Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementTechnologies & SolutionsSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceCybersecurity News

COVID-19 and the need for a national cyber director: How the response to the pandemic illustrates the importance of a leadership

By Trevor Daughney
cyber_lock
October 28, 2020

Would the United States be ready if we were to experience a massive cyberattack? With a lack of federal strategy, a lot of cybersecurity experts are not so sure. After all, the country has seen the damage a lack of a federal-backed plan to fight a threat can cause with the COVID-19 pandemic. 

The U.S. House Committee on Oversight and Reform recently held a hearing on the nation’s cybersecurity preparedness. During the meeting, there was a bipartisan bill introduced that called for the creation of a national cyber director role within the White House. The role previously existed, but was eliminated by the current administration in 2018, and instead, the responsibilities were lumped in with those of the national security director. Various cybersecurity experts argued that the role being its own entity is necessary to help defeat threats and coordinate a cohesive strategy across federal agencies. 

Cyber defense is vastly different from kinetic wars fought on the ground and requires different kinds of preparation and leadership. Due to the nature of cyberattacks, it is harder to prepare and respond since the private enterprise and all levels of government are directly exposed. 

But is a federal plan of action necessary? There are members of the government who believe it should be up to the states to protect themselves against cyberthreat actors. However, this can be dangerous. 

 

The Case for a National Cyber Director 

Without a strong federal coordination to battle COVID-19, the United States has experienced considerable impact compared to other countries across the world. Since the beginning of 2020, millions of individuals have been diagnosed with the virus, and over 170,000 people have passed away as a result of infection. Each state was left to its own devices, fighting for PPE and relief from overwhelmed hospitals and increasing unemployment numbers. Without any border controls, the virus has easily moved from one part of the country to another. 

Much like the pandemic, hacking threats deserve federal attention and resources to mitigate horrific damages. Cybersecurity is the issue of our time. The United States has just as much to lose if there is an unstructured response to a nation-state backed cyberattack. In the past few years, we have seen its influence on critical infrastructure, elections, intellectual property (IP) theft, service interruptions due to ransomware and more. Much like how the virus moved, the same could happen with a cyberattack if malware was passed along online.

Russia has done more damage than just interfering in the 2016 presidential election - the country has also been accused of hacking Ukranian and Georgian power grids to cause countrywide blackouts. In 2019, one in five North American-based corporations on the CNBC Global CFO Council said that Chinese companies had stolen their IP within the last year. Stolen IP can ruin an organization’s competitive advantage. 

If we ended up in a cyberbattle with some of the top nation-state actors, they could shut down supply chains, hospitals, the internet, oil and gas, electricity grids, water systems and more. 

A national cyber director would be able to coordinate the cybersecurity flow of information to the executive branch and be able to coordinate a strategy to defend against these kinds of attacks. They could also build out a proactive offensive strategy to retaliate if necessary - long before a cyberattack successfully hit our shores. 

 

Qualifications for the Role 

If the United States were quicker to respond to COVID-19, we could be in the same position as Taiwan, whose population is 24 million people but has only had 449 confirmed cases of the virus and seven deaths as of July. The ability for a tactical and quick response is critical for candidates seeking the national cyber director role. Candidates should be evaluated in terms of their ability to lead the country to have a short mean time to respond (MTTR) to a cyberattack. In the cyber world, an organization’s MTTR has to be quick. An organization or entity risks exposing more data and halting business operations the longer the threat actor is in a network. 

In 2019, CrowdStrike released a report that gave insight into how fast a nation-state attacker could act. According to the report, nation-state attackers like Russia are able to breach an organization and conduct their first lateral movement across a network in 19 minutes. If you think about that in relation to how quickly a traditional Army would have to move for battle - it is magnitudes faster. 

The parallels continue between COVID-19 and its response and the need for a national cyber director. Just as Dr. Deborah Birx and Dr. Anthony Fauci are in charge of spearheading advisement on the pandemic response to the president, the national cyber director would be responsible for gathering information on threats, prevention and response. The role would involve having a strong understanding of the types of government regulations needed to implement the best protection possible for the nation, as well as divvying up the budget to the companies making the technology to keep everyone protected.

Just as federal and state officials had daily briefings to keep the public informed on the pandemic in the beginning of our battle with COVID-19, the national cyber director would have to be able to work collaboratively with various federal agencies to make sure both the public and private sector are protected against threats. 

 

Learning from the Pandemic 

Before 2020, no one could have predicted the impact a virus like COVID-19 would have on the United States. We must not allow ourselves to be caught in the same place twice with a massive cyberattack. 

The effectiveness of a national cyber director will come down to people, process and technology. Not only does the right candidate have to be selected for the job, there needs to be federal guidelines in place. Preparing and responding to a massive cyberattack is hard. Before appointing a person to this position, the federal government needs to iron out the details of how this role will work with existing cyber organizations. Next, everyone needs to recognize this role isn’t a panacea. As we have seen with COVID, other elements are required, such as strong political leadership.  

The private sector has a role to play, too. The cybersecurity industry needs to be encouraged to keep innovating and working together with the federal government to build the best offensive and defensive tools. With the right candidate and strategy in place, the United States could be much better prepared for a massive cyberattack than they were for the pandemic with a national cyber director in charge. 

KEYWORDS: COVID-19 cyber security risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Trevor daughney headshot

Trevor Daughney is vice president of product marketing at Exabeam. Trevor is a marketing executive with a track record of building high performing teams to take enterprise cybersecurity SaaS and software technology and turn them into successful global businesses. Prior to Exabeam, he led enterprise product marketing at McAfee, Ping Identity and Symantec. Trevor approaches marketing with a global mindset, and builds on his experiences living and working in the US, Canada and Asia. He has an MBA from the University of California, Berkeley.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Cybersecurity
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Logical Security
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    Technologies & Solutions
    By: Charles Denyer
Subscribe For Free!
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

White post office truck

Department of Labor Sues USPS Over Texas Whistleblower Termination

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Coding

AI Emerges as the Top Concern for Security Leaders

Person working on laptop

Governance in the Age of Citizen Developers and AI

patient at healthcare reception desk

Almost Half of Healthcare Breaches Involved Microsoft 365

2025 Security Benchmark banner

Events

June 24, 2025

Inside a Modern GSOC: How Anthropic Benchmarks Risk Detection Tools for Speed and Accuracy

For today's security teams, making informed decisions in the first moments of a crisis is critical.

August 27, 2025

Risk Mitigation as a Competitive Edge

In today’s volatile environment, a robust risk management strategy isn’t just a requirement—it’s a foundation for organizational resilience. From cyber threats to climate disruptions, the ability to anticipate, withstand, and adapt to disruption is becoming a hallmark of industry leaders.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • phishing

    2020’s top 5 phishing scams exposing hackers’ questionable morals – And how to hold strong against them

    See More
  • Data Stream

    The Five Rings: Understanding the importance of physical security of colocation data centers as a fundamental service during COVID-19

    See More
  • cybersecurity

    How to Minimize the Risk of Insider Threats (Physical and Cyber) During COVID-19

    See More

Related Products

See More Products
  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing