
TESTIMONY OF SARA C. SANTARELLI, VERIZON COMMUNICATIONS BEFORE THE COMMITTEE ON HOMELAND SECURITY AND GOVERNMENTAL AFFAIRS UNITED STATES SENATE “PROTECTING CYBERSPACE AS A NATIONAL ASSET: COMPREHENSIVE LEGISLATION FOR THE 21ST CENTURY“, JUNE 15, 2010
Mr. Chairman, Ranking Member Collins, and members of the Committee, thank you for this opportunity to discuss the important topic of cyber security. My name is Sara Santarelli and as Verizon’s Chief Network Security Officer my primary responsibility is to ensure the integrity of Verizon’s network systems, including risk management, threat detection, and incident response.
The Committee’s interest in cyber security is timely and crucial to the security of our nation. As a provider of communications services to millions of customers around the world, Verizon addresses cyber attacks daily and has developed a wide range of measures intended to help protect our network and the networks of our customers. But this is not a fight that should be left solely to the private sector—there is a very important role for government in securing cyberspace and we applaud the Committee’s efforts to help bring clarity and definition to that role.
The legislation you have proposed represents a positive step forward in building a stronger bond between the public and private sectors with respect to cyber security. While we may not agree with some of the finer points in the bill and look forward to working with your staff to iron out those differences, we feel that the majority of the legislation supports the common goal of creating a much safer online environment for our customers and for the nation. We appreciate the difficulty you face in crafting legislation that is constructive and useful for increasing our nation’s security in cyberspace, while also not placing an undue burden on private companies, large and small, that are struggling in the current economic downturn.
My testimony gives you a brief background of what cyberspace looks like from our point of view and provides several examples of actions we’ve taken over the past few years to address and mitigate online threats. It identifies how we believe a strong partnership between the private companies that own and operate the networks that make up cyberspace can be established with government agencies that are responsible for providing for the security of our nation against all threats, including those in the virtual world.
Verizon manages thousands of voice, video, and data networks at the local, regional, national, and international level. Ours is a global backbone network that carries large volumes of the Internet’s traffic, one of the many thousands of independently owned and operated networks that make up today’s global Internet. Verizon’s data network includes more than 633,000 route miles of terrestrial and undersea cable, spanning six continents, and reaching customers in more than 2,700 cities and 150 countries. We provide communications services to tens of thousands of businesses and government agencies around the globe, including 97 percent of Fortune 500 companies and roughly 10 million residential broadband customers here in the United States.
Given the nature of our business, cyber security is vitally important to us. The Internet is not centrally controlled or managed. Rather, it is a globally distributed network‐of‐networks linked solely by implementation of a few common Internet protocols. It imposes virtually no barrier to any person seeking to reach a global audience.
But as with many technologies, the same capabilities that make the Internet a useful tool for those with good intent can also be used by those with harmful intent. The number of people connected to the Internet is estimated by some to exceed 1 billion, and not all of them have good intentions. The Internet allows for the rapid adoption of useful software applications that enhance users’ lives, but it also allows for the dissemination of harmful viruses that destroy and steal data. It allows for consumers and companies to interact more efficiently with one another, but it also could be used to attack and disrupt commercial transactions. The crossborder nature of the Internet magnifies its potential for good but also complicates law
enforcement.
This is the reality Verizon deals with every day. As a result, Verizon engages in a wide range of activities to enhance cyber security for ourselves, our customers, and other users of our network. These activities take place at many different layers within our organization. For example, before even deploying our network, we work closely with our vendors to help ensure that their products are able to meet our security requirements. Our network security group manages security on our networks using a variety of tools, security sensors, and other technologies to identify and mitigate threats on the Internet as they are emerging. We take action daily to address spam, phishing, denial‐of‐service and other malicious activity that threatens to disrupt our network or our customers’ use of it. We invest in advanced threat detection and mitigation technologies. We also make strategic R&D investments to develop new technologies that deal with emerging and future threats.
In addition to addressing cyber security issues in our network core, we offer a wide range of services to help customers secure their networks and data. Services such as managed firewall, intrusion detection, intrusion prevention, and encrypted virtual private networking help customers keep their networks safe. Verizon’s Government Network Operations and Security Center provides federal agencies with a single point of contact to obtain products and services to meet network operations requirements and related security matters, putting both network and security operations under one umbrella. Our security‐certified data centers offer enhanced security features for customer systems and data. For residential broadband customers we offer parental controls, anti‐spam features, and other security software to assist them in securing their computers.
