Cyber Focus: Cybersecurity, National Security, and Critical Infrastructure

Frank Cilluffo / McCrary Institute

As cyber threats evolve faster than policy, Cyber Focus delivers executive-level briefings on cybersecurity, national security, and critical infrastructure. From the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University, host Frank Cilluffo speaks with senior leaders across government, industry, and the intelligence community about ransomware, state-sponsored threats, AI, and the systems we all rely on—energy, water, telecom, and supply chains. Each episode focuses on real-world risk tradeoffs and practical steps organizations can take to strengthen resilience.

  1. 2d ago ·  Video

    Who Will Defend America in the Cyber Age? with Rep. Chrissy Houlahan

    Because cybersecurity has become central to national security and military strategy, Rep. Chrissy Houlahan says the United States needs to create a dedicated Cyber Force to prepare for the challenges ahead. Rep. Houlahan joins Frank Cilluffo to discuss why the military must adapt to the cyber age, how AI and strategic competition with China are reshaping national security, and why developing the next generation of technical talent may be America's greatest long-term advantage. Together, they explore how better workforce development, military modernization, and stronger public-private partnerships can help prepare the United States for future threats. Main Topics Cyber's evolution The case for a Cyber Force Military modernization Cyber Command's role Building the cyber workforce Project-based learning Neurodiversity and national service Breaking down organizational silos Competition with China AI and emerging technologies Key Quotes "When you think about cyber, cybersecurity, cyber warfare, cyber anything, it's always the weakest link. It's the seam. And so in our economy and in our military industrial complex, we need to be focused on the weakest links." — Representative Chrissy Houlahan "I believe that [cyber] should be its own domain because of where it's headed or likely headed in the next 50 or so years. ... I think inevitably 50, 100 years from now, we will be glad for the change that... was a Cyber Force." — Rep. Chrissy Houlahan "I would argue we don't have time not to. … If we look forward half a century, will we regret that we didn't take the time, didn't spend the resources to be as competitive as we possibly could be in this particular area?" — Rep. Chrissy Houlahan "One of the things that I'm most concerned about in our way of viewing our workforce right now is we are maligning smart people. We are somehow othering people who think technologically, who pursue degrees in hard stuff and that's bananas." — Representative Chrissy Houlahan "If we turn our backs to the next generation of talent, make it too hard for people to be educated here and take those American values either with them or keep them here, we are going to turn around and wonder why everyone's left." — Rep. Chrissy Houlahan Relevant Links and Resources Rep. Chrissy Houlahan CSIS Commission on U.S. Cyber Force Generation About the Guest:  Representative Chrissy Houlahan (D-PA) is an Air Force veteran, engineer and former entrepreneur who represents Pennsylvania's 6th District. She earned an engineering degree from Stanford through ROTC and later received a master's in Technology and Policy from MIT. In Congress, she serves on the House Armed Services Committee and the House Permanent Select Committee on Intelligence, where her work includes defense modernization, cybersecurity and the military's technical workforce.

    Who Will Defend America in the Cyber Age? with Rep. Chrissy Houlahan
  2. Jul 21 ·  Video

    Who Should Control the Airspace Around Critical Infrastructure? with Scott Parker

    Drones are a serious operational concern for critical infrastructure owners and operators. In this episode of Cyber Focus, Frank Cilluffo sits down with Scott Parker, founder of Aerisq and former Chief of UAS Security at CISA, to discuss how drone capabilities have changed the risk picture for airports, utilities, chemical facilities, pipelines, prisons, and other sensitive sites. The conversation examines the FAA's Section 2209 rulemaking (open for public comment through August 5th, 2026), along with the limits of flight restrictions and the growing need for "Air Domain Awareness" alongside cyber and physical security. Parker also explains why counter-UAS strategy must balance technology, legal authority, proportional response, and the practical realities of defending infrastructure at scale. Main Topics Drone risks to critical infrastructure Lessons from Ukraine FAA Section 2209 Standard vs. special UASFRs Air Domain Awareness State and local counter-UAS authority Cost and scale of drone defense AI and autonomous drone risk Secure-by-design drone capabilities Key Quotes "There is a huge imbalance between what it costs to take [a drone] down as opposed to what it costs to fly one." — Scott Parker "A vast majority of our critical infrastructure is open airspace. ... Of the 90-something nuclear facilities, less than five have active flight restrictions over them." — Scott Parker "There are thermal sensors that can read how much oil is in a tank. There are LiDAR that can map an infrastructure's detailed schematics. And there are also cyber tools that can be equipped to sniff out open networks around facilities." — Scott Parker "Someone who means to do harm, they can add real-time collection to what's already out there using AI and... very likely develop a very structured plan on how to be successful." — Scott Parker "They [critical infrastructure owner-operators] are on the front lines. That's what we're concerned about. So they need the protection." — Scott Parker Relevant Links and Resources CISA UAS Security FAA Section 2209 rulemaking (Public comment open until August 5, 2026) Safer Skies Act rulemaking  (Public comment open until September 4, 2026) About the Guest:  Scott Parker is the founder and principal consultant of Aerisq, where he helps public and private sector organizations manage the cyber and physical risks posed by drones. He previously served as the Chief of UAS Security at CISA, where he built and led the agency's first UAS Security Program and helped shape national guidance on drone risk management for critical infrastructure. Parker also served 27 years in the U.S. Army, culminating as Sergeant Major for the Special Operations Division at the Pentagon.

