GOAL 3 Drive Security at Scale As a society, we can no longer accept a model where every technology product is vulnerable the moment it is released and where the overwhelming burden for security lies with individual organizations and users. Technology should be designed, developed, and tested to minimize the number of exploitable flaws before they are introduced to the market. We must think about cybersecurity as a safety issue and ask more of the most capable and best-positioned actors in cyberspace — technology providers — to build security into products throughout their lifecycle, ship products with secure defaults, and foster radical transparency when known weaknesses are present in software, hardware, systems, and supply chains. Even as we confront the challenge of unsafe technology products, we must ensure that the future is more secure than the present — including by looking ahead to reduce the risks posed by adoption of artificial intelligence (AI) and the advance of quantum-relevant computing. Recognizing that a secure future is dependent first on our people, we will do our part to build a national cybersecurity workforce that reflects the diversity of our country. C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N 18

Select target paragraph3