
Loading summary
Commercial Narrator
Future readying your tech stack software. Define it. To refine and redefine with all systems at hand, you update anything and everything from wherever you are. Transform the everyday with Siemens.
Brooke Devard
When you're a maintenance engineer in a beverage manufacturing plant, you keep production lines moving and quality on track because there is no room for slowdowns. With Grainger's vast selection of high quality motors, sensors, battery belts and hard to find parts, you can get what you need fast and all in one place. So nothing gets in the way of getting the job done. Call 1-800-GRAINGER clickranger.com or just stop by Granger for the ones who get it done.
Chad Serena
40 years ago, would you have noticed if there were two cameras inside your house, one on your computer, three on your neighbor's house, one on the doorbell? You would have said, yeah, it would have stood out like a sore thumb. Now you probably walk into your office at any point in time and you don't even notice those things. You wouldn't even be aware that there's microphones or that somebody's phone's laying there that could potentially be recording you.
Jonathan Cederbaum
It's the Lawfare podcast. I'm Jonathan Cederbaum, Lawfare's book review editor, with Colin Clark and Chad Serena, senior researchers at the Soufan Center.
Colin Clark
Think about what the Chinese did with Volt Typhoon pre positioning itself within various US Utilities, transportation hubs. But instead of just immediate disruption, these kind of penetrations are more likely to, you know, precursors to a future pre positioned cyber attack.
Jonathan Cederbaum
Today we're talking about their new report, Closing the Software Understanding and US National Security. Your report talks about the software understanding gap. What do you mean by that term?
Colin Clark
Yeah, I would say just very briefly, that's our ability to, the way we've explained it, to understand, to verify, to reason about software which has been, you know, dramatically outpaced by its production and uptake and implementation. That created a gap. And in our report we have a graphic that kind of shows this. And because of the increasing prevalence and importance of software to really everything we do right, US national security interests US military, US intelligence agencies, but also every civilian function you can think of. There's tremendous risk that is built into this gap. And the gap continues to grow. It is exacerbated by a number of different factors. The newest monkey wrench is artificial intelligence and how we conceive that.
Chad Serena
Very good.
Jonathan Cederbaum
So is the problem of the software understanding gap principally about the quality of software and how it's developed, or is it one about how users of software have limited understanding of how software works.
Chad Serena
I think it's an all. All of the above, Jonathan, in terms of the. Not just on the understanding side, it's the what is the software going to do? How's it going to perform under different circumstances, as Colin talked about. But it's also, then how is it, what are user expectations? What do users do with it? What do different types of users do with it? And I see this spanning across a range of different types of users and organizations. So if you have chief technical officers or engineers or software engineers at one place, they're going to understand this problem very well. They if you have your individual users, like say any of us that are on this podcast right now, our understanding of how this works is going to be radically different. And I see that in terms of thinking about the differences again between how security professionals would deal with this subject and how individual civilians would deal with this subject. But now the difference between what of those apply to the national security ecosystem, those civilians who don't have quite the same understanding of this and the way they think about, you know, the implications of how secure things are, this becomes more problematic. So, for instance, one of the examples that we cited in the report was smart home devices. So things like your thermostat or your refrigerator or elsewhere, those could be tapped into technically. And then the IT systems that are governing those and the infrastructure that is then connected to those could be accessed through things in a person's home. This is unconceivable 20, 30, 40 years ago where you would never even stop to think about, is there something in my house that could conceivably be tied back to national security or maybe even just a security issue, a local security issue. Now that is certainly on the table and something that's possible.
Jonathan Cederbaum
Got it. So one of the recent seminal studies about this issue that you mentioned is the 2023 software understanding for National Security Initiative. What was that and has it led to any practical initiatives?
Chad Serena
So the Sun's report as we understand it and we don't have, I can tell you this is one of those questions that we don't have a great answer for, Jonathan, but we can probably provide a little bit of understanding of this. I think of this as a cusp know, what was that report about? What was this that was. That was generated. I think the national need for software understanding was generated from a 2023 workshop that was held by Sandia Laboratories out in. Out in New Mexico that then led to a number of different initiatives. So one would have been the oncd report, the Office of the National Cyber Director back to the building blocks, that report and then another report through Sandia Laboratories, but with others on Closing the Software understanding Gap. And that came out in June 2025. And why I say we don't have the best answer to some of these questions like this is a lot of this is very new, not just to us as security practitioners, but also to people that work in this area. Colin and I spent some time asking different people we knew just anecdotally, how well do you understand this concept of the software understanding gap and what do you know about software understanding? And a lot of people just didn't have an answer for us. They didn't know what the terminology meant. And we're sort of there too. We understand most more than, you know, the next guy or the average person. But at the same time it's something that's only a couple years old and has mostly been dealt with by people that are technically gifted and understand the subject very well and hasn't been explored in depth by people that understand the policy and security side of it.
Colin Clark
And I would add to that, I would say, you know, this is one of those cases of we don't need to reinvent the wheel, right? So the Sunsec Initiative, this group has already done substantial work on the topic 2023. It ran a systematic research agenda, it published the technical roadmap, it helped coordinate the Closing the Software Understanding Gap report. And there you had real interagency buy in, right? You had CISA, NSA, OUSD, R&E, DARPA. And so there's been a lot of work. And in some ways I look at our report as kind of building on the shoulders of that and bringing some of these issues to the forefront. And one of the things that we really tried to do here was connect this tangibly to what's happening in the operational environment geopolitically. So how does this impact the United States vis a vis our adversaries?
Brooke Devard
Right.
Colin Clark
We're in an era of great power competition. China, Russia, Iran, North Korea, a range of violent non state actors and other adversaries with lesser capabilities but that are improving each day. I mean, you know, my, my background is in studying transnational jihadist groups. And I've been spending a lot of time for the past year, year and a half looking at the lowering to barriers of entry into using a range of emerging technologies. Now I don't think, you know, violent non state actors are at the low end of that spectrum and, and China would be at the high end nation States. But as we've seen with Iran, right, and their proxies, this kind of tacit knowledge transfer to a range of terrorists and insurgent and militia groups can be quite effective. It extends the battlefield in many ways and it keeps us, that is the United States busy at places further afield.
Jonathan Cederbaum
Understood. I want to go more deeply into those geopolitical risks with you, but before we do so, I'd like to spend just another few minutes on the Software Understanding for National Security Initiative. As you mentioned, a gathering at the Sandia national labs in 2023, a report from the Office of the National Cyber director in 2024, then a follow on report in 2025 with proposals about addressing the software understanding gap involving interagency collaboration. Are there some highlights from that 2025 report that you think are most important for folks focusing on this issue to be aware of?
Colin Clark
You know, for, for me, I think it's, it's a lot about the potential that's there, but playing almost a convening role.
Brooke Devard
Right.
Colin Clark
Because there's been, you know, because it's been at the center of the, in our agency. So how do we elevate this to, to provide a kind of coherent, coordinated research agenda across the federal government, particularly for a topic that, as Chad mentioned, is technical? And we've seen this, our backgrounds, we spent years at the RAND Corporation doing some work on cyber warfare. And anytime you mention certain terms, cyber, cyber, anything, right, Cybersecurity, cyber warfare, and now software understanding, you're going to get a lot of people that just wholly back off, put their hands up and say, oh, that's too technical for me. I don't understand it. And so, you know, one of the things we're trying to discuss here is elevating that kind of bringing this out into the mainstream and, you know, really diffusing this across the federal government where you have the authorities, the resources, the institutional support needed to elevate this to, I think the priority it should be.
