The Defense Industrial Base Cybersecurity Strategy plots a course for increased focus and collaboration between the Defense Department and the U.S. defense industrial base on cybersecurity initiatives amid what officials say are persistent cyberthreats.
“Our adversaries understand the strategic value of targeting the DIB,” said David McKeown, DOD‘s deputy chief information officer for cybersecurity. “Private sector DIB contractors are at risk for malicious cyber activities by adversaries and nonstate actors alike,” he said. “Working in conjunction with the DIB, we can better ensure the safety of critical information and unauthorized disclosure of that information.”
McKeown, who also serves as DOD’s senior information security officer, was joined by Stacy Bostjanick, DOD’s chief of defense industrial base cybersecurity, in unveiling the strategy at the Pentagon.
“We need to get on top of this extremely complex challenge,” Bostjanick said. “This is a well contemplated, multifaceted, agile and nuanced response to the constant and evolving challenge [of] securing the DIB against malicious cyber activity.”
The strategy lays out DOD’s vision over the next three years for a secure, resilient and technologically superior U.S. defense industrial base to ensure the United States’ warfighting edge.
It outlines four goals aligned with that vision:
- Strengthening DOD’s governance structure for U.S. defense industrial base cybersecurity;
- Enhancing the cybersecurity posture of the U.S. defense industrial base;
- Preserving the resiliency of critical defense industrial base capabilities in a cyber-contested environment; and
- Improving cybersecurity collaboration between DOD and the U.S. defense industrial base.
Central to the goal of strengthening DOD’s cybersecurity governance structure are efforts to bolster interagency collaboration and develop regulations that will further govern the cybersecurity responsibilities of contractors and subcontractors.
In terms of enhancing the DIB’s cybersecurity posture, the strategy outlines steps to evaluate compliance with departmental cybersecurity requirements and evaluate the effectiveness of regulations and requirements. It also outlines steps to improve cyber-related threat and intelligence information with industry partners, identify vulnerabilities and recover from malicious cyber activity.
The strategy also directs the department to prioritize cyber resiliency among critical defense production capabilities and establish policies that reflect a focus on cybersecurity for key suppliers.
That focus aligns with broader department guidance, including the 2022 National Defense Strategy and the 2023 National Cybersecurity Strategy.
The newly released document also responds to a requirement to develop a comprehensive plan to ensure the reliability and integrity of production nodes for critical weapons systems outlined in the 2023 strategy.

