gorodenkoff/iStock.com

The US Desperately Needs a Civilian Cybersecurity Corps

Bipartisan legislation aims to augment the National Guard’s cyber reservists, but a wholly civilian component could be larger and more flexible.

The pace at which the Biden administration and the 117th Congress are addressing gaps in our national cybersecurity strategy, including by nominating and appointing incredibly talented and experienced individuals like Chris Inglis for national cyber director, Jen Easterly as director of the Cybersecurity and Infrastructure Security Agency, and Anne Neuberger for the National Security Council is impressive. And so is the pace at which our adversaries act. The clock is ticking and we must adopt a posture that is as bold, agile and creative as the criminals and nation-states that are embedded in our networks and carrying out operations against us.

Recently, a bipartisan group of lawmakers introduced legislation to create a “Civilian Cybersecurity Reserve,” a National Guard-like program under the auspices of both the Homeland Security and Defense departments to address growing cybersecurity vulnerabilities and breaches faced by the U.S. government. 

Under the bill, which is being co-sponsored by Sens. Jacky Rosen, D-Nev., and Marsha Blackburn, R-Tenn., and in the House by Reps. Jimmy Panetta, D-Calif., and Ken Calvert, R-Calif., the DOD and DHS secretaries would appoint members of the cyber reserve to six-month positions in the department as federal civil service employees. Joining the reserve corps would be voluntary and by invitation only and requires prior federal government or military service.  

This effort would augment the work being done already by the National Guard’s reserve corps, which has successfully leveraged civilian talent to build cybersecurity capability within its ranks to both defend its own networks as well as provide support when called into service by states or the federal government.  The proposal follows the recommendations of the National Commission on Military, National and Public Service, the Cyberspace Solarium Commission, and builds on the 2021 National Defense Authorization Act that directed DOD officials to look into options for building a cyber reserve force.

There is no question that finding ways to shore up cybersecurity talent and mobilize that talent in times of crisis is critical and while the Civilian Cybersecurity Reserves proposal should help address existing talent gaps when responding to federal, state and perhaps local government entities, it still leaves a critical gap with respect to cybersecurity needs in the private sector, which is under similar assault by both malicious nation-state adversaries as well as criminal organizations. While starting with a reserve corps that addresses U.S. government needs makes sense, Congress should consider quickly organizing and funding a similar program focused on private-sector needs, tapping private-sector expertise, especially with respect to technical knowledge of private-sector networks.

Today, by and large, the targets of ransomware attacks are small- and medium-sized businesses and government entities that hold valuable information but are under-resourced when it comes to IT and cybersecurity. These organizations often do not have the budget to build specialized security teams, and even if they do, have difficulty recruiting and retaining top talent. As a result of their limited resources, they have limited ability to respond to ransomware attacks in real time. Ultimately it is the communities that suffer when their schools, hospitals and small businesses are taken down by cyber adversaries. While the current proposal would potentially support municipalities in recovering from these attacks, the private-sector organizations impacted would still have to fend for themselves.

Much as there is a pool of government and military workers who can be tapped for a government reserve corps, there is a vast pool of private-sector cybersecurity talent that can be cultivated and mobilized when there is a widespread incident impacting tens of thousands of organizations simultaneously as we are experiencing right now.  

As pointed out by Natasha Cohen and Peter Singer of New America, in their proposal for a Cybersecurity Civilian Corps over two years ago, true civilian corps could tap (a) older and retired cybersecurity professionals, (b) professionals working in the cybersecurity field, with a desire to do volunteer work and perform civic service using their skills, (c) “white hat” hackers, who don’t work full time in a cybersecurity job; (e) people who are in job transition; (f) independent contractors looking to fill gaps in their time and expand their networks; and even (g) stay-at-home parents. Removing the physical fitness, citizenship, age, and clearance requirements, as well as prior government or military services, creates the opportunity to tap this vast pipeline of talent.

There is no question that the Biden administration and Congress are moving fast. But our adversaries are faster, more creative, persistent and unconstrained by law and regulation. Unless we change our approach, they will continue to identify vulnerabilities in software used across varied networks for maximum impact with little to no fear of retaliation. They will continue to advance intrusion tools and tradecraft faster than gaps in cyber defenses can be closed. They will continue to use common anonymization platforms, open source capabilities, generalized toolkits, and leverage inherent functionality built into operating systems to obfuscate their activity and make attribution difficult. They will continue to leverage our laws and regulations to enable their operations for maximum effect. And they will do all this at a pace and on a scale that will continue to be breathtaking. 

The first half of 2021 has been, should be, a wake-up call. And let’s be clear, there are no silver bullets when it comes to cybersecurity.  It will take a series of actions, persistent and purposeful, to prevent, defend and have resilience to cyber threats. The Civilian Cybersecurity Reserve proposal builds on our existing military reserve programs and it is an important step forward.  

We need to begin taking leaps.

Niloofar Razi Howe is chair of the board at Pondurance and previously served as chief strategy officer and senior vice president of strategy and operations at RSA.

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.