    Who Should Control the Airspace Around Critical Infrastructure? with Scott Parker
  3. Jul 14 ·  Video

    How Universities Like Auburn Help Defend the Nation

    National security challenges increasingly cut across technology, economic competitiveness, critical infrastructure, manufacturing and workforce development. Universities have a growing role to play not only in conducting research, but also in translating ideas into practical solutions and preparing students to confront real-world problems. Auburn University President Dr. Chris Roberts, McCrary Institute Chairman Lt. Gen. (Ret) Ron Burgess, Senior Vice President for Research Dr. Steve Taylor and Samuel Ginn College of Engineering Dean Dr. Mario Eden join Frank Cilluffo to discuss Auburn's commitment to national security. The conversation explores the changing threat environment, the university's expanding research presence in Huntsville, partnerships among academia, government and industry, and how experiential education can prepare students for jobs and technologies that do not yet exist. Main Topics The changing national security landscape The convergence of security, technology and economic threats Building security into emerging technologies Auburn's national security mission The value of interdisciplinary research Auburn's expanding presence in Huntsville Universities as trusted government and industry partners Experiential learning for national security careers Preparing engineers for an AI-driven workforce Key Quotes "We're starting to see national security, economic security – it's all becoming intertwined and inseparable." — Frank Cilluffo "The largest fraction of our research at Auburn University is national security related. And that's not an accident. It's a commitment." — Dr. Chris Roberts "We're still putting band-aids on [the internet] to make it work. And so that's where we find ourselves. AI is so new. Let's get the foundation set like it needs to be up front, in terms of its security... so that we're not having to band-aid it in 10 years.— Lt. Gen. (Ret) Ron Burgess "We're not selling a product. We're here to educate our students and use our faculty and researchers to solve some tough problems." — Dr. Steve Taylor "We're not a diploma factory. I always tell our students that if the only thing that defines them when they graduate is their GPA, then we have failed."— Dr. Mario Eden Relevant Links and Resources Auburn University Auburn University's Cyber Education Programs About the Guests Lt. Gen. (Ret.) Ron Burgess is chairman of the McCrary Institute Advisory Board and former director of the Defense Intelligence Agency. During a 38-year Army career, he also served as acting principal deputy director of national intelligence and held senior intelligence roles with the Joint Chiefs of Staff and U.S. Southern Command. Dr. Chris Roberts is the 21st president of Auburn University, leading the university's academic, research, extension and public-service missions. An accomplished engineering scholar, he previously served for a decade as dean of Auburn's Samuel Ginn College of Engineering. Dr. Steve Taylor is Auburn University's senior vice president for research and economic development. He previously served as interim dean and associate dean for research in the Samuel Ginn College of Engineering, where he helped expand research funding and establish major applied research institutes and facilities. Dr. Mario Eden is dean of Auburn University's Samuel Ginn College of Engineering and the Joe T. and Billie Carole McMillan Professor. A longtime Auburn faculty member and former chair of chemical engineering, his research focuses on process systems engineering, simulation, design and optimization.

