A World On Fire: Playing Defense in a Digitized World...and Winning

RSA Conference 2024 · South Stage Keynote

Overview

In a candid and urgent discussion at RSAC 2024, former CISA Director Chris Krebs and current CISA Director Jen Easterly, moderated by The Washington Post's Joseph Menn, painted a stark picture of the global cybersecurity landscape, aptly titled "A World On Fire." The session delved into the profound intertwining of geopolitical conflict and cyber warfare, emphasizing that the digital realm is no longer a separate battlefield but an integral component of modern military doctrine and statecraft. The core message underscored that businesses and national security agencies alike face an unprecedented confluence of threats, from escalating nation-state aggression to the relentless scourge of cybercrime, all exacerbated by inherently insecure technology and rapid innovation.

Watch on YouTube

Visual summary for A World On Fire: Playing Defense in a Digitized World...and Winning
Visual summary for A World On Fire: Playing Defense in a Digitized World...and Winning

Key moments

  1. 0:00 Introduction: "A World On Fire, Playing Defense and Winning"
  2. 0:50 Chris Krebs explains "World on Fire" and key risk drivers
  3. 3:30 Jen Easterly on critical infrastructure threats and ransomware
  4. 5:00 Volt Typhoon: Chinese actors burrowing into critical infrastructure
  5. 6:10 The "winning" strategy: Secure by Design revolution
  6. 7:15 Discussing Secure by Design as a voluntary effort

A World On Fire: Playing Defense in a Digitized World...and Winning

Speakers: Chris Krebs (Former Director, CISA), Jen Easterly (Director, CISA), Joseph Menn (Panel Moderator, The Washington Post)

Conference: RSAC 2024

YouTube: https://www.youtube.com/watch?v=oYRYgRcgS-c

Overview

In a candid and urgent discussion at RSAC 2024, former CISA Director Chris Krebs and current CISA Director Jen Easterly, moderated by The Washington Post's Joseph Menn, painted a stark picture of the global cybersecurity landscape, aptly titled "A World On Fire." The session delved into the profound intertwining of geopolitical conflict and cyber warfare, emphasizing that the digital realm is no longer a separate battlefield but an integral component of modern military doctrine and statecraft. The core message underscored that businesses and national security agencies alike face an unprecedented confluence of threats, from escalating nation-state aggression to the relentless scourge of cybercrime, all exacerbated by inherently insecure technology and rapid innovation.

The talk articulated three primary drivers of this elevated risk: the explosion of diverse threat actors, the inherent complexity and insecurity of foundational technologies, and the relentless emergence of new, poorly understood innovations like generative AI. While acknowledging the gravity of these challenges, the discussion pivoted from problem identification to actionable solutions, with a significant focus on the "Secure by Design" revolution. This paradigm shift advocates for a fundamental change in how technology is developed, pushing manufacturers to prioritize security from inception rather than as an afterthought, offering a pathway to "winning" in an increasingly perilous digital world.

This session serves as a critical call to action for every stakeholder in the digital ecosystem—from software developers and hardware manufacturers to enterprise security teams and national policymakers. It highlights that the current reactive cybersecurity model is unsustainable against sophisticated adversaries and a rapidly expanding attack surface. By dissecting the nature of contemporary threats and championing a proactive, security-first approach, the speakers provided a roadmap for building resilience and defending critical infrastructure, ultimately aiming to safeguard the safety, security, and livelihoods of citizens in a highly digitized and interconnected world.

Background

▶ Watch: Introduction: "A World On Fire, Playing Defense and Winning" (0:00)

The "World On Fire" metaphor articulated by Chris Krebs stems from a pervasive sense of geopolitical instability, with "conflagration in every corner of the globe." Unlike a decade ago, technology, cyber operations, information warfare, and disinformation are no longer peripheral but have become integral to modern conflict and military doctrine. This integration means that traditional business risk and geopolitical risk are now inextricably linked, making it impossible for organizations to operate without considering the broader international security context.

The problem's roots are multifaceted. Firstly, the threat actor space is exploding, encompassing not only highly resourced nation-states but also a burgeoning ecosystem of cybercriminals and hacktivists. These diverse groups possess varying motivations and capabilities, making the threat landscape incredibly complex to defend against. Secondly, the very technologies that underpin modern society are often "shipped in a way that creates risk, vulnerabilities," and are "configured and deployed in a way that is incredibly complex." This echoes William Gibson's description of cyberspace in his 1984 novel Neuromancer as having "unthinkable complexity," a sentiment that resonates deeply with the challenges of managing a large enterprise today. This complexity is not just about the sheer number of systems but also about the intricate interdependencies and the inherent insecurities baked into their design.

Finally, the relentless pace of technological innovation further complicates matters. New technologies, such as generative AI, which only achieved general availability in late 2022, are being rapidly integrated into existing infrastructures. This adoption often occurs while organizations are still grappling with the security implications of previous generations of technology, such as hyperscale cloud deployments. The continuous influx of new, unhardened systems creates an ever-expanding attack surface, leaving defenders in a perpetual state of catch-up. This historical trajectory of prioritizing speed to market and features over fundamental security has resulted in a global digital infrastructure that is "inherently insecure," laying the groundwork for the persistent and escalating cyber threats we face today.

