INTRODUCTION
The American people are increasingly dependent upon the Internet for daily conveniences,
critical services, and economic prosperity. Substantial growth in Internet access and networked
devices has facilitated widespread opportunities and innovation. This extraordinary level of
connectivity, however, has also introduced progressively greater cyber risks for the United
States. Long-standing threats are evolving as nation-states, terrorists, individual criminals,
transnational criminal organizations, and other malicious actors move their activities into the
digital world. Enabling the delivery of essential services—such as electricity, finance,
transportation, water, and health care—through cyberspace also introduces new vulnerabilities
and opens the door to potentially catastrophic consequences from cyber incidents. The growing
number of Internet-connected devices and reliance on global supply chains further complicates
the national and international risk picture. More than ever, cybersecurity is a matter of homeland
security and one of the core missions of the U.S. Department of Homeland Security (DHS).
At DHS, we believe that cyberspace can be secure and resilient. 1 We work every day across the
Department and with key partners and stakeholders to identify and manage national
cybersecurity risks. We do this by adopting a holistic risk management approach. Like every
organization, no matter how big or small, we must minimize our organizational vulnerability to
malicious cyber activity by protecting our own networks. DHS also has broader responsibilities
to protect the larger federal enterprise and improve the security and resilience of other critical
systems. At the same time, we seek to reduce cyber threats by preventing and disrupting cyber
crimes, and to lessen the consequences of cyber incidents by ensuring an effective federal
response when appropriate. Finally, we work to create conditions for more effective cyber risk
management through efforts to make the cyber ecosystem more fundamentally secure and
resilient. This strategy sets forth our goals, objectives, and priorities to successfully execute the
full range of the Secretary of Homeland Security’s cybersecurity responsibilities.
Scope
This strategy provides the Department with a framework to execute our cybersecurity
responsibilities during the next five years to keep pace with the evolving cyber risk landscape by
reducing vulnerabilities and building resilience; countering malicious actors in cyberspace;
responding to incidents; and making the cyber ecosystem more secure and resilient.
1
The term “cyberspace” in this strategy refers to the interdependent network of information technology
infrastructure, including the Internet, telecommunications networks, computers, information and communications
systems, and embedded processors and controllers.
1