/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

CISA Director Jen Easterly and Executive Assistant Director Eric Goldstein say incentives for developing and selling tech should not eclipse customer safety

> - Secure products not just security products - Security built in not bolted on - Raise everyone's baseline by reducing the [total] cost of control @CISAJen https://www.foreignaffairs.com/ ... Patrick Howell O'Neill / @howelloneill : An important article from CISA on US industry making cyber safety a secondary concern. https://www.foreignaffairs.com/ ... Crucially, they contrast this with car safety. A fact worth acknowledging out loud: Car safety exists today due to federal regulation, not voluntary standards. https://twitter.com/... Ciaran Martin / @ciaranmartinoxf : Significant, welcome intervention by ⁦@CISAJen⁩ in ⁦@ForeignAffairs⁩ Huge among to digest & it'll need several readings, but headline is welcome emphasis on what over here we'd call secure by default: making tech safer when it's designed/built https://www.foreignaffairs.com/ ... @cisajen : Thoughts from Eric Goldstein & me on building a sustainable approach to cybersecurity, to include technology manufacturers taking responsibility for the security outcomes of their customers as a fundamental issue of safety. Feedback welcome. https://www.foreignaffairs.com/ ... @royalhansen : Cybersecurity is one of the top issues facing the world- so why is cybersecurity often relegated to the “IT team”? This is why @Google has security baked in from the beginning, instead of bolted on as an afterthought. Great read from @CISAgov on this issue https://www.foreignaffairs.com/ ... Andrew Thompson / @imposecost : “Indeed, a number of technology providers, including Google, Amazon, and Salesforce, are moving in this direction, providing strong security measures by default for their customers and introducing innovative advances toward security by design.” https://twitter.com/... Phil Venables / @philvenables : Users & organizations deserve safe tech they can rely on. The industry needs to come together to build secure products not more security products. Public/private cooperation will be key to defining& building approaches that scale this across the ecosystem https://foreignaffairs.com/...

Foreign Affairs

Context & Ripple Effects

The Foreign Affairs essay lands weeks after CyberScoop reported that current and former CISA staff see an agency lacking a clear strategic direction and focused on PR — so Easterly and Goldstein are answering that critique by staking out a doctrine: secure-by-design, with manufacturers accountable for customers' security outcomes rather than selling security as an add-on.

The argument is deliberately regulatory in ambition. The directors invoke car safety as a field transformed by federal mandates rather than voluntary standards, and they write from an agency that Politico found underfunded, short on talent, and outmatched by adversaries — making persuasion of industry a substitute for enforcement capacity.

First-order effects

  • Major vendors are put on notice that CISA's benchmark for credibility is building security into products and owning customer outcomes, not shipping security products — a standard aimed at the entire commercial software market.
  • Easterly and Goldstein convert an op-ed into agency positioning: with internal critics questioning CISA's direction, the secure-by-design doctrine becomes the leadership's answer to what the agency actually stands for.

Second-order effects

  • Vendors begin pricing reputational risk against the doctrine — Microsoft's subsequent move to tie security principles and goals to executive compensation packages after the Cyber Safety Review Board's scathing report shows the secure-by-design argument translating into internal incentives, not just rhetoric.
  • If manufacturers absorb responsibility for security outcomes, the cost of breaches shifts up the stack to the vendor's balance sheet, pressuring laggards who still treat security as a paid add-on.

Third-order effects

  • The car-safety analogy sketches the endgame: software liability migrating from buyer-beware to regulated manufacturer accountability, with baseline security set by public policy rather than voluntary pledges — a shift whose pace depends on whether CISA's persuasion is backed by legislative teeth.
  • If the pattern holds, security posture becomes a market-access question, with procurement and regulation rewarding vendors who can demonstrate built-in safety and sidelining those who cannot.

The trend: Software security is moving from a product customers buy to a responsibility regulators expect manufacturers to carry, with CISA's secure-by-design campaign as an early marker of that shift.

Discussion

  • @philvenables Phil Venables on x
    Secure by Default + Secure by Design —> - Secure products not just security products - Security built in not bolted on - Raise everyone's baseline by reducing the [total] cost of control @CISAJen https://www.foreignaffairs.com/ ...
  • @imposecost Andrew Thompson on x
    “Indeed, a number of technology providers, including Google, Amazon, and Salesforce, are moving in this direction, providing strong security measures by default for their customers and introducing innovative advances toward security by design.” https://twitter.com/...
  • @philvenables Phil Venables on x
    Users & organizations deserve safe tech they can rely on. The industry needs to come together to build secure products not more security products. Public/private cooperation will be key to defining& building approaches that scale this across the ecosystem https://foreignaffairs.c…
  • @dalperovitch Dmitri Alperovitch on x
    Great piece by @CISAJen and Eric Goldstein on the need for greater accountability in cyber defense https://www.foreignaffairs.com/ ...
  • @howelloneill Patrick Howell O'Neill on x
    An important article from CISA on US industry making cyber safety a secondary concern. https://www.foreignaffairs.com/ ... Crucially, they contrast this with car safety. A fact worth acknowledging out loud: Car safety exists today due to federal regulation, not voluntary standard…
  • @ciaranmartinoxf Ciaran Martin on x
    Significant, welcome intervention by ⁦@CISAJen⁩ in ⁦@ForeignAffairs⁩ Huge among to digest & it'll need several readings, but headline is welcome emphasis on what over here we'd call secure by default: making tech safer when it's designed/built https://www.foreignaffairs.com/ ...
  • @cisajen @cisajen on x
    Thoughts from Eric Goldstein & me on building a sustainable approach to cybersecurity, to include technology manufacturers taking responsibility for the security outcomes of their customers as a fundamental issue of safety. Feedback welcome. https://www.foreignaffairs.com/ ...
  • @royalhansen @royalhansen on x
    Cybersecurity is one of the top issues facing the world- so why is cybersecurity often relegated to the “IT team”? This is why @Google has security baked in from the beginning, instead of bolted on as an afterthought. Great read from @CISAgov on this issue https://www.foreignaffa…
  • @dnvolz Dustin Volz on x
    Interesting @ForeignAffairs piece from @CISAJen and Eric Goldstein, but a bit puzzled by the oft-used “government cannot solve the problem” line that is followed by comparisons of cybersecurity to auto safety, which is heavily regulated (e.g. seatbelts). https://www.foreignaffair…