U.S. National Security Strategy – Tony Scott, Intrusion
Intrusion CEO Tony Scott and former CIO for the U.S. federal government weighs in on how the U.S. National Security Strategy outlined by the Biden administration will improve the overall state of cybersecurity.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Tony Scott. Who's the CEO for intrusion? And as it happens at one time CIO for the federal government and we're talking about the new US cybersecurity strategy that's been rolled out Tony.
Welcome the show. Thanks good to be here. There's a lot to unpacking this document.
But what's your general impression from? The get-go is to what's in this and how actionable it is it and you know what he what really leaps out of you here. I think there's a couple of things that are super important about this one is and probably the most important is trading the right kind of conversation across.
The Tech Community as well as the government and other stakeholders in what I think is one of the biggest battles Of our time which is cybersecurity. And it's all about changing both the economics but also the strategies and tactics that we use to fight this thing. That's become just such a plague on.
um people individually as well as you know businesses and institutions all around the world and I'd say, you know, pretty much what we have been doing is not nearly effective enough in terms of addressing this so I'm hoping the new policy starts at different conversation and leads to a completely different outcome than what we're getting today. On the one hand, it seems like there's going to be incentives to do the right cybersecurity thing and a few sticks along the way there's some conversation in that strategy there about more accountability for how data is handled and liability for faulty software are these things actually things that we can implement or is that going to be more wishful thinking because it seems to me you're gonna have to get some folks down the other end of Pennsylvania Avenue involved. Yeah, I think they can be.
what I like in it to my goal is I'm old enough to remember that quality crisis that we had in manufacturing in the 1990s if you remember that Japan and everybody was just eating our lunch in terms of the quality of products that we produced Six Sigma was not in our language and you know a lot of the things that we were Manufacturing in this country were just garbage basically compared to you know, our German competitors of the Japanese competitors and so on. And we got religion around that we launched the Baldridge program the baldrigord President Reagan gave out. Awards every year to organizations that had improved their quality.
and in a pretty short period of time this nation improved its quality and Manufacturing pretty Democratic dramatically to the point where today You don't even think about you know, the differences in those. you know kinds of standards and and quality manufacturing is just table Stakes for anybody who's in that business today. We need that same sort of focus when it comes to Quality and software and Telecom and in compute and all of that.
We need to be a lot more focused than we have that and we just can't be tolerant of accepting status quo in my view. um, this is cybersecurities hugely costly to every man woman and child and every business in the country and it should be intolerable in the long run just like in the you know late part of the last century we said we got a fixed quality or doomed as a An economy we're doomed as an economy if we don't. Fix this problem that way different way than we have.
That well, since Ron Automotive metaphors are we essentially unsafe at any speed here? Because we're building software faster than we secure it and we need to kind of rethink the whole process of devops and devsecops and that's a big part of this conversation. I think it starts with a set of first principles and fundamentals, you know, we all love the internet.
and you know, I've been in Tech a long time. So of you way back when these things weren't connected together, right you wanted to move information from one computer to the other you had to Put it on a floppy disk or a hard disk or you know punch cards or whatever the hell you had but a tape and you move data that way and then networking came along and then the internet came along. And for decades now, we've been focused on creating the maximum amount of interoperability possible.
And so it's super easy today to connect any computer or any system or any network any other network because the standards are there. The protocols are there and you just don't see failures in that. Very often anymore.
It just works because like plugging something into the wall. It just it works. That's great.
What we didn't do is we didn't take the next step and say all right, I can connect but should I is this thing? I'm connecting to shape. Has it been hanging around with people or devices that it shouldn't be?
You know, is it been compromised in some ways it healthy? Those are all the next set of questions that we've got to find. Technical Solutions for Added on top of interoperability.
And the only group of folks that are going to be able to do that are the technology companies themselves the software companies. Playing along with government help figure out what the right rules are. and make that a part of the fabric of You know the whole infrastructure.
so it's not just application software, which I think is where a lot of Focus has been you know, because of privacy concern and so on. This core cybersecurity just needs to be built into the underlying fabric of everything that we do. And that's where I think the dialogues been missing for many years.
There's also language that suggests the federal government will be more aggressive in chasing down cyber criminals and disrupting networks. Is that something they can really do give in the current fact that everybody seems to be hiding out in a country where we have no extradition treaties. So what's feasible and what's not feasible?
Well, I think there you're getting into both some public policy things and also some technical capabilities. I think we've got to be clear about what we're going to tolerate is a country and what we're not in terms of Behavior coming from any place whether it's within the United States or outside the United States. you know if you fly a plane into the World Trade Center It's very clear.
That's an act of war and we know what we're going to do. But if you want to Cyber attack that has You know devastating impact. All of the World Trade Center, it's not clear what we would do.
And we've been reluctant historically to identify. Even when we know who did it and those kinds of things that has to change we've got to be clear about attribution and we've got to be clear about what the consequences are. If somebody does act like this.
And what the consequences are and that means in some cases that we're going to use offensive capabilities that we have. To go after those actors wherever they are. And I think to a policy perspective.
We haven't been that clear about it. We're kind of inching in that direction, but we're not clear about it. And I think we got to be a lot more definitive.
So there's a clear Line in the Sand around. you know criminal activity versus You know state sponsored, you know kinds of activities. That's number one.
Most of the strategy document seems to be focused on federal agencies. Do you think that corporations are going to follow suit or for that matter? Are they already further down the path towards tightening their supply chains in the government is and this is a little bit of ketchup.
Yeah. I think it's a mixed bag. You know when I was Federal CIO, we saw federal agencies.
Some of them were really really good. And some of them were not so good to put it my healthy. And so just like the rest of the country.
I think there's you know places that do a pretty good job and then There's some that just don't and the reality is we're all hopelessly interconnected in some fashion these days. There isn't anything that isn't somehow connected to everything else and so we've got a sort of raise the water level. for everybody if we're ever going to get better at Cybersecurity I used to joke when I was in the federal government that the Marine Mammal Commission.
You know had the same cybersecurity risk as Department of Defense, you know, but the Marine Mammal commission didn't have the resources. that the Department of Defense did but the requirement was exactly the same in terms of their cybersecurity. Requirements and that just didn't seem to make sense.
And and so the argument there was what DOD or somebody who's got the resources provide the defenses for the Marine Mammal commission, you know don't send them off on their own and say hey by the way do a better job, but we're not going to give you the resources or the technical know how to do that. It's a silly ass, you know. Like asking me to run a hundred mile marathon, it ain't gonna happen.
Yeah. You think we have this skills and resources to do the job and we are shorthanded on cybersecurity folks. We have been trying to shift stuff left and right to varying degrees as this become much more of a team sport and what might be termed the national crisis.
I think it is a team sport, but I think there's also things that we can do to improve the availability of human resources that we need. First one is you know, drop the requirements that everybody has to have a college degree. You know to get one of these jobs, there's a pretty wide spectrum of.
of talent out there that I would enlist in the fight against, you know, cyber criminals and so on that that you know college degree isn't going to help you with. and so we could widen the pool of people that we draw from second is I would have a much stronger program of people leaving the military to get the training for these jobs that are in high demand and their high paying and and guys and gals leaving the military have in a lot of cases great incentives to You know move that direction when they get out of the military and it's an untapped resource that we just haven't. Fully leverage and then the third one is getting young people engaged at a much earlier age than we do today.
There's kind of a stigma. You know in grade school even that if you're a techie, you're kind of a nerd you're out of it. You know, it's you know, the least popular kid on the Block and I think there's a lot of things that we can do to sort of begin to shift that I think the Girl Scouts for example have a unbelievably good program in terms of Technology oriented merit badges or whatever.
They call them when your girl scout that is a huge step in the right direction has been very effective in getting young girls in particular interested in some of these more technical, you know, Science and Technology oriented roles, but we could do a lot more and we are and that space. Are we asking too much of the IT people and developers and maybe we should just come to the conclusion that security is better consumed as a service maybe than it is if we're relying on everybody to go Implement that individually maybe we should just start leveraging up the cloud and the services and it's time for a different mindset. I think that there is an answer there to some degree at least.
You know. it's kind of the difference between in the old days trying to stand up your own telephone service versus leveraging AT&T or Sprint or you know, whoever you're telephone service provider is if we had more broad-based. consumable cybersecurity services both for individuals and for institutions.
I think that would go a long way to getting the scale and the economics shifted in the right direction that doesn't exist today by and large. All right, folks. Will you hear it's a whole new fight and a whole new year and hopefully there's a lot to look forward to hey, Tony.
Thanks for being on the show. My pleasure. Good to see you.
All right back to you guys in the studio.