
Consent is not optional.
Dave Bittner: Hello, everyone, and welcome to "Caveat," N2K CyberWire's privacy, surveillance law, and policy podcast. I'm Dave Bittner, and joining me is my co-host, Ben Yelin, from the University of Maryland Center for Cyber Health and Hazard Strategies. Hey, there, Ben.
Ben Yelin: Hello, Dave.
Dave Bittner: On today's show, Ben and I discuss the ongoing saga of Grok and its ability to create nonconsensual nudes. And later in the show, my conversation with Caitlin Clarke, Senior Director for Cybersecurity Services at Venable. We're discussing CISA 2015. While this show covers legal topics and Ben is a lawyer, the views expressed do not constitute legal advice. For official legal advice on any of the topics we cover, please contact your attorney. [ Music ] All right, Ben, let's jump in here. There's one story that's been kind of -- well, that's not fair to say there's one story that's been dominating the news, one of -- [laughs]
Ben Yelin: In our world at least.
Dave Bittner: There's one story relative to us that has been dominating the news. It's been a noisy week for news all around. But I think it's fair to say that these issues with Grok have really caught the attention of a lot of folks, and there's certainly some interesting policy issues at play here. Go ahead.
Ben Yelin: Yeah, it was kind of a news dump, because the story starts on Christmas Eve when everybody's paying attention to hanging out with their in-laws, right, and maybe watching football or basketball. But on that night, Elon Musk announced new image and video editing capabilities for Grok, which is the AI chatbot developed by Musk's AI company, xAI.
Dave Bittner: Mm-hmm.
Ben Yelin: I will say, as a prominent X user, a self-hating X user in many circumstances, Grok is pretty good. Oftentimes, like Musk gets frustrated because he holds a lot of false beliefs about things, and Grok is good enough as a chatbot that it contradicts Musk frequently.
Dave Bittner: Right. Right.
Ben Yelin: So he's tried to kind of alter it to align more with his bizarre views on various things.
Dave Bittner: Yeah.
Ben Yelin: But as a chatbot, I found it to be pretty effective.
Dave Bittner: Yeah.
Ben Yelin: But --
Dave Bittner: Can I just give you my regular ribbing of you that why the hell are you still on that platform, Ben? What's it going to take?
Ben Yelin: Part of it is network effects where all of the people that I enjoy following, the people that provide news that's useful to me are still on there. So unless all of us leave and go somewhere else, I feel like I need to stay there. I also found Bluesky to be a little insular. I think it's important to hear views from a bunch of different perspectives, and how as awful as X has become -- and in many ways, it's very awful -- there's a lot of antisemitism, casual antisemitism on there.
Dave Bittner: Yeah.
Ben Yelin: You know, I also don't want it to be a dominant platform that has -- that also becomes insular, just in the other direction. So I think it's important to have diverse voices on there. But yes, I definitely hate myself for being on there and --
Dave Bittner: [laughs] I will continue to give you a hard time about it --
Ben Yelin: Let's just say my --
Dave Bittner: -- until you see the light.
Ben Yelin: -- New Year's resolution this year may have had to do with spending less time on X. And --
Dave Bittner: Yeah.
Ben Yelin: -- we're just a couple weeks into the new year and so far, I have not been very successful.
Dave Bittner: I'm very happy over on Mastodon, I have to say.
Ben Yelin: You're still a Mastodon guy, huh?
Dave Bittner: Yep, yep. That's my version of that of choice.
Ben Yelin: I mean, the way I think about it is like you've been going to the same neighborhood bar for 20 years and all of your friends go to that bar.
Dave Bittner: Yeah.
Ben Yelin: And maybe kind of a --
Dave Bittner: And then one day it becomes a Nazi bar and you keep going? [laughs]
Ben Yelin: Right. It's a dump and the -- you know, the owner has maybe put up some paraphernalia --
Dave Bittner: Mm-hmm.
Ben Yelin: -- of past fascist groups.
Dave Bittner: Mm-hmm.
Ben Yelin: But it's your bar, you've been going there.
Dave Bittner: Okay. So you're hanging -- okay. [laughs]
Ben Yelin: I guess that does not -- yeah, that does not make --
Dave Bittner: You've got --
Ben Yelin: -- things seem better, does it?
Dave Bittner: All right. Well, you know, it's not my job to tell you what to do, but I will shame you relentlessly until you change your ways. I think so. [laughs]
Ben Yelin: Yeah, maybe a few more months of shaming.
Dave Bittner: Right. Right.
Ben Yelin: Now, I know I would feel better mental health-wise if I did leave.
Dave Bittner: Yes. Yes.
Ben Yelin: So --
Dave Bittner: Absolutely.
Ben Yelin: -- maybe you can convince me.
Dave Bittner: That was my experience. Anyway, so we are keying a lot of our conversation here from an editorial that Riana Pfefferkorn wrote for the "New York Times". Riana's been a guest on this show, and certainly a well-respected person in the tech space. She's a former tech lawyer and currently a policy fellow at the Stanford Institute for Human-Centered AI, and someone whose opinions I respect. So she wrote about this issue with Grok. So let's jump back in here. What did Grok start doing that has caught everyone's attention here, Ben?
Ben Yelin: So they introduced new image and video editing capabilities. Basically, users can prompt Grok to edit photos of people in a way that can sometimes present offensive material or most consequentially CISAM. So basically, what happens is anybody can ask Grok -- if there's a photo that they've uploaded or just that they see online, you can ask Grok to remove all of the clothing. And you can't -- I guess you can't make it naked, but you can say, "Portray this person in a bikini."
Dave Bittner: Hmm.
Ben Yelin: Now, it's very funny when everybody has portrayed Elon Musk himself in a bikini. [laughter] That's an image I wish I had not seen.
Dave Bittner: Right.
Ben Yelin: But there are very few guardrails here. Grok obviously they will filter for actual pornography, but for the most part, they are complying with these requests. And because people are degenerate, a lot of people are requesting these types of sexualized images, and that's raising significant concerns, both in the United States and abroad, and prompting questions about the legal response. And it's kind of a gray area, where especially in the United States, I don't think there's any law that would mandate that the service be taken down. Again, like the images that are being produced as a result of this change are not by definition pornographic in nature.
Dave Bittner: Mm-hmm.
Ben Yelin: If you're going by the "I know it if I see it," standard, you're going to be unsatisfied because it's kind of in that gray area where you don't know where the line is. It's definitely sparked public outrage in certain corners, and I think has the potential to do reputational damage to Grok, to X, and maybe to Musk, although I don't think he particularly cares that much.
Dave Bittner: Yeah. What about laws against nonconsensual sexual imagery? Wouldn't this fall into that?
Ben Yelin: Yeah, so things like COPPA could potentially apply. But first of all, it's very hard to enforce. And second, if it's an image of you that's nonconsensual, under COPPA, you can have that taken down. But oftentimes, we see stock photos, or most notably, and I think critically for our purposes, photos generated through the use of AI.
Dave Bittner: Hmm.
Ben Yelin: So they are not depicting actual human beings, even before you give it the prompt that says, "Put this person in a bikini." But the images themselves, because they appeal to prurient interest, are still offensive. Just because it's not portraying a real child, it's still something that's bad and as a society we don't want to see on a very public platform like this.
Dave Bittner: Hmm.
Ben Yelin: So we've seen countries take action, not our country necessarily. Indonesia and Malaysia temporarily blocked access to Grok. I've been following developments in the UK --
Dave Bittner: Yeah.
Ben Yelin: -- where they have this child online safety law called the "Online Safety Act," and the relevant regulator in the UK has started to investigate X, claiming that their laws requiring platforms to block illegal content might end up applying in these circumstances, because there's been a, quote, "Proliferation of undressed images of people that may amount to intimate image abuse, pornography, and child sexual abuse material on X." And as a result, the UK government through this investigation is threatening significant fines on Grok, which they could do, they could impose significant fines or they could ban it in the UK. And Musk and Grok -- or xAI seem to be cooperating with the investigation. But there is a small chance that Grok as an application could be banned in the United Kingdom. And that's obviously a very large market. And it just kind of underscores this conflict between we love capabilities that AI image and video editing provide us, but without these guardrails, we can start to see things that are offensive and are going to raise the ire of regulators across the world.
Dave Bittner: So Elon is saying that this is a free speech issue, that it amounts to censorship, the demands to take these things down. Does that hold water? Does creating and sharing images of minors in, I don't know, provocative outfits, does that fall under free speech, or is that that gray area?
Ben Yelin: I think it depends on how you define "free speech". We have more robust free speech protections in the United States, but I will implore everybody to not use the crowded in a -- or yelling, "Fire" in a crowded theater thing. As you know, that's been one of my longtime hobby horses.
Dave Bittner: [laughs] Right.
Ben Yelin: But there are restrictions on speech in the United States, and one of them is on child pornography, which is not protected by the First Amendment. Again, this is not very clearly child pornography. I think you could make the argument that it is CISAM-adjacent, in which case, it might not enjoy constitutional protection. But we do have -- in the interest of having a marketplace of ideas and freedom of expression, we do have robust First Amendment rights in the United States. Those do not exist in the UK.
Dave Bittner: Hmm.
Ben Yelin: And we've seen that in a bunch of circumstances. I think you and I have covered a bunch of stories about --
Dave Bittner: Yeah, yeah.
Ben Yelin: -- just in the name of online safety, people are getting arrested for hate speech, which except under very limited circumstances does not happen in the United States. It's been a major drag on the governing party, the Labour Party in the UK. They're about as popular right now as -- I don't know. I'm trying to think of something stereotypically British that's deeply unpopular. [laughter] It's as unpopular as fish and chips without a side of vinegar. I don't know. Let's just say that they're very unpopular.
Dave Bittner: Right, okay.
Ben Yelin: And I think this effort to basically arrest people under these laws that in the United States would violate free speech principles is one contributing factor --
Dave Bittner: Mm-hmm.
Ben Yelin: -- to their unpopularity.
Dave Bittner: What about the fact that Grok is limiting some of these image-generation requests to paid subscribers? That strikes me as odd, an odd response.
Ben Yelin: Yeah. I find that very odd. I think Musk and kind of his entrepreneurial spirit is always trying to nickel and dime users, and so that any advantage he can give to paid subscribers even for features that had previously been free -- over time since he's owned xAI and since he's owned X, the platform, he's put a lot of functionality behind the paywall. But yeah, that doesn't -- I mean, I guess it could potentially limit distribution, and it could limit the number of people who are able to create these images. But it doesn't really address the policy issues here. Just because you pay eight dollars and can produce these images --
Dave Bittner: Right. [laughs]
Ben Yelin: -- eight dollars a month, by the way --
Dave Bittner: Right.
Ben Yelin: -- doesn't change things from a legal perspective or a constitutional perspective.
Dave Bittner: Yeah.
Ben Yelin: And I think a lot of people have contrasted this with another Grok controversy from last year when Grok was producing offensive political speech. Some of this is so dark, but it still cracks me up. Like Grok got to the point -- I think, because Musk engineered the AI to be less politically correct --
Dave Bittner: Mm-hmm.
Ben Yelin: -- and he just like turned the dials too far, so people would give Grok prompts like, "Who is a person from the 20th century that is worth admiring?" And it would be like, "Adolph Hitler."
Dave Bittner: Right. [laughs] Right, right.
Ben Yelin: So that was a big controversy last year.
Dave Bittner: Right. Yes, I remember. Yeah.
