The U.S. government recently released a new National Cybersecurity Strategy, detailing recommendations and changes to ensure a safe and secure digital ecosystem. The policy document from the White House represents several major shifts to defend cyberspace, stay resilient against attacks, and protect national security.
Since the last strategy came out during the previous administration in 2018, the cybersecurity landscape has changed dramatically. There has been a massive distribution in the workforce from the COVID-19 pandemic, as well as increased cyber intrusions and ransomware attacks. Despite the time in between official cybersecurity strategies, the current administration has not been lax in its consideration of the cyber landscape. This new document comes on the heels of conversations around the cybersecurity of IoT devices, new executive orders regarding cybersecurity, and legislation around cyber disclosure. So while the strategy is not new law or executive order, the strategy does come at a very timely and critical inflection point.
The 35-page document lays out a cyber roadmap using five key pillars to build and enhance collaboration. In these details, Bitsight has identified two major strategy shifts:
- New regulatory requirements for critical infrastructure
- A new focus on reducing risks from insecure software & IoT devices
Cyber shift #1: New regulatory requirements for critical infrastructure
The document’s first pillar discusses the strategy around defending critical infrastructure. First, I will summarize this pillar, and then provide Bitsight’s takeaways.
Strategy summary: Defend critical infrastructure
For years, there has been a debate in the U.S. about broadening cybersecurity regulation for critical infrastructure owners and operators. Broadly speaking, some critical infrastructure sectors—such as the financial sector and parts of the energy sector—have had years of cybersecurity regulations. Meanwhile, others—like water, food, and agriculture systems—have largely been voluntary. The new strategy calls for the development of new mandatory requirements for non-regulated entities calibrated to meet the needs of national security and public safety. Specifically, the strategy describes taking a performance-based approach.
Bitsight takeaways: Defending critical infrastructure requires better visibility and measurement within government
Currently non-regulated entities will likely view new regulatory proposals as controversial, particularly in the absence of meaningful measurements and metrics to describe the current situation. Policymakers have long grappled with implementing an approach to cybersecurity rooted in data and metrics, rather than subjectivity or perception. Cybersecurity may be notoriously difficult to measure, but it’s exactly what is needed to be successful.
For years, Bitsight has suggested that policymakers leverage data and measurement to understand the performance of critical infrastructure sectors and industries. Data-driven decisions are inherently more trustworthy and valuable, and it’s critical that the government rely on data and metrics to effectively implement this (or any) cyber strategy.
The strategy recognizes the importance of data-driven decision-making. According to the document, “In implementing this strategy, the Federal Government will take a data-driven approach. We will measure investments made, our progress toward implementation, and ultimate outcomes and effectiveness of these efforts.”
Bitsight encourages national and international policymakers to accelerate their efforts in developing a baseline of cybersecurity performance across sectors and industries to make better decisions about new policies and regulations to protect sensitive data.