Cyber Focus: Cybersecurity, National Security, and Critical Infrastructure

Frank Cilluffo / McCrary Institute

As cyber threats evolve faster than policy, Cyber Focus delivers executive-level briefings on cybersecurity, national security, and critical infrastructure. From the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University, host Frank Cilluffo speaks with senior leaders across government, industry, and the intelligence community about ransomware, state-sponsored threats, AI, and the systems we all rely on—energy, water, telecom, and supply chains. Each episode focuses on real-world risk tradeoffs and practical steps organizations can take to strengthen resilience.

  1. 1d ago ·  Video

    Boarding the Dark Fleet: Coast Guard Cyber and Maritime Security with RADM Jason Tama

    The maritime world is more connected than ever, creating new efficiencies—and new ways for cyber incidents to move quickly from shore-based networks to ships operating around the globe. Rear Admiral Jason Tama, Commander of U.S. Coast Guard Cyber Command, joins Frank Cilluffo to explain how the Coast Guard operates across military, intelligence, law-enforcement, regulatory, and homeland-security missions to protect the Marine Transportation System and counter adversaries in cyberspace. The conversation also examines the Coast Guard's latest Cyber Trends and Insights in the Marine Environment report, including cyber operations aboard Dark Fleet vessels, the growing convergence of IT and operational technology, persistent weaknesses in basic cyber defenses, and the importance of working closely with industry. Tama argues that prevention alone will never be enough: maritime operators also need to be prepared to keep functioning through their "worst digital day." Main Topics Covered Coast Guard Cyber Command's three-part mission Title 10, Title 14, and Title 50 authorities Coast Guard integration with U.S. Cyber Command Cyber operations aboard Dark Fleet vessels Cyber risk across ports and maritime infrastructure Public-private operational partnerships Persistent cybersecurity fundamentals International maritime cyber cooperation Key Quotes "You can't wait till the crisis or contingency to bring everyone together." — Rear Admiral Jason Tama "The great thing about ships now is they're all connected all the time. The bad thing is the ships are all connected all the time." — Rear Admiral Jason Tama "We're never going to Cyber our way out of this problem, right? There's no Cyber panacea." — Rear Admiral Jason Tama "Resilience is so important and everybody has to be able to think about and have a plan for how do you continue to operate on your worst digital day because it's not a matter of if, it's a matter of when." — Rear Admiral Jason Tama "The work we're doing in the wild from whether it's power plants to cranes to locks and dams ... all over the world, it's really incredible mission work." — Rear Admiral Jason Tama Relevant Links and Resources Cyber Trends and Insights in the Marine Environment (CTIME) Guest Bio Rear Admiral Jason Tama is Commander of U.S. Coast Guard Cyber Command, where he oversees cyberspace operations to defend Coast Guard networks, protect maritime critical infrastructure, and counter adversary activity. He also serves as the Coast Guard's Service Cyber Component Commander to U.S. Cyber Command. Previously, Tama served as Senior Director for Resilience at the National Security Council and as Captain of the Port of New York and New Jersey. He is a graduate of the U.S. Coast Guard Academy and holds advanced degrees from the University of California, Berkeley, and MIT Sloan School of Management.

    Boarding the Dark Fleet: Coast Guard Cyber and Maritime Security with RADM Jason Tama
  2. 1d ago ·  Video

    Private Sector Cyber Offense: What the New White House Memo Does—and Doesn't Do with Mike McLaughlin

