The State of Our Cyber Is Strong: The View from the White House

RSA Conference 2024 · South Stage Keynote

Overview

In a candid and insightful discussion at RSAC 2024, National Cyber Director Harry Coker Jr. joined former Principal Deputy Director of National Intelligence Sue Gordon to offer a high-level perspective from the White House on the current state of national cybersecurity. The conversation centered on the recently released National Cyber Security Implementation Plan (NCISIP) version two, a pivotal document designed to translate the strategic vision of the National Cyber Security Strategy into tangible, accountable actions. This talk underscored the Biden-Harris administration's commitment to enhancing the nation's digital resilience through unprecedented levels of interagency coordination and robust public-private partnerships.

Watch on YouTube

Visual summary for The State of Our Cyber Is Strong: The View from the White House
Visual summary for The State of Our Cyber Is Strong: The View from the White House

Key moments

  1. 2:00 Overview of National Cyber Strategy Implementation Plan v2
  2. 2:50 Shifting cyber defense responsibility to capable entities
  3. 3:05 Incentivizing long-term investment in cyber resilience
  4. 3:50 Accountability and transparency in the implementation plan
  5. 4:30 The challenge of measuring cybersecurity outcomes and impact
  6. 5:40 Call for community help on cybersecurity effectiveness metrics
  7. 7:30 Praise for the administration's cyber 'dream team'
  8. 8:15 ONCD's role: bringing coherence to federal cyber ecosystem

The State of Our Cyber Is Strong: The View from the White House

Speakers: National Cyber Director Harry Coker Jr., former Principal Deputy Director of National Intelligence Sue Gordon

Conference: RSAC 2024

YouTube: https://www.youtube.com/watch?v=6ZDjGrqJG7I

Overview

In a candid and insightful discussion at RSAC 2024, National Cyber Director Harry Coker Jr. joined former Principal Deputy Director of National Intelligence Sue Gordon to offer a high-level perspective from the White House on the current state of national cybersecurity. The conversation centered on the recently released National Cyber Security Implementation Plan (NCISIP) version two, a pivotal document designed to translate the strategic vision of the National Cyber Security Strategy into tangible, accountable actions. This talk underscored the Biden-Harris administration's commitment to enhancing the nation's digital resilience through unprecedented levels of interagency coordination and robust public-private partnerships.

The dialogue highlighted the critical shifts in the nation's approach to cybersecurity, emphasizing a move from individual end-user responsibility to a collective defense model led by the federal government and Big Tech. Director Coker detailed the ambitious scope of NCISIP v2, which outlines 100 specific actions with assigned lead agencies, deliverables, and due dates, reflecting a new era of transparency and accountability in federal cyber initiatives. This discussion is particularly relevant for cybersecurity professionals, policymakers, and critical infrastructure operators who seek to understand the strategic direction and operational priorities guiding the United States' efforts to secure its digital landscape against an increasingly sophisticated and pervasive threat environment.

Why this talk matters is rooted in the fundamental reality that cybersecurity is no longer merely a technical challenge but a core component of national security, economic stability, and societal well-being. With nation-state adversaries actively targeting critical infrastructure and the digital supply chain, the White House's comprehensive approach, as articulated by Director Coker, provides a roadmap for collective action. It serves as a call to arms for all stakeholders—government, private sector, and local communities—to collaborate in building a more resilient and defensible cyber ecosystem, acknowledging that no single entity can tackle these complex threats alone.

Background

▶ Watch: Overview of National Cyber Strategy Implementation Plan v2 (2:00)

The evolution of U.S. national cybersecurity strategy has been a journey marked by increasing recognition of the pervasive digital threat and the imperative for a unified national response. Prior to the current administration, efforts were often fragmented, with various agencies addressing cyber challenges in isolation. The establishment of the Office of the National Cyber Director (ONCD) was a landmark development, born from a bipartisan consensus that the nation required a central coordinating body to bring coherence to the vast and complex federal cybersecurity ecosystem. Congress recognized that while exceptional mission partners existed, their efforts needed to be more coordinated and strategically aligned.

