Public Policy
Resource Center

Cybersecurity is central to today’s most important technology, privacy policy and regulatory developments. CrowdStrike informs decision makers around the globe based on what it sees in the field and how it thinks the trends it observes today will affect the security environment tomorrow. We are at the forefront of these issues globally. Learn how CrowdStrike can help.

Highlights

CrowdStrike’s Privacy and Public Policy practice engages on some of the key issues at the intersection of security and technology policy.

Data Protection Compliance

Cybersecurity is central to data protection compliance obligations.

Learn how

Election security


Interference in democratic processes is on the rise globally. Here’s what we’re doing to help.

Learn more

Countering Adversaries

Adam Meyers, Cristian Rodriguez and Morgan Adamski, NSA Cybersecurity Collaboration Center Chief, Discuss Evolved Approaches for Countering Adversaries

Watch now

Artificial Intelligence

Drew Bagley and Eric Hysen, DHS CIO and Chief AI Officer, Discuss Leveraging AI for the Defenders’ Advantage

Watch now

Protecting Democracy

Shawn Henry and Senator Mark Warner, Chairman of the U.S. Senate Select Committee on Intelligence, Discuss Threats to Global Democracy in 2024

Watch now

Recent Testimonies, Comments & Blogs

CrowdStrike engages with policymakers globally to advance the causes of privacy and cybersecurity. Select examples include:

Testimonies

 

Adam Meyers
Testimony on “An Outage Strikes: Assessing the Global Impact of Crowdstrike’s Faulty Software Update” before the U.S. House Committee on Homeland Security, Subcommittee on Cybersecurity and Infrastructure Protection
Drew Bagley Testimony
on “CISA 2025: The State of American Cybersecurity from a Stakeholder Perspective” before the U.S. House of Representatives Committee on Homeland Security, Subcommittee on Cybersecurity and Infrastructure Protection
Adam Meyers Testimony
on “Mobilizing our Cyber Defenses and Securing Critical Infrastructure Against Russian Cyber Threats” before the U.S. House Committee on Homeland Security
Rob Sheldon Testimony
on “Examining Health Sector Cybersecurity”
before the U.S. House Committee on Energy
and Commerce, Subcommittee on Health
Zeki Turedi Call for Evidence
on “Inquiry into Ransomware” before the UK
Joint Committee on the National Security
Strategy
George Kurtz Testimony
on “Cybersecurity and Supply Chain Threats” before the U.S. Senate Select Committee on Intelligence
Rob Sheldon Testimony
on "Intellectual Property and Strategic Competition with China: Part III - IP Theft, Cybersecurity, and AI” before the U.S. House Judiciary Subcommittee on Courts, Intellectual Property, and the Internet
Rob Sheldon Testimony
on “Protecting American Innovation” before the U.S. Senate Intelligence Committee
 
Rob Sheldon Testimony
on “Evaluating CISA’s Federal Civilian Executive Branch Cybersecurity Programs” before the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection
 

Request for Comment Responses

 

Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) (July 2024)

EU Cyber Solidarity Act (July 2023)Securities and Exchange Commission (SEC): Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure (May 2022)
Revised New York Hospital Cybersecurity Requirements (June 2024)White House OSTP National Priorities for Artificial Intelligence (July 2023)Consultation on Draft Regulations to Saudi Arabia’s Personal Data Protection Law (March 2022)
Department of Justice AI EO Comment (May 2024)NIST Cybersecurity Framework 2.0 Core Discussion Draft (May 2023)Zero Trust Maturity Model (October 2021)
Cybersecurity in the Marine Transportation System (May 2024)SEC Cybersecurity Risk Management Proposed Rule (May 2023)Cloud Security Technical Reference Architecture (October 2021)
2023–2030 Australian Cyber Security Strategy: Legislative Reforms Consultation Paper (March 2024)Australia 2023-2030 Cyber Security Strategy (April 2023)Federal Zero Trust Strategy (September 2021)
New York Hospital Cybersecurity Requirements (February 2024)Australia Privacy Act Review Report (March 2023)Modernizing Privacy in Ontario, Canada (September 2021)
NIST AI EO Comment (February 2024)California CPPA Cyber Comments (March 2023)Strengthening Australia's Cybersecurity Regulations and Incentives (August 2021)
Consumer Financial Protection Bureau Personal Financial Data Rights (December 2023)NIST 2.0 Comments (March 2023)Cybersecurity Labeling Programs for Consumers: Internet of Things (IoT) Devices and Software (August 2021)
OMB Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence Draft Memorandum (December 2023)FCC E-Rate Comments (February 2023)Software Bill Of Materials Elements & Considerations (June 2021)
FCC Libraries Cybersecurity Pilot Program (December 2023)FCC Data Breach Requirement Comments (February 2023)Cybersecurity - Uniform Rules for EU institutions, bodies and agencies (January 2021)
Brazil ANDP International Data Transfer Regulation (September 2023)TSA Enhancing Surface Cyber Risk Management (January 2023)Public Consultation on Data protection - standard contractual clauses for transferring personal data to non-EU countries (implementing act) (December 2020)
Singapore Use of Personal Data in AI Systems (August 2023)Proposed Second Amendment to 23 NYCRR Part 500: Cybersecurity Requirements for Financial Services Companies (January 2023)Public Consultation on the European Data Protection Board Guidelines (October 2020)
New York Financial Sector Cybersecurity Requirements (August 2023)India's Digital Personal Data Protection Bill 2022 (December 2022)Cyber and Critical Technology International Engagement Strategy (CCTIES), Australia (June 2020)
Kingdom of Saudi Arabia Data Transfer Law (July 2023)Cyber Incident Reporting for Critical Infrastructure Act of 2022 (November 2022)Public Consultation on the EU’s General Data Protection Regulation (GDPR) (April 2020)
Kingdom of Saudi Arabia Personal Data Protection Law (July 2023)Office of the National Cyber Director (ONCD) Cyber Workforce, Training, and Education (November 2022) 
Safe and Responsible AI in Australia Discussion Paper (July 2023)Brazil ANDP: International Transfers of Personal Data (June 2022) 
 CISA Secure Cloud Business Applications (SCuBA) Technical Reference Architecture (TRA) (May 2022) 
 European Union Data Act (May 2022) 
 Proposal for New Telecoms Security Regulations and Code of Practice (May 2022) 

