Why Has the US Delegated So Much of Cybersecurity to the Private Sector, and What Are the Next-Generation "Meta-Cybersecurity" Domains?

The first half is a factual survey grounded in real policy documents. The second half is explicitly labeled speculation. These two things have very different epistemic status, so this article keeps them clearly apart.

This article is deliberately built out of two parts with different levels of certainty. Part 1 is documented history — verifiable against published US policy documents, statutes, and official doctrine. Part 2 is speculation about what might come next, and should not be read as fact. The article states clearly in the text where the switch happens.

Part 1: The Documented Policy History — Why the US Model Took This Shape

The Structural Reason: The Government Doesn't Own the Networks It Needs to Defend

The question "why does America leave cybersecurity to the private sector?" has an answer that comes before any ideology, and it is extremely concrete: the federal government neither owns nor operates the great majority of the networks and systems that need defending.

Power grids, financial settlement systems, telecom networks, pipelines, water utilities, hospitals — most of these are owned and operated by private companies (or by state and local governments). That is a different starting point from a model in which a state telecom monopoly or a state power authority directly controls most national infrastructure. So if the federal government wants national-scale cyber defense, it cannot get there by command. It has to work through indirect instruments aimed at the owners: information-sharing frameworks, sector-specific regulation, and public-private partnerships. This is less a choice than a structural constraint.

The Starting Point: PDD-63 (1998) and the ISACs

The institutional origin most often cited for this framework is Presidential Decision Directive 63 (PDD-63), signed on May 22, 1998. Following the 1997 findings of the President's Commission on Critical Infrastructure Protection (PCCIP), PDD-63 laid the foundation for an industry-government public-private partnership to reduce the vulnerability of America's critical infrastructure.

PDD-63 asked each critical infrastructure sector to establish sector-specific information sharing organizations. Those became the ISACs (Information Sharing and Analysis Centers). Sector ISACs began forming from 1999 onward, with the financial sector's FS-ISAC first. An ISAC is not a government body; it is an industry-run information sharing hub. The pattern established here — industry builds the sharing venue itself and government participates in it, rather than government issuing orders — is the basic American template that has persisted for more than two decades since.

PPD-21 (2013) and Its Successor, NSM-22 (2024)

This thinking was formalized in Presidential Policy Directive 21 (PPD-21), "Critical Infrastructure Security and Resilience," issued by President Obama on February 12, 2013. PPD-21 organized critical infrastructure into 16 sectors, assigned coordination responsibilities across federal agencies, and built its approach around information sharing, risk management, and public-private partnership.

What matters most is that PPD-21 framed security as a shared responsibility. Along with federal, state, local, tribal, and territorial entities, it explicitly names the public and private owners and operators of critical infrastructure as parties on equal footing. In other words, the framing is not "government defends, industry is defended," but "owners and operators are themselves components of national defense." That reads as a direct translation of the structural constraint described above into policy language.

Note that PPD-21 is no longer the operative document. It was superseded by National Security Memorandum 22 (NSM-22), issued on April 30, 2024. NSM-22 retains the skeleton of 16 sectors and the Sector Risk Management Agency (SRMA) framework, while updating the policy in light of a changed threat environment (a shift from counterterrorism to strategic competition, nation-state malicious cyber activity, advances in technologies such as AI). It designates the Secretary of Homeland Security, acting through the Director of the Cybersecurity and Infrastructure Security Agency, as the official responsible for coordination. Plenty of commentary still cites PPD-21 as if it were currently in force, so this is worth watching for.

Telling the Two "CISA"s Apart

Terminology warning — there are two different "CISA"s:
(1) The Cybersecurity Information Sharing Act of 2015 — a statute, enacted in December 2015. It is often written as "CISA 2015."
(2) The Cybersecurity and Infrastructure Security Agency — a federal agency, established in 2018 under the Department of Homeland Security (DHS) by the Cybersecurity and Infrastructure Security Agency Act of 2018.
These are two entirely different things that happen to share an acronym. Because the two are constantly confused, this article writes the statute as "CISA 2015" and the agency as "the CISA agency" throughout.

What CISA 2015 (the statute) actually did was create protections for private companies that share cyber threat indicators and defensive measures with government agencies or with each other — shielding them from antitrust liability, regulatory enforcement, private lawsuits, and public-records disclosure arising from what they share. Rather than exhorting companies that sharing is desirable, it lowers the legal risk of sharing in order to encourage it. That is a distinctly American design: if you cannot order it, move it with incentives and liability protection.

The statute carried a ten-year sunset provision and lapsed once, on September 30, 2025. Congress has since passed a series of short-term extensions; the information-sharing provisions were reauthorized as part of the appropriations law enacted on February 3, 2026. As of this writing (September 2026), no permanent long-term reauthorization has been enacted and the law continues to run on time-limited extensions. The fact that the legal foundation of US public-private information sharing is exposed to expiry on a near-annual basis says something about the structural fragility of the arrangement. For the current expiration date, please check a primary source such as Congress.gov.

The National Strategies: 2018, 2023, and 2026

"The National Cyber Strategy" is not a single document — multiple versions exist, one or more per administration. Here they are in order.

  • September 20, 2018 — National Cyber Strategy (first Trump administration): About 40 pages. Alongside defending federal networks and critical infrastructure and streamlining regulation, it was widely reported for embracing the use of offensive cyber operations to shape adversary behavior. It was also publicly reported around the same time that Presidential Policy Directive 20 (PPD-20), the Obama-era directive governing the interagency process for offensive cyber operations, had been rescinded.
  • March 2023 — National Cybersecurity Strategy (Biden administration): This one made rebalancing responsibility an explicit theme in the text. It sought to shift the cybersecurity burden away from individuals, small businesses, and local governments and onto "the biggest, most capable, and best-positioned actors in our digital ecosystem" — in practice, including major software vendors. It included shaping market forces and pursuing liability for software makers that ship insecure products.
  • March 6, 2026 — President Trump's Cyber Strategy for America (second Trump administration): A short framework document of roughly seven pages, organized around six policy pillars. According to reporting and law-firm analyses, it departs from the 2023 strategy's emphasis on mandatory compliance requirements for critical infrastructure and on shifting liability to software developers, and instead signals a more aggressive deterrence posture, a lighter-touch approach to cybersecurity regulation, expanded reliance on and cooperation with the private sector in threat response, and accelerated adoption of AI and other emerging technologies for network defense.

There is a tension here that should be stated honestly. The 2023 strategy's idea of moving responsibility toward the most capable actors was, read the other way, an acknowledgment of a problem with decades of reliance on private-sector self-regulation. The voluntary information-sharing and partnership approach running from PDD-63 onward was, at least as of 2023, judged insufficient on its own. And yet the 2026 strategy is analyzed as swinging back toward expanded private-sector cooperation. The accurate description, then, is that the US trajectory is not a straight line: it oscillates between relying on voluntarism and imposing responsibility. "America has consistently delegated to the private sector" is too simple to be correct.

The Military and DoD Angle — Strictly Within What Is Public

This section requires particular care. Everything below is drawn only from published strategy documents, official public statements, and public reporting. It does not address non-public information about what operational capabilities US Cyber Command (USCYBERCOM) actually possesses.

What is established as public doctrine are the concepts of "defend forward" and "persistent engagement," introduced in USCYBERCOM's 2018 vision document "Achieve and Maintain Cyberspace Superiority" and reflected in the 2018 DoD Cyber Strategy of the same year.

The rationale, as explained in public documents, runs roughly like this. Passive, after-the-fact defense — waiting to be breached and then responding, finding vulnerabilities and patching them — cannot take the initiative away from the attacker. So the aim is to disrupt or halt malicious cyber activity at or near its source, stopping threats before they reach their targets, and to contend with adversaries continuously as an ongoing campaign rather than as a series of discrete incidents — imposing friction, exposing tradecraft, and seizing the initiative. The concepts have been analyzed publicly in academic venues such as Intelligence and National Security, and USCYBERCOM itself explains both terms in its public "CYBER 101" explainer material.

A publicly acknowledged application is the "hunt forward" operations conducted by USCYBERCOM and the NSA, in which US teams deploy to partner countries to identify adversary malware on those countries' networks. Deployments to Ukraine, Estonia, Lithuania, and North Macedonia, among others, have been publicly disclosed.

Where this article stops: questions like "what offensive capabilities does USCYBERCOM actually have" or "which vulnerabilities does it hold back" cannot be settled from public information. An article that states such things confidently is quite likely presenting speculation in the costume of fact. This article does not cross that line.

The Supply Chain Question: SolarWinds (2020) as a Public Case Study

That supply-chain security is a matter of strategic interest to the military and intelligence community is a theme that has been discussed extensively in public commentary and reporting. The canonical case study is the SolarWinds Orion incident of 2020.

The published sequence of events is as follows. Attackers gained access to SolarWinds' software development environment and inserted backdoor code (SUNBURST) into builds of the Orion platform. The trojanized versions were distributed as legitimate updates between March and June 2020, and roughly 18,000 customers are understood to have downloaded them. On December 13, 2020, the CISA agency issued Emergency Directive ED 21-01, "Mitigate SolarWinds Orion Code Compromise," ordering federal civilian agencies to immediately disconnect or power down affected Orion versions. On April 15, 2021, the US government attributed the activity to Russia's Foreign Intelligence Service (SVR).

What the incident demonstrated is a structural point: the trusted, legitimate update channel is itself an attack surface. And it connects directly to the first half of this article. What was breached was a private company's build pipeline; what was affected was 18,000 organizations, federal agencies among them. To defend its own networks, the government was depending on the security of a vendor development environment it did not control. It is the clearest possible illustration of the risk inherent in the "delegated to the private sector" structure.

Part 2: From Here On, This Is Speculation — Candidate Next-Generation "Meta-Cybersecurity" Domains

⚠ The nature of this article changes here — Part 1 was fact, Part 2 is speculation.

Everything up to this point was verifiable, grounded in real policy documents, statutes, published doctrine, and publicly disclosed incident timelines. Every document cited is public and can be checked by the reader against primary sources.

By contrast, what follows is necessarily speculative. These are candidate domains discussed in technology-policy circles — informed speculation about where cybersecurity-relevant strategic technology competition may be heading next. They are not settled predictions, not government policy, and not established fact.

The individual research programs and experiments referenced below (quantum satellites, national quantum network testbeds, fusion experiments, plasma control research) are restricted to real, publicly documented activity. What is speculative is the interpretive claim that these will become central cybersecurity issues — not the existence of the research itself. Keeping that distinction in mind matters for reading what follows.

Candidate 1: Quantum Computing and Quantum Communication Infrastructure

The long-term threat that quantum computers pose to today's public-key cryptography (RSA, DH, ECC), and why lattice cryptography is not currently a target of the same attack, is covered in depth in a separate article on this blog. Rather than repeat it here, please see: What Are Quantum Cryptanalysis Algorithms? Shor's Algorithm and Where Lattice Cryptography Stands Today

What is worth adding in this article's context is that national-scale investment is going not only into "breaking cryptography," but into using quantum technology to protect the communication channel itself. The leading example is QKD (quantum key distribution) and quantum networking.

Real, publicly documented efforts include the following. China's quantum science satellite Micius, launched in August 2016 by a team led by Professor Jian-Wei Pan of the Chinese Academy of Sciences, demonstrated decoy-state QKD from satellite to ground over distances up to roughly 1,200 km in 2017, and carried out intercontinental quantum key sharing between China and Austria (Beijing–Vienna) across a ground distance of approximately 7,600 km, which was used for a roughly 75-minute video conference. Later work reported a hybrid quantum communication network of about 4,600 km total, integrating the satellite link with an existing ~2,000 km Beijing–Shanghai terrestrial "trusted node" link. In the United States, the Department of Energy (DOE) published a blueprint for a quantum internet and has funded multiple national-laboratory-led quantum networking testbeds, including a testbed loop around Argonne National Laboratory and the Quant-NET project. In Europe, EuroQCI is building a pan-EU quantum communication infrastructure combining a terrestrial fiber backbone with a satellite segment.

A very large caveat is required here, however. The idea that QKD will replace general communications infrastructure any time soon does not match the official position of major government cryptographic authorities. The US NSA has publicly stated that, for national security systems, post-quantum cryptography (PQC) is more cost-effective and easier to maintain than QKD, and that it does not support the use of QKD unless its limitations are overcome. The limitations the NSA cites include the lack of hardware authentication, the requirement for special-purpose equipment, increased infrastructure cost and insider-threat risk, the difficulty of security validation, and increased exposure to denial-of-service attacks. The UK's NCSC took a similar public position in 2025, stating it will not support the use of QKD for government or military applications and endorsing PQC instead. So the fair present-tense description is that QKD is a real and active area of research, but remains far from practical, scalable deployment, and experts genuinely disagree about its place.

Candidate 2: Nuclear Fusion and Plasma Control — The Most Speculative Item Here

Let us be blunt up front. The link between nuclear fusion and cybersecurity is clearly more indirect and more speculative than the quantum item above. This article does not claim that "fusion is the next cybersecurity battleground." What can be argued is only that two possible lines of connection exist.

