Issue #69

America's New Cyber Strategy vs. CISA's Shrinking Budget

The White House wants stronger offense and defense alike, but CISA's staff and budget are being cut—so who actually executes the defense?

SocietyAmerica's New Cyber Strategy vs. CISA's Shrinking Budget

I looked at the organization and resources meant to carry out the new strategy

Writing this on March 23, I read through the United States’ new cyber strategy. Beyond the goals the document lays out, I wanted to see what changes are underway in the organization tasked with actually carrying it out.

The White House released 《President Trump’s Cyber Strategy for America》 on March 6, 2026. The entire PDF runs 7 pages — shorter than the Biden administration’s 39-page strategy from 2023. It’s a directional document; the concrete implementation plans are left to follow-on policy.

The new strategy emphasizes proactive measures, including disrupting adversary networks. It also states that response measures won’t be confined to the cyber domain alone. At the same time, it names modernizing federal networks, protecting critical infrastructure, and building up skilled personnel as major goals. The idea is to strengthen offense and defense together.

What caught my attention was how this plan squares with the push to cut the budget and staff of CISA1, the agency responsible for defense. The administration’s fiscal year 2026 budget request includes deep cuts, and reports say actual headcount has already shrunk due to voluntary departures and the like. It’s worth checking what resources will actually be used to execute the goal of strengthening defense.

Views on regulation and private-sector responsibility have shifted

US cyber strategy has consistently dealt with defense, offense, and public-private cooperation. What’s changed from administration to administration is which tools and responsibilities get emphasized.

The Bush administration’s 2003 national cyber strategy emphasized cooperation between government and the private sector. Trump’s first term brought a more assertive posture into focus in 2018. That year, the Department of Defense’s Cyber Strategy put forward Defend Forward2 — disrupting or halting malicious activity at its source. This concept connects to the White House’s national strategy but was actually laid out in a separate Defense Department document.

The Biden administration’s 2023 strategy emphasized regulation to protect critical infrastructure and placed security responsibility on software vendors. The idea was that burdens previously left to individual users should be shared by companies and institutions with far greater capacity to bear them. It also included proactive measures to disrupt adversary activity.

The 2026 strategy places its weight on reducing the burden of regulatory compliance and expanding cooperation with the private sector. It also shows a strong resolve to impose costs on adversary behavior using the government’s own offensive and defensive tools. The real difference between the two strategies isn’t defense versus offense — it’s how they combine regulation, corporate responsibility, and government intervention.

There’s data that shows the scale of the cyber threat, too. The FBI’s Internet Crime Complaint Center (IC3) reported receiving 859,532 complaints in 2024, with reported losses of $16.6 billion — up 33% from the previous year. This figure covers reported internet fraud and similar crimes broadly; it isn’t limited to nation-state hacking damage. Meanwhile, CISA, the NSA, and the FBI warned that Volt Typhoon, a group linked to China, has infiltrated IT networks within US critical infrastructure — including telecommunications, energy, and water systems.

Six Policy Areas and Expanded Private-Sector Involvement

The new strategy lays out six areas: shaping adversary behavior, modernizing regulation, upgrading federal government networks, protecting critical infrastructure, maintaining a technological edge in emerging tech, and expanding workforce and capabilities. The first area calls for mobilizing both the government’s offensive and defensive capabilities.

The document’s introduction cites operations related to Iran’s nuclear facilities and the capture operation targeting Venezuela’s Nicolás Maduro, asserting the contribution of US cyber capabilities in both cases. It doesn’t disclose the technical details of specific operations. I read this as the administration’s attempt to signal, through these examples, its willingness to actively confront adversaries.

There’s also a line about creating incentives for the private sector to identify and disrupt adversary networks. Companies have already participated in threat-intelligence sharing and blocking criminal infrastructure, but this phrasing draws attention to just how far that participation might now expand. The specific authorities and procedures aren’t spelled out. It doesn’t immediately grant companies independent authority to attack other networks on their own, so we’ll need to watch how follow-up measures define government approval and corporate liability.

