White House cybersecurity chief defines cyberthreat
Computerworld - Richard Clarke, chairman of the president's Critical Infrastructure Protection Board, recently spoke with Computerworld reporter Dan Verton about the nature and potential of the threat to the nation's critical infrastructure and what he sees as his biggest challenges with respect to national cybersecurity.
Excerpts from the interview follow:
Q: Can you briefly explain the cybersecurity threat for those who still may not be sure who or what the enemy is?
A: There's a spectrum of threats out there, some of which we experience every day. That spectrum runs from [individuals] who simply vandalize Web pages to those who conduct nuisance denial-of-service attacks. That's on the low end, which is usually conducted by young hackers -- so-called script kiddies.
In the middle, you have criminals who conduct fraud and industrial espionage online. The middle range of threats is usually carried out by organized crime, companies and also nation-states.
![]()
![]()
Coming next week:
Computerworld's in-depth look at the IT response to the Sept. 11, 2001, attacks.
![]()
I think we have to anticipate that a smart opponent would use some of these asymmetric tactics against us. In the larger scenarios, the private sector would be the targets for attack, either by terrorist groups or nation-states because those groups would seek to disrupt the national economy.
Q: What are the greatest challenges facing the private sector in terms of cybersecurity, particularly with respect to your mission of building an effective public/private partnership that can provide for a common defense?
A: The first problem we've always had was awareness. However, the awareness problem has diminished greatly for two reasons. People in boardrooms asked themselves after Sept. 11, "How secure is our company?" Also, there have been a lot of cyberattacks, which have doubled in the last year.
The second problem facing companies is determining what is a good product, who's a good service provider and what they should be asking for. Most people think the first thing to do is to run out and buy a firewall or an intrusion-detection system. But that doesn't even begin to solve your problems. You need to have a continuous process of looking for vulnerabilities and you need to have a layered defense. We passed the 2,000 mark a few months ago in terms of known vulnerabilities that we have to deal with.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- Protecting Point of Sale Systems from Targeted Attack
- If you are responsible for protecting retail systems, download this case study to learn how this retailer eliminated the threat of malware on...
- From the Frontline - Preventing APT
- Is your company's network secure? Are your endpoints and servers secured? Before you answer, read this case study on a US Military Command...
- Stop Hackers Before They Attack
- Hacktivism, Identify Theft, Financial Gain, Cyber War - regardless of motivation, stopping today's hackers requires a new proactive approach to protecting endpoints. Learn...
- The four rules of complete web protection
- As an IT manager you've always known the web is a dangerous place. But with infections growing and the demands on your time... All Cybercrime and Hacking White Papers
- WikiLeaks: How am I Affected?
- The latest WikiLeaks episode has raised questions about how organizations and governments protect their sensitive information. While this incident was isolated, it has...
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn... All Cybercrime and Hacking Webcasts