The Biden Administration has released its long-awaited National Cybersecurity Strategy that sketches a blueprint for how the federal government plans to deal with the immense volume of cyber threats hitting targets in the public and private sectors and critical infrastructure facilities.The 35-page document is not law and the White House does not expect it to pass Congress in its current iteration but hopes that it will serve as a guideline for future cyber legislation. Indeed, in its current form it could also serve as a standard for how third-party companies compete for lucrative federal and private sector contracts based on minimally acceptable cybersecurity protections by law.Walden said that the "biggest, most capable and best-positioned actors in our digital ecosystem can and should shoulder a greater share of the burden for managing cyber risk and keeping us all safe.”She added that laying responsibility on individuals and groups who lack the resources to protect themselves is both “unfair” and “ineffective.” And vendors are currently rewarded for being “first to market, not secure to market.” Translated, it means that the policy asks the tech sector to bake security into its products, similar to a call to action that CISA Director Jen Easterly delivered in remarks last week at Carnegie Mellon University in a lead-in to the cyber policy document.2.) Disrupt and Dismantle Threat Actors3.) Shape Market Forces to Drive Security and Resilience4.) Invest in a Resilient Future5.) Forge International Partnerships to Pursue Shared Goals
Strategy's MSSP Advantage
The document gives managed security service providers (MSSPs) a potentially notable windfall, set up as they are to deliver cyber expertise well beyond what other third-party providers can do. While the policy paper does not specifically mention MSSPs, the inference and opportunity is clear for big deals in the public and private sector.The bottom line change is that the proposition relieves individuals, small businesses and local governments from the burden of implementing and protecting their cyber investments. In truth, the White House doesn't have the power to make the tech sector do anything, but the strategy is much more than ideas and intentions: It can serve as a beacon of where legislative priorities are headed and signal which companies are leading the charge.Commenting on the strategy during a press briefing, Acting National Cyber Director Kemba Walden said:“The president’s strategy fundamentally reimagines America’s cyber social contract. It will rebalance the responsibility for managing cyber risk onto those who are most able to bear it.”
A Closer Look at the White House Cyber Strategy
Among the key precepts of the document, the White House is proposing that legislation be directed at software makers that fail to safeguard their products and services, suggesting that a bill of that magnitude not be merely a stick but also a carrot. The Administration is offering an “adaptable safe harbor framework” to protect companies that follow through with locking down their products from digital sabotage.“Companies that make software must have the freedom to innovate, but they must also be held liable when they fail to live up to the duty of care they owe consumers, businesses or critical infrastructure providers,” the White House said in the report.The national cybersecurity strategy is built on what the Administration calls five pillars (abridged and based on a White House fact sheet):1.) Defend Critical Infrastructure- Expanding the use of minimum cybersecurity requirements in critical sectors to ensure national security and public safety
- Strategically employing all tools of national power to disrupt adversaries
- Engaging the private sector in disruption activities through scalable mechanisms
- Addressing the ransomware threat through a comprehensive Federal approach and in lockstep with our international partners
- Promoting privacy and the security of personal data
- Shifting liability for software products and services to promote secure development practices
- Ensuring that Federal grant programs promote investments in new infrastructure that are secure and resilient
- Prioritizing cybersecurity R&D for next-generation technologies such as postquantum encryption, digital identity solutions, and clean energy infrastructure
- Developing a diverse and robust national cyber workforce
- Leveraging international coalitions and partnerships among like-minded nations to counter threats to our digital ecosystem through joint preparedness, response, and cost imposition
- Increasing the capacity of our partners to defend themselves against cyber threats, both in peacetime and in crisis
- Working with our allies and partners to make secure, reliable, and trustworthy global supply chains for information and communications technology and operational technology products and services




