Opening Session: Disruption, Defense and Operational Readiness

Nick Andersen (Acting Director · CISA), Katherine E. Sutton (Assistant Secretary of War for Cyber Policy · Department of War), Brett Leatherman (Assistant Director, Cyber Division · FBI), Daniel Kroese (Vice President, Global Policy · Palo Alto Networks)

Black Hat USA 2026 · Day 1 · Main Stage

Overview

This Black Hat USA session, "Disruption, Defense and Operational Readiness," brought together top cybersecurity leaders from U.S. government agencies and industry to discuss the evolving threat landscape and the collaborative strategies being deployed to strengthen national cybersecurity. Moderated by Daniel Kroese of Palo Alto Networks, the panel featured Nick Andersen from CISA, Brett Leatherman from the FBI, and Katherine E. Sutton from the Department of War. The discussion centered on the foundational principles of the National Cyber Strategy for America, emphasizing a proactive approach to deterrence, robust defense, and enhanced operational readiness through unprecedented interagency and public-private partnerships.

Watch on YouTube

Key moments

  1. 0:30 Panel introduction: disruption, defense, and operational readiness
  2. 1:30 National Cyber Strategy: relentless focus on defense and deterrence
  3. 2:05 FBI's Operation Riptide: imposing costs on cyber adversaries
  4. 3:45 Industry partnerships crucial for effective cyber deterrence efforts
  5. 4:25 Department of War: integrating cyber into all military operations
  6. 6:40 CISA's mission as nation's civilian cyber defense agency

Opening Session: Disruption, Defense and Operational Readiness

Speakers: Nick Andersen (Acting Director, CISA), Katherine E. Sutton (Assistant Secretary of War for Cyber Policy, Department of War), Brett Leatherman (Assistant Director, Cyber Division, FBI), Daniel Kroese (Vice President, Global Policy, Palo Alto Networks)

Conference: Black Hat USA

YouTube: https://www.youtube.com/watch?v=iGimE6sg9GQ

Overview

This Black Hat USA session, "Disruption, Defense and Operational Readiness," brought together top cybersecurity leaders from U.S. government agencies and industry to discuss the evolving threat landscape and the collaborative strategies being deployed to strengthen national cybersecurity. Moderated by Daniel Kroese of Palo Alto Networks, the panel featured Nick Andersen from CISA, Brett Leatherman from the FBI, and Katherine E. Sutton from the Department of War. The discussion centered on the foundational principles of the National Cyber Strategy for America, emphasizing a proactive approach to deterrence, robust defense, and enhanced operational readiness through unprecedented interagency and public-private partnerships.

The talk highlighted a pivotal shift in the U.S. government's cybersecurity posture, moving beyond incremental adjustments to embrace "big swings" designed to impose significant costs on adversaries. Speakers detailed initiatives aimed at disrupting cybercriminal ecosystems, integrating cyber capabilities into traditional military operations, and fortifying critical infrastructure against nation-state threats. The core message underscored the imperative for a unified, prioritized effort across all sectors to ensure national security and economic stability in the face of persistent and sophisticated cyber threats.

The insights shared by these leaders are critically important for the broader cybersecurity community, as they illuminate the strategic direction of federal efforts and articulate clear calls to action for industry partners. The discussion provided a candid look into how governmental bodies are leveraging their unique authorities, resources, and intelligence to dismantle adversary operations, develop specialized cyber talent, and implement frameworks that enable more effective vulnerability management and risk prioritization. The emphasis on collaboration signals a new era where shared intelligence and coordinated action are paramount to securing the digital frontier.

Background

▶ Watch: Panel introduction: disruption, defense, and operational readiness (0:30)

The genesis of this discussion lies within the framework of the National Cyber Strategy for America, which serves as the "North Star" for the administration's cybersecurity agenda. This strategy, released in March, signaled a departure from previous "half measures," advocating for a relentless focus on both cyber defense and, crucially, deterrence. For too long, adversaries — whether nation-state actors or cybercriminals — have operated with a perceived sense of impunity, exploiting vulnerabilities and causing widespread disruption without facing commensurate consequences. The panel's objective was to articulate how various government entities are working to rectify this imbalance.

Historically, cyber operations within government have sometimes been stovepiped, with different agencies pursuing their mandates in relative isolation. The Department of War, for instance, traditionally viewed cyber as a specialized tool to counter malicious cyber actors, rather than an integrated component of broader military operations. Similarly, law enforcement efforts, while effective, often faced challenges in scaling operations globally and moving "upstream" against sophisticated threat actors operating from safe havens. CISA, as the nation's civilian cyber defense agency, has been focused on risk advising and critical infrastructure coordination but faces the immense challenge of securing an increasingly complex and interconnected digital landscape.

