Could ISIS be the Next Big Cyber Threat to OPM?

Just as millions of federal workers and contractors received confirmation that their data had indeed been breached at OPM earlier this year, another threat is lurking.

The OPM’s new cybersecurity adviser, Clifton Triplett, says he expects ISIS may breach the agency’s systems too, reports NextGov.

Triplett was appointed in early November and is the agency’s first senior cyber advisor, He will work alongside the OPM’s CIO to support responses and the mitigation of future incidents. A former CIO, with extensive private sector and military defense experience, Triplett shared his expectations at a recent webinar hosted by Bloomberg Government earlier this month.

ISIS Has Already Tried to Breach U.S. Systems

Attempted attacks on U.S. infrastructure by ISIS is nothing new, in October the Department of Homeland Security disclosed that ISIS had attempted to sabotage the U.S. electrical grid, albeit unsuccessfully, but warned that “ISIS is beginning to perpetrate cyber-attacks”. "Strong intent. Thankfully, low capability," said John Riggi, a section chief at the FBI's cyber division. "But the concern is that they'll buy that capability."

Triplett backs that assumption. "I think what I have to do is . . . assume that, at some point in time, they may be successful," and pledges to focus on access control as a priority. OPM will "make it more of a need-to-know kind of access control," he said, “so if we do have a compromise, it is far more contained than, for example, our last incident."

OPM Data is Part of the IoT

Yet very real concerns remain about the security of PII information gathered during background checks that resides on OPM networks. To quote NextGov: “what really frightens Triplett is that OPM’s records sit beside smart toasters and air conditioners in the Internet of Things.”

"We're too interconnected. Not enough air gaps in our systems…We are trying to automate and connect one more thing to one more thingI'll have a reasonably minor event that will turn into a catastrophic event, and I won't be able to find out where the root cause was because of the ripple potential."

Read more here about OPM’s challenge on NextGov here.