Cyber Focus: Cybersecurity, National Security, and Critical Infrastructure podcast artwork

PODCAST · government

Cyber Focus: Cybersecurity, National Security, and Critical Infrastructure

As cyber threats evolve faster than policy, Cyber Focus delivers executive-level briefings on cybersecurity, national security, and critical infrastructure. From the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University, host Frank Cilluffo speaks with senior leaders across government, industry, and the intelligence community about ransomware, state-sponsored threats, AI, and the systems we all rely on—energy, water, telecom, and supply chains. Each episode focuses on real-world risk tradeoffs and practical steps organizations can take to strengthen resilience.

Publisher-supplied feed metadata · PodParley refreshed Jun 7, 2026 · Source feed

  1. 127

    25 Years After 9/11: Lessons in Modern Homeland Defense with Michael Chertoff

    Twenty-five years after the September 11 attacks, former Homeland Security Secretary Michael Chertoff joins Frank Cilluffo for a firsthand account of that day and the national security transformation that followed. Chertoff recalls arriving at the FBI command center as the attacks unfolded, hearing the order to shoot down the fourth plane and confronting the urgent question of whether more attacks were coming. He also describes the information-sharing barriers exposed by 9/11 and the effort to bring agencies with different missions and cultures together under the newly created Department of Homeland Security. The conversation then turns to the threats facing the country today. Chertoff explains why terrorism has become more distributed and difficult to detect, how cyberattacks and artificial intelligence are changing homeland security, and why the United States must remain vigilant without treating every risk as something that can be eliminated entirely. Main topics Michael Chertoff's memories of September 11 Building DHS and breaking down information silos How the terrorist threat has evolved Cyber, AI and critical infrastructure Vigilance and managing risk Key quotes "Within minutes after I arrived, we heard about the third plane hitting the Pentagon, and then I remember sitting in the command center and hearing the order being relayed to shoot down the fourth plane." — Michael Chertoff "If you don't coordinate at the federal level, you run the risk of again having another missed opportunity to stop a terrorist attack." — Michael Chertoff "We've undermined those big terrorist organizations, but now we have very small networks or even individuals who are acting because they're being prompted or even on their own, they're getting radicalized." — Michael Chertoff "The distributed nature of terrorism now, and the fact that we now have domestic terrorists, indigenous to the U.S., means that the process of detecting is much more difficult." — Michael Chertoff "The problem has not gone away. It's simply altered and modified and evolved." — Michael Chertoff "What you have to do is manage the risk by understanding what's a reasonable amount of risk you have to tolerate." — Michael Chertoff Links and resources About the Guest Michael Chertoff served as U.S. secretary of homeland security from 2005 to 2009, following roles as a federal appeals court judge and assistant attorney general for the Justice Department's Criminal Division. He previously supervised the Justice Department's investigation into the 9/11 attacks and is the author of Exploding Data: Reclaiming Our Cyber Security in the Digital Age. He is now co-founder and executive chairman of the Chertoff Group, a global security risk management and advisory firm.

  2. 126

    How DARPA Is Preparing for the Next Technological Surprise with Patrick Lincoln

    Cybersecurity has spent decades in a reactive cycle: find a vulnerability, patch it and wait for the next one. Dr. Patrick Lincoln joins Frank Cilluffo to discuss DARPA's effort to break that cycle by building systems that are inherently secure, private and resilient from the start. They explore lessons from the AI Cyber Challenge, the role of mathematical proof in eliminating vulnerabilities and the challenge of making complex systems trustworthy even when individual components fail. The conversation also examines how research can move beyond isolated demonstrations to strengthen the technologies and infrastructure society increasingly depends on. Main Topics Preventing and providing technological surprise IPTO's return to computer science foundations Inherent security and privacy AI-enabled vulnerability discovery and patching Formal methods and mathematical proof Trust and resilience in megasystems Moving research into real-world use Key Quotes "This back and forth or cat and mouse game has been going on a long time. I'm getting tired of that. And so we're trying to find new foundations to build inherently secure systems and inherently private systems." — Patrick Lincoln "We need power tools to let people do more, better, faster, with quicker reaction time and higher assurance that what they do actually does lead to really fixing the problem and not creating new problems, not causing harm to the system." — Patrick Lincoln "Software is difficult. And so how can you get to high assurance for a complex system involving the analog systems, the sensors and actuators, the digital systems and hardware, and the digital systems and software? And there are processes for this, some of those involving mathematical proof and formal methods." — Patrick Lincoln "If you've got a million subsystems, there will be failures, and perhaps some of them even maliciously so. ... By building these compositional—think internal firewalls—within a complex system, and ways that we can understand the emergent properties of a large collective of systems, ... we can then predict and therefore give assurance about its behavior long term." — Patrick Lincoln "My favorite answer to this problem, the world's most urgent critical problem, I'll say the DARPA answer is improving our collective ability to solve urgent critical problems." — Patrick Lincoln Links and Resources DARPA Information Processing Techniques Office Patrick Lincoln biography DARPA AI Cyber Challenge PROVERS formal-methods program Resilient Software Systems Capstone About the Guest:  Patrick Lincoln is director of the Information Processing Techniques Office at DARPA, where he leads work spanning artificial intelligence, cybersecurity and privacy, and resilient complex systems. Before joining DARPA, Lincoln held senior research leadership roles at SRI, an independent nonprofit research and development institute, where he led multidisciplinary work across computing, cybersecurity, artificial intelligence, and advanced systems research. Lincoln holds a Ph.D. in computer science from Stanford University and a B.S. in computer science from MIT.  

  3. 125

    CI Fortify: Isolation, Recovery and a Minimum Viable America with CISA's Matt Rogers

    If communications fail and operational technology is damaged during a cyber attack, critical infrastructure operators may have to keep essential services running without internet access, outside assistance or readily available replacement hardware. Matt Rogers of the Cybersecurity and Infrastructure Security Agency (CISA) explains how CI Fortify prepares water, energy and transportation systems for that scenario. He and Frank Cilluffo discuss operating through compromise, uncovering hidden dependencies and testing whether critical systems can isolate and recover before a crisis arrives. Main Topics CI Fortify and emergency planning Operating through compromise Communications outages Hidden IT/OT dependencies Isolation and functional testing OT sovereignty Secure by Design for OT Public service and technical talent Key Quotes "If there is another Colonial Pipeline type incident again... how do we make sure that their incentive structure isn't I go from 100 to 0, it's that I go from 100 to 30? 40, where that... X is defense critical infrastructure, it's health and public safety, because we just can't afford to go to zero for our minimal services. We need sort of a minimum viable America." — Matt Rogers "Nobody is coming to save you unless you've prearranged to be saved, which is a bit grim. But in a communications outage, you can't call for help." — Matt Rogers "The more you tell me you have an air gap, the less I believe you... It's just really unsustainable for a lot of organizations.." — Matt Rogers "Security doesn't have to be frictional and hard. The goal should be to design security such that you are kind of the well-lit path, the easy path, the default state is the secure thing to do." — Matt Rogers Links and Resources CISA: CI Fortify CISA: Secure Connectivity Principles for Operational Technology CISA: ​​Barriers to Secure OT Communication: Why Johnny Can't Authenticate​ CISA: Secure by Design About the Guest: Matthew Rogers, PhD is an Industrial Control Systems cybersecurity expert in CISA's Office of the Technical Director and leads the agency's Secure by Design initiative for Operational Technology. He earned his bachelor's degree in software engineering from Auburn University and later completed a DPhil in Cyber Security at the University of Oxford as a Rhodes Scholar, focusing on securing legacy OT networks in vehicles. Before joining CISA, Rogers was a founding engineer at Shift5 and worked on broader ICS cybersecurity efforts at MITRE. His work at CISA focuses on translating ICS research and development into practical capabilities for critical infrastructure.  

  4. 124

    Boarding the Dark Fleet: Coast Guard Cyber and Maritime Security with RADM Jason Tama

    The maritime world is more connected than ever, creating new efficiencies—and new ways for cyber incidents to move quickly from shore-based networks to ships operating around the globe. Rear Admiral Jason Tama, Commander of U.S. Coast Guard Cyber Command, joins Frank Cilluffo to explain how the Coast Guard operates across military, intelligence, law-enforcement, regulatory, and homeland-security missions to protect the Marine Transportation System and counter adversaries in cyberspace. The conversation also examines the Coast Guard's latest Cyber Trends and Insights in the Marine Environment report, including cyber operations aboard Dark Fleet vessels, the growing convergence of IT and operational technology, persistent weaknesses in basic cyber defenses, and the importance of working closely with industry. Tama argues that prevention alone will never be enough: maritime operators also need to be prepared to keep functioning through their "worst digital day." Main Topics Covered Coast Guard Cyber Command's three-part mission Title 10, Title 14, and Title 50 authorities Coast Guard integration with U.S. Cyber Command Cyber operations aboard Dark Fleet vessels Cyber risk across ports and maritime infrastructure Public-private operational partnerships Persistent cybersecurity fundamentals International maritime cyber cooperation Key Quotes "You can't wait till the crisis or contingency to bring everyone together." — Rear Admiral Jason Tama "The great thing about ships now is they're all connected all the time. The bad thing is the ships are all connected all the time." — Rear Admiral Jason Tama "We're never going to Cyber our way out of this problem, right? There's no Cyber panacea." — Rear Admiral Jason Tama "Resilience is so important and everybody has to be able to think about and have a plan for how do you continue to operate on your worst digital day because it's not a matter of if, it's a matter of when." — Rear Admiral Jason Tama "The work we're doing in the wild from whether it's power plants to cranes to locks and dams ... all over the world, it's really incredible mission work." — Rear Admiral Jason Tama Relevant Links and Resources Cyber Trends and Insights in the Marine Environment (CTIME) Guest Bio Rear Admiral Jason Tama is Commander of U.S. Coast Guard Cyber Command, where he oversees cyberspace operations to defend Coast Guard networks, protect maritime critical infrastructure, and counter adversary activity. He also serves as the Coast Guard's Service Cyber Component Commander to U.S. Cyber Command. Previously, Tama served as Senior Director for Resilience at the National Security Council and as Captain of the Port of New York and New Jersey. He is a graduate of the U.S. Coast Guard Academy and holds advanced degrees from the University of California, Berkeley, and MIT Sloan School of Management.

  5. 123

    Private Sector Cyber Offense: What the New White House Memo Does—and Doesn't Do with Mike McLaughlin

    A new White House memorandum aims to bring the private sector more directly into cyber operations against transnational criminal organizations. But turning that policy goal into practice raises immediate questions about legal authority, liability, deconfliction and the risks companies could assume by participating. In this edition of Cyber Focus: To the Point, Frank Cilluffo talks with Mike McLaughlin about what the memorandum does—and does not do—under existing law, what needs to be resolved during the 60-day implementation window, and where private-sector capabilities may be most useful without interfering with ongoing military, intelligence or law-enforcement operations. Main Topics Covered Private-sector cyber offense Legal authority and liability Deconfliction with government operations Risks for participating companies The 60-day implementation window Where private-sector capabilities may fit Key Quotes "The [National Security Presidential Memorandum] isn't actually creating an authority; it's creating a record… that the administration or federal law enforcement can point to and say we gave you very clear authority… and if you step outside of that, you're on your own. — Mike McLaughlin "Deconfliction is a big problem because when you're dealing with the National Security Agency and the CIA and the FBI and US Cyber Command and CNMF and, you know, US SOCOM, and then you bring in ASD from Australia or GCHQ from the UK, and we're trying to deconflict all of this blue activity in cyberspace, it's really challenging." — Mike McLaughlin "If we start contracting with companies to conduct offensive operations, those companies become combatants." — Mike McLaughlin "For me, if the authorized target set are cryptocurrency wallets or keys or on-chain infrastructure that's being used to support transnational criminal organizations, that's an area that the private sector can cleanly operate without risking running afoul of traditional intelligence community activities, law enforcement operations, or military cyber operations." — Mike McLaughlin Relevant Links and Resources White House national security presidential memorandum National Cybersecurity Strategy Computer Fraud and Abuse Act (CFAA) Buchanan Ingersoll Rooney — Mike McLaughlin Guest Bio Mike McLaughlin co-leads the cyber practice at Buchanan Ingersoll Rooney. He previously served in government roles involving U.S. Cyber Command and the Cyber National Mission Force.  

  6. 122

    AI, Risk, and the Future of the Federal Workforce with OPM Director Scott Kupor

    The federal government is competing for technology and cybersecurity talent at the same time AI is beginning to reshape how that workforce operates. OPM Director Scott Kupor argues that meeting both challenges requires more than new tools or recruiting campaigns: government needs a personnel system that better reflects how people build careers today, rewards performance and adaptability, and creates room for responsible experimentation. Kupor joins Frank Cilluffo to discuss Tech Force and the push to bring more early-career technologists into public service; why he believes agencies should focus on practical, near-term AI gains rather than long-range plans that may quickly become obsolete; and what his years in Silicon Valley taught him about risk, execution and talent. They also explore what Washington and the technology industry misunderstand about one another—and why U.S. economic and national security increasingly depend on getting that relationship right. Main Topics Tech Force and two-year tours of public service Recruiting cyber and technology talent into government The federal government's early-career workforce gap Performance, merit and tenure in federal employment AI productivity and the changing federal workforce AI literacy and the continuing role of human judgment "Permissioned innovation" and responsible risk-taking Execution, adaptability and decision-making under uncertainty What Washington and Silicon Valley can learn from one another Key Quotes "I think every person coming out of high school or college, hopefully we can convince them spending 2 years in government is good for the country and good for them. It's really that simple." – Scott Kupor "If we're gonna attract early career people, they have to be able to come in an environment where their performance and their merit is a lot more important than how many years they've been here." – Scott Kupor "We should not be building, in my mind, the 2040 or 2050 plan for AI, because the very honest answer is we have no idea." – Scott Kupor "Everybody needs to develop some kind of AI literacy, right? So, and not just people who are software developers." – Scott Kupor "So the good companies, the good organizations, the good nonprofits, whatever it is, you have a theory of the case, but then you actually have to be willing to say, okay, our theory was wrong for X number of reasons and we're gonna change it. And I think it's very hard intellectually for people to do that. But that, I think, is the difference, ultimately, between successful and unsuccessful organizations." – Scott Kupor Links and Resources: Scott Kupor's OPM Blog About the guest:  Scott Kupor is director of the U.S. Office of Personnel Management, where he leads efforts to build a more accountable, mission-driven federal workforce. Before joining OPM, he was a managing partner at Andreessen Horowitz, which he helped build into one of the country's largest venture capital firms. He previously held senior technology leadership roles, chaired the National Venture Capital Association and taught entrepreneurship at Stanford. He is also the author of Secrets of Sand Hill Road: Venture Capital and How to Get It.   

