In our latest episode, former U.S. National Cyber Director Kemba Walden joins Alex Botting and Jen Ellis from the Center for Cybersecurity Policy & Law. The discussion includes Kemba’s reflections on her time at the Office of the National Cyber Director, and the multitude of major policy initiatives that she spearheaded - including the release of the updated U.S. National Cybersecurity Strategy, the associated Implementation Plan, the Cybersecurity Priorities for the Fiscal Year 2025 Budget, and the U.S. National Cyber Workforce and Education Strategy -  and all in just ten months of tenure. 

Kemba reflected upon:

  • Receiving the call from President Biden while at Munich Security Conference
  • Her experiences working with international partners
  • The development and rollout of the U.S. National Cyber Strategy
  • What's next for implementation of the Strategy

In addition, Alex discusses the Cyber Resilience Act (CRA) news with a short recap of the political agreement reached between the European Commission, Council and Parliament around the proposed legislation. In terms of timing, the CRA will come into force over a phased transition period starting in late 2025. He also touches on the newly-released Australian Cyber Security Strategy and how it builds on the cyber policy efforts of the Five Eyes community. Finally, our Mystery Trivia Master this week is the information security wizard, Casey Ellis. 

Check out the newest Distilling Cyber Policy episode on Spotify, Apple or Google. As always, if you would like to submit cyber policy trivia, or have topic ideas for upcoming episodes, please email iaj01@venable.com.

Ines Jordan-Zoob

Read Next

What States Can Learn from North Carolina’s Approach to Securing Government

As states across the country grapple with how to adopt AI responsibly, North Carolina offers a compelling case study - not because it has all the answers, but because it has built the institutional muscle to learn, adapt, and lead.

Developing a National Cybersecurity Strategy

Developing a national cybersecurity strategy is a critical investment a government can make to secure its future. This paper outlines the components and offers a framework with the tools to design, implement, and improve their strategies.

FedRAMP Signals Acceleration of Requirements for Machine-Readable Packages in the Rev5 Process

FedRAMP has proposed modifications to the Rev5 process in the newly published RFCs that could enact major changes and require Cloud Service Offerings to provide authorization packages in a “machine-readable format.”