SocietyIssue #69

US Cyber Strategy Shrinks from 39 Pages to 7

Why a strategy that hits harder but defends less isn't just America's problem

US Cyber Strategy Shrinks from 39 Pages to 7

Opening

Hello, subscriber. The Iran-US-Israel war keeps getting murkier. As I write this on March 23rd, Trump declared he’d flatten Iran within 48 hours, then within 24 hours announced a 5-day pause on strikes, then posted on social media that he’d focus on domestic issues instead. Trying to figure out what’s going on in that man’s head, I sat down to write today’s newsletter.

On Friday, March 6th, the White House released a document titled “President Trump’s Cyber Strategy for America.” It’s only 7 pages long. The equivalent document from the Biden administration 3 years earlier ran 39 pages. That’s more than a 5x reduction in length.

If it were just shorter, I’d chalk it up to “getting concise.” But the message is actually far more aggressive. It even includes a declaration that the US “won’t limit itself to the cyber domain” — meaning physical retaliation is now on the table in response to a cyberattack. So… the title says “cyber,” but this reads more like a declaration of offense.

What caught my attention even more than the strategy document itself was what’s happening behind it. CISA1, the agency that would actually have to execute this ambitious strategy, is seeing its budget and staff slashed dramatically. It’s like sharpening the sword while shrinking the shield. Today I want to unpack this contradiction — and what it means for Korea.

20 Years of Change — From Defense to Offense

To understand why this strategy matters, we first need to trace the arc of US cyber strategy over time.

The US created its first national cyber strategy in 2003, under the Bush administration. Back then, the core idea was simply “let government and the private sector cooperate voluntarily” — fairly loose by today’s standards. A major shift came in 2018, during Trump’s first term. A 40-page strategy document introduced the concept of Defend Forward2 for the first time: entering an adversary’s network first, to preempt an attack before it lands.

In 2023, the Biden administration produced a meticulous 39-page document built around 5 pillars with concrete implementation goals. The direction was different — it leaned toward tighter regulation, putting more security responsibility on the companies that build software.

And in March 2026, the Trump 2.0 strategy arrived. It’s the shortest cyber strategy document in US history — the actual body text runs barely 5 pages. Yet it sets out 6 pillars. The difference in core philosophy is stark. Biden’s approach was “tighten regulation to raise private-sector accountability.” Trump’s is “loosen regulation, expand private-sector autonomy, and go harder on offense.” Whether to impose defensive responsibility through regulation, or to protect through government offensive deterrence — these are fundamentally different approaches.

This strategic pivot didn’t come out of nowhere. According to the FBI’s Internet Crime Complaint Center (IC3), roughly 860,000 complaints were filed in 2024 alone, with losses reaching $16.6 billion (about ₩24 trillion) — a 33% increase over the previous year. It’s also been confirmed that a Chinese hacking group called Volt Typhoon has infiltrated critical US infrastructure, including power grids, telecom networks, and water systems.

6 Pillars — What’s New, What’s Risky

What sets the tone for this strategy is Pillar 1, “Shape Adversary Behavior.” Here, the document declares that the US “won’t limit itself to the cyber domain.” It directly cites cyberattacks on Iran’s nuclear infrastructure and the cyber component of the operation to capture Venezuela’s Maduro in the strategy document itself. Citing specific operational examples in a national strategy document is highly unusual — it’s a demonstration that “we have this capability, and we’re actually using it.”

More noteworthy is the plan to give the private sector incentives to disrupt adversary networks. Until now, responding to cyberattacks has been the government’s job — but this opens the door for private companies to get involved too. In effect, it leaves the door open to privatizing cyber warfare. Once private companies start touching other countries’ networks, the line between state action and private action blurs. That raises international-law questions that are now unavoidable.

There’s also something new on the technical front. The document explicitly states that agentic AI3 will be used on both the defensive and offensive sides of cyber operations — AI handling network anomaly detection, automatically generating honeypots4, even auto-patching vulnerabilities. This is the first time AI security has been elevated to a core pillar of national strategy. Of course, attackers are doing the same. According to a 2025 SoSafe survey, 87% of global organizations have already experienced AI-powered attacks. The AI-versus-AI arms race has already begun.

