Previous All Posts Next

Government Shutdown Creates Cybersecurity Gaps

Posted: January 14, 2019 to Cybersecurity.

Tags: NIST, Work from Home, Data Breach

The prolonged and ongoing government shut down due to a standoff between President Trump and Congress is affecting more than just 800,000 government paychecks and border walls.  The shutdown is affecting key agencies that control cybersecurity, such as the Department of Homeland Security, and compromised government cyber systems are the root of anxiety for many. Tom Kellerman, chief cybersecurity officer for Carbon Black, stated that he is not sleeping well in light of the shutdown-caused vulnerability.  With Chinese, Russian, and North Korean cyber sieges in full force, Kellerman says that when the shutdown is called off, the first order of business needs to be compromise assessment and infiltration suppression. Michael Daniel, CEO of the Cyber Threat Alliance and former White House cybersecurity coordinator, expressed his concern over the threat.  “Like so many areas across the government, over time a shutdown will steadily erode the federal government’s cybersecurity readiness.”  Much of the U.S. government’s science laboratory, NIST, is furloughed for the shutdown duration, and many countries outside of the U.S. depend on NIST’s guidelines on computer security to secure their own systems.  “New policy work is essentially frozen,” says Daniel, “so needed changes or updates to existing policies will not occur, nor will the government develop policies to address new areas. Some areas of NST will remain in operation during the shutdown, such as the timing infrastructure that is essential for synchronizing computer clocks.  The National Vulnerability Database also remains open.  Also, the U.S. Computer Emergency Readiness Team, which is part of the Department of Homeland Security, is continuing to publish alerts. Daniel also voiced concerns over the viability of Trump’s new organization- the Cybersecurity and Infrastructure Security Agency (CISA) that was signed into Act in November 2018.  With 45% of its staff furloughed, Daniel feels the new agency will have a difficult time catching up once funding returns. “Over time, personnel slots will go unfilled and contracts will expire,” says Daniel, “making it difficult to sustain a workforce or upgrade equipment.” More than 80 TLS government certificates for .gov websites have not been renewed, making them inaccessible to parties outside the U.S.  “Dozens of U.S. government websites have been rendered either insecure or inaccessible during the ongoing U.S. shutdown,” says Netcraft, a U.K. anti-cybercrime firm.  “These sites include sensitive government payment portals and remote access services, affecting the likes of NASA, the U.S> Department of Justice, and the Court of Appeals.” Even the FBI is feeling the pains of a prolonged shutdown.  The Bureau is having difficulty running operations and paying informants.  Failing to pay employees during the prolonged furlough also damages the government’s hiring pool as many government workers will defect to private sector employers that pay more and do not shut down.  Especially in a fast-growing field like cybersecurity.

Protect Your Business Today

Petronella Technology Group has provided cybersecurity, compliance, and managed IT services from Raleigh, NC for over 23 years. Contact us today for a free consultation and technology assessment.

Need help implementing these strategies? Our cybersecurity experts can assess your environment and build a tailored plan.
Get Free Assessment

About the Author

Craig Petronella, CEO and Founder of Petronella Technology Group
CEO, Founder & AI Architect, Petronella Technology Group

Craig Petronella founded Petronella Technology Group in 2002 and has spent more than 30 years working at the intersection of cybersecurity, AI, compliance, and digital forensics. He holds the CMMC Registered Practitioner credential (RP-1372) issued by the Cyber AB, is an NC Licensed Digital Forensics Examiner (License #604180-DFE), and completed MIT Professional Education programs in AI, Blockchain, and Cybersecurity. Craig also holds CompTIA Security+, CCNA, and Hyperledger certifications.

He is an Amazon #1 Best-Selling Author of 15+ books on cybersecurity and compliance, host of the Encrypted Ambition podcast (95+ episodes on Apple Podcasts, Spotify, and Amazon), and a cybersecurity keynote speaker with 200+ engagements at conferences, law firms, and corporate boardrooms. Craig serves as Contributing Editor for Cybersecurity at NC Triangle Attorney at Law Magazine and is a guest lecturer at NCCU School of Law. He has served as a digital forensics expert witness in federal and state court cases involving cybercrime, cryptocurrency fraud, SIM-swap attacks, and data breaches.

Under his leadership, Petronella Technology Group has served 2,500+ clients, maintained a zero-breach record among compliant clients, earned a BBB A+ rating every year since 2003, and been featured as a cybersecurity authority on CBS, ABC, NBC, FOX, and WRAL. The company leverages SOC 2 Type II certified platforms and specializes in AI implementation, managed cybersecurity, CMMC/HIPAA/SOC 2 compliance, and digital forensics for businesses across the United States.

CMMC-RP NC Licensed DFE MIT Certified CompTIA Security+ Expert Witness 15+ Books
Related Service
Protect Your Business with Our Cybersecurity Services

Our proprietary 39-layer ZeroHack cybersecurity stack defends your organization 24/7.

Explore Cybersecurity Services
Previous All Posts Next
Free cybersecurity consultation available Schedule Now