Insights & Research

Papers & Reports

Public Sector AI Governance: Build on Existing, Strong Foundations

The use of AI technologies in federal agencies is ever expanding but governance is necessary to ensure its proper use. This report looks at existing governance structures, the role of the CAIO, and recommendations to make governance more effective.

Through the Looking Glass: An Updated Vision for the Office of the National Cyber Director

The ONCD was established to advise the President on cybersecurity and has matured into a key component of cybersecurity policymaking. However, changes are needed to ensure the efficacy of the office, especially as it relates to other agencies.

Addressing Concentration Risk in Federal IT

The Center conducted a multi-stakeholder tabletop exercise in April to explore a form of concentration risk where a single software, configuration, service, or hardware becomes dominant in an ecosystem.

Cybersecurity Coalition Releases EU Policy Roadmap 2024-2029

At CyberNext Brussels, the Cybersecurity Coalition released an EU Policy Roadmap that would help ensure Europe's collective digital resilience.

Trusted App Stores: Protecting Security and Integrity

The mobile app store provisions of the DMA could undermine foundational security in the mobile phone ecosystem. The Center is concerned that a proliferation of ways to install apps will be overwhelming to users and open avenues for bad actors.

Reframing the Conversation: A Deep Dive into the Encryption Debate

Governments say encryption prevents law enforcement from doing their job, but encryption protects everyone, including children and other vulnerable populations.

Protecting Network Resiliency

Vulnerabilities, flaws, or misconfigurations in the network device ecosystem can have a devastating effect. To prevent this, the Network Resilience Coalition is making recommendations on best practices for both vendors and consumers.

Joint Letter of Experts on CRA and Vulnerability Disclosure

As concerned cybersecurity experts who have dedicated our lives to improving the security of the online environment, we urge you to reconsider the vulnerability disclosure requirements under the proposed EU Cyber Resilience Act (CRA).

Diverse Perspectives, Stronger Defenses: Growing the Cyber Workforce Through Diversity

The demand for cybersecurity professionals far outstrips the supply and the need to fill these positions will only grow. The necessity of a strong, diverse workforce to fill these positions is critical to protecting the public and private sectors.

Prioritizing Cybersecurity for State Government: How a ‘Whole of Government’ Approach Benefits All

As cybersecurity concerns are front and center for state technology leaders, some jurisdictions are looking at a "whole of government" approach that would enable them to help locals and school districts.