Caveat 2.5.26
Ep 294 | 2.5.26

The algorithm is writing the rulebook now.

Transcript

Dave Bittner: Hello, everyone, and welcome to "Caveat", N2K CyberWire's Privacy Surveillance Law and Policy podcast. I'm Dave Bittner, and joining me is my cohost Ben Yelin from the University of Maryland's Center for Cyber Health and Hazard Strategies. Hey there, Ben.

Ben Yelin: Hello, Dave.

 

Dave Bittner: On today's show, Ben has the story of the promise of AI to automate compliance. I've got reports that the Trump administration plans on using AI to write federal regulations. And later in the show, my conversation with Tony Scott, CEO of Intrusion and a former federal CIO, he's sharing his perspective on evolving regulation and the realities behind critical policy shifts. While this show covers legal topics and Ben is a lawyer, the views expressed do not constitute legal advice. For official legal advice on any of the topics we cover, please contact your attorney. [ Music ] All right, Ben, we are following the trends this week and talking about AI.

 

Ben Yelin: Every story is an AI story these days.

 

Dave Bittner: Yeah, there's no getting away from it. So, why don't you lead things off for us here?

 

Ben Yelin: So this is a positive story. You know, usually we start out with such negativity.

 

Dave Bittner: Yeah.

 

Ben Yelin: But this story offers some promise.

 

Dave Bittner: Okay.

 

Ben Yelin: So it comes from the Lawfare blog, an unrequited friend of this podcast. And they talk about how AI has the potential to dramatically reduce, potentially to near zero, the cost of regulatory compliance by automating many of the kind of repetitive, boring, meaningless tasks that go into compliance with federal, state, and even private industry regulation. So just to give you a couple of examples, AI has the capability to automate end-to-end compliance. Usually, these tasks are very structured, rule-based, that is very well-suited for AI, following instructions, if A, then B, if not, you know, that type of logical progression.

 

Dave Bittner: Right.

 

Ben Yelin: And then the interesting thing about automation is that it ends up being better at compliance than humans, just like how self-driving cars are better than us at being safe on the roads and highways, which I am a true believer, having ridden in a Waymo once in my life.

 

Dave Bittner: Okay.

 

Ben Yelin: But when you have a human--

 

Dave Bittner: It's not a very large sample size,

 

Ben Yelin: It's not a large sample size, but it was a pleasure.

 

Dave Bittner: Okay.

 

Ben Yelin: So, you know, humans fail at things. They fail compliance tasks because they might have inaccurate, outdated information. Their compliance paperwork might be incomplete. And oftentimes, the compliance branch of an office, whatever the sector is, public or private sector, are understaffed. And so it's hard to comply with rules and regulations effectively. So AI has the potential to ensure that you can have accurate real-time reporting, you can adhere to-- properly to regulatory standards, and you'll have the ability to have robust enforcement. And then there are downstream effects from this potential. So the big battle policy-wise with AI-- I mean, I think there are a lot of different kind of sub-battles, but the big battle is on do we want to go all out in innovation? Do we want to out-compete China? That's kind of the Trump approach, where let's build up data centers, let's become the world's leader in AI technology, and let's take away all of these regulations and guardrails because we want to win this race for our economic future. Of course, the other side to that is we want to prevent this technology from killing us all.

 

Dave Bittner: Right, okay.

 

Ben Yelin: So that's always-- that is always a very live tension.

 

Dave Bittner: It's a very subtle A, B-- yeah. >> Ben Yelin:: Right. I think this could tilt that debate, because if compliance with regulations becomes easier, if we get to that place where there's kind of a near-zero cost of regulatory compliance, we can set greater guardrails without sacrificing economic output. So it could be the best of both worlds. I heard the doubt in your voice there. Well, okay, I guess I need some explanations here. So what kind of compliance are we talking about? Can you give me an example of the kind of compliance that this could help streamline?

 

Ben Yelin: Sure. So in our world, obviously, there are cybersecurity requirements. You know, even if some of these are voluntary, if you want to be credentialed, sometimes if you want to avoid legal liability, you'll have cybersecurity regulatory tasks. So, being able to implement, monitor, update cybersecurity controls more consistently and effectively. Compliance with emerging safety methodologies. Some of those could be automated. Sometimes, as the technology evolves, it's hard for humans to evolve with it. So you could have the AI be reactive and kind of be retrofitted to match those new safety and alignment techniques. You could test models against safety-related metrics or performance thresholds, that's something that's very difficult for humans to do on their own, or even just something as simple as reporting obligations, transparency, filling out report logs, incident reporting, some of that can be labor-intensive. If it's not labor intensive, I think the industry, or maybe all industries, would be more willing to engage in those compliance tasks if it's not taking so many man hours the way it does now. I still hear your skepticism, though.

