Season 2, Episode 7: Richard Horne
Brett Leatherman, assistant director, FBI Cyber Division: Welcome back to “Ahead of the Threat.” I’m Brett Leatherman, assistant director of the FBI’s Cyber Division. Coming up, I sit down with Richard Horne, chief executive of the United Kingdom’s National Cyber Security Centre, or NCSC. We get into what the UK is seeing on nation-state threats, the strain on critical infrastructure, and where AI [artificial intelligence] is taking all of this.
Before that, I want to do something a little different with the news today. Instead of running the recent headlines, I want you to meet the person joining me from London, because her job is a window into how the FBI fights cyberthreats at home through our field offices and how that fight extends across borders. Then we close on one news story, which sets up my conversation with Richard.
My co-host today is Kathryn Sherman. Kathryn is the FBI’s cyber assistant law enforcement attaché in London. What we call a cyber ALAT. You’ve heard us say that before here on the program. She is a career cyber special agent who has spent time in assignments across the bureau in our Dallas Field Office, at FBI Headquarters in Cyber Division, and leading a cyber squad in the Washington Field Office before she deployed to London.
So, Kathryn, welcome to the show.
Kathryn Sherman, cyber assistant law enforcement attaché: Hey, Brett. Thanks for having me. Appreciate it.
Leatherman: You bet. You started as an investigator in the Dallas Field Office, which is where you and I met. What do the days, weeks, and months look like for FBI cyberteams who are working the threat on the front lines from a field office?
Sherman: One thing I love about this job is that every day is different. So, you can wake up one day and you’re out interviewing a victim. The next day, you might be working with your prosecutors to develop a strategy on a case. And then the third day, you might be with a company helping them with a tabletop exercise.
Over the course of a month, you’re working with the intel analysts on your squad, the computer scientists, the data analysts, and your prosecutors to develop a strategy on disrupting a major cyberthreat that you’ve been investigating. So, there’s never a dull moment. I was lucky when I went to Dallas that that squad … had a wonderful history.
And they had really built a good rapport with the community there. So, I really got to get to Dallas and get to work and kind of stand on the shoulders of the folks that came before me. And the work was great.
Brett: Yeah. And you … So, field offices specialize in different things on the national security side. And then all the field offices work cybercrime-type investigations. What does it look like as an investigator to build a case over time meant to impose cost on the bad actors—either through prosecution, disruption or other things—while also taking kind of the intelligence that we’re learning from those cases and applying them to our relationships with the industry to help them protect themselves?
Can kind of walk the listeners through what it looks like to build a case over time working with prosecutors, working with victims, working with international partners. How … do case agents do that?
Sherman: Sure. So, in order to open investigation … it has to be predicated on something. So, that can be predicated on an incident that a victim reports to you; a major intrusion; a major ransomware attack; major exfiltration. It could be a referral from a private-sector partner. Or it could be a referral from one of our intel partners that might lead to … pointing a case towards maybe a national security nexus.
So, with that, you start to gather the facts. One of the first steps is if there is evidence that we need to go get from providers, from companies, then we need to launch preservation letters because data is fleeting, and we need to be able to preserve that. And then we work with our prosecutors, and we explain to them a little bit about what we’re seeing.
And we get their buy-in. We go to them for legal process so we can, get the subpoenas, get the pen register trap and traces, or … the search warrants to start to gather the data that we need to understand the threat, be able to tell the picture. During all that process, you’re likely continuing to get notifications of different victims, or different infrastructure that we need to pursue, and that quickly launches things overseas.
And so, that’s when you’re working with your other government partners in the United States. As well as your foreign partners. Because it really takes kind of all hands on deck to be able to preserve evidence, get evidence around the globe. And of course, the other critical pieces are private-sector partners. They are in the front lines of this data, and they often see the threat before we do.
So, partnering with them and allowing them to kind of tell you a little bit about what they’re seeing points us in the right direction. But also helps us establish those relationships when it’s time to build towards a disruption. And, you know, ultimately at that point, we kind of have to understand what are the goals here.
You know, who’s the best player to pursue infrastructure take down? Who might be in the best position to go after the actual actors? All of that kind of comes to the table as you develop a joint sequenced operation.
Leatherman: Yeah. That’s great. And our goal then is to take folks who have experience in that discipline over time and do it well and start to move them into positions of leadership. So, fast forward a few years later, you ran a cyber national security squad at the Washington Field Office, where the operational tempo is incredibly high, while the threats are not slowing down. As someone who led a team of special agents, intelligence analysts, computer scientists, professional support staff on that threat, how did you start to prioritize the work that the Washington Field Office was doing at the time?
Sherman: Sure. Well, first, it goes without saying that I had an incredible team. I inherited an incredible team, and a team that we would just work together really seamlessly. And I’m super grateful for that. But this was also a time, during Covid. And it was 2020 and we were in the middle of an election cycle. So, first, what we really had to do is I had to really understand my people.
That was also challenging because I was in the middle of Covid and people are in and out. But what motivates your folks and what are their strengths and weaknesses? If you can understand that, you can really understand and set them up for success and what needs to be handled day to day.
So, there were kind of really two paths. I needed folks to focus on the casework that we already had on our plate. We had to move the cases forward.
We have to develop intelligence, because at the end of the day, if we’re missing that threat picture or if we’re not developing that threat picture, that’s just as bad as if we are not providing critical threat briefings in a timely manner.
But then there were just a constant cycle of threat briefings that we had to give around the election time and around everything that was happening specifically in the Washington Field Office area of responsibility.
So, I had a team that really focused on that, and those threat briefings became muscle memory. And what that allowed them to do is it allowed them to be able to articulate the threat in a manner that could be understood. These were technical details that can sometimes be challenging for folks to understand, especially when you’re telling them bad news. But they were able to do that in a way that could be understood.
And then secondly, as they could provide mitigation steps … in a way that was tangible, it was something that they could understand. And that only was able to be done because of their expertise and their reps and the tempo that we that we were working.
But on the personnel side, I also think there are two things that that were really instrumental in me kind of understanding and learning at that time. And one is to recognize burnout in your team. It was an extremely high-tempo time. And not just burnout in your team, but burnout in yourself and sometimes taking time, taking a breath, taking a moment, is important and ensuring your folks do that is important because that’s when mistakes are made, if you aren’t able to recognize that.
And the second is asking for help. It was during Covid. Sometimes people were taken offline unexpectedly if there was an exposure or something. So, we benefited at Washington Field Office from a large cyber branch.
And so, I often had to ask the other supervisors for help. At the end of the day, we all have the same badge. We’re all working towards the same mission. So, asking for help was also key to making sure we balanced the threat.
Leatherman: Yeah, that’s incredibly important. I think, you know, we all deal with artificial crises and real crises and part of a leader’s job is to identify what is the priority. What’s the real crisis here? And for FBI supervisory special agents, you’re kind of that frontline supervisor where you’re having to make the determination about how your resources are deployed.
And, I think industry is now facing the same thing in the cyber discipline. Burnout is real. Crises are real. Whether a ransomware attack takes major systems down and you are running multiple shifts of incident response; you’ve got reporting obligations; you’re trying to determine what is a priority here versus what is an artificial crisis.
As a leader in the FBI, what were you think, the top one or two traits that you had or that you see across leadership here at the FBI that makes … it such an impactful, I think, organization, where we have great frontline leaders making good decisions? What are those traits that you think make those leaders not good, but really good?
Sherman: Sure. Well, I think first and foremost, you have to put your people first. You know, you are the frontline supervisor, and that means you are supervising people with a lot of experience at times and sometimes are just out of the Academy or maybe even just out of college if they’re coming to us at a professional staff level.
So, really care about your people and making sure you’re getting them what they need to be successful. And that’s just not successful at the job. But that’s successful at life, right? Sometimes it requires, you know, helping them understand a little bit about when to take breaks or when this is, you know, what is considered an emergency and when we really need to dig in deeper.
Because you’re managing supervisor, you’re managing special agents, but as well as professional staff. So, I think … I think care about your people is probably the No. 1 thing. And then, I think the other thing specific to our organization is really being able to kind of manage up and down, right, is being able at the frontline supervisor level.
Highlight the wins of your team, but also highlight what they need and, and be able to get them the resources. But then also, on the way down, manage down is managing expectations and being able to navigate a way forward for them to be successful because sometimes you don’t get your way, right?
Sometimes a prosecutor doesn’t agree with the decision that you’ve made. Or wants to go a different way. Or sometimes another foreign partner or other government partner is in the better position to lead on an effort. And so, you’re kind of having to explain to your team, like, maybe we need to sit second fiddle to this one.
So, those are conversations that you need to be kind of able to manage up and down and explain to them in a way that helps them learn and grow in the organization.
Leatherman: And is part of that, I hear you saying, also transparency? In those engagements, transparency is incredibly important. And the other thing I would tack on to that, I think too, that goes hand in hand, with that is communication. And communication is key. A vacuum of communication, especially in a high operational environment, leaves people wondering what the priorities are or today what we should be addressing.
And I think the best leaders, at least in our organization, communicate well. In fact, they look to overcommunicate. That’s part of your job now. And that’s what we’re going to pivot into, is a cyber law enforcement attaché. You’re one of a small number of cyber ALATs. We have just shy of a couple dozen cyber ALATs who are posted around the world. And communication is so key to the work that you do.
It’s communicating with the partners in country that you deal with, but then it’s communicating back with the FBI teams, both here at Headquarters and across the … across the 56 field offices, to help them understand kind of the emerging threat, in your case, in the United Kingdom.
So, what does having you in London let the FBI do that we couldn’t do from Washington?
Sherman: Sure. Well, first, I think having face-to-face relationships really matters. It matters even more so during a critical situation that you’re trying to navigate.
Specifically here in the UK, we benefit from 80 years of partnership with the UK. You know, our partnership was defined after World War II and this is the 80th anniversary of that.
So, I got to step in to a partnership that already was built on trust and confidence in how we were moving that forward. But specifically, when it comes to the cyberthreat, is we have to execute things at speed. And with that, we have to be able to understand what each partner needs from us or what we might need from them in order to facilitate that action.
But sometimes there are challenging conversations to be had, too. We need to kind of figure out what role we’re going to play in an operation or what role maybe a partner is going to play in an operation and sometimes you have to give … a give and take. Those conversations, those challenging conversations, are done face to face.
And the relationship is built and it’s maintained because of the respect and showing up that I do when we need to kind of work through the tough decisions to kind of get to the next phase of an operation.
Leatherman: Yeah. You mentioned speed of action, kind of joint action. You’ve been in the room for some of the biggest joint sequenced operations and joint investigations between the U.S. and the UK over the past few years. I’m thinking Operation Cronos, the takedown of LockBit, our work together on Scattered Spider, and other things. Without getting ahead of obviously anything sensitive, what does it take to make … transatlantic operations like those come together?
Sherman: Sure. So, it goes without saying, like, we have to have respect and you have to have patience. At the end of the day, in every situation, we all want the same thing, right? We want to stop criminality and we want to protect the public, whether that’s the American people or the citizens of the United Kingdom. Everyone wants the same thing.
The challenge comes in figuring out the path that we’re going to get there. You know, we have … the U.S. and UK are very similar in many ways, but we’re also very different. The U.S. and specifically the FBI, are very large, and we have a lot of resources, which can be advantageous at times. But it also has its disadvantages.
The U.S. and UK legal system actually operate very differently. And so, it’s a challenge sometimes to be able to navigate that. However, me living here and me working here and after three years understanding kind of how the UK investigative process works, it’s really helped me to understand where we can best fit with each other, and it’s helped me to manage those expectations and set goals for our case teams back home.
What should be shared? What can the UK do with our intelligence? And sharing at speed because I’m here and because I have those trusted relationships, also allows us to move the ball forward at a much quicker pace.
Leatherman: Great. Before we get into the news item today, I want to ask you one more question. You’ve now done this work domestically and abroad. You’ve seen kind of the best of what the FBI does. If you were to talk to a college student or a young professional who’s already working in a private sector security role, about weighing the opportunity to become an FBI special agent and working the cyber mission: What would you tell them … as they weighed that?
Like, how would you advise them to think through whether they pursue a job with the FBI as a special agent or whether they stay in industry?
Sherman: Sure. Well, I think we have the best job in the world. I think we can do anything in this organization that we set our minds to, and we get to protect the public in the meantime. So, first and foremost, I think you have to have the passion to want to do that, to want to be a public servant.
But specifically with cyber, I think you really have to maintain that curiosity to learn. The threat actors are constantly changing the tactics and techniques they’re using. And the technologies always are already changing. I mean, you know, AI is the front of every conversation. So, if you don’t have that curiosity to keep learning, you’re going to be way behind.
The FBI provides great training, but the curiosity, that kind of keeps you motivated, keeps you wanting to learn, is, I think, what makes very good cyber agents at the end of the day. But overall, it’s the mission of the FBI. I mean, we get to work in the law enforcement side as well as on the national security side, and we get to work incredible … with incredible partners all over the world.
And at the end of the day, the disruptions that are known in the news cycles and also the disruptions that are not known in the news cycles, it’s just such a rewarding feeling knowing that you even played a small role in that bigger picture. So, there’s nothing like it. And, it’s rewarding every day for sure.
Leatherman: Yeah. Somebody who used to work in cyberdefense before joining the FBI, I loved it. I love defending networks and data against bad guys, but there’s nothing like being able to punch the bad guys in the nose and hold them accountable for what they’re doing, and we get to do that in this job. And like you said, there’s a lot that we do publicly.
Cronos was a great operation that really disrupted and impacted a very prevalent ransomware ecosystem. We did … we couldn’t have done it without our partners in the UK at the NCA [National Crime Agency] and with Europol. But those kind of operations mean something, right? They mean something. And for every one of those that the public sees, there are lots that the public doesn’t see on the national security front.
And that is all our work to defend the homeland. So, incredibly important.
Now, you mentioned the evolution of AI, and I want to end on one story because it’s one that we and our UK partners are living every day. Just recently, in May, Verizon published its annual Data Breach Investigations report. For 19 years, it has been one of the most trusted reads in our field, and this year’s edition draws on more than 22,000 confirmed breaches reported by law enforcement, incident responders, and industry.
Several things jump out, but one really stood out to me. For the first time in those 19 years, exploiting a known software vulnerability, past stolen credentials, is the most common way attackers first break into a network. It now accounts for 31% of breaches, up from 20% the year before, a 55% increase year-over-year, while stolen credentials fell to 13%.
The numbers behind that shift are what should get all of our attention. Attackers are weaponizing known flaws faster than defenders can close them. Of the … vulnerabilities listed on CISA’s Known Exploited Vulnerabilities list—or the KEV, the ones we know for certain are being used in attacks—only 26% were fully remediated last year, down from 38%. And the median time to fully patch one rose from 32 days to 43 days.
The exposure is also shifting to the edge with internet-facing devices and VPNs climbing from 3% of these breaches to 22%. Verizon ties the speed to AI, which has collapsed the window from disclosure to exploitation from months to hours. The report calls the rapid weaponization of known vulnerabilities a capacity crisis for security teams.
And this is not just a U.S. read. Earlier in May, the UK’s National Cyber Security Centre, Richard Horne’s agency, told organizations to brace for the same thing: a wave of AI-driven vulnerability disclosures they called, “a patch wave.” A leading U.S. report and the UK’s NCSC in the same month, pointing at the same problem.
So, Kathryn, you have visibility into how both U.S. and UK organizations respond when a major vulnerability lands. How should cybersecurity executives prepare … their boards and stakeholders now?
Sherman: Sure. Well, first, I think it’s important to highlight the phrase that NCSC used in that article, which was “technical debt.” I thought that was brilliant, as they say here in the UK, because I think it really is catchy and grabs the attention of the board members. Right. Debt, anything monetary, is something that really kind of sparks our interest.
So, I think that’s something I’ll steal going forward. But I think there are three things that cyber executives should really, really be focused in on. The first is they need to be able to articulate their attack surface. That includes internet-facing devices, that includes their cloud workload, their third-party services. And … as well as our critical applications.
And secondly, with a patch wave coming or the need to really enhance the speed of patching, they need to realize that its … executives need to realize that this is going to cost money, right? If they’re doing this right, when those patches come, they’re going to identify end-of-life devices; they’re going to be taken offline and replaced.
Critical applications might need to be taken offline for patches to be implemented. That could cost money, but the risk of not doing it could cost even more.
And the third, I think, is having an operational plan and testing that operational plan, and making sure that it’s something that you have executive buy-in for … when some critical applications might come offline or what you’re going to demand of your third-party providers.
And highlight the wins, right? If you’re a CISO [Chief Information Security Officer] and you have, you know, you patch 50,000 end users in two critical applications and it all goes off without a hitch, don’t just hide in the background. Like, that is something stakeholders should understand and know, and put a monetary … number towards what they have potentially saved the company by making sure that that was done successfully.
Leatherman: Yeah. You hit on two things there: technical applications, which is looking at that patch management life cycle, looking at vulnerability management, looking at those edge devices, those end-of-life devices. But the other part is the leadership buy-in here and as executive understanding that there is an investment that … is needed. It’s a financial investment, it’s a time investment in that is … whether you’re in the board of directors or you’re a CEO or CSO or CIO, you’re part of the risk-management equation in understanding what this risk is that is coming downstream is incredibly important.
Helping your CISO and your network defense team start to mitigate that through thought leadership and applying kind of what you learn from that is incredibly important.
And I think that is the piece that is going to separate the organizations who do really well at defending against this versus those that don’t. Which organizations have buy-in at the executive level, that are prepared to step into the fight, and start to resource the teams that need to defend against this evolving threat landscape?
Sherman: Absolutely, boss. I mean, at the end of the day, an organization and the leaders should want their cybersecurity teams to be on their toes and ready to launch into that operational plan during either a vulnerability announcement when they need to execute critical patches or during an incident, and not be on their heels. And so, the difference of those two and the different postures are going to be what they do now and what they’re prepared to do when … that time comes, which is what we do every day in law enforcement, right?
We constantly train, we’re constantly ready to execute operational activity. And that mindset, that understanding, needs to be needs to be applied here as well.
Leatherman: Yeah, absolutely.
Well, Kat, thank you so much for the conversation today. And more importantly, thank you for representing the FBI in LEGAT London. I get to see what you and your colleagues do in LEGAT London every day to defend the homeland and take the fight to the adversary, but also to defend all of us, critical infrastructure, both here in the United States and in the UK.
My goal—I get to see it. My goal was to give our listeners a small glimpse into what you guys do. And I know it’s given them that small picture based on this conversation. And I just appreciate you coming on to do that. I know it’s evening in the UK, so we’ll let you get back to it, but thanks for being on the show today.
Sherman: Absolutely. Hey, it was an honor and thank you for having me, I appreciate it.
Leatherman: Great. My conversation with Richard Horne, chief executive of the UK’s National Cyber Security Centre, an agency Kathryn and our London teams work with regularly, is next.
Leatherman: Welcome back to the episode. I’m really happy to be joined today by Richard Horne, who is the CEO of the UK’s National Cyber Security Centre [NCSC], which is part of GCHQ [Government Communications Headquarters]. Fresh off the heels of the UK’s kind of flagship cyber security conference, which is hosted by the NCSC, Richard Horne is here in the U.S. and agreed to join us on “Ahead of the Threat.”
So, Richard, welcome to the show.
Richard Horne, CEO of the UK’s National Cyber Security Centre: Thank you, Brett. It’s great to be here.
Leatherman: Are you recovered yet from last week?
Horne: I think so, yeah. Okay. Pretty much.
Leatherman: Alright. Well, it was a busy week. I was there all week and really enjoyed the opportunity to see both the presentations, hear your keynote, as well as kind of participate in the one-off engagements with industry and key government partners throughout. So, thank you for putting on such a great event. It was … I think everybody thought … it was an outstanding experience.
Leatherman: So, I’d love to kind of hear initially your reflections, but first for our U.S. audience, can you help them understand what is the UK’s NCSC?
Horne: Yeah. So, thank you for having me, Brett. It’s great to be here with you. And some would say being led to a windowless room in the basement of the Hoover Building for an interview is a trepidating experience, but …
Leatherman: We promise you will leave here unscathed.
Horne: So, yeah. So, NCSC, we sit within GCHQ, which is a signals intelligence agency.
Leatherman: Similar to the NSA [National Security Agency], right?
Horne: Similar to the NSA. So, we generate the intelligence on our cyber adversaries. And I guess in terms of the U.S. system, we overlap with the NSA, you in the Bureau, and CISA [Cybersecurity and Infrastructure Security Agency] sort of in various ways. So, we lead the charge in the UK in terms of defending against the most advanced threats. So, the nation-states. We lead in terms of raising the resilience and the defenses across the UK as a whole, and particularly our critical national infrastructure. And we’re the national technical authority for cyber security.
So, issuing the kind of authoritative advice and advisories and guidance, and also input into government risk assessments. And then obviously we partner with the likes of the National Crime Agency [NCA], who also work with you in, in this space. So, sort of, you know, we’re overlapping Venn diagrams in terms of how we map to the U.S. system.
Leatherman: Yeah, the partnership is incredibly important because it’s taking that national security picture, which you, GCHQ, sees on a regular basis. And certainly, distilling that in ways that the public can action, you know, to defend networks and to defend national security as part of that.
Horne: Yeah, absolutely. And I think kind of increasingly, in the world we’e in, we’re in getting that kind of really tight line between intelligence as to what’s happening against us into being able to take action to defend ourselves. And as well, action to disrupt is really important, and getting them as close together is critical.
Leatherman: Yeah, increasingly important because … and we’ll talk through kind of some of the implications at, you know, a through line of, of Cyber UK was artificial intelligence and closing the gap between how the actors are able to exploit technology.
But let me first get your reflections because, you know, NCSC does take perspective and distill it into ways folks can protect their networks.
From a technical standpoint, there’s a lot of advisories that go out that we often co-seal on together. The conference itself was really broadening that context a little bit and giving folks the opportunity to come together in person and hear from NCSC’s perspective, to hear from the FBI’s perspective—I had an opportunity to speak there—to hear from industry’s perspective.
And so, what are your reflections from last week that kind of still sit with you this week?
Horne: Yeah. So, it was really interesting because each year we try and kind of set the tone, as it were, in terms of where are we in in terms of cybersecurity as a nation. And man, what a time to try and set sort of to the moment we’re in.
So … we sort of settled on an idea for my speech of, you know, I talked about driving through Florida—I think it was 2008 — and just on “Alligator Alleyway” kind of across Florida, and suddenly got caught in this torrential downpour and just could not see the road ahead. And you could just see the tip of the bonnet and just make out the start of the white line in front and just had to stick to that because you can’t stop because someone might be coming behind you.
So, you know, it’s that sort of that real sense of sort of angst in terms of you can’t see the road ahead, you have to keep going. And how do you manage through that? And a lot of it is about focusing on the fundamentals of how do you drive well, how you alert to risks, how do you respond quickly.
And sort of that painted a picture, I think, of where we are in cybersecurity. And I talked about kind of the idea of a perfect storm, where we’ve got two forces coming together. One is just incredible technology disruption. And we’ve seen it the last few weeks, especially in Frontier AI. But there’ll be all sorts of other things that will drive that disruption in the coming years, coupled with rising geopolitical tensions and the changing landscape geopolitically.
And they come together and cybersecurity’s in the intersection. And that does create a kind of perfect storm for us in cybersecurity. So, recognizing that but as well recognizing we do know how to get through. And yes, we will need to reimagine cybersecurity over coming years as technology changes and it changes how we can do cybersecurity. But right now, a lot of the emphasis needs to be on focusing on the fundamentals that we’ve always known we need to do.
