You choose, we deliver
If you are interested in this story, you might be interested in others from The Journal Gazette. Go to www.journalgazette.net/newsletter and pick the subjects you care most about. We'll deliver your customized daily news report at 3 a.m. Fort Wayne time, right to your email.

Editorial columns

  • Pakistani caught in diplomatic whiplash
    How could Pakistan sentence someone to 33 years in prison for helping track down Osama bin Laden? Bending over backward to be fair, you might reply:
  • The No. 1 pick for No. 2
    The most striking thing about the current Republican vice presidential field is its striking superiority to the Republican presidential field of six months ago.Former Gov. Jeb Bush, Sen. Marco Rubio, Gov. Chris Christie and Sen.
  • Rerouting budget’s flight plan
    Tired of jostling lines to board overcrowded aircraft? The taxpayers have a solution for that, but it involves flying to and from destinations like Ely, Nev., Dubois, Pa., and Hagerstown, Md.
Advertisement

Cybersecurity boost can wait no longer

In a recent briefing to Congress about worldwide threats, FBI Director Robert Mueller said that the danger of cyberattacks will equal or surpass the danger of terrorism “in the foreseeable future.” What makes that assessment particularly alarming is that the United States may be as unprepared as it was to protect against al-Qaida before Sept. 11, 2001.

Though the Pentagon has a cybercommand, it does not cover the domestic civilian economy, including vital infrastructure systems. Many of the computers controlling those utilities lack adequate security measures and could be devastated by viruses launched by hostile states or even hackers. As it is, U.S. companies are under continual assault from China and Russia, which seek to steal industrial or national security secrets and probe for infrastructure weaknesses.

Congress and the Obama administration have at least recognized the problem: Both have drawn up detailed proposals for hardening U.S. cyberdefenses. Like so much in Washington, action has been slowed by gridlock; yet senior legislators in both parties have committed themselves to passing legislation.

In fact, cyberdefense could be a signature achievement of this election year, if a few more senators can set aside partisanship and special interest appeals.

The most important – or at least, the biggest – legislation is emerging in the Senate under the sponsorship of Joe Lieberman, I-Conn.; Susan Collins, R-Maine; John Rockefeller, D-W.Va.; and Thomas Carper, D-Del. It is packed with provisions and updates to outdated legislation, but its most important sections would provide for information sharing by the government and private companies and mandate better security for critical infrastructure. (A couple of overreaching provisions in earlier legislation, such as authority for the president to halt Internet traffic in a crisis, have been dropped.)

Both areas are contentious. Fresh from blocking legislation on Internet piracy, some net purists are denouncing provisions that would make it easier for companies to tell each other, and the government, about security breaches and ways to prevent them – and mandate reporting in the event of critical breaches. While there are legitimate civil liberty concerns, it is essential that companies are able to share information about stolen data and other cyberattacks without compromising individual privacy or exposing themselves to government sanctions.

Cooperation between the government and private companies is also badly needed to ensure protection of power and water plants, banking networks and other infrastructure essential to modern society. The Senate legislation rightly gives the Department of Homeland Security, rather than the Pentagon, authority in this area and lays out an appropriately narrow definition of computer systems to be supervised: those whose interruption could cause “a mass casualty event”; “the interruption of life-sustaining services;” “mass evacuations”; or “catastrophic economic damage to the United States.”

Firms with such systems would be required to work with Homeland Security on a plan and to submit, or submit to, an audit on its effectiveness; those that fail to comply could be fined. The U.S. Chamber of Commerce and several Republican senators have objected to such Homeland Security authority, claiming it amounts to unnecessary and costly regulation.

But in the absence of government supervision, critical systems have remained unprotected. To accept the status quo would be an unacceptable risk to U.S. national security.