The National Cyber Security Strategy, released in March 2023, represented a significant policy shift. It articulated two primary objectives designed to fundamentally alter the landscape of cybersecurity responsibility and investment. Firstly, it aimed to shift the burden of defending cyberspace away from individual end-users and onto "those that are more capable" – specifically, the federal government and large technology companies. This acknowledges the inherent asymmetry where individual users often lack the resources, expertise, and visibility to defend against sophisticated threats, while large organizations possess greater capacity to implement robust security measures and absorb costs. Secondly, the strategy sought to incentivize long-term investment in resilience, moving beyond reactive defense to proactive measures that ensure critical systems can withstand and rapidly recover from cyberattacks. This shift recognizes that perfect prevention is often unattainable, and the ability to endure and adapt is paramount.

The initial version of the National Cyber Security Implementation Plan (NCISIP v1) was developed to operationalize these strategic shifts, outlining 69 initiatives to guide federal agencies. However, as Director Coker highlighted, a strategy, no matter how well-written, remains largely aspirational without a concrete plan for execution and accountability. The continuous growth and evolving nature of cyber threats, coupled with the lessons learned from previous administrations and initiatives like the Cyberspace Solarium Commission, necessitated a more robust and dynamic approach to implementation. This led to the development of NCISIP v2, which builds upon previous efforts to provide a more detailed, transparent, and actionable framework for securing the nation's digital future, reflecting a maturing understanding of the scale and complexity of the problem.

Key Findings

▶ Watch: Incentivizing long-term investment in cyber resilience (3:05)

The central finding of this discussion is the unveiling and detailed explanation of the National Cyber Security Implementation Plan (NCISIP) version two. This document is a significant leap forward, expanding on its predecessor with 100 distinct actions designed to operationalize the National Cyber Security Strategy. A core tenet of NCISIP v2, as highlighted by Director Coker, is its commitment to transparency and accountability. Unlike previous strategies that might have lacked clear ownership, NCISIP v2 explicitly assigns lead departments and agencies for each action, defines specific deliverables, and sets clear due dates. This programmatic approach, rooted in the speakers' shared background in program management, aims to ensure that progress is measurable and that responsibility cannot be diffused.

Another critical finding is the administration's frank acknowledgment of the challenges in measuring outcomes in cybersecurity. While NCISIP v2 focuses on observable outputs (the 100 actions and their deliverables), Director Coker emphasized the fundamental difference between outputs and actual outcomes – the real-world impact on digital resilience and security. He called for community assistance in developing robust measures of effectiveness for cybersecurity, citing a technical report issued earlier in the year on memory-safe programming languages which, beyond its primary focus, also underscored the urgent need for better metrics in software measurability. This reveals a pragmatic understanding that while the government can mandate actions, the broader cybersecurity community's expertise is essential for truly gauging the impact and refining future strategies.

Furthermore, the talk underscored the significant, albeit ongoing, progress in fostering public-private partnerships. Director Coker noted that while the term "public-private partnership" has been frequently used, it historically often represented a one-way street where the government requested information and capabilities without full reciprocation. Recent engagements, including a session with 16 CEOs of Big Tech companies, indicated a positive shift, with the private sector acknowledging a stronger, more collaborative relationship. This finding suggests a growing mutual trust and recognition of shared responsibility, which is vital for addressing threats that transcend governmental and corporate boundaries. The collective effort to bring coherence to the federal cyber ecosystem, led by ONCD, and the increasing coordination among key operational partners like CISA, NSA, FBI, and Cyber Command, further illustrate a strengthening national cyber posture, though with the consistent caveat that "we have to do more."

Technical Deep Dive

▶ Watch: The challenge of measuring cybersecurity outcomes and impact (4:30)

While "The State of Our Cyber Is Strong" is primarily a policy and strategy discussion rather than a deep dive into specific code or protocols, it meticulously outlines the architectural framework and operational dynamics of the United States' national cybersecurity efforts. The structure described is akin to a distributed system, with the Office of the National Cyber Director (ONCD) acting as the central orchestrator, tasked with bringing coherence to the sprawling federal cybersecurity ecosystem. Director Coker clarified ONCD's distinct role: it serves as the President's principal advisor on cyber security strategy and policy, but crucially, it does not possess operational responsibility. This clear delineation allows ONCD to focus on strategic alignment, policy development, and cross-agency coordination, leaving execution to specialized operational entities.