Jonathan Cederbaum
Well, from what you're describing, the kind of interagency coordination and elevation of the issue across the federal government, it sounds to me like the sort of issue, the sort of task that is suited for the work of the Office of National Cyber Directorate, because of course, the function of that office is to engage in just such coordination around the government about essential issues concerning cybersecurity. So is the ONCD carrying forward the initiative you've described, whether based on that 2025 report or otherwise? Do you know if the ONCD has an active effort going on to work on these issues, I think there are
Colin Clark
active efforts within the government. ONCD would be a chief player there. I do think this is one of the rare areas where we have seen bipartisan agreement. I've spent some time recently on Capitol Hill talking to lawmakers about this. And so I am a little bit optimistic that this is something that we can continue to move forward. But in terms of which office does it, with my researcher hat on, I'm less concerned about advocating for a specific office. ONCB seems well positioned, and I think one area that we've talked a lot about is the need for a public private partnership.
Jonathan Cederbaum
Well, let's talk a little bit more about the nature of the problem and the nature of the risks that you identify in your report as arising from the software understanding gap. You talk about six dimensions of national security risks. I would be happy to hear you discuss any of them. But I wanted to focus on two first that struck me as less well appreciated than some of the others. The first I wanted to highlight is what you call inured blindness. What do you mean by that term and how does it come out of this problem of the software understanding gap?
Chad Serena
So I tend to think of this question. When we were developing this report, we were trying to think about how to categorize some of the things that have come out of the growth of the software understanding gap, cyberspace in general, things becoming more technical, especially since the end of the Cold War. And one of the things that stood out to us when we were of looking backwards through this were some really recent examples of blindness and what we would consider then to be inured blindness. It's something we. We've developed blindness because we just don't pay attention to our circumstances anymore. Now, if I were to say to anyone here 40 years ago, would you have noticed if there were two cameras inside your house, one on your computer, three on your neighbor's house, one on the doorbell? You just said, yeah, it would have stood out like a sore thumb. Now you probably walk into your office at any point in time and you don't even notice those things. You wouldn't be aware that there's microphones or that somebody's phone's laying there that could potentially be recording you. It's not something that really occurs to you anymore. And that's the inured part. This is no different than, say, driving down the road and discovering traffic cams anymore. I would say 20 years ago, that would have been something that would have popped out immediately. Now they're probably on every traffic light or intersection that we drive through and we don't even notice it anyway anymore. So that's in Europe side. The application of that or the operational side of that is to think about what happened recently in Iran. We've, we've read reports about how the Israelis had tapped into various cameras throughout Tehran to be able to do pattern of life monitoring of people coming in and out of various buildings to figure out what they were doing, who was there, who they were meeting with. We've seen it with cartels as well, being able to tap into these various systems in order to gather information and be able to track people. Apparently Russia was also doing this in Ukraine as well to track logistics, things coming in and out of different logistics hubs like train stations. And then Hamas apparently also was able to use these different types of systems in order to gather information. Right. What I think is particularly interesting about this is the break with where if you think back to say any of the movies or novels we would have read in the 50s, 60s or 70s, you start to think about how gathering this type of information would have been a really low density Jason Bourne, James Bond type of activity where you'd have to spend all this money to sneak a 30 year trained professional into a country to gather this information. Now it's completely different. You have established the infrastructure, put it in place, put in things that are like microphones, cameras and everything else and that I don't even have to pay for, I just have to access them and make sure you don't catch me accessing them. You've set up the surveillance and intelligence system that I then want to exploit in order to be able to engage in various nefarious activities against you. Whether that's an actual kinetic strike or whether it's gathering information for information operations purposes or, or something else. And that, that's completely different. But the inured part is we don't even know that is going on around us anymore because we're surrounded by so much technology.
