Featuring distinguished guests from the business world and government, Ahead of the Threat will confront some of the biggest questions in cyber: How will emerging technology impact corporate America? How can corporate boards be structured for cyber resilience? What does the FBI think about generative artificial intelligence? Listen to new episodes biweekly and stay Ahead of the Threat.
Listen to Ahead of the Threat episodes, read the transcripts, and find related material at fbi.gov/aheadofthethreat.
You can also follow the FBI Cyber Division on LinkedIn at linkedin.com/company/fbicyber.
Brett Leatherman, assistant director, FBI Cyber Division: Welcome to another episode of “Ahead of the Threat.” I'm Brett Leatherman, assistant director of the FBI's Cyber Division. Later, I sit down with Frank Cilluffo, director of the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University and host of the “Cyber Focus Podcast.” Frank has spent his career on a question I keep coming back to, which is, “How do you make cyber aggression cost enough to change an adversary's behavior, and how do you keep the systems Americans depend on running while you do that?”
But before that, the news. And this time I've brought in a key partner from inside the FBI. The FBI is running a coordinated push against cybercrime and cyber-enabled fraud that drains the money from American families across the country, and we've directed significant resources towards that effort. So, I've asked my partner in crime to sit down with me.
And that is Heith Janke, assistant director of the FBI's Criminal Division. Before his role as assistant director in the Criminal Division, he was SAC [special agent in charge] in the Phoenix Division of the FBI. And prior to that, he was a section chief of the Cyber Criminal Operations Section out of Cyber Division, the team at Headquarters that goes after cybercrime every day. He's worked these cases from the inside, and he brought that same cyber mission and perspective with him into the Criminal Division where his portfolio goes from violent crime to public corruption to cyber-enabled fraud, among other things.
So, Heith, welcome to the show.
Heith Janke, assistant director, FBI Criminal Division: Hey. Thanks, Brett. It's an honor to be here. I've watched the podcast since the very first episode, back when I was in the Cyber Division with you all. And to finally get to be on here is ... this is great. So thanks for having me.
Leatherman: Well, it's a good opportunity for you and I to talk through Operation Riptide, which is a campaign that we launched on June 9th. It runs the gamut from Cyber Division at Headquarters, Criminal Division at Headquarters, to all 56 field offices and even globally, leveraging our cyber legal attachés from around the around the world to work with international partners to impose cost on both cyber criminals and cyber-enabled fraudsters.
So, both our teams are working this. It really puts into action the priorities that the president set out in the executive order on cyber crime and fraud and in President Trump's Cyber Strategy for America. So from your perspective, as we started to talk about this, why now, in addition to the president's strategy, in addition to the EO [executive order] that we talked about, why was now the right time to engage in Operation Riptide and to pull our resources together to combat this pervasive threat?
Janke: Yeah. As I look across this, I think we need to frame it first of all when we're talking about fraud, cyber-enabled fraud, and cyber-criminal actors and the one thing we use constantly is the IC3 [Internet Crime Complaint Center] report. So, we encourage all victims to go to IC3 and report their crimes to the FBI -- or being a victim of a crime.
And when we look at the 2025 report that was put out in March, we saw that over $21 billion in loss had been reported to the FBI, and that was more than 1 million complaints. So, we saw a 26% increase from 2024, both in those reporting and the amount of the loss. So, one, we see that drastic increase.
Two, the other part: When we look at that as we can break that down into cyber-enabled fraud. And of the 21 billion, 17.7 billion was cyber-enabled fraud. So, what we are seeing is the criminal actors, the ability for them to scale and to move quickly, has increased dramatically, which is leading to more Americans being fleeced every day of their life savings. And the ability for us now to come together as the whole of government under this executive order, to do something more to target the actual criminal enterprises that are behind this. So, it's the first time through this executive order of everyone brings their tools and their different techniques and their expertise to put together one joint mission with the U.S government and working with private sector to target them.
So, that is the numbers in itself. You and I, we use data every day. We've got to make ... what our priorities are and then how we're going to use budgets and our resources to address them. Using this data from IC3 just shows this continues to escalate. And what we know behind every one of those million complaints, there's a real victim.
This is our grandparents. This is a teenager that is being, you know, financially motivated sextortion going on; that every one of those million complaints is someone going through a very horrible situation in their life. So, that's why this is so important for us to stop the fleecing of Americans and stop these transnational criminal organizations that are doing this.
Leatherman: And we know it's gotten easier and easier with the prevalence of emerging technology for actors to be able to target individual Americans to fleece them of their life savings, but also to leverage ransomware and other cybercrime tools to extort companies out of significant money. And so, one kind of theme that holds Operation Riptide together -- it's kind of the slogan for Riptide -- is, “No Safe Harbor.” And we call it “No Safe Harbor,” because it's important to demonstrate the work we do with our international partners overseas to really increase the ability to find the actors and hold them accountable wherever they sit.
And so, what does that mean for you when we talk about “no safe harbor”?
Janke: You know, it says an international problem. And that's why we work not only with our FVEYs partners, but across the globe. We have law enforcement attachés working -- I think it's in over 180 countries -- and developing those relationships within the country so that we can share intelligence and better target these networks.
So, for us, it is putting that constant pressure of wherever these organizations are, that one, we're holding them accountable, but two, making sure they know that they are being watched no matter where they want to conduct these frauds in the world. So, while most of these frauds may be done by transnational organized crime groups overseas, they know there's no safe harbor for them there, too. We will come and work with our partners to hold them accountable.
Leatherman: And we'll talk about this a little bit later. But “no safe harbor” applies to them as individuals, their criminal organizations, but also their money, their infrastructure, the tools that they use to target Americans. And so, “no safe harbor” applies to anything we can reach within that criminal ecosystem that allows us to have an impact on the threat during these two months that we're operating in this sustained campaign. We're really targeting all of that.
And so, the second story today is one of yours out of Criminal Division, and it's Operation Level Up. The idea is easy to say, but kind of hard to do, right? It's rather than meeting a victim after the money is gone or after a fraud has occurred, we endeavor to find the people while the fraud is still happening, or before it happens, and get to them first. It's on the prevention side of what we do. Tell our listeners what Level Up is and where it stands right now.
Janke: Yeah. So, what we're really predominantly talking about is the Southeast Asia scam centers that are doing romance and crypto investment frauds. That ... that’s the highest amount of fraud we see ongoing right now. So, we've got three pillars we look across to prevent, disrupt, and dismantle. And that is where the whole-of-government is focused right now.