On the technology front, the strategy proposes using AI for threat detection, evasion-inducement, and deception, along with agentic AI3 for network defense and disruption. Using honeypots4 to observe attacker behavior or automating vulnerability response come to mind as related use cases, but the document doesn’t mandate any specific function.

Attackers are using AI too. In a 2025 survey by security firm SoSafe, 87% of security professionals said their organization had experienced an AI-powered attack in the past year. Since the responses come from security professionals across multiple countries and the firm’s own customer base, this shouldn’t be read as a confirmed attack rate across every organization worldwide. SoSafe survey announcement

The strategy also explicitly names the security of cryptocurrency and blockchain technology as something to protect. In February 2025, roughly $1.5 billion in crypto assets were stolen from Bybit, and the FBI attributed the theft to North Korea. Incidents like this show that digital asset security is a major challenge. That said, the strategy document doesn’t cite the Bybit incident as a reason for this focus, nor does it propose regulatory measures for mixers or privacy coins.

The transition to post-quantum cryptography (PQC)5 is also included. This is meant to prepare for the concern that a sufficiently powerful quantum computer could someday break some of the public-key cryptography widely used today. Since migrating cryptographic systems takes time, the direction here is to start preparing for the transition now.

CISA’s Proposed Cuts and the Actual Staff Losses

An illustration depicting the tension between cyber offense-defense policy and the organizations tasked with executing it

The administration’s FY2026 budget request called for cutting CISA’s budget by roughly $500 million. On staffing, the proposal would cut budgeted positions from 3,732 to 2,649 — a reduction of about 29%. This figure, compiled by the US Congressional Research Service (CRS), compares FY2024 baseline numbers against the FY2026 request, so it doesn’t reflect actual headcount on the ground. CRS Budget Analysis

The real staff reduction has unfolded separately. Reporting and analysis from March 2026 indicate that CISA has lost roughly 1,000 people to voluntary resignations, early retirements, and layoffs. You can’t simply add the proposed cuts to the departure numbers, but the fact that a substantial number of working staff have already left matters when assessing the agency’s operational capacity.

The cuts under discussion also touch cybersecurity training, risk analysis, and coordination with outside agencies. As of early March 2026, CISA had no Senate-confirmed director and was being run by an acting leadership structure. Having no one at the helm at all is different from a formal directorship simply sitting vacant, but it’s worth examining how frequent leadership turnover affects long-term planning.

This is why BISI’s March 8 analysis flagged a potential gap between the strategy’s stated goals and the actual capacity of private-sector cyber defense organizations. Operations aimed at disrupting attackers and the work of finding and fixing vulnerabilities in internal systems are complementary functions. Growing offensive capability doesn’t reduce the staffing needed for day-to-day defensive work.

The administration says it will follow up with a detailed implementation plan. The thinking may be that reorganizing responsibilities or adopting new technology will let the agency do more with the same resources. Whether that bet pays off should be judged by what work gets cut versus reinforced, and by how response times and recovery outcomes change as a result. We’ll need to track this through each stage — the budget request, Congress’s final approval, and actual execution.

Korea needs to watch both the shift in cooperation and its own defense capacity

The strategy states that costs and responsibilities should be shared fairly between the US and its allies. That’s a line that makes you think Korea, too, could face demands for a bigger role and heavier burden. Still, it doesn’t lay out a specific dollar figure for Korea or a concrete plan to scale back cooperation.

CISA has worked with security agencies in other countries to provide threat alerts and response information. Domestic institutions and companies like the Korea Internet & Security Agency (KISA)6 also draw on international cooperation to get the information they need. We need to watch whether changes in CISA’s workforce affect this flow of information, while also building up our own domestic capacity to detect and respond to threats.