Colin Clark
I would add to that, I think when you think about the concept of pre positioning, you look at the scale and the complexity of all the software defined systems that undergird U.S. national security. They can hide intrusions for extended periods. They allow adversaries freedom to act strategically at a place and time of their choosing before defenders even know what's occurred. So if you go back to kind of the solar winds supply chain intrusion perpetrated by the Russians, you know, there you had kind of malicious code injected through into third party software updates distributed to thousands of government agencies and private companies. And it went undetected for nearly a year. So what did that allow the Russians to do? I think we still don't know really the intelligence that they gained from, from that. But certainly that long term covert access to sensitive systems was a boon, one would suspect, for the Kremlin. And those are the breaches that we know about. I think, you know, it gets into the. I don't know. In some ways I'm reminded of the Rumsfeldian unknown unknowns, which I realize is a kind of different rabbit hole. But, you know, and there's been other examples from a range of different adversaries as well, including some that, you know, we would maybe consider less sophisticated cyber actors, but that are getting into different targets and some benign targets. Right. Civilian targets, water plants in random parts of the United States. What's the purpose of that? Is this the kind of equivalent of a weapons test? Is it just get in, hang out, see how long you can be in there before you're undetected and then try to replicate that in a different system? When you think about the vast realm of possibilities, that can get quite dizzying.
Sponsor Narrator
Ground News, in addition to being the sponsor of this episode of the Lawfare podcast and is an app that lets you jump out of your media bubbles and see the blind spots that exist in whatever media ecosystem you operate. Ground news doesn't just show you what the news is. It shows you who's reporting the news, how many news sources are covering it, and how coverage is distributed across the political spectrum. For example, ground news shows that there are 50 different sources reporting that Oman warned allies that SHI ships going through the Straits of Hormuz might have to pay a fee. And the headlines are quite different depending on where you look. From right leaning news sources, you get headlines like ships face voluntary charges under plan for post war Hormuz. From more left leaning outlets, you get headlines like Oman tells allies ships going through Hormuz may have to pay. And further, ground news shows that only 19% of the news organizations covering the story are left leaning. 69% of the news sources covering it are conservative. You're much less likely to have encountered that story if you primarily read left leaning outlets. Ground News helps you jump out of your media bubbles and get closer to the ground truth. It's not a publisher and it's much more than an aggregator. It's a combination of a rating system and a focused look at who is reporting what. Like Lawfare, Ground news is about bringing you high quality information that you can figure out what to do. With. For me, the most valuable feature is simply discovering the stories I probably would have missed because of my own media habits. So check out Ground News and subscribe to the vantage plan for 40% off, which gives you unlimited access to a better way to read the news. Visit groundnews.comlaw that's groundnews.com law one last time. It's really worth checking out groundnews.com law hey folks, Ben Whittes here and I want to talk to you about upwork. When I started lawfare and we were trying to scale it up, we had all kinds of needs for specialized people to do temporary work of one sort or another, building a website, payroll, all kinds of things that we didn't know how to do because we know how to write about national security law. Upwork did not exist at the time, but boy, scaling a business takes the right expertise at the right time and up upwork helps growing teams quickly bring in specialized freelancers so you can move faster and take the business to the next level. This would have been super helpful to me 15 years ago. Upwork is a one stop platform to find, hire and pay expert freelancers across web and software development, data and analytics, marketing, business operations and more. It helps you grow your business by giving you fast access to all kinds of specialized talent across 125 categories so you can fill skill gaps, launch projects faster and scale support up or down without committing to full time headcount. So what can you do with it? You can browse profiles of possible hires, you can review past work, you can can get help scoping the role you want to hire for and so you can move with confidence and you can get started quickly with the Business plus plan. You can access the top 1% of talent on Upwork and with AI powered shortlisting you'll get matched to the right freelancer in less than six hours. There's no endless searching required. It also cuts down on the operational hassle by handling things like contracts and payments all in one place so you can spend more time running the business. This would have been so valuable to me. Thousands of growing businesses are already trusting upwork to hire flexible, high quality freelance talent for everything from one off projects to ongoing support. It's free to sign up and posting a job is easy so visit Upwork.com right now and post your job for free. That is Upwork.com to connect with top talent ready to help your business grow. That's up w o r k.com Upwork.com
Commercial Narrator
Losing weight can feel like a rollercoaster full of ups, downs and being thrown for loops like when someone brings donuts into the office or your kid's dino nuggets start giving you that look again. That's why there's NOOM. They combine GLP1s to quiet the food noise with healthy habits that help you keep it quiet even if you get off the meds. Their program is designed to make weight loss a smooth ride, helping you understand what drives you so you can build better habits to not just lose weight, but keep it off. Noom Lose for keeps. Get started@noom.com not all customers will clinically qualify for medications. Individual results may vary.