The "dream team" mentioned by Director Coker—comprising Chris Inglis (the first National Cyber Director), Anne Neuberger (Deputy National Security Advisor for Cyber and Emerging Technology), and Jen Easterly (Director of CISA)—exemplifies the high-level talent and strategic intent behind the current administration's cyber initiatives. This leadership was instrumental in establishing the foundational coherence that ONCD now stewards.

Key operational partners form the distributed nodes of this cyber defense architecture. These include:

  • CISA (Cybersecurity and Infrastructure Security Agency): The nation’s risk advisor, working to understand, manage, and reduce risk to the cyber and physical infrastructure.
  • NSA (National Security Agency): Focused on signals intelligence and cybersecurity for national security systems.
  • FBI (Federal Bureau of Investigation): Responsible for investigating cybercrime and national security cyber threats.
  • Cyber Command (USCYBERCOM): Conducts military cyberspace operations to defend and advance U.S. national interests.
  • Department of State: Recently issued its own International Cyber Security Strategy, demonstrating a unified front across diplomatic and national security domains.

The strategies of these operational partners are designed to flow directly from the overarching National Cyber Security Strategy, ensuring a cascade of aligned objectives and actions throughout the federal government. This top-down strategic alignment, coupled with ONCD's informal leadership and emphasis on collaboration, aims to maximize the collective impact.

A significant structural element highlighted is the strengthening of Sector Risk Management Agencies (SRMAs). These federal departments and agencies act as the primary conduits for public-private partnerships with the owners and operators of America's critical infrastructure. Historically, the focus on critical infrastructure was predominantly on physical threats; however, the cyber threat is now recognized as severe and persistent. SRMAs are being resourced with the necessary personnel, expertise, and capabilities to effectively partner with critical infrastructure entities in their respective sectors (e.g., energy, finance, transportation). This decentralized approach leverages sector-specific knowledge while ensuring a consistent national cybersecurity posture.

Finally, the talk underscored the critical vulnerability and need for enhanced support for State, Local, Tribal, and Territorial (SLTT) entities. These entities, often operating with limited resources, are frequently targeted by nation-state actors who seek out the "weakest link" in the national defense chain. Securing public utilities, school systems, hospitals, and local governments at this level is crucial, as adversaries view them not just as targets for data exfiltration or disruption but as potential entry points to broader national infrastructure or as means to disrupt military mobilization in a conflict scenario. The challenge of effectively supporting these diverse and resource-constrained entities represents a significant ongoing architectural and policy hurdle.

Demo / Proof of Concept

▶ Watch: Call for community help on cybersecurity effectiveness metrics (5:40)

This particular talk, focusing on high-level strategy, policy, and national coordination, did not include a technical demonstration or a proof of concept. The discussion was centered on the implementation plan for the National Cyber Security Strategy, detailing organizational structures, strategic shifts, and collaborative efforts rather than specific tools, exploits, or defensive technologies.

Defensive Implications

▶ Watch: ONCD's role: bringing coherence to federal cyber ecosystem (8:15)

The insights shared by Director Coker and Sue Gordon carry profound defensive implications for a broad spectrum of stakeholders, from federal agencies to local communities and the private sector. Understanding these implications is crucial for developing robust and adaptive cybersecurity postures.

