Trump signs executive order for extensive review of US government's cybersecurity, but mostly maintains the cyber policy path set by last two administrations
President Donald Trump on Thursday signed a long-delayed cybersecurity executive order that is expected to launch sweeping reviews …
Context & Ripple Effects
This 2017 order is the continuity data point in a story that later became discontinuity: it launched reviews but deliberately kept the cyber policy path of the prior two administrations, in contrast to Biden's 2021 order that imposed new software-security standards on government vendors and, more sharply, to Trump's own second-term move scrapping or revising several Biden- and Obama-era programs, including AI security and post-quantum cryptography work.
Read against that later coverage, the 2017 order matters as the baseline: an incoming administration choosing review over reversal, before the same president's later cyber strategy pivoted to offense operations, AI security, and regulatory streamlining.
First-order effects
- Federal agencies face sweeping cybersecurity reviews of their practices and procurement, with no immediate change to the substantive policies they were already executing.
- Government IT vendors and contractors get regulatory stability: the order signals continuity rather than new compliance requirements.
Second-order effects
- Because the order preserves the existing framework rather than replacing it, the burden of tightening cyber defenses shifts to subsequent instruments — as later happened when Biden's 2021 EO set software-security standards for companies selling to the government.
- Congress faces renewed pressure to legislate where executive orders only review: the order's reliance on studies rather than mandates leaves statutory gaps that each successive administration fills by its own pen.
Third-order effects
- If the pattern holds across administrations, US cyber policy becomes a pendulum of executive orders — built, reviewed, and dismantled by successive presidents — making multi-year programs like post-quantum cryptography and AI security structurally vulnerable to political turnover.
- Agencies and vendors rationally discount long-horizon federal cyber initiatives, since any program not anchored in statute can be rescinded by the next EO.
The trend: US cybersecurity policy is increasingly made and unmade through presidential executive orders, with each administration reviewing or reversing its predecessor's programs instead of building on them.