- 3 months ago
"Cybersecurity has become a core pillar of national security. As cyber threats grow in scale and sophistication, governments are rethinking their approach: not only defending against hackers, but in some cases engaging or integrating cyber talent into their strategies.
Where is the line between threat and asset? Bringing together perspectives from government, private sector security, and cyber intelligence, this session explores how the role of hackers is evolving in today’s geopolitical landscape, and what it means to turn adversaries into capabilities. As boundaries blur between state and non-state actors, the discussion examines how governments and companies are redefining cooperation, deterrence, and resilience in cyberspace."
Where is the line between threat and asset? Bringing together perspectives from government, private sector security, and cyber intelligence, this session explores how the role of hackers is evolving in today’s geopolitical landscape, and what it means to turn adversaries into capabilities. As boundaries blur between state and non-state actors, the discussion examines how governments and companies are redefining cooperation, deterrence, and resilience in cyberspace."
Category
🤖
TechTranscript
00:00Good morning. I'm Jennifer Schenker, founder and editor-in-chief of the Innovator, a global publication that connects business with
00:10technology, and it is my pleasure to welcome you to our session on state-sponsored hacking.
00:20Let me begin by just taking a minute to set the scene.
00:28A few days ago, an Iran-linked hacker group called Handela threatened the FIFA World Cup.
00:36They claimed to have spent months inside FBI surveillance drones watching players and fans through face recognition feeds.
00:45Within 24 hours, they posted an alleged breach of California's water infrastructure.
00:52The evidence for both turned out to be questionable at best, but the story ran everywhere in the press, which,
01:00as any intelligence analyst will tell you, was the entire objective.
01:05That's one half of what Iran's cyber operations looked like in 2026.
01:11The other half looked very different.
01:14In March, operators linked to Iran's intelligence ministry silently destroyed the internal system of Stryker, one of the world's largest
01:23medical technology companies, remotely wiping tens of thousands of devices with no warning and no ransom demand.
01:32U.S. officials called it the most significant wartime cyber attack on an American corporate target to date.
01:41Disinformation and destruction, noise and sabotage, sometimes from the same adversary in the same week.
01:49It's an example of how cyberspace is now a primary area of geopolitical conflict.
01:57The U.S. Office of the Director of National Intelligence 2026 Annual Threat Assessment makes clear that cyberspace is now
02:06a primary arena of geopolitical conflict.
02:10Indeed, Britain's NCSC head, Richard Horne, disclosed in April that the U.K. is now handling four nationally significant cyber
02:21incidents every week, with the majority now traced back to hostile foreign governments rather than criminal hackers, a dramatic shift
02:32from previous years.
02:33This session will explore how the role of state-sponsored hackers is evolving in today's geopolitical conflict.
02:43Now, we have three experts here to talk about that.
02:47I'd like to introduce them.
02:50First, to my immediate right, is Christopher Porter, head of international security cooperation at Google.
02:57Next to him, we have Nicole Cardigan from Darktrace, and we have Dakota Carey, who is an adjunct professor at
03:06Georgetown University and a strategic advisory consultant at Sentinel One.
03:12Now, I'd like to just, for each of you, to just take one minute to give us a little idea
03:17of your background and what your day-to-day job looks like.
03:20So, let's start with you, Christopher.
03:22Yeah, thank you.
03:23So, head of international security cooperation, that's a title my boss let me make up for myself when I got
03:30the job.
03:30What is that?
03:31I'm in charge of sort of setting up, on behalf of Google, our intelligence-sharing agreements with governments around the
03:38world.
03:39That's mostly cyber intelligence, but it includes geopolitical and other kinds of intelligence, right, to sort of make the world
03:45safer for all Google users.
03:48Prior to that, I kind of have gone back and forth between the U.S. intelligence community and Silicon Valley.
03:55So, 10 years almost at CIA on the operations and analysis side, the Obama White House, I was the CIA
04:03briefer for cyber briefly, and at FireEye.
04:06And then, probably most famously, the national intelligence officer for cyber, half of which under President Trump as his cyber
04:15intelligence and election threats advisor through 2020 election as well.
04:20And then, half under President Biden and his team, up through being in charge of cyber analysis for the start
04:26of Russia's war in Ukraine.
04:29So, kind of have gone back and forth between those two.
04:32Thanks.
04:33I'm super impressed.
04:34Nicole, over to you.
04:36I'm the SVP of security and AI strategy at Darktrace.
04:40I spent about 20 of my 27 years in cyber security supporting the U.S. intelligence community, 10 years directly
04:49in tech ops.
04:50The rest of the time was building out big data science programs with machine learning and AI models running threat
04:55research.
04:56And then, the last seven years have been more on the commercial side and kind of extending the cyber warfare
05:03outside of the government and empowering more organizations to defend against a lot of the threats that they're seeing today.
05:12And, Dakota, tell us a little about you.
05:15Hi.
05:16My name is Dakota.
05:17I am a consultant at SentinelOne.
05:20I do research on China.
05:22I've written a number of reports on vulnerability management and reporting laws, talent pipelines and programs to improve education for
05:31hackers into the security services and the military.
05:39And I'm so happy to be joining you.
05:41Okay, great.
05:43Well, let's dive right into the discussion.
05:44So, I'm going to ask each of you to please describe how states hire and utilize hackers for strategic close
05:54and cite some specific examples.
05:57Who wants to go first?
06:00I'll probably just speak in broad terms since we have so much expertise.
06:04People might want to get into the details.
06:05But I'll just make the broad point that all hackers start off as non-state hackers, right?
06:12That's on your way to work.
06:13You're a non-state actor.
06:15And then, when you arrive at work, if you're working in the government or for a military, suddenly you're a
06:18state actor.
06:19So, different states have different ways of doing this.
06:22In Iran, you might be acting as a hacker as part of your sort of obligatory military service.
06:28So, they're young and highly skilled, but maybe not always spending a lot of time in the intelligence services to
06:33build up expertise.
06:35If you're Russia, I mean, it could go either way, right?
06:37Their nation's elite want to work in the intelligence services, but they also are recruiting from graduate schools.
06:43And that's where a lot of the new ideas around attacking railways, attacking power systems are now using AI and
06:49offense.
06:50They're plucking that out of their elite universities through student hacking competitions.
06:54And in the U.S. and in the West, there's obviously a more formal pathway into public service.
07:00But I think the important thing to realize is when you're thinking about cyber power, you think big countries, small
07:06countries, but there's talented people in many of these countries.
07:10North Korea is a great example.
07:13There isn't a lot of private sector competition siphoning off talent in North Korea.
07:18There's some, but not a lot.
07:20Most of their best, smartest people are going to go into government work.
07:23So you really want to respect the potential threat that those countries can pose, even if they don't have the
07:29resources of, you know, Europe or the U.S. and its allies.
07:33Oh, Dakota, I see you like really nodding your head.
07:36You want to jump in here?
07:38Yeah.
07:39So obviously, I'll contextualize a lot about China.
07:44But generally speaking, I can talk about U.S. operations also, which is a good contribution.
07:49We had recent research out of Sentinel-1 about a software program called FAST-16 that was widely reported.
07:57It's, you know, available online.
07:59And it was about a U.S. operation as early as 2005 to use tools to create and manipulate data
08:09inside of Iranian nuclear research facilities in order to impact their perception of their ability to conduct nuclear enrichment.
08:18And that was a strategic effect offered by, you know, a piece of software that manipulated the integrity of the
08:25data.
08:26So that is one way in which operations can contribute to state goals.
08:30We see a lot of other ways of doing this.
08:32China has been excellent at acquiring intellectual property from abroad and applying that to actual commercial issues.
08:41A lot of countries can steal information and intellectual property from the private sector, but they are exceptional in applying
08:48that and commercializing it.
08:50That contributes to economic national security and economic competitiveness.
08:55And then finally, we see intrusions that are meant to have a strategic effect on the way that governments think
09:02about conflict or future conflict.
09:05In the United States, we talk a lot about Volt Typhoon.
09:08It's a naming convention from Microsoft for a hacking group from China.
09:13They have infiltrated a number of critical infrastructure sectors, including power, water, and transportation.
09:21And the goal for those operations is simply to deter U.S. policymakers in any potential future conflict between the
09:31United States and China.
09:32So the goal is cognitive.
09:35The goal is to change the way people think, but that's done with access and malicious code.
09:41Nicole, please.
09:43And I think it's quite changed and shifted a lot.
09:46So back when I started in the 90s and early 2000s, it was recruit them young before they had done
09:53anything too disruptive to where they couldn't get cleared.
09:56And then pull them in and train them a little bit more on the tools that were there.
10:01But even then, we saw the rise of vulnerability discovery on the black market, which was actually a prime recruiting
10:09ground for a lot of different state-sponsored programs to test out the veracity of those specific operators and to
10:17see if they had the right mentality and mission-oriented focus that could be brought into the fold.
10:22So you actually saw that across multiple different countries, from Saudi to the U.S., to China, to even some
10:29here in Europe.
10:31And then you also kind of had this great burgeoning European group where it was of hackers that were not
10:37associated with the government.
10:39They didn't have that kind of ideology that went to serve for the government, but that they ended up getting
10:45pulled into a lot of the private sector that ended up partnering back in and bringing that valuable intelligence back
10:52into a variety of different governments.
10:54And we have someone in our organization there.
10:57And then lastly, I mentioned it before, actually, when I made the jump from government into public sector or private
11:04sector, it was, we're not fighting a cyber war that's just between governments now.
