Integration of Effort: Securing Critical Infrastructure from Cyberattack
| Published date | 01 July 2022 |
| Author | Sean Atkins,Chappell Lawson |
| Date | 01 July 2022 |
| DOI | http://doi.org/10.1111/puar.13493 |
Integration of Effort: Securing Critical Infrastructure from Cyberattack 771
Public Administration Review,
Vol. 82, Iss. 4, pp. 771–775. © 2022 by
The American Society for Public Administration.
DOI: 10.1111/puar.13493.
Sean Atkins
Chappell Lawson
Massachusetts Institute of Technology
Integration of Effort: Securing Critical Infrastructure from
Cyberattack
Abstract: Securing privately owned critical infrastructure from cyberattacks poses a novel challenge for the modern
regulatory state. In this domain, the interests of the government are only partly aligned with those of nongovernmental
owner-operators, necessitating some sort of state action. However, because (1) security conditions change swiftly
and (2) the information and tools necessary for effective planning and response are distributed across the private
and public sectors, standard regulatory tools are unlikely to produce security. “Integration of effort,” which involves
intensive strategic and operational collaboration between systemically important firms and the government, is a more
promising approach.
Evidence for Practice
• The dominant U.S. approach to cybersecurity for critical infrastructure—“voluntary partnership” between
industry and government—is inadequate to the objective of ensuring continuity of operations.
• Cybersecurity mandates aimed at private owner–operators of critical infrastructure, which have been
contemplated by successive Administrations and Congress—would prove cumbersome, costly, and
ineffective.
• The best approach for protecting critical infrastructures against well-resourced threat actors (such as foreign
nation-states) is “integration of effort.” This model would leverage the distinctive capabilities and authorities
of private owner–operators and the government to efficiently (1) identify vulnerabilities and threats; (2)
steer investment toward where it is most needed; and (3) prevent, disrupt, or mitigate the damage from
cyberattacks on critical systems. One institutional instantiation of integration of effort is a joint “war room”
that includes representatives of the relevant federal agencies and a few dozen systemically.
Over the last century, the modern regulatory
state has confronted a wide variety of policy
challenges, each requiring a somewhat
different set of instruments to address. Cybersecurity
for critical infrastructure (CIPA2001)—more
specifically, preventing disruptive cyberattacks on
the systems that undergird modern society—poses
another such challenge. Because threats to the
continuity of operations in critical infrastructure
constitute a broad social danger, there is a significant
public interest in securing the digitized systems
essential to their functioning (PPD-212013,
CISA2015; EO13636,2013; NIPP2013,
2009). However, because critical infrastructures
in many countries are owned by private firms,
the government must engage in some form with
industry to secure them (Carlin and Brill2020;
Durkovich2020).
Even though both sides share an interest in continuity
of operations, firms have little financial incentive to
account for the broader societal harm that would
attend disruption of their operations. In addition,
the government and critical infrastructure owner–
operators have access to different information, such
as classified intelligence (from the government) and
activity on privately owned networks (from firms).
A final challenge is that barriers to collective action
impede firms’ ability to share information with one
another, engage in joint planning, and synchronize
responses. An effective cybersecurity regime must
address all these challenges.
So far, the dominant approach to cybersecurity in the
United States has been based mainly on the voluntary
partnership between industry and government
(Atkins and Lawson2021a; Clinton2021; Clinton
and Perera2016; Griffith2020; Harknett and
Stever2011). However, this approach does not address
the fundamental problem of misaligned incentives.
And although the U.S. government possesses
The views expressed in this article are those of the author and do
not necessarily reflect the official policy or position of the U.S. Air
Force, U.S. Department of Defense, or the U.S. government.
Chappell Lawson is an Associate
Professor of Political Science at the
Massachusetts Institute of Technology,
Cambridge, MA. He previously served,
among other positions, as an adviser to the
Undersecretary for Policy in the Department
of Homeland Security during the Obama
Administration, Executive Director of Policy
at U.S. Customs and Border Protection
during the Obama Administration, and a
Director on the National Security Council
staff during the Clinton Administration.
Email: clawson@mit.edu
Sean Atkins is a Political Science PhD
candidate at the Massachusetts Institute of
Technology, Cambridge, MA and an active
duty Air Force officer. His research focuses
on competition and national defense in
cyberspace. His military service includes
national cyber policy and operations
experience.
Email: atkinss@mit.edu
Viewpoint Article
Get this document and AI-powered insights with a free trial of vLex and Vincent AI
Get Started for FreeStart Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant
-
Access comprehensive legal content with no limitations across vLex's unparalleled global legal database
-
Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength
-
Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities
-
Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting
Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant
-
Access comprehensive legal content with no limitations across vLex's unparalleled global legal database
-
Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength
-
Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities
-
Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting
Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant
-
Access comprehensive legal content with no limitations across vLex's unparalleled global legal database
-
Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength
-
Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities
-
Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting
Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant
-
Access comprehensive legal content with no limitations across vLex's unparalleled global legal database
-
Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength
-
Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities
-
Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting
Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant
-
Access comprehensive legal content with no limitations across vLex's unparalleled global legal database
-
Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength
-
Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities
-
Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting