The ongoing digitalization of surveillance processes, coupled with increased cybersecurity threats, has led the CIA to launch a digital directorate focused on improved monitoring and protecting electronic information.

In a letter that was made publicly available on the CIA’s website, CIA Director John Brennan said the Directorate of Digital Innovation would span activities such as listening in on social media channels, cyber espionage and more traditional security functions such as protecting email servers.

Experts told SC Magazine that while the CIA obviously needs to keep pace with modern forms of communication, the digital directorate could raise more questions about other public sector organizations such as the National Security Agency (NSA), which has been criticized for spying on citizens. As its reorganization takes shape, the CIA may need to explain which types of checks and balances will be put in place to prevent overreaches.

On the other hand, the Washington Post said the digital directorate will create better cohesion throughout the CIA, particularly branches that have focused on potential cyberattacks from foreign entities and those that provide various forms of data analysis. The overhaul will also provide a means of training and developing talent to help CIA agents avoid being tracked by their digital activities.

This is only the latest move by a U.S. government organization to take steps toward better IT security. Just last month, the White House announced a broad cybersecurity strategy as part of President Barack Obama’s State of the Union address, which looked at measures by which private businesses could better share information about data breaches and cyberattacks. With that backdrop, it’s unsurprising that the CIA is also placing greater emphasis on studying the way information is digitally collected and stored.

In a story from Reuters, former CIA officials said too much of the expertise on digital subjects has been siloed across the agency, which reportedly hasn’t pursued a reorganization of this magnitude in more than 20 years. Given external threats such as ISIS and internal threats such as Edward Snowden — who was a contractor for the CIA and NSA — the digital directorate feels nearly inevitable.

More from

Worms of Wisdom: How WannaCry Shapes Cybersecurity Today

WannaCry wasn't a particularly complex or innovative ransomware attack. What made it unique, however, was its rapid spread. Using the EternalBlue exploit, malware could quickly move from device to device, leveraging a flaw in the Microsoft Windows Server Message Block (SMB) protocol. As a result, when the WannaCry "ransomworm" hit networks in 2017, it expanded to wreak havoc on high-profile systems worldwide. While the discovery of a "kill switch" in the code blunted the spread of the attack and newly…

Emotional Blowback: Dealing With Post-Incident Stress

Cyberattacks are on the rise as adversaries find new ways of creating chaos and increasing profits. Attacks evolve constantly and often involve real-world consequences. The growing criminal Software-as-a-Service enterprise puts ready-made tools in the hands of threat actors who can use them against the software supply chain and other critical systems. And then there's the threat of nation-state attacks, with major incidents reported every month and no sign of them slowing. Amidst these growing concerns, cybersecurity professionals continue to report…

RansomExx Upgrades to Rust

IBM Security X-Force Threat Researchers have discovered a new variant of the RansomExx ransomware that has been rewritten in the Rust programming language, joining a growing trend of ransomware developers switching to the language. Malware written in Rust often benefits from lower AV detection rates (compared to those written in more common languages) and this may have been the primary reason to use the language. For example, the sample analyzed in this report was not detected as malicious in the…

Why Operational Technology Security Cannot Be Avoided

Operational technology (OT) includes any hardware and software that directly monitors and controls industrial equipment and all its assets, processes and events to detect or initiate a change. Yet despite occupying a critical role in a large number of essential industries, OT security is also uniquely vulnerable to attack. From power grids to nuclear plants, attacks on OT systems have caused devastating work interruptions and physical damage in industries across the globe. In fact, cyberattacks with OT targets have substantially…