The annual US defense policy bill for 2023 contains significant spending increases for US Cyber Command and other efforts to bolster cybersecurity defenses
Suzanne Smalley / CyberScoop :
Context & Ripple Effects
This year's defense authorization continues a pattern in which Congress loads its cybersecurity agenda onto the annual NDAA rather than passing standalone cyber legislation. Last December's defense bill codified voluntary cybersecurity frameworks for the private sector, which operates most US critical infrastructure; this one shifts the emphasis toward military capacity.
The throughline runs back further: Obama's $19B Cybersecurity National Action Plan sought a 35% funding jump in 2016, and the 2021 infrastructure law added $2B for cyber programs including federal help for state and local governments. The 2023 bill's boost for US Cyber Command extends that spending arc into offensive military cyber power.
First-order effects
- US Cyber Command receives significant new funding and expanded statutory authority to conduct offensive operations against foreign powers, formalizing activity its chief Paul Nakasone has already acknowledged, including cyberattacks supporting Ukraine after Russia's invasion.
Second-order effects
- Defense contractors and cyber vendors gain a larger, congressionally mandated customer as Cyber Command scales up, while adversaries face a US military explicitly resourced for persistent offensive cyber operations rather than episodic response.
Third-order effects
- If each annual authorization keeps adding cyber authorities and dollars, the NDAA becomes the de facto vehicle for national cyber policy — consolidating offensive capability inside Cyber Command while civilian-sector defenses remain tied to voluntary frameworks.
The trend: Congress is using successive defense authorization bills to steadily convert US cybersecurity policy from voluntary private-sector frameworks into funded, offensive military cyber capacity.