
Exploited: The Cyber Truth · 2026-06-25 · 30 min
Key moments - from our scoring
Substance score
56 / 100
Five dimensions, 20 points each
Lieutenant General Bill Bender, retired U.S. Air Force, discusses why pure compliance-based cybersecurity approaches fail at military scale and how the Air Force shifted from compliance to mission-driven resilience. Managing 700,000 endpoints across a global organization, Bender explains how the Air Force moved beyond checkbox compliance through three key strategies: understanding current IT state through enterprise mapping of major commands, wings, and squadrons; prioritizing security around mission-critical systems rather than applying uniform controls; and building a culture shift through education and partnership. Bender shares concrete examples, including consolidating 2,200 Cisco contracts into one enterprise agreement, saving $300 million while improving service delivery. He details introducing the CISO and Chief Data Officer roles to the Department of Defense and establishing the Air Force Innovation Unit to accelerate software development through 34 software factories - enabling rapid iteration critical for modern threats like agentic AI. For commercial suppliers, government contractors, and security leaders, this episode addresses how to implement zero trust across heterogeneous legacy systems, manage technical debt in industrial control environments, and navigate public-private partnerships that drive innovation without compromising operational security.
Compliance-only approaches create unsustainable training costs across transitory workforces and ignore the critical need for mission-driven prioritization and technology deployment. The Air Force found that securing top missions first while methodically addressing second and third-order requirements - combined with technology and better methodologies - was far more effective than uniform compliance mandates across 700,000 endpoints.
The Air Force consolidated 2,200 individual Cisco contracts across bases into one enterprise contract, saving approximately $300 million over five years while eliminating counterfeit parts, improving response times, and enabling better leverage of vendor capabilities through a true partnership model.
The Innovation Unit, established with special funding and fast-track authority, enabled the Air Force to engage Silicon Valley startups, cancel legacy programs like the struggling billion-dollar AOC command-and-control system, and pivot to software-defined approaches already proven in the commercial sector, eventually leading to 34 Air Force software factories.
Bender implemented zero trust as a five-year prioritized journey focused on critical mission threads and nodes, accepting that 100% implementation is impossible but methodically moving from most to least important systems while respecting budget cycles and affordability constraints.
AI can identify vulnerabilities and write exploits faster than organizations can patch them, requiring serious conversations about accelerating DevOps pipelines and vulnerability response to match machine-speed threat generation across operational technology and critical infrastructure networks.
Our reviewer’s read on each dimension, with quotes from the episode.
A handful of genuinely substantive anecdotes - the Cisco contract consolidation, the cancelled AOC programme, and the CISO/CDO standup - provide real operational learning, but large stretches dissolve into high-level exhortation about culture, AI, and critical infrastructure that add little new. The ratio of specific insights to general commentary is modest for a 30-minute episode.
we were managing our Cisco components one base, one organization at a time. And we, no kidding, had 2,200 different contracts that ran across the Cisco equipment that was part of the global Air Force. When we thought about it differently and made that a single enterprise contract, we were able to save something on the order of $300 million
That had been struggling along and was probably close to a billion dollars and 10 years behind what it was supp to be. And we ended up canceling that outright and moving to a much more software defined approach
The 'Chief Education Officer' framing and the observation that decision-making cadence - not technology selection - was the real bottleneck are genuinely counterintuitive, but the episode otherwise covers well-worn ground: compliance-is-not-enough, zero trust is hard to implement, AI is a new threat. The thesis is familiar and no contrarian or first-principles argument is developed to completion.
surprisingly, as I got into a CIO role, talked much more about cultural mindset shift and process change than I ever did about the technology itself
It was really the decision makers. And the process by which we got to decisions had to move at the pace of technology
Lt. Gen. (ret.) Bender is a genuine practitioner at exceptional scale - actual CIO of the US Air Force, responsible for 700,000 endpoints, and credibly the first person in DoD to stand up both a CISO and CDO. He speaks from direct operational experience rather than thought-leadership abstraction, which elevates the episode significantly.