  7. 121

    How Do You Rebuild Systems That Can't Go Offline? with Peraton's Tom Afferton

    Tom Afferton [00:00:00]: If you're introducing security controls or a maintenance activity or modernization that interrupts that operation, then you're no better off than if there was a cyber interruption.   Frank Cilluffo [00:00:16]: Welcome to Cyber Focus from the McCrary Institute, where we explore the people and ideas shaping and defending our digital world. I'm your host, Frank Cilluffo, and this week I have the privilege to sit down with Tom Afferton. Tom is president of the Cyber and Intelligence Service at Peraton, where he oversees a number of the most mission-critical entities inside the US government and has been there for a number of years. Prior to that, he also was at AT&T and many years at Northrop Grumman. Tom, thank you so much for joining us today.   Tom Afferton [00:00:50]: Happy to be here.   Frank Cilluffo [00:00:50]: So I thought I'd start at the beginning, and a lot of your clients are mission-critical.   Tom Afferton [00:00:57]: Yes.   Frank Cilluffo [00:00:57]: And very different than a traditional IT enterprise. And I'd be curious what that looks like. Why is that different and what your initial thoughts are there?   Tom Afferton [00:01:07]: So when we look at a lot of the systems services that we protect, you have to think about the consequences of them not operating. When we think about, you know, a large-scale modernization as well, right, you have to think about the whole point of, of cybersecurity is to protect that institution, to protect its operability. So if you're introducing security controls or a maintenance activity or modernization that interrupts that operation, then you're no better off than if there was a cyber interruption, right? And so when we go through, again, thinking about something like a modernization, we take an approach we call sort of a layered uplift, which is you introduce that new capability in an incremental way. You make sure that it's instrumented so that as you introduce it, you're monitoring, is it doing what you expected it to do? And then over time, it takes on more responsibilities. And then ultimately, you can turn off the legacy environment. Now, there's of course prioritization involved, deciding, you know, where are you going to start? Where are you going to build in that resilience and redundancy? Something that Nick Andersen over at CISA has introduced, the term of ruthless prioritization.   Frank Cilluffo [00:02:37]: Mm-hmm.   Tom Afferton [00:02:38]: And I think that's helpful. It's helpful when thinking about resilience planning. It's helpful when thinking about planning resources up front, coordination, but it's then also helpful in thinking about incident response. And when I've heard him speak and he's explained it, what he's talking about is going beyond just prioritizing a category of critical infrastructure. It's understanding that, you know, the key mission, the crown jewel that we need to have keep operating, we need to understand the assets associated with it.   Frank Cilluffo [00:03:13]: Mm-hmm.   Tom Afferton [00:03:14]: So what GPU is that workload or that workflow operating in what cluster and what data centers powered by what part of the grid? And knowing that sort of connection between the critical infrastructure and the mission and the physical and the technical infrastructure allows you to then prioritize.   Frank Cilluffo [00:03:32]: Because you really can't pause operations during an upgrade, right?   Tom Afferton [00:03:36]: Absolutely.   Frank Cilluffo [00:03:37]: So it's a challenge. These are— because you're also behind a number of critical systems that most Americans don't think about every day.   Tom Afferton [00:03:44]: That's right.   Frank Cilluffo [00:03:45]: One in particular that's gotten a little bit of news, and I know we can't get into great detail here, is FAA and the modernization.   Tom Afferton [00:03:51]: Yeah. And that's an interesting one. Peraton's very proud to be part of that. The administration has framed that as one of the most important modernization projects in American history. And part of that is because, you know, our air travel depends upon it, right? It's critical to our economy, but it's also large and complex. One of my colleagues, Justin Sciaccio, is the one leading that for Peraton, and he recently met with stakeholders in the press along with Secretary Duffy to talk about the program.   Frank Cilluffo [00:04:23]: Mm-hmm.   Tom Afferton [00:04:23]: And what Secretary Duffy explained is that they were looking to do something radically different in terms of program management and bring in an integration partner. And Peraton were— we were fortunate to be selected to do that. And one of the reasons that they selected us is that we've brought a revolutionary agentic AI technology to the equation.   Frank Cilluffo [00:04:44]: Mm-hmm.   Tom Afferton [00:04:45]: And what Justin has been explaining that we're doing is we are ingesting I think it was like something 5.7 million records of schedule data as well as historical information about projects that have completed, and then have the AI start to do analysis around that so that we can stress test schedules, you know, we can identify gaps and whatnot. And he had this quote that sort of went viral that he said, like, we're not looking to replace the humans. We want to enable them to have superhuman insights. And that's what we're really— what we're finding here. And it's just the schedule, all the interdependencies, all the suppliers, all the different sites. It's just too much for one person to consume. And so providing those insights has been part of the value add there.   Frank Cilluffo [00:05:29]: And, you know, you can't escape without us getting into a conversation around AI and agentic AI.   Tom Afferton [00:05:34]: Sure.   Frank Cilluffo [00:05:36]: What it means for threat hunters. But before jumping there, I mean, you've got technology time cycles that are moving so fast, but a lot of the systems you're dealing with here are in very different timelines. And we've had a number of discussions around the energy sector and grid, and we don't have to go there, but a lot of their OT systems are 25, 30 years old, and they're being netted with IoT devices and it brings about a new attack surface. How do you reconcile sort of that balance between a fast-moving tech cycle and not always so fast critical infrastructure sector?   Tom Afferton [00:06:13]: So I'll jump to the answer, but then I want to go back and I will give you an example of the type of work that our folks are doing because I think it illustrates the sort of both ends of the spectrum.   Frank Cilluffo [00:06:24]: And your an EE background, right?   Tom Afferton [00:06:25]: Right, thank you. Yes.   Frank Cilluffo [00:06:26]: Stanford and UVA.   Tom Afferton [00:06:27]: So go Hoos. So—   Frank Cilluffo [00:06:30]: Blue and orange. You know the history between the football uniforms between Auburn, UVA, and Clemson.   Tom Afferton [00:06:27]: No, I don't.    Frank Cilluffo [00:06:36]: All right. This is— sorry, but—   Tom Afferton [00:06:38]: That's okay.   Frank Cilluffo [00:06:39]: We will include this in the episode. So initially, the first football coach at Auburn was a football coach at UVA, brought the uniforms because they were so expensive. And then he went to Clemson and brought the uniforms. That's why it turned less than blue. It was a little more purple. So true story.   Tom Afferton [00:06:55]: I did not know that.   Frank Cilluffo [00:06:56]: Yeah.   Tom Afferton [00:06:57]: So going back to the question about sort of the pace of technology, right? So if, you know, we were to talk 6 months ago, we would have been talking about buying back time to the analysts. And that's still important and something that I do want to talk about. We look now within the age of Mythos and, you know, the ability for agentic AI to produce vulnerabilities at an unprecedented speed and scale, right, the cutting edge is now thinking about automating remediations and sort of the bottleneck has shifted down. But before we go to either of those, I think it's helpful to just have— let's have a practical example. Like, this is a day in the life of some of my folks.   Frank Cilluffo [00:07:37]: Mm-hmm.   Tom Afferton [00:07:38]: I have some folks that are supporting CISA in the Code and Media Analysis Team, and they are involved with malware analysis and ultimately incident response for critical infrastructure. So without getting into any details, right, one recent situation- they were brought in as a result of some classified intel to take a look at some malware. They did some analysis to determine kind of what vulnerabilities it was associated with. They determined that it was associated with some edge devices and sort of double alarm bells went off because number one, they were edge devices that could be used in a carrier network, that OT was being used, basically programmable logic controllers sitting behind these edge devices that had no inherent security in them. So if you penetrated this edge device, you could get access to the programmable logic controllers and control that environment. And then secondly, these edge devices were also in federal civilian executive branch. So from— and you go back to in a critical environment, what do you need to think about? Well, one is consequences.   Frank Cilluffo [00:08:49]: Mm-hmm.   Tom Afferton [00:08:49]: So, okay, This has potentially wide-ranging impact. The second then is sort of thinking about it from a risk standpoint. And so now these folks are going off and looking on— they know the right blog posts. There is some of the monitoring that CISA does. Combine that with some tradecraft on the dark web to say, are these exploits being published? You know, are there any IP addresses associated with it? You then enrich that with some of the classified intel to make a decision. Is this something that we really need to focus some energy around in analyzing and potentially producing some remediation? And then you get to that step and now you've got to reproduce it. So a lab environment where we— I call it exploding the malware in a sandbox.   Frank Cilluffo [00:09:34]: Mm-hmm.   Tom Afferton [00:09:34]: See what it does, what its signatures look like, and then ultimately producing reports. And there's a lot of discussion. You think about who are we reporting to, what are we disclosing on all that. So that whole cycle, right, we have anywhere from 5 to 20 folks. That's it. All of critical infrastructure. So that goes back to what Nick Andersen's talking about, ruthless prioritization, right? So you got to think about consequence. You got to think about that risk.   Tom Afferton [00:10:02]: So if we think about now AI in that process, one area is the sensemaking, and that goes back to buying back time from the analysts. All of that monitoring data is coming in from disparate sources. So how do we help them prioritize?   Frank Cilluffo [00:10:20]: Mm-hmm.   Tom Afferton [00:10:21]: And that can be an initial prioritization, but then you can go back and have the AI running in the background and continuing to correlate. Are new events coming and suddenly this was an isolated thing and now it's not? And so that's something we want to prioritize. We also think about it in terms of malware reporting and again, sensemaking of we're getting all this malware in, what should we prioritize?   Frank Cilluffo [00:10:42]: Mm-hmm.   Tom Afferton [00:10:43]: If I go to the backend, we think about building that remediation for the vulnerability and can AI help? We've had some really interesting discussions with CISA thinking about what's the right model or engagement with AI, meaning do they engage with tools that are available in, you know, a cloud environment or, going back to exploding it in a sandbox, right, do we have- and we've looked at this and helped them with this, is actually buy some GPUs and have a good old-fashioned on-prem environment that you're not paying for tokens. You bought the GPU and now you have a locally hosted environment that now you can unleash the malware on. So, you know, those are just examples of thinking through the practical day-to-day on where we can help.   Frank Cilluffo [00:11:36]: That's actually a really interesting analogy. And something that just dawned on me is these are also lessons from a counter-IED perspective where we're applying in a cyber domain or a BSL-3 kind of lab approach. And, you know, Peraton has visibility across a wide range of customers, not only in the civilian agency department, which we've discussed here, but also the national security and Title 50 intel world. Any lessons from that work that you think pops up loud and clear in a civilian environment?   Tom Afferton [00:12:16]: So one area that— it's interesting, as we brought the company together and as we brought my organization together, it was, you know, one of the first times— at the time it was actually as Chris Inglis was standing up the first Office of the National Cyber Director.   Frank Cilluffo [00:12:34]: National Cyber Director. Yep.   Tom Afferton [00:12:34]: I, when I met him, I described my organization and I said, we're kind of mirroring what you're trying to do in the government, which is promote that cross-collaboration across different stakeholders, right?   Frank Cilluffo [00:12:46]: Mm-hmm.   Tom Afferton [00:12:46]: All the customers that you want to interact, all the agencies I am supporting from one organization.   Frank Cilluffo [00:12:51]: Mm-hmm.   Tom Afferton [00:12:52]: And so one of the first things that came out was we talked earlier about the tidal wave of data and we help one of our customers in the I.C. deal with some of the largest datasets on the planet.   Frank Cilluffo [00:13:06]: Mm-hmm.   Tom Afferton [00:13:07]: And helping them take that mindset and approach and governance and bring that now into a civilian environment to say, hey, there's another organization that has dealt with this. Here is a roadmap for maturing through your data governance. Here are, you know, some data structures and here's a stack you can think about and all those different things. So that's something that I have seen carried from the I.C. environment over to the civil environment.   Frank Cilluffo [00:13:36]: And it aligns well to Nick's approach for ruthless prioritization because it really is a signal-to-noise set of challenges. I mean, there's a lot of telemetry and there's a lot of data and sometimes you can drown in data if you don't know what you're looking for. And I do want to pull the thread on that in a second. But prior to that, you know, when you look at some of these mission-critical sectors, and I love the environment 'cause it really is an environmental set of issues. It's not just a tech issue. It's a governance issue, it's an integration issue, it's everything across the board. But what do most people underestimate in terms of the complexity? Is it the technology itself? Is it supply chains and, dare I say, lack of visibility into what that looks like?   Frank Cilluffo [00:14:27]: Is it legacy infrastructure? Is it a people challenge or is it all of the above? And clearly it is a little bit of all of the above.   Tom Afferton [00:14:34]: A little of all the above, but I'm going to pick the people challenge and I'm going to go back to one of my first programs at Northrop Grumman. We were doing a technology demonstrator on— it was actually critical infrastructure, state and local emergency service interaction. And we built a platform that would allow different emergency services at different echelons to be able to all interoperate.   Frank Cilluffo [00:15:03]: Mm-hmm.   Tom Afferton [00:15:04]: And we set up this whole demonstration environment. We had this, this whole exercise. It was at a university campus and there was a mock explosion and everything. And at the end of the day, we had this amazing technology. And in the middle of this crisis, all the different folks would do is radio check. Hey, look at that. We can talk to the police. We had not gone through and done the operational elements to say, how do we take advantage of this technology? And I remember being elated at first that, holy cow, look at how we did all these technical achievements.   Frank Cilluffo [00:15:41]: Yeah.   Tom Afferton [00:15:41]: And then quickly realized that the part that was missed was enabling the people to take advantage of that technology.   Frank Cilluffo [00:15:49]: Well said. And our first preventer community and first responder community, that was a real-world set of issues as we come to the 25th year of the anniversary of the horrific attacks of 9/11. I think some of those lessons are still being learned and hopefully earned and learned along the way. I do want to sort of- since you brought up some of the AI discussions in different ways, from a threat hunting perspective, there's a big signal-to-noise challenge there as well. How are you looking at ways to, A, apply it yourselves or for customers to be able to enhance that capability?   Tom Afferton [00:16:36]: So, a couple of thoughts there. One is that, you know, we're recognizing that what we've gotten good at is recognizing humans and what they are doing. And now we have to also be thinking about agents and what they're doing.   Frank Cilluffo [00:16:57]: What does an insider threat model look like for AI agents?   Tom Afferton [00:17:00]: Exactly. Exactly. The- you know, one of the things that we've looked at there, and it's a program that we have done with one of the research organizations in the DOD, along with one of our customer sponsors.   Frank Cilluffo [00:17:20]: Mm-hmm.   Tom Afferton [00:17:22]: Is having— we call it a wingman for red teaming. And so having AI kind of sit alongside and monitor what's being done, capture some of that, learn from it, and then make recommendations. So that's not a case where you have AI in the loop and you're displacing the human. You're kind of watching what they're doing, watching the experienced folks do it, capture that, and then capture— then come back and make some recommendations.   Frank Cilluffo [00:17:52]: Is this an Air Force contract? Wingman, love it. You don't have to.   Tom Afferton [00:17:56]: No, it was not. But in some ways, is that becoming obsolete because Mythos can just do it now? Again, I think that's at the cutting edge. And yet I look across the customer community and, you know, folks are still crawling, right? And there's a variety of challenges, some of which we talked about in terms of the human element and are people— do they have the AI fluency? Do they have the, the comfort level?   Frank Cilluffo [00:18:28]: Mm-hmm.   Tom Afferton [00:18:29]: But there's also some practical matters. A lot of, you know, when I poll some of my teams that are on the front lines supporting customers in day-to-day cyber operations, there's still a lot of data jockeying going on, you know, and getting the data in the right place and making sure that you have data integrity and whatnot. There's also the clear demand signal that, you know, meet us where we are. Don't give us a tool that's going to operate in a commercial environment.   Frank Cilluffo [00:19:03]: Mm-hmm.   Tom Afferton [00:19:04]: You need to be able to operate in our environment. And, you know, there are different ways to do that. You can do some things on the low side and go through cross-domain, bring some products up, further enriched on the high side. But it also means meet us where we are from an operational process standpoint. And I know that, you know, you could roll your eyes and say, well, no, your whole point of AI is you need to build new processes. But, you know, we're, we're talking about sergeants and folks that—   Frank Cilluffo [00:19:31]: Absolutely.   Tom Afferton [00:19:31]: That they, they are, what they are taught is to follow the procedure. Now, we do need to work to help modify those procedures to take advantage of the technology. But you can't just throw this over the wall and say, isn't this amazing?   Frank Cilluffo [00:19:45]: Yeah. I like to say technology changes, human nature remains pretty consistent. And Maslow's hierarchy is still in play, right? So, you know, we chatted earlier and you had some very interesting approaches around telemetry of data and how you're crunching all of that. Anything you want to share there?   Tom Afferton [00:20:04]: So I will do a shout out. 2 weeks ago at the AWS Summit, Peraton released a new capability called Peraton[x]. And it's actually the platform when I talked earlier about supporting the FAA and their program management, that was the first application that kind of drove its maturity. So Peraton X is an agentic AI platform, sits on top of the different LLMs, but there's much more to it. And as I'm digging into it, I'm myself learning more about it. But it has a whole orchestration layer, library of agents, capabilities in there for workflow automation and resistance of hallucinations and so forth. But the key part of it is this data structure. They call it Cortex.   Tom Afferton [00:20:55]: And what it does is it allows you to ingest information that creates a context for the engagement of the AI for whatever your domain, whatever your use case is. And that context can be your policies, it can be your org chart, it can be your acronym list, it can be critical datasets. But that creates this persistent context for then any further engagement with the AI. Now that makes the users much more efficient because every prompt doesn't start over. It's more efficient with tokens, but it also now creates this— our Peraton Labs folks that that built this, they call it a fuzzy twin, that initially you build this fuzzy twin of the enterprise, but the more you interact with it, the more precise that twin becomes.   Frank Cilluffo [00:21:43]: Exactly, not so fuzzy.   Tom Afferton [00:21:44]: Right. And I was thinking about it, it's sort of like, you know, you're an intern or a new employee and you show up and you'll be given the policies and you see the org chart. But then once you hang around a while, you kind of know how things really work, right? And that's kind of the concept here. What we've done, though, is that that is what I would call sort of an extensible platform, a foundation. And now we can tailor it for different use cases. So one was the program management for the FAA. How do we help people digest this massive information for program management? We're looking at it for fraud. We'll probably talk later a little bit about influence operations and information operations.   Tom Afferton [00:22:26]: That was actually the prototype, the starting product that we built that we said, hey, well, let's generalize this to Peraton[x], a platform called IRIS. But, you know, we're talking about cyber. And so how do we think about tailoring something for cyber? So when we tailor for an application, we're going to build that cortex and we're going to build what are the cyber operations for a given team. We're also going to think about what are the curated datasets that we want to bring in. There might be some third-party tools. We're going to then think through the security environment, right? We are at IL5 today, going to IL6 very soon. And we've thought through what do we do on the low side, what, you know, and we don't want to have all of the data being ingested on the high side, ingested on the low side, get the outcomes and then bring that up and then further enrich it on the high side.   Tom Afferton [00:23:20]: But all of that is sort of built on now we have this extensible environment that we can apply to different applications. So where we're going next, and again, we're a cyber podcast here, is we're trying to think about that in enabling cyber operations, going beyond the sensemaking to now thinking of that downstream bottleneck in terms of automation.   Frank Cilluffo [00:23:42]: Which also gets to principles 101 of Sun Tzu, Clausewitz, and all, before you know your enemy, you have to know yourself.   Tom Afferton [00:23:51]: Right, right.   Frank Cilluffo [00:23:53]: And it's not always looking for the exquisite or unique signal in all of that volume. Sometimes it's literally just knowing how it operates daily, right?   Tom Afferton [00:24:03]: So yeah, actually at that same summit, Dave Luber spoke.   Frank Cilluffo [00:24:08]: A senior fellow, and he's been on the podcast in his NSA role and otherwise.   Tom Afferton [00:24:12]: You know, he talked about that, you know, the concern now, again, that something like a Mythos is out there with our adversary and they can create vulnerabilities at, you know, this speed and scale that's unprecedented. And, you know, the offense has the advantage right now.    Frank Cilluffo [00:24:32]: It's had it for a while, I would argue. It's turbocharged now.   Tom Afferton [00:24:35]: But one of the things that he talked about that was interesting, and I gave him full credit on this, was this idea of the home field advantage. And what he meant by that is at least let's recognize that the defenders, you're defending in your own turf. And so let's make it hard for the adversary to understand that turf. Right? And so you get into obfuscation, you get into, you know, software-defined networks that you can keep moving things around and whatnot.   Frank Cilluffo [00:25:00]: And displacing risk to the guy next door. Right?   Tom Afferton [00:25:03]: Yes, exactly. What— but one of the other things, as we've been talking about now, again, let's, let's go downstream. We recognize the practical challenges of data jockeying and security controls and all that. We're helping the analysts. But now let's go to that cutting edge and says, okay, vulnerabilities are coming at us faster than ever before. What are we going to do about it? All right. We, we're going to start contemplating unleashing—   Frank Cilluffo [00:25:30]: You stole my question, but I'm glad you did.   Tom Afferton [00:25:32]: Yeah, well, I figure that's where you're going to go. Yeah, right. We're going to unleash AI on cyber operations, cyber actions. And when we exchanged stuff in advance of this, actually the question that your folks posed was, what cyber decisions do you allow AI to make versus, you know, humans? And I would twist that a little bit and say, let's talk first about what cyber actions we want the AI to take, because we can have humans make decisions about what actions we want to allow, and then we can put some guardrails in place as far as how the agents can then take those actions.   Frank Cilluffo [00:26:17]: Makes sense.   Tom Afferton [00:26:18]: And so as I've been working with Peraton Labs and thinking about this, you know, we can imagine, okay, sure, routine remediation, block that IP. Those are things that are low consequence, they're reversible. There isn't ambiguity. It's fairly deterministic action. We're good with that.   Frank Cilluffo [00:26:38]: Mm-hmm.   Tom Afferton [00:26:39]: But are we going to have, you know, the AI generate code to remediate a, you know, machine-level vulnerability that's down in a chipset, right? Are we going to unlock and let that run? Probably not. And it certainly will depend on the system and the environment and all the prioritization we talked about earlier, right? So the term that our CTO came up with is he said, we need this risk potentiometer that, you know, depending on the circumstance, depending on which system, that you're going to sort of turn this knob and allow a certain level of automation. And that may change over time as you become more comfortable with some of the actions, right?   Tom Afferton [00:27:25]: And there's certainly things you can do that- I go back to, you know, you give your AI a better context, it can make better decisions and be more precise, but there's still going to be risks. And so having that as we think about this automation, yes, it can do it, but what controls do we want to put in place to make sure that we're not introducing more risk than the risks that we're trying to defend against?   Frank Cilluffo [00:27:51]: Very thoughtful approach. And to me, it is about the cyber effect, an adversary or even us if we're engaged in such activity or looking for operational outcomes. So I think that is a very smart way to start looking at it. You know, one thing that— and I'd be curious, you can shoot down the premise, but it's one thing to protect a system, it's another to keep it operational while under attack. Do we now— and that to me, that gets to a resilience discussion. That's more than a tactical discussion. It's strategic resilience.   Frank Cilluffo [00:28:29]: Should we assume to one extent or another that we need to be able to operate under compromise?   Tom Afferton [00:28:36]: Absolutely. I think we see that with critical infrastructure and the prepositioning of, you know, our adversary things.   Frank Cilluffo [00:28:46]: Volt Typhoon.   Tom Afferton [00:28:48]: Right. You know, we talked about risk of AI, and I think there's a couple of risks there. One is you're introducing a new attack vector or surface rather, right, you know, that the AI itself-   Frank Cilluffo [00:29:05]: Is creating.   Tom Afferton [00:29:06]: Right. And you don't know how it's going to be deterministic, right, so you don't know the outcomes, but then also it can be attacked, right? You talk about data poisoning, and Peraton Labs has done some interesting work with IARPA, I believe, looking at just the absolutely microscopic percentage of data poisoning that can be done and successfully create a backdoor, right? And so, you know, okay, is the AI going to do what it's expected to do?    Frank Cilluffo [00:29:32]: Literally drip, drip, drip, drip, drip kind of approach, right?   Tom Afferton [00:29:33]: Yeah, right. And then is- you know, are you going to get the outcomes that you expected? So, and then, you know, the other one going back to people is, are we— is there overreliance on that toolset?   Frank Cilluffo [00:29:48]: Mm-hmm.   Tom Afferton [00:29:50]: Are we now creating operators that don't know how to operate without that tool? And the simple analogy I go back to is when my kids were teenagers, I would say to them, you know, you have a car now, you go drive around, make sure you know how to get home without your map on your phone because you never know. You're going to be in an area where you don't have coverage. You forgot your charging cable or whatever. You need to be able to get home without the tech. Right? And I think that that has to be something that we keep in mind as well.   Frank Cilluffo [00:30:23]: Now, that, that, that's well said. And I genuinely feel we are at that point. We haven't fully recognized that, but we're going to have to. And it was actually very interesting. A number of years ago, I guess about 10 years ago, Mike Rogers, Admiral Rogers, when he went in to become DIRNSA and take the reins of US Cyber Command, had a whole section, Cyber Command's ability to operate when the internet's down. Right? When there is no— that's precisely what we need to be thinking right now. You know, the more I hear, and we've covered so much ground in a short amount of time, but the more I listen to your thoughts, we're really talking more than cyber.   Frank Cilluffo [00:31:05]: This is mission assurance.   Tom Afferton [00:31:07]: Yes.   Frank Cilluffo [00:31:08]: And I'd be curious if, A, if you would agree with that. This is broader than a cyber discussion and an IT enterprise discussion and even a mission assurance discussion. It actually goes beyond that to one extent or another. And before I ask sort of the last question, anything ring there that you think would help policymakers think about this challenge? Because here's the truth, you— and again, disagree with me— if the People's Republic of China had rolled out Mythos, would we be having a discussion about responsible use? Would there be press conferences? Would there be any of these discussions or would we know when we're burnt?   Tom Afferton [00:31:53]: So I think at the end of the day, and it's kind of where I started, that the point of cybersecurity is to sustain the integrity of the operations of these critical systems.   Frank Cilluffo [00:32:08]: And that's trust too, right?   Tom Afferton [00:32:09]: Right. That is a great way to look at it, right, that you have whoever the users are, the operators, the general public, whoever the people are that depend on this system, right, at the end of the day, it is about maintaining the operational integrity of that system. And cyber is cool and interesting and there's technical challenges and there's all the nuts and bolts in there about defending a system, but ultimately it is still about preserving the operation of that system that people depend upon.   Frank Cilluffo [00:32:41]: And trust is still the coin of the realm. Tom, just because we're near the end of our time, what questions didn't I ask that I should have?   Tom Afferton [00:32:48]: So I'm going to jump right off of what you were just talking about. Something that I don't think gets enough attention is that connection between cybersecurity and trust and sort of the converse when you lose that trust. So what I'm talking about is, well, let me give an example.   Frank Cilluffo [00:33:10]: Please.   Tom Afferton [00:33:10]: Right. The Colonial Pipeline, right? So when the Colonial Pipeline, when the news came out about it, that this pipeline had been hacked, first people didn't— I've never heard of the Colonial Pipeline, but then you heard, but the whole East Coast is dependent on its supply, you know, the supply of gasoline. So what did everybody do? I know what I did. I was driving home. I went and sat in line at the gas station for an hour, right, just like everybody else.    Tom Afferton [00:33:33]: A behavior change happened as a result of the perception that a critical system was, its operational integrity was compromised. Now, at the end of the day, it's my understanding that the actual operational system of the pipeline was never compromised. It was the IT side of the house that was compromised. But that didn't matter. Everybody still went and got in line.   Frank Cilluffo [00:33:56]: Mm-hmm.   Tom Afferton [00:33:56]: So, you know, you mentioned the Typhoon series earlier, right? We've seen this change in the goal of some of the cyberattacks from espionage or IP theft to prepositioning, potentially to cause panic, to cause disruption and distraction.   Frank Cilluffo [00:34:17]: Mm-hmm.   Tom Afferton [00:34:18]: Well, if the connection between sort of trust in an institution and a system and a capability and behavior is broken, there's 2 ways to attack that. One is to directly attack the system, and that's the nuts and bolts cybersecurity we talked about earlier. The other is to just change the perception.   Frank Cilluffo [00:34:36]: Exactly.   Tom Afferton [00:34:37]: And that's where influence operations comes in. And I don't think we give enough attention to that. Peraton runs one of the largest programs supporting the combatant commands in information operations overseas. And through that, we have a frontline view of the capabilities of the US and what's going on with our adversaries in the information environment. And I can tell you, we do have the best tech. We do have the best tradecraft. But at the same time, our adversaries are much better at integrating that into their diplomatic efforts, their military efforts, their economic efforts, and they are much more persistent and they spend anywhere from 10 times to 100 times what we spend.   Frank Cilluffo [00:35:21]: Wow.   Tom Afferton [00:35:22]: And so if we go back to now, we're not only defending against the direct cyberattack, but also the perception of the cyberattack. We need to put some more energy and some more budget around countering foreign influence.   Frank Cilluffo [00:35:35]: You know, that's really, really well said. I mean, at the end of the day, if you limit freedom of maneuverability, if you erode and undermine trust and confidence in our systems, and you change your behavior, checkmate. You don't even have to attack, right? So that is a valuable set of issues. I think it's how they're integrating it into broader doctrine and strategy that we've got to keep our eyes on. Tom, thank you so much for spending so much time with us today. Thank you for delivering on such an important mission set for the women and men of this country, and thank you for all you're doing. So let me leave you with a token, figuratively and literally, of our appreciation. Thank you.   Tom Afferton [00:36:16]: Thank you. Pleasure to be here.   Frank Cilluffo [00:36:19]: Thank you for joining us for this episode of Cyber Focus. If you liked what you heard, please consider subscribing. Your ratings and reviews help us reach more listeners. Drop us a line if you have any ideas in terms of topics, themes, or individuals you'd like for us to host. Until next time, stay safe, stay informed, and stay curious.

  8. 120

    Who Will Defend America in the Cyber Age? with Rep. Chrissy Houlahan

    Because cybersecurity has become central to national security and military strategy, Rep. Chrissy Houlahan says the United States needs to create a dedicated Cyber Force to prepare for the challenges ahead. Rep. Houlahan joins Frank Cilluffo to discuss why the military must adapt to the cyber age, how AI and strategic competition with China are reshaping national security, and why developing the next generation of technical talent may be America's greatest long-term advantage. Together, they explore how better workforce development, military modernization, and stronger public-private partnerships can help prepare the United States for future threats. Main Topics Cyber's evolution The case for a Cyber Force Military modernization Cyber Command's role Building the cyber workforce Project-based learning Neurodiversity and national service Breaking down organizational silos Competition with China AI and emerging technologies Key Quotes "When you think about cyber, cybersecurity, cyber warfare, cyber anything, it's always the weakest link. It's the seam. And so in our economy and in our military industrial complex, we need to be focused on the weakest links." — Representative Chrissy Houlahan "I believe that [cyber] should be its own domain because of where it's headed or likely headed in the next 50 or so years. ... I think inevitably 50, 100 years from now, we will be glad for the change that... was a Cyber Force." — Rep. Chrissy Houlahan "I would argue we don't have time not to. … If we look forward half a century, will we regret that we didn't take the time, didn't spend the resources to be as competitive as we possibly could be in this particular area?" — Rep. Chrissy Houlahan "One of the things that I'm most concerned about in our way of viewing our workforce right now is we are maligning smart people. We are somehow othering people who think technologically, who pursue degrees in hard stuff and that's bananas." — Representative Chrissy Houlahan "If we turn our backs to the next generation of talent, make it too hard for people to be educated here and take those American values either with them or keep them here, we are going to turn around and wonder why everyone's left." — Rep. Chrissy Houlahan Relevant Links and Resources Rep. Chrissy Houlahan CSIS Commission on U.S. Cyber Force Generation About the Guest:  Representative Chrissy Houlahan (D-PA) is an Air Force veteran, engineer and former entrepreneur who represents Pennsylvania's 6th District. She earned an engineering degree from Stanford through ROTC and later received a master's in Technology and Policy from MIT. In Congress, she serves on the House Armed Services Committee and the House Permanent Select Committee on Intelligence, where her work includes defense modernization, cybersecurity and the military's technical workforce.

  9. 119

    Who Should Control the Airspace Around Critical Infrastructure? with Scott Parker

    Drones are a serious operational concern for critical infrastructure owners and operators. In this episode of Cyber Focus, Frank Cilluffo sits down with Scott Parker, founder of Aerisq and former Chief of UAS Security at CISA, to discuss how drone capabilities have changed the risk picture for airports, utilities, chemical facilities, pipelines, prisons, and other sensitive sites. The conversation examines the FAA's Section 2209 rulemaking (open for public comment through August 5th, 2026), along with the limits of flight restrictions and the growing need for "Air Domain Awareness" alongside cyber and physical security. Parker also explains why counter-UAS strategy must balance technology, legal authority, proportional response, and the practical realities of defending infrastructure at scale. Main Topics Drone risks to critical infrastructure Lessons from Ukraine FAA Section 2209 Standard vs. special UASFRs Air Domain Awareness State and local counter-UAS authority Cost and scale of drone defense AI and autonomous drone risk Secure-by-design drone capabilities Key Quotes "There is a huge imbalance between what it costs to take [a drone] down as opposed to what it costs to fly one." — Scott Parker "A vast majority of our critical infrastructure is open airspace. ... Of the 90-something nuclear facilities, less than five have active flight restrictions over them." — Scott Parker "There are thermal sensors that can read how much oil is in a tank. There are LiDAR that can map an infrastructure's detailed schematics. And there are also cyber tools that can be equipped to sniff out open networks around facilities." — Scott Parker "Someone who means to do harm, they can add real-time collection to what's already out there using AI and... very likely develop a very structured plan on how to be successful." — Scott Parker "They [critical infrastructure owner-operators] are on the front lines. That's what we're concerned about. So they need the protection." — Scott Parker Relevant Links and Resources CISA UAS Security FAA Section 2209 rulemaking (Public comment open until August 5, 2026) Safer Skies Act rulemaking  (Public comment open until September 4, 2026) About the Guest:  Scott Parker is the founder and principal consultant of Aerisq, where he helps public and private sector organizations manage the cyber and physical risks posed by drones. He previously served as the Chief of UAS Security at CISA, where he built and led the agency's first UAS Security Program and helped shape national guidance on drone risk management for critical infrastructure. Parker also served 27 years in the U.S. Army, culminating as Sergeant Major for the Special Operations Division at the Pentagon.  

  10. 118

    How Universities Like Auburn Help Defend the Nation

    National security challenges increasingly cut across technology, economic competitiveness, critical infrastructure, manufacturing and workforce development. Universities have a growing role to play not only in conducting research, but also in translating ideas into practical solutions and preparing students to confront real-world problems. Auburn University President Dr. Chris Roberts, McCrary Institute Chairman Lt. Gen. (Ret) Ron Burgess, Senior Vice President for Research Dr. Steve Taylor and Samuel Ginn College of Engineering Dean Dr. Mario Eden join Frank Cilluffo to discuss Auburn's commitment to national security. The conversation explores the changing threat environment, the university's expanding research presence in Huntsville, partnerships among academia, government and industry, and how experiential education can prepare students for jobs and technologies that do not yet exist. Main Topics The changing national security landscape The convergence of security, technology and economic threats Building security into emerging technologies Auburn's national security mission The value of interdisciplinary research Auburn's expanding presence in Huntsville Universities as trusted government and industry partners Experiential learning for national security careers Preparing engineers for an AI-driven workforce Key Quotes "We're starting to see national security, economic security – it's all becoming intertwined and inseparable." — Frank Cilluffo "The largest fraction of our research at Auburn University is national security related. And that's not an accident. It's a commitment." — Dr. Chris Roberts "We're still putting band-aids on [the internet] to make it work. And so that's where we find ourselves. AI is so new. Let's get the foundation set like it needs to be up front, in terms of its security... so that we're not having to band-aid it in 10 years.— Lt. Gen. (Ret) Ron Burgess "We're not selling a product. We're here to educate our students and use our faculty and researchers to solve some tough problems." — Dr. Steve Taylor "We're not a diploma factory. I always tell our students that if the only thing that defines them when they graduate is their GPA, then we have failed."— Dr. Mario Eden Relevant Links and Resources Auburn University Auburn University's Cyber Education Programs About the Guests Lt. Gen. (Ret.) Ron Burgess is chairman of the McCrary Institute Advisory Board and former director of the Defense Intelligence Agency. During a 38-year Army career, he also served as acting principal deputy director of national intelligence and held senior intelligence roles with the Joint Chiefs of Staff and U.S. Southern Command. Dr. Chris Roberts is the 21st president of Auburn University, leading the university's academic, research, extension and public-service missions. An accomplished engineering scholar, he previously served for a decade as dean of Auburn's Samuel Ginn College of Engineering. Dr. Steve Taylor is Auburn University's senior vice president for research and economic development. He previously served as interim dean and associate dean for research in the Samuel Ginn College of Engineering, where he helped expand research funding and establish major applied research institutes and facilities. Dr. Mario Eden is dean of Auburn University's Samuel Ginn College of Engineering and the Joe T. and Billie Carole McMillan Professor. A longtime Auburn faculty member and former chair of chemical engineering, his research focuses on process systems engineering, simulation, design and optimization.

  11. 117

    Why the Human Element Still Matters in Cyber Defense with Nightwing's Chris Jones

    AI is changing the speed and scale of cyber conflict, but the burden on defenders remains the same: they have to protect complex systems all the time, while attackers only need one opening. That imbalance is especially urgent as critical infrastructure, intelligence missions, and space systems become more connected, more contested, and harder to secure. Chris Jones, Chief Technology Officer at Nightwing and a former senior CIA technology leader, joins Frank Cilluffo to discuss what that means for national security. He explains why AI may give attackers a short-term advantage, why many breaches still come down to basic defensive discipline, and why even the most advanced tools depend on skilled people, sound judgment, and mission-focused teams. Main Topics AI and the attacker-defender gap Why cyber defense is so hard Human-enabled cyber and intelligence Digital exhaust and privacy risk Known vulnerabilities and defensive basics Space systems as cyber terrain Securing legacy infrastructure Cyber, RF, EW, autonomy, and AI convergence The workforce behind advanced technology Key Quotes "In the world we live in today, basic privacy is at risk. Everything you do creates digital dust. That digital dust reveals your activities, plans and intentions." — Chris Jones "Having an offensive mindset when you're trying to play defense is really important." — Chris Jones "The notion with any technology that you're going to be able to control and contain it... is just overstated. ... Once the genie is out of the bottle, it's super hard." — Chris Jones "In order to be really effective, it's not just the application of advanced technology. It's the application of advanced technology by really well-trained and experienced operators of that technology." — Chris Jones "We also need people who are looking at how the systems are engineered today and asking the contrarian questions on why they exist the way they do." — Chris Jones Relevant Links and Resources Nightwing About the Guest: Christopher Jones is Chief Technology Officer at Nightwing, where he helps lead the company's technology strategy and the integration of advanced capabilities in support of customer missions. He joined Nightwing in 2024 after a 26-year career at the Central Intelligence Agency, where he finished serving as Associate Deputy Director for Science and Technology. His career has focused on bringing technology into national security operations, and he has received numerous awards including the CIA Director's Award, the Distinguished Career Intelligence Medal, multiple Meritorious Presidential Rank Awards and CIA Exceptional Performance Awards. Jones holds a bachelor's degree in electrical engineering from the University of Notre Dame and a master's degree in systems engineering from Virginia Tech.  

  12. 116

    The Army's "No Fail" Cyber Mission with Brandon Pugh

    Note: This episode was first released on December 2, 2025 This week Army Principal Cyber Advisor Brandon Pugh joins Frank Cilluffo to address a stark reality: if critical infrastructure fails, the Army cannot mobilize. To meet this "no fail" mission, Pugh explains how the service is aggressively merging cyber with electronic warfare and cutting red tape to field new technology in days rather than years. They also discuss the Army's unique edge in this digital fight—Reservists who bring high-level private sector expertise directly to the battlefield. The conversation also explores how AI and operational technology are reshaping the Army's cyber battlefield and threat landscape. Main Topics Covered • How Congress created the principal cyber advisor role and defined its authorities. • Army cyber's four focus areas: AI, defense critical infrastructure, acquisition, and workforce. • Integrating cyber, electronic warfare, RF, and information operations into Army warfighting doctrine. • Defending defense critical infrastructure and preparing for Volt Typhoon-style cyber disruptions. • Leveraging AI for continuous monitoring, faster detection, and protection of sensitive Army data. • Reforming cyber acquisition through FUZE prototypes, VC-style partnerships, and Guard and Reserve expertise. Key Quotes "Cyber is not an isolated capability. It's not something that just rests at Fort Gordon or Fort Meade." – Brandon Pugh "If an adversary goes after one of our military bases and we can't mobilize people, tanks, equipment in a time of conflict, that is a major concern… we can't accept the fact that cyber could be the barrier to our ability to do other military tasks." – Brandon Pugh "It's a national security imperative to leverage AI. We know adversaries are going to leverage AI or exploit our AI regardless of what we do here. We could put barriers in terms of aggressive regulation which some have proposed in the past or seek to slow it down. All that's going to do is help our adversaries." – Brandon Pugh "We have some individuals that show up their reserve weekend in $300,000-$400,000 vehicles because they are the experts in what they do as civilians. They have signed up and taken the oath because they want to serve this country. That is the talent we have in the Reserve and Guard that we need to continue to expand." – Brandon Pugh "We don't have to go through a multi-year acquisition cycle, spend millions of dollars where we've seen 3D printed drones for mere dollars in some cases being leveraged [in Ukraine]… We need some of these capabilities in a matter of days or weeks, not years." – Brandon Pugh Relevant Links and Resources • Jack Voltaic: Critical infrastructure resiliency • Army's FUZE Initiative Guest Bio Brandon Pugh is the Principal Cyber Advisor to the Secretary of the Army, advising the Secretary and Army Chief of Staff on cyber readiness, budget, capabilities, and strategy. He previously served as a director at the R Street Institute and continues to serve in the U.S. Army Reserve as a national security law professor, having earlier been a paratrooper and international law officer.

