Podcast charts
Published by Frank Cilluffo / McCrary Institute
As cyber threats evolve faster than policy, Cyber Focus delivers executive-level briefings on cybersecurity, national security, and critical infrastructure. From the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University, host Frank Cilluffo speaks with senior leaders across government, industry, and the intelligence community about ransomware, state-sponsored threats, AI, and the systems we all rely on—energy, water, telecom, and supply chains. Each episode focuses on real-world risk tradeoffs and practical steps organizations can take to strengthen resilience.
On the charts
Every published chart this podcast appears in, in the snapshot behind this page. Each one links to the chart it came off.
From the feed
The latest episodes published to this podcast’s own RSS feed. Titles and descriptions are the publisher’s.
The federal government wants private companies to play a more active role in cyber operations. A new White House memo would allow vetted firms to support government action against transnational criminal groups. The plan marks a shift from sharing threat data to disrupting threats together. But key questions remain: Who controls the mission? Who carries the risk? Where does private support end and government authority begin? Stacy O'Mara joins Frank Cilluffo to discuss those questions. They examine oversight, liability, AI and critical infrastructure. O'Mara also draws lessons from SolarWinds and the war in Ukraine. Her bottom line: Trust must exist before a crisis, and new programs must be tested before they are scaled. Main Topics Covered New rules for private cyber operations From information sharing to joint action Authority, oversight and private-sector risk AI, critical infrastructure and human judgment Trust and readiness before a crisis Key Quotes "We can put all these partnerships in place, create a 70-page memo on how to do it. But at the end of the day, if there's a significant event, it's going to be the leadership of major ISPs, telecoms, and cybersecurity providers who are picking up the phone and calling each other in the middle of the night." — Stacy O'Mara "My gut tells me it is going to take a serious incident, and it would probably include loss of life. …But until we actually go through it and suffer some of the consequences, I don't know that we'll actually be able to put everything into place " — Stacy O'Mara "It can't just be: 'We're going to collaborate, and we're going to do all these things together because we're scared and we don't know what's coming.' But it needs to be: 'What are our desired outcomes?'" — Stacy O'Mara "You want AI to perform operations—or activities, rather—at speed and scale. But the human aspect should be around judgment and consequences. That should not be left up to AI." — Stacy O'Mara "Pilot these programs. Get a win. Figure out what works and doesn't work. And then replicate it and scale it. We don't have to do everything all at once." — Stacy O'Mara Relevant Links and Resources White House memorandum: Expanding Capabilities to Combat Transnational Cyber-Enabled Crime CISA Gold Eagle initiative Armadin Guest Bio Stacy O'Mara leads government affairs at Armadin. She previously held cybersecurity policy and government affairs roles at FireEye, Mandiant and Google. She later advised technology companies at Venable.
Twenty-five years after the September 11 attacks, former Homeland Security Secretary Michael Chertoff joins Frank Cilluffo for a firsthand account of that day and the national security transformation that followed. Chertoff recalls arriving at the FBI command center as the attacks unfolded, hearing the order to shoot down the fourth plane and confronting the urgent question of whether more attacks were coming. He also describes the information-sharing barriers exposed by 9/11 and the effort to bring agencies with different missions and cultures together under the newly created Department of Homeland Security. The conversation then turns to the threats facing the country today. Chertoff explains why terrorism has become more distributed and difficult to detect, how cyberattacks and artificial intelligence are changing homeland security, and why the United States must remain vigilant without treating every risk as something that can be eliminated entirely. Main topics Michael Chertoff's memories of September 11 Building DHS and breaking down information silos How the terrorist threat has evolved Cyber, AI and critical infrastructure Vigilance and managing risk Key quotes "Within minutes after I arrived, we heard about the third plane hitting the Pentagon, and then I remember sitting in the command center and hearing the order being relayed to shoot down the fourth plane." — Michael Chertoff "If you don't coordinate at the federal level, you run the risk of again having another missed opportunity to stop a terrorist attack." — Michael Chertoff "We've undermined those big terrorist organizations, but now we have very small networks or even individuals who are acting because they're being prompted or even on their own, they're getting radicalized." — Michael Chertoff "The distributed nature of terrorism now, and the fact that we now have domestic terrorists, indigenous to the U.S., means that the process of detecting is much more difficult." — Michael Chertoff "The problem has not gone away. It's simply altered and modified and evolved." — Michael Chertoff "What you have to do is manage the risk by understanding what's a reasonable amount of risk you have to tolerate." — Michael Chertoff Links and resources About the Guest Michael Chertoff served as U.S. secretary of homeland security from 2005 to 2009, following roles as a federal appeals court judge and assistant attorney general for the Justice Department's Criminal Division. He previously supervised the Justice Department's investigation into the 9/11 attacks and is the author of Exploding Data: Reclaiming Our Cyber Security in the Digital Age. He is now co-founder and executive chairman of the Chertoff Group, a global security risk management and advisory firm.
Cybersecurity has spent decades in a reactive cycle: find a vulnerability, patch it and wait for the next one. Dr. Patrick Lincoln joins Frank Cilluffo to discuss DARPA's effort to break that cycle by building systems that are inherently secure, private and resilient from the start. They explore lessons from the AI Cyber Challenge, the role of mathematical proof in eliminating vulnerabilities and the challenge of making complex systems trustworthy even when individual components fail. The conversation also examines how research can move beyond isolated demonstrations to strengthen the technologies and infrastructure society increasingly depends on. Main Topics Preventing and providing technological surprise IPTO's return to computer science foundations Inherent security and privacy AI-enabled vulnerability discovery and patching Formal methods and mathematical proof Trust and resilience in megasystems Moving research into real-world use Key Quotes "This back and forth or cat and mouse game has been going on a long time. I'm getting tired of that. And so we're trying to find new foundations to build inherently secure systems and inherently private systems." — Patrick Lincoln "We need power tools to let people do more, better, faster, with quicker reaction time and higher assurance that what they do actually does lead to really fixing the problem and not creating new problems, not causing harm to the system." — Patrick Lincoln "Software is difficult . And so how can you get to high assurance for a complex system involving the analog systems, the sensors and actuators, the digital systems and hardware, and the digital systems and software ? And there are processes for this, some of those involving mathematical proof and formal methods ." — Patrick Lincoln "If you've got a million subsystems, there will be failures, and perhaps some of them even maliciously so . ... By building these compositional—think internal firewalls—within a complex system, and ways that we can understand the emergent properties of a large collective of systems, ... we can then predict and therefore give assurance about its behavior long term ." — Patrick Lincoln "My favorite answer to this problem, the world's most urgent critical problem, I'll say the DARPA answer is improving our collective ability to solve urgent critical problems." — Patrick Lincoln Links and Resources DARPA Information Processing Techniques Office Patrick Lincoln biography DARPA AI Cyber Challenge PROVERS formal-methods program Resilient Software Systems Capstone About the Guest: Patrick Lincoln is director of the Information Processing Techniques Office at DARPA, where he leads work spanning artificial intelligence, cybersecurity and privacy, and resilient complex systems. Before joining DARPA, Lincoln held senior research leadership roles at SRI, an independent nonprofit research and development institute, where he led multidisciplinary work across computing, cybersecurity, artificial intelligence, and advanced systems research. Lincoln holds a Ph.D. in computer science from Stanford University and a B.S. in computer science from MIT.
