Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

On January 18, 2024, the President’s Council of Advisors on Science and Technology (PCAST) approved recommendations aimed at helping the United States keep essential infrastructure services running through cyberattacks, accidents, and other disruptions. The recommendations focus on service-level performance goals, coordinated research, stronger government capacity, and greater accountability for private-sector leaders.

What PCAST approved

CyberScoop reported that PCAST, a 28-member advisory council, approved the recommendations on January 18, 2024. The working group was co-led by Eric Horvitz, then Microsoft’s chief scientific officer, and Phil Venables, then Google Cloud’s chief information security officer. The article reported that the full report was expected in mid-February. Working-group member Kevin Fu later wrote that PCAST released it on February 27, 2024; the official report link in his post returned 404 when checked for this article, so the accessible account of the report’s wording is Fu’s post, not the full report text.

Venables described infrastructure as inherently interconnected: “All of our modern infrastructure are cyber-physical by nature.” The point is practical: services such as energy, water, communications, and health care rely on physical equipment and digital systems working together. A disruption in one part can affect the service as a whole.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What cyber-physical resilience means

Fu relayed the report’s definition: “Resilience entails the ability of a system to anticipate, withstand, recover from, and adapt to cyberattacks and natural or accidental disruptions.” He also quoted the report’s goal that “the core functioning of systems must continue despite failures of one or more computational or physical components.” Fu identified his post as personal opinion, not official government guidance.

This definition puts service continuity at the center. Keeping individual devices reliable matters, but it is not enough if an outage, attack, or unclear incident forces operators to shut down a wider system. Resilience planning therefore considers what service must continue, which dependencies could interrupt it, and how the system can recover and adapt.

The four recommendation areas

1. Set goals for essential service delivery

PCAST recommended establishing performance goals, including minimum operating capabilities and delivery objectives. Rather than measuring success only by whether equipment or networks are functioning, such goals would specify the minimum service that should remain available during a disruption.

CyberScoop reported an illustrative proposed objective involving avoiding a situation in which 50,000 people go without water or food for more than one week. This was an example of a possible delivery objective, not a measured national performance figure or an observed outcome.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Coordinate and strengthen research and development

The recommendations called for bolstering and coordinating research and development. A reported proposal was a National Critical Infrastructure Observatory for the Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA), intended to build knowledge and tools about infrastructure across sectors.

3. Reduce silos and strengthen government capacity

PCAST called for breaking down institutional silos and improving government’s ability to support cyber-physical resilience. Reported examples included clarifying the National Critical Functions list, and providing sector risk management agencies with better funding, staffing, and authorities. The recommendations also called for more capacity for the Cyber Safety Review Board.

4. Increase private-sector leadership accountability

The fourth area was greater accountability for private-sector leaders. Venables told CyberScoop: “Fundamentally, we believe the tone at the top from executives can amplify the resources in the ranks that are needed in these organizations to drive that increased resilience.” The recommendation links leadership decisions to the resources and priorities needed to meet resilience goals.

Why component reliability may not protect a whole service

Venables cautioned that measures such as patching systems or adding backup power can improve the reliability of individual components without removing bottlenecks or single points of failure. If dependencies remain concentrated or poorly understood, a local problem can still cascade into a service-wide interruption.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CyberScoop cited the Colonial Pipeline shutdown as an example. Venables said a lack of IT network segmentation reportedly contributed to the precautionary decision to shut down the entire system, including operational technology, because operators were unsure how far ransomware had spread. This is Venables’ account as reported by CyberScoop, not a separate technical investigation presented here.

The distinction is between keeping a component available and keeping the essential service available. A resilience plan asks what can fail, how failures could spread across digital and physical dependencies, and what service can continue while operators contain the incident and recover.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to assess a resilience plan

The reported recommendations suggest five useful questions for assessing a plan. These are practical comparison axes inferred from the recommendation themes, not a formal PCAST scoring rubric.

  • Service maintained: What minimum level of service must continue during a disruption?
  • Dependencies: Which digital, physical, organizational, or cross-sector dependencies could become bottlenecks or single points of failure?
  • Recovery: How quickly and reliably can the service recover, and can it adapt after the disruption?
  • Coordination: Can operators and responsible agencies share information and coordinate across organizational and sector boundaries?
  • Accountability: Who sets the performance goals, allocates resources, and is answerable for meeting them?

What the recommendations establish—and what remains unclear

The January 2024 reporting describes a policy agenda across 16 critical-infrastructure sectors, as Fu characterized its scope, rather than a specific operational standard or implementation schedule. The available sources do not establish measured outcomes from the recommendations, named empirical studies supporting a particular performance target, or how each proposal was subsequently implemented. The 50,000-person example should therefore be read as an illustration of a possible service objective, not as a verified benchmark.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The central proposal is to judge resilience by whether critical services can continue and recover—not solely by whether individual systems have been hardened. The full report text could not be retrieved from the link in Fu’s post, so details beyond the recommendations summarized by CyberScoop and the quotations Fu relayed cannot be confirmed here.

Sources

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.