Cyber Focus
In this episode of Cyber Focus, host Frank Cilluffo moderates a timely and wide-ranging conversation on the future of AI policy and governance with Sarah Beth Jansen, a senior fellow at the McCrary Institute and longtime DC policy expert, and Austin Carson, founder of SeedAI and former legislative director for Rep. Mike McCaul. The discussion covers the Trump administration’s AI Action Plan, sector-specific regulatory approaches, and how Congress can play a constructive role without stifling innovation. Both guests emphasize the importance of local experimentation, procurement reform, and...
info_outlineCyber Focus
In this episode of Cyber Focus, Frank Cilluffo is joined by Brad Medairy, Executive Vice President at Booz Allen Hamilton, and Dave Forbes, who leads Cyber Physical Defense for the firm. Together, they unpack their joint report with the McCrary Institute, Anchored in Zero Trust, examining the cybersecurity vulnerabilities of U.S. ports. The conversation explores China’s cyber activities, the significance of Volt Typhoon, and the risks posed by Chinese-made cranes operating at American ports. They highlight how economic and national security intersect at ports, the unique challenges of...
info_outlineCyber Focus
In this special Cyber Focus episode recorded at Black Hat 2025, host Frank Cilluffo sits down with two senior leaders from the Cybersecurity and Infrastructure Security Agency (CISA): Chris Butera, a more than decade-long CISA veteran currently serving as Acting Director of the Cybersecurity Division, and Bob Costello, the agency’s Chief Information Officer. They discuss how CISA is adapting its mission in the face of evolving threats, budget pressures, and leadership changes, while maintaining a rapid operational tempo. Topics include the agency’s fast-turn vulnerability response through...
info_outlineCyber Focus
Forescout CEO Barry Mainz joins host Frank Cilluffo to unpack the evolving cybersecurity threat landscape—from nation-state hacktivism to post-quantum vulnerabilities. Mainz highlights how adversaries are leveraging crowdsourced expertise and agentic AI to target critical infrastructure, especially operational technology (OT) systems in sectors like water, energy, and healthcare. The conversation explores Forescout's research on hacktivist proxy groups, the growing danger posed by embedded and aging devices, and the urgency of preparing for post-quantum cryptographic threats. Mainz...
info_outlineCyber Focus
In this special crossover edition of Cyber Focus and the Power Podcast, host Frank Cilluffo sits down with Aaron Larson to explore the evolving intersection of energy innovation and cybersecurity. From breakthroughs in small modular reactors and geothermal technologies to the power demands of AI and electric vehicles, they examine how the U.S. grid is being reshaped by both opportunity and threat. Larson draws on his background in nuclear power and conversations with top industry leaders to highlight the promise of emerging energy sources—and the urgent need to bake in security from the...
info_outlineCyber Focus
Richard Horne, CEO of the United Kingdom’s National Cyber Security Centre (NCSC), joins host Frank Cilluffo to explore how the UK is strengthening cyber resilience across critical infrastructure, private industry, and international partnerships. Drawing from his experience in both government and the private sector, Horne outlines NCSC’s approach to tackling advanced threats, closing resilience gaps, and collaborating with allies on systemic cyber defense. The conversation spans ransomware, AI, supply chain risk, quantum cryptography, and how organizations—large and small—can better...
info_outlineCyber Focus
Kristina Walter, Director of the NSA’s Cybersecurity Collaboration Center, joins Frank Cilluffo to explain how the NSA is building trusted partnerships with private industry to counter advanced cyber threats. Walter shares how collaborative work with defense contractors and tech providers has helped uncover zero-day vulnerabilities, block billions of malicious domains, and expose Chinese operations like Volt Typhoon. She also discusses the role of AI in cyber defense, the race to prepare for quantum computing, and why resilience—not perfection—is the new benchmark for critical...
info_outlineCyber Focus
In this episode of Cyber Focus, Frank Cilluffo sits down with Jonathan Braley, Director of the Food and Agriculture Information Sharing and Analysis Center (Food and Ag-ISAC), to explore the growing cybersecurity threats facing the U.S. food and agriculture sector. They examine the integration of operational technology (OT), the rise in ransomware attacks on farms and food producers, and the fragile nature of supply chain cybersecurity. Braley highlights why even small farms are increasingly targeted and how awareness, threat intelligence sharing, and proactive cyber defense strategies are...