The problem persists due to several factors: the rapid evolution of cyber threats, the global and anonymous nature of cybercrime, the strategic pre-positioning of capabilities by nation-states, and a persistent talent gap within the cyber workforce. This panel aimed to demonstrate how a coordinated, holistic approach, leveraging the unique authorities and capabilities of each agency, is now being deployed to address these systemic challenges. The imperative is to not just defend, but to disrupt and deter, making it increasingly costly and difficult for adversaries to achieve their objectives.

Key Findings

▶ Watch: FBI's Operation Riptide: imposing costs on cyber adversaries (2:05)

The panel revealed several key findings and strategic shifts in the U.S. government's approach to cybersecurity:

  1. Aggressive Deterrence and Cost Imposition: A central theme was the shift towards imposing significant costs on cyber adversaries. The FBI, through initiatives like Operation Riptide, has demonstrated a proactive stance in arresting and charging cybercriminals globally, targeting not just individuals but also their underlying infrastructure, finances, and tools. This includes disrupting VPN anonymization services and bulletproof hosters that enable ransomware groups. The goal is "no safe harbor" for malicious actors.
  1. Integration of Cyber into All Military Operations: The Department of War is fundamentally rethinking how cyber capabilities are used, moving from a stovepiped approach to integrating cyber into all military operations. This provides warfighters with a "foundational tool" for decisive advantage, as demonstrated in operations like Absolute Resolve and Epic Fury. This ensures cyber is a critical component of joint planning and mission execution, aiming to bring troops back safely.
  1. Prioritized and Risk-Based Defense for Critical Infrastructure: CISA is spearheading efforts to secure federal networks and critical infrastructure through a lens of "ruthless prioritization." This involves moving beyond traditional vulnerability scoring (like CVSS) to focus on attributes that indicate higher risk, such as internet accessibility and automatable exploitability. This ensures resources are directed towards the most consequential threats impacting public health, safety, national security, and economic continuity.
  1. Strategic Talent Management and Specialization: Recognizing the critical importance of human capital, the Department of War's Cyber Command 2.0 initiative aims to build a future-ready cyber workforce. This involves fostering domain mastery, promoting specialization (e.g., in cloud, operational technology), and enhancing mission agility. New incentive pays and tailored career paths are being introduced to attract, train, and retain top talent.
  1. Unprecedented Government-Industry Collaboration: All speakers underscored that industry partnerships are not just beneficial but absolutely crucial to these efforts. The FBI explicitly stated that its joint sequenced operations are "empowered by industry." CISA's new Clearinghouse and Gold Eagle initiatives are designed to facilitate AI-enabled vulnerability reporting and disclosure at scale, explicitly welcoming industry collaboration to harmonize related efforts. This collaborative spirit extends to co-location of teams across agencies and with international partners.

Technical Deep Dive

▶ Watch: Industry partnerships crucial for effective cyber deterrence efforts (3:45)

The discussion, while high-level, touched upon several strategic technical and operational frameworks underpinning the U.S. government's cyber initiatives.

The FBI's approach to deterrence, exemplified by Operation Riptide, is a multi-faceted technical strategy. Beyond traditional arrests, the FBI focuses on dismantling the entire adversary ecosystem. This includes:

  • Infrastructure Takedowns: Targeting the servers, networks, and hosting providers used by cybercriminals. A notable example was the operation against First VPN, an anonymization service that facilitated operations for 25 different ransomware groups. By disrupting such services, the FBI aims to remove the anonymity layer crucial for these actors. Another significant action was against MediaLand, a bulletproof hoster in Russia that provided a platform for 17 ransomware groups, including LockBit. This operation involved seizing millions of dollars in cryptocurrency and providing decryption capabilities to victims, mitigating almost three-quarters of a billion dollars in potential ransom payments.
  • Financial Disruption: Following the money by seizing cryptocurrency and other assets, making cybercrime less profitable.
  • Tool Removal: Identifying and neutralizing the specific tools, malware, and exploits used by threat actors.
  • Leveraging Novel Authorities: The FBI is actively innovating in how it uses its authorities, including court authorization and intelligence community authorities, to conduct operations that remove capacity and capability from adversaries. This is particularly critical in countering sophisticated nation-state operations, such as the PRC-backed Volt Typhoon, Flax Typhoon, and Salt Typhoon campaigns aimed at pre-positioning cyber capabilities against U.S. critical infrastructure.

