Cyber Security isn't (just) an IT problem: How Emergency Management improves cybersecurity
CIOREVIEW >> Adobe >> NEWS

Colorado

Nathan Fogg, Director of Emergency Management, Arapahoe County

Cyber Security isn't (just) an IT problem: How Emergency Management improves cybersecurity

Nathan Fogg, Director of Emergency Management, Arapahoe County
Nathan Fogg, Director of Emergency Management, Arapahoe County, Colorado

It’s Tuesday afternoon. Users across your enterprise notice their computers are sluggish and rebooting into safe mode. By now, employees have figured out that restarting their machines can fix most computer problems, but that isn't working. Your IT service desk receives calls about “my computer not working.” Remote access to those machines is failing. Soon, the service desk is inundated with more calls describing the same problem. Fast forward several days, maybe a week or more, and you’re recovering from a ransomware attack. We know detection is critical. We know recovery is critical. What happens in the middle? Are you alone, dealing with internal and external pressures around response, communication, resources, and continuity?

What is Emergency Management?

In many organizations, especially in the public sector, emergency managers (EMs) are tasked with implementing and managing a cycle that includes hazard and threat identification, planning, mitigating, responding, and recovering. Historically, the focus was natural disasters; as the world changed, human-caused disasters were added, and the term 'All Hazards' was included in the lexicon. Our focus was on studying the hazards and threats, assessing the capabilities to address them, managing the consequences to quicken the recovery, and developing improvement plans based on comprehensive after-action reviews. Only in the last few years have emergency managers started including cyberattacks in the realm of all hazards. In between these real-world events, EMs use a cycle like the one above to conduct exercises intended to refine plans, test capabilities developed, and identify and close additional gaps. 

Emergency managers are resources to help in all cybersecurity phases, particularly in the middle. EMs generally have capabilities to help develop your plans, playbooks, and map dependencies. Recent experiences demonstrate that most cybersecurity response and recovery entities have foundational plans and tools in place. Those include all the things you are aware of, from phishing and intrusion detection to antivirus and beyond. These same experiences show that cybersecurity staff are incredibly dedicated, jump immediately into working on the problem, and will keep going—for a long time. This is the middle. These response teams are looking in and down, working the problem, isolating systems, containing threats, and exhausting the lead and themselves.

Who is dealing with the consequences of this attack?

Organizational leadership is looking for answers, updates, timelines, and ways around the outage. Your responders are tiring without a relief shift coming in. Customers, used to having five 9s uptime in a secure and user-friendly environment, are hitting the socials; the absence of authoritative information worsens the consequences. These things all degrade the quality and speed of response and recovery and exacerbate the consequences.

"Emergency managers are resources to help in all cybersecurity phases, particularly in the middle"

In this case, your cybersecurity team and emergency managers worked together, and this was not the story. These teams planned, memorialized, and practiced. They established processes for early detection of an event, developed a management structure during the response, and addressed the command, control, and communication required to support the responders. They spent time learning each other's languages, translating and understanding the jargon, defining operational periods to minimize responder exhaustion, facilitating standardized information sharing, internally and externally and spent time developing interdisciplinary trust. They practiced all of this before your bad day and refined the plans, making sure the stakeholders from finance to public affairs to executives understood and supported the plan. When the bad day happened, the emergency management team was in step with your cybersecurity responders, managing the middle, allowing your responder to address the threat and speed to recovery.

Certainly, this scenario is a simplified compression of the timeline, level of effort, and challenges faced getting to the end state. The process is not a panacea, but it proved effective in the real world. There will be difficulties in all these phases from both a human and technological perspective. Combining the expertise of these teams, facilitating their efforts, and allowing the emergency managers to support the middle does speed response and recovery. 

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.