If communications fail and operational technology is damaged during a cyber attack, critical infrastructure operators may have to keep essential services running without internet access, outside assistance or readily available replacement hardware. Matt Rogers of the Cybersecurity and Infrastructure Security Agency (CISA) explains how CI Fortify prepares water, energy and transportation systems for that scenario. He and Frank Cilluffo discuss operating through compromise, uncovering hidden dependencies and testing whether critical systems can isolate and recover before a crisis arrives. Main Topics CI Fortify and emergency planning Operating through compromise Communications outages Hidden IT/OT dependencies Isolation and functional testing OT sovereignty Secure by Design for OT Public service and technical talent Key Quotes "If there is another Colonial Pipeline type incident again... how do we make sure that their incentive structure isn't I go from 100 to 0, it's that I go from 100 to 30? 40, where that... X is defense critical infrastructure, it's health and public safety, because we just can't afford to go to zero for our minimal services. We need sort of a minimum viable America." — Matt Rogers "Nobody is coming to save you unless you've prearranged to be saved, which is a bit grim. But in a communications outage, you can't call for help." — Matt Rogers "The more you tell me you have an air gap, the less I believe you... It's just really unsustainable for a lot of organizations.." — Matt Rogers "Security doesn't have to be frictional and hard. The goal should be to design security such that you are kind of the well-lit path, the easy path, the default state is the secure thing to do." — Matt Rogers Links and Resources CISA: CI Fortify CISA: Secure Connectivity Principles for Operational Technology CISA: Barriers to Secure OT Communication: Why Johnny Can't Authenticate CISA: Secure by Design About the Guest: Matthew Rogers, PhD is an Industrial Control Systems cybersecurity expert in CISA's Office of the Technical Director and leads the agency's Secure by Design initiative for Operational Technology. He earned his bachelor's degree in software engineering from Auburn University and later completed a DPhil in Cyber Security at the University of Oxford as a Rhodes Scholar, focusing on securing legacy OT networks in vehicles. Before joining CISA, Rogers was a founding engineer at Shift5 and worked on broader ICS cybersecurity efforts at MITRE. His work at CISA focuses on translating ICS research and development into practical capabilities for critical infrastructure.
The maritime world is more connected than ever, creating new efficiencies—and new ways for cyber incidents to move quickly from shore-based networks to ships operating around the globe. Rear Admiral Jason Tama, Commander of U.S. Coast Guard Cyber Command, joins Frank Cilluffo to explain how the Coast Guard operates across military, intelligence, law-enforcement, regulatory, and homeland-security missions to protect the Marine Transportation System and counter adversaries in cyberspace. The conversation also examines the Coast Guard's latest Cyber Trends and Insights in the Marine Environment report, including cyber operations aboard Dark Fleet vessels, the growing convergence of IT and operational technology, persistent weaknesses in basic cyber defenses, and the importance of working closely with industry. Tama argues that prevention alone will never be enough: maritime operators also need to be prepared to keep functioning through their "worst digital day." Main Topics Covered Coast Guard Cyber Command's three-part mission Title 10, Title 14, and Title 50 authorities Coast Guard integration with U.S. Cyber Command Cyber operations aboard Dark Fleet vessels Cyber risk across ports and maritime infrastructure Public-private operational partnerships Persistent cybersecurity fundamentals International maritime cyber cooperation Key Quotes "You can't wait till the crisis or contingency to bring everyone together." — Rear Admiral Jason Tama "The great thing about ships now is they're all connected all the time. The bad thing is the ships are all connected all the time." — Rear Admiral Jason Tama "We're never going to Cyber our way out of this problem, right? There's no Cyber panacea." — Rear Admiral Jason Tama "Resilience is so important and everybody has to be able to think about and have a plan for how do you continue to operate on your worst digital day because it's not a matter of if, it's a matter of when." — Rear Admiral Jason Tama "The work we're doing in the wild from whether it's power plants to cranes to locks and dams ... all over the world, it's really incredible mission work." — Rear Admiral Jason Tama Relevant Links and Resources Cyber Trends and Insights in the Marine Environment (CTIME) Guest Bio Rear Admiral Jason Tama is Commander of U.S. Coast Guard Cyber Command, where he oversees cyberspace operations to defend Coast Guard networks, protect maritime critical infrastructure, and counter adversary activity. He also serves as the Coast Guard's Service Cyber Component Commander to U.S. Cyber Command. Previously, Tama served as Senior Director for Resilience at the National Security Council and as Captain of the Port of New York and New Jersey. He is a graduate of the U.S. Coast Guard Academy and holds advanced degrees from the University of California, Berkeley, and MIT Sloan School of Management.
A new White House memorandum aims to bring the private sector more directly into cyber operations against transnational criminal organizations. But turning that policy goal into practice raises immediate questions about legal authority, liability, deconfliction and the risks companies could assume by participating. In this edition of Cyber Focus: To the Point, Frank Cilluffo talks with Mike McLaughlin about what the memorandum does—and does not do—under existing law, what needs to be resolved during the 60-day implementation window, and where private-sector capabilities may be most useful without interfering with ongoing military, intelligence or law-enforcement operations. Main Topics Covered Private-sector cyber offense Legal authority and liability Deconfliction with government operations Risks for participating companies The 60-day implementation window Where private-sector capabilities may fit Key Quotes "The [National Security Presidential Memorandum] isn't actually creating an authority; it's creating a record… that the administration or federal law enforcement can point to and say we gave you very clear authority… and if you step outside of that, you're on your own. — Mike McLaughlin "Deconfliction is a big problem because when you're dealing with the National Security Agency and the CIA and the FBI and US Cyber Command and CNMF and, you know, US SOCOM, and then you bring in ASD from Australia or GCHQ from the UK, and we're trying to deconflict all of this blue activity in cyberspace, it's really challenging." — Mike McLaughlin "If we start contracting with companies to conduct offensive operations, those companies become combatants." — Mike McLaughlin "For me, if the authorized target set are cryptocurrency wallets or keys or on-chain infrastructure that's being used to support transnational criminal organizations, that's an area that the private sector can cleanly operate without risking running afoul of traditional intelligence community activities, law enforcement operations, or military cyber operations." — Mike McLaughlin Relevant Links and Resources White House national security presidential memorandum National Cybersecurity Strategy Computer Fraud and Abuse Act (CFAA) Buchanan Ingersoll Rooney — Mike McLaughlin Guest Bio Mike McLaughlin co-leads the cyber practice at Buchanan Ingersoll Rooney. He previously served in government roles involving U.S. Cyber Command and the Cyber National Mission Force.
The federal government is competing for technology and cybersecurity talent at the same time AI is beginning to reshape how that workforce operates. OPM Director Scott Kupor argues that meeting both challenges requires more than new tools or recruiting campaigns: government needs a personnel system that better reflects how people build careers today, rewards performance and adaptability, and creates room for responsible experimentation. Kupor joins Frank Cilluffo to discuss Tech Force and the push to bring more early-career technologists into public service; why he believes agencies should focus on practical, near-term AI gains rather than long-range plans that may quickly become obsolete; and what his years in Silicon Valley taught him about risk, execution and talent. They also explore what Washington and the technology industry misunderstand about one another—and why U.S. economic and national security increasingly depend on getting that relationship right. Main Topics Tech Force and two-year tours of public service Recruiting cyber and technology talent into government The federal government's early-career workforce gap Performance, merit and tenure in federal employment AI productivity and the changing federal workforce AI literacy and the continuing role of human judgment "Permissioned innovation" and responsible risk-taking Execution, adaptability and decision-making under uncertainty What Washington and Silicon Valley can learn from one another Key Quotes "I think every person coming out of high school or college, hopefully we can convince them spending 2 years in government is good for the country and good for them. It's really that simple." – Scott Kupor "If we're gonna attract early career people, they have to be able to come in an environment where their performance and their merit is a lot more important than how many years they've been here." – Scott Kupor "We should not be building, in my mind, the 2040 or 2050 plan for AI, because the very honest answer is we have no idea." – Scott Kupor "Everybody needs to develop some kind of AI literacy, right? So, and not just people who are software developers." – Scott Kupor "So the good companies, the good organizations, the good nonprofits, whatever it is, you have a theory of the case, but then you actually have to be willing to say, okay, our theory was wrong for X number of reasons and we're gonna change it. And I think it's very hard intellectually for people to do that. But that, I think, is the difference, ultimately, between successful and unsuccessful organizations." – Scott Kupor Links and Resources: Scott Kupor's OPM Blog About the guest: Scott Kupor is director of the U.S. Office of Personnel Management, where he leads efforts to build a more accountable, mission-driven federal workforce. Before joining OPM, he was a managing partner at Andreessen Horowitz, which he helped build into one of the country's largest venture capital firms. He previously held senior technology leadership roles, chaired the National Venture Capital Association and taught entrepreneurship at Stanford. He is also the author of Secrets of Sand Hill Road: Venture Capital and How to Get It .
