
Threat Talks · 2026-04-28 · 27 min
Key moments - from our scoring
Substance score
61 / 100
Five dimensions, 20 points each
Supply chain security has become a critical vulnerability in protecting U.S. critical infrastructure following high-profile intrusions like Volt Typhoon and Salt Typhoon. Caitlin Clarke breaks down how organizations should think beyond just physical hardware - routers, 5G antennas, CCTV cameras - to include software, open-source components, and the people involved in development and R&D. The conversation explores the tension between cost-driven procurement decisions and security risk, where cheaper products from certain jurisdictions may carry hidden vulnerabilities known to foreign governments before patches exist. Clarke emphasizes that CISOs and CFOs must align on total cost of ownership, not just upfront expenses. She recommends mapping supply chains to the nth-party level, developing exit strategies for critical infrastructure, conducting business continuity testing around forced vendor replacement, and implementing behavioral-based insider risk programs. The discussion also addresses emerging risks from AI-generated code, open-source library compromises, and the need for organizations to understand their complete "trusted tech stack" from data centers to cloud environments. This is essential listening for CISOs, infrastructure operators, and anyone responsible for critical infrastructure resilience.
The cheaper product may come with hidden vulnerabilities known to foreign governments before industry patches exist, creating downstream costs of forced replacement, patching delays, and operational disruption that far exceed the initial savings over 5-10 years.
Organizations should map to the nth-party level - supplier's supplier's supplier - to prevent adversaries from hiding behind shell companies, and third-party risk management questionnaires should specifically ask about technology provenance.
Supply chain risk includes hardware, software, open-source libraries, firmware updates, R&D outsourcing locations, people/insiders, and the full "trusted tech stack" from data centers to cloud environments.
Use vulnerability scanning tools to continuously monitor for risky changes, build custom code using AI instead of external libraries if provenance is uncertain, or maintain a software bill of materials that gets updated as dependencies change.
Test your ability to swap out critical infrastructure components without operational downtime, develop exit strategies upfront, and maintain backup supply options - similar to earthquake or pandemic preparedness plans.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode covers substantive topics relevant to infrastructure security (supply chain risk, vendor selection, software provenance, insider threats) with some actionable framings (align CISO/CFO, map supply chain, test exit strategies). However, the conversation frequently circles back to broad concepts without drilling into specific mechanisms, metrics, or novel tactical guidance. Many insights are restated across different angles rather than layered densely.
I think one we need to get some of the procurement folks and the security folks together and making sure that everybody... So CISO and CFO. Yeah. Talk.
I think there needs to be strategies developed upfront about, if this were to be something and it really needs to be about criticality and proportionality, right.
The discussion centers on well-known nation-state threats (Volt/Salt Typhoon), standard supply chain risk frameworks, and familiar vendor evaluation criteria. While the 'trusted tech stack' framing and the emphasis on economic security are somewhat fresher, the core insights (government vulnerability disclosure risks, multi-tier supplier mapping, software bill of materials) are already circulating in policy and security circles. The AI-as-mitigation angle is emerging but underdeveloped.
vulnerabilities are known by a government before industry knows about a vulnerability, before industry can take action to mitigate the vulnerability.
And I think this needs to start going through. And we talked a little bit about understanding the supply chain. I mean like fully mapping your supply chain.
Caitlin Clarke holds significant institutional credibility: former White House special assistant to the president for cyber and emerging technology, DHS background, and current Senior Director at a major law firm (Venable). She demonstrates insider knowledge of government cyber strategy development and policy mechanics. However, she explicitly cannot discuss classified details and speaks more as a policy interpreter than as an operator who has managed large-scale infrastructure or rip-and-replace projects firsthand.
Senior director of cybersecurity services at Venable. And previously, she's been at the white House, at DHS, and she's been a special assistant to the president for cyber and emerging technology.
I can't say. It was just joking.
The episode names threat campaigns (Volt Typhoon, Salt Typhoon) and regulatory frameworks (EU ICT high risk vendor, Huawei rip-and-replace) but provides minimal concrete data, timelines, or cost figures. The discussion of open-source compromise risks mentions an SSH key incident discovered by Microsoft and a building in Shanghai with 50 people managing an account (speculative), but no specific metrics on supply chain penetration rates, remediation timelines, or financial impact. Advice remains largely procedural rather than quantified.
You mentioned Salt and Volt Typhoon. You know, I think we talked Volt Typhoon last year when we were here in, you know, that was intrusions for the purpose of disruption. Then you have Salt Typhoon, which was a massive espionage campaign.
There's probably some kind of building in Shanghai I imagine with 50 people that control this one account.
The host asks reasonable follow-up questions and attempts to translate policy into practitioner language (e.g., 'What do I do if a product is 40% cheaper?'). However, the questioning often accepts broad answers without pressing for specifics, mechanisms, or disagreement. When Clarke states that mapping supply chains to the 'end' is necessary, the host doesn't challenge cost/feasibility tradeoffs. The conversation meanders across hardware, software, people, and AI without sharp interrogation of contradictions (e.g., the tension between multi-year contracts and dynamic threat landscapes is acknowledged but not resolved in depth).
So if I'm a CISO and I know okay, this I have doubt about this product, I know it's 40% cheaper. What do I do then?
But you sign a contract, a multi-year contract. And then two years later, one of your supplier's supplier, is bought by some other company that is on some list.
Computed from the transcript - who did the talking, and the words that came up most.
Volt Typhoon spent years pre-positioning inside US critical infrastructure. Salt Typhoon pulled off one of the largest espionage campaigns in history. They didn't break in. They were already there. So what do you actually do about it? Caitlin Clarke , Senior Director of Cybersecurity Services at Venable and former Special Assistant to the President for Cybersecurity and Emerging Technology, joins Lieuwe Jan Koning, Co-founder and CTO at ON2IT Cybersecurity, to work through the practical steps security leaders should be taking right now, before the regulatory guidance catches up with the threat. What's in this episode for you: A clearer view of what's actually in your stack. Hardware is the easy part. Software updates, open source libraries, AI-generated code, outsourced R&D - any of it could be adversarial, and most teams have never asked. A practical way to map your supply chain before you have to. Fourth party. Nth party. Vendor exit strategies baked into business continuity. Procurement and security in the same room before the purchase, not after the incident. A framing that goes beyond the technical. Insider risk. IP theft. Economic espionage.
Transcribed and scored by The B2B Podcast Index.
How can we avoid China to be in our critical infrastructure? Welcome to Threat Talks. My name is Lieuwe Jan Koning and here from headquarter at Venable in San Francisco during the RSA conference this year, we bring you the next episode. And last week we talked about the new cyber strategy of America that was recently released.
And today we'll explore a little bit deeper in what the consequences of this are. And we take it a little bit broader actually. We're going to talk about what are practical things that we can do, what is not in the in the regulation yet. What will be there.
What kind of things you could do today to fortify your defenses and to make sure that these awful things that we've seen won't happen in your organization. Welcome to Threat Talks. Let's delve deep into the dynamic world of cybersecurity. And I'm thrilled that she is here with me again.
Caitlin Clarke, welcome. Welcome to the show. Thank you. Senior director of cybersecurity services at Venable.
And previously, she's been at the white House, at DHS, and she's been a special assistant to the president for cyber and emerging technology. So she knows a lot of what the government can do in this and what should be done. I'm sure we cannot talk about everything you know, today, unfortunately or fortunately. Yes, unless, you need that Men in Black movie wand to erase memory and then we can start all over again.
I don't think our... We don't have that. We don't have it yet. Not here, but it probably requires a device in every postcard listener.
Exactly. Device as well. Yeah. We'll see.
We'll talk about that when it emerges.. Talking about emerging technology. Yes. Does that exist already?
I don't know. Or you can’t say. I can't say. It was just joking.
Last time we talked about the new cyber strategy. And a lot is still unclear. Of course. And we expect that to become more concrete in the next coming months.
But especially given your experience, we can already say a lot about the things that that we can do. And maybe let's start with; I know it's not directly related to the strategy, but we have seen in the past couple of years” Volt Typhoon, Salt Typhoon as examples of what is possible when, for example, China tries to get in, gather intelligence, attack critical infrastructure specifically, that could be many different things. I'm sure it's crossed the president’s mind when he wrote the the new strategy.
