This article explores the origins and evolution of the institutional, policy, and legal frameworks that define the defensive and offensive aspects of UK and US cyber strategies. There is a strong degree of convergence, particularly from a defense perspective, but there are also important variations, especially in the degree to which the countries’ most capable operators—the National Security Agency and the Government Communications Headquarters—are integrated into non-intelligence activities.