Section Insights
Introduction to Cybersecurity Panel
What is the focus of the upcoming discussion?
The panel will discuss disruption, defense, and operational readiness in cybersecurity, emphasizing collaboration between government and industry to enhance cybersecurity measures.
- The panel features key figures from cybersecurity agencies.
- The discussion aims to address evolving threats in the cybersecurity landscape.
- Collaboration between government and industry is crucial for strengthening cybersecurity.
Cyber Effects and Traditional Kinetic Activity
How are cyber capabilities evolving in relation to traditional defense strategies?
There is a merging of cyber capabilities with traditional military strategies, which is essential for national defense. The focus is on providing robust cyber options to decision-makers.
- Cyber capabilities are becoming integral to national defense strategies.
- A strong vision for cyber strategy is essential for effective defense.
- The evolution of cyber warfare requires new approaches and capabilities.
Empowering Decision Makers in Cybersecurity
How can decision makers be better supported in cybersecurity?
Empowering decision makers involves focusing on risk management rather than just automated responses to vulnerabilities. This includes sharing information broadly with federal and local agencies.
- Decision makers need to prioritize risk management over automated fixes.
- Collaboration with state and local agencies enhances cybersecurity efforts.
- A unified approach to vulnerability reporting is necessary for effective cybersecurity.
Talent Management in Cybersecurity
What strategies are being implemented to manage cybersecurity talent?
There is a focus on purpose-built teams for specific missions, along with new incentive structures to attract and retain skilled personnel in cybersecurity roles.
- Agility in talent management is crucial for mission success.
- New incentive programs are being introduced to enhance training and certification.
- A comprehensive approach to recruiting and retaining talent is being developed.
Call to Action for Non-Federal Partners
What is needed from non-federal partners in cybersecurity?
There is a need for honest communication and collaboration between federal and non-federal partners to effectively secure critical infrastructure, acknowledging that not everything can be secured at once.
- Collaboration between government and industry is essential for effective cybersecurity.
- Realistic goals must be set for securing infrastructure.
- Open communication is key to strengthening partnerships in cybersecurity.
Transcript
0:10 Thank you to Sean and Misha. A thought provoking and insightful discussion. We'll now turn our attention to disruption, defense and operational readiness. A conversation on how government and industry are working together to strengthen cybersecurity security and respond to an evolving threat landscape. Please join me in welcoming Nick Anderson, Acting Director of the Cybersecurity and Infrastructure Security Agency. Brett Leatherman, Assistant Director of the Cyber Division at the FBI.
0:43 Katie Sutton, Assistant Secretary of War for Cyber Policy, Principal Cyber Advisor to the Secretary of War, Department of War, and our moderator tonight, Daniel Cruz, Vice President of Global Policy at Palo Alto Networks. Please welcome our panelists to the main stage.
1:16 All right, well, good afternoon, everyone. Katie, Brett, Nick, thanks for being here to share your insights. Your cybersecurity credentialing needs no further introduction, so let's dive right into the meat of the topic here. I think we all just listened to a really dynamic conversation with Director Karen Cross where he outlined how the cyber strategy for America really sets the administration's North Star and how underneath that North Star, yes, a relentless focus on cyber defense is, is important, but also we need to redouble down our efforts on the deterrent side of the equation, recognizing that these adversaries can't act with impunity forever.
1:57 Right. Sizing that imbalance there. And Brett, starting with you, the FBI has done a ton in this space. A lot of wins just in the last few months that perhaps are underappreciated. Love you to walk the audience through exactly how you are leading the charge on the deterrence front.
2:13 Yep. So thank you, Appreciate that question. So the FBI lead law enforcement agency in support of cyber operations here in the homeland. We are executing under pillar one of the National Cyber Strategy. For 118 years, the FBI has been a global or national law enforcement agency. Now a global law enforcement agency focused on counter criminal and nation state cyber activity. So we're executing over the last 60 days what we call Operation Riptide. Sean talked a little bit about that, which is our work to scale offensive operations, deterrence operations against the bad guys.
2:48 Through that, we always like to go after bad guys. As a law enforcement agency, we have arrested over 2 in 60 days. Over 200 actors engaged in cyber enabled or cyber crime operations globally charged another 50 extradited six international fugitives to the homeland here to face charges. So our goal is to impose cost on the actors themselves. But we recognize, unlike counterterrorism, counterintelligence and criminal investigations, the three other operational divisions in the FBI, we can't always get an actor in Custody.
