Cyber Mass Mobilization: The Fringe and the Flag
Cyber mass mobilization is the missing piece in the American cyber playbook, and this unrehearsed Black Hat panel makes the case in plain language. Fred Wilmot, CEO of Detecteam, Chris Cleary, President of the Military Cyber Professionals Association, and Pat Arvidson, CTO of Risk Aperture, join Alan Shimel to unpack The Fringe and the Flag essays.
About the panel
Fred, Chris and Pat bring decades of NSA, Navy, ManTech, JumpCloud, Devo and Splunk experience together in one conversation. Consequently, they can compare United States and adversary cyber models with rare hands on authority.
Inside cyber mass mobilization
Adversaries like North Korea and China field hacker groups with nation state resources but almost zero regulatory friction. As a result, the United States struggles to generate matching mass through CYBERCOM alone. Meanwhile, industry now houses many of the operators who once wore the uniform, and the trust equation between government and industry has flipped.
In addition, the panel argues cyber mass mobilization needs a merchant marine style model where government enables, authorizes and endorses private cyber capability without micromanaging every move. Therefore, ideas like a formal cyber reserve, command by negation and Google style disruption units belong squarely on the table.
Why this matters now
Meanwhile, AI SOC economics, token maxing and rising breach costs are already reshaping the market for detection and response. Consequently, boards will trim information technology and security budgets unless the community explains why cyber protects business continuity, not just risk on a spreadsheet.
Explore more cybersecurity coverage and the latest Techstrong TV interviews. Furthermore, the panel previews upcoming Fringe and Flag essay drops and where readers can follow the conversation after Black Hat wraps in Las Vegas.
For more information please visit detecteam.com
Transcript
Hey, everyone. Welcome back here to our Black Hat coverage. This is why you come to Techstrong for, because what you're going to see right here, unrehearsed.
We're giving it a shot. I don't even know myself how it's going to come out, but I think you're going to like it. We've got my friend, Fred Wilmot.
If you watch Techstrong, gang, you know Fred from Seattle here with me. We've also got Chris Vierly? Cleary.
Cleary. And Pat O'vensick. Correct.
Man, 10 years ago, I would have forgotten that these days, but I'm here. More importantly, though, I'm going to ask each of these gentlemen to introduce themselves. I think this is going to be really special, our panel, if you want to pay attention.
Chris, why don't you kick us off? Thanks for having me. So, Chris Cleary.
I'm currently the president of the Military Cyber Professionals Association. But prior to that, I was a senior executive with the Department of the Navy, the first principal cyber advisor for the department, and then retired naval officer, information warfare type, drove ships for a bit of time, bunch of time in industry. Some startups that failed, some startups that did pretty well, defense contractor.
So kind of a potpourri of a lot of... Have seen this community from a lot of different angles, which has shaped this opinion over many years. To be the outsider looking in, never overly technical, not a technical expert.
Policy, particularly the time in the Pentagon, watching the services struggle with how we're going to do cyber, watching the tech industry trying to engage with government. So it's just been an interesting collection of experiences that has shaped this idea that I've put together, we've put together over a period of time, that we're going to be talking to you about. Chris, you say that so matter-of-factly.
There are a lot of people out here who'd give their left ear to live, because it sounds like the kind of things you've done. It's been an interesting journey. But the real secret is I fell back into most of those jobs.
I think because as cyber is so new, as they were creating a lot of these jobs, 10 years ago, there was no such thing as a principal cyber advisor. Yeah. 10 years from now, there might still not even be a clear path to get to it.
It's just sort of a- There's not a human who does it yet. It may not... Well, that's another good point, right?
Yeah. Somebody build a machine. That's a really good point.
Principal advisor. Pat, how about you? I'm going to jump on that bandwagon and talk about some of the back going into some of the things I've done.
Currently now, I'm the chief technology officer for a company called Risk Capture. We just recently out of stealth. I'm also an advisor for another startup company that's doing some pretty interesting things that they're in stealth.
But prior to that, I did 36 years at the National Security Agency, and that's kind of a misnomer. So 15 years of that, the very beginning, I was actually a Chinese linguist in the United States Air Force. Really?
So over the career of NSA Air Force type of stuff, we'll work backwards. I was the technical director for weapons of space cybersecurity. I was the technical director for the national manager, Marianne Bailey, Rob Joyce.
You've seen him on TV around here today. Prior to that, I actually led a couple of operations. One of them actually made "60 Minutes".
Deb Plunkett did a thing. Back when 60 Minutes was sick. Right, yeah, back when that...
So if you ever go back and look at "60 Minutes" as a profile of NSA, and Deb Plunkett, who was the director of IAD at the time, gets up and talks about a foreign nation state coming after BIOS activity. I was the person that led that activity to counter that. And the interesting thing, the things that came out of that, just FYI, was Eclypsium, Wiz.
HBSS was a time, and I went where that went. But we built Sharkseer, which was the largest zero-day net defense based upon that. Prior to that, interesting enough, I was the senior cybersec liaison to NATO.
Hmm. So I like to tell people I'm illiterate in 26 other languages. Yes.
Right? And the whole thing where I started my career, you talk about backdooring. Yeah.
I was a Chinese linguist. I'd come back from Korea, and NSA was just starting up this idea of looking at threat intelligence type of thing. And so I didn't like what I was doing, so I just started surfing the internet, and I'm the guy that found Titan Rain.
Really? Yeah, and the Hacker Union of China. Really?
So I ended up doing a tour on that. So I've done all of that kind of stuff. I did my tour as the executive director for the principal cyber advisor in that space, too.
So same thing with Chris. There are a lot of things, and we'll talk about the sins of my career, CMMC being one of them, that went on that when I got out of government and looked back at it and went, "Yeah, that's not going to work. " Yeah.
So understanding that, and we'll talk about that some more, and we'll go further. No, that's good. This isn't a bench session.
No. When you walk that mile in those shoes, you kind of know what the track is. Yeah.
And that's really the point of it, and I appreciate it. And I just want to throw one other thing. Our audience, a good amount of cyber people, but we also have a lot of developers, software people, platform engineers, digital transformation people.
And for those not in the cyber game, know that there's always been a very tight... Well, until recently. There's always been a very tight relationship between NSA, between the federal powers that be in the cyber industry.
Yeah. Before we called it cyber, we called it the security industry. Right.
A good friend, Tony Sanger, you probably- I love Tony. Tony. Yeah.
I love him, too. Yeah. I probably know Tony 20 years.
Yeah, 20 years. Well, that op I was talking about, real quick, one of the other things that fell out of that op was we couldn't share information. So that's what created the Enduring Security Framework.
Oh. " And Tony was probably the best ambassador they ever had. Yes.
Yeah. I'll tell you. What a great guy.
But so Fred, what do you have to say for yourself? Well, to keep pace with these guys who have distinguished careers, I think I fell backwards into cyber anyway, as you know. But things that we could put on the first mobile virus in the US on the first mobile network.
And I found that, wrote detections and signatures for the first hacking occurrences on operational technology, and for the DOE and Symantec at the time. And we did a whole thing for American Association of Railroads and how do we compromise positive train control. And was co-founder of the Red Team here at DEF CON- Yeah ...
and a number of other things throughout. Multi-time CISO. Multi-time CISO.
Built a lot of SaaS products. And I spent a lot of time in the spaces where people are either defending or attacking from organizations and governments around the world. So I've been in this problem space, sat in this problem space in a lot of ways for the entirety of my career, really.
And I just sit here feeling wholly inadequate. But it's okay. I'm going to let you guys carry this.
" Excuse me. Chris, if you don't mind, why don't you kind of- Yeah ... talk about this foundation?
So I don't know. I say that the better part of a year ago, you reflect on the things that you've done, and you look where the community's going. And this also was my beginning of a very unhealthy relationship with ChatGPTs and large language models, which, in full disclosure, allowed you to flush ideas out.
Get an idea out, get it onto paper. Like nothing we've ever- Like, not right. Yeah.
So how do I take this idea? How do I take these things? Can you help me turn it into 1,000 words so I can get this message out?
And what I found was I created all these crazy essays. And then what I saw was that there was actually a journey that I didn't realize I was going on. " Now, again, it's not a technical framework.
It's more of trying to tell a story to get people to understand through using pop culture references, because that's the way we think right now. It's all analogies based. How can I take a movie reference or something and put a cyber idea in your head?
Because most people are not technical. Most people aren't going to get it. And what I found is we started framing a bunch of these together, and this led into many conversations between the three of us with just this idea.
" Why? I don't know. But if you read them, it would sort of make sense.
And what these essays do is they take you on a story, and it begins with using an "Ender's Game" reference. When you looked at "Ender's Game" as an analogy, Ender was the hero of the story, but it was really the Colonel Graff character that believed in Ender, that put Ender in an environment for him to be successful. So it's not about Ender, it's about who's that person that's willing to take some risk for people that understand the environment better than everybody else does, and set them up to be successful.
Right. Empower it. Which leads to the next essay which talks about, well, what's this really demographic of people you're looking for?
They don't look like the traditional, in this instance, military character. It's this community. It's the DEF CON community.
And they're not something to be feared. It's something to be understood and harnessed in a way that you could do it a little bit better. And then it leads into, okay, well now that I've got a person pulling the idea, and I've got the community that I'm going to leverage, well, what's the framework to which we would argue that they operate in?
Which leads to really where the papers start getting somewhat, not contentious, but going down a path. And again, to use another movie reference, I used the "John Wick" movies just to make the point. And for everybody who's seen it, everybody at this conference has seen the "John Wick" movies.
Which basically- You've also read the "Ender" trilogy. Yeah. Right?
In the end, these are chosen, not at random. It's trying to... The people already.
But what did you see in the "John Wick" movies? Not that you had the John Wick, his car, and his dog, and he goes on a rampage. But what it really builds out is this community.
You understand the table. You understand the world to which they operate and the rules which they follow, which got the wheels turning. And so, well, wait a minute, if we have a lot of formal institutions created.
We have CYBERCOM, we have FBI, we have CISO. We have all these things that's set up. But as technology continues to advance and as this workforce gets better, you have this whole other workforce that we haven't figured out how to harness.
And this idea is, again, Tuna Moore at Vanderbilt University wrote a paper, something along these lines, which is really how are you going to get this? You've seen a lot of legislation come out recently, 1604 and the NDAA, allowing contracts to access as a service. You've seen privateering legislation.
So you have all these kind of ideas, which means now government is scratching their head on how to do this. Can I interrupt you for a second? Yeah.
So let me step back one piece. Yeah. Let's talk about the environment.
The environment we're talking about is I don't think a lot of people understand the environment. Yeah. Outside of the United States, other nations are actively using hacker groups to promote their national positions Right?
So whether it's Russia using illicit groups, whether it's North Korea using hacker groups to do fraud and stuff like that to fund their government, they all do different things, and they all do it their own way. And the second thing is that a basic underlying thing that everybody needs to understand is that all nations will act in their own best interests. They will not act in the best interest of the United States.
They'll act in their own best interests of their country. Okay, great. So within that scope, right, what do you really have?
You have hacking groups that have the resources of a nation state, but are not restricted by the rules and regulations of the normative behavior within society. Right? So if North Korea says, "You know what?
It'd be nice if everybody had some food. I need a couple million dollars. " They don't care that they are hacking some lady's account in Sun City- Yeah ...
Nevada, right? They don't care, right? But I think that story's the- Right ...
a sizable percentage of the GDP of the People's Republic- Yeah. Right ... of North Korea is, or whatever they call it- Right ...
the Democratic Republic, is illicit hacking. So the problem that we're getting to, and we're trying to discuss it, and I want to make sure that we understand that we're trying to get to discuss it, not solve it. That's another soapbox I'll get on in a minute, right?
The point is, how do you, as a United States nation, meet the mass that another nation can generate in cyber in the way that they can generate it, which is basically unconstrained, right? " We're stop talking about that. We're talking about, how do we generate like mass?
Because military theory tells us mass on mass is the only way you can win, right? So two parts to that, go Pat. First of all, what you're really discussing is you got a whole bunch of people playing by one set of rules and another bunch of people playing by a different set of rules.
People would say those are two different games, right? Because if you're playing a game, you're playing by the set of rules. Number two, I think, forgive me for jumping in here, but- No, it's good No, because that's a conversation ...
this is how we want it, right? Yeah. This is, we want a conversation.
