Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Latest News - Trump Administration Rewrites Cybersecurity Policy in New Executive Order
Latest News Business and Policy News & Analysis

Trump Administration Rewrites Cybersecurity Policy in New Executive Order

Kirsten DoyleBy Kirsten DoyleJune 10, 20255 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Trump Administration Rewrites Cybersecurity Policy in New Executive Order
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Trump Signs Executive Order Overhauling Federal Cybersecurity Policy, Refocusing on Technical Defense and Threat Mitigation

President Donald Trump has signed a new Executive Order aimed at reinforcing the country’s defenses against foreign cyber threats.

The order strips away what the administration describes as “political distractions” from previous directives, prioritizing hands-on technical safeguards over bureaucratic mandates.

The new order amends and replaces key elements of two Obama- and Biden-era Executive Orders (14144 and 13694) declaring a return to cybersecurity fundamentals: protecting digital infrastructure, defending against state-backed cyber campaigns, and preparing the U.S. for next-generation threats like quantum computing.

A Return to Technical Rigor

Key technical initiatives outlined in the order include:

  • Advancing Secure Software Development: By August, the National Institute of Standards and Technology (NIST) will partner with industry to update the Secure Software Development Framework (SSDF) and establish a consortium at the National Cybersecurity Center of Excellence. A final version of the revised SSDF will be published early next year.
  • Protecting Internet Infrastructure: The order directs agencies to harden border gateway protocol (BGP) routing, an area frequently exploited for traffic hijacking and espionage.
  • Preparing for the Quantum Future: Recognizing the disruptive potential of quantum computers, the order sets deadlines for agencies to transition to post-quantum cryptography (PQC). PQC-capable product categories will be identified by December 1, 2025, and protocols like TLS 1.3 will become mandatory across federal systems by 2030.
  • Upgrading Encryption Across the Board: The directive mandates the adoption of the latest encryption standards in all federal systems, reducing exposure to known cryptographic weaknesses.

A New Focus on AI in Cybersecurity

In contrast to earlier directives that emphasized regulating AI content, Trump’s order refocuses AI policy on technical vulnerability management.

By November, agencies including the Department of Defense and the Department of Homeland Security must begin tracking and responding to vulnerabilities specific to AI systems, including sharing compromise indicators and incident data. Public and academic access to cybersecurity datasets will also be expanded to accelerate research.

Simplifying and Securing the Internet of Things

The order also launches a new machine-readable policy initiative designed to bring transparency and automation to federal cybersecurity rules. NIST, CISA, and the Office of Management and Budget (OMB) will jointly establish a pilot program to encode cybersecurity policy into “rules-as-code” format.

And in a notable consumer-focused move, by 2027, all Internet-of-Things (IoT) products sold to the government must display a “U.S. Cyber Trust Mark”, a formal security assurance label under the Federal Acquisition Regulation (FAR).

Stripping Away the Bloat

The order doesn’t just add, it removes. Several provisions from the previous EO 14144 were struck down or rewritten, including:

  • Digital ID requirements for undocumented immigrants, which the administration said could have facilitated entitlement fraud.
  • Broad software inventory mandates that critics said created more red tape than security value.
  • Provisions that centralized technical decisions in the White House rather than empowering agency-level innovation and risk assessment.

Geopolitical Context: Eyes on China

The revised EO doesn’t mince words about foreign threats. The People’s Republic of China is named as “the most active and persistent cyber threat” to the United States, followed by Russia, Iran, and North Korea. These adversaries are blamed for ongoing campaigns targeting federal systems, critical infrastructure, and the private sector.

The updated national policy now explicitly prioritizes defenses against these adversaries’ known tactics, aligning cybersecurity posture more closely with national security concerns.

With deadlines as early as August, agencies now face a tight window to align with the new direction. But for a government under relentless cyber pressure, urgency may not be a bad thing.

Walking Away From Important Lessons

Dave Gerry, CEO at Bugcrowd says: “This order walks away from important lessons. Rolling back secure by design software attestations and limiting sanctions to only foreign actors sends the wrong message at the wrong time. Those were put in place to reduce risk across the supply chain. Also, narrowing sanctions to only apply to foreign actors leaves a clear gap, especially when we’ve seen domestic enablers working in lockstep with foreign adversaries.”

Gerry adds that while the shift toward voluntary guidance sounds nice, in practice it often means slower adoption and fewer safeguards. “It’s hard to see how this makes us safer. Cybersecurity should be a nonpartisan commitment to national resilience, not a political bargaining chip.”

Mike McGuire, Senior Security Solutions Manager at Black Duck, comments that with the executive actions that took place early in the current administration, it was notable that the cybersecurity executive orders from the previous administration were left untouched.

“With this new executive order, the current administration reverses the software attestation requirements established in OMB memo M23-16 which was authorized under EO14028. By modifying EO14144, which was an extension of EO14028 and built upon lessons learnt in industry, EO14028 is practically rescinded.”

What we should expect to see is a more prescriptive set of guidance documents from NIST in 2025, says McGuire. “By establishing a consortium with industry at the NCCoE, this executive order signals a desire by the administration to collaborate with industry on advancing the nation’s cybersecurity skills and competencies. With a focus on NIST publications SP800-218 and SP800-53, the administration recognizes that deploying secure software starts at development, and ultimately, cybersecurity success is based on securely deploying that software. Lastly, this order recognizes both the contributions open-source technologies bring to American innovation, but also the unique risks they pose.”

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

What Are AI SOC Agents? Use Cases, Architecture, and the Leading Vendors

June 19, 20266 Mins Read

AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals

June 19, 20265 Mins Read

ShinyHunters targets Oracle PeopleSoft customers through critical zero-day

June 19, 20263 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}