CISA Director Jen Easterly and Executive Assistant Director Eric Goldstein say incentives for developing and selling tech should not eclipse customer safety
> - Secure products not just security products - Security built in not bolted on - Raise everyone's baseline by reducing the [total] cost of control @CISAJen https://www.foreignaffairs.com/ ... Patrick Howell O'Neill / @howelloneill : An important article from CISA on US industry making cyber safety a secondary concern. https://www.foreignaffairs.com/ ... Crucially, they contrast this with car safety. A fact worth acknowledging out loud: Car safety exists today due to federal regulation, not voluntary standards. https://twitter.com/... Ciaran Martin / @ciaranmartinoxf : Significant, welcome intervention by @CISAJen in @ForeignAffairs Huge among to digest & it'll need several readings, but headline is welcome emphasis on what over here we'd call secure by default: making tech safer when it's designed/built https://www.foreignaffairs.com/ ... @cisajen : Thoughts from Eric Goldstein & me on building a sustainable approach to cybersecurity, to include technology manufacturers taking responsibility for the security outcomes of their customers as a fundamental issue of safety. Feedback welcome. https://www.foreignaffairs.com/ ... @royalhansen : Cybersecurity is one of the top issues facing the world- so why is cybersecurity often relegated to the “IT team”? This is why @Google has security baked in from the beginning, instead of bolted on as an afterthought. Great read from @CISAgov on this issue https://www.foreignaffairs.com/ ... Andrew Thompson / @imposecost : “Indeed, a number of technology providers, including Google, Amazon, and Salesforce, are moving in this direction, providing strong security measures by default for their customers and introducing innovative advances toward security by design.” https://twitter.com/... Phil Venables / @philvenables : Users & organizations deserve safe tech they can rely on. The industry needs to come together to build secure products not more security products. Public/private cooperation will be key to defining& building approaches that scale this across the ecosystem https://foreignaffairs.com/...
Context & Ripple Effects
The Foreign Affairs essay lands weeks after CyberScoop reported that current and former CISA staff see an agency lacking a clear strategic direction and focused on PR — so Easterly and Goldstein are answering that critique by staking out a doctrine: secure-by-design, with manufacturers accountable for customers' security outcomes rather than selling security as an add-on.
The argument is deliberately regulatory in ambition. The directors invoke car safety as a field transformed by federal mandates rather than voluntary standards, and they write from an agency that Politico found underfunded, short on talent, and outmatched by adversaries — making persuasion of industry a substitute for enforcement capacity.
First-order effects
- Major vendors are put on notice that CISA's benchmark for credibility is building security into products and owning customer outcomes, not shipping security products — a standard aimed at the entire commercial software market.
- Easterly and Goldstein convert an op-ed into agency positioning: with internal critics questioning CISA's direction, the secure-by-design doctrine becomes the leadership's answer to what the agency actually stands for.
Second-order effects
- Vendors begin pricing reputational risk against the doctrine — Microsoft's subsequent move to tie security principles and goals to executive compensation packages after the Cyber Safety Review Board's scathing report shows the secure-by-design argument translating into internal incentives, not just rhetoric.
- If manufacturers absorb responsibility for security outcomes, the cost of breaches shifts up the stack to the vendor's balance sheet, pressuring laggards who still treat security as a paid add-on.
Third-order effects
- The car-safety analogy sketches the endgame: software liability migrating from buyer-beware to regulated manufacturer accountability, with baseline security set by public policy rather than voluntary pledges — a shift whose pace depends on whether CISA's persuasion is backed by legislative teeth.
- If the pattern holds, security posture becomes a market-access question, with procurement and regulation rewarding vendors who can demonstrate built-in safety and sidelining those who cannot.
The trend: Software security is moving from a product customers buy to a responsibility regulators expect manufacturers to carry, with CISA's secure-by-design campaign as an early marker of that shift.