Should US Hacked Federal Employees Lose Security Clearance?

At least one federal chief information security officer is concerned about how frequently even senior-level federal employees fall for the bogus emails and is considering get-tough solutions. Paul Beckman, the Department of Homeland security’s chief information security officer, said he sends his own emails designed to mimic phishing attempts to staff members to see who falls for the scam.  

“These are emails that look blatantly to be coming from outside of DHS — to any security practitioner, they’re blatant,” he said during a panel discussion on CISO priorities at the Billington Cybersecurity Summit in Washington recently. “But to these general users” — including senior managers and other VIPs, “you’d be surprised at how often I catch these guys.”
Employees who fail the test — by clicking on potentially unsafe links and inputting usernames and passwords — are forced to undergo mandatory online security training.

But Beckman said a small number of employees continue to fall for the fake scams — even in the second of third round of phishing tests.

“There are no repercussions to bad behavior,” he said. “There’s no punitive damage, so to speak. There’s really nothing to incentivize these people to be aware, to be diligent.”

Beckman said he wants to start discussions with DHS’ chief security officer — who’s responsible for overall personnel security — about incorporating employees’ susceptibility to phishing in broader evaluations of their fitness to handle sensitive information.

“Someone who fails every single phishing campaign in the world should not be holding a TS SCI with the federal government,” he said, using the government acronym to describe a top-secret security clearance. “You have clearly demonstrated that you are not responsible enough to responsibly handle that information.”

Beckman said such discussions are still in their infancy. And not all CISOs are on board with the tough approach he advocates.

Rod Turk, the Commerce Department’s CISO, said he also runs phishing tests on his employees, but he said he views it as solely a training exercise. More broadly, federal CISOs are concerned about the increasing sophistication of phishing campaigns against high-level federal personnel. They worry the recent massive breach of background-investigation files at the Office of Personnel Management — hackers stole data on 22 million federal employees and contractors — could be used to craft even more convincing phishing attempts.

“One of the things they’re going to do with [that information], you can bet your bottom dollar, is coming up with insidious anti-phishing campaigns that look very tailored and very personal to these people,” Beckman said.

“Every bit of my personal information is in an attacker’s hands right now. They could probably craft my email that even I would be susceptible to, because they know everything about me virtually.”

Turk agreed, calling the stolen data a “a goldmine for phishing expeditions.”

DefenseOne

 

 

« These Facts Explain the Threat of Cyber Warfare
Bitcoin Made Official by US Trade Commission »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

SmartSearch

SmartSearch

SmartSearch is a leading online provider of Anti-Money Laundering and Fraud Prevention Services.

Evidian

Evidian

Evidian, a Bull Group company, is the European leader and one of the major worldwide vendors of identity and access management software.

NUS-Singtel Cyber Security R&D Lab

NUS-Singtel Cyber Security R&D Lab

NUS-Singtel Cyber Security R&D Lab conducts research into predictive security analytics.

National Cyber Security Centre Finland (NCSC-FI)

National Cyber Security Centre Finland (NCSC-FI)

The NCSC-FI develops and monitors the operational reliability and security of communications networks and services in Finland.

Chainalysis

Chainalysis

Chainalysis provides blockchain analysis software to prevent, detect and investigate cryptocurrency money laundering, fraud and compliance violations.

Defence Intelligence

Defence Intelligence

Defence Intelligence is an information security firm specializing in advanced malware protection.

National Cyber Security Authority (NCA) - Saudi Arabia

National Cyber Security Authority (NCA) - Saudi Arabia

The NCA is the government entity in charge of cybersecurity in Saudi Arabia and serves as the national authority on its affairs.

UNIDIR Cyber Policy Portal

UNIDIR Cyber Policy Portal

The UNIDIR Cyber Policy Portal is an online reference tool that maps the cybersecurity and cybersecurity-related policy landscape.

Crypto Valley Association

Crypto Valley Association

Crypto Valley Association is an independent, government-supported association established to build the world’s leading blockchain and cryptographic technologies ecosystem.

NightDragon

NightDragon

NightDragon is a venture capital firm investing in innovative growth and late stage companies within the cybersecurity, safety, security, and privacy industry.

Mitnick Security

Mitnick Security

Mitnick Security is a leading global provider of information security consulting and training services.

BlastWave

BlastWave

BlastWave’s BlastShield integrates three innovative products into a single solution to help prevent inadvertent and intentional attacks.

Vector Choice Technologies

Vector Choice Technologies

Vector Choice Technology Solutions has a long standing reputation in cyber security consulting since 2008.

AKS iQ

AKS iQ

AKS iQ leads the RegTech sector with AI, automating regulatory compliance in the banking industry and ensuring paperless TBML and CFT adherence in finance.

Illustria

Illustria

Illustria is your agent-less “watchdog” for all open source libraries. Our mission is becoming a dev-velocity company, enabled via cyber security.

Vonahi Security

Vonahi Security

Vonahi Security is a cybersecurity SaaS company that pioneered automated network penetration testing.