 

Dave Bittner: Well, I mean, I guess I'm viewing these descriptions as being kind of hand-wavy because we're still humans who have to comply, it's still humans who are on the hook if the compliance doesn't happen or if the AI lies about it, right?

 

Ben Yelin: It hallucinates compliance.

 

Dave Bittner: Yeah, the AI wants to please. So if you say to the AI, hey, your job is to make sure that we pass compliance, and the AI comes back and says, "Hey, good news, we passed compliance." Then the regulators come back, and they say, "Hey, you didn't pass compliance." And the AI says, "Oh, you're right. I'm sorry. I made a mistake. We did not-- " You know, like, how many times does that happen? Anything that you have expertise on that you ask AI about, you catch it in mistakes. And so I'm wondering, how do you put guardrails on this, from both the inescapable human component of this?

 

Ben Yelin: I think the human component just changes, and that's my positive philosophy on this.

 

Dave Bittner: Okay. Go on.

 

Ben Yelin: So if right now the human is going through the checklist and figuring out, Are we complying with X, Y, and Z, here's the evidence. I'm going to put together a report. That is labor-intensive.

 

Dave Bittner: Right.

 

Ben Yelin: What if the human focuses that human's energy on prompting the AI and figuring out which prompts will get the AI to do what we actually need it to do? So you can say something like, I do not want you to try and please me. I want you to check this system and make sure that it is compliant. I mean, I think, and I've started to use this just in my work, so much of the human element of AI is learning how to come up with iterative prompts that train the chatbot or whatever you're using to avoid the common pitfalls of AI when you don't give it specific instructions.

 

Dave Bittner: Yeah.

 

Ben Yelin: So that's my positive take on it. So you could do something like tell your AI to do automated red teaming, right? So, try and figure out like what are all the ways that some other system that we're not using might malfunction? And that can give us guidance on whether you use that system. In being creative with your prompts, you can have the AI do what you want it to do with that human element of, I'm going to guide you in the right direction. And hopefully you'd have somebody who's coming up with these prompts that has expertise and compliance. So it's not-- you're not taking the human element out of it entirely, you're just making the human element less tedious and rote and more based on subject matter expertise and things like threat detection.

 

Dave Bittner: So you could say to the AI, "I want you to go through this checklist and see where our organization is in compliance and where we're out of compliance." So the human, rather than having to go through that exhaustive checklist, will now get a report from the AI that says, "Hey, here are the areas that need attention."

 

Ben Yelin: Right. And you can control the universe in which the AI operates. So say like, check these systems to make sure, and then that limits the chance for something like hallucinations. So this is something that I think is going to change not just industry, but I think it's going to change how policymakers approach regulation and potential compliance. I mean, I think we're going to get to the point, maybe in the not-so-distant future, where compliance can be automated and then aggregated. And not only is it better on an individual organizational level, because the task is a little bit simpler, but also when we're talking about something like cybersecurity, we could have a better idea of the threat landscape if we have this automatically generated data that's coming into us in real time, if we had an effective cybersecurity agency at the federal level. So I certainly see the potential here. Again, you are absolutely right that there are pitfalls, like if you become too reliant on AI, where it gets circular, and like, you know, BS in BS out, that could be a big problem. If there's some like fundamental error in the prompt that is generating automated compliance checklists, then like if you do that at scale, it's going to have very deleterious downstream effects.

 

Dave Bittner: Right.

 

Ben Yelin: But I just think this is the vision for the future, and this is what I think policymakers at all level should start thinking about. Like, how can we make compliance? And I would guess like a good portion of our listener base is engaged in some type of compliance-related efforts as part of their job. How can we make this less painful and a more positive sum, where there's still a human element to it? The human is still guiding the compliance, but we can automate tasks to limit the cost of compliance, and therefore, we can put up proper guardrails to prevent AI from doing the things we don't want it to do.

 

Dave Bittner: Right. It's the dream, Ben.

 

Ben Yelin: It's the dream.

 

Dave Bittner: Of putting-- giving the humans the interesting work that they find fulfilling, and the drudgery to the robots.

 

Ben Yelin: And I go back and forth every day, you know. There are some days where I'm like, it's going to take all our jobs.

 

Dave Bittner: Yeah.

 

Ben Yelin: They can't replicate our banter yet. But I'm sure at some point--

 

Dave Bittner: They're working on it.

 

Ben Yelin: Yeah, they're going to be able to do it. I mean, you could probably have like a-- you could probably generate a "Caveat" script through AI. That would be a good approximation of what we do here.

