[HN Gopher] New rule would give electric utilities incentives fo...
___________________________________________________________________
New rule would give electric utilities incentives for investing in
cybersecurity
Author : geox
Score : 72 points
Date : 2023-06-24 15:29 UTC (7 hours ago)
(HTM) web link (www.federalregister.gov)
(TXT) w3m dump (www.federalregister.gov)
| Bloating wrote:
| electric utilities are the poster boys of cronyism... regulatory
| capture, guaranteed returns by socializing costs.
| imchillyb wrote:
| Electric Utilities in the USA don't require incentives. The
| Electric Utility companies are monopolies and regulated by the
| State. These companies need RULES to follow, or the regulators
| auction off their property and sell it to someone that will
| follow THE RULES.
|
| Screw incentivizing this and mandate it instead. Follow the rules
| or lose your company.
| samstave wrote:
| This makes me quite mad, actually - we need thee reverse of this
| bill:
|
| "Act for PENALIZING infrastucture companies, financial companies,
| utility companies and other key compnents to USA's national
| security and economy, by failing to invest in cyber securirty,
| egregious data leaks/losses/deletions as penalized financialy,
| quartly following audits until complaince is met."
|
| We should be "incentivising them" -- we did that alreadfy, and
| failed so many times:
|
| * gas tax to people, subsidies to oil companies for cheap gas,
| better roads and exanding refining capabilities <-- Total failure
|
| * 4 billion 'incentive' to AT&T for high speed internet infra, in
| the 1990s?(or early 2000s) - they took the money and did nothging
| with it
|
| * Rail subsidies and many billions wasted on a failed study for a
| highspeed rail
|
| * Food sunsidy incentives to keep prices low (oh look at all the
| food processing facilities that blew up, or caught fire during
| the pandemic and a large inflationary period.
|
| * Bank bailouts to keep people from getting financially destroyed
| by interest hikes, etc...
|
| * Lets help Ukraine with billions in arms sales and money which
| loops right back to back-door kick-backs to both actual
| politicians and defense contractors etc.
|
| (I personally believe we are pummeling Ukraine with billions in
| un-auditable funds to hide the corrupt kickbacks coming from
| these to the US politicians, and some of their family members)
|
| Incentives like this are simply a grift act on the taxpayers,
| again.
|
| --
|
| I know we dont like GPT much in comments - but I find it great
| for summarizing PDFs from any .gov link:
|
| ---
|
| Title: Incentives for Advanced Cybersecurity Investment Act
| Summary
|
| The Incentives for Advanced Cybersecurity Investment Act, as
| outlined in the provided document, aims to encourage and support
| organizations in investing in advanced cybersecurity measures.
| The act offers financial compensation in the form of grants and
| incentives to qualifying entities that make substantial
| investments in cybersecurity technologies and practices. Here is
| a summary of the key points regarding compensation and
| qualifications:
|
| 1. Compensation Offered: The act provides financial support to
| eligible entities through grants and incentives. The compensation
| is structured into two categories: Grants for Advanced
| Cybersecurity Investments (GACIs) and Cybersecurity Investment
| Tax Credits (CITCs). The specific compensation amounts are
| detailed in the document and are subject to change over time.
|
| A. Grants for Advanced Cybersecurity Investments (GACIs): GACIs
| are non-repayable funds granted to qualifying organizations to
| support their cybersecurity investments. The grants are designed
| to help cover the costs associated with implementing advanced
| cybersecurity measures, technologies, and training programs.
|
| B. Cybersecurity Investment Tax Credits (CITCs): CITCs offer
| eligible entities tax credits based on their investments in
| advanced cybersecurity. These tax credits aim to provide
| financial incentives to organizations that invest in
| cybersecurity technologies and practices.
