Students, officials discuss cybersecurity legal barriers at summit at LSU | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


BATON ROUGE, La. (WAFB) – Students, industry leaders, and government officials gathered at LSU to discuss challenges in the cybersecurity field, including legal barriers that can slow down efforts to respond to hackers.

Ronald Gibson III, a senior at LSU studying cybersecurity, has known what he wanted to do since middle school.

“Cybersecurity just was kind of a new, unexplored realm that allowed me to use my computer science skills in a really deep and technical way,” Gibson said.

Gibson was one of dozens of students sitting alongside industry professionals and officials at the Cyber Civil Defense Summit. He said one of the biggest takeaways from the event was the barriers forensic investigators face when trying to help a company.

“The first person that I met with is a lawyer, right? And they’re telling me, no, you can’t come in here because this is data that you can’t see, that we don’t want you messing with, and maybe you could even do something to the data,” Gibson said.

Whole of state approach

Organizers said they are seeing that gap across the country.

“We like to think of a concept called ‘whole-of-state cybersecurity,’ where the state is working in conjunction with the local and the counties and the municipal and even the neighborhood level and community grassroots level to work together to protect ourselves using the people and the resources that we have and the relationships between them,” said Ann Cleaveland, executive director of the UC Berkeley Center for Long-Term Cybersecurity.

Cleaveland said Louisiana has been a leader in the whole of state cybersecurity approach, pointing to a security operations center run out of LSU that provides cybersecurity services to public agencies that might not otherwise be able to afford them.

Cleaveland said cybersecurity threats generally fall into two categories: financially motivated cybercriminal gangs and nation-state attackers targeting critical infrastructure for purposes such as spying or intelligence gathering.

Leadership and basic cyber hygiene

Officials said leadership still has room to grow, especially when it comes to protecting data.

“The problems that we’re trying to solve were problems that we solved in the private sector 20 years ago. I mean, literally, we’re dealing with things that we should have moved past many years ago. And it’s the basic password complexity, simple cyber awareness,” said Gary Vance, chief information security officer for the state of Arkansas.

He said the most common day-to-day threats his office deals with are ransomware, business email compromise, and phishing. Vance said Arkansas has implemented mandatory annual cyber awareness training, and employees who do not complete it within the performance period have their accounts suspended.

Vance said he has not seen specific AI-related threats in Arkansas yet but said AI agents are becoming more prevalent and have been reported attacking other segments of industry and government elsewhere. He said state governments as a whole are “probably 10 to 15 years behind” on cyber controls.

Greg Trahan, assistant vice chancellor for strategic research partnerships at LSU, said the university began a strategic cybersecurity initiative several years ago that led to the creation of a cybersecurity clinic, initially funded by the National Security Agency.

Trahan said one of the biggest challenges in the field is a lack of coordination between military, agency, industry, and academic approaches to cybersecurity.

Breaking down barriers

Gibson said that gap is why events like the summit matter — getting everyone on the same page before they are out in the field.

“Just breaking down that communication barrier, even breaking down legal barriers, is a big help towards, you know, getting us all towards a safer future,” Gibson said.

Gibson said he plans to work in offensive security for the government after graduating in December, which involves securing government systems by testing them for vulnerabilities.

Cleaveland pointed to a public campaign called Take Nine, which encourages people to take nine seconds to think before clicking on a suspicious link. Organizers say the habit can stop some of the most common cyberattacks before they start.

Click here to report a typo. Please include the headline.

Click here to subscribe to our WAFB 9 News daily digest and breaking news alerts delivered straight to your email inbox.

Watch the latest WAFB news and weather now.

——————————————————-


Click Here For The Original Source.