The 2025 SK Telecom incident showed why that’s necessary. The government’s final investigation in July confirmed 28 infected servers and 33 types of malware, with 25 categories of SIM-related information leaked. The scale of the leak was roughly 26.96 million records, measured by subscriber identification number (IMSI) — not a straight headcount of affected individuals. The earliest confirmed malware installation dated back to August 2021, and the government pointed to problems in account management, the handling of a past breach, and the encryption of key information. Government’s final investigation

The December 2025 investigation into KT revealed problems of its own. KT had discovered infected servers between March and July 2024, handled the issue internally, and did not report it to the government; a separate breach via an illegal femtocell — an unauthorized small-cell base station — was also confirmed. In LG Uplus’s case, the relevant servers’ operating systems had been reinstalled or decommissioned, making it impossible to fully trace the incident, so the government referred the matter for criminal investigation. Rather than lumping the three companies’ cases together as the same kind of hacking, we should look at the mismanagement and investigative limits that surfaced in each. Announcement on KT and LG Uplus investigations

Korea, too, drew up a national cybersecurity strategy in 2024. Now each company and institution needs to examine how it manages accounts and access privileges, how it keeps incident records, and how it responds once a breach is discovered. That’s work to be done domestically, regardless of how international cooperation shifts.

Oswarld’s Lens

I think you have to look at a strategy document’s goals together with the organization tasked with carrying them out. A strategy can only be evaluated once it’s clear who will execute it, with what resources, and by when. The United States’ new strategy says it will strengthen the defense of federal networks and infrastructure. Amid CISA’s organizational changes, what matters is confirming that this work actually gets done.

I’m particularly watching how far the government will let the private sector go in disrupting hostile networks. If the lines between government direction/authorization and corporate responsibility stay blurry, there’s a real risk of misidentifying who’s behind an operation, or of disputes escalating. Even when a company’s technology is being put to use, the authority and accountability for the operation need to be spelled out clearly.

Korean companies, too, should be building up their own security capabilities rather than waiting for outside help. Rather than treating zero trust7 as a slogan, I think the real work is starting with the most critical systems—verifying user and device access rights and stripping away unnecessary permissions. Patching vulnerabilities, keeping proper logs, and running recovery drills all need to happen alongside that.

Closing

The US’s new strategy pushes forward on three fronts at once: assertive cyber response, regulatory overhaul, and modernization of defensive systems. What to watch next is how budget, personnel, and the scope of activity granted to the private sector get allocated across each of these goals. Whether CISA’s defense and coordination work actually improves is important too.

For Korea, this shift should serve as a moment to review the terms of cooperation — but first, we need to fix the problems our own domestic incidents have exposed. What I want to see isn’t how forcefully a strategy is worded, but whether our actual capabilities improve: stopping account takeovers, detecting breaches faster, and recovering services more quickly.

The English draft matches the Korean source accurately with correct structure, glossary terms, and no Hangul remaining. No corrections needed.

Your take shapes the next issue

What resonated most in this issue, or where has your experience been different?

Any registered reader can comment for free.

References & Further Reading

The author is Oswarld (Kwangseob Ahn). Current roles: Adjunct Professor at Sejong University, Strategy Consultant at INLEVEL9. Career, research, books, and recent work are kept current on the About page. Latest · July 2026: HEMA-2: A Consolidation-Aware Tri-Memory Architecture with Multi-Channel Scheduling for Lifelong Conversational AI.

Footnotes

  1. CISA is the Cybersecurity and Infrastructure Security Agency, part of the U.S. Department of Homeland Security. It handles security for federal civilian agency networks and critical infrastructure, along with threat information sharing. It is not the agency that commands all U.S. cyber operations.

  2. Defend Forward is the Department of Defense’s approach of disrupting or halting malicious cyber activity at its source, before that activity can cause damage.

  3. Agentic AI refers to AI that performs multi-step tasks and uses tools within a given set of goals and permissions.

  4. A honeypot is a system or resource set up to be accessed by attackers, used to observe attack attempts and behavior.

  5. Post-quantum cryptography (PQC) is a cryptographic technology researched and developed to withstand attacks from both classical and quantum computers. It does not mean absolute security against all attacks.

  6. KISA is the Korea Internet & Security Agency, which handles cyber incident response and internet/information security work.

  7. Zero Trust is a security principle that does not trust users or devices simply because they are on an internal network, instead verifying identity and permissions whenever resources are accessed.