|
| 2. Qualifications for Applying: To be eligible for the grants and
| incentives provided by the act, organizations must meet certain
| criteria. The qualification requirements include:
|
| A. Entity Type: The act is applicable to various types of
| entities, including but not limited to:
|
| - For-profit organizations
|
| - Non-profit organizations
|
| - Educational institutions
|
| - State, local, tribal, and territorial governments
|
| - Federal government agencies (subject to specific conditions)
|
| B. Cybersecurity Investment: Entities must make a significant
| investment in advanced cybersecurity technologies, practices, or
| training programs. The act defines the investment threshold and
| specifies the qualifying cybersecurity areas.
|
| C. Certification and Compliance: Applicants may need to
| demonstrate compliance with certain cybersecurity standards or
| obtain relevant certifications to be considered for the grants
| and incentives.
|
| D. Reporting and Documentation: Entities are required to provide
| detailed reports and documentation to substantiate their
| investments, costs, and compliance efforts. These documents may
| include receipts, invoices, training records, and other relevant
| evidence.
|
| It is important to note that the specific details, requirements,
| and eligibility criteria may vary and are subject to updates. It
| is recommended to refer to the original document provided for the
| most accurate and up-to-date information.
| OldGuyInTheClub wrote:
| I agree. Securing computer systems is a part of doing business,
| not something that needs wheedling and cajoling. Bottom dollar
| that these outfits will come for a bailout when (not if)
| they're compromised.
| samstave wrote:
| I started to use AutoGPT and Chat GPT to look for grift in
| congress, along with fines
|
| I was looking up announcements for certain industries /
| companies who announced large projects granted/influenced by
| legislation, then grants and associated politicians
| investments from opensecrets.org... - it was pretty tedious
| with the free account - Ill need GPT 4 to do what I would
| like --
|
| It will be great to have 'GovWatchGPT' monitor acts such as
| these, the companies that apply, granted, success/fail and
| the politicians they donated to, and whom invested into their
| companies just prior to an act passing.
|
| Doing things like this between AutoGPT, and ChatGPT - you can
| see kind of how I was starting to look at congress, but to
| get current articles and such, had to use autoGPT - but it
| was having issues saving data...
|
| --
|
| https://chat.openai.com/share/7dd61596-c83a-4c24-98f2-b39b3e.
| ..
| NoZebra120vClip wrote:
| Whenever I see the phrase "investment in cybersecurity", I sigh a
| little bit. It's nice to spend money on important things, and you
| can seldom improve anything without spending money on it. But
| cybersecurity is one of the things that you can't improve just by
| enlarging its budget. You build a culture. You hire personnel who
| care about it. You train your employees. You set policies and
| establish structures.
|
| You can't just purchase a "deluxe cybersecurity firewall
| appliance" and plug it into your network, even if it costs
| $50,000. I bet that a lot of people believe that's what it takes,
| though.
|
| Compare this to, say, education funding. It's good to spend more
| money on schools, right? I mean, teachers gotta be paid, students
| need (Chrome)books. But I always vote "no" on municipal school
| bond measures. I believe that money isn't everything, and I
| believe that it funds the wrong kind of things. The measures
| always pass, though, so don't worry, I'm not oppressing all the
| little kids in town.
| buggythebug wrote:
| It's a utility company - someones uncle booger works there -
| there will always be zero culture there _face palm_
| nunuvit wrote:
| Never heard of a hardware vendor accepting payment in the form
| of company culture.
| carabiner wrote:
| I worked at an electric utility in the tech side and we had a
| steady brain drain of guys going to Google, Meta in order to 2x
| or 3x their TC. Money talks.
| KennyBlanken wrote:
| https://www.google.com/search?q=US+electric+industry+profits
|
| That seems to be a "management is unwilling to pay enough"
| problem, not a "the industry is struggling and needs a
| government handout for relief from the burden of enhancing
| security" problem.
|
| Congresscritters are demanding we cut "fat" out of basic
| social assistance programs by increasing requirements from
| beneficiaries but we're going to give electrical companies,
| _making half a trillion in profits running basic
| infrastructure_ , a big handout, with trivial or no
| requirements?
|
| Pass.
| enkid wrote:
| Money isn't everything, but it's really hard to run an
| effective school or cyber security enterprise without money.
