President's Cyber Action Plan Once Again Spotlights the Private Sector
Client Alert | 4 min read | 02.10.16
This week, President Obama directed his administration to implement a Cybersecurity National Action Plan (CNAP) with near- and long-term steps to improve both public and private sector cybersecurity. The President's FY 2017 Budget proposes spending $19 billion on CNAP initiatives, a 35 percent increase in cybersecurity spending over his FY 2016 budget. The CNAP places significant focus on the private sector's role in securing the nation's cyber borders and, in many ways, draws heavily on the private sector's experience with cyber resilience and an enterprise-wide, multi-year approach to cybersecurity.
As with earlier public/private initiatives, the CNAP contemplates voluntary activities and does not impose cybersecurity obligations on the private sector. Relevant highlights from the CNAP include:
- Expanding support for critical infrastructure. The CNAP extends prior federal efforts to strengthen voluntary partnerships with private companies that own and operate key resources and assets and that provide products and services critical to the nation's day-to-day life. These efforts include
(i) creating the National Center for Cybersecurity Resilience, where private companies can test their system security in a controlled environment before deploying to the real-world; (ii) doubling the number of advisors available to assist critical infrastructure with cybersecurity assessments and best practices; (iii) creating the Cybersecurity Assurance Program to test and certify connected devices within the Internet of Things (IoT) that meet threshold security standards; and (iv) urging healthcare stakeholders to develop and refine their data security practices. - Improving cyber hygiene. The CNAP calls for Americans to move beyond basic passwords and instead take advantage of the increased protection provided by multi-factor authentication (MFA). The administration will kick off a public awareness campaign and work in coordination with technology and financial services companies to make MFA technology accessible and to help individual Americans understand their role in protecting the nation's cybersecurity. Separate efforts will be made to further the president's "BuySecure" initiative that focuses on Chip-and-PIN payment systems and to promote the Federal Trade Commission's IdentityTheft.Gov resource for victims of identity theft. The CNAP additionally calls on federal agencies to use MFA, adopt identity proofing practices, and further reduce their reliance on social security numbers.
- Enhancing cyber incident response. Acknowledging the volume of U.S. cyber incidents experienced over the last year, the CNAP calls for maintaining resilience when incidents occur, in addition to focusing on prevention and deterrence. By this spring, the administration will release a policy for national cyber incident coordination. The policy will be accompanied by a methodology for evaluating the severity of cyber incidents to enable government agencies and the private sector to communicate effectively and provide an appropriate and consistent level of response when incidents occur.
- Establishing the Commission on Enhancing National Cybersecurity. The Commission will consist of twelve cybersecurity experts – all from outside of the federal government – who will be charged with crafting recommendations for government activities over the next decade to improve public and private cybersecurity while protecting privacy.
- Modernizing government IT and governance. The CNAP directs federal agencies to begin retiring, replacing, and modernizing outdated IT infrastructure, with the assistance of a $3.1 billion "IT Modernization Fund," which departs from the traditional federal model of year-end, lump-sum IT funding in favor of strategic and long-term agency investments in modernization. At the same time, agencies would transition to a shared-services, government-wide approach to IT that would permit agencies to benefit from each other's experiences and move toward standardized cybersecurity practices. The CNAP creates the position of Federal Chief Information Security Officer, who will report to the Federal Chief Information Officer and will be exclusively focused on developing, managing, and coordinating federal cyber strategy.
- Developing cybersecurity technology and workplace skills. The CNAP also incorporates the National Science and Technology Council's 2016 Federal Cybersecurity Research and Development Strategic Plan for evidence-based improvements in cybersecurity technology, and identifies a number of cybersecurity education and training initiatives to develop the cybersecurity expertise that federal agencies will need to follow through on improving their cybersecurity.
The CNAP builds on recent federal efforts to enhance the country's cybersecurity posture, including proposed guidance for implementing cyber protections in federal acquisitions, President Obama's Public-Private Sector Cybersecurity Information Sharing Executive Orders, the National Institute of Standards and Technology (NIST) Cybersecurity Framework, and a Cybersecurity Strategy and Implementation Plan for agencies to identify and address their cybersecurity gaps. Significantly, much of the CNAP as applied to federal agencies reflects lessons learned and best practices already in place in the private sector, and thus is an important step toward bringing federal cybersecurity practices more in line with their private sector counterparts.
As the end of the president's term approaches, the CNAP is an ambitious and consistent next step in this administration's series of cybersecurity initiatives, but it is by no means a quick or light undertaking. To succeed, the CNAP requires a long-term commitment from the next administration, federal agencies, and the Hill, not to mention a $19 billion infusion from the House of Representatives.
Contacts

Partner, Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 5 min read | 12.12.25
Eleventh Circuit Hears Argument on False Claims Act Qui Tam Constitutionality
On the morning of December 12, 2025, the Eleventh Circuit heard argument in United States ex rel. Zafirov v. Florida Medical Associates, LLC, et al., No. 24-13581 (11th Cir. 2025). This case concerns the constitutionality of the False Claims Act (FCA) qui tam provisions and a groundbreaking September 2024 opinion in which the United States District Court for the Middle District of Florida held that the FCA’s qui tam provisions were unconstitutional under Article II. See United States ex rel. Zafirov v. Fla. Med. Assocs., LLC, 751 F. Supp. 3d 1293 (M.D. Fla. 2024). That decision, penned by District Judge Kathryn Kimball Mizelle, was the first success story for a legal theory that has been gaining steam ever since Justices Thomas, Barrett, and Kavanaugh indicated they would be willing to consider arguments about the constitutionality of the qui tam provisions in U.S. ex rel. Polansky v. Exec. Health Res., 599 U.S. 419 (2023). In her opinion, Judge Mizelle held (1) qui tam relators are officers of the U.S. who must be appointed under the Appointments Clause; and (2) historical practice treating qui tam and similar relators as less than “officers” for constitutional purposes was not enough to save the qui tam provisions from the fundamental Article II infirmity the court identified. That ruling was appealed and, after full briefing, including by the government and a bevy of amici, the litigants stepped up to the plate this morning for oral argument.
Client Alert | 8 min read | 12.11.25
Director Squires Revamps the Workings of the U.S. Patent Office
Client Alert | 8 min read | 12.10.25
Creativity You Can Use: CJEU Clarifies Copyright for Applied Art
Client Alert | 4 min read | 12.10.25
Federal Court Strikes Down Interior Order Suspending Wind Energy Development