 

Dave Bittner: Yeah, yeah. So, well, okay, I guess the places that I'm concerned about are places where we are in the physical world, and we have to measure things in the physical world. So let's say I am running a wastewater treatment plant, right? And part of my regulatory framework is to say, you know, you must have no more than so many parts per million of chlorine in the water, right? So the AI has to check in and say, you know, to the human and say, what's our chlorine levels? Although I suppose the AI could go directly to the testing.

 

Ben Yelin: Go directly to the source, yeah.

 

Dave Bittner: But do you see where I'm going here, where like there's still-- what if the human lies? What if the-- like, how do you-- there's only so much trust we can give the AI. I guess it's high-risk, high-reward potential. Because I'm also imagining the person who gets their regulatory report all screwed up and has to sit in front of the regulator and go, "Well, actually-- "

 

Ben Yelin: "It wasn't me. It was my AI."

 

Dave Bittner: "I was using AI." And the regulator's like, "Well, you know what? I got good news and bad news. The bad news is you're the one going to jail." Right?

 

Ben Yelin: Can I give the techno-optimist answer on this and say that I'm not sure I entirely believe it?

 

Dave Bittner: Please.

 

Ben Yelin: But like, people who have to do those types of checks now are prone to very common human errors, errors that do happen.

 

Dave Bittner: Yeah.

 

Ben Yelin: Like, we should at least have some type of metric where we can measure whether it's humans doing the compliance work or some type of AI-automated system, and figure out what the fail rate is. We've done that in certain industries. Like, that's my Waymo optimism case. For x number of miles driven, here are the accidents. Now, again, if you get to a high-profile story where a Waymo runs over a cute kitty cat, which is what happened, then people are going to be very negative about it, no matter which statistics you try to describe.

 

Dave Bittner: Right.

 

Ben Yelin: But like to say there are risks, also wouldn't that also imply that there are risks to the current approach?

 

Dave Bittner: Yeah, you're right. I mean, we can't let the perfect be the enemy of the good, and if-- to use your automated car scenario, you know, if self-driving cars cut accident, you know, fatalities in half, still a lot of people are going to die, but it's half as many. Right.

 

Ben Yelin: Right. And this also doesn't have to be like an all sizes approach, where we just decide one day, like today is automation day. And all compliance tasks from here on out are going to be automated. I think it's going to be sector by sector, regulation by regulation. Like, there might be risks that emerge with certain compliance automating AI systems, and you can address those as they arise. But just slowly but surely, we're going to get into this world where compliance tasks become easier to comply with, and therefore we can set up additional compliance tasks to protect our safety, to protect our data, to protect our networks. And, like, that's where the promise is here to me. And we won't have to make this binary decision between, you know, do we let private organizations take these risks, that's going to put our entire company's system in jeopardy, the entire state, country's network in jeopardy, or are we going to put in overly burdensome regulations to the extent that we fall behind in the global AI race. And this phenomenon is a path out of that binary. And that's why I'm positive about it.

 

Dave Bittner: Okay.

 

Ben Yelin: Even though I don't think it's going to be like the panacea that tomorrow, all of a sudden, all the compliance folks will just be working within a beautifully designed AI system. This is a longer-term-- this is a longer-term effort. But it just kind of opened my eyes to the potential here.

 

Dave Bittner: Well, I mean, let's just roll into my story here because these really are related, and you mentioned, you know, that we don't want to get into a circle here. My story this week comes from reports. This is a reporting from Engadget that the Trump administration is planning to use AI to write federal regulations. So--

 

Ben Yelin: By the way, we don't coordinate our stories here. So that was purely a coincidence. They segue very nicely into one another.

 

Dave Bittner: So who watches the watchman?

 

Ben Yelin: Right.

 

Dave Bittner: And I can see the utility here of-- in this case, evidently, they're planning on using Google Gemini to help draft regulations. They say they're starting with the Department of Transportation.

 

Ben Yelin: Elon must be so angry. They're like, "They didn't use xAI."

 

Dave Bittner: Oh, because they're not using Grok. Yeah, yeah, yeah. So they're starting with the Department of Transportation. What could possibly go wrong with airplanes and trains?

 

Ben Yelin: That's a bad one to hallucinate on. Like, don't worry, you know, don't worry about the safety of the wings, or whatever. That's fine.

 

Dave Bittner: But they're saying, kind of to your point, with what we're talking about, that it can speed stuff up. And I suppose that's true. They quoted General Counsel Gregory Zerzan, who said that the president himself is very excited, and they want to use AI for drafting rules. He says that-- this is Zerzan says that they are emphasizing speed over quality, saying agencies want good enough rules and to flood the zone. Now, flood the zone is very much a phrase out of this administration. So that's a loaded phrase.

 

Ben Yelin: It's a term of art. Yeah.

