• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
CommentaryCybersecurity

The Biden administration just kicked off an era of better cybersecurity in the U.S.

By
Andrew Rubin
Andrew Rubin
Down Arrow Button Icon
By
Andrew Rubin
Andrew Rubin
Down Arrow Button Icon
May 14, 2021, 1:40 PM ET
President Biden answers questions about the Colonial Pipeline ransomware attack at the White House on May 13, 2021. “The Biden administration’s five-pronged approach to modernizing and strengthening our nation’s cyber defenses comes not a moment too soon,” writes Andrew Rubin.
President Biden answers questions about the Colonial Pipeline ransomware attack at the White House on May 13, 2021. “The Biden administration’s five-pronged approach to modernizing and strengthening our nation’s cyber defenses comes not a moment too soon,” writes Andrew Rubin.T.J. Kirkpatrick—The New York Times/Bloomberg/Getty Images

On May 12, 2021, the Biden administration made cybersecurity history by signing into order an executive framework that fundamentally shifts how we approach securing our country. The Biden administration’s five-pronged approach to modernizing and strengthening our nation’s cyber defenses comes not a moment too soon. 

Ransomware has become our nation’s latest and most cunning adversary. Globally, we spent $173 billion on cybersecurity last year, yet we have more breaches than at any time in history—and they’re the most catastrophic breaches of all time, causing global economies and business transactions to come to a complete standstill and costing American taxpayers the equivalent of millions of dollars annually. Most recently, Colonial Pipeline paid nearly $5 million to Eastern European hackers, following a cyberattack that forced the first-ever full shutdown of its main pipeline and sent gas prices soaring. 

SolarWinds, Microsoft Exchange, and now the Colonial Pipeline cyberattack have made it abundantly clear that the need for cybersecurity reform has never been greater. This is something that we all know, and this is something that the federal government has long been aware of. But what the Biden administration acknowledged Wednesday, and where cybersecurity history was truly made, is that cybersecurity solutions alone aren’t failing us. It’s the model that’s failing us. 

Our entire approach to cybersecurity since the early 2000s has been about shoring up our perimeter defenses—keeping the bad guys out. Incidents like SolarWinds have opened the public’s eyes to the fact that attackers, our adversaries, are already in our networks. They’re already in our supply chains, and they already have access to our infrastructure. On the off chance that they haven’t already infiltrated our supply chains, they soon will—and to deny that would be a fundamental underestimation of our nation’s cybersecurity shortcomings. 

In this executive order, the Biden administration mandated a new cybersecurity framework that puts cyber resilience front and center. These mandates go beyond prevention and detection strategies so we can stop minor incidents from becoming cyber disasters. Those newfound mandates are largely founded on a single framework: Zero Trust.      

Google “Zero Trust” and you’ll find a million different definitions. A recent blog post by Forrester analyst Steve Turner puts it best, “Zero Trust is not one product or platform; it’s a security framework built around the concept of ‘never trust, always verify’ and ‘assuming breach.’”

Section 3 of the executive order states: 

“To keep pace with today’s dynamic and increasingly sophisticated cyber threat environment, the Federal Government must take decisive steps to modernize its approach to cybersecurity…The Federal Government must adopt security best practices; advance toward Zero Trust Architecture; accelerate movement to secure cloud services…and invest in both technology and personnel to match these modernization goals.”

In Section 3B, the order goes on to explain that within 60 days, the heads of each federal agency must develop a plan to implement a Zero Trust architecture within their organization. In section 4G, the order notes that agency heads must apply practices of least privilege (the concept of limiting access to all information, applications, and systems from all users and only granting access to those who require it), network segmentation (not allowing any user or communications to travel between clouds, networks, data centers, or applications unless explicitly stated—also known as Zero Trust Segmentation), and proper configuration within the next 60 days. These explicit instructions outline long acknowledged industry best practices when it comes to cybersecurity and Zero Trust. 

In short, we can only expect this order to be as effective as those that abide by its mandates. The move to a Zero Trust architecture won’t be achieved overnight. But with this executive order and recognition that it’s time for meaningful change, I’m optimistic that we’re on the right path to bolstering our nation’s cyber resiliency. We’re on our way to a world where every incident doesn’t have to be catastrophic—and that should be our nation’s No. 1 priority. 

Andrew Rubin is the CEO and cofounder of Illumio, a cybersecurity company.

Our mission to make business better is fueled by readers like you. To enjoy unlimited access to our journalism, subscribe today.
About the Author
By Andrew Rubin
See full bioRight Arrow Button Icon

Latest in Commentary

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Commentary

golf
Commentarybooks
How playing golf alone can make you better at your job
By Gary BelskyMay 8, 2026
10 hours ago
naomi
Commentarymental health
Naomi Osaka: the things I didn’t do to succeed
By Naomi OsakaMay 8, 2026
12 hours ago
amanda
Commentarybatteries
Why energy storage is moving beyond the capex debate
By Amanda SimonianMay 7, 2026
1 day ago
trump
CommentaryMedicare
Auto-enrollment in Medicare Advantage isn’t a nudge. It’s a trap
By Brian KeyserMay 7, 2026
1 day ago
nyse
CommentaryAI agents
Your trusted advocate or your rebellious Frankenstein: how you deploy agentic AI determines which one you get
By Jeffrey Sonnenfeld, Stephen Henriques, Yevheniia Podurets and Jasmine GarryMay 7, 2026
1 day ago
moore
CommentaryAntitrust
I litigated the JetBlue-Spirit merger. A few thoughts on the future of antitrust in the airline industry
By James "Jimmy" MooreMay 7, 2026
2 days ago

Most Popular

California farmers must destroy 420,000 peach trees after Del Monte closes its canneries and cancels more than $550 million in long-term contracts
North America
California farmers must destroy 420,000 peach trees after Del Monte closes its canneries and cancels more than $550 million in long-term contracts
By Sasha RogelbergMay 7, 2026
1 day ago
'Blue dot fever' plagues musicians like Post Malone, Meghan Trainor, and Zayn as a growing list of artists cancel tours due to lagging ticket sales
Arts & Entertainment
'Blue dot fever' plagues musicians like Post Malone, Meghan Trainor, and Zayn as a growing list of artists cancel tours due to lagging ticket sales
By Dave Lozo and Morning BrewMay 7, 2026
1 day ago
A Michigan farm town voted down plans for a giant OpenAI-Oracle data center. Weeks later, construction began
Magazine
A Michigan farm town voted down plans for a giant OpenAI-Oracle data center. Weeks later, construction began
By Sharon GoldmanMay 6, 2026
3 days ago
U.S. Treasury will have to borrow $2 trillion this year just to continue functioning—more than $166 billion every month
Economy
U.S. Treasury will have to borrow $2 trillion this year just to continue functioning—more than $166 billion every month
By Eleanor PringleMay 7, 2026
1 day ago
Airbnb CEO Brian Chesky warns two types of people won’t survive the AI era: ‘pure people managers’ and workers who resist change
Success
Airbnb CEO Brian Chesky warns two types of people won’t survive the AI era: ‘pure people managers’ and workers who resist change
By Emma BurleighMay 7, 2026
1 day ago
Current price of oil as of May 7, 2026
Personal Finance
Current price of oil as of May 7, 2026
By Joseph HostetlerMay 7, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.