FLORIDA'S CRITICAL INFRASTRUCTURE RISK ASSESSMENT (CIRA) OCTOBER 2022
WHY ARE WE DOING THIS? State of Florida Appropriation 2944B FY 2023 states that Cyber Florida shall conduct a risk assessment of the state’s critical infrastructure (CI) and submit a draft report by 9 Jan 2023 and a final report with actionable solutions to improve the state’s preparedness and resilience to significant cybersecurity incidents by 30 Jun 2023 2
WHAT ARE WE EVALUATING? • The CI Risk Assessment (CIRA) includes the 16 Critical Infrastructure sectors as identified by the State of Florida and the Department of Homeland Security (DHS) • Cyber Florida will assess the current status of the state’s CI posture to protect against cyberattacks • Data collection and analytics to determine a baseline and develop actionable solutions to improve and protect the state’s CI against cyber-attacks
3
WHY ARE WE LOOKING AT THIS? • The threat landscape for cyberattacks increases daily.
• Cyber Florida will establish a baseline of current CI cybersecurity protections and provide actionable solutions to increase the state’s CI preparedness and resilience to cyberattacks. • Reduce vulnerabilities of critical systems, assets, and networks while increasing resiliency and security to protect the people, property, and prosperity of Florida.
4
WHAT ARE WE ORGANIZING? • Developing a state-wide confidential/anonymous survey to measure the state’s CI against standards set forth by the National Institute of Science and Technology (NIST) and the Cybersecurity Framework (CSF) • Utilizing Idaho National Lab (INL) Cybersecurity Evaluation Tool (CSET) downloaded to a USF server • All data submitted will be sent to USF • A robust communications, outreach, and educational platforms to increase awareness and training in utilizing the tool to increase engagement from CI owners/operators. • Phase 1 All CI Sectors in Regions 1, 2, 3, 4, 5, and 7 • Phase 2 All CI Sectors in Region 6
5
WHAT ARE THE DELIVERABLES? • A statewide report to support actionable solutions for improving the state’s preparedness and resiliency to cyber attacks • Creation of a FL Cybersecurity Risk Assessment tool • Individual risk assessment at NO cost to CI owners/operators • Cyber Florida certification of completion • Advocacy of resources working with partner agencies INL, MITRE, State of Florida, and community leaders 6
WHEN WILL IT BE READY? • Oct 2022, an anonymous and secure self-assessment will be delivered to lifeline CI sectors • A preliminary report will be shared with the Leaders of the Legislative Branch and the Governor by 9 Jan 2023 • A final report with the remaining CI’s assessment will be shared with the Leaders of the Legislative Branch and the Governor by 30 June 2023
7
CYBERSECURITY EVALUATION TOOL • Idaho National Labs • 156 questions • Baseline of FL CI • Data and participation will feed into report
8
HOW CAN YOU HELP AND WHY? • Complete and submit the CSET • Creating a baseline to determine future support and investments
• Help advocate security and resiliency by participating • Share with your vendors, contractors, suppliers, etc.
• Help inform the legislature of the most urgent need of funding and resources • Cybersecureflorida.org
9
QUESTIONS/COMMENTS? https://cyberflorida.org/cybersecureflorida/ Bryan Langley bjlangley@cyberflorida.org
10
Emilio Salabarria Sr. esalabarria@cyberflorida.org