Will the shutdown drive cybersecurity experts away from the government?
From: The Washington Post/The Switch
By Andrea Peterson
Cybersecurity threats don’t just disappear during a government shutdown — in fact, some think that the shutdown increases the risks associated with digital federal infrastructure. We spoke to Mike Carpenter, President for the Americas at cybersecurity company McAfee about how the shutdown might make government cybersecurity worse. This interview has been lightly edited for length and clarity.
Andrea Peterson: Tell me a little about yourself and your role.
Mike Carpenter: I’m the President of the Americas at McAfee — been here for 12 years. Actually, my background at McAfee is that I was the VP of public sector and the VP of federal at one point. So I have a lot experience specifically in this space.
So you’ve dealt a lot with government security, I would imagine.
Yes, absolutely — both domestically and internationally.
And what have you seen in relation to cybersecurity challenges and the shutdown?
A couple different things. One is that after the president’s executive order, we started to see a lot of momentum, mainly around CDM (Continuous Diagnostics and Mitigation) and with the exfiltration from [Edward] Snowden, there’s been a lot of momentum around developing programs, policy, and measurement criteria to help start to mitigate these threats. The risk that I see with the shutdown is for every day that you have a shutdown like this, the damage is a little more punitive: You’re two days to get back on track — it’s not a day for day, if you go down for a day, you make up a day — it’s a little bit more aggressive than that because you have the momentum, impact, and beyond.
I think another piece which is interesting is that you’re in position where there’s a critical workforce that shows up which is the skeleton crew that shows up to keep everything operationally active as well as secure. That can be the target of some phishing attacks. The people that are showing up, responding to e-mails could create some targets of people with critical access who are required, which would be a good social engineering ploy to go after. So it creates vulnerabilities as much as it create opportunity.
The final piece I think is that you’re talking about a huge shortage of cybersecurity experts. And the reason that someone would come to work for the government is most importantly support of the mission, but the second piece if you surveyed them would be about stability. I think the shutdown creates a bit of a gap in that belief about job security. With the shortage of workforce that you have and the demand you have for a cybersecurity workforce, I think it’s going to open up some of the more talented cybersecurity experts to look at public versus privacy industry roles.
| Print article |