Cyber Policy: A View from the White House

Alexei Bulazel (Senior Director for Cyber, National Security Council · The White House), Stewart Baker (Principal · Stewart Baker Consulting PLLC)

RSA Conference 2025 · Day 2 · YBCA Stage · Keynote

Overview

Alexei Bulazel, the Trump administration's Senior Director for Cyber at the National Security Council and its highest-ranking cyber official at the time of the conference, delivered a candid account of the administration's cyber priorities: countering Chinese infrastructure intrusions with active deterrence rather than passive defense, refocusing CISA on its core technical mission, and rethinking the legal boundaries that prevent private-sector defenders from acting outside their own networks. In conversation with attorney and former NSA General Counsel Stewart Baker, Bulazel offered one of the most direct public accounts yet of where the new administration's cyber posture is heading. ---

Watch on YouTube

Visual summary for Cyber Policy: A View from the White House by Alexei Bulazel, Stewart Baker
Visual summary for Cyber Policy: A View from the White House by Alexei Bulazel, Stewart Baker

Key moments

  1. 0:54 NSC, ONCD, and CISA roles clarified by top White House cyber official
  2. 3:27 White House declares CISA had troubled past, commits to mission refocus
  3. 8:00 Admin compares Volt Typhoon pre-positioning to planting C4 in substations
  4. 10:44 Cold War deterrence model fails in cyberspace, new doctrine required
  5. 10:26 Non-response to cyber attacks is itself escalatory, officials argue
  6. 14:47 Administration re-examines legal authority for private-sector active defense
  7. 21:02 DOGE scrutinized for cybersecurity implications of rapid government IT changes
  8. 28:30 Administration signals prioritization of skilled cyber workforce and tooling

Cyber Policy: A View from the White House

Speakers: Alexei Bulazel, Senior Director for Cyber, National Security Council, The White House; Stewart Baker, Stewart Baker Consulting PLLC

Event: RSA Conference 2025 — April 28–May 1, 2025, Moscone Center, San Francisco

Track: Keynote — YBCA Stage

Watch: YouTube

Reading time: ~8 minutes

TL;DR

Alexei Bulazel, the Trump administration's Senior Director for Cyber at the National Security Council and its highest-ranking cyber official at the time of the conference, delivered a candid account of the administration's cyber priorities: countering Chinese infrastructure intrusions with active deterrence rather than passive defense, refocusing CISA on its core technical mission, and rethinking the legal boundaries that prevent private-sector defenders from acting outside their own networks. In conversation with attorney and former NSA General Counsel Stewart Baker, Bulazel offered one of the most direct public accounts yet of where the new administration's cyber posture is heading.

Introduction

When Alexei Bulazel took the stage at RSA Conference 2025, he held a distinction that was as telling as it was unusual: he was the highest-ranking cyber official in a new administration that had not yet confirmed several senior positions. As Senior Director for Cyber at the National Security Council, Bulazel coordinates cyber policy for national security matters across the executive branch — a role that has put him at the center of some of the most consequential strategic decisions the administration faces in the digital domain.

His conversation with Stewart Baker — a former NSA General Counsel who has spent decades at the intersection of law and national security — was framed as an opportunity for the security industry to understand not just what the administration's policies are, but how it reasons about the threat landscape. What emerged was an unusually frank discussion of Chinese cyber aggression, the limits of deterrence theory in cyberspace, CISA's identity crisis, and the question of how much latitude private-sector defenders should be given to fight back.

The NSC, ONCD, and CISA: Mapping the Institutional Landscape

Baker opened by asking Bulazel to demystify the overlapping cybersecurity roles within the executive branch — a question of genuine practical importance to practitioners trying to understand which government entity to engage for what purpose. ▶ Watch: NSC vs. ONCD vs. CISA explained (2:00)

Bulazel's explanation was crisp. The National Security Council, an institution more than seventy years old, exists to coordinate interagency policy on national security matters and translate the president's priorities into operational direction for departments including DoD, DOJ, and DHS. The NSC does not conduct operations — it does not run a national Security Operations Center or write code — but it sets the direction and ensures agencies row in the same direction on security matters.