| piuantiderp wrote:
| This is lost to many in the West. There are things you cannot
| buy or strong arm your way out
| NoZebra120vClip wrote:
| Well that's a strawman. I've seen churches, corporations, and
| families being run on amazing shoestring budgets, but you
| couldn't tell from the outside, because the holder of the
| purse strings was judicious about spending.
|
| Years ago, I learned a peculiar thing about corporate or
| municipal budgets: sometimes a line item has to be spent or
| it won't come back next year. So there is often some strong
| impetus to spend $XXX,XXX -- or else -- and the deadline
| comes on June 30, and often that is how you arrive at bad
| spending decisions, because it's "burning a hole in your
| pocket".
| enkid wrote:
| That's not what the word strawman means.
| NoZebra120vClip wrote:
| "it's really hard to run an effective school or cyber
| security enterprise without money."
|
| GP is actually understating this; if my budget and
| revenue is $0, then I cannot run a school or enterprise
| at all and it will file for bankruptcy and close.
|
| A strawman is the informal fallacy of refuting an
| argument different from the one being discussed. I never
| said that a budget should be $0 or "without money".
| That's a _reductio ad absurdum_.
| bojo wrote:
| Having helped implement NIST 800-171 for a small enterprise
| company preparing to work prime government contracts I can
| assure you it costs money either way.
|
| Time and money spent working with cybersecurity professionals
| writing SOG/SOPs which map the business practices to the
| standard. Money spent buying and setting up some of the
| necessary equipment to handle CUI properly. Time (indirectly
| money) spent redoing decades old business processes to map to
| the new paradigm. Time (indirectly money) as the business spent
| time training their staff up on the components relevant to
| their business units.
|
| I agree that building a culture is at the root of it, however,
| that culture alone isn't going to move the needle unless
| everything else is in place as well. Worse, you have to walk
| the company through the 5 phases of grief because in general
| people don't entirely understand what is actually going on and
| why it's important. "So you can get government prime contracts"
| is an easy answer, but doesn't erase the confusion behind all
| of the hand-wavy procedural work required to execute them.
| konschubert wrote:
| I'm not convinced that implementing cybersecurity standards
| actually improves security.
| bojo wrote:
| No disagreements there. What's a better answer though? No
| one wants to do it, most non-tech people don't understand
| it, yet the standards and procedures need to improve to
| reduce the attack surface area - especially for businesses
| which support critical infrastructure.
| konschubert wrote:
| You could legally mandate companies to insure themselves
| against cybersecurity risks.
|
| It's really an interesting idea:
|
| https://www.cato.org/sites/cato.org/files/serials/files/r
| egu...
|
| This creates a "market for effective practices", because
| companies that follow good security practices would get
| cheaper insurance.
|
| But it would allow insurances and companies to figure out
| dynamically what is cost effective and what isn't.
|
| There would be lots of financial incentive to figure out
| what protects you effectively and what is just security
| theatre.
| Veserv wrote:
| Most companys already do. Unfortunately for the insurance
| companys their actuarial tables are backwards looking and
| cyberattacking is one of the fastest growing industrys.
|
| The smart insurance companys are all getting out of
| cybersecurity insurance because the premiums on the
| policys they wrote 10 years ago when the average attack
| cost $1,000 to remediate do not look so good when the
| average attack now costs $100,000 to $1,000,000 to
| remediate. Since the expected probability of a successful
| attack in any given year that requires payout is
| approaching 100% these days the insurance needs to be
| priced something like 10x-100x the prevailing prices to
| be survivable.
|
| Eventually it will shake out once the cyberattacking
| industry becomes mature because at that point backwards
| looking projections make sense. Until that time, we are
| in for a wild ride.
| [deleted]
| kyawzazaw wrote:
| Don't you need money(investment) to hire personnel, training,
| etc?
| evanreichard wrote:
| So just be smart about how you spend your money? Like any other
| department?