Leatherman: Yeah. I … for the American audience, first of all, a bonnet, I think is a hood, probably in the front of the car.
So, a little bit of translation there on my end. Yeah, I was struck by that. Going back to the fundamentals. You know, a lot of folks think about, the proliferation of artificial intelligence and new technologies with we have to get more sophisticated with what we do, and fundamentals matter here, right? Because it continues to be the exploitation of the fundamentals.
As I sat there listening to your keynote and kind of you talking about that, it took me back to my days as a pilot flying aircraft. When you are kind of hit with this perfect storm, when you start to have conditions that deteriorate, similar to what you faced, you go back to the fundamentals, which is aviate, communicate, navigate. In that order. Right? The goal is fly the aircraft at first, like whatever is happening outside, your goal, keep the aircraft upright. Fly it.
Then you communicate. Let others know kind of what your position is, and what your plans and intentions are. And then you start to navigate, you start to, “Okay, now we’ve settled things down. How do we navigate to, you know, where we need to get, as a result of this perfect storm?” And it really is something that I think the audience should hear is, “fundamentals matter in this environment.”
The threat actors themselves haven’t changed. We still face the same nation-state, and there’s still criminal actors, the same groups, but the way they operate is different. But it still targets identity and access management. It still targets edge devices and those kind of things. And being able to focus on that is important.
Horne: Absolutely. And I think, you know, what we’ve seen in recent weeks with all the Frontier AI discussions around what it’s enabling us and our attackers to do is, essentially it means we’ve been for so long as a sort of mutual society, dependent on technology that people haven’t been necessarily keeping up to date. You know, replacing legacy systems, modernizing, haven’t necessarily been patching all the things they need to apply security updates for.
And Frontier AI is just going to shine a light on that and expose whether that’s, you know, whether the fundamentals haven’t been happening. And then things like access control, you’re controlling who has access to what in a strong way. So, those fundamentals that this sort of immediate wave of AI developments, I think is just going to expose where those fundamentals haven’t been practiced.
And so, for us to get our societies in a place where we are consistently and urgently practicing those fundamentals, is really important.
Leatherman: Yeah. I had the opportunity to host the CISO [chief information security officer of AWS [Amazon Web Services] a few episodes back where we talked about Russian groups who were leveraging AI that AWS was able to track across the ecosystem, and that when they saw the fundamentals were in place, those actors actually moved on. But the AI allowed them to scale and to really act with urgency or speed against those who did not have the fundamentals in place.
So, that, I think, is something that that industry has also seen as well.
You wrote a letter in the Financial Times on April 15, and then a week later we had Cyber UK. And during your keynote, you really made a similar argument about AI. The core of it is that AI accelerates the exposure of organizations where the cybersecurity fundamentals haven’t been addressed or are just not visible to the network defenders.
And I think the answer is to raise the baseline there. So, walk us through the throughline of those two pieces and what you’re signaling about the fundamentals that CISOs listening to this, or boards of directors listening to this, how do they start to approach that tomorrow?
Horne: Yeah. And it’s a really interesting reflection. And I think, you have the same here in the U.S., where CISOs have trod quite a lonely path, where they’ve known the IT [information technology] base that they’re working on in their organizations isn’t where it needs to be in terms of overreliance on legacy technology exposed, you know, unpatched systems and what have you.
So, I think … this creates an opportunity to take that conversation to the board where it needs to sit in terms of are we properly investing in reducing our technical debt, you know, in managing our technology base in the same way as we manage cash in the bank carefully to make sure we don’t run out of money.
You know, we have to manage our technology base in the same way and be as concerned as a board and … leading to what the CISOs have been saying to their boards, which is, “We need your help. We need technology, we need our operational technology,” which is often in different parts of the organization. Yet, to have that focus and to have that understanding at board level, that this is a really important part of running as a business in today’s world.
Leatherman: Yeah, we see organizations … there’s a clear distinction. Organizations who have board buy in, who have C-Suite executive buy in, who tabletop … with folks outside the CISO chain of command, they tend to be more resilient and they tend to have better recovery timelines than those who don’t involve everybody.
And we frequently say, “cyber risk is business risk” for a reason, right? That it’s often the case that risk managers outside cyber will look at financial risk or physical risk. And they are a part of those discussions, but they’re not necessarily a part of the discussions around cyber risk.
Is that because, from your perspective, it’s perceived as too complex for them to talk about? Why is it that we tend to see cybersecurity as something that organizations don’t fully embrace from a culture standpoint?
Horne: Yeah, I think there’s probably a few reasons. You know, I talk with a lot of boards and frankly, they don’t have much understanding around technology. You know most boards, if you said to them, “cash is running low,” they’d know that that’s an urgent situation we need to deal with because they have some sort of intuition around what that means.
Many boards struggle with that intuition when it comes to technology and rely on what they’re being told, and maybe don’t necessarily have the ability to judge and to understand the urgency. So, I think that’s one really important facet.
The other thing that I observe is organizations, for example, that get hit by ransomware attacks. You know, overnight suddenly it’s the board’s issue because the CISO can’t work out how to keep the business running without IT.
That’s … an organization-wide challenge that the board has to lead on. So, I often sort of talk with boards in terms of that challenge, you know, just ask yourself the question, “How are you going to run your business for four weeks without IT?” And until you can answer that, you’re not ready for a ransomware attack. And when you answer that, you’ll realize how you don’t want to be in that position, and you’ll probably invest more in making sure you don’t get there.
So, I think it’s a really good leading question. I often say to non-execs when they say, “Well, what’s one question I could ask in my board?” Like ask, “What’s our plan to run our business for four weeks without IT?”
Leatherman: And bring the folks in that are stakeholders in that, whether it’s the CISO or others, and have them tell you what that plan is, and have them highlight if you were to change anything about preparedness, what would you ask me to do as a board member to help us change, to be more resilient, to operate through that crisis?
Yeah, I think that’s an important message. I think every CISO listening would advocate for that.
And I would encourage every CISO listening to leverage your keynote, which is currently out there, by the way. NCSC has published that, as part of the opportunity to engage with their boards to say, “Here is what NCSC is saying about resilience,” especially in the coming weeks, months, and years. Or this podcast, even, and the discussion here because I would say we’re relatively unbiased.
We’re not trying to sell products. We’re trying to sell national security. Right?
You said success is going to rely on the defenders embracing AI as quickly and rapidly as the offenders using it. I, from my perspective, I don’t think we’re there yet. I see adversaries really looking to scale how they’re operating in the AI space.
How do we start to approach that as defenders looking at AI adoption? I look at it as a step before you run, kind of walk-before-you-run model. But what’s your perspective on how defenders start to adopt AI in meaningful ways?
Horne: So, there’s so many layers to that question. I think, you know one layer is many product providers are baking AI into their products. And that’s a good thing.
Leatherman: EDRs [Endpoint Detection Response]. If you leverage cloud-based platforms right now they’re using artificial intelligence so it’s embedded in.
Horne: So, a lot of the kind of, you know, looking for anomalous behavior, even some of the access systems and things like, you know, SOCs—Security Operation Centers—how they run and using AI to replace some of the first line activities that are quite manually intensive. But actually, if you automate them with AI, you can make them quicker, you can make alerts more effective and what have you.
So, using AI to optimize that tooling is one step. I think the other step that’s kind of a really pressing opportunity for all of us is using AI to improve the quality of code. And this is where it’s … there’s a real long-term opportunity, but there’s a short-term bump to get through. And that is, you know, the long-term opportunities we can have code that has had all of its vulnerabilities eliminated before it hits the market, before it gets deployed.
Leatherman: Truly kind of secure by design. Right now, you’ve got this model that is not human, right? It is generating code that is hopefully more secure by design and maybe in a continually … a continual process of updating that code over time as well. So, that’s one way.
Horne: So, that’s a real opportunity. Now there is a bump to get through in that we’ve all got code deployed that hasn’t been through that process. And so, it will go through that process with us needing to apply security updates at scale and at pace. So, I think that’s the, you know, that’s the short-term bump to a longer-term, almost better future.
I think it does give organizations opportunity to change their procurement practices. And you could procure on the basis of bespoke software or services. And, you know, we want the reassurance of it’s been through our favorite LLM [large language model] to get a clean bill of health in terms of vulnerabilities. So, there’s huge opportunity there and, as well, AI used for code generation.
Horne: This is the vibe coding type tools. Again, if it’s done right, it can generate code that’s good code and address a whole load of the quality issues that we face today. But there was an “if” there, in that the code generation needs to be trained well, the models need to be good so that it does generate good code.
Leatherman: I’m struck by “if it’s done” right because there’s a lot of bad ways to employ AI in our environments as a knee jerk reaction, right? It’s really starting to think through logically in the near term, and then long term how do we start to employ this technology that is ethical, safe, and also helps us scale and accelerate defense?
Horne: Absolutely. Yeah. That’s right. And that kind of, I spoke at RSA about sort of the different spaces we defend in. So, we defend the near space, which is sort of the systems of companies, critical national infrastructure, and others in our environment. We defend in the far space, where we kind of take action against our adversaries and disrupt them, degrade them, so on.
And then we have a mid-space, which is the cloud infrastructure, the telecoms’ infrastructure that we all rely on. And actually, we’ve kind of viewed them as separate spaces in the past. But I think increasingly with AI, we have a real opportunity to detect something here and turn it into an action over here and in real time at national level and international level, be able to intervene and disrupt at scale in a way that we haven’t before.
Horne: And there’s, you know, a real opportunity for us to research and work on together around how we … how we join up those environments and defense across them.
Leatherman: What is required of industry to help us do that; to close that gap between the near term and the long term or the near technology and, you know, going after actors’ infrastructure, conducting those disruption operations? To do that at speed and scale … what do we need from industry to do that?
Horne: Yeah. So, I think for private sector organizations, you know, the first thing that the organizations that are likely to be targets, you know, or all organizations—the first thing is getting the fundamentals right. Because attackers will always go for the easiest path. And the easiest path often isn’t finding some new vulnerability. The easiest path is finding and exposing with a default password or whatever it is.
So, getting those fundamentals right is absolutely key. And that’s a key challenge we have across all our societies. I think for us in the UK, we really focus on how we can work with tech providers, with telecoms providers, to make interventions at scale.
So, we have a service we call “share and defend,” where we just, at the moment, we just collect all the malicious links we know about, you know, banks feed in and all sorts of others.
It’s often sort of fraud related, but just any malicious links we know of, and then we pass them to the ISPs—the Internet Service Providers—and they’re now starting to block in real time when people try and click on one of those links and the figures are staggering in terms of how many times an attempt to resolve a link is blocked.
You know, we’re in billions already and it’s just phenomenal. And it makes you realize that some of those interventions we can make in that mid-space, in the cloud environment, and telecoms environment, can have huge impacts and just take so much noise out of the system.
Leatherman: That’s where the telcos and the major cloud providers have real reach. And being able to defend our collective populations, is we pass intelligence and their willingness to employ defensive measures across their ecosystem is important.
But to your point, where they’re seeing that intelligence and they can share that intelligence with us, that’s what makes us better at either helping defend sectors, defend the economy, or the sooner they share, maybe even move upstream against the actors themselves.
Horne: Absolutely. That’s right. And that’s, you know, that’s the unique position that we’re in. You’re in. Yeah. Being able to sit in the middle of an ecosystem and partner with industry, with private sector organizations who either can give us intelligence or give us the ability to intervene in partnership with them and act on that intelligence.
Leatherman: And … those are the industry partners who have unique perspective. But there’s also a role, I think, in victims of a cyberattack coming to us. And there’s a, what I would describe as “a time to live” when it comes to reporting. Like the sooner they report to us, the more we can do to help them, the sector, and move upstream.
The problem is the more they wait to report, whether it’s in the UK or the U.S., the less likelihood we are to be able to pursue meaningful disruptive efforts, but also to share intelligence that might impact other organizations.
Horne: Absolutely. So, in the UK, we operate something called “Trust Groups” through the National Cyber Security Centre, where we just have CISOs from all organizations within a sector or a particular market segment, and they’re able to share information together in real time. But we’re part of the mix as well and able to feed things in.
So, for example, we had a spate of retail attacks last year. We were able to feed in.
Leatherman: Scattered Spider type.
Horne: Yeah, Scattered Spider type stuff. Able to feed into that, those trust groups. “This is what we’re seeing. This is what you need to look for in your help desks” and what have you. And be able to kind of as quickly as possible, get the message out to help organizations defend themselves against kind of a new wave of attacks.
Leatherman: Yeah. It’s how we all come together to defend is by sharing that information quickly.
Something that struck me during your keynote was there is a lot of discussion, over the last few weeks in particular, about new large language models and the release of new technology in the AI space. We’ve talked a little bit about that here today. But one thing you said, you called workforce perhaps our biggest challenge.
And so, I think not a lot of people are thinking through that right now. They’re thinking through the AI piece. But on the U.S. side, not too long ago, the White House released the President’s National Cyber Strategy, which makes developing cyber talent and capacity a top priority here. It’s one of six pillars. It’s incredibly important. We’ve identified that gap in technical workforce and prioritized that.
Clearly, you see that is an area of risk as well. How are you pulling together industry, academia, vocational technical paths? Like, where are you guys looking to bolster workforce resilience and what does that look like in the UK?
Horne: Yeah. So, I mean, I’ve been in this role 18 months and came to an organization that’s now been running for sort of 10 years. And one of the first things the National Cyber Security Centre did was focus on this challenge. And the interesting thing for me is we’re now starting to see the fruits of what was started 10 years ago, and only because it’s been kind of applied consistently for 10 years.
Horne: So, there was a scheme started called Cyber First, which is all about getting school kids interested in cybersecurity and particularly, you know, back then especially there were very few women in cybersecurity. So, how do we get more girls interested in cybersecurity? How do we get people from less privileged backgrounds, and what have you?
Leatherman: And by the way, the last day of Cyber UK, I saw a whole group of students coming through and visiting, and they were so excited to be there. Going through the Expo Center meeting, you know, heads of government agencies. So, you employ that even at Cyber UK?
Horne: Yeah, absolutely. It’s been sort of very much integral to the thinking of all of what NCSC does. And now, 10 years on, we’re now seeing kids who started on that journey when they were 13 now employed by us and by others. They’ve been through sort of schooling, they’ve had bursaries to go to university, and they’re now in employment in cybersecurity.
Horne: And it’s really made me realize that addressing a workforce challenge is a, you know, it’s a long-term project. It’s not something you can kind of dip into and out of. Year by year, you have to stick with it for a long time.
So, Cyber First, we do a lot of work with universities. So, we have accredited courses at universities. And a lot of research work that we work closely with them on. So, sort of looking at that whole ecosystem, how can we tie it together?
And then one thing we do in the NCSC is we have a scheme called I100, where we encourage industry partners to second people into us, on a kind of formal secondment, but it might be a day a month, it might be a week every three months, whatever kind of works for them.
Leatherman: With a technical discipline?
Horne: With a technical discipline, with, you know, background that can help us, and they work on our work. But it also means that when they go looking, you know, in their home companies where they’re bringing insights from having worked with us.
So, getting much more fluidity between people in private sector and people in government working on cybersecurity and getting that sort of sharing of views and propagating an understanding of the environment we’re in.
Leatherman: I think an appreciation for what you guys are doing as well, that there’s a lot of, probably misconceptions about what happens within NCSC, GCHQ, and in the UK government, and it gives them the ability to say, “This is how,” you know, “they’re working to defend us.” And that perspective is important when you go back out to your company and then you start to, you know, be able to share with others, this is an ambassador, what it is that they’re doing to help.
