Cyber Focus: Cybersecurity, National Security, and Critical Infrastructure

Frank Cilluffo / McCrary Institute

As cyber threats evolve faster than policy, Cyber Focus delivers executive-level briefings on cybersecurity, national security, and critical infrastructure. From the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University, host Frank Cilluffo speaks with senior leaders across government, industry, and the intelligence community about ransomware, state-sponsored threats, AI, and the systems we all rely on—energy, water, telecom, and supply chains. Each episode focuses on real-world risk tradeoffs and practical steps organizations can take to strengthen resilience.

  1. 2d ago ·  Video

    Who's in Control of the AI Race? with Bill Evanina and Matt Hayden

    Can the United States compete with China in AI while managing the risks the technology creates? Host Frank Cilluffo welcomes McCrary Institute senior fellows Bill Evanina and Matt Hayden for a discussion of the difficult choices behind that question. Evanina, who previously led U.S. counterintelligence, and Hayden, a former senior CISA official now at GDIT, assess expectations for the Trump–Xi summit, the limits of cyber cooperation, and the trade-offs behind chip export controls. The conversation also examines Chinese influence efforts surrounding data centers, the importance of energy to AI competition, the stakes of quantum computing, and whether familiar approaches to accountability can work when an AI agent becomes an insider threat. Main topics Trump–Xi summit expectations Volt Typhoon and cyber deterrence Chip exports and technology theft S.–China crisis communications Chinese influence on data center debates AI, energy, and the quantum race AI safeguards and accountability Taiwan and semiconductor dependence Key quotes "We cannot be AI dominant unless we're energy dominant. We can't be. And when you look at AI, it's not AI in its own, it's that it accelerates everything else." ­­— Frank Cilluffo "And so when we look at AI, it's not a matter of having the most advanced models. That helps. But it is a matter of getting that implementation into every corner of industry so that those efficiencies are known and used." — Matt Hayden "The big question is AI— should it be considered an insider threat? And the answer was a resounding yes. But what do we do with insider threats? We try to catch them and prosecute them. Are we going to prosecute an AI agent?" —Bill Evanina "From a pure liability standpoint of who we can blame, there's no AI agent that operates without compute. And so somebody's got to empower this thing at an original sin level." — Matt Hayden "As a metaphor, AI is a supermarket gas station on the highway to quantum. ... Whoever wins quantum, they say wins the world. I think you have to win AI before you win quantum." — Bill Evanina Links and resources CISA: Volt Typhoon and persistent access to U.S. critical infrastructure   About the guests: Bill Evanina is a McCrary Institute senior fellow and founder and CEO of the Evanina Group. He previously directed the National Counterintelligence and Security Center, leading U.S. government counterintelligence efforts, and held senior roles at the FBI and CIA. Matt Hayden is a McCrary Institute senior fellow and vice president of cyber and emerging threats at General Dynamics Information Technology. He previously served as assistant secretary for cyber, infrastructure, risk and resilience policy at the Department of Homeland Security and as senior advisor to the director of CISA.

    Who's in Control of the AI Race? with Bill Evanina and Matt Hayden
  2. Sep 15 ·  Video

    Can the Private Sector Go on Cyber Offense? with Armadin's Stacy O'Mara

    The federal government wants private companies to play a more active role in cyber operations. A new White House memo would allow vetted firms to support government action against transnational criminal groups. The plan marks a shift from sharing threat data to disrupting threats together. But key questions remain: Who controls the mission? Who carries the risk? Where does private support end and government authority begin? Stacy O'Mara joins Frank Cilluffo to discuss those questions. They examine oversight, liability, AI and critical infrastructure. O'Mara also draws lessons from SolarWinds and the war in Ukraine. Her bottom line: Trust must exist before a crisis, and new programs must be tested before they are scaled. Main Topics Covered New rules for private cyber operations From information sharing to joint action Authority, oversight and private-sector risk AI, critical infrastructure and human judgment Trust and readiness before a crisis Key Quotes "We can put all these partnerships in place, create a 70-page memo on how to do it. But at the end of the day, if there's a significant event, it's going to be the leadership of major ISPs, telecoms, and cybersecurity providers who are picking up the phone and calling each other in the middle of the night." — Stacy O'Mara "My gut tells me it is going to take a serious incident, and it would probably include loss of life. …But until we actually go through it and suffer some of the consequences, I don't know that we'll actually be able to put everything into place" — Stacy O'Mara "It can't just be: 'We're going to collaborate, and we're going to do all these things together because we're scared and we don't know what's coming.' But it needs to be: 'What are our desired outcomes?'" — Stacy O'Mara "You want AI to perform operations—or activities, rather—at speed and scale. But the human aspect should be around judgment and consequences. That should not be left up to AI." — Stacy O'Mara "Pilot these programs. Get a win. Figure out what works and doesn't work. And then replicate it and scale it. We don't have to do everything all at once." — Stacy O'Mara Relevant Links and Resources White House memorandum: Expanding Capabilities to Combat Transnational Cyber-Enabled Crime CISA Gold Eagle initiative Armadin Guest Bio Stacy O'Mara leads government affairs at Armadin. She previously held cybersecurity policy and government affairs roles at FireEye, Mandiant and Google. She later advised technology companies at Venable.

    Can the Private Sector Go on Cyber Offense? with Armadin's Stacy O'Mara
  3. Sep 8

    25 Years After 9/11: Lessons in Modern Homeland Defense with Michael Chertoff

    Twenty-five years after the September 11 attacks, former Homeland Security Secretary Michael Chertoff joins Frank Cilluffo for a firsthand account of that day and the national security transformation that followed. Chertoff recalls arriving at the FBI command center as the attacks unfolded, hearing the order to shoot down the fourth plane and confronting the urgent question of whether more attacks were coming. He also describes the information-sharing barriers exposed by 9/11 and the effort to bring agencies with different missions and cultures together under the newly created Department of Homeland Security. The conversation then turns to the threats facing the country today. Chertoff explains why terrorism has become more distributed and difficult to detect, how cyberattacks and artificial intelligence are changing homeland security, and why the United States must remain vigilant without treating every risk as something that can be eliminated entirely. Main topics Michael Chertoff's memories of September 11 Building DHS and breaking down information silos How the terrorist threat has evolved Cyber, AI and critical infrastructure Vigilance and managing risk Key quotes "Within minutes after I arrived, we heard about the third plane hitting the Pentagon, and then I remember sitting in the command center and hearing the order being relayed to shoot down the fourth plane." — Michael Chertoff "If you don't coordinate at the federal level, you run the risk of again having another missed opportunity to stop a terrorist attack." — Michael Chertoff "We've undermined those big terrorist organizations, but now we have very small networks or even individuals who are acting because they're being prompted or even on their own, they're getting radicalized." — Michael Chertoff "The distributed nature of terrorism now, and the fact that we now have domestic terrorists, indigenous to the U.S., means that the process of detecting is much more difficult." — Michael Chertoff "The problem has not gone away. It's simply altered and modified and evolved." — Michael Chertoff "What you have to do is manage the risk by understanding what's a reasonable amount of risk you have to tolerate." — Michael Chertoff Links and resources About the Guest Michael Chertoff served as U.S. secretary of homeland security from 2005 to 2009, following roles as a federal appeals court judge and assistant attorney general for the Justice Department's Criminal Division. He previously supervised the Justice Department's investigation into the 9/11 attacks and is the author of Exploding Data: Reclaiming Our Cyber Security in the Digital Age. He is now co-founder and executive chairman of the Chertoff Group, a global security risk management and advisory firm.