  13. 115

    Anthropic and the Fight Over Frontier AI Risk with CyberScoop's Greg Otto

    As frontier AI models become more capable at finding vulnerabilities, cybersecurity is entering a period where old timelines, disclosure norms, and governance tools may no longer fit the speed of the technology. In this episode of Cyber Focus, Frank Cilluffo speaks with CyberScoop editor-in-chief Greg Otto about the recent controversy surrounding Anthropic's Fable-5 and Mythos 5 models, the government's use of export controls, and the difficulty of distinguishing between dangerous AI capability and legitimate defensive cyber use. The conversation moves from the Anthropic fight to a broader operational challenge: AI may help defenders discover more weaknesses, but organizations still have to validate, prioritize, and fix them. Otto explains why vulnerability disclosure, patching, open-source security, and public-private coordination are all being tested by AI's pace — and why the most important question may not be whether AI can find the problem, but whether institutions can absorb what it reveals. Main Topics Covered Anthropic's Fable-5 and Mythos 5 models Project Glasswing and vetted model access AI-enabled vulnerability discovery Jailbreaks, guardrails, and defense-oriented prompting Export controls and frontier AI governance Vulnerability disclosure timelines Microsoft, Nightmare Eclipse, and researcher-vendor trust AI-generated bug reports and remediation overload Key Quotes "I think a lot of it was in the White House not fully understanding what is possible. And that's not necessarily on the White House. This is new technology." — Greg Otto "The model itself isn't the problem, it's the output." — Greg Otto "[AI vulnerability discovery] has really laid bare just how dependent we are on software that is literally maintained by people in their basement." — Greg Otto "If you're using AI to generate the answer, that's bad. That is unequivocally bad. It is not going to help."— Greg Otto "If you're using [AI] for something that requires judgment or human care, I think that you should really exercise some caution." — Greg Otto Relevant Links and Resources CyberScoop Safe Mode podcast Guest Bio Greg Otto is editor-in-chief of CyberScoop, where he leads coverage of cybersecurity, emerging technology, public-sector cyber policy, and the threats shaping the digital ecosystem. He also hosts CyberScoop's weekly podcast, Safe Mode, which examines major developments in cyber and technology through conversations with practitioners, executives, researchers, and reporters.

  14. 114

    Inside the FBI's Push to Disrupt Hackers Before They Strike with Brett Leatherman

    In this episode of Cyber Focus, Frank Cilluffo sits down with Brett Leatherman, Assistant Director for Cyber at the FBI, for a wide-ranging conversation about how the Bureau is using law enforcement authorities, intelligence, partnerships, and court-authorized technical operations to disrupt adversaries, help victims, and defend U.S. critical infrastructure. Leatherman explains why the FBI expects to conduct more operations like Operation Masquerade, which evicted Russian GRU actors from compromised routers, and why privately owned routers, edge devices, and small networks can become valuable infrastructure for foreign intelligence services and criminal groups. He also discusses the rise of agentic AI in ransomware, China-linked threats to operational technology and critical infrastructure, Operation Winter SHIELD, supply-chain risk, and why early victim reporting can help the FBI move upstream against cyber adversaries. Main Topics Covered FBI cyber threat response and disruption operations Operation Masquerade and court-authorized cyber actions Ransomware, agentic AI, and emerging threats China-linked threats to critical infrastructure Public-private partnerships and victim reporting Operation Winter SHIELD and cyber defense best practices Key Quotes "Deterrence for us is not just about arrests, indictments, convictions, although that still matters a lot to what we do. It's also about removing capacity and capability from the actors where they're not touchable. Their infrastructure is touchable, their money is touchable, their tools are touchable." — Brett Leatherman "The idea of security through obscurity is dangerous." — Brett Leatherman "The FBI will never ask you to maintain breach while we are conducting evidence collection." — Brett Leatherman "Ransomware actors are starting to leverage agentic AI, along with the nation states, to really move across the cyber kill chain at speeds we haven't seen before, and at speeds defenders might not be ready for."  — Brett Leatherman "We can't defend against machine speed at human speed." — Brett Leatherman  Relevant Links and Resources FBI Cyber Division Internet Crime Complaint Center (IC3) Operation Masquerade Operation Winter SHIELD Guest Bio Brett Leatherman is the Assistant Director for Cyber at the FBI, where he oversees the Bureau's cyber efforts, including incident response, threat response, and cyber disruption operations. A 23-year FBI agent, Leatherman has worked or managed programs across counterterrorism, counterintelligence, cyber, and criminal investigations. He previously served in senior roles in the FBI's Cyber Division and in Dallas, and has also served as an FBI pilot and negotiator.

  15. 113

    The New AI Executive Order and the Race to Harden America's Systems with Daniel Kroese

    A new executive order on artificial intelligence and cybersecurity sends a clear signal: advanced AI now sits at the center of how the United States thinks about cyber defense, national security, critical infrastructure resilience, and strategic competition. In this episode of Cyber Focus, Frank Cilluffo sits down with Daniel Kroese, Vice President of Global Policy at Palo Alto Networks and a Senior Fellow at the McCrary Institute, to unpack what the order means in practice. Kroese argues that the most important signal is the administration's effort to bring government, industry, and critical infrastructure operators together quickly — not simply to study AI risk, but to operationalize AI-enabled defense while preserving the innovation advantage that gives the United States its head start. Main Topics Covered The executive order's "North Star" signal on AI innovation, cybersecurity, and national security Why AI and cybersecurity are increasingly inseparable How frontier models are transforming vulnerability discovery, software red teaming, and cyber defense The urgency of hardening systems before adversaries catch up Expanding AI-enabled cyber tools to under-resourced critical infrastructure operators The role of voluntary frameworks and the proposed AI cybersecurity clearinghouse Managing a surge in vulnerabilities while improving detection and response times Key Quotes "In three weeks, [Mythos] was able to conduct one to two years' worth of red teaming on our own code base. We're not talking 5 percent better, 10 percent better, 15 percent better. We're talking about doing something in three weeks that would have taken us one, if not more, years previously. So that is an inflection point." — Daniel Kroese "We have a head start, but it is not an infinite head start." — Daniel Kroese "We also have to recognize that for your average electric utility or water treatment plant, if we were to give them Mythos or GPT-5.5 access tomorrow, due to the operational realities of how they are organized, they wouldn't know what to do with it. So it's not as simple as just flicking on access. It's about how do we scale and democratize the Cyber defense benefits of these models." — Daniel Kroese "Detection response times must be measured in single-digit minutes, not days, weeks, or never." — Daniel Kroese "This isn't about information sharing alone. It's about operational collaboration." — Daniel Kroese Relevant Links and Resources White House Executive Order: Promoting Advanced Artificial Intelligence Innovation and Security Palo Alto Networks Guest Bio Daniel Kroese is Vice President of Global Policy at Palo Alto Networks, where he leads the company's engagement with policymakers and government stakeholders. He previously served as Staff Director for Ranking Member John Katko on the House Homeland Security Committee and held senior cybersecurity roles at CISA and on Capitol Hill. He is also a Senior Fellow at the McCrary Institute.  

  16. 112

    AI Is Not Your Friend: Geoffrey Fowler on Rating AI for Kids

    In this episode of Cyber Focus, Frank Cilluffo speaks with Geoffrey Fowler, head of public engagement for the Youth AI Safety Institute at Common Sense Media, about why AI requires a different kind of safety framework than movies, apps, games, or social media. Fowler argues that generative AI is not static content; it is dynamic, conversational, multipurpose, and capable of changing from one interaction to the next based on the user, the prompt, the model, and the length of the conversation. The conversation explores how AI products that appear friendly, educational, or therapeutic can create new risks for children, from emotional dependency and privacy concerns to unsafe mental-health guidance and weakening guardrails over extended conversations. Fowler explains how Common Sense Media is working to build independent AI safety ratings for kids, modeled in part on crash testing for cars: transparent evaluations that help parents and schools make better decisions while pushing companies toward safer design. Main Topics Covered Why AI needs a new safety rating Lessons from social media and smartphone adoption AI companions, mental-health claims, and dependency risk AI toys, privacy, and weakening guardrails Independent testing, ratings, and child-development standards Company responsibility, public policy, and trust Key Quotes "AI is not your friend. AI is not human. It does not make the kinds of choices that a human being would make when you're having a bad day or when you're in a crisis or when you need somebody to really trust." — Geoffrey Fowler, Common Sense Media "[AI companies] shouldn't be experimenting on our kids. They should make it safe from the get go." — Geoffrey Fowler, Common Sense Media "These AI toys are little spies that you're putting in kids' rooms. They're recording their voices, they're recording behavioral data." — Geoffrey Fowler, Common Sense Media "The Common Sense Media Youth AI Safety Institute is neither pro AI nor anti AI. It's pro kid." — Geoffrey Fowler, Common Sense Media "We are here to research not just the hype of what companies say about what their technology does, we're here to see what it actually does and tell the truth about it." — Geoffrey Fowler, Common Sense Media Relevant Links and Resources https://www.commonsensemedia.org/ai-ratings/ai-risk-assessments Guest Bio Geoffrey Fowler is head of public engagement for the Youth AI Safety Institute at Common Sense Media. He is a longtime technology journalist whose work has appeared at The Washington Post and The Wall Street Journal. In this role, Fowler helps communicate Common Sense Media's work to evaluate AI products used by children, teens, families, and schools, including the development of independent safety ratings and risk assessments for youth-facing AI tools.  

  17. 111

    Estonia's Lessons for the Cyber Future with Ambassador Kristjan Prikk

    For Estonia, cyber resilience is not an abstract policy goal. It is a national survival issue shaped by history, geography, and the reality of living next to Russia. In this episode, Ambassador Kristjan Prikk explains how Estonia turned a lack of legacy infrastructure into a digital advantage, why the 2007 cyberattacks became a strategic wake-up call for the West, and what Ukraine's defense against Russia reveals about preparation, public-private cooperation, and the future of conflict. The conversation also looks ahead: to AI in government and education, to Estonia's support for Ukraine, and to the cyber lessons NATO must operationalize before the next crisis. At the center is a clear argument from one of the world's most digitally advanced democracies: cyber defense is not just about hardening systems, but building the relationships, institutions, and resilience needed to keep a society functioning under pressure. Main Topics Covered Estonia's digital transformation Life after Soviet occupation The 2007 cyberattacks Resilience over perfect defense Ukraine's cyber defense Private-sector support in wartime AI in government and education Support for Ukraine NATO's cyber priorities Key Quotes "We had a really strong incentive to go ahead and try out something almost crazy, something that no one had ever tried before, and just see what's going to happen." — Ambassador Kristjan Prikk "We believe that our kids will not lose [their] jobs to AI, but rather they may risk losing their jobs to other kids who know how to use AI better than them." — Ambassador Kristjan Prikk "We reduce or limit the risk of particularly high impact threats, risks materializing. But then again, the more important part is the ability to rebound; the ability to use alternatives if plan A is not working." — Ambassador Kristjan Prikk  "The way the cyberspace is set up means that we cannot only be confined in our own quarters and expect that if we keep it in order, then nothing happens." — Ambassador Kristjan Prikk  "Cybersecurity is a team sport…we have to make sure that when the problem appears, then we don't have to start searching for contacts of other people. The organization has to be there." — Ambassador Kristjan Prikk Relevant Links and Resources Embassy of Estonia in Washington, D.C. Estonia's national cybersecurity strategy or cyber agency resources Tallinn Mechanism information page IT Coalition for Ukraine information page About the Guest: Kristjan Prikk has served as Estonia's Ambassador to the United States since May 2021, and will soon serve as Estonia's Ambassador to NATO. Before assuming his current duties, Prikk served for nearly three years as the Permanent Secretary of the Estonian Ministry of Defense. In this role he was responsible for the management of the Ministry and for the coordination of activities of the agencies under the Ministry, including the Estonian Defense Forces, the Estonian Foreign Intelligence Service, and the Centre for Defense Investments.  

  18. 110

    Who's Accountable When AI Acts? — With Walter Haydock

    In this episode of Cyber Focus, Frank Cilluffo speaks with Walter Haydock, founder of StackAware, about the accountability, governance, and national security challenges emerging as organizations rush to deploy artificial intelligence. Haydock argues that AI does not erase familiar cybersecurity and risk-management problems; it accelerates them. From non-human identities and AI agents to third-party risk, federal regulation, and the environmental demands of AI infrastructure, the conversation centers on a core question: who is accountable when AI systems act, fail, or cause harm? Rather than treating AI governance as a compliance checklist, Haydock makes the case for assigning clear ownership, focusing policy on outcomes, and giving business leaders—not risk advisors alone—responsibility for the risks their organizations accept. Main Topics Covered AI accountability and non-human identities Managing AI agents as unpredictable actors Who should own AI risk inside an organization Third-party risk, supply chains, and contractual accountability Avoiding checkbox compliance in AI governance National AI policy, innovation, and strategic competition Key Quotes: "I see organizations spending a lot of time, money, resources, brain power on low-impact problems, on things that they shouldn't be focused on, and instead they're kind of ignoring the higher-risk issues that have easier mitigations, easier solutions." — Walter Haydock "The question of who is accountable for a given outcome is a critically important one." — Walter Haydock "At the level of an individual business, I think it's important to assign accountability for actions of AI agents to cross-functional business leaders who have the wherewithal, the full understanding of all the issues that are impacting a given company." — Walter Haydock "The framework I use is that business leaders are risk and system owners. They are ultimately accountable. They make the final decisions." — Walter Haydock "When the government hard codes in supposed best practices, they end up creating perverse incentives where companies are focused very closely on checking the box and not necessarily on getting the good outcome." — Walter Haydock Relevant Links and Resources Stack Aware Guest Bio Walter Haydock is the founder of StackAware, an AI security and governance company. Before founding StackAware, he worked in government, national security, and the military, including service on the House Homeland Security Committee, at the National Counterterrorism Center, and in the U.S. Marine Corps in intelligence and reconnaissance roles.

  19. 109

    The End of Human-Speed Cyber: Mythos, Glasswing & the AI Exploit Race with CrowdStrike's Drew Bagley

    Cyber defense is entering a machine-speed era. With Anthropic's Mythos and Project Glasswing bringing AI-driven vulnerability discovery and exploit development into the center of the cyber conversation, CrowdStrike's Drew Bagley says organizations need to prepare for a world where vulnerabilities can be found, chained, and exploited faster than traditional patching cycles can handle. Bagley joins Frank Cilluffo to explain why this shift is not just about one model, one company, or one headline-grabbing project. It points to a broader change in how attackers and defenders will operate: exploit stacks may make once-latent vulnerabilities newly dangerous, critical infrastructure operators may face risks they cannot patch away, and unmanaged AI agents inside organizations may become another source of exposure. The answer, Bagley argues, is not panic or patching alone, but continuous discovery, continuous remediation, visibility across the kill chain, AI-powered defense, and resilience planning built for a world moving faster than human-speed cyber. Main Topics Covered Mythos, Project Glasswing, and AI-driven vulnerability discovery Why exploit stacks change how organizations should think about risk Continuous patching, prioritization, and machine-speed defense Critical infrastructure, OT systems, and unpatchable legacy technology AI agents, unmanaged access, and the next insider-style risk Key Quotes "We're now in an era in which AI has been proven to be able to find vulnerabilities and write exploits at scale much quicker than humans can." — Drew Bagley "We should think about this as an opportunity to think through this problem set now and assume that this is going to be just a widespread capability pretty soon." — Drew Bagley "Previously latent [OT] vulnerabilities… [relied on] security through obscurity. That's no longer the case. And now those are exploitable." — Drew Bagley "If you don't have visibility and you can't see the risk, then you can't mitigate the risk." — Drew Bagley "It's important to think about the ways in which AI has been incorporated over the past two years, especially in organizations to get work done better, but in ways that have often been unmanaged where AI has access to things you wouldn't give an intern access to." — Drew Bagley Relevant Links and Resources Anthropic's Project Glasswing CrowdStrike's Project Quiltworks Guest Bio:   Drew Bagley is CrowdStrike's Chief Privacy Officer, where he leads the company's privacy and public policy work. In his 12 years at CrowdStrike, he has helped shape the company's approach to data protection, cybersecurity policy, and engagement with government leaders as CrowdStrike grew into a global cybersecurity company.

  20. 108

    What Most People Get Wrong About Secure Messaging with Signal CTO Ehren Kret

    Most people think secure messaging begins and ends with encryption. Signal CTO Ehren Kret says that is only part of the picture. In this episode of Cyber Focus, host Frank Cilluffo sits down with Kret to discuss what private communication really requires, from protecting message content to limiting what platforms can learn from metadata, identity, group membership and social graphs. Kret explains how Signal's nonprofit model shapes its privacy-first design choices, why endpoint security remains a major challenge, and how AI built into operating systems could create new risks for private communication. The conversation also explores post-quantum encryption, lawful access debates, phishing threats against messaging accounts, and why the future of secure communication depends not only on better technology, but on helping users understand what is and is not truly private. Main Topics Secure messaging misconceptions Metadata and social graphs Endpoint security risks AI and platform privacy Post-quantum encryption Signal's nonprofit model Key Quotes "Disappearing messages, and that's one piece of the puzzle... But a lot of people think that's sort of the end." — Ehren Kret "You should also be looking at does your service provider have access to the message content and is it protected from visibility from them?" — Ehren Kret  "Being able to build a social graph can reveal information, even though you don't necessarily have the message content, it is highly leaky. You can infer from a social graph, you can see who is talking to who, and a lot of times that reveals information about the content of those communications ." — Ehren Kret "Signal...is an anti mass surveillance tool. It's not necessarily an anti targeted surveillance tool because at the end of the day your phone is still an endpoint that can be targeted." — Ehren Kret "Since it's a nonprofit, the primary goal for Signal is to spread the use of end-to-end encrypted for messaging and for communications in general." — Ehren Kret Relevant Links and Resources Signal Foundation Signal: Sealed Sender Signal: Quantum Resistance and the Signal Protocol Cloudflare Post-Quantum Roadmap Google Research on Quantum Vulnerabilities About Ehren Kret Ehren Kret is the Chief Technology Officer at Signal, where he helps lead the development of privacy-preserving communication technology. He previously served as an engineering director at WhatsApp, where he helped scale end-to-end encryption for more than a billion users.  

