

Guest author Bruce deGrazia, JD, CISSP, is a collegiate professor of聽cybersecurity聽management and聽policy at t 色情直播软件大全.
Every day a new cyberattack聽takes place聽somewhere in the聽United States. These attacks can originate domestically or internationally, and their motives range from financial gain to state-sponsored,聽low-level warfare.聽Whatever the threat, the common聽thread聽is聽that there is no聽easy way to stop them.
What is the solution? We鈥檝e seen聽policy approaches, including simple聽strategies聽such as聽training. We鈥檝e seen聽technical approaches, such as聽stronger firewalls.聽Also in the national cybersecurity conversation is a discussion around what is聽known as the Orlando Doctrine,聽in which聽private organizations聽can聽legally target suspected hackers and destroy their infrastructure. None of these approaches appear to聽work, as聽successful聽cyberattacks have only increased, leading experts聽to search for聽other solutions.
One of those is the聽idea of聽public-private partnerships.
A public-private partnership takes various forms,聽from the sharing of costs and profits, as聽occurs with聽a toll聽road, to the sharing of information between the private sector and the government without the fear of liability for antitrust. It is the latter type聽of public-private partnership聽that has been proposed to address cyber-vulnerabilities and attacks. The question聽is:聽Will it work?
This聽idea聽is not new. As early as 2009鈥攁 lifetime in cybersecurity聽years鈥攖he聽Intelligence and National Security Alliance (INSA), a not-for-profit organization of聽private聽sector government contractors聽in the intelligence and national security fields,聽offered聽various models of how such a partnership would work.聽INSA looked at successful partnerships in聽fields聽other聽than cybersecurity to determine whether those聽approaches聽could be transferred.聽Ultimately, it proposed聽bringing together聽a series of panels, the聽members of which would聽encompass聽individuals, private sector companies and聽government聽organizations,聽to聽share information and聽draft聽voluntary聽standards聽for use聽across industry.
INSA鈥檚聽proposal聽was聽good but聽was never implemented. To have done so would have required action not only by the聽executive聽branch聽of government, but聽also through聽legislation. In addition, the private sector, including聽internet service providers, would have needed聽to accept the concept of voluntary regulation. The聽information technology industry is vehemently opposed to regulation of any sort. Even voluntary standards were a non-starter.
Legislation has been proposed in聽Congress to create聽public-private partnerships for cybersecurity. In聽2020 and聽2021,聽the bipartisan聽聽was introduced in both the聽U.S.聽House and Senate. This bill focuses on just a single industry鈥攖he electricity creation and transmission sector鈥攂ut one that is seen as particularly vulnerable聽and for which a聽successful attack on the grid would have devastating consequences. Focus on preventing such an attack is聽a聽logical place to start.
The proposed legislation is hardly earthshaking. It simply directs the聽secretary聽of聽energy聽to create a program to聽develop a basic framework for auditing, self-assessments, training, sharing聽best practices聽and聽setting up聽third-party vendor guidelines.聽It also requests聽that the secretary聽of energy聽provide a report聽that聽evaluates聽policies and procedures for enhancing the cybersecurity of the grid.
So, what happened to the bill? In the previous Congress, it passed the House and was sent to the Senate, where it died in聽committee. In the current Congress, the bill has also passed the House and is back in the Senate鈥攗nder consideration by the same聽committee聽that previously reviewed it.
Unfortunately, the outlook for public-private partnerships聽to advance聽cybersecurity looks dim. The most comprehensive proposal,聽that of INSA,聽appears to have gone nowhere. Even approaches that target a single industry, like the bill聽now聽in the Senate, are not assured.
Perhaps the public-private partnership is not the way forward.聽We need only look as far as the INSA proposal聽to see why. Voluntary regulation is聽unpopular. Industry does not like regulation聽in general聽and will use the process to delay any attempt to impose rules. The IT industry is notoriously independent and likes it that way.聽Also,聽because there are as many cybersecurity technology solutions as there are companies, competition among the creators of those solutions is fierce. Where would the 鈥渂est practices鈥 come from?
The bottom line is that the INSA and legislative approaches presuppose a high-level of voluntary cooperation between government and the private sector.聽In our competitive marketplace, that cooperation聽is聽difficult to聽achieve聽if a trade secret might be revealed or if a company聽might聽lose a聽strategic聽advantage.