White House names retired Air Force Brigadier General Gregory Touhill as first chief information security officer
Retired Air Force Brigadier Gen. Gregory Touhill just got a promotion. — The White House has named Touhill as the first ever federal chief information security officer …
Context & Ripple Effects
In 2016 the White House created a job that had not existed before: a single federal chief information security officer, filled by retired Air Force Brig. Gen. Gregory Touhill, giving civilian agencies one named owner for cybersecurity policy. The role stuck. Five years later Chris DeRusha took the same post under Biden as US CISO, and cyber leadership has since been layered with adjacent positions — the national cyber director nomination of ex-NSA deputy Chris Inglis alongside a CISA head, and more recently Trump's pick of Sean Cairncross for the director job as his first major cybersecurity choice.
What makes Touhill's appointment worth revisiting is that it established the template every subsequent administration has followed: name a senior cyber official early, draw them from national-security or campaign-trusted circles, and anchor cyber policy inside the Executive Office rather than in any single agency.
First-order effects
- Federal civilian agencies gain a single point of accountability for cybersecurity policy, with Touhill's military background signaling an operations-first approach over compliance paperwork.
- The White House creates a precedent for staffing cyber policy with political appointees close to the president, a pattern DeRusha (ex-Biden campaign CISO) and Cairncross (ex-RNC COO) later repeat.
Second-order effects
- The CISO role stops being a one-off: each incoming administration treats naming its own cyber leadership as standard transition business, and the portfolio fragments into parallel posts — CISO, national cyber director, CISA head — forcing new coordination mechanisms between them.
- Agencies and vendors now face overlapping authorities, since directives can originate from the White House CISO, the national cyber director, or CISA depending on which office an administration empowers.
Third-order effects
- Cybersecurity has become a standing executive-branch function that survives partisan turnover — every administration since 2016 has named its own cyber officials rather than dismantling the structure — pointing toward permanent White House-level cyber governance with the exact division of labor still contested between the CISO, the director, and CISA.
The trend: White House cyber leadership is being institutionalized administration by administration, expanding from a single CISO into a layered structure of CISO, national cyber director, and CISA whose boundaries each new team redraws.