The White House has published its National Cybersecurity guidelines, aiming to make fundamental shifts in how the United State allocates roles, responsibilities, and resources in cyberspace.
The strategy says there must be a rebalancing in the burden of cybersecurity away from individuals, small businesses, and local governments, and onto the organisations that are most capable and best-positioned to reduce risks.
Furthermore, it states that incentives must be realigned to favour long-term investments by striking a balance between defence against urgent threats and simultaneously planning for and investing in a ‘resilient future.’
What’s the strategy’s vision?
The guidelines demand a more ‘intentional, more coordinated, and more well-resourced approach to cyber-defense’, in light of the complex threat environment, with state and non-state actors developing and executing novel campaigns to threaten national interests. It also states that ‘next-generation technologies are reaching maturity at an accelerating pace, creating new pathways for innovation while increasing digital interdependencies.’
The administration claims it has already taken steps to secure cyberspace and the digital ecosystem, with initiatives including the National Security Strategy, Executive Order 14028 (Improving the Nation’s Cybersecurity), National Security Memorandum 5 (Improving Cybersecurity for Critical Infrastructure Control Systems), M-22-09 (Moving the U.S. Government Toward Zero-Trust Cybersecurity Principles), and National Security Memorandum 10 (Promoting United States Leadership in Quantum Computing While Mitigating Risks to Vulnerable Cryptographic Systems).
What’s the approach?
The strategy seeks to build and enhance collaboration around five pillars:
1 Defend Critical Infrastructure
This entails expanding the use of minimum cybersecurity requirements in critical sectors to ensure national security and public safety and harmonising regulations to reduce the burden of compliance. Furthurmore, the strategy will seek to enable public-private collaboration at the speed and scale necessary to defend critical infrastructure and essential services. Finally, defending and modernising Federal networks and updating Federal incident response policy has been cited as a priority.
2 Disrupt and Dismantle Threat Actors
Using all ‘instruments of national power’, the White House aims to make malicious cyber-actors incapable of threatening the national security or public safety of the United States, by strategically employing all tools of national power to disrupt adversaries; Engaging the private sector in disruption activities through scalable mechanisms; and, Addressing the ransomware threat through a Federal approach and in lockstep with the US’ international partners.
3 Shape Market Forces to Drive Security and Resilience
The US Gov will place responsibility on those within its digital ecosystem that are best positioned to reduce risk and shift the consequences of poor cybersecurity away from the most vulnerable in order to make the digital ecosystem more trustworthy.
It seeks to do this by promoting privacy and the security of personal data; shifting liability for software products and services to promote secure development practices; and, ensuring that Federal grant programs promote investments in new infrastructure that are secure and resilient.
Recommended
- Comment | The 2023 Regulatory Reporting Landscape
- UK Retailor WH Smith Suffers Cyber ‘Incident’
- AI Could Revolutionise Organ Transplant System
4 Invest in a Resilient Future
Through strategic investments and coordinated, collaborative action, the United States will seek to reduce systemic technical vulnerabilities in the foundation of the Internet and across the digital ecosystem while making it more resilient against transnational digital repression; prioritize cybersecurity R&D for next-generation technologies such as postquantum encryption, digital identity solutions, and clean energy infrastructure; and, develop a ‘diverse and robust national cyber workforce.’
5 Forge International Partnerships to Pursue Shared Goals
The United States seeks a ‘world where responsible state behavior in cyberspace is expected and reinforced and where irresponsible behavior is isolating and costly’, specifically by:
- Leveraging international coalitions and partnerships among like-minded nations to counter threats to our digital ecosystem through joint preparedness, response, and cost imposition;
- Increasing the capacity of our partners to defend themselves against cyber threats, both in peacetime and in crisis; and,
- Working with our allies and partners to make secure, reliable, and trustworthy global supply chains for information and communications technology and operational technology products and services.