    How Universities Like Auburn Help Defend the Nation
  4. Jul 7 ·  Video

    Why the Human Element Still Matters in Cyber Defense with Nightwing's Chris Jones

    AI is changing the speed and scale of cyber conflict, but the burden on defenders remains the same: they have to protect complex systems all the time, while attackers only need one opening. That imbalance is especially urgent as critical infrastructure, intelligence missions, and space systems become more connected, more contested, and harder to secure. Chris Jones, Chief Technology Officer at Nightwing and a former senior CIA technology leader, joins Frank Cilluffo to discuss what that means for national security. He explains why AI may give attackers a short-term advantage, why many breaches still come down to basic defensive discipline, and why even the most advanced tools depend on skilled people, sound judgment, and mission-focused teams. Main Topics AI and the attacker-defender gap Why cyber defense is so hard Human-enabled cyber and intelligence Digital exhaust and privacy risk Known vulnerabilities and defensive basics Space systems as cyber terrain Securing legacy infrastructure Cyber, RF, EW, autonomy, and AI convergence The workforce behind advanced technology Key Quotes "In the world we live in today, basic privacy is at risk. Everything you do creates digital dust. That digital dust reveals your activities, plans and intentions." — Chris Jones "Having an offensive mindset when you're trying to play defense is really important." — Chris Jones "The notion with any technology that you're going to be able to control and contain it... is just overstated. ... Once the genie is out of the bottle, it's super hard." — Chris Jones "In order to be really effective, it's not just the application of advanced technology. It's the application of advanced technology by really well-trained and experienced operators of that technology." — Chris Jones "We also need people who are looking at how the systems are engineered today and asking the contrarian questions on why they exist the way they do." — Chris Jones Relevant Links and Resources Nightwing About the Guest: Christopher Jones is Chief Technology Officer at Nightwing, where he helps lead the company's technology strategy and the integration of advanced capabilities in support of customer missions. He joined Nightwing in 2024 after a 26-year career at the Central Intelligence Agency, where he finished serving as Associate Deputy Director for Science and Technology. His career has focused on bringing technology into national security operations, and he has received numerous awards including the CIA Director's Award, the Distinguished Career Intelligence Medal, multiple Meritorious Presidential Rank Awards and CIA Exceptional Performance Awards. Jones holds a bachelor's degree in electrical engineering from the University of Notre Dame and a master's degree in systems engineering from Virginia Tech.

    Why the Human Element Still Matters in Cyber Defense with Nightwing's Chris Jones
  5. Jun 30 ·  Video

    The Army's "No Fail" Cyber Mission with Brandon Pugh

    Note: This episode was first released on December 2, 2025 This week Army Principal Cyber Advisor Brandon Pugh joins Frank Cilluffo to address a stark reality: if critical infrastructure fails, the Army cannot mobilize. To meet this "no fail" mission, Pugh explains how the service is aggressively merging cyber with electronic warfare and cutting red tape to field new technology in days rather than years. They also discuss the Army's unique edge in this digital fight—Reservists who bring high-level private sector expertise directly to the battlefield. The conversation also explores how AI and operational technology are reshaping the Army's cyber battlefield and threat landscape. Main Topics Covered • How Congress created the principal cyber advisor role and defined its authorities. • Army cyber's four focus areas: AI, defense critical infrastructure, acquisition, and workforce. • Integrating cyber, electronic warfare, RF, and information operations into Army warfighting doctrine. • Defending defense critical infrastructure and preparing for Volt Typhoon-style cyber disruptions. • Leveraging AI for continuous monitoring, faster detection, and protection of sensitive Army data. • Reforming cyber acquisition through FUZE prototypes, VC-style partnerships, and Guard and Reserve expertise. Key Quotes "Cyber is not an isolated capability. It's not something that just rests at Fort Gordon or Fort Meade." – Brandon Pugh "If an adversary goes after one of our military bases and we can't mobilize people, tanks, equipment in a time of conflict, that is a major concern… we can't accept the fact that cyber could be the barrier to our ability to do other military tasks." – Brandon Pugh "It's a national security imperative to leverage AI. We know adversaries are going to leverage AI or exploit our AI regardless of what we do here. We could put barriers in terms of aggressive regulation which some have proposed in the past or seek to slow it down. All that's going to do is help our adversaries." – Brandon Pugh "We have some individuals that show up their reserve weekend in $300,000-$400,000 vehicles because they are the experts in what they do as civilians. They have signed up and taken the oath because they want to serve this country. That is the talent we have in the Reserve and Guard that we need to continue to expand." – Brandon Pugh "We don't have to go through a multi-year acquisition cycle, spend millions of dollars where we've seen 3D printed drones for mere dollars in some cases being leveraged [in Ukraine]… We need some of these capabilities in a matter of days or weeks, not years." – Brandon Pugh Relevant Links and Resources • Jack Voltaic: Critical infrastructure resiliency • Army's FUZE Initiative Guest Bio Brandon Pugh is the Principal Cyber Advisor to the Secretary of the Army, advising the Secretary and Army Chief of Staff on cyber readiness, budget, capabilities, and strategy. He previously served as a director at the R Street Institute and continues to serve in the U.S. Army Reserve as a national security law professor, having earlier been a paratrooper and international law officer.

