By
Jay Stanley, Senior Policy Analyst, ACLU Speech, Privacy and Technology Project at 5:38pm
A few links that have caught our eye this past week:
Paul Rosenzweig has posted a nice piece on Lawfare on the reasons to be skeptical of the need for cybersecurity regulation. He breaks cybersecurity down into its constituent parts (as we have urged) of cybercrime, cyber espionage, and truly catastrophic “digital Pearl Harbor” attacks. He suggests that the first two do not justify regulation, and (like us) is skeptical about the degree of risk of the third. In explaining that skepticism, he provides an elegant analysis of the electric grid, the taking down of which is a frequent cyber-attack scenario, and makes the point that the pro-regulation viewpoint “mistakes vulnerability for risk”—in other words, there can be a vulnerability in a system, but still a low risk that anyone will actually be able to or try to exploit it.