  21. 107

    How Idaho National Laboratory Is Building the Future of Infrastructure Security with Zach Tudor

    America is asking more from its critical infrastructure just as adversaries are finding more ways to target it. AI, data centers, electrification, and next-generation energy systems all depend on operational technology—the control systems that keep power, water, transportation, and industry moving. As that backbone grows more connected, the stakes of securing it grow even higher. In this episode of Cyber Focus, Frank Cilluffo speaks with Zach Tudor, Associate Laboratory Director at Idaho National Laboratory, about how INL tests and secures critical infrastructure at scale. Tudor explains why resilience must guide infrastructure defense, what Ukraine and China reveal about the risks facing critical infrastructure, and why cyber-informed engineering is essential as new technologies move into energy, nuclear, wireless, and industrial systems. The conversation also covers AI's role in control environments, the workforce needed to secure future infrastructure, and the challenge of moving faster before a major event forces action. Main Topics Covered INL's critical infrastructure mission Testing infrastructure at scale OT security and resilience AI risks in control systems Cyber-informed engineering Workforce needs for energy security Key Quotes "No infrastructure is impervious to attack." — Zach Tudor "I think we're getting to the point where, if you are delivering power to the nation, then you are a risk professional as well as a power engineer." — Zach Tudor "Resilience for me is not just the preparation for an attack or the response to an attack, but the ability to mitigate the effects of an attack, to respond quickly, and to recover quickly as well." — Zach Tudor "We are a national lab in the public economic and national security interest. And so we'll do what needs to be done. We say that labs do what others can't, won't or shouldn't do." — Zach Tudor "The mindset of an engineer who's thinking about operations is different from the mindset of an IT security person who's protecting databases or privacy or other data." — Zach Tudor Relevant Links and Resources Idaho National Laboratory Department of Energy National Laboratories Cyber-Informed Engineering (CIE) Guest Bio Zach Tudor is Associate Laboratory Director for National and Homeland Security at Idaho National Laboratory, where he leads programs focused on critical infrastructure protection, operational technology security, and national security innovation. He previously served at the Department of Homeland Security's ICS-CERT and is a former U.S. Navy submariner. Tudor has spent decades working at the intersection of cybersecurity, energy systems, and national defense.

  22. 106

    Hacking Reputation: Disinformation, Trust, and Cyber Crisis Response with Preston Golson

    A cyber incident can damage far more than systems and networks. It can also become a reputational crisis, especially when false or misleading narratives move faster than facts. In this episode of Cyber Focus, Frank Cilluffo speaks with Preston Golson of Brunswick Group about why organizations need to treat reputation as a vulnerability that can be tested, stress-tested, and defended much like any other part of their cyber posture. Drawing on his work in cyber incident response and his earlier career at the CIA, Golson explains how misinformation and disinformation take hold, why many damaging narratives are foreseeable, and how companies can prepare before a crisis hits. The conversation explores red teaming, "prebunking," unified crisis response, and the growing importance of trust, credibility, and AI-generated search results in shaping public perception. For leaders trying to manage cyber risk in a more volatile information environment, this episode offers a practical framework for thinking about reputation, crisis communications, and resilience. Main Topics Covered Reputation as a cyber target Disinformation and viral narratives Red teaming reputational risk Cyber crisis communications Prebunking and digital inoculation Key Quotes "Misinformation is like a forest fire and we live in a forest with combustible conditions … false and misleading narratives can be caught quickly and they can affect a company's license to operate." — Preston Golson   "If you have a dedicated team to look for [reputational risks], you can hack your own reputation, understand where your vulnerabilities are and then reverse engineer defenses and proactive communications … to help build resiliency amongst your audiences." — Preston Golson "We don't play whack a mole. Not every narrative deserves a response. As a matter of fact, some narrative, if you give them a response, it'll give it more oxygen." — Preston Golson "What effective [misinformation] narratives are doing are playing on people's insecurities, [and] people's desire to understand a world that is increasingly complex. It doesn't always make sense." — Preston Golson "Ransomware really did democratize cyber. Everyone's a target from the biggest Fortune 10 down to every mom and pop shop..." — Frank Cilluffo Relevant Links and Resources Brunswick Group Preston Golson's article, "Hacking Reputation" Guest Bio Preston Golson is a director at Brunswick Group, where he works on cyber incident response and related communications challenges. Before joining Brunswick, he spent more than 15 years at the Central Intelligence Agency. In this episode, he draws on that experience to discuss cyber crisis response, disinformation, reputational risk, and how organizations can prepare for false or misleading narratives before they take hold.

  23. 105

    Cult of the Dead Cow and the Roots of Modern Cyber Ethics with Joe Menn

    Cybersecurity's history is often told through breaches, crime, and disruption. Joe Menn argues that the story of early hacker culture also offers something constructive: a model for how technical curiosity, ethical reflection, and independent thinking can shape the public good. Drawing from his work on Cult of the Dead Cow, Menn traces how figures once associated with pranks, underground tools, and legal gray zones helped influence vulnerability disclosure, hacktivism, privacy debates, and even the way government and major companies think about security today. But the episode does not stay in the past. Menn connects those earlier lessons to much more current concerns: digital surveillance, the tightening relationship between big tech and government, and the security risks emerging from the rush into AI. The result is a conversation about far more than hacker lore. It is about who gets to shape technology, what values guide that work, and why critical thinking itself may now be part of the infrastructure worth defending. Main Topics Covered The legacy of Cult of the Dead Cow The evolution of hacktivism Ethics and critical thinking in cyber Surveillance, privacy, and state power AI security and concentrated tech influence Key Quotes "I think it's very interesting to me that... any Fortune 100 CISO who's in his mid-50s or older broke the law as a teenager." — Joe Menn "Hackers are by definition, if they're any good, are critical thinkers, because they're taking stuff and saying, well, okay, this is the intended purpose. What else can it do? What else can I make it do?" ­— Joe Menn "Hackers should be big players in legislation and in protecting critical infrastructure, and all these other things because they are critical thinkers and won't just repeat what the conventional wisdom is. You get value from people who are thinking differently. — Joe Menn "[A]t the most recent inauguration, you had Jeff Bezos and Mark Zuckerberg, and I believe Elon Musk standing closer to Trump than his cabinet members. The allegiance of big tech is actually more important than some of the entire branches of government. And their interests are now, by and large, very closely joined." — Joe Menn "[W]henever there's a new exciting technology; people rush into it and then sometime later they figure out about security ... And right now, there's this land rush where all the vulnerabilities are now visible through the wonder of AI. And so, tech debt that was swept under the rug is now become a forest fire." — Joe Menn Relevant Links and Resources  Cult of the Dead Cow Fatal System Error    Citizen Lab About the Guest Joe Menn is a longtime technology reporter and author who has covered cybersecurity, privacy, and related policy issues for decades. In the episode, Frank Cilluffo notes that Menn has written for The Washington Post, Financial Times, Reuters, and the Los Angeles Times, and is the author of two bestselling cybersecurity books, including Cult of the Dead Cow.

  24. 104

    From Fax Machines to Quantum: Canada's Sami Khoury Reflects on Three Decades in Cyber

    Cybersecurity now reaches far beyond government networks and traditional IT systems. In this episode, Sami Khoury explains how the threat environment increasingly touches critical infrastructure, operational technology, undersea cables, and space—and why that shift is pushing governments to work more closely with private industry and trusted international partners. Drawing on more than three decades in Canadian government, Khoury offers a clear view of how Canada has built out its cyber posture, how the Canadian Centre for Cyber Security fits into that mission, and where the threat is evolving fastest. He also reflects on the growing overlap between nation-state activity, cybercrime, and hacktivism; the promise and risk of AI; the long transition toward post-quantum security; and the enduring pull of public service in a field where the stakes keep rising. Main Topics Covered Canada's cyber strategy Critical infrastructure security OT, undersea cables, and space AI and post-quantum risk Public-private and international partnership Key Quotes:  "When cyber came about or when we started paying attention to cyber, it was predominantly an IT issue. But unfortunately, these days it's not just an IT issue and we have to pay attention to OT." — Sami Khoury "We know that cyber, and it might be cliche, cyber knows no border." — Sami Khoury  "We welcome people from different educational background because it's the analytical thinking capacity that we're looking for, not critical thinking skills. It's not necessarily that you're the best coder or that you are the best hardware architect. We want people with the critical thinking skills." — Sami Khoury "The day there's a cryptographically relevant quantum computer that can break today's encryption will not, I presume, will not come with a press release." — Sami Khoury "It's no longer government on government, it's government on private sector, it's mercenaries on private sector, it's mercenaries on government or hacktivist on government. So it's completely asymmetric and it takes a whole team to basically make a difference." — Sami Khoury Relevant Links and Resources Canadian Centre for Cyber Security  Canada's national cyber threat assessment Canada's AI strategy Canada's Post-quantum encryption bulletin Guest Bio: Sami Khoury is the Government of Canada Senior Official for Cyber Security and the former head of the Canadian Centre for Cyber Security. He has spent over 30 years in the Canadian government, primarily within the Communications Security Establishment (CSE), Canada's signals intelligence and cryptologic agency. A veteran of the "Five Eyes" intelligence community, Khoury has been instrumental in shaping Canada's national cyber strategy and fostering deep operational ties with international partners.

  25. 103

    Ukraine, Private Sector Power, and Cyber Defense with Greg Rattray

    Ukraine's cyber defense has become one of the clearest real-world tests of what resilience actually looks like under sustained attack. In this episode of Cyber Focus, Greg Rattray explains why Ukrainian defenders held up better than many expected, and what their experience reveals about the limits of prevention, the value of shared visibility, and the growing operational role of the private sector. Drawing on his work leading the Cyber Defense Assistance Collaborative, Rattray argues that exposing adversary activity across a more "brightly illuminated cyberspace" helped blunt Russia's offensive advantage. But the larger lesson is not just about threat visibility. It is about recovery, adaptability, and trust: teams under pressure need tools they already know how to use, leaders need to plan for bad days, and governments need to make room for industry to do more than simply wait for direction. Main Topics Covered The "bright room" concept in cyber defense Why resilience matters more than perfect prevention Familiar tools vs. cutting-edge tech in crisis The private sector's front-line role How cyber, EW, and drones are converging Key Quotes: "It's pretty hard to do cyber offense in a bright room, in a dark room, it's a lot easier. But like what we've done here is give the Ukrainians the position that the Russian attacks are trying to occur in a pretty brightly illuminated cyberspace." — Greg Rattray "Kyivstar, [Ukraine's] major telecommunications provider, got leveled in December of 2023. I thought they would be out for weeks. Two days later they were back up and running." — Greg Rattray "The speed at which drones have to change in order to stay survivable and effective; these innovation cycles are weeks, not years." — Greg Rattray "While the NIST cybersecurity framework talks about respond and recover, the amount of energy that goes into resilience is still to my mind, under thought, under exercised, [and] under invested in." — Greg Rattray "The notion that you're going to be targeted has to be part of your risk calculus. And therefore you even with a good team... you cannot guarantee you won't have a bad day." — Greg Rattray Links/Resources Cyber Defense Assistance Collaborative: https://crdfglobal-cdac.org Guest Bio:  Dr. Greg Rattray is Chief Strategy and Risk Officer at Andesite and Executive Director of the Cyber Defense Assistance Collaborative (CDAC), which has facilitated more than $30 million in voluntary cyber defense support to Ukraine. He previously served as J.P. Morgan Chase's Global CISO and Head of Global Cyber Partnerships, and spent 23 years in the U.S. Air Force, including as the National Security Council's Director for Cybersecurity.  

  26. 102

    Transatlantic Reset: Private Sector Diplomacy & Digital Trust with Sébastien Garnault

    Overview Transatlantic cyber cooperation is being tested by political strain, regulatory divergence, and competing ideas about sovereignty, trust, and market access. In this episode of Cyber Focus, Sébastien Garnault argues that if the United States and Europe want to keep working together on security, they need to move quickly to make that cooperation practical, especially in critical infrastructure and digital markets. Speaking from a French private-sector perspective, Garnault makes the case that governments alone may not be able to repair or sustain that cooperation at the speed the moment requires. He points instead to private-sector partnerships, shared market incentives, and clearer language around security standards as possible ways to keep the transatlantic relationship workable even when public-sector trust is under pressure. The conversation also explores how Europe and the United States differ on clean versus trusted technology stacks, how threat perceptions shape national requirements, and how privacy, AI, and data localization debates can either strengthen or complicate cooperation. The conversation was recorded on February 11, 2026. Main Topics Covered Private-Sector Cooperation as a Strategic Bridge: Why Garnault believes business-to-business cooperation may move faster than government-to-government diplomacy when trust is strained. Clean Stack vs. Trusted Stack: How U.S. national-security thinking and EU market-standard thinking create different paths for defining who can participate in secure digital markets. Threat Perception and Market Access: How geography, history, and national priorities shape security requirements across Europe and affect access to critical infrastructure markets. Trust, Sovereignty, and the Transatlantic Reset: Why Garnault sees damaged trust as a real obstacle, and why he argues for a reset rather than a rupture in U.S.-European cyber cooperation. Privacy, AI, and Data Localization: How French and European views on privacy, regulation, and AI governance differ from those in the United States, and why those differences matter for security and interoperability. Key Quotes "Maybe what we've done in the last decade and what we will do in the next decade don't belong from government but belongs to us." — Sébastien Garnault "We can do a reset; we cannot afford a reboot." — Sébastien Garnault "The damages that have been done in our trust, mutual trust, are very deep. So we need to fix it quickly." — Sébastien Garnault "The best way for us to cooperate with our allies is to use the market because the market is less political than national security." — Sébastien Garnault "From my standpoint, the glue that binds us together is much greater than anything that can tear us apart." — Frank Cilluffo Links/Resources CyberTaskForce: https://www.cybertaskforce.fr/ Paris Cyber Summit: https://www.paris-cyber-summit.com/ Guest Bio Sébastien Garnault is the founder of the CyberTaskForce and president of the Paris Cyber Summit. He joined Cyber Focus while in Washington leading a French delegation meeting with U.S. policymakers, industry leaders, and other decision-makers, and spoke in a private-sector capacity rather than on behalf of the French government.  

  27. 101

    Keeping the Lights On in the AI Era with DOE's Alex Fitzsimmons

    Electricity demand is surging—and DOE's Alex Fitzsimmons argues that the country's ability to "keep the lights on" is now inseparable from how fast we can expand energy infrastructure, how we manage affordability, and how seriously we treat security. In this conversation with Frank Cilluffo, Fitzsimmons, the Acting Under Secretary of Energy and Director of the Office of Cybersecurity, Energy Security, and Emergency Response (CESER), frames "energy dominance" as a practical governing problem: meet rapid load growth (including from AI and data centers), avoid reliability shortfalls, and do it in a way that doesn't push unacceptable costs onto everyday Americans. Main Topics Covered AI- and data center-driven demand growth Affordability and "ratepayer protection" Resource adequacy and reliability risk OT security and critical infrastructure stakes Supply chain risk and security vs speed Key Quotes "Privacy, data breaches, all of these things are important. They matter. They matter. But OT matters more. Keeping the lights on matters more." — Alex Fitzsimmons "These tech companies recognize that for their technology to be politically and economically viable, that the American people cannot be shouldered with the burden of new data centers." — Alex Fitzsimmons "We were set to lose 100 gigawatts of reliable dispatchable generation by 2030, at the same time that we may need to build 100 gigawatts of generation and associated infrastructure to win the AI race." — Alex Fitzsimmons "We have to [build supply] securely. So we can't sacrifice security for speed." — Alex Fitzsimmons "[AI-FORTS] is focused on 3 things: secure the energy system from AI, secure it with AI, and secure the AI itself." — Alex Fitzsimmons Relevant Links and Resources DOE's CESER Office DOE's Genesis Mission  DOE 2025 resource adequacy report NERC; RTOs and ISOs (mentioned in the episode; link not provided) Guest Bio Alex Fitzsimmons serves in the Trump Administration as the Acting Under Secretary of Energy at the U.S. Department of Energy (DOE), where he spearheads DOE's energy dominance mission and oversees a broad portfolio of offices advancing affordable, reliable, and secure energy for the American people. He also serves as Director of DOE's Office of Cybersecurity, Energy Security, and Emergency Response (CESER), leading efforts to safeguard the nation's energy infrastructure against evolving cyber and physical threats and strengthen resilience across critical energy systems.

  28. 100

    Deterrence and the New Cyber Strategy with White House National Cyber Director Sean Cairncross

    Cyber deterrence has long lagged behind the threat. In this special episode of Cyber Focus recorded on March 11, 2026, White House National Cyber Director Sean Cairncross argues that the United States can no longer afford a posture built mainly around resilience and response while adversaries, criminal groups, and state-backed proxies operate at low cost and low risk. He presents President Trump's new National Cyber Strategy as an effort to change that calculus by aligning government policy, offensive and defensive capabilities, industry partnership, and international coordination around a more forward-leaning approach. The conversation walks through the strategy's six pillars, from shaping adversary behavior and streamlining regulation to modernizing federal systems, securing critical infrastructure, protecting U.S. technological advantage, and expanding the cyber workforce. Cairncross emphasizes a core theme throughout: private companies should not be left to fend for themselves against foreign intelligence services and military-linked actors, and government must do more to impose cost, remove friction, and support practical security outcomes. Main Topics Covered Cyber deterrence and imposing costs on adversaries Public-private partnership and smarter regulation Federal modernization and procurement reform Critical infrastructure resilience AI, post-quantum policy, and cyber workforce development Key Quotes "Resiliency is great, but resiliency…implies that you're taking hits." — Sean Cairncross "There is a lot that can be done to deny [bad cyber actors] the benefits of their activity, to make life harder for them online and to deny them safe haven." — Sean Cairncross "I think if you get hit by a foreign adversary, for the USG to turn around and point a finger at you is essentially shifting blame… It's not going to succeed unless both sides of that coin are working together and being collaborative." — Sean Cairncross "We can work on procurement speed. We can work on technological innovation and adopting that technology much more quickly than we have." — Sean Cairncross "This [low-cost, high-reward incentive structure for malicious cyber actors] has been allowed to go too far and get too far out of whack ... and we need to reset that." — Sean Cairncross Relevant Links and Resources President Trump's National Cyber Strategy Cybercrime executive order signed the same day as the strategy Post-quantum policy / "PQC" executive order or action under development Guest Bio Sean Cairncross is the White House National Cyber Director, serving as the principal adviser to the president on cyber policy matters. Before taking this role, he served in the Trump White House as deputy assistant to the president and senior adviser to the chief of staff. He also served as CEO of the Millennium Challenge Corporation and has held senior leadership roles in politics, government, and strategic consulting.

  29. 99

    The Cyber Dimension of the Iran Conflict with Cynthia Kaiser & Mark Montgomery

    Cyber is now woven into modern conflict, alongside conventional military force. In this episode, Frank Cilluffo examines how that shift shapes the threat from Iran—especially the risk of cyber retaliation aimed at U.S. critical infrastructure, U.S. businesses, and public confidence. Rear Admiral (Ret.) Mark Montgomery of the Foundation for Defense of Democracies brings a strategic and military lens to the discussion, explaining how cyber is being built into conflict planning alongside kinetic operations. Cynthia Kaiser, a former FBI cyber leader now with Halcyon, brings an operational view of how Iranian cyber activity can create disruption, spread fear, and produce real effects even without the sophistication of China or Russia. Main Topics Covered Cyber as an integrated warfighting tool Iran's cyber posture and likely retaliation paths Critical infrastructure and OT vulnerabilities Disruption, fear, and information effects Gaps in U.S. civilian cyber defense Key Quotes "They're not at the level of capability as Russia and China, but that's almost irrelevant. They've got a drive-by shooting capability." — Frank Cilluffo "We're seeing cyber integrated at the front end of planning. It's not cyber only or cyber as an afterthought, but it's cyber as an integrated element." — Mark Montgomery "The vast majority of our critical infrastructure doesn't have a shield."— Mark Montgomery "[Iran is] really one of the world's most malicious and capable cyber actors. They're not necessarily as good as China or Russia, but they don't need to be to have an effect." — Cynthia Kaiser "The point's the fear. The point's the chaos. And the point is the internal messaging for their own people—to say we did something in retaliation." — Cynthia Kaiser Relevant Links and Resources Foundation for Defense of Democracies Halcyon Ransomware Research Center NSA Cybersecurity Collaboration Center Guest Bio Mark Montgomery is a senior fellow at the Foundation for Defense of Democracies and former executive director of the Cyberspace Solarium Commission. He brings deep experience in cyber strategy, defense policy, and national security planning. Cynthia Kaiser is a senior cyber executive at Halcyon and a former FBI leader with extensive experience in cyber investigations and ransomware response. She brings an operational perspective on Iranian cyber activity, disruption campaigns, and cyber risk to critical infrastructure.  

  30. 98

    The Regulatory Shift: How CIRCIA and NIST are Redefining Cyber Defense with Sara Friedman

     Cyber incident reporting is about to become mandatory for much of critical infrastructure—and the details are where the fight is. On February 26th, Frank Cilluffo spoke with Inside Cybersecurity managing editor Sara Friedman about CIRCIA's proposed reporting rules, what industry says is overbroad, and why the 72-hour clock is hard in the real world. They also dig into overlap with other federal requirements, CISA's capacity to execute the rulemaking, and what "getting it right" means for public-private trust. The conversation then pivots to NIST, AI agent standards, and how Washington is balancing innovation, security, and competitiveness. Main Topics Covered What CIRCIA is designed to do. Who's covered and what counts as reportable. The practical challenge of determining incident facts within 72 hours. Duplication concerns across rules, including SEC cyber disclosure timelines. Whether CISA has the staffing and leadership capacity to deliver. NIST's role in AI agent standards and broader cyber "rules of the road." Key Quotes "CISA was supposed to have voluntary partnerships… And with this new role, CISA is moving into more of a regulator role." —Sara Friedman "This rulemaking, when it was put out, it's over 400 pages. There's a lot in there." — Sara Friedman "House Homeland Security Chairman Andrew Garbarino threatened to, if the rulemaking does not meet congressional intent…to potentially roll this back." — Sara Friedman "When there's a large attack on critical infrastructure, it just seems to wake up lawmakers in some ways that they need to be able to do something." —Sara Friedman "They've shed about a third of their workforce…One of the questions is, does CISA have the capacity that they need for this rulemaking and to do it effectively? —Sara Friedman Relevant Links and Resources CIRCIA town halls scheduled for March: https://insidecybersecurity.com/share/17759 When the CIRCIA NPRM was published: https://insidecybersecurity.com/share/15688 RSA 2024 panel on the rulemaking: https://insidecybersecurity.com/share/15832 NIST launches AI Agent Standards initiative: https://insidecybersecurity.com/share/17775 NIST AI security request for information: https://insidecybersecurity.com/share/17654 NIST work on an AI profile for the Cybersecurity Framework: https://insidecybersecurity.com/daily-news/stakeholders-weigh-ai-considerations-cybersecurity-nist-workshop-draft-framework-profile Guest Bio Sara Friedman is the managing editor of Inside Cybersecurity and has covered federal cybersecurity policy for years, including CIRCIA, NIST standards, and related rulemakings.

  31. 97

    Deepfakes & Laptop Farms: How Nation-States Infiltrate the Defense Supply Chain with Luke McNamara

    Cyber threats against the Defense Industrial Base (DIB) don't stop at the battlefield—they extend into suppliers, perimeter devices, and even hiring pipelines. Luke McNamara of Google's Threat Intelligence Group joins Frank Cilluffo to unpack Mandiant's report Beyond the Battlefield: Threats to the Defense Intelligence Base and the patterns it flags across today's threat landscape. They discuss how the war in Ukraine is shaping targeting priorities, why China's cyber espionage increasingly begins at the network edge, and how "fast follower" exploit cycles compress patch timelines. McNamara also explains the North Korean IT worker problem, where remote hiring fraud can create both revenue and potential access pathways. The takeaway for mid-sized defense suppliers is practical: harden identity, reduce perimeter exposure, and assume meaningful risk often starts outside traditional corporate visibility. Main Topics Covered Why manufacturing remains a top target and a warning sign for broader supply-chain risk How the war in Ukraine is influencing cyber targeting tied to drones and UAS ecosystems China's focus on edge-device compromise (VPNs, routers, email gateways) and why it matters The "fast follower" dynamic that turns one vulnerability into many intrusions North Korean IT worker operations, remote hiring fraud, and AI-enabled deception The highest-leverage defensive priorities for DIB organizations, especially identity and MFA Key Quotes "Manufacturing is always the most targeted sector going back to 2020. And I think that's a larger canary in the coal mine." ­­— Luke McNamara "It's not just some of these top-tier Chinese APT actors and their ability to leverage these as a zero-day, but the ability for secondary groups, once some of the details leak around a particular vulnerability, to start weaponizing it themselves." — Luke McNamara "If I had to narrow it down to one category to put more resources to, I would say identity…hardening around the identity piece is certainly key." — Luke McNamara "Organizations that are more aware of [the North Korean IT worker infiltration], where the security teams have met with their HR folks, their recruiters, helped inform them about the nature of these threats, I think they're a little bit better secured." — Luke McNamara "It sounds more like a movie than reality, but it's happening." — Frank Cilluffo Relevant Links and Resources Mandiant report — Beyond the Battlefield: Threats to the Defense Intelligence Base Mandiant podcast — Defenders Advantage Guest Bio Luke McNamara is a Deputy Chief Analyst at Google Cloud's Mandiant Intelligence and part of Google's Threat Intelligence Group, focused on cyber threat trends and emerging risks.

  32. 96

    Botnets, Edge Devices, and AI: Inside Forescout's Threat Findings with Daniel dos Santos

    A new wave of cyberattacks is being routed through everyday devices—and defenders can't rely on old assumptions about geography or "known bad" infrastructure. Daniel dos Santos, VP at Vedere Labs (Forescout), walks through findings from their 2025 Threat Roundup, drawn from a global network of hundreds of honeypots and decoy systems. The conversation focuses on why web-facing systems and edge devices have become prime targets, how attackers hide inside cloud and ISP-managed networks, and what defenders can do earlier in the kill chain. Dos Santos also explains why many exploited vulnerabilities never appear on CISA's KEV list—and how security teams should think about patching and risk anyway. Main Topics How honeypots reveal attacker intent across IT, IoT, and OT environments. Why attacks increasingly come from ISP-managed networks and consumer devices. Cloud and "benign" services used to blend in and evade traditional filters. Why distributed botnets weaken country-based blocking for defenders. The rise of web-facing exploitation and the shift away from stolen passwords. Edge devices, OT exposure, and why "discovery" dominates post-breach activity. Key Quotes "We have hundreds [of honeypots] throughout the world. Some of them are simulations… Some of them are real devices… we expose them with the intention of seeing them attacked." — Daniel dos Santos "Home routers, but also home IP cameras or doorbells or solar inverters or…whatever it is that you have in your house that might be exposed to the internet and might be vulnerable can be these days recruited into a botnet." — Daniel dos Santos "Attackers…have figured out that when you find a zero-day in a popular router or a popular firewall or a popular VPN appliance, you can really go against thousands and thousands of organizations." — Daniel dos Santos "With one zero-day or one critical exploit, you can compromise thousands of organizations today." — Daniel dos Santos "But what we do see in the signals that we see there and what we present in the report is that there is a whole world of vulnerabilities being exploited." — Daniel dos Santos Relevant Links and Resources https://www.forescout.com/research-labs/2025-threat-roundup/ https://www.forescout.com/blog/anatomy-of-a-hacktivist-attack-russian-aligned-group-targets-otics/ About the Guest: Daniel dos Santos is the VP of Research at Forescout Research — Vedere Labs, where he leads a team of researchers that identifies new vulnerabilities and monitors active threats. He holds a PhD in computer science, has published over 35 peer-reviewed papers, has found or disclosed hundreds of CVEs — and is a frequent speaker at security conferences.

  33. 95

    Storms, Cyber, and the Fight to Keep the Lights On with Scott Aaronson

    Grid resilience has become a test of whether the U.S. can keep essential systems running through disruption—and recover fast when they don't. In this episode, Frank Cilluffo talks with Scott Aaronson about how the electric power sector plans for and responds to an "all-hazards" landscape, from major storms to cyber and physical attacks. Aaronson explains why the grid is a "network of networks" with a huge attack surface but few true single points of failure, and how mutual assistance became a national-scale capability. They also dig into interdependencies across "lifeline" sectors, the practical reality of IT/OT differences, and why surging demand—from AI and data centers to EVs and reshoring—raises urgent reliability and supply chain questions. Main Topics Covered Why electricity is consumed the moment it's produced—and why balance matters. How mutual assistance evolved from bilateral help to national-scale response. Lessons from severe weather events, including what makes ice storms uniquely hard. The IT vs. OT gap, and why operational tech changes the cyber playbook. Interdependencies: why adversaries can hit electricity by targeting other sectors. Rising demand and the push to rebuild domestic manufacturing capacity for grid equipment. Key Quotes "Electricity is the only commodity that is consumed at the moment it is produced." – Scott Aaronson "[Power companies] are competitive in some ways, but we are completely non-competitive when it comes to security, when it comes to resilience, when it comes to response and recovery." – Scott Aaronson "I don't really care if it is a storm or a pandemic or a cyber or physical attack or the zombie apocalypse… The impact is what matters." – Scott Aaronson "The adversary is not attacking the electric sector. They are attacking the United States." – Scott Aaronson "The first 72 are on you… Have food, have water, have a plan, be prepared. The cavalry is coming." – Scott Aaronson "Regulations are great, but they are a foundational level of security… if you mandate… a 10-foot fence… the adversary brings a 12-foot ladder." – Scott Aaronson Relevant Links and Resources Edison Electric Institute (EEI) Electricity Subsector Coordinating Council (ESCC) CRISP (Cyber Risk Information Sharing Program) STEP (Spare Transformer Equipment Program) ESF-12 (Emergency Support Function 12 – Energy) About the Guest Scott Aaronson is Senior Vice President for Energy Security and Industry Operations at Edison Electric Institute (EEI) and Secretary of the Electricity Subsector Coordinating Council (ESCC), serving as a key industry-government liaison on power-sector security and preparedness.

  34. 94

    How Apple's iPhone Supply Chain Built China into a Manufacturing Superpower with Patrick McGee

    Supply chains are essential infrastructure—and the iPhone's supply chain sits at the center of U.S.–China competition. As Washington reassesses economic security, this episode explores what it looks like when market incentives collide with geopolitical reality. Frank Cilluffo speaks with Patrick McGee, author of Apple in China, about his reporting on Apple's deep manufacturing reliance on China—and what that reveals about leverage, resilience, and risk. They explore how industrial capacity is built through repetition, why diversification is harder than headlines suggest, and how concentrated production creates choke points that can ripple far beyond consumer tech. The result is a clear, practical case study in why supply chains matter for critical infrastructure, national security, and long-term competition. Main Topics Covered How "learning by doing" powered China's rise in high-end electronics manufacturing The "epic transfer of technology" behind Apple's scale and China's supply-chain competence Xi Jinping's post-2013 pressure campaign and Apple's strategic recalibration in China Why supply-chain diversification is slower than headlines suggest, especially in India The "red supply chain" and how Apple suppliers became capability multipliers Taiwan/TSMC as a single-point-of-failure risk—and the AI chip-export debate it echoes Key Quotes "China isn't dependent on Apple in the way that Apple is inarguably dependent on China. My big worry in a certain sense is that the student has become the master." — Patrick McGee "If you just take the $55 billion that they invested in 2015 alone, which was 22% of revenue … and just go from let's say the birth of the iPhone 2007–2025, you're talking about a trillion dollars that Apple's invested in China." — Patrick McGee "None of those phones are really being made in India, they're just being assembled there. The joke that one manufacturing design engineer told me was that the phones are assembled in China, disassembled in China and sent to India for reassembly." — Patrick McGee "Our narrative is essentially that Apple exploits Chinese workers. In a certain sense, that's the only narrative about Apple in China we've had in the past two decades. And I flip that on its head…[China is] getting more out of the relationship. It's a story about China exploiting Apple. — Patrick McGee "I think there still is a mindset that China is an imitator, not an innovator. I think we should recognize that… is not the case." — Frank Cilluffo Relevant Links and Resources Apple in China (Patrick McGee's book) McCrary Institute' Code Red report on "Typhoon" threat actors (Vault/Salt/Flax) Anthropic's Dario Amodei's essay: "The Adolescence of Technology" Guest Bio Patrick McGee is a Financial Times journalist and the author of Apple in China, covering geopolitics, technology, and global supply chains.

  35. 93

    AI, Critical Infrastructure, and Cascading Failures with Madison Horn

    Madison Horn joins host Frank Cilluffo to explain why AI-driven cyber risk may be quieter, faster, and harder to spot in 2026. She breaks down "cascading failures" in critical infrastructure—and how a disruption in one sector can quickly ripple into others. The conversation zeroes in on AI agents, especially their ability to create new user accounts, get access to systems, and hide inside everyday routine activity. Horn also warns that AI supply chain weaknesses could spread faster than traditional zero-days.   Main Topics Covered  Why AI-enabled attacks may look like normal business activity.  Cascading failures across water, power, telecom, and healthcare systems.  AI agents creating identities and operating with "human-like" access.  Why "AI supply chain" risk could eclipse zero-day exploits.  "Slow and steady" AI adoption for critical infrastructure operators.  Why quantum planning should happen alongside today's AI rollouts.   Key Quotes "Within critical infrastructure… water needs electricity, electricity needs telcos, and healthcare needs all three." —Madison Horn "Hackers are lazy. And I mean that not to be offensive, but if you can reach your objective, reaching the lowest hanging fruit, then you're going to." —Madison Horn "Attacks are not going to look as restricting and as loud. I think it's going to look just like business as normal until we see [impacts] in the physical world." — Madison Horn "What I worry about is people assuming and trusting that an AI tool is doing what it's supposed to and not necessarily understanding or being able to detect that it's doing something malicious." — Madison Horn "I just don't want quantum to get lost into the AI conversation." — Madison Horn Relevant Links and Resources Madison Horn's 2026 predictions (Nextgov) About the Guest  Madison Horn is the national security and critical infrastructure chief advisor at World Wide Technology, with 15+ years leading cyber strategy and incident response in high-consequence, regulated environments. She previously held senior roles at Siemens Energy, PwC, and Accenture Security, and founded Roserock Advisory Group focused on cybersecurity and geopolitics.

  36. 92

    Cyber Leadership, Workforce Morale, and the House Email Breach with Nextgov's David DiMolfetta

    CISA leadership, NSA/Cyber Command staffing, and offensive cyber operations are colliding early in 2026. Frank Cilluffo and reporter David DiMolfetta unpack Sean Plankey's renomination for CISA Director, and what a prolonged leadership vacuum can mean for agency direction and momentum. They then turn to Lt. Gen. Rudd's confirmation hearing and the evolving debate over the Title 10/Title 50 "dual hat." The conversation also examines morale and workforce pressures inside NSA, including reported staffing reductions. It closes with "Absolute Resolve," what public discussion of cyber "effects" might signal for deterrence, and a China-linked House staff email breach that frames what Molfetta is watching next.  Main Topics Covered What Sean Plankey's CISA renomination signals about cyber leadership priorities. Why "core mission" talk at CISA still depends on who's in charge. Lt. Gen. Rudd's hearing, and how the dual-hat debate is evolving. NSA morale and workforce cuts, and what that means for capability. "Absolute Resolve," cyber effects, and the deterrence value of public signaling. House staff email targeting, Salt Typhoon questions, and the midterms-AI threat mix. Key Quotes "Cisa's work does not stop. That said, if you don't have a permanent leader in place, you don't have a guy to set direction, and things can't really go anywhere." — David DiMolfetta "When you don't have people at their desks [because of workforce reductions], that means they may not be tracking adversaries, they may not be doing that work to cultivate relationships with sources on a kind of human intelligence style level. — David DiMolfetta "[In Venezuela] lights went off, but they also went back on." — David DiMolfetta "Authority, accountability, and resources — I found those to be the three criteria to get things done in D.C." — Frank Cilluffo Relevant Links and Resources David DiMolfetta's stories at Nextgov.com Guest Bio: David DiMolfetta covers cybersecurity for Nextgov. Previously, he researched The Cybersecurity 202 and The Technology 202 newsletters at The Washington Post and covered AI, cybersecurity and technology policy for S&P Global Market Intelligence. He holds a BBA from The George Washington University and an MS from Georgetown University.