And for the first time, cryptocurrency and blockchain are explicitly named as things to protect — entirely absent from previous strategies. The direct backdrop: North Korea’s Lazarus Group stole roughly $1.5 billion (about ₩2.2 trillion) worth of Ethereum from the Bybit exchange in February 2025 — the largest crypto hack on record. At the same time, the document signals tighter regulation on mixers5 and privacy coins.

The transition to post-quantum cryptography (PQC)6 is included too. Once quantum computers become practical, current cryptographic systems could be rendered useless. The logic: swap the locks now, before the master key of the future arrives.

An Ambitious Strategy, A Shrinking Shield

Taken on its own, this is the most aggressive strategy in US history. But what’s happening at the organization tasked with executing it is the exact opposite. Look at CISA: under the administration’s FY2026 budget proposal, cuts of roughly $495 million (about 17%) have been proposed. Staffing cuts of about 29% have been proposed as well — from 3,732 down to 2,649 — and in practice, a mix of voluntary departures and early retirements has already brought headcount down to an estimated 2,200–2,600. A full 1/3 of the original workforce is gone.

As for which specific programs took the hit: the National Risk Management Center (NRMC) faces a proposed 73% cut, the stakeholder engagement division faces a 62% cut, and cyber defense training programs lost $45 million. The election security program was eliminated outright. More importantly, CISA still doesn’t have a confirmed director. The organization is shrinking with nobody at the helm.

Experts have been fairly blunt about this. Michael Daniel, CEO of the Cyber Threat Alliance (CTA), stated plainly that these budget cuts “will weaken cyber incident response capability.” CSIS’s James Lewis put it this way: “CISA may have needed a scalpel. But you don’t perform surgery with a hammer.” What’s telling is that this concern is bipartisan — even Republican Rep. Andrew Garbarino, who chairs the House Homeland Security Subcommittee on Cybersecurity, warned that “cutting staff at a time when cyber threats are growing could hamper CISA’s ability to carry out its mission.”

The administration has its own logic, of course. National Cyber Director Sean Cairncross explained that the strategy was deliberately designed to be concise, with detailed implementation plans to follow. The CISA cuts, in this framing, are simply “recalibrating the scope of the mission” — trimming the unnecessary to focus on the core. That may well be true. But the problem is that this isn’t a moment when cyber threats are declining — they’re rising sharply. We’ll need the follow-up implementation documents to make a real judgment, but for now, the gap between the strategy’s ambition and the reality of its execution looks quite wide.

Impact on Korea — A Shrinking Protective Umbrella

There’s a line in this strategy document that’s easy to overlook: “cost-sharing with allies must be fair.” That’s a signal that the US will demand more cyber defense responsibility — and cost — from allies, Korea included. It also connects to the defense-spending burden-sharing rhetoric the Trump administration has pushed consistently across both terms.

Until now, CISA has served as a hub for international cyber threat intelligence sharing, including a cooperative relationship with Korea’s KISA7. If CISA weakens, that entire global information-sharing ecosystem weakens along with it.

Korea’s own situation looks even more concerning. 2025 was the year Korea’s critical cybersecurity vulnerabilities were laid bare. The biggest shock was the SKT (SK Telecom, Korea’s largest mobile carrier) SIM hacking incident. According to the government’s final investigation, 33 types of malware were found across 28 servers, and about 26.96 million records across 25 categories of SIM data were leaked — a figure approaching half of Korea’s entire population. The initial breach dated back to August 2021, meaning hackers sat inside the system for roughly 4 years. Global security consulting firm CMA named this one of the 7 major cyberattacks of 2025.

It wasn’t just an SKT problem. KT (Korea’s second-largest carrier) concealed a hacking breach from 2024 for 18 months before finally reporting it in the second half of 2025, and signs of a hack were confirmed at LG Uplus (Korea’s third major carrier) as well. All 3 of Korea’s telecom carriers suffered security breaches in succession. This isn’t one company’s problem — it’s a systemic one.

