1 / 4100%
Cyber Insecurity
The impact of the internet in the modern world cannot be understated. Today, virtually all aspects of
human life are impacted by the use of the internet in either one way or another. According to Jackson
Computer Consulting, about 97 percent of businesses in any community use the internet
communication, marketing, and sales. Healthcare, education, and entertainment sectors are other
sectors that leverage the internet to enhance accessibility to service. Even governments have migrated
their services to online platforms to enhance accessibility. Although the internet offers a plethora of
benefits to our communities, it has opened an attack surface for online criminals. Today, cyber insecurity
is a major problem in United States communities that has affected over 64 percent of Americans (Pew
Research Center).
While the problem of cybersecurity can be attributed to the fact that cyber criminals are always finding
new ways to harm users, I think the problem should be largely blamed on the lack of seriousness by
businesses and government institutions to protect consumer data. A majority of cyberattacks in our
communities result from breached data stored by businesses and government agencies. The growing
cyber insecurity can also be attributed to low public awareness about cybercrimes, how they manifest,
and best practices to avoid them. Low public awareness about cyber insecurity is the reason a
considerable number of cyberattacks are executed through social engineering.
The impacts of cyber insecurity are wide ranging. Many victims of cyberattacks report financial losses.
Pew Research Center notes that 41 percent of Americans have reported fraudulent charges on their
credit cards. Cyberattacks also contravenes right to privacy by breaching victims’ confidential
information. Businesses that fall victim to cyberattacks suffer financial losses, reputational damages, and
exposure of business secrets. Businesses with operations in states and regions with comprehensive data
privacy laws may also face law suits and penalties resulting from attacks. Amazon, Meta, and Equifax are
some of the companies that have been fined heavily for exposure of customer data (CSO). Besides
penalties and fines, businesses found guilty of exposure of customer data may be banned from
respective countries or regions.
Who is responsible
The cyber space is an expansive field that is ever evolving. Due to the complex nature of the field and
ever changing landscape, the United States constitution does not precisely state under whose
jurisdiction the sector operates. The Privacy Act of 1974 was created in response to the adverse impact
computerized databases would have on the privacy of users. Although the act still functions as the
primary data privacy law in the United States, it is vulnerable to various weaknesses that were not
envisaged in the 1970s. As a result of the weaknesses of Privacy Act of 1974, state governments have
also been ratifying laws in attempt to mitigate the cyber security challenge.
Basing on the current legal landscape in the United States in regards to cybersecurity, Both the federal
government and state governments are responsible for addressing the cyber insecurity challenge in
American societies. Article VI, Clause 2 of the United States Constitution allows State governments to
ratify legislations as long they do not contradict federal government laws. Consequently, since the
constitution does not bar state governments from regulating the cyber space to protect the citizenry,
state governments can pass cybersecurity laws as long they are in tandem with existing federal cyber
laws.
To support the federal government in mitigating cyber insecurity, various states have adopted
cybersecurity laws. California implemented adopted the California Consumer Privacy Act (CCPA) and the
California Privacy Rights Act (CPRA) in 2018, Colorado ratified the Colorado Privacy Act (CPA) in 2021,
Connecticut assimilated the Connecticut Data Privacy Act (CTDPA) in 2022, Maryland ratified the
Maryland Online Data Privacy Act (MODPA), and Indiana state passed the Indiana Consumer Data
Protection Act in 2023. Other states that have assimilated data privacy laws to address cyber insecurity
include Florida, Delaware, Lowa, Kentucky, Montana, Oregon, and a few more others. In a nutshell, it is
the responsibility of the United States federal government and state governments to address the cyber
insecurity challenge in American societies.
Government officials responsible
According to my sources, the inability of the United States to pass laws that can protect Americans from
online criminals should be blamed on government institutions at the federal level and state level. Some
of the key personalities mentioned include;
Joe Biden, 46th president of the United States.
Donald Trump, 45th president of the United States.
Cathy McMorris Rodgers, chairperson House Committee on Energy and Commerce and Washington's
5th congressional district representative.
Jon Heining, Martha Wigton, and JJ Gentry, presidents of National Conference of State Legislatures
(NCSL) between 2019 and 2022.
How they attempted to resolve
One of the first steps former president Donal Trump undertook to protect Americans from online
criminals was signing the National Cyber Strategy (Whitehouse). The order directed heads of federal
agencies to be responsible for implementing risk management measures and updating their system. This
directive was meant to enhance the cybersecurity of data held by federal agencies. The order also
mandated operators of critical infrastructure and networks such as vital utilities, financial systems, and
health systems to identify and implement better ways of protecting their networks. Trump’s directives
were mainly designed to enhance the cyber security of government institutions, critical infrastructure,
and vital online based services in the community.
Following a series of cyberattacks on public and private institutions after his assumption in Office,
President Joe Biden promulgated Executive Order (EO) 14028 to enhance the country’s
cyberspace. The order sought to modernize US government cybersecurity practices
and establish higher standards for software security across industries. The order
directed respective agencies to develop strategies to enhance public-private
collaboration and information sharing. It also directed government and private
networks to assimilate zero trust architectures, encryption models, and multifactor
authentication. In 2023, the Biden administration assimilated a National Cybersecurity
Strategy that sought to bolster the regulatory landscape in the cyber space and increase legal and
financial liability on big private entities in the cybersecurity ecosystem (Whitehouse).
As the chairperson House Committee on Energy and Commerce, Cathy McMorris Rodgers is one of the
leaders at the national level mandated to help shape policies and regulations in the cybersecurity space.
Besides participating in formulation of data privacy laws, the congress woman has been active in
organizing forums for discussing the rising cyber security threat in the United States. She has also been a
frontier in reminding the United States government on cybersecurity challenges and risks they pose on
American communities. She has also advocated for public awareness programs to educate the public on
cyberattacks, how they manifest, and best practices to mitigate them. For example, in 2024 she delivered
an address on Strengthening American cybersecurity. In the address, she warned that the cost of
cybersecurity would surpass $10.5 trillion and cautioned that as more service and social interaction
migrate to online platforms, the cybersecurity threat would worsen (McMorris). In the address she
reminded the government and the public on the need to be aware of adversary state sponsored threats
and why the US government and US companies should cease sourcing IT products from foreign
companies such as Huawei and ZTE. The role of Cathy McMorris Rodgers in the cyberspace has
significantly contributed in reducing the effects of cyber insecurity in American communities.
The National Conference of State Legislatures (NCSL) plays an essential role in formulation of policies at
state level. Between 2019 and 2022, the National Conference of State Legislatures under the leaderships
of Jon Heining, Martha Wigton, and JJ Gentry encouraged and helped various states develop
cybersecurity laws. The body supported state legislatures by providing resources, policy examples, and
best practices for developing functional cybersecurity laws. The body has also been on the forefront of
educating state legislatures on the basics of technologies such as AI and their impacts on cybersecurity
(NCSL).
My opinion on government efforts
Cybersecurity is an evolving field. Technology in the cyberspace keeps changing so rapidly that it is
difficult for authorities to craft laws that can stand the test of time. A cyberspace legislation ratified this
year may not be able to effectively fulfill its purpose two years from now. Besides a rapidly changing
landscape, cyber insecurity is an international problem. A majority of cyber attackers targeting
Americans are based in foreign countries like Russia, China, Romania, and Nigeria (Monash University).
To be effective, cyber laws must be implemented at international level. Creating partnerships with
foreign governments is a major hindrance in implementing of cybersecurity laws. Regardless of the
efforts to combat cyber insecurity, cyber threats will always be challenge.
But also, the United States state governments and federal governments are doing enough to combat the
cyber problem. Although several state governments have ratified cybersecurity laws to protect their
citizens, reports indicate that all state cybersecurity laws except California’s are weak and incapable of
protecting against cybercrimes. According to EPIC (), state privacy laws are shaped by tech lobbyists like
Amazon and other big tech companies. As a result of this interference, these laws are just void and do
not have real protections. They allow companies to continue collecting data uncontrolled and the
penalties for violations are weak. While they allow consumers to opt out in data collection programs and
request for their data to be deleted, the process is intentionally complex to prevent people from
controlling how their data is collected and used.
The federal government has also failed in its mandate to protect citizens in two ways. One, despite the
cyber industry being a multi billion industry, the federal government is yet to develop a comprehensive
data privacy law similar to Europe’s GDPR. The Record () notes that the lack of a comprehensive federal
data privacy law has permitted states to enact lax data privacy laws. Two, the federal government has
ratified various industry specific laws such HIPAA to protect consumer data. These laws are not elaborate
enough to cover their industries. For example, HIPAA is meant to protect patient electronic data but only
covers data in healthcare electronic systems and ignore digital platforms such as data collected by health
websites and applications such as FitBits (PIRF Org, 2024). Most of these industry specific laws are also
outdated.
While protecting Americans from cyber insecurity is major challenge, authorities at the national level
and state level can start with ratifying laws with real protections. The federal government should take
the lead by developing a comprehensive cybersecurity law similar to Europe’s GDPR. A comprehensive
cybersecurity law at the national level will not only protect all Americans by regulating how their data is
collected, stored, and used but will also provide a blueprint for state governments to enact cyber laws
with real protection free of influence from big tech lobbyists.
Students also viewed