Like Kennedy’s moonshot, the next president will need to think boldly, not incrementally. There is no better place for the next president to start than with his or her own house.
Fixing the federal enterprise first will send a strong signal to the private sector while leading from the front. Make the federal enterprise the bastion of strong security technology and practices and set the bar high as the exemplar for the private sector and the nation. Making the bold changes required will require taking on entrenched sacred cows: checkbox security that brought us “cyber hygiene” such as expiring passwords, mandated user training and software patch percentages as a goal designed to satisfy auditors, not secure networks.
This problem suffers not from a lack of awareness but from a lack of leadership. For example, the standard defense to spear-phishing attacks has been user training and user shaming. Security professionals have abdicated their responsibility for stopping spear-phishing attacks by placing it squarely on employee users.
In a nutshell, the spear-phish defense strategy espoused by most organizations is that every user must determine which emails to click on and which to avoid, while being shamed if you make a mistake. By extension, the security of the entire network depends on every user to make the correct decision on every email — an untenable position that remains the de facto security posture for most networks.
The best way to break the perpetual cycle of penetrate-and-patch is to call on America’s strength — tech innovation — while breaking down the bureaucratic barriers that stymie adoption. In a global economy, America’s core strength remains its technology innovation funded by private capital markets and the ability for startups to take big ideas to market. The same entrepreneurial spirit driving innovation is thriving in cybersecurity with a well-funded venture capital industry to back it.
The U.S. government has the ability to ditch failing solutions such as traditional anti-virus in favor of next-generation solutions; the ability to favor startups over entrenched security companies that are slow to innovate; the ability to seek solutions directly from the market instead of contracting solutions from the contractors who feed at the government trough; the ability to scrap an antiquated procurement system with five-year budgeting cycles to an agile process that allows it to acquire the latest technologies from market directly.
Small, nimble agencies in government, including the Defense Advanced Research Project Agency (DARPA), In-Q-Tel and Defense Innovation Unit Experimental, have demonstrated the government can be innovative in its approach, but their successes need broad adoption.
As is often the case, leadership typically determines outcomes. Failure to learn from history is a recipe for continued failure. The opportunity for the next president is to be bold and visionary in cybersecurity by leveraging America’s innovation economy.
Anup Ghosh is founder and CEO at Invincea. Prior to founding Invincea, he was a program manager at DARPA where he created and managed an extensive portfolio of cybersecurity programs.




