On Point: Q&A With Daniel McCormack
What trends are you seeing with the cyber threat?
Two trends that I would highlight are the very malware-lite situations that we’re dealing with. Malware seems to be deployed only in the most necessary cases. We see plenty of zero days still being developed and used, obviously, but an incredible amount of end days that are being used for access to the edge, or social engineering still works a treat in a lot of cases. But once adversaries are inside the network, the way that they’re moving around, the way that they’re persisting is with the natural form of the network. It’s with the administrator’s own credentials, their own tools, everything that people have put in place.
Do U.S. cyber forces kick butt?
Yes. I think I can confidently say ‘yes, we do.’ But it’s everything in combination, the cyber forces and the ability to go and impact other people’s infrastructure. Their tooling is a big part of it, but it’s also matching that with the public information. We put out cybersecurity advisories from my directorate that go into excruciating detail on what actors are doing, in part to make that easier for everyone else to defend against and send the adversaries back to the drawing board.
It may not matter in some cases that their infrastructure still functions if the entire rest of their tradecraft is now common knowledge. That’s something that we work very closely with industry partners because we’re all looking at the same things, the same actors, the same technologies, just from different perspectives.
Can you estimate how much damage U.S. cyber forces impose on adversaries?
Yeah, I would say we are easily millions of dollars’ worth and probably measured best in tools that don’t work anymore. Where we have been able to thwart these campaigns the best is where we can address the capabilities the earliest because it’s really three people doing the entire operation from tool development all the way through exploitation.
It’s largely outsourced, and these exploits are expensive, weaponizing them even more so. So, when those things don’t function as intended when it comes time to start the operation, that’s an impact that hits directly into the wallet.
How cyber works nowadays means that some of the tools that don’t feel like cyber response are very useful—the sanctions, the indictments, the things that make an ecosystem harder to work in also have the effect of driving up those costs.
How does NSA swiftly implement AI-enabled cyber tools and adopt agentic AI?
This is one of the most collaborative areas because it is so new and evolving. The AI Security Center is focused first on deployment. If people can’t get these things into their environment in a safe way and in a trustworthy way, nothing else is going to matter.
We are looking and working with our industry partners to find out what else needs to be added, how these things roll out and how they can be used. The sheer magnitude that you can gain in terms of additional insights and ability to process and react almost can’t be quantified at this point because we haven’t done enough of it.
That’s the stage we’re in now, probably for the next several months. We have that long to find out how best to get these things in the environment, how best to measure the results that we get from it.
But I think the next phase becomes even more interesting where we see the ultimate effect and we see the changes that have to be made because, for the most part, this won’t work if we’re continuing to play the last game. If this is just a way to look at your logs faster, that’s not going to be successful.
A lot has been said about the difficulty of simply patching at pace to keep up with the number of bugs that are going to be found in the coming months. This is going to help with that, but it can’t be the solution.
A lot of this is how we turn this agentic option into changing the nature of the networks, changing that attack surface into something that can be defended in a different way even while you’re overwhelmed with logs, overwhelmed with things to patch. The immediate term is using these things in a way that changes what adversaries have visibility to and can act on.
Editor-in-Chief George I. Seffers edited questions and answers for clarity, concision and style from the final fireside chat at TechNet Cyber in Baltimore in June. For more complete answers, see the YouTube video.
Comments