US Air Force had on, um, any given day, 700,000 endpoints
We were at an inflection point within the Air Force just understanding the cybersecurity threat for starters
The episode contains several concrete data points - $300M saved, 2,200 contracts to 1, a ~$1B programme cancelled 10 years late, 34 software factories, a 5-year zero-trust plan - but these are clustered in a few stories; the rest of the conversation is appreciably vaguer, particularly the AI and critical infrastructure sections.
we were able to save something on the order of $300 million in the costs of those contracts over a five year period
probably close to a billion dollars and 10 years behind what it was supp to be
Paul asks reasonable scene-setting questions and makes a few timely pivots (zero trust, supply chain), but questions are often leading or pre-answered in the framing, and neither host pushes back on any claim or probes for failure modes, trade-offs, or quantified outcomes beyond what the guest volunteers. The result is a comfortable PR-adjacent conversation rather than a rigorous one.
Bill, uh, my understanding is that you were actually the first person in the Department of Defense in the US to introduce the roles of CISO and coo
do you mind if I just zoom in very briefly on, um, a specific aspect
Computed from the transcript - who did the talking, and the words that came up most.
In this episode of Exploited: The Cyber Truth , host Paul Ducklin is joined by RunSafe Security CEO Joe Saunders and Lt. Gen. (Ret.) Bill Bender, former Chief Information Officer of the U.S. Air Force, to discuss what it takes to build true cyber resilience across some of the world's most complex digital environments. Drawing on his experience overseeing a $17 billion IT portfolio and helping establish the first Chief Information Security Officer (CISO) and Chief Data Officer (CDO) offices within the Department of Defense, Bender explains why organizations must move beyond checklist-driven security and adopt a mission-focused approach to risk management.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Exploited the Cyber Truth, a podcast by RunSafe Security. Welcome back everybody, to Exploited the Cyber Truth. I am Paul Ducklin. I'm joined as usual by Joe Saunders, CEO and founder of Run Safe Security. Hello, Joe.
Speaker B: Hey, Paul. Excited for today's conversation?
Speaker A: Me too. Because we have an extremely distinguished guest indeed, and that is Lieutenant General retired Bill Bender, U.S. air Force. Bill, I'm going to call you Bill from now on. I hope you don't mind.
Speaker C: I would love it if you'd do that. That's great, Paul, and thanks for having me. And Joe, nice to meet you.
Speaker A: Bill. Our, uh, title for today is From Compliance to Securing Digital Mission Systems at Military Scale. Now Bill, you've led both cybersecurity and IT for, let's be quite frank, one of the biggest organizations in the entire world, the U.S. air Force. When it comes to matters like compliance, which a lot of people talk about and are required to do, how do pure compliance based approaches fall short when you try and secure a system as complex as that of the U.S. air Force?
Speaker C: That's a fantastic question, and I probably would have been a much more successful chief Information Officer of the US Air Force if I had, uh, all of the right answers here. But certainly I have some general thoughts to your uh, point about a large organization the US Air Force had on, um, any given day, 700,000 endpoints. Wow,
Speaker A: that is literally anywhere and everywhere
Speaker C: in the category of the top 10 companies in the world. The scale is the issue. And when you start to talk about compliance and the challenges with a compliance only approach, you start to bring in, well, what's the training regimen? You can imagine that this workforce, similar to most workforces, is a very transitory one. Yes, the training bill associated with a compliance only oriented approach to securing your enterprise is really a non starter. And yet training has a significant piece of it. You have to have an all in approach within your workforce. And so I don't dismiss that as a requirement, but it's insufficient solely to do that. It's compliance plus the use of technology and better methodologies. And so in the case of the US Air Force, we spent a lot of time up front understanding what constitutes our enterprise and what is the current state of our it. Broadly, what were the component parts in the Air Force it would be the major commands and then the wings and the squadrons. You just sort of extrapolate that down and get a better understanding of your current state of it. If you don't know where you are, you'll never know where you're going. And Then trying to break that into relatively bite sized pieces primarily around mission priorities. Securing your top missions first and finally satisfying yourself with some of the second and third order requirements. A smart prioritized approach to what you're trying to do.
Speaker A: There's also the complexity compared say to a, uh, commercial organization that's selling items online. If something goes down, lives might be at stake, missions might be compromised. Rather than just that, uh, some customers might not be able to buy the shoes they want for the next 30 or 40 minutes.
