Former Homeland Security Director: Cyber-Security Risks Growing & Never Going Away

tom ridge

Paul Berry (left) and Tom Ridge during GAC Q&A

WASHINGTON—Credit unions, and especially their volunteer boards, received something of a stern reminder from the former director of Homeland Security that it’s not enough to address cyber-security risks by passing off responsibility to someone in IT.

Former Homeland Security Director Tom Ridge, who now works in the private sector in his own firm that offers cyber-security consulting, offered a frank assessment to credit unions of the risks to their operations and the fact that that risk is never going to go away.

Individual Responsibilities

“There are individual responsibilities in this space for all of us,” said Ridge. “The digital world is full or promise—and full of peril. It has no geographic boundaries, and I urge you to understand this. The attacks expand every day, as does the complexity and sophistication. Managing that risk as a government or as a company is critical to the success of both. The digital sun will never set. We live in the digital for evermore.”

Ridge said credit unions and all businesses and individuals must deal with both the known nation-state players, such as China, Russia and Iran, which he called “implicit” in their cyber-attacks, as well as the “cyber-guerillas” who are hacktivists and others not associated with any country or even a cause. They are simply seeking data to sell.

Interconnected World

“In the interconnected world, attribution (of hacks) is getting easier and easier. But in this day and age, how do you hold the attacker accountable? It continues to be one of the biggest challenges,” said Ridge. “The digital perimeter fence used to be the most important barrier. Ten years ago everyone thought we could build a wall around our system. You still need a perimeter, but as somebody once said, ‘There are two kinds of  companies, those that have been hacked and know it, and those that have been hacked and don’t know it.’ The barbarians aren’t just at the gate, they’re inside, and exquisitely concealed.”

Ridge urged credit unions not to wait on government, which moves at a “glacial” speed, to resolve the security risks. “It’s going to depend on you.”

“One of the individual mindsets that I find interesting is that there are still enterprises that say that’s an IT problem, not a business risk. It’s a business risk!” said Ridge. “If your CTO tells you your IT system is buttoned up, you should fire him. There’s also a notion that we’re too small, nobody will pay attention to us. That’s wrong. At the end of day everyone has a responsibility to provide a minimum level of assurance to employees, members, shareholders, that they have taken steps to protect against a breach. That it’s being treated as a dynamic environment. That you have insurance.”

Cyber-Weapons

Ridge said he was a “great admirer” of credit unions because of the voluntary nature of board members, but stressed that’s no excuse for not ensuring data is protected, and he called on board members to step up their vigilance.

During a Q&A following his remarks Ridge was asked whether he believes other countries have cyber-weapons pointed at the U.S. that they might one day use. “You can argue it either way,” he said, noting countries that have such weapons won’t use them because the U.S. will respond in kind. “But some of the actors are not rational. I still think there’s a possibility for that, and would like to think the restraint on some of these actors would be the consequences for them and their economies. But there are irrational actors out there, such as ISIL.”

Section: Standard
Word Count: 734
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/Former-Homeland-Security-Director-Cyber-Security-Risks-Growing-Never-Going-Away