
The SBOM where it happens.
Dave Bittner: Hello, everyone; and welcome to Caveat, N2K CyberWire's privacy, surveillance, law and policy podcast. I'm Dave Bittner. And joining me is my cohost, Ben Yelin from the University of Maryland Center for Cyber Health and Hazard Strategies. Hey there, Ben.
Ben Yelin: Hello, Dave.
Dave Bittner: On today's show, Ben has a follow-up story on the Anthropic Pentagon dust-up. I've got the latest on the new national cyber strategy from the White House. And, later in the show, my conversation with Jean-Paul Bergeaux, CTO for Federal for GuidePoint Security. We're talking about some Biden-era orders from the OMB that have been rescinded. This has to do with SBOMs, a software bill of materials. Stick around for that. While this show covers legal topics, and Ben is a lawyer, the views expressed do not constitute legal advice. For official legal advice on any of the topics we cover, please contact your attorney. All right. Ben. Let's jump into our stories here. You want to lead things off for us.
Ben Yelin: Sure. So we missed you last week, Dave.
Dave Bittner: I missed you too.
Ben Yelin: But Ethan and I tried to hold it together. I think we did a decent job of it. And we talked about Anthropic losing its contract with the Pentagon and being put on this naughty list of being a supply chain risk.
Dave Bittner: Yeah.
Ben Yelin: And we also talked about how the new contract has gone to OpenAI. So I want to do a follow-up to that story and talk about a lawsuit that was filed this week by Anthropic in federal court in California. It is Anthropic versus U.S. Department of War, U.S. Department of Treasury, whole list of agencies and their secretaries/executives in their official capacity. The idea here is that Anthropic is suing the federal government for rescinding -- for not only rescinding the contract but for, more importantly, putting them on this supply chain risk list, which means that all federal agencies are prohibited from contracting with them; and not just agencies themselves but contractors to the federal government, which is obviously going to be a big hit to Anthropic's business.
Dave Bittner: Yeah.
Ben Yelin: So there are a couple of claims here. The first and less interesting one is that this violates the Administrative Procedure Act. And we've talked about this. But you can't promulgate any type of regulation that's arbitrary and capricious. And the central allegation here is that this doesn't have to do with any sort of safety concern. It's really just retaliation for Anthropic's comments on security and safety and their refusal to do the Pentagon's bidding when it comes to autonomous weapons system and -- autonomous weapon systems and mass surveillance.
Dave Bittner: Right.
Ben Yelin: You know, it's kind of a gray area for me on that one, frankly, just because they are -- the Pentagon has requested that they do something. You can agree with what they want to do or not, but Anthropic's refusal to do that thing also might imply some type of breach of contractual obligation. So I understand that. I think extending that to then putting them on this you-are-a-threat to-the-supply-chain naughty list is I think what's retaliatory here. And, speaking of that retaliation, there is a First Amendment claim. The First Amendment claim is that Anthropic is being punished for its speech. And, by speech, they mean a bunch of things. They mean public comments from the CEO, discussions from Anthropic executives about the importance of privacy and ethical boundaries, and then the very public decision by Anthropic to try to put guardrails on the use of autonomous weapon systems and mass surveillance. And the allegation here is that this is a potential federal contractor being summarily punished, not just for speech but for speech based on its viewpoint. So, if you have a content-neutral restriction on speech, that's going to be viewed with intermediate scrutiny. Those sometimes survive. Going one step above that is a content-based restriction on speech. So that's prohibiting speech because of its content. So you can't talk about X subject, and that's usually not kosher. The Supreme Court will say -- will apply strict scrutiny to that. Even more extreme than that is viewpoint discrimination. You're going to be punished for taking a particular side on a topic of public interest. And that's what Anthropic is arguing here, that this is viewpoint discrimination. That is considered through the process of strict scrutiny, that we're discriminating against this company not because of anything that it did because of its actions but because of its viewpoint and the viewpoint here being they are conscious about privacy and security and the ethics of using their algorithms to do these very, very serious things. So, if you look at it under a strict-scrutiny framework -- and I think this is what Anthropic is going to try and argue -- the government might have a compelling interest. National security is a compelling interest. So the government is almost certainly going to argue that. But then the second part of the test there is, are the means narrowly tailored to achieving that interest. And here the means are certainly not narrowly tailored. There are a bunch of things the government could have done to solve the potential national security issue besides putting Anthropic on this supply chain risk list.
