Many aspects of our lives have now become computerized; financial, transportation, energy, and emergency response are just a few. Without a substantial boost to cybersecurity capabilities, companies, individuals, and different levels of government will remain in a very vulnerable position that threatens our personal information and poses a serious risk to our country's national security. From identity theft, to full blown government and corporate hacks; it's evident that cyber-attacks are a growing threat that must be quickly addressed with eyes wide open.
A May 2016 report conducted by the Government Accountability Office (GAO) found that cyberattacks against the U.S. government have increased drastically over the past ten years; rising from 5,500 attacks in 2006 to over 77,000 attacks in 2015. Two recent high profile attacks against Yahoo and the Democratic Party have highlighted the urgent need to take cyber security more serious than ever before.
There are several key principles that must be considered to aggressively achieve necessary progress; not least of which is that the best defense is a good offense as a deterrent. Foreign actors need to know that the United States not only has the ability to employ the same tactics to them that they use against us, but we are absolutely willing to go on offense to ensure an attack on Americans is not worth the effort. The Department of Defense (DOD) and National Security Agency (NSA) are two agencies in particular in a unique position to lead with this strategy.
In Congress, I have placed a high priority on advancing legislation to boost cyber security capabilities. The House has passed the Critical, Infrastructure Protection Act (H.R. 1073), Protecting Cyber Networks Act (H.R. 1560), National Cybersecurity Protection Advancement Act (H.R. 1731), Strengthening State and Local Cyber Crime Fighting Act (H.R. 3490), State and Local Cyber Protection Act of 2015 (H.R. 3869), and Cyber Networks Act (H.R. 1560). These bipartisan bills help strengthen our cybersecurity infrastructure and intelligence collection ability while also promoting more coordination between different levels of governments and the private sector.
Companies as well have a massive responsibility to protect private personal information in their possession. Infrastructure systems must be strengthened as much as possible to mitigate vulnerabilities to cyber attack. It is the duty of businesses to be up to date on the latest technology to boost cybersecurity and not to cut any corners. Businesses should also work with law enforcement whenever necessary and possible to further strengthen cybersecurity protections.
Employee practices must be constantly sharpened to boost cybersecurity. "Whaling" and "Phishing" are examples of tactics used to trick an individual into sending sensitive information that should not otherwise be forwarded. These are just two concepts that many employees throughout our country know nothing about even though all must become experts on how to identify and respond to the use of these tactics. Individually, we can all practice better "cyber hygiene" in monitoring our own networks and personal computers, being aware of the latest threats and having the best software installed to combat those threats, using strong passwords and avoiding questionable sites and emails. In the military, where I currently drill as part of the Army Reserves, we receive regular training on all of these basic but key concepts: Not leaving our military ID in the computer; not opening or responding to suspicious emails; not opening suspicious attachments to emails, not distributing sensitive information to unauthorized parties, and not leaving our computers unattended.
Cyber security is a 2016 challenge that we need to be much more prepared to address. There is so much more to do and so little time to get ready to prevent the threats that now face all of us.