  37. 91

    The Hammer and the Anvil: Offensive Cyber Strategy with Chris Inglis

    Chris Inglis joins Frank Cilluffo to break down what offensive cyber strategy should look like in an era of strategic competition. Drawing from the McCrary Institute's new report on U.S. cyber policy, Inglis argues that resilience and consequences are not competing theories—they have to work together. He explains why "defend forward" and persistent engagement reshaped authorities and expectations after 2018, including how NSPM-13 changed delegation for operations. The conversation also tackles the messy seam between Title 10 and Title 50 in cyberspace, and why integration—not exquisite tools—will decide whether cyber power is truly strategic. Main Topics Covered Why offense and resilience must operate as one integrated cyber strategy Cyber deterrence as changing an adversary's decision calculus, not perfection How NSPM-13 helped shift delegation and operational tempo in 2018 What "defend forward" means in plain terms—and why it's defensive Blurring of Title 10 and Title 50 in cyberspace—and why that matters The warning: the U.S. is behind on integrating cyber with power Key Quotes "My view is that the discussion of whether it's going to be a focus on defense kind of inherent resilience or a focus on imposing consequences is a false choice." — Chris Inglis "But when you get to cyberspace, it turns out that the Title 50, which is trying to get information from cyberspace, and the Title 10, which is trying to actually achieve effects in cyberspace, are about 90% the same." — Chris Inglis "[With defend forward] We're not going to wait onshore for [malicious cyber activity] to arrive and then kind of cede the initiative to adversaries." — Chris Inglis "What keeps me awake at night? We don't have time. We're way behind the curve." — Chris Inglis Relevant Links and Resources McCrary Institute report — U.S. Cyber Policy: Offense, Deterrence, and Strategic Competition Guest Bio Chris Inglis is the former U.S. National Cyber Director and former NSA Deputy Director, with decades of experience in national security and cyber policy.

  38. 90

    Are We Ready for 2026? Top Cyber Predictions on Policy, Tech, and Threats

    Cyber Focus kicks off 2026 (and its 100th new episode) with rapid-fire predictions from McCrary Institute senior fellows. They flag big policy inflection points—especially whether Congress can reauthorize "CISA 2015," sustain information-sharing protections, and keep state and local cybersecurity funding on track. Tech-wise, the group focuses on AI's accelerating integration, the "speed" divide between defenders and adversaries, and emerging pressures across connectivity and infrastructure. On threats, they warn about deepfake-driven social engineering, ransomware that's getting faster and more accessible, "typhoon" intrusions, and the compounding risk of encryption and security tech debt. Main Topics Covered CISA 2015 reauthorization, information sharing, and state/local cyber funding priorities. Cyber offense and deterrence: shaping adversary behavior by imposing real costs. AI everywhere: faster attacks, faster defense, and higher infrastructure stakes. Convergence and connectivity: data centers, wireless, subsea cables, satellite, and scale. Deepfake social engineering and shrinking ransomware dwell times in 2026. "Typhoon" intrusions, critical infrastructure exposure, and major-event targeting pressure. Key Quotes "What I believe is going to overtake identity just in general is deep fake social engineering. And that means the calls that look like your CEO that tell you to get on an urgent call right now... I think I'd click on that if I didn't know better. And a lot of us in the security realm would." — Cynthia Kaiser "We're actually getting the broader dividing line between haves and have nots... If you can't move fast, you're going to need to find someone who can... If you're someone that can't receive new information and immediately improve your defensive posture, you're probably a have not." — Matt Hayden "We're seeing and hearing that the US government is interested in taking the fight to the adversaries... shaping the adversary's behavior is important because it slows them down, it imposes costs on them, and perhaps it could lead to deterrence." — Christopher Roberti "I started with China and I'm going to end with China... making sure again, we don't take our eye off the ball that wow, there may be reasons to make deals economically with China. We have to treat them as a potential adversary." — Bob Kolasky "At the end of the day, I look at as the typhoon epidemic—Salt, Vault... What is the next typhoon we're going to uncover in 2026 that's going to be driving our cybersecurity defense measures?" — Bill Evanina Relevant Links and Resources https://mccraryinstitute.com/directory/senior-fellows/

  39. 89

    AI-Orchestrated Cyber Espionage and the Future of Cyber Defense with CISA's Nick Andersen

    AI is speeding up cyber operations and shrinking the window for defenders to respond. Nick Andersen, who leads CISA's Cybersecurity Division, explains why Anthropic's recent report caught attention: it described what Anthropic called the first publicly reported AI-orchestrated cyber espionage campaign, in which threat actors misused its Claude models to automate and scale parts of an intrusion. Andersen and Frank Cilluffo unpack what that signal means for resilience, from model safeguards to the infrastructure and people surrounding them. They apply secure-by-design thinking to frontier AI, stress risk ownership for adopters—especially in OT—and warn against silver-bullet claims. The conversation closes on what it takes to build capacity, including KEV-driven prioritization and CISA's Scholarship for Service pipeline. Main Topics Covered Why AI changes cyber defense through speed, scale, and attacker efficiency. What the "Anthropic/Claude" case signals about resilience for AI providers. Secure-by-design expectations for AI systems and the infrastructure around them. OT adoption: governance, data flows, and safety-first decision-making. Workforce and talent pipelines, including CISA's Scholarship for Service interns. Practical prioritization: vulnerabilities, KEV, and remediation at operational pace. Key Quotes:  "If we don't engage now in having a resilience conversation around our artificial intelligence companies, we're going to see a lot more of what, what happened with Claude, in this case." – Nick Andersen "The core principles regarding what we're focused on as cyber defenders don't necessarily change here, but the speed through which I think we can expect known vulnerabilities to be weaponized and exploited in the wild now that's going to change for us." – Nick Andersen "There is no silver bullet. Anybody who has a sales pitch they're receiving that says that this AI solution is going to solve all of your problems... they should immediately become exceedingly skeptical and start asking an awful lot of questions." – Nick Andersen "OT operators are going to have some really tough conversations coming up about what control are they willing to give away... We know within the OT environment safety and security has to come first." – Nick Andersen "Our adversary has a pretty clear-eyed view of what they're trying to achieve. And it is both the opportunities for, you know, discord and societal panic." – Nick Andersen Relevant Links and Resources House Hearing: The Quantum, AI, and Cloud Landscape: Examining Opportunities, Vulnerabilities, and the Future of Cybersecurity Anthropic Report: Disrupting the first reported AI-orchestrated cyber espionage campaign CISA: Principles for the Secure Integration of Artificial Intelligence in Operational Technology CISA: Scholarship for Service Guest Bio:  Nick Andersen serves as Executive Assistant Director for CISA's Cybersecurity Division, where he leads national efforts to defend against major cyber threats and improve the resilience of U.S. critical infrastructure. He previously held senior cyber leadership roles at the White House, the Department of Energy, and in intelligence roles for the Coast Guard and Navy.   

  40. 88

    Revisiting Offensive Cyber Discussion with Adm. Mike Rogers (Ret.)

    In this re-releases episode of Cyber Focus, host Frank Cilluffo sits down with Admiral Mike Rogers (Ret.), former Commander of U.S. Cyber Command and Director of the National Security Agency. Rogers shares insights from his leadership across two administrations, discussing offensive cyber operations, the evolution of Cyber Command, and pressing national security challenges. The conversation spans from undersea cable vulnerabilities to public-private integration, the future of quantum and AI, and the enduring need for clarity in cyber policy. A decorated Auburn alum, Rogers reflects on lessons learned, historical inflection points, and what must change for the U.S. to stay ahead in the cyber domain. Main Topics Covered: Shifting to a proactive cyber posture: persistent engagement and defend forward The evolving role of Cyber Command and comparisons to SOCOM Vulnerabilities in undersea cable infrastructure and space-like situational awareness Lessons from Ukraine on real-time public-private integration Strategic implications of AI and quantum technologies Key Quotes: "I believe that what [offensive cyber actions] we ought to authorize is not just going after infrastructure but directly going after capability within those nations that are generating these effects against us." — Adm. Mike Rogers "If you're going to deter an entity, they have to have some level of awareness of both [your] capability and intent." — Adm. Mike Rogers "If you had asked me five years ago when I left Cyber Command, would a foreign entity, in this case a nation-state, upload destructive malware into critical U.S. infrastructure in a time of peace?... I would have said to you… there's a low probability. Boy, I got that wrong." — Adm. Mike Rogers "I think it requires a little precision in how we discuss these matters. Because not all hacks are the same, not all hackers are the same, not all intentions are the same, not all capabilities are the same. [Not] everything is an 'attack'." — Frank Cilluffo "I'm not interested in collaboration; I'm interested in integration. I'm interested in a real-time situational awareness between government and the private sector." — Adm. Mike Rogers Relevant Links and Resources: U.S. Cyber Command – Mission and Vision https://www.cybercom.mil/About/Mission-and-Vision/ NSA – About the Agency https://www.nsa.gov/about/ Cyberspace Solarium Commission Final Report https://www.solarium.gov/report Guest Bio: Adm. Mike Rogers (Ret.) served as the Director of the National Security Agency and Commander of U.S. Cyber Command from 2014 to 2018. A four-star admiral with a distinguished 37-year career in the U.S. Navy, he helped shape modern cyber strategy at the highest levels of government. Since retiring from active duty, he has advised Fortune 500 companies, startups, and global institutions on cyber, intelligence, and national security issues.

  41. 87

    The Hidden Backbone of the Internet: Subsea Cable Security with Alex Botting

    Undersea cables quietly carry almost all global internet traffic yet rarely feature in security debates. This episode explains how subsea infrastructure underpins the global economy, data flows, and modern military operations while facing frequent "accidental" disruptions and growing geopolitical risk. Listeners hear why chokepoints, island dependencies, and hotspots from the Red Sea to the Taiwan Strait keep national security officials up at night. The conversation also explores how redundancy, smarter investigations, and faster permitting can harden this hidden backbone against both negligence and sabotage. Frank and Alex close by looking at AI, quantum, fiber sensing, and satellite backups as the next frontier for cable resilience and deterrence. Main Topics Covered Subsea cables as the physical backbone of global internet and finance. How outages happen, from ship anchors to suspected sabotage. Strategic chokepoints, island dependencies, and contested regions like the Red Sea. Building resilience through redundancy, permitting reform, and trusted infrastructure partners. New monitoring tools: fiber sensing, AI, and quantum for cable security. How governments and industry share intelligence and fund resilient capacity. Key Quotes: "Subsea cables carry the vast majority of Internet traffic around the world… Estimates vary from 95 to 99% of Intercontinental data traffic. So when you think about the Internet, subsea cables are the basis of the Internet." "Redundancy is our biggest defense… We have 100 cables coming into the US and therefore it makes it very hard to do anything meaningful in a short time frame to actually impact it. "Do I think our adversaries would want to do this [tap cables]? Yes... Do I think they can do it? Possibly. Do I think the juice is worth the squeeze? No, I don't." "There were more cable cuts in the Taiwan Strait in January of this year than either 2024 or 2023 in total. That is a sharp uplift at a time when we know that hostility in that part of the world is rising. I would be shocked if none of those incidents were knowingly done." "The entire Starlink... global capacity is equivalent to [only a few] subsea cable[s]... So when you talk about truly replacing [subsea cables], it's not there." Relevant Links and Resources Alex Botting paper "Shoring Up Subsea Security" for the Center for Cybersecurity Policy and Law. House Homeland Committee Hearing: An Examination of Foreign Adversary Threats to Subsea Cable Infrastructure Alex's Podcast: Distilling Cyber Policy Guest Bio: Alex Botting is the Senior Director of Global Security & Technology Strategy at Venable.  His career has focused on shaping policies at the intersection of security, technology & telecoms in more than 50 countries and multilateral organizations around the world. In November he testified before the House Homeland Security Committee about threats to the subsea cable infrastructure.

  42. 86

    The Army's "No Fail" Cyber Mission with Brandon Pugh

    Army Principal Cyber Advisor Brandon Pugh joins Frank Cilluffo to address a stark reality: if critical infrastructure fails, the Army cannot mobilize. To meet this "no fail" mission, Pugh explains how the service is aggressively merging cyber with electronic warfare and cutting red tape to field new technology in days rather than years. They also discuss the Army's unique edge in this digital fight—Reservists who bring high-level private sector expertise directly to the battlefield. The conversation also explores how AI and operational technology are reshaping the Army's cyber battlefield and threat landscape. Main Topics Covered • How Congress created the principal cyber advisor role and defined its authorities. • Army cyber's four focus areas: AI, defense critical infrastructure, acquisition, and workforce. • Integrating cyber, electronic warfare, RF, and information operations into Army warfighting doctrine. • Defending defense critical infrastructure and preparing for Volt Typhoon-style cyber disruptions. • Leveraging AI for continuous monitoring, faster detection, and protection of sensitive Army data. • Reforming cyber acquisition through FUZE prototypes, VC-style partnerships, and Guard and Reserve expertise. Key Quotes "Cyber is not an isolated capability. It's not something that just rests at Fort Gordon or Fort Meade." – Brandon Pugh "If an adversary goes after one of our military bases and we can't mobilize people, tanks, equipment in a time of conflict, that is a major concern… we can't accept the fact that cyber could be the barrier to our ability to do other military tasks." – Brandon Pugh "It's a national security imperative to leverage AI. We know adversaries are going to leverage AI or exploit our AI regardless of what we do here. We could put barriers in terms of aggressive regulation which some have proposed in the past or seek to slow it down. All that's going to do is help our adversaries." – Brandon Pugh "We have some individuals that show up their reserve weekend in $300,000-$400,000 vehicles because they are the experts in what they do as civilians. They have signed up and taken the oath because they want to serve this country. That is the talent we have in the Reserve and Guard that we need to continue to expand." – Brandon Pugh "We don't have to go through a multi-year acquisition cycle, spend millions of dollars where we've seen 3D printed drones for mere dollars in some cases being leveraged [in Ukraine]… We need some of these capabilities in a matter of days or weeks, not years." – Brandon Pugh Relevant Links and Resources • Jack Voltaic: Critical infrastructure resiliency • Army's FUZE Initiative Guest Bio Brandon Pugh is the Principal Cyber Advisor to the Secretary of the Army, advising the Secretary and Army Chief of Staff on cyber readiness, budget, capabilities, and strategy. He previously served as a director at the R Street Institute and continues to serve in the U.S. Army Reserve as a national security law professor, having earlier been a paratrooper and international law officer.

  43. 85

    Inside State Cyber Defense: Whole-of-State Security with Alabama's Daniel Urquhart and Chad Smith

    State and local governments are stepping up to defend critical services against fast-evolving cyber threats. In this episode of Cyber Focus, Alabama's top IT leaders show how they're staying ahead of the curve. They explain how a hybrid, highly decentralized environment forces them to lean on shared standards, SLCGP funding, and whole-of-state partnerships. Along the way, they unpack a recent incident that came dangerously close to crisis and what it revealed about tools, visibility, and trust. They also look ahead to AI-enabled attacks, deepfakes, and "distortion," and why automation and better intel will shape Alabama's next moves. Watch to see what other states, utilities, and local leaders can learn from Alabama's playbook.  Main Topics: How Alabama OIT governs technology across roughly 140 executive agencies in a mostly decentralized environment. Using SLCGP funds, shared contracts, and enterprise tools to lift up smaller municipalities that lack resources. Rethinking threat intelligence by pairing MS-ISAC and CISA feeds with deep knowledge of state business processes. Lessons from a major cyber incident, including incident-response retainers, tooling gaps, and the value of open communication. Building whole-of-state partnerships with CISA, FBI, utilities, National Guard, and the McCrary Institute through exercises and real incidents. Preparing for AI-enabled cyberattacks through automation, platform integration, and continuous upskilling for Alabama's cyber workforce. Key Quotes: "Cybersecurity is a team sport. It's not just one person. We're trying to build the community." — Daniel Urquhart "There's a huge concern that I have as we think about the amount of threats that are going to come at us from an AI enabled cyber attack. It is going to be so broad and so unlike anything that we've seen today." — Chad Smith "I think we have to be willing to talk about [a recent cyber incident] so that people can learn from it, but also so that people know, hey, they're actually doing something and things are happening in a way that we can respect."— Chad Smith "We try to do a lot of education and team building and building that cohesive whole estate approach by setting up technology demos and articulating the why." — Daniel Urquhart "We've done a really good job the last couple of years working with the FBI, Secret Service, National Guard. Those types of partnerships can make us stronger as a state." — Daniel Urquhart   Relevant Links and Resources ·       Alabama Office of Information Technology ·       Multi-State Information Sharing and Analysis Center   Guest Bios:  Daniel Urquhart is the Secretary of the Alabama Office of Information Technology. OIT is responsible for the strategic planning, governance, and resource utilization of all IT for the State of Alabama. Before joining OIT, he served as CIO for the Alabama Law Enforcement Agency, where he worked with industry partners to build a state-of-the-art criminal justice network. Chadwick Smith serves as the Chief Information Security Officer for Alabama's Office of Information Technology (OIT). Mr. Smith has worked in the technology industry for over twenty-five years. Prior to joining OIT, Chad worked in the insurance, banking, and data communications industries.

  44. 84

    The Hidden Dangers in Your Supply Chain with SecurityScorecard's Aleksandr Yampolskiy

    SecurityScorecard CEO Aleksandr Yampolskiy joins Cyber Focus to warn that third-party risk is now the dominant cybersecurity epidemic. With just 150 companies responsible for 90% of the global attack surface, a single compromise can ripple across sectors and continents. He and host Frank Cilluffo explore the cascading risks of software dependencies, fourth- and fifth-party exposure, and the challenges of shadow IT and shadow AI. Yampolskiy outlines where companies fall short on governance and calls for outcome-driven oversight, not just busywork. They also discuss how AI can be both a vulnerability vector and a force multiplier for defense. Main Topics Covered • Third-party breaches now account for 65% of cyber incidents globally • Only 150 companies comprise 90% of the global attack surface • The risks of shadow IT and "shadow AI" leaking sensitive data • Systemic vulnerabilities in critical infrastructure like U.S. ports and healthcare • Limitations of compliance-driven approaches without continuous risk measurement • The need for clear governance, outcome-oriented metrics, and board-level engagement Key Quotes "65% of data breaches today happen through use of a third party. Hackers go after one weak link." — Aleksandr Yampolskiy "150 companies' products comprise 90% of a global attack surface. So if one of those companies gets compromised, all of a sudden, you can compromise almost everybody." — Aleksandr Yampolskiy "You can be fully compliant with all the regulations, but not secure. Or you could be really secure but not compliant." — Aleksandr Yampolskiy "An employee takes [the] general ledger or... some sensitive corporate information, uploads it to ChatGPT—or worse, to [a model] in China—gets a beautiful response, looks like a champion... but then you just leaked sensitive information from a company and nobody knows about it." — Aleksandr Yampolskiy "Our ability to network has far outpaced our ability to protect networks." — Frank Cilluffo Relevant Links and Resources • SecurityScorecard Research Guest Bio Aleksandr Yampolskiy is the Co-Founder and CEO of SecurityScorecard, a global leader in cybersecurity ratings and risk management. A former CISO and CTO, he has led the company since 2014 in helping tens of thousands of organizations—including half of the Fortune 100—measure and strengthen their cyber resilience.

