Skip to content
SPECIAL

THREATS TO CRITICAL INFRASTRUCTURE IN IRAN CONFLICT

READ MORE

Welcome to the sandbox: Championing cyber resilience over regulatory theater

(Image by Sebastian Mey from Pixabay)

By Alex Botting and Alison King

In today’s hyper-connected world, with everything from toothbrushes to insulin pumps, vehicles and port cranes now digitized, the connectivity between any two points has created a deluge of cyber vulnerabilities, many of which are severe. The waves of ransomware attacks and breaches of hospitals, water systems and the operational technology networks that underpin critical infrastructure present an unacceptable risk to public health and safety. Therefore, it’s no surprise that governments worldwide continuously have introduced more stringent cybersecurity regulations, including cyber baseline requirements and incident reporting laws that aim to get ahead of these escalating threats.  

While it’s understandable for governments to require organizations to ‘raise the bar’ on cybersecurity in their enterprises and products, the divergence in regulatory approaches has created a Frankenstein-like regulatory monster, counterproductive to governments’ economic and security objectives. As a direct result, inefficient resource allocation by frontline defenders directly empowers malicious actors as they target American businesses. 

Rather than requiring organizations to comply with conflicting regulations to achieve the same objectives, governments should utilize regulatory sandboxes to trial existing international cyber standards, frameworks and best practices. 

Time to stop admiring the problem

In 2023, the Office of the National Cyber Director (ONCD) issued and received industry feedback on challenges associated with streamlining cybersecurity regulations. Themes discussed within the 86 responses representing 11 critical infrastructure sectors included:

  • How a lack of streamlining and reciprocity damages cybersecurity and increases administrative burdens and associated compliance costs to entities.
  • How businesses in all sectors and sizes deal with cybersecurity challenges, regulatory streamlining and a lack of reciprocity across jurisdictional borders.
  • The need for the U.S. government to address cybersecurity reporting challenges by identifying opportunities for reciprocity and collaboration.

As required by Congress under the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), the U.S. Department of Homeland Security convened the Cyber Incident Reporting Council that year. The council examined 50 existing cybersecurity incident reporting requirements in the U.S. alone. Its final reportnoted duplicative and redundant reporting requirements and recommended streamlining the reporting and sharing of information related to cybersecurity incidents. 

This situation forces organizations to divert an exhausted cyber workforce with finite resources toward duplicative paperwork drills instead of implementing important updates to defense-in-depth architectures, such as zero-trust. Organizations today must conduct overlapping audits, often multiple times a year, to answer the same questions for different governments and regulatory sectors. As Bank Policy Institute Vice President of Regulatory Technology Patrick Warren referenced in his July testimony before the House Oversight and Government Reform Committee, a recent survey of large financial institutions reflected several firms reporting that their cyber teams now spend more than 70% of their time on regulatory compliance activities.

Rather than requiring organizations to jump through conflicting hoops to meet the same regulatory objectives, governments should look to align their approaches using international standards, frameworks and best practices. This alignment reflects the global nature of cyber threats, empowering defenders with the latitude to address them effectively. While many governments have come to appreciate the merits of greater conceptual alignment, tangible initiatives have been slow to emerge due to a combination of status quo bias and a lack of muscle memory among cybersecurity policymakers in executing regulatory cooperation initiatives.

Welcome to the sandbox

Regulatory sandboxes are controlled environments in which companies can introduce services with temporary relief from regulatory requirements, other than those pertaining to consumer protection, health or safety. This enables companies to test and experiment with new services while ensuring that key regulatory objectives are met. Regulators, meanwhile, gain visibility into the impact of the sandbox, enabling them to identify potential risks, assess negative regulatory trade-offs and develop insights into how regulations could be improved. Meanwhile, consumers benefit from the new and innovative products that emerge from sandboxing, as well as the safety and protection provided by efficient government oversight. 

Due to their success, sandboxes have been applied to areas as diverse as FinTechdata privacy and medical device cybersecurity. The last led to the effective alignment of the labeling scheme with existing international standards. When applied to cybersecurity regulatory cooperation, sandboxes can demonstrate the impact of aligning with or reciprocating with another jurisdiction’s regulatory model before introducing it at scale. The Organization for Economic Co-operation and Development (OECD) also set a precedent by including regulatory sandboxes in its 2022 Policy Framework on Digital Security, which recommends policies aimed at realigning market incentives and empowering stakeholders “to enhance the digital security of the products and services.” 

Industry regulators streamlining priorities

Industry organizations, such as the Coalition to Reduce Cyber Risk and the U.S. Chamber of Commerce, have called for an international approach that promotes compliance activities that can be performed once and recognized by regulators across different jurisdictions, with customization where necessary. 

Sandboxes can serve as a bridge to these broader efforts aimed at regulatory alignment. Specifically, these organizations have highlighted the following policy areas as needing a more internationally cohesive approach:

  • Cybersecurity incident reporting: Although governments require the same basic information following a cybersecurity incident, there is significant divergence in the information companies must report, the timeline for reporting, and the process through which they report it. This is harmful to incident response efforts.
  • Cybersecurity labeling: Driving mutual recognition among the growing number of national cybersecurity labeling schemes is crucial for maintaining international trade in digital products and services. A robust system of mutual recognition agreements would ease the burden of meeting overlapping certification requirements.
  • Critical infrastructure cybersecurity: More than 100 countries have regulatory measures for critical infrastructure cybersecurity. In many sectors, covered entities operate in multiple countries, subjecting them to overlapping or conflicting requirements. This complexity hinders the seamless deployment of essential resources and cybersecurity best practices.

Unlocking innovation

Sandboxes would generate several positive benefits for regulatory alignment if introduced:

  • They would provide a platform for regulators to test the efficacy of multiple approaches to meeting regulatory objectives, therefore aligning and cross-pollinating approaches. 
  • They enable testing of innovative security and regulatory compliance approaches in an environment that poses minimal security risks. While the path of future innovation is always unclear, providing space for innovation will likely lead to future cybersecurity gains.
  • A sandbox for cybersecurity regulations will facilitate collaboration between regulators and industry by providing them with joint visibility into the impact of new technologies. 

The lessons learned from the sandbox can lead to joint regulatory undertakings, the development of future international standards or, at the very least, closing the gap in understanding what is needed in regulatory frameworks. Investments in cyber regulatory cooperation offer the potential for enhanced security outcomes, reduced workforce burden and the ability to invest in new, critical security capabilities. 

Alex Botting is the Coordinator of the Coalition to Reduce Cyber Risk (CR2), which partners with governments worldwide to increase the adoption of risk-based approaches to cybersecurity, and a Global Fellow at the Wahba Institute for Strategic Competition.

Alison King is Vice President of Government Affairs at Forescout, a Senior Fellow at Auburn University’s McCrary Institute for Cyber and Critical Infrastructure Security, and an Advisory Board Member at the Technology Advancement Center (TAC) headquartered in Columbia, Maryland.

Click to listen highlighted text!