Speaker C: Paul, that is very much the case. And uh, you know, we maybe overuse this term in the military sense, but no fail missions, yes, there are things that have to get done or lives are at stake. A lot of interplay, a lot of interconnections, a lot of interoperability required, a massive number of systems that have to be secured. And so starting with where am I today? Before I know where I want to go was really critical and it seems almost fundamental. But very often IT leaders want to jump to the conclusion that I've got a new technology, a new widget that's supposed to save everything. But the problem is it just doesn't
Speaker A: work that way in a commercial organization. Well, it might be expensive, it might be complicated, but you can shift from Windows 10 to Windows 11. But military systems typically include such a breadth and depth of different types of computer, operating system software and management interface that you can't really do that, can you? There are some things that you have to live with, like in industrial control systems, 4, 5, 15, 25 years, possibly even longer. How do you build that into both compliance and culture?
Speaker C: You have what you have and there's not any mechanism by which to get healthy overnight. And so there's a tremendous amount. I don't know that you mentioned it, but technical debt and a very legacy infrastructure and only so many dollars. The dollars are not a, uh, get healthy quick. You have to be really strategic and thoughtful about the approach. When I stepped into the Air Force role, we were managing our Cisco components one base, one organization at a time. And we, no kidding, had 2,200 different contracts that ran across the Cisco equipment that was part of the global Air Force. When we thought about it differently and made that a single enterprise contract, we were able to save something on the order of $300 million in the costs of those contracts over a five year period. But far more importantly, eliminate gray parts. Yes, have much better response times. We went from 2,200 to 1 and improved everything about our ability to take best advantage of good Technology that Cisco was providing as an industry partner. Part of my challenge was one of being a, uh, Chief Education Officer of the people both above me who typically developed those requirements and resources and weren't thinking in enterprise terms and definitely the people below me who felt like uh, for lack of a better descriptor, money is power. I have the money, I can make all the decisions. And I would be like, yes, but you don't get the best solution.
Speaker B: And I suppose there's always opportunities for even other areas. I think even today, much like your example with Cisco, other providers like Red Hat and folks that provide operating systems and things like that also may have significant number of individual contracts for certain projects, programs, missions and the like. There's room to both consolidate and modernize. And when you can create $300 million of savings and improve service, I mean that's a double win. Yes, that's a great step forward in general and a good example of how to create opportunity at the enterprise level.
Speaker C: And I think palt, if I could just pull the thread a little further on this, it would not have been possible without the partnership with Cisco. Yeah, was a full partnership. They were in from the beginning. They helped us take accountability of what was out there and helped us restructure and frankly had to deliver on the back end because they had made some promises under their service level agreements to provide 24 hour service, 72 hour service, whatever it was. And so it's definitely a partnership. But I think there's a lot of room for managing these big complex organizations by taking an enterprise approach, which was my initial point.
Speaker A: I was delighted to hear you use the term, um, I suppose almost in jest, but also seriously. Chief Education Officer building a culture where people wanted to do the right thing, not just wanted to, but felt that they were able to do so.
Speaker C: There were plenty of examples where you had to really drive a mindset shift about how we do this. Helping culturally to bring people up to an understanding of what technology provides them. I said it in jest, but quite seriously. Yeah, in most cases my focus was not on the digital natives, the young people who are using it every day who know very well what's possible and uh, for all the right reasons, were walking into work every day for the US Air Force frustrated because they weren't getting to leverage the best of technology. It was really the decision makers. And the process by which we got to decisions had to move at the pace of technology. And so a lot of the work that I did was really uh, to help leadership understand that there Were great changes taking place in the environment. And that meant that they had to change in their ability to get to quick decisions to leverage what was happening. By and large, we're getting better at that. But I would say it was complacency. We had gotten to the point where we were somewhat complacent and satisfied, and all of a sudden the technology was outpacing us and our processes. So surprisingly, as I got into a CIO role, talked much more about cultural mindset shift and process change than I ever did about the technology itself.
Speaker A: Bill, uh, my understanding is that you were actually the first person in the Department of Defense in the US to introduce the roles of CISO and coo, Chief Information Security Officer and Chief Operating Officer, bringing a sort of industrial or commercial flavor to managing things that I guess traditionally we just considered, oh, uh, well, it's computers. That's just technology. What was the idea of introducing those roles and how did they change how you perceived and handled risk?