Tom Afferton [00:00:00]: If you're introducing security controls or a maintenance activity or modernization that interrupts that operation, then you're no better off than if there was a cyber interruption. Frank Cilluffo [00:00:16]: Welcome to Cyber Focus from the McCrary Institute, where we explore the people and ideas shaping and defending our digital world. I'm your host, Frank Cilluffo, and this week I have the privilege to sit down with Tom Afferton. Tom is president of the Cyber and Intelligence Service at Peraton, where he oversees a number of the most mission-critical entities inside the US government and has been there for a number of years. Prior to that, he also was at AT&T and many years at Northrop Grumman. Tom, thank you so much for joining us today. Tom Afferton [00:00:50]: Happy to be here. Frank Cilluffo [00:00:50]: So I thought I'd start at the beginning, and a lot of your clients are mission-critical. Tom Afferton [00:00:57]: Yes. Frank Cilluffo [00:00:57]: And very different than a traditional IT enterprise. And I'd be curious what that looks like. Why is that different and what your initial thoughts are there? Tom Afferton [00:01:07]: So when we look at a lot of the systems services that we protect, you have to think about the consequences of them not operating. When we think about, you know, a large-scale modernization as well, right, you have to think about the whole point of, of cybersecurity is to protect that institution, to protect its operability. So if you're introducing security controls or a maintenance activity or modernization that interrupts that operation, then you're no better off than if there was a cyber interruption, right? And so when we go through, again, thinking about something like a modernization, we take an approach we call sort of a layered uplift, which is you introduce that new capability in an incremental way. You make sure that it's instrumented so that as you introduce it, you're monitoring, is it doing what you expected it to do? And then over time, it takes on more responsibilities. And then ultimately, you can turn off the legacy environment. Now, there's of course prioritization involved, deciding, you know, where are you going to start? Where are you going to build in that resilience and redundancy? Something that Nick Andersen over at CISA has introduced, the term of ruthless prioritization. Frank Cilluffo [00:02:37]: Mm-hmm. Tom Afferton [00:02:38]: And I think that's helpful. It's helpful when thinking about resilience planning. It's helpful when thinking about planning resources up front, coordination, but it's then also helpful in thinking about incident response. And when I've heard him speak and he's explained it, what he's talking about is going beyond just prioritizing a category of critical infrastructure. It's understanding that, you know, the key mission, the crown jewel that we need to have keep operating, we need to understand the assets associated with it. Frank Cilluffo [00:03:13]: Mm-hmm. Tom Afferton [00:03:14]: So what GPU is that workload or that workflow operating in what cluster and what data centers powered by what part of the grid? And knowing that sort of connection between the critical infrastructure and the mission and the physical and the technical infrastructure allows you to then prioritize. Frank Cilluffo [00:03:32]: Because you really can't pause operations during an upgrade, right? Tom Afferton [00:03:36]: Absolutely. Frank Cilluffo [00:03:37]: So it's a challenge. These are— because you're also behind a number of critical systems that most Americans don't think about every day. Tom Afferton [00:03:44]: That's right. Frank Cilluffo [00:03:45]: One in particular that's gotten a little bit of news, and I know we can't get into great detail here, is FAA and the modernization. Tom Afferton [00:03:51]: Yeah. And that's an interesting one. Peraton's very proud to be part of that. The administration has framed that as one of the most important modernization projects in American history. And part of that is because, you know, our air travel depends upon it, right? It's critical to our economy, but it's also large and complex. One of my colleagues, Justin Sciaccio, is the one leading that for Peraton, and he recently met with stakeholders in the press along with Secretary Duffy to talk about the program. Frank Cilluffo [00:04:23]: Mm-hmm. Tom Afferton [00:04:23]: And what Secretary Duffy explained is that they were looking to do something radically different in terms of program management and bring in an integration partner. And Peraton were— we were fortunate to be selected to do that. And one of the reasons that they selected us is that we've brought a revolutionary agentic AI technology to the equation. Frank Cilluffo [00:04:44]: Mm-hmm. Tom Afferton [00:04:45]: And what Justin has been explaining that we're doing is we are ingesting I think it was like something 5.7 million records of schedule data as well as historical information about projects that have completed, and then have the AI start to do analysis around that so that we can stress test schedules, you know, we can identify gaps and whatnot. And he had this quote that sort of went viral that he said, like, we're not looking to replace the humans. We want to enable them to have superhuman insights. And that's what we're really— what we're finding here. And it's just the schedule, all the interdependencies, all the suppliers, all the different sites. It's just too much for one person to consume. And so providing those insights has been part of the value add there. Frank Cilluffo [00:05:29]: And, you know, you can't escape without us getting into a conversation around AI and agentic AI. Tom Afferton [00:05:34]: Sure. Frank Cilluffo [00:05:36]: What it means for threat hunters. But before jumping there, I mean, you've got technology time cycles that are moving so fast, but a lot of the systems you're dealing with here are in very different timelines. And we've had a number of discussions around the energy sector and grid, and we don't have to go there, but a lot of their OT systems are 25, 30 years old, and they're being netted with IoT devices and it brings about a new attack surface. How do you reconcile sort of that balance between a fast-moving tech cycle and not always so fast critical infrastructure sector? Tom Afferton [00:06:13]: So I'll jump to the answer, but then I want to go back and I will give you an example of the type of work that our folks are doing because I think it illustrates the sort of both ends of the spectrum. Frank Cilluffo [00:06:24]: And your an EE background, right? Tom Afferton [00:06:25]: Right, thank you. Yes. Frank Cilluffo [00:06:26]: Stanford and UVA. Tom Afferton [00:06:27]: So go Hoos. So— Frank Cilluffo [00:06:30]: Blue and orange. You know the history between the football uniforms between Auburn, UVA, and Clemson. Tom Afferton [00:06:27]: No, I don't. Frank Cilluffo [00:06:36]: All right. This is— sorry, but— Tom Afferton [00:06:38]: That's okay. Frank Cilluffo [00:06:39]: We will include this in the episode. So initially, the first football coach at Auburn was a football coach at UVA, brought the uniforms because they were so expensive. And then he went to Clemson and brought the uniforms. That's why it turned less than blue. It was a little more purple. So true story. Tom Afferton [00:06:55]: I did not know that. Frank Cilluffo [00:06:56]: Yeah. Tom Afferton [00:06:57]: So going back to the question about sort of the pace of technology, right? So if, you know, we were to talk 6 months ago, we would have been talking about buying back time to the analysts. And that's still important and something that I do want to talk about. We look now within the age of Mythos and, you know, the ability for agentic AI to produce vulnerabilities at an unprecedented speed and scale, right, the cutting edge is now thinking about automating remediations and sort of the bottleneck has shifted down. But before we go to either of those, I think it's helpful to just have— let's have a practical example. Like, this is a day in the life of some of my folks. Frank Cilluffo [00:07:37]: Mm-hmm. Tom Afferton [00:07:38]: I have some folks that are supporting CISA in the Code and Media Analysis Team, and they are involved with malware analysis and ultimately incident response for critical infrastructure. So without getting into any details, right, one recent situation- they were brought in as a result of some