Sandy Levine | Survival Guide: Perspectives from the field
Sandy Levine, president of Advice Unlimited LLC
- By Alice Lipowicz
- Sep 29, 2006
The intricacies of cybersecurity can be difficult enough for IT experts to explain to each other. How effective are IT executives and the federal government at explaining it to the public? Not as good as they could be, said public relations expert Sandy Levine. Miscommunications and misunderstandings can make bad situations worse, she said.
Sandy Levine, president of Advice Unlimited LLC
She should know. Levine has many years of experience handling public relations for IT government contractors, including Cisco Systems Inc., Citadel Technologies Inc., McAfee Corp. and Microsoft Corp. She was part of a public relations working group that advised the Homeland Security Department on its Cyber Storm cybersecurity drill earlier this year. She spoke recently with Staff Writer Alice Lipowicz.WT:
What happened in Cyber Storm from a public relations point of view?Levine:
They had scenarios, "reporters" asking questions, people who were role-playing public information officers. As things unraveled, you could see how quickly the reporters started to ask questions.
None of the information leaked [to the real world]; everyone was respectful that it was an exercise. If you leak information, you cannot have lessons learned. There were no leaks on how technologies worked and did not work.
There were more than 200 organizations involved: federal, state and local, and the private sector. Mistakes were made, of course, since you are trying to push the envelope to see what might break. The fact that this many organizations stepped up to the plate is impressive.WT:
How did you become involved in Cyber Storm?Levine:
I got involved because of my clients McAfee and Citadel. Their technologies were used in the exercise by participating government agencies. These are anti-virus, intrusion-detection and intrusion-prevention technologies.WT:
What was your contribution to Cyber Storm?Levine:
I was in my office, on call, and did some things online. Beforehand, I helped with information for the "real world" press conference, with names for the press release. I helped to shape the message. I applaud DHS, they were very forthcoming in saying what they were hoping to accomplish and the lessons learned.WT:
Do cyberincidents have specific public relations needs?Levine:
Yes, they are very, very serious. We have seen this with data breaches and other situations, such as the theft of the Veterans Affairs Department laptop computer, and it is very scary. From a public relations perspective, you have to be vigilant and pay attention to the world. It's a 24/7 response. You have to respond right away. A good public relations person gets information to the public as soon as possible, letting them know
what happened and what is being done to correct it, to calm fears and reassure everyone that everything is being taken care of as quickly as possible.WT:
How do you decide what to tell the public? Levine:
These are the questions: Can you really contain it? Who does this impact? Are the people to be impacted aware of the situation, and how do we protect them?
The point is there are many systems in our nation controlled by computers and networks, and we need to be aware that they need to be protected. It's expensive and challenging. You cannot put a lock on every single door, so you have to choose and balance, decide how much risk and how much privacy you want.WT:
Looking back on year 2000 as a major cybersecurity issue, how successful was the public relations industry in handling that?Levine:
I think we did a phenomenal job. From a PR perspective, we were very proactive in saying, "This is a problem we can see, and here are the steps you can take." Folks did a very good job of educating the public to make them aware of what might happen and how to prevent it. As you recall, nothing horrible happened. I think there were no problems because people were proactive.WT:
Are there basic misunderstandings about cybersecurity that affect how you explain it to the public?Levine:
Yes. In the last year, more newspapers are trying to cover technology, and some of the reporters might not understand what cybersecurity actually means. They are on deadline and trying to grasp something that is complex ? The challenge is when you talk about all the different types of protective measures you can take ? so many technologies do so many things.
My concern is that people tend to blame the government and say they don't have the right technology. But the VA breach ? that was human error.
Alice Lipowicz is a staff writer covering government 2.0, homeland security and other IT policies for Federal Computer Week.