11:09I mean, we're fighting a much more global impacted war, and so you see a lot of mission-oriented people
11:16working in the private sector, working together, but also taking that valuable technical operations and offensive security understanding to build
11:25out better products that could actually secure organizations and marrying them with now the AI engineers, the ML engineers, the
11:35mathematicians that are harnessing this valuable knowledge and technology.
11:40So, you know, I think it's probably a good time to make the distinction between the way different governments operate
11:50in terms of recruiting, because, you know, in some countries, there is no hesitation from the government to recruit criminal
12:00actors who may also have a sideline business and ransomware or other things.
12:07It's maybe a different situation in democracies where you want to be able to hire people who have a good
12:21understanding of the vulnerabilities, but you can't just hire anyone.
12:27You want to make any comment about that?
12:30I mean, yeah, there's, so there's a lot of complexities to that, because even the governments that are okay with
12:36the side hustles, they sometimes don't want it to mess with diplomatic relationships.
12:41And so you always have to think about attribution and what you might get pulled into, and so there is
12:46even a little bit more control there.
12:48I think where you allow for more of those enterprising side hustles are for those who are more financially motivated
12:55that might just be tied or linked to state government operations and help with infrastructure or initial access, but then
13:02things get kind of turned over from there.
13:04And so there is ways of still keeping levels of distance that allow them to operate with more agility, and
13:12also then, we haven't talked about North Korea yet, but they are fully self-funded in a lot of their
13:19operations.
13:19So they have financially motivated operations, and they have disruption-oriented or surveillance-oriented operations.
13:27And so I think it does different per model, per country, but I think there is always the, and you
13:33could probably talk to this way more than I could, how much of the risk do you want associated of
13:38an attribution blowback?
13:39I was going to add to that just a little bit, one of the big evolutions in the last few
13:44years is the willingness of nation-states themselves to commit crimes.
13:49North Korea is the best example.
13:51Normally when you say, oh, we're going to go after these cyber criminals, you mean financially motivated, you know, mafiosos,
13:56and you don't mean nation-state espionage.
13:58In North Korea's case, they are literally robbing banks and stealing money.
14:03A little bit more tolerance in recent years on China's part.
14:06For a long time, they were not really willing to do that, but the MSS, you know, the intelligence service,
14:13now has what you might call a bounty kind of system,
14:15where they're willing to work indirectly with contractors or, you know, defense contractors.
14:20And let's not forget, the initial shots in the, you know, Russia's invasion of Ukraine weren't artillery shells.
14:28It was an attack on the banking system in Kiev, essentially to try and terrorize the people of Ukraine.
14:34So the very first front line in the war in Ukraine was a cyber front line of Russian intelligence officers
14:42using criminals to terrorize civilians.
14:45And the people of Ukraine themselves were the fighters who, you know, I mean, obviously it's a bad day if
14:51you can't take money out of the ATM,
14:52but they weren't willing to capitulate just because they, you know, had that initial psychological shock.
14:58They were well prepared and did that without any government guidance per se, that just as a people decided to
15:04do that.
15:05So, yeah, it's a very complex situation where nation states are increasingly using criminals as a method of accomplishing statecraft.
15:14And the front line on that is often private companies because we're the ones who are directly interfacing with citizens
15:19for the most part.
15:21Dakota, I know you wanted to add to that.
15:24Yeah, I would just I think the only thing that I would add is that there are, I think, a
15:31number of ways that states will come to tolerate that cyber criminal behavior by their contractors,
15:37so long as it's not interfering with diplomatic relations.
15:41I think the 2020, 2021 hack of U.S. COVID relief funds to the order of tens of millions of
15:51dollars by a Chinese contracting company, Chengdu 404.
15:56It's a kind of a perfect example of a guy who founded the firm.
16:01Tan Dai Lin was an individual hacker when he was in college in the early 2000s.
16:06He ends up getting imprisoned and then is released if he's willing to hack for the military in China.
16:14And he does that for a number of years.
16:16He sets up his own firm.
16:18He is one of these state contractors now working for a number of different customers.
16:24And in the middle of the pandemic, his company and the people who work for him set out to collect
16:31tens of millions of dollars from COVID relief funds.
16:34And they did an excellent job at that.
16:37And that individual and that firm are a perfect case of how countries can compel people who have committed crimes
16:46into service.
16:47They can formalize the way that those individuals operate.
16:50They tolerate the willingness for self-enrichment as part of the gig so long as state objectives are being met.
16:58And they don't mess up diplomatic relations.
17:01Those organizations don't carry out cyber attacks inside of China.
17:06And they certainly don't go after countries that the government is not approving of.
17:10Okay.
17:11So we're talking really about a world that is operating in different speeds, you could say.
17:19You know, and so how do the nation states that are not at least directly hiring criminals fight back?
17:34Go to school.
17:36You have to go to university.