Horne: And then it kind of it really reflects in your comments about Cyber UK when you kind of bring the whole community together. You’ve got sort of government, you’ve got industry, you’ve got CNI [critical national infrastructure]. You’ve got academia. You’ve got all sorts of different sort of interests reflected, but a real sense of community and a real sense of shared mission that we’re here to make … the UK the safest place to live and work online.
Leatherman: The … kind of issue that I struggle with is kids now who are in university and studying the computer sciences and understanding like where this is going as it relates to artificial intelligence. And, you know, I tell them a lot, “Like, really embrace AI right now. While you’re in university, understand how AI can augment what you do, whether it’s coding, systems administration, networking, you know, whether you’re looking at forensic artifacts. How can you start to learn artificial intelligence?”
I don’t think a lot of universities are probably teaching that. But there’s an opportunity to do that kind of on their own. How would you advise a student right now who is studying computers, who might be afraid that, you know, their job may be outsourced to AI at some point someday? What would you tell them as far as how they should prepare for their future kind of entry job in cybersecurity, whether it’s in the government or outside the government?
Horne: Yeah. And I mean, it’s a really interesting area. I often say to kids when I talk to them, “When I was your age, my job didn’t exist.” And, you know, cybersecurity didn’t exist. And really, what fueled my journey was a passion and an interest in the subject. So, you know, for me, it started off in a passion for math, pure maths, which led me into cryptography and led me into what then became cybersecurity.
And yeah, that’s sort of how I’ve been drawn into this and sort of been on this career my whole life. So, I think, yeah, more than anything, it’s about being passionate about how things work; how the digital world works, being curious, being interested. But as well realizing that will make us unique as humans is what makes us humans.
So, those soft skills—the ability to speak in public, the ability to inspire others, the ability to lead others—you know, they’re really important skills as well.
Leatherman: Yeah, it’s incredibly important.
So, you mentioned, your time, your kind of mathematics background in cryptography. You have a Ph.D in cryptography. So, you kind of started out, looking at cryptography, which is, very unique skill set for somebody who now leads the NCSC. So, being a mathematician by training with that Ph.D in cryptography, I also remember you said during your keynote, that right now quantum readiness is in our gift. Meaning, we have an opportunity here to still make progress, I think, right against what is going to come.
Can you help us understand what you meant by that, and what that looks like over the next year, five years, or 10 years?
Horne: Yeah. So, the whole post-quantum world is a really interesting topic for discussion because we do know algorithms today that are quantum resistant. So, in some ways you could view this for people of our generation as a sort of Y2K challenge of, you know, at some point we’re going to have to find all the cryptography we use, all the public key cryptography, and rip and replace with quantum resistant.
I think it’s probably a bit deeper than that, in that, you know, I remember when public key cryptography was first being used, and we were finding all sorts of kind of tweaks that needed to be made to implementation. So, I remember, you know, with RSA, we started using short exponents to start with, to make the computation easier and then realized that actually that introduced weaknesses.
So, you had to use longer keys and what have you. So, I think there will be a journey. It’s not a one stop thing with replacing cryptography with quantum resistant. There will be a journey as we realize algorithms need modifying and what have you.
So, I think sort of a mindset of crypto agility is what we all need to understand where we use cryptography and understand that we will need to be agile in terms of being able to replace that or modify it as time goes on. But the standards are there now for post-quantum crypto. They’re starting to be implemented. We’re starting to see some of the big tech companies using quantum-resistant technology and internet protocols and things like that.
So, we’re starting on the journey and organizations, I think, need to be in a place now where they’re thinking about how they procure IT to make sure that that crypto agility is baked into the procurement, and starting to think about how they get a grip of all the places where cryptography is used in their organization, and how they would go about addressing a new kind of technical debt that we’re going to have to deal with in the coming years.
Leatherman: And this isn’t a “I’m just going to make a decision tomorrow to start using post-quantum cryptography.” This is a complex issue, and I think that’s why you framed it well in Cyber UK is we have time. We have algorithms, right now, that are out. There’s still a lot of learning to be done, but really, it’s not a tomorrow decision. It’s a next month, next year, next five years.
Like, how do we start to build a roadmap? Is that where organizations need to be to start thinking about kind of their perimeter devices, how they serve protocols, or how they communicate between machines or sites? Like, how do they start to prepare and frame that out?
Horne: Yeah. And it is a real challenge for organizations. And many private-sector organizations and many government organizations, you know, work on annual budget cycles. We’re talking about a five-to-10-year plan, which doesn’t fit well within many of the sort of the structures within which we work. So, I think it is really important to be quite overt within organizations about we need … a 10-year roadmap, and this is what it’s going to look like.
And we’re going to have to be on this journey and stick on this journey year by year as we go through different budget cycles. So, I think the most important thing now is to be clear about the plan and the phases of the plan, and that we are on a multi-year journey, and we need to set ourselves up for success on a multi-year journey.
Leatherman: That makes sense. And I think that’s something that, you know, that’s an opportunity for folks who don’t understand post-quantum cryptography to leverage, No. 1, the folks who are experts in this industry, like the mathematicians who do this and lead, you know, consequential government agencies, or the folks who work for them to understand where our points of vulnerability are, where our key data is, and how we start to maybe … incrementally provide those or replace devices with technology that already implement these kind of safeguards.
Horne: Yeah.
Leatherman: Switching topics a little bit, staying on cryptography because we’re gonna talk about ransomware, an epidemic that we continue to see here in the U.S. and I know is a big issue in the UK.
During your keynote, you said, I’m trying to get the language close here, “We should already be at the point where paying ransoms in the face of destructive attacks simply doesn’t happen.”
Walk us through what you meant by that.
Horne: So, there’s a there’s a bit of unpicking here, and I think this is really important, firstly, for organizations that are blessed with not having been in this situation. That what happens with the ransomware attackers is you have two things: one, a load of data is taken out and, you know, there’s a threat to publish that data.
Leatherman: The exfiltration, publication, embarrassment, and the threats to it.
Horne: And the other side of it is they often encrypt systems. Impacts the availability. And then the, the extortion has two levers to it. One is, “Pay us and we won’t publish the data we’ve taken.”
And the other part of the extortion is, “You probably can’t recover your systems. Pay us, and we’ll give you a tool that enables you to decrypt all the systems we’ve encrypted.”
Now, for both of those, there shouldn’t be a need to pay. If an organization is prepared, there shouldn’t be a need. For the threat to publish data, we know from the joint operation that we had internationally to take down the LockBit ransomware group a couple of years ago now.
Leatherman: Operation Cronos.
Horne: Yeah, we know from taking down their servers that there were companies that had paid a ransom and their data was still on their servers. So, we know that you can’t trust the criminals’ words for it. They might not publish the data, but it doesn’t mean they’ve deleted it.
Leatherman: It doesn’t mean they’re not going to come back to you at some point and extort you for that.
Horne: So, there should be no drive to pay on the basis of “by paying the data will be deleted,” because we know that you can’t rely on that.
The second driver of “pay because it will help you recover,” there is a myth that it’s like kind of you pay a ransom, you get a key, you put it in the door, the door swings open and the lights are on. And it’s nothing like that. We know that even if you pay a ransom, all that does is give you the ability to recover your data.
You still got to rebuild all your systems. It’s still a weeks-, months-long journey to get your systems back. And if you’ve got backups of your data that are protected so that even your systems administrator can’t delete them, then you will have secure backups of data that you can recover from.
Horne: So, you shouldn’t need to pay a ransom to get back your data to recover your systems. Now, it’s still a long journey to rebuild those systems. If you haven’t thought through a plan for how you would rebuild your systems at scale and an environment where you can recover your data into and rebuild your systems. But actually, there shouldn’t be that incentive for organizations to pay a ransom, because those two big drivers actually shouldn’t be there.
Leatherman: Yeah … for me, there are situations where, you know, you experience a destructive attack or a ransomware incident—think NotPetya—where, you’re encrypted and you think you might have an opportunity to pay a ransom to get your data back. The opportunity is just not there.
Horne: And that’s really important, because in the world we’re in of rising geopolitical tensions, we’re going to see more hacktivist attacks, which are essentially like ransomware attacks, but no opportunity to pay.
Leatherman: Yeah, we saw the Handala attacks on Stryker, of course, where, you know, a U.S.-based corporation was attacked by … an Iranian-aligned group and that was destructive. That was not meant to solicit a ransom payment or anything.
So, I think that idea of resilience is increasingly important, because at some point here, with geopolitical tensions, with artificial intelligence, you may not be able to pay a ransom. The actors may not care about that.
And that resilience key is how do you operate? How do you fight through that? Air gapped, immutable backups is an example of something everybody should be thinking about right now. But I’m afraid right now we’re in this, this culture of, “Well, they’re always going to offer us a key, and it’s an insurance payment away. It’s a cyber insurance policy away. We have a $1 million deductible and we can, you know, make the payment. We’ll get the key back and we’ll start to reconstitute.”
I agree. Like, we see in those cases, it’s not as easy as just plugging in a decrypter. You’re still rebuilding …
Horne: Absolutely. You’ve still got to rebuild.
Leatherman: … you’re decrypting your stuff. It’s not as easy. And we’ve seen folks who have paid a ransom and gotten the decryption key who’ve then said it’s actually just still easier to reconstitute from backup at this point. It’s too complex.
So, I think there has to be a mindset shift, like you said, around, “How do we get to the place where we don’t rely on bad actors, give us access to our data back?”
Horne: Absolutely. And then acceptance that if you’re hit by a ransomware attack that has encrypted all your systems, it’s going to take weeks or months to recover, regardless of whether you pay a ransom or not. So, you need to be in a position where you have those backups that are secure.
And a key question is, “Could my systems administrator delete my backups?” Because that’s what the attackers try and do. They try and become the systems administrator.
Leatherman: They get privileged access, which they know gives them the keys to the kingdom at that point.
Horne: So, having those backups that are immutable, but also having thought through the plan and even having some environment in place to be able to recover those backups. I often say to people, “If you’ve got my DNA, it doesn’t mean you can clone me.” It’s like, “Yeah, this having my data doesn’t mean you’ve got a working version of me overnight.”
There are a lot of steps to be taken, and it’s a bit like that with recovering IT after a destructive attack. Just having the data isn’t enough. You have to sort through all the steps how you turn that data into a working model.
Leatherman: And practice it.
Horne: And practice it.
Leatherman: And practice it, because nothing goes as planned. And so, being able to have your incident response plan work through it with all stakeholders and practice is incredibly important to find where those gaps are.
You know, in ransomware; it was interesting. On my way to Cyber UK, I had an opportunity to meet with CISOs in industry during a roundtable and one of the CISOs, his organization had experienced … a significant ransomware incident, cyberattack. And it struck me when he said, “You know, we were living through crisis and two of the folks who work for me in doing the incident response and recovery were hospitalized as a result of that.” Just the physical toll that that had taken on the defenders. We don’t often think about kind of the welfare of the workforce when it comes to this.
You had some unconventional voices at Cyber UK, which I really enjoyed. Folks who were maybe not CISOs or government officials, who came in to talk through different topics that had direct correlation to cybersecurity and the work that we do, but weren’t technical topics necessarily.
So, Margaret Heffernan opened the conference on willful blindness, which I thought was fascinating. But then you had a session from the … Red Cross, where they spoke about leading through crisis. Can you talk a little bit about that and kind of the thought process behind bringing the Red Cross?
Horne: Yes, absolutely. So, the Margaret Heffernan one was really interesting because I’ve been really struck by boards just not understanding the risks they’re facing in cybersecurity. And it’s almost like the sort of systemic blindness to failing to sort of being able to judge the risks they’re carrying.
So, this lady, Margaret Heffernan, talks about willful blindness and how leaders of organizations can be in a position where they don’t see the crocodiles that close to the canoe. So, that was a really powerful session. So, that was one.
And then the one you were referring to … I’ve had several, big ransomware attacks where I often sort of end up having a weekly call with the CEO [chief executive officer] just to check in with them, and it becomes quite therapeutic in a way, because there’s no one else they can talk to, just at a sort of personal level.
And, you know, I’ve been really struck by the strain on them and the strain on the organization at a human level of an organization that wasn’t expecting to be in that kind of pressured situation, and especially the IT departments and the security departments that are right in the middle of it and this sort of crucible of pressure. And they’re just, as people, they’re not prepared for that pressure and not armed with the ability to be resilient.
And there was a CEO of one company, Keri Gilder, who I was talking to, and she was describing this sort of pressure that she and the teams felt and the impact it had on them as people. And I talked to her about, “Well, wouldn’t it be interesting?” And this was her suggestion, “Wouldn’t it be interesting to get someone who works in an organization where their whole organization is designed to deal with those traumatic situations and pressure and compare how do you prepare your people for that?”
So, we ended up finding an amazing lady called Elsaba from International Committee of Red Cross. So, I had the two of them in conversation talking about the pressure of recovering from a ransomware attack, coupled with Els talking about how do we prepare our people for the trauma of going into warzones, seeing all the things, dealing with all the pressure that you get with that?
And you know, how do you prepare your people for that? And how do you … what is the social contract? Because with many of our IT staff, there’s an almost implicit social contract of it’s a 9-to-5 job. You know you’re not going to be required to come in the office and sleep in the office every day for three months kind of thing, but actually that is where many organizations end up finding themselves.
So, how do you prepare your people for that, and how do you put the right constructs in place so that you can manage through in a way that kind of safeguards your people, as well as safeguarding your business?
Leatherman: It’s interesting. What I often say to folks in industry who suffer breaches, one of the value propositions that we bring in the FBI is we deal with crisis 365 days a year, right? I mean, it doesn’t matter if it’s counterterrorism, criminal investigations, like our agents, our analysts, our folks are kind of geared for that. And our goal is to bring some calm to the crisis in a cyber incident.
And I think leveraging that mindset … no private-sector company is probably equipped to go through crisis like a ransomware event where you just are looking around the corner, you know, nights and weekends to see is the actor still here? Have they persisted? Have they moved laterally? Do they still have access to the environment? But leveraging those who have that experience is important because they can help you understand systemically.
Like, “What are we doing next?” You know, the FBI teams are used to working in command post postures. Crisis happens; we immediately set up a command post, and then we start to think through shifts and scheduling out multiple days in advance. “Who are the other agencies who offer mutual aid who might come in and provide help to us?”
We kind of prepare for that. And so, I think that that perspective is important and the best time to think about that is before the breach.
Horne: Absolutely.
Leatherman: And having the conversations, you know, with organizations like the Red Cross or with the FBI or with the NCSC, who are used to kind of seeing reps around the crisis. And that’s what struck me about this session, was it really made it accessible to those who were listening and probably was a first heard for many of them.
Is that kind of what you hear that that is not something, at least in the UK, that organizations are thinking through? Is that crisis in the health and welfare of the employees?
Horne: Absolutely. I think … and you do see a lot of organizations where they’ll do like a board exercise, and they’ll have exercised the first 24 hours quite effectively. “Who we’re going to call? What’s our first message going to be to the public?” And all those kind of things? Yeah, they kind of have thought that through, but haven’t really thought through the long term.
“How do we manage three months of crisis?” And exactly as you were saying, “How do we … put the right structures in place, rotors, the ability to swap people in and out? Those kind of things to make it a manageable experience for three months of rebuilding our organization and getting back on our feet.? And it’s that kind of structured thinking up front that’s so important.
And that’s where getting Els’ view from the International Red Cross. How you, how you think through that in advance and how you create the right structures around people. And interesting the conversations I’ve had with CEOs of companies that’ve been hit by big cyber attacks where, you know, they realized that once you get to the end of that three months and you’re kind of back on your feet and the adrenaline sort of rush goes from everywhere, that’s when often you see sort of impact on people as well.
And again, comparing that with how the International Committee of the Red Cross supports people coming back from traumatic situations, it’s really interesting learning the parallels and seeing how you can learn from organizations that deal with traumatic situations as part of their daily life.
Leatherman: Yeah, I mean, we look at it is ensuring people get the rest they need, maybe not necessarily just during the crisis, but post-crisis, because that’s kind of when the let-down period, where you kind of lose that adrenaline of what happened in that crisis mindset and things start to hit home. And you have kind of some trauma associated with that.
So, very, very great perspective. And I think you guys have put some… guidance out there previously on kind of the welfare of the workforce that I would encourage folks to take a look at on your website.
And certainly, kind of going back to Margaret’s speech, that was eye opening to me, too, because the idea of willful blindness is … we see something, maybe we should say something, but we don’t necessarily understand it.
So, I’m going to assume somebody else is dealing with it, right? And that is kind of in … a lot of people would say, “Well, I’m not making a choice there. I see it as somebody else’s problem, but we’re making a choice to ignore it.”
And I talked to my teams at FBI Cyber really about kind of radical ownership. Until you understand, it doesn’t matter if it’s part of your job or not, if you see an issue, until there’s a positive hand-off with somebody else, own the issue, that’s now your issue until we hand it off to somebody who can acknowledge it and is going to take ownership of that.
Kind of talk through your thoughts around bringing Margaret on, and kind of what you see in industry and what you hope they get out of Margaret’s message, which I think is going to … is either out there already or is going to be.
Horne: It is out there already. So, yeah, all of our kind of big plenary sessions, like the, the one we were talked about and the one with Margaret, are on our CyberUK TV channel, which is on YouTube. So yeah, do search for that. And we really wanted to create a kind of a resource for people to use with their organizations.
Because I’m really aware. Yeah. I mean, spent time in industry myself. Being a CISO is a lonely place. You see all the issues across your organization that are way beyond you. You can’t support them, and you need leadership support across the organization to get them sorted.
And we wanted to try and create a sort of a resource that people could use in their organizations to help their wider organizations understand that, you know, this willful blindness thing might be going on here around our technology risk and our digital risk, and to sort of help equip CISOs with the ability to have the conversation with their organization about, “This is bigger than me. I need the whole organization to lean into managing our digital risk, of which cybersecurity is a big part of. It’s not just about me. It’s about the whole organization and I need to get you all kind of helping me manage this risk and leading this risk.
So that was kind of the thinking behind it. So, how do you how do you address that cultural challenge and get a cultural shift, not just to sort of dealing with the bits and bytes?
Leatherman: Yeah, I have a Cyber Division leadership retreat coming up and certainly now that that is out on the YouTube channel, I think that is just germane to anybody who works in this space, whether you’re in government, law enforcement, or industry, to kind of listen through ownership and what you see and your visibility and providing … both accountability and empowering your CISO or others to take responsibility or share things with you as well and ways that you can, enter into discussions and support them.
Let’s … kind of circle back to where we started here, which was the NCSC and GCHQ’s role in the UK government and the FBI’s role. And this idea that offense informs defense. And you said in your speech, “In cyberspace, offense is a critical part of defense.”
What did you mean by that?
Horne: Yeah. So, I did a talk at the RSA conference and talked quite a bit about this. Where this, this idea of sort of, you know … people often talk about sort of the contest we’re in is almost like a wrestling match or something like that, whereas I think it’s more like a team sport match, something like basketball, for example.
I grew up playing basketball, surprisingly, given my height, in the UK and you know, the idea of a full court press, where offense and defense are kind of the same, and it’s a fluid motion between defending on your goal line straight through to getting the ball in the net the other end. And there’s this fluidity between offense and defense.
And they’re the same thing, it’s just a contest. And offense and defense sort of playing together all the time. And the idea of how do we construct that full court press as a collective, as government, as intelligence agencies, as law enforcement, as industry, as tech providers, academia, you know, how do we create this full court press where we’re defending on our goal line at the same time as putting the ball in the net, the other end? And that sort of holistic view of cyber defense, I think is really important.
Leatherman: It’s increasingly persistent engagement in cyberspace, right? It’s … kind of moving quickly to where we see the threat manifest itself and then also alerting folks as to where we’re seeing the threat manifest itself.
So, I often talk about, you know, our work to remove capacity and capability of the actors from infrastructure, to out their malware to out their TTPs [tactics, techniques and procedures] and IOCs [indicators of compromise], those things are part and parcel to each other, really.
And, there’s very few agencies in the UK and the U.S. that have that mission that allow us to lawfully go up and collect and identify and disrupt. And it’s incumbent upon us—I think our populations expect it—that we’re sharing that intelligence, and just this last week, I think we coauthored two different advisories together on PRC-based [People’s Republic of China] actors and other things.
And increasingly, we’re trying to do that quickly in a way that helps us distill, again, very quickly what we’re seeing into actionable ways industry can understand context around a threat and defend against it. You guys led this last one, which was an incredibly impactful one on, you know, residential proxy networks and obfuscation networks leveraged by PRC actors.
What would you recommend as far as organizations developing a threat intelligence program that centers around some of this offensive, defensive cyber intelligence that we put out there?
Horne: Yeah. So, I think it’s so important that we can … we can get those advisories out there. We get people acting on them quickly and giving us feedback because, you know, we will see certain things, either from incidents that we’ve worked on or from intelligence we’ve gained in the file space, as it were.
By feeding that into defenders in their home turf and getting them to look for it and identify more of the picture, they can feed that back to us.
And we can then identify ways to intervene in the mid space, in cloud or telco environment, or more we could do in the file space. And you create this sort of continuous, virtuous cycle of sort of intelligence here, feeding action here, which then generates more intelligence, which can feed action here, which then generates more intelligence and that sort of that continual feedback is so important.
And creating that cycle and the opportunity to use AI within that picture to make it quicker and more real-time and of thinking is there’s a really exciting opportunity for us as nations and, you know, as sort of democratic societies to position ourselves so well in the new world where we’re walking into. And we don’t know that whole picture, but we know the opportunity and that kind of cycle we can create.
Leatherman: But it takes all of us. Like … in that same advisory I just talked about, we called out that you know, technology companies in China are helping them broker access to our environments.
So, we talked early on about the importance of industry and victims engaging with us early and often on this stuff. It kind of goes to that willful blindness conversation we had, right? You know, in industry, you’ve been drafted into the fight. Unfortunately, you’ve been drafted into the fight. Right? So sharing is a key part of that. And, really that radical ownership in industry is what we would ask as well.
Where can folks get these alerts? Where can they look to get this threat intelligence from NCSC in the UK, the UK government?
Horne: Yeah. So, our website, NCSC.Gov.UK, is where, you know, we put everything there. And yeah, for organizations in the UK that are parts of key sectors, we have trust groups that they can be part of, more of a conversation. And then we have various other schemes that they can work with us. But the key thing is sort of, you know, our website, our trust groups, our engagement through there in a similar way as you have over here.
Leatherman: Great. Thank you, Richard, really appreciate it. I know you’ve got a busy week lined up here with engagement, with partnerships, but I know the audience will appreciate your perspective, and I appreciate it, as always, the partnership that we share with you guys.
So, thank you for coming into the bowels of the J. Edgar Hoover Building here in Washington, D.C. And thank you for joining us now.
Horne: Thank you. We really appreciate the partnership that we have with you and, you know, across the Atlantic. So, thank you.
Leatherman: Great. Well, that’s Richard Horne, CEO of the UK’s National Cyber Security Centre, joining us today to talk AI, the importance of fundamentals. And we’ve talked about this throughout the Operation Winter SHIELD campaign that the fundamentals really matter.
And over the next few months they’re going to matter—and years—they’re going to matter more and more as we see actors start to leverage AI in support of enumeration and other technical operations.
Thank you for joining us. We look forward to seeing you next time on “Ahead of the Threat.” I’m Brett Leatherman, assistant director for FBI’s Cyber Division. We’ll see you next time.