The Office of the National Cyber Director (ONCD), created more recently by Congress, handles the large category of cybersecurity concerns that matter at a whole-of-government level but do not necessarily rise to national security significance — ensuring the Department of Agriculture and Department of Housing and Urban Development are following appropriate cybersecurity guidance, for example. ONCD also engages more directly with the private sector than NSC traditionally does.

CISA, Bulazel said plainly, "has had somewhat of a troubled past over the past six years." He expressed the administration's commitment to returning the agency to laser focus on the two functions in its name: cybersecurity and infrastructure security. The nominee to lead the agency, Sean Planky, worked on the NSC cyber team during the first Trump administration and brings deep critical-infrastructure experience from the Department of Energy. The administration's expectation is that CISA will be operationally focused rather than policy-diffuse.

Salt Typhoon, Volt Typhoon, and the Problem of Deterrence

The conversation's most substantive section concerned China's persistent intrusions into U.S. critical infrastructure — specifically the Salt Typhoon and Volt Typhoon campaigns. Baker characterized the Volt Typhoon penetrations of U.S. infrastructure, including positions taken up in systems that serve no intelligence-collection purpose, as something a previous administration was "shocked and upset about but didn't find a lot of tools to deter." ▶ Watch: Volt Typhoon and Salt Typhoon threat assessment (8:00)

Bulazel offered an analogy that cut through the abstractness of cyber conflict: "If we had a foreign actor, a foreign government putting packs of C4 and landmines down in a power substation or something like that, it would be very, very well understood what an act of aggression that is." The cyber equivalent — pre-positioned capabilities in critical infrastructure, ready to cause failures — carries the same strategic logic but far less public comprehension.

On deterrence itself, Bulazel was candid about its difficulty. The dynamics of cyberspace make it structurally easy for adversaries to probe and persist, and the Cold War-derived model of mutual assured destruction does not translate cleanly to a domain where the costs of retaliation are asymmetric. He cited a book by Dr. Emily Goldman, chief strategist of U.S. Cyber Command, on Cyber Persistence Theory as the intellectual framework most relevant to understanding why deterrence is hard.

The administration's answer involves several tools used in combination: imposing costs through sanctions, indictments, and other cross-domain instruments; conducting offensive operations to degrade adversary capabilities before they can be used ("defanging" rather than deterring); and communicating clearly that certain behaviors will not go unanswered. Bulazel was pointed on the last point: "Not responding, I think, is escalatory in its own right." Persistent non-response, he argued, establishes a norm in the adversary's mind that the United States will not act — which is itself a form of strategic signal. ▶ Watch: Responding to cyber aggression (10:00)

He was also candid about the limits of symmetric cyber retaliation: the United States, as a deeply digitally dependent society, often has more to lose from escalating in the cyber domain than the adversary does. The administration is exploring responses in other domains — economic, legal, diplomatic — that impose real costs without necessarily triggering a cyber exchange the U.S. might regret.

Rethinking the Public-Private Defensive Boundary

Baker pressed Bulazel on one of the field's longest-running policy debates: the legal line separating what defenders can do inside their own networks from what they can do outside them. Under current law, operating outside one's own network — even to collect threat intelligence or neutralize an attacker's tools — exposes a company to serious criminal liability. Baker argued that this structure leaves private-sector defenders behind a wall with no option but to wait for the adversary to come over it. ▶ Watch: Active defense and private-sector authority (14:00)

Bulazel agreed the current structure is insufficient. His answer distinguished between the public debate — which he said has drifted into unproductive extremes like "cyber letters of marque" that conjure images of privateers with unlimited authority — and the legitimate policy question of what specific, bounded authorities might be extended to qualified private defenders.

