How the World Cup Helped Boston Improve Its Cybersecurity | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Boston knew that hosting seven matches during the World Cup would attract fans from all over the world. What officials there didn’t know, however, is that the World Cup would also improve the city’s cybersecurity.

Thanks to the international event, Boston Chief Information Security Officer Greg McCarthy found himself sharing intel and cybersecurity concerns with a larger network than usual, one that had expanded to include his counterparts in the event’s other host countries, Canada and Mexico. And McCarthy is no stranger to coordination, having co-founded the Coalition of City CISOs.

He said security officials in the host cities — which spanned North America, including three jurisdictions in Mexico and two in Canada — kept in regular communication throughout the World Cup, talking about indicators of malicious cyber campaigns, threats or compromises in their respective cities. The calls also created opportunities to hear from the FIFA cybersecurity team, the Multi-State Information Sharing and Analysis Center and the New Jersey Cybersecurity and Communications Integration Cell, who all helped guide the tournament to a successful run without any major cyber incidents.


That deep commitment to coordination also reflects the broader scope of work in a large city like Boston, where McCarthy has served as CISO since 2014, starting out as the city’s second-ever cybersecurity team member. Today, his team has about 26 members, and they support roughly 26,000 active employees across city operations, public safety, schools and libraries.

“We cover traditional cybersecurity operations, identity and access management, both for our workforce and our residents and businesses, and the newest function on our team is our risk compliance and audit function,” McCarthy said. “We are the only cybersecurity team within the city. There are some cyber analysts in pockets of IT groups like at our schools and libraries, but we are the only full-service cybersecurity team.”

The city has a successful identity and access management program for its workforce, and now it has also turned to working on resident identity and access. Boston began developing a customer identity and access management system at the end of 2024, according to information provided by the city. The project is intended to provide a unified login for each resident or business rather than the assortment of credentials they currently use to access different city services.

Examples include a parent registering a child for school, a resident accessing library services, or someone paying taxes or applying for a permit through city systems. It’s about simplifying the experiences into a unified login, McCarthy said, then using the centralized profile to provide more efficient ways of doing things, such as prefilling forms. But centralizing data also means deciding what data should and shouldn’t be collected, so his team is examining the data collection process.

The project will also have an opt-out feature, the ability for users to request that stored data be removed. McCarthy said it is still in the initial stages, with a small number of services integrated so far.

Speaking to the most pressing issue of the year, McCarthy said he sees AI as both an opportunity and a risk, describing himself as cautious about introducing emerging technology because of his cybersecurity responsibilities. Boston developed AI standards and policy starting around 2023, alongside piloting use cases. Coding assistance has proved valuable for developers, but the city continues to weigh productivity gains against cost, environmental impact and security concerns.

“There are not a lot of efficient technical controls in place right now for protecting against, say, data exfiltration via AI or putting inappropriate data into public data models,” McCarthy said.

He is interested in seeing whether AI can help with cybersecurity, and his team plans to participate in Anthropic’s state, local, tribal and territorial cyber defense program. The company pledged in June to give credits for public-sector entities to use its AI models to identify vulnerabilities and help remediate them. The city is working through the approval process and will use the tools to conduct security assessments of its codebase, McCarthy said.

Still, the project he is most excited about is the identity and access management program because it is public-facing. He said the cybersecurity team rarely works on something that residents see directly.

“With cybersecurity, when cyber is working well, no one knows it’s there,” McCarthy said. “Being able to work on a project that will have an impact on my home life and the home life of the residents in the city is pretty cool.”



——————————————————-


Click Here For The Original Source.