17:38So I like this question a lot because obviously I get to talk about China more, which is always wonderful
17:44for me.
17:44But the United States set out a program in 2007 called the National Initiative for Cybersecurity Education.
17:52It was right at the end of the Bush administration.
17:55Stuxnet and Fast 16 had impacted Iranian systems.
17:59So they, like policymakers were aware of the strategic impact that cyber operations could have.
18:05And so they decided to formalize a talent pipeline into the security services.
18:09So in the early 2000s, as Nicole was talking about, you had to go out and find people who were
18:14already doing their own vulnerability research
18:16and make sure they were not too much of a criminal that you could not hire them.
18:21And by the late 2000s, the government set out to formalize a university pipeline into government service and into the
18:28private sector as well, right?
18:30So the NSA and the Department of Homeland Security certify some universities as centers of academic excellence.
18:37There's cyber operations, cyber research, cyber defense, et cetera.
18:40And so they have formalized the process for individuals who want to move into government service.
18:48And I think when we think about democratic governments and governments that are not interested in working with criminals,
18:55the best way to do that is to make sure that you have a robust talent pipeline of people that
19:00you can trust
19:01because they have not earned their stripes in the black market.
19:06They are not out there ransoming companies.
19:07They just went to a few really good colleges that you as a government and as policymakers invested in and
19:14can now go higher out of.
19:17I love that.
19:18And I would add two points to that because I do think that's a critical component.
19:22First, you're also making it economically an advantage to those people to have a steady stream income,
19:28but to still pursue their true passion, which is really just tearing things apart.
19:33I mean, ultimately, that's really what it is.
19:36And then there's an element in the education that I think we could probably bring down to education systems more
19:41that is really kind of ingrained in you when you're in the government is think like your adversary.
19:48Think how, like if you're doing an operation, think how they would tear that apart.
19:53And you constantly are thinking in this mentality of the opposite of what you're trying to accomplish,
19:59which actually allows you to be better cybersecurity analysts and defenders and product makers across the rest of your career.
20:07And so I think, yeah, the fact that you can actually incentivize them with a good, steady income that's not
20:12dependent on the successful operation,
20:15but also at the same time allowing them to do what they want to do, which is tinker, tear apart.
20:23I'll offer maybe it's in a way a tactical observation, but having briefed and written for several U.S. presidents,
20:31one of the hardest issues that you face is knowing when to respond as a nation to a cyber attack
20:37because it's sort of like nothing happens at a government level for a long time.
20:41Nothing serious happens for a long time, and then it flips, and it becomes a huge reaction, sanctions or military
20:47action, whatever.
20:48But the threshold to get there is very high.
20:51North Korea robbing, you know, I think at the time they started looking into it,
20:55maybe 18 central banks, mostly in Latin America, before anybody really thought about committing nation-state resources to it.
21:03China stealing U.S. intellectual property across every industry for a decade.
21:07And each individual instance really isn't worth the president doing anything about.
21:12Oh, you stole a million dollars worth of IP, like, you know.
21:15But it adds up over time.
21:17And the U.S. system really is not built for handling the slow adding up of many hundreds or thousands
21:24of little operations.
21:26You also have a psychological element where I think to the previous generation of leaders,
21:31cyber operations still have an element of being kind of unreal.
21:35You know, when North Korea destroys Sony, there's a sense of it kind of being on the Internet or fake.
21:40But I think that is going away, but it's still going to be an ongoing problem.
21:44When do you confront another country over major cyber operations?
21:50And the U.S. and its allies, including NATO for sure, when do you start invoking NATO for cyber defense?
21:56The reality is you can stay just below that red line and do as many operations as you want and
22:01nothing will happen.
22:03That's not how the private sector handles things.
22:05We respond to every incident to defend people.
22:07It doesn't really make sense for cyberspace.
22:10So this is a larger strategic problem where a lot of countries have figured out if they work with criminals,
22:16if they work with other non-state actors and tap them and do a little bit less than a total
22:21disaster,
22:22they can get away with it a hundred or a thousand times.
22:26And there won't be the kind of serious reaction that would counter that.
22:29And that's still an ongoing policy problem throughout Europe and the U.S.
22:35Super interesting.
22:35So is there information sharing going on between nation states?
22:44Are there like specific alliances that have formed to deal with that?
22:49Like maybe even inside NATO, do they share like what they know about, you know, the methods of state-backed
22:58hackers?
22:58Yeah, I mean, that's ongoing.
23:00That's a very popular solution.
23:02It's one of the most important tools we have for countering hackers.
23:05You just have to be careful when you talk about those.
23:08You know, a lot of think tanks like to write white papers and say, well, we should increase intelligence sharing.
23:13But they say that because it doesn't cost them anything to do it.
23:17It's easy.
23:17It's kind of an easy solution that doesn't require anyone to sacrifice or do anything.