Key Findings

▶ Watch: Jen Easterly on critical infrastructure threats and ransomware (3:30)

The talk identified several critical findings that underscore the current state of global cybersecurity and the urgent need for a paradigm shift:

  1. Exploding Threat Landscape: The number and diversity of threat actors are rapidly increasing. This includes sophisticated nation-state actors, prolific cybercriminal gangs, and politically motivated hacktivists, all leveraging technology to achieve their objectives. This broad spectrum of adversaries necessitates a comprehensive and adaptable defense strategy.
  2. Pervasive Insecurity of Technology: For over 40 years, the technology underpinning critical infrastructure has been designed with a primary focus on "speed to market" and "cool features" rather than foundational security. This inherent insecurity means that systems are routinely shipped with known public flaws and defects, providing a fertile ground for exploitation by a wide array of threat actors. This fundamental design flaw is a core reason for the existence of multi-billion-dollar cybersecurity agencies and the ongoing struggle against cyber threats.
  3. Ransomware as a Trillion-Dollar Scourge: The ransomware ecosystem continues to explode, evolving into a multi-billion, and by some estimates, a multi-trillion-dollar business. The cost of global cybercrime is projected to exceed $10 trillion by next year. This pervasive threat impacts individuals, businesses, and critical services like hospitals, directly putting lives at risk despite concerted efforts by law enforcement and international cooperation.
  4. Emergence of Destructive Nation-State Threats (Volt Typhoon): Beyond traditional espionage and data theft, nation-state actors are now actively preparing for disruptive and destructive attacks on critical infrastructure. Specifically, Chinese cyber actors, colloquially known as Volt Typhoon, have been observed burrowing into US critical infrastructure. Their objective is not intellectual property theft or data exfiltration but to launch disruptive and destructive attacks in the event of a major conflict, such as in the Taiwan Straits. This represents a "different threat in kind," aiming to incite "societal panic and chaos" and deter US military and citizen resolve.
  5. The "Secure by Design" Imperative: The common thread linking ransomware and state-sponsored infiltration of critical infrastructure is their reliance on exploiting known vulnerabilities stemming from inherently insecure technology. This realization culminates in the urgent need for a "Secure by Design" revolution. This initiative aims to catalyze technology manufacturers to build, design, test, and deliver products that are "first and foremost secure by design," shifting the burden of security away from end-users and onto the producers of technology.

Technical Deep Dive

▶ Watch: Volt Typhoon: Chinese actors burrowing into critical infrastructure (5:00)

The technical exposition of the talk highlighted two paramount threats: the pervasive issue of ransomware and the alarming, distinct nature of nation-state actors like Volt Typhoon. Both, critically, exploit the foundational insecurity of prevalent technologies.

Ransomware, as noted, has transcended mere cybercrime to become a global economic destabilizer, with estimates placing the cost of global cybercrime north of $10 trillion annually by 2025. Its technical modus operandi typically involves exploiting known vulnerabilities in network perimeters (e.g., unpatched VPNs, exposed RDP ports), phishing campaigns, or supply chain compromises to gain initial access. Once inside, threat actors often use techniques like lateral movement to expand their foothold, privilege escalation to gain administrative control, and data exfiltration before deploying encryption payloads. The sophistication lies not just in the malware itself but in the entire ecosystem supporting it, including initial access brokers, ransomware-as-a-service (RaaS) models, cryptocurrency for payments, and even dark web negotiation services. The impact is immediate and often devastating, leading to operational shutdowns, data loss, and significant financial costs for recovery, often affecting critical services like healthcare where delays can directly imperil lives.

However, the more technically distinct and strategically concerning threat discussed was that posed by Volt Typhoon. This specific group of Chinese state-sponsored cyber actors has been observed engaging in pre-positioning operations within US critical infrastructure. Unlike traditional cyber espionage, where the primary goal is intelligence gathering or intellectual property theft, Volt Typhoon's objective is explicitly disruptive and destructive. Their activities involve living off the land (LotL) techniques, utilizing legitimate system tools and processes to maintain persistence and evade detection. This allows them to blend in with normal network traffic, making attribution and expulsion incredibly challenging. They target a broad spectrum of critical sectors, including:

  • Pipelines: Potential for disrupting energy supply and causing environmental damage.
  • Water facilities: Risk of contaminating water supplies or disrupting access.
  • Communications networks: Ability to sever vital communication links, impacting emergency services, military command and control, and public information flow.
  • Transportation systems: Potential for derailing trains, disrupting air traffic control, or disabling port operations.

The strategic intent behind these actions is to achieve societal panic and chaos within the US mainland during a potential conflict in the Taiwan Straits. By undermining the safety, security, and livelihoods of Americans at home, China aims to deter the US's ability to "marshal military might and citizen will." This pre-positioning represents a significant escalation, shifting from a focus on espionage to a clear intent for physical-world disruption through cyber means. This "different threat in kind" highlights a more aggressive and potentially kinetic dimension of cyber warfare, demanding a re-evaluation of defensive priorities. Both ransomware and Volt Typhoon exploit the fundamental flaw that for decades, technology has been developed for "speed to market" and "cool features" rather than being "secure by design," leaving a vast attack surface of known public flaws and defects for adversaries to leverage.

