Apocalypse Avoided: The Future According to the Four Horsemen of Cyber
RSA Conference 2024 · South Stage Keynote
Overview
This insightful panel discussion at RSAC 2024 brought together a truly unique assembly of cybersecurity pioneers, colloquially known as the "Four Horsemen of Cyber," for their first public appearance together. Moderated by Garrett Graf, the panel featured Paul Nakasone, TJ White, SL Davis, and Jen Easterly, all titans of US national security and cyber defense. The talk delved into the foundational moments that shaped the US military's approach to cyber warfare, specifically focusing on the critical events that spurred the creation of US Cyber Command (USCYBERCOM).

Key moments
- 0:00 Introduction of moderator and 'Four Horsemen' panel
- 2:00 Formal introduction of the four distinguished panelists
- 4:00 Origin story: 'Buckshot Yankee' and US Cyber Command's genesis
- 6:00 Describing the 'harrowing impact' and DOD crisis
- 10:00 Military lessons from Iraq: IEDs and RT10 system
- 12:00 RT10's impact: illuminating terrorist networks and saving lives
- 14:00 Cyber's strategic importance recognized by combat commanders
Apocalypse Avoided: The Future According to the Four Horsemen of Cyber
Speakers: Garrett Graf (Moderator, Contributing Editor Wired Magazine, Director Cyber Initiative Aspen Institute), Paul Nakasone (Retired Director NSA and General, Commander US Cyber Command), TJ White (Retired Vice Admiral, Commander 10th Fleet), SL Davis (Retired Air Force General, Inspector General of the Air Force), Jen Easterly (Director CISA)
Conference: RSAC 2024
YouTube: https://www.youtube.com/watch?v=VJUHmMdf43s
Overview
This insightful panel discussion at RSAC 2024 brought together a truly unique assembly of cybersecurity pioneers, colloquially known as the "Four Horsemen of Cyber," for their first public appearance together. Moderated by Garrett Graf, the panel featured Paul Nakasone, TJ White, SL Davis, and Jen Easterly, all titans of US national security and cyber defense. The talk delved into the foundational moments that shaped the US military's approach to cyber warfare, specifically focusing on the critical events that spurred the creation of US Cyber Command (USCYBERCOM).
The discussion provided a rare historical perspective from the individuals who were at the forefront of establishing the nation's digital defenses. They recounted harrowing early cyber incidents and the innovative, often improvised, solutions developed under intense pressure in combat zones. The session underscored not only the technical challenges but also the significant cultural and organizational shifts required to recognize cyber as a distinct and strategic domain of warfare, ultimately preventing a "cyber apocalypse" through proactive defense and operational integration.
Background
▶ Watch: Introduction of moderator and 'Four Horsemen' panel (0:00)
The genesis of US cyber capabilities, particularly the formation of US Cyber Command, is rooted in two pivotal experiences that exposed profound vulnerabilities and simultaneously demonstrated the immense potential of integrated cyber operations. The first was the Buckshot Yankee incident in 2008, a watershed moment that revealed the alarming penetration of both classified and unclassified Department of Defense (DOD) networks. This event, originating from a flash drive in Afghanistan, disseminated malware across critical warfighting systems used by US Central Command, triggering an unprecedented crisis within the Pentagon. The immediate aftermath was characterized by daily video teleconferences among senior leadership, grappling with fundamental questions such as the scope of the compromise, the number of affected systems (which, strikingly, could not be definitively answered), and the origin of the attack. Paul Nakasone described this period as a "no shipper" event, where commanders globally relied on these networks for mission execution, only to find them potentially compromised. The National Security Agency (NSA) played a crucial role in detecting and mitigating the threat, but the incident unequivocally highlighted a severe lack of network visibility and a systemic unpreparedness for sophisticated cyber intrusions. This crisis served as the direct catalyst for serious discussions about a dedicated cyber command.
The second foundational experience emerged from the battlefields of Iraq in 2006-2007, where the military confronted the devastating impact of improvised explosive devices (IEDs) and explosively formed penetrators (EFPs) used by insurgents. General Keith Alexander, then head of NSA, recognized the urgent need to make NSA's intelligence capabilities directly relevant to warfighters on the ground. This led to the deployment of NSA officers, including Paul Nakasone, to train and support Brigade Combat Teams with cryptologic support teams. Concurrently, a highly classified project known as RT10, later renamed Real-Time Regional Gateway (RTRG), was initiated. This system was designed to integrate and correlate diverse communication data—from satellite and cell phone communications to ground reporting—used by insurgents to plan attacks. The goal was to illuminate terrorist networks not in days or weeks, but in hours and minutes. Jen Easterly, a leader of these efforts in Baghdad, emphasized the incredible degree of entrepreneurship, innovation, and teamwork required to bring this system online in a war zone. The success of RTRG in aiding joint special operations command to remove thousands of insurgents from the battlefield underscored the life-saving potential of rapid, integrated cyber and intelligence operations. This demonstrated the strategic importance of cyber as an instrument of power, garnering crucial support from combat commanders like General David Petraeus for the establishment of a new sub-unified command dedicated to cyber.
