>the government's approach to cybersecurity has been 100% offense.
I also read your other comment that you posted in the comment
>This is a serious problem, not only from the problems intelligence angies with many powers and poor oversight; ignoring defense is going to bite a lot of people in bad ways. We are already seeing the beginnings of this with the escalating impact computer-based attacks are having on their victims.
I agree. Yes its embarrassing and they keep claiming "Do more Penetration Testing, more Vulnerability Scanning, more Risk assessment" Nobody even knows what the hell that even means and we're still getting breached! The biggest mistake we've made is to claim, "a great offense is always the best defense."
We should be doing Security Compliance aka Defense in Depth! But everybody seems to think Defense in Depth is somehow different from Security Compliance.
>Defense in Depth is when multiple layers of security controls are placed throughout a critical environment. It is a layering tactic, conceived by the National Security Agency (NSA) as a comprehensive approach to information and electronic security.
If they actually went through the diligence of conforming with the security controls (ISO 27002, FEDRAMP, NIST 800-53) that they defined (much like financial compliance conforms to policies, standards, or laws), they'd be in a much more comprehensive shape. Even PCI-DSS...just replace the word cardholder data with sensitive data and you have more defense than whatever snake-oil Security Risk Plan is out there.
I champion for compliance =).