3:21 So we go after the underlying ecosystem, the adversaries infrastructure, we go after their finances, we go after their tools. The more of those we can remove in any given joint sequenced operation, the more impactful and effective it is. And for victims, that matters. So the tagline for Operation Riptide is no safe harbor. And our teams came up with no safe harbor. Because it's not just about the cyber fugitives having no safe harbor when they travel to Milan, Italy, where we captured Ju, who was a alleged CCP hacker who conducted the hafnium attacks and is now sitting in Houston, Texas, ready go to to go to trial on violating the Computer Fraud and Abuse Act.
4:04 But we also, when we're talking about no safe harbor, go after their infrastructure, money and other things. Because if they can't monetize their activity, it serves as a deterrent as well. Industry partnerships are crucial to that. Unlike anything else that the FBI does in this space, it is industry that engages us early and often, that allows us to move upstream against the actors, and that is incredibly important to imposing cost on those actors. So welcome to the fight.
4:29 Thank you, thank you for what you guys do to empower what we do and appreciate my colleagues here who also contribute every day to the fight to defend the homeland.
4:38 Really impressive work. And Katie, in a similar vein, the Department of War recently, when you think about cyber effects and traditional kinetic activity, there's a marriage and a fusing of those that perhaps is underappreciated out there. Would love to learn more about that.
4:55 So as you stated earlier, we have a pretty solid North Star that was set for us. The Cyber strategy for America has a very strong vision for where we see the Department of War contributing and then our national defense strategy sets those priorities. So in the cyber domain, it's pretty simple. What is our North Star? We must provide a more robust set of cyber capabilities for the President and the Secretary to have options. What we've been really focused on over the last year is the evolution of how we're going to fight in the cyber domain.
5:28 Historically, cyber has been viewed very much in a stovepipe, where it was used as a tool to counter malicious cyber actors. We've gotten really good at that. We've spent a lot of time focused on that. Where we're focusing going forward is the ability for cyber to integrate into all of our military operations, to really provide a foundational tool for our war fighters to be able to have more successful military missions. In just the last year, we've had several instances of that operation.
6:00 Absolute resolve and Epic Fury. Both were something that were highlighted by the Chairman and the President as how instrumental it was to integrate cyber into that. And that's something where we've been very focused on how do we integrate in joint planning, how do we think about cyber from the fight and what is cyber going to provide to our war fighters to be able to have that decisive advantage so that when we're sending troops into harm's way, we have cyber opportunities to make sure that we can bring them back safely.
6:29 As we go through that process, we're really looking at how we need to build our organizations, how we need to build our talent, and aligning a lot of initiatives within the department to execute well.
6:43 As a proud American, I certainly appreciate hearing everything you have done to fuse those domains together for defense of the country. So appreciate that. Pivoting a little bit to Nick on the civilian and critical infrastructure focus, we've seen some really significant policy announcements over the last few months. The Cyber Strategy for America and EO on AI Security and Innovation, and two PQC quantum related executive orders that follow that. A lot of that implementation. CISA is at the tip of the spear.
7:13 So please walk us through. Under your leadership, you are driving a lot of those efforts forward right now.
7:19 Yeah, well, I think if you look at all the different areas of mission space that CISA covers, everything from cyber to emergency communications to physical security with our infrastructure security division, and then now we operationalize it out in the field, those are key enabling elements for us fulfilling the mission of being the nation's civilian cyber defense agency, of being the nation's risk advisor and being the national coordinator for critical infrastructure security and resilience. All elements of those missions go into representing what is it that is our piece of the pie of moving forward against that North Star.
7:52 That is the President's cyber strategy across all those different elements. I think primarily the ones where we're focusing a lot of attention right now are the securing and modernizing federal networks and our efforts to secure critical infrastructure alongside owner operators and alongside the OEMs that build. Build the technology that sort of underpin, you know, the makings of that critical infrastructure. So for us, you know, you mentioned a couple of the things that have come out recently, you know, from executive orders and sort of executive actions that we've taken.
8:22 You know, we're continuing to push forward extremely hard on the. The AI, you know, front in particular. You know, we've released, you know, our bod 2604 very recently that you sort of gets at the way that we think about vulnerability and risk prioritization. And that's at the core, not just of how we're thinking about vulnerability management, but really at the core of how we're thinking about risk management overall as an agency and you know, the risk picture that we look at for our nation's critical infrastructure.
8:49 So that's a shift from focus exclusively on a CVSS score, maybe as listed in the kev, to focusing instead on a series of different attributes. You know, chiefly, you know, is it Internet accessible? Is it something that's automatable and being, you know, able to be exploited and really be able to make an empowered decision as risk makers to be able to focus on? Is this something where I need to focus my time rather than just saying the scores that really, you know, really high, I'm just going to patch it because it has a high CBSS score.
9:20 Empowering those decision makers and risk is a lot of the focus of that binding operational directive which applies to our federal agencies and we share very broadly with state and locals and our traditional critical infrastructure owner operators. All of that leads us to other elements that we have aligned to the AI Executive order, such as the Clearinghouse and Gold Eagle. You know, those are fantastic opportunities. We have to really provide a unifying function around the way that we're going to do AI enabled vulnerability reporting and disclosure at scale in a way that we haven't had to do before with some of our legacy platforms and just continue to expand out those opportunities that access to build off the director's point earlier to really enable that industry collaboration that's so key and critical to us as we move forward.
10:07 I know Paul to Networks has appreciated plugging into Gold Eagle and the fact that this has been a project that welcomes the ability to harmonize and fuse a lot of these related efforts together. So thank you for stitching all of that together. As I hear everything that you've been working on, all three of you, and how it all ties back to that North Star, the cyber strategy for America. I remember when that came out in March and as I'm going through it, there was a line in there that I triple underlined because it really stood out for me.
10:35 And that was we are no longer going to tinker around the edges and provide half measures. And I think one of the reasons that really stood out is while we should always be turning the crank every single day and there's some role for incrementalism, today's threat landscape, sometimes you got to take some big swings. We got to really Turn the page and not be tethered to orthodoxy. And so perhaps, Katie, I would love to hear about some of those big swings you're taking and perhaps related to our most precious cyber resource, our people.
11:04 That is something that you could probably have me on stage for the rest of the night. Don't worry, we won't. But we talk a lot about tools, impressive amount of tools and tools are fundamental in how we operate in this domain. I look forward to hearing, spending the rest of the conference being able to learn more about all the tools. Lots of impressive capabilities out there. The most important tool that we have in the Department of War is our war fighters and our people.
11:30 And what we've seen over the last few years is how we build the talent that we need just isn't keeping pace with the domain and allowing us to have the right talent at hand. So, as you mentioned, instead of doing an incremental approach, we're taking a huge step forward with an initiative called Cyber Command 2.0. This is something that the Secretary approved the plan for last fall, and we have rapidly moved out on implementation. So the focus of Cyber Command 2.0 is how do we build our warfighters to fight the future fight in cyber that I talked about?
12:04 And it's based on three primary objectives. The first is that we have to build more domain mastery into our force. The traditional military force generation model is one where someone comes in and they do an assignment for two or three years, and then they rotate to a different assignment, and then they rotate to a different assignment. That's really hard in cyber, where experience matters. And so how do we get that domain mastery that we need? The other area, the second objective is specialization.
12:35 Cyber has grown significantly and it's no longer significant for us to have an operator or a defensive specialist. We need to think about specifics and have people finely tuned. So it would be akin in the medical facility, in the medical profession, saying, we have medical professionals. Well, you probably wouldn't want a pediatrician to do heart surgery or an EMT to do, to do a dermatology consultation. We shouldn't accept the same thing in cyber.
13:06 And so we're looking through our talent management process of how do we specialize that talent so that we can have people who are experts in cloud, in operational technology and other areas and can build that domain mastery in that specialized skill. And then as we think about how we're going to fight the adversary in the future, agility and mission. Agility is going to be fundamental to success. It's no Longer going to be acceptable to say I can take these single set of people and expect them to do every mission.
13:37 We're going to need to be able to purpose build for each mission that we have. And having the agility in that system is important. So as we looked at those objectives we came up with, we looked across the entire talent management process. How we recruit, how we incentivize people, how we train them, how we retain them, what is their career path look like and how do we help them be successful over a career and then how do we manage that talent and what organizations do we need?