    The Army's "No Fail" Cyber Mission with Brandon Pugh
  6. Jun 23 ·  Video

    Anthropic and the Fight Over Frontier AI Risk with CyberScoop's Greg Otto

    As frontier AI models become more capable at finding vulnerabilities, cybersecurity is entering a period where old timelines, disclosure norms, and governance tools may no longer fit the speed of the technology. In this episode of Cyber Focus, Frank Cilluffo speaks with CyberScoop editor-in-chief Greg Otto about the recent controversy surrounding Anthropic's Fable-5 and Mythos 5 models, the government's use of export controls, and the difficulty of distinguishing between dangerous AI capability and legitimate defensive cyber use. The conversation moves from the Anthropic fight to a broader operational challenge: AI may help defenders discover more weaknesses, but organizations still have to validate, prioritize, and fix them. Otto explains why vulnerability disclosure, patching, open-source security, and public-private coordination are all being tested by AI's pace — and why the most important question may not be whether AI can find the problem, but whether institutions can absorb what it reveals. Main Topics Covered Anthropic's Fable-5 and Mythos 5 models Project Glasswing and vetted model access AI-enabled vulnerability discovery Jailbreaks, guardrails, and defense-oriented prompting Export controls and frontier AI governance Vulnerability disclosure timelines Microsoft, Nightmare Eclipse, and researcher-vendor trust AI-generated bug reports and remediation overload Key Quotes "I think a lot of it was in the White House not fully understanding what is possible. And that's not necessarily on the White House. This is new technology." — Greg Otto "The model itself isn't the problem, it's the output." — Greg Otto "[AI vulnerability discovery] has really laid bare just how dependent we are on software that is literally maintained by people in their basement." — Greg Otto "If you're using AI to generate the answer, that's bad. That is unequivocally bad. It is not going to help."— Greg Otto "If you're using [AI] for something that requires judgment or human care, I think that you should really exercise some caution." — Greg Otto Relevant Links and Resources CyberScoop Safe Mode podcast Guest Bio Greg Otto is editor-in-chief of CyberScoop, where he leads coverage of cybersecurity, emerging technology, public-sector cyber policy, and the threats shaping the digital ecosystem. He also hosts CyberScoop's weekly podcast, Safe Mode, which examines major developments in cyber and technology through conversations with practitioners, executives, researchers, and reporters.

    Anthropic and the Fight Over Frontier AI Risk with CyberScoop's Greg Otto
  7. Jun 16 ·  Video

    Inside the FBI's Push to Disrupt Hackers Before They Strike with Brett Leatherman