Going beyond our network services, we offer a wide range of professional services to include security consulting, network analysis, incident response, and computer forensics. Our professional security engineers hold over sixty different certifications and federal clearances, and are available 24/7 around the world to assist customers in responding to breaking cyber security incidents.
When it comes to the security of critical networks and systems, we practice what we preach. Within our own enterprise, network‐connected systems are inventoried and assigned a criticality score based on the sensitivity of the data they contain. They are then scanned periodically to identify security vulnerabilities. The results of the scanning activity are correlated to threats and system value, and the results are automatically displayed in real time on our internal system security dashboard. This real‐time threat and vulnerability information about our own corporate systems has proved invaluable to our internal business leaders in helping them identify affected systems and establish priorities for remediation. Internal groups
actually compete against each other to see who can consistently maintain the cleanest scorecard!
Our backbone security activities redound to the benefit of all of our users at no charge. We spend thousands of hours each year analyzing data collected from our involvement in cyber security events which, after rigorous scrubbing to remove any attribution, we publish, free of charge, in our annual data breach investigation report (DBIR). This report, which uses a Verizon‐developed information‐sharing framework called VERIS that we have also published as an open‐source initiative, provides valuable advice and guidance for enterprise and government customers on tangible, effective steps they can take to better secure their networks today. The bottom line for Verizon is that unless our networks add value, our customers won’t use them.
Customers who are assailed by denial of service attacks, spam, phishing, identity theft, network scanning, hacking, and other criminal activity won’t be customers of ours for long. They will quickly move to a network that is better protected.
Finally, we view ourselves as being a leader in the larger cyber security community. Verizon and other companies within the communications sector have a long history of cooperation in emergency preparedness and assisting law enforcement, to the extent authorized by law. This history distinguishes the sector from most other critical sectors identified in the National Infrastructure Protection Plan and is a reflection of our relationship with the federal government and the public policy community. The sector personifies cooperation and trusted relationships, which has resulted in the delivery of critical services when emergencies and disasters occur. This strong bond between the private and public sectors exists today in large part because of several organizations that were created in response to earlier threats to the nation’s critical infrastructure. Some of the organizations that Verizon has a leadership role in or is a significant participant in include the President’s National Security Telecommunications Advisory Committee (NSTAC), the National Coordination Center for Telecommunications (NCC), the Communications Sector Coordinating Council (C‐SCC), the National Security Information Exchange (NSIE), and the FCC’s Communications Security, Reliability, and Interoperability Council (CSRIC).
Security events are a constant reminder that our networks and our customers’ networks are under a steady assault from individuals, groups, and organizations that intend to do harm. And it is important to note that these assaults are constantly changing and evolving as criminals and hackers develop new techniques to get around the latest defenses. Once launched, these assaults can escalate with astonishing speed. Improvements in computer processing power, memory, and bandwidth not only help support new lawful applications like VoIP and streaming video, but they also enable hackers to wield tremendous weapons in cyber space. Distributed virtual computer networks known as botnets can flood victims with vast amounts of traffic, send millions of spam messages to ensnare new victims, and serve as a virtual hosting network for illicit commercial activity. Government regulation of private sector network security activities must not diminish the flexibility, speed, and independence that network providers find essential in waging war on cyber crime.
In recent years, we have faced many cyberspace challenges as the four examples that follow demonstrate. In each of these cases, we have worked with other parties (providers, companies, the government, and others) to quickly address the issue at hand. Any new requirements must continue to afford us the flexibility and speed to continue resolving problems as we have in the past.
Headlines often make it appear that the Internet is so vulnerable and open to attack that nothing can be done or is being done to safeguard consumers and our country. But what these events illustrate is that public and private sector response and remediation activities and information sharing exist today in ways that are highly advanced and effective, and that speed and flexibility are essential for combating such cyber threats. Even without government mandated information sharing and oversight, private sector operators are—and have been for years—moving “full speed ahead” to expand their tools, expertise, and capabilities necessary to identify threats, address them, and preserve providers’ ability to serve their customers.
That’s not to say there is not a role for government—there is. The government is uniquely positioned to do things the private sector simply can’t. For example, the government has the power to:
With this in mind, we believe government efforts should be focused on the following key goals and objectives, most of which are addressed in the proposed legislation:
We look forward to working with you and your staff on further refining these mechanisms to ensure that network service providers and other private sector actors retain the freedom to act quickly as they see fit to address these ever‐evolving and rapidly spreading threats to our networks, our economy, and our way of life.
Mr. Chairman and members of the Committee, I again thank you for the opportunity to appear before the Committee to discuss the important topic of cyber security and the challenges of securing critical infrastructure information systems. I look forward to answering any questions you may have.
If you would like to make a comment, please fill out the form below.