Insights & Research

Blog

What States Can Learn from North Carolina’s Approach to Securing Government

As states across the country grapple with how to adopt AI responsibly, North Carolina offers a compelling case study - not because it has all the answers, but because it has built the institutional muscle to learn, adapt, and lead.

Event Recap: Secure DNS and the Evolution of NIST SP 800-81

The Center for Cybersecurity Policy and Law held an event with industry and government stakeholders to discuss the importance of securing the Domain Name System (DNS) to combat increasing global cybersecurity threats.

FedRAMP Signals Acceleration of Requirements for Machine-Readable Packages in the Rev5 Process

FedRAMP has proposed modifications to the Rev5 process in the newly published RFCs that could enact major changes and require Cloud Service Offerings to provide authorization packages in a “machine-readable format.”

Yet Another Blog about 'Cyber Operations' Part I: The Lexicon

The vocabulary around cyber operations has become muddled with policymakers often conflating terms. This post aims to set a standard lexicon for all to use moving forward.

2025 Year in Review: Advancing Cybersecurity Through Collaboration

In 2025, the cybersecurity ecosystem became more complex and we’ve seen governments rethink critical policy frameworks. Nonetheless, the Center has remained steadfast in strengthening cybersecurity through policy, collaboration, and education.

Fighting the Adversarial Use of AI: Innovation in Cyber Insurance, Incident Response

The rise of AI is reshaping every aspect of cybersecurity. While AI holds promise for automating defenses, it also empowers threat actors. This is driving an AI arms race with placing the cyber insurance market in the middle.

FinCEN: Ransomware Payments Peaked in 2023

Ransomware payments peaked in 2023 at $1.1 billion with 1,512 reported incidents and dropped by a third to $734 million on 1,476 incidents in 2024, according to FinCEN.

Cairncross Talks Cyber Strategy, Shaping Adversarial Behavior

National Cyber Director Sean Cairncross signaled a shift in the Trump Administration’s approach to digital threats – one defined by transparency, accountability, and consequences. 

Coalition Sends Paper on Post-Shutdown Priorities To ONCD and Congressional Cyber Leaders

The Cybersecurity Coalition’s new paper, "Reinvigorating Federal Cybersecurity Initiatives: A Post-Shutdown Call to Action for the Trump Administration and Congress," urges ONCD and Congress to take decisive action around four areas of cyber policy.

Brussels’ Regulatory Assertiveness Collides With Standards Development Process, Diplomacy

While standards are not the most exiting topic in the world, they are critical in many respects, and the development of AI standards in the EU is causing some consternation among many.