What are the hidden cybersecurity risks of the U.S. government shutdown?

On January 10, it was reported that 80 government websites had let their security certificates expire due to the government shutdown. This left some websites inoperable, but this lapse in security could also allow hackers to acquire sensitive data. 

As bad as this sounds, this is only an outward manifestation of a much deeper and larger problem. Cybersecurity is an ongoing effort that requires constant vigilance in a complex and changing environment. Cyberspace does not care about political machinations and government timetables, and massive furloughs in key government agencies both weaken U.S. cybersecurity and embolden adversaries.

Suzanne Spaulding, a former U.S. Department of Homeland Security under-secretary warns: “Our adversaries are not missing a beat and the daily attacks on our systems continue. Cybersecurity is hard enough with a full team. Operating at less than half strength means we are losing ground against our adversaries.” Some of the key agencies and programs affected by the shutdown include: 

  • Cybersecurity and Infrastructure Security Agency (CISA). This fledgling agency under the oversight of DHS, is to lead the national effort on assessing risk and vulnerability for critical infrastructure. CISA has sent home 43 percent of its normal workforce. CISA has only been in operation since November 2018.
  • Automated Indicator Sharing (AIS). This program within DHS has furloughed more than 80 percent of its staff. AIS is responsible for sharing threat intelligence between government agencies and private industry—a critical function in defending against the constantly-evolving threats in cyberspace.
  • National Institute of Standards and Technology (NIST). Among NIST’s responsibilities is providing advice and guidance on cybersecurity for government agencies and the private sector. NIST has furloughed almost 85 percent of its staff. The website for NIST’s Computer Security Resource Center, which supplies guidelines and other resources for government and corporate entities, has been unavailable with the following message: “Due to the lapse in government funding, csrc.nist.gov and all associated online activities will be unavailable until further notice.” 

In addition to the agency furloughs above, staff shortages across the government weaken cybersecurity. People are critical to cybersecurity— ranging from the system administrators and technicians, who install critical updates and keep everything running smoothly, to security

information analysts who monitor network traffic for threats. Without constant round-the-clock monitoring, breaches could go undetected for a longer period of time—creating more damage and giving hackers opportunity to hide their presence and their tracks—and leading to problems long after the government shutdown concludes. “The first 24 hours between a hack and detection is vital,” stated Tom Gann, of McAfee. Indeed, charges were filed Tuesday against 9 defendants who allegedly participated in an international insider trading scheme that involved hacking into the SEC’s corporate filing system in 2016. SEC chair, Jay Clayton, said of this cyberattack: “These threats to our marketplace are significant and ongoing and often involve threats from actors outside our borders.”

“Financial security is national security”

Thomas O’Connor

The shutdown also creates financial uncertainty in the lives of people involved in national security—adding unnecessary stress to occupations where peak performance is required. “Financial security is national security,” said Thomas O’Connor, president of the FBI Agents Association, regarding recent FBI staff furloughs. 

A truly long-term problem may be the government’s inability to attract and retain quality cybersecurity staff. In many respects cybersecurity has already been critically understaffed, and a government shutdown only makes matters worse. The 2018 (ISC)2 Cybersecurity Workforce Study reports a global cybersecurity workforce gap of almost 3 million, with North America having nearly a half-a-million unfilled positions. In a job market aggressively looking for talented cybersecurity staff, some federal workers who have been furloughed may leave for better paying

jobs in the private sector. Additionally, young college graduates who will be entering the cybersecurity workforce may think twice about applying for government jobs in the wake of the shutdown.

Share This Article

more insights

New Post 3
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
New Post 2
This is an excerpt for the test post. This is an excerpt for the test post. This is an excerpt for the test post. This is an excerpt for the test post.
What are the hidden cybersecurity risks of the U.S. government shutdown?
On January 10, it was reported that 80 government websites had let their security certificates expire due to the government shutdown. This left some websites inoperable, but this lapse in security could also allow hackers to acquire sensitive data.