classified intel to take a look at some malware. They did some analysis to determine kind of what vulnerabilities it was associated with. They determined that it was associated with some edge devices and sort of double alarm bells went off because number one, they were edge devices that could be used in a carrier network, that OT was being used, basically programmable logic controllers sitting behind these edge devices that had no inherent security in them. So if you penetrated this edge device, you could get access to the programmable logic controllers and control that environment. And then secondly, these edge devices were also in federal civilian executive branch. So from— and you go back to in a critical environment, what do you need to think about? Well, one is consequences. Frank Cilluffo [00:08:49]: Mm-hmm. Tom Afferton [00:08:49]: So, okay, This has potentially wide-ranging impact. The second then is sort of thinking about it from a risk standpoint. And so now these folks are going off and looking on— they know the right blog posts. There is some of the monitoring that CISA does. Combine that with some tradecraft on the dark web to say, are these exploits being published? You know, are there any IP addresses associated with it? You then enrich that with some of the classified intel to make a decision. Is this something that we really need to focus some energy around in analyzing and potentially producing some remediation? And then you get to that step and now you've got to reproduce it. So a lab environment where we— I call it exploding the malware in a sandbox. Frank Cilluffo [00:09:34]: Mm-hmm. Tom Afferton [00:09:34]: See what it does, what its signatures look like, and then ultimately producing reports. And there's a lot of discussion. You think about who are we reporting to, what are we disclosing on all that. So that whole cycle, right, we have anywhere from 5 to 20 folks. That's it. All of critical infrastructure. So that goes back to what Nick Andersen's talking about, ruthless prioritization, right? So you got to think about consequence. You got to think about that risk. Tom Afferton [00:10:02]: So if we think about now AI in that process, one area is the sensemaking, and that goes back to buying back time from the analysts. All of that monitoring data is coming in from disparate sources. So how do we help them prioritize? Frank Cilluffo [00:10:20]: Mm-hmm. Tom Afferton [00:10:21]: And that can be an initial prioritization, but then you can go back and have the AI running in the background and continuing to correlate. Are new events coming and suddenly this was an isolated thing and now it's not? And so that's something we want to prioritize. We also think about it in terms of malware reporting and again, sensemaking of we're getting all this malware in, what should we prioritize? Frank Cilluffo [00:10:42]: Mm-hmm. Tom Afferton [00:10:43]: If I go to the backend, we think about building that remediation for the vulnerability and can AI help? We've had some really interesting discussions with CISA thinking about what's the right model or engagement with AI, meaning do they engage with tools that are available in, you know, a cloud environment or, going back to exploding it in a sandbox, right, do we have- and we've looked at this and helped them with this, is actually buy some GPUs and have a good old-fashioned on-prem environment that you're not paying for tokens. You bought the GPU and now you have a locally hosted environment that now you can unleash the malware on. So, you know, those are just examples of thinking through the practical day-to-day on where we can help. Frank Cilluffo [00:11:36]: That's actually a really interesting analogy. And something that just dawned on me is these are also lessons from a counter-IED perspective where we're applying in a cyber domain or a BSL-3 kind of lab approach. And, you know, Peraton has visibility across a wide range of customers, not only in the civilian agency department, which we've discussed here, but also the national security and Title 50 intel world. Any lessons from that work that you think pops up loud and clear in a civilian environment? Tom Afferton [00:12:16]: So one area that— it's interesting, as we brought the company together and as we brought my organization together, it was, you know, one of the first times— at the time it was actually as Chris Inglis was standing up the first Office of the National Cyber Director. Frank Cilluffo [00:12:34]: National Cyber Director. Yep. Tom Afferton [00:12:34]: I, when I met him, I described my organization and I said, we're kind of mirroring what you're trying to do in the government, which is promote that cross-collaboration across different stakeholders, right? Frank Cilluffo [00:12:46]: Mm-hmm. Tom Afferton [00:12:46]: All the customers that you want to interact, all the agencies I am supporting from one organization. Frank Cilluffo [00:12:51]: Mm-hmm. Tom Afferton [00:12:52]: And so one of the first things that came out was we talked earlier about the tidal wave of data and we help one of our customers in the I.C. deal with some of the largest datasets on the planet. Frank Cilluffo [00:13:06]: Mm-hmm. Tom Afferton [00:13:07]: And helping them take that mindset and approach and governance and bring that now into a civilian environment to say, hey, there's another organization that has dealt with this. Here is a roadmap for maturing through your data governance. Here are, you know, some data structures and here's a stack you can think about and all those different things. So that's something that I have seen carried from the I.C. environment over to the civil environment. Frank Cilluffo [00:13:36]: And it aligns well to Nick's approach for ruthless prioritization because it really is a signal-to-noise set of challenges. I mean, there's a lot of telemetry and there's a lot of data and sometimes you can drown in data if you don't know what you're looking for. And I do want to pull the thread on that in a second. But prior to that, you know, when you look at some of these mission-critical sectors, and I love the environment 'cause it really is an environmental set of issues. It's not just a tech issue. It's a governance issue, it's an integration issue, it's everything across the board. But what do most people underestimate in terms of the complexity? Is it the technology itself? Is it supply chains and, dare I say, lack of visibility into what that looks like? Frank Cilluffo [00:14:27]: Is it legacy infrastructure? Is it a people challenge or is it all of the above? And clearly it is a little bit of all of the above. Tom Afferton [00:14:34]: A little of all the above, but I'm going to pick the people challenge and I'm going to go back to one of my first programs at Northrop Grumman. We were doing a technology demonstrator on— it was actually critical infrastructure, state and local emergency service interaction. And we built a platform that would allow different emergency services at different echelons to be able to all interoperate. Frank Cilluffo [00:15:03]: Mm-hmm. Tom Afferton [00:15:04]: And we set up this whole demonstration environment. We had this, this whole exercise. It was at a university campus and there was a mock explosion and everything. And at the end of the day, we had this amazing technology. And in the middle of this crisis, all the different folks would do is radio check. Hey, look at that. We can talk to the police. We had not gone through and done the operational elements to say, how do we take advantage of this technology? And I remember being elated at first that, holy cow, look at how we did all these technical achievements. Frank Cilluffo [00:15:41]: Yeah. Tom Afferton [00:15:41]: And then quickly realized that the part that was missed was enabling the people to take advantage of that technology. Frank Cilluffo [00:15:49]: Well said. And our first preventer community and first responder community, that was a real-world set of issues as we come to the 25th year of the anniversary of the horrific attacks of 9/11. I think some of those lessons are still being learned and hopefully earned and learned along the way. I do want to sort of- since you brought up some of the AI discussions in different ways, from a threat hunting perspective, there's a big signal-to-noise challenge there as well. How are you looking at ways to, A, apply it yourselves or for customers to be able to enhance that capability? Tom Afferton [00:16:36]: So, a couple of thoughts there. One is that, you know, we're recognizing that what we've gotten good at is recognizing humans and what they are doing. And now we have to also be thinking about agents and what they're doing. Frank Cilluffo [00:16:57]: What does an insider threat model look like for AI agents? Tom Afferton [00:17:00]: Exactly. Exactly. The- you know, one of the things that we've looked at there, and it's a program that we have done with one of the research organizations in the DOD, along with one of our customer sponsors. Frank Cilluffo [00:17:20]: Mm-hmm. Tom Afferton [00:17:22]: Is having— we call it a wingman for red teaming. And so having AI kind of sit alongside and monitor what's being done, capture some of that, learn from it, and then make recommendations. So that's not a case where you have AI in the loop and you're displacing the human. You're kind of watching what they're doing, watching the experienced folks do it, capture that, and then capture— then come back and make some recommendations. Frank Cilluffo [00:17:52]: Is this an Air Force contract? Wingman, love it. You don't have to. Tom Afferton [00:17:56]: No, it was not. But in some ways, is that becoming obsolete because Mythos can just do it now? Again, I think that's at the cutting edge. And yet I look across the customer community and, you know, folks are still crawling, right? And there's a variety of challenges, some of which we talked about in terms of the human element and are people— do they have the AI fluency? Do they have the, the comfort level? Frank Cilluffo [00:18:28]: Mm-hmm. Tom Afferton [00:18:29]: But there's also some practical matters. A lot of, you know, when I poll some of my teams that are on the front lines supporting customers in day-to-day cyber operations, there's still a lot of data jockeying going on, you know, and getting the data in the right place and making sure that you have data integrity and whatnot. There's also the clear demand signal that, you know, meet us where we are. Don't give us a tool that's going to operate in a commercial environment. Frank Cilluffo [00:19:03]: Mm-hmm. Tom Afferton [00:19:04]: You need to be able to operate in our environment. And, you know, there are different ways to do that. You can do some things on the low side and go through cross-domain, bring some products up, further enriched on the high side. But it also means meet us where we are from an operational process standpoint. And I know that, you know, you could roll your eyes and say, well, no, your whole point of AI is you need to build new processes. But, you know, we're, we're talking about sergeants and folks that— Frank Cilluffo [00:19:31]: Absolutely. Tom Afferton [00:19:31]: That they, they are, what they are taught is to follow the procedure. Now, we do need to work to help modify those procedures to take advantage of the technology. But you can't just throw this over the wall and say, isn't this
Because cybersecurity has become central to national security and military strategy, Rep. Chrissy Houlahan says the United States needs to create a dedicated Cyber Force to prepare for the challenges ahead. Rep. Houlahan joins Frank Cilluffo to discuss why the military must adapt to the cyber age, how AI and strategic competition with China are reshaping national security, and why developing the next generation of technical talent may be America's greatest long-term advantage. Together, they explore how better workforce development, military modernization, and stronger public-private partnerships can help prepare the United States for future threats. Main Topics Cyber's evolution The case for a Cyber Force Military modernization Cyber Command's role Building the cyber workforce Project-based learning Neurodiversity and national service Breaking down organizational silos Competition with China AI and emerging technologies Key Quotes "When you think about cyber, cybersecurity, cyber warfare, cyber anything, it's always the weakest link. It's the seam. And so in our economy and in our military industrial complex, we need to be focused on the weakest links." — Representative Chrissy Houlahan "I believe that [cyber] should be its own domain because of where it's headed or likely headed in the next 50 or so years. ... I think inevitably 50, 100 years from now, we will be glad for the change that... was a Cyber Force." — Rep. Chrissy Houlahan "I would argue we don't have time not to. … If we look forward half a century, will we regret that we didn't take the time, didn't spend the resources to be as competitive as we possibly could be in this particular area?" — Rep. Chrissy Houlahan "One of the things that I'm most concerned about in our way of viewing our workforce right now is we are maligning smart people. We are somehow othering people who think technologically, who pursue degrees in hard stuff and that's bananas." — Representative Chrissy Houlahan "If we turn our backs to the next generation of talent, make it too hard for people to be educated here and take those American values either with them or keep them here, we are going to turn around and wonder why everyone's left." — Rep. Chrissy Houlahan Relevant Links and Resources Rep. Chrissy Houlahan CSIS Commission on U.S. Cyber Force Generation About the Guest: Representative Chrissy Houlahan (D-PA) is an Air Force veteran, engineer and former entrepreneur who represents Pennsylvania's 6th District. She earned an engineering degree from Stanford through ROTC and later received a master's in Technology and Policy from MIT. In Congress, she serves on the House Armed Services Committee and the House Permanent Select Committee on Intelligence, where her work includes defense modernization, cybersecurity and the military's technical workforce.
Drones are a serious operational concern for critical infrastructure owners and operators. In this episode of Cyber Focus, Frank Cilluffo sits down with Scott Parker, founder of Aerisq and former Chief of UAS Security at CISA, to discuss how drone capabilities have changed the risk picture for airports, utilities, chemical facilities, pipelines, prisons, and other sensitive sites. The conversation examines the FAA's Section 2209 rulemaking (open for public comment through August 5th, 2026), along with the limits of flight restrictions and the growing need for "Air Domain Awareness" alongside cyber and physical security. Parker also explains why counter-UAS strategy must balance technology, legal authority, proportional response, and the practical realities of defending infrastructure at scale. Main Topics Drone risks to critical infrastructure Lessons from Ukraine FAA Section 2209 Standard vs. special UASFRs Air Domain Awareness State and local counter-UAS authority Cost and scale of drone defense AI and autonomous drone risk Secure-by-design drone capabilities Key Quotes "There is a huge imbalance between what it costs to take [a drone] down as opposed to what it costs to fly one." — Scott Parker "A vast majority of our critical infrastructure is open airspace. ... Of the 90-something nuclear facilities, less than five have active flight restrictions over them." — Scott Parker "There are thermal sensors that can read how much oil is in a tank. There are LiDAR that can map an infrastructure's detailed schematics. And there are also cyber tools that can be equipped to sniff out open networks around facilities." — Scott Parker "Someone who means to do harm, they can add real-time collection to what's already out there using AI and... very likely develop a very structured plan on how to be successful." — Scott Parker "They [critical infrastructure owner-operators] are on the front lines. That's what we're concerned about. So they need the protection." — Scott Parker Relevant Links and Resources CISA UAS Security FAA Section 2209 rulemaking (Public comment open until August 5, 2026) Safer Skies Act rulemaking (Public comment open until September 4, 2026) About the Guest: Scott Parker is the founder and principal consultant of Aerisq, where he helps public and private sector organizations manage the cyber and physical risks posed by drones. He previously served as the Chief of UAS Security at CISA, where he built and led the agency's first UAS Security Program and helped shape national guidance on drone risk management for critical infrastructure. Parker also served 27 years in the U.S. Army, culminating as Sergeant Major for the Special Operations Division at the Pentagon.
