Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
ColumnsCybersecurity News

Push Ahead of Cyber Security Legislation

By Mark McCourt
January 2, 2013

The rise in global security incidents, diminished budgets and downsized security programs have left organizations to deal with security risks that are neither well-understood nor consistently addressed. Executives around the world feel confident that they’re winning the high-stakes game of information security despite the growing number of obstacles, according to The Global State of Information Security® Survey2013 by PwC U.S. in conjunction with CIO and CSO magazines.

“Security models of the past decade are no longer effective. Today’s rapidly evolving threat landscape represents a danger that shows no signs of diminishing, and businesses can no longer afford to play a game of chance,” says Mark Lobel, a principal in PwC’s Advisory practice. “Companies that want to be information security leaders should prepare to play a new game – one that requires advanced skills and strategy to win against emerging threats.”

If you thought corporate and physical security were challenging enough, they have nothing on information security in the age of cyber crime. The above quoted study of more than 12,000 business and technology executives points to “the lack of information security leadership as a serious obstacle to an effective information security strategy in their organizations.” And on its heels appears to be a relatively toothless Executive Order to improve the digital defense of critical infrastructure, voluntarily.

A short history: in November 2012, the Senate failed to pass legislation mandating cyber security to prevent against a “Cyber Pearl Harbor” as Secretary of Defense Leon Panetta noted during a speech in October 2012, discussing U.S. critical infrastructure. The Senate killed the legislation in large part due to U.S. Chamber of Commerce opposition to the voluntary standards, viewing them as a back door to regulation and one that would quickly fall out of date with evolving threats.

That prompted the White House to move ahead with an Executive Order (EO 13587). However, most critical infrastructure is privately owned, limiting the Executive Order’s impact because it can only ask for voluntary participation among most of the targeted power plants and water systems. Further, it excludes commercial products from being ‘cyber security compliant’ (undefined) and leaves it to the individual government agencies to determine if changes to procurement procedures are necessary. There is also discussion of creating incentives for vendors to be ‘cyber compliant’ or awarding preferential status to those that are compliant. 

Further, a key sticking point in the Senate legislation was the information sharing among government and private sector organizations. While the legislation encouraged government and companies to share information about cyber threats, the Obama Administration promised to veto legislation that did not safeguard the privacy of that shared consumer data. So, while information sharing has been identified as a core element of cyber defense, it will not happen without protections for those doing the sharing.

Well, if you have read this far, you have the sense of all the things the Executive Order does not do. So, what does it do?

It does outline orders for certain agencies to take a proactive role. At the core, NIST will be charged with developing a cyber security framework. And DHS will produce unclassified reports on specific, targeted threats (similar to OSAC’s information sharing policy). And a system for tracking and reporting cyber security incidents would be developed on a multi-agency level. And maybe the most important outcome is the recognition of the problem and getting leaders across silos to discuss threats, vulnerabilities and mitigation strategies. And from signing to publication at the government agency level, the goal is 605 days.

In summary, do not sit tight waiting for this Executive Order to be signed. Rather, corral your peers across the enterprise and lead the charge because the folks on the other side of your firewall are charging ahead too. With only 21 percent of Security 500 CSOs managing Cyber Security for their enterprises, this is an outstanding career opportunity for leaders with security subject matter expertise to lead. After all, nature abhors a vacuum.

This article was previously published in the print magazine as "Nature Abhors a Vacuum."


Executive Order 13587 Near Term Actions

The President’s Cyberspace Policy Review identifies 10 near- term actions to support our cybersecurity strategy:

1. Appoint a cybersecurity policy official responsible for coordinating the Nation’s cybersecurity policies and activities. 

2. Prepare for the President’s approval an updated national strategy to secure the information and communications infrastructure.

3. Designate cybersecurity as one of the President’s key management priorities and establish performance metrics.

4. Designate a privacy and civil liberties official to the NSC cybersecurity directorate.

5. Conduct interagency-cleared legal analyses of priority cybersecurity-related issues.

6. Initiate a national awareness and education campaign to promote cybersecurity.

7. Develop an international cybersecurity policy framework and strengthen our international partnerships.

8. Prepare a cybersecurity incident response plan and initiate a dialog to enhance public-private partnerships.

9. Develop a framework for research and development strategies that focus on game-changing technologies that have the potential to enhance the security, reliability, resilience and trustworthiness of digital infrastructure.

10. Build a cybersecurity-based identity management vision and strategy, leveraging privacy-enhancing technologies for the Nation.

KEYWORDS: cyber attack cyber security cyber warfare federal security requirements infrastructure security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Mark McCourt was once the publisher of Security magazine.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

Cybersecurity predictions of 2026

5 Cybersecurity Predictions for 2026

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Rendered Microsoft icon

    Staying Ahead of the Cyber Curve: Strategic Security in a Shifting Landscape

    See More
  • Los Angeles World Airports Push Ahead with Integrated Command and Control Center

    See More
  • 5 minutes with Kumar

    How Can Cyber Leaders Stay Ahead of Accelerating Cyber Threats?

    See More

Related Products

See More Products
  • 9780367339456.jpg.jpg.jpg

    Cyber Strategy: Risk-Driven Security and Resiliency

  • 9780367259044.jpg

    Understanding Homeland Security: Foundations of Security Policy

  • 9780815378068.jpg.jpg

    Biometrics, Crime and Security

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing