• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

The Pentagon said Iran War costs $29 billion, but the real cost is closer to $200 billion—and counting

2

Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic

3

After forcing workers back to the office, Goldman Sachs and JPMorgan Chase are now letting their staff work remotely—but only for the World Cup

1

The Pentagon said Iran War costs $29 billion, but the real cost is closer to $200 billion—and counting

2

Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic

3

After forcing workers back to the office, Goldman Sachs and JPMorgan Chase are now letting their staff work remotely—but only for the World Cup
CommentaryCybersecurity

Why New Regulations Won’t Scare Off Cyber Hacks

By
Peter J. Beshar
Peter J. Beshar
Down Arrow Button Icon
By
Peter J. Beshar
Peter J. Beshar
Down Arrow Button Icon
November 29, 2016, 2:00 PM ET
Photograph by Andrew Brookes — Getty Images
Add Fortune on Google for similar content.

For nearly 70 years, the NATO treaty has stood the test of time. Elegant in its simplicity, this two-page treaty has established the principle, and defined the terms, of collective defense. An attack against one ally constitutes an attack against all 28 member nations.

As one might expect of a document written in 1949, there are references to armed attacks on territories, troops, ships and planes. Not surprisingly, the word “cyber” appears nowhere. To try to address this gap, NATO Secretary General Jens Stoltenberg in June stated that a cyber attack could, in fact, be interpreted as an “armed attack” under the treaty. Left unstated is how significant or disabling that cyber attack must be before Article 5 would be triggered.

This uncertainty captures the challenge of relying on systems and protocols constructed decades ago to confront dynamic new threats like cyber.

When it comes to national security, change too often comes in the wake of tragic events that defy accepted paradigms. The most recent was September 11th, which caught political and military leaders by surprise.

With senior defense officials raising alarms about the potential for a “Cyber 9/11” or a “Cyber Pearl Harbor,” however, there is an opportunity to take decisive action now on the issue that is among the most critical to America’s physical and economic security. As President-elect Donald Trump assembles his national security team, the new administration and the business community should collaborate to develop a sophisticated, forward-looking cyber policy that is founded on three core principles:

First, understand the scale of the risk.

When most people think about cyber security right now, what comes to mind is the theft of personal data through hacking e-mails or stealing passwords. For the average American, the risk feels more like a nuisance than a threat to our existence.

Respected military officials, however, have asserted that cyber potentially poses a more immediate threat to our collective security than even nuclear weapons.

We must move away from the mindset that the damage caused by cyber attacks will be limited to data and the digital world. Our physical assets, in particular the industrial systems that control our country’s critical infrastructure, are vulnerable as well.

A July study by the University of Cambridge’s Centre for Risk Studies estimated that an attack on the power grid in the northeast could cause up to $1 trillion in damages. And as we move closer to a world of smart cities, driverless cars and a connected everything, the potential for crippling physical attacks only increases. Moreover, unlike other countries, more than 80% of our nation’s critical infrastructure is owned and operated by the private sector. When put in this context, cyber should and must be a critical focus of America’s national security.

Second, think best practices, not new regulations.

In the U.S., we have scores of regulations relating to cyber security and data privacy. The Trump administration can make tangible progress in enhancing our collective cyber resilience without necessarily pressing for additional laws or regulations.

In the interactions my firm, Marsh & McLennan, has with thousands of businesses across the country, executives are no longer under any illusions about the potential severity of the cyber threat to their companies. Accordingly, the goal should be to make “best practices” into “common practices.” The U.S. should be thinking about innovative technologies, enhanced security protocols and incentives that encourage greater collaboration between the public and private sectors.

One example involves the Domain Name System (DNS), which is essentially the telephone book of the internet. When a user types in an internet address, that address needs to be translated into the language of the internet (IP numbers like 10.100.10.10). DNS performs that translation. Hackers, however, have devised methods to misdirect internet traffic intended for one site and divert it to another, malicious site.

Fortunately, there is a relatively simple fix called “DNS filtering” to combat this new vector of attack. By reviewing millions of feeds from public and private sources, data scientists can identify malicious sites that are being used by hackers to launch cyber attacks. “DNS filtering” is equivalent to blacking out those pages, or sites, from the internet phone book.

Particularly for small and medium sized enterprises, this solution can be implemented in a matter of hours by IT staff. Despite its effectiveness and simplicity, however, only a fraction of companies have implemented this solution. For this reason, the Global Cyber Alliance, a public-private partnership led by the New York District Attorney, the City of London Police Commissioner, and the Center for Internet Security, has made global deployment of DNS filtering one of its top priorities.

A second example involves the Internet of Things. The recent Mirai “botnet” attack was a wakeup call about the threat posed by the Internet of Things. Hackers manipulated hundreds of thousands of common consumer devices like security cameras and thermostats to launch an extremely sophisticated attack. The manufacturers of these products distributed these devices to the public with simple default passwords like “12345” or even “password.” As a result, hackers were able to scan the internet for any device with these passwords and then reprogram these devices – at the appointed moment – to flood a target in a massive Distributed Denial of Service attack. If this attack had been directed at critical infrastructure, rather than the service provider for websites like Twitter and Spotify, the consequences would likely have been far more severe.

Once again, there are tangible steps that can be taken to mitigate this new threat. The Internet Engineering Task Force, a community of network designers, operators and researchers, has developed a potential framework for manufacturers to configure their products in a manner that will preclude their being weaponized in this fashion.

To accelerate this effort, government and industry should collaborate to develop a set of best practices for IoT products that would enhance their security and provide consumers with greater confidence in the products they buy.

Third, see the opportunities, not just the challenges.

America has always been adept at following Winston Churchill’s sage comment: “The optimist sees opportunity in every danger; the pessimist sees danger in every opportunity.” World War II led to a manufacturing boom that lifted the country out of the Great Depression. The Soviet threat of the 1960s spurred us to win the space race. Cyber security affords a similar opportunity.

A recent study by CyberSecurity Ventures predicts that the global market for cyber security will grow from $75 billion in 2015 to $170 billion in 2020. All of this investment will lead to the creation of new companies, and therefore, new jobs – especially for our veterans, who often leave our armed forces with unique knowledge and perspective on the digital battle lines of tomorrow. Just as in times past, the United States can take the lead, not just making our country and the world safer, but creating new jobs and opportunity in the process.

Peter J. Beshar is executive vice president and general counsel of Marsh & McLennan Companies.

About the Author
By Peter J. Beshar
See full bioRight Arrow Button Icon
Add Fortune on Google for similar content.

Latest in Commentary

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Commentary

Asia’s defense boom is rewiring the global arms supply chain
Commentaryarms, weapons, and defense
Asia’s defense boom is rewiring the global arms supply chain
By Chris OberoiJune 24, 2026
9 hours ago
steve
Commentary250 Years of Innovation
Steve Case: America was built by entrepreneurs. Here’s how we keep that edge for the next 250 years
By Steve CaseJune 24, 2026
18 hours ago
t
CommentaryWhite House
Trump mistakes the bully pulpit for bullying leadership — history’s villains were never heroes
By Jeffrey Sonnenfeld and Steven TianJune 24, 2026
18 hours ago
mg
CommentaryHealth
The ‘tech neck’ time bomb: why 43 million young Americans could cripple U.S. health care within a generation
By Michael GerlingJune 24, 2026
19 hours ago
sb
Commentaryclimate change
The climate policy triangle: why leaders can no longer choose between growth, security and sustainability
By Sebastian BuckupJune 23, 2026
1 day ago
brett
CommentaryManagement
Middle managers aren’t going extinct—they’re evolving into something more powerful
By Brett HurtJune 23, 2026
2 days ago

Most Popular

The Pentagon said Iran War costs $29 billion, but the real cost is closer to $200 billion—and counting
Economy
The Pentagon said Iran War costs $29 billion, but the real cost is closer to $200 billion—and counting
By Jacqueline MunisJune 24, 2026
23 hours ago
Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic
Success
Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic
By Orianna Rosa RoyleJune 24, 2026
23 hours ago
After forcing workers back to the office, Goldman Sachs and JPMorgan Chase are now letting their staff work remotely—but only for the World Cup
Success
After forcing workers back to the office, Goldman Sachs and JPMorgan Chase are now letting their staff work remotely—but only for the World Cup
By Orianna Rosa RoyleJune 23, 2026
2 days ago
Amazon's record Prime Day masks a darker truth: Americans are spending more and getting less
Retail
Amazon's record Prime Day masks a darker truth: Americans are spending more and getting less
By Nick LichtenbergJune 24, 2026
16 hours ago
Ray Dalio just finished a 10-day trip to China. He says global leaders know America ‘doesn’t have what it takes to fight to maintain its empire’
Asia
Ray Dalio just finished a 10-day trip to China. He says global leaders know America ‘doesn’t have what it takes to fight to maintain its empire’
By Nick LichtenbergJune 24, 2026
17 hours ago
Current price of gold as of June 23, 2026
Personal Finance
Current price of gold as of June 23, 2026
By Danny BakstJune 23, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.