 

Dave Bittner: Yeah. But I wonder to what degree is this notion of good enough true. I can see people feeling like they're overly regulated, and certainly the current administration wants to cut back on regulations. They've been actively doing that. But again, you know, I-- like, danger, danger.

 

Ben Yelin: It seems dangerous, yeah. I mean--

 

Dave Bittner: Well, who's ultimately responsible? Like, you have regulations that are written by AI, and presumably, they will be labeled as such. So what happens when people bring these things to court? How do you justify them? How do you back up the decisions that the AI systems have made when bad things happen?

 

Ben Yelin: I mean, I think if you're going to take the approach of automating drafting of regulations, you have to do it with some standardized rules around human supervision. So you have to have subject matter expertise review everything. I think that's the only way that you can ensure its safety, at least in this kind of pilot phase, where we're starting with the Department of Transportation, which does seem like a bad place to start. Like, I probably would have chosen something else, like are there any regulations around the National Endowment of the Arts, or something?

 

Dave Bittner: Right, right.

 

Ben Yelin: That's harder to screw up.

 

Dave Bittner: Right. There's not so many lives at risk.

 

Ben Yelin: Right.

 

Dave Bittner: Yeah.

 

Ben Yelin: But I kind of want to just like take Trump out of this because I think that's going to color a lot of people's opinions on it.

 

Dave Bittner: Yeah.

 

Ben Yelin: I think in the long run, this type of thing is very important. If you want to build something or if there's some type of transportation system that requires an extensive environmental review process, and that puts off, you know, the building of high-speed rail in California or the building of a new train tunnel under the Hudson River. And you get bogged down in years of this type of bureaucratic morass. I think there is a role to be played for automated regulation drafting that could expedite parts of that process. Now, it's still going to be a cumbersome process. When you have rules about, you know, it has to protect endangered animals, and some company that doesn't want the train line to be built will be like, "I saw a bald eagle over there once."

 

Dave Bittner: Right. Right.

 

Ben Yelin: So that's going to be hard to avoid. But if you can speed up the part of the process that just involves like writing the rules, which can sometimes be extremely cumbersome, I think it's very important for the long term. And I think a lot of this probably could be automated with a significant level of human review. I don't think it can be done without that. You know, I don't think these agencies should be DOGE-ing their employees because they've decided that AI can do all the work. That would be terrible, and planes would crash.

 

Dave Bittner: Well, I mean, this article points out that the Department of Transportation has lost more than 4000 employees, including over 100 attorneys, during this second Trump administration. So those are raw numbers.

 

Ben Yelin: I mean, that's a lot of people for the department.

 

Dave Bittner: Is this inevitable, though? Because I guess part of me thinks it is.

 

Ben Yelin: I think it is. I mean, I don't know what the timeframe is going to be. But like this type of work, and frankly, it's a lot of the legal profession where it's like you have to reference language from previous regulations. And that requires opening up, you know, a million different editions of the federal register and pulling out quotes. And like that is time-consuming.

 

Dave Bittner: Yeah.

 

Ben Yelin: And like, if we could devote human effort to something a little more exciting and better than that in the long term, this is not about anybody's job today, this is about like where we are 20, 30 years from now. Yeah, this is an innovation that we're going to have to take advantage of. And if the private sector is going to do it, I don't think the government can lag behind, where, you know, sometimes you're going to need a federal department to promulgate regulations quickly to help a fledgling industry or help ensure safety in an industry that's growing. So I do think there is going to be a role for this long term. I tend to think it is inevitable, and I see the promise in it.

 

Dave Bittner: I see where you're coming from. Here's a concern I have. Right now, as we deal with this, we have decades, perhaps even centuries of institutional knowledge at hand. If you think about a law firm, there are lawyers of all different levels and experiences in that law firm.

 

Ben Yelin: Guys who've been there since the '70s.

 

Dave Bittner: Right, and they can look over these things. They have their own intuitions and their spidey sense and all those sorts of things of reviewing what the AI generates. It is not impossible for me to imagine getting to a place where we've taken away all of the entry-level, all those-- that first decade of being a lawyer, of doing the no-fun work.

 

Ben Yelin: Right.

 

Dave Bittner: Right.

 

Ben Yelin: That's how you become the subject matter expert.

 

Dave Bittner: Exactly. So, how do you get high-level people if you no longer have people doing the low-level work? And ultimately, do you end up with people who are not equipped to provide oversight to the AI because they never learned that stuff? The AIs just took over that part of it, and, well, we just, I guess we have to trust what it says because nobody here really knows anymore, and Bob retired, you know?

 

Ben Yelin: Once again, it's like the boomers who are the most excited about this because they get to keep their jobs.

