The public sector faces a siege of cybersecurity threats, driven by ransomware, phishing, and nation-state attacks targeting sensitive data and critical infrastructure. Outdated legacy systems, budget constraints, and rapid digitization create vulnerabilities, making government agencies, healthcare, and education prime targets for extortion and disruption. The book recognizes that the Internet has rapidly changed the way the public sector interacts with citizens. The quick ramp-up to Internet connectivity has led many public sector agencies to give short shrift to the issues of security and privacy. This work provides a high-level overview of security trends surrounding the effort to make government more connected, taking a broad approach with a heavy international focus. Numerous examples demonstrate how agencies worldwide have dealt with the threats and vulnerabilities involved in moving to an e-government mode. One challenge that governments face is that they often move at a snail's pace, while security threats move substantially more quickly. For those who need a highly detailed approach to cybersecurity in the public sector, this may not be the best title. Attacks are becoming more sophisticated and more targeted, and they are not limited to public sector departments. They extend to the supply chain that keeps the public sector in business utilities, telecoms, banks and the critical national infrastructure supporting that supply chain. It is this highly interconnected nature of our modern "systems of systems" that requires an ongoing risk-based approach balancing technical with non-technical threat mitigation methods, where success will be judged by the ability of an organisation to continue with its critical functions and business operations despite hostile activities. From smart meters on the energy grid to building control sensors, from the pervasiveness of smart phones to devices on open networks using standard protocols, our systems are becoming increasingly instrumented and interconnected - and they are generating large volumes of data in real time. While this may mean increased intelligence for organisations, it also opens the door to more threats and places greater dependency on components in the infrastructure. A walled garden approach is no longer sufficient. Systems that are linked to the internet are exposed to security threats. The key for organisations is to focus on resilience at the business process level while driving a balanced approach to investment in IT security. Look at healthcare. In the past, medical equipment stood alone but these days, while one end may be connected to a patient, monitoring or even keeping the individual alive, the other end of the system is commonly connected to an IP network. There is an inherent risk in data aggregation enabled by interconnectivity. Meaning can be derived by combining lots of innocuous fragments of information, so there is a need to c
Dr. Anthony Hodge, assistant professor in the Department of Computer and Information Sciences at Fordham University also affiliated with the Fordham Center for Cybersecurity. He is a Fordham-NYU and Fordham-IBM fellow. He received PhD in Electrical Engineering from New York University (NYU), Tandon School of Engineering in 2020. He is an experienced and transformational IT researcher with more than 20 years of expertise in providing high-quality and innovative solutions and leading the continuous improvement of IT services aligned with enterprise strategies. He has worked both nationally and internationally on driving academic, research and administrative innovations and promoting entrepreneurship in a digital culture.
Preface
1. THE GLOBAL RISE OF E-GOVERNMENT AND ITS SECURITY IMPLICATIONS
2. UNDERSTANDING CYBER THREATS
3. CYBER SECURITY IN EAST ASIA
4. TOWARDS A GLOBAL APPROACH TO CYBER SECURITY
5. THE CYBER SECURITY POLICY CHALLENGE
6. U.S. FEDERAL CYBER SECURITY POLICY
7. EUROPEAN CYBER SECURITY POLICY
8. A LOCAL CYBER SECURITY APPROACH
9. SECURING GOVERNMENT TRANSPARENCY
10. THE CIVILIAN CYBER INCIDENT RESPONSE POLICIES OF THE U.S. FEDERAL GOVERNMENT
11. CYBER SECURITY HEALTH CHECK
12. BEYOND PUBLIC-PRIVATE PARTNERSHIPS
13. COMMON CYBERSECURITY THREATS IN THE PUBLIC SECTOR
14. IS THERE A CONCLUSION TO CYBER SECURITY
Bibliography
Index