Back to news

November 21, 2018 | International, C4ISR

Disruptive technologies show why government needs data security standards now

By:

Telepathy. Data uploading to the brain. Even humanoid sex robots. These are among the ideas that exist on a periodic table of disruptive technologies, a new visual guide that predicts what will alter human existence in the coming years.

Created by Imperial College London, the table identifies what is set to change societies in the short term (smart controls and appliances), as well as fringe ideas that are decades away from existence, if they will exist at all (think force fields.)

Yet the disruption could turn disastrous without proper data-security standards, according to one of the chart's creators, Richard Watson, the futurist in residence at Imperial College London.

“There is very little here that is not in some way digital and connected, which makes it vulnerable,” Watson said.

“Any kind of internet-of-everything device doesn't really work if you haven't got common standards — if Apple isn't sharing with Google and the French aren't sharing with the Germans.”

Experts have long expressed concern about the lack of data standards for internet-connected devices. There is no international standard for data security. And U.S. government oversight of internet-connected devices is spread across at least 11 different federal agencies, according to a 2017 Government Accountability Office report.

“As new and more ‘things' become connected, they increase not only the opportunities for security and privacy breaches, but also the scale and scope of any resulting consequences,” the report said.

And there has been a flurry of cyberattacks using internet-connected devices. Some hackers are exploiting smart devices as an intermediary to attack computer networks, the FBI warned Aug. 2. Ninety-three percent of respondents told Armis, a security platform, in an August survey that they expected governments to exploit connected devices during a cyberattack.

The Imperial College London chart offers a further glimpse at how important it may be to create these common regulations by imagining a wealth of potential breach points. Watson listed some of the table's future technologies that could be hacked.

“Smart controls and appliances.”

Hackable.

“Autonomous robotic surgery.”

Hackable.

“Autonomous ships and submarines.”

Hackable.

“One of the issues with the stuff on here is that it relies on extremely good data security,” Watson said.

The problem with having a developing ecosystem without global standards is that a single vulnerability could allow access to more than one network, and government officials and businesses are currently taking a strategy of letting the private sector debate how, or if, to regulate itself when it comes to internet-connected devices.

One piece of bipartisan federal legislation, the 2017 Internet of Things Cybersecurity Improvement Act, mandates that “devices purchased by the U.S. government meet certain minimum security requirements," but it has stalled in Congress.

As a first step, manufacturers should collaborate to establish device security baselines, Jing de Jong-Chen, general manager for global cybersecurity at Microsoft, said during a June conference hosted by the Woodrow Wilson Center, a Washington, D.C.-based think tank.

One private solution is a set of common guidelines developed by the IEEE Standards Association, an industry trade organization. The trade association's voluntary standards is evidence of a fear of government regulation that the private sector is openly hostile to. During the June event, the idea of government regulation of smart devices was laughed at by private sector officials in the room. But that laughter may have been premature.

In September 2018, California Governor Jerry Brown approved a bill that requires companies to install connected devices with “a reasonable security feature” protecting it against unauthorized access. The bill means that the periodic table of disruptive technologies may eventually be impacted by a modicum of public regulation, although it is not clear if that will be effective.

Not making it any easier is that no amount of planning can compensate for every technological innovation. For example, when it comes to the most disruptive future technology, the chart is secretive. In position 100, predicted to be the most innovative idea, the chart says it is too dangerous to publish. “We can't talk about this one,” it reads.

In this instance, however, a potential security risk is averted. When asked if this technology is the one that will literally “break the internet,” Watson is forced to make a confession: “It's a joke. It's just us dodging the ball because we couldn't think of what to put there.”

https://www.fifthdomain.com/industry/2018/11/20/disruptive-technologies-show-why-government-needs-data-security-standards-now/

On the same subject

  • Contract Awards by US Department of Defense - December 15, 2020

    December 17, 2020 | International, Aerospace, Naval, Land, C4ISR, Security

    Contract Awards by US Department of Defense - December 15, 2020

    DEFENSE LOGISTICS AGENCY Thomas Scientific LLC, Swedesboro, New Jersey, has been awarded a maximum $105,820,000 firm-fixed-price, indefinite-delivery/indefinite-quantity contract for nasopharyngeal swabs. This was a sole-source acquisition using justification 10 U.S. Code 2304(c)(2), as stated in Federal Acquisition Regulation Part 6.302-2. This is a four-month contract with a three-month option period. Location of performance is New Jersey, with an April 24, 2020, ordering period end date. Using customers are Veterans Administration, Indian Health Service, Department of Justice, Department of Homeland Security, Department of Health and Human Services and Department of Defense. Type of appropriation is fiscal 2021 defense working capital funds. The contracting activity is the Defense Logistics Agency Troop Support, Philadelphia, Pennsylvania (SPE2DP-21-D-0004). Fidelis Sustainability Distribution LLC, Carson City, Nevada, has been awarded a maximum $45,000,000 fixed-price with economic-price-adjustment, indefinite-delivery/indefinite-quantity contract for various robotic surgery systems and associated hardware, software and consumable items. This was a competitive acquisition with 105 offers received. This is a five-year contract with no option periods. Locations of performance are Nevada and Illinois, with a Dec. 14, 2025, ordering period end date. Using customers are Army, Navy, Air Force, Marine Corps and federal civilian agencies. Type of appropriation is fiscal 2021 through 2026 defense working capital funds. The contracting activity is the Defense Logistics Agency Troop Support, Philadelphia, Pennsylvania (SPE2D1-21-D-0002). Silver Oak Leaf Inc.,** Alpharetta, Georgia, has been awarded a maximum $13,534,957, firm-fixed-price, indefinite-delivery/indefinite-quantity contract for coats and trousers. This is a two-year base contract with one two-year option period. This was a competitive acquisition with two responses received. Locations of performance are Georgia and Puerto Rico, with a Dec. 14, 2022, ordering period end date. Using military services are Army and Air Force. Type of appropriation is fiscal year 2021 through 2023 defense working capital funds. The contracting activity is the Defense Logistics Agency Troop Support, Philadelphia, Pennsylvania (SPE1C1-21-D-1407). Innovative Federal Operations Group Inc., Carlsbad, California, has been awarded a maximum $7,557,359 firm-fixed price, definite-quantity contract for disposable protective coveralls. This was a competitive acquisition with seven responses received. Locations of performance are California and Turkey, with a Jan. 14, 2021, performance completion date. Using customer is Federal Emergency Management Agency. Type of appropriation is fiscal 2021 defense working capital funds. The contracting activity is the Defense Logistics Agency Troop Support, Philadelphia, Pennsylvania (SPE1C1-21-C-0003). AIR FORCE The Boeing Co., St. Louis, Missouri, has been awarded a $46,890,000 firm-fixed-price contract for the F-15 Qatar program. This contract provides for the Foreign Military Sales (FMS) requirement to procure Digital Electronic Warfare System spares for the Qatar Emiri Air Force. Work will be performed in St. Louis, Missouri, and is expected to be completed Aug. 23, 2023. This award is the result of a sole-source acquisition. FMS funds in the amount of $22,976,100 are being obligated at the time of award. The Air Force Life Cycle Management Center, Wright-Patterson Air Force Base, Ohio, is the contracting activity (FA8634-18-C-2701). The Boeing Co., St. Louis, Missouri, has been awarded a $17,764,388 fixed-price-incentive-firm, cost-plus-incentive-fee, cost-plus-fixed-fee modification (P00009) to contract FA8634-18-C-2697 for infrared search and track to upgrade the current Air Force design equivalent of the Navy Block II configuration. This contract will retrofit the production ship sets by modifying the Block I Legion Pod with a replacement of the infrared receiver processor with the V3 infrared receiver and V3 processor from the Navy Block II and modified cabling harness within the pod structure. Work will be performed in St. Louis, Missouri, and is expected to be completed October 2022. This award is the result of a sole-source acquisition. Fiscal 2019 National Guard and Reserve equipment defense funds in the full amount are being obligated at the time of award. The F-15 Division Contracts Branch, Wright-Patterson Air Force Base, Ohio, is the contracting activity. NAVY Saxman One LLC, Manassas, Virginia, is awarded a $50,750,000 indefinite-delivery/indefinite-quantity contract for the Navy Internship and Apprenticeship Programs. This contract provides for the promotion of student internship opportunities such as the Science and Engineering Internship Program (SEAP), the Naval Research Enterprise Internship Program (NREIP), Naval Horizons and other short-term internship programs. The work to be performed includes web site development, provide customer service, increase program awareness, develop virtual training opportunities, provide intern notification, make payment of intern stipends, work with Naval Commands to obtain the proper security paperwork for the intern(s), coordinate internship agreements and provide reports to the Office of Naval Research. Work will be performed in Manassas, Virginia, and is estimated to be completed by Dec. 15, 2025. The total cumulative value of this contract is $50,750,000. Fiscal 2021 research, development, test and evaluation (Navy) funds in the amount of $125,000 are being obligated on a task order on a cost-plus-fixed-fee basis at the time of award. These funds will not expire at the end of the current fiscal year. This contract was solicited on a sole-source basis using an Alaska Native Corporation in accordance with 13 Code of Federal Regulations 124.506(b). The Office of Naval Research, Arlington, Virginia, is the contracting activity (N00014-21-D-4002). CSRA LLC, a General Dynamics Information Technology Co., Falls Church, Virginia, is awarded a $28,092,546 modification to previously awarded indefinite-delivery/indefinite-quantity (IDIQ) contract N00039-17-D-0002 to extend network and information technology services being provided under the Outside Continental U.S. Navy Enterprise Network (ONE-Net) contract. The services provided under ONE-Net include service desk support, networks and systems operations support, field services support, information assurance services support, network technical support, business management office support, Tier II/III support, Tier IV support and host based security system support. Work will be performed in various locations outside the U.S. based on the requirement for each task order placed. Work is expected to be completed by September 2021. The total cumulative value of this contract is an estimated $171,828,967. No contract funds will be obligated on the base contract at the time of award. Contract funds will be obligated on individual task orders and will at the end of the fiscal year. This modification extends the period of performance of the contract by adding Option Period Five (Dec. 28, 2020, to June 27, 2021) with a ceiling of $17,717,296; and Option Period Six (June 28, 2021, to Sept. 30, 2021) with a ceiling of $10,375,250, which are both exercised with award of this modification. The contract type of the modification is an IDIQ hybrid contract with firm-fixed-price and cost only contract line item numbers. This contract includes options, which are being exercised at the time of award of this modification. This contract was not competitively procured because it is a sole-source acquisition pursuant to the authority of 10 U.S. Code 2304(c)(1) - only one responsible source (Federal Acquisition Regulation subpart 6.302-1). The Naval Information Warfare Systems Command, San Diego, California, is the contracting activity. Bell Textron Inc., Fort Worth, Texas, is awarded a $22,791,652 cost-plus-fixed-fee order (N00019-21-F-0228) against previously issued basic ordering agreement N00019-16-G-0012. This order provides engineering and logistics support, procures four resident integrated logistics support detachment computer seats, trailer lease site for flight test engineers, support equipment workaround material and aircraft wiring integration remote terminal and flight control computer test station material in support of Marine Corps (USMC) AH-1Z; the governments of Bahrain and the Czech Republic UH-1Y and AH-1Z production aircraft; and USMC UH-1Y and AH-1Z aircraft modifications and sustainment. Work will be performed in Fort Worth, Texas (70%); and Patuxent River, Maryland (30%), and is expected to be completed in February 2022. Fiscal 2021 operation and maintenance (Navy) funds in the amount of $957,796; fiscal 2021 aircraft procurement (Navy) funds in the amount of $703,526; fiscal 2019 aircraft procurement (Navy) funds in the amount of $14,842,613; and Foreign Military Sales funds in the amount of $2,645,319 will be obligated at time of award, $15,800,409 of which will expire at the end of the current fiscal year. The Naval Air Systems Command, Patuxent River, Maryland, is the contracting activity. The Boeing Co., Huntington Beach, California, is awarded a $8,000,000 fixed-price incentive (firm target) undefinitized contract modification to previously awarded contract N00024-17-C-6307 for extra-large unmanned undersea vehicle maintenance analyses and logistics products. Work will be performed in Newport News, Virginia (52%); and Huntington Beach, California (48%), and is expected to be completed by December 2022. Fiscal 2020 research, development, test, and evaluation (Navy) funds in the amount of $4,000,000 will be obligated at time of award and will expire at the end of the current fiscal year. The Naval Sea Systems Command, Washington, D.C., is the contracting activity. *Small business **Service-disabled veteran-owned small business https://www.defense.gov/Newsroom/Contracts/Contract/Article/2447883/source/GovDelivery/