 

Dave Bittner: Right.

 

Ben Yelin: But it's the entry-level folks. Yeah, I don't think we've resolved that problem. And I think it's a very serious problem. Like, you can say, well, we don't need entry-level attorneys because we have the partners. They've been here long enough. They can do the human review. Like, we don't need some 25-year-old to be reviewing thousands of pages of documents. But like, the 70-year-old lawyer started their career by reviewing thousands of pages of documents.

 

Dave Bittner: Exactly.

 

Ben Yelin: And I just, I don't see how that's going to end up in a good place. And so I think that's something that we definitely have to contend with. I think this is going to be, at least in the medium term, some type of hybrid effort where you still have those same entry-level positions or medium-tier positions. And instead of performing the tasks they perform now, they are supervising the AI-generated regulations, doing kind of the same work we talked about in the previous segment, guiding prompts, having several set of eyes to make sure that they're not making mistakes. Like, that's what has to happen in the medium term, because we are not equipped at this point to just do away with that entire class of people who are trying to get that institutional expertise. And if we fail, then that's where AI can really take over the world and screw us. Because we get to the point 20, 30 years from now, where it's like, they formulated this regulation based on Bob's knowledge in the 2020s. And like Bob's been dead for 30 years. And those types of like-- those regulations aren't going to work for x, y, z reasons, but only the AI knows about those reasons, not, like, the human staff. So, yeah, I think this is a long-term prospect, and it's not something that like even in this kind of smaller scale, we're going to pilot it at an agency. I think it's not something we can do hastily and without significant guardrails.

 

Dave Bittner: How would you feel if somebody gave a Supreme Court seat to an AI?

 

Ben Yelin: You know, I don't think it would be that different. Because, like, we can guess the outcome of, I don't know, a significant portion of Supreme Court cases based on the ideological makeup of the court. I feel like it would be much more difficult for those very obscure areas of the law that nobody pays attention to. Like, for example, Justice Gorsuch, who was a doctrinaire conservative on almost everything, has this soft spot for Indian tribes. And so, like he always takes the liberal position on Indian affairs issues.

 

Dave Bittner: Oh, interesting.

 

Ben Yelin: I don't think that's something where-- like you can't train an AI to be like, all right, you're going to be the conservative justice, but like, you know, you're going to have your one or two areas where somebody got in your ear 20 years ago and talked to you about the importance of tribal sovereignty, and now you take this position that strays from your general ideology. Like, I don't think we can replicate that yet. But I would not be surprised if like the parties to litigation are conducting oral arguments in front of some type of AI system, and they are generating responses from an automated Supreme Court. Like, I think that's probably something that allows appellate attorneys to practice their craft, and you don't have to have actual judges monitor the work that you're doing. I think that's actually a very good use case for it.

 

Dave Bittner: I don't mean to sound so sort of blanket negative on all this. I mean, I do truly see the utility of these tools, and they're-- I use them in my profession, you know, I absolutely see how they can be useful. At the same time, I see people who say that these tools might be-- might-- it could turn out that they are like asbestos, right? A miracle development, something that makes life better all around.

 

Ben Yelin: It's so cheap to build these houses now.

 

Dave Bittner: Right. Yeah, we use it for insulation. We use it for, you know, fake snowflakes. We use it on the brakes of our cars. It's a miracle. And then we spend a hundred years cleaning it up. Right? Turns out.

 

Ben Yelin: That's the danger.

 

Dave Bittner: Right?

 

Ben Yelin: And there's definitely that danger. We cannot underestimate it. And that's why like all of our spidey senses should tingle in a story like this. Especially when it comes to transportation, because like there are a lot of high-profile transportation incidents. They happen all the time. And I would hate to see something happen because Google Gemini hallucinated a regulation, and we stopped putting, you know, the safety trigger on a certain type of airplanes and the airplane crashed. Like, that would be an asbestos-style situation, and it would not only set back safety, but also the promise and potential of AI for a significant period of time.

 

Dave Bittner: Yeah, yeah. All right. These are interesting questions, and I'm glad we get to hash them out together.

 

Ben Yelin: Yeah, and I think there are strong opinions on this, and like I am very open to persuasion on all of this because I think like this is uncharted territory. And we all need to be having these conversations. I'm on a committee at my university where we're talking about how this applies to the education system. And I think everybody needs to be having these conversations. Like, what capabilities do these tools present to us? And what are the risks? And like let's evaluate those against one another.

 

Dave Bittner: All right. Well, we will have links to those stories in our show notes. And of course, we would love to hear from you. If there's something you'd like us to consider for the show, you can email us. It's caveat@n2k.com. [ Music ] Ben, I recently had the pleasure of speaking with Tony Scott. He is the CEO of a company named Intrusion. He's also a former federal CIO. And he's sharing his perspective on some of these evolving regulations and the realities behind these critical policy shifts. Here's my conversation with Tony Scott. [ Music ]

 

Tony Scott: I've had some pretty fun and cool roles. I was the federal CIO for the last two years of the Obama administration. And before that, I held CIO roles at VMware and Microsoft, at the Walt Disney Company. I was CTO at General Motors, ran infrastructure for Bristol Myers Squibb. And before that, a bunch of jobs in various, you know, large corporations. I did two startups, started my career at Sun Microsystems. And the common thread among all of those roles is I noticed even early on that cybersecurity was playing a larger and larger role in everything I was doing. It was coming up more frequently in conversation. There were more and more incidents occurring. And it just has been sort of the common thread and throughline for all of the roles that I've ever had. Two or three weeks after I started the federal CIO job, and I was still kind of learning where the bathroom was, we had the breach of the OPM systems, which was the Office of Personnel Management. And 21 million identities were compromised. And, you know, that was probably the worst of the things that occurred, you know, while I was in a role. But the roots of that stemmed back several years. So, while I got, you know, a lot of credit for sort of, you know, the actions we took after the incident had happened. The real preventative things could have and should have been done years and years earlier.

 

Ben Yelin: Do you see a difference in the private and public sectors in terms of the pace of your ability to create change? Is that something that has frustrated you only in the public sector, or do you think that that's something that exists in the private sector as well?

 

Tony Scott: Well, I think it exists across the board. And it's true, whether it's cybersecurity or any other initiative that is important. If it has strong leadership, and the commitment of leadership, and the right amount of resourcing, you can get it done. If it's just, you know, sort of hand-waving that, you know, oh, yeah, we're doing this, but there's no real leadership or, you know, resourcing, then it's not going to get done. In the case of the federal government, the law and regulation that was requiring two-factor authentication had been passed 10 years earlier.

 

Ben Yelin: Wow.

 

Tony Scott: And by the time the OPM breach occurred, there was only around 50% adoption across the federal government. And it was clearly a case where a good idea, a solid idea, the technology was there. All agencies had adopted two-factor to some degree. But in most cases, the leadership, the funding, and the resources to really get it done hadn't been prioritized. And then after the OPM breach, everybody got religion real quick. We launched the cybersecurity sprint. And within, you know, six to eight weeks, we went from 50% adoption to mid-90% adoption of two-factor. So, you know, it tells you that it can be done. But clearly, there hadn't been the focus on it that there needed to be.

 

Ben Yelin: And that gets at something, I mean, people focus on cybersecurity after the high-profile breaches. I've never heard more discussion of the need to protect-- local governments, for example, when I was living in Baltimore, and they suffered a terrible ransomware attack. So, is there something that policymakers can do in the interim between these high-profile breaches to kind of raise the salience so that you can institute these policy reforms before the storm hits?

 

Tony Scott: I think there's a couple of things that you can do. One is continuous monitoring and testing of your, you know, core infrastructure that is, you know, the bedrock of all cybersecurity. People who just do an occasional pen test are kind of missing the boat, I think. You know, it's like taking a picture of your house on a sunny day. You know, that doesn't tell you much about, you know, whether the roof is good during a heavy rainstorm or, you know, other things that might be wrong with the house. And so I'm a firm believer in sort of continuous testing and continuous monitoring of your environment. The second recommendation is, and this is a question all boards and leaders should ask of their IT organization is, you know, how modern is our core infrastructure, you know, and are we replacing and upgrading regularly? A lot of the issues that I've encountered in my career are due to just old aging infrastructure that wasn't suitable for the mission that the organization was now undertaking. And to me, that's just a cardinal sin. What happens then is, you know, a breach occurs, and now all of a sudden, you've got to go spend a whole bunch of money to upgrade stuff all at once, rather than continuous improvement along the way. And so to me, that's number two on my list for sure.

 

Ben Yelin: Do you-- I mean, just in talking to folks in the private sector in particular, a lot of them-- individuals can be reticent to federal or state cybersecurity regulation for understandable reasons. They'll say, you know, we handle our own system well. Do you think that our current regulatory frameworks are keeping pace with technology? Or do you think that it would be better for private sector organizations to just take the initiative on their own? Don't wait for guidance from a federal agency or a state agency. How do you balance that?

 

Tony Scott: Well, you know, the regulatory framework is, in my view, sort of the minimum acceptable standard. You know, it's kind of like, you know, the base for what you should be doing, but it's certainly not the standard of excellence in any case. And so I absolutely advocate for, you know, taking the initiative, be as good as you can be, don't settle for, you know, last place, you know, to get to the baseline. That's just kind of bordering on malpractice in my view.

 

Ben Yelin: Just looking at the federal landscape now, does what's happened in the last year, the difficulty in renewing CISA 2015, some of the staff reductions at CISA, the agency, are those concerning? And have you started to see real-world impacts of that in the work that you're doing? Or is that not something that's really shown up yet?

 

Tony Scott: I don't think it's shown up yet, but I guarantee you it will. And I lament a lot of those cutbacks and drain on resources. There's a view, and I've seen this over and over and over again, that, you know, we want smaller government, we want fewer government employees, you know, all of that sort of thinking. And it's admirable in its intent, right, which is to save money and, you know, reduce costs and reduce taxes and all of that. But the alternative is to do those functions, we then outsource to, you know, a commercial business or a private sector business, and so on, which, again, could be fine. But over time, what that does is erode the expertise that we have in the actual federal government. And we turn government employees into just procurement specialists, you know, contract administrators, and so on, without the actual technical expertise that you need to be smart about strategy and all of the other things. I saw this when I was at GM. We had outsourced to EDS, turned all of IT over to EDS. And so the internal IT organization at GM was a handful of people at one point that lacked the technical expertise to, you know, sort of layout strategy for the future. And in 1996, GM abandoned that approach, made EDES an independent company, and then started bringing back into the organization, you know, a real CIO, people with the right technical expertise, and so on. And I joined in like '99, after this repatriation, if you will, was sort of well underway. And here's the amazing thing. Our budget went from $4 billion-something a year and eventually got down to a little over $2 billion a year over the next several years. So by bringing these capabilities back in-house, saved a ton of money, but probably more importantly, you know, developed a much better strategy for IT, you know, for the company. You know, that's not a criticism of EDS. That's just a leadership, you know, resourcing sort of question.

 

Ben Yelin: And I know the political winds can shift, but is this something, you know, in 2029, for example, that you can try to recreate and rebuild, that institutional expertise, the people who actually know the technology, or is that something that can't really be rebuilt once it's been--

 

Tony Scott: No, I think it can be. And I think GM is a classic example of that. Where there's a will, there's a way. I think the good news about my experience in IT, and this was true in the Obama administration, and it was true in the first Trump administration, and also in the Biden administration that IT was not looked at as a political football, generally speaking. You know, good IT doesn't wear a D or an R or any of those other, you know, symbols.

 

Ben Yelin: It's vaunted letters, yep.

 

Tony Scott: Yeah, and it can be practiced well by people of either party. So I hope that continues. I think it's a little too early to tell whether it actually has or not. I think the cutbacks that did occur were more of a broad stroke, you know, blunt sword to try to reduce, you know, spending in the federal government and those kinds of things. I don't think it was specifically aimed at cybersecurity or IT. I think it was just sort of the broad brush thing. And hopefully, people come to their senses and realize that we need to really invest in this to be competitive in the world.

 

Ben Yelin: Yeah. So switching gears a little bit, I want to be a little more forward-looking. So what keeps you up at night about the cybersecurity threat landscape, say, over the next five years? Is this something where it's AI-related, quantum computing? Is it something else? What are kind of the threats that keep you up as a practitioner in this?

 

Tony Scott: Well, it's all of those things that you mentioned. Certainly, we've seen already examples where AI has been used to weaponize various tools at scale. And so, you know, it is the latest development in an ongoing arms race to see who can, you know, create more effective attacks. And the defenders, like my company, are also using AI to defend against the, you know, AI-generated attack. So there's just this constant, you know, arms race to see who could use technology. Quantum will play into that. And who knows what's coming next after that. You know, is this going to erupt into space as well? You know, space has up till now been a safe place, generally speaking, a combat-free zone, if you will, from, you know, a warfare perspective. But, you know, that could be the next, you know, war space as an example. So, anyhow, I think, you know, the notion is, at least for the foreseeable future, it's going to be an arms race. We're going to have to invest. The biggest concern I have is, are we going to have enough people with enough smarts to really be competitive in that arms race? You're going to have all the AI you want, but without people who have the right expertise, that's not going to get directed at the right things. We're not going to prioritize resources and spending and so on, which rely on votes in Congress and, you know, everyday people to understand, you know, what the right thing to do is. And that's my biggest concern.

 

Ben Yelin: Yeah, I guess just kind of following up on that, how do you see us continuing to develop this emerging cyber workforce? Is that something that you see as a problem right now? Are there policy solutions that can help us accelerate a better workforce for these purposes? Are there solutions that the private sector can take on, partnerships? Like, how do you see us improving the perspective of the workforce?

 

Tony Scott: Well, I think there's a couple of things, or influencers that I see. And I do see it starting to happen in some areas. I'll give you one simple example. The Girl Scouts years ago started a program where they were teaching young girls good cybersecurity practices just for their home environment, right? Starting kids in an early age to be situationally aware of the environment that they found themselves in critical activity. When I was growing up, we were worried about, you know, Halloween, somebody sticking bad stuff into your Halloween bag.

 

Ben Yelin: Yeah, I'm old enough to remember that. Yeah, I remember that phase.

 

Tony Scott: My grandmother was paranoid about, you know, that kind of thing. You know, that's minor in comparison to some of the, you know, actual threats that we face today, especially with young kids and all the devices they have in their hands and so on. So I think we've got to start, you know, and have a part of every education curriculum that starts creating awareness, contextual awareness of, you know, what you should be doing at any age or stage in life. That will then, I think, help create better conversations as people move up through, you know, their life, whether it's school or into their careers and so on. You know, if you're blissfully ignorant of threats, you're going to get hit by them. If you don't understand, you know, wearing a face mask when you have a cough or you don't wear warm clothes when you go out in the cold. If you're just blissfully ignorant of, you know, the things that can harm you. Or wandering around in a lightning storm with a metal rod in your hand, you know. You know, that's kind of the equivalent of being ignorant of cybersecurity threats today because they can come and they can bite you and they can make your life miserable as we've seen sort of over and over and over again. So that'd be number one. And then I think at the professional level, there needs to be some strong incentives for people to, you know, become professionals in this particular space. And there's some good efforts that have already been washed, but we need to triple down on those, you know, like we've focused on fighting cancer or, you know, some of the other big social initiatives that have occurred, you know, over the last several decades.

 

Ben Yelin: And then to close out, I just kind of wanted to take advantage of the fact that you offer a lot of wisdom based on your experience, going back decades, and the kind of breadth of your experience. So a couple of questions along those ends. You've worked in pretty intense scenarios. Obviously, OPM is kind of the one that's top of mind for me. What did that teach you about your own style of leadership and how leaders in the cyber field can and should react in those situations?

 

Tony Scott: Well, you don't have the three weeks I could tell you about all the lessons learned there, but a couple of them stick out to me, which is, you know, don't waste a good crisis, number one. I mean, OPM was, you know, big, it was huge, you know, it was terrible that it had happened, and so on. But we could have just said, oh, well, that was OPM. Everything else is fine. You know, we should just try to fix OPM and stop there. But I realized once we did the survey of all the federal agencies and discovered that there'd only been 50% adoption, I went, oh, my goodness, you know. This is not good. You know, this is a big, terrible problem that we've got to go figure out how to address, and which ultimately we did. But we had great engagement from Congress. We had great engagement from the president. And all of that allowed us to then, you know, go address this big hairy problem. So, and I've used that in other roles. Whenever there's a crisis of some kind, you know, recognize it, get after it. And don't let it fester. Those are, you know, sort of the top-level learnings that I've had over and over and over again. The second one was just to engage the right people. You know, we had at that point incredible talent to be able to go address the problem, to figure out how big it was, how broad it was. And without the help of a lot of really good, smart people, it would have been a very difficult task for sure. And probably the third one was, it's not a one-and-done sort of thing. When we turned over the administration, my successor was really good about following up and making sure that we didn't slip back to, you know, a bad state. And it became, you know, a continuous focus of the federal CIO office to make sure that we were maintaining at least where we had-- where we had gotten to. And there were a number of other ongoing improvements that were undertaken. So to me, those are the big takeaways from that experience. [ Music ]

 

Dave Bittner: Ben, what do you think?

 

Ben Yelin: Very on theme for our show today, talking about federal regulations.

 

Dave Bittner: Yes.

 

Ben Yelin: Yeah, no, I thought it was very good and also reflective of the conversation we had about how federal approaches have been changing in the past year. And this is something that businesses have had to adapt to. So it was a really interesting conversation.

 

Dave Bittner: Yeah, yeah, definitely. It's a time where I think we need nuance in a world that is struggling to not be black and white.

 

Ben Yelin: Right.

 

Dave Bittner: Right.

 

Ben Yelin: A good theme of today's show, I would say.

 

Dave Bittner: There you go. All right. Well, again, our thanks to Tony Scott from Intrusion for joining us. We do appreciate him taking the time. [ Music ] And that is "Caveat," brought to you by N2K CyberWire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to caveat@n2k.com. This episode is produced by Liz Stokes. Our executive producer is Jennifer Eiben. The show is mixed by Tré Hester. Peter Kilpe is our publisher. I'm Dave Bittner.

 

Ben Yelin: And I'm Ben Yelin.

 

Dave Bittner: Thanks for listening. [ Music ]