Speaker C: That is absolutely true. We were at an inflection point within the Air Force just understanding the cybersecurity threat for starters. I came into the building well aware of significant breaches and having enough situational awareness to understand that we should be very concerned about protecting our data, protecting our weapons system, protecting our critical infrastructure, and did not see that as a matter of course on a regular basis. And was concerned because all of a sudden I'm in charge of it or responsible for it. So the first thing I did was stand up a cybersecurity task force. You can't have anything if it's not a task force in the military. We had all of the functional Air Force involved and, uh, together in the, the idea of raising all boats. We raised our awareness of the challenges and to talk to the stand up of a, uh, chief Information Security officer. It was a first in the Department of Defense, but we also stood up a chief Data officer along the way, stood up the Air Force Innovation Unit. That actually was the forerunner to the Defense Innovation Unit. And it was really all premised on, um, the world around us has changed. We have to change too. CISO was very common inside of large corporate organizational structures. And so we very much mimicked what was taking place out in the commercial world. And I think that it was validated by the fact that every single service, including the Department of Defense, all have these positions today. They followed in quick suit.
Speaker A: So I guess that would be the start of a very different way for the military to do their public private collaboration. Yeah, a lot more free flowing of information and ideas than perhaps had been either thought possible or desirable in the past. How do you embrace the private sector without undermining that operational security of something like the Air Force?
Speaker C: I kind of alluded to it in terms of recognizing that the relationship between government and industry had to change at that time. There was some challenges still to overcome in terms of wanting to be involved with the Department of Defense, for example, because things move really slow. If I'm an innovator and an entrepreneur, I'll be out of business before I ever get my first contract with the Department of Defense. So we had some responsibilities internal to the Air Force, in my case, to move those along. And so that was the standup of the Air Force Innovation Unit because they had special funding and the ability to move fast. There's an innovation hub out on the West Coast. I surprisingly spent quite a bit of time out in Silicon Valley just seeing what was possible. Eventually what it led to was the ability to look at some of the legacy programs and the way that they were proceeding and have more confidence in canceling those programs and taking a new, fresh look at it in the weapons system of the Air Force, that is Command and control, they call it the aoc. That had been struggling along and was probably close to a billion dollars and 10 years behind what it was supp to be. And we ended up canceling that outright and moving to a much more software defined approach, which the commercial sector had been dealing with for probably 15 years already. But it was new to the Air Force that led to a proliferation of software development across the Air force. We have 34 software factories. The other services are doing the same thing. And so it's a much more modern defense infrastructure and much more capable today.
Speaker B: And that acceleration of software development obviously drives further innovation for the warfighter. And interestingly enough, it's just a few years later, hence that we face a new major transition with AI.
Speaker C: The takeaway there is technology's moving fast. You can never rest on your laurels. You can't be complacent. You have to stay abreast of it. So let's think in today's discussion. One of the conversations I think with every company I intercede with at all is around agentic, uh, AI. And how are we going to defend against it? We have to have a serious discussion about that because you can't build a wall high enough or fast enough to keep up with it. To your point, Joe, it's a good thing that we went through this journey not too long ago with software development, because now we've got AI in front of us, and who knows what it'll be a couple weeks from now.
Speaker B: Yeah, and I would just add to your point around AI and agencic workflows and security. The fact that AI can identify vulnerabilities and even perhaps write exploits faster than organizations can patch is a serious concern. Serious conversations are taking place to find ways to improve and respond to vulnerabilities and exploits being written at machine speed, faster than we can patch, even faster than DevOps pipelines can produce fixes.
Speaker C: Correct.
Speaker B: Uh, Paul, I think we even have some discussions exactly on that point coming up. Yes, the ability to accelerate your software development processes through these software pipelines that you alluded to earlier, Bill, only enhances our ability to keep driving on innovation for the warfighter. You said tech debt earlier, Bill. With vulnerabilities, it could be more tech debt, but finding that way to continue to accelerate and deliver software fast. War fighters have the innovation is always a top priority.