    A new White House memorandum aims to bring the private sector more directly into cyber operations against transnational criminal organizations. But turning that policy goal into practice raises immediate questions about legal authority, liability, deconfliction and the risks companies could assume by participating. In this edition of Cyber Focus: To the Point, Frank Cilluffo talks with Mike McLaughlin about what the memorandum does—and does not do—under existing law, what needs to be resolved during the 60-day implementation window, and where private-sector capabilities may be most useful without interfering with ongoing military, intelligence or law-enforcement operations. Main Topics Covered Private-sector cyber offense Legal authority and liability Deconfliction with government operations Risks for participating companies The 60-day implementation window Where private-sector capabilities may fit Key Quotes "The [National Security Presidential Memorandum] isn't actually creating an authority; it's creating a record… that the administration or federal law enforcement can point to and say we gave you very clear authority… and if you step outside of that, you're on your own. — Mike McLaughlin "Deconfliction is a big problem because when you're dealing with the National Security Agency and the CIA and the FBI and US Cyber Command and CNMF and, you know, US SOCOM, and then you bring in ASD from Australia or GCHQ from the UK, and we're trying to deconflict all of this blue activity in cyberspace, it's really challenging." — Mike McLaughlin "If we start contracting with companies to conduct offensive operations, those companies become combatants." — Mike McLaughlin "For me, if the authorized target set are cryptocurrency wallets or keys or on-chain infrastructure that's being used to support transnational criminal organizations, that's an area that the private sector can cleanly operate without risking running afoul of traditional intelligence community activities, law enforcement operations, or military cyber operations." — Mike McLaughlin Relevant Links and Resources White House national security presidential memorandum National Cybersecurity Strategy Computer Fraud and Abuse Act (CFAA) Buchanan Ingersoll Rooney — Mike McLaughlin Guest Bio Mike McLaughlin co-leads the cyber practice at Buchanan Ingersoll Rooney. He previously served in government roles involving U.S. Cyber Command and the Cyber National Mission Force.

    Private Sector Cyber Offense: What the New White House Memo Does—and Doesn't Do with Mike McLaughlin
  3. Aug 11 ·  Video

    AI, Risk, and the Future of the Federal Workforce with OPM Director Scott Kupor

    The federal government is competing for technology and cybersecurity talent at the same time AI is beginning to reshape how that workforce operates. OPM Director Scott Kupor argues that meeting both challenges requires more than new tools or recruiting campaigns: government needs a personnel system that better reflects how people build careers today, rewards performance and adaptability, and creates room for responsible experimentation. Kupor joins Frank Cilluffo to discuss Tech Force and the push to bring more early-career technologists into public service; why he believes agencies should focus on practical, near-term AI gains rather than long-range plans that may quickly become obsolete; and what his years in Silicon Valley taught him about risk, execution and talent. They also explore what Washington and the technology industry misunderstand about one another—and why U.S. economic and national security increasingly depend on getting that relationship right. Main Topics Tech Force and two-year tours of public service Recruiting cyber and technology talent into government The federal government's early-career workforce gap Performance, merit and tenure in federal employment AI productivity and the changing federal workforce AI literacy and the continuing role of human judgment "Permissioned innovation" and responsible risk-taking Execution, adaptability and decision-making under uncertainty What Washington and Silicon Valley can learn from one another Key Quotes "I think every person coming out of high school or college, hopefully we can convince them spending 2 years in government is good for the country and good for them. It's really that simple." – Scott Kupor "If we're gonna attract early career people, they have to be able to come in an environment where their performance and their merit is a lot more important than how many years they've been here." – Scott Kupor "We should not be building, in my mind, the 2040 or 2050 plan for AI, because the very honest answer is we have no idea." – Scott Kupor "Everybody needs to develop some kind of AI literacy, right? So, and not just people who are software developers." – Scott Kupor "So the good companies, the good organizations, the good nonprofits, whatever it is, you have a theory of the case, but then you actually have to be willing to say, okay, our theory was wrong for X number of reasons and we're gonna change it. And I think it's very hard intellectually for people to do that. But that, I think, is the difference, ultimately, between successful and unsuccessful organizations." – Scott Kupor Links and Resources: Scott Kupor's OPM Blog About the guest:  Scott Kupor is director of the U.S. Office of Personnel Management, where he leads efforts to build a more accountable, mission-driven federal workforce. Before joining OPM, he was a managing partner at Andreessen Horowitz, which he helped build into one of the country's largest venture capital firms. He previously held senior technology leadership roles, chaired the National Venture Capital Association and taught entrepreneurship at Stanford. He is also the author of Secrets of Sand Hill Road: Venture Capital and How to Get It.