23:22I would say not just intelligence sharing, but intelligence partnership is vital.
23:27At Google, we own 25% of the global Internet in terms of data centers and fiber optic cables and
23:33so forth.
23:34We have the apps on your phone.
23:36We have, you know, everything in between the cloud layer.
23:39For those of you with technical backgrounds, we have a good intelligence presence on every step of the OSI model,
23:46right?
23:47That makes it really hard for hackers to hide from us and to hide attribution because we can see a
23:53little bit of everything that they're doing.
23:54Pretending to be a hacktivist, stealing data, moving it back to their intelligence headquarters.
23:59What are they saying on Telegram?
24:01You have at least a bite at the apple to catch them every single time.
24:05What we benefit most from as a company is, well, what do we look for?
24:09Nation states are uniquely good at saying, this is a nation state actor pretending to be a criminal, not just
24:16a criminal.
24:17We can do that attribution ourselves, but what's the priority?
24:20What does the prime minister care about?
24:22What's the biggest threat in your country, not just generically to the world?
24:26Those are all areas where you really need savvy government leaders to not just share information back and forth like
24:33we're writing each other reports,
24:34but really partner in a way, help us find the threats that will best defend your country in particular.
24:41And that's a lot of why I'm here.
24:43We do a lot of work with France and with other partners, NATO and others throughout Europe.
24:47We absolutely, you know, we would defend Google users every day regardless,
24:52but we're 10 times as powerful when we're working with our public sector partners.
24:57So, yeah, I think not just sharing data back and forth, but actual true, like, co-work on these issues
25:02is very important.
25:05Yeah, and this is going to dabble into our topic at the next talk.
25:09So, if you're really kind of interested in breaking the cybercrime business model, please stay for that one.
25:14But there is an element, I think, that international organizations are getting a lot better,
25:18especially with collaboration of infrastructure takedown.
25:21I think there's still a lot of work to be done on following up with prosecution and charges of specific
25:27threat actors.
25:28And then I'm going to take a spicy take.
25:31This is not a dark trace take, so I'm not going to attribute it to them.
25:34It's me.
25:35I actually think that we need to get better at hacking back and immediately causing more costs within the model
25:42in order to deter, especially some of those more lower threshold operations from being effective.
25:50Because it really is a financial model, and ultimately that has to come down to it.
25:55And then the flip side of it, so that's the financial model.
25:58When we talk about state-sponsored, it's so much more difficult, and it's going to become so much more difficult
26:06as more offensive adversaries are adopting AI, where infrastructure is not going to be reused.
26:14Scripts are not going to be reused.
26:15Vulnerabilities are not going to be reused.
26:17It's really being able to share valuable behavioral-based intelligence in a consumable fashion across being agnostic to vendors
26:29or however you consume it, so that you can actually see the true tactics and techniques that are actually being
26:36observed within these attacks.
26:37We put out a great Chinese Nexus threat report in April that really talked about the slow and low and
26:45slow model
26:46for really surveillance operations for Chinese Nexus threat actors, but ultimately also staging for disruption.
26:54And how do you pull together those small behavioral-based intelligence signals over longer periods of time
27:01to be able to detect it earlier, so that you're not sitting in an example where they've sat there for
27:06seven years?
27:07So, Dakota, I'd love to hear your views on that, and then maybe that's a good segue, since Nicole mentioned
27:15AI,
27:16to talk about how does that impact the threat landscape?
27:21Yeah, so I'll give a two-part answer, both of which come from researchers at ETH Zurich.
27:28So the first part is Max Smeets at ETH Zurich has an excellent recent book that focuses on government operations
27:38and their impact on criminal actors.
27:41Operation Kronos is an excellent example of how states can work together beyond information sharing and do enforcement.
27:49Operation Kronos, if you're not familiar with it, was a takedown of, I believe it was Lockbit at the time,
27:55although it's gone undergone many permutations.
27:58And not only was it a site seizure, which we've all seen a number of times,
28:04what they did very well was show the victims that the data that they had paid to be deleted
28:13was, in fact, not deleted.
28:15And the goal of Operation Kronos was to break down the trust between the victim and the attacker.
28:23If you are paying a criminal group to delete the information, you have to trust that they will do that
28:29or the value that you are remitting to them is not worthwhile.
28:32And what Operation Kronos very cleverly did was show victims and future victims that just because you have paid these
28:40actors millions of dollars
28:41does not mean that they will actually do the thing that they are saying to do.
28:45So it's probably not worthwhile paying them.
28:47And I think that's a really excellent example of how states can go beyond just information sharing
28:52but actually do more to impact the actors themselves.
28:56The second part of the ETH Zurich answer is a friend of mine, Eugenio Benincasa,
29:02he's just put out a good piece about AI's impact on vulnerability reporting
29:09and AI's impact on vulnerability discovery inside China.
29:13He focuses specifically on a number of companies and the models that they are using for vulnerability research.
29:19I think that we've all kind of absorbed the idea that Claude Mythos has the ability to do excellent code
29:29review,
29:29find high number of software vulnerabilities, etc.
29:32The first and obvious and immediate impact for everyone in this room who is a defender
29:37is that you have to have a very fast patching cadence.
29:42You need to have the ability to stay online while providing service to your customers and your business partners
29:50while also patching critical systems.
29:53So we're talking about redundancy and resiliency in the face of just that onslaught basically of large patches
30:03that we're going to have to apply.
30:04And that's probably going to happen for the next two years.
30:07I think that's just going to be the cycle that we live in.
30:09The other part of AI impacting cyber operations, I don't think it gets a ton of focus,
30:16is on operational technology and industrial control systems.
30:21These systems very frequently have what is called a data historian.
30:26It records the metrics that are touched by this system, the pressure in all the valves,
30:33the way that the water or the oil is flowing, etc.
30:38Back in 2019, so this is seven years ago now, there are researchers in Singapore who went to a cyber
30:46test bed.
30:47It was a facility that the government had constructed and it had 18 known attacks.
30:52And what they did was they took down the data historian and they ran their own machine learning model
30:58on the data historian and then asked if they could come up with new attack methods.
31:03And this test range had been in place for more than a decade and it only had 18 known attacks
31:09on it.
31:10And seven years ago, those researchers were able to find three additional ways to bring down this industrial control system
31:18in its preceding decade, right?
31:20And so all of these operational technology and ICS systems maintain a repository of training data
31:27on their own systems that if you are able to collect and bring back and do research on,
31:34you can come up with very specific ways to attack those systems that previously you had to rely on human
31:42knowledge
31:42and very specific process comprehension in order to affect.
31:47You had to have engineers involved to understand what the layout was and how the system operated.
31:51Now you can feed the data historian to machine learning models and make those attacks much more effective.
31:57Thanks.
31:57So you brought up a number of important topics that, you know, I think are worth digging deeper into.
32:03But let me just go back to, you mentioned, you know, mythos and the ability to find, its extraordinary ability
32:12to find vulnerabilities.
32:14And, you know, the anthropic and now the U.S. government, you know, are really trying to keep control over
32:27that technology
32:28on who can access it, et cetera.
32:30But when you and I have talked in the past, you mentioned that, in fact, there is no holding it
32:39back
32:39because very rapidly, probably within 18 months, open source models will be able to do exactly the same thing.
32:46So, you know, this ability of AI to models to find vulnerabilities in the system
32:57means more exposure for nation states, but also for companies.
33:02So with that, let's dig more into the industrial, the threat to industry.
33:11Yeah, we could have a whole separate panel just on AI-enabled cyber offense.
33:16So I'll just give you a couple of things that we're looking at at Google.
33:19The first is that it, you know, using AI when you're on offense means shrinking sort of the time window.
33:26Instead of taking, you know, you break in, instead of taking four or five hours to find what you're looking
33:31for,
33:31maybe it's an hour.
33:32And so we're seeing, at least in the lab, exfil times from scanning the outside of a network to,
33:38if you're just there to smash and grab and steal documents, you know, maybe 25 minutes, 15 minutes.
33:43Median time, probably half an hour or less.
33:45That means half the time it's faster than half an hour.
33:48Well, our personnel systems aren't really set up for that insecurity yet, right?
33:52You know, you think, you tend to think if I have an hour to respond to a breach, that's pretty
33:56good.
33:57I mean, 99.9% of the time, if I respond even to an elite APT within an hour,
34:01there's probably not any significant damage.
34:04That's not going to work.
34:05It doesn't work now.
34:06It's not going to work 18 months from now.
34:09So that's not a technology problem.
34:11That's a policy problem.
34:12We haven't caught up to the speed of AI-enabled offense.
34:15It's not something that human beings can manually respond to.
34:19You're going to have to automate a lot of your defenses.
34:22There really is no other choice.
34:23I'm professionally a problems expert.
34:26I'm not really a solutions expert like some of my colleagues.
34:29But, you know, I actually am kind of optimistic here that in the long run,
34:33all of this will add up to a much safer cyberspace.
34:36It will be a net positive for defenders, but it could be a rough couple of years, you know,
34:41in the two to three years in between it becoming a net positive for defenders.
34:44The other thing I'll point out just briefly is think about when you have a question,
34:49a medical question or a legal question.
34:52These LLMs are not really a replacement for a skilled doctor or, you know, a barrister who can represent you,
34:58but they're pretty good.
35:00They're maybe better than a recent graduate.
35:03LLMs for any kind of intellectual labor, virtually any field,
35:08all the frontier LLMs are going to be better than the median person sort of at producing it with, you
35:15know,
35:16low to mid-career experience.
35:18Well, that's also true in cybersecurity.
35:20What does it mean when every person on earth potentially is a pretty good hacker, you know,
35:27a third or a fourth tier APT group?
35:29No one's going to mistake them for Russia or China or North Korea or Iran or one of the top
35:32financial groups.
35:33But if every little alert that you get on your network isn't just, you know, a kid and, you know,
35:39just playing around but is potentially a big breach of your network,
35:43that really changes how you think of things.
35:45Conversely, defenders can also scale their defense much greater than in the past.
35:48But I'll just leave that as a thought-provoking idea for now.
35:53What does it mean when everyone is pretty good at hacking?
35:56I think it's something besides the speed that we haven't really grappled with yet.
36:01Super interesting.
36:02Nicole, you want to add?
36:03I think you brought up the most critical point today,
36:07which is autonomous containment and autonomous response.
36:10And that needed to be turned on yesterday.
36:13And I think organizations are starting to see that.
36:15I think there's a few other things that need to be done very quickly.
36:18If an organization has not shifted from a malicious classification detection engineering workflow
36:25to a probabilistic, non-deterministic, behavioral-based anomaly detection workflow,
36:30that also needs to be done yesterday.
36:33Really looking at more of a defense in-depth strategy.
36:36Obviously, the three of us on here, that's been our entire careers for the most part.
36:41NIST is about to come out with a new cybersecurity framework for AI adoption.
36:45We've provided commentary on it.
36:47It's great.
36:48I would say what most organizations kind of lagged was with the detect, respond, and recover,
36:53especially as we went to rapid cloud adoption.
36:57So that needs to be lessons learned.
36:58They stuck into that visibility, governance, and protect model
37:02and thought that that would protect them.
37:04And it won't.
37:05We have to assume vulnerability.
37:07We have to assume compromise.
37:08And you really have to make sure that you have that detect autonomous response
37:14and a plan for remediation and recovery.
37:16That will probably more be human in the loop there,
37:19but autonomous response for initial containment to stop the spread and mitigate the risk.
37:24And so there's a lot of things that security operations teams need to do today in order to do this.
37:29And especially as they're adopting more AI within their infrastructure, that is the attack surface.
37:35That is an easy mark right now.
37:37And it's ripe with privilege and access and movement laterally throughout the environment.
37:45So really preparing your SOC for that insider threat model,
37:48because that's going to catch identity compromise, which is still going to persist.
37:52Supply chain risk, especially across SaaS and cloud.
37:55And then you're talking about really just the insider risk profile of AI itself.
38:02So, okay, we've talked about threats.
38:06We've talked about, but one that we haven't talked about yet that I'd like to bring up is,
38:14you know, as geopolitics affects cyberspace more and more,
38:20the threats are not limited to the entry of hackers.
38:26We're now talking about the possibility of nation states to just turn off the access to a particular technology or
38:37technologies.
38:38And, you know, so how do you see what happened with Fable 5 as a foreshadowing of what's to come?
38:50How does this impact?
38:52I mean, the big theme here at this conference is European, you know, technology sovereignty.
38:57What does this mean in terms of, you know,
38:59how every company and every nation state has to look at their technology stack?
39:06Yeah, I think broadly when you talk about AI sovereignty, that doesn't mean isolation, right?
39:11Even in the United States, you know,
39:13ASML is providing the lithography and you're getting the memory from South Korea.
39:17Like, no country is an island unto itself.
39:19It's also important to remember that the fundamental science behind these LLMs isn't secret, right?
39:26There are trade secrets, but the fundamental science is given away for free.
39:30It's something anyone could imitate if they're willing to make the scaled investments.
39:35France in particular is a really, I'd say, probably the best example in the world of a country that has
39:40struck a good balance.
39:41The physical infrastructure, the cloud infrastructure,
39:44Google Cloud provides them with sort of the technology insight and the open source software stack,
39:50but they, you know, Thales runs it themselves.
39:53There's no ability to deny them the ability to run their own AI.
39:56They own and control it.
39:58So there's trade-offs in doing that, but to the degree that it's important,
40:02countries can already choose to do that.
40:04Mistral already develops a, you know, a world-class frontier AI model.
40:08If you're willing to do it, it is a doable thing.
40:11I think the balance for Europe is going to be not, it's not binary.
40:14Do you do it or not do it?
40:16It's under what circumstances is it really important to you to have your own AI stack that cannot be denied
40:23or that is just customized to your particular culture or legal environment.
40:26That is the same problem the U.S. government has with its own companies.
40:31I mean, the conflict, you know, but you're talking about the export of Fable.
40:35Some of that is sui generis to the company and their relationship with the U.S. government, right?
40:40So the U.S. military already expressed the same concerns that Europe is now expressing.
40:45I'll just leave it there and say these are not, you know, uniquely Europe versus the U.S. problems.
