logo

Industry leaders on CISA’s secure-by-design pledge: A great program with some issues

ID: e724ea15-80dd-5c96-937b-61d92f576678

STIX ID: report--e724ea15-80dd-5c96-937b-61d92f576678

Feed Name: CyberScoop

Date Published: 2024-12-05

Date Updated: 2026-04-21

Author: mbracken

...
...

Executive Summary: Tech industry witnesses told a House Homeland Security Subcommittee that CISA’s voluntary secure-by-design pledge has driven meaningful progress (over 250 signees) but faces significant gaps — notably its current focus on IT rather than operational technology, the difficulty of eliminating whole classes of vulnerabilities (memory-safety issues account for an estimated ~70% of critical-infrastructure vulnerabilities), insufficient developer security training (including offshore development concerns), and unequal resources at smaller municipalities; witnesses suggested incentives, tooling for memory-safe languages, funding, and potential help from generative AI, while noting uncertainty about the program’s priority under the next administration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.