
Loading summary
Daniel Byman
The following podcast contains advertising to access an ad free version of the Lawfare Podcast. Become a material supporter of lawfare@patreon.com lawfare that's patreon.com Lawfair also check out Lawfare's other podcast offerings, Rational Security Chatter, Lawfare, no Bull and the Aftermath.
Memorial Care Saddleback Medical Center
At Memorial Care Saddleback Medical center, we're dedicated to making your birthing experience exceptional. That's why we offer a dedicated maternity concierge, private birthing suites, and around the clock care from expert physicians and nurses. And for babies who need extra attention, our Level 3 NICU provides advanced specialized care in a nurturing environment. Your journey into parenthood deserves the very best. Saddleback Medical Center Caring is our calling.
Laura Kim
Imagine a toilet so striking it inspired a couture dress. That's right, Kohler's Veil Smart Toilet in Honed Black actually inspired fashion designer Laura Kim to create a stunning black chiffon dress that debuted on the Runway at New York Fashion Week. The Vail Smart Toilet, with its curved design, deep rich textural color, touchscreen controls, and customizable cleansing features, can transform your routine into something extraordinary. That's the power of design. Design changes everything. Vail Smart Toilet in Honed Black only from Kohler Discover the Vail Smart Toilet and go behind the scenes of Kohler's partnership with Creative Director Laura Kim@kohler.
Michael Sohmeyer
We have to make sure that those at the federal level are able to provide the kind of assistance to those at the local level to truly help get ahead of these sorts of threats and then, heaven forbid it happens, but react fast, mitigate the damage, and recover as quickly as possible.
Daniel Byman
It's the lawfare Podcast. I'm Daniel Byman, the foreign Policy editor of lawfare, and I'm here with Michael Sohmeyer, who was the senior Department of Defense official for all aspects of cyber policy and will soon be coming to my program at Georgetown University to join me as a fellow professor.
Michael Sohmeyer
When you're in the national security space by default, to me it seems like it's an international matter that can be very much improved, and you can gain a lot of insight by working with foreign partners and allies.
Daniel Byman
Today we're talking about cybersecurity challenges for the United States and the best response for the US Government and for governments around the world. First of all, can you simply talk about the cybersecurity threat landscape today when you entered the Biden administration? What did it look like and how did it change during your time in government?
Michael Sohmeyer
Thanks, Dan. It's great to be with you And I'm a longtime listener, but first time caller for the Lawfare podcast series. And so it's great to be able to be back with the Lawfare community. I was involved with it before I went back into government in 2019 and have been a big fan for a long time. When I look at the threat landscape, I think the traditional way folks work through this is look at the bad guys and make some generalizations. I think the way I'd offer is that first, from my experience at the Defense Department for the last several years, one of the main missions is you have to be ready across all the bad threat actors for the worst day for a true conflict. Part of how I see the threat landscape is how is the military doing? How's the Defense Department doing on being ready for a truly bad day in cyberspace? And I, I saw a lot of maturity over time over those four plus years in how the military is preparing what we could think of as its readiness in advance of a potential conflict. So I think that is a very good development. The second thing is that there still remains obviously a significant amount of espionage that is conducted through cyberspace. So espionage is conducted all sorts of ways, but there's been all sorts of public reporting obviously over the years and over a decade of espionage that goes on using computers, computer network operations, and generally cyberspace. And I think the debate on that, you know, has generally gone between two poles. First poll would be, we don't want to be the victim of any of that. And the second poll would be, everyone does this, and how do countries manage their responses to something that in effect, everybody, everybody, spies. And so having to walk between those two poles when it comes to cyber espionage is something that I know the Biden administration grappled with a lot, and I have no doubt the current administration will have to do that as well. The final thing about the threat that I would just point out is I think we've really seen how ransomware and these kinds of extortion based attacks, not espionage, but attacks through cyberspace, affecting local communities in the United States and around the world. Hospitals, schools, those are still a serious risk. And we have to make sure that those at the federal level are able to provide the kind of assistance to those at the local level to truly help get ahead of these sorts of threats. And then heaven forbid it happens, but react fast, mitigate the damage and recover as quickly as possible.
