What Business Needs to Know About the New U.S. Cybersecurity Strategy

In March 2023, the Biden administration released a new National Cybersecurity Strategy, which makes it clear that the time for private companies voluntarily opting into cybersecurity has long passed. Instead, the new strategy promises to support new regulatory frameworks that will shift liability and create incentives for private firms to defend against critical vulnerabilities. This article discusses three concrete things business leaders should know about the new strategy. First, every company will need to identify their distinct vulnerabilities and risks. Second, companies will then need to adopt measures that address those vulnerabilities. Third, the strategy categorically states that it will push for legislation to hold these firms liable when they fail to live up to the duty of care they owe consumers, businesses, or critical infrastructure providers.

On March 2, 2023, the Biden administration released its long-awaited National Cybersecurity Strategy. In light of cyberattacks targeting American infrastructure, business, and governmental agencies, the document elevates cybersecurity as a critical component of the United States’ economic prosperity and national security. It also intimates a fundamental dilemma, which is that the private sector — with key stakeholders consisting of software firms, small- and medium-sized businesses, broadband providers, and utility companies — holds the key to the public good of cybersecurity:

Continued disruptions of critical infrastructure and thefts of personal data make clear that market forces alone have not been enough to drive broad adoption of best practices in cybersecurity and resilience.

Voluntary progress toward better cyber hygiene on the part of the private sector is no longer enough. Instead, the new strategy promises to support new regulatory frameworks that will shift liability and create incentives for private firms to defend against critical vulnerabilities.

Why a Public Sector Document Is Fixated on the Private Sector

The private sector has attracted the attention of a cyber-wary public sector because of a slew of high-profile cyber incidents in the last few years. In 2017, customer credit bureau Equifax experienced a hack that compromised the personal information of more than 143 million Americans, leading to a $425 million settlement with the Federal Trade Commission. Malicious actors have increasingly employed ransomware against American businesses, demanding large sums of money for the safe exchange of sensitive data.


Ransomware continues to be a popular tactic amongst hackers precisely because these campaigns have often been successful in generating lucrative payouts. According to Comparitech’s analyses of ransomware incidents throughout the U.S., ransomware attacks on American businesses cost $20.9 billion from 2018–2023, with an average ransom demand of $4.15 million dollars for affected businesses in 2022. For example, Colonial Pipeline, which transports 100 million gallons of fuel per day, or 45% of all fuel used on the East Coast, suffered a devastating ransomware breach in 2021, the largest publicly disclosed attack on critical U.S. oil infrastructure in history. The perpetrator, DarkSide, stole 100 gigabytes of data within two hours, which it threatened to release unless the company paid 75 bitcoins to the group, worth approximately $5 million dollars at the time, which Colonial Pipeline paid within a few hours, blackmailed into action by the disruptiveness of the attack.

No part of the economy is immune. As a 2021 survey by the Center for Strategic & International Studies indicated, 42% of small- and medium-sized businesses experienced a cyberattack in the last year and estimates suggest that 40% of 2021 cyberattacks concentrated on small and medium-sized businesses, with attacks on these businesses growing 150% over the last two years. The potential data and revenue extractability might be lower when compared to that of large businesses like Microsoft, but small- and medium-sized firms also have fewer resources to devote to robust cybersecurity. In some cases, these companies simply don’t have any dedicated resources for cybersecurity.

Three Things Companies Need to Know About the National Cybersecurity Strategy

While the 39-page document features bureaucratic buzzwords like “harmonize”, “stakeholders,” and “multilateral,” we’ve identified three concrete things business leaders should know about the new strategy.

First, every company needs to identify their distinct vulnerabilities and risks. The Biden administration’s strategy makes it clear that the time for companies voluntarily opting into cybersecurity has long passed. Instead, they need to take proactive measures to test and understand their threat landscape. Companies should conduct formal vulnerability scans and penetration tests that identify potential access points. Where possible, companies should hire “ethical hackers,” otherwise known as “red teams,” that simulate sophisticated cyberattacks and reveal whether and how adversaries could access sensitive data or disrupt networks. Firms must also thoroughly vet third-party vendors and software suppliers to minimize the risk of attacks through the supply chain.

Second, companies then need to adopt measures that address those supply chain vulnerabilities. As part of this step, they should take advantage of the strategy’s promise for public-private collaboration in the form of information-sharing, as well as practical guidance and support on how to navigate the cyber threat environment. More generally, they need to then take preventative measures, including patching known exploits, providing regular security training for employees, and incorporating anomaly-detection tools, while ensuring that they have response plans that can minimize the scale and harm of successful hacks.