info_outlineCyber Focus
In this special Independence Day episode of Cyber Focus, we bring together highlights from three influential House leaders shaping U.S. cyber policy: Chairman Mark Green (Homeland Security), Chairman Mike Rogers (Armed Services), and Chairman Rick Crawford (Intelligence). From digital warfare and offensive cyber capabilities to workforce development and interagency reform, this episode offers a rare look into how Congress is working to strengthen national security in the digital age. Listen to their full interviews: • Rick Crawford – We Are in a State of Digital Warfare • Mike Rogers...
info_outlineCyber Focus
In this urgent episode of Cyber Focus recorded June 24, 2025, host Frank Cilluffo speaks with retired General Frank McKenzie, former Commander of U.S. Central Command and Executive Director of the Global and National Security Institute at the University of South Florida. The discussion focuses on the unfolding crisis between Iran and Israel, recent U.S. military strikes on Iranian nuclear sites, and the fragile ceasefire now in place. McKenzie offers expert insight into the strategic weakness of Iran, the state of its proxy forces, and the growing threat of Iranian cyberattacks. They also...
info_outlineIn this special Cyber Focus episode recorded at Black Hat 2025, host Frank Cilluffo sits down with two senior leaders from the Cybersecurity and Infrastructure Security Agency (CISA): Chris Butera, a more than decade-long CISA veteran currently serving as Acting Director of the Cybersecurity Division, and Bob Costello, the agency’s Chief Information Officer. They discuss how CISA is adapting its mission in the face of evolving threats, budget pressures, and leadership changes, while maintaining a rapid operational tempo. Topics include the agency’s fast-turn vulnerability response through the Known Exploited Vulnerabilities (KEV) catalog, expansion and quality focus of the Common Vulnerabilities and Exposures (CVE) program, and the push to strengthen operational technology (OT) security. The conversation also explores resilience strategies like CISA’s new eviction tool, deepening public-private operational collaboration, securing supply chains, and the importance of reauthorizing the Cybersecurity and Information Sharing Act.
Main Topics Covered
- CISA’s mission, workforce, and adapting to leadership and budget changes
- Rapid vulnerability response and the Known Exploited Vulnerabilities (KEV) catalog
- Threat landscape, including nation-state actors and OT security
- Operational collaboration with industry, JCDC, and new IT platforms
- CVE program growth and automation for vulnerability management
- Resilience strategies, eviction tool, and micro-segmentation
- Supply chain security and Secure by Demand guidance
- SLTT cybersecurity grants and field support
- Importance of reauthorizing the Cybersecurity and Information Sharing Act (2015)
Key Quotes:
- “I'm really honored to work with some of the most experienced cyber professionals I think that exists anywhere in the world… We're seeing people step up into new roles, leadership positions, work on new technical projects that maybe they weren't before. And we're just hitting grand slams every day.” – Bob Costello
- “[I ask organizations] ‘How can you continue your mission without access to some of your critical systems? Whether these are your billing systems, your IT systems, your even just access to the Internet.’ And I think a lot of organizations don't have those kind of plans in place or can't function in those cases.” – Chris Butera
- “One of the things that we are trying to do every single day is remove some of those OT systems from the Internet. That is a very critical step that we think that there are very few business cases where you should have an OT system connected directly to the Internet.” – Chris Butera
- “We absolutely support reauthorization of [CISA 2015 authorities]… collaboration is what we're all about. We talk about cyber being a team sport and this helps make all the teams play a lot better together.” – Bob Costello
- “I think we all need to think about [supply chains] a lot differently. And it's across the board, whether it's open source, closed source, or hardware, everything is kind of linked together, and often we don't know where those linkages are.” – Bob Costello
Relevant Links and Resources:
Guest Bios:
- Chris Butera is Associate Director for Cybersecurity at the Cybersecurity and Infrastructure Security Agency (CISA), where he oversees operational efforts to protect the nation’s critical infrastructure from cyber threats.
- Bob Costello is Chief Information Officer at CISA, leading the agency’s enterprise IT systems, collaboration platforms, and secure information-sharing initiatives with public and private sector partners.