    25 Years After 9/11: Lessons in Modern Homeland Defense with Michael Chertoff
  4. Sep 1 ·  Video

    How DARPA Is Preparing for the Next Technological Surprise with Patrick Lincoln

    Cybersecurity has spent decades in a reactive cycle: find a vulnerability, patch it and wait for the next one. Dr. Patrick Lincoln joins Frank Cilluffo to discuss DARPA's effort to break that cycle by building systems that are inherently secure, private and resilient from the start. They explore lessons from the AI Cyber Challenge, the role of mathematical proof in eliminating vulnerabilities and the challenge of making complex systems trustworthy even when individual components fail. The conversation also examines how research can move beyond isolated demonstrations to strengthen the technologies and infrastructure society increasingly depends on. Main Topics Preventing and providing technological surprise IPTO's return to computer science foundations Inherent security and privacy AI-enabled vulnerability discovery and patching Formal methods and mathematical proof Trust and resilience in megasystems Moving research into real-world use Key Quotes "This back and forth or cat and mouse game has been going on a long time. I'm getting tired of that. And so we're trying to find new foundations to build inherently secure systems and inherently private systems." — Patrick Lincoln "We need power tools to let people do more, better, faster, with quicker reaction time and higher assurance that what they do actually does lead to really fixing the problem and not creating new problems, not causing harm to the system." — Patrick Lincoln "Software is difficult. And so how can you get to high assurance for a complex system involving the analog systems, the sensors and actuators, the digital systems and hardware, and the digital systems and software? And there are processes for this, some of those involving mathematical proof and formal methods." — Patrick Lincoln "If you've got a million subsystems, there will be failures, and perhaps some of them even maliciously so. ... By building these compositional—think internal firewalls—within a complex system, and ways that we can understand the emergent properties of a large collective of systems, ... we can then predict and therefore give assurance about its behavior long term." — Patrick Lincoln "My favorite answer to this problem, the world's most urgent critical problem, I'll say the DARPA answer is improving our collective ability to solve urgent critical problems." — Patrick Lincoln Links and Resources DARPA Information Processing Techniques Office Patrick Lincoln biography DARPA AI Cyber Challenge PROVERS formal-methods program Resilient Software Systems Capstone About the Guest:  Patrick Lincoln is director of the Information Processing Techniques Office at DARPA, where he leads work spanning artificial intelligence, cybersecurity and privacy, and resilient complex systems. Before joining DARPA, Lincoln held senior research leadership roles at SRI, an independent nonprofit research and development institute, where he led multidisciplinary work across computing, cybersecurity, artificial intelligence, and advanced systems research. Lincoln holds a Ph.D. in computer science from Stanford University and a B.S. in computer science from MIT.

    How DARPA Is Preparing for the Next Technological Surprise with Patrick Lincoln
  5. Aug 25 ·  Video

    CI Fortify: Isolation, Recovery and a Minimum Viable America with CISA's Matt Rogers

    If communications fail and operational technology is damaged during a cyber attack, critical infrastructure operators may have to keep essential services running without internet access, outside assistance or readily available replacement hardware. Matt Rogers of the Cybersecurity and Infrastructure Security Agency (CISA) explains how CI Fortify prepares water, energy and transportation systems for that scenario. He and Frank Cilluffo discuss operating through compromise, uncovering hidden dependencies and testing whether critical systems can isolate and recover before a crisis arrives. Main Topics CI Fortify and emergency planning Operating through compromise Communications outages Hidden IT/OT dependencies Isolation and functional testing OT sovereignty Secure by Design for OT Public service and technical talent Key Quotes "If there is another Colonial Pipeline type incident again... how do we make sure that their incentive structure isn't I go from 100 to 0, it's that I go from 100 to 30? 40, where that... X is defense critical infrastructure, it's health and public safety, because we just can't afford to go to zero for our minimal services. We need sort of a minimum viable America." — Matt Rogers "Nobody is coming to save you unless you've prearranged to be saved, which is a bit grim. But in a communications outage, you can't call for help." — Matt Rogers "The more you tell me you have an air gap, the less I believe you... It's just really unsustainable for a lot of organizations.." — Matt Rogers "Security doesn't have to be frictional and hard. The goal should be to design security such that you are kind of the well-lit path, the easy path, the default state is the secure thing to do." — Matt Rogers Links and Resources CISA: CI Fortify CISA: Secure Connectivity Principles for Operational Technology CISA: ​​Barriers to Secure OT Communication: Why Johnny Can't Authenticate​ CISA: Secure by Design About the Guest: Matthew Rogers, PhD is an Industrial Control Systems cybersecurity expert in CISA's Office of the Technical Director and leads the agency's Secure by Design initiative for Operational Technology. He earned his bachelor's degree in software engineering from Auburn University and later completed a DPhil in Cyber Security at the University of Oxford as a Rhodes Scholar, focusing on securing legacy OT networks in vehicles. Before joining CISA, Rogers was a founding engineer at Shift5 and worked on broader ICS cybersecurity efforts at MITRE. His work at CISA focuses on translating ICS research and development into practical capabilities for critical infrastructure.

    CI Fortify: Isolation, Recovery and a Minimum Viable America with CISA's Matt Rogers
  6. Aug 18 ·  Video

    Boarding the Dark Fleet: Coast Guard Cyber and Maritime Security with RADM Jason Tama

    The maritime world is more connected than ever, creating new efficiencies—and new ways for cyber incidents to move quickly from shore-based networks to ships operating around the globe. Rear Admiral Jason Tama, Commander of U.S. Coast Guard Cyber Command, joins Frank Cilluffo to explain how the Coast Guard operates across military, intelligence, law-enforcement, regulatory, and homeland-security missions to protect the Marine Transportation System and counter adversaries in cyberspace. The conversation also examines the Coast Guard's latest Cyber Trends and Insights in the Marine Environment report, including cyber operations aboard Dark Fleet vessels, the growing convergence of IT and operational technology, persistent weaknesses in basic cyber defenses, and the importance of working closely with industry. Tama argues that prevention alone will never be enough: maritime operators also need to be prepared to keep functioning through their "worst digital day." Main Topics Covered Coast Guard Cyber Command's three-part mission Title 10, Title 14, and Title 50 authorities Coast Guard integration with U.S. Cyber Command Cyber operations aboard Dark Fleet vessels Cyber risk across ports and maritime infrastructure Public-private operational partnerships Persistent cybersecurity fundamentals International maritime cyber cooperation Key Quotes "You can't wait till the crisis or contingency to bring everyone together." — Rear Admiral Jason Tama "The great thing about ships now is they're all connected all the time. The bad thing is the ships are all connected all the time." — Rear Admiral Jason Tama "We're never going to Cyber our way out of this problem, right? There's no Cyber panacea." — Rear Admiral Jason Tama "Resilience is so important and everybody has to be able to think about and have a plan for how do you continue to operate on your worst digital day because it's not a matter of if, it's a matter of when." — Rear Admiral Jason Tama "The work we're doing in the wild from whether it's power plants to cranes to locks and dams ... all over the world, it's really incredible mission work." — Rear Admiral Jason Tama Relevant Links and Resources Cyber Trends and Insights in the Marine Environment (CTIME) Guest Bio Rear Admiral Jason Tama is Commander of U.S. Coast Guard Cyber Command, where he oversees cyberspace operations to defend Coast Guard networks, protect maritime critical infrastructure, and counter adversary activity. He also serves as the Coast Guard's Service Cyber Component Commander to U.S. Cyber Command. Previously, Tama served as Senior Director for Resilience at the National Security Council and as Captain of the Port of New York and New Jersey. He is a graduate of the U.S. Coast Guard Academy and holds advanced degrees from the University of California, Berkeley, and MIT Sloan School of Management.

    Boarding the Dark Fleet: Coast Guard Cyber and Maritime Security with RADM Jason Tama
  7. Aug 18 ·  Video

    Private Sector Cyber Offense: What the New White House Memo Does—and Doesn't Do with Mike McLaughlin

    A new White House memorandum aims to bring the private sector more directly into cyber operations against transnational criminal organizations. But turning that policy goal into practice raises immediate questions about legal authority, liability, deconfliction and the risks companies could assume by participating. In this edition of Cyber Focus: To the Point, Frank Cilluffo talks with Mike McLaughlin about what the memorandum does—and does not do—under existing law, what needs to be resolved during the 60-day implementation window, and where private-sector capabilities may be most useful without interfering with ongoing military, intelligence or law-enforcement operations. Main Topics Covered Private-sector cyber offense Legal authority and liability Deconfliction with government operations Risks for participating companies The 60-day implementation window Where private-sector capabilities may fit Key Quotes "The [National Security Presidential Memorandum] isn't actually creating an authority; it's creating a record… that the administration or federal law enforcement can point to and say we gave you very clear authority… and if you step outside of that, you're on your own. — Mike McLaughlin "Deconfliction is a big problem because when you're dealing with the National Security Agency and the CIA and the FBI and US Cyber Command and CNMF and, you know, US SOCOM, and then you bring in ASD from Australia or GCHQ from the UK, and we're trying to deconflict all of this blue activity in cyberspace, it's really challenging." — Mike McLaughlin "If we start contracting with companies to conduct offensive operations, those companies become combatants." — Mike McLaughlin "For me, if the authorized target set are cryptocurrency wallets or keys or on-chain infrastructure that's being used to support transnational criminal organizations, that's an area that the private sector can cleanly operate without risking running afoul of traditional intelligence community activities, law enforcement operations, or military cyber operations." — Mike McLaughlin Relevant Links and Resources White House national security presidential memorandum National Cybersecurity Strategy Computer Fraud and Abuse Act (CFAA) Buchanan Ingersoll Rooney — Mike McLaughlin Guest Bio Mike McLaughlin co-leads the cyber practice at Buchanan Ingersoll Rooney. He previously served in government roles involving U.S. Cyber Command and the Cyber National Mission Force.