I think what we're seeing now is because of AI, but we're also seeing this, we're seeing this in the Ukraine, we're seeing it in Iran, we're seeing it in the Israeli stuff, asymmetric- Yes ... warfare. Exactly.
But not only asymmetric warfare, asymmetric cyber. Yes. Yeah.
Right? And what is that going to mean? Because that- Yeah ...
it's very hard to say how much money is the Chinese Communist Party funneling into packing groups. So you could guess. I'm sure you probably have a better picture than I would.
But what are we putting in to defend it or our own stuff? What are the Israelis doing? Unit 8100 or whatever that, 3200.
Yeah, 8300. Right? But now we've turned into an asymmetric game.
Is that as important anymore, right? How does that change the rules of these games we're playing? And games, these are deadly serious games.
These are- Yes ... for life games. Yes.
So go ahead. Well, so- No, you speak ... so back, so kicking it back to you.
So, again, so it tells a story, it tells a framework, it suggests ways we could go about doing this. None of them profess to be, again, to Pat's point, to be right. Right.
It's really to start a conversation. But one of the interesting things that have changed in the last, let's say, 20 years, and I use aviation to make this point. If I go to Lockheed Martin tomorrow, I'm probably going to run across somebody who flew a P-51 in combat, or he's probably still working there, right?
As well as an F-35 pilot, and every flavor of military aviator is probably working there as an engineer or a consultant or whatever because we've created an environment where that ecosystem churns out. We create pilots in the military. They go fly planes.
They go work in industry. Industry makes new planes, and it churns over. It's only been- There's also tribal knowledge there.
Well, and this- That's the reason ... and what should the new plane of the future look like? Because I used to fly these in combat.
It's not where the switches are. It's the community. You need engineers, you need operators, you need employment, you know all that.
Well, only really in the last, let's say, 10 or 15 years-ish, has the cyber community started to have people that came from it that are now working in it. Right? 20 years ago, you couldn't go to the...
I'll say the technical acumen in the community has always been similar. And again, this is not an AI debate. It's obviously the curves has increased.
But the point is, there weren't a lot of people from government and industry who had done those things. It's different now. So one of the things that I think has changed most importantly, is the trust equation.
So 20 years ago, if I went to DEF CON, I wouldn't trust those guys as far as I could throw them because they wouldn't operate in a way that I'd be comfortable with. I can now sort of go into industry and talk to Pat or Chris or so-and-so, or General So-and-So, or sergeant that have all worked there that now work in industry that said, "Look, I'm as capable, if in some instances more capable than the government is. " There's lots of models that we've seen this before.
You could argue this was sort of in the Blackwater world, right? There was all known operators. They're former, that's why they were trusted to do what they did.
Not to say that's the complete model, but these things are possible because the community has matured to a point where there's as many people inside doing the job as there are outside doing a job, and they know each other. And you know my model, right? Yeah.
The model that I like to refer to is the merchant marines. Okay? Right?
Sure. You've got maritime folks that know how to sail a boat, and they can, or sail a ship, I should, sorry. No.
Sorry, Navy guy, right? That's all right. Fair enough.
Right? Air Force guy, Navy guy. Right?
So So we have areas that this has worked before, right? And I'm saying they don't paste one for one. I'm not going to say that, right?
" That's right. " Right? And as the- Stop it.
That's juvenile. And the irony with the things that I get, the irony of these conversations are, is let's even say we went down the hack-back model. Well, that's only going to incentivize our adversaries to do more to us.
More than they're doing now. Right? More than they're doing now.
And the other one would be, well, maybe they did enough to us that now this is our reaction to that. Like, "You've been doing it to us for so long, well, now we're going to start doing it to you. " So are we going to play eye for an eye?
Well, but see, it's not like you engage me, I engage you. It kind of goes in, I'll say it started with defend forward, right? That kind of construct.
" Like the Cold War of cyber. You're out there, I'm out there, we're going to see each other. So let me be naive.
Yes. Haven't we been doing that for a little bit already? So, I would argue yes.
