Introduction On February 12, 2013, the President issued Executive Order 13636, stating that the “cyber threatto critical infrastructure continues to grow and represents one of the most serious nationalsecurity challenges we must confront.”1The Executive Order sets out a number of steps toaddress this problem, including calling on the Department of Commerce’s National Institute ofStandards and Technology (“NIST”) to develop a Cybersecurity Framework (“Framework”) andthe Department of Homeland Security (“DHS”) to build a voluntary program (“Program”) “tosupport the adoption of the Cybersecurity Framework by owners and operators of criticalinfrastructure and any other interested entities. . .”2The Program could include guidance on howto implement the Framework in specific sectors, as well as incentives for companies to aligntheir cybersecurity practices, with the practices and standards specified in the Framework. ThePresident requires DHS, the Department of Commerce (“Commerce”), and the Department ofTreasury (“Treasury”) to draft separate reports on incentives to join the Program. The followingrecommendations are Commerce’s contribution to this analysis of incentives. Department of Commerce Recommendations The incentives the government offers to participants in the Program must help align the Nation’sinterest in improving the cybersecurity posture of all critical infrastructure entities with theinterests of individual companies.These incentives should specifically promote participation inthe Program; involve judicious commitment of any additional federal government resources; andadvance a full range of policy interests, including protecting privacy and civil liberties as well aspromoting effective cybersecurity for critical infrastructure entities. To inform its views of how to achieve this balance, Commerce issued a Notice of Inquiry(“NOI”) on March 28, 2013, asking stakeholders for input on a broad array of questions aboutincentives that affect cybersecurity practices. Based on responses to this NOI, previous input tothe Commerce Internet Policy Task Force (“IPTF”), consultations with other federal departmentsand agencies, and related analysis, Commerce makes the following preliminaryrecommendations to the President on potential actions that the U.S. Government can take tobuild a successful incentives structure for the Program. Engage insurance companies in the creation of the Framework:NIST should engagecritical infrastructure cybersecurity stakeholders, including the insurance industry, whendeveloping and demonstrating the utility and effectiveness of the standards, procedures, and other measures that comprise the Framework and thus underlie the Program.Specifically, cybersecurity insurance carriers would bring extensive knowledge of theeffectiveness of specific cybersecurity practices and could help evaluate specificproposed elements from this perspective. This collaboration between insurancecompanies, NIST, and other stakeholders could serve as a basis for creating underwritingpractices that promote the adoption of cyber risk-reducing measures and risk-basedpricing. This collaboration could also foster a competitive cyber insurance market. Study tort liability:Once the Program is developed, DHS, in consultation with theDepartment of Justice, should study the legal and financial risks that criticalinfrastructure owners and operators face from tort liabilities arising out of cyber attacks,and whether these risks promote or inhibit participation in the Program. This studyshould include a review of tort cases against critical infrastructure owners and operatorsand an assessment of mechanisms (e.g., insurance or statutory liability limitations) thathave the potential to reduce or transfer their tort liability if a cyber incident causesdamage despite the owner or operator’s adoption and implementation of some or all ofthe standards, procedures, and other measures that comprise the Framework. Consider participation in the Program as a criterion for NSTIC Pilot and otherCommerce grants:As NIST makes future decisions about pilot grants related to theNational Strategy for Trusted Identities in Cyberspace (“NSTIC”), it should work withDHS to study whether to make consistency with the framework an evaluation criterionfor awarding grants. Commerce should also look into using Framework adoption andProgram participation as a consideration for critical infrastructure development grants. Offer guidance to federal agencies on compliance with the Framework andparticipation in federal grant programs:Commerce recommends that the White Houseissue guidance to federal agencies to promote cybersecurity protections as appropriatelyweighted criteria for evaluating federal grant applicants. Ensure that the Program links research and development efforts to overcomingreal-world challenges:NIST’s National Cybersecurity Center of Excellence (“NCCoE”)should work with DHS, Program participants, and vendors of information