Caveat 4.2.26
Ep 302 | 4.2.26

Reversing the risk label.

Transcript

Dave Bittner: Hello, everyone, and welcome to "Caveat", N2K CyberWire's privacy, surveillance, law and policy podcast. I'm Dave Bittner. Ben Yelin is out this week, so I'm pleased to be joined by my N2K CyberWire colleague and author of the "Caveat" newsletter, Ethan Cook. Hey, Ethan.

Ethan Cook: Hey, Dave.

Dave Bittner: On today's show, I have the story of the Fed's pondering a cyber insurance backstop. Ethan explains why a judge has put a hold on Anthropic being designated a supply chain risk. Stay tuned for all of that. [ Music ] All right, Ethan, let's jump into our stories here. You want to start us off?

Ethan Cook: Yeah. So Anthropic, for those who have not been following along, Anthropic and the federal government have a bit of a falling out over the past month and a half. This all stemmed when there's kind of a he-said-she-said kind of thing going on where the U.S. government has said Anthropic won't let them use their AI systems for various use cases specifically related to defense. I think the original citation was the federal government posed, would you let us use us for missile defense in case the continental U.S. was attacked? And they were kind of off-put by Anthropic's answer of, ah, kind of give us a call, you know, we'll get around to it.

Dave Bittner: Right.

Ethan Cook: That's how the federal government has characterized it. Whereas Anthropic has come back and categorically, one, denied that, and then two, has said, no, that is not what we disagreed over. We disagreed over the fact that you would not give us guarantees that our AI systems would be not implemented into mass domestic surveillance systems as well as autonomous weapon systems. So you know, kind of a mile apart on the two stories.

Dave Bittner: Constitutional rights and war crimes.

Ethan Cook: Exactly, you know, it's close to defense, you know.

Dave Bittner: Right.

Ethan Cook: And so this all continued to escalate. Eventually, it kind of really boiled over with Pete Hegseth coming in and saying, if Anthropic doesn't comply by the end of the month, essentially, on a Friday, 5:01 p.m., essentially, if they do not comply with us, we are basically going to cut them all off from all their contracts and blacklist them. Anthropic said, all right, do it. See what happens. The federal government said, all right, we're going to do it and see what happens. So they proceed to then blacklist them. And it didn't just go that far. They labeled them as a supply chain risk, as well as then President Trump signed an executive order instructing all federal agencies and departments to stop using any AI systems that have been implemented by Anthropic. And this was particularly notable because this was not only the first major AI partnership that the government signed with. I think it was a $200 million contract last summer in July 2025, I believe. But this had been now six to eight months of developing these systems. This isn't something you can just rip out overnight now.

Dave Bittner: Right.

Ethan Cook: These have been integrated. These have been set up.

Dave Bittner: Right. Tight. The fact that it wasn't just this particular contract that Anthropic declined to pursue, but that basically the federal government shoved this poison pill down their throat.

Ethan Cook: Right. Yeah.

Dave Bittner: To say this whole entire federal government will not do business with you, which I think it's arguably fair to say that they are the largest customer in the world for many of these things. So what's the response been from observers here? I mean, it seems to me, in my opinion, that this is clearly retaliatory on the government's part that they didn't get what they want, so they're going to push back.

Ethan Cook: Yeah. So from I think there's kind of two perspectives that you can kind of give the pushback on, which is first is the industry perspective. Ignoring that, OpenAI immediately then signed a deal with the federal government, basically doing the exact same thing that Anthropic was doing. You know, there was some drama related to it. There's a whole other conversation about less restrictions on the old mass domestic surveillance and autonomous weapons systems. But there was a lot of support for Anthropic afterwards. Basically, you know, companies coming out and saying this is a very dangerous road where we have ideological differences from a business perspective with the federal government. They can then just turn around and blacklist you. And it's worth noting that this blacklist thing wasn't just like, oh, federal contractors, you know, you know, the DOD or this, you know, the FCC or name an agency aren't able to work with you. Blacklist was labeling them as a supply chain risk, which is this is something that is typically preserved for foreign adversaries. And that prevents anyone who touches the federal government pretty much from working with you, which was expected to impact the relationships for Anthropic with over 100 different clients. So this wasn't just like, oh, we can't get the federal government. That $200 million is gone. This is something that's going to not, I think, destroy their business line, but certainly would be unhelpful and disruptive to their operations. So Microsoft, as well as some other big AI companies, et cetera, people in OpenAI who were mad at OpenAI basically backed the government, signed letters quitting. And all of them came out and said, like, this is something that we are vehemently against. And then you also saw a lot of government officials coming out saying, like, hey, this is unprecedented. We have never had an executive branch coming through and just cherry pick executive or cherry pick contractors and say, I don't like you because of X, so I'm canceling all your contracts right now.

Dave Bittner: Right.

Ethan Cook: And even though they signed them --

Dave Bittner: It's a philosophical thing. Wasn't it? I mean, it's certainly been a political talking point from the Republicans that the government shouldn't be picking winners and losers.

Ethan Cook: Yeah. Exactly. And so the response from there was on both sides of that was like, this is a very broad leap in terms of what we're doing. And honestly, very scary because let's take this to its logical conclusion, if we're saying this is okay, then any new administration that comes in says, okay, oh, I don't like this company because of X. So I'm going to just delete them now from the federal government and put in my people that I like. And then four years later, the next person comes and does that. Let's say it's a new administration. Then we can just get this thing where nothing gets done because, as we all know, the federal government moves the pace of a snail. So by the time we get a new contract spun up, it's going to take two years and everything gets going. So they get a year and a half of progress. We delete them in a year and a half of progress. Delete them over four years. It's just not worth it.

Dave Bittner: Right. Right. No, obviously, all sorts of perils that come out of operating this way. And that's why we have these rules and regulations to try to prevent these sorts of things.

Ethan Cook: Yeah.

Dave Bittner: So that brings us up to where we find ourselves today. What's the latest with this ruling from a judge?

Ethan Cook: Yeah. So Anthropic filed two lawsuits in response to this designation, which obviously they filed one in California and one in D.C. Now, this update is specifically for the one in California. The D.C. one has not made any progress that I'm aware of. So there is this potential where there could be conflicting results, but I don't know. But in California, a federal district judge has ruled in favor of Anthropic and put a temporary pause on this reclassification. It basically overturned it for the time being and had pretty much crushed the opposition statement on this one, or I should say the government's position on this one. They're labeling it as a classic illegal First Amendment retaliation.

Dave Bittner: That's not ambiguous.

Ethan Cook: Yeah. Right. So they called it that. I believe in the judge's opinion, she labeled it as Orwellian, dystopianesque. It was just a very, very stark response to basically saying not only is this unprecedented, but this is so clearly retaliatory because they did not do what you wanted to do. And you did not follow the proper procedures to remove them because you decided to do in essentially a week. And it takes way longer to do that. You know, we have to go through processes and steps. You can't just shut someone off, turn off the faucet. Clearly the Anthropic is going to win this legal battle was the judge's opinion. So which is why she put the temporary injunction to kind of pause this whole the order as well as all that. So with that, the federal government has already announced it is going to appeal this injunction and, you know, try and shut it down. And the judge kind of implied that they would have a very, very steep uphill battle.

Dave Bittner: Come at me, bro.

Ethan Cook: Exactly. Because they decided to do this on such short notice and were basically like, yeah, well, you know, let's pull the trigger. You know, one minute we're with them, one minute we're not. She's like, you didn't follow any proper procedures. So like we can point to eight things you did wrong or whatever the number is. Right? And she's like, you didn't do this. You didn't do that. So you're going to really have to convince me that this was something that, you know, not only the ending, the contract was appropriate, but then going in so far to label them as a supply chain risk on top of that. Like we really crossed some lines here.

Dave Bittner: Well, I wonder, too, despite all of the legal machinations that are going on here, if I'm a supplier to the federal government and I'm caught up in the middle of this as is a bystander, right? I'm using Anthropic for various things within the product that I supply to the feds and I see all this going on. What's my best move? Because I don't want to displease the government. And if we have -- you know, this administration is not known for its subtlety. If they don't like something, they will respond to it and do so, you know, quickly and forcefully. So even with these rulings, I wonder if you're caught up in the middle of this, do you shift away from Anthropic just because or do you any new projects that you start, do you not use Anthropic just because? In other words, has the brand been sullied? Has the word been put out from the feds that even despite the legal wranglings, you're going to be better off to just stay away from Anthropic because they're kind of poison?

Ethan Cook: In my personal opinion, given that the legal uphill battle for the administration to prove that they were correct on this one is going to be so steep, I don't think there's a world where Anthropic really stays blacklisted. We're talking one of the top three, and probably in some metrics, arguably the largest AI producer in America, certainly one of the most advanced ones, and something that has integrated itself not just within the federal government but within business lines in all various aspects. Removing one of these people from just the industry is, I think, really hard to do. Now, obviously, labeling them as a supply chain risk is a great way to do it because now it's not a choice, it's a legal requirement to not use them. But given that that's probably not going to be upheld, that opens the door, obviously, for now. It's kind of that, to your point, it's subjective. It's like, well, what's good for the business kind of thing or what's good for me? I think what it's probably going to result in is a lot of people are going to have to have some really uncomfortable conversations, not about the quality of the product they're getting, but how much risk, kind of subjective risk tolerance they have, where it's, okay, obviously, even if we go back to normal and they can't rule us, et cetera, but it's clear that they're not going to renew them. Even if they have to reinstate them for the remainder of this contract, it's clear the Trump administration has no interest in working with them, and they're not going to want to expand upon or renew this contract. Is that something where -- we have this openly hostile relationship. Is that something that we really want to risk tolerate and really want to just kind of keep in our back burner? Or is it more advantageous to switch to a competitor, whether it be like a Microsoft Copilot or it's a, you know, ChatGPT or whatever it is? Is that more safe?

Dave Bittner: Right, right. It also strikes me just that the government might be shooting themselves in the foot here from a national point of view when we're in the midst of this global race to dominate with AI. If you only have a handful of players, why throw one out?

Ethan Cook: Oh, I agree.

Dave Bittner: If a player that's in a leadership position is performing as well or if not better than many of its competitors, depending on how you measure, why would we take that potential competitive advantage off the table out of spite?

Ethan Cook: Yeah, I think it's also particularly weird coming from an administration that has said since day one that all it cares about in the AI space is AI advancement, which, you know, it has come through and said we want no regulations. I mean, AI preemption has come up 10 times, it feels like, in the last year alone, right?

Dave Bittner: Right.

Ethan Cook: Just to remove all state laws, let's break the handles off everything, you know, remove the red tape and just go full crazy with development. To then turn around and say, well, we did want that, but only if you're willing to play ball with us. And I think that, you know, this whole situation has kind of opened the door, which is, you know, kind of classic Trumpism where it's they are cool with development or, you know, advancement, business advancement, as long as it is under the purview of what the Trump administration wants. So they don't care about unrestrained progress as long as they get their cut. And in this case, according to Anthropic, the cut is unclear, muddy waters when it comes to AI being used in automated defense systems and mass domestic surveillance. And I think that that is a very scary aspect for AI where not just for obviously the use cases, that's obviously terrifying, but in the premise of, we have this booming industry that is one of the only industries that has been successful, economically speaking, in the past several years. And we're willing from a government perspective, at least from a Trump perspective, to shoehorn it, to slow it if the industry does not play ball for the administration's AI goals.

Dave Bittner: So what are the possibilities here going forward? How might this play out?

Ethan Cook: Yeah, so I think there are two kind of -- with the two court cases, I think that we're going to have interesting developments on both ends. Obviously, the California case has already come out and voiced some pretty strong favoritism to Anthropic. Not surprising, given that it's California and that's Silicon Valley. And also the judge, I believe, was appointed by Biden. So already more of a left-leaning perspective there. So unsurprising there, I would be highly, highly shocked if the judge comes out and, again, given her initial opinion on the matter, changes her opinion drastically for the federal government or comes out and says, oh, I didn't mean that, you know, we're going to keep the designation. I expect her to continue course and overturn this thing. I think the interesting thing will be to see how D.C. plays out. Specifically, not that they will overturn it. I think that likely will get overturned because this was such an unprecedented move. But if there is nuances in what is overturned and to the extent of its overturn, et cetera, because that's where I think we're going to get into a legal gray zone where it's going to be, okay, if we have two court cases, both at the federal level, disagreeing on this matter, then -- and not in terms of fundamental differences, but in just terms of nuance, what does that play itself out? And does this eventually make its way up even further? Does it go to appeals? Does it go up higher? And, you know, I think there's a world where it could hit the Supreme Court. And that would be a very, very interesting ruling. And I don't know, part of me says the Supreme Court -- you have Clarence Thomas who would be like probably, oh, give Trump whatever power he wants. But in the last ruling, the major ruling, the Supreme Court came out against his tariffs. And, you know, that was kind of a shocker. So I don't really know where it goes, if it goes there.

Dave Bittner: Yeah. No, it'd be interesting to play. I mean, it seems to me like the constitutional issues are pretty clear. And that's the point that the judge made. But I guess it could be a win the battle, lose the war thing for Anthropic, right? Because there's so much subtext here. And I guess that's kind of a mark of where we are these days, where even if you do the right thing or do what you believe in or try to stand up for whatever standards you have set for your own organization, sometimes you're going to find yourself up against things. And it's hard to push that rock uphill, I guess, to make metaphors.

Ethan Cook: Yeah.

Dave Bittner: Well, it's one to keep an eye on for sure. It's a head scratcher, I guess, in a lot of ways. But on the flip side, I guess in some ways not at all surprising.

Ethan Cook: Yeah, not surprising at all. You know, I was waiting -- you know, I think there's always that moment with the Trump administration where, you know, everything you think is going to play itself out flips on its head. And this has happened numerous times for different sectors and businesses and allies, et cetera. And I was waiting for the dissolution between him and AI because it was going to happen at some point. I didn't know what it was going to look like, how wide it was going to be. This one is actually smaller than I thought it was going to be. I think it's going to be over quickly given the clear violations of executive power that played out. Whether it goes up further in the appeal, et cetera, I think that will be an interesting one. But I'm not surprised that him and AI have finally had some rocky waters given just his past nature and relationships.

Dave Bittner: Right. Just the notion that someone said no, which is, you know, a quick way to get on President Trump's bad side. I mean, time and time again. So yeah, it's going to be interesting to see how it plays out. All right. Well, we will have a link to that story in the show notes. Let's take a quick break to hear from our sponsor. We'll be right back after this message. [ Music ] And we are back. Ethan, my story this week comes from the folks over at GovInfoSecurity. And I have to say, when I saw this story come by, I kind of did a little fist pump for myself because I think listeners to this show and maybe the CyberWire have heard me say over the past few years that I wondered if we were going to see some kind of a federal backstop for cyber insurance. In the same way that the federal government provides flood insurance, I wondered whether it was inevitable that that would have to happen with cyber insurance just because of the numbers that are involved and all that sort of thing. And wouldn't you know it? We're looking into it.

Ethan Cook: We're here.

Dave Bittner: Well, yeah.

Ethan Cook: 2026, we're here.

Dave Bittner: Right.

Ethan Cook: I forgot the year for a second.

Dave Bittner: So it's not happening yet. Basically, what's happened is the Treasury Department has put out a request for comment on how cyber incidents might fit within this program called TRIP, which is the Terrorism Risk Insurance Program. TRIP was created after 9-11. And basically, it creates this federal safety net when terrorism losses exceed industry thresholds. So the concern is that -- the way the insurance industry works is a whole lot of people pay in and you get a certain number of claims every year and hopefully the claims don't exceed what's paid in and the insurance company makes some money and people get their insurance claims and everybody wins. But certainly, historically, we've seen things like a major hurricane comes through.

Ethan Cook: Oh, I wonder where that happened.

Dave Bittner: The insurance companies take it on the chin because the losses exceed what they've taken in. What the feds are looking at here is the possibility that there could be a cyber event that exceeds the capability of the insurance companies to maintain their businesses and having to pay out and so providing some sort of federal backstop for that.

Ethan Cook: Yeah.

Dave Bittner: Before we dig in any more here, what are your initial thoughts when it comes to this sort of thing?

Ethan Cook: Yeah, I mean, from a risk management perspective, I'm very passionate about cyber risk and how we as an industry approach it, or sometimes I should unfortunately say don't approach it. This is something that I think has been long, long, long overdue. And while it's not there yet, obviously, we're still doing public comments. I think it's something that I don't really see as a lose in any capacity. I mean, I guess the only way if you're really trying to nitpick is saying, well, now the federal government's going to slow things down, et cetera, blah, blah, blah, blah, blah.

Dave Bittner: Yeah, and it would cost money. I mean, obviously, any program costs money, so there are budget concerns.

Ethan Cook: Absolutely, but I kind of always walk away, and my evaluation when the federal government decides to make a new program is like, is the net positive there? Can I make the argument in my head? Because anything the federal government's going to do is always going to create red tape. It's always going to cost money, and there's always going to be some politician who gets his hands in it who was like, let me try and put my thing in there that has nothing to do with this, but I'm going to try to do it anyways.

Dave Bittner: Right, right.

Ethan Cook: But at the end of the day, does it still net positive for the industry that it's touching, the businesses that it's touching, the individuals that it's touching? Is it net positive? And I think in this case, it's very clear in my mind that it is. You know, the cyber incident area and the cyberspace in general is so understood and yet untouched in so many ways, where you have these year-over-year just major incidents happening. And every year we go, how did this happen? You know, how are we still having this happen? And, you know, it's because some person still is not securing a server and not just not securing it. They don't have a password on it or something. Or it's like, yeah, we still don't have multi-factor authentication. And you're just like, how? You know, this isn't, you know, 2015 here. This is 2026.

Dave Bittner: Yeah, I mean, I like the metaphor of comparing it to public health, where on an individual level, you can do everything that you should do. You could wash your hands. You can take your vitamins. But every now and then, you're still going to get a cold.

Ethan Cook: Yeah.

Dave Bittner: And so I think the notion of eliminating cyber risk and cyber threats is unrealistic. But certainly we should minimize them. And in this case, what they're talking about is should there be a backstop? You know, I kind of nerded out probably about a decade ago. The home that I live in is not that far away from a lake. And so when my wife and I bought the home, it was designated as not being in a flood zone. So I didn't have to pay extra flood insurance. The way that it works is if your home is in a flood zone and you have a mortgage, the government requires that you pay into this federal flood insurance program. So we weren't in that. And it's not cheap.

Ethan Cook: With the federal government, nothing is.

Dave Bittner: Yeah. So we were not in this flood zone. And then the feds, you know, I think they tossed some new satellites up into space that were able to more accurately map the terrain. And they came back and said, good news, you're now in a flood zone.

Ethan Cook: Good news. We'll take an extra chunk from you every year.

Dave Bittner: Right. So anyway, my point is that there was a period of time about a decade ago and I was really nerding out on this and learning all about it. And how this is relevant is that one of the things I learned is that flood insurance is terrible insurance. It's not good at all. It is just a basic backstop. It's costly. It really doesn't cover a lot. It's not up to the level of, say, your homeowner's insurance where you can say to them, oh, I want to spend some money and make sure that everything gets put back the way it was. Like, that's not an option with flood insurance. It's just sort of like we're going to put -- you know, when we're all said and done, there'll be a house there.

Ethan Cook: Theoretically.

Dave Bittner: Yeah. Yeah. So my concern or my question is, if this were to play out, if the Treasury Department decides this is something that we need to we need to offer, will it be any good? You know, to what degree will it really put people at ease? How much of a backstop will it be? These are all unknown questions. But based on what we've seen with flood insurance, I'm left wondering.

Ethan Cook: Yeah. No, I think it's a great question. Obviously, we'll have to see what the final version of it is. But I think in an ideal world, it's great and it covers and it's super perfect, right? And when you bring it back to reality, I think there is a world where I imagine we're going to get into a very legally gray and complicated zone on what is a cyberattack. And what are the different types of cyberattacks? Is it ransomware? Is it a scam? Is it an insider threat? You know, what are the different attack vectors, et cetera? And that's going to make -- it's not like, you know, to take a step back and say a flood. Well, sure, you can get into the nuances of where the flood came from. Was it a hurricane? Was it a, you know, rising river or whatever?

Dave Bittner: Oh, yeah. I talk to insurance people. There's a whole thing about whether the water comes up from below or down from the sky.

Ethan Cook: Like, yeah, I'm sure that you got to make a nuance thing. Right?

Dave Bittner: Yeah.

Ethan Cook: But, you know, there is at least the element of like, okay, the basement's full of water. I'm pretty sure I'm flooding. Right? You know, I think you get into a cyber. And I think part of it is because there is no general consensus from like an industry perspective on what we would define as severe. You know, is it one million people affected? Is that severe, or is it 10 million people affected? Obviously cyberattacks have been evolving over the past decade, you know, whether it be ransomware, which has exploded onto the scene. We've had a lot of, you know, phishing and social engineering attacks have always been dominant, but the way they've been executed over the years has been changing. Each of these, you know, I guess, nuances of cyber, because cyber is such a large and broad category, I think that's where this is really going to be hard to predict if it's going to be effective. And I think that's where it's going to be like, okay, how do we set up a program that actually provides comprehensive or at least manageable backstop coverage, right? And without getting overly complex and bogged down in this legal, you know, red tape, you got to go through this to go through that to go through this to then maybe get coverage. Now it's like, okay, what are the metrics? What is it? Does it only cover businesses over a set size? And if you're under that, it's not considered -- like if you're just a mom-and-pop shop or like a small scale Internet provider, is that something that you have to be aware of or is there no federal support? And I think it's a really great concept of a program and I'm not against it at all. Like you, I fist pump as well. Right? But I think when we bring it back and I'm like, okay, how does this actually look? And I sit there and go, this is really, really, really complicated and nuanced. And it's why a lot of businesses have just started buying cyber insurance from a private party because they just go, this is way too complicated. And I don't know if the federal government is really in the position at the moment to actually sit down and make a comprehensive plan here.

Dave Bittner: Yeah, I mean, I think the initial goal is to handle, you know, hurricane level attacks. Right? You know, things like Solar Winds.

Ethan Cook: Salt Typhoon.

Dave Bittner: Salt Typhoon. Yeah. Just, you know, the nightmare scenarios we talk about. There's no water. There's no electricity. Those sorts of things that are that are in the category of catastrophic clearly, then that's, I think, the initial wave of what this would cover. Where it gets stickier is when you get down to those smaller types of events. Who's paying in, all those kinds of things. It's interesting. This article notes that over in the UK, they had considered a similar cyber insurance scheme, but they decided not to do it. They were concerned about market distortion. So in other words, the private companies feeling as though, hey, good news, we've offloaded some of our risk to the federal government. And how does that affect things?

Ethan Cook: Yeah, I mean, I think that has been a longstanding kind of question, which is let's say we go and we create this program and companies kind of then first turn around and say, well, I have my risk partially covered by the federal government now. I don't need to go buy private insurance, right, or invest in it as much. I think then you get into the concern of, okay, obviously, how does that impact the space from a market perspective for these insurance companies, et cetera? But then I think also, does that change how people evaluate risk if they say, oh, well, I have the federal government to back me up. I don't really even need to secure myself because the federal government will cover my butt. Right? From a loss perspective, you know, whatever about the consequences.

Dave Bittner: Right. We have a cyber FEMA.

Ethan Cook: Yeah. And I think that gets into that weird kind of zone, which is are we doing more harm by implementing a safety program than we are doing good?

Dave Bittner: Yeah.

Ethan Cook: And that I am really interested to see what the discourse is from actual insurance companies as well, because I don't know if they would see this as a win.

Dave Bittner: Yeah. I mean, that's a really interesting question. I think they would appreciate the fed stepping in when the insurers are in over their heads, because that's really what this is about. I don't think it's designed to replace private insurance.

Ethan Cook: No.

Dave Bittner: It's just there when the insurance companies can say this is too big for us to cover, this is an extinction event for us. Help. Right?

Ethan Cook: Yeah.

Dave Bittner: Yeah, I don't know. And honestly, I don't know enough about, you know, the structure of insurance companies and all that sort of thing to know really how it would or wouldn't affect them. But it's just interesting to me and I guess kind of, you know, validating some of the things that I thought were inevitable that the government is putting out a request for comment on this to see what people think.

Ethan Cook: Yeah, I think it was an inevitable conclusion. You know, I think given that breaches happen, not just like small scale breaches, but major breaches happen pretty much year over year. There's at least one major one, at least one major one every year, whether it's UnitedHealthcare, whether it's, you know, SolarWinds, Salt Typhoon, whatever it may be, that aren't just impacting, you know, a small state or, you know, a small section of a business area, but like are, okay, this is impacting half the nation or potentially has compromised the entire nation or whatever it may be. How do we as a federal government manage that? Because it's clear that when left to their own devices, private industry is not living up to the par because we're still having this every year. So what are the ways that as a government, we can approach this, right? And what are the ways that we can do it from both a regulatory perspective as well as a recovery perspective? And I think the recovery part, we've kind of started to have the regulatory conversation. It has evolved over the years and there are regulations in place. Everyone will have their own opinion on whether they are effective or not. But that's besides the point, we've had the conversation. But I think the recovery perspective has largely been ignored. It's been of the point of, okay, well, how can we get you back if something happens and, you know, kind of contact us and we'll work with you rather than like, let's actually have a designated system or plan in place for recovery.

Dave Bittner: Yeah, I mean, it's good to see this sort of proactive approach happening.

Ethan Cook: Yeah.

Dave Bittner: I mean, I guess you could say if it's taken them this long, maybe it's not proactive, but I don't know. Give them the benefit of the doubt that they're trying to get ahead of things.

Ethan Cook: I'll take anything, any progress.

Dave Bittner: That's right.

Ethan Cook: I'll take anything.

Dave Bittner: Especially, yeah -- I mean, you're right. The pace, the way that Congress in particular seems to be bogged down in everything, anything we can get moving forward, it would be a good thing here, I suppose it's fair to say. All right. Well, we will have a link to that story in the show notes. Again, that's from the folks over at GovInfoSecurity. [ Music ] And that is "Caveat", brought to you by N2K CyberWire. This episode is produced by Liz Stokes. Our executive producer is Jennifer Eiben. The show is mixed by Trey Hester. Peter Kilpe is our publisher. I'm Dave Bittner.

Ethan Cook: And I'm Ethan Cook.

Dave Bittner: Thanks for listening.