Should there be federal ordinances in place for cybersecurity threats where the affected organization is billed for the shutdown?

1.9k viewscircle icon2 Upvotescircle icon7 Comments
Sort by:
Senior Information Security Manager in Software4 years ago

This opens a Pandora’s Box. 

Does the fire department bill people who should have been more careful with kitchen fires?

No insurance coverage to obese patients?

Police department not show up to those who didn’t have good locks?

Lightbulb on1 circle icon2 Replies
no title4 years ago

When you frame it that way, it does sound more plausible that this could happen. Policies do each of those things in some cases, mostly by racist design, but otherwise simply for profit.

Lightbulb on1
no title4 years ago

Private fire departments (before municipalities had public fire depts) definitely charged homeowners and businesses to put out their fires.<br><br>This article from ABC News in 2010 documented a trend to begin to charge and bill for firefighting service in some locations:<br>https://abcnews.go.com/Business/fire-department-bills-basic-services-horrify-residents-insurance/story?id=9736696<br><br>Also, from Wikipedia, the free encyclopedia:<br>Jump to navigation<br>Jump to search<br><br>&#34;In the United States, an emergency response fee, also known as fire department charge, fire department service charge, accident response fee,[1][2] accident fee,[3] Traffic Infraction Accident Fee,[4] ambulance fee,[5] etc., and pejoratively as a crash tax[6] is a fee for emergency services such as firefighting, emergency medical services, environmental response, etc., performed by a local fire department, EMTs, police department, etc., at the scene of a structure fire, wildfire, traffic collision, or other emergency, billed afterward to the surviving property owner or owner(s), operator(s) of the vehicle(s) involved, and/or their insurance companies.&#34;<br><br>&#34;Many states and localities have approved these fees. Many states and localities prohibit these fees.[7]&#34;<br><br>&#34;Some fire departments charge small and large fees for firefighting.[8] Some bill the survivors, some bill the insurance companies of the survivors.[9]&#34;<br><br>&#34;Some fire departments charge an advance fire subscription fee for fire protection. They often do not fight fires that are not covered, refusing offers of back payment.[10][11]&#34;<br><br>&#34;The fees are controversial, with multiple arguments for and against.[12&#34;<br><br>[ https://en.wikipedia.org/wiki/Emergency_response_fee ]

Lightbulb on3
Senior Director, Defense Programs in Software4 years ago

If I read this right, it’s asking if victims of a cybersecurity incident should be billed for impacts of shutting down?

Broadly, no.

There are additional rules around trade, privacy, etc that make sense that could apply here, as well as ones in regulated industries.

Lightbulb on1
Board Member, Advisor, Executive Coach in Software4 years ago

There should be some level of a federal ordinance on which the government can take action if you're posing a risk to others, even in the logical sense. And, if warranted, they should be able to take the systems down or offline so you're not damaging others.

Lightbulb on1 circle icon1 Reply
no title4 years ago

But if we accept that level of government interference, we quickly reach the point where they can say, “We think that you haven&#39;t patched your systems in a while. You&#39;re at a risk so we&#39;re going to take your company down.” It&#39;s a super slippery slope. An ordinance follows policy and law; the FBI action that happened in April was a judge’s subpoena. I would be surprised if they had coordinated with private sector cybersecurity leaders on any of it.

Lightbulb on1
Member Board of Directors in Finance (non-banking)4 years ago

I don't think it's unreasonable for the government to create strict guardrails to regulate cybersecurity and say “This is not acceptable. You must take action and, if you don't, we'll do it for you and send you a bill.” For example, if you don't cut your lawn in Saratoga you'll get a letter. If you continue without mowing your lawn—creating blight in Saratoga—you'll get a second letter. And then the third time they will come and use a service to cut your lawn. And for the cost of that service they will put a lien on your house. It's an ordinance. It’s invasive.

Lightbulb on1

Content you might like

I know the exact number19%

I don't know the exact number, but have a dashboard that can tell it to me.62%

We don't have a way to determine that number currently.18%

View Results

No Increase17%

1-5% increase46%

6-25% increase24%

26-50% increase7%

51-75% increase1%

76%+1%

Other2%

View Results