    In this episode of Cyber Focus, Frank Cilluffo sits down with Brett Leatherman, Assistant Director for Cyber at the FBI, for a wide-ranging conversation about how the Bureau is using law enforcement authorities, intelligence, partnerships, and court-authorized technical operations to disrupt adversaries, help victims, and defend U.S. critical infrastructure. Leatherman explains why the FBI expects to conduct more operations like Operation Masquerade, which evicted Russian GRU actors from compromised routers, and why privately owned routers, edge devices, and small networks can become valuable infrastructure for foreign intelligence services and criminal groups. He also discusses the rise of agentic AI in ransomware, China-linked threats to operational technology and critical infrastructure, Operation Winter SHIELD, supply-chain risk, and why early victim reporting can help the FBI move upstream against cyber adversaries. Main Topics Covered FBI cyber threat response and disruption operations Operation Masquerade and court-authorized cyber actions Ransomware, agentic AI, and emerging threats China-linked threats to critical infrastructure Public-private partnerships and victim reporting Operation Winter SHIELD and cyber defense best practices Key Quotes "Deterrence for us is not just about arrests, indictments, convictions, although that still matters a lot to what we do. It's also about removing capacity and capability from the actors where they're not touchable. Their infrastructure is touchable, their money is touchable, their tools are touchable." — Brett Leatherman "The idea of security through obscurity is dangerous." — Brett Leatherman "The FBI will never ask you to maintain breach while we are conducting evidence collection." — Brett Leatherman "Ransomware actors are starting to leverage agentic AI, along with the nation states, to really move across the cyber kill chain at speeds we haven't seen before, and at speeds defenders might not be ready for."  — Brett Leatherman "We can't defend against machine speed at human speed." — Brett Leatherman  Relevant Links and Resources FBI Cyber Division Internet Crime Complaint Center (IC3) Operation Masquerade Operation Winter SHIELD Guest Bio Brett Leatherman is the Assistant Director for Cyber at the FBI, where he oversees the Bureau's cyber efforts, including incident response, threat response, and cyber disruption operations. A 23-year FBI agent, Leatherman has worked or managed programs across counterterrorism, counterintelligence, cyber, and criminal investigations. He previously served in senior roles in the FBI's Cyber Division and in Dallas, and has also served as an FBI pilot and negotiator.

    Inside the FBI's Push to Disrupt Hackers Before They Strike with Brett Leatherman
  8. Jun 9 ·  Video

    The New AI Executive Order and the Race to Harden America's Systems with Daniel Kroese

    A new executive order on artificial intelligence and cybersecurity sends a clear signal: advanced AI now sits at the center of how the United States thinks about cyber defense, national security, critical infrastructure resilience, and strategic competition. In this episode of Cyber Focus, Frank Cilluffo sits down with Daniel Kroese, Vice President of Global Policy at Palo Alto Networks and a Senior Fellow at the McCrary Institute, to unpack what the order means in practice. Kroese argues that the most important signal is the administration's effort to bring government, industry, and critical infrastructure operators together quickly — not simply to study AI risk, but to operationalize AI-enabled defense while preserving the innovation advantage that gives the United States its head start. Main Topics Covered The executive order's "North Star" signal on AI innovation, cybersecurity, and national security Why AI and cybersecurity are increasingly inseparable How frontier models are transforming vulnerability discovery, software red teaming, and cyber defense The urgency of hardening systems before adversaries catch up Expanding AI-enabled cyber tools to under-resourced critical infrastructure operators The role of voluntary frameworks and the proposed AI cybersecurity clearinghouse Managing a surge in vulnerabilities while improving detection and response times Key Quotes "In three weeks, [Mythos] was able to conduct one to two years' worth of red teaming on our own code base. We're not talking 5 percent better, 10 percent better, 15 percent better. We're talking about doing something in three weeks that would have taken us one, if not more, years previously. So that is an inflection point." — Daniel Kroese "We have a head start, but it is not an infinite head start." — Daniel Kroese "We also have to recognize that for your average electric utility or water treatment plant, if we were to give them Mythos or GPT-5.5 access tomorrow, due to the operational realities of how they are organized, they wouldn't know what to do with it. So it's not as simple as just flicking on access. It's about how do we scale and democratize the Cyber defense benefits of these models." — Daniel Kroese "Detection response times must be measured in single-digit minutes, not days, weeks, or never." — Daniel Kroese "This isn't about information sharing alone. It's about operational collaboration." — Daniel Kroese Relevant Links and Resources White House Executive Order: Promoting Advanced Artificial Intelligence Innovation and Security Palo Alto Networks Guest Bio Daniel Kroese is Vice President of Global Policy at Palo Alto Networks, where he leads the company's engagement with policymakers and government stakeholders. He previously served as Staff Director for Ranking Member John Katko on the House Homeland Security Committee and held senior cybersecurity roles at CISA and on Capitol Hill. He is also a Senior Fellow at the McCrary Institute.

    The New AI Executive Order and the Race to Harden America's Systems with Daniel Kroese
5
out of 5
18 Ratings

About

As cyber threats evolve faster than policy, Cyber Focus delivers executive-level briefings on cybersecurity, national security, and critical infrastructure. From the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University, host Frank Cilluffo speaks with senior leaders across government, industry, and the intelligence community about ransomware, state-sponsored threats, AI, and the systems we all rely on—energy, water, telecom, and supply chains. Each episode focuses on real-world risk tradeoffs and practical steps organizations can take to strengthen resilience.