Scale without secrecy
The Manhattan Project analogy refers to urgency, concentrated national effort, scientific engineering, and guaranteed demand. It does not justify a secret cyber laboratory, one brittle super-system, or unchecked executive power.
The proposed National Defensive Coscaling Program would have a 10-year charter and an emergency first 3 years. It would set a measurable duty, operate common infrastructure, finance the compliance path for organizations that cannot build it, and intervene when an exposed service threatens others.
Put the duty where the power is
Congress should create a Duty of Cyber Continuity for every legal entity operating a material service reachable from an untrusted public network.
The duty cannot attach mechanically to the owner of an IP address. Clouds, carriers, content-delivery networks, and shared platforms may own the address while a tenant controls the vulnerable service. Responsibility should follow operational control, knowledge, and the ability to remediate.
Covered boards should:
- adopt the Continuity SLO;
- receive a continuous exposure and recovery dashboard;
- fund the architecture and staffing needed to meet the duty;
- certify that no known, reachable, unmitigated material path remains open; and
- record business decisions that delay closure instead of transferring the risk silently to IT.
Make minutes safe
The end state is patch or isolate within minutes of authoritative disclosure or validated discovery. Today's legacy architecture often cannot do that safely. The program must finance the transition.
Known or emergency-designated public paths that yield material control and can be automated.
Other exposed paths yielding material control, including validated chains.
Reachable conditions that materially reduce the work needed for compromise.
Lower-risk conditions under a documented plan, unless new evidence shortens the clock.
The initial deadlines are legal ceilings for a transition, not the destination. As the national stack proves that a class of service can close a path safely in minutes, the deadline should ratchet down through public rulemaking.
Build the public option for defense
- Verify scopeConfirm the operator and the systems it owns or is authorized to test.
- Discover and attributeContinuously map exposed services to an accountable entity and local asset.
- Fingerprint safelyIdentify software and configuration without unsafe exploitation by default.
- Reason across pathsCombine exploitation, automation, impact, identity adjacency, dependencies, and chainability.
- Build a proposed closureUse a free federal frontier-class defensive model to propose a patch, configuration, isolation rule, or migration.
- Test before actionRun the change in a twin, sandbox, replay environment, or canary.
- Act within authorityDeploy with explicit local authority, automatic rollback, and deterministic emergency isolation.
- Verify and attestConfirm closure from inside and outside, then produce signed evidence.
The stack should be open source. The federal model service should be free at the baseline and operated as governed critical infrastructure. That does not require publishing unrestricted weights or offensive tooling. Access can be limited to verified assets, logged, rate-limited, red-teamed, and independently evaluated. Company data stays local unless the operator authorizes a minimized defensive exchange.
Capacity before punishment
A mandate without an affordable way to comply would accelerate consolidation and punish the organizations least able to absorb it. The federal program should provide no-cost external measurement, shared Cyber Stewards, grants and zero-interest replacement financing, maintainer funds for critical open source, emergency engineering teams, catastrophe reinsurance, and a conditional safe harbor for truthful participation.
Capable firms may comply independently if they produce equivalent evidence. Everyone else receives a public path.
Penalties that can survive contact with law
- Civil penalties follow verified overdue pathsNot raw findings, duplicate signatures, or unknown vulnerabilities.
- The first band must be materialPotentially up to 1 percent of annual U.S. revenue for each unresolved 30-day enforcement period involving a material-control path, with caps and review.
- Operational orders remain availableRegulators may require isolation, suspend a service, restrict procurement, appoint a monitor, or disqualify a vendor from high-consequence markets.
- Executives attest to evidenceClawbacks and officer or director consequences attach to knowing false certification and sustained governance failure.
- Criminal law requires culpabilityReserve it for knowing falsification, concealment, obstruction, intentional aid, corruption of the defense system, or willful defiance of a lawful emergency order.
The hard edge remains. A company should not be able to treat national exposure as a cheap cost of doing business. But the law should punish overdue verified attack paths and culpable conduct—not unknown flaws, duplicate scanner signatures, or an operator who lacked the authority and resources to act.
The first three years
- First 180 days · Know the boundaryPass the duty, create the protected registry and schemas, expand measurement, publish the first open stack, launch bounded federal-model pilots, and protect good-faith research.
- Year 1 · Close systemic pathsCover critical and concentrated providers, require responsibility maps and Continuity SLOs, prove minute-scale workflows, fund unsupported-system replacement, and exercise correlated failure.
- Years 2–3 · Reach the installed economyExtend the duty, subsidize shared Stewards and Nodes, require clean-room restoration, connect incentives to verified performance, and ratchet mature service classes toward minutes.
Guardrails are part of the design
The registry and national reasoning plane would be exceptional targets. Entity mappings should be compartmented, encrypted, minimized, and purpose-bound. No analyst or model should be able to export a national attack graph. Registry compromise must be exercised as a normal failure scenario.
The national system must also preserve appeal, judicial review, good-faith research, local custody of private data, dual control for consequential action, clean recovery outside model reach, and a nonautomated path when the defensive system itself fails.
The goal is not a federal machine with authority over every network. It is a common capacity that makes a measurable duty possible without making ordinary organizations disposable.