| balderdash wrote:
| It's not about smarts it's about incentives, if I'm
| incentivized to buy cybersecurity equipment but there is no
| incentive or penalty for not actually preventing
| cybersecurity breaches, a whole bunch of stuff is going to be
| bought with little effect.
| jlund-molfese wrote:
| The government only has so many levers it can pull, though.
| Even if we, the enlightened of HN have some idea of which
| investments are beneficial (for example, hiring a good CISO
| instead of buying the $50K cybersecurity box), laws and
| policies move too slowly and are too hard to change once
| enacted.
|
| So this situation still seems better than a rule which only
| benefits companies that hire Cisco Certified Security Posture
| Experts or something. There's at least a chance that some of
| these companies have competent CTOs (or equivalents, at smaller
| utilities) and will spend in the right area.
| balderdash wrote:
| Government has plenty of levers to pull - they just don't
| pull them.
|
| Want to have utilities (or any industry) put cyber security
| front of mind? Just tell them that they are liable for
| consequential damages for any service outages related to a
| cyber security incident, and watch how good they get at
| cybersecurity.
| candiddevmike wrote:
| All I see here is a government subsidy for security vendors.
| I'd rather see more liability and insurance requirements for
| security breaches, including personal liability for executives.
| Whatever it takes to get past checkbox-driven security.
| gtowey wrote:
| And schools are just a subsidy for the textbook industry.
|
| Regulation & incentives are literally the tools governments
| have to shape policy. It's a start, but moving the needle on
| issues can be hard, slow work -- especially when it seems
| like so many people have the attitude that if a particular
| action wasn't the their perfect, preferred solution, then it
| shouldn't have been done at all.
| hedora wrote:
| In your analogy, the vendors are the people manufacturing
| textbooks that are mandatory, but never get opened and
| cannot be resold on the used market. The regulators are the
| administrators (or whoever) that require the useless
| textbooks.
|
| Of course, there are many useful textbooks with none of the
| above properties, but they don't require complicated
| incentive structures to ensure they're made mandatory.
| halJordan wrote:
| This is intensely defeatist. Regulations and compliance are
| essentially what you described and they work for banks (despite
| the clever responses I'm sure are incoming). For the critical
| industry sectors they need to be buying the 50k appliance. And
| they need to be looking at a checklist that they only want to
| complete to avoid fines. Culture will accrete later.
| hedora wrote:
| I disagree with the GP's approach of defunding education to
| improve education, but I've seen the culture that accretes
| from checklists and expensive security appliances.
|
| Everyone involved correctly comes to the conclusion that the
| company's security policy is purely performative.
|
| The people that care leave. The people that don't care about
| securing the system implement the useless checkboxes and put
| the standalone box in the correct room (and might even plug
| it in), then get promoted.
|
| FIPS security certifications are the poster child for this.
| There's basically no way to get a securely architected system
| certified, so you end up adding vulnerabilities and (in the
| best case) a configuration parameter like the old "enable
| FIPS certification (default off; do not enable unless you are
| required to do so)" button from windows.
| kortilla wrote:
| 50k appliance doesn't do shit if people work from their
| personal laptop and use shared passwords.
|
| The only thing a regulation that mandates a 50k appliance
| will do is boost the appliance makers sales.
| hinkley wrote:
| An appliance also externalizes responsibility. I don't need
| to think of anything, because we have the box that goes,
| "ping".
| kodah wrote:
| Regulations are rules, this is a formalized incentive
| structure. They're a tad different.
|
| Regulation is good to a degree; there's a balance to strike
| between overly burdensome regulation and regulation which
| basically may as well not exist. The lines between these are
| sometimes vague as the times evolve and are also subject to
| regulatory capture by interest groups (political groups and
| companies).
|
| The incentive structure generally makes spending money free
| or more free so long as an entity abides by the guidelines
| set out by the incentive.
|
| You need both and both need to reflect the correct goals for
| the times.
| akira2501 wrote:
| > This is intensely defeatist.
|
| It's realistic.
|
| > Regulations and compliance
|
| Which might be nice. "Do this, or you will be penalized like
| this." These are marketed as "incentives" which is "Buy
| something, anything, and here's some abstract additional
| cash."
|
| > And they need to be looking at a checklist that they only
| want to complete to avoid fines
|
| The problem here is, you do the checklist, and you get an
| incentive. I wonder how that's actually going to be
| implemented?
| Veserv wrote:
| It emphatically does not work for banks. They spend hundreds
| of millions of dollars a year and any bank CISO would tell
| you, off the record, that their systems could be completely
| breached for less then a million dollars. That is not because
| they suck at doing it, that is because commercial
| cybersecurity is just plain garbage. That is literally the
| best you can get no matter how much you spend and no matter
| how "good" your people are if you use commercial IT security
| practices. Nobody does better than that who uses anything
| from a big brand cybersecurity vendor.
|
| The only reason banks are not totally wrecked by cyberattacks
| is that:
|
| 1) They actually are being constantly attacked by ransomware
| and the like, they just do not disclose it; I do not remember
| the budget line item the payments all go under but it is one
| of those compliance/administrative ones such as for
| insurance.
|
| 2) Cyberattacks, contrary to their standard portrayal as
| always being run by "state-sponsored" groups to make the
| companys being destroyed look better, are largely run by
| kids. They are largely unsophisticated on financial and
| business matters so do not know how much to ask for, how to
| maximally leverage a breach as a first party (i.e. do not
| know how to use say investment bank deal details to do
| effective trades), and how to actually cash out large amounts
| of money undetectably.
|
| 3) The non cybersecurity processes and fraud detection are
| actually fairly effective. There are large number of
| accounting checks in place that make it very hard to do
| simple hacks (like make the numbers in one account higher)
| that can not be detected. Banks have the equivalent of very
| complex, bespoke DRM systems that requires knowledge of
| financial systems and of their internal processes to crack.
| As I said before, the hackers are largely financially
| unsophisticated, so it is very hard for them to do this.
|
| No, it is intensely defeatist to just give up on actually
| solving the problem and demanding useless security theater in
| the vain hopes that it will somehow improve the situation.
| samtho wrote:
| > They are largely unsophisticated on financial and
| business matters so do not know how much to ask for, how to
| maximally leverage a breach as a first party (i.e. do not
| know how to use say investment bank deal details to do
| effective trades), and how to actually cash out large
| amounts of money undetectably.
|
| I wonder how many actually sophisticated attackers gain
| access to banks and other companies and purposefully keep a
| low profile but skim off low-bandwidth information meant
| for internal communications only, then aggregate and sell
| the intel to hedge funds or trade stocks on their own.
|
| Maybe the reason why we think that most attacks are caused
| by unsophisticated actors is because those are the one who
| are actually detected.
|
| Just kind of an interesting hypothesis that I've heard
| variations of before.
| tredre3 wrote:
| Regulations and rules force banks to be held accountable.
| Whether or not their cybersecurity prevents all breaches is
| besides the point. They are incentive in minimizing
| breaches, and when one occurs they're the one who have to
| cover the losses (yes I'm sure you're already typing clever
| examples of banks avoiding responsibility that one time but
| the fact that we rarely hear about then, as you say
| yourself, is that they cover it up and refund all the
| losses themselves).
|
| > demanding useless security theater in the vain hopes that
| it will somehow improve the situation.
|
| The security theatre required by these new rules might not
| prevent all breaches, or any breaches, but they will force
| utilities to be accountable for their failures.
|
| No longer will it be "Oopsie, mean hacker hacked us. Not
| our fault. Whatchugonna do anyway? Your business had to
| shutdown because no power/internet? Tough luck I guess".
|
| Now it will be "Oh fuck, hackers got in. We'll have to
| cover our customers losses and spend millions in PR to spin
| the story and avoid total bankruptcy."
|
| Do you really not see how that's still an improvement?
| hedora wrote:
| That's not what regulators do in this space. Instead, the
| rules are of the form "use certified vendor, and you will
| be shielded from liability".
