The new version of the National Strategy to Secure Cyberspace was released on Valentines Day, and it comes forth with a clear requirement. That the government lead by example. Thats praiseworthy, for sure. But, unlike the longer draft strategy released for public comment last September, the final draft says not a word about regulating the private sector in matters of security, and is almost as silent on what companies should actually do next. Alan Paller, director of the SANS Institute, describes the report as a wonderful description of the problem. A Washington Post story the day after the strategy was released was entitled, Cyber Security Strategy Depends on Power of Suggestion. And Paller told the public radio show Marketplace, The problem is that the suggestions that are being made are too soft.Indeed, a quick look at the executive summary of the report shows that, in the list of actions to be undertaken, verbs like foster, encourage, promote and understand far outnumber verbs like provide, secure, create or, god forbid, fund. (You wont find that last one in there at all, honestly.)In general, security experts dis the report as having let industry and the private sector off the hook, though they give the government a nod for trying to get its own house in order. Leaving it to the vendors is basically the path weve been following&and the whole reason we have the problems that we have, Eugene H. Spafford, a security expert and Purdue professor told the Post. On the other hand, industry reps unsurprisingly praise the hands-off report. Because the report originated in the White House (though it was released by the Department of Homeland Security), the authors arent required to disclose how input received in the comment period influenced the revised draft. Its no secret though, that technology and telecom companies lobbied hard against any regulation. Did the government give in too much? Did they wimp out on creating a cybersecurity strategy with teeth and end up mouthing platitudes? Does this strategy make you feel secure? Let us know. Related content news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Regulation Regulation news UK data regulator warns that data breaches put abuse victims’ lives at risk The UK Information Commissioner’s Office has reprimanded seven organizations in the past 14 months for data breaches affecting victims of domestic abuse. By Michael Hill Sep 28, 2023 3 mins Electronic Health Records Data Breach Government news EchoMark releases watermarking solution to secure private communications, detect insider threats Enterprise-grade software embeds AI-driven, forensic watermarking in emails and documents to pinpoint potential insider risks By Michael Hill Sep 28, 2023 4 mins Communications Security Threat and Vulnerability Management Security Software news SpecterOps to use in-house approximation to test for global attack variations The new offering uses atomic tests and in-house approximation in purple team assessment to test all known techniques of an attack. By Shweta Sharma Sep 28, 2023 3 mins Penetration Testing Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe