Experts debate US national cyber strategy priorities
Atlantic Council panel of cyber policy experts discusses what should shape the upcoming US national cyber strategy, citing SolarWinds and Colonial Pipeline as cautionary examples.
This is an opinion/discussion piece from the Atlantic Council's Cyber Statecraft Initiative, presenting five cybersecurity policy experts' views on the structure, goals, and measures of success for a future US national cyber strategy, prompted by the UK's newly published Government Cyber Security Strategy and anticipation of a US equivalent. The panelists—including Jason Healey, Joshua Rovner, Emma Schroeder, Camille Stewart, and Heli Tiirmaa-Klaar—debate topics such as public-private collaboration, offense/defense balance, measuring strategic effectiveness, and organizational roles across government agencies.
Notable threat references are used illustratively rather than as new reporting: Tiirmaa-Klaar cites the 2020 SolarWinds supply-chain compromise (attributing the intrusion to Sandworm, though mainstream attribution for that specific campaign is APT29/Cozy Bear) and the 2021 Colonial Pipeline ransomware incident as evidence of insufficient private-sector cybersecurity investment in the United States. Estonia's resilience to the 2017 NotPetya ransomware outbreak is offered as a positive case study of rigorous patching and public-private threat-sharing. The article is fundamentally a policy and strategy discussion piece with no new technical findings, indicators, or active threat campaigns described.
Mentioned in this report
Source reporting: https://www.atlanticcouncil.org/content-series/the-5x5/the-5x5-whats-in-a-cyber-strategy
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free