ZeroHour
CyberScooppublished ()ingested @CyberScoopNews

White House cybersecurity strategy to force large companies to make systems secure by design

criticalExploit / PoC exploited in the wildimportance 60
Full article764 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The highly anticipated strategy document aims to deliver security improvements to the broader digital ecosystem.

A forthcoming White House cybersecurity strategy document aims to force large companies to shoulder greater responsibility for designing secure products and to redesign digital ecosystems to be more secure, Camille Stewart Gloster, the deputy national cyber director for technology and ecosystem security, said at a CyberScoop event Thursday.

By “shifting the burden back from the smaller players” and toward larger players “that can build in security by design” the strategy aims to deliver broad security gains, Stewart Gloster said. The strategy documents also looks at how to “rearchitect our digital ecosystem” so “that we are creating future resilience,” she said.

According to an early draft of the document obtained by Slate — which White House officials have emphasized is not a final document — the strategy includes a wide range of mandatory regulations on American critical infrastructure companies to improve security and authorizes law enforcement and intelligence agencies to take a more aggressive approach to hack into foreign networks to prevent attacks or retaliate after they have occurred.

The strategy document is expected to broadly abandon the mostly voluntary approach that has defined U.S. policy in recent years in favor of more comprehensive regulation.

The Biden administration has worked to draft the strategy over the past year, an initiative that was spurred by a string of major breaches early in the administration — among them the SolarWinds and Kaseya breaches — that saw attackers exploit vulnerabilities at companies that occupy central positions in the computer security ecosystem.

Breaching these companies allowed attackers access to large numbers of client systems, and by mandating greater security requirements at companies that occupy these systemically important positions, the White House is looking to create security improvements for the large numbers of clients and users that rely on their services.

The recently retired National Cyber Director Chris Inglis served as the primary author of the document, and following his retirement last week, the highly anticipated strategy is expected to be released imminently.

More Scoops

United States National Cyber Director Sean Cairncross (2nd-L) accompanied by United States Chief Technology Officer Dr. Ethan Klein (L), White House Office of Science and Technology Policy Director Michael Kratsios (3rd-L), U.S. President Donald Trump (R), and Commerce Secretary Howard Lutnick (2nd-R), speaks during an event in the Oval Office of the White House on June 22, 2026 in Washington, D.C. (Photo by Andrew Harnik/Getty Images)

National cyber director lays out White House plans to secure AI without writing new rules

The Trump administration executive order on artificial intelligence tried to strike the balance between responsible use, security and mutual benefit, all with an eye toward not making…

Chairman Rick Crawford, R-Ark., center, and ranking member Rep. Jim Himes, D-Conn., right, conduct the House Select Intelligence Committee hearing titled “Worldwide Threats Assessment,” in Longworth building on March 26, 2025. (Tom Williams/CQ Roll Call)

House intel bill includes provisions on state and local threat intelligence, election security, AI

Russell Vought, the director of the Office of Management and Budget (OMB) for the second Trump administration speaks during a Senate Committee on the Budget hearing to examine the President’s fiscal year 2027 budget proposal in Capitol Hill on April 16, 2026. (Photo by Roberto Schmidt/Getty Images)

White House charts new course for federal agencies and cybersecurity logging

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/white-house-cybersecurity-strategy/