{"id":8252,"date":"2019-01-09T10:59:23","date_gmt":"2019-01-09T15:59:23","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=8252"},"modified":"2019-01-09T16:41:09","modified_gmt":"2019-01-09T21:41:09","slug":"the-government-shutdown-is-catastrophic-for-us-cybersecurity","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/the-government-shutdown-is-catastrophic-for-us-cybersecurity\/","title":{"rendered":"The government shutdown is catastrophic for US cybersecurity"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">While the short-term impact is jarring, the long-term effects could prove\neven more harmful<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The current US government shut down is doing serious damage\nto the US cybersecurity apparatus, but the longer-term impact could be even\nworse. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019ve paid any attention to the news in the US lately it\u2019s\nhard to ignore the massive government shutdown currently taking place. Case in\npoint, last night all of the American networks paused whatever they were\ncarrying to air a presidential address about said shutdown. Then an opposition\nresponse about the shutdown.<\/p>\n\n\n\n<p>It\u2019s kind of a big deal. <\/p><span id=\"newline\"><\/span>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignright\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"240\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/01\/bigstock-Capitol-Building-Retro-Ad-Ar-17988470-300x240.jpg\" alt=\"The government shutdown is catastrophic for US cybersecurity\" class=\"wp-image-8257\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/01\/bigstock-Capitol-Building-Retro-Ad-Ar-17988470-300x240.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/01\/bigstock-Capitol-Building-Retro-Ad-Ar-17988470-768x614.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/01\/bigstock-Capitol-Building-Retro-Ad-Ar-17988470.jpg 1000w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">My job isn\u2019t to wax philosophic about politics, so I\u2019ll just stick to the facts. The dispute is over immigration, specifically securing the United States\u2019 southern border with Mexico. The president, in keeping with a campaign promise, wants $5 billion to pay for a physical barrier, a wall, and has refused to sign any legislation to continue funding the government until he gets it. In the meantime, the US government is effectively shut down \u2013 including the State department, Justice Department, Treasury, Transportation Department, Department of the Interior, of Agriculture and of Homeland Security \u2013 and about 800,000 federal employees are currently furloughed or working without pay to carry out \u201cessential\u201d operations like air traffic control.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So today we\u2019re going to talk about what the shut down is\ndoing to the United States\u2019 cyber defenses, and what impact this could have in\nthe future. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Who is still at work?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As we discussed in November, <a href=\"https:\/\/www.thesslstore.com\/blog\/us-cybersecurity-and-infrastructure-agency-trump-signs-bill-to-place-new-agency-under-dhs\/\">the US recently created a new agency<\/a>, the Cybersecurity and Infrastructure Security Agency (CISA), under the umbrella of the Department of Homeland Security. <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>&#8220;Elevating the cybersecurity mission within the Department of Homeland Security, streamlining our operations, and giving NPPD a name that reflects what it actually does will help better secure the nation&#8217;s critical infrastructure and cyber platforms,&#8221; said NPPD Under Secretary Christopher Krebs. &#8220;The changes will also improve the Department&#8217;s ability to engage with industry and government stakeholders and recruit top cybersecurity talent.&#8221;<\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Now, not even two months later, CISA has effectively been\nknee-capped by the shutdown. As has the National Institute for Standards in\nTechnology (NIST). <\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignleft\"><img loading=\"lazy\" decoding=\"async\" width=\"250\" height=\"250\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/01\/thumbnail_CISA.jpg\" alt=\"The government shutdown is catastrophic for US cybersecurity\" class=\"wp-image-8255\"\/><\/figure><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">The Cybersecurity and Infrastructure Security Agency <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s start with CISA, the agency that has been created specifically to help with US cybersecurity. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What the federal government considers \u201cessential\u201d is a bit opaque, and purposefully so. But that does mean some of the federal security apparatus is exempt.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Per the Office of Management and Budget in a January 2018\nmemo offering guidance on a previous government shutdown:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\u201cAt a minimum, agencies must avoid any threat to the security, confidentiality and integrity of the agency information and information systems maintained by or on behalf of the government\u2026 Agencies should maintain appropriate cybersecurity functions across all agency information technology systems, including patch management and security operations center (SOC) and incident response capabilities.\u201d<\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">But, as reassuring as that may sound, it forgets two very\nimportant facts: <\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Roughly half of the federal workforce (estimates\nrange from 345,000 to 400,000) is furloughed, so these departments are not\nfunctioning at anything even close to full strength. <\/li><li>The employees that are working, currently are\nnot being paid for that work. They\u2019re working for free. And this happened right\nin the middle of the holidays. So morale is probably great.