As August turns to September, it’s a time of transition and also of taking stock. At my house, we always try to schedule one more waterpark trip between visits to the store to grab that last back-to-school item. But this isn’t a blog post about summer reading lists or even doing a review of your organization’s cybersecurity processes (though you should finish up both); this is about why NCPC courses are free to you and also mid-20th Century Naval history.
September also marks the countdown to the end of the U.S. Government’s Fiscal Year, and in addition to the all-too-real scramble to avoid a shutdown—it’s the time the United States Congress begins making final decisions about how to allocate your tax dollars to do the most good for you. If you want an idea of how hard that can be, just go back and re-read the previous sentence and see how you felt reading “the most good for you”, and then multiply it by over 330 million.
One thing that has been designated for funding again and again and again is cybersecurity training for state, local, tribal and territorial governments. The good folks at the Federal Emergency Management Agency (FEMA), the lead coordinating agency for preparedness in our communities, have a National Training and Education Division (NTED) that identifies needs and promotes high-quality training so that Americans everywhere stand a better chance when disaster hits. Among the many preparedness trainings they pay for so you can learn it for free are the offerings on this National Cybersecurity Preparedness Consortium website.
But why? And why is FEMA, the hurricane agency, the one doing it?
Many years ago, I was working on Capitol Hill when then-CIA Director Leon Panetta was testifying to the House Permanent Select Committee on Intelligence and uttered one of those phrases that passes into common speech. “The potential for the next Pearl Harbor could very well be a cyber-attack,” he said.
Since then, the phrase “Cyber Pearl Harbor” has become shorthand for a massive cyber event that cripples the United States and allows an adversary to carry out successful attacks all over the world. There’s even a Cyber Pearl Harbor backlash with the concept of a massive surprise attack used as an example of fear-mongering, since none has seemingly been successful since Panetta said those words in 2011. Here’s where I get to begin indulging things I picked up with my Naval War College degree and point out that the Interwar Fleet Problems showing that Pearl Harbor was at risk back in 1932 were also dismissed as fear-mongering.
The thing that often gets overlooked is that the attack on December 7, 1941, began as a local event in Honolulu. Cyber Pearl Harbor will first appear in a rural electrical co-op’s payments system, or a Department of Motor Vehicles’ online records, or a municipal water system in Minnesota, and only after the fact will we come to realize it was the first move of a nation-state.
That means the first person to respond to Cyber Pearl Harbor is probably going to be you.
I helped pass Federal appropriations for over a decade and, believe me, nobody ever said we have enough CISA employees, FBI Agents, National Guard, CYBERCOM teams, or anyone else to keep your hometown from getting hacked. And with the exponential growth of attack capabilities available through AI automation, the gap is getting bigger.
That’s why Congress gives NTED the job of providing training, and why it uses everyone’s tax dollars to make sure you don’t have to pay for it. Because the only way to close the gap and get professionals with enough cyber skills to protect, detect, react, and rebuild is to get everyone involved. And the best people to help you prepare are the same folks that help you prepare for other localized disasters with the potential of national impact.
That’s right, Uncle Sam wants you. The cyber training and other preparation you invest time in is not just good for dealing with the legions of criminals that are hitting your system every day, but it’s a critical component to national defense in the same way the Ground Observer Corps in World War II helped prepare for a second surprise attack on U.S. soil. By having Americans all over the country with preparation that would allow them to identify enemy planes and a clear process for communicating the information to public safety officials for the community and Federal officials for response, we were more ready.
What you do in the first minutes, hours, and days when you’re attacked is critical for your organization, Cyber Pearl Harbor or not. Especially when your systems are already stressed by natural disasters, the decisions and actions that come from you may literally mean life or death for people in your community–and certainly will affect the final cost to the organization.
But the perspective I got sitting through years of cyber risk briefings to the nation solidified that what you do in those first minutes, hours, or days until the national-level actors realize it really is Cyber Pearl Harbor will shape the entire future of the United States. The piece of evidence you snag, or the switch you turn off, or the backup phone tree you activate when email is down, could be the first in a chain of events that makes a difference for all of us.
So that’s well worth the investment of Federal appropriations. And I think it’s also well worth the investment of your time. Head over to our course page, and whether you are the hero that mitigates Cyber Pearl Harbor or you just help your organization do a little better, take stock of what you’re prepared for and what you might be able to squeeze in before September ends to up your game a little more.
By Sherman Patrick, vice president of strategic partnerships, Norwich University Applied Research Institutes