|
| Also, the vendors and the people being shielded largely
| write the rules.
| Veserv wrote:
| No, liability requirements force banks to be held
| accountable. They do eat most of the costs of the direct
| consequences of being hacked. Luckily for them, the
| people hacking them are still, frankly, inexperienced
| from a business perspective so their losses have to this
| point been largely immaterial.
|
| The losses are not low because the cybersecurity
| processes and regulations are good, they are low because
| even though the vault is being guarded by the
| metaphorical equivalent a chihuahua, all they are doing
| is stealing the pens because they do not know how to pawn
| the gold in bulk.
|
| This state of affairs is changing very quickly. 15 years
| ago the hackers were walking into the vault and asking
| for $1,000 because they were 16 year olds who thought
| that was a lot of money. Now the good ones are 30 years
| old and are still walking into the vault, but asking for
| $10,000,000. Last I saw the number of attacks was
| increasing 3x year over year and the average ask was
| increasing 3x year over year.
|
| The entire cybersecurity insurance industry is already
| underwater at current premiums. I have heard they have
| basically stopped issuing policys over a few million
| dollars because it is literally ruinous. It is no longer
| becoming possible to paper over the omnipresent security
| deficiencys with insurance, betting on the incompetence
| of the attackers, and betting only one of you is going to
| get eaten.
|
| The sensible solution right now would be liability
| requirements on advertising security. You can not
| insinuate you are "secure" whatever that even means. You
| can instead only advertise a dollar amount per customer
| which is tied to a mandatory bug bounty. If you are a big
| bank with 100 million customers, you can put up a 10
| billion dollar bug bounty on breaching your systems and
| then you can advertise $100 of security on your customer
| deposits.
|
| This would force them to put their money where their
| mouth is while not preventing new small companys from
| existing as long as they truthfully report that they are
| not providing security. It would also help us pull the
| customer desired security requirements forward in time
| instead of waiting for the destruction first.
|
| Absent that, what is going to happen is that everybody
| keeps lying about their security to trick their customers
| into trusting them. Then one of them is going to get hit
| by a truly expensive attack and all the customers will be
| caught with their pants down.
|
| The only technical solution to this is either dropping
| reliance on these easily hacked systems, or throwing out
| all the existing crap that was never designed for
| security and can thus never be retrofitted to be secure
| such as Microsoft, Linux, Cisco, and Crowdstrike. Instead
| we must deploy systems designed for security such as
| those targeted to conform to the (now deprecated) Orange
| Book Class A1 or Common Criteria EAL 6/7 systems which
| are certified and proven to resist nation state attackers
| such as the NSA.
| balderdash wrote:
| Regulations and compliance is not what is being proposed
| here.
| mac-chaffee wrote:
| > You can't just purchase a "deluxe cybersecurity firewall
| appliance" and plug it into your network, even if it costs
| $50,000
|
| Those cost a quarter of a million per year nowadays...
| photochemsyn wrote:
| Any rational country would just nationalize the electric
| utilities, as they constitute a natural monopoly and as such
| there's no real competition. Eliminating the rentier investor
| class the system makes a lot of sense in this case, as all
| they're doing is running off with profits that would be better
| invested in infrastructure (including cybersecurity).
|
| This particular rule will most likely be gamed to increase rates
| while providing no improvement in security, with a compliant FERC
| nodding along under the current system of corporate regulatory
| capture of government.
| htag wrote:
| Electrification happened ~100 years ago. In 100 years it seems
| likely a combination of photovoltaic and storage will have
| rendered the grid largely moot.
|
| The electric utilities might be a natural monopoly today, but
| moving to nationalize it is addressing yesterday's concerns. If
| we're spending political capital to nationalize natural
| monopolies the electric utilities would be very far down my
| list of priorities.
| balderdash wrote:
| Utilities are in the business of spending capital so that they
| can charge rate payers. Any subsidy that does not also include
| alignment of incentives around outcomes is money wasted.
___________________________________________________________________
(page generated 2023-06-24 23:02 UTC)