Skip to Main Content Subscribe

Public-Private Threat Sharing Could Give Defenders an Edge

Share

Industry and government professionals say they will ultimately have the tactical advantage around threats as long as they work together.

4m read
Written by:
Speaking at the Billington Cybersecurity conference Tuesday, a panel of international cybersecurity officials said greater cooperation between industry and government could help combat AI-enabled cyberattacks.
Speaking at the Billington Cybersecurity conference Tuesday, a panel of international cybersecurity officials said greater cooperation between industry and government could help combat AI-enabled cyberattacks. Photo Credit: GovCIO Media & Research

Artificial intelligence is changing the playing field for defending the cyberattack surface, but expanded public-private partnerships could soon tip the advantage toward network defenders and away from attackers.

Speaking at the Billington Cybersecurity conference Tuesday, Cohere Co-Founder Ivan Zhang said that while AI’s capabilities have increased the speed and methods of cyberattacks, defenders from both the public and private sectors will adjust their data advantage to keep pace. Better sharing of that data could increase the defenders’ advantage more quickly.

“My optimism comes from the fact that defenders fundamentally have more telemetry than the attackers. This has been true since the beginning of the internet,” said Zhang, speaking on a panel about AI’s effects on the cyber landscape. “If we form the alliances necessary between nations, public [and] private, we can have more visibility and telemetry than the hackers and make those exploits way more expensive to follow up.”

Public-private partnerships are not new when it comes to threat intelligence, but the speed with which AI cyberattacks are deploying is making it an even more integral practice.

David Imbordino, director of the National Security Agency’s Cybersecurity Directorate and deputy national manager of national security systems, said the public-private partnership has gotten stronger as both are looking to address vulnerabilities and exploits that are materializing more quickly.

“There’s been a lot of creative thought in terms of how do you solve some of these problems with compensating controls or otherwise when you know people are not going to be able to patch fast enough,” he said. “How do you deal with that problem with technology? We’re really relying on industry for that.”

But maintaining the two-way street of trust between government and industry is also integral, said Stephanie Crowe, head of the Australian Cyber Security Centre at the Australian Signals Directorate. Crowe said that requires government communicating more on what strategies and intelligence coming from industry are most effective.

“We’ve worked really hard on feedback loops in Australia,” she said. “We know that when you tell government things sometimes, you don’t actually get feedback on what we’ve used it for or how valuable it was. That’s been a really important part of building trust with industry in Australia.”

Crowe said the Australian government has also worked on getting the right legislation in place to ensure that any industry information shared can only be used for security purposes to build trust.

Imbordino said that while past threat sharing between industry and government may have involved more limited information and outcomes, the speed that both now have to operate creates a symbiosis that both can benefit from.

“The problem is the attack timeline has been compressed significantly, and I think what we could share as much as we could share, even if we may not be as high confidence, where industry can take that and hack up on it or adjust the tooling, adjust the products and feed things back to the government so we can work upstream, the better we can do that,” he said.

Related Content