Under the prevent pillar, Operation Level Up is the most impactful that we've seen. So, basically it is as we are seeing an ongoing crime happening with a victim, we go out and warn them and say, “Hey, this is happening. Please stop sending, wiring this money, going out and investing in Bitcoin ATMs or kiosks, and sending because we believe you are a target of a fraud.”
So, we've gone out and -- this has started in 2024, but really during Riptide, we're putting even special emphasis on it over this next 60 days. But we've been out to over 99 -- 9,900 victims and have warned them. And what we found is 77% of them were completely unaware that they were being targeted. And we've saved over 630 million. So, by going out and doing this prevention, we've stopped them from sending over 630 million.
The other devastating stat that I think about with the Operation Level Up that we sometimes forget, this has caused people to lose their entire life savings. They ... target our senior citizens for a number of reasons. That's a trusting community. They've had a life savings. They know it's there. Often isolated. So, they go after our senior citizens. And this has given ... driven people to the point where they've wanted to take their own lives because they've lost everything and don't know what to do. By our agents and partners going out and doing these warnings, we've referred 97 victims to a critical suicide intervention services because we've sound ... found them in such desperation. So, again, that shows the impact of what is going on.
The other thing that we do with Level Up, not only warning, but we work with our private-sector partners to take down the fraudulent investment platform domains. And just in the last month, when we did our recent sprint on our strike force that targets the scam centers, we took down 584 fraudulent domains that were being used to target American victims.
So, again, we see that force multiplier of ... we're making this investment to go warn, to stop the fraud from going, but also taking down that infrastructure that is being used to facilitate it. And I think between cybercrime and cyber-enabled fraud, that's what we've seen. Right? These groups will use the same type of infrastructure, whether it's a ransomware group or just a cyber-enabled fraud group, there's still pieces of the infrastructure, the key services they use that, when the Criminal Division and the Cyber Division team up and we take those down, we're impacting a bunch of cyber cases and a bunch of criminal cases, and that's why our two divisions, working in concert together, I think we've probably never had a closer relationship and how we're targeting this now, which means we're making a better impact every day for the American people.
Leatherman: That's right. And three quarters ... almost three quarters of $1 billion prevented in going to these fraudsters, but more importantly, lives that haven't been devastated, like we continue to see over and over because of the prevention of that money going over to these scammers, incredibly important. And then looking at ... after the mental health of victims as part of our victim pledge and promise, which is, recognizing they are victims of criminal activity and trying to find them the help that they need as victims and that that that's pervasive throughout how the, the FBI, whether it's the Cyber Division, Criminal Division, counterintelligence or counterterrorism approach, victims of crime.
Talk a little bit about the field office ... how the field offices lead this. You were in Phoenix as the special agent in charge for a little while. Phoenix is part of the operation. We also have partnerships with Secret Service and others to help scale this effort out. It's only, it's less than 2 years old. So, how has that progressed as an operation overall as time has gone on?
Janke: Yeah. So, we have a core group that's part of Operation Level Up that is working with different techniques to identify who the victims are. And then we actually have volunteers from every field office that sign up for a set period that every time essentially a lead comes in and it says, the group says, “We think this person is being scammed. Can we go get ahold of them right away?” People sign up and want to do this because we talk about a victim-centered approach and saving people in the FBI.
So, we've got people in every field office. When those leads come in, they make a phone call or go knock on a door to stop the fraud from occurring. And just recently; you know, we've got all kinds of great stories of how this has impacted. But one of the people we talked was getting ready to wire $1 million when we made that phone call and stopped it. And we've got countless examples of those of, you know, “Thank you to the FBI for letting me know this. I was just getting ready to do this or I was getting ready to sell my house and wire are these proceeds.”
So, I just can't say enough good work of what the field offices are doing. And our partners. The U.S. Secret Service has been with us from the beginning on this, too, along with several private-sector companies. But the work and dedication of going out to do this is just, you know, something we're proud of back here at Headquarters.
Leatherman: We talk about the IC3 reporting having gone up by 20% or so and looking at that 20 billion number, that is significant, right? But that's probably well underreported. And so, the number -- that is people voluntarily going to IC3 and making a report -- again, probably underreported, which means, the number’s probably significantly higher. And significantly more lives are being devastated as a result of this.
And that's why I think the administration has made such a priority here on targeting the scam centers that are, that are behind this. And we've increased some partnerships in some unique countries as well that maybe we haven't been quite as latched up with before on this stuff. So, as we kind of move forward here, how do you anticipate the ... law enforcement attachés playing into this whole model of prevention and working with and holding scam centers and individuals accountable outside the U.S.?
Janke: I mean, that's a key component. Because the scam centers are overseas. So, the criminal organizations are putting them in places where they know it ... it may be harder for us to reach to. So, just give you an example, we've developed a relationship with the Royal Thai Police in Thailand, who have been actively working on helping assist to dismantle the compounds that are over there and to stop it.
This is even more trickier because these criminal organizations are employing human trafficking victims that are the ones actually conducting the fraud. So, they're responding to a job notice where they think they are, and they end up being a labor trafficked victim, which just shows the complexity of this, of are those that are actually on the keyboards, talking to the Americans, to fleece them are victims themselves in a forced labor situation.
So, everything that we do here in the U.S. has to have that international component. And I only see that advancing because we're talking scam centers, but we still have the romance scams, the business email compromises, the tech support scams, all the things we've heard about for years aren't going down either. And even business email compromises—we thought that would probably go away. We would get those emails with misspellings. Now with AI (artificial intelligence) and with voice cloning and all those things, it can actually sound like a phone call from the CEO (Chief Executive Officer) saying to transfer this. Or it’s actually... the email is perfect. So AI is allowing them to scale more quickly and to do these frauds that are a greater scale and just it looks like it's legitimate. So, we're talking scam centers, but it's all throughout the world. And the West African Nigerian scams, all those things that we've talked about for years and years aren't decreasing either.
Leatherman: Yep. I think that's a great point. We're going to all continue to face a scaled threat environment. So we've got to scale through those partnerships—international, domestic, private sector—to take the fight to the bad guys as much as we can. The Royal Thai police, you mentioned them, during Operation Riptide, we were able to get a significant extradition from Thailand in the cybercrime program of an individual who allegedly conducted cyber attacks against the United States. So, really, this has been a great operation so far. We're halfway through, and we're looking forward to hopefully more extraditions and more accountability to actors here in the near future.
But that takes me to our third story, because you talked a little bit about the infrastructure and targeting, the ecosystem itself as well. And this is a good example.
On the first day Riptide was announced, we also announced the takedown of FirstVPN. It was an FBI-supported international takedown of FirstVPN, which had been running since approximately 2014. It allowed a variety of criminal groups to leverage anonymity, tools towards anonymity, to really hide where they were coming from to conduct a variety of different frauds, ransomware attacks and whatnot.
