Financial firms hungry for more DHS data

15.12.2006
The Department of Homeland Security's Computer Emergency Readiness Team (US-CERT) raised a few eyebrows in late November when it sent a warning out to U.S. banks and financial institutions about a by Islamic militants. The alert, dated Nov. 30, was triggered by a posting on what the DHS considered an Islamic jihadi Web site calling for hackers to attack U.S. financial and banking Web sites, apparently to protest the detention of Muslims at Guantanamo Bay, Cuba. However, the warning was heavily qualified, with DHS calling the threat "more aspirational than operational." Financial firms downplayed the danger, too. One security executive at a major brokerage told InfoWorld that the warning was a "non-event."

But could repeated warnings about such non-events eventually make critical infrastructure owners deaf to DHS's warnings? InfoWorld Senior Editor Paul F. Roberts recently chatted with John Carlson, senior director of security and risk Assessment at BITS, a financial-services industry consortium focused on security, fraud, and risk management, about the DHS warning and state of the public-private partnership on cybersecurity.

InfoWorld: I'm guessing that your members received the US-CERT warning about the cyber terrorist attack?

John Carlson: There were two messages sent: the first was [Nov. 30]; then a second revision came out [Dec. 1]. The gist of it was that these reports were not corroborated.

IW: What was the reaction of BITS members to the warning?

JC: Our members have an "all hazards" approach to business-continuity planning. They've got well-developed approaches that have been bolstered since 9/11. In response to new regulatory requirements, firms have done a lot to improve backup, they've done tests with the various exchanges. They're also working in closer harmony with the federal government to share information on threats and vulnerabilities. I think there's a spirit of appreciation that the government is willing to share information with the financial services industry. The firms take that information into account in responding and activating their business continuity plans.