Agencies are becoming more aware of the cyber threats attacking federal systems daily, but most are still fighting a losing battle, taking too long to identify problems and not using the wealth of data they’re collecting.

A MeriTalk and Splunk survey of 302 cybersecurity professionals working at the federal, state and local levels found malware and other threats that penetrated cyber defenses remained on systems for an average of 16 days before being identified, let alone remediated.

Report: Go Big Security

Similarly, a recent report from the Government Accountability Office reiterated past findings that agencies’ responses to cyber incidents have been inconsistent. The report cited statistics from 2012 that showed agencies failed to document their remediation efforts in 65 percent of incidents and six of the 24 major agencies did not have comprehensive policies on the books.

“The number of information security incidents affecting systems supporting the federal government is increasing,” GAO analysts wrote. “Specifically, the number of information security incidents reported by federal agencies to US-CERT increased from 5,503 in fiscal year 2006 to 67,168 in fiscal year 2014, an increase of 1,121 percent.”

Report: Actions Needed to Address Challenges Facing Federal Systems

As agencies deal with the cyber threat, many are being overwhelmed by the amount of security data being collected.

According to the MeriTalk survey, 68 percent of agencies and organizations are taking in more cybersecurity data than they can manage, with almost 80 percent saying at least some of that data goes unanalyzed.

Another telling statistic showed 76 percent of cybersecurity professionals believe their teams are reactive instead of proactive.

More: FISMA report shows feds weak on user authentication

“Agencies are investing in security technologies, deploying network analysis and visibility solutions and investing in skills training for personnel,” said Bill Glanz, MeriTalk content director, noting “big data isn’t among the go-to solutions.”

MeriTalk analysts suggested agencies make big data a bigger part of their cybersecurity efforts, employing new analytical methods to mine the trove of data in real time.

“It’s time to have an honest conversation about using big data to improve cyber security,” Glanz said.

About 

Aaron Boyd is an awarding-winning journalist currently serving as editor of Federal Times — a Washington, D.C. institution covering federal workforce and contracting for more than 50 years — and Fifth Domain — a news and information hub focused on cybersecurity and cyberwar from a civilian, military and international perspective.