US Cyber Strategy Shrinks from 39 Pages to 7
Why a strategy that hits harder but defends less isn't just America's problem
Opening
Hello, subscriber. The Iran-US-Israel war keeps getting murkier. As I write this on March 23rd, Trump declared he’d flatten Iran within 48 hours, then within 24 hours announced a 5-day pause on strikes, then posted on social media that he’d focus on domestic issues instead. Trying to figure out what’s going on in that man’s head, I sat down to write today’s newsletter.
On Friday, March 6th, the White House released a document titled “President Trump’s Cyber Strategy for America.” It’s only 7 pages long. The equivalent document from the Biden administration 3 years earlier ran 39 pages. That’s more than a 5x reduction in length.
If it were just shorter, I’d chalk it up to “getting concise.” But the message is actually far more aggressive. It even includes a declaration that the US “won’t limit itself to the cyber domain” — meaning physical retaliation is now on the table in response to a cyberattack. So… the title says “cyber,” but this reads more like a declaration of offense.
What caught my attention even more than the strategy document itself was what’s happening behind it. CISA1, the agency that would actually have to execute this ambitious strategy, is seeing its budget and staff slashed dramatically. It’s like sharpening the sword while shrinking the shield. Today I want to unpack this contradiction — and what it means for Korea.
20 Years of Change — From Defense to Offense
To understand why this strategy matters, we first need to trace the arc of US cyber strategy over time.
The US created its first national cyber strategy in 2003, under the Bush administration. Back then, the core idea was simply “let government and the private sector cooperate voluntarily” — fairly loose by today’s standards. A major shift came in 2018, during Trump’s first term. A 40-page strategy document introduced the concept of Defend Forward2 for the first time: entering an adversary’s network first, to preempt an attack before it lands.
In 2023, the Biden administration produced a meticulous 39-page document built around 5 pillars with concrete implementation goals. The direction was different — it leaned toward tighter regulation, putting more security responsibility on the companies that build software.
And in March 2026, the Trump 2.0 strategy arrived. It’s the shortest cyber strategy document in US history — the actual body text runs barely 5 pages. Yet it sets out 6 pillars. The difference in core philosophy is stark. Biden’s approach was “tighten regulation to raise private-sector accountability.” Trump’s is “loosen regulation, expand private-sector autonomy, and go harder on offense.” Whether to impose defensive responsibility through regulation, or to protect through government offensive deterrence — these are fundamentally different approaches.
This strategic pivot didn’t come out of nowhere. According to the FBI’s Internet Crime Complaint Center (IC3), roughly 860,000 complaints were filed in 2024 alone, with losses reaching $16.6 billion (about ₩24 trillion) — a 33% increase over the previous year. It’s also been confirmed that a Chinese hacking group called Volt Typhoon has infiltrated critical US infrastructure, including power grids, telecom networks, and water systems.

Your take shapes the next issue
Reply with your experience or perspective — the best responses feed into future issues.
Sign in to commentAny registered reader can comment — it takes 10 seconds.