14:06 And over the last nine months, it's been really exciting to start implementing that. We approved a new incentive pay which is going to incentivize people who get to the higher levels of training and certification and are going to be rolling that out in the next few months. And we're already seeing people move towards that. So really excited to see what's going to come and look forward to, forward to hearing more about that and how we can and how it's helping our war fighters execute their mission.
14:32 Excellent.
14:33 And in that, in that vein of taking big swings, Brett, you teased us with some of these stats earlier, but the work the FBI is doing to put bad guys behind bars and to impose consequences in a way that we've never seen before, at a scale that we've never seen before.
14:50 Yeah. Part of that is aligning resources to our work. So you know, we are not just a law enforcement agency. We are the nation's domestic intelligence. And so looking at it from a national security perspective and understanding what is the tactical threat, ransomware in various types of criminal exploitation. But then what is the existential threat that we face by foreign nation states? And it's aligning resources to counter PRC operations, for example, Volt Typhoon, Flax Typhoon, Salt Typhoon, some of those the most consequential cyber espionage and pre placement of cyber capability campaigns launched against the United States.
15:29 The FBI is helping to lead those efforts by innovating in the space of our authorities, leveraging our authorities to remove capacity and capability from those actors to impede military operations in the Indo Pacific by targeting critical infrastructure right here in the United States. So leveraging court authorization or intelligence community authorities in novel ways to defend the homeland is incredibly important. All while ensuring that we are balanced and aligned to the nation state versus criminal mindset that we have, training our folks, keeping them engaged in the fight with the newest techniques and technologies as they emerge.
16:07 Scaling those operations is incredibly important. Every time you hear about a joint sequenced operation that the FBI has done. It is empowered by industry. So we conducted a operation against First VPN, a VPN anonymization service that allowed 25 different ransomware groups to operate from anonymity. We did that with industry partnerships when we conducted a operation against them. We just announced a technical operation, an enforcement operation against Media Land, a bulletproof host or sitting in Russia that allowed 17 ransomware groups, including Lock Bit to operate from that bulletproof hosting platform.
16:46 We seized millions of dollars in cryptocurrency and we've provided decryption capability to victims to the tune of mitigating ransom payments by almost three quarters of a billion dollars. So it is leveraging all those authorities, leaning into those partnerships, looking to scale those operations. The only way we can do that is to not do it ad hoc, but to really look to close the gaps with industry and our partners in the intelligence community and our international partners and to make this more steady state counter cyber operations, all in defense of the homeland.
17:19 As I'm hearing you walk through these examples, there's a clear synergy between the work on the defensive side for our department of War mission, the law enforcement mission, the civilian critical infrastructure mission and the role of industry. It feels like that it's all being integrated together better than it has been before.
17:36 It has. And that's. It's by design.
17:38 Right.
17:39 I have team members that sit with Nick in his over at CISA and Nick has team members that sit with FBI. The same is true of our intelligence community partners, our five eye partners. We're co located to ensure that we are fully aligned, encountering these actors.
17:53 Absolutely. As we wrap things up here, Nick, CISA in its storefront role, if you will, to the 16 critical infrastructure sectors, you engage and your team engages frequently with all of the non federal partners, many of whom are in the audience today. So if you had a call to action for them, what do you need from them that you're not getting? What do you need more of? How can the partnership strengthen? What would that big ask be for all your non federal friends out here today?
18:22 Well, we love our federal friends too, but for all of our non federal friends here, really we have to be honest with each other, I think about what's most important. We're not going to be able to secure everything everywhere, all at once. Not, it's not going to happen. That is an unreasonable goal for us to attempt to attain. But you know, the approach that we can take in working together as a government industry team, you know, in the same way that we're taking that approach here as an interagency team, you know, it really has to be focused on just ruthless prioritization.
18:56 You know, whether we're talking about our approach to the clearinghouse and AI enabled vulnerability research and reporting, or we're talking about the, you know, the, you know, new and ambitious goals and timelines that we have for, you know, pqc, you know, risk mitigation that we've seen coming out, coming out of the administration very recently and all of those elements we have to be focused on ruthless prioritization. You know, so for us, we're focused on things that are going to be most consequential and focused on public health and safety, national security, overall continuity of our economy and defense, critical infrastructure.