Brooke Devard
Hi, this is Brooke Devard from Naked Beauty. I am always looking for ways to elevate our daily rituals, and the Kohler Smart Toilet is proof that design changes everything. It's this stunning sculptural piece that feels like quiet luxury for your bathroom. It totally transforms your daily ritual into something elevated with customizable cleansing and touch screen controls. It's functional art that makes your space feel cleaner and more intentional. A modern home deserves a modern toilet. Experience the difference of Kohler Smart Toilets. Find more@kohler.com this message is brought to you by Cologuard.
Commercial Narrator
If you recorded songs off the radio for a mixtape, it might be time to screen for colon cancer. The Cologuard test is non invasive, requires no special prep or time off, and you start screening right from your home. It's just three simple setup, sample and ship. If you're 45 or older and at average risk, ask your doctor about the Cologuard test, available by prescription only. Learn more or request a prescription@cologuard.com podcast
Jonathan Cederbaum
how do you think this problem of inured blindness in the United States compares to the same issue in other countries? Certainly I see what you're saying about the pervasiveness of software enabled systems. That pervasiveness leading us to forget how we are surrounded by these systems. But certainly the United States is not the only country aware of ever more of these systems are controlling many physical infrastructures around us. How does the US compare to either our allies or our adversaries when it comes to this issue of inured blindness? Are they also suffering from these kinds of issues?
Chad Serena
I think in part it's a matter of scale. So simply put, it's the how much technology you have of different stripes, whether it's surveillance or other types of things. But here we're we're generally talking about surveillance that are insecure or that we don't know how they're going to behave, and then could also be accessed for these purposes. So in that regard, although we haven't done an actual account of these types of devices, I'd have to expect that the United States is probably a leader in this, but certainly Western Europe too. If you think that the United Kingdom certainly has a lot of different surveillance set up throughout London and other. Other cities within England, certainly these are things that could then be tapped into. So any of the more sophisticated, any of the more sophisticated countries that use these things for other purposes, whether it's traffic control or even detecting and evaluating criminal behavior, or watching people getting on the subways, where there are more of those, then it would seem to make sense that there would be more opportunity for these things to be exploited. And then if you were to go to countries where things were more sparse or people aren't that densely populated, or you don't have the equipment around, it would seem that there'd be less of a risk to that.
Jonathan Cederbaum
We've been talking about one dimension of the risks you identify in your blindness. I wanted to switch and focus a little bit on one of the other ones next. That is what you call the tactical becomes the strategic. What do you mean by that?
Colin Clark
That's right.
Chad Serena
So again, thinking about how the scale and scope of these things have changed over time, what we mean by a tactical becoming a strategic is that if you think of some of the things that have been taken over or manipulated in order to generate either actual or potential effects, the way that we have to think about these now would be different Again, and I hate to keep referring back to Cold War period or then, but it's a good reference point point because a lot of this stuff has changed since the end of the Cold War and a lot of these problems have emerged since the end of the Cold War and the increased use of software and software enabled devices and software defined systems. But if you think about something like an industrial control system, which we reference in the report and talking about that, if one of these were to be taken offline, say either deliberately or accidentally in a local environment, like the Iranians tried to do with the system in Aliquippa, Pennsylvania, if that were to occur, it's. It's a smaller scale problem, it's a tactical problem. However, when you have all sorts of industrial control systems scattered throughout the country that are then controlled by software or software defined. Now, if those things could be penetrated at scale, you could have that same type of disruption occur, except you could have it occur at Thousands of different water treatment facilities. Now what would have been a tactical problem at one point that we never would have even considered really in a national security sense unless it were to happen at a military installation or somewhere else. Now that simple tactical problem becomes a strategic issue if these things were to be manipulated at scale or simultaneously. And that applies too for other places where, whether it's transportation hubs, if you were to look at airports, you could take something that would be a very simple problem like interfering with the computer systems or communication systems at airports and then all of a sudden not going to be able to have airplanes taking off from a bunch of different places. That problem then compounds. If people can't move, if people aren't able to move, if logistics aren't able to move, you could see where the problems just cascade onwards.
Colin Clark
Yeah, I would add to that. I think, you know, it's kind of death by a thousand paper cuts.
Chad Serena
Right.
Colin Clark
You have these low level attacks that, you know, when taken in aggregate or cumulatively, they produce strategic consequences. So if you think about what the Chinese did with Volt Typhoon pre positioning itself within various US utilities transportation hubs, but instead of just immediate disruption, these kind of penetrations are more likely to, you know, precursors to a future pre positioned cyber attack. And obviously when, when we talk about this, it's hard not to think of a Taiwan scenario, some kind of a future Taiwan scenario, but you know, play that out across a range of, of different adversaries and not even necessarily US adversaries, but as these capabilities, you know, are kind of enhanced in other theaters of conflict.
Commercial Narrator
Right.
Colin Clark
And other interstate rivalries, you know, whether it's India, Pakistan or Israel, Iran or Turkey. I mean this is really, I think, something we're going to be seeing a lot more in the foreseeable future and probably not in the distant future.
Chad Serena
It's important to point out too, Jonathan, that we tend to think of this, Colin and I both were certainly guilty of it because of our perspectives on the subject. We tend to think of this as a security issue, that this is something that's going to happen during an attack or an adversary is going to do this. This can also happen accidentally and sometimes it's difficult to determine whether it was an accident or whether it was an attack that caused it in the first place. So if you were to look at something like the Iranian hacks into gas stations and the digital control devices on those, normally if you're a person working at a gas station, you wouldn't think, well, I'm sitting here at the Head of an international attack on system that controls the pumps at my local gas station. You might be thinking something else, but at the same time, it could also be an accident. Either way, if the attack or the disruption at, say, Aliquippa or some other water treatment facility was Iranian or it was accidental, it can still lead to cascading effects. So some of this is about the software. If it doesn't perform correctly, you still could have these cascading interdependencies of different systems failing or being unable to support each other. Or you could have this done because of an attack where the software is manipulated and still have the same result. Understood.
Jonathan Cederbaum
We've talked a little bit about how the government is beginning to address this very consequential problem. One of the elements of response that you mentioned in your report is a provision in last year's National Defense Authorization act, the big annual statute that provides guidance to the Department of Defense. And you mentioned that there's a provision in last year's NDAA that directs the Department to develop, quote, a comprehensive strategy for transitioning DARPA's formal methods, research investments into production environments across the Department. Can you translate that a little bit for folks who may not be familiar with what form formal methods, research investments mean? What is that directive telling DoD to do so?
Colin Clark
I think in some ways, because national security functions and systems are so deeply software defined and the risks that are posed by, as we kind of talked about in the intro, the software understanding gap continue to grow. This is about actually putting our money where our mouth is, so evaluating the potential and actual effects of the gaps. But, okay, we're not just observing these kind of, you know, throwing our hands up and saying, oh, wow, I wish we could do something about this. This is kind of trying to mobilize the cavalry, if you will, developing the policies, you know, software development requirements and the capabilities and practices, for example, formal methods, but also the procedures, data sharing agreements that can help at least mitigate the effects of the gap.
