decades old business processes to map to the new paradigm. Time (indirectly money) as the business spent time training their staff up on the components relevant to their business units.
I agree that building a culture is at the root of it, however, that culture alone isn't going to move the needle unless everything else is in place as well. Worse, you have to walk the company through the 5 phases of grief because in general people don't entirely understand what is actually going on and why it's important. "So you can get government prime contracts" is an easy answer, but doesn't erase the confusion behind all of the hand-wavy procedural work required to execute them.
It's really an interesting idea:
https://www.cato.org/sites/cato.org/files/serials/files/regu...
This creates a "market for effective practices", because companies that follow good security practices would get cheaper insurance.
But it would allow insurances and companies to figure out dynamically what is cost effective and what isn't.
There would be lots of financial incentive to figure out what protects you effectively and what is just security theatre.
The smart insurance companys are all getting out of cybersecurity insurance because the premiums on the policys they wrote 10 years ago when the average attack cost $1,000 to remediate do not look so good when the average attack now costs $100,000 to $1,000,000 to remediate. Since the expected probability of a successful attack in any given year that requires payout is approaching 100% these days the insurance needs to be priced something like 10x-100x the prevailing prices to be survivable.
Eventually it will shake out once the cyberattacking industry becomes mature because at that point backwards looking projections make sense. Until that time, we are in for a wild ride.
The only reason banks are not totally wrecked by cyberattacks is that:
1) They actually are being constantly attacked by ransomware and the like, they just do not disclose it; I do not remember the budget line item the payments all go under but it is one of those compliance/administrative ones such as for insurance.
2) Cyberattacks, contrary to their standard portrayal as always being run by “state-sponsored” groups to make the companys being destroyed look better, are largely run by kids. They are largely unsophisticated on financial and business matters so do not know how much to ask for, how to maximally leverage a breach as a first party (i.e. do not know how to use say investment bank deal details to do effective trades), and how to actually cash out large amounts of money undetectably.
3) The non cybersecurity processes and fraud detection are actually fairly effective. There are large number of accounting checks in place that make it very hard to do simple hacks (like make the numbers in one account higher) that can not be detected. Banks have the equivalent of very complex, bespoke DRM systems that requires knowledge of financial systems and of their internal processes to crack. As I said before, the hackers are largely financially unsophisticated, so it is very hard for them to do this.
No, it is intensely defeatist to just give up on actually solving the problem and demanding useless security theater in the vain hopes that it will somehow improve the situation.
I wonder how many actually sophisticated attackers gain access to banks and other companies and purposefully keep a low profile but skim off low-bandwidth information meant for internal communications only, then aggregate and sell the intel to hedge funds or trade stocks on their own.
Maybe the reason why we think that most attacks are caused by unsophisticated actors is because those are the one who are actually detected.
Just kind of an interesting hypothesis that I’ve heard variations of before.
> demanding useless security theater in the vain hopes that it will somehow improve the situation.
The security theatre required by these new rules might not prevent all breaches, or any breaches, but they will force utilities to be accountable for their failures.
No longer will it be "Oopsie, mean hacker hacked us. Not our fault. Whatchugonna do anyway? Your business had to shutdown because no power/internet? Tough luck I guess".
Now it will be "Oh fuck, hackers got in. We'll have to cover our customers losses and spend millions in PR to spin the story and avoid total bankruptcy."
Do you really not see how that's still an improvement?
Also, the vendors and the people being shielded largely write the rules.
The losses are not low because the cybersecurity processes and regulations are good, they are low because even though the vault is being guarded by the metaphorical equivalent a chihuahua, all they are doing is stealing the pens because they do not know how to pawn the gold in bulk.
This state of affairs is changing very quickly. 15 years ago the hackers were walking into the vault and asking for $1,000 because they were 16 year olds who thought that was a lot of money. Now the good ones are 30 years old and are still walking into the vault, but asking for $10,000,000. Last I saw the number of attacks was increasing 3x year over year and the average ask was increasing 3x year over year.
The entire cybersecurity insurance industry is already underwater at current premiums. I have heard they have basically stopped issuing policys over a few million dollars because it is literally ruinous. It is no longer becoming possible to paper over the omnipresent security deficiencys with insurance, betting on the incompetence of the attackers, and betting only one of you is going to get eaten.
The sensible solution right now would be liability requirements on advertising security. You can not insinuate you are “secure” whatever that even means. You can instead only advertise a dollar amount per customer which is tied to a mandatory bug bounty. If you are a big bank with 100 million customers, you can put up a 10 billion dollar bug bounty on breaching your systems and then you can advertise $100 of security on your customer deposits.
This would force them to put their money where their mouth is while not preventing new small companys from existing as long as they truthfully report that they are not providing security. It would also help us pull the customer desired security requirements forward in time instead of waiting for the destruction first.
