Anatomy of an "Aggressive" Cybersecurity Measure by the Razorbacks

Where: Arkansas

The legislation: Senate Bill 632 (2019 | AR)

What does SB632 do?

  • Creates the Cyber Initiative
  • Housed within the Economic Development Commission
  • mitigate the cyber-risks to Arkansas
  • increase education relative to threats and defense
  • provide the public and private sectors with threat assessments and other intelligence
  • foster growth and development around tech, IT and defense
  • create a “cyber alliance” made up of partnerships with a variety of insitutitions like…

Regulatory TREND. What do I need to know about Active Cyber Defense?

Active Cyber Defense uses private sector cyber bounty hunters and hackers  to protect critical infrastructure.

Who is behind this concept?

  • An Atlantic Council report,
  • by, Frank Kramer, Assistant Secretary for International Security Affairs for the Clinton administration
  • and by, Bob Butler, Deputy Assistant Secretary for Space and Cyber in the Obama administration

How would this private sector system work?  the private sector hackser would be deputized  “certified active defenders” to assist…

Local TREND. It's Official. City Bans Facial Recognition

Where: San Francisco

What else does the ban on facial recognition tech by municipal entities and local law enforcement do ? 

  • requires disclosure of surveillance technology they currently use
  • requires approval from the Board of Supervisors on any new technology that either collects or stores someone’s data

What are supporters saying?

  • “This is really about saying we can have security without being a security state.”
  • “We can have good policing without being a police state.”

2 More cities set…

Regulatory TREND. Anatomy of a State Cyber Office. How to hold agencies accountable to the Executive Branch?

West Virigina HB 2452 (2019 |WV)  created the a new Cybersecurity Office within the Office of Technology.

Goals of the a new Cybersecurity Office:

  • risk assessment across state agencies
  • establish unifying security standards among state agencies
  • will leverage a risk management approach
  • provide for “apples-to-apples comparison of cyber-risk assessments across all agencies within the Executive Branch.”  

Stems from WV’s 2018 particiaption in the National Governors Association (NGA)…

3 Reasons States Should Act on Cybersecurity Standards

  • Timely. All 6 US Senators running for President in 2020 are cosponsors of cybsercurity legislation
  • History of federal Action. Standardizing cybersecurity practices at the federal level is difficult
  • Agency infighting  is creating disparate standards
  • State Success. State leaders have pushed legislative success to protect its citizens like:
    • TX, IL, WA and MA protecting biometric data
    • OH liability protection law
    • CA version of GDPR

The Hill | Why states should push forward with cyber laws

Lege TREND. Public Private Cyber WorkForce Exchange

WHAT: Cyber Security Exchange Act,”

Bipartisan? Yes, Senators Thune (R) & Klobuchar (D)

How does the Cyber security Exchange work?

  • create an exchange program between the federal government and private firms
  • to bring more cybersecurity expertise to the federal workforce
  • The program would allow for a 2 year tours of duty with the federal government

 

The Hill | Bipartisan bill would create public-private cyber workforce exchange

Procurement Opportunity State Employee Cyber Security Training

What are states doing to train their employees to protect data?

  • Michigan, Oklahoma and Wyoming encourage but don’t require training
  • Idaho Governor Excutive order requires training for all executive staff
  • Illinois in 2017 made cybersecurity training mandatory for state employees
  • Indiana’s CIO has authority to make training mandatory for state employees
  • Utah sends out phony phishing emaisl to state employees to test them
  • CT offers voluntary training every 2 months
  • Alabama offers daily…

3 Ways States Benefit from a State Data Officer.

 

  • data helps create more efficient permitting processes
    • CT allows local governments to get occupational licensing data directly form the state
  • overdose data helps first responders and hospitals prepare for epidemics
  • Prevent fraud 
    • IN adopted its Indiana’s Management and Performance Hub to “integrate” data from several agencies to build custom analytics solutions.” Its addressing issues from car crashes and infant mortality to Medicaid optimization.
    • TX shared data across agencies…