Srsly Risky Biz: Why two hats are better than two heads
Dec 19, 2024
auto_awesome
Explore the intriguing dynamics between the NSA and Cyber Command, where a potential split could shift priorities from intelligence collection to cyber disruption. Delve into the impact of new SEC disclosure rules that have led companies to produce vague reports, creating confusion. Discover WhatsApp’s transformation into a vital communication tool, especially in crisis situations, as it balances humanitarian uses with some troubling misapplications. The conversation highlights the need for clear guidelines and effective strategies in navigating today's cyber landscape.
The potential separation of leadership roles between US Cyber Command and the NSA could severely undermine critical intelligence capabilities and coordination.
Recent SEC disclosure rule changes have led to over-reporting of cyber incidents, diminishing the significance of actual material events in corporate communication.
Deep dives
The Implications of Splitting Cyber Command and NSA
The potential split between the heads of the NSA and Cyber Command raises significant concerns regarding the balance of priorities between the two organizations. Cyber Command, operating under a four-star general, has a mandate to execute disruptive operations, while NSA focuses on stealthy intelligence collection. The dual leadership currently in place allows for cohesive decision-making, weighing the risks of aggressive actions against the benefits of intelligence gathering. Separating these roles could jeopardize critical intelligence capabilities, as each organization relies on overlapping resources and personnel, making coordination essential for effective operations.
SEC's Cyber Incident Reporting Landscape
Recent disclosure requirements from the SEC regarding cyber incidents have led to an unexpected outcome in the reporting landscape. Over the past 11 months, out of approximately 70 reported incidents, only a small fraction were considered material, exposing a trend of over-reporting driven by CISO panic. This overuse of boilerplate language in SEC filings diminishes the significance of actual incidents, illustrating a heavy reliance on standard responses rather than substantive disclosure. Long-term, the SEC aims to improve education around reporting practices, ensuring that material incidents receive the attention they necessitate while promoting thoughtful disclosures.
The Impact of WhatsApp in Global Communication
WhatsApp has established itself as a crucial tool for communication across various contexts, especially in regions with poor connectivity. The app's design aims for reliability, enabling it to function effectively even in conflict zones or areas with intermittent internet access. This has led to its adoption by both NGOs providing aid and those perpetuating violence, highlighting its double-edged nature. The app's wide reach and versatility underline its significance in modern communication, transforming how people connect in both everyday and crisis situations.
In this podcast Tom Uren and Patrick Gray talk about the likelihood that the incoming Trump administration will end the ‘dual-hat’ arrangement where a single officer leads both US Cyber Command and the National Security Agency. This would result in Cyber Command outranking NSA and could prioritise cyber disruption operations over intelligence collection. That would be a bad outcome.
They also talk about how changes to SEC disclosure rules have led to an outpouring of corporate drivel and how WhatsApp became an everything app.