Absent that, what is going to happen is that everybody keeps lying about their security to trick their customers into trusting them. Then one of them is going to get hit by a truly expensive attack and all the customers will be caught with their pants down.
The only technical solution to this is either dropping reliance on these easily hacked systems, or throwing out all the existing crap that was never designed for security and can thus never be retrofitted to be secure such as Microsoft, Linux, Cisco, and Crowdstrike. Instead we must deploy systems designed for security such as those targeted to conform to the (now deprecated) Orange Book Class A1 or Common Criteria EAL 6/7 systems which are certified and proven to resist nation state attackers such as the NSA.
Everyone involved correctly comes to the conclusion that the company’s security policy is purely performative.
The people that care leave. The people that don’t care about securing the system implement the useless checkboxes and put the standalone box in the correct room (and might even plug it in), then get promoted.
FIPS security certifications are the poster child for this. There’s basically no way to get a securely architected system certified, so you end up adding vulnerabilities and (in the best case) a configuration parameter like the old “enable FIPS certification (default off; do not enable unless you are required to do so)” button from windows.
The only thing a regulation that mandates a 50k appliance will do is boost the appliance makers sales.
Regulation is good to a degree; there's a balance to strike between overly burdensome regulation and regulation which basically may as well not exist. The lines between these are sometimes vague as the times evolve and are also subject to regulatory capture by interest groups (political groups and companies).
The incentive structure generally makes spending money free or more free so long as an entity abides by the guidelines set out by the incentive.
You need both and both need to reflect the correct goals for the times.
It's realistic.
> Regulations and compliance
Which might be nice. "Do this, or you will be penalized like this." These are marketed as "incentives" which is "Buy something, anything, and here's some abstract additional cash."
> And they need to be looking at a checklist that they only want to complete to avoid fines
The problem here is, you do the checklist, and you get an incentive. I wonder how that's actually going to be implemented?
Regulation & incentives are literally the tools governments have to shape policy. It's a start, but moving the needle on issues can be hard, slow work -- especially when it seems like so many people have the attitude that if a particular action wasn't the their perfect, preferred solution, then it shouldn't have been done at all.
Of course, there are many useful textbooks with none of the above properties, but they don’t require complicated incentive structures to ensure they’re made mandatory.
That seems to be a "management is unwilling to pay enough" problem, not a "the industry is struggling and needs a government handout for relief from the burden of enhancing security" problem.
Congresscritters are demanding we cut "fat" out of basic social assistance programs by increasing requirements from beneficiaries but we're going to give electrical companies, making half a trillion in profits running basic infrastructure, a big handout, with trivial or no requirements?
Pass.
Expenses must be approved by the regulator as well. How strict that is depends on the state but in New York for example it's approved at the department level. All utility salaries are below non-utility equivalents and keeping people from going to Google or Meta by paying higher salaries is effectively illegal.
This is not to boo-hoo for utilities. The ones that are for-profit do fine. But they are not parasitically extracting vast profits because that isn't allowed.
Years ago, I learned a peculiar thing about corporate or municipal budgets: sometimes a line item has to be spent or it won't come back next year. So there is often some strong impetus to spend $XXX,XXX -- or else -- and the deadline comes on June 30, and often that is how you arrive at bad spending decisions, because it's "burning a hole in your pocket".
GP is actually understating this; if my budget and revenue is $0, then I cannot run a school or enterprise at all and it will file for bankruptcy and close.
A strawman is the informal fallacy of refuting an argument different from the one being discussed. I never said that a budget should be $0 or "without money". That's a reductio ad absurdum.
So this situation still seems better than a rule which only benefits companies that hire Cisco Certified Security Posture Experts or something. There's at least a chance that some of these companies have competent CTOs (or equivalents, at smaller utilities) and will spend in the right area.
Want to have utilities (or any industry) put cyber security front of mind? Just tell them that they are liable for consequential damages for any service outages related to a cyber security incident, and watch how good they get at cybersecurity.
The state public utility / service commission determines how much profit a utility is allowed to make (really it's return on equity) based on federal guidelines. Every year the utility must make a rate case that includes what it's going to spend and why and why its shareholders deserve to get anything on top of that. If the utility has misbehaved that RoE number can literally be zero, though this would be rare.
Punitive profit slashing (not quite that extreme) has definitely happened for major customer-facing IT issues and would probably happen for a major breach.
Those cost a quarter of a million per year nowadays...
This particular rule will most likely be gamed to increase rates while providing no improvement in security, with a compliant FERC nodding along under the current system of corporate regulatory capture of government.
The electric utilities might be a natural monopoly today, but moving to nationalize it is addressing yesterday's concerns. If we're spending political capital to nationalize natural monopolies the electric utilities would be very far down my list of priorities.
