Malware silently spread through a Texas law enforcement system—hidden inside body camera footage that police uploaded to the department server and then shared with county officials, prosecutors, and defense attorneys. As the compromised video traveled through the chain of command, the danger of putting highly sensitive data at risk only grew.

That is one example that highlights how important it is for various arms of law enforcement to receive adequate cyber training, explains Justin Miller, associate professor of practice of cyber studies at University of Tulsa, and a retired senior special agent with the U.S. Secret Service. The police department bought body cameras thinking the biggest concern was going to be storage costs, but they actually opened themselves up to an attack. The real cost turned out to be more cyber training.

Any investigation nowadays will have a cyber component, and different officers and authorities need to understand the basics of how to secure digital evidence, Miller tells Dark Reading. However, it’s proving difficult due to budget constraints, strained resources, and competing priorities.

Related:Mission-Driven Security: Inside a Global Bank’s Defense

While the National Computer Forensics Institute (NCFI) does provide helpful training to state and local law enforcement, as well as prosecutors and judges, long-term funding remains difficult, Miller adds.

“You’ve got to find a piece to continue that funding because we may give you the equipment to start, and sometimes there’s programs that will continue to pay, but after five or six years from that initial startup, then it’s kind of on the police department to continue the upgrades and those costs just sneak up on people,” he says.

The Barriers: Funding and Focus

When Miller worked as a police officer, he’d over hand over his reporting to a detective who would then follow up. Now that process has evolved; police officers are more often responsible to be the first on the scene to secure critical evidence.

Therefore, NCFI training, which Miller was a part of from 2019 to 2022, focuses on how to place evidence in signal-blocking Faraday bags and capture volatile memory from computers’ short-term Random Access Memory (RAM), explains Miller. Crucial evidence can be scraped off computers, so officers learn which tools to use before they turn off the computer and potentially lose everything, he says.

Though the case for training is high, the cost is higher — even the price for Faraday bags, which can cost hundreds of dollars. Unexpected expenses continually pop up when someone is trying to run cyber operations or curate a cyber-aware department, adds Miller. For example, they face data storage burdens and concerns that the equipment they buy was not already compromised by cybercriminals, like the Texas body cams.

Related:Walmart Takes a ‘Trusted Agent’ Approach to Purple Teaming

Funding isn’t the only barrier to improving training; focus is also an issue, says Cynthia Kaiser, SVP of Halcyon’s ransomware research center and a former FBI cyber deputy director. Law enforcement needs money to implement training, it also likely needs policymakers to who are willing to make it a priority, and push it through the system. Progress can be difficult if leadership doesn’t back it.

Further support is necessary as cybercrime explodes. The culture at the local law enforcement level is to defer cases to the FBI if they lack technically trained personnel, Kaiser notes, warning that it’s not a sustainable system. The Internet Crime Complaint Center receives around 3,000 or more tips a day, which makes it difficult for the FBI to keep up with all of the threats, whether potential or real.

“You have a lot of victims across America who have no recourse with no one helping them,” Kaiser tells Dark Reading. “We really have to get our local law enforcement better cyber training to be able to be a force multiplier across the U.S.”

Related:Walmart Leaders Transform Security Operations Without Going Bananas

Her recommendation is to add cyber training to the FBI National Academy, which is widely attended by various arms of law enforcement, including sheriffs. And that training doesn’t even have to be super sophisticated; it’s more important to get additional funding just to provide the basics, she adds.

“I don’t think we’re talking about countering the Chinese, but we’re talking about being able to follow the digital evidence of a scam,” she says.

‘Training Should Not Stop’

While funding is a major barrier to cyber training, the limited availability of qualified experts who can deliver meaningful instruction may be just as significant an obstacle due to the constantly evolving nature of cybercrime, says Cooper A. Maher, assistant professor at Michigan State University’s School of Criminal Justice.

The training itself needs to shift focus to better support the needs of officers responding to cybercrime, Maher adds. It’s tough enough for law enforcement to keep with threat actors who launch ransomware attacks, pig-butchering, and romance scams at massive scales. The list of cybercrimes is only growing and becoming more dangerous.

Many aspects of training focus on internet crimes against children. And while that is critical, education needs to expand to address online fraud, impersonation, and cyberstalking, Maher adds.

The need for training is most pronounced among front-line officers operating at the local level because they face an increased number of cybercrime cases and digital evidence, observes Maher. Like Kaiser, he supports putting tools into the hands of local officers who act as first responders. In many cases it can alleviate pressures on specialized investigators, who operate with strained resources due to the high number of cybercrime-related complaints flooding their lines.

The first step to promote cyber training is to start at the law-enforcement academy, recommends Maher.

“Since academy training is mandated prior to serving as a sworn officer, they are great opportunities to ensure that all officers are able to respond to cybercrime moving forward,” he says. “Training should not stop at the academy, however, and should be an ongoing process which reflects the evolving nature of cybercrime.”





Source link

#

Comments are closed