Key Findings
▶ Watch: Origin story: 'Buckshot Yankee' and US Cyber Command's genesis (4:00)
The panel's historical recounting revealed several critical findings that profoundly influenced the trajectory of US cyber defense and offense:
Firstly, the Buckshot Yankee incident served as an undeniable "wake-up call" for the Department of Defense regarding its fundamental vulnerability to cyber threats. The penetration of both classified and unclassified networks, particularly those supporting warfighting efforts, exposed a severe lack of basic network hygiene and visibility. The inability to even quantify the number of computers on their own networks underscored a pervasive blindness to the digital terrain, highlighting that even the most sensitive environments were not immune to sophisticated malware. This crisis demonstrated that cyber compromise could directly impact military operations and national security.
Secondly, the development and deployment of RT10/RTRG in Iraq showcased the transformative power of real-time intelligence integration in a combat environment. By correlating disparate data sources—satellite, cellular, and ground intelligence—the system enabled military forces to illuminate and disrupt insurgent networks with unprecedented speed. This capability, moving from days or weeks to hours and minutes, directly translated into saving lives and enhancing operational effectiveness. It proved that cyber capabilities, when properly integrated with traditional intelligence, could be a decisive strategic instrument.
Thirdly, the experiences from both Buckshot Yankee and RT10/RTRG collectively demonstrated the urgent necessity for a dedicated, integrated command structure for cyber operations. The reactive, ad-hoc responses to Buckshot Yankee contrasted sharply with the proactive, integrated approach that proved successful in Iraq. This dual experience solidified the argument for establishing US Cyber Command, not merely as an IT support function, but as a strategic warfighting command capable of both defending critical networks and conducting offensive cyber operations.
Finally, the panel stressed the indispensable role of human capital. The success of initiatives like RTRG was attributed to "sending high quality people" into challenging environments, fostering entrepreneurship, innovation, and collaboration. Leaders like Jen Easterly in Baghdad exemplified the caliber of personnel required to overcome technical and logistical hurdles in a high-stakes, real-world scenario. This underscored that technology alone is insufficient; it must be paired with skilled, adaptable, and dedicated individuals.
Technical Deep Dive
▶ Watch: Describing the 'harrowing impact' and DOD crisis (6:00)
The technical core of the discussion revolved around two distinct yet interconnected events: the Buckshot Yankee malware incident and the Real-Time Regional Gateway (RTRG) intelligence system.
The Buckshot Yankee incident, occurring in 2008, represented a significant compromise of Department of Defense (DOD) networks. While the specific malware variant was not named during the discussion, its characteristics were described as highly impactful: it successfully infiltrated both unclassified and classified networks, specifically those supporting US Central Command's warfighting operations in Afghanistan. The mechanism of initial infection was identified as a flash drive, highlighting a common vector for air-gapped or segmented network breaches. The malware's presence led to a profound crisis, exposing a critical lack of situational awareness within DOD. Paul Nakasone detailed the inability of senior leadership to answer basic questions such as "how many computers are impacted?" or "where did it come from?" This pointed to a systemic deficiency in asset management and network visibility. The NSA's role was crucial in the detection and mitigation phases, leveraging its advanced capabilities to identify the malware's scope and develop countermeasures. This incident demonstrated that even highly secured, classified military networks were vulnerable to sophisticated, state-sponsored or advanced persistent threats (APTs) that could traverse network boundaries.
In stark contrast, the Real-Time Regional Gateway (RTRG), initially known as RT10, represented a proactive and innovative technical solution developed in the crucible of combat in Iraq during 2006-2007. Though "super classified at the time," it has since been declassified, allowing for a glimpse into its sophisticated architecture. The primary technical function of RTRG was data integration, enrichment, and correlation on an unprecedented scale for its time. It ingested a vast array of communication data from the theater of operations, including:
- Satellite communications: Intercepted signals from various satellite platforms.
- Cell phone communications: Data from mobile networks used by insurgents.
- Reporting from troops on the ground: Tactical intelligence gathered by military personnel.
The system's core innovation was its ability to rapidly integrate and fuse these disparate data streams. This fusion process involved enrichment, where raw data was contextualized with additional intelligence, and correlation, where connections and patterns between seemingly unrelated pieces of information were identified. The objective was to illuminate terrorist networks by creating a comprehensive, real-time operational picture. This allowed for the identification of insurgent planning, communication nodes, and operational movements not in "days or weeks," as was previously the norm, but in "hours and minutes." The accelerated intelligence cycle provided actionable insights for Joint Special Operations Command (JSOC), enabling them to conduct targeted operations and "take in thousands of insurgent[s] off the battlefield." RTRG was a pioneering example of leveraging big data analytics and real-time processing in a tactical military context, fundamentally altering the speed and effectiveness of counter-insurgency operations.
Demo / Proof of Concept
▶ Watch: RT10's impact: illuminating terrorist networks and saving lives (12:00)
This panel discussion focused on historical accounts and strategic insights rather than current technical demonstrations. As such, no live demo or proof of concept was presented during the talk.
Defensive Implications
▶ Watch: Cyber's strategic importance recognized by combat commanders (14:00)
The narratives shared by the "Four Horsemen of Cyber" carry profound defensive implications for both military and civilian cybersecurity practitioners, underscoring lessons learned from the very origins of modern cyber warfare.
Firstly, the Buckshot Yankee incident highlights the critical importance of fundamental cyber hygiene and comprehensive network visibility. The inability of the DOD to accurately inventory its own systems ("how many computers do we actually have?") is a stark reminder that you cannot defend what you cannot see. Organizations must invest in robust asset management, continuous network monitoring, and endpoint detection and response (EDR) solutions to maintain real-time situational awareness. This includes understanding attack surfaces, identifying all connected devices (including shadow IT), and diligently patching vulnerabilities. The flash drive vector also emphasizes the enduring threat of simple, physical compromises, necessitating strict removable media policies and vigilant user education.
Secondly, the success of RT10/RTRG in Iraq provides a powerful blueprint for integrated threat intelligence and rapid response. Defenders should strive to correlate diverse data sources—such as network logs, endpoint telemetry, human intelligence, and open-source intelligence—to build a comprehensive picture of adversary activity. The emphasis on moving from "days or weeks" to "hours and minutes" for threat illumination underscores the need for automated analysis platforms and security orchestration, automation, and response (SOAR) capabilities. Real-time correlation and enrichment of data are crucial for detecting sophisticated threats, understanding their context, and initiating timely defensive actions before significant damage occurs.
Thirdly, the foundational role of US Cyber Command arising from these incidents emphasizes the necessity of proactive and dedicated cyber defense structures. Organizations should move beyond reactive incident response to establish dedicated Cybersecurity Operations Centers (CSOCs) or similar functions that integrate intelligence, defensive operations, and strategic planning. This includes developing clear command and control structures for cyber incidents, establishing robust playbooks for various threat scenarios, and conducting regular tabletop exercises to test readiness and refine response protocols.
Finally, the panel's focus on "high quality people" underscores that technology alone is insufficient. Investing in human capital is paramount. Defenders need highly skilled, innovative, and entrepreneurial individuals who can adapt to evolving threats. This requires continuous training, fostering a culture of curiosity and collaboration, and empowering teams to develop novel solutions. The integration of cyber specialists with traditional operational teams, as seen with NSA officers supporting Brigade Combat Teams, highlights the need for cross-functional collaboration and bridging the gap between technical expertise and operational realities. Ultimately, these early lessons advocate for a holistic, intelligence-driven, and people-centric approach to cybersecurity that treats cyber as a strategic domain rather than merely an IT problem.
Key Takeaways
- Buckshot Yankee as a Catalyst: The 2008 Buckshot Yankee incident exposed critical vulnerabilities in Department of Defense networks, including a severe lack of network visibility and the ease with which classified systems could be compromised, directly leading to the urgent need for a dedicated cyber command.
- Real-Time Intelligence is a Game-Changer: The RT10/RTRG system in Iraq demonstrated the transformative power of integrating and correlating diverse communication data (satellite, cell, ground reporting) to illuminate adversary networks in hours and minutes, significantly enhancing operational effectiveness and saving lives.
- Cyber as a Strategic Instrument: Early combat experiences, particularly in Iraq, elevated cyber from a technical support function to a strategic instrument of warfighting, proving its direct impact on military operations and garnering high-level support for its institutionalization.
- The Power of People and Innovation: The success of early cyber initiatives was heavily dependent on "high quality people" who exhibited entrepreneurship, innovation, and a collaborative spirit in high-pressure, real-world combat environments.
- Foundational for US Cyber Command: The combined lessons from Buckshot Yankee's crisis and RTRG's success provided the irrefutable rationale and operational blueprint for the establishment of US Cyber Command, marking a pivotal shift in the nation's approach to cyber defense and offense.
- Speed and Data are Paramount: The ability to rapidly collect, process, and act upon data proved essential for success in both defensive and offensive cyber operations, highlighting the critical role of speed and comprehensive data insights in modern conflict.
About the Speaker(s)
The panel comprised distinguished leaders who have shaped the landscape of US national security and cybersecurity:
Garrett Graf served as the moderator, bringing his expertise as a contributing editor at Wired Magazine, where he covers national security, and as the director of the Cyber Initiative at the Aspen Institute.
Paul Nakasone is a recently retired General who held the dual roles of Director of the National Security Agency (NSA) and Commander of US Cyber Command. His career includes significant contributions to the early development of US cyber capabilities, including training cryptologic support teams deployed in combat zones.
TJ White is a three-star retired Vice Admiral who previously served as the Commander of the 10th Fleet, a key operational command within the US Navy responsible for cyber and information warfare.
SL Davis is a three-star Air Force General and currently serves as the Inspector General of the Air Force. His experience spans various strategic roles within the Air Force, contributing to the broader military's understanding and integration of cyber into its operations.
Jen Easterly is the Director of the Cybersecurity and Infrastructure Security Agency (CISA), a role equivalent to a four-star General in the government's "plum book" of senior positions. She played a critical leadership role in the early stages of US cyber operations, particularly in Iraq, where she led teams developing real-time intelligence capabilities.