Speaker A: Joe, we had a discussion a few podcasts ago with someone who had just come back from naval conventions in South Korea, reporting that apparently the South Korean Navy figured we've got all these plans to build some new aircraft carriers, which are, uh, the way you project your power historically. Let's scrap all of that. Let's have lots and lots of autonomous vessels instead. Let's do things completely differently. So they really did think of throwing out the. Well, you don't throw out the water in the Navy, I guess, but it's almost as though they did throw out the baby in the bathwater and say, let's start over.
Speaker C: Yeah, yeah. These conversations are taking place on new innovations. And I know there's a lot of really good people thinking about this, and certainly in the defense sector specifically, it's the defensive side, like, how are we going to defend against it? And that's the conversation I tend to be in. Just defending against determined adversaries who are now using AgentIC AI for nefarious purposes is a conversation worth having. And I know it's taking place, and I'm thankful to hear that from somebody like you, Paul. I'm hoping that we get some good, solid directions on where to go. There's just a world of possibilities, but honing in on them, um, and getting started and putting resources against it from a Department of Defense perspective is really important. And so I hope to be a part of that conversation going forward.
Speaker A: Bill, do you mind if I just zoom in very briefly on, um, a specific aspect that has become quite an issue, certainly for Commercial companies these days, notably after the coronavirus pandemic, as we've learned to have people working all over the world, which is something the military has been able to deal with for years and years and years. And that is the issue of zero trust. Mhm. Quite a buzzword these days. How does something like that, where you worry about people identifying themselves or devices identifying themselves in a much more ongoing way than perhaps in the past. How does something like that look in an organization like the U.S. air Force, which is just so very big? 700,000 endpoints?
Speaker C: Well, I think it goes back to uh, the first part of the conversation where first understanding where you are and how it all comes together and then a mission driven assessment. We called it mission assurance. And that exercise, intellectual as it is, helps you identify the critical nodes. These mission threads had to be determined and then prioritized inside of that. And the concept of zero trust, to your question, Paul, I don't think there has ever been an argument it makes perfect sense. It's accepting the fact that the enemy's already in your systems and in your networks. The concept was good, but the larger exercise of trying to make some sense of your enterprise really did portend to more of a cultural discussion around understanding. You can't take anything for granted. The weakest link will be what brings the whole thing down. And so first a security mindset overall, including your own personal role, and then a good understanding of your infrastructure to the level that you could prioritize it through the lens of how do I get from where I am today to where I want to be? And all of that has to get wrapped into practical matters like affordability and timing of budgets and things like that. You can imagine it gets pretty difficult. It's easy to talk about zero trust, really hard to implement it. I took a five year plan and really looked at it through. Let's be confident in our priorities. We won't get that 100% right, but let's methodically work our way through from most important to least important and do it over time that budgets could support. I was very not Pollyannish, but had a good understanding that at the end of the day we'll be in a much better place. We won't be perfect because you never are, but you'll be in a much better place if you take that approach. So zero trust, I think, has been a good organizing concept for the US Air Force and for the Department of Defense at large.
Speaker A: Joe, do you want to say something about how commercial organizations that want to provide smaller and Smaller, more compact systems into the Department of Defence. So no longer the huge contracts we had, but lots of different suppliers providing smaller projects. How would they go about making sure that they can support that move to zero trust? And where does something like supply chain security and software bills of materials come into that?
Speaker B: I think the uh, smaller organizations often bring innovation and novel new approaches. There's always a great relationship between the department and what's called Silicon Valley or technology startups in general. And of course uh, leaders like Bill and others spend time in California, spend time in Los Angeles, others spend time in San Francisco and build those bridges. And part of that is to bring a uh, pipeline of great innovation in. And there are a lot of mechanisms for small organizations to get introduced. We've seen the CIBBER programs and extensions of the CIBR program to help organizations get in. But at the same time there are then compliance requirements that even the smaller organizations need to adopt. In some cases they can partner with large primes. In other cases they'll develop their own adoption of say things like CMMC and the current standards that are expected within that. And along those lines, to your point Paul, I think organizations that are delivering software then can help enable the missions that Bill speaks of by helping to support organizations with the understanding of what they're actually delivering in their software. Yes, and that's where the role of software Bill Materials comes in. In the examples Bill gave was assessing the whole landscape and then developing the priorities. There's a lot of really, really, really good information inside these software Bill materials. So thinking about even zero Trust, the extension to operational technology networks and things like that, where zero trust, they're starting to be a focus in on O2 networks for zero trust and they're in with all the vendors that are involved in providing operational technology to the military. Understanding the software Bill materials is a good enabler, uh, to understanding the uh, software risk and therefore understanding the broader threat that an organization might face if there's a challenge to its critical infrastructure.