19:30 The way that we get after that problem, you know, most honestly is by developing these joint action plans that we're developing alongside our industry partners and the approach that we've taken, sort of integrated homeland defense, you know, as part of an interagency team here, you know, whether that is somebody that has a traditional cyber mission or doesn't have a traditional cyber mission. As long as they've got a tool to be able to bring to the fight, you know, we want to be able to engage with them.
19:53 But again, it has to be focused on, you know, ruthless prioritization. You know, we're all going to have to make risk trade off decisions here. Just in the same way that we've talked about with vulnerability discovery and vulnerability management. We're going to have to make those trade offs, you know, for the foreseeable future. Now that is, I think, a responsibility that we all bear, especially, you know, from my perspective, sitting on the, on the government side, you know, the American people have put a special trust and a special responsibility on us to be able to represent their interests well and to be able to make sure that critical infrastructure is going to continue to operate, no matter the intention of the adversary, and to be able to make sure that we're making appropriate risk trade off decisions for them.
20:33 We can only do that when we're well informed by the open and honest communication and feedback that we enjoy with our industry partners. So I'd encourage you all just to continue to interact with us, hold us accountable, be honest with us, engage in all of these opportunities as we continue to sort of set up and evolve what the future of a lot of this workflow is going to be. If you don't know who else to reach out to and you're thinking about the AI enabled vulnerability research and our clearinghouse efforts and what Gold Eagle is going to be able to provide, I'd encourage you to reach out to us at Clearinghouse, you know, @cisa.dhs.gov it's a fantastic opportunity to continue engage and you know, as our partners can see, it's very easy to be able to flip, flip right in and be able to engage with us and the various mechanisms that we set up in there.
21:16 And again, building off a lot of the success that we've had as an interagency team and being able to deliver some of these initial wins and initial successes that are just going to continue to build momentum as we continue to see the evolution of maturity as we deliver against the President's cyber strategy.
21:31 Well, Nick, whether it's your work and CISA's work to be more prioritized in how you defend against the threat in the critical infrastructure community across federal networks, or the impressive work of the FBI for with takedown efforts and to impose costs on cyber adversaries that we've never seen before, or Katie, the worker of the Department of War, to fuse together cyber and kinetic operations in never before seen ways. While cybercom is going through a necessary and substantial overhaul, it's very clear that the three of you are on the digital front lines every single day at a moment when the stakes are really, really high.
22:07 So thank you for your leadership, thank you, you for your service. And you see out here today we have the broader cyber security community. I know everyone here is eager to roll up our sleeves and to work with you in that fight.
22:19 So thank you, thank you.
Summary
- The FBI's Operation Riptide aims to deter cybercriminals by imposing costs on their operations, leading to significant arrests and infrastructure disruptions.
- The Department of War is integrating cyber capabilities into military operations to enhance effectiveness and ensure the safety of warfighters.
- CISA is prioritizing the modernization of federal networks and securing critical infrastructure through collaborative efforts with industry partners.
- A shift in focus from traditional vulnerability scoring to a more nuanced risk management approach is being implemented to enhance decision-making.
- Cyber Command 2.0 is being developed to build specialized talent and domain mastery within the military to better address future cyber challenges.
- The importance of open communication and collaboration between government and industry is emphasized to effectively prioritize and manage cybersecurity risks.
- The panelists advocate for a proactive approach to cybersecurity, moving beyond incremental measures to address the current threat landscape comprehensively.
Questions Answered
What is the focus of the upcoming discussion?
The panel will discuss disruption, defense, and operational readiness in cybersecurity, emphasizing collaboration between government and industry to enhance cybersecurity measures.
How are cyber capabilities evolving in relation to traditional defense strategies?
There is a merging of cyber capabilities with traditional military strategies, which is essential for national defense. The focus is on providing robust cyber options to decision-makers.
How can decision makers be better supported in cybersecurity?
Empowering decision makers involves focusing on risk management rather than just automated responses to vulnerabilities. This includes sharing information broadly with federal and local agencies.
What strategies are being implemented to manage cybersecurity talent?
There is a focus on purpose-built teams for specific missions, along with new incentive structures to attract and retain skilled personnel in cybersecurity roles.
What is needed from non-federal partners in cybersecurity?
There is a need for honest communication and collaboration between federal and non-federal partners to effectively secure critical infrastructure, acknowledging that not everything can be secured at once.