So, this effort, you know, targeted servers across 27 countries that was run by this particular criminal group. It sold itself as complete privacy and anonymity for cyber criminals. In practice, it really was built for criminal use. At least 25 ransomware crews had used it to scope out targets and break into networks. And partners in France, the Netherlands, Ukraine, the UK, Switzerland and Luxembourg, as well as Europol and Eurojust help with coordination all work together with the FBI, specifically FBI Boston Division and the FBI's Cyber teams to conduct technical operations to take those servers down. And what that does is across dozens, you know, those dozens of ransomware groups that are using that service amongst the scam centers who might be using it to hide where they're coming from, it removes that tool of anonymity.
And so you were chief of cybercrime for the FBI. You saw a lot of these operations come through. And I sometimes hear from folks, well, you know, if you don't get people into United States to face justice, what are you really doing in the cyber program? Talk a little bit about your perspective on why these kinds of takedowns matter. These technical takedowns and operations, even when we might not get a bad guy in custody?
Janke: Yeah, I think that's important. And we saw that in the ransomware space, you know, all the time when I was there. And that's why we had developed that key services model similar to the case you just talked about of how do we look at the services being used and how do we take action to stop that. And we always talked about throwing sands in the gear.
The more disruption we can constantly do means the less victimization they can do here in the U.S. So while it may not keep them offline forever, we disrupt and then we find where they pivot and move to, and we continue to disrupt until hopefully we can dismantle the entire group, find them in a country that may have an extradition treaty that we can eventually get them here.
But knowing a lot of time those actors do hide in countries that are difficult, how do we continue to attack the ecosystem from multiple angles and constantly be throwing those disruptions in there to stop? And now the one you just talked about. That's huge. And that's where those international partners come in.
Again, this isn't just the FBI doing these things and doing these takedowns and these disruptions. It's us, our domestic and our international partners. And when we come about this from all directions, that's when impact is made. And I think that's what's changed over the last several years of everyone coming together with what they have. And sometimes it may be, one of our Five Eyes partners overseas has a better authority and a better result. And the takedown may be happening with them, and we just assist from here in the U.S, but it's that type of strategy that continues to make an impact, because the more we can do to stop the daily victimization in the ransomware space, stopping the attack on our critical infrastructure across the U.S., the better off we are.
Leatherman: Yeah, I think it's safe to say you and I have the same perspective when it comes to kind of that “best athlete” approach. Our teams.... we ask our teams to look at who is the best athlete. If it's us, we should run, but keep partners with us to aggressively go after the actors. But if it is a partner, whether it's, you know, outside the United States or domestically, our job is just to keep up with them as best athlete and support them in any way we can to allow them to do really good work and provide them the tools, resources, intelligence and other things that help them do it better, the best we can. And sometimes that means sharing until it hurts and we should... there should be no egos in the room when it comes to taking the fight to the bad guys. And, you know, kind of that ego-less approach in allowing teams to really nimbly but, but quickly go after the bad actors is incredibly important.
Janke: For sure.
Leatherman: All right, Heith, thank you so much. Let me just ask this real quick before we go: What do you see... where do you see Criminal Division and the FBI's criminal program going, you know, in the next few months? Where should folks expect to see you go?
Janke: I mean, we've got so many different priorities. We're protecting, you know, our streets from violent crime and gangs every day. We are fighting cartels and through our Homeland Security Task Force and all the fentanyl and drugs that are coming into the U.S that are killing Americans. We've got the crimes against children mission and human trafficking mission where we're saving kids.
And then now with the priority on the frauds and both the government fraud of those that are taking... committing the healthcare fraud acts. And then all of the organized crime actors that are doing these scams. Like, it is all at once moving as a priority. But it just means our taxpayers are getting so much more out of us, along with our partners, to make this the safest place in the world like we love that it is.
Leatherman: Yeah. I often say the Cyber Division teams punch above their weight because, and you've seen it, there's so few relative to the adversaries we face. But the teams are dedicated and committed at, you know, headquarters across the field and globally. And having a front row seat to what Criminal Division is doing as well. Criminal Division is punching above its weight in this environment where you're targeting drugs, predators, corruption, and a variety of different things.
So I just want to say thanks to you and your teams, and what they're doing as part of Operation Level Up for the partnership that you guys have with Cyber Division, for the days, nights and weekends that you guys work to keep America safe. And thanks to all 56 field offices and the teams that are working the criminal fight there, along with their colleagues in Cyber Division for what they're doing. And thanks for joining me on the show today.
Janke: Thanks for having me.
Leatherman: Great. Well, that was Heith Janke, assistant director of the FBI's Criminal Division. So this is where my conversation with Frank Cilluffo will pick up. Heith and I work the enforcement end of this. Frank works the strategy and policy side of what's happening. How do you deter behavior over the long run, and how the country stays standing when deterrence sometimes falls short? That conversation with Frank is next.
_________
Brett Leatherman, assistant director, FBI Cyber Division: Welcome back. Joining me today is Frank Cilluffo, director of the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University and host of the weekly “Cyber Focus podcast,” which I got to be on last week.
Frank has spent decades at the center of U.S. cyber policy. He served on the Cyberspace Solarium Commission, advised the White House on homeland security and counterterrorism, and now leads one of the most active cyber poly in … policy institutes in the country.
Over the past year, the institute has put out numerous papers, to include addressing the PRC [People’s Republic of China] cyberthreat, a paper on offense, deterrence, and strategic competition, and has built several task forces, to include one with the U.S. Chamber of Commerce on regulatory harmonization.
In January, Frank carried that work into testimony before the House Homeland Security Committee.
Frank, welcome to the show.
Frank Cilluffo, director of the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University: Brett, thank you so much for having me.
Leatherman: Glad to have you. So Frank, McCrary has had a busy year. Before we get into any one piece, for the listeners who are less familiar with McCrary, can you tell us what it is?
Cilluffo: Sure. So, I like to think of ourselves as a think-and-do tank, not simply admire problems, but be in the solutions business as well. The way to summarize it very briefly is, in D.C. we do our policy work, which hopefully is left of boom. We try to shape and look at strategic approaches that we think the government, industry, and others should take and move forward.
In Auburn, that’s sort of our tech bench. We have multiple labs there where we support different utilities; we support the government; we have work with the U.S. Secret Service; we have work with Department of Energy. That’s where a lot of our students … hopefully also to be FBI agents in the future and support that … tomorrow’s workforce.
And then in Huntsville, we have a group that’s a little more operations, where we focus largely on applied research. I have nothing against all the good work that’s being done in terms of bench research, but we’re focused on the here-and-now kinds of problems and, and want to be part of that solution set. So, a lot have one of those pieces, very few have all of those pieces coming together.
Leatherman: Yeah. We rely on McCrary a lot for kind of understanding the emerging policy picture. And that’s why I’m so excited to have you on the show. The show is focused very much on the operational environment, kind of the threat environment seen from CISOs [chief information security officers] and industry. But a lot has happened this last year when it comes to the policy front.
And I think it’s that … that perspective is so important. If you were to say kind of what your top priorities are for McCrary, right now, what are those, you know, in June of 2026, and where is it going, do you think, through the remainder of ‘26?
Cilluffo: You know, that’s a great question. We have a lot going on in all of our various vehicles and mechanisms. But I think at the end of the day, it’s supporting the women and men who are doing … the important work inside the United States. FBI very much at the top of the list.
I would also add the National Security Agency [NSA], CISA [Cybersecurity and Infrastructure Security Agency] … and our friends at DHS. Uh, how that connects with SLTT — state, local, tribal, territorial. And then to me, the public-private partnership: I’ve been a little dismissive. I’ve always said, “Long on nouns, short on verbs.”
We’re actually getting to the point where we’re seeing operational collaboration. And that’s where I think you’re going to have the biggest breakthroughs, because quite honestly, they’re on the front lines of this war for a while.
And this is not aimed at any agency. We’ve been blaming victims. We’ve got to make sure that they’re … that we actually impose cost and consequence on the actual perpetrators and bring in our private sector to be part of the solution. So, not a very eloquent answer, but we’ve got a lot going on.
China, China, China, China.
Obviously, some of the activity and the lessons learned that we will see from Ukraine and the Russian invasion. These are all movies coming to a theater near you. We have an opportunity to not only support the Ukrainians, but also to learn from them, because don’t think that that’s not coming to a domestic environment in the future.
And obviously, looking at some of the regulatory harmonization issues which you discussed and then … sort of package it all and hopefully advance the ball on some of these issues.
Leatherman: That’s great. We’ll get into a few of those in particular. I love the industry piece for us. We have to close the gaps when it comes to deterrence and disruption against actors. And there are increasingly companies who are looking to do that, who have the ability, the visibility across their ecosystems, and the ability to conduct those disruptions.
Cilluffo: And the Bureau has been really good at that, I have to note.
Leatherman: No, thank you. Yeah. Whether it’s Microsoft when it comes to the LummaC2 takedown or working with Google on IPIdea, or working with Lumen on some of the residential in Comcast and others on some of the residential proxy providers, we really can scale our disruption operations when we leverage more companies like that.
Cilluffo: Well said. I’m looking forward to seeing more of that.
Leatherman: Good. You’ll see more coming here to a theater near you soon.
So, your December paper on offense deterrence and strategic competition and then your January testimony, in front of the House, made the same argument. The U.S. has been historically reactive in a space that needs a more deliberate strategy. The institute draws a clear … a clean line between deterrence by denial, and deterrence by cost imposition.
So, from McCrary’s position, where does the U.S. need to pivot when it comes to deterrence and what does a more deliberate approach look like?
Cilluffo: You know, that’s a great question. That could be a 45-minute conversation, but I’ll try to be brief, which is rare for me. I’ve never had an unspoken thought. But the way I would look at it is, deterrence by denial and cost … they’re part of the same coin. If you look at one and not the other, you’re missing out on the opportunity to ultimately influence the behavior of our adversaries.
Heretofore, I think we’ve been focused very much so, and for good reason, on deterrence by denial, making it harder for the adversary to have impact on their attacks and, and everything we can do to defend our systems. That … we need to double down on those efforts.
But in itself, that would be insufficient. We’ve got to actually become a little more proactive, where we ultimately get in the decision chain and calculus of our adversaries to recognize that, “Hey, there’re going to be consequences for this behavior.”
That means, sometimes it can be a diplomatic initiative, sometimes it can be an economic initiative, sometimes it can be a law enforcement initiative, sometimes if need be, and last resort, it could be a military or intelligence initiative.
Leatherman: Or a combination, sometimes, of each of those.
Cilluffo: And I think it really is. That’s the beauty of it. It has to be a combination of all of the above.
We’ve almost treated cyber in isolation. It’s mainstream. It’s part of everything we do as an economy, as a country, as a national security community. And we need to start looking at it, I think, through that lens.
Leatherman: Yeah, I think cyber effects to counter cyber effects are not … they’re impactful, but they’re not as impactful as when you pair a lot of that work together. I love the kind of distinction you guys draw between deterrence by denial and deterrence by cost imposition.
Just this past winter, we did Operation Winter SHIELD. It … we got a lot of airtime on “Ahead of the Threat,” our podcast here that you’re sitting on today. And we thought it was so important to share our perspective because we have room to grow on the defensive side. We need to raise that collective resilience in order to defend critical infrastructure and everything else.
By the time this podcast launch … launches … we will have announced the initiation of Operation Riptide, which is the imposition of cost against the actor side.
Our goal is to defend the United States through, you know, providing threat intelligence and defensive action, but really imposing costs. We’ve got to continue to scale our effort to do that. And that’s really aligned with the president’s cyber strategy.
So, it’s taking the fight to the bad actors. And we call … the slogan for this one is, “No Safe Harbor,” which means it doesn’t matter where you are in the globe, our goal is to reach out and grab you or impose cost in some way, shape, or form to deter you.
So, is there an area where you see more value in one side of the equation or the other, or do you kind of see that as an equal opportunity for all of us?
Cilluffo: You know, I have been a big advocate that we need to lean forward. We’re never going to firewall our way out of this problem alone. But if you do move in that direction, the importance of defense goes up, too, because obviously we’re dealing with thinking predators here, and they base their actions on our actions in part.
So, I think they have to … they’re not mutually exclusive. I think they’re mutually reinforcing. But, at the end of the day, we do need to impose costs. I want them, if not, dissuaded or even compellence if need be.
But I want them looking over their shoulder where, in a military setting, it’s sort of like suppressive fire. You may not always stop everything, but if they’re looking over their shoulder, they’re not planning attacks as much.
Leatherman: So, they’re thinking twice about some of those attacks as a result of that.
Cilluffo: And they’re thinking twice. And if they do, there will be consequences. And I think there have been some good success stories, but I think we have to scale that.
Leatherman: Yeah. Be more intentional. You have previously said that we need to shift from reactive and episodic responses to a more durable posture. What does that look like?
Cilluffo: You know, let me … so in a way, we’ve ceded our strategy to the adversary. If you think about it, we’re looking through rearview mirrors. Someone does something to us, we fix that. We focus on that act or we’ve given them the initiative. We need to get to the point where we’re shaping that in our best interests.
And I think the national strategy laid out a really good roadmap in terms of its six pillars to get to that. I think law enforcement plays a critical role in all of that. But to me, it’s … this is an always-on environment. It’s not episodic. We do amazing work, but it’s like a one-and-done.
I want to do that every day, all day.
Leatherman: Persistent engagement.
Cilluffo: And persistent engagement. Absolutely. And to me, it’s not just military persistent engagement. I mean, there’s been a disconnect between the Title 10 and Title 50 world. For a long time, the Title 50 world and the national security and intelligence business; they would never want to compromise a tactic, technique, procedure, tool, whatever it may be.
AI [artificial intelligence] is changing that overnight. So, whatever we thought we had in our arsenal, we got to re-up that daily. So, when you actually look at it, it’s sort of like Krav Maga. You’ve got to wrestle.
Leatherman: Yeah.
Cilluffo: Fight with the enemy to know where they’re going to punch.
Leatherman: So, differentiate between Title 10 and Title 50 for the audience.
Cilluffo: OK. So, Title 10 are largely military authorities, where it is very much in a war fighting. So, we do need to integrate cyber into our warfighting strategy and doctrine. That is essential. Title 50 is this significant and hugely important role that the National Security Agency, of FBI, the Central Intelligence Agency, and others play in terms of … collecting, information and other activities short of military operations.
Leatherman: And then you’ve got your Title 18, which allows us to collect on …
Cilluffo: Which is essential.
Leatherman: … the law enforcement side of things.
Cilluffo: And 32 with the National Guard and domestic. So, getting all that alphabet soup combined is essential.
Leatherman: Integrating that and being able to move across agencies and authorities where necessary is what’s so important.
Cilluffo: Because everyone plays a big role in it. I mean, I’m at Auburn, we love football. So, at the end of the day—exactly. But we’re back. We’re back. Well, we’ll be back this year. —But I mean, if all you have is … a defensive or an offensive line, at best, you’re just—at best—staying even.
You need a quarterback. You need linebackers blitzing the adversary’s quarterback. You need all of it synchronized and you need an offensive coordinator and a defensive coordinator. Those should all come … come together through a head coach. And right now it’s sort of like a lot of … a lot of calls are being made, but they’re not always as synchronized as I think maybe they should be.
And I’m a little dated. It’s getting better, it’s much better. But we need to double down on those efforts.
Leatherman: Well, that’s a good transition into … the amount of change that has happened in the cyber policy side this year alone. On March 6, the White House released President Trump’s Cyber Strategy for America. And at the same time, they released Executive Order 14390 on Combating Cybercrime, Fraud and Predatory Schemes Against American Citizens.
You had Director Cairncross on your show kind of talking about the National Cyber Strategy. How is the Institute reading that and preparing for that implementation? Like, kind of give me your thoughts on how that changes the perspective when it comes to that forward lean … leaning approach we’re looking to take.
Cilluffo: Yeah, that’s great. So, I think it really did emphasize and recognize that we do need a more proactive forward-leaning approach. So, for starters it’s the narrative making the case. And … that in itself was actually a feat and is important. And … it’s not that it didn’t occur in the past. It’s that it was largely episodic, driven by individual operations, cases, and the like.
So, I think there is recognition, we need to be leaning in that direction. Secondly, I … you know, a policy promulgation and implement; it’s always in the implementation that it matters. And just like the announcement you made momentarily ago with Operation Riptide, these are the sorts of things that will change the calculus. It’ll put thoughts in the adversary.
And most importantly, it’s going to stop blaming the companies who need to do more. And actually the perpetrators, if you think of like—let’s talk the Typhoons real quickly. Salt Typhoon: catastrophic. But that’s espionage. “I’m shocked there’s gambling going on in the casino.” In a way, you can say hats off. That’s not the right answer because it pisses me off. But it is what it is.
Flax Typhoon, Silk Typhoon, with particular devices. But with Volt Typhoon, I think a line was clearly crossed in the silicon. This was a red line. This had zero espionage value. This had zero value other than and partially maybe letting us know that they’re there, as part of their calculus, to sort of like, as my friend Rob Joyce says,”It’s like strapping IEDs [Improvised Explosive Devices] and … digital IEDs onto our critical infrastructure.” And that to me is unacceptable. That demanded a response.
Leatherman: Yeah. I, you know, and we did conduct counter-Volt Typhoon activity, but that was a shift in posture by the PRC [People’s Republic of China], moving what we had from what we had traditionally seen as intellectual property theft and competing with us, which is a national security issue.
Cilluffo: Absolutely it is.
Leatherman: Because they’re …
Cilluffo: Our economy is. Yeah.
Leatherman: … competing with us economically by stealing our intellectual property. But this was different in that it preplaced that capability on critical infrastructure, in the event of some sort of military action.
You guys, released kind of Code Red, a paper that talked about this, which was really consequential. Can you get into a little bit of what you guys looked at in that paper?
Cilluffo: Yeah. What we wanted to do with this paper was, everyone was confusing the various typhoons. Each one on their own is a really bad day. Collectively, it’s the perfect storm.
Leatherman: And I think that’s the key …
Cilluffo: So …
Leatherman: …with the paper is, a lot of folks look at this and they say, “Flax Typhoon did this, Volt Typhoon did this, Salt Typhoon did this.” You know, we tried to bucket it into espionage, intellectual property theft, preplacement capability. What you’re saying is that we’ve got to look at this together. In totality, it represents something potentially even more significant.
Cilluffo: Absolutely. It indicates … it’s a clear indicator of what the intentions and capabilities are. And yes, we do need to look at this holistically. And each one in itself, like I said, is significant. But collectively it, it sort of raised I think what many of us intuitively knew and thought made it very blatantly, “Hey, we’re here.”
And … obviously, with Volt Typhoon, if they have the potential to cause effects at a time of their choosing, that’s not a good day, especially with, Taiwan in 2027, 2030, and all these sorts of things out there. To think that the homeland is off piste and not a target would be foolish.
Leatherman: And talk about that. You mentioned 2027 and 2030. Kind of … that’s been a discussion that you have been having at McCrary with some of the folks there. Talk through what that means to you.
Cilluffo: So, this task force—I’m trying to remember who all our chair—Bill Evanina, who … former FBI, was, part of this, as well as Brad Medairy at Booz [Booz Allen Hamilton], and Mark Montgomery at FDD [The Foundation for Defense of Democracies].