Daniel Byman
So you've already brought in a lot of different potential threats. And some of those, of course, are Department of Defense threats. But a lot of it goes outside the Department of Defense or is done in conjunction with defense officials. Can you talk a little bit about roles and missions? Who's responsible for what on the government side?
Michael Sohmeyer
So a lot of the way, I think from someone like me who comes from the military side, though I never served, but in the title 10 or Armed Forces side of cyber operations, that is largely the away game. And so there's a series of institutions that are really involved in the away game, like DoD and the military services, US Cyber Command. There's also a number of institutions that are involved much more in the home game. And that's the FBI and that's dhs. And so for the Federal Bureau of Investigation, their primary role, investigate the violations of crime of criminal acts within the homeland and bring those perpetrators to justice. Those perpetrators may be abroad and so it may be very difficult to get them to justice. But, but the law enforcement role, that's a home game based on U.S. statute and domestic authority and DHS too, as the overseer of the sector specific agencies and how the homeland is protected. Again, a home game type of entity, one entity that falls in the middle a little bit, we keep coming back to from earlier is the National Guard. The National Guard, those individuals report to a governor and so our military, but actually are at the disposal of a governor to determine how to be employed and often have a lot more authority at home. And so if you were to draw a spectrum for roles and missions, you could have a home game on one side, away game on the other side, and then try to line up different agencies along the that kind of a spectrum. So I hope that helps our listeners get a feel for who does some of what.
Daniel Byman
Absolutely. I want to drill down on a few particular vulnerabilities in the cyber realm. So one is critical infrastructure. Can you explain both how you see the threat, but also what are some of the important measures for defense from a cyber perspective Here the threat to.
Michael Sohmeyer
Critical infrastructure is much more visible now than it was 10 years ago because the number of companies like Microsoft and others have written about the threat to critical infrastructure at home. And it's not a situation of a series of anonymous comments to one reporter and it makes its way into a news article, but is not sourced or you know, now the story is out and there's a lot of technical detail that's available that can shed light on the true threats to critical infrastructure, not just from intrusions through cyberspace, but pre positioning of ATTCK and other types of software that could pose a really bad day. There are three real challenges, at least three challenges that critical infrastructure defense poses. First, it's not just IT but also ot. So for those taking notes at home, hang a star by ot. Operational technology is a little different than IT or information technology. It's one thing to manage cybersecurity across Georgetown Edu, a big IT domain. It's another thing when you're also having to manage the cybersecurity of how power generation and water purification physical systems interact with those networks as well. That's the ot. And generally operational technology doesn't get updated very often. It's historically not been written with a lot of security in mind and so you end up with a lot of vulnerability there. So the OT IT nexus is really crucial when it comes to defending critical infrastructure because you have to do both. Second, there are issues of federalism. That is it poses big federal and national security risk. But states and local municipalities are often closer to the management or governing of critical infrastructure and even sometimes the ownership of critical infrastructure. And so you get issues about jurisdiction. What can the federal government do? But what does the state government or local municipality actually need to do? Hands on the third element. If the first was OT and IT and the second was federalism, the third, I'd hang a star. By public private partnership, no doubt. You know, this is one of these phrases that everybody loves to mention and has for decades. But for critical infrastructure security, usually a piece of critical infrastructure is owned or operated by a non government entity, which means government has in some cases very limited authority to actually direct change and improvement. And so the opportunity is to mature the public private relationship with certain key owners and operators before there's an incident. So that when the call for help goes out, the government and other experts have something to work with. They know who to call, they know who to talk to, and some familiarity to jump in and help. So those are three issues that I hope help our listeners understand a little bit about the challenges of defending critical infrastructure from cyber issues.
Daniel Byman
Now, if we shifted to supply chain vulnerabilities, which people have talked a lot about in recent recent years, how would that picture be adjusted? Or is it really the same sorts of factors?