Speaker A: By all means appoint a chief compliance officer. But if you're going to do that, definitely have a chief education officer as well. You're not just getting the driving license and then never thinking about road safety ever again for the rest of your natural life. So gentlemen, I'm conscious of time, so perhaps we can finish up, offer either or both of you a chance to say something about where you think we will or should go as more and more of our stuff in our regular lives, in our home lives in our home, automation in industrial plants and uh, very Definitely in the military, as more and more of our stuff becomes software driven, so we can sort of change it almost at will, like a web app, seven times a day if we really want to. How do we sort out the cyber security challenges that that brings, particularly for organizations as important and as broad and as deep as the U.S. air Force?
Speaker C: I think one of the greatest challenges for the country and for the military today is really around our critical infrastructure, our operational technology, our not too much effort would be expended in researching where does that become critical in challenging our society around some things that we've become pretty used to having. Paul, you mentioned the advances of software and automation in our home and stuff. I would say really thinking through some of the advances in technology, addressing some long standing shortcomings and maybe even failures to consider the worst outcomes in how we designed the infrastructure that we're living with today and turn at least some of the intellectual energy around the tremendous advances taking place with AI and with technology more generally towards addressing some of the challenges that we have in particular around our critical infrastructure and take care of the big problems so that we can focus on the small problems. And I know there's a lot of smart people, a lot of agencies, a lot of research and development money being spent here, but for many, many years we have built ourselves into a box with software that isn't entirely secure, with a lot of breach capable system designs. And so now all of those are at risk, especially with the advances in AI. And then of course we haven't even talked about quantum, but that's right around the corner. And so technology will be our solution, but we have to think in some cases differently about it in terms of at least an aspect of defending and recovering and ameliorating some of the challenges, the weaknesses that exist today.
Speaker B: And I don't think I could say it better than you did, Bill, and I'll just say a couple things in my own words related to it, which is that I do think critical infrastructure is an extension of national security. And it's a requirement to ensure that we have sufficient energy, sufficient data center capability and all the other mechanisms that support the expectation that we can operate our programs and our systems and our missions. Ironically, perhaps the AI threat could awaken us on some of the critical infrastructure areas, especially if AI is identifying those vulnerabilities faster than we can patch. It's going to force us to really think about how do we change and update or defend these systems. And it's much like saying that you don't truly understand algebra until you start to understand calculus and then you become an expert in algebra. I guess I am always the eternal optimist here, and I think there's great things to come with AI, and certainly there will be significant challenges. But when you operate at machine speed and the threat is increasing, those are some of the great moments, I think, for people, for teams and organizations to grow and learn. And I suspect all of our military and certainly other aspects of critical infrastructure are going to rise to the occasion. And perhaps it is AI that's going to induce us to do so.
Speaker C: I certainly share that, uh, sense of optimism. I do think that therein lies the answer. We just have to think differently about how to use it to solve problems, but also an honest assessment of where those problems exist. I'm an optimist in the long run, so thank you for that perspective.
Speaker B: Thank you, Bill.
Speaker A: I think that's a really brilliant way to conclude. If I might try and summarize it, there's a great Australian saying about let's not worry, which is, she'll be right. The problem is, she probably won't be right unless we all bring a little bit of our own effort to the table.
Speaker C: Yes.
Speaker A: Ask not what technology can do for you, ask what you can do for technology. And remember, folks, you heard it here from Joe. It's time to brush up on those differential equations. So that's a wrap for this episode of Exploited the Cyber Truth. Thanks to everybody who tuned in and listened. If you enjoy this podcast and find it useful, please like and share us on social media. Once again, thanks to everybody who tuned in and listened. And remember, stay ahead of the threat. See you next time.
Speaker C: M.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.