So, we’re looking at sort of, what could trigger in the event of a Chinese invasion of Taiwan and they’ve made very clear, some of the timing, but, obviously that’s going to be up to their time in choosing as to when and if they want to act.
But ultimately to try to stymie our ability to sort of weigh in, I think that that was the signal they were trying to send with, with Volt Typhoon. I … mean, I don’t think … I think they knew we were going to, unveil some of this and recognize what was happening. So, it’s not like a traditional espionage campaign. I think this was a message and sent strong message.
Very strong. Yeah.
Leatherman: OK. Now, shifting back to the cyber … national cyber strategy, which kind of encompasses both nation-states and criminal actors, the six pillars of the cyber strategy couldn’t be more clear and what the expectations of the U.S. government are.
And really kind of establishing that new relationship that you talked about with industry: not treating them as victims, but enabling disruption operations with industry and shifting the risk calculus in the cost from victims to foreign actors.
Cilluffo: The perpetrators, yeah.
Leatherman: Which is incredibly important. And then EO [executive order] 14390 was released at the same time, which kind of operate … operationalizes Pillar One. And I’ll say Operation Riptide is a direct response to Pillar One and to the executive order. It’s meant to execute across industry, our international partners against the actors for 60 days to impose cost.
What’s your kind of interpretation of where we need to go with Pillar One and … the EO, to be able to combat just this rampant targeting of U.S. critical infrastructure and industry by these foreign actors?
Cilluffo: You know, firstly, to make clear that it’s unacceptable behavior. So, sometimes it’s not cutesy signaling. We’ve just got to be very plainspoken, blunt, and demonstrate that there will be consequences.
Secondly, it is to work with the broader interagency to be able to harness some of those capabilities because everyone has an important play to role … a role to play.
But it’s getting, all of that moving in the same direction at the same time to have an outcome and an impact that you’re hoping to achieve. Can’t do this without industry. That’s … they’re essential partners.
And nor can we do this without our international allies. I mean, obviously, we start with the Five Eyes relationship because that’s a strong, robust relationship and tons of history and scar tissue. And to me, trust is so essential in this space.
But then we’ve got to start expanding with bilats and other organizations such as NATO and the equivalent on the law enforcement side. These are, these are essential kind of going forward because a lot of the perpetrators are operating in areas that are provided safe haven by countries that are … definitely don’t have our interests at heart, you know. Quite opposite, inimical to our own.
So, how do we start getting there? And I’m excited about some of the activity the Bureau’s doing there. And I think you will need to do that with some of your partners in the region.
Leatherman: Yeah. Nothing that we do would be as sustained or enduring as what we do when paired with industry visibility.
Cilluffo: And allies, right?
Leatherman: And allies and U.S. Intelligence Community authorities or visibility into the threat. And certainly, our Five Eye, or what we call our Cyber Nine partners, who are that eight countries plus Europol working together to combat cybercrime every day of every week of every month of every year, just to try to take that fight to the bad actors.
Now, we know that both, the PRC, this through the CCP [Chinese Communist Party], and criminal actors are targeting critical infrastructure. You have a standing task force focused on critical infrastructure and emerging tech, specifically AI and quantum-based considerations. AI is reshaping what the threat looks like for energy, water, telecom, transportation, health care, and on and on.
Cilluffo: Everything, yeah.
Leatherman: It’s changing, really, from an AI perspective, what defenders can do, especially in those operational technology environments. The recent AI executive order, with its voluntary frontier model framework, is directly tied to the conversation that we’re having here
So, from your perspective, what is the Critical Infrastructure and Emerging Tech Task Force focused on right now? And how are you thinking about this problem when it comes to AI?
Cilluffo: Oh, that’s an excellent question. And AI is changing; everyone says … that the current shiny object is changing the world. But in this case, it really is transforming the way we do business, the way we fight wars, the way we defend our country, the way we live as human beings, and obviously fight crimes
So, what would be in the hands of maybe three or four nations five years ago, the bar is getting even lower to entry to be able to have a significant cyber capability.
So, when it comes to AI, I genuinely think Anthropic handled Mythos very responsibly. If China had come out with a Mythos, would there be a press conference? Would there be any responsible use? We wouldn’t know until we’re owned.
So, the reality is, is how do you replicate that? That, that’s hard. But I think that getting to the point where you have voluntary relationships between the frontier model companies—OpenAI, Anthropic, and others—is a very smart way to go because ultimately, we got to get it into the hands of our defenders of our critical infrastructure that basically keep the lights on and our economy going.
So, I think in this case, everyone’s interests aligned in the right way. I just hope we can sustain that. And to me, I think we had responsible actors here, but, in the future, we’re going to have to make sure that we, whenever the next model comes forward, they are literally coming up with …
… I just today I released a podcast with Daniel Cruz of Palo Alto Networks, who is a partner at Glass Wing on the executive order. And, what they saw in three to seven years is being done in weeks. The KEV List, the known exploited vulnerability list that the government holds—CISA [Cybersecurity and Infrastructure Security Agency] in particular has about 1,500 that’s just been quadrupled, if not more, overnight.
So, the reality is—and we like to call them “zero days.” Zero days is someone … but the unknown, exploited vulnerabilities, those are popping up left, right, and center and I think that the initiative in this space has always remained with the attacker, which is why I think we need to go forward as well and learn from that.
But I also am very concerned about, obviously, our critical infrastructure on our operators. So, how do we make sure that we get it into their hands?
So … and Patch Tuesday? Blow that up. That’s not happening.
Leatherman: It’s patched by the hour.
Cilluffo: Patched by the minute. Yeah, it’s almost.
Leatherman: Continuous patching is what we’re looking at. Continuous vulnerability management, as opposed to a 30-day patch cycle or a one-week patch cycle, which is historically, it’s got to be instantaneous.
Cilluffo: By the way, the Bureau needs access to future models. And they will. And, I do think that’s essential as well as CISA, in terms of the role that they’re playing with some of their critical infrastructure owner-operators. So, I think, right now it’s … the executive order struck a really delicate balance between innovation and security.
Leatherman: That’s key.
Cilluffo: Here’s the other thing: We can’t cede that to China either.
Leatherman: That’s key. We’ve got to innovate … if we cede innovation we give the bad guys …
Cilluffo: We lose. We lose.
Leatherman: … a leg up. And so, I love how the White House is focused on innovate. Continue to innovate at speed because that’s a national security issue. Our private sector; the United States is what it is because of the innovation of it. And we can’t stifle that. And that’s the position that the administration has taken: continue to innovate.
But let’s work together to find ways to defend critical infrastructure.
Cilluffo: So, if you’re purely looking at it through a national security lens, the hope would be to try to stymie it. You can’t: the genie’s out of the bottle and, and you’re absolutely right. It’s striking that right balance.