<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Now, the Senate did pass a bill that should give these\nemployees backpay, but that doesn\u2019t change the fact that these people haven\u2019t\nbeen paid in at least 18 days and this shutdown could continue for weeks. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And beyond that, even at full strength the US cyber defense apparatus is being <a href=\"https:\/\/www.thesslstore.com\/blog\/public-facing-government-websites-need-ev\/\">pushed to the brink by foreign, state-sponsored hackers and cyber cells<\/a>. So weakening it puts the whole country at greater risk.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\u201cCyber threats don\u2019t operate on Washington\u2019s political timetable, and they don\u2019t stop because of a shutdown,\u201d <a href=\"https:\/\/www.axios.com\/newsletters\/axios-codebook-024a875f-88bb-4ee8-a1ad-6426733c720c.html\">Lisa Monaco, former assistant to the president for homeland security and counterterrorism, told Axios<\/a>.<\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Or, <a href=\"https:\/\/duo.com\/decipher\/government-shutdown-impacts-enterprise-security\">as\na report from Duo Security said<\/a>:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\u201cTrying to keep networks and data safe and thwarting attacks when not at full-strength is risky, especially when no one can predict how long this state of affairs will last.\u201d<\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Right now, 45% of the Cybersecurity and Infrastructure\nSecurity Agency is furloughed. 45% is also the percentage of employees on the\nDHS\u2019 analysis and operations teams \u2013 comprised of the Office of Intelligence\n&amp; Analysis, and the Office of Operations Coordination \u2013 that are furloughed,\ntoo. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The National Protection and Programs Directorate \u2013 which handles a range of functions like the US-CERT (US \u2013 Computer Emergency Readiness Team) Continuous Diagnostics (CDM) and Automated Indicator Sharing (AIS) programs \u2013 has a whopping 85% of its workforce furloughed. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And depending on how long this shutdown continues, we could see a lot of these agencies that are currently operating on short-term reserves run out of money and be forced to shutter even more of their operations.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignright\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"300\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/01\/logo-nist-300x300.png\" alt=\"The government shutdown is catastrophic for US cybersecurity\" class=\"wp-image-8256\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/01\/logo-nist-300x300.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/01\/logo-nist.png 420w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/figure><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">The National Institute of Standards in Technology<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">NIST is the agency responsible for setting standards. For instance, <a href=\"https:\/\/www.thesslstore.com\/blog\/what-are-nist-encryption-standards\/\">it\u2019s issued extensive guidance on encryption standards<\/a> that has helped inform the industry standards set forth by the CA\/B Forum. It\u2019s an exceedingly useful agency and it has been thoroughly depleted by this shutdown. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">85% of NIST is furloughed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That means a number of new standards that have been under review \u2013 standards that businesses rely on to set a baseline for their own security programs \u2013 are now on indefinite hold. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That includes: <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/csrc.nist.gov\/projects\/risk-management\/risk-management-framework-(rmf)-overview\">The\nrisk management framework<\/a> <\/li><li><a href=\"https:\/\/nvd.nist.gov\/800-53\">Changes to\nthe federal government\u2019s guidelines on security controls<\/a><\/li><li><a href=\"https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-171\/rev-1\/final\">Requirements\nto access controlled unclassified information<\/a><\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Currently, clicking any of those links effectively leads you\nto a dead end courtesy of this shutdown.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"742\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/01\/Dead-end-1024x742.jpg\" alt=\"\" class=\"wp-image-8253\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/01\/Dead-end-1024x742.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/01\/Dead-end-300x217.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/01\/Dead-end-768x556.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/01\/Dead-end.jpg 1031w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">There are a few NIST services that will stay open, but to say they are lightly staffed would be a profound understatement. <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>A computer scientist and an IT specialist will\nmanage the National Vulnerability Database<\/li><li>16 employees will manage NIST\u2019s time servers<\/li><li>And an IT specialist will be present at the\nNational Cybersecurity Center of Excellence<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">That\u2019s one of those tidbits of information that is supposed to make you feel better but actually just makes everything seem worse. That\u2019s less than 20 people handling critical functions for a country of nearly 300,000,000.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The real damage this shutdown may cause is long-term<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Eventually, possibly as soon as today, this shutdown will\nend. But it\u2019s also quite possible that it stretches on days or even weeks\nlonger. With every passing day, more and more long-term damage to the US\nnational cybersecurity apparatus is being done. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s why: <strong>If you\u2019re a talented cybersecurity professional, why would you ever work for the US government?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That may sound silly or unpatriotic, but ask any of the nearly 400,000 federal employees that didn\u2019t get paid over the holidays if their patriotism took care of their power bill or put food on their family\u2019s table? <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">No, patriotism is going to give way to pragmatism, and let\u2019s\nlook at the facts:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignleft\"><img loading=\"lazy\" decoding=\"async\" width=\"196\" height=\"257\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/01\/uncle-sam.jpg\" alt=\"The government shutdown is catastrophic for US cybersecurity\" class=\"wp-image-8254\"\/><\/figure><\/div>\n\n\n\n<ul class=\"wp-block-list\"><li>You could go to the private sector where you\u2019ll\nbe better compensated with more opportunities for advancement.<\/li><li>You could work for the government where your ability\nto work and be paid are subject to the partisan whims of elected officials. <\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">And here\u2019s the real match in the powder barrel, all of those\ngovernment officials whose whims have cost you pay and potentially even caused\nyou to have to work for free \u2013 they\u2019re all getting paid.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Congress and the Executive Branch have already been funded\nvia a previous spending bill.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And while historically the federal employees that are\ncurrently affected \u2013 both furloughed and working without pay \u2013 have been given\nbackpay to compensate, the timing of that backpay is contingent upon the\nshutdown ending and Congress passing a bill (oh, and the wheels of bureaucracy churning)\nbefore you actually see that money.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Already, they\u2019ve missed an entire pay period (December\n23-January 5). <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">None of that is going to attract the best and brightest. And\nwhy should it? The average American couldn\u2019t scrape together $400 in an\nemergency, try taking away an entire paycheck. That\u2019s the type of uncertainty\nyou\u2019d do well to avoid.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And this is not without precedent, the NSA got hammered\nfollowing the 2013 shutdown. For one, it caused management to divide employees\ninto \u201cessential\u201d and \u201cnon-essential\u201d categories \u2013 not exactly a shot in the arm\nfor morale \u2013 and the 16 days out of work threw many lives into disarray.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\u201cI was paying money out of my pocket\u2026 The guys were sitting at home, they couldn\u2019t go work with the shutdown because they had to work from government spaces, so they really could not go,\u201d <a href=\"https:\/\/www.buzzfeednews.com\/article\/kevincollier\/the-last-government-shutdown-rocked-the-nsa-another-will\">one former NSA employee who left following the 2013 shutdown told Buzzfeed<\/a>. \u201cI can say anecdotally, because I do know several guys who worked there who went off on their own around 2013, 2014. There was a bigger exodus than normal, and you\u2019ve gotta [sic] figure at least some of that was due to the shutdown and guys going \u2018screw this.\u2019\u201d<\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">The current shutdown has already gone on two days longer and if a morning conference between the president and the two leaders of the congressional democrats doesn\u2019t solve things\u2014it could go on much longer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">UPDATE: <a href=\"https:\/\/www.cnn.com\/2019\/01\/09\/politics\/chuck-schumer-nancy-pelosi-trump\/index.html\">It didn&#8217;t solve things<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the meantime \u2013 and possibly for the foreseeable future \u2013 our\nnational cyber defenses will suffer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>As always, leave any comments or questions below\u2026<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"267\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-1024x267.jpg\" alt=\"Hashed Out by The SSL Store is the voice of record in the SSL\/TLS industry.\" class=\"wp-image-7276\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-1024x267.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-300x78.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-768x200.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568.jpg 1559w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>While the short-term impact is jarring, the long-term effects could prove even more harmful The current US government shut down is doing serious damage to the US cybersecurity apparatus, but&#8230;<\/p>\n","protected":false},"author":6,"featured_media":8258,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[16],"tags":[3367],"class_list":["post-8252","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hashing-out-cyber-security","tag-us-government","post-with-tags"],"views":15187,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/01\/bigstock-Government-Shutdown-And-Usa-Cl-275433343.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/8252","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=8252"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/8252\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/8258"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=8252"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=8252"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=8252"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}