ZeroHour
CyberScooppublished ()ingested @CyberScoopNews

White House advisory group says market forces ‘insufficient’ to drive cybersecurity in critical infrastructure

criticalAdvisory exploited in the wildimportance 60
Full article920 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

An industry-led group is calling for the federal government to develop economic incentives for small and medium-sized businesses, simplify cyber regulations and provide clear liability protections around information sharing.

(Getty Images)

A White House advisory board is recommending the federal government create new economic incentive programs to prod critical infrastructure owners and operators to raise their cybersecurity standards, develop new liability protections around information sharing and simplify an increasingly complex national cyber regulatory regime.

The recommendations are part of a report approved Thursday by the National Security Telecommunications Advisory Committee, which is made up of representatives from the nation’s largest telecommunications companies as well as cybersecurity firms. The report focused on why so many organizations that provide critical services to the nation often struggle to adopt best practices or invest sufficient resources into their cybersecurity operations.

It concluded that market forces alone are “insufficient” to incentivize privately owned entities to prioritize cybersecurity at the levels needed to protect national security.

The report also found that stakeholders in critical infrastructure are broadly unaware of the technical assistance and programs already offered by the federal government to help improve cybersecurity, and are facing increasingly complex compliance burdens as the Biden administration has sought to flex its regulatory powers to raise the cybersecurity bar in different sectors.

To address these obstacles, the committee recommended that the Office of the National Cyber Director work with industry to examine a range of new financial incentives, such as tax deductions and federal grants, to help close the cybersecurity investment gap. It also recommended that ONCD work with other federal agencies on a nationwide push to educate owners and operators about free federal services — like CISA’s Cyber Hygiene Service, the NSA’s Cyber Collaboration Center and NIST’s National Cybersecurity Center of Excellence — that aren’t being effectively utilized.

The committee also suggested that ONCD take the lead on developing a strategy that provides “unambiguous language” that carves out liability protections and safe harbor for companies to more freely share information around cyber threats and vulnerabilities that could impact one or multiple industrial sectors.

National Cyber Director Harry Coker gave brief remarks during the meeting, thanking the committee and remarking on the recommendations in the report: “I’ve already reviewed them and I like them.”

Matthew Desch, CEO of Iridium Communications and co-chair of the subcommittee that created the report, said the conclusions were drawn from more than 50 briefings conducted by NSTAC members with critical infrastructure providers, cloud and tech service providers, consultants, trade associations and think tanks.

“The lack of consistent adoption and implementation of cyber best practices and standards is especially problematic as U.S. critical infrastructure entities face a significantly heightened threat landscape, and even more so considering the current geopolitical climate,” Desch said.

The recommendations in the report were approved shortly after U.S. officials warned in January that a hacking group tied to the Chinese government, known as Volt Typhoon, has spent years lurking inside the systems and networks of American critical infrastructure providers. Brandon Wales, CISA’s executive director, said the group’s “aim appears to be burrowing into our critical infrastructure for the purpose of conducting disruptive or destructive attacks.”

More Scoops

A data center in Vernon, Calif. They are groups calling for AI, and the technology it sits on, to be designated as critical infrastructure. (Getty Images)

The push to designate AI as the next critical infrastructure sector

The designation would unlock a range of federal services, tools and resources for an industry that policymakers view as increasingly tied to national and economic security.

United States National Cyber Director Sean Cairncross (2nd-L) accompanied by United States Chief Technology Officer Dr. Ethan Klein (L), White House Office of Science and Technology Policy Director Michael Kratsios (3rd-L), U.S. President Donald Trump (R), and Commerce Secretary Howard Lutnick (2nd-R), speaks during an event in the Oval Office of the White House on June 22, 2026 in Washington, D.C. (Photo by Andrew Harnik/Getty Images)

National cyber director lays out White House plans to secure AI without writing new rules

U.S. Sen. Kirsten Gillibrand, D-N.Y., attends a subcommittee hearing with the Senate Committee on Appropriations in the Dirksen Senate Office Building on April 22, 2026. (Photo by Anna Moneymaker/Getty Images)

Dem senators criticize Trump administration decisionmaking on AI security risks

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/nstac-white-house-advisory-group-critical-infrastructure/