Report on Securing and Growing the Digital Economy · 2026-03-05 · 22 min
Key moments - from our scoring
Substance score
18 / 100
Five dimensions, 20 points each
The Cybersecurity Framework - released by NIST in February 2014 through Executive Order 13636 - provides a voluntary, risk-based approach organized around five core functions: identify, protect, detect, respond, and recover. This section argues the framework remains underutilized despite its proven value, particularly among federal agencies, smaller organizations, and state/local governments. The commission recommends mandatory federal agency adoption, regulatory harmonization to reduce compliance burden, and the creation of a Cybersecurity Framework Metrics Working Group (CFMWG) to develop industry-led consensus metrics. A key action item establishes the Cyber Incident Data and Analysis Repository (CIDAR) - a national voluntary incident reporting program to inform insurance actuarial models and peer-benchmarking. The report also emphasizes targeted support for the 28 million small and medium-sized businesses (SMBs) that drive 46% of private sector output, recommending NIST expand implementation-ready framework profiles, DHS work with the National Cybersecurity Center of Excellence (NCCoE) to develop technology integration blueprints, and creation of lessons-learned programs tied to real attacks. Liability protections, tax incentives, and procurement advantages are proposed to incentivize adoption.
The five core functions are: identify, protect, detect, respond, and recover. The framework uses these functions to provide a risk-based approach to managing cybersecurity that applies to organizations of any size or sector.
Most federal agencies are currently not using the framework despite its proven value. Mandatory adoption via Office of Management and Budget directive would drive agencies away from simple compliance thinking and toward holistic cyber risk management, immediately improving their security posture.
CIDAR is a nationwide voluntary incident reporting program that aggregates cybersecurity incident data to inform the Cybersecurity Framework Metrics Working Group, enable insurers to standardize premiums and coverage decisions, and allow organizations to perform peer benchmarking and cost-benefit analysis.
Regulatory agencies should explicitly map their requirements to the framework and harmonize approaches to reduce redundancy and confusion. The OMB should require agencies departing significantly from the baseline framework to demonstrate through regulatory impact analysis that added compliance costs are outweighed by public benefits.
NIST should expand implementation-ready framework profiles tailored to SMB business objectives, DHS and NCCoE should develop practical technology integration blueprints, and government and industry should collaborate on lessons-learned programs translating past cyber attacks into SMB-specific mitigation guidance.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode is a straightforward reading of government policy recommendations with minimal novel insight. It recites the Cybersecurity Framework's structure and existing action items without adding analytical depth, interpretation, or non-obvious claims that would educate a B2B operator. The content is largely procedural and policy-focused rather than substantive business or operational insight.
The framework provides a risk based approach to cybersecurity through five core functions identify, protect, detect, respond, and recover.
The Commission recommends the publication of information, including example and sector profiles, to help smaller companies use the Cybersecurity Framework.
This is a direct reading of a government commission report with no original thinking, contrarian perspectives, or first-principles analysis. It presents standard policy recommendations and widely-known frameworks without fresh interpretation or counterintuitive argument. The content is entirely derived from existing government documentation.
The Framework for Improving Critical Infrastructure Cybersecurity, more widely known as the Cybersecurity Framework, was called for by Executive Order one three six three six in January twenty thirteen and released in February twenty fourteen.
Organizations need to make informed, smart choices about risks to their assets and operations, and to set priorities for cybersecurity efforts and investments justice as they do in dealing with other enterprise risks.
This is not a guest-based podcast episode; it is a LibriVox recording (public domain audiobook reading) of a government commission report read by a narrator. There are no practitioner guests, operators, or subject matter experts in conversation. The absence of any human guest discussion is a fundamental structural limitation.
This is a LibriVox recording. All LibriVox recordings are in the public domain.
Recording by Maria Casper
The episode includes some specific numbers and named programs (28 million small businesses, 46% of private sector output, 63% of new jobs, NIST, DHS, Treasury), but lacks concrete case examples, real company implementations, measured outcomes, or empirical data on framework effectiveness. References are to policy recommendations and programs rather than evidence of their actual impact.
There are more than twenty eight million small businesses in the United States. These businesses produce approximately forty six percent of our nation's private sector output and create sixty three percent of all new jobs in the country.
Department of Homeland Security and NIST, through the National Cybersecurity Center of Excellence NCCoE, in collaboration with the private sector, should develop blueprints for how to integrate and use existing cybersecurity technologies
This is a recited government report with no host, no guest, and no conversation whatsoever. There are no questions, no follow-ups, no debate, and no productive disagreement. It is purely a linear reading of policy text, making conversational craft entirely inapplicable as a dimension.
Section seven of Report on Securing and Growing the Digital Economy. This is a LibriVox recording.
End of Section seven. Recording by Maria Casper
Computed from the transcript - who did the talking, and the words that came up most.
On April 13, 2016, President Obama established The Presidents Commission on Enhancing National Cybersecurity to devise a comprehensive strategy for safeguarding our cyberspace and the economic foundations built upon it. The commissions final report, published in December 2016, provides a thorough examination of the current state of cybersecurity, anticipates future challenges, and presents actionable recommendations for the incoming Trump administration and future leaders. It emphasizes the critical roles that the military, government, and private sector must play in strengthening our defenses against cyber threats. Join us as we explore the insights and strategies laid out in this pivotal report. - Summary by TriciaG
Transcribed and scored by The B2B Podcast Index.
Section seven of Report on Securing and Growing the Digital Economy. This is a LibriVox recording. All LibriVox recordings are in the public domain. For more information or to volunteer, please visit LibriVox dot org.
Report on Securing and Growing the Digital Economy by the Commission on Enhancing National Cybersecurity Imperative one, Part three Recommendation one point four. The next administration should build on the success of the Cybersecurity Framework to reduce risk both within and outside of critical infrastructure by actively working to sustain an increase use of the framework. Organizations need to make informed, smart choices about risks to their assets and operations, and to set priorities for cybersecurity efforts and investments justice as they do in dealing with other enterprise risks.
The Framework for Improving Critical Infrastructure Cybersecurity, more widely known as the Cybersecurity Framework, was called for by Executive Order one three six three six in January twenty thirteen and released in February twenty fourteen. The development of this voluntary framework was coordinated by NIST through a collaborative process involving industry, academia, and government agencies. The framework provides a risk based approach to cybersecurity through five core functions identify, protect, detect, respond, and recover.
It is designed to assist organizations of any size, in any sector and at any stage of their cybersecurity maturity. The framework provides a vocabulary to bridge the commun unication gap that sometimes exists between technologists and executives. NIST was directed to create the framework specifically for managing cybersecurity risks related to critical infrastructure, but a broad array of private and public sector organizations across the United States and some around the world now use it.
There is potential for even more widespread use of the framework's risk management approach to address and reduce cyber security issues. The cyber Security Framework is playing an important role strengthening the risk management ecosystem, and if effectively implemented, it can reduce the need for future legislation and regulation. For this reason, the Commission recommends focusing additional attention on cyber security risk management and conformity assessment. Risk management and measurement can be helpful in making decision about cyber insurance coverage and possibly in reducing premiums.
The framework has tremendous value for organizations such as small business and state, local, tribal, and territorial governments that are resource constrained and need an efficient and effective way to address cybersecurity risk. In addition, the cyber Security Framework augments existing Federal Information Security Modernization Act FISMA practices used by federal agencies. The framework already has proven its value to larger organizations both up and down the management chains, from boards of directors and chief executives to the IT and business operations.
In short, the framework is a low cost, high yield option for enhancing cyber security. The Commission heard repeatedly in workshops from stakeholders and in public comments that the Cybersecurity Framework is a highly valued tool for managing cyber risk. Still, many organizations, including the majority of federal and other government agencies, are not yet taking advantage of it. The Commission believes that the framework should be better utilized, both domestically and globally by all organizations inside and outside government for greater impact.
The Commission recommends the publication of information, including example and sector profiles, to help smaller companies use the Cybersecurity Framework. The Commission emphasizes the importance of ensuring continuous updates to the action items below to align with Evolving Capabilities Action Item one point four point one. NIST, in coordination with the NCP three should establish a cyber Security Bank Framework Metrics Working Group CFMWG to develop industry led consensus based metrics that may be used by one industry to voluntarily assess relative corporate risk, two the Department of Treasury and insurers to understand insurance coverage needs and standardize premiums.
And three Department of Homeland Security to implement a nationwide voluntary incident reporting program for identifying cyber security gaps. This reporting program should include a cyber Incident Data and Analysis Repository CIDAR. Short term, the cyber Security Framework Metrics Working Group would develop meaningful metrics for better understanding and quantifying the benefits that use of the framework brings to organizations that adopt it. Current efforts to measure cybersecurity effectiveness focus on the actions taken by an organization rather than on those actions effectiveness.