    AI, Risk, and the Future of the Federal Workforce with OPM Director Scott Kupor
  4. Aug 4 ·  Video

    How Do You Rebuild Systems That Can't Go Offline? with Peraton's Tom Afferton

    Tom Afferton [00:00:00]: If you're introducing security controls or a maintenance activity or modernization that interrupts that operation, then you're no better off than if there was a cyber interruption.   Frank Cilluffo [00:00:16]: Welcome to Cyber Focus from the McCrary Institute, where we explore the people and ideas shaping and defending our digital world. I'm your host, Frank Cilluffo, and this week I have the privilege to sit down with Tom Afferton. Tom is president of the Cyber and Intelligence Service at Peraton, where he oversees a number of the most mission-critical entities inside the US government and has been there for a number of years. Prior to that, he also was at AT&T and many years at Northrop Grumman. Tom, thank you so much for joining us today.   Tom Afferton [00:00:50]: Happy to be here.   Frank Cilluffo [00:00:50]: So I thought I'd start at the beginning, and a lot of your clients are mission-critical.   Tom Afferton [00:00:57]: Yes.   Frank Cilluffo [00:00:57]: And very different than a traditional IT enterprise. And I'd be curious what that looks like. Why is that different and what your initial thoughts are there?   Tom Afferton [00:01:07]: So when we look at a lot of the systems services that we protect, you have to think about the consequences of them not operating. When we think about, you know, a large-scale modernization as well, right, you have to think about the whole point of, of cybersecurity is to protect that institution, to protect its operability. So if you're introducing security controls or a maintenance activity or modernization that interrupts that operation, then you're no better off than if there was a cyber interruption, right? And so when we go through, again, thinking about something like a modernization, we take an approach we call sort of a layered uplift, which is you introduce that new capability in an incremental way. You make sure that it's instrumented so that as you introduce it, you're monitoring, is it doing what you expected it to do? And then over time, it takes on more responsibilities. And then ultimately, you can turn off the legacy environment. Now, there's of course prioritization involved, deciding, you know, where are you going to start? Where are you going to build in that resilience and redundancy? Something that Nick Andersen over at CISA has introduced, the term of ruthless prioritization.   Frank Cilluffo [00:02:37]: Mm-hmm.   Tom Afferton [00:02:38]: And I think that's helpful. It's helpful when thinking about resilience planning. It's helpful when thinking about planning resources up front, coordination, but it's then also helpful in thinking about incident response. And when I've heard him speak and he's explained it, what he's talking about is going beyond just prioritizing a category of critical infrastructure. It's understanding that, you know, the key mission, the crown jewel that we need to have keep operating, we need to understand the assets associated with it.   Frank Cilluffo [00:03:13]: Mm-hmm.   Tom Afferton [00:03:14]: So what GPU is that workload or that workflow operating in what cluster and what data centers powered by what part of the grid? And knowing that sort of connection between the critical infrastructure and the mission and the physical and the technical infrastructure allows you to then prioritize.   Frank Cilluffo [00:03:32]: Because you really can't pause operations during an upgrade, right?   Tom Afferton [00:03:36]: Absolutely.   Frank Cilluffo [00:03:37]: So it's a challenge. These are— because you're also behind a number of critical systems that most Americans don't think about every day.   Tom Afferton [00:03:44]: That's right.   Frank Cilluffo [00:03:45]: One in particular that's gotten a little bit of news, and I know we can't get into great detail here, is FAA and the modernization.   Tom Afferton [00:03:51]: Yeah. And that's an interesting one. Peraton's very proud to be part of that. The administration has framed that as one of the most important modernization projects in American history. And part of that is because, you know, our air travel depends upon it, right? It's critical to our economy, but it's also large and complex. One of my colleagues, Justin Sciaccio, is the one leading that for Peraton, and he recently met with stakeholders in the press along with Secretary Duffy to talk about the program.   Frank Cilluffo [00:04:23]: Mm-hmm.   Tom Afferton [00:04:23]: And what Secretary Duffy explained is that they were looking to do something radically different in terms of program management and bring in an integration partner. And Peraton were— we were fortunate to be selected to do that. And one of the reasons that they selected us is that we've brought a revolutionary agentic AI technology to the equation.   Frank Cilluffo [00:04:44]: Mm-hmm.   