Legacy IT makes federal agencies less secure, study says
Full article767 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
On average, for each one percent of its spending that an agency shifts from maintaining legacy systems to buying new ones, it can expect a five percent reduction in the number of security incidents.
Federal agencies that shift money from maintaining outdated legacy IT systems to modernizing them can expect to see fewer cybersecurity incidents — as can the agencies that migrate legacy systems to the cloud or implement strict data governance policies, according to a new academic study.
On average, for each 1 percent of its spending that an agency shifts from maintaining legacy systems to buying new ones, it can expect a 5 percent reduction in the number of security incidents, found the authors of the study “Security Breaches in the U.S. Federal Government.” It was written by two academics from the Fox Business School at Temple University and the Red McCombs School of Business at the University of Texas at Austin and published last week by the Social Science Research Network.
The study also found that federal agencies that migrate their legacy IT systems to the cloud suffer fewer security incidents of improper access. And that strict IT governance, risk and control, or GRC, policies — such as network monitoring, access controls, continuous employee training and risk management systems — as measured by agency inspector-general audits, appear to mitigate the security risks of legacy systems.
“We wanted to dispel some widely held but incorrect ideas,” Min-Seok Pang, assistant professor of information systems at the Fox School told CyberScoop. He said the article crunched incident data from the annual reports agencies are required to submit under the Federal Information Systems Modernization Act, or FISMA, and spending data from the Federal IT Dashboard.
One idea the study challenges, he said, is the notion of “security through antiquity” — the idea that legacy IT is more secure, because there is so little documentation and knowledge about it for attackers to discover and comb through for potential vulnerabilities.
“‘Security through antiquity’ might be correct for a particular individual system,” said Pang, “But from the point of view of the whole enterprise, the whole organization” it definitely makes them more vulnerable. “Legacy systems make an IT enterprise more complex, more messy,” he said, “That may expose it to more risk.”
“Counterintuitively, we also found that agencies which are geographically centralized and functionally homogenous tend to suffer more security breaches,” Pang added. “We were surprised. We expected to find the opposite: That agencies which were geographically dispersed and functionally diverse would have poorer security outcomes.”
One theory to explain the finding, Pang said, was that “functional or geographic centralization makes them less costly for intruders to penetrate, and [therefore] a more attractive target because the information [the intruder wants to steal] is more concentrated.”
“We’re trying to show not just correlation, but causality,” he added.
He cautioned that the study was based on only four years worth of data: 2012-15, and that the 2016 incident data was compiled on a different basis, making comparison impossible. “Unfortunately, because the federal government changed the definitions relating to the reporting of cybersecurity incidents, we were not able to use [the] 2016 data [released last week] in our study,” he said.
Nonetheless, Pang said the study had a clear takeaway for policy makers: “Pass the [Modernizing Government Technology, or] MGT Act now,” he said.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/study-legacy-makes-agencies-less-secure/