I mean, that's very logical. I think that's the context in which the strategy was being developed is, you know, we've had multiple years of campaigns in the US of nation state adversaries targeting critical infrastructure for different purposes. You mentioned Salt and Volt Typhoon. You know, I think we talked Volt Typhoon last year when we were here in, you know, that was intrusions for the purpose of disruption.
Then you have Salt Typhoon, which was a massive espionage campaign. But I think that is the context around which the vision of the National Cyber Strategy was written. And I think it's also the context in which CISOs need to be thinking about how they operate their businesses today. Yeah.
So and we talked a little bit about this. A big part of it is this supply chain thing. And agreed we need to see how it bends out. Is it about countries, companies or that are blacklisted somehow.
So you cannot put them in... That could be it. But regardless of this, I mean, you mentioned last time you need to figure out what your supply chain is and where they are from. Could you elaborate; how are customers coping with it?
Where do you start in this, if you're completely new to this? If you're completely new. So I think a couple of things here. One, I think we need to think about supply chain more than just the physical devices.
Right? Because when we talk about adversary technology, there's a lot of... there's a lot of pieces to that puzzle. There is the device itself.
Yeah. Like a router, like a 5G antenna. Like a router. And you know...
Or a car with a camera in it. There's, you know, closed circuit television cameras, which I know has been discussed in Europe and other places. There are home routers. There are...
Everything from large cranes and ports to scanning machines. I mean, there is technology in every part of our lives, every single day. And I guarantee you, most people don't ask the question about where's this from? Well, I think some people do, but I think a vast majority of people look for what is cost effective and maybe don't think about downstream costs.
And that is something that we've seen in products and critical infrastructure, especially those that are maybe PRC manufactured. They are quality products that are made that cost less than others on the market. And so when you are looking for a new purchase, oftentimes the number one criteria you use is cost. Is supply chain management, is that a procurement problem, then?
It's a little bit of both. I think sometimes the procurement side is looking at let's make purchases. And again from a perspective of cost, whereas the security side is thinking about let's make decisions based off of how secure it is and what does that lifecycle look like. I mean, the initial cost upfront is not the only cost.
It's maintaining.. But it's so much clearer. It's so hard to guess what the cost will be, the total cost is, over the lifetime of your investment. It is really hard.
But I’m... look at the- So if I’m a CISO and I know okay, this I have doubt about this product, I know it's 40% cheaper. What do I do then? Well, I think that's where you have to start talking about the concept of potential vulnerabilities, right.
And that gets to some of the things that we talked about in the high risk vendor piece of the EU’s proposal, right, is that there are some laws on the books in some places that require vulnerabilities to be reported to government authorities before they have a mitigation or remediation. That means that that government knows about flaws in products before everyone else, and they could potentially exploit those flaws in products before everyone else. Now, if I'm a CISO I can't really do anything about that, right?
I can't do anything until I get a CVE, until somebody tells me this is an exploitable ability. And here's the patch. But now I'm behind, right. Are you saying this because say there's a let's say it's a Chinese manufacturer and they have this vulnerability and it's disclosed to China.
So now China knows a way to get into your country, is that it? I think that's the concern. Or the other way around, that- Okay. I think that's the concern.
Okay. Is that vulnerabilities are known by a government before industry knows about a vulnerability, before industry can take action to mitigate the vulnerability. And how does, like the challenge is, how does a CISO convey that potential risk to the folks making the financial decisions? Because that potential risk of leaving, you know, having a product from a company that must fall under that jurisdiction of that law on your network could potentially leave you vulnerable.
And that has downstream costs of either patching or replacing. So maybe you pay 40% less now, but you're going to pay a lot more in 5 to 10 years. Yeah. Well with the new strategy, the economics change a little bit because, you can now expect that you have to rip and replace if you're unlucky, an investment that you had not yet written off.
Right. So if you're two years in your five year renewal term or so. Yeah, it's very costly if you have to do it at that moment already. So you'd better already today...
It’s better to factor that in today. Yeah. But we've also seen a challenge with rip and replace is that there's been laws on the books to rip and replace Huawei and other Chinese manufacturers out of mobile telecom in the United States, and it's taken us years to get there because the costs are so high. Once the technology is embedded in your network, having to remove that and having to make sure that the remove- we talked last year about the, sometimes there's a priority for maintaining operations over security.