Michael Sohmeyer
It can be some issues on ot, it kind of depends on the prime, depends on the largest upstream entity and the kind of business that they're in. But for the army for example, that's a large institution that has a lot of subcontractor, a lot of contractors, a lot of subcontractors, lots of subs of subcontractors, and so a very Complex web of entities. And I think largely we've looked at supply chain vulnerability from cyber related intrusions as something that we, we know is important, it's no longer head in the sand kind of business. Biden administration jumped right in on that very early on, and I've no doubt that the current administration will focus on that too. But increasingly, I think there are opportunities to provide cybersecurity as a service to those near the end of a supply chain who have no shot at realistically defending themselves against a nation state adversary. And so where I hope the conversation goes increasingly on supply chain cybersecurity is not what information can be laundered and provided four weeks after a big prime contractor learns about it, figures out how to get the word out, but instead what kind of environments can be developed securely from the start, where subcontractors and others who have no shot can just do their work in an environment that's already secured and helps them spend more time on their mission, more time on their role, and less on having to also figure out how to be cybersecurity experts.
Daniel Byman
As you know, artificial intelligence is kind of sweeping much of the discourse on tech issues, and some of it, I'm sure, is overstated. But at the same time, AI does seem to be changing a lot of cyber policy and cyber vulnerabilities. Can you talk a little bit about how you see AI changing the threat, but also if AI could be effectively leveraged to improve defenses as well?
Michael Sohmeyer
Well, leveraging it for defenses is a big opportunity. Let me, I'd rather conclude the discussion on AI on a positive note with that. So the two concerns obviously to start there are first that it makes disinformation and those adversary or competitor nation states who really seek to weaponize information against us, it can make their lives easier. It can make it easier to perpetrate that kind of a campaign. It also could allow a low level organization or entity that's trying to figure out how to conduct aggressive cyber activities. It could help them get better, faster, and so can replace or at least accelerate a training curve for malicious entities to make them more dangerous. But on the plus side, as you mentioned, there's a big opportunity for the cybersecurity business, that is the defense business, to unpack code that has been layered upon for defense decades that has become so complex, and that in most cases stays complex because companies maintain the need to support legacy builds and legacy systems and don't cut bait. With the oldest technology, there's opportunities to utilize AI to help us unpack that complexity. Identify bugs that could become exploitable, hopefully before others have a chance to exploit them. So it's a big opportunity on the.
Daniel Byman
Cybersecurity side, When I was in college, I used to dream about starting my own magazine. A few decades later I started this little site with two friends and Lawfare just turned into the magazine I always wanted to edit. It was quite literally a dream come true. The only thing more important than achieving a dream is protecting it. So protect your family by securing their future with life Insurance from policygenius policygenius makes finding and buying life insurance simple and ensures your family has a financial safety net they can use to cover debts and routine expenses, or even invest that money to earn interest over time. With policygenius you can find life insurance policies that start at just $292 per year for $1 million of coverage. Some options are 100% online and let you avoid unnecessary medical exams. On the Lawfare podcast we talk about risk and how to manage the risks associated with terrible things happening. Terrorist attacks, authoritarian takeovers, coups, cybercrimes. I have life insurance because it's a good form of financial planning. It's a good way to manage the risk of something bad happening to me to make sure my loved ones are cared for. That feels good. Policygenius combines digital tools with the expertise of real licensed agents. It lets you compare quotes from America's top insurers side by side for free. Their licensed support team helps you get what you need fast. They answer questions, handle paperwork and advocate for you throughout the process. PolicyGenius is the country's leading online insurance marketplace. Thousands of happy Policy genius customers have left five star reviews on Google and trustpilot. So secure your families tomorrow so you have peace of mind today. Head to policygenius.com or click the link in the description to get your free life insurance quotes and see how much you could save. That's policygenius.com.
Ryan Reynolds
Ryan Reynolds here from Mint Mobile with a message for everyone Paying Big Wireless way too much. Please, for the love of everything good in this world, stop with Mint. You can get premium wireless for just $15 a month. Of course if you enjoy over paying. No judgments. But that's weird. Okay, one judgment anyway. Give it a try@mintmobile.com Switch upfront payment.
Mint Mobile
Of $45 for 3 month plan equivalent to 15 per month required Intro rate first 3 months only, then full price plan options available, taxes and fees extra. See full terms@mintmobile.com what makes a great.
Warby Parker
Pair of glasses at Warby Parker? It's all the invisible extras without the extra cost. Their designer quality frames start at 95 including prescription lenses plus scratch resistant, smudge resistant and anti reflective coatings and UV protection and free adjustments for life. To find your next pair of glasses, sunglasses or contact lenses or to find the Warby Parker store nearest you, head over to warbyparker.com that's warbyparker.com hold that.
Noom
Sir, there's no time for pickleball because you're going to want to hear this. NOOM now has GLP1s.
Daniel Byman
No way.
Ryan Reynolds
Hold.
Noom
Oh yes. Wayfred psychology and meds. That's how Noom helps you lose the weight and keep it off.
Daniel Byman
That's really smart.
Noom
Oh, Danny, it's Noom smart. And they start at just 149 bucks and they're shipped to your door in seven days.
Daniel Byman
Holy smokes, that's fast.
Noom
But not as fast as my service game.
Michael Sohmeyer
Hey, who's ready to get pickled?
Mint Mobile
Get started with Noom GLP1. Today, not all customers will medically qualify for prescription medications. Compounded medications are not reviewed by the FDA for safety, efficacy or quality.
Daniel Byman
You've mentioned when we discussed roles and missions, the complexity of the number of actors. You've also talked about private ownership. When we're thinking about cybersecurity regulations, how do we think about harmonizing these across different jurisdictions of national security and more broadly, I'll say across society, given that it's such a so many actors are involved in the solutions to these problems.
Michael Sohmeyer
The R word has gone in and out of fashion a little bit when it comes to cybersecurity. There was a time, 10, 15 years ago, r word was a swear word and regulation was absolutely seen as something that would trade off innovation, would somehow cripple the ability for companies to innovate and make money. More recently, I think there was a sense that if the regulations for cybersecurity could be foundational enough and common enough to preempt a variety of local differences, that is, if companies could shoot for one standard or, you know, that was common, that that would actually help lift all boats. And I think here, you know, you saw the National Cyber Director office take a take a run at, at this during the last administration and I think now from what I understand it's something that is difficult as a word for folks to get behind. But I don't think folks have really distanced themselves from saying some form of baseline common standards to protect the most valuable and vulnerable entities in the country is required because the threat environment has changed so drastically. This is not an environment where ISIS is the primary challenge that is faced in national security. If you're serious about saying China poses the most aggressive competitive threat, then your cybersecurity policy, not your offense policy, your cybersecurity policy should reflect that according accordingly. And so I think what we'll see happening is two things. We're going to see a resurgence of states trying to put forward their own ideas for regulation or baseline standards and see which take. And so you'll get a little bit of confusion as a result, but you'll see some innovation. The second thing I think we'll see is insurance will become somewhat of a backstop for or in the absence of explicit regulations. Insurance companies will keep an eye on the evolving threat environment, and different companies, if they don't keep up with being mindful of that threat environment, will be less insurable at a certain point or their premiums will go up. So I will also be looking at the insurance world to see how they react, given the different posture on regulations going forward.
Daniel Byman
One challenge that we are trying to address as teachers at Georgetown University, but it's a broader challenge than a few students here or there, is the need for skilled people who understand the dangers but also have the technical skills to deal with cybersecurity threats and the necessary response. How big is the talent shortage? And are there things you feel the government or universities or private sector should be doing to address it?
