The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/The Government Huddle with Brian Chidester
The Government Huddle with Brian Chidester artwork

210: The One About the Future of Cyber Warfare

The Government Huddle with Brian Chidester · 2026-06-29 · 27 min

0:00--:--

Key moments - from our scoring

Substance score

43 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality8 / 20
Guest Caliber11 / 20
Specificity & Evidence8 / 20
Conversational Craft7 / 20

Cyber warfare represents a fundamental shift from the financially-motivated attacks and espionage of past decades toward destruction-focused campaigns targeting critical societal infrastructure. Tom Marlowe explores how adversaries are now positioning themselves strategically within networks - as evidenced by the Volt Typhoon and Salt Typhoon campaigns - waiting to unleash coordinated attacks that could paralyze essential services before kinetic conflict begins. The Colonial Pipeline attack exemplifies attacker creativity: rather than targeting obvious operational systems, the attackers compromised the billing system, cutting off revenue and forcing a complete operational shutdown with cascading societal disruption. Marlowe emphasizes that defenders must think beyond technology vulnerabilities to understand attackers' true mission-based objectives - what data or operations they're actually targeting. For government agencies, this means conducting comprehensive red teams that account for supply chain risks, implementing zero-trust cloud architectures, assuming breach scenarios, and focusing defenses on life-critical and mission-critical systems. He addresses AI's dual role: increasing attack volume and discovering obscure vulnerabilities, while also enabling defenders to conduct faster threat hunting and vulnerability discovery at machine scale rather than human scale. The discussion covers CMMC compliance, SBOM (Software Bill of Materials) analysis, NIST guidance, and the necessity of continuous vulnerability management across interconnected systems that government and critical infrastructure operators depend on daily.

Key takeaways

  • →Cyber warfare has shifted from theft and espionage to destruction-focused attacks on critical infrastructure like power grids, water treatment, and communications networks, with positioning phase currently underway through campaigns like Volt Typhoon and Salt Typhoon.
  • →The Colonial Pipeline attack demonstrates that attackers often target mundane business systems (like billing) rather than obvious operational controls, requiring defenders to think about mission impact across entire operational chains.
  • →Government agencies should conduct comprehensive red teams, implement zero-trust cloud architectures, and prioritize defenses for life-critical systems while assuming they've already been breached.
  • →AI amplifies both attacker and defender capabilities at machine scale - increasing attack volume and discovering obscure vulnerabilities faster than human analysis, but defenders can leverage the same tools for threat hunting and red team automation.
  • →Social engineering to obtain valid login credentials remains the highest-probability attack vector, making security awareness training and phishing simulations critical baseline defenses alongside technical controls.

Guests

Tom Marlowe

Topics in this episode

Zero trust architectureCMMC (Cybersecurity Maturity Model Certification)Cyber warfareCritical infrastructureVolt TyphoonSalt TyphoonColonial Pipeline attackDark Wolf SolutionsNIST guidanceSoftware Bill of Materials (SBOM)

Questions this episode answers

What is the difference between cyber attacks and cyber warfare?

Cyber warfare differs from traditional attacks by focusing on destruction of critical infrastructure (power grids, water systems, communications) rather than financial gain or espionage. Adversaries are currently in a positioning phase, establishing footholds in networks before launching coordinated destruction campaigns, often as a precursor to kinetic conflict.

How did the Colonial Pipeline attackers successfully shut down operations?

Rather than attacking operational control systems, they compromised the billing system, preventing Colonial Pipeline from metering gas flow and charging customers. This cut off revenue streams and forced complete operational shutdown, demonstrating how attackers target business functions that enable mission-critical operations.

What concrete steps should government agencies take right now to defend against cyber warfare?

Conduct comprehensive red teams including penetration testing and phishing simulations, identify and prioritize life-critical and mission-critical systems using NIST guidance, implement zero-trust cloud architectures, perform software bill of materials (SBOM) analysis, ensure CMMC/NDAA supply chain compliance, and assume breach scenarios with AI-enabled threat hunting.

What role is AI playing in cyber attacks and cyber defense?

AI increases attack volume, discovers obscure vulnerabilities (like 20-year-old exploits) faster, and helps attackers generate exploitation scripts at scale. Defenders use the same AI capabilities for vulnerability discovery, threat hunting, red team automation, and analyzing systems at machine scale rather than human scale.

Why should government agencies think about mission and business functions when assessing cyber risk?

Attackers target systems based on what they're trying to achieve - stealing payroll records, design documents, or disrupting mission capability - not just random vulnerabilities. Understanding an organization's mission and business operations reveals which systems attackers would prioritize, allowing defenders to focus protection efforts accordingly.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

The episode surfaces a few useful framings - mission-lens threat modeling and the Colonial Pipeline billing-system creativity example - but is padded heavily with generalities like annual training, assume breach, and NIST guidance that add nothing for an informed operator.

cybersecurity, for lack of a better term, is no longer happening at human scale. It's happening at machine scale
Colonial pipeline couldn't meter how much gas was coming through its system, so they couldn't charge their customers

Originality

8 / 20

The 'think about the organization's mission, not just the technology' framing is a genuinely useful reframe, but nearly everything else - assume breach, zero trust, red teaming, phishing campaigns - is well-worn standard doctrine recycled without a fresh angle.

What is their mission? What is their objective, especially in the government? What is it that they are legislatively or trying to accomplish? That's where they need to consider their risks from
it's massive armies of AI agents charging at each other

Guest Caliber

11 / 20

Tom Marlowe is a working practitioner at a government-focused cyber firm with real client exposure, which lends credibility, but he speaks mostly at an introductory-generalist level and shares no proprietary operational depth or hard-won insider knowledge that distinguishes him from a senior consultant.

we're seeing the NDAA requirements that especially have come out under this administration, drive a lot of compliance testing and auditing for our customers
we work with them to think about not just the technology that they're using and how it might be vulnerable, but what is their mission

Specificity & Evidence

8 / 20

Named references to Volt Typhoon, Salt Typhoon, Colonial Pipeline, Claude, CMMC, NDAA, and SBOM are legitimate and grounding, but there are zero quantitative metrics, dollar figures, timelines, or breach statistics to substantiate any claim.

we've seen that in the typhoon attacks of Bolt Typhoon, Salt Typhoon. This is positioning in our networks
We saw that recently in reports on Claude Mythos with 20-year-old vulnerabilities being discovered

Conversational Craft

7 / 20

The host asks broadly framed, leading questions and inserts personal anecdotes (empty gas tank, Netflix movie) where follow-up pressure would serve better; there is no meaningful pushback or challenge to any of the guest's claims throughout the episode.

I feel like a lot of what we do today is on a network and it is communicating with one another
I know I've heard rumblings of things like the 2027 attacks in Taiwan

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

cyber22systems20government19mission15critical14system14attack12back11warfare11attacks11network10vulnerability10vulnerabilities10networks9perspective9today8

Episode notes

Tom Marlow, Managing Director at Dark Wolf Solutions joins the show to discuss the evolution from opportunistic cybercrime to full-scale cyber warfare. Together we break down why today's adversaries aren't just after financial gain, they're positioning inside critical infrastructure, waiting. From the Salt Typhoon intrusions to water treatment plant exploits, the targets have shifted to the very systems that hold society together: power grids, communications networks, and healthcare. We also dig into what government agencies can do right now, from comprehensive red-teaming to zero trust architecture and AI-enabled threat hunting, and what cyber conflict could look like in the next five to ten years, when autonomous AI agents may be the ones charging into battle.

Full transcript

27 min

Transcribed and scored by The B2B Podcast Index.

you're listening to the government huddle podcast brought to you by g mark you each episode features a unique discussion led by public sector executive and global government thought leader brian chitister experts in all things government from around the world join the show to share their stories and provide insight into the rapidly changing landscape that is the public sector from digital transformation to workforce issues, and even thoughts on policy. Nothing is off limits. Come on, let's huddle up.

Welcome back to the Government Huddle Podcast, guys. I'm your host, Brian Chidester, and today we have with us Tom Marlowe. He's the Managing Director at Dark Wolf Solutions. Tom, welcome to the show.

Thanks so much for being here today. Thank you for having me, Brian. Yeah, and we're going to talk all things cyber and more specifically kind of how that has evolved into full-scale cyber war. So tell me a little bit, I mean, we've talked about cybersecurity on the show a fair amount.

We haven't really delved into what we're going to talk about today around cyber warfare. So how has the nature of how we think about cyber attacks generally really evolved from things that we saw, especially during the pandemic around financial or even during political campaigns, more espionage driven motives into something that has really resembled full scale cyber warfare? Yeah, so it's definitely evolving. And as we see a push more towards cyber warfare, I would say that it's changing into a focus on destruction, as opposed to financial gain, you know, disruption and mischief or even notoriety.

But with destruction, we've seen in recent conflicts that the first shots fired are likely cyber shots. It's taking out critical infrastructure before anything kinetic actually happens to follow up on that. So that's the targets that we then need to think about. And we need to have a broad level of thinking, in my opinion, about all of those things that really support us as a society.

Our communications networks, our power grids, our clean water drinking supply, our abilities to provide health care, all of these start to become their targets today and they're exploited today, but not necessarily with the focus on bringing them down or causing even a denial of service. What I find interesting with cyber warfare is that you could picture things blowing up potentially, or we've even seen cases where hackers have managed to change the settings on industrial control systems at water treatment plants and potentially introduce chemicals at dangerous levels.

And while that is certainly frightening enough, I think it takes a lot less than that to really cause chaos in society, which I think would be the goal of destruction. Denial of service to these types of basic services would also, I think, cause quite a bit of confusion and decrease our ability to effectively face an adversary. And so when I think about cyber warfare, I'm more concerned about, you know, real destruction, real societal inconvenience, and things that go beyond just the financial gain or notoriety sought by the types of hackers that we see today.

So help me understand this a little bit. I like to think of things, especially this type of approach and sort of a maturity model. Are there things that we could be looking for or things that might foreshadow a more grave cyber attack from that cyber warfare perspective? And I think about, like you mentioned, critical infrastructure or things of that nature.

Are those some of the first things that would be a telltale sign that maybe something more catastrophic is going to happen? Or help us understand the way you rationalize what that maturity on the attack looks like. I think it's establishing footholds. So it goes back even a little bit before that and positioning and potentially getting ready.

And with that, we've seen that in the typhoon attacks of Bolt Typhoon, Salt Typhoon. This is positioning in our networks. They aren't necessarily denying networks or really abusing that ability right now. But we know the adversaries are being found in those networks.

They're there. The networks are breached, but not much is happening. And so I think it's a question of why hasn't the network been brought down itself yet? Why would the adversaries even want to do these things?

It's clear that everything today runs on the internet. It runs on communication. So the logical place to start positioning is in the communication networks to bring those down and reduce our society's capabilities and infrastructure, the ability for all of that to communicate with itself, which is going to introduce denial of service well before you get into the scarier scenarios of introducing too much lie into a water cleaning system or bringing down power or surging power, things of that nature.

So I would look back and realize that almost in a traditional cycle, there's reconnaissance going on right now and early positioning. And that's why I think it's critical that those types of threats and that type of call it, you know, sitting on the networks is still critical to go and hunt and root out, as well as to test those networks and even design and architect those networks in a way that make that much more difficult to do. How vulnerable are we right now? I mean, you talked about communication, right?

And I think about the way, like all of these certain devices that we use on a daily basis communicate with one another and how that's evolved significantly. I know just a few years ago, my wife and I were watching a movie on, I think it was Netflix, and I can't even remember the name of the movie, but there was a cyber attack, a cyber war type attack that happened. And then one of the things that they showed in the movie, again, Hollywood, but the ability for attackers to take over Teslas and send them in certain directions or things.

I feel like a lot of what we do today is on a network and it is communicating with one another. So what is what is our vulnerability right now to an attack like this? I think that we're definitely vulnerable, especially to attacker creativity. Certainly there's the Hollywood scenarios like taking over Teslas, but I go back to the colonial pipeline attack.