This is that on steroids right. Like because you know that product works and now I have to rip it out and replace it with something that I may not have the.. I may not know how it will function. I've got to do the testing.
I mean, that's a key thing. You gotta... if you need to replace something, you need to start testing, identifying what potential replacements are, you know, do some sandbox testing, to make sure that your operations won't have any impact for downtime, because that's the biggest thing, right? You need to maintain your operations.
[ ] would really be your primary advice to anyone to do this, because it has such a long term.. when you reap the benefits of choosing the right vendors. I think one we need to get some of the procurement folks and the security folks together and making sure that everybody- So CISO and CFO. Yeah.
Talk. I think they need.. and not just with the like “Oh no. We've had a security incident.
” Yeah, exactly. That's too late. This needs to be an upfront risk management decision. They need to start going through.
And we talked a little bit about understanding the supply chain. I mean like fully mapping your supply chain. Does that also mean the supplier of your supplier? I think it does.
How do you do this? Because that means that you impose like a requirement if you are purchasing that your supplier gives you insight in his supplier? Well, I think that's part of the third party programs for a lot of folks right now is that they ask questions about who are your critical supplier, that that fourth party relationship, that endth party relationship. I think there's still some question about how far down you need to go.
I would say to end, I mean, otherwise you could put shell companies in between all you like. And that's the other part is I don't think necessarily everybody knows all the time the provenance of some of their suppliers because.. Or don't want to disclose it. Yes.
It may be a competitive advantage. Exactly. And so I think another thing, so we talked about getting the CFO and the CISO aligned so that they can start looking at what this cost will be. We need third, I think third party risk management programs really need to make sure that they if they are sending out questionnaires to their vendors as part of their third party risk management programs, that they are asking questions around provenance of the technology used to support your services, so that they know that because, you know, if I'm a critical infrastructure owner and operator, and I have to remove adversary tech from my network.
My supplier, you know, maybe it's a service company or somebody else and they're not considered critical infrastructure. And they have quote unquote adversary tech on their... Am I? Do I need to make sure that they remove it?
Like what is it like there's I think just starting to ask those questions so you can map where those dependencies are and determine whether or not there is optionality. Because what I think we might find is in some places there's just not a good alternative. Yeah. And this is not a CISO problem.
But I think this is a US government problem about creating a marketplace for alternatives to grow when there are not what I refer to as trusted vendors in a market. You know... Is that because of international price dynamics, that certain industries are only to be found in a country that in hindsight, we don't really like to be in our infrastructure? I think sometimes we don't see the market penetration until it's already occurred, because nobody's fully tracking that.
But I think what we need to think about is like, what are the emerging technologies that are going to drive economies globally, understand the tech that underpins that and then do that same supply chain mapping. And maybe, you know, if I were queen for a day, I would be starting to invest in building trusted vendors in those places where we know that's where the economy is going to be moving. That's where technology is going to be moving, so that we have a trusted supply chain and we're not doing, oh, we know that this is where people are going to invest in.
I don't know, I'm just going to say like biotechnology, right. Like that's clearly going to drive a lot of of investment and economies over the next ten, 15, 20 like 50 years, right. Where are there risks in particular devices and different parts of the supply chain that we need to start thinking now about developing and investing in a trusted alternative, so that when you have to, when that time comes and you no longer can use that, there is something- There’s an alternative with enough capacity to produce.
Yeah. And what about... So that's all upfront. So I get that.
So you select your vendors. You make sure that your vendor’s vendors are okay. But you do this at procurement time, right, at the start of the deal. And you may have equipment for ten, five, ten, maybe longer.
But the world is changing all the time. So how do you solve this? I mean, an exit strategy from a vendor, for example. Is that an important thing or do you recommend investing in shorter contracts or so?
Because it sounds a bit odd to me that you make a decision on when you first buy, let's say, you’re telco and you want to have the 5G modems or the 6G modems coming in. Yeah, it's a photo, not a movie, right? It's a snapshot in time. Yeah.
And I think that's what everybody needs to realize is this is not a one and done situation. Like I think that this needs to- But you sign a contract, a multi-year contract. And then two years later, one of your supplier’s supplier, is bought by some other company that is on some list - But I think that's exactly why, you mentioned an exit strategy. I think there needs to be strategies developed upfront about, if this were to be something and it really needs to be about criticality and proportionality, right.