Tom Afferton [00:04:45]: And what Justin has been explaining that we're doing is we are ingesting I think it was like something 5.7 million records of schedule data as well as historical information about projects that have completed, and then have the AI start to do analysis around that so that we can stress test schedules, you know, we can identify gaps and whatnot. And he had this quote that sort of went viral that he said, like, we're not looking to replace the humans. We want to enable them to have superhuman insights. And that's what we're really— what we're finding here. And it's just the schedule, all the interdependencies, all the suppliers, all the different sites. It's just too much for one person to consume. And so providing those insights has been part of the value add there.   Frank Cilluffo [00:05:29]: And, you know, you can't escape without us getting into a conversation around AI and agentic AI.   Tom Afferton [00:05:34]: Sure.   Frank Cilluffo [00:05:36]: What it means for threat hunters. But before jumping there, I mean, you've got technology time cycles that are moving so fast, but a lot of the systems you're dealing with here are in very different timelines. And we've had a number of discussions around the energy sector and grid, and we don't have to go there, but a lot of their OT systems are 25, 30 years old, and they're being netted with IoT devices and it brings about a new attack surface. How do you reconcile sort of that balance between a fast-moving tech cycle and not always so fast critical infrastructure sector?   Tom Afferton [00:06:13]: So I'll jump to the answer, but then I want to go back and I will give you an example of the type of work that our folks are doing because I think it illustrates the sort of both ends of the spectrum.   Frank Cilluffo [00:06:24]: And your an EE background, right?   Tom Afferton [00:06:25]: Right, thank you. Yes.   Frank Cilluffo [00:06:26]: Stanford and UVA.   Tom Afferton [00:06:27]: So go Hoos. So—   Frank Cilluffo [00:06:30]: Blue and orange. You know the history between the football uniforms between Auburn, UVA, and Clemson.   Tom Afferton [00:06:27]: No, I don't.    Frank Cilluffo [00:06:36]: All right. This is— sorry, but—   Tom Afferton [00:06:38]: That's okay.   Frank Cilluffo [00:06:39]: We will include this in the episode. So initially, the first football coach at Auburn was a football coach at UVA, brought the uniforms because they were so expensive. And then he went to Clemson and brought the uniforms. That's why it turned less than blue. It was a little more purple. So true story.   Tom Afferton [00:06:55]: I did not know that.   Frank Cilluffo [00:06:56]: Yeah.   Tom Afferton [00:06:57]: So going back to the question about sort of the pace of technology, right? So if, you know, we were to talk 6 months ago, we would have been talking about buying back time to the analysts. And that's still important and something that I do want to talk about. We look now within the age of Mythos and, you know, the ability for agentic AI to produce vulnerabilities at an unprecedented speed and scale, right, the cutting edge is now thinking about automating remediations and sort of the bottleneck has shifted down. But before we go to either of those, I think it's helpful to just have— let's have a practical example. Like, this is a day in the life of some of my folks.   Frank Cilluffo [00:07:37]: Mm-hmm.   Tom Afferton [00:07:38]: I have some folks that are supporting CISA in the Code and Media Analysis Team, and they are involved with malware analysis and ultimately incident response for critical infrastructure. So without getting into any details, right, one recent situation- they were brought in as a result of some classified intel to take a look at some malware. They did some analysis to determine kind of what vulnerabilities it was associated with. They determined that it was associated with some edge devices and sort of double alarm bells went off because number one, they were edge devices that could be used in a carrier network, that OT was being used, basically programmable logic controllers sitting behind these edge devices that had no inherent security in them. So if you penetrated this edge device, you could get access to the programmable logic controllers and control that environment. And then secondly, these edge devices were also in federal civilian executive branch. So from— and you go back to in a critical environment, what do you need to think about? Well, one is consequences.   Frank Cilluffo [00:08:49]: Mm-hmm.   Tom Afferton [00:08:49]: So, okay, This has potentially wide-ranging impact. The second then is sort of thinking about it from a risk standpoint. And so now these folks are going off and looking on— they know the right blog posts. There is some of the monitoring that CISA does. Combine that with some tradecraft on the dark web to say, are these exploits being published? You know, are there any IP addresses associated with it? Yo

