Trump admin to revisit bedrock cyber policies as it implements new strategy

<p>The White House&rsquo;s soon-to-arrive cybersecurity strategy includes parallel plans to examine and revise bedrock policy frameworks that govern U.S. cyber operations and responses to major cyberattacks from foreign adversaries, according to four people familiar with the matter.</p>

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

<p>Implementation steps for the Trump administration&rsquo;s forthcoming cyber strategy, set for release in January, will include reexamining policies like NSPM-13, a classified document that governs what agencies can launch cyber operations and how they are authorized; PPD-41, which governs what happens when a major cyber incident hits U.S. soil, including lead agencies and coordination structures; and NSM-22, which sets standards for protecting critical infrastructure across various sectors.&nbsp;</p>

<p>Executive orders focused on cybercrime and ransomware groups are also being arranged, two of the people said.&nbsp;</p>

<p>All sources spoke on the condition of anonymity because they were not authorized to publicly discuss the Trump administration&rsquo;s intentions. They cautioned that some of the plans are fluid and may be subject to change.</p>

<p>Details of the cyber strategy itself were also laid out in part in an industry document obtained by <em>Nextgov/FCW</em>. The six-pillar strategy would focus on taking steps to preempt foreign adversaries&rsquo; hacking capabilities, reform cybersecurity regulations to reduce compliance burdens, modernize federal networks, secure critical infrastructure, encourage superiority in emerging technologies and build a business-driven cyber talent pipeline.&nbsp;</p>

<p>CyberScoop <a href=“Five-page draft Trump administration cyber strategy targeted for January release | CyberScoop”>first reported</a> on those pillars.</p>

<p>The strategy and associated reworking of cybersecurity policy documentation underscore the scale of the White House&rsquo;s effort to recalibrate U.S. cyber policy amid sustained nation-state pressure on the nation&rsquo;s digital and physical infrastructure.&nbsp;</p>

<p>The effort also comes as the White House has overseen sweeping moves to reduce the size of major <a href=“DHS says shutdown layoffs at CISA will proceed despite court injunction - Nextgov/FCW”>cyberdefense</a> and <a href=“NSA has met 2,000-person workforce reduction goal, people familiar say - Nextgov/FCW”>national intelligence</a> offices across the government, though some of those workforce reductions are reportedly being <a href=“https://www.cybersecuritydive.com/news/cisa-hiring-workforce-strategy/805733/”>reversed</a> in the coming calendar year.</p>

<p>&ldquo;We do not comment on pre-decisional policy matters,&rdquo; said a spokesperson for the Office of the National Cyber Director, the White House office overseeing implementation of these plans. &ldquo;The Trump administration is determined to make Americans, and our vital infrastructure, networks and information secure in cyberspace.&rdquo;</p>

<p>The offensive pillar would focus on reshaping adversary behavior by being more proactive in cyberspace, including by resetting foreign adversaries&rsquo; risk calculus and leaning into partnerships with the private sector to aid in that work. The goal, ultimately, is &ldquo;preemptive erosion&rdquo; of adversaries&rsquo; hacking capacity, the industry document says.</p>

<p>Bloomberg News <a href=“https://www.bloomberg.com/news/articles/2025-12-12/trump-administration-turning-to-private-firms-in-cyber-offensive”>first reported</a> details on the administration&rsquo;s offensive cybersecurity plans with private industry.</p>

<p>How that offensive realignment takes shape is not entirely clear. Debates over the role of the private sector in national cyber operations have included proposals to grant companies authority to conduct offensive cyber activity against adversaries.</p>

<p>The concept has been discussed between U.S. officials and the private sector, <em>Nextgov/FCW</em> <a href=“An 18th-century war power resurfaces in cyber policy talks - Nextgov/FCW”>reported</a> in May, though sources acknowledged that any modern framework would be more constrained than those used in past centuries.</p>

<p>Still, there is clear intent to &ldquo;take off the kid gloves&rdquo; inside government agencies that already have legal authority to offensively hack, one person familiar with the administration&rsquo;s thinking said. The administration has been making these statements of intent <a href=“Top NSC official wants to normalize offensive hacking as tool of US might - Nextgov/FCW”>for months</a>.</p>

<p>Two other people familiar with the matter also suggested that the White House&rsquo;s plans could involve more innovative and creative ways to integrate cyber threat intelligence &mdash; technical data that helps identify who is behind hacking campaigns and how they operate &mdash; more closely with spy agencies&rsquo; signals intelligence tools, which monitor foreign communications and digital activity for national security purposes.</p>

<p>On the defensive side of the strategy, the White House will focus on pushing agencies to adopt quantum-safe security measures, part of an effort aimed at ensuring encrypted government networks remain secure even as future <a href=“Energy allocates $625M for national labs’ quantum research - Nextgov/FCW”>quantum computers</a> gain the ability to crack today&rsquo;s encryption standards.&nbsp;</p>

<p>A related component of the blueprint involves adopting tools that promote &ldquo;zero trust&rdquo; &mdash; the notion that all users on a network should never be trusted and always verified to ensure their authenticity.</p>

<p>There is also a procurement dimension to the strategy, which would seek to increase competition in the government contracting space by not deferring only to giant defense and technology prime contractors that have historically dominated large federal cyber contracts.</p>

<p>More broadly, the critical infrastructure pillar would focus heavily on moving away from Chinese technology, building on prior efforts to <a href=“FCC to investigate potential US operations of restricted Chinese firms  - Nextgov/FCW”>jettison</a> China-linked telecom hardware from U.S. networks.</p>

<p>The government will also explore business incentives to spur interest in cybersecurity careers and develop the concept of a U.S. cyber academy, the workforce pillar shows. A venture capital component for funding cyber startups is also being crafted in tandem with those goals.</p>

<p>An executive order implementing the cyber strategy is also planned, according to the industry document, and is expected to be <a href=“National cyber strategy coming ‘as quickly as possible,’ official says - Nextgov/FCW”>much shorter</a> than its <a href=“New National Cyber Strategy Asks 'More' from Industry and Government - Nextgov/FCW”>Biden-era equivalent</a> released in 2023.&nbsp;</p>

Article Link: Trump admin to revisit bedrock cyber policies as it implements new strategy - Nextgov/FCW