Like critical pieces of your network is where you should focus your energy. Like there's a lot out there. I would focus on what technology is driving, what is at the heart of my business and focus there, you know, and focus on the components and also- And those where the exit strategy, the execution of the exit strategy is most costly. It is most costly.
And it's also where you need to do your business resilience work with your business continuity folks, so that you can practice the, If I need to make this switch, do we, can we do it? And I think for a lot of folks, that's a question that they haven't really asked or answered. There's a lot of, you know, if this goes down, can we maintain continuity? I don't know how much.
I mean, I don't even know if I've ever like, even in my many times about if I had to replace this right now, can I continue operations? Yeah. Make a plan for those situations. Like you make a plan if there is an earthquake or so, like, or a pandemic.
When we talk about business continuity, I think it needs to be more than like there's a disruption to the you know, we've talked about supply chain disruptions during Covid a lot. And that was delays in products getting here. What if there is no alternative supply chain that you are permitted to use? Like what's your play?
You have to have a backup plan all the time for at least for the like you mentioned, the critical ones. Yes. Let's explore a couple of other things, we talked about indeed, you started with equipment, but it's not only equipment. We never finished that part.
It's not only equipment. It's also... what else? You know, it's the hardware.
It's the software. It's the people. It's the research and development. The software.
Let's explore the software. So you have hardware and there’s, let's say a car. There’s quite a lot of software in cars right now. But if there's a vendor that pushes an update that completely changes the landscape.
I mean, that's where I think we have to rethink how we document some of our security compliances in the new world. Right. Like if I give you a software bill of materials for my product right now, that's not the same software bill of materials, probably in three, four months. Not at all.
And yet, you know- But even within the software bill of materials, I mean, we've had several examples where in your software bill of materials, there is some kind of library that may be open source, for example, and then the ownership or the maintainer of this piece of software was transferred to someone else. Very clever person, very helpful. Okay, you do it. And then probably...
Very enthusiastic around coding. Yeah, there’s probably some kind of building in Shanghai I imagine with 50 people that control this one account. But and we've seen people put a public key in SSH for example. So one key in the world could log onto every system.
And that was discovered by Microsoft just in time. Right. We're also talking about those kind of sophisticated things. And that's really hard to factor in.
It is really hard to factor in. And I think that's something that- What’s the government gonna do? What's the government... That's a very good question.
It's why I'm not in government anymore. I... just joking. I think those are some of the nuances that need to be discussed as ICT high risk vendor approaches go into effect, right.
How do you account for open source repositories? I mean, I don't know who necessarily wrote that piece of code that I've ingested, but that's a risk flag for folks to understand how much open source code they are using. Right. Like so maybe you don't know the provenance of who was the first person to develop it so you can't answer whether or not it's, you know, developed by an individual in a quote unquote adversarial nation.
But I at least know where it is. Yeah. Right? Yeah.
And sometimes identifying where that is is the first part of the equation. Emerging technology. I mean, AI could help here, maybe because the hard part about software quality is always to find those bugs, etc., because there's simply not enough manpower to do it.
But now we have artificial manpower, which scales very well. So maybe... honestly, my personal opinion is that open source is going to get a hard time because those things you can now create rather simply yourself so you don't need it anymore. These libraries, if you're concerned about it.
So or you have a scanner that constantly checks for changes, whether they are risky or ... I think exactly what you talked about and I've heard that this week is that through the advent of AI, there are a lot of companies who are using AI to build their own software in code. Yeah, the developers,... Developer is no longer a very good...
Right. But so then. Career perspective. So then maybe you don't have that risk, right.
Because you have in, you've in sourced it to your company through the use of AI. So maybe you don't have that open source risk or you identify your open- So then it becomes super important to have trusted AIs. Yeah, exactly. So that we don't have, so that you know, the full extent of the AI tech stack from, and I think we have to talk about these things from data, you know, subsidy cables to data centers to, you know, networks to cloud environments.
All of these things are part of that, what I would call the trusted tech stack. And understanding that entire ecosystem is going to become more important. But I think, you know, as we talked about, the landscape is changing, as you said, maybe these questions that people have had about open source and provenance will go away because they they won't use that as much. Maybe.