Ben Yelin: And I think it's interesting that xAI moved faster to intervene and to try and counteract the AI when that happened, as opposed to right now when they're cooperating with the investigation in the UK, but they've been slow to act. And just limiting it to premium members is certainly only a small step in ameliorating this problem.
Dave Bittner: Yeah. One of the things that Riana Pfefferkorn points out in her editorial here for "The Times" is that there's kind of a legal Catch-22 for AI safety that a researcher can't test this stuff without potentially being charged with a crime. If you -- in other words, testing to see if these AI models can create CISAM images can put you -- can get you in the slammer for just even trying.
Ben Yelin: This is so interesting to me, and I don't know what a good solution is here. Because in every other context, I think red teaming is very important. I don't know, Dave, in these circumstances, like do we want researchers, whomever they are, to ever see these types of images, and especially if there's a risk of images that are generated as part of red teaming is research just getting out into the ether and being viewable by the general public.
Dave Bittner: Well, I -- what's the -- what is it, the National Center for Missing and Exploited Children, aren't they the -- they're the group that sort of heads up our nation's fight against this sort of thing?
Ben Yelin: Yep.
Dave Bittner: They're protected, aren't they? I mean, in other words, if they -- in their work, evidence gets presented to them. The fact that they're possessing that evidence, as horrific as it may be, everyone says, "Okay, this is a good organization. You know, obviously, they're not the bad guys here. So we're not going to go after them for possessing this sort of thing when it's in -- when it's, you know, part of their work." So I guess what I'm saying is it seems to me like there are safe harbors that have been reasonably carved out, and, you know, maybe that organization has their own red team in house that -- to test these sorts of things and they're the ones who get, you know, approved to do it, as horrible a job as that would be for anybody.
Ben Yelin: Yeah, I think that's probably the best solution, but that's not something that's codified in statute. So there is no statutory safe harbor for good faith AI safety testing in the United States. Congress could create that if they ever got around to regulating AI --
Dave Bittner: Oh, okay.
Ben Yelin: -- which they'll get to as soon as we see the data privacy bill they've been working on for the past decade.
Dave Bittner: [laughs] Right. Right. Well, yeah, I guess -- I mean, my initial thought when you said that of Congress working on that is I guess any congressperson who brings something like this up could be accused of being soft on CISAM --
Ben Yelin: Yes.
Dave Bittner: -- right? So --
Ben Yelin: They can and will be accused, mm-hmm.
Dave Bittner: Right. So it has to be rolled into a larger AI bill. It strikes me it can't be the main thing.
Ben Yelin: Right. I mean, if you look back and think about Section 230, that was part of a bill to protect decency online. Even though there was a provision there shielding platforms from liability, it was part of a larger law that was called the "Communications Decency Act". So I think you'd have to do something like that, like in the context of other robust regulations, particularly relating to children, you put some provision in there calling for that safe harbor. But I also -- I understand it. I understand why legislators would be nervous about providing that good-faith exception for red teaming, because you might end up seeing a lot of cases where somebody is claiming that they were only viewing these images as part of a red teaming effort and, you know, it's hard to know when that's true and when it isn't.
Dave Bittner: Yeah.
Ben Yelin: I watch a lot of -- you know the old sting operation shows with Chris Hansen?
Dave Bittner: Oh, right, "To Catch a Predator," or whatever?
Ben Yelin: "To Catch a Predator," yeah.
Dave Bittner: Yeah, yeah, yeah.
Ben Yelin: I've gone down a rabbit hole and --
Dave Bittner: Really. [laughs]
Ben Yelin: I mean, they're more of just -- it's also like probably something I should not be doing, just like my X addiction, because it's trash television.
Dave Bittner: Yeah.
Ben Yelin: But in all of those, like he catches the predator. He has somebody pose as somebody underage online and go invite that person over to a house that's really a sting house, and Chris Hansen will come and catch that and say, "Why did you come here," like, "Why -- were you intending on doing this to somebody who's 15 years old?" And in so many of these episodes, the person was like, "Oh, I was just trying to protect them."
Dave Bittner: Mmm.
Ben Yelin: Like, "I wanted to come over and make sure this person I was talking to online was okay."
Dave Bittner: Mm-hmm.
Ben Yelin: Now, that generally doesn't fly in the show or in the legal system, but it could make cases more complicated in this context where somebody says like, "Oh, I was just red teaming, like, this -- you know, I didn't possess these images. I was simply doing research to improve the filtering system on Grok AI to ensure that we're not putting children in bikinis." So that's something that I would be concerned about.
Dave Bittner: I'm reminded -- I had a friend of mine who at a point in his career was the executive director of a YMCA, right? So they had athletic facilities, swimming pools, all that kind of stuff. And he made the point that you have to hire a locker room attendant, right? But you don't want to hire the person who really wants to be a locker room attendant.
Ben Yelin: [laughs] Yep.
Dave Bittner: Right?
Ben Yelin: Yeah. Yeah, you have to hire somebody who's reluctant --
Dave Bittner: Yeah.
Ben Yelin: -- to be the locker room attendant, you know?
Dave Bittner: Right. Right. Let me ask you this, if -- what legal recourse do I have if I'm the parent of a 12-year-old and some stranger takes a picture of my kid at summer camp and runs it through Grok and puts them in a bikini in some sort of seductive pose? What can I do about that?
Ben Yelin: So you could -- under the Children's Online Privacy Protection Act, parents have the right for children -- any children under 13 to request deletion online. So you could request deletion of that image. It gets complicated when like AI alters the image enough that the image is no longer recognizable.
Dave Bittner: Mm-hmm.
Ben Yelin: And it's hard to know exactly how courts or even xAI itself is going to deal with those issues. Of course, the big problem with COPPA, not just here, but in other contexts, it only applies to children under 13 years old.
Dave Bittner: Hmm.
Ben Yelin: So there are some other laws that might be applicable, but there have been a lot of efforts to extend COPPA's protection to children up until 17 years old, which I think is more appropriate, given the rest of our legal system and how it treats people who are minors. But also, there has been federal regulation applying COPPA to altered images through the use of AI. So as long as the image is still recognizable, parents can exercise that right to review and have that image deleted.
Dave Bittner: Could I sue?
Ben Yelin: COPPA does not have a private right of action. You could use a violation of COPPA for a state-level claim, like it breaks state consumer privacy protection laws. But there's no private right of action that allows people to sue for COPPA violations. Other laws do grant federal agencies -- or other laws do grant private individuals the right to bring a lawsuit, but not that particular statute.
Dave Bittner: Hmm, okay. So again, what we really need is privacy legislation, right? [laughs]
Ben Yelin: Yeah. Yeah, and privacy legislation in the age of AI that contends with these types of problems where it's not exactly the original image that was uploaded, but it's been altered by AI and altered in a way that makes a completely innocuous image something that's at the very least sexually suggestive.
Dave Bittner: Yeah. Seems to me like this is an area where there would be broad support of erring on the side of not allowing this, right, you know?
Ben Yelin: Yeah. Yeah, I mean --
Dave Bittner: And yet, here we are.
Ben Yelin: So I do think there is a legitimate pro free speech, pro free expression side that says there's always a slippery slope when somebody goes -- what's Reverend Lovejoy's wife in "The Simpsons" --
Dave Bittner: Right, "Think of the children."
Ben Yelin: -- once -- "Could somebody think of the children," yeah.
Dave Bittner: [laughs] Right. Right.
Ben Yelin: And I understand that as a perspective. I think it's useful to have that perspective. But yeah, I mean, for me when we're talking about children, I do think erring on the side of caution is always prudent. So that's the way I've come down, but I also understand people who don't want restrictive laws simply because those laws are drafted in the name of protecting children.
Dave Bittner: Yeah. All right, well, we will have a link to that story in our show notes. Again, it's an editorial from Riana Pfefferkorn, who has been a guest on this show, so I highly suggest you go look up the episode that she was with us here, always a good guest and someone whose work is always worth checking out. I'll tell you what, there's a lot more to this, but before we get to that, let's take a quick break to hear from our show sponsor. [ Music ] All right, Ben, we are back. And our guest this week is Caitlin Clarke. She is Senior Director for Cybersecurity Services at Venable, also has a background working in the White House for President Obama. And our discussion we're talking about CISA 2015. This is not CISA, the Cybersecurity Information and Security Agency. This is the law CISA 2015. So here's my conversation with Caitlin Clarke.
Caitlin Clarke: I describe the Cybersecurity Information Sharing Act of 2015, which I will be very clear, I say the full acronym, so that we don't confuse it with an agency, I see it as a voluntary framework that authorizes private sector entities to monitor and operate defensive measures on its own information systems, and then authorizes those entities to share or receive cyber threat indicators with the federal government and with other private entities. And the key part of this legislation is as part of that voluntary sharing framework that there are legal protections for those who are involved in the information sharing activity so that they are protected from antitrust, from federal and state disclosure requirements, from how the US government can potentially use that information for enforcement actions. It's limited. And so it is a voluntary framework that does not require entities at all to participate, but it is -- it provides clarity and certainty around the legal environment in which information sharing can happen.
Dave Bittner: And so what did it enable? What did it allow to happen between the private sector and the government?
Caitlin Clarke: So I think it's really important to recognize that information sharing happened before the passage of this legislation in 2015. What the legislation provided was clarity around protections, as I just described, for companies who were sharing information. So if I were a bank and I had information about a cyber threat that was impacting my systems or network, I could share that information with another bank through an information-sharing analysis center or other information-sharing arrangements, without fear that I am violating any, you know, antitrust rules, or that I might be sued for sharing that information with that other bank. And then with the government, it's an ability to share what you're seeing on your network with the government who's getting additional reporting in and they're able to provide a picture of potentially ongoing cyber campaigns or new tactics, techniques, and procedures that are being seen by one company that could help protect others. And so it's just -- it really sped up that process. So as I said, information sharing was happening before, but oftentimes you'd bring in your lawyers to say, "Hey, I want to share this piece of intelligence with somebody else. Can you review it and give me the permission to share?" And that would potentially take some time to get to yes --
Dave Bittner: Hmm.
Caitlin Clarke: -- or not everything could be shared, because they would -- there would be concern about, again, liability risk of sharing whatever it is that you had. The beauty of the voluntary framework is it took that discussion out of the mix. And so information sharing was sped up. You did not need to bring your lawyers into the conversation. If I was a cyber threat intelligence analyst and I had a piece of information that I thought was helpful to share with other companies or with the government, I could do so because I felt I had the clarity around sharing that information. And it just -- it sped up cyber defenses for the last 10 years.
Dave Bittner: Well, it strikes me that this was, I guess, comparatively noncontroversial. Was there anyone who came out against this sort of thing?
Caitlin Clarke: There were. There were some concerns about the types of information that may be shared, and particularly around privacy and if the -- you know, if there was any personally-identifiable information that could be incorporated into a cyber threat indicator. And Congress specifically added a requirement in the legislation in 2015 that said, "PII must be removed from any cyber threat indicator or defensive measure before it can be shared." And Congress also added language restricting the government's disclosure, and retention, and use of the cyber threat information for very specific purposes, again, for protecting federal networks or further sharing for protecting other critical infrastructure networks. So the challenge here was kind of around what could be shared under the CISA 2015 framework. And that was really addressed through Congress adding the language around requirements for removing PII.
Dave Bittner: Mm-hmm.
Caitlin Clarke: And I think I've seen a ton of OIG reports in the year since, and the inspector generals have not seen any violation of that clause in the legislation where PII was shared inappropriately, that they've seen that in fact, it is stripped out before information is shared.
Dave Bittner: Hmm. Well, how successful has it been? What -- looking back, do people consider this to be overall a good thing?
Caitlin Clarke: Yes, I think that they do. You know, again, information sharing was happening prior to the passage of this legislation in small pockets of trust, right, the telecommunication sector was sharing information, the financial sector was sharing information. But what you saw after the passage of the Cyber Information Sharing Act of 2015 was the standup of a lot more information-sharing organizations. You saw things like the Cyber Threat Alliance standoff, which is a bunch of cybersecurity companies who have a lot of telemetry and visibility across multiple companies, and they were able to share information amongst themselves, right? So it kind of -- it opened the aperture from very small circles of trust to an apparatus for cyber defense that really enables real-time sharing in many different sectors across the US economy.
Dave Bittner: Well, we had the recent government shutdown and this legislation lapsed. Where do we find ourselves today?
Caitlin Clarke: Well, since the continuing resolution was passed, the CISA 2015 authorities have been extended to the length of the continuing resolution, so the end of January 2026. What I think you saw is what -- during that lapse is what we saw prior to CISA 2015 in that --
Dave Bittner: Hmm.
Caitlin Clarke: -- information was still being shared, but there was additional friction in the process, right, because lawyers had to be brought back in. They had to -- and I work in a law firm and I love lawyers. I'm not one myself. But you know, they slow things down sometimes. It takes a while for them to do a risk assessment and get to yes. And I think that there has been some anecdotal evidence that yes, information sharing still occurred, but not as quickly as it would have occurred if the protections were clearly in place.
Dave Bittner: So what are people hoping to see going forward here? Are we looking for another 10-year renewal or something like that?
Caitlin Clarke: I think where the industry is and the community is, is at least a 10-year reauthorization. You need to have that certainty and clarity that I'm going to be sharing this information in a certain way for a significant period of time. If we continue to have like these short extensions, we're continuing to, as I just said, add friction, because people don't know when it may lapse again. So that 10-year reauthorization gives us that 10-year runway to continue to build upon where the cyber defense community is now. You know, build more tooling that might help make that more effective. How can AI fit into this and continue to speed up information sharing? That 10-year reauthorization just gives people certainty that the way that they're approaching information sharing now will be something that they can do for the next decade.
Dave Bittner: What's your sense for the likelihood of it being reauthorized?
Caitlin Clarke: I think it's positive. I think that this is something that you see a lot of everyone concurring that this is an important voluntary framework to have in place. You see the administration and National Cyber Director, Sean Cairncross, out talking about how the administration would like to see a 10-year clean reauthorization. From industry side, you have everyone's aligned, "We want to see the protection's extended." There are some questions around whether or not there should be tweaks to the language of the original bill or it should be a clean reauthorization. I personally think that if you make any changes to the bill as is, you bring in -- back in some of those questions that were debated 10 years ago, and any change, then, brings more debate about what does this work mean, whereas everyone kind of got used to, you know, what the process looked like for the last 10 years. If it ain't broke, don't fix it, just extend the time.
Dave Bittner: Right.
Caitlin Clarke: And so I do think that you're seeing a lot of bipartisan support for the fact that this does need to get done.
Dave Bittner: Well, you are Senior Director for Cybersecurity Services at Venable, as you mentioned. But before that, you served in the White House with the National Security Council. What insights can you share from your time there?
Caitlin Clarke: So yes, I had the opportunity to serve as Senior Director for Cyber and Emerging Tech on the National Security Council, where part of my portfolio was incident response. And I think it's important to frame the conversation around CISA 2015 and the authorities, and how that helps enable -- how that enables incident response, you know, getting an understanding of the tactics, techniques, and procedures where people were successful in attacks on critical infrastructure, understanding how that worked, and then turning that around and getting it out more broadly to the community at large. I was always very concerned around the companies that may not have the most resources to spend on cybersecurity. And so getting them actionable information in clear steps that they could take to prevent or mitigate risk was the most important thing to me, and I think continues to be important to this administration about getting information into the hands of the people who need it as quickly as you can, with as much context and actionable information as you could possibly have. And like that was really what drove me in that role was, well, we may not be able to prevent every incident, but how can we mitigate the risk of future incidents and learn from every single one?