This group's work should help address that gap, offering quantifiable information that can be used to improve the framework and more precisely demonstrate where and how its use is most effective. The metrics developed must also be useful for insurers seeking to understand evolving coverage needs. The discrete risks associated with insurance coverage must be measurable so that insurers can have a stronger basis for making coverage decisions and standardizing insurance premiums.
Pre Existing public private collaborations such as the Department of Treasury led to Financial and Banking Information Infrastructure Committee, are logical venues to gather input for the CFMWG, share the resulting consensus metrics, and discuss the use of those metrics. It is important that the working groups approached to metrics be consistent and align with that of the Cyber Incident Data and Analysis Repository CIDAR. This repository will provide the insurance industry with metrics to be used in actuarial calculations and modeling, and enable the industry to understand the sector differentiation of aggregate risks and effective practices.
A CIDAR will also enable organizations of all types to better manage information security risks by helping them to understand peer to peer benchmarking and by supporting effective cost benefit analysis. It will also highlight the returns on cyber security investments. Voluntary incident reporting data will greatly inform the development of cfmwg's metrics. For this reason, it is important that Congress provide Department of Homeland Security with the resources to expand the current CIDAR pilot to a national capability via a grant program.
Congress also needs to eliminate key barriers to private sector participation in a CIDAR by providing protections to industry modeled on those granted by the twenty fifteen cyber Security Information Sharing Act. Department of Justice and Department of Homeland Security can greatly bolster CIDAR incident reporting data by ensuring that all federal cyber incident reporting mechanisms, including those of the FBI, the United States Secret Service, and the Internet Crime Complaint Center IC three, request data to be submitted automatically to supplement the cidar's repository.
Consistent with Federal Privacy and Security Regulations Action Item one point four point two, all federal agencies should be required to use the cyber Security Framework. Short term. Federal agencies now are encouraged, but not required, to use the Cybersecurity Framework. Notably, some are infusing the core functions of the frame work into the language of cyber security risk management efforts.
Other agencies are using the frame work as an overarching guide to improve their management of risk and to set implementation priorities, pursuing the improvements that will have the greatest impact. However, many agencies are not yet using the cyber Security Framework. They may be reluctant to do so because they are focused on the many requirements that they face, or because they do not understand how they can make productive use of the framework within the larger context of managing their operations.
To address the lack of urgency displayed by the majority of agencies, the Office of Management and Budget OMB should mandate their use of the framework as part of their enterprise risk management approach. For additional details, see Imperative five Recommendation five point three. NIST should also provide agencies with additional guidance. Using the Cybersecurity Framework would bring immediate benefits, driving agencies to shift their approaches away from simple compliance and toward thinking more holistically about cyber security risk management.
Action Item one point four point three. Regulatory agencies should harmonize existing and future regulations with the cyber Security Framework to focus on risk management, reducing industry's cost of complying with prescriptive or conflicting regulations that may not aid cyber security and may unintentionally discourage rather than incentivize innovation short term. The private sector has voiced strong concerns about the ways in which regulatory agencies are beginning to use the Cybersecurity Framework or in which they refer inconsistently to the framework.
As each agency makes different decisions about its application, such disparate regulations risk redundancy and confusion among regulated parts of our economy. Federal regulators should harmonize their efforts relating to the framework, an action called for in Executive Order one three six three six but never executed. Regulatory agencies should make explicit how their requirements map to the cyber Security Framework, as the Federal Trade Commission has done. Office of Management and Budget should also issue a circular that makes the adoption of regulations that depart significantly from the cyber Security Framework explicitly subject to its regulatory impact analysis, quantifying the expected costs and benefits of proposed regulations because of the efficiencies and reduced compliance costs that covered entities would realize from a common framework.
An agency that advances an approach which substantially departs from the baseline framework would be required to make the case that its added cost is outweighed by a public benefit. Likewise, to reduce the impact on industry of overlapping and potentially conflicting requirements, it is important that state and local regulatory agencies strongly consider aligning their approaches with the risk management oriented cyber Security Framework Action Item one point four point five.
The private sector should develop conformity assessment programs that are effective and efficient and that support the international trade in business activities of US companies. Short term conformity assessment is an approach by which organizations determine and demonstrate that they are exercising diligence with regard to cybersecurity. When an industry driven approach is widely used, conformity can be a powerful tool to reduce industry risk if the assessment regime promotes meaningful results and outcomes rather than simply affirming that a review has been conducted.