But you still need to know where that is currently on your network so that you can make those decisions about do I feel comfortable here? Do I feel confident with this? If not, then maybe I write it myself using AI, I don't know. Yeah.
But there's also the other side of the AI going is of course there's also going to be more different, more attack factors so, the world is changing a lot, let’s ... So I've just, you know, I've closed one gap and I've potentially opened another. Yes. There’s still work for all of us.
Yeah. We're not putting ourselves out of work just yet by developing secure technology from the get go. Well, it should be our goal, right, to make ourselves obsolete in cybersecurity. But I've always had jobs for some reason that my, my end goal was to put me out of a job first in emergency management.
So people were so prepared that they could handle response, an incident on their own. And now, apparently in cybersecurity, I must have some- There’s always a next gig. I must have something in the back of my mind that is like, I want to make myself obsolete. Yes.
There's one aspect of this that I would like to discuss with you. It's around people. And because we didn't talk about that risk yet, I mean, well, there's people in open source project, maybe in some kind of building in China, that’s also people, but that's more of an abstract thing, I think. But hiring, for example, is that is that something or maybe some, some organizations outsource their R&D to a certain other region?
How do you think about that? I think we have to think about adversarial risk across things, from products to people. And, you know, I think a lot of companies have insider risk programs that, you know, develop for themselves risk flags for what they might look like. I want to be very clear.
I'm not sitting here saying that you develop a risk flag based off a person's country of origin, but I think that there are behaviors or, you know, risk thresholds that companies can set and flag against that if certain you see certain documents being moved around on the network, that should be a risk flag, right? Like there are certain things here, I'm not encouraging, I want to be, I'm going to double down on that. I'm not encouraging anybody to profile somebody based off of their country of origin.
But on behavior. But on behavior. And I think that's how most insider risk programs are organized now. And I think that is, will, if that's how you're organized now, then you're going to be well positioned for any potential regulatory requirements to remove adversary tech.
And although it says adversary tech, I think we still need to think about the full spectrum of what I would call economic security, which goes beyond just the technology piece. It also talks about the people in the research. Economic. Economic security?
Yeah. So securing the economics of your company and things, you know, there's, when you look at counterintelligence programs, we know that IP theft is oftentimes, is oftentimes what people want. Because you can supercharge your development if you didn't have to do the R&D yourself. So I think, you know, IP theft is still something we need to think about in this environment as we're moving so quickly with new technologies.
And that's where that kind of like people insider risk comes factored in. There's a lot to unwrap here. There's a lot. A lot to do.
It doesn't. Well, you might think with technology increasing and the cybersecurity industry becoming a little bit more mature, or at least leaving its infancy, it would be easier. Doesn't feel like it. It doesn't..
I think as we talked about, as you close one door, another door opens. And I think we're starting to get to that. There's so much complexity in the market that there's now a complexity risk, like the one job I think we're not making obsolete is our enterprise risk managers and folks who are managing risk. You know, I think they're going to have a very busy role for the next 5 to 10.
But as soon as we can, if we can quantify risk somehow, that is actually in most organizations, very well understood. It is very well understood. So to align with those processes probably is something to always keep in the back of your mind. Yes.
To become more successful. And like I said last year, let's make sure that security is not on the last check of the rest. Let's put them up front. That's why we said that the CISOs and the procurement managers should talk tomorrow.
Yes, exactly. Be best friends, please. Yes. Yes.
Well, thank you so much. I don't think we can hold any more for today. Any more new ideas and things to think about. Because otherwise we won't sleep tonight.
But I still want to, I want to thank you very much for for your insights and vision on these matters. And, well, let's continue making the world a little bit more secure day by day. And thank you for your participation in this. Great.
Thank you. And thank you for being on this show. Appreciate it. And to our viewers, thank you very much for tuning in today.
If you like this today, award us with a like you can also press the subscribe button. So next week's episode will also be in your inbox, so you have more of this great content at your disposal. And for now, I thank you for watching, for tuning in. Hope to see you next time.
Bye bye. Thank you for listening to Threat Talks, a podcast by ON2IT cybersecurity and AMS-IX. Did you like what you heard? Do you want to learn more?
Follow Threat Talks to stay up to date on the topic of cybersecurity.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.