Demo / Proof of Concept

▶ Watch: The "winning" strategy: Secure by Design revolution (6:10)

This particular session was a panel discussion and did not feature a live technical demonstration or proof of concept of any specific exploit or defensive tool. Instead, the speakers focused on a high-level strategic overview of the threat landscape and the overarching philosophical shift required for effective defense.

Defensive Implications

▶ Watch: Discussing Secure by Design as a voluntary effort (7:15)

The defensive implications arising from this talk are profound and necessitate a fundamental recalibration of cybersecurity strategies, moving from reactive patching to proactive, systemic security. The overarching message for defenders is the urgent need to embrace and catalyze the "Secure by Design" revolution.

Firstly, organizations must recognize that the traditional model of purchasing insecure technology and then layering on defensive tools is no longer sustainable. The burden of security must shift upstream to technology manufacturers. Defenders should actively demand and prioritize products that are secure by design, meaning security is built in from the earliest stages of development, rather than bolted on as an afterthought. This includes rigorous secure coding practices, threat modeling, secure configuration defaults, and transparent vulnerability disclosure programs. Procurement decisions should increasingly factor in the security posture of the vendor and their commitment to secure by design principles.

Secondly, the specific threat posed by actors like Volt Typhoon demands a heightened focus on resilience in critical infrastructure sectors. This goes beyond mere prevention to ensuring that systems can withstand, respond to, and quickly recover from disruptive and destructive attacks. This involves:

  • Deep visibility: Implementing advanced monitoring and detection capabilities to identify the subtle, "living off the land" techniques favored by sophisticated adversaries.
  • Network segmentation: Isolating critical operational technology (OT) networks from IT networks to contain breaches and prevent lateral movement.
  • Incident response planning: Developing and regularly exercising comprehensive incident response plans specifically tailored for destructive attacks, including manual override procedures and offline backups for critical systems.
  • Supply chain security: Scrutinizing the security of third-party vendors and components, as supply chain compromises are a common vector for initial access.
  • International cooperation: Enhancing collaboration with government agencies (like CISA) and international partners to share threat intelligence and coordinate defensive efforts against nation-state adversaries.

Thirdly, the "unthinkable complexity" of modern enterprise environments and the rapid emergence of new technologies like generative AI require a strategic approach to managing risk. Defenders must invest in security automation and orchestration to manage the scale and complexity, while also dedicating resources to research and understand the unique security implications of emerging technologies before widespread adoption. This includes developing secure configurations and best practices for AI systems, understanding potential attack vectors against AI models (e.g., data poisoning, model evasion), and securing the underlying infrastructure that supports these new capabilities.

Finally, the talk implicitly calls for a cultural shift within organizations, elevating cybersecurity to a board-level imperative that is integrated into every aspect of business operations and strategic planning. By prioritizing secure by design principles, enhancing resilience in critical sectors, and proactively addressing the challenges of technological complexity and innovation, defenders can move beyond merely being "on fire" to actively "winning" against the evolving threat landscape.

Key Takeaways

  • Geopolitical and cyber risks are intertwined: Modern conflicts integrate cyber warfare, making business risk inseparable from geopolitical instability, driven by an explosion of threat actors, complex technology, and rapid innovation.
  • Ransomware remains a colossal global threat: The ransomware ecosystem is a multi-trillion dollar criminal enterprise, projected to cost over $10 trillion by 2025, impacting critical services and putting lives at risk.
  • Destructive nation-state threats are escalating: Chinese cyber actors like Volt Typhoon are actively pre-positioning in critical infrastructure, not for espionage, but to launch disruptive and destructive attacks to incite chaos during potential conflicts.
  • Technology is fundamentally insecure by design: For over 40 years, the focus on speed and features over security has resulted in inherently vulnerable technology, creating a vast attack surface of known flaws.
  • "Secure by Design" is the imperative for winning: CISA advocates for a revolution where technology manufacturers prioritize security from inception, building, designing, and delivering products that are secure first, shifting the security burden upstream.
  • Defenders must prioritize resilience and proactive security: Organizations must move beyond reactive measures, demanding secure by design products, enhancing critical infrastructure resilience against destructive attacks, and strategically managing the security implications of new technologies like AI.

About the Speaker(s)

Chris Krebs is the former director of the Cybersecurity and Infrastructure Security Agency (CISA), a position he held from November 2018 until November 2020. During his tenure, he played a crucial role in securing US elections and critical infrastructure.

Jen Easterly is the current director of CISA, having succeeded Chris Krebs. She is responsible for leading the national effort to understand, manage, and reduce risk to the cyber and physical infrastructure of the United States.

Joseph Menn is a panel moderator from The Washington Post and a Pulitzer Prize finalist, known for his insightful reporting on cybersecurity and technology.

All talks from RSA Conference 2024