Brooke Devard
Right.
Colin Clark
We're not saying that formal F is the be all end all, but it certainly puts us in a better position to close this gap. You know, and one of the things we've talked about not only in the paper, but again, Chad and I have been colleagues going back for a very long time Now, I guess 20 years almost. And we have these kind of long running, sometimes philosophical, you know, conversations and debates as you kind of close out or mitigate vulnerabilities, new ones will arise as well. But this is trying just to kind of get, again, I guess I'd go back to the putting your money where your mouth is and getting this language introduced into legislation and formally, you know, added as a requirement for the government to move forward.
Jonathan Cederbaum
Well, you mentioned how the nature of vulnerabilities changes and that leads me to think about the issue that hovers over every issue related to digital systems today, and that is the impact of AI. How will the increasing ability of AI systems both to identify and apparently to repair software vulnerabilities affect this problem of the software understanding gap?
Chad Serena
So I think in some ways it's both in the identification of risks. Whether you're doing that from the position of being an attacker or a defender is important. As we understand it is more difficult to defend certain things because you have to be right all the time, as the phrase goes. You have to be correct all the time about what it is that you're trying to defend, whereas the attacker only needs to be right once in order to weaken your defenses. Thinking about AI, this produces quite a challenge in terms of the speed and the depth and the sorts of things that AI would be able to find for both sides, so both on the offensive and defensive side. So it opens up a lot of capabilities in terms of being able to find vulnerabilities and to test software and to really use AI to enable formal methods in order to get towards greater software understanding. But then on the other side too, to use this as a means of exploring vulnerabilities in different systems and thinking about that at a macro level, you start to say, well, I'm going to secure X, Y and Z. You will see and, and we would expect to see an adaptation amongst the different aggressors in this, that as you start to secure targets and make targets harder, you're then going to expose software targets that haven't necessarily been defended in the same way or haven't been evaluated in the same way. And AI will just speed that up and make that sort of exploitation that much more, more difficult. We would also expect to see some sort of competition not just amongst the different larger, like the United States, China, Russia or nation states in terms of using AI to do these things. We would also expect for other organizations and states that are less thought of non state actors and others to be able to use these things in order to amplify their capabilities and to do things that we wouldn't expect them normally to be able to, to do.
Colin Clark
I would add to that, you know, AI has become a force multiplier in so many different ways. But the advantage is naturally you know, they're not always distributed evenly. So for attackers they need to find a single exploitable flaw. Defenders, much more difficult task. They have to identify and remediate all these. So I think AI accelerates both tasks, but the attackers is fundamentally easier, gives them a structural advantage. And I think there's going to be different. You know, this isn't a kind of static race or competition, if you will. It's highly dynamic. There's going to be different developments on both sides. And you know, I think when you think about the potential for AI and I talked before about public private partnerships, you know, one of one of these areas when we're specifically dealing with closing the gap, is going to be our adversaries. Whether those are nation states or non state actors, they're operating under a different set of rules, right. They're not in many ways governed by the same laws, authorities, policies, procedures that governments are, that the US Government is and that tech companies are. So I think there's so much uncertainty in this area, it's really difficult to predict where this is going to go and, and how the gap kind of, you know, diverges or, or kind of ebbs and flows over time, if you will.