    Private Sector Cyber Offense: What the New White House Memo Does—and Doesn't Do with Mike McLaughlin
  8. Aug 11 ·  Video

    AI, Risk, and the Future of the Federal Workforce with OPM Director Scott Kupor

    The federal government is competing for technology and cybersecurity talent at the same time AI is beginning to reshape how that workforce operates. OPM Director Scott Kupor argues that meeting both challenges requires more than new tools or recruiting campaigns: government needs a personnel system that better reflects how people build careers today, rewards performance and adaptability, and creates room for responsible experimentation. Kupor joins Frank Cilluffo to discuss Tech Force and the push to bring more early-career technologists into public service; why he believes agencies should focus on practical, near-term AI gains rather than long-range plans that may quickly become obsolete; and what his years in Silicon Valley taught him about risk, execution and talent. They also explore what Washington and the technology industry misunderstand about one another—and why U.S. economic and national security increasingly depend on getting that relationship right. Main Topics Tech Force and two-year tours of public service Recruiting cyber and technology talent into government The federal government's early-career workforce gap Performance, merit and tenure in federal employment AI productivity and the changing federal workforce AI literacy and the continuing role of human judgment "Permissioned innovation" and responsible risk-taking Execution, adaptability and decision-making under uncertainty What Washington and Silicon Valley can learn from one another Key Quotes "I think every person coming out of high school or college, hopefully we can convince them spending 2 years in government is good for the country and good for them. It's really that simple." – Scott Kupor "If we're gonna attract early career people, they have to be able to come in an environment where their performance and their merit is a lot more important than how many years they've been here." – Scott Kupor "We should not be building, in my mind, the 2040 or 2050 plan for AI, because the very honest answer is we have no idea." – Scott Kupor "Everybody needs to develop some kind of AI literacy, right? So, and not just people who are software developers." – Scott Kupor "So the good companies, the good organizations, the good nonprofits, whatever it is, you have a theory of the case, but then you actually have to be willing to say, okay, our theory was wrong for X number of reasons and we're gonna change it. And I think it's very hard intellectually for people to do that. But that, I think, is the difference, ultimately, between successful and unsuccessful organizations." – Scott Kupor Links and Resources: Scott Kupor's OPM Blog About the guest:  Scott Kupor is director of the U.S. Office of Personnel Management, where he leads efforts to build a more accountable, mission-driven federal workforce. Before joining OPM, he was a managing partner at Andreessen Horowitz, which he helped build into one of the country's largest venture capital firms. He previously held senior technology leadership roles, chaired the National Venture Capital Association and taught entrepreneurship at Stanford. He is also the author of Secrets of Sand Hill Road: Venture Capital and How to Get It.

    AI, Risk, and the Future of the Federal Workforce with OPM Director Scott Kupor
5
out of 5
18 Ratings

About

As cyber threats evolve faster than policy, Cyber Focus delivers executive-level briefings on cybersecurity, national security, and critical infrastructure. From the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University, host Frank Cilluffo speaks with senior leaders across government, industry, and the intelligence community about ransomware, state-sponsored threats, AI, and the systems we all rely on—energy, water, telecom, and supply chains. Each episode focuses on real-world risk tradeoffs and practical steps organizations can take to strengthen resilience.

You Might Also Like