National security challenges increasingly cut across technology, economic competitiveness, critical infrastructure, manufacturing and workforce development. Universities have a growing role to play not only in conducting research, but also in translating ideas into practical solutions and preparing students to confront real-world problems. Auburn University President Dr. Chris Roberts, McCrary Institute Chairman Lt. Gen. (Ret) Ron Burgess, Senior Vice President for Research Dr. Steve Taylor and Samuel Ginn College of Engineering Dean Dr. Mario Eden join Frank Cilluffo to discuss Auburn's commitment to national security. The conversation explores the changing threat environment, the university's expanding research presence in Huntsville, partnerships among academia, government and industry, and how experiential education can prepare students for jobs and technologies that do not yet exist. Main Topics The changing national security landscape The convergence of security, technology and economic threats Building security into emerging technologies Auburn's national security mission The value of interdisciplinary research Auburn's expanding presence in Huntsville Universities as trusted government and industry partners Experiential learning for national security careers Preparing engineers for an AI-driven workforce Key Quotes "We're starting to see national security, economic security – it's all becoming intertwined and inseparable." — Frank Cilluffo "The largest fraction of our research at Auburn University is national security related. And that's not an accident. It's a commitment." — Dr. Chris Roberts "We're still putting band-aids on [the internet] to make it work. And so that's where we find ourselves. AI is so new. Let's get the foundation set like it needs to be up front, in terms of its security... so that we're not having to band-aid it in 10 years.— Lt. Gen. (Ret) Ron Burgess "We're not selling a product. We're here to educate our students and use our faculty and researchers to solve some tough problems." — Dr. Steve Taylor "We're not a diploma factory. I always tell our students that if the only thing that defines them when they graduate is their GPA, then we have failed."— Dr. Mario Eden Relevant Links and Resources Auburn University Auburn University's Cyber Education Programs About the Guests Lt. Gen. (Ret.) Ron Burgess is chairman of the McCrary Institute Advisory Board and former director of the Defense Intelligence Agency. During a 38-year Army career, he also served as acting principal deputy director of national intelligence and held senior intelligence roles with the Joint Chiefs of Staff and U.S. Southern Command. Dr. Chris Roberts is the 21st president of Auburn University, leading the university's academic, research, extension and public-service missions. An accomplished engineering scholar, he previously served for a decade as dean of Auburn's Samuel Ginn College of Engineering. Dr. Steve Taylor is Auburn University's senior vice president for research and economic development. He previously served as interim dean and associate dean for research in the Samuel Ginn College of Engineering, where he helped expand research funding and establish major applied research institutes and facilities. Dr. Mario Eden is dean of Auburn University's Samuel Ginn College of Engineering and the Joe T. and Billie Carole McMillan Professor. A longtime Auburn faculty member and former chair of chemical engineering, his research focuses on process systems engineering, simulation, design and optimization.
AI is changing the speed and scale of cyber conflict, but the burden on defenders remains the same: they have to protect complex systems all the time, while attackers only need one opening. That imbalance is especially urgent as critical infrastructure, intelligence missions, and space systems become more connected, more contested, and harder to secure. Chris Jones, Chief Technology Officer at Nightwing and a former senior CIA technology leader, joins Frank Cilluffo to discuss what that means for national security. He explains why AI may give attackers a short-term advantage, why many breaches still come down to basic defensive discipline, and why even the most advanced tools depend on skilled people, sound judgment, and mission-focused teams. Main Topics AI and the attacker-defender gap Why cyber defense is so hard Human-enabled cyber and intelligence Digital exhaust and privacy risk Known vulnerabilities and defensive basics Space systems as cyber terrain Securing legacy infrastructure Cyber, RF, EW, autonomy, and AI convergence The workforce behind advanced technology Key Quotes "In the world we live in today, basic privacy is at risk. Everything you do creates digital dust. That digital dust reveals your activities, plans and intentions." — Chris Jones "Having an offensive mindset when you're trying to play defense is really important." — Chris Jones "The notion with any technology that you're going to be able to control and contain it... is just overstated. ... Once the genie is out of the bottle, it's super hard." — Chris Jones "In order to be really effective, it's not just the application of advanced technology. It's the application of advanced technology by really well-trained and experienced operators of that technology." — Chris Jones "We also need people who are looking at how the systems are engineered today and asking the contrarian questions on why they exist the way they do." — Chris Jones Relevant Links and Resources Nightwing About the Guest: Christopher Jones is Chief Technology Officer at Nightwing, where he helps lead the company's technology strategy and the integration of advanced capabilities in support of customer missions. He joined Nightwing in 2024 after a 26-year career at the Central Intelligence Agency, where he finished serving as Associate Deputy Director for Science and Technology. His career has focused on bringing technology into national security operations, and he has received numerous awards including the CIA Director's Award, the Distinguished Career Intelligence Medal, multiple Meritorious Presidential Rank Awards and CIA Exceptional Performance Awards. Jones holds a bachelor's degree in electrical engineering from the University of Notre Dame and a master's degree in systems engineering from Virginia Tech.
Note: This episode was first released on December 2, 2025 This week Army Principal Cyber Advisor Brandon Pugh joins Frank Cilluffo to address a stark reality: if critical infrastructure fails, the Army cannot mobilize. To meet this "no fail" mission, Pugh explains how the service is aggressively merging cyber with electronic warfare and cutting red tape to field new technology in days rather than years. They also discuss the Army's unique edge in this digital fight—Reservists who bring high-level private sector expertise directly to the battlefield. The conversation also explores how AI and operational technology are reshaping the Army's cyber battlefield and threat landscape. Main Topics Covered • How Congress created the principal cyber advisor role and defined its authorities. • Army cyber's four focus areas: AI, defense critical infrastructure, acquisition, and workforce. • Integrating cyber, electronic warfare, RF, and information operations into Army warfighting doctrine. • Defending defense critical infrastructure and preparing for Volt Typhoon-style cyber disruptions. • Leveraging AI for continuous monitoring, faster detection, and protection of sensitive Army data. • Reforming cyber acquisition through FUZE prototypes, VC-style partnerships, and Guard and Reserve expertise. Key Quotes "Cyber is not an isolated capability. It's not something that just rests at Fort Gordon or Fort Meade." – Brandon Pugh "If an adversary goes after one of our military bases and we can't mobilize people, tanks, equipment in a time of conflict, that is a major concern… we can't accept the fact that cyber could be the barrier to our ability to do other military tasks." – Brandon Pugh "It's a national security imperative to leverage AI. We know adversaries are going to leverage AI or exploit our AI regardless of what we do here. We could put barriers in terms of aggressive regulation which some have proposed in the past or seek to slow it down. All that's going to do is help our adversaries." – Brandon Pugh "We have some individuals that show up their reserve weekend in $300,000-$400,000 vehicles because they are the experts in what they do as civilians. They have signed up and taken the oath because they want to serve this country. That is the talent we have in the Reserve and Guard that we need to continue to expand." – Brandon Pugh "We don't have to go through a multi-year acquisition cycle, spend millions of dollars where we've seen 3D printed drones for mere dollars in some cases being leveraged [in Ukraine]… We need some of these capabilities in a matter of days or weeks, not years." – Brandon Pugh Relevant Links and Resources • Jack Voltaic: Critical infrastructure resiliency • Army's FUZE Initiative Guest Bio Brandon Pugh is the Principal Cyber Advisor to the Secretary of the Army, advising the Secretary and Army Chief of Staff on cyber readiness, budget, capabilities, and strategy. He previously served as a director at the R Street Institute and continues to serve in the U.S. Army Reserve as a national security law professor, having earlier been a paratrooper and international law officer.