    How Do You Rebuild Systems That Can't Go Offline? with Peraton's Tom Afferton
  5. Jul 28 ·  Video

    Who Will Defend America in the Cyber Age? with Rep. Chrissy Houlahan

    Because cybersecurity has become central to national security and military strategy, Rep. Chrissy Houlahan says the United States needs to create a dedicated Cyber Force to prepare for the challenges ahead. Rep. Houlahan joins Frank Cilluffo to discuss why the military must adapt to the cyber age, how AI and strategic competition with China are reshaping national security, and why developing the next generation of technical talent may be America's greatest long-term advantage. Together, they explore how better workforce development, military modernization, and stronger public-private partnerships can help prepare the United States for future threats. Main Topics Cyber's evolution The case for a Cyber Force Military modernization Cyber Command's role Building the cyber workforce Project-based learning Neurodiversity and national service Breaking down organizational silos Competition with China AI and emerging technologies Key Quotes "When you think about cyber, cybersecurity, cyber warfare, cyber anything, it's always the weakest link. It's the seam. And so in our economy and in our military industrial complex, we need to be focused on the weakest links." — Representative Chrissy Houlahan "I believe that [cyber] should be its own domain because of where it's headed or likely headed in the next 50 or so years. ... I think inevitably 50, 100 years from now, we will be glad for the change that... was a Cyber Force." — Rep. Chrissy Houlahan "I would argue we don't have time not to. … If we look forward half a century, will we regret that we didn't take the time, didn't spend the resources to be as competitive as we possibly could be in this particular area?" — Rep. Chrissy Houlahan "One of the things that I'm most concerned about in our way of viewing our workforce right now is we are maligning smart people. We are somehow othering people who think technologically, who pursue degrees in hard stuff and that's bananas." — Representative Chrissy Houlahan "If we turn our backs to the next generation of talent, make it too hard for people to be educated here and take those American values either with them or keep them here, we are going to turn around and wonder why everyone's left." — Rep. Chrissy Houlahan Relevant Links and Resources Rep. Chrissy Houlahan CSIS Commission on U.S. Cyber Force Generation About the Guest:  Representative Chrissy Houlahan (D-PA) is an Air Force veteran, engineer and former entrepreneur who represents Pennsylvania's 6th District. She earned an engineering degree from Stanford through ROTC and later received a master's in Technology and Policy from MIT. In Congress, she serves on the House Armed Services Committee and the House Permanent Select Committee on Intelligence, where her work includes defense modernization, cybersecurity and the military's technical workforce.

