• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
CommentaryCybersecurity

The U.S. is overdue for a dramatic shift in its cybersecurity strategy–but change is finally coming

By
Andrew Rubin
Andrew Rubin
Down Arrow Button Icon
By
Andrew Rubin
Andrew Rubin
Down Arrow Button Icon
September 19, 2022, 10:41 AM ET
U.S. infrastructure has always been a prime target for cyberattacks–but recent years have seen threats grow exponentially.
U.S. infrastructure has always been a prime target for cyberattacks–but recent years have seen threats grow exponentially. Mario Tama—Getty Images

In 2021, ransomware attacks hit 649 U.S. critical infrastructure entities, according to the FBI. Even worse, the FBI’s Internet Crime Complaint Center (IC3) revealed that “of the 16 critical infrastructure sectors … 14 sectors had at least one member that fell victim to a ransomware attack in 2021.” Almost 90% of all U.S. critical infrastructure sectors were hit by a successful ransomware attack in 2021. It’s a dismal and harrowing reality.

U.S. critical infrastructure has long had a very large and obvious target on its back. But in the past four years, as our entire world has become increasingly digital, cyberattacks on our nation’s most valuable assets have become incessant–and increasingly catastrophic. This unfortunate fact pattern is the reason why the Cybersecurity and Infrastructure Security Agency (CISA) was formed in 2018. CISA, the “quarterback for the federal cybersecurity team,” was created to work across sectors to bolster national resilience in cyberspace.

Since that time, the threat landscape has shifted drastically. In the past two years alone, more than 76% of organizations have been attacked by ransomware and 66% have experienced at least one software supply chain attack.

The world will spend nearly $170 billion on cybersecurity in 2022, and nearly $20 billion of that will be spent by the U.S. Federal Government–yet we’re still hemorrhaging losses to ransomware. It’s clear that the way we’re approaching cyber is wrong–and it’s on all of us. That’s why the 2023-2025 CISA Strategic Plan–the agency’s first document of its kind–is so highly anticipated, and frankly, such a big deal. It’s not only affirmation and acknowledgment of the problem (we’re moving much too slowly in a threat landscape that changes faster each day), but also outlines a new path forward: one predicated on resilience.

In fact, the very first objective (1.1) in the plan is to “enhance the ability of federal systems to withstand cyberattacks and incidents”–ensuring that “FCEB agencies are prepared for and able to rapidly recover from cyberattacks and incidents” and “maintain mission continuity during and after cyberattacks and incidents.” This is an evident and deliberate shift away from the traditional security approaches of keeping attacks out (prevention) and detecting them quickly when they break through the perimeter. Unfortunately, our track record is proving again and again that these tactics no longer reliably work.

The traditional security models that we’ve relied on for decades aren’t designed to solve the problems posed by a hyperconnected, digital-first landscape. Ransomware and bad actors are bound to breach the perimeter and evade detection. It’s the inevitable reality of today’s technology and data-enabled world.

And so now, finally, we enter the era of breach containment and resilience. Organizations are focusing on isolating and minimizing breaches to reduce the impact and recover much more quickly. We are focusing on enhancing visibility across networks, workloads, endpoints, and critical infrastructure since you can’t defend what you cannot see. Risk reduction and resilience are finally serving as the north star for cybersecurity.

We know that government and legislation tend to be slow-moving in nature. But in an industry as dynamic, fast-paced, and far-reaching as cyber, we have long been behind the ball when it comes to mandating and regulating cybersecurity strategy across both public and private industries. CISA’s plan demonstrates that even at the federal level, there is enormous value in pivoting as the circumstances change and the need for a new strategy becomes evident. The attackers are experts at failing fast and adjusting, and the defender’s job is to always be as agile, and hopefully a step ahead.

This plan is yet another industry calling card to rectify the way we approach national resilience and cyber at large. Organizations and agencies are going to be attacked. Breaches and ransomware will remain the norm and those are now operating assumptions that should be held as facts. What we can control is how much (or little) damage or operational fallout those breaches incite.

CISA is the first federal agency to acknowledge that not only is the threat landscape shifting, but the way we must approach and defend against today’s evolving threat landscape must dramatically change as well.

Andrew Rubin is the CEO of Illumio.

The opinions expressed in Fortune.com commentary pieces are solely the views of their authors and do not reflect the opinions and beliefs of Fortune.

More must-read commentary published by Fortune:

  • Recession or resilience? Here’s how the U.S., Europe, and Asia stack up
  • Patagonia: ‘We are turning capitalism on its head by making the Earth our only shareholder’
  • How Germany’s regulators beat the SEC in the race for crypto regulation–and convinced me to establish my business there
  • Week-to-week management could be the solution to employers’ distrust of remote work
  • Don’t spoil the unique chemistry between America’s universities and pharmaceutical companies

Sign up for the Fortune Features email list so you don’t miss our biggest features, exclusive interviews, and investigations.

About the Author
By Andrew Rubin
See full bioRight Arrow Button Icon

Latest in Commentary

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Commentary

boardroom
CommentaryCorporate Governance
When AI decides how shareholders vote, boards need to rethink governance
By Jane SadowskyJanuary 17, 2026
15 hours ago
moreland
CommentaryHuman resources
Fortune 500 exec: College grads aren’t ready for today’s jobs
By Mary MorelandJanuary 17, 2026
16 hours ago
depa
CommentaryConsulting
Adaptability is the new job security and 4 more future AI trends from EY’s global chief innovation officer
By Joe DepaJanuary 16, 2026
2 days ago
verma
CommentaryGoogle
Google Meet exec on the knowledge engine hiding in your calendar: meetings become IP
By Awaneesh VermaJanuary 16, 2026
2 days ago
sharma
CommentaryTraining
AI will infiltrate the industrial workforce in 2026—let’s apply it to training the next generation, not replacing them
By Kriti SharmaJanuary 15, 2026
3 days ago
CommentaryBusiness
Using AI just to reduce costs is a woeful misuse of a transformative technology
By Nigel VazJanuary 15, 2026
3 days ago

Most Popular

placeholder alt text
Newsletters
The oil CEO who stood up to Trump is a follower of the disciplined 'Exxon way' and has a history of blunt statements
By Jordan BlumJanuary 13, 2026
5 days ago
placeholder alt text
Politics
The Nobel Prize committee doesn't want Trump getting one, even as a gift—but they treated Obama very differently
By Nick LichtenbergJanuary 16, 2026
1 day ago
placeholder alt text
Economy
America’s $38 trillion national debt is so big the nearly $1 trillion interest payment will be larger than Medicare soon
By Shawn TullyJanuary 15, 2026
3 days ago
placeholder alt text
Banking
'Absolutely, positively no chance, no way, no how, for any reason': Dimon says he'd never run the Fed but 'would take the call' to lead Treasury
By Jacqueline MunisJanuary 16, 2026
1 day ago
placeholder alt text
Success
Jensen Huang tells Stanford students their high expectations may make it hard for them to succeed: 'I wish upon you ample doses of pain and suffering'
By Orianna Rosa RoyleJanuary 16, 2026
2 days ago
placeholder alt text
Europe
Americans have been quietly plundering Greenland for over 100 years, since a Navy officer chipped fragments off the Cape York iron meteorite
By Paul Bierman and The ConversationJanuary 14, 2026
3 days ago

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.