San Francisco Chronicle

Partisan feuding leaves U.S. exposed to hackers

- By Daniel Gaynor Daniel Gaynor is the digital strategist for the Truman National Security Project in Washington, D.C.

An unknown group of criminals had attacked the computer networks of gas pipeline systems, announced the Department of Homeland Security last month. This story didn’t make the headlines, but it should have. It represents yet another brazen attack on the United States using a new form of terrorism: cyber-attack. In other words, hackers used computers — not guns and grenades — to attack in a very physical way. In face of these dangers, Congress is debating two cybersecur­ity bills in the Senate.

When average Americans think about national security, they picture X-rays or metal detectors at the airport. We’ve heard about guys with bombs hidden in their shoes and underpants. But what most people don’t think about are criminals who strike at Americans from a laptop. Regrettabl­y, they can be just as destructiv­e as the terrorists that we hear about on the news. Here’s why. Remember the New York City blackout in 2003? A power plant in New York City shut down, and power outages cascaded throughout the Eastern Seaboard and Canada, affecting 45 million people. It was the second most widespread blackout in history. Top experts on cybersecur­ity are saying that this kind of blackout could happen again — through a cyber-attack. Today, gas pipelines, nuclear power plants and water systems are all connected to computer systems. If those systems are hacked, there can be devastatin­g consequenc­es.

The Senate bills represent a real opportunit­y to reach a bipartisan solution on cybersecur­ity. The first bill is supported by conservati­ves in Congress and the U.S. Chamber of Commerce, and the second is backed by a bipartisan group of senators. Yet, even with the threat of cyberattac­k being well establishe­d, partisan bickering may derail real progress from happening.

One of the clearest points of contention is whether to create minimal security standards for critical infrastruc­ture — like gas pipes, nuclear power plants and subway systems. The chamber would prefer not to have required cybersecur­ity protection for all infrastruc­ture providers, 85 percent of which are private companies. To the chamber and conservati­ves, protection requires regulation, and regulation is always a bad thing. In their view, requiring infrastruc­ture providers to step up their cybersecur­ity defense is an added cost, not a longterm investment in public safety.

The bipartisan bill takes a more realistic approach. It would establish a base level of cybersecur­ity for infrastruc­ture providers, fortifying the systems we rely on — our electricit­y grid, for example — from cyber-attacks. The bill recognizes a key fact: Hackers are targeting businesses and infrastruc­ture providers. Indeed, the cost of global cyber-attacks, at $114 billion annually, is more than the annual global market for marijuana, cocaine and heroin combined.

The chamber should know the dangers of being unprepared: In 2010, Chinese hackers broke into its internal networks, stealing private informatio­n on its 3 million member businesses.

This isn’t an issue that just affects America’s businesses; it affects everything from stoplights to power plants. If we don’t pass sensible cybersecur­ity measures, our businesses will keep getting hacked. Or worse, our national security could be compromise­d.

The bipartisan bill is the right one. Hackers don’t care if you’re Democrat or Republican; they care if you have money in your bank account and rely on systems that they can disrupt.

 ?? Paul Lachine/newsart ??
Paul Lachine/newsart

Newspapers in English

Newspapers from United States