I really have to credit the creativity there. They went after the most mundane part of the network which was the billing system I not sure any security architects would have thought of that Most would picture the great Michael Bay explosion scenes with the pipelines or the storage tanks. Instead, they just took down the billing system. Colonial pipeline couldn't meter how much gas was coming through its system, so they couldn't charge their customers.

That heads cut off their revenue streams, so they had to stop all shipments until they could get it back online. But the societal impact, and I live here in the Mid-Atlantic, was that gas was temporarily unavailable. And so we all had to look at our gas tanks, calculate how long we could go for, hitch rides with friends who had more gas in their tanks. And you saw some other stories in the news.

That's the kind of societal disruption that can come with cyber war. And looking at those parts of the infrastructure network that maybe get overlooked because they are mundane. They aren't the operational control systems. It was just the billing system.

One of the things that we have covered on this show is the prevalence of AI within cyber attacks and cyber warfare. I mean, how much are we seeing AI being leveraged right now in not just the creation, but the acceleration of these attacks? And is this something, when we're looking at this through the lens of government, that they can really defend themselves against? You know, it's interesting from the defender's perspective, does AI really add anything or not?

That's a lot of the debate right now. I would argue the question is a little bit different. For me, cybersecurity, for lack of a better term, is no longer happening at human scale. It's happening at machine scale.

And it's increasing. What AI can do, if nothing else, is just increase the volume of even script kitty level attacks. And so if you're a defender on a network or you're monitoring a security operation center, that's that many more alerts that you're dealing with when you were already dealing with alert fatigue prior to any of this exponential increase in activity. The AI can automatically drive for people looking to attack the systems.

And that's just the noise or it could even be the vibe coded cybersecurity attacks. attacks. Where AI think it's particularly dangerous from an attacker perspective is that, again, you can combine it with that cleverness to think about those systems that normally wouldn't be targeted, to look at the obscure operating systems. We saw that recently in reports on Claude Mythos with 20-year-old vulnerabilities being discovered that no one had thought about.

AI starts to open up at a faster rate those more unique attack paths that aren't going to be as well defended. However, that's where the defenders also need to use AI to find those same vulnerabilities. Now, finding a vulnerability and exploiting a vulnerability are two completely different things. But at the same time, AI finds the vulnerability.

For a knowledgeable attacker, AI can quickly generate a script that defeats the vulnerability and can escalate or pivot access. Once in, AI can help the attacker understand what they're seeing. Likewise, from the defender's side, The defenders can provide the exact same analysis of their systems through red team reviews, as well as use that for Threadhut to increase the volume and increase the effectiveness of what they're already do and to put it more at a machine scale and a computer scale rather than at human scale.

yeah so i mean you talked about that i mean i guess ultimately it's sort of that that stress test side of things can ai support kind of the stress testing and and i feel like this is a good example where maybe ai and human in the loop can support because i feel like there is a creativity side of this i mean you mentioned the creativity within the colonial pipeline attack i mean we have to be thinking differently in terms of where our vulnerable areas are. I know we've talked a lot about the psychological side of things and being able to infiltrate the lowest common denominator to get into a system.

But how much are you seeing governments and organizations be able to think creatively and outside the box in terms of where their vulnerabilities could be? I think that this is, there's two things here. When I'm working with our clients, I work with them to think about not just the technology that they're using and how it might be vulnerable, but what is their mission? What is their objective, especially in the government?

What is it that they are legislatively or trying to accomplish? That's where they need to consider their risks from. Yes, an attacker may be after a flaw in, you know, free BSD or some other unpacked system, But why are they going after that? What are they really trying to get after?

And it might be to deny mission, to steal sensitive data that only that customer has. Maybe it's sensitive financial data on our citizens, protected health information, if it's an agency that provides health care, something along those lines. and consider what those targets are and why attackers want to go after them and exfiltrate or deny or destroy that data. And I think that's really getting into the mindset of an attacker.

The limitation I sometimes see is that the focus is solely on the technology. The conversations around cloud mythos, around technology, the tools, the software. But there's that why factor that comes in. Do I want to hack a piece of software because I just want to get into a system?

or am I after payroll records? Am I after sensitive design documents? Am I after mission plans? And I think that's where it opens up.

In the Colonial Pipeline, hindsight, of course, being 2020, it's Colonial Pipeline is a business. They need to make money. And so that's why if you take down the billing system, they can no longer make money and you've effectively brought them to a standstill. So that combination of, yes, the technology is very important, but also think about the organization's mission to really develop that comprehensive risk and threat model that you need to go protect against.

And that's where I think red teams need to come in too. Red teams should look not just at the technology, not just at the vulnerabilities and controls, but really think about what is their customer's mission? What are they trying to do? How could an attacker through the customer's systems interrupt that mission?

So a lot to unpack there. One of the things that I started thinking about is if we're thinking about it through the lens of mission, like you were talking about, and you layer on the complexity of, say, a supply chain within a certain project. So let's just take some type of military program, whether it's like for an air platform or whatever it is. You have a long list of vendors that are supporting that.

Maybe there is someone within that supply chain I mean this is the spirit of CMMC but you get to a point where the mission isn necessarily something that goes to the overarching project right It a small little cog in the overarching project. So how are you seeing across the supply chain, vendors really solidify that when they are working with government, where mission becomes so critical, when something shuts down, it shuts down the whole thing. How are you seeing whether it's pressure testing or going through an auditing and making sure that the entire supply chain is secure from top to bottom?

So we're seeing a lot of focus around what's essentially auditing and security testing with NDAA compliance testing. That's some work and services that we provide to commercial customers seeking to do business with the government from a supply chain perspective. We want to make sure that no critical components are coming from a nation that we may not necessarily be able to trust. The issue there is that if a critical component, say it's in a drone, has something to do with how the drone flies, what its camera can record, or where it calls back to, that presents some serious security vulnerabilities.

And so we're seeing the NDAA requirements that especially have come out under this administration, drive a lot of compliance testing and auditing for our customers to ensure that they comply with it. And rightfully so. It's a serious risk and this administration is aware and wants to control against that. From a software perspective, we're looking at ways and customers are trying to find ways to automate that software bill of materials checks.

Given that we've seen a couple of attacks against open source software repositories, open source software is still a great place to go to get software, but there needs to be appropriate testing and checks in order to ensure that code isn't sneaking in there that involves creating vulnerabilities. There's a number of tools out there that provide that support. But at the SBOM level, we're really looking at the source code and doing source code analysis to ensure that vulnerabilities aren't sneaking in if something was downloaded from a public repository to be incorporated into a piece of proprietary or sensitive software.

That makes a lot of sense. And you touched on earlier the colonial pipeline side of things. I mean, critical infrastructure isn't always necessarily governed by government, right? Or at least owned by government in that way.

So, I mean, it feels like from a vulnerability perspective, going back to one of the questions that I asked earlier, we are pretty vulnerable through that mission lens. I mean, if it's a company that's running something that is critical to the foundation that we as human beings are relying upon on a daily basis, I mean, if you knock things out like that, we become paralyzed. I mean, that seems like a pretty big vulnerability to me. Absolutely.

And I think sometimes, too, it's we forget what those things are until they're no longer available to us. when there's a power outage at the house, I forget that our internet is now also down. I can only find out about updates on whether or not when we're going to get power back from my phone, which is connected to the outside, you know, Verizon T-Mobile system. So and as it's like, it's almost like managing by exception, which you don't really want to do, which is you wait for something to go wrong, and then respond and then realize how critical something was.

I think Healthcare also comes to mind here in that hospitals rely on electricity. They rely on clean water to serve their patients, to help their patients to get healthy, to save lives and to provide positive outcomes. And when these basic services that we take for granted every day no longer become available, it can be quite jarring. Again, Colonial Pipeline caught me completely off guard.

I think I had a mostly empty tank when it happened. And so we were down to one car in our family until everything came back online. I had not thought about it. I had not planned for it.

It was a complete surprise. Now I keep both cars at half tank or better. So it's maybe sitting down and taking an inventory to understand what are all those different services out there that we depend on for our quality of life, for daily life, and understanding that those are vulnerable. We know that through events like Salt Typhoon, Volt Typhoon, hospital ransomware attacks, other instances of incidents that have been published in the media, there are certainly vulnerabilities out there and those things deserve a closer look.

We also know that the government has been working and negotiating with private industry to help create vulnerability reporting structures that don't necessarily penalize industry for reporting on those things, but at the same time also keep these vulnerabilities closed before they can be exploited. So if you had to narrow it down, I mean, if you're a government agency right now and you're thinking about this, obviously, I mean, cyber war is is a macro, a macro challenge. Right.

But there are micro focuses that I think we can do to solidify and make the vulnerability or that attack factor smaller. What are what are some concrete steps that these government agencies should be taking right now to do just that? We believe that one of the most significant opportunities for access into a network, the best case scenario for an attacker is to have a valid set of login credentials to go onto a network rather than exploiting a 20-year-old vulnerability in an operating system.

And that's typically obtained through social engineering. So what we would encourage a government agency to do is to figure out what its critical functions for operation are, what are its utilities. So not just mission systems, but how it runs its business, how it pays its employees, how it works with its suppliers and vendors, the contracting and acquisition process. And to take a look at those processes and to walk through them, but also to red team them and to do a comprehensive red team that involves some penetration testing tool, you know, also building and planting tools on the government agency network to see how long it takes a security operations center to pick up on it.

That way, the signature files the SOC is running on can be updated and better fine-tuned, as well as just educating employees. We know a lot of our customers, a lot of federal agencies, they have an annual training, security awareness training. Some of them are also running phishing awareness campaigns, whereby emails are sent out. Employees hopefully don't click on them, but if they do, rather than being taken through a link that operates something malicious, they're taken back to the security training website.

things of that nature I really believe it critical for that comprehensive red team to build awareness but knowing too that we humans nobody ever going to be perfect Also ensuring that if I was a government agency I would look at what some of my critical systems are I can follow some of the NIST guidance to determine where I should be focused. What are systems that are mission critical? What are systems that are life support or life enabling? What are systems that I need to keep the doors open?

Taking a look at how they're designed, within the government, there's been a lot of activity over the last 10, 15 years to transition to the cloud, to get out of the physical data center, and all of that's good. But one of the things we see again and again is that systems are lifted and shifted off of an on-prem network, dropped into an S3 bucket in the cloud, and then shipped out to production. One, that's a really expensive way to do it. And two, you're not taking advantage of all of the security features and services that the cloud has to offer to protect your information systems.

So we firmly believe that there's a lot of opportunity to take advantage of cloud native services, as well as the complementary tools that are out there to really implement zero trust, to make it really hard to navigate around the cloud in an unauthorized manner. Or if you are authorized, but say you're suddenly downloading data at three in the morning, something alerts on that quickly and stops it. There are services that do this. And also three, and I think at this point, everybody is doing this.

Assume you've been breached. and act like you've been breached. And that's where Threat Hut comes in, and especially AI-enabled Threat Hut. I think that there's huge advantages there from AI to help with that volume perspective and help to provide coverage to at least do some of the initial steps to determine whether or not a piece of the system or a piece of the network warrants further human inspection.

And just really kind of focus that. And to your point, where should they focus? Where should they narrow down? Because they can't do everything.

And that's where I would encourage, Think about the business from a risk perspective. Think about the operations from a risk perspective, especially if the government agency has any, you know, missions where life is dependent, you know, systems need to be up in order for lives to be protected. Those are probably going to be highest priority first. That makes a lot of sense.

And all really good tips. It's always interesting too. We hear, I mean, we have these conversations all the time, whether it's at work or even on the podcast. And they're all, I mean, generally ones that you think are common sense things, but we don't think about it on a regular basis and the adversaries are.

And they're thinking about how to penetrate. So I think continuous reminders are important. And as we start to wrap up, Tom, let's prognosticate just a little bit. So kind of looking ahead, I mean, what is the next five to 10 years of cyber conflict really look like in your mind?

I mean, I know I've heard rumblings of things like the 2027 attacks in Taiwan and how China and other nation states might attack the U.S. first to kind of limit our ability to retaliate. I think there's there's other things that we can also be looking into as well.

