Should US Hacked Federal Employees Lose Security Clearance?

At least one federal chief information security officer is concerned about how frequently even senior-level federal employees fall for the bogus emails and is considering get-tough solutions. Paul Beckman, the Department of Homeland security’s chief information security officer, said he sends his own emails designed to mimic phishing attempts to staff members to see who falls for the scam.  

“These are emails that look blatantly to be coming from outside of DHS — to any security practitioner, they’re blatant,” he said during a panel discussion on CISO priorities at the Billington Cybersecurity Summit in Washington recently. “But to these general users” — including senior managers and other VIPs, “you’d be surprised at how often I catch these guys.”
Employees who fail the test — by clicking on potentially unsafe links and inputting usernames and passwords — are forced to undergo mandatory online security training.

But Beckman said a small number of employees continue to fall for the fake scams — even in the second of third round of phishing tests.

“There are no repercussions to bad behavior,” he said. “There’s no punitive damage, so to speak. There’s really nothing to incentivize these people to be aware, to be diligent.”

Beckman said he wants to start discussions with DHS’ chief security officer — who’s responsible for overall personnel security — about incorporating employees’ susceptibility to phishing in broader evaluations of their fitness to handle sensitive information.

“Someone who fails every single phishing campaign in the world should not be holding a TS SCI with the federal government,” he said, using the government acronym to describe a top-secret security clearance. “You have clearly demonstrated that you are not responsible enough to responsibly handle that information.”

Beckman said such discussions are still in their infancy. And not all CISOs are on board with the tough approach he advocates.

Rod Turk, the Commerce Department’s CISO, said he also runs phishing tests on his employees, but he said he views it as solely a training exercise. More broadly, federal CISOs are concerned about the increasing sophistication of phishing campaigns against high-level federal personnel. They worry the recent massive breach of background-investigation files at the Office of Personnel Management — hackers stole data on 22 million federal employees and contractors — could be used to craft even more convincing phishing attempts.

“One of the things they’re going to do with [that information], you can bet your bottom dollar, is coming up with insidious anti-phishing campaigns that look very tailored and very personal to these people,” Beckman said.

“Every bit of my personal information is in an attacker’s hands right now. They could probably craft my email that even I would be susceptible to, because they know everything about me virtually.”

Turk agreed, calling the stolen data a “a goldmine for phishing expeditions.”

DefenseOne

 

 

« These Facts Explain the Threat of Cyber Warfare
Bitcoin Made Official by US Trade Commission »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Research Institute in Trustworthy Industrial Control Systems (RITICS)

Research Institute in Trustworthy Industrial Control Systems (RITICS)

RITICS is one of three Research Institutes formed as part of the UK National Cyber Security Strategy.

MixMode

MixMode

MixMode's PacketSled platform delivers network monitoring, deep forensic analysis and incident response.

Panaseer

Panaseer

Panaseer is an enterprise cybersecurity automation and data analytics company that helps organizations stop preventable breaches by ensuring security controls are working effectively.

Virgil Security

Virgil Security

Virgil Security provides easy-to-deploy and easy-to-use cryptographic software and services for use by developers and end-users.

SANS CyberStart

SANS CyberStart

SANS CyberStart is a unique and innovative suite of tools and games designed to introduce children and young adults to the field of cyber security.

TitanHQ

TitanHQ

TitanHQ offers ultimate protection from internet based threats and powerful Web filtering functionalities to SMBs, Service Providers and Education sectors around the World.

ENAC

ENAC

ENAC is the national accreditation body for Spain. The directory of members provides details of organisations offering certification services for ISO 27001.

GreenWorld Technologies

GreenWorld Technologies

GreenWorld has a proven track record in industry leading IT asset management, secure data destruction and remarketing.

Tines

Tines

The Tines security automation platform helps security teams automate manual tasks, making them more effective and efficient.

SAP National Security Services (NS2)

SAP National Security Services (NS2)

SAP NS2 are dedicated to delivering the best of SAP innovation, from cloud to predictive analytics; machine learning to data fusion.

Dynics

Dynics

The Dynics ICS-Defender is an Industrial Control System Security Appliance for OT or OT/IT convergent environments.

Adit Ventures

Adit Ventures

Adit Ventures is a venture capital firm with a focus on dynamic growth sectors including AI & Machine Learning, Big Data, Cybersecurity and IoT.

Brace168

Brace168

Specialising in Cyber Security incident identification and response, Brace168 is uniquely positioned to provide a vast experience in managed security services to meet the needs of all business types.

V3 Cybersecurity

V3 Cybersecurity

V3 Cybersecurity is a unique company focused on contextualization of security programs from a business perspective. Our mission is to provide enterprise IT Risk Management capabilities.

Diversified Search Group - Alta Associates

Diversified Search Group - Alta Associates

Diversified Search Group is an industry leader in recruiting diverse, inclusive and transformational leadership for clients.

Inveo Group

Inveo Group

Inveo group is the Italian leader for the management of privacy and data protection issues.