Korea hasn’t been sitting still either. It established a National Cybersecurity Strategy in 2024 and launched a government-wide Cybersecurity Council. But reality still hasn’t caught up with the strategy’s ambition. As US defense infrastructure shrinks, Korea’s own independent capabilities matter that much more.

Oz’s Lens

Honestly, looking at this strategy document, what struck me most was that the context outside the document matters more than the document itself. A strategy document’s quality should be judged by executability, not length. Whether it’s 7 pages or 70, the real question is: who executes this, with what resources, and by when? Yet this strategy presents the most aggressive vision on record while shrinking the very organization meant to carry it out. When a gap like this opens up between strategy and execution, I can tell you from experience as a data professional — the first party to test that gap is always the adversary.

What I’m watching most closely is the possibility of privatizing cyber warfare. Giving private companies incentives to disrupt adversary networks means the line between war and business grows blurrier still. If this direction plays out, the order of cyberspace could change fundamentally. If the US moves this way, China and Russia gain the same justification to build up their own private-sector cyber offensive capabilities. It’s a scenario where the cyber arms race spreads from the state level down to the private level. (e.g., Palantir, Anduril, and similar firms.)

For Korea, one thing is certain: the era of leaning on America’s protective umbrella is shrinking. As we saw in the 2025 telecom breaches, private companies’ security capabilities need to improve fundamentally. I think it’s time to move zero trust8 architecture from “under review” to “being deployed.”

Closing

First, the US has formalized its identity as an “attacker” in cyberspace. This will have long-term implications for the global cyber order. Second, the gap between the ambitious strategy and the CISA cuts is the central issue. We’ll need the follow-up implementation documents before a real assessment is possible. Third, Korea needs to accelerate building its own independent cyber defense capabilities. A shrinking US defense infrastructure means a bigger share of the burden falls to Korea.

Let me leave you with the core question this strategy document raises: can a strategy that shrinks the shield while sharpening the sword actually make cyberspace safer? If you want to dig deeper into this topic, I’d recommend starting with the original strategy document in the references below — it’s only 7 pages, so it won’t take long.

References & Further Reading

The author, Kwangseob Ahn, is a professor of business administration at Sejong University and lead consultant at OBF (Oswarld Boutique Consulting Firm). He teaches statistics and data analysis — business data management and business analytics — while leading GTM and AI strategy consulting in the field, designing the seam between technology and business. He has published academic research on a memory architecture for AI dialogue systems (HEMA) and runs Daily Arxiv, a daily curation of global AI papers. He holds a master’s from Korea University’s Graduate School of Technology Management and a KMBA. He is the author of Homo Brainless: The People Who Outsource Their Thinking.

Footnotes

  1. CISA (Cybersecurity and Infrastructure Security Agency): the cybersecurity arm of the US Department of Homeland Security. Think of it as “cyberspace’s fire department” — its core missions are protecting federal networks, securing critical infrastructure, and sharing threat intelligence.

  2. Defend Forward: the concept of entering an adversary’s network first to eliminate threats before an attack ever reaches you. It’s like searching the burglar’s house before the burglar gets to yours.

  3. Agentic AI: AI that can judge and act on its own toward a given goal, without needing step-by-step human instructions — similar to a self-driving car that finds its own route once you give it a destination.

  4. Honeypot: a deliberately vulnerable fake system designed to lure hackers in. Once a hacker takes the bait, security teams analyze their behavior patterns to better protect the real systems.

  5. Mixer: a service that scrambles the origins of cryptocurrency transactions to make them hard to trace. By pooling funds from many users and redistributing them, it can be abused for money laundering.

  6. Post-Quantum Cryptography (PQC): next-generation cryptography designed to resist even quantum computers. It’s about swapping out the locks now, ahead of the “master key of the future” that quantum computing represents.

  7. KISA (Korea Internet & Security Agency): the Korean agency responsible for internet security and development — handling cyber incident response, personal data protection, and internet infrastructure management.

  8. Zero Trust: a security architecture built on the principle of “trust no one” — every access attempt is verified, whether it originates inside or outside the network. Think of it as checking ID from family members every single time.