  1. Shift in Responsibility and Investment: The most significant implication is the explicit shift in responsibility for cybersecurity from end-users to more capable entities – primarily the federal government and Big Tech. For private sector organizations, especially large technology providers, this means an increased expectation and, potentially, regulatory pressure to embed security by design, invest in resilient architectures, and contribute to the collective defense. For smaller businesses and individual users, while the ultimate burden is shifting, it doesn't absolve them of basic cyber hygiene. Instead, it implies they should expect and demand more secure products and services from their providers. This also mandates long-term investment in resilience, encouraging organizations to move beyond mere compliance to proactive measures that ensure continuity of operations even in the face of attack.
  1. Enhanced Public-Private Collaboration: The acknowledged strengthening of public-private partnerships necessitates active engagement from both sides. Private sector companies should proactively participate in information sharing initiatives, contribute expertise to policy development (e.g., metrics for software measurability), and collaborate with government agencies on threat intelligence and incident response. The government, in turn, is committed to reciprocation, providing valuable insights and support. Organizations that historically viewed government engagement as a one-way street must adapt to this new paradigm of mutual support.
  1. Critical Infrastructure Protection: The focus on strengthening Sector Risk Management Agencies (SRMAs) directly impacts owners and operators of critical infrastructure. These entities should expect increased engagement from their respective SRMAs, which will be better resourced with personnel, expertise, and capabilities. This means more opportunities for collaboration, information sharing, and potentially, joint exercises to enhance resilience against nation-state threats. Critical infrastructure operators must recognize that they are not just targets for financial gain or espionage, but potential strategic targets for disruption in a conflict scenario, as evidenced by the PRC's Volt Typhoon network targeting U.S. infrastructure for military mobilization disruption. This demands a heightened level of vigilance and partnership.
  1. Support for State, Local, Tribal, and Territorial (SLTT) Entities: The recognition that SLTTs represent a potential "weak link" for adversaries implies a forthcoming push for increased federal assistance and resources. SLTT governments and public utilities should actively seek out and leverage these evolving support mechanisms, whether through CISA, federal grant programs, or direct engagement with federal partners. Investing in foundational cybersecurity capabilities, even basic ones, will be critical to receiving and effectively utilizing this support. The lesson learned during the pandemic – that global threats have local effects – underscores the urgency for SLTTs to bolster their defenses.
  1. Threat Awareness and Demand for Action: The public disclosure of nation-state threats, particularly from the PRC, against critical infrastructure serves as a call to action for the broader public. Citizens need to be aware of the severity of these threats and demand robust defensive measures from their government and service providers. For organizations, this means understanding that they are either "the target or the transportation" – everyone will be affected. This necessitates a proactive, layered defense strategy that assumes compromise and focuses on detection, response, and recovery.
  1. Focus on Measurable Outcomes: The emphasis on developing better measures of effectiveness for cybersecurity signals a shift towards data-driven defense. Defenders should contribute to and adopt metrics that go beyond simple compliance or output (e.g., number of patches installed) to truly assess the reduction of risk and improvement in resilience (e.g., time to detect, time to respond, mean time to recovery). This also reinforces the importance of adopting secure development practices, such as using memory-safe programming languages, as a foundational step towards improving software security measurability and overall digital hygiene.

Key Takeaways

  • NCISIP v2 is the operational roadmap: The National Cyber Security Implementation Plan version two outlines 100 specific, transparent, and accountable actions with assigned lead agencies, deliverables, and due dates, providing a clear framework for national cyber defense.
  • Responsibility is Shifting: The U.S. strategy is actively moving the primary burden of cyber defense from individual end-users to the federal government and large technology companies, emphasizing collective defense and long-term resilience.
  • Public-Private Partnership is Strengthening: While still evolving, collaboration between the government and the private sector is improving, fostering a more reciprocal relationship essential for addressing complex global cyber threats.
  • Critical Infrastructure is a Strategic Target: Nation-state adversaries, notably the PRC (via Volt Typhoon), are targeting U.S. critical infrastructure not just for espionage or financial gain, but for potential disruption during a conflict, necessitating heightened vigilance and strong SRMAs.
  • SLTT Entities Need More Support: State, Local, Tribal, and Territorial governments and public services are recognized as potential "weak links" and require significantly more federal assistance and resources to defend against sophisticated threats.
  • Measuring Outcomes is a Collective Challenge: The cybersecurity community needs to collaborate on developing robust measures of effectiveness, moving beyond mere outputs to truly gauge the impact of defensive efforts and improve software measurability, including the adoption of memory-safe programming languages.

About the Speaker(s)

Harry Coker Jr. is the current National Cyber Director, serving in a pivotal role within the White House to coordinate the nation's cybersecurity strategy and policy. His background includes extensive leadership experience, having served in the military and in various government capacities. As the National Cyber Director, he is responsible for bringing coherence to the federal cybersecurity ecosystem, advising the President on cyber strategy, and driving the implementation of national cyber initiatives without holding direct operational authority.

Sue Gordon is the former Principal Deputy Director of National Intelligence. With a distinguished career in intelligence, she has held numerous significant positions within the U.S. government, providing her with deep insights into national security and cyber threats. Beyond her impressive professional accolades, she is also noted for her athletic achievements, having been a three-time captain of the Duke University basketball team. Her expertise lies in understanding complex threat environments and fostering collaboration across diverse agencies.

All talks from RSA Conference 2024