Line (a): control systems as a new category of high-value attack surface. Fusion experiments depend on extraordinarily complex real-time control software. This is not an abstract point. As a documented example, a collaboration between DeepMind and EPFL (École Polytechnique Fédérale de Lausanne) developed a deep reinforcement learning method for magnetic control of tokamak plasmas and applied it to the real TCV tokamak, publishing the result in Nature in 2022 (Degrave et al., "Magnetic control of tokamak plasmas through deep reinforcement learning"). In the published configuration, the trained neural network takes in 90 different measurements describing plasma shape and position ten thousand times per second and adjusts the voltages of 19 magnets in response.

What that describes is a fast, safety-critical, high-value control system that also contains a machine learning model. The inference that a new category could emerge here — an extension of existing industrial control system (ICS/OT) security, with added questions about model integrity, poisoning of training data or simulators, and interference with real-time control loops — seems reasonable enough. But it remains an inference: no attack targeting a fusion control system has been publicly reported.

Line (b): the historical treatment of energy security as a strategic capability. Abundant, reliable power-generation capability has historically been treated as a capability adjacent to national security. On that basis, one view holds that the closer fusion gets to practical deployment, the more strategic value its underlying R&D — design data, materials and superconducting magnet technology, control know-how — acquires as a target for economic espionage and intellectual property theft. This too is an analogy drawn from general principles; this article makes no claim about any specific case.

Briefly, on the public state of fusion research itself: the international ITER project adopted a revised baseline in 2024 that sets the start of research operations (SRO) for 2034 and the start of deuterium–tritium (D-T) operations for 2039 (a four-year delay to D-T operations relative to the prior plan). On the private side, several companies including Commonwealth Fusion Systems (SPARC) and Helion Energy are building and operating demonstration devices, but as of 2026 no commercial fusion plant has delivered electricity to the grid. Individual companies' claimed timelines shift substantially, so this article avoids specific milestone dates for them and stays at the level of "several national and private fusion research programs are running in parallel."

Closing Part 2: This Is Not a Forecast

To restate it plainly: the quantum and fusion items in Part 2 are candidate areas of strategic technology competition that may have future cybersecurity dimensions. They are not confident predictions.

And crucially, genuine experts differ on how central any of these will actually turn out to be to cybersecurity specifically. On quantum, the NSA and NCSC have publicly taken a cautious line on QKD, while China and the EU invest in quantum communication infrastructure at national scale. As for fusion, the more common assessment is probably that it belongs to technology competition and energy security broadly rather than to cybersecurity as such — and this article does not dispute that assessment. What is offered here is a plausible line of reasoning, not a conclusion.

Summary

  • [Fact] The fundamental reason the US runs a public-private cybersecurity model is the structural constraint that the federal government neither owns nor operates most of the networks needing defense
  • [Fact] The institutional origin is PDD-63 (1998) and the ISACs it produced; the formalization is PPD-21 (2013); the current operative document is NSM-22 (2024), which superseded it
  • [Fact] "CISA 2015" is a statute (the Cybersecurity Information Sharing Act of 2015); "the CISA agency" is the Cybersecurity and Infrastructure Security Agency, established 2018. Different things, coincidentally identical acronyms
  • [Fact] CISA 2015 lapsed on September 30, 2025 and has since run on repeated short-term extensions (check a primary source for the current expiry)
  • [Fact] The strategic line is not a straight one: the 2023 strategy moved responsibility toward major vendors, while the 2026 strategy is analyzed as expanding private-sector cooperation — an oscillation between voluntarism and imposed responsibility
  • [Fact, public sources only] "Defend forward" and "persistent engagement" (2018) exist as published USCYBERCOM doctrine. This article does not address non-public information about actual operational capability
  • [Speculation] Quantum communication infrastructure (QKD) is a real research area, but the NSA and NCSC are cautious about government adoption and it remains far from practical deployment
  • [Speculation, most indirect] Fusion plasma control systems could become a novel safety-critical control-system attack surface, but this is an analogy — no such attack has been publicly reported

Go Deeper on Quantum Computing and Cryptography

The substance behind the quantum item in Part 2 — what Shor's algorithm actually does, and why lattice cryptography is currently considered safe — is explained in detail in this article.

Read What Are Quantum Cryptanalysis Algorithms?