Organizations want to have confidence that they, their business partners and collaborators, and their supply chain are effectively managing risk. They also wish to demonstrate their conformance in order to bolster trustworthy business relationships. In the US. This respect conformance is a helpful tool for organizations seeking to expand partnerships and other business relationships.
Conformity assessments conducted by private sector organizations can increase productivity and efficiency in government and industry, expand opportunities for international trade, conserve resources, improve health and safety, and protect the environment. The increasing use of Cybersecurity Framework, both in critical infrastructure and beyond, makes it a good basis for conformity assessment. The conformity assessment that is being undertaken by the private sector could in part meet the needs of owners and operators, business partners, and supply chains in demonstrating their effective use of the cyber Security Framework.
Action Item one point four point five, the government should extend addition incentives to companies that have implemented cyber risk management principles and demonstrate collaborative engagement. Short term incentives must play a more substantial role in building a cyber secure nation. To accomplish this goal, the next administration and Congress should pass legislation that provides appropriate liability protections for businesses that engage in cyber risk mitigation practices that are consistent either with the cyber Security Framework or with common industry segment practices and that engage in cyber collaboration with government and industry.
Safe harbors would be particularly appropriate to consider in the context of providing business certainty for companies that operate in regulated sectors. Additional benefits to encourage enhanced cybersecurity might include tax incentives, government procurement incentives, public recognition programs, prioritized cyber technical assistance, and regulatory streamlining. In addition, research and development efforts should specifically include a detailed study of how best to improve network security through incentives Recommendation one point five.
The next administration should develop concrete efforts to support and strengthen the cyber security of small and medium sized businesses SMBs. There are more than twenty eight million small businesses in the United States. These businesses produce approximately forty six percent of our nation's private sector output and create sixty three percent of all new jobs in the country. Nearly all rely on information technologies, including the Internet, other digital networks, and a variety of devices.
For some small businesses, the security of their information systems and networks either is not their highest priority or is something they do not have the resources to address. A cyber security incident can harm their business customers, employees, and business partners. Incidents involving their companies can also have far broader consequences, adversely affecting segments of the digital economy. The federal government can and should provide assistance to these companies.
Action Item one point five point one. The National Institute of Standards and Technology NIST should expand its support of small and medium sized businesses in using the cybersecurity Framework and should assess its cost effectiveness specifically for small and medium sized businesses. Short term Security Framework is being adopted by organizations of all sizes, but many smaller businesses are unclear about how to use it. NIST recently published Small Business Information Security the Fundamentals, based in part on the framework.
NIST should continue to help small and medium sized businesses use the cybersecurity Framework and expand those efforts that help should take the form of implementation ready profiles that address commonly occurring business objectives, for example, availability of web services confidentiality of intellectual property using the cybersecurity framework. These framework profiles should align and organization's cybersecurity activities with its business requirements, risk tolerance, and resources, and should aid in the communication of risk within and between organizations.
NIST, Department of Homeland Security, the Small Business Association, and SSAS should educate small and medium sized businesses on the use of the profiles in achieving desired business outcomes. This outreach should be included as part of these agencies ongoing cybersecurity information and assistance programs. Significantly, NIST should provide fact based metrics to establish whether and to what extent use of the framework is effective. Action Item one point five point two.
Department of Homeland Security and NIST, through the National Cybersecurity Center of Excellence NCCoE, in collaboration with the private sector, should develop blueprints for how to integrate and use existing cybersecurity technologies with a focus on meeting the needs of small and medium sized businesses. Short term, the federal government develops best practice guides for cybersecurity, and it provides technical assistance to smaller businesses. It is not currently providing customized guidance about how to integrate and use cybersecurity technologies that are available to meet a variety of needs that small businesses face.
Department of Homeland Security and NIST, through the NCCoE should initiate focused efforts, including the use of private sector partners and collaborators, to provide the kind of practical guides needed by small and medium sized companies that have limited technical capabilities, time, and resources. These guides should be consistent with the Cybersecurity Framework Action Item one point five point three. Pacific agencies, ssas and industry associations and organizations should collaborate to develop a program to review past public cyber attacks to identify lessons learned from the event, including a focus on application to small and medium sized businesses.
Short term government and the private sector should collaborate to develop this program, which would translate lessons learned into guidance to mitigate the vulnerabilities exploited. This guidance should be tailored to small and medium sized businesses. End of Section seven.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.