CISA's technical leadership is evident in its strategic shift towards enhanced vulnerability and risk management. The agency's Binding Operational Directive (BOD) 2604 moves federal agencies away from an exclusive reliance on the Common Vulnerability Scoring System (CVSS). Instead, it advocates for a more nuanced risk prioritization model based on a series of critical attributes, chiefly:

  • Internet Accessibility: Is the vulnerable system exposed directly to the internet?
  • Automatability: Can the vulnerability be easily exploited through automated means?
  • Exploitation Status: Is the vulnerability known to be actively exploited in the wild (as listed in CISA's Known Exploited Vulnerabilities Catalog, or KEV)?

This framework empowers risk managers to make informed decisions, focusing resources on vulnerabilities that pose the most immediate and impactful threats to public health and safety, national security, economic continuity, and defense critical infrastructure.

Furthermore, CISA is at the forefront of addressing emerging technological challenges. The agency is driving initiatives related to AI security and innovation, including the development of a Clearinghouse and Gold Eagle. These platforms are designed to unify and scale AI-enabled vulnerability reporting and disclosure, a new frontier in cybersecurity that requires robust mechanisms for collaboration and information sharing with industry. CISA is also actively engaged in Post-Quantum Cryptography (PQC) risk mitigation, responding to executive orders that set ambitious goals and timelines for transitioning to quantum-resistant cryptography, preparing for a future where current encryption standards may be vulnerable.

The Department of War's Cyber Command 2.0 represents a significant technical and organizational overhaul focused on human capital. Its objectives translate into a new architecture for cyber talent development:

  • Domain Mastery: Building deep, sustained expertise rather than short rotational assignments. This implies specialized training tracks and longer assignments within specific cyber disciplines.
  • Specialization: Moving beyond generic "cyber operators" to cultivate highly specialized roles, akin to medical specialties. This includes experts in cloud security, operational technology (OT) security, and other niche areas, ensuring that the right skills are available for specific mission requirements.
  • Agility: Developing a flexible workforce capable of purpose-building teams for diverse and evolving missions. This requires adaptive training, cross-skilling, and dynamic talent allocation.

This initiative involves a comprehensive review of recruitment, incentivization (e.g., new incentive pay for higher-level training and certification), training, retention, career paths, and organizational structures to ensure the military's cyber warfighters are equipped for future conflicts.

Demo / Proof of Concept

▶ Watch: Department of War: integrating cyber into all military operations (4:25)

As a panel discussion featuring senior government officials, this session did not include a live technical demonstration or a traditional proof of concept. The format was an exchange of strategic insights and updates on ongoing initiatives.

However, the operational successes cited by Brett Leatherman of the FBI serve as real-world "proofs of concept" for the effectiveness of their deterrence and disruption strategies. The successful takedown of First VPN and the enforcement operation against MediaLand, which led to the seizure of millions in cryptocurrency and the provision of decryption capabilities to victims, concretely demonstrate the impact of their multi-pronged approach. These actions, along with the arrest of over 200 actors and the extradition of international fugitives, validate the FBI's strategy of imposing significant costs on adversaries, thereby reducing their capacity and capability to operate. Similarly, the Department of War's references to operations like Absolute Resolve and Epic Fury highlight the practical application and success of integrating cyber effects into traditional military operations.

Defensive Implications

▶ Watch: CISA's mission as nation's civilian cyber defense agency (6:40)

The insights from this panel offer critical guidance for defenders across all sectors, emphasizing the need for proactive engagement, strategic prioritization, and continuous adaptation.

  1. Prioritize Vulnerability Management ruthlessly: Defenders should adopt CISA's principles articulated in BOD 2604. Instead of solely relying on high CVSS scores, prioritize vulnerabilities that are internet accessible, automatable, and known to be actively exploited (e.g., those in CISA's KEV Catalog). This risk-based approach ensures resources are allocated to mitigate the most impactful threats first, focusing on systems critical to public health, safety, national security, and economic continuity.
  1. Engage Proactively with Law Enforcement: Industry organizations are critical partners in the FBI's disruption efforts. Early and frequent engagement with the FBI regarding cyber incidents, threat intelligence, and adversary infrastructure can enable law enforcement to move "upstream" against actors. Sharing information about ransomware groups, their tools, infrastructure (e.g., VPNs, bulletproof hosters), and financial flows directly contributes to takedowns and cost imposition, as evidenced by the First VPN and MediaLand operations.
  1. Leverage CISA's Collaborative Platforms: Businesses and researchers involved in AI security and vulnerability research should actively participate in CISA's Clearinghouse and Gold Eagle initiatives. These platforms are designed to facilitate AI-enabled vulnerability reporting and disclosure at scale, harmonizing efforts and fostering a unified defense posture against emerging AI-specific threats. Defenders should also prepare for the future by understanding and planning for Post-Quantum Cryptography (PQC) risk mitigation, aligning with CISA's guidance.
  1. Invest in Specialized Cyber Talent: Drawing lessons from the Department of War's Cyber Command 2.0, organizations should critically assess their cyber workforce strategies. Focus on building domain mastery through continuous training and development, encouraging specialization in areas like cloud security, operational technology (OT), and incident response. Developing agile teams capable of adapting to diverse mission sets is crucial for maintaining a competitive edge against evolving threats. Implementing incentive programs for advanced training and certifications can help attract and retain top talent.
  1. Foster Interagency and Public-Private Information Sharing: The success of government operations hinges on seamless collaboration. Defenders should actively seek opportunities to share threat intelligence and best practices within their industry sectors and with government agencies. The "co-location" model adopted by federal agencies should inspire similar integrated approaches between industry security operations centers and relevant government entities, ensuring a unified front against both criminal and nation-state adversaries like those behind Volt Typhoon.

Key Takeaways

  • National Cyber Strategy as the North Star: The U.S. government is operating under a unified national cyber strategy focused on both relentless defense and aggressive deterrence, moving away from incremental "half measures."
  • Aggressive Deterrence and Cost Imposition: Law enforcement, particularly the FBI, is taking "big swings" to disrupt adversary ecosystems by targeting actors, infrastructure (e.g., First VPN, MediaLand), finances, and tools, leading to hundreds of arrests and significant financial impacts (e.g., mitigating $750M in ransom payments).
  • Integrated Cyber-Kinetic Operations: The Department of War is fundamentally integrating cyber capabilities into all military operations, making cyber a foundational tool for warfighters to achieve decisive advantages and enhance mission safety (e.g., Operations Absolute Resolve, Epic Fury).
  • Risk-Based Prioritization for Critical Infrastructure: CISA is driving a shift from solely CVSS-based vulnerability management to a more "ruthless prioritization" model, focusing on internet accessibility, automatable exploitability, and known exploitation for critical infrastructure and federal networks.
  • Strategic Investment in Cyber Talent: The Department of War's Cyber Command 2.0 initiative emphasizes building domain mastery, specialization (e.g., cloud, OT), and agility within the cyber workforce through new incentive programs and tailored career paths.
  • Crucial Role of Government-Industry Partnership: Unprecedented levels of collaboration, including early engagement with law enforcement and participation in CISA's new platforms like Clearinghouse and Gold Eagle, are essential for successful national cybersecurity outcomes.

About the Speaker(s)

Nick Andersen is the Acting Director of the Cybersecurity and Infrastructure Security Agency (CISA). In this role, he is at the forefront of the nation's civilian cyber defense, leading efforts to secure and modernize federal networks, advise on risk, and coordinate critical infrastructure security and resilience across the United States. His work focuses on implementing key policy announcements, including executive orders on AI security and quantum-related initiatives, emphasizing a prioritized, risk-based approach to cybersecurity.

Katherine E. Sutton serves as the Assistant Secretary of War for Cyber Policy and the Principal Cyber Advisor to the Secretary of War, Department of War. Her responsibilities include shaping the department's strategy for fighting in the cyber domain. She is a key architect of initiatives like Cyber Command 2.0, which aims to evolve the military's cyber talent management, focusing on domain mastery, specialization, and agility to integrate cyber capabilities more effectively into all military operations.

Brett Leatherman is the Assistant Director of the Cyber Division at the FBI. He leads the bureau's efforts as the lead law enforcement agency for cyber operations within the homeland, extending globally. His division is responsible for executing aggressive deterrence operations, imposing costs on both cyber criminal and nation-state actors through arrests, infrastructure takedowns (such as First VPN and MediaLand), financial seizures, and leveraging innovative legal and intelligence authorities to defend the nation.

Daniel Kroese is the Vice President of Global Policy at Palo Alto Networks and served as the moderator for this panel discussion. His role involves shaping policy discussions and facilitating collaboration between the private sector and government agencies on critical cybersecurity issues. His expertise helps bridge the gap between industry innovation and governmental strategic imperatives, ensuring that the private sector's perspective is integrated into national cybersecurity initiatives.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

Government keynote that reads like a comms team deck. Lots of program names dropped (Cyber Command 2.0, Gold Eagle, Clearinghouse), almost zero specificity about what any of them actually do, when they ship, or what resources back them. The FBI enforcement stuff is the only part with concrete numbers.

Heather Calloway (CISO) — WEAK

Standard government panel with nothing your leadership team doesn't already assume. No new policy, no operational detail, no decision points. Skip unless you need a refresher on how federal agencies describe their coordination efforts.

→ Top-rated talks at Black Hat USA 2026

All talks from Black Hat USA 2026