Michael Sohmeyer
I spent a tremendous amount of my time at DoD focused on talent, or in wonderful DoD terminology, because we can't just say talent. We would say force generation and we would drop our voice two octaves every time we said it. But the issue at DOD is we've two types of humans. We have those in uniform and we have those outside of uniform. Both are critical sources of talent when it comes for cybersecurity. I have found at least over several years of working in and with the Department of Defense, I'm going to limit my observations on talent to the DoD adjacent world of talent just because that's what I know. And I feel like I want to stick to my brief. But for folks who come in and who are attracted to working on issues about cybersecurity or cyber operations, there are very unique opportunities that are not available elsewhere. But the culture of the organizations that they join privileges and encourages other types of work as a condition of getting promoted and advancing in a career. And so for the Navy, for example, not to pick on the Navy, but the Navy is very much a culture of going to sea it's not a shock. At least it shouldn't be a shock to anyone listening that the Navy cares a lot about going to sea. And so it's taken a long time for Navy leadership to get comfortable with having a career field that's treated as its own independent thing, where we're not going to invest very significant sums of national treasure in training someone to conduct very exquisite things with a computer and then send them to sea to paint the battleship gray. And that obviously is a little bit of an exaggeration, but culture in these organizations matters a lot when it comes to force generation and talent. And so what we were really trying to work on for the last year or so was building sustained mastery in the force for civilians and those in uniform to be able to say that if we're going to invest all this money in training you to do these very, very complex things, we need to keep you in these roles. And that means we need to find ways to promote you, to develop your career, to allow you to move around while still having you utilize that investment we made in you, that the taxpayers made in you to do very, very difficult things online. Developing those independent career paths was helped a tremendous amount by the creation of the Cyber Accepted Service. This is something that Senator Rounds and others on the Armed services community really led the way on. And so we have the legislative authority to do it now. We just have to make sure in the implementation that is follow through. The hitch, I would say, in what we're seeing right now with the cuts to probationary workforce folks. Rob Joyce made this point at an open hearing last month that sometimes when folks come in through an accepted service, like the Cyber Accepted Service, they are easier targets for the efficiency cutters. So what I am really not thrilled about seeing happening is the risk that we cut the very people that we've created, these special hiring authorities in these special career paths, that we cut them because they don't. They may not have the kinds of civil service protections to make them difficult to cut, but they're prized individuals. There's not that many of them, but they're prized because of what we've invested in them to do. So that's my biggest worry when it comes to talent management. Sorry, force generation going forward.
Daniel Byman
Can I ask, just as a continuation of that last point, one thing that I think makes some of the tech fields a little different is that experience and knowledge don't always go together, that you can have someone who's been in the field for 15 or 20 years in most cases, and they're better at their job than someone who's not been there as long. But with tech, often you have new technologies that younger people are simply more proficient at. Does that show up in the cyberspace or is it more traditional, kind of learn on the job, get better and better as you go along?
Michael Sohmeyer
It's another reason why I think optimizing towards mastery is so important, because the more time you stay on a hard target and the more time you stay in the field developing as a professional, from a novice to an apprentice, you know, to a master, the more exposure you should be given and should have to new technologies that are developing, whether it's new vendors, whether it's new products, or whether it's a way to just completely be done with an old way of doing business. And I think it's one of the reasons that I'm so excited to come to Georgetown, Dan, because under, you know, your leadership and ssp, what we are really trying to do with a, with a, a class of civilians and as well as some of those in the armed forces, is how do you accelerate that opportunity to learn about new technologies and figure out what can be most impactful to your mission and to help that next generation get a jumpstart for that type of issue spotting, I want.
Daniel Byman
To shift gears a little bit. We've talked about coordination across government. We've talked about coordination with the private sector and also some of the federalism issues. But how much is cybersecurity done in conjunction with US Allies and partners? Is this something that is, you know, there is a dependence with allies and partners or coordination? How should we think about how global this effort is?
Michael Sohmeyer
It's a great point, Dan, because so much of cybersecurity in the national security world is an international matter. I would point to an article that I co wrote with General Nakasone many years ago in Foreign affairs, where we open with a story of international collaboration through what is called a Hunt Forward operation. And that is different than the Defend Forward strategy, although upon further reflection, one can imagine a different nomenclature of things that would make it a little easier to distinguish. But while Defend Forward was the strategy from 2018 and the first Trump administration, Hunt Forward was a particular type of operation where at the invitation of a foreign partner, US Forces would be invited to join a foreign partner to look for evidence of malicious activity. And then we could take certain steps to inoculate at scale based on what we learned and that insight that was generated. So there's a tremendous amount of potential with allies and partners when it comes to Cybersecurity, but also if you think about just the force lay down of the Defense Department and how many countries the Department of Defense is active in at any given time, their cybersecurity risk at some point becomes our cybersecurity risk. And so when you're in the national security space by default, to me it seems like it's an international matter that can be very much improved and you can gain a lot of insight by working with foreign partners and allies.