I think it did find the right balance and calibrated it right. And I think, like any other executive order or presidential directive, implementation is going to be key.
And you got to make sure you have the resources, too. Policy without resources is rhetoric. You want to make sure that, yeah, you’re funded as well.
Leatherman: Your point is well taken that, Anthropic in this case was very responsible in coming out and saying, “Hey, this is going to cause problems, very significant problems. So let’s pause on the release.”
OpenAI has also released their trusted defender. I can’t remember the exact program, but where vetted defenders can get access to a model which reduces the guardrails in order to look at their own environment where their vulnerabilities are.
I think the frontier companies recognize where this is going, and they’re being incredibly transparent and responsible …
Cilluffo: U.S. companies.
Leatherman: … U.S. companies. That’s a good point. In November, Anthropic released, you know, a report talking about how PRC actors were able to utilize their commercial platform, their chat bot, basically, to conduct, CNO [computer network operations] …
Cilluffo: They were doing some signaling, maybe?
Leatherman: Yes. Maybe some signaling there. So, transparency is key. And I think, as long as we have these relationships with the providers, that is … allows the government to understand risk and then convene and work with critical infrastructure owners and operators, key organizations that support the government in the defense industrial base, to start to get ahead of that. It’s going to put us in a better position, not a great position, but a better position, I think.
And then we’ve got to get to this mindset where we can’t just defend at human speed. In adoption; my fear is adoption of AI is happening in some cases too slowly here. And I know there’s … we’ve got to look at the effects of agentic AI and whatnot. But at some point, we have to start to put these technologies in place and embrace them a little bit quicker, because we can’t defend the machine operations at human speed.
And so, where’s your perspective, is the task force looking at this particular issue, adoption? What kind of speed and time frames we need, what it takes to do that across critical infrastructure?
Cilluffo: We’re looking at it. I would be lying if I told you I had a comfortable answer in all of that. You know, there are certain … certain decisions that I think someone, only someone who’s sworn to the Constitution should make. I don’t necessarily want to outsource that.
By the way, there’s a really interesting set of issues looking at insider threat from a AI agent perspective as well, because, if you think of the traditional insider threat in foreign counterintelligence, that’s changing as we speak.
So, how do you vet and trust agents that are trusting one another? And next thing you know, you have 17 of them, all playing the same game. So, there’s some interesting challenges there. I do think, though, your bigger point is more, in some cases, more important, because if we don’t unleash and take advantage of this, game over.
So, the question is, how do we get to the point where we’re comfortable enough with the guardrails? We’re comfortable enough that CEOs, if you’re in a company, are asking the right questions of their CISO [chief information security officer], CSO [chief security officer], or general counsel, and others. I think we’re just starting to scratch the surface there. And … I don’t think it’ll ever be AGI … agentic AI on agentic AI alone.
I don’t know how that plays out. I don’t think anyone does. But I also think that if we don’t seize the opportunity we’ll be left way behind, and that’s unacceptable. And from a law enforcement standpoint, too. I mean, you have the ability to do trend analysis and threat analysis and data is king still.
And you have the ability to crunch a lot of data.
Leatherman: A lot quicker. Because we’re collecting more and more data. And so, the FBI Director, Patel, has made it a priority implementing AI. And we have done that significantly over the last probably six months in particular. Which means both classified and unclassified holdings were using … responsibly using artificial intelligence to try to help us find what’s important, but always keeping the human—the analyst, the agent—in that loop; the computer scientists in the middle of that.
And then from my perspective, looking at using—you know, we do a lot of disruption operations, technical operations—using that to help us scale our operations against the adversary to have more impact than what just the small numbers of technical folks have on the team.
Cilluffo: You know, we used to talk about sort of single-point failure and impact. Well, the adversary has vulnerabilities, too. We want to find those single-point failures, right, where you can have maximum impact on an operation.
Leatherman: Yeah. One area of, maybe not single-impact failure, but risk for many organizations is, the tech talent that they can pull from. The amount of technical folks, the cyber deficit, sometimes across the various workforces.
So, I want to kind of talk about Pillar Six of the Cyber Strategy, which is Building Talent and Capacity. You’ve been on this question for, I know, years talking through it, including as chairman of the Board of Trustees of the Alabama School of Cyber Technology and Engineering.
And through your work at Auburn. Where do you see the future of the cyber workforce going, and what does it take for us to start to build that pipeline, to start to feed the next … the next generation of cyber defender in industry, but also in the U.S. government?
Cilluffo: Just one point of clarity. I’m a trustee at the Alabama School for Cyber Technology, but I chair Cyber Florida, which is also looking at the … the state institutions of Florida looking at cyber.
But, you know, I actually think—and this will allow me to do a little infomercial on ASCTE [Alabama School of Cyber Technology and Engineering], which is located in Huntsville. This is the first magnet school of its kind, focused on cyber and engineering.
You’ve got a number of STEM programs that are all very strong and important, but what differentiates what ASCTE does from others is that it’s very experiential. Kids learn by doing. So, you walk into that campus, you’re going to see UAS [unmanned aircraft systems] everywhere. You’re going to see counter-UAS everywhere. You’re going to see robots … manning the halls. That’s what gets kids excited.
And obviously FBI has a huge mission in Huntsville now, especially on the cyber side.
Leatherman: Our cyber kinetic range. Yeah, yeah. We try to cross over with some of those technical schools that were bringing real-world visibility to some of those primary and secondary education points.
Cilluffo: But I think that the message that I would say is you learn by doing. It’s one thing if you can rote learn and cite back something you read in a textbook that, quite honestly, is going to be overtaken by events in a day, nowadays, when it comes to some of the cyber activity we’re seeing. But you get a curious young woman or man engaged in a big hairy problem, they do cool stuff.
And to me that’s where … And at college, college, it’s essential, but it’s almost too late. You’ve got to get, you’ve got to get them early and you’ve got to get them excited and you’ve got to get them interested, and they’ve got to tap that.
And, there are also opportunities for neurodiverse individuals who society’s left behind in some ways. They are playing key roles in this space. So, net net, I am very passionate about the workforce. If I were to tell you today, though, what the curricula and what the skill sets are, it’s changing so fast that I think you have to do it by experience. You do.
Leatherman: And it’s starting at a young age, like you said, to get kids finding some sort of enjoyment in getting on a command line or finding out how to engage in, like, API [application program interface] access to hack a satellite.
Cilluffo: It’s cool. There’s a cool factor to it.
Leatherman: There’s a lot of cool things that you can do, but it’s getting those opportunities in front of these kids at a younger age. It sounds like there’s some good opportunities.
Cilluffo: It’s great. The … what they’re doing, they’re going gangbusters. Obviously at Auburn, we take that very seriously. But we tend to look at it through higher ed. And I think we have to go K through 12 and, and to me, the skill sets; I mean, in your space, you have so many good investigators who’ve worked crime cases, they may not be cyber savants, but they’re essential to what you’re doing in the cyber division.
And how do you blend all of that? And … how do you actually focus it on an outcome?
You know, in the military, I don’t want all computer geeks running … they … you need the operator mixing with those that actually understand the technology and are behind that green door and everything else. So, you’ve got to mix it all together and hopefully make some magic.
And I just underscore that the numbers game, those numbers look awful. Every, everyone’s done a study in terms of workforce and talent gaps. But I … would just argue we need to look at it a little differently. We need to give them hard problems. We need to let them focus on that. And use their creativity because they’re running faster than I ever will.
Leatherman: That’s right. Well, kind of looking forward now for McCrary, what’s the next product or initiative that we should expect from the task forces from you and your team? Where are you going from here?
Cilluffo: Well, firstly, I have a great team. I’m lucky. So, not only my immediate team; I’ve got some real rock stars. We’re also able to lean on a cohort of senior fellows who are some of the best in the business, all of … most of whom have, had many, many, many years of public service who are taking another job, but they miss; they … scratch their … they’re all public servants at heart.
So, they, want to contribute to some of our work.
So, the next task force report we have coming out, and that’s this month, is one we’re doing with the U.S. Chamber of Commerce, looking at regulatory harmonization. So, here, it’s to sort of get out of that compliance mindset, which matters.
I can’t say that at the FBI, I guess, but when you have one third to 50% of your time focused on filling out forms and not doing security—these are, these are companies that are already strapped.
So, we’re looking at how do you streamline that? How do you make CIRCIA [Cyber Incident Reporting Infrastructure Act] work? So, you have some ruling opportunities that can sort of get rid of some of the weeds underneath, focus on a new one, do it and do it right.
So, that is our next task force. The one after that is looking at some of our critical infrastructure, looking at AI, but I also want to leave with your audience just because Dave Bowdich, who is one of my, dear friends and a great FBI former …
Leatherman: FBI executive leader.
Cilluffo: … former leader. He is helping us lead an effort on looking at our offensive cyber and strategic competition to make sure we did not really zero in on the law enforcement component of that because law enforcement is key to our deterrence posture. It’s key to a more proactive posture.
And not only at the federal level, but also getting our state, local, tribal, territorial LE [law enforcement], as part of this solution. I worked for President Bush after 9/11, trying to work with our first preventers and responders was a huge challenge after 9/11. But we need to make sure that they’re part of that solution set, because still to this day, they’re first on scene, last to leave. And they know their local communities.
So, how do we pull them into the fold even more so? And I’m really excited about that work. So. Because I genuinely believe we’re never going to simply shoot our way out of this, arrest our way; but they have to be part of that solution, because it’s bringing all of these pieces together to make some hay.
Leatherman: And like we said earlier, I think it’s looking at that law enforcement piece is important. You know, we are looking at, not just being able to deter actors, do arrests, indictments, and extraditions, but we’re also looking to reach portions of their ecosystem where we can’t get them back here to the U.S. or seizing their cryptocurrency, denying them the funds and the monetization of that activity. Sanctioning them is a financial implication that Treasury can levy. Rewards for Justice through the Department of State.
Cilluffo: Yep.
Leatherman: It is really bringing a variety of things together. The law enforcement component is one important piece of that. So, I’m looking forward to the FBI’s opportunity. I hope to participate in that working group.
Cilluffo: You always have an open invitation and … dare I say, it really is bringing all of those pieces together. Because we are amazing when we go after—something happens to us, I’m telling you, we’re getting you. It may take some time, but we’re getting you.
But what does that look like in the steady state where we don’t have one objective, but we do focus on cyber and cyber investigations and criminal organizations and TCOs [transnational criminal organizations] and nation-states and their proxies.
If we put all those pieces together, we’ll not only put a dent in it, we’ll actually shape and influence the bad actors’ behavior. And I think the Bureau is moving in that direction. I think the government recognizes we’ve got to recalibrate our approach. Easier said than done, I get it. But if we focus on this mission, we will have the impact we want.
Leatherman: That’s a great way to end the substance of our conversation. But my version of your standard close from your podcast: what should I have asked you about the policy conversation and what it actually needs, I guess, that I didn’t ask you today?
Cilluffo: You know, the only thing I’ll bring up here is we’ve got to ask the right questions. So, this is not meant to be provocative. I almost, I do care who wins the cyber war, but I care more about who wins the war and how cyber is part of that solution.
So, firstly, asking the right questions. Secondly, supply chain is a big issue. You know, I just came back from the Paris Cyber Summit and FBI was well-represented and very thoughtful in the conversation. So, your colleagues crushed it.
But there is this moral equivalency argument that just bugs me in terms of tech stacks comparing the U.S. to China. And to me, that’s just ideologically bankrupt. If you think about it, for a few minutes.
But that is the discussion some people are having. So, what’s in your supply chain from a hardware, firmware, or software perspective is we need more visibility into that. And that’s where I think, there’s also some opportunity to make change.
Leatherman: Yeah. That’s outstanding. That’s the supply chain component is key and the decisions folks make on those supply chains now are going to stick with them for years and decades to come. And that’s why it’s so important.
Cilluffo: And it has consequences.
Leatherman: And it has consequences.
So, Frank, thank you for joining us. Frank Cilluffo is the director of McCrary Institute and of course, host of the weekly “Cyber Focus Podcast.” I would encourage you to check that out. Also check out the episode I had a chance to join Frank on.
So, Frank, thanks for joining us.
Cilluffo: Right. Thank you for what you do every day. Thank you for the women and men you lead. And thank you for making America more safe. So, thank you.
Leatherman: And thanks for, thanks to everybody at McCrary for what you do to help provoke these conversations that are so important for all of us, all of us to have across industry, policy, law enforcement, military, intelligence community, and beyond.
Cilluffo: Well said.
Leatherman: Thank you. So, to our listeners, thank you for tuning in. Brett Leatherman, assistant director for the FBI Cyber Division. I mentioned today Operation Riptide. You can check out Operation Riptide and more at fbi.gov/cyber.
You can also check out the FBI socials to learn more as well. It’s an incredibly important initiative. And we need industry, our international partners, and everybody joining together over the next 60 days to implement the National Cyber Strategy and imposing cost on malicious cyber actors.
Until next time, let’s stay ahead of the threat. Thank you.