Why Politics Matters For Cybersecurity and Privacy
Politics. Love it or lump it, but if you want actual privacy and cybersecurity to stand a chance of happening, you need to be championing legislation, now.
I generally try to be apolitical in my professional life. In the workplace I avoid talking about the big three subjects:
- Politics
- Religion
- The airspeed velocity of European Swallows1
But in reality legislation, government departments, and the courts do directly and significantly impact our industry. It turns out this is an important topic if we - practitioners and data owners alike - want our private data kept private, and our cyber environments secured. But first, I'm not going to tell you who to vote for. I'm going to focus on what policies and initiatives I think are important in cybersecurity. If you want my overall political views I encourage you to invite me out for a beer or engage with me on some other platform. I also recognize that cybersecurity and privacy are just two of many issues that may be important to you, and I won't assume that they are the top two.
With that caveat out of the way, let's dive in.
Privacy Shield and International Law

Let's start with something you can't really impact with your vote: International data handling laws. The EU, China, Australia, Brazil, India, Mexico, and Switzerland all have wide-ranging privacy laws that you and your company must follow if you process private data of their residents. Global Data Protection Regulation (GDPR) from the EU is probably the most well known of these international laws here in the US.
The EU and the US have attempted multiple times to negotiate some level of appropriate requirements for US companies to achieve to be compliant with the spirit of GDPR. Safe Harbor was one such attempt, and in 2015 it was finally ruled as insufficient by the EU. Since then Privacy Shield was created, and has had a rocky history as well.
State Privacy Laws
Did you know that every state in the union, and every non-state territory - including Guam - has its own privacy law protecting its residents? It is absolutely true. Does your corporate privacy leader know them all? How does your privacy program identify the residence of every person who shares data with you to ensure you're applying the correct policy to them? Are you ready for Illinois residents to sue you in a class action because you violated the state's Biometric Information Privacy Act?
So what is your strategy? Find the most restrictive laws and follow those nation wide? That's what our peers in the automotive industry finally did with regards to emissions standards set by California. Are we, as an industry, ready to do that as well? Does that mean that California or Illinois gets to dictate stringent privacy laws across the nation? Are you somehow attempting to identify which users are residents of which states and only apply the strict privacy policies to them and their data?
Or is your company's collective response "we'll deal with it if we get sued?" (I'm willing to bet this is the stance your company takes whether or not they'll admit it publicly)
The Courts
Here in the US the courts have had a major impact on our cybersecurity environment. One positive impact was in 2021 when the Computer Fraud and Abuse Act was narrowed significantly in Van Buren v. United States by better defining the definition of the clause of "exceeds authorized access." Prior to this, security researchers faced criminal charges for actions that today we consider not only appropriate but absolutely necessary to our ability to identify vulnerabilities and develop mitigations and remediation for them.
But the courts have also recently significantly curtailed the Executive Branch's ability to create and enforce regulatory rules in the Loper Bright Enterprises v. Raimondo case, more commonly known as the case that repealed the Chevron decision. The fallout is still not well understood, but it does suggest that departments like CISA, the FTC, and others will have a harder time enforcing cybersecurity mandates that aren't literally written into laws explicitly by congress. This has the potential to prevent new regulations from occurring, and impede enforcement of existing regulation, if those regulations were created by the Executive branch organizations and not spelled out explicitly in the law, which Congress very rarely does.
Admittedly here in the US we don't elect federal judges, but we do elect the President and Senators who are part of the process of installing them.
National Legislation
The US has been incredibly bad at enacting meaningful cybersecurity and privacy legislation at a national level. I suggest you only need to look at the section earlier about how every state and territory has at least one privacy law of its own, or I could simply point you to the partisan dysfunction that shows up on the nightly news. The fights over "continuing resolutions" for government funding are a telltale sign of the issue. One of the last truly meaningful cybersecurity or privacy laws that comes to mind for me is HIPAA and HITECH, the later of which was passed in 2009! That's 15 years. Given that the role of CISO first appeared about 30 years ago, that's an absolute age in our industry. For comparison, Windows 7 debuted that same year, and Windows 10 - two generations later - is already end-of-life.
The Executive Branch
NIST, CISA, SEC, and the FTC are all parts of the executive branch of the US government, Their policies and impact on cybersecurity are among the most impactful in the US. From the various NIST standards including the CSF, the CVE and KVE databases, as well as the reporting requirements from the SEC and FTC all have direct impact on cybersecurity. That doesn't even mention the Department of Justice, whose impact on cybersecurity prosecution is also critical.

We can't fix privacy and cybersecurity individually. We have to work together, and that includes getting our elected officials working with us on these topics. The EFF has a great primer on how to make an impact when you choose to reach out to your legislators on these topics. Please, make your voice heard.
1 With or without coconuts.