Daniel Byman
Michael, I've gone through my question list, but is there anything more substantive I should be asking you before we end this?
Michael Sohmeyer
Well, Dan, if it's okay to break protocol, I'm sure. But I'd love to ask a question of you. And because I'm rusty coming back to civilized world after five, six years away, I'm interested in how the broader national security community, not the cyber people, but how the broader national security people see the challenges posed by cyber attacks. And if they think that actually life has moved on and now it's all about AI and cyber. So hot yesterday, but that's not a real thing anymore. Or is there an appreciation that the threat has grown alongside the rise in the threat from China? I'd just be interested in the non cyber person's view on cyber threats and challenges.
Daniel Byman
So I'll give you my truly non expert view of all this. So part of it in terms of, you know, what is the latest shiny object, certainly AI has taken the place of cyber. However, the Ukraine war I think really showed the importance of cyber defense to many people. The repeated Russian attacks on different parts of Ukraine's critical infrastructure and government attempts to take down power as well, and the role of the private sector in all that, in playing important roles in helping defend Ukrainian systems. So I think it was a very vivid reminder of the importance of cyber to me. A bit like air defense where, you know, it's the sort of thing we need air defense, we need cyber defense. Everyone nods. But when you actually see attacks happening and realize the tremendous potential of these, it really forces you to pay attention to, you know, does the United States have the necessary defenses? Also, as you said, as it's been more and more an emphasis on China in particular, there's a recognition that, you know, truly heroes appear in terms of technological capacity, that this is certainly not just not isis, but it's also not Russia, that this is a country that really has world class scientists, world class engineers, and is investing heavily in this capability. So the good news for people in this community is I think there's a real recognition of the importance of all this. However, part of the I will say good news is also a bit of bad news, which is when there are problems and failures, so far they haven't been dramatic. And what that has meant is people can kind of brush it off and say, well, you know, sure it's important, but people often miss the potential, I think, for some more truly catastrophic losses. But I think there has been a maturity on the non expert side in recognizing the necessity of a very strong cyber capability on defense. I think there is less understanding of offensive possibilities on the cyber side and I certainly put myself in that category, but of how this could really facilitate war fighting and in general serve as a very strong instrument for the United States if things get much darker in a conflict with China.
Michael Sohmeyer
I think that's a that's a great set of points, Dan. And I really should have mentioned on your last question about allies and partners, the Ukraine example, because it really does show that defense pays. And a lot of times we struggle for examples. But in this case the work that Ukraine put in with US Entities and other entities ahead of the invasion paid off. It's hard to argue it paid off. And it's a little easier when you're an entity and you say, oh gosh, maybe can we do that another day? Or we really don't, we've got other things we have to do. It's a great reminder that when things really go wrong, you're going to appreciate the fact that you made some early investments, time and relationships and capability development in case a bad day really comes. And for them it did. And thank goodness the relationships were there. So it's a great point, Dan, and.
Daniel Byman
It'S nice also to end our podcast on an up note. So Michael Sohlmeyer, thank you so much for joining us today.
Michael Sohmeyer
Dan Bimon, thanks so much for having me on. Great to be back again with the Lawfare community and joining Georgetown in the fall.
Daniel Byman
The Lawfare Podcast is produced in cooperation with the Brookings Institution. You can get ad free versions of this and other Lawfare podcasts by becoming a Lawfare material supporter at our website, lawfaremedia.org support. You'll also get access to special advice, events and other content available only to our supporters. Please rate and review us wherever you get your podcasts. Look out for other podcasts including Rational Security, Allies, the Aftermath, and Escalation. Our latest Lawfare Presents podcast series about the war in Ukraine. Check out our written work as well@lawfaremedia.org the podcast is edited by Jen Pacha and our audio engineer this episode was Kara Schillen of Go Rodeo. Our theme song is from Alibi Music. As always, thank you for listening.
Mint Mobile
Weight Loss it needs to be fast and sustainable. Noom GLP1 starts at just $149 and ships to your door in seven days. Take it from Lauren, who lost 22 pounds on Noom. If I come off of the GLP1.