Dave Bittner: What was the transition like for you to go from all those years of public service back over to the private sector?
Caitlin Clarke: So I've made the transition once before. I spent many years in the Department of Homeland Security at the start of my career, and then left and went to the corporate side of the house in an internal information security, or EO, the information security organization of a large company. And so that was eye-opening going from now where the US government were putting out the guidance and the best practices and here's the information, and then being on the other side and receiving that information and having to actually implement it. And that's where I got the like -- my love of action of, "Thank you for the guidance. What are the steps I should be taking?" Right?
Dave Bittner: Yeah.
Caitlin Clarke: I've got a lot on my plate. And, you know, I'm saying, "I" here, but I -- this -- I can imagine in many companies around the country you've got a lot of information coming in. You only have so many resources, so understanding the risk and how to prioritize action against the potential risk so that you can focus on high-impact actions that will mitigate the most risk for your organization. And I also learned how to speak business because it's definitely a different conversation than in government. You know, operational risk, and business risk, and financial risk was not necessarily the way that I talked when I was in US government. And then I spent four years in the corporate side of the things, and then I thought, "Well, you know what, maybe I should bring -- maybe I should go back to government, because now I speak both.
Dave Bittner: Hmm.
Caitlin Clarke: And I can straddle that line of, 'Okay, so if we're going to put this out, here's how this will be received by people on the other end, and what does this actually mean in practice to security teams if they were to receive certain, you know, bulletins or advisories'?" And then, you know, I've been able to move that back into my new role. And again, I kind of see myself as, I don't know, like a Rosetta Stone between --
Dave Bittner: Yeah. [laughs]
Caitlin Clarke: -- government and private sector --
Dave Bittner: Right, right.
Caitlin Clarke: -- and speak both; a translator, if you will. I also -- you know, I'm not a hands-on keyboard computer engineer developer, coder, or anything like that. But what I was able to do -- and this is my other translator position, is I understood enough of the technology and what my hands-on keyboard defenders were doing to be able to translate that to a nontechnical staff --
Dave Bittner: Hmm.
Caitlin Clarke: -- which is what you find in most companies. It's what you find in the government. Right, when you're going to talk to, you know, a CEO, or a department head, or, you know, a secretary, or a deputy secretary, they don't know indicators of compromise, indicators of attack, what -- you know, what an IP address means. And, you know, there's just a lot of information that could be coming at them, and being able to help people understand, "Here's what -- here's how you explain the risks that you face in the way that will be received by the audience." And that is something that I've tried to work hard on in my career and hopefully I've been successful, and I look forward to continuing to try to be successful in that role. [ Music ]
Dave Bittner: Ben, what do you think?
Ben Yelin: Yeah, I think it's really interesting. I measure, CISA 2015 was temporarily extended, but it's been -- I wouldn't say on the chopping block, but it's been threatened, and Congress has had to renew it temporarily attaching it to appropriations bills. And we've talked a lot about what the consequences of that would be. This is all voluntary information sharing and I think having that public-private collaboration is so critically important, so yep, it's good conversation.
Dave Bittner: Absolutely. All right, well again, our thanks to Caitlin Clarke from Venable for joining us. We do appreciate her taking the time. [ Music ] And that is "Caveat," brought to you by N2K CyberWire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly-changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes, or send an email to caveat@n2k.com. This episode is produced by Liz Stokes. Our executive producer is Jennifer Eiben. The show is mixed by Tre Hester. Peter Kilpe is our publisher. I'm Dave Bittner --
Ben Yelin: And I'm Ben Yelin.
Dave Bittner: -- thanks for listening. [ Music ]