Third, companies need to recognize that one size will not fit all when it comes to cybersecurity. An important subtext of the strategy is its focus on establishing more aggressive regulatory standards on larger business, critical infrastructure, and software providers.

The strategy categorically states that “the lack of mandatory requirements has resulted in inadequate and inconsistent outcomes” and that it will push for legislation to hold these firms “liable when they fail to live up to the duty of care they owe consumers, businesses, or critical infrastructure providers.” These firms may in turn seek to shape legislation and liability, but the strategy makes it clear that more of the onus in terms of finding and fixing vulnerabilities will fall on the larger businesses where stakes are higher and resources are more abundant. Small businesses are not in the crosshairs (yet), but are also not off the hook. They should also seek out opportunities for collaboration, such as the National Institutes of Standards and Technology’s recently launched initiative to foster communication across small businesses.

When it comes to the concrete implications of the Biden administration’s new National Cybersecurity Strategy for American industry, the devil will be in the details. The document includes core pillars and noble goals that we would expect, given that cyberspace is arguably now the backbone of the U.S. national economy. The trick will be doing this in ways that are mindful of the realistic challenges of identifying and patching all vulnerabilities, and the risks that inadequate care will affect not just individuals, but the entire global economy.

Read More
Sarah Kreps

Latest

SBA Announces Finalists for $1 Million Patriot Pitch Competition

The U.S. Small Business Administration (SBA) has unveiled the five finalists for its Freedom 250 Patriot Pitch Competition, a showcase emphasizing innovation and entrepreneurship in American small businesses. Scheduled for September 18 in Washington, D.C., these finalists will compete before a panel of celebrity judges for a share of a $1 million cash prize pool

I Started My Career With a Borrowed Ladder. Here’s How That Shaped the Way I Evaluate My Business Partners.

Opinions expressed by Entrepreneur contributors are their own. Key Takeaways I couldn’t afford my own equipment when I decided to become a roofer, so I borrowed a ladder from my dad. The way he treated me when I was looking for my first shot in business shaped how I vet partners and dealers. It taught

Formerly bankrupt retailer overhauls 48-year-old offering

Please enable JS and disable any ad blocker

Newsletter

Don't miss

SBA Announces Finalists for $1 Million Patriot Pitch Competition

The U.S. Small Business Administration (SBA) has unveiled the five finalists for its Freedom 250 Patriot Pitch Competition, a showcase emphasizing innovation and entrepreneurship in American small businesses. Scheduled for September 18 in Washington, D.C., these finalists will compete before a panel of celebrity judges for a share of a $1 million cash prize pool

I Started My Career With a Borrowed Ladder. Here’s How That Shaped the Way I Evaluate My Business Partners.

Opinions expressed by Entrepreneur contributors are their own. Key Takeaways I couldn’t afford my own equipment when I decided to become a roofer, so I borrowed a ladder from my dad. The way he treated me when I was looking for my first shot in business shaped how I vet partners and dealers. It taught

Formerly bankrupt retailer overhauls 48-year-old offering

Please enable JS and disable any ad blocker

NYT: Trump-Backed WLFI Took $100M From a Money Laundering Suspect

World Liberty Financial’s largest disclosed token purchase traces back to a Chinese businessman under active UK investigation for money laundering, the New York Times reported, with up to $75 million flowing to Trump family and Witkoff-linked entities. Key Takeaways Aqua1 Foundation bought $100 million in WLFI tokens on June 26, per the New York Times.

The business of football

Mar­i­ano Browne The FI­FA World Cup is the largest sin­gle-event sport­ing com­pe­ti­tion in the world. No sin­gle sport­ing event match­es the sin­gu­lar, world­wide fo­cus and tele­vi­sion view­er­ship of the World Cup. The 2026 ver­sion is es­ti­mat­ed to have reached over 5 bil­lion peo­ple, out of the world’s 8.3 bil­lion. It is the most pop­u­lar sport

‘Sabah is open for business’: Hajiji courts investors with promise of sustainable growth, carbon‑negative credentials

Sabah is pitching itself as an Asia-Pacific hub for impact investing, betting that its forests, biodiversity and natural resources can become drivers of economic growth as it seeks private capital for sustainable development. — Picture by Firdaus Latif By Julia Chan First Published: Monday, 13 Jul 2026 11:44 AM MYT KOTA KINABALU, July 13 —

Want Your Business to Be Seen Everywhere? Meet Tonia Ryan, Creator of Fix Your Search

Some people are good at their jobs. Then there is Tonia Ryan, who has turned “getting found online” into something close to magic. She is the creator of Fix Your Search, and if you have ever wondered why some businesses pop up everywhere while others seem invisible...