  45. 83

    CVE at a Crossroads: Global Standards, Local Failures, and What Comes Next with Nick Leiserson

    Cybersecurity veteran Nick Leiserson joins Cyber Focus this week to break down critical governance gaps in the Common Vulnerabilities and Exposures (CVE) system and what's at stake if they're not fixed. He and host Frank Cilluffo explore the risks of global fragmentation, the lingering fallout from the F5 breach, and why policy tools like Executive Order 14028 remain stalled. Leiserson warns that the U.S. court system faces an under-the-radar cyber crisis, and shares specific, actionable funding priorities Congress should tackle now. From software supply chain failures to operational coordination gaps, the episode provides a sharp look at what's missing in the federal cybersecurity response—and what can still be done to fix it. Main Topics Covered ·       Why CVE is the global "lingua franca" for vulnerabilities—and what happens if it fails ·       How a near-shutdown exposed CVE's fragile funding and governance model ·       The F5 breach and what it reveals about persistent risks in the software supply chain ·       Missed opportunities in EO 14028 and regulatory inertia in implementation ·       Why the U.S. court system breach is a cybersecurity crisis hiding in plain sight ·       Urgent spending needs: water system grants, K-12 cybersecurity, and court system defense Key Quotes "CVE... It's the universal language that we can all look at and understand what we're talking about. And today in 2025, we totally take that for granted." "The worst case is fragmentation. The second worst is [when] government comes in and says, we're going to supplant the expertise that's been built up over 25 years" —Nick Leiserson "[Some ask] 'Didn't we put a bunch of policy in place to stop SolarWinds?' The answer is we did. If you look at Executive Order 14028… it came out in the immediate aftermath of SolarWinds, and it has not been implemented." —Nick Leiserson "This is just one of those things that's vaguely terrifying, and it takes a lot to terrify me after 15 years in this space. But as best we can tell from public reporting, either there's been one continuous breach since 2020, or at least similar types of actors are continually being able to get into the federal court system." —Nick Leiserson "[F5 is] one of these bits of technologies that most people would not immediately wake up and say that's essential to our economy, our national security, our public safety. But it is." —Frank Cilluffo   Relevant Links and Resources Institute for Security + Technology report on CVE reform Executive Order 14028 – Improving the Nation's Cybersecurity  CISA's Known Exploited Vulnerabilities (KEV) Catalog FCC K–12 Cybersecurity Pilot Program   Guest Bio Nick Leiserson is Senior Vice President for Policy at the Institute for Security and Technology. He was a founding member of the Office of the National Cyber Director, where he led national cyber policy development and helped launch the National Cybersecurity Strategy Implementation Plan. Previously, he served as Chief of Staff to Rep. Jim Langevin and helped enact dozens of recommendations from the Cyberspace Solarium Commission. A longtime strategist on Capitol Hill and in the White House, Leiserson is known for translating complex tech policy into action on issues ranging from regulatory harmonization to software liability.

  46. 82

    Code Red: Breaking Down China's Cyber Offensive—Volt, Salt, and Flax Typhoon

    What do Volt Typhoon, Salt Typhoon, and Flax Typhoon reveal about China's cyber playbook? This episode of Cyber Focus breaks down a new McCrary Institute report on China's advanced persistent threat campaigns—and what they mean for U.S. national security. Frank Cilluffo sits down with Mark Montgomery, Brad Medairy, and Bill Evanina to explain how China is embedding itself in American infrastructure, telecom, and data systems. They warn that Beijing is laying the groundwork for future conflict and that the U.S. response has been dangerously slow. The guests call for stronger deterrence, better public awareness, and a renewed focus on the economic toll of cyber theft. Main Topics Covered China's long-term cyber threat strategy Volt Typhoon and infrastructure targeting Salt Typhoon and telecom espionage Flax Typhoon and persistent access Gaps in U.S. cyber deterrence Economic costs of IP theft Relevant Links and Resources McCrary Institute Typhoon Report Booz Allen October 2025 China report Key Quotes: "Each year we can say the threat has grown. And I would say the leading driver of that growth in the cyber threat environment in the United States is China." — Mark Montgomery "China is using cyberspace to project power. And as a nation, I think that we need to recognize this threat." — Brad Medairy (~05:50) "Until people believe that [China's cyber actions] matters to them, we're not going to get the kind of actions we need." — Mark Montgomery "China['s] … offensive cyber tradecraft is going to be AI enabled. They're going to be able to deliver effects and capabilities at pace that we never imagined. — Brad Medairy "I think the Chinese want not only us, but they want the world to know that they're inside… Xi wants… the world to know that he can do this." — Bill Evanina "We have to expeditiously get into place where we could harden ourselves so the railroad could work, the ports work, the electricity grids work. We're not ready. We're nowhere near ready." — Bill Evanina   Guest Bios: RADM Mark Montgomery (Ret.) is Senior Director of the Center on Cyber and Technology Innovation and a Senior Fellow at the Foundation for Defense of Democracies. He also serves as Executive Director of Cybersolarium.org, a nonprofit advancing the recommendations of the Cyberspace Solarium Commission, which he led from 2019 to 2021. Previously, he was Policy Director for the Senate Armed Services Committee under Senator John McCain, following a 32-year career as a nuclear-trained surface warfare officer in the U.S. Navy, retiring as a Rear Admiral in 2017. Bill Evanina is the Founder and CEO of the Evanina Group, where he advises corporate boards and CEOs on strategic risk, counterintelligence, and national security threats. He served as the first Senate-confirmed Director of the National Counterintelligence and Security Center (NCSC), leading U.S. government efforts to defend against espionage and foreign influence. A 24-year FBI veteran, Evanina held senior roles in both counterintelligence and counterterrorism and previously led the CIA's Counterespionage Group. He also chairs national and international security boards and is an instructor at the University of Chicago. Brad Medairy is an Executive Vice President at Booz Allen Hamilton, where he leads the firm's cybersecurity business and supports national-level clients including the FBI, DHS, DOD, U.S. Cyber Command, and the Intelligence Community. He focuses on protecting critical infrastructure, securing emerging technologies, and defending against advanced cyber threats. Medairy leads multidisciplinary teams that integrate AI, cloud, and cyber operations to deliver full-spectrum solutions. He has been recognized as a Top 50 Cybersecurity Leader and Cyber Executive of the Year, and holds degrees from UMBC and Johns Hopkins University.

  47. 81

    Fuel, Force, and the Frontlines: Critical Infrastructure in Conflict with Chris Cleary

    What if the easiest way to disrupt U.S. military operations isn't with missiles—but by targeting fuel logistics? In this episode, Chris Cleary explains how civilian infrastructure has become a frontline in national defense. He and Frank Cilluffo discuss how adversaries exploit cyber vulnerabilities to slow military response, and why deterrence requires more than just rhetoric. They unpack the case for a dedicated Cyber Force, the suprising way Chris thinks it should be structured, and the challenges of coordinating across government and industry. With prepositioned threats like Volt Typhoon in the headlines, the stakes are higher than ever. Main Topics Covered How fuel logistics shape U.S. military readiness in the Pacific Why adversaries target civilian infrastructure like water and power systems What defines a "cyber attack" under rules of engagement Gaps in deterrence, response, and public signaling The case for a U.S. Cyber Force modeled after the Coast Guard Challenges of coordination across agencies and private sector providers Key Quotes "I could degrade the Navy's ability to run around in the Pacific by just limiting the ability to move fuel on the west coast of the United States." — Chris Cleary "If [China's cyber forces] are in Littleton, Massachusetts, they're everywhere." — Chris Cleary "I would argue a cyber force of the future looks more like a Coast Guard than a Navy."— Chris Cleary "I am a true believer that cyber is a legitimate means and methods of warfare. And we are going to have to professionalize in it." — Chris Cleary "All the zero trust in the world is not going to stop—a China, a Russia, a sophisticated organization—from targeting you." — Chris Cleary Relevant Links and Resources 60 Minutes on China's Cyber Infiltation: https://www.cbsnews.com/news/china-hacking-us-critical-infrastructure-retired-general-tim-haugh-warns-60-minutes-transcript/ Guest Bio Christopher Cleary is Vice President of Global Cyber Practice at ManTech. He previously served as the Department of the Navy's Principal Cyber Advisor, where he led the implementation of the DoD Cyber Strategy across the Navy and Marine Corps. Prior to that, he was the Navy's Chief Information Security Officer and Director of Cybersecurity within the Department of the Navy CIO's office.

  48. 80

    Cyber Force, ROI, and the Case for Reform with Ed Cardon & Josh Stiefel

    Should the U.S. have a dedicated Cyber Force? In this episode, General Ed Cardon and Josh Stiefel examine persistent gaps in the nation's cyber posture, from undefined mission boundaries to unclear return on billions in cyber spending. They explore the organizational tradeoffs, workforce realities, and coordination challenges that have stalled progress, despite years of warnings. With host Frank Cilluffo, they unpack what it would take to move beyond patchwork solutions. Main Topics Covered The failure of past "wake-up calls" to drive meaningful cyber reform Gaps in command, control, and mission clarity across defensive cyber operations The case for a dedicated Cyber Force and what it would need to solve on day one Why workforce development—not just recruitment—is central to cyber readiness The role of metrics and return-on-investment in cyber spending The importance of establishing clear operational roles between NSA, CNMF, DC3, DCDC Key Quotes: "How many of these have we been through, these quote, unquote, watershed moments that were going to change everything? … How cataclysmic does an incident have to be to get us to actually move one way or the other? - Josh Stiefel "From 2020 to 2025, if you take all the budgets together, we've spent $29.9 billion on cyber operations. That's as much as two Ford-class aircraft carriers. Do we have the equivalent combat capability in cyberspace as two Ford-class carriers? I'd argue no." - Josh Stiefel "[Cyber Com] just is not where it needs to be. It's doing great work, but not at the scale and breadth that we know we're going to need. – Ed Cardon "In my experience, we tend to study [decisions like standing up a Cyber Force] for a couple of years before we implement it. We don't have that kind of time." – Ed Cardon "Each one [of the typhoons] is a really bad day. Collectively, it's the perfect storm. And the fact that we at least publicly haven't made it a much bigger set of issues is going to send a signal to all of our adversaries that this is okay." – Frank Cilluffo Relevant Links and Resources CSIS Cyber Force Commission: https://www.csis.org/programs/strategic-technologies-program/projects/commission-us-cyber-force-generation Guest Bios: Joshua Stiefel is the former Professional Staff Member on the House Armed Services Committee, where he oversaw cyber and IT policy, operations, and procurement. He previously served as Senior Cyber Policy Advisor at the Department of the Treasury, leading sector-wide cybersecurity initiatives and authoring its first vulnerabilities study. A former DoD intelligence officer who deployed with Special Operations Forces in Iraq, he now serves in the U.S. Navy Reserve. He is a Term Member of the Council on Foreign Relations and holds degrees from Harvard and Lehigh. Lt. Gen. Edward Cardon (Ret.) served 36 years in the U.S. Army, including as Commanding General of Army Cyber Command, where he built it into a world-class force with 41 cyber mission teams. He later directed the Army Office of Business Transformation, helping establish Army Futures Command. His career also included leading the 2nd Infantry Division in South Korea and multiple combat deployments. Today, he is a Senior Counselor at The Cohen Group and advises defense and technology organizations.

  49. 79

    Inside In-Q-Tel: Investing in America's Cyber Future with Katie Gray

    Katie Gray, a senior partner at In-Q-Tel, joins host Frank Cilluffo to pull back the curtain on the venture firm's role in advancing U.S. national security through tech innovation. As head of In-Q-Tel's cyber investment practice, Gray offers rare insight into the organization's dual-use investment model, its evolving priorities, and the technologies it believes will define the next 25 years. They discuss how In-Q-Tel identifies emerging threats, evaluates startups, and bridges the gap between cutting-edge technology and urgent government needs. Topics include AI, quantum, cyber-physical security, and the vulnerabilities shaping today's threat landscape. The conversation also highlights In-Q-Tel's unique role as both strategic investor and national security partner. Main Topics Covered In-Q-Tel's origin, mission, and evolution beyond the intelligence community How In-Q-Tel identifies promising startups and matches them with agency needs The shifting threat landscape in cyber, including Volt Typhoon and AI-driven attacks Investment priorities in space, supply chain security, and operational technology The dual-use tech model and building resilience at machine speed A case study: VulnCheck and its impact across multiple government agencies Key Quotes "We are dramatically under invested as a nation in our cyber defenses… as we look to the future conflict, we're so vulnerable from a cybersecurity standpoint. " – Katie Gray "[For] every dollar that In-Q-Tel invests in a company, there's $40 that are invested from the private sector." – Katie Gray "One of the things we do look for is to try and fund dual-use technology that has strong commercial [and] government market." – Katie Gray "We're going to be in a world where 80-90% of the code that is being written is being written by AI systems. – Katie Gray "We can't be responding to [AI-driven cyber attacks] at human speed. We have to be responding to that at machine speed." – Katie Gray Relevant Links and Resources https://www.iqt.org/mission https://mccraryinstitute.com/time-to-designate-space-systems-as-critical-infrastructure/ Guest Bio Katie Gray is a senior partner at In-Q-Tel, where she leads the organization's cyber investment practice and supports mission-driven innovation across the U.S. national security landscape. She previously spent more than a decade in software product management, leading development for mobile devices at Palm, HP, and Plastic Logic.

  50. 78

    How Scammers Exploit Trust and FOMO: Kicking Off Cybersecurity Awareness Month with Lisa Plaggemier

    Lisa Plaggemier, Executive Director of the National Cybersecurity Alliance, joins host Frank Cilluffo to discuss how public education can combat online scams, fraud, and cyber threats. With billions of campaign impressions and only a nine-person team, the Alliance focuses on motivating behavior change through creative, jargon-free outreach. Plaggemier explains how scams like pig butchering are orchestrated by organized crime and even nation-state actors—and why the U.S. needs a coordinated national response. The episode highlights the growing need for cross-sector data sharing, targeted messaging for seniors, and a "scam czar" to unite fragmented efforts. As Cybersecurity Awareness Month kicks off, the conversation underscores how individual actions and shared responsibility can help close critical gaps in digital safety. Main Topics Covered • The mission of the National Cybersecurity Alliance and its consumer-focused campaigns • Core Cybersecurity Awareness Month themes: MFA, passwords, updates, and scams • Reaching overlooked populations through creative outreach like Kubikle and safe-word campaigns • The scale and structure of online scams like pig butchering and their ties to nation-state actors • The call for a national "scam czar" to coordinate public-private response • Challenges in cross-sector data sharing and the limits of current fraud response models • Upcoming efforts to reach K-12 audiences and improve campaign impact across age groups Key Quotes "We are a tiny nonprofit of nine people and we reach billions of people every October." — Lisa Plaggemier "I can hack away at our banks and probably not come away with any cash. [But] I can hack away at individual customers of the bank and come away with millions of dollars, and there's no ISAC for my mom." — Lisa Plaggemier "I do not think it would be a bad idea if we had a scam czar at this point because the adversary is so well organized." — Lisa Plaggemier "Older folks are targeted less often, but when they fall victim, the dollar amounts are very high. They have their whole life savings at stake." — Lisa Plaggemier "We've got in a lot of organizations, fraud teams that don't talk to security teams that don't talk to trust and safety teams. And so if you're still siloed in your organization, I think the call to action here is that that all needs to be seen as one." — Lisa Plaggemier Relevant Links and Resources National Cybersecurity Awareness – staysafeonline.org Then & Now: Helping Older Adults Stay Secure Kubikle Series Guest Bio Lisa Plaggemier is Executive Director of the National Cybersecurity Alliance, where she leads efforts to make cybersecurity practical and accessible. She describes herself as "on a crusade to eliminate stock photos of hackers in hoodies," underscoring her focus on real-world education over clichés. A former Ford Motor Company marketing executive, she now serves on the U.S. Secret Service Cyber Investigations Advisory Board and is based in Austin, Texas.

Type above to search every episode's transcript for a word or phrase. Matches are scoped to this podcast.

Searching…

We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.

No matches for "" in this podcast's transcripts.

Showing of matches

No topics indexed yet for this podcast.

Loading reviews...

ABOUT THIS SHOW

As cyber threats evolve faster than policy, Cyber Focus delivers executive-level briefings on cybersecurity, national security, and critical infrastructure. From the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University, host Frank Cilluffo speaks with senior leaders across government, industry, and the intelligence community about ransomware, state-sponsored threats, AI, and the systems we all rely on—energy, water, telecom, and supply chains. Each episode focuses on real-world risk tradeoffs and practical steps organizations can take to strengthen resilience.

HOSTED BY

Frank Cilluffo / McCrary Institute

Produced by McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University

CATEGORIES

Frequently Asked Questions

How many episodes does Cyber Focus: Cybersecurity, National Security, and Critical Infrastructure have?

Cyber Focus: Cybersecurity, National Security, and Critical Infrastructure currently has 50 episodes available on PodParley. New episodes are automatically indexed when they're published to the podcast feed.

What is Cyber Focus: Cybersecurity, National Security, and Critical Infrastructure about?

As cyber threats evolve faster than policy, Cyber Focus delivers executive-level briefings on cybersecurity, national security, and critical infrastructure. From the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University, host Frank Cilluffo speaks with senior leaders...

How often does Cyber Focus: Cybersecurity, National Security, and Critical Infrastructure release new episodes?

Cyber Focus: Cybersecurity, National Security, and Critical Infrastructure has 50 episodes. Check the episode list to see recent publication dates and frequency.

Where can I listen to Cyber Focus: Cybersecurity, National Security, and Critical Infrastructure?

You can listen to Cyber Focus: Cybersecurity, National Security, and Critical Infrastructure on PodParley by clicking any episode. We provide an embedded audio player for direct listening, and you can also subscribe via your preferred podcast app using the RSS feed.

Who hosts Cyber Focus: Cybersecurity, National Security, and Critical Infrastructure?

Cyber Focus: Cybersecurity, National Security, and Critical Infrastructure is created and hosted by Frank Cilluffo / McCrary Institute.
URL copied to clipboard!