U.S. businesses on their own when facing foreign cyber attacksReprints
BOCA RATON, Fla. — Cyber attacks by nation states are a serious threat to U.S. business, and companies should not rely on the government to protect them from the attacks, said Mike Rogers, a former chairman of the House Intelligence Committee.
China, Russia, North Korea and Iran are targeting U.S. businesses, in many cases to steal intellectual property and in other cases to disrupt operations, but privacy laws in the U.S. prevent government security agencies from protecting commercial enterprises from the attacks, said the former Republican congressman from Michigan.
New technologies are becoming available to help businesses protect themselves from cyber attacks, but insurance can also be a useful tool in focusing attention on cyber security, he said Wednesday at the World Captive Forum, being held in Boca Raton, Florida.
There are numerous examples of nation states attacking U.S. companies to obtain information or to disrupt operations, Mr. Rogers said.
One of the most well-known examples is an attack on Sony Pictures Entertainment Inc., which the U.S. blamed on North Korea, in which, among other things, financial data was wiped from the company's system. Other examples include Iran reportedly attacking Las Vegas Sands Corp. in retaliation for comments made by the casino operator's CEO about Iran, and Russia attacking the Ukrainian power grid, he said.
“The world has changed. I'm not sure we are ready for it,” Mr. Rogers said, noting that 85% of U.S. networks are private-sector networks.
“The (National Security Agency) is not permitted to be on your networks; it's against the law of the United States. The only way they catch an attack coming in is if they catch it overseas first, so every American with your own network, you're on your own,” he said.
Businesses face the challenge of defending their networks from domestic and international cyber attacks every day, Mr. Rogers said.
“And the challenges are not getting smaller, they are getting bigger, and they are already thinking past you,” he said.
Technology companies are forming and producing security solutions that will offer protection, “but what we have to get the business community to understand is that the government isn't going to be able to help you,” Mr. Rogers said.
Buying cyber insurance can help concentrate the minds of executives on cyber security, he said.
“Insurance is the best way to get people involved in the fight — I have a premium and I'm accountable. Guess what — I'm going to pay attention to this,” Mr. Rogers said.