    Who Will Defend America in the Cyber Age? with Rep. Chrissy Houlahan
  6. Jul 21 ·  Video

    Who Should Control the Airspace Around Critical Infrastructure? with Scott Parker

    Drones are a serious operational concern for critical infrastructure owners and operators. In this episode of Cyber Focus, Frank Cilluffo sits down with Scott Parker, founder of Aerisq and former Chief of UAS Security at CISA, to discuss how drone capabilities have changed the risk picture for airports, utilities, chemical facilities, pipelines, prisons, and other sensitive sites. The conversation examines the FAA's Section 2209 rulemaking (open for public comment through August 5th, 2026), along with the limits of flight restrictions and the growing need for "Air Domain Awareness" alongside cyber and physical security. Parker also explains why counter-UAS strategy must balance technology, legal authority, proportional response, and the practical realities of defending infrastructure at scale. Main Topics Drone risks to critical infrastructure Lessons from Ukraine FAA Section 2209 Standard vs. special UASFRs Air Domain Awareness State and local counter-UAS authority Cost and scale of drone defense AI and autonomous drone risk Secure-by-design drone capabilities Key Quotes "There is a huge imbalance between what it costs to take [a drone] down as opposed to what it costs to fly one." — Scott Parker "A vast majority of our critical infrastructure is open airspace. ... Of the 90-something nuclear facilities, less than five have active flight restrictions over them." — Scott Parker "There are thermal sensors that can read how much oil is in a tank. There are LiDAR that can map an infrastructure's detailed schematics. And there are also cyber tools that can be equipped to sniff out open networks around facilities." — Scott Parker "Someone who means to do harm, they can add real-time collection to what's already out there using AI and... very likely develop a very structured plan on how to be successful." — Scott Parker "They [critical infrastructure owner-operators] are on the front lines. That's what we're concerned about. So they need the protection." — Scott Parker Relevant Links and Resources CISA UAS Security FAA Section 2209 rulemaking (Public comment open until August 5, 2026) Safer Skies Act rulemaking  (Public comment open until September 4, 2026) About the Guest:  Scott Parker is the founder and principal consultant of Aerisq, where he helps public and private sector organizations manage the cyber and physical risks posed by drones. He previously served as the Chief of UAS Security at CISA, where he built and led the agency's first UAS Security Program and helped shape national guidance on drone risk management for critical infrastructure. Parker also served 27 years in the U.S. Army, culminating as Sergeant Major for the Special Operations Division at the Pentagon.

    Who Should Control the Airspace Around Critical Infrastructure? with Scott Parker
  7. Jul 14 ·  Video

    How Universities Like Auburn Help Defend the Nation

    National security challenges increasingly cut across technology, economic competitiveness, critical infrastructure, manufacturing and workforce development. Universities have a growing role to play not only in conducting research, but also in translating ideas into practical solutions and preparing students to confront real-world problems. Auburn University President Dr. Chris Roberts, McCrary Institute Chairman Lt. Gen. (Ret) Ron Burgess, Senior Vice President for Research Dr. Steve Taylor and Samuel Ginn College of Engineering Dean Dr. Mario Eden join Frank Cilluffo to discuss Auburn's commitment to national security. The conversation explores the changing threat environment, the university's expanding research presence in Huntsville, partnerships among academia, government and industry, and how experiential education can prepare students for jobs and technologies that do not yet exist. Main Topics The changing national security landscape The convergence of security, technology and economic threats Building security into emerging technologies Auburn's national security mission The value of interdisciplinary research Auburn's expanding presence in Huntsville Universities as trusted government and industry partners Experiential learning for national security careers Preparing engineers for an AI-driven workforce Key Quotes "We're starting to see national security, economic security – it's all becoming intertwined and inseparable." — Frank Cilluffo "The largest fraction of our research at Auburn University is national security related. And that's not an accident. It's a commitment." — Dr. Chris Roberts "We're still putting band-aids on [the internet] to make it work. And so that's where we find ourselves. AI is so new. Let's get the foundation set like it needs to be up front, in terms of its security... so that we're not having to band-aid it in 10 years.— Lt. Gen. (Ret) Ron Burgess "We're not selling a product. We're here to educate our students and use our faculty and researchers to solve some tough problems." — Dr. Steve Taylor "We're not a diploma factory. I always tell our students that if the only thing that defines them when they graduate is their GPA, then we have failed."— Dr. Mario Eden Relevant Links and Resources Auburn University Auburn University's Cyber Education Programs About the Guests Lt. Gen. (Ret.) Ron Burgess is chairman of the McCrary Institute Advisory Board and former director of the Defense Intelligence Agency. During a 38-year Army career, he also served as acting principal deputy director of national intelligence and held senior intelligence roles with the Joint Chiefs of Staff and U.S. Southern Command. Dr. Chris Roberts is the 21st president of Auburn University, leading the university's academic, research, extension and public-service missions. An accomplished engineering scholar, he previously served for a decade as dean of Auburn's Samuel Ginn College of Engineering. Dr. Steve Taylor is Auburn University's senior vice president for research and economic development. He previously served as interim dean and associate dean for research in the Samuel Ginn College of Engineering, where he helped expand research funding and establish major applied research institutes and facilities. Dr. Mario Eden is dean of Auburn University's Samuel Ginn College of Engineering and the Joe T. and Billie Carole McMillan Professor. A longtime Auburn faculty member and former chair of chemical engineering, his research focuses on process systems engineering, simulation, design and optimization.