Michael Sohmeyer
It'S not going to automatically make the.
Mint Mobile
My weight yoyo back $149 GLP ones. Now that's NOOM smart. Get started at noom. Com Real NOOM user composited to provide their story. Individual results may vary. Not all customers will medically qualify for prescription medications. Compounded medications are not reviewed by the FDA for safety, efficacy, or quality.
Summary of "Lawfare Daily: Cybersecurity Challenges and Opportunities"
Released on April 25, 2025, "Lawfare Daily: Cybersecurity Challenges and Opportunities" is an insightful episode of The Lawfare Podcast hosted by Daniel Byman from The Lawfare Institute. In this episode, Byman engages in a comprehensive discussion with Michael Sohmeyer, the former senior Department of Defense official for cyber policy, who is set to join Georgetown University as a fellow professor. The conversation delves into the evolving landscape of cybersecurity, the multifaceted threats facing national security, and the strategic responses required to mitigate these challenges.
Timestamp [02:45] - Changing Dynamics Under the Biden Administration
Michael Sohmeyer begins by reflecting on the cybersecurity threat landscape as he entered the Biden administration. He emphasizes a shift from traditional categorizations of threats to a more nuanced understanding of military readiness in cyberspace. Sohmeyer states:
"One of the main missions is you have to be ready across all the bad threat actors for the worst day for a true conflict." [02:45]
He highlights three primary areas of concern:
Cyber Espionage: Persistent and sophisticated espionage activities conducted through cyberspace remain a significant threat. Sohmeyer notes the ongoing debate between recognizing cyber espionage as a universal practice among nations versus striving to protect against it.
Ransomware and Extortion: The rise of ransomware attacks targeting critical local infrastructures like hospitals and schools underscores the necessity for robust federal assistance to combat and recover from such incidents.
Military Preparedness: There has been noticeable maturity in the military's approach to cyber readiness, positioning it to handle potential conflicts effectively.
Timestamp [06:16] - Defining Responsibilities Across Agencies
When discussing the distribution of responsibilities within the U.S. government, Sohmeyer outlines a spectrum ranging from "home game" to "away game" operations:
Away Game: Handled primarily by the Department of Defense (DoD), military services, and U.S. Cyber Command, focusing on offensive and defensive cyber operations beyond domestic borders.
Home Game: Managed by agencies like the FBI and Department of Homeland Security (DHS), concentrating on investigating cybercrimes, protecting domestic infrastructures, and enforcing cyber laws within the United States.
National Guard's Role: Positioned between home and away games, the National Guard operates under state governors but can be mobilized for federal cyber defense missions when needed.
Sohmeyer's explanation provides clarity on the complex interplay between various federal entities in safeguarding national cybersecurity.
A. Critical Infrastructure Protection
Timestamp [08:32] - Challenges in Defending Vital Systems
Sohmeyer addresses the heightened visibility and vulnerability of critical infrastructure in the cyber domain. He identifies three main challenges:
Operational Technology (OT) vs. Information Technology (IT): Protecting critical infrastructure requires securing both IT systems and OT, such as power generation and water purification networks, which are often outdated and not designed with cybersecurity in mind.
Federalism: The decentralized nature of infrastructure management across federal, state, and local jurisdictions complicates unified defense strategies.
Public-Private Partnerships: Since much of the critical infrastructure is privately owned, fostering strong collaborations between the government and private sector entities is essential for preemptive defense measures and rapid response during cyber incidents.
B. Supply Chain Vulnerabilities
Timestamp [12:29] - Strengthening Cybersecurity Across Supply Chains
Shifting focus to supply chain security, Sohmeyer emphasizes the complexity introduced by multiple tiers of contractors and subcontractors in sectors like defense. He suggests:
Secure Environments: Developing secure operational environments from the outset to enable subcontractors to focus on their missions without the burden of extensive cybersecurity management.
Early Investment: Highlighting the importance of early partnerships and investments to ensure robust supply chain defenses against nation-state adversaries.
