Foreign Interference In US Elections 'Will be repeated'

The United States’ former top cyber diplomat has warned that foreign interference in the US and other democratic national elections will keep happening if western countries don’t get better at imposing consequences on so-called ‘bad actors’ on the Internet.

Chris Painter, (pictured) who was until last year the Director of Cyber Issues at the US State Department and previously the head of cybersecurity in the Obama White House’s National Security Council, told SBS News that US government cyber specialists had been “caught off guard” by Russian online operations aimed at dissuading voters from voting for Hillary Clinton in favour of now President Donald Trump in the 2016 election.  

Those operations are the subject of an indictment by Special Counsel Robert Mueller which last week charged 13 Russian nationals for allegedly attempting to interfere in the US electoral process. There is the possibility that if the 13 ever travel to a third country with an extradition treaty with the US, they will have to face a US court.  

“There was some detection, our director of National Intelligence, our FBI director, our head of Homeland Security came out during the election and said this was happening,” Mr Painter said of the interference operations. 

“But what we didn’t really see coming was this hybrid attack that was cyber-enabled but also more of a traditional influence operation... I don’t think we were looking at the whole range of activity out there. I think that caught us a bit off guard but... once it was seen, there was a lot of activity to respond to it.”

Mr Painter said before the 2016 election the US cyber community was largely focused on instances or threats of more “traditional” cyber-crime.

“We were looking at things like theft of intellectual property, or intrusion and theft of personal information, credit card information; we were focused on the threat of attacks on critical infrastructure like an attack on the electrical grid or financial system,” he said.

He warned that the Russian operation will be emulated by other state and non-state groups seeking to destabilise democracies.

“This is something that absolutely will be repeated again. If there’s no consequence for this bad action it will be repeated - it’s an invitation to repeat it. So we really have to as a community in the US and around the world make sure we are doing everything we can to prevent this, both by hardening our system, and making sure there’s costs and consequences for the people who do it,”.   

But he said the Trump administration has fallen well short of an effective response.

“There’s more we can do frankly,” he said. “One of the things the US needs to do is come out with a strong declaratory statement that this activity will not be countenanced and there will be consequences. It has to come from the very top and we haven’t had that yet.”

Mr Painter was the world’s first top cyber diplomat, a job created out of the recognition that transnational crimes and threats require high-level coordination between countries. With malicious hackers or other cyber criminals operating from anywhere in the world, and often routing their attacks through countries with lax cyber jurisdictions, a single nation's law enforcement cannot achieve much without coordinating with other nations.

Since Mr Painter's 2011 appointment under former Secretary of State Hillary Clinton, at least 25 countries have followed suit, Australia included. Australia’s Ambassador for Cyber Affairs is Dr Tobias Feakin, appointed one year ago by Prime Minister Turnbull with the brief to lead a “whole of government” approach to protecting Australia’s interests and security in cyberspace.

Mr Painter is visiting Australia with the Canberra think tank the Australian Strategic Policy Institute, meeting policy-makers, researchers and bureaucrats involved in the country's cybersecurity infrastructure. He said that Australia had been responding effectively to the range of cyber threats, but that no one country has yet successfully figured out how to deter cybercrime.

“One thing we have not done well, no one in the international community has done well, is deterrence, imposing costs on adversaries when they do bad things. Calling them out is good, name and shame is part of it, but it’s not going to change your behaviour necessarily if you’re a nation state getting a benefit out of it.”

Other tools might be economic sanctions, law enforcement indictments (such as the five Chinese PLA officers indicted in the US in 2014 for industrial espionage) or offensive cyber tools which he said are more limited in use than people understand.

Despite some successes in creating what Mr Painter calls “rules of the road” in cyberspace, including a 2015 agreement between China and the US not to steal intellectual property for the benefit of the commercial sector; the international community is still grappling with the dimensions and implications of cyber threats.

UN Secretary General Antonio Guterres last week called for international rules protecting civilians from the potentially deadly impacts of cyber warfare such as attacks on power grids.

Australia is a big target of cybercriminals as a rich country that’s heavily dependent on technology. A report by Norton Cyber Security Insights released recently said more than one in four Australians were the victims of cybercrime last year, losing an average $195 each and two days dealing with the consequences. 

Australia’s mandatory data breach reporting laws has come into effect, which will force companies to reveal when they’ve been hacked. 

SBS:       Image: Nick Youngson

You Might Also Read: 

Leaked NSA Report Claims Russian 'Cyber Espionage' Against US Elections:

Hillary Clinton’s Cyber Warfare Warning:

Russian Fake Brexit Tweets & Attacks On The UK:
 

 

« Millions Of Compromised Accounts Discovered On The Dark Web
AI Will Boost Cybercrime & Security Threats »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Truth Technologies Inc (TTI)

Truth Technologies Inc (TTI)

TTI is a premier provider of worldwide anti-money laundering, anti-fraud, customer identification, and compliance products and services.

Ground Labs

Ground Labs

Ground Labs is a security software company dedicated to making sensitive data discovery products that help organisations prevent sensitive data loss.

Capita

Capita

Capita is a consulting, digital services and software business, providing end-to-end enterprise IT services and solutions focused around digital transformation and innovation.

Dark Cubed

Dark Cubed

Dark Cubed is an easy-to-use cyber security software as a service (SaaS) platform that deploys instantly and delivers enterprise-grade threat identification and protection at a fraction of the cost.

National Cyber Security Centre (NCSC) - New Zealand

National Cyber Security Centre (NCSC) - New Zealand

The role of the NCSC is to help New Zealand’s most significant public and private sector organisations to protect their information systems from advanced cyber-borne threats.

Naukrigulf

Naukrigulf

Naukrigulf.com is one of the fastest growing job sites in the Gulf, with thousands of registered job seekers and a robust CV database across many sectors, including cybersecurity.

EVOLEO Technologies

EVOLEO Technologies

EVOLEO provides engineering services covering a wide range of needs in the electronics design, embedded and systems engineering.

CHEQ

CHEQ

CHEQ provides fully autonomous, preemptive technology for brand safety and ad-fraud prevention.

Pires Investments

Pires Investments

Pires is building an investment portfolio of high-tech businesses across areas such as Artificial Intelligence, Internet of Things, Cyber Security and Augmented/Virtual Reality.

Cider Security

Cider Security

Cider Security - It’s time to revolutionize the way Security, Dev and DevOps teams work together to supercharge security at the speed of engineering.

Surfshark

Surfshark

Surfshark is a cybersecurity company focused on developing humanized privacy & security protection solutions to secure people's digital lives.

SecOps Group

SecOps Group

SecOps Group is a boutique cybersecurity consultancy helping enterprises identify & eliminate security risks on a continuous basis.

Chainguard

Chainguard

Founded by the industry's leading experts on open source software, security and cloud native development, Chainguard are on a mission to make the software supply chain secure by default.

Foresiet

Foresiet

Foresiet is the first platform to cover all of your digital risks, allowing enterprise to focus on the core business.

Silicon Valley Cybersecurity Institute (SVCSI)

Silicon Valley Cybersecurity Institute (SVCSI)

SVCSI aims to investigate, develop, and promote technical excellence and the best security practices for dependable and secure systems and applications.