Videos, Webinars, Talks & Podcasts

We have additional resources covering specialized topics and issues. See here:

Drew Bagley on the Next Steps for Ecosystem Level Cybersecurity, Washington Post LiveDrew Bagley on Cyber Security Connect Australia PodcastWebinar: Workshop on Cybersecurity Labeling Programs for Consumers: Internet of Things (IoT) Devices and Software
Rob Sheldon on CyberScoop to discuss zero trust implementationCrowdCast: The SEC Has Spoken: Aligning to the New Rules on CybersecurityPodcast: Data Protection & Data Security: Two Sides of the Same Coin
CrowdStrike-American University-Wiley Rein LLP Joint Podcast: “Start Here: Cyber Public Policy Fundamentals” on cyber policy 101Drew Bagley on Securing Cyberspace- Next Generation of Threats, Washington Post LiveWebinar: Navigating Data Protection with a Newly Deployed Remote Workforce
Drew Bagley on the Adversary Universe Podcast to discuss the SEC’s new incident reporting regulationsRob Sheldon on Public-Private Collaboration at the 2023 US Cyber Command Legal ConferenceWebinar: USAID Digitalization & Cybersecurity series
Christoph Bausewein on "Data Protection - Minimizing Financial Risks with a Strong Security Concept" Podcast (in German)Podcast: Adam Meyers on the Cyber Threat Landscape- Cipher Brief Open Source Report (Jan 16-20, 2023)Data Sheet: Quick Start Guide To Securing Cloud-Native Apps
Christoph Bausewein on German Data Protection Law Firm Härting Podcast (in German)Talk: Adam Meyers on Securing Cyberspace - Global Cybersecurity Landscape, Washington Post Live 
   

Committees & Memberships

CrowdStrike representatives serve on a number of boards and committees. CrowdStrike also belongs to a number of trade associations.
These include:

Alliance for Digital InnovationGermany Federal Office for Information Security-Alliance for Cyber SecurityNASCIO Privacy & Data Protection Working Group
American Chamber of Commerce in GermanyGovTech Campus DeutschlandOneTrust PrivacyConnect Frankfurt Chapter
BITKOMGlobal Cyber AlliancePartnership for a Secure America
Bundesverband der Datenschutzbeauftragten Deutschlands (BvD) e.V.ICANN Competition, Consumer Choice, and Consumer Trust Review TeamThe German Association for Data Protection and Data Security (GDD)
Cross Border Data ForumInformation Technology Industry CouncilUnited States Artificial Intelligence Safety Institute
DNS Research FederationInternational Association of Privacy Professionals, KnowledgeNetUnited States Department of State International Digital Economy and Telecommunication Advisory Committee
European Data Protection Board (EDPB) Pool of ExpertsIAPP Privacy Engineering Section Advisory BoardUnited States President’s National Security Telecommunications Advisory Committee’s (NSTAC)
Addressing the Abuse of Domestic Infrastructure by Foreign Malicious Actors (Abuse of Domestic Infrastructure) Subcommittee
Europol EC3 Advisory Group on Internet SecurityIT Sector Coordinating CouncilU.S Chamber of Commerce
European Federation of Data Protection OfficersIT Security Association Germany (TeleTrust) 
German Bundesverband - Security in Industry and CommerceJapan Data Protection Officers Organization 
Germany Economic Council (Wirtschaftsrat der CDU e.V.)Japan Electronics and Information Technology Industries Association (JEITA)