Security has typically fallen under O&M... there are some operational parts of utilities and the sector that are well resourced, but the general corporate side is rough. I'm sure there's already some security spend that gets worked into capital budgets, but this is going to make the case much easier. I'm just concerned that they're going to spend a lot more money on products and blinking boxes than building out teams to improve security and do hard work modernizing IT infrastructure.
OTOH, if anybody is looking for someone with sales experience in the sector as well as infosec technical sales experience, this handle @gmail works for an intro ;).
[1] https://en.wikipedia.org/wiki/Averch%E2%80%93Johnson_effect
Screw incentivizing this and mandate it instead. Follow the rules or lose your company.
"Act for PENALIZING infrastucture companies, financial companies, utility companies and other key compnents to USA's national security and economy, by failing to invest in cyber securirty, egregious data leaks/losses/deletions as penalized financialy, quartly following audits until complaince is met."
We should be "incentivising them" -- we did that alreadfy, and failed so many times:
* gas tax to people, subsidies to oil companies for cheap gas, better roads and exanding refining capabilities <-- Total failure
* 4 billion 'incentive' to AT&T for high speed internet infra, in the 1990s?(or early 2000s) - they took the money and did nothging with it
* Rail subsidies and many billions wasted on a failed study for a highspeed rail
* Food sunsidy incentives to keep prices low (oh look at all the food processing facilities that blew up, or caught fire during the pandemic and a large inflationary period.
* Bank bailouts to keep people from getting financially destroyed by interest hikes, etc...
* Lets help Ukraine with billions in arms sales and money which loops right back to back-door kick-backs to both actual politicians and defense contractors etc.
(I personally believe we are pummeling Ukraine with billions in un-auditable funds to hide the corrupt kickbacks coming from these to the US politicians, and some of their family members)
Incentives like this are simply a grift act on the taxpayers, again.
--
I know we dont like GPT much in comments - but I find it great for summarizing PDFs from any .gov link:
---
Title: Incentives for Advanced Cybersecurity Investment Act Summary
The Incentives for Advanced Cybersecurity Investment Act, as outlined in the provided document, aims to encourage and support organizations in investing in advanced cybersecurity measures. The act offers financial compensation in the form of grants and incentives to qualifying entities that make substantial investments in cybersecurity technologies and practices. Here is a summary of the key points regarding compensation and qualifications:
1. Compensation Offered: The act provides financial support to eligible entities through grants and incentives. The compensation is structured into two categories: Grants for Advanced Cybersecurity Investments (GACIs) and Cybersecurity Investment Tax Credits (CITCs). The specific compensation amounts are detailed in the document and are subject to change over time.
A. Grants for Advanced Cybersecurity Investments (GACIs): GACIs are non-repayable funds granted to qualifying organizations to support their cybersecurity investments. The grants are designed to help cover the costs associated with implementing advanced cybersecurity measures, technologies, and training programs.
B. Cybersecurity Investment Tax Credits (CITCs): CITCs offer eligible entities tax credits based on their investments in advanced cybersecurity. These tax credits aim to provide financial incentives to organizations that invest in cybersecurity technologies and practices.
2. Qualifications for Applying: To be eligible for the grants and incentives provided by the act, organizations must meet certain criteria. The qualification requirements include:
A. Entity Type: The act is applicable to various types of entities, including but not limited to:
- For-profit organizations
- Non-profit organizations
- Educational institutions
- State, local, tribal, and territorial governments
- Federal government agencies (subject to specific conditions)
B. Cybersecurity Investment: Entities must make a significant investment in advanced cybersecurity technologies, practices, or training programs. The act defines the investment threshold and specifies the qualifying cybersecurity areas.
C. Certification and Compliance: Applicants may need to demonstrate compliance with certain cybersecurity standards or obtain relevant certifications to be considered for the grants and incentives.
D. Reporting and Documentation: Entities are required to provide detailed reports and documentation to substantiate their investments, costs, and compliance efforts. These documents may include receipts, invoices, training records, and other relevant evidence.
It is important to note that the specific details, requirements, and eligibility criteria may vary and are subject to updates. It is recommended to refer to the original document provided for the most accurate and up-to-date information.
I was looking up announcements for certain industries / companies who announced large projects granted/influenced by legislation, then grants and associated politicians investments from opensecrets.org... - it was pretty tedious with the free account - Ill need GPT 4 to do what I would like --
It will be great to have 'GovWatchGPT' monitor acts such as these, the companies that apply, granted, success/fail and the politicians they donated to, and whom invested into their companies just prior to an act passing.
Doing things like this between AutoGPT, and ChatGPT - you can see kind of how I was starting to look at congress, but to get current articles and such, had to use autoGPT - but it was having issues saving data...
--
https://chat.openai.com/share/7dd61596-c83a-4c24-98f2-b39b3e...