Spend enough time reading federal law, and you start to notice something odd. The word “cybersecurity” is everywhere. It funds programs, names agencies, justifies budgets, and anchors entire government offices. But nowhere does the U.S. federal law stop and tell you what the word actually means. Congress writes around it the way you might describe a color you can’t name, by pointing at things that have it, never by defining the thing itself.

That should bother anyone whose job depends on the answer. If you run security for a law firm or a professional services organization, your legal obligations, your exposure to liability, and increasingly your insurance coverage all turn on a word that the people writing the rules have quietly declined to define.

So what do we actually have to work with? No clean definition, but a few useful outlines.

The first comes from the Cybersecurity Enhancement Act of 2014, which defines the “cybersecurity mission” as a broad list of activities: reducing threats, closing vulnerabilities, deterring attacks, responding to incidents, and recovering from them. Read it carefully and notice what it actually is. It’s a list of jobs, not a concept. Congress tells you what cybersecurity does, but never what it is. It’s the legislative equivalent of defining “medicine” by listing everything a hospital does.

The second comes from the Cybersecurity Information Sharing Act of 2015, which defines a “cybersecurity threat” as any action, taken through a computer system, that could harm the security, availability, or integrity of that system or the data inside it, with one notable carve-out: speech protected by the First Amendment doesn’t count. Congress felt the need to draw a line between a security problem and protected expression. That tells you the boundary between cybersecurity and free speech was contested enough that lawmakers wanted it on the record. It’s a reminder that cybersecurity has never been a purely technical field. It lives where technology meets rights, and the statute admits as much.

The third comes from the Homeland Security Act of 2002, which defines “cybersecurity risk” as the threats and vulnerabilities facing information systems, and any resulting harm from unauthorized access, disruption, destruction, or tampering, including harm caused by terrorism. This one is the closest to how a security professional actually thinks: threat, vulnerability, consequence. But it still describes the shape of risk rather than the substance of security.

Put the three together and a pattern emerges. Congress can describe what cybersecurity protects against, what activities it involves, and what damage it tries to prevent. It just won’t say what it is. And I don’t think that’s sloppiness. I think it’s deliberate, or at least unavoidable.

Cybersecurity belongs to the same family as words like justice and democracy. We use them constantly, we build institutions around them, and we’d struggle to write a single sentence that fully captures them. The reason is the same in each case: the concept has to move. It has to absorb new technology and a shifting sense of what actually threatens us. A definition written in 2002 or 2015 would already be outdated, and Congress would have to revise it every few years just to keep pace.

You can watch the scope expand in real time. As networked systems become embedded in more of daily life, the set of problems we file under “cybersecurity” grows with them. Right now, most attention focuses on the obvious surfaces: websites, email, online banking, and the systems holding client data and money. A decade from now, the center of gravity may have shifted to the devices managing our physical health: pacemakers, insulin pumps, and the sensors quietly monitoring our bodies. The word will still be “cybersecurity.” What it covers will look very different.

For those of us doing this work, that’s the real takeaway. We don’t get a stable definition to anchor to, and we shouldn’t wait for one. The law gives us outlines, not a fixed boundary. Our job is to operate competently inside a definition that keeps changing shape, to protect what matters now while staying honest about the fact that what matters will keep moving. That ambiguity isn’t a flaw in the field. It’s the nature of it.


I hope you find this post helpful and informative. Thanks for stopping by!

Leave a Reply

Discover more from root@cybercasta:~$

Subscribe now to keep reading and get access to the full archive.

Continue reading