Chad Serena
In some ways you can think of this as a boon for organizations that don't have rules or have lessened rules. So if you think of Russia, Russia's, Russia's control over this and how it is that people that act on Russia's behalf or with the Russian government, whether they're non state or semi state actors, this allows them a greater amount of flexibility, like Colm was saying, in order to engage in these types of behaviors. Part of the challenge here is, and why it's so important that this needs to be organized well in the United States through sunset and through interagency cooperation is we don't have whether and when I say we either as the United States or organizations within the United States, we don't have that sort of flexibility to operate outside of the law and do whatever it is that we want to do in order to defend ourselves or to protect ourselves. So it's important that these steps be taken, these first steps, and trying to at least get a coordinating body together to think about how it is that the software understanding gap can be closed because you're, you're going to be perpetually behind the curve. If you're trying to very slowly and piecemeal establish laws across the country with 330 million people. And when you're thinking about these non state actors that have nothing preventing them from doing what it is that they want to do, and in many cases having state support and doing what it is that they're going to do. That is a tough dichotomy when you're thinking about being a defender, when you're on the side that has to follow the law and you're fighting against people that just have no interest whatsoever in following any of the rules that you would like to establish.
Colin Clark
The way it was described to me by one intelligence official was in many ways violent. Non state actors, terrorist insurgents are able to stay one or two steps ahead of us. There's growing concern that AI will make that three or four steps ahead and that it becomes impossible to close that gap over time.
Jonathan Cederbaum
Well, on that troubling note, I think we're going to close for today. Chad and Colin, it's been a pleasure talking with you about this very urgent problem of the Software understanding gap, and I hope your report will get the wide readership that it deserves. Thanks very much.
Colin Clark
Thanks for having us.
Chad Serena
Yes, thank you.
Lawfare Podcast Host/Producer
The Lawfare Podcast is produced by the Lawfare Institute. If you want to support the show and listen ad free, you can become a Lawfare material supporter@lawfairmedia.org support supporters also get access to special events events and other bonus content we don't share anywhere else. If you enjoy the podcast, please rate and review us wherever you listen. It really does help. And be sure to check out our other shows, including Rational Security, Allies, the Aftermath and Escalation, our latest Lawfare Presents podcast series about the war in Ukraine. You can also find all the of our written work@lawfaremedia.org the podcast is edited by Jen Pacha with audio engineering by
Jonathan Cederbaum
Noam Osband of Goat Rodeo.
Lawfare Podcast Host/Producer
Our theme song is from Alibi Music and as always, thank you for listening.
Commercial Narrator
Think of a toilet as just an everyday object. Your entire perspective shifts the moment you experience a Kohler Smart toilet. Design changes everything, transforming a basic routine into something extraordinary. With standout aesthetics and intuitive controls. These are functional works of art, stunning design that never sacrifices performance. Enjoy customizable features for elevated comfort and convenience. It's more than a fixture, it's a cleaner routine and a more refined space. Experience the difference of Kohler Smart Toilets. Find more at kohler. Com.
Episode Title: How Our Growing Software Dependence Threatens National Security
Host: Jonathan Cederbaum (Lawfare’s book review editor)
Guests: Colin Clark & Chad Serena (Senior Researchers, Soufan Center)
Date: July 30, 2026
This episode explores the critical findings of Colin Clark and Chad Serena’s new report on the "software understanding gap" and the increasing national security risks created by America’s growing reliance on complex, pervasive software systems. The discussion covers how the lack of comprehension around how software operates, especially in key infrastructure and national defense contexts, is opening the door to both accidental failures and deliberate attacks. The episode dives into policy responses, challenges posed by AI, and the need for broad-based government and public-private action.
A. Inured Blindness
B. The Tactical Becomes Strategic
On the Nature of Inured Blindness:
On Cumulative, Hidden Threats:
On AI and the Escalating Attack–Defense Imbalance:
On the Policy Catch-Up Problem:
The episode shines a light on the massive, often invisible risks lurking in the U.S.'s rapidly growing reliance on networked software systems—risks not just of isolated technical failure, but of strategic, society-wide consequences. The "software understanding gap" is not just a technical issue, but a central national security challenge, requiring coordinated, proactive effort across government, industry, and civil society—especially as advances in AI continue to tilt the playing field. The conversation closes on a warning: without greater software transparency and rapid adaptation, defenders may soon be left far behind evolving threats.