  • Thales launches a new integrated 24/7 NOC-SOC in the Netherlands

    July 24, 2020 | International, C4ISR, Security

    Thales launches a new integrated 24/7 NOC-SOC in the Netherlands

    July 21, 2020 - Thales has expanded managed services for its customers with the launch of a new integrated Network Operations Center (NOC)/ Cybersecurity Operations Center (SOC) in the Netherlands. With trained experts present 24/7, the integrated NOC-SOC can provide organisations with premium services for IS-IT asset management and cybersecurity supervision, a critical necessity following the explosion of remote working during the Covid-19 crisis. With more than 40 years of expertise, Thales already serves more than 40 clients around the world through its five existing Cybersecurity Operations Centres (Canada, France, Hong Kong, Netherlands, United-Kingdom). Forming part of Thales's international network of premium Cybersecurity Operations Centres, the Group's first integrated Network Operations Centre (NOC) and Security Operations Centre (SOC) will simultaneously monitor customers' IT and OT infrastructure 24/7. Since IT/OT assets in the new NOC/SOC are monitored from the Netherlands, data remain in the country and sensitive information is viewed only by screened personnel. Being able to deliver these secure integrated managed services in the Netherlands is a first for Thales. As a rule, organisations outsource night-time monitoring to SOCs in other countries. From now on, Thales will be able to offer this service for and from the Netherlands. The NOC currently analyses anonymised transaction data from public transport companies 24/7 in order to rectify faults, and the SOC focuses on monitoring the computer and network activities of critical infrastructure companies, while keeping the networks physically separate. The NOC monitors mainly systems availability, while the SOC monitors cyber security. This enables both services to intervene quickly in the event of an incident, shortening any downtime and reducing damage. Now the two centres have been merged so that the teams have everything at their disposal to further optimise service levels and meet the highest standards of security. SOC and NOC employees are screened and trained to meet far-reaching Dutch quality standards and SOC services fully comply with Dutch legislation and regulations (ISO 27001 and NEN 7510). Thales has more than 15 years' experience in managed cybersecurity services worldwide. The Group is positioned as the trusted partner of choice for the most demanding organisations worldwide in terms of cybersecurity, operating five premium Cybersecurity Operations Centers around the world, in France, the United Kingdom, the Netherlands, Canada and Hong Kong. "I am proud of this next step in our provision of services, as a result of which we are the first to offer 24/7 monitoring of assets and IT on Dutch soil," said Mark Donderwinkel, VP Thales Secure Communications and Information Systems."As a result of Covid-19, much more use is being made of remote collaboration tools. This is making organisations more vulnerable, and the number of cyber attacks is rising sharply. Now that we are in a phase of opening up our infrastructure and networks, it is crucial that downtime is kept to the absolute minimum. In order to achieve this, better monitoring is necessary, both of assets and of computer and network activities. We can now provide our customers with the highest and continuous level of service for both asset management and cyber security." View source version on Thales: https://www.thalesgroup.com/en/group/press-release/thales-launches-new-integrated-247-noc-soc-netherlands-0

  • CrowdStrike Explains Friday Incident Crashing Millions of Windows Devices

    July 24, 2024 | International, C4ISR, Security

    CrowdStrike Explains Friday Incident Crashing Millions of Windows Devices

    CrowdStrike's faulty update caused a widespread Windows device crash, impacting millions. The company is improving its error handling and testing proc

All news