His position was that the government has, in past administrations, effectively abdicated responsibility for protecting private-sector organizations operating on the digital frontier. Critical infrastructure companies, in particular, face adversaries that are foreign militaries and intelligence services — opponents for whom even excellent commercial security hygiene is inadequate. "When you're being hacked by a foreign military or a foreign intelligence service, not necessarily the time to blame a company," he said. The administration is actively examining what responsible expanded authorities might look like — not unconstrained offensive operations by private actors, but targeted, legally defined capabilities that allow defenders to operate closer to the adversary.

CISA's Refocus and the Broader Federal Cybersecurity Posture

Threading through the conversation was the question of CISA's identity and direction. Bulazel reiterated the administration's position that the agency's detour into content moderation and mis/disinformation policy — work that had no clear grounding in the agency's statutory mandate — was a mistake. The agency was created to hunt and harden systems, support state and local governments and small businesses, and coordinate critical infrastructure security. That is the mission it will return to under the current administration. ▶ Watch: CISA's mission refocus (6:00)

Bulazel also highlighted the value of technical credibility in government. His background — security research and architecture at both Apple and Oracle, combined with policy experience across two administrations — informs an approach that Baker noted approvingly: when faced with a policy dispute about the scope of a problem, Bulazel has been known to ask simply, "Why don't you just show me the code?" That orientation — grounding policy in technical reality rather than abstraction — is a disposition the administration appears to value, and one the security community at RSA Conference 2025 received warmly.

Notable Quotes

"This administration, we do think that cybersecurity is national security."

"If we had a foreign actor putting packs of C4 and landmines down in a power substation, it would be very, very well understood what an act of aggression that is. When it's the cyber equivalent — a cyber bomb, a cyber landmine — people sort of look at it differently."

"Not responding, I think, is escalatory in its own right. If you continually let the adversary walk all over you and do nothing, that in itself sets a norm."

"When you're being hacked by a foreign military or a foreign intelligence service, not necessarily the time to blame a company."

"We're very committed to having CISA stay laser-focused on the two things that are in its name: cybersecurity and infrastructure security."

Key Takeaways

  1. The NSC, ONCD, and CISA serve distinct but complementary roles. Practitioners engaging the federal government on cyber issues need to understand which institution handles which class of problem — the NSC for national security matters, ONCD for whole-of-government civilian coordination, and CISA for operational security support to critical infrastructure and subnational entities.
  1. Volt Typhoon represents a strategic threat, not just a breach. Pre-positioned Chinese capabilities inside U.S. critical infrastructure are, in Bulazel's framing, the cyber equivalent of buried explosives — a deliberate, aggressive act whose true nature is often obscured by the technical language used to describe it.
  1. Deterrence in cyberspace requires a multi-domain toolkit. Symmetric cyber retaliation is a poor fit for the United States given its network dependency. Cost imposition through sanctions, indictments, and pre-emptive degradation of adversary infrastructure offers more leverage without triggering escalatory dynamics the U.S. might regret.
  1. The passive-defense model for the private sector is under review. The current legal framework confines private defenders to their own perimeter and leaves them structurally unable to respond to foreign state-sponsored attackers. The administration is exploring bounded authorities that could give qualified defenders more room to operate.
  1. Technical credibility is a policy asset. Bulazel's willingness to read code rather than rely solely on briefings signals an administration posture that prioritizes technical grounding — a message that landed well at a conference dominated by practitioners who have long argued that policy divorced from engineering reality tends to fail.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

The highest-ranking cyber official in the current U.S. administration lays out actual policy positions on deterrence, CISA's mandate, Volt/Salt Typhoon, and active defense authority for private actors — with the technical credibility to back it up. Bulazel's C4-in-the-substation analogy is reductive but deliberately so: the administration wants the public to understand that pre-positioned cyber capabilities in critical infrastructure are acts of aggression, not espionage. Rare case of a government keynote with real content.

Heather Calloway (CISO) — MUST SEE

White House NSC Cyber Directorate's Alexei Bulazel lays out the current administration's cyber policy direction — more aggressive posture toward adversaries, skepticism of regulatory approaches, focus on incentive redesign and technology-led defense. This is the first detailed public articulation of where policy is heading.

→ Top-rated talks at RSA Conference 2025

All talks from RