Main Stage: Solving the Cyber Hard Problems: A View into Problem Solving from the White House
Unknown
Black Hat USA 2024 · Day 1 · Briefing
Overview
This Black Hat USA main stage talk featured Director Harry Coker of the White House’s Office of the National Cyber Director (ONCD) in a candid discussion about the United States’ National Cyber Security Strategy and its ongoing implementation. The conversation, moderated by an unnamed former National Security Council (NSC) official who was instrumental in the strategy's development, delved into the evolving landscape of cyber threats, particularly the escalating impact of ransomware and other disruptive incidents on critical infrastructure. Director Coker’s presence at Black Hat underscored the administration's commitment to engaging directly with the security research community, recognizing its vital role in addressing complex national cybersecurity challenges.

Key moments
- 0:00 Director Coker's welcome and purpose at Black Hat
- 1:15 Evolving cyber threats: from data breaches to critical infrastructure disruptions
- 2:15 Introduction to the National Cyber Security Strategy's vision
- 3:00 Strategy's core shift: responsibility to most capable entities
- 4:50 The role of regulation in critical infrastructure cybersecurity
Main Stage: Solving the Cyber Hard Problems: A View into Problem Solving from the White House
Speakers: Harry Coker, Director, Office of the National Cyber Director (ONCD), The White House
Conference: Black Hat USA
YouTube: https://www.youtube.com/watch?v=U03KN2fc904
Overview
This Black Hat USA main stage talk featured Director Harry Coker of the White House’s Office of the National Cyber Director (ONCD) in a candid discussion about the United States’ National Cyber Security Strategy and its ongoing implementation. The conversation, moderated by an unnamed former National Security Council (NSC) official who was instrumental in the strategy's development, delved into the evolving landscape of cyber threats, particularly the escalating impact of ransomware and other disruptive incidents on critical infrastructure. Director Coker’s presence at Black Hat underscored the administration's commitment to engaging directly with the security research community, recognizing its vital role in addressing complex national cybersecurity challenges.
The talk emphasized a fundamental shift in cybersecurity policy: moving the burden of defense from the "least capable" entities, such as small businesses, schools, and hospitals, to the "most capable" — those who design, build, and operate the digital infrastructure and services upon which the nation relies. This strategic pivot aims to foster more resilient and secure digital foundations for economic prosperity, technological innovation, and national security. The discussion also highlighted the increasing acceptance of regulation as a necessary tool to enforce baseline cybersecurity practices within critical infrastructure sectors and the crucial need for regulatory harmonization to ensure effective implementation without imposing undue friction on industry.
Director Coker articulated the White House's view that cybersecurity is no longer merely an issue of information assurance but has become central to the functioning of core critical infrastructure. The severe real-world impacts of recent cyber incidents, such as disruptions to healthcare services and airlines, serve as stark reminders of this new reality. By focusing on ecosystem-level interventions and fostering robust public-private partnerships, the ONCD seeks to proactively tackle "hard problems" like cybercrime and ransomware, moving beyond reactive measures to build a more secure and resilient cyber future for the nation.
Background
▶ Watch: Director Coker's welcome and purpose at Black Hat (0:00)
The contemporary cybersecurity landscape has evolved dramatically, transitioning from an era characterized primarily by data breaches in the 2010s to one defined by critical infrastructure disruptions. Speakers at the conference highlighted recent incidents such as the widespread impact on Change Healthcare, the Crowdstrike incident, and numerous ransomware attacks affecting hospitals and airlines, which have had tangible, real-world consequences beyond mere data compromise. An emergency room doctor, for instance, presented a harrowing account of the direct impacts on patient care and hospital operations following a ransomware event, underscoring that cybersecurity is now a matter of life, safety, and core operational functionality, rather than just information security.
This escalating threat environment spurred the development and release of the National Cyber Security Strategy approximately a year and a half prior to the Black Hat talk. Authored by Director Coker’s office, the strategy represents an affirmative vision for the nation's digital foundation, recognizing its indispensable role in national security, economic prosperity, and technological innovation. It acknowledges that the digital infrastructure underpins every aspect of modern life, making its security a paramount national imperative. The strategy was born from the recognition that the previous approach, often placing the onus of defense on individual users or smaller, less-resourced organizations, was unsustainable and ineffective against increasingly sophisticated and well-resourced adversaries.
Prior to this strategy, cybersecurity efforts often focused on encouraging "potential victims" to improve their individual behaviors and defenses. While valuable, this approach proved insufficient to address systemic vulnerabilities and the scale of modern threats. Many entities, including schools, houses of worship, and small healthcare providers, simply lack the resources, expertise, and capabilities to mount an adequate defense. This created an environment where attackers could consistently find and exploit the weakest links in the digital ecosystem, leading to cascading failures that impact broader society. The National Cyber Security Strategy was thus conceived to address this fundamental imbalance, aiming to implement systemic changes rather than relying solely on individual endpoint hardening.
Key Findings
▶ Watch: Evolving cyber threats: from data breaches to critical infrastructure disrupt... (1:15)
The central pillar of the National Cyber Security Strategy, and a recurring theme throughout the discussion, is the paradigm shift in responsibility for defending cyberspace. The strategy explicitly aims to move this burden from those "least capable" to those "most capable" of implementing robust security measures. This means that instead of placing the primary defensive responsibility on end-users, small businesses, or under-resourced critical infrastructure entities like local hospitals and schools, the focus shifts to the developers, manufacturers, and large operators of software, hardware, and digital services. These "most capable" entities are better positioned to integrate security by design, manage supply chain risks, and deploy sophisticated defenses at scale.
A significant, and previously "dreaded," shift in policy articulated by the strategy is the embrace of regulation for cybersecurity practices within critical infrastructure. For years, the concept of mandatory cybersecurity requirements was met with resistance, perceived as a drag on innovation and industry. However, the escalating frequency and severity of disruptive cyber incidents have demonstrated that voluntary measures alone are insufficient. The strategy now champions regulation as a necessary tool to establish baseline security standards, ensure accountability, and drive systemic improvements across vital sectors. This includes specific requirements like incident reporting, exemplified by the recently released CISA rule on critical cyber incident reporting for critical infrastructure entities, which mandates timely disclosure of significant cyber events.
Crucially, the strategy also acknowledges the potential pitfalls of fragmented regulatory landscapes. With various government departments and agencies potentially imposing different, sometimes conflicting, cybersecurity requirements, there is a risk of creating undue "friction and drag on industry." To mitigate this, a key finding and ongoing effort is regulatory harmonization. The ONCD has been tasked with initiating conversations and coordinating efforts to streamline these requirements, aiming to achieve desired security outcomes efficiently without overwhelming regulated entities. This need for harmonization is so critical that a bill, introduced by Senators Peters and Lankford, is currently in Congress seeking to codify this responsibility for the ONCD, highlighting its importance in ensuring a coherent and effective national cybersecurity posture.
Finally, the talk underscored the indispensable role of public-private partnership. Director Coker explicitly stated that the federal government cannot solve the complex cybersecurity challenges of today and tomorrow in isolation. A "true partnership" with the private sector, including the security research community, is essential. This collaborative approach recognizes that innovation, threat intelligence, and defensive capabilities are distributed across both government and industry. The ONCD's presence at Black Hat, listening and learning from security researchers, exemplifies this commitment to fostering a symbiotic relationship to collectively address the nation's "hard problems" in cyberspace.
Technical Deep Dive
▶ Watch: Introduction to the National Cyber Security Strategy's vision (2:15)
While the talk primarily focused on policy and strategy rather than granular technical exploits or code, the implications for technical implementation are profound and represent a significant paradigm shift in how cybersecurity is approached at a national level. The core concept of shifting responsibility to the "most capable" entities has direct technical ramifications, pushing for secure-by-design principles and upstream security interventions. This implies that those who develop operating systems, network devices, cloud platforms, and critical software components are expected to embed security features from the outset, rather than relying on downstream users to patch vulnerabilities or configure complex defenses. This includes a focus on the security of the software supply chain, particularly for widely used components like open-source software (OSS), which was briefly mentioned as a challenge identified by the security research community that the White House is addressing. Securing OSS involves investing in vulnerability discovery, patching mechanisms, and ensuring the integrity of development pipelines.
A key technical mechanism introduced by the strategy is enhanced incident reporting. The CISA rule on critical cyber incident reporting for critical infrastructure mandates a structured approach to how incidents are identified, analyzed, and communicated. Technically, this requires critical infrastructure entities to establish robust detection capabilities, implement clear incident response playbooks, and integrate mechanisms for rapid and accurate reporting to CISA. The data collected through these reporting requirements provides crucial threat intelligence, enabling government agencies to identify emerging attack patterns, correlate incidents across sectors, and disseminate timely warnings to other potential victims. This creates a collective defense mechanism, transforming individual incidents into shared learning opportunities.
The initiative for regulatory harmonization also presents a significant technical challenge and opportunity. Currently, various federal agencies might impose differing technical standards, auditing requirements, and reporting formats. Harmonization efforts aim to coalesce these into a more unified framework, potentially leveraging existing and widely accepted cybersecurity frameworks like the NIST Cybersecurity Framework. From a technical perspective, this involves developing common security controls, shared assessment methodologies, and interoperable data formats for compliance reporting. The goal is to reduce the burden on industry by providing clear, consistent technical guidelines that can be applied across multiple regulatory mandates, allowing organizations to invest in a single, robust set of security controls that satisfy diverse requirements. This could involve standardizing security architectures, adopting common security protocols, and leveraging automation for compliance validation.
Furthermore, the strategy's emphasis on protecting critical infrastructure implies a technical focus on operational technology (OT) and industrial control systems (ICS) security. Unlike traditional IT, OT environments often involve legacy systems, real-time constraints, and unique communication protocols that demand specialized security approaches. The shift in responsibility means that vendors and integrators of OT/ICS solutions are expected to deliver more secure products, with robust segmentation capabilities, secure remote access, and built-in anomaly detection. While the talk did not delve into specific OT/ICS technologies, the broader strategic imperative clearly encompasses these specialized technical domains, pushing for a higher baseline of security across all components of critical infrastructure.
Demo / Proof of Concept
▶ Watch: Strategy's core shift: responsibility to most capable entities (3:00)
This main stage discussion was a high-level policy dialogue and did not include any technical demonstrations or proofs of concept. The speakers focused on outlining the strategic direction and implementation progress of the National Cyber Security Strategy, rather than presenting specific tools, exploits, or defensive technologies.
Defensive Implications
▶ Watch: The role of regulation in critical infrastructure cybersecurity (4:50)
The National Cyber Security Strategy and its implementation carry significant defensive implications for a wide range of stakeholders, fundamentally altering the approach to cybersecurity across the nation.
- For Critical Infrastructure Operators: These entities, ranging from healthcare providers and energy companies to transportation and water utilities, should anticipate increased regulatory scrutiny and mandated cybersecurity requirements. This includes establishing robust incident reporting capabilities to comply with rules like the CISA critical cyber incident reporting mandate. Defenders in these sectors must proactively invest in modernizing their security postures, aligning with established frameworks such as the NIST Cybersecurity Framework, and implementing controls that address systemic risks rather than just individual vulnerabilities. This also means dedicating resources to understand and comply with harmonized regulations, which, while intended to reduce burden, will still require significant internal effort to implement effectively.
- For "Most Capable" Entities (Technology Developers, Manufacturers, and Large Operators): This group bears a heightened responsibility for embedding security into their products and services from the earliest stages of development. The emphasis on secure-by-design principles means that software developers, hardware manufacturers, and cloud service providers must prioritize security features, conduct thorough vulnerability testing, and implement secure development lifecycles. This also extends to managing the security of their supply chains, particularly for open-source components, requiring rigorous vetting, dependency management, and rapid patching mechanisms. Failure to meet these expectations could lead to regulatory penalties or market disadvantages as customers increasingly demand inherently secure solutions.
- For the Security Research Community: The White House explicitly values engagement with the security research community. Defenders and researchers are encouraged to continue identifying "hard problems," disclosing vulnerabilities responsibly, and providing actionable feedback on policy and technical implementations. This collaborative spirit is crucial for refining the national strategy, developing innovative defensive techniques, and sharing threat intelligence that can bolster collective defense. Participation in government-led initiatives, providing expert advice, and contributing to open standards will become even more impactful.
- For Federal Agencies: The strategy mandates a coordinated approach to cybersecurity, requiring agencies to work together on regulatory harmonization. This means moving away from siloed requirements and towards unified, consistent guidance for industry. Agencies like CISA will continue to play a central role in providing operational guidance, threat intelligence, and incident response support, while others will focus on sector-specific regulatory oversight. This requires internal defensive efforts within government to be robust and exemplary, as the federal government cannot credibly demand security from the private sector without demonstrating it itself.
- Overall Shift to Proactive Risk Management: The strategic shift moves the nation from a reactive, incident-response-heavy posture to a more proactive risk management and systemic resilience approach. Defenders across all sectors must transition from simply reacting to breaches to actively identifying and mitigating systemic risks, investing in foundational security practices, and fostering a culture of continuous improvement. The goal is to create an ecosystem where vulnerabilities are addressed at their source, and critical functions are inherently resilient to cyber attacks, thereby reducing the frequency and impact of disruptive incidents.
Key Takeaways
- Shift in Responsibility: The National Cyber Security Strategy fundamentally shifts the burden of cybersecurity defense from the "least capable" entities (e.g., end-users, small businesses, hospitals) to the "most capable" (e.g., technology manufacturers, large service providers, critical infrastructure operators).
- Critical Infrastructure Protection through Regulation: Cybersecurity for critical infrastructure is recognized as a national security imperative, with the strategy embracing regulation (including mandatory incident reporting via rules like CISA's) as a necessary tool to enforce baseline security practices and ensure accountability.
- Regulatory Harmonization is Crucial: To avoid undue friction on industry, the ONCD is leading efforts to harmonize disparate cybersecurity regulations across different federal agencies and sectors, aiming for consistent and efficient compliance.
- Cybersecurity as Foundational: The strategy affirms that cybersecurity is no longer merely "information assurance" but is core to national security, economic prosperity, technological innovation, and the functioning of essential critical infrastructure.
- Indispensable Public-Private Partnership: The federal government acknowledges it cannot solve complex cyber problems alone and requires a robust, true partnership with the private sector, including the security research community, to develop and implement effective solutions.
- Focus on Ecosystem-Level Interventions: The strategy emphasizes moving beyond individual victim behavior modification to implementing systemic, ecosystem-level interventions that address vulnerabilities at their source and build collective resilience against threats like ransomware.
About the Speaker(s)
Director Harry Coker serves as the Director of the Office of the National Cyber Director (ONCD) within the White House. This talk marked his first attendance at "hacker summer camp" (Black Hat), highlighting his commitment to engaging directly with the security research community. His primary objective in attending was to listen, learn, and gather feedback from experts outside the Washington D.C. Beltway, demonstrating ONCD's dedication to incorporating diverse perspectives into national cybersecurity policy. Director Coker's office is responsible for authoring and leading the implementation of the comprehensive National Cyber Security Strategy.
The discussion was moderated by an unnamed former official from the National Security Council (NSC). This individual was recognized by Director Coker as a "key partner" and instrumental in the "heavy lift" of pulling together the National Cyber Security Strategy during their tenure at the NSC. Their role as moderator provided valuable historical context and insight into the strategy's development and intent.