As frontier AI models become more capable at finding vulnerabilities, cybersecurity is entering a period where old timelines, disclosure norms, and governance tools may no longer fit the speed of the technology. In this episode of Cyber Focus , Frank Cilluffo speaks with CyberScoop editor-in-chief Greg Otto about the recent controversy surrounding Anthropic's Fable-5 and Mythos 5 models, the government's use of export controls, and the difficulty of distinguishing between dangerous AI capability and legitimate defensive cyber use. The conversation moves from the Anthropic fight to a broader operational challenge: AI may help defenders discover more weaknesses, but organizations still have to validate, prioritize, and fix them. Otto explains why vulnerability disclosure, patching, open-source security, and public-private coordination are all being tested by AI's pace — and why the most important question may not be whether AI can find the problem, but whether institutions can absorb what it reveals. Main Topics Covered Anthropic's Fable-5 and Mythos 5 models Project Glasswing and vetted model access AI-enabled vulnerability discovery Jailbreaks, guardrails, and defense-oriented prompting Export controls and frontier AI governance Vulnerability disclosure timelines Microsoft, Nightmare Eclipse, and researcher-vendor trust AI-generated bug reports and remediation overload Key Quotes "I think a lot of it was in the White House not fully understanding what is possible. And that's not necessarily on the White House. This is new technology." — Greg Otto "The model itself isn't the problem, it's the output." — Greg Otto "[AI vulnerability discovery] has really laid bare just how dependent we are on software that is literally maintained by people in their basement." — Greg Otto "If you're using AI to generate the answer, that's bad. That is unequivocally bad. It is not going to help."— Greg Otto "If you're using [AI] for something that requires judgment or human care, I think that you should really exercise some caution." — Greg Otto Relevant Links and Resources CyberScoop Safe Mode podcast Guest Bio Greg Otto is editor-in-chief of CyberScoop, where he leads coverage of cybersecurity, emerging technology, public-sector cyber policy, and the threats shaping the digital ecosystem. He also hosts CyberScoop's weekly podcast, Safe Mode , which examines major developments in cyber and technology through conversations with practitioners, executives, researchers, and reporters.
In this episode of Cyber Focus, Frank Cilluffo sits down with Brett Leatherman, Assistant Director for Cyber at the FBI, for a wide-ranging conversation about how the Bureau is using law enforcement authorities, intelligence, partnerships, and court-authorized technical operations to disrupt adversaries, help victims, and defend U.S. critical infrastructure. Leatherman explains why the FBI expects to conduct more operations like Operation Masquerade, which evicted Russian GRU actors from compromised routers, and why privately owned routers, edge devices, and small networks can become valuable infrastructure for foreign intelligence services and criminal groups. He also discusses the rise of agentic AI in ransomware, China-linked threats to operational technology and critical infrastructure, Operation Winter SHIELD, supply-chain risk, and why early victim reporting can help the FBI move upstream against cyber adversaries. Main Topics Covered FBI cyber threat response and disruption operations Operation Masquerade and court-authorized cyber actions Ransomware, agentic AI, and emerging threats China-linked threats to critical infrastructure Public-private partnerships and victim reporting Operation Winter SHIELD and cyber defense best practices Key Quotes "Deterrence for us is not just about arrests, indictments, convictions, although that still matters a lot to what we do. It's also about removing capacity and capability from the actors where they're not touchable. Their infrastructure is touchable, their money is touchable, their tools are touchable." — Brett Leatherman "The idea of security through obscurity is dangerous." — Brett Leatherman "The FBI will never ask you to maintain breach while we are conducting evidence collection." — Brett Leatherman "Ransomware actors are starting to leverage agentic AI, along with the nation states, to really move across the cyber kill chain at speeds we haven't seen before, and at speeds defenders might not be ready for." — Brett Leatherman "We can't defend against machine speed at human speed." — Brett Leatherman Relevant Links and Resources FBI Cyber Division Internet Crime Complaint Center (IC3) Operation Masquerade Operation Winter SHIELD Guest Bio Brett Leatherman is the Assistant Director for Cyber at the FBI, where he oversees the Bureau's cyber efforts, including incident response, threat response, and cyber disruption operations. A 23-year FBI agent, Leatherman has worked or managed programs across counterterrorism, counterintelligence, cyber, and criminal investigations. He previously served in senior roles in the FBI's Cyber Division and in Dallas, and has also served as an FBI pilot and negotiator.
A new executive order on artificial intelligence and cybersecurity sends a clear signal: advanced AI now sits at the center of how the United States thinks about cyber defense, national security, critical infrastructure resilience, and strategic competition. In this episode of Cyber Focus , Frank Cilluffo sits down with Daniel Kroese, Vice President of Global Policy at Palo Alto Networks and a Senior Fellow at the McCrary Institute, to unpack what the order means in practice. Kroese argues that the most important signal is the administration's effort to bring government, industry, and critical infrastructure operators together quickly — not simply to study AI risk, but to operationalize AI-enabled defense while preserving the innovation advantage that gives the United States its head start. Main Topics Covered The executive order's "North Star" signal on AI innovation, cybersecurity, and national security Why AI and cybersecurity are increasingly inseparable How frontier models are transforming vulnerability discovery, software red teaming, and cyber defense The urgency of hardening systems before adversaries catch up Expanding AI-enabled cyber tools to under-resourced critical infrastructure operators The role of voluntary frameworks and the proposed AI cybersecurity clearinghouse Managing a surge in vulnerabilities while improving detection and response times Key Quotes "In three weeks, [Mythos] was able to conduct one to two years' worth of red teaming on our own code base. We're not talking 5 percent better, 10 percent better, 15 percent better. We're talking about doing something in three weeks that would have taken us one, if not more, years previously. So that is an inflection point." — Daniel Kroese "We have a head start, but it is not an infinite head start." — Daniel Kroese "We also have to recognize that for your average electric utility or water treatment plant, if we were to give them Mythos or GPT-5.5 access tomorrow, due to the operational realities of how they are organized, they wouldn't know what to do with it. So it's not as simple as just flicking on access. It's about how do we scale and democratize the Cyber defense benefits of these models." — Daniel Kroese "Detection response times must be measured in single-digit minutes, not days, weeks, or never." — Daniel Kroese "This isn't about information sharing alone. It's about operational collaboration." — Daniel Kroese Relevant Links and Resources White House Executive Order: Promoting Advanced Artificial Intelligence Innovation and Security Palo Alto Networks Guest Bio Daniel Kroese is Vice President of Global Policy at Palo Alto Networks, where he leads the company's engagement with policymakers and government stakeholders. He previously served as Staff Director for Ranking Member John Katko on the House Homeland Security Committee and held senior cybersecurity roles at CISA and on Capitol Hill. He is also a Senior Fellow at the McCrary Institute.
In this episode of Cyber Focus, Frank Cilluffo speaks with Geoffrey Fowler, head of public engagement for the Youth AI Safety Institute at Common Sense Media, about why AI requires a different kind of safety framework than movies, apps, games, or social media. Fowler argues that generative AI is not static content; it is dynamic, conversational, multipurpose, and capable of changing from one interaction to the next based on the user, the prompt, the model, and the length of the conversation. The conversation explores how AI products that appear friendly, educational, or therapeutic can create new risks for children, from emotional dependency and privacy concerns to unsafe mental-health guidance and weakening guardrails over extended conversations. Fowler explains how Common Sense Media is working to build independent AI safety ratings for kids, modeled in part on crash testing for cars: transparent evaluations that help parents and schools make better decisions while pushing companies toward safer design. Main Topics Covered Why AI needs a new safety rating Lessons from social media and smartphone adoption AI companions, mental-health claims, and dependency risk AI toys, privacy, and weakening guardrails Independent testing, ratings, and child-development standards Company responsibility, public policy, and trust Key Quotes "AI is not your friend. AI is not human. It does not make the kinds of choices that a human being would make when you're having a bad day or when you're in a crisis or when you need somebody to really trust." — Geoffrey Fowler, Common Sense Media "[AI companies] shouldn't be experimenting on our kids. They should make it safe from the get go." — Geoffrey Fowler, Common Sense Media "These AI toys are little spies that you're putting in kids' rooms. They're recording their voices, they're recording behavioral data." — Geoffrey Fowler, Common Sense Media "The Common Sense Media Youth AI Safety Institute is neither pro AI nor anti AI. It's pro kid." — Geoffrey Fowler, Common Sense Media "We are here to research not just the hype of what companies say about what their technology does, we're here to see what it actually does and tell the truth about it." — Geoffrey Fowler, Common Sense Media Relevant Links and Resources https://www.commonsensemedia.org/ai-ratings/ai-risk-assessments Guest Bio Geoffrey Fowler is head of public engagement for the Youth AI Safety Institute at Common Sense Media. He is a longtime technology journalist whose work has appeared at The Washington Post and The Wall Street Journal. In this role, Fowler helps communicate Common Sense Media's work to evaluate AI products used by children, teens, families, and schools, including the development of independent safety ratings and risk assessments for youth-facing AI tools.