Two interesting things have happened in the last, let's say, year alone. One is CYBERCOM has been a little more public acknowledging they've participated in certain things, which I think is important. I think there's a way you can say that without giving anything away.
I make the joke about, I use the Columbia-class submarine all the time to make this point. " I have no idea how deep it goes, how quiet it is, the range it'll actually, of its weapons, its sonar sensitivity. I don't know any of those things.
No. But I do know the Columbia class is coming to replace the Ohio class. I can tell you almost how much per hull we're going to pay for it.
I can tell you where they're going to be deployed. I can tell you when they're going to be built, and I can explain to you exactly why we're spending all this money, because it fits into this national mission. This is why we need the Columbia and the Sentinel missile and the B2.
" Well, we have to talk a little more publicly about what these communities do, what they mean to the nation, in a way without giving any secrets away. " Right. But it's not giving anything away that said CYBERCOM took an action that enabled Operation Midnight Hammer.
And that's a yes and. Yeah. There is a difference between plugging USCYBERCOM into a military operation to achieve an objective and dealing with eight, nine, 12, 15, 18 water systems falling down in Minnesota and Wisconsin, right?
Right. And the point that I'm trying to make is, you're correct. They are doing that.
But we can't meet the speed and scale of our adversaries. Right? It's not true.
If you can't meet the speed and scale, then you have a problem. You have a problem that goes... There is a reason the United States keeps the selective service and the draft on the books.
Just in case, right? Yeah. It's a just in case.
All I'm advocating for is, do we need something like that to mobilize cyber in case of something that's actually really, really big? So, gentlemen, I don't disagree with you for a second. We've just got a funny way of going about it right now, because we are burning bridges, I think, between government and the cyber community.
Well, this is where, again, you're getting into the certain... There's a million ways to solve this problem in theory. You could have a very formal cyber reserve force, or be very military-like.
There's the Coast Guard. There's all these different models that could be referenced. But then there's another one that says, there's a term in the Navy called command by negation.
And basically what it says is, "I give you some fundamental direction, and unless you hear from me, just assume you're doing the right thing. " Right. And I think where we're going to get to, because industry controls so much of the environment, is where the government enables, authorizes, endorses, but doesn't necessarily fully move-by-move direct how these things are sort of happening.
And we've seen it sort of with the Google disruption unit, right? Google? Yes.
They're like, "This is my environment. I see an adversary in it. " They're not told to do that.
And some of those things might have actually national-level impact in a good way, right? Like, "Hey, I see trash on the road, I'm going to pick it up. " Mm-hmm.
" Hopefully, right? So I think what we're going to see is the difference between positive command and control and sort of implied actions. Again, back to what Pat was saying.
" And then they just go figure it out. Yeah. So let me move this from pure cyber to AIs.
Right? We have a very different model in the US for AI than, let's say, our friends in China do, right? Mm-hmm.
We're building Cadillacs and they're building Priuses, it seems. However, putting the egos and the people who are running these companies aside for a second, if we can, do we trust and empower them to do the right thing to keep America's best interests at heart in these, the next Mythos, the next iterations, the next models, the next things come down? Are you talking about the frontier model makers?
You're talking about the Anthropics, the ChatGPTs, the OpenAIs, right? Right. All of them.
Correct, yeah. I think one of the things that we have to come to realization at in this discussion piece is For lack of a better term, there is a profit motivation within these organizations, right? And everybody should make a buck.
Don't get me wrong, right? Everybody wants- Private industry there, that's what makes the world go round, right? The problem that you get into in this kind of space is when you outprice the solution.
So I'll just be honest with you. We're seeing it now, right? Just beginning of the AI movement, right?
Walk down the floor, see how many AI SOCs are floating around, right? Yeah. If you want.
Yeah. That's what I'm saying. There's a lot, right?
Yeah. And then the other half of it is, come buy my product to make sure your AI is operating your AI SOC correctly, right? The reality is, is that you're starting to see from an industry perspective, a non-cyber, but needs cyber, right?
We all need cyber, we all need IT, is the medium-sized companies, right, are looking at this saying, "Okay, I've got two choices. " That is a business decision. It is not a security decision, right?
Tokenization models run by the frontier things. I like that. The discussion now is, it was token maxing.
Now, Uber ran through their entire year's worth of token- Of tokens ... they ran through their entire thing in two months, right? So, the point now is, okay, if those kind of capabilities are outstripping my budget, I am not going to invest in them, and I'm going to take money from cost centers to fix it.
Well, where are my cost centers? IT is a cost center. Cybersecurity is a cost center.
I'm going to start taking money from that to pay for other things. If you're not helping to police the environment, if you're not Google helping to police the environment, if you're not AT&T helping to police the environment, and you don't recognize that it is in your best interest from a business perspective- To police the environment ... to police the environment, you will find that you have less business.
The landscape is- So we're talking about market conditions in there. Yeah. You're seeing it happen in other areas all the time, right?
It is coming. There is a reckoning coming for cyber, and it's around cost, right? So whether it's I'm getting hacked, I'm being exploited, and it's going to cost me this much to recover.
I'm getting hacked. I'm being exploited. It's going to cost this much to defend.
Whatever it is, there is a reckoning coming on the cost model of cyber. And there's a big difference between defending against a breach and continuing to operate, conduct business as usual, right? So when Maersk can't dock a ship, it's $500 million of lost revenue because they can't operate their business.
It's maybe $10 million, I'm generalizing cost on that, but for a breach, and they have cyber insurance, right? But you have to be able to operate the business. Some would argue the proxy for that, the analog was the United States has to be able to operate, right?
Water treatment facilities, municipal facilities have to operate. Pretty robust structure. Structure.
This is not a new discussion. No, not at all. And so some of the asymmetry part of that problem is, doesn't matter which model we choose.
The challenge is what feels like a force majeure in this particular case is really what we're faced with. It is the fundamental basis for the conversation. Look, if you would've asked me three, four years ago, I'd have said, "I don't see a future where we're going to top war," let's call it.
Who knows? Here we are. But I do believe this is the battlefield.
Yeah, absolutely. Now. Yeah.
I think there's a war being waged right now. I think the Chinese, put the hate meter, they want. But the Chinese are insidious with genius in following this whole sway- Yeah ...
model, because it's like embedding a Trojan horse, right? They probably have 30, 35% of the market already. Well, excuse me, but the Silk Road belt and suspenders type of model, right?
So, not even open-weight AI. A perfect example, but I'll give you a better one. Huawei Telecom.
Yeah. Where is Huawei Telecom distributed? China.
South America. Europe. Why?
Why? Because they're subsidized. They give it away for- They gave it away for free.
That's right. Near free. Yeah.
They gave it away for free, right? So you're absolutely right. So first off, if you want to actually go all the way back, it goes back to the '90s.
They did this with their J-7 fighter, right? Which was the predecessor, below an F-15, so that's how far we're going back. They would design, build it, then send it to India, sell it to India, let India crash it.
Learn, try. No, let India crash it. They would take the lessons learned from India crash it, and then refine it, and then they made the J-8 from that, right?
And eventually, they stole the plans and made the F-35, but that's a different issue, right? The point being is this model of build something that is good enough, give it away, right? Let other people break their heads on it, use it to refine it, and make a better one, has been within their culture for years.
Absolutely. We're going to continue the conversation. Perhaps not in person, as you do a lot of stuff virtually, Fred does.
But for people out here, we wet their whistle on that, right? We got them thinking about this. Chris, these posts you're putting up, where can we see them?
Oh, well, that's the thing, right? Well, a lot of this is sort of the brainchild of the three of us, and I'd love to share them with whoever would like to read these things. So you haven't published them.
Yeah, they haven't published yet. I've got a place on you. Oh, I'd be happy to drop it there.
We will talk off camera. Okay. Stay tuned for Techstrong.
You're going to find out how to read these things, how to stay on top of it. Excuse me. And we will continue the conversation, but Chris, Pat, Fred, thank you for coming on here- My hero ...
and at least starting the conversation. We will continue this conversation as soon as next week, hopefully. I'm out of here Thursday.
And, Fred, we'll reach out to you to make that happen. Yeah. Guys, this is an important conversation.
Yeah. It's an important conversation we have to have. So, we're going to end this right here.
Enjoy Black Hat. We've got more coming at you. This is Alan Shimel for Techstrong TV.