Skip to Main Content Subscribe

Partnerships in Focus for Cybersecurity Efforts at Health Agencies

Share

Agencies find opportunity in increasing diversity within cyber programs and leveraging shared services.

7m read
Written by:
Cyber security, data protection, information privacy. Internet and technology concept
Photo Credit: Funtap/iStock

As the federal government navigates an evolving cyber-threat landscape, health agency officials are increasing their attention toward expanding workforce recruitment, training and retention efforts to better safeguard personal health information. The main focus of these efforts include cultivating a diverse workforce, as well as raising awareness within and across different agencies of the available shared tools and services available to everyone, health officials said during last weekโ€™s Health IT Summit.

The Food and Drug Administration is one agency that wants to bring in diverse perspectives to strengthen cyber protection efforts.

โ€œWe want to have a workforce where everyoneโ€™s opinions are valued and respected and are able to contribute to a holistic program where we donโ€™t just have one mindset and one background,โ€ said Leah Buckley, director of counterintelligence and insider threat at FDA. This includes enticing more women into the short-staffed field and hiring people from various backgrounds and sectors, ranging from students whoโ€™ve just graduated from college to active-duty military members, to join its growing cyber teams.

With concerns over the overall low percentage of women working in cybersecurity in the public sector, Buckley highlighted contrasting efforts at the FDA in which women make up 31% of its cyber workforce.

FDA also is improving employee professional development opportunities and retention rates through biannual employee review processes, prioritizing training and career development plans, and offering telework days. About half of the agencyโ€™s employees have worked for the federal government for less than five years, while over 90% of those employees are looking to grow internally, Buckley added.

To prepare for the next generation of workers, the Department of Veterans Affairs is identifying new ways to improve and train the workforce using the NICE Cybersecurity Workforce Framework, noted VA Cyber Workforce Management Director Stephanie Keith.

Still, there are gaps in the framework for health security job roles.

โ€œWe are looking at how we develop what that goal looks like,โ€ for health care technology managers, biomedical informaticists and biomedical engineers, Keith said.

Thatโ€™s why Keithโ€™s office has created a Cyber Workforce Development Management Program to identify and define those missing cyber position requirements and goals, as well as a Cyber Training Academy to provide its employees with baseline that can transfer across VA and other agencies.

โ€œIโ€™m about federal national standards,โ€ Keith said. โ€œHow do we leverage this across the board?โ€

Sharing information and services across agencies is also necessary for critical cyber support, said Janet Vogel, CISO at the Department of Health and Human Services. With 416 potential threats a minute, addressing traffic as effectively as possible is one of her agencyโ€™s top priorities, she said.

Vogel noted the value of adopting a continuous diagnostics and mitigation program from the Department of Homeland Security, which has allowed the agency to respond very quickly to those incoming threats.

Still, many agencies are largely unaware of available shared services, like LookingGlass and Einstein, noted National Institutes of Health CISO Jothi Dugar. Dugar suggested that educating agencies and their personnel of whatโ€™s available to them could advance agenciesโ€™ security efforts.

She also suggested that educating potential applicants on the breadth of careers available to them in the field matters equally as much for attracting a diverse workforce.

โ€œThe beauty of security is that you can get it from all kinds of different angles,โ€ Dugar said. โ€œEven if youโ€™re an art major or an English major, you need to be able to communicate. You need to be able to speak the language of the person youโ€™re speaking with.โ€

Moreover, public-private partnerships can help achieve these goals, said VA CISO Paul Cunningham.

โ€œIf somebody thinks thereโ€™s a barrier to come into cybersecurity, whether itโ€™s a diversity issue or maybe a geographical issue, we need to look to see how to remove that barrier so itโ€™s not there,โ€ he said.

Related Content
Woman typing at computer

Stay in the Know

Subscribe now to receive our newsletters.

Subscribe