FAS

Secrecy of Cyber Threats Said to Cause Complacency

04.18.11 | 2 min read | Text by Steven Aftergood

The American public does not have an accurate sense of the threat posed by attacks in cyberspace because most of the relevant threat information is classified, according to Sen. Sheldon Whitehouse (D-RI), who introduced legislation last week to raise public awareness of cyber security hazards.

“The damage caused by malicious activity in cyberspace is enormous and  unrelenting,” Sen. Whitehouse said on April 14. “Every year, cyber attacks inflict vast damage on our Nation’s consumers, businesses, and government agencies. This constant cyber assault has resulted in the theft of millions of Americans’ identities; exfiltration of billions of dollars of intellectual property; loss of countless American jobs; vulnerability of critical infrastructure to sabotage; and intrusions into sensitive government networks.”

“These massive attacks have not received the attention they deserve.  Instead, we as a nation remain woefully unaware of the risks that cyber attacks pose to our economy, our national security, and our privacy,” he said.

“This problem is caused in large part by the fact that cyber threat information ordinarily is classified when it is gathered by the government or held as proprietary when collected by a company that has been attacked. As a result, Americans do not have an appropriate sense of the threats that they face as individual Internet users, the damage inflicted on our businesses and the jobs they create, or the scale of the attacks undertaken by foreign agents against American interests.”

With Sen. Jon Kyl (R-AZ), Sen. Whitehouse introduced the “Cyber Security Public Awareness Act” to require government agencies to provide increased public reporting of cyber threat information.

“As of 2011, the level of public awareness of cyber security threats is unacceptably low. Only a tiny portion of relevant cyber security information is released to the public. Information about attacks on Federal Government systems is usually classified. Information about attacks on private systems is ordinarily kept confidential. Sufficient mechanisms do not exist to provide meaningful threat reports to the public in unclassified and anonymized form,” the bill stated.

Last year, Sen. Whitehouse chaired a bipartisan Senate Intelligence Committee task force on cyber security.

“The government keeps the damage we are sustaining from cyber attacks secret because it is classified,” he said last November. The private sector keeps the damage they are sustaining from cyber attacks secret so as not to look bad to customers, to regulators, and to investors. The net result of that is that the American public gets left in the dark.”

publications
See all publications
Emerging Technology
day one project
Policy Memo
How to Safely Bring AI into Law Enforcement:  The Case of AI-Generated Police Reports

Commercial artificial intelligence tools have recently emerged that are able to produce police reports. If the resulting reports are inaccurate, incomplete or biased, or if the process leaks confidential information, this could undermine the criminal justice system and harm citizens.

06.09.26 | 20 min read
read more
Emerging Technology
day one project
Policy Memo
FairCare Verification Offers a Human-Centered Path for AI in Medicaid

Too often, affected patients, clinicians, and regulators cannot see how the system works, why a decision was made, or whether meaningful human oversight occurred.

06.09.26 | 15 min read
read more
Emerging Technology
day one project
Policy Memo
The Federal Government Should Pilot a Decision Subject Representative Program for AI Systems

Existing tools from other domains, such as existing robust public engagement processes in drug development, when applied to AI deployment can help strengthen public trust in these systems and enhance perceptions of their legitimacy and the decisions they produce.

06.09.26 | 10 min read
read more
Emerging Technology
Blog
Americans Would Trust AI More if Policies Ensuring Fairness Were Implemented. Here are Ten Ways to Start.

With thoughtful policy action, it is still possible to build systems that are fair, transparent, and accountable, and to earn the public trust that will ultimately determine AI’s future. We hope policymakers are ready to act.

06.08.26 | 4 min read
read more