Discussion about this post

User's avatar
Tracy Sanders's avatar

I completely agree that this is a governance failure issue. Also completely agree that the issue is ownership/accountability and not a funding issue. These types of problems require someone with the authority to enforce action to spend their political capital to achieve an outcome. I love it: "the failure is never that a defense was defeated. It is that no one owned the outcome."

Consistently you describe ownership of outcomes as being the differentiator. Of course, ownership also means accountability. This is no different than the BoD of an org owning risk therefore having accountability for risk in the organization. Yet we persistently see that without external enforcement either by customers driving “proof of state” transparency or perceived risk of non-compliance with insurance, that organizational leadership rarely moves to support initiatives to proactively close gaps. The security stewardship that occurs is being done by operations personnel that engage in the proactive due diligence and risk management on their own that has no additional cost to the entity so there is nothing to deny. When they have not asked for more resources, and they just do it along with everything else they are doing, it just gets done.

I can understand the cutting of CISA personnel from the perspective that the agency was politicized and used as a weapon against the American public while choosing to be completely ineffective where it could have made a difference. In a direct example I know of, CISA was provided hundreds of public facing vulnerability proofs that were all tied to a software provider servicing critical infrastructure. They were handed this issue on a silver platter with copious evidence. All they needed to do was to send letters to the software company telling them to get their act together. But instead, CISA literally closed the case. Closed the ticket without action. That is the epitome of uselessness. At one point, the head of CISA went public claiming that there was no election tampering. It was such a bald-faced lie that all credibility was removed from that individual. As the agency head, that reflected very poorly on the agency as a whole.

As with most things, the Federal government is a poor substitute for local control, local demand, local enforcement.

I took action talking to the local people who should own the accountability verification. Those people are the city, town, village administrators or executives who represent the populace. If they rely on a water utility to service their population, they should care to ask for proof of a regular vulnerability assessment and management program. If they don’t think they have the skill to do that, they should ask for residents who would be willing to volunteer to help out. But instead, I got smirks and disrespectful disregards with statements such as “the water utility is responsible for those items.”

The water utility is never going to make their attestation documentation public. If the representatives of the stakeholders do not step in and ensure accountability on those who are paid to own the problems, I'm seriously doubtful it will ever occur. The populace is equally complicit in the abdication of responsibility to demand accountability.

No posts

Ready for more?