As the U.S. federal government embarks on another administration change, it is an appropriate time to discuss what should be key priorities for the next administration. Cybersecurity attacks and related breaches against private and public organizations occur regularly and make national news. However, rarely do our politicians raise the issue that cybersecurity attacks have become our largest national security threat, nor do they openly discuss any solutions to address this threat.

Behind the scenes, the U.S. Department of Homeland Security (DHS) has defined 16 critical infrastructure sectors that “are considered so vital to the United States that their incapacitation or destruction would have a debilitating effect on security, national economic security, national public health or safety, or any combination thereof.” Included in these sectors are financial services, food and agriculture, energy, and transportation systems.

DHS, the FBI and other government organizations do work closely with organizations across the critical infrastructure sectors on their cybersecurity protection measures, but no one could claim that we do not have significant vulnerabilities in these sectors, and adversaries are constantly looking for these vulnerabilities to exploit — not just to steal data, but to affect organizations’ ability to provide their services.

The impact of disruptions in any of these sectors could have a profoundly negative impact on our society. While there are a number of initiatives underway to help address our national cybersecurity protection posture, here are three core elements that, if addressed, could have a profoundly positive impact on our society.

Focusing on the Most Important Risk Management Issue

First, we need to continue to educate all organizations on the importance of viewing cybersecurity as their most important risk management issue and to treat it as such. The good news is that we have, as a society, made significant progress in this area. A couple of years ago, the National Institute for Standards and Technology (NIST) published a cybersecurity framework that was crowdsourced by 3,000 experts from industry, academia and government.

This comprehensive roadmap for conducting cybersecurity risk management has quickly become the standard, and the Gartner Group recently reported that 20 percent of U.S.-based organizations are now relying on that framework. We need to build on this success, further championing the importance of all organizations to do the proper planning and risk protection for their enterprise.

Real-Time Sharing of Threat Information

Second, we need a robust and comprehensive approach to sharing cybersecurity threat information on a near real-time basis. Adversaries are constantly looking for previously unknown vulnerabilities in operating systems, data bases, etc. Once they have found such a vulnerability and launched an attack, the speed at which the vulnerability is identified and fixed becomes critical to limiting the impact of the attack.

This is a team sport, and while there are pockets of information sharing within certain sectors and across some cybersecurity product firms, we need a national framework that provides the incentives and legal protections to enable such information sharing.

Addressing the Mission-Critical Talent Shortage

Third, and most daunting, is to address the talent shortage we have in cybersecurity. Reports vary, but we have a worldwide shortage of cybersecurity professionals that may be as high as two million people. Even with a solid cybersecurity risk management plan in place, and even with good information sharing, many organizations will struggle to hire and develop the talent to properly implement cybersecurity controls and monitor and respond to attacks and breaches. We need a multi-faceted approach to attracting individuals of all ages into the field and to providing the education and training opportunities to help them develop the required skills and knowledge.

Addressing this skills shortage will require efforts to attract young people in high school and college to the field as well as offering retraining opportunities for existing workers. While there are certainly cybersecurity roles that require extensive technical backgrounds, there are many roles that can be filled by individuals with good analytical capabilities, training and on-the-job experience.

Attracting talent to the cybersecurity field will require a national mandate and a public-private partnership at the national, state and local levels. We need to support universities and colleges in developing cybersecurity programs and to implement incentives for companies to invest in developing their employees.

We have not yet had a cybersecurity attack that has profoundly affected our society, yet we should act is if we had a cyber version of 9/11. The threat is real, and with a new administration, there is a window of opportunity to set a new direction to address this key national challenge.