But I mean, what is the next five to 10 years really look like through your eyes? I think a continued acceptance of opening cyber volleys, if you will, as major doctrine for any type of conflict to take out radar systems. And to take out radar systems, you may need to take out power systems. But you're essentially throwing sand in the face of the person that you're going against and blinding them so that you can then bring in the kinetic operations.

I think I also, too, sometimes picture scenes from Lord of the Rings where it's just massive armies converging at each other. But in the case of cyber, it's massive armies of AI agents charging at each other. And a lot of that's going to be automated and operating autonomously, especially in the next five to 10 years as more of those tools become more capable, become easier to use. If nothing else, they can just create a lot of noise and distraction, which could be very hard to filter through.

And so I see AI continuing to take a primary role. And the fact of the matter is that, again, it's to scale humans to the size of the teams that you're going to need to try to handle all of this manually just isn't economically feasible in any budget environment. And so I firmly believe that AI is going to have to play a role in scaling human capability, human creativity up to machine size to take on what's going to be thrown at you or at the country from adversaries, whether that's part of an actual opening conflict or if it's just the ongoing nation state kind of espionage and harassment activities that have been ongoing for decades now.

So it's super fascinating to me, especially as someone who loves history, to take a look at the kind of the history of warfare and all the way. I mean, you could go back even further, but I mean, just if you want to start at the beginning of our country, I mean, the Revolutionary War and the way things were done there and what espionage looked like at the time, all the way into kind of World War I, World War II. and then how much things change going from Vietnam all the way into kind of Afghanistan and urban warfare and kind of how that changed the game.

And now this is a complete 180 around how to think about warfare and kind of what a preliminary attack could look like. It's no longer Navy SEALs going in and getting mines off the beaches of Normandy. It's cyber attacks to shut things down with platforms headed en route. So it's just really, really interesting to think about what cyber warfare looks like now and what it could look like in the future.

And appreciate you coming on to have this conversation with us, Tom. Absolutely. Thank you so much, Brian, for your time. And again, if I wanted to really focus on any key points, it's that the idea of really keeping a focus on when you're trying to decide how to prioritize to protect systems, think about systems dependencies on each other.

For example, you know, a radar system depends on a power system. And then also thinking about how that relates to the accomplishment of your primary mission goals and realizing that that may be what an adversary is truly after, your ability to complete your mission. And then that's the path that needs to be looked at and really focused on. Yeah, I think that that's one of the things I took away from what you said is that mission lens is a really good lens to be able to put on it.

and one to really identify what your true vulnerabilities could be. Well, thanks again. And thanks again for those listening. This has been the Government Huddle Podcast.

You can check out more episodes of the show by heading over to governmenthuddle.com or wherever you access your podcasts. And feel free to connect with me on LinkedIn or Twitter at Chittis Draby. Thanks for listening, guys.

Bye for now.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Mythos And The Disappearing Patch WindowAI Proving Ground Podcast · on Zero trust architecture96 / 100
  • How GTT Rebuilt Global Security For The AI EraWhat's Up with Tech? · on Zero trust architecture91 / 100
  • Why CMMC became necessary in the first place.Trust Issues · on CMMC (Cybersecurity Maturity Model Certification)88 / 100
  • Enterprise Buyers Now Demand a Vendor Software Bill of MaterialsB2B SaaS Talks with Fexingo · on Software Bill of Materials (SBOM)81 / 100
  • The Hidden Risk of Your InfrastructureThreat Talks · on Volt Typhoon81 / 100
  • The CMMC Reality Check: Gap Assessments, Documentation Overload & Why 30-Day Compliance Claims Are a Red FlagCMMC Compliance Guide · on CMMC (Cybersecurity Maturity Model Certification)80 / 100

More from The Government Huddle with Brian Chidester

All episodes →
  • 209: The One About the Future of Benefits Delivery
  • 208: The One with the GovCon AI Research Study
  • 207: The One with the Dataminr Global Field CTO
  • 206: The One with the Homeland Security SME
  • 205: The One with the Elastic Public Sector VP
Explore the best B2B Ops podcasts →
All The Government Huddle with Brian Chidester episodes →