For Estonia, cyber resilience is not an abstract policy goal. It is a national survival issue shaped by history, geography, and the reality of living next to Russia. In this episode, Ambassador Kristjan Prikk explains how Estonia turned a lack of legacy infrastructure into a digital advantage, why the 2007 cyberattacks became a strategic wake-up call for the West, and what Ukraine's defense against Russia reveals about preparation, public-private cooperation, and the future of conflict. The conversation also looks ahead: to AI in government and education, to Estonia's support for Ukraine, and to the cyber lessons NATO must operationalize before the next crisis. At the center is a clear argument from one of the world's most digitally advanced democracies: cyber defense is not just about hardening systems, but building the relationships, institutions, and resilience needed to keep a society functioning under pressure. Main Topics Covered Estonia's digital transformation Life after Soviet occupation The 2007 cyberattacks Resilience over perfect defense Ukraine's cyber defense Private-sector support in wartime AI in government and education Support for Ukraine NATO's cyber priorities Key Quotes "We had a really strong incentive to go ahead and try out something almost crazy, something that no one had ever tried before, and just see what's going to happen." — Ambassador Kristjan Prikk "We believe that our kids will not lose [their] jobs to AI, but rather they may risk losing their jobs to other kids who know how to use AI better than them." — Ambassador Kristjan Prikk "We reduce or limit the risk of particularly high impact threats, risks materializing. But then again, the more important part is the ability to rebound; the ability to use alternatives if plan A is not working." — Ambassador Kristjan Prikk "The way the cyberspace is set up means that we cannot only be confined in our own quarters and expect that if we keep it in order, then nothing happens." — Ambassador Kristjan Prikk "Cybersecurity is a team sport…we have to make sure that when the problem appears, then we don't have to start searching for contacts of other people. The organization has to be there." — Ambassador Kristjan Prikk Relevant Links and Resources Embassy of Estonia in Washington, D.C. Estonia's national cybersecurity strategy or cyber agency resources Tallinn Mechanism information page IT Coalition for Ukraine information page About the Guest: Kristjan Prikk has served as Estonia's Ambassador to the United States since May 2021, and will soon serve as Estonia's Ambassador to NATO. Before assuming his current duties, Prikk served for nearly three years as the Permanent Secretary of the Estonian Ministry of Defense. In this role he was responsible for the management of the Ministry and for the coordination of activities of the agencies under the Ministry, including the Estonian Defense Forces, the Estonian Foreign Intelligence Service, and the Centre for Defense Investments.
In this episode of Cyber Focus, Frank Cilluffo speaks with Walter Haydock, founder of StackAware, about the accountability, governance, and national security challenges emerging as organizations rush to deploy artificial intelligence. Haydock argues that AI does not erase familiar cybersecurity and risk-management problems; it accelerates them. From non-human identities and AI agents to third-party risk, federal regulation, and the environmental demands of AI infrastructure, the conversation centers on a core question: who is accountable when AI systems act, fail, or cause harm? Rather than treating AI governance as a compliance checklist, Haydock makes the case for assigning clear ownership, focusing policy on outcomes, and giving business leaders—not risk advisors alone—responsibility for the risks their organizations accept. Main Topics Covered AI accountability and non-human identities Managing AI agents as unpredictable actors Who should own AI risk inside an organization Third-party risk, supply chains, and contractual accountability Avoiding checkbox compliance in AI governance National AI policy, innovation, and strategic competition Key Quotes: "I see organizations spending a lot of time, money, resources, brain power on low-impact problems, on things that they shouldn't be focused on, and instead they're kind of ignoring the higher-risk issues that have easier mitigations, easier solutions." — Walter Haydock "The question of who is accountable for a given outcome is a critically important one." — Walter Haydock "At the level of an individual business, I think it's important to assign accountability for actions of AI agents to cross-functional business leaders who have the wherewithal, the full understanding of all the issues that are impacting a given company." — Walter Haydock "The framework I use is that business leaders are risk and system owners. They are ultimately accountable. They make the final decisions." — Walter Haydock "When the government hard codes in supposed best practices, they end up creating perverse incentives where companies are focused very closely on checking the box and not necessarily on getting the good outcome." — Walter Haydock Relevant Links and Resources Stack Aware Guest Bio Walter Haydock is the founder of StackAware , an AI security and governance company. Before founding StackAware, he worked in government, national security, and the military, including service on the House Homeland Security Committee, at the National Counterterrorism Center, and in the U.S. Marine Corps in intelligence and reconnaissance roles.
Cyber defense is entering a machine-speed era. With Anthropic's Mythos and Project Glasswing bringing AI-driven vulnerability discovery and exploit development into the center of the cyber conversation, CrowdStrike's Drew Bagley says organizations need to prepare for a world where vulnerabilities can be found, chained, and exploited faster than traditional patching cycles can handle. Bagley joins Frank Cilluffo to explain why this shift is not just about one model, one company, or one headline-grabbing project. It points to a broader change in how attackers and defenders will operate: exploit stacks may make once-latent vulnerabilities newly dangerous, critical infrastructure operators may face risks they cannot patch away, and unmanaged AI agents inside organizations may become another source of exposure. The answer, Bagley argues, is not panic or patching alone, but continuous discovery, continuous remediation, visibility across the kill chain, AI-powered defense, and resilience planning built for a world moving faster than human-speed cyber. Main Topics Covered Mythos, Project Glasswing, and AI-driven vulnerability discovery Why exploit stacks change how organizations should think about risk Continuous patching, prioritization, and machine-speed defense Critical infrastructure, OT systems, and unpatchable legacy technology AI agents, unmanaged access, and the next insider-style risk Key Quotes "We're now in an era in which AI has been proven to be able to find vulnerabilities and write exploits at scale much quicker than humans can." — Drew Bagley "We should think about this as an opportunity to think through this problem set now and assume that this is going to be just a widespread capability pretty soon." — Drew Bagley "Previously latent [OT] vulnerabilities… [relied on] security through obscurity. That's no longer the case. And now those are exploitable." — Drew Bagley "If you don't have visibility and you can't see the risk, then you can't mitigate the risk." — Drew Bagley "It's important to think about the ways in which AI has been incorporated over the past two years, especially in organizations to get work done better, but in ways that have often been unmanaged where AI has access to things you wouldn't give an intern access to." — Drew Bagley Relevant Links and Resources Anthropic's Project Glasswing CrowdStrike's Project Quiltworks Guest Bio: Drew Bagley is CrowdStrike's Chief Privacy Officer, where he leads the company's privacy and public policy work. In his 12 years at CrowdStrike, he has helped shape the company's approach to data protection, cybersecurity policy, and engagement with government leaders as CrowdStrike grew into a global cybersecurity company.
Ranking source
Apple Podcasts rankings via the Mato Topic Intelligence Platform.
Observed September 20, 2026.
Apple and Apple Podcasts are trademarks of Apple Inc., registered in the U.S. and other countries.
Pairs with
Bring this source into Mato to read its transferable patterns, then turn them into an original show for your own audience.