Timestamp [14:27] - AI as Both a Threat and a Defensive Tool
The conversation turns to the role of Artificial Intelligence (AI) in cybersecurity. Sohmeyer acknowledges the dual-edged nature of AI:
Threats Posed by AI:
Defensive Opportunities:
Sohmeyer optimistically views AI as a significant asset for bolstering cybersecurity defenses, provided its implementation is strategic and well-managed.
Timestamp [20:38] - Balancing Regulation with Innovation
Addressing the debate over cybersecurity regulations, Sohmeyer discusses the historical aversion to regulation due to fears of stifling innovation. However, he posits that:
Standardization Benefits: Establishing baseline, common standards can enhance overall security without hampering innovative progress.
Insurance as a Regulatory Proxy: In the absence of explicit regulations, insurance companies may impose their own cybersecurity standards, influencing corporate behaviors and risk management practices.
Sohmeyer foresees a landscape where both state-led initiatives and market-driven mechanisms like insurance play pivotal roles in shaping robust cybersecurity frameworks.
Timestamp [23:50] - Strategies for Building a Skilled Workforce
The discussion moves to the critical issue of a cybersecurity talent shortage. Sohmeyer identifies several factors:
Cultural Challenges: Military branches, such as the Navy, have traditional cultures that may not prioritize or retain cyber specialists, leading to difficulties in sustained talent development.
Career Path Development: Initiatives like the Cyber Accepted Service aim to create dedicated career paths for cyber professionals, ensuring that their expertise is maintained and valued within the defense ecosystem.
Retention Concerns: Budget cuts and shifting priorities pose risks to retaining specialized cyber talent, potentially undermining national cybersecurity efforts.
Sohmeyer underscores the need for deliberate investments in training, career development, and cultural shifts within institutions to cultivate and retain the necessary cybersecurity workforce.
Timestamp [30:04] - Building Global Alliances
Sohmeyer highlights the international dimension of cybersecurity, emphasizing collaboration with allies and partners as crucial for effective defense strategies. He references the "Hunt Forward" operations, where U.S. forces work alongside foreign partners to identify and neutralize malicious cyber activities. This cooperative approach not only enhances threat intelligence but also strengthens global cybersecurity resilience.
Timestamp [32:19] - Integration of Cyber Threats in National Security
In a reflective exchange, Byman discusses with Sohmeyer how the broader national security community perceives cyber threats. Drawing parallels with traditional defense mechanisms like air defense, Byman points out:
Heightened Awareness Post-Ukraine Conflict: The cyber-attacks on Ukraine's infrastructure have underscored the tangible impacts of cyber warfare, prompting increased recognition of cybersecurity's importance among non-experts.
Perception of Cyber as a Strategic Asset: While offensive cyber capabilities are less understood, there is growing acknowledgment of their potential to serve as significant instruments in national defense against adversaries like China.
Sohmeyer's agreement reinforces the notion that proactive investments and international collaborations are pivotal in fortifying defenses against evolving cyber threats.
Lawfare Daily: Cybersecurity Challenges and Opportunities offers a thorough examination of the contemporary cybersecurity landscape, elucidating the intricate challenges and strategic responses necessary for national and global security. Michael Sohmeyer's expertise provides valuable insights into government roles, infrastructure vulnerabilities, the impact of AI, regulatory harmonization, workforce development, and the imperative of international cooperation. The episode serves as a crucial resource for policymakers, security professionals, and informed citizens seeking to understand and navigate the complexities of cybersecurity in the modern era.
Notable Quotes:
"You have to be ready across all the bad threat actors for the worst day for a true conflict." — Michael Sohmeyer [02:45]
"Critical infrastructure defense... you have to do both IT and OT." — Michael Sohmeyer [08:50]
"Insurance companies will keep an eye on the evolving threat environment..." — Michael Sohmeyer [20:38]
"Developing those independent career paths... has helped a tremendous amount." — Michael Sohmeyer [24:23]
"It's a great reminder that when things really go wrong, you're going to appreciate the fact that you made some early investments." — Michael Sohmeyer [35:34]
For more insights and detailed discussions on national security, law, and policy, visit Lawfare Blog and explore their podcast offerings.