Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Mike McConnell and Patrick Gorman’s five-step cybersecurity roadmap is an ecosystem-level policy agenda, not a deployment checklist. Its core idea is to move beyond isolated compliance: account for how services depend on one another, reward measurable security, coordinate across sectors, and invest in future technology and people. The recommendations appeared in a Dark Reading commentary on January 3, 2018, so proposed measures—especially liability protection—should not be mistaken for current law.

What the five steps are designed to fix

The roadmap responds to a mismatch between interconnected digital services and cybersecurity practices often organized around individual organizations or compliance requirements. A hospital, payment network, supplier, and small business can rely on overlapping infrastructure; a weakness in one place may affect others. The authors therefore argue for a broader view of risk and for incentives and collaboration that extend beyond any one organization.

The commentary cited more than $90 billion spent per year on cybersecurity and argued that progress was still halting. That figure is the authors’ 2018 framing; the article names no separate statistical publisher for it. The five proposals are policy directions rather than a costed or tested implementation plan.

Step 1: Rethink what counts as critical infrastructure

McConnell and Gorman question a rigid split between “critical” and “noncritical” infrastructure. Hospitals, payment networks, small businesses, and other services may depend on shared digital systems, so an incident affecting a seemingly noncritical organization can still disrupt a critical service.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The practical implication is to assess dependencies and consequences, not just an organization’s label. For a business, that means considering which suppliers, platforms, communications channels, and customers depend on its systems—and which outside services it needs to operate. The article advocates risk models that reflect this interdependence; it does not specify a particular assessment method.

Step 2: Use incentives and legal expectations, not compliance alone

The authors argue that checking boxes against regulations is not enough to drive durable security. They call for market and legal incentives that reward stronger practice, including measurable performance criteria, procurement requirements, and higher expectations for vendors and suppliers.

For organizations buying technology or services, procurement can make security expectations concrete: define the outcomes a supplier must meet, how performance will be evaluated, and what evidence is required. The commentary proposes these levers but does not prescribe a universal set of metrics or contract clauses. Its preference for market incentives over reliance on regulation is an argument in the article, not a finding that regulation is unnecessary.

Step 3: Leverage NIST through common standards and measurement

The authors propose building on the National Institute of Standards and Technology (NIST) by using a common framework alongside control standards, measurable performance criteria, uniform audit approaches, and breach-disclosure criteria. Their aim is comparability: organizations and assessors would have a clearer shared basis for describing security practices and evaluating them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The article also advocates liability protection for organizations that adopt such a framework. This is a proposed policy incentive in the 2018 commentary, not a statement of current law or a guarantee that using a NIST framework shields an organization from liability. The piece does not identify a current NIST version, implementation schedule, or legal mechanism for the proposed protection.

Step 4: Improve information sharing and collaboration

McConnell and Gorman propose a National Cybersecurity Center that would connect federal government cyber centers, private-sector information sharing and analysis centers (ISACs), and nonprofit entities. They envision collaboration spanning preparation, prevention, detection, response, and recovery.

The point is to make coordination part of resilience rather than treating each organization’s response as an isolated effort. The proposal describes the participants and broad mission, but does not set out a governance model, operating procedures, or a launch plan. Organizations can still use the underlying principle at their own scale by clarifying how they exchange relevant threat information and coordinate with partners, while recognizing that the article does not offer a specific protocol.

Step 5: Invest in next-generation security research and people

Fund research for emerging risks

The roadmap identifies Internet of Things (IoT) security, quantum computing and cryptography, and autonomous systems as areas for next-generation security research and development. The recommendation is to invest before these technologies create or amplify risks that existing approaches may not address. The commentary does not allocate funding or define a research program.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Build the cybersecurity workforce

The authors also call for education and training investment to address specialist shortages. They cited more than 500,000 unfilled cybersecurity jobs, a figure from their 2018 article that has no separate statistical source named there; it should not be read as a current vacancy count.

For leaders, the workforce proposal complements technology investment: security capability depends not only on tools but also on people able to design, operate, assess, and improve them. The article does not specify a training curriculum, hiring target, or timeline.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to apply the roadmap without mistaking it for a checklist

The five steps operate at different levels. The first expands the scope of risk from a single organization to connected services. The second and third focus on governance, incentives, standards, and measurement. The fourth addresses collaboration across organizational boundaries. The fifth looks further ahead to research and workforce capacity.

A leader translating the ideas into priorities can use these questions to frame decisions:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Dependencies: Which outside services and partners could affect our operations, and which other organizations rely on ours?
  • Incentives: Do procurement and supplier expectations reward demonstrable security outcomes, rather than documentation alone?
  • Measurement: Can our security posture be evaluated consistently against a shared framework and clear criteria?
  • Coordination: Who needs to share information or coordinate with us before, during, and after an incident?
  • Capacity: What emerging technologies and workforce needs should shape our longer-term investment?

These questions are an organizational way to use the article’s policy principles; they are not a substitute for a detailed security assessment or a legal determination.

What the 2018 roadmap does—and does not—establish

The commentary is useful as a way to organize cybersecurity priorities across governance, infrastructure, collaboration, innovation, and skills. It does not provide implementation budgets, timelines, tested outcome data, a current NIST version, or evidence that any one proposal by itself fixes cybersecurity. Its figures and policy context date to 2018, and its liability-protection idea remains an advocacy proposal in the article rather than an account of present law.

There is also a numbering error in the original list: both “Leverage the efforts of NIST” and “Improve information sharing and collaboration” are labeled Step 3. They are distinct recommendations, treated separately here as the third and fourth steps.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.