Shortcomings of the National Cybersecurity Strategy

The National Cybersecurity Strategy fails to adequately address fundamental control system and critical infrastructure issues
March 10, 2023

In May 1998, Presidential Decision Directive (PDD) 63 mandated the cyber security of the critical infrastructures be implemented by May 2003 (not a typo). Twenty years and multiple PDDs and Presidential Executive Orders later, the government agencies responsible for securing the critical infrastructures are still failing to adequately address the issues that can cripple our country and its critical infrastructures – the process control systems. The more than 17 million actual control system cyber incidents attest to the failure. The March 2023 National Cybersecurity Strategy is based on issues associated with Internet Protocol (IP) networks and consumer Internet of Things (IOT) devices, not control system devices such as process sensors that affect process safety nor do they address the cultural issues between the engineering and network security communities.

Joe Weiss

About the Author

Joe Weiss

Cybersecurity Contributor

Joe Weiss P.E., CISM, is managing partner of Applied Control Solutions, LLC, in Cupertino, CA. Formerly of KEMA and EPRI, Joe is an international authority on cybersecurity. You can contact him at [email protected]

Sign up for Control eNews
Get the latest news and updates