40:49It is a question of how do you remain integrated and benefit from a global research environment?
40:56Google's AI lab is in the U.K.
40:58Those are the people winning the Nobel Prizes.
41:01So you want to remain integrated into global developments,
41:04but obviously for national security or citizen data privacy, there's different reasons.
41:08You might want to have certain things that are customized for you
41:11or that you're willing to, you know, pay a little extra or make some sacrifices
41:15to be undeniable, 100% certain you could have it.
41:18Those are totally reasonable things to do, and it's not a hypothetical.
41:22If you need an example, France is probably the best country in the world at balancing that,
41:27benefiting from world-class research while still having sovereign control
41:30and, most importantly, undeniability of access to the models and the infrastructure.
41:37Dakota or Nicole, who wants to chime in?
41:40I think there's also an element, too, where as we're rapidly innovating,
41:45we will get back to principles of data science.
41:48We have decades of responsible use of AI, responsible use of data, safety, security,
41:56all those other things, and I think right now we're in a rapid innovation cycle,
42:00but you are going to see more and more countries figure out the right wraparound
42:07in order to adopt technology effectively, as well as also as it was a great panel yesterday
42:14that discussed this was our, and it was actually two days ago,
42:19but we discussed do you trust the people handling your data?
42:22And I think ultimately that's what sovereignty is coming down to.
42:26Do you trust the people handling your data?
42:28And I think those that show that they can handle it well and that they can do it responsibly
42:33and safely, I think you're going to be able to marry that with innovation quite easily.
42:39Dakota?
42:40I would sum it up as if you don't want the foreign government where this technology is produced
42:48to turn it off, don't integrate it into that core part of your infrastructure.
42:54Telecoms, electricity, go down the list of things that you need to have working all the time.
43:00Either set up a legal and regulatory framework where the foreign owners of that intellectual property
43:06and that device cannot push software updates to it,
43:10and that you have validated the code behind that product,
43:13and that you are the only people able to access that product when it is operating in your country,
43:18or accept that it may be turned off by the people who own it.
43:24Supply chain risk question and diversify your supply chain.
43:27Exactly.
43:28We are almost out of time, so I'm going to ask each of you now,
43:32what is the one thing that you would like the audience to take away from this panel?
43:38All problems are solvable.
43:41You should continue to invest in education and talent pipelines.
43:46The AI whiz-bang is cool, but it will take humans who know things,
43:51who have read books, and who know how to solve complex problems
43:54to continue to engineer solutions to the problems that we have.
43:58Please, dear God, don't just type prompts into a machine
44:02and lose the essence of who you are.
44:06I will jump on that for my second point.
44:09First point, think like an adversary, always be curious, continue to tinker, continue to break.
44:16The second component, I'm going to quote Clark Gregg,
44:20Agent Coulson from the Marvel Universe.
44:21He actually testified in front of Congress in the U.S. on AI within Hollywood.
44:27He goes, as we are harnessing this incredible technology,
44:31don't lose your creativity, imagination, and soul.
44:34And I think that's actually how we're going to get the most benefit out of it.
44:38I like both of those.
44:39Yeah, write on paper and play around at home.
44:41Those are both great suggestions.
44:43Since they took my two tops, I'll say, I would like to see Europeans be more optimistic.
44:47I was really shocked at yesterday's panel I was on,
44:50how pessimistic Europeans are about your own capability to do these things.
44:53Oh, we can't have sovereign AI.
44:55We can't develop this technology.
44:56And there's a bad investment environment and so forth.
44:58You would know better than I would.
45:00I get that there are obstacles to overcome.
45:03But, you know, France built a sovereign nuclear deterrent after World War II
45:07when the U.S. accounted for the lion's share of global GDP and patents and so forth.
45:12If it's really important to you as a country,
45:14these are much smaller problems than you faced in the past.
45:18I also just work with many brilliant European citizens every day.
45:21So it struck me as very odd, the pessimism,
45:24when some of my top counterparts are in Poland and France and Belgium and the U.K.
45:29And then I come to this conference and there's a lot of anxiety about it.
45:32But I think it's largely, it's not because of, it's not for fundamental reasons.
45:37Those things are, those are very important barriers.
45:39I get that.
45:40But those are not fundamental.
45:41This is a nation and a continent of science and of technical people
45:45who have taken chances in the past and succeeded.
45:47And I, it's, it seems odd to me to see such pessimism.
45:50So yeah, be optimistic that you can do these things.
45:53There's no, like a historian would not describe this period as
45:56some period in which Europe is unable to act on its own.
45:59I think that's very odd to think of yourselves that way.
46:01So yeah, be optimistic.
46:02I, I certainly am.
46:04I think that's a great note to end on.
46:07So with that, I would like to ask the audience to give a nice round of applause to our panelists.
46:13Thank you very much.
Comments