    How Universities Like Auburn Help Defend the Nation
  8. Jul 7 ·  Video

    Why the Human Element Still Matters in Cyber Defense with Nightwing's Chris Jones

    AI is changing the speed and scale of cyber conflict, but the burden on defenders remains the same: they have to protect complex systems all the time, while attackers only need one opening. That imbalance is especially urgent as critical infrastructure, intelligence missions, and space systems become more connected, more contested, and harder to secure. Chris Jones, Chief Technology Officer at Nightwing and a former senior CIA technology leader, joins Frank Cilluffo to discuss what that means for national security. He explains why AI may give attackers a short-term advantage, why many breaches still come down to basic defensive discipline, and why even the most advanced tools depend on skilled people, sound judgment, and mission-focused teams. Main Topics AI and the attacker-defender gap Why cyber defense is so hard Human-enabled cyber and intelligence Digital exhaust and privacy risk Known vulnerabilities and defensive basics Space systems as cyber terrain Securing legacy infrastructure Cyber, RF, EW, autonomy, and AI convergence The workforce behind advanced technology Key Quotes "In the world we live in today, basic privacy is at risk. Everything you do creates digital dust. That digital dust reveals your activities, plans and intentions." — Chris Jones "Having an offensive mindset when you're trying to play defense is really important." — Chris Jones "The notion with any technology that you're going to be able to control and contain it... is just overstated. ... Once the genie is out of the bottle, it's super hard." — Chris Jones "In order to be really effective, it's not just the application of advanced technology. It's the application of advanced technology by really well-trained and experienced operators of that technology." — Chris Jones "We also need people who are looking at how the systems are engineered today and asking the contrarian questions on why they exist the way they do." — Chris Jones Relevant Links and Resources Nightwing About the Guest: Christopher Jones is Chief Technology Officer at Nightwing, where he helps lead the company's technology strategy and the integration of advanced capabilities in support of customer missions. He joined Nightwing in 2024 after a 26-year career at the Central Intelligence Agency, where he finished serving as Associate Deputy Director for Science and Technology. His career has focused on bringing technology into national security operations, and he has received numerous awards including the CIA Director's Award, the Distinguished Career Intelligence Medal, multiple Meritorious Presidential Rank Awards and CIA Exceptional Performance Awards. Jones holds a bachelor's degree in electrical engineering from the University of Notre Dame and a master's degree in systems engineering from Virginia Tech.

    Why the Human Element Still Matters in Cyber Defense with Nightwing's Chris Jones
5
out of 5
18 Ratings

About

As cyber threats evolve faster than policy, Cyber Focus delivers executive-level briefings on cybersecurity, national security, and critical infrastructure. From the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University, host Frank Cilluffo speaks with senior leaders across government, industry, and the intelligence community about ransomware, state-sponsored threats, AI, and the systems we all rely on—energy, water, telecom, and supply chains. Each episode focuses on real-world risk tradeoffs and practical steps organizations can take to strengthen resilience.