Dave Bittner: Right.
Ben Yelin: So they could have just terminated the Pentagon contract and left it at that. They could have worked with Anthropic for some type of equitable solution that would have satisfied all of the parties. Instead, they are forbidding Anthropic from contracting with any federal agency or federal contractor. So this is certainly something that's not narrowly tailored.
Dave Bittner: Yeah.
Ben Yelin: All of that is to say I would not be surprised at all to see a preliminary injunction here. So, if I had to prognosticate, I think Anthropic, at least on first impression, has a very good chance of winning this case.
Dave Bittner: And so what would that preliminary injunction mean?
Ben Yelin: So that's a -- that's a really, really great question because the natural remedy would be restore the contract it had with the Pentagon. But that's really, really difficult as a remedy. It could reverse the executive order coming from the administration prohibiting Anthropic from contracting with agencies or contractors, and I think it might do that. How implementable that is, is certainly within question. For agencies and contractors who had existing agreements with Anthropic, it might be easier. You could just put on pause the transition process that's already in place to get these agencies away from Anthropic services. But, if there are companies who have newer agreements or are in the process of forming agreements, the looming threat of future litigation or future executive decisions might put a chilling effect on some rich company in Northern Virginia trying to purchase an Anthropic product and use it in their system so --
Dave Bittner: Right when there are other options available.
Ben Yelin: Right. You know, they'll go to the government's now-favored AI service, which is OpenAI. And they know that they'll be on much firmer ground. So the remedy --
Dave Bittner: Thought we weren't supposed to be picking winners and losers, Ben.
Ben Yelin: Oh, we pick winners and losers. Yeah. That only applies to solar energy. That doesn't apply to --
Dave Bittner: Oh. I see.
Ben Yelin: Yeah. AI-generated autonomous weapons that might kill us all.
Dave Bittner: So what if, for example, the FDA was using Anthro -- I'm just total hypothetical here. What if the FDA was using Anthropic to help craft nutritious lunch programs for kids, right.
Ben Yelin: Would probably be better than whatever RFK Jr.'s coming up with but...
Dave Bittner: But -- so this bans them from doing that, or something that has nothing to do with the military or anything, just a potential use case for their tools. And now, because they got in this little dust-up with the military, it precludes them from anything like that.
Ben Yelin: That's exactly right, and I think that's why this lawsuit has a good chance of succeeding. Under strict scrutiny, when you -- when you have that second part of the test that the means have to be narrowly tailored, prohibiting Anthropic from doing, like, a banal task for some obscure federal agency, like let's have Claude synthesize all of the federal regulations on X topics so that some worker in the Department of Treasury can write a report, like prohibiting that is not something that's narrowly tailored to the government's national security interests. It's just -- it's just simply not, whereas the way this authority has been used in the past, the authority to label a company a supply chain risk, is, well, you can't use Huawei because they are an entity controlled by the Communist Chinese government. There, like, any use of that product is really a risk for things like espionage or whatever. But that's just clearly not the case here, and we know it's not the case because of the evidentiary record. So this is the other point of emphasis in the lawsuit. Like, the Trump administration -- and this is just very typical of them -- if they had just kept their mouth shut and just said we're doing this because of national security, like, they'd probably have a better chance of winning this case.
Dave Bittner: Right.
Ben Yelin: That's not what happened.
Dave Bittner: Oh.
Ben Yelin: Trump went on Truth Social. It was like, they're too woke. We don't like them.
Dave Bittner: Yeah, yeah.
Ben Yelin: Yeah. Like, it's -- when you start to go far afield from the national security interest, courts can read into that, as well, and say all of this is pretextual. All this is just an excuse for you to punish this company for not doing your bidding. And I think courts are going to read right through that.
Dave Bittner: Yeah. So could we see a potential outcome here where the military is still within its right to say, yeah. You know, we don't choose this company to do these particular things, but we can't restrict the entire breadth of the government from doing business with them.
Ben Yelin: I think that's a very likely outcome. You know, I think it's perfectly reasonable for the Pentagon to say, We tried to work with you. We want you to fulfill this mission. That's why we were going to contract with you. And, if you're not willing to do it, like, more power to you. You can have a beer on your way out, but we're going to contract with somebody else. I think that's perfectly reasonable.
Dave Bittner: Yeah.
Ben Yelin: I think it's this broad punishment that's going to be held to be unconstitutional as a restriction on speech and expression. And so I think a very predictable equilibrium here is contractors will still be able to use Anthropic, and it's just the military will continue with this -- or the Pentagon will continue with this new contract that they came up with, with OpenAI. And I think that's probably the path of least resistance here. Now, who knows what Anthropic is going to do. They might say like, screw all of you guys. We want the injunction in this case, but we actually don't want to contract with a government that's going to be so disrespectful of the boundaries that we're trying to set. I don't think they're going to do that because you're just -- you'd be giving up on so much business. But certainly Anthropic, depending on how much of a stink they want to make about this, well, it would not necessarily just go back to the pre-status quo of a month ago, for example.
Dave Bittner: And that injunction could be speedy.
Ben Yelin: I think it could be quite speedy. I mean, I think a matter of weeks. And then it would be a preliminary injunction or a temporary restraining order. And then the court -- the federal court and district in Northern California would hear a full case on the merits and would either sustain that injunction and make it permanent or lift that injunction. And then you could go through the whole appeals process. I don't think we're going to get, like, a final adjudication of this anytime soon. But I do think the potential for this preliminary injunction or temporary restraining order in the very near future is definitely with us here.
Dave Bittner: Does Anthropic have any case to say that this whole thing just stinks, and, as you said, the specter of being on the wrong side of this particular White House put such a shadow over our business that people are just going to avoid us because of the chaos and the uncertainty.
Ben Yelin: Yeah. I think they -- they tried to say that in their complaint here. They say it in legalese, so it's not exactly those words.
Dave Bittner: Right.
Ben Yelin: But I think that's exactly what's happening here. What we've seen with the Trump administration is they have tried to use the legal system -- and I'm trying not to be partisan here, but they've tried to use the legal system to go after their enemies. So law firms that worked on cases that went against Trump in the past, they were put on blacklists. And the government says we're not going to give you security clearances, meaning you won't be able to go into certain federal courts. And a few law firms were extremely scared of that outcome and came to the table and negotiated an agreement with the administration and said, Fine. We won't do XYZ. We'll apologize for being part of the Russia, Russia, Russia witch hunt or whatever, and we'll do some pro bono work on behalf of administration priorities. Then there are a bunch of other law firms who were on that naughty list who said, Screw it. We're going to sue you because this is arbitrary retaliation. And they basically succeeded, the ones that held strong. The Trump administration just last week announced quietly that it's going to refuse to further pursue cases against these law firms. So law firms sued the administration. The administration initially was going to try to defend against those suits. Now they're kind of quietly given up on that.
Dave Bittner: Bully's always back down, Ben.
Ben Yelin: Yeah. But I think that's kind of what Anthropic is trying to do here --
Dave Bittner: Right.
Ben Yelin: -- is to put themselves in a similar -- similarly situated position where they're saying, We are the victims of federal retaliation; and federal agencies, from a constitutional perspective, can't do that. You can't, on a pretextual basis, end binding agreements or forbid us from contracting with even non-government entities like contractors just because you don't like a decision that we made or just because you don't like certain elements of our political speech. So I think that's going to be a central point in the argument, that this is all pretextual. This is all just a made-up security threat, and this is an abuse of the very narrow authority that the President has to protect our national security.
Dave Bittner: Yeah. I mean, seems to me like they've got a case.
Ben Yelin: Yeah. I think so. I think it's a very well-put-together brief that I read. It just came out yesterday, so I've been trying to make my way through it. But I think it's a really interesting argument. There's some good case law on contractors specifically being punished for speech. Now, none of these precedent cases are exactly on point. A lot of them occurred with local governments, like a trash contractor who said something bad about the mayor and lost their contract. But there's a pretty good history of courts stepping in and saying you can't terminate a contract for pretextual reasons if the real reason is just to suppress or antagonize speech that you're against. So there's a decent body of law on that, and I think that's going to be critical in this case.
Dave Bittner: Okay. All right. Well, we will have a link to that story in the show notes. My story this week is the fact that the Trump administration just late last week put out their National Cybersecurity Strategy, the new U.S. National Cybersecurity Strategy. This was anticipated, teased for a while. But now it's official. So I thought it might be useful to go through some of the things that are in here and some of the things that might be of interest to us.
Ben Yelin: Sure.
Dave Bittner: It is concise I guess is a good way to say it. It's only five or six pages long, which is, I think, the style of this administration to not get -- they would say bogged down in pesky details.
Ben Yelin: Love it for the purposes of how long it takes me to read it.
Dave Bittner: Exactly, exactly. It does help make it more straightforward and to the point.
Ben Yelin: Exactly. I don't have to, you know, put a 500-page document in an AI and say, summarize this for me.
Dave Bittner: Right, right.
Ben Yelin: I can actually just read the whole thing. It's great.
Dave Bittner: So it's the -- at the highest level, there are six policy pillars here; and then I'll just go through them. They say they want to shape adversary behavior, promote common-sense regulation, modernize and secure federal government networks, secure critical infrastructure, sustain superiority in critical and emerging technologies, and build talent and capacity. That all --
Ben Yelin: Sounds pretty good to me.
Dave Bittner: All strikes me as being pretty straightforward, right?
Ben Yelin: Absolutely. Yeah. Those are all good goals.
Dave Bittner: But within that -- and I think the thing that has caught a lot of folks' attention is this idea of engaging the private sector to be more active with offensive cyber operations. And offensive cyber, which is sometimes called hacking back or active defense, which is such a nice military euphemism [inaudible 00:18:09]. Right, right. It's like incomplete success. So this means, instead of just defending your own systems, basically putting a big wall and moat around your own organization, it means going out and messing with other people's systems, the people who hack you, going after them offensively. And the controversy here is that there really doesn't seem to be, so far, supporting legislation to make that legal.
Ben Yelin: There isn't. What's weird about that is, in the One Big Beautiful Bill, the reconciliation bill from last year, there's actually money appropriated for the private sector to conduct offensive cyber operations. I mean, I think you have to be prepared with some type of offensive cyber tools in the 21st century. I think it's necessary for our own national defense. There are really important ethical questions and setting boundaries on hacking back, but I think it would be naive to just deny that we're considering engaging in offensive cyber operations. I think that's just not the way we operate geopolitically. So I think it's good to kind of acknowledge that this is something that exists and something that we should dedicate resources to.
Dave Bittner: Yeah. This article points out that there are laws that prohibit these sort of actions. There's the Computer Fraud and Abuse Act, which is the big federal anti-hacking statute. There are some state laws from, like, New York, California, Virginia, computer crime laws there. And then there's some foreign hacking laws in other countries like the U.K., Germany, and China. The Computer Fraud and Abuse Act prohibits accessing computers without authorization or transmitting code that causes damage to protected systems. So it seems to me like, if something like this were to be encouraged, there's going to have to be changes to the Computer Fraud and Abuse Act. Yes?
Ben Yelin: Yeah. Either that or some type of federal regulation that specifies exceptions to the CFAA for these type of offensive cyber operations or, at the very least, some sort of liability shield for private companies if they are contracted to conduct offensive cyber operations. It is weird that they're creating an incentive structure for companies to identify and obstruct or disrupt adversary networks without explicitly making it legal for them to do so.
Dave Bittner: Yeah.
Ben Yelin: But I think they could potentially do that just through federal regulation. It would be much more helpful if Congress were to step in and make some changes to the CFAA to at least be explicit that hacking back in certain circumstances is legal or there's a liability shield. But I don't expect that to happen.
Dave Bittner: Yeah.
Ben Yelin: They've got more important things to do.
Dave Bittner: Yeah. And I'm leaning on some coverage here from the folks over at Lawfare, who did some digging into this. And they provided a list of business and operational risks for companies who go on the offensive. Obviously, there's reputational damage if they accidentally harm an innocent party. There's friendly fire, right? There's investor concerns, potential impact to the stock, questions about disclosure obligations for public companies. How much do you have to share?
Ben Yelin: Right.
Dave Bittner: They could lose their cyber insurance coverage. And then, of course, just relationships with their customers or partners, if they're not in agreement with this sort of thing because I really do think it stretches the boundaries of norms I guess is good way to say it.
Ben Yelin: Yeah. I think so. And, just given everything you just said there, like, I would be very hesitant to be involved in any type of national effort if I were a private company. They're just -- there are a lot of risks out there, so you need some type of regulatory clarity before you assume those risks because the easy thing for you to do is just say, I don't want to be involved in this at all. Like, I don't want to risk my reputation. I don't want to risk my status as -- as a public company. I don't want to have to disclose this and then all my customers get angry. So I think there's this kind of mismatch between the incentives being offered here and the level of risk inherent to these companies that are being incentivized.
Dave Bittner: Yeah. I mean, I think it's fair to say that this cybersecurity strategy is an aspirational document, which these things usually are.
Ben Yelin: Totally.
Dave Bittner: Yeah.
Ben Yelin: This isn't -- I mean, cybersecurity strategies are not supposed to be bullet by bullet everything we're going to do on cybersecurity as some type of official administration policy or even like a legislative agenda. It's intended to be high-level. These are what our general goals are. And I think in that sense it's appropriate.
Dave Bittner: Yeah. I mean -- and I think it really aligned. The only thing that seems to be raising eyebrows is this push towards offensive cyber operations from private companies. But the rest of it, common-sense regulation, I mean, that's totally in line with this administration. Modernizing and securing federal government networks, there's a tale as old as time, right? Securing critical infrastructure, no-brainer.
Ben Yelin: Yeah. Check that box. For sure.
Dave Bittner: Yeah. Superiority in critical and emerging technologies. Okay. We've had a leadership role. We want to stay there.
Ben Yelin: Yeah. And it's a part of this administration's posture when it comes to AI, for example.
Dave Bittner: Yeah.
Ben Yelin: And more important than anything else is for us to be a leader in this technology and to outrun our adversaries, and any way we can support that we should.
Dave Bittner: Yeah. AI I'd say also quantum is another area where they're -- you know, they want to emphasize that. And then building talent and capacity so making sure stuff's in place to keep people educated and fill that pipeline with talent, be it with human beings or AI. So I don't know. I mean, I -- I think, again, other than the part about offensive cyber, not really a whole lot of controversy here. I think it's pretty much -- there's nothing that I wouldn't expect from really any administration on this. Maybe the thing about common-sense regulations, it leans a little more towards a Republican administration than a Democratic one.
Ben Yelin: I guess. But I think Democrats would also describe their regulatory scheme as common-sense regulation.
Dave Bittner: Yeah. That's true.
Ben Yelin: Just depends on your definition of common sense.
Dave Bittner: That's right. And sense is not so common.
Ben Yelin: I mean, I think the backdrop to all of this that's important to mention is that the Department of Homeland Security is currently shut down.
Dave Bittner: Yeah.
Ben Yelin: That includes CISA. I don't know how long this is going to go on for, and a large portion of Department of Homeland Security personnel are designated as people who have to work during government shutdowns. Now, we're starting to see with people like TSA agents, they're calling in sick because they're not receiving paychecks.
Dave Bittner: Right.
Ben Yelin: So it's going to hurt the mission a little bit. But that's some context behind this as well. It's like we're in this backdrop of the entire agency that's supposed to manage cybersecurity at the federal level is shut down for the moment because of a dispute on immigration policy.
Dave Bittner: Yeah, yeah. All right. Well, we will have a link to that story, again, from the folks over at Lawfare, their coverage of this framework. So we'll include that in the show notes. Ben, I recently had the pleasure of speaking with Jean-Paul Bergeaux. He is the Chief Technology Officer for the Federal Division of GuidePoint Security. And we're talking about the Office of Management and Budget. Is that OMB?
Ben Yelin: Uh-huh.
Dave Bittner: Yeah. Rescinding two Biden-era orders which had mandated software bills of materials, known as SBOMs, from software vendors. And this was a big thing when it happened during former President Biden's administration. Lots of folks spun up whole processes and things to do SBOMs, and now it's gone. So Jean-Paul Bergeaux certainly has some expertise and is going to fill us in on what this means. Here's our conversation.
Jean-Paul Bergeaux: So this all really came back to 2020. There was a pretty significant supply chain breach of a major software provider. That breach highlighted the potential that attackers could get into the actual code released by a legitimate vendor and put into federal agencies. That then started a chain of events. The most significant that applies to this is OMB Directives M-2218, which was released in September of 2022 -- the first number is the year -- M-2316, which was released in June of 2023. And those two required that agencies first get an attestation, their own "I'm saying that I do this" of secure software development so that the agencies at least had the verbal guarantee, written guarantee, the yes, we do these things to make sure that our software does not have these problems. That was the first one in '22. In '23 it said, Hey. We want to be able to produce an SBOM, a software bill of materials, to understand what's in what we're being provided and started to say, We need these. First, we're going to require you to say that you do the secure software development. Now we're going to start to require that an SBOM is produced and available to us to make sure that we understand what's in them. And it was written and hard-coded. You must do these in order to acquire, and it was put into the FAR. So that was in '22 and '23. And so the OEMs and the agencies then had to go through the steps to have that requirement done in any purchase they made. So that's where we start. And the idea behind that was we don't want to have this happen like we did in 2020 where a bad guy got into our code of a software provider, put in malware insider hooks, and was able to get into federal environments, right? We don't want that to happen. So this is going to help us highlight that, secure that so that we don't have this happen again.
Dave Bittner: Well, correct me if I'm wrong here; but my recollection is that it was -- it's fairly straightforward. I think most people understood what was driving this.
Jean-Paul Bergeaux: Yep.
Dave Bittner: But then also a bunch of opportunities popped up for folks in the industry to help people with their SBOMs, to help them understand it. So there was a business side of this as well. Do I have that right?
Jean-Paul Bergeaux: Absolutely. There are -- there are software providers who do SBOMs, and there's two ways to do it. There is a -- when I'm developing, I need to retain and provide documentation of a software bill of materials while I'm coding. Then there are other providers -- and this is the more advanced -- that has the ability to look at a compiled and running application and provide what everyone believes is, and I think fairly accurate, a software bill of materials and says, Well, I don't even need access to the code. I can produce a software bill of materials just by looking at the application. And that is an opportunity that I still -- I think still exists. But that is an opportunity that came out of all of this where agencies were asking for SBOMs. Correct.
Dave Bittner: Was there much grousing about this? In other words, you know, we see that the Office of Management and Budget has rescinded this. Is this in response to people complaining that this was too burdensome?
Jean-Paul Bergeaux: Partly. I believe partly. I think there has been some OEMs that are not larger. It's fairly heavy on them to be able to do these things and make sure that they can attest to a secure software. Even if they're doing it, they have to attest to it and document it and really back that up and then produce SBOMs. So there is some of the medium to small providers that it was burdensome enough on them. There's also the agencies that had to go through and do this and in some cases felt it wasn't -- is this really, really good for everything we have? Maybe only for some. So there's probably some of that. I know of some that have grumbled about it. I think more -- more likely from what I'm hearing and reading from this particular administration, they wanted to put the onus on the agency to say that may not be the end of the game. Those two things are great. But there may be more risk that could be mitigated, and you as the agencies need to come up with what is it that you think you need. That could be it, and it could be no different than what we've had in the past. It could be less for some things. It could be more for some things. We want to put the onus and the risk ownership, actually, on the agencies to make those decisions and to back that up and say this is why we're making these decisions.
Dave Bittner: So SBOMs may still be a thing. They're just not mandatory.
Jean-Paul Bergeaux: I think they will definitely be a thing. I don't think they're going away. I think many agencies will have almost identical requirements that they have now. There's just going to be the freedom to say I want more than that or I want less than that and to be able to make those decisions by their own assessment of what they're purchasing and what it means.
Dave Bittner: How do you anticipate this shaking out in the immediate future here over the next year or so as people settle into these new realities?
Jean-Paul Bergeaux: I think most agencies are going to keep status quo just because that's the easiest starting point. I think few will deviate from it just because I think that's an easy way to look, Hey. I'm not going to add any more risk. I'm not going to do anything. I think this was good. I'm just going to keep doing what I'm doing. I think most will start there. I think there's two things that could happen. The most important pieces that they're purchasing, they may add more requirements to because they have the freedom to. It's not a baseline check box. So they may say, No; I want more than that for this because this is really important to my -- my mission. Then there's going to be times when they may not view the risk too great, and they may ask for less for certain ones. The most interesting to me, Dave, is going to be very small startup emerging vendors that have really interesting technology but simply don't have the resources themselves to provide what would have been required in 2218 and 2316 -- yeah, 2316. And now the agency will waive that maybe from them but still try to do some of those on their own. So they may purchase it without requiring the OEM to do it. But, as you said, there are opportunities. Maybe they'll purchase an SBOM creator that looks at a compiled and say, I'm not going to make you do it, Mr. OEM. You're a small company providing a really cool technology emerging, and I need that. But I'm going to run something against it to make sure that it's good. And, if I find things, you're done.
Dave Bittner: So bottom line for you, do you consider this to be a good adjustment? Is this a worthwhile move?
Jean-Paul Bergeaux: You know, it's funny, Dave. I really liked the first two OMB directives. I thought it was a really good thing that they did it. I endorsed it and thought this is a really good start and had never thought until the rescinding that it would be a good idea. And then, as I processed it, I said, actually, this might be a good idea, too, because we started with a requirement. We made a big deal out of it. It raised the visibility. It gave us a starting point. But now we're telling the agencies, Okay, agency. Own this. You own the decision, and you have to back up your decision to auditors when they come in and ask what are you doing. And I kind of like that too.
Dave Bittner: What do you suppose the mindset is here from the administration to make these changes?
Jean-Paul Bergeaux: This administration is not high on rules and compliance. They are high on outcomes. They want outcomes. And one of the thought processes in this is, by focusing on risk-based security versus compliance, they're looking for outcomes from the agency and shifting the risk from the administration to the agency to make those decisions for those outcomes.
Dave Bittner: Ben, what do you think?
Ben Yelin: It's really interesting. I mean, now that these requests are optional, like, what do private sector -- or what do agencies do, rather?
Dave Bittner: Yeah.
Ben Yelin: Do they move towards flexibility, or are they just trying to tread water trying to figure out what the next administration is going to do.
Dave Bittner: Right?
Ben Yelin: That just creates a level of uncertainty.
Dave Bittner: Yeah. That -- that was, you know, as we discussed, like, I not to put too fine a point on it, but the people who invested so much in SBOMs, they must be pissed.
Ben Yelin: They sure are. Yeah.
Dave Bittner: Like, you know. on the other hand.
Ben Yelin: You think you're golden, and then politics changes everything.
Dave Bittner: Right, right. But, on the other hand I guess they don't have to worry about it or invest in it or at least not for now. So that's -- I think a big unanswered question is like how much do organizations continue along that line, at least loosely or casually, on the chance that, should we get a different administration in a few years, that SBOMs will be back? Who knows. All right. Our thanks to Jean-Paul Bergeaux for joining us. Again, he is the CTO for Federal at GuidePoint Security, and we do appreciate him taking the time. That is Caveat, brought to you by N2K CyberWire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to caveat@n2k.com. This episode is produced by Liz Stokes. Our executive producer is Jennifer Eiben. The show is mixed by Tr Hester. Peter Kilpe is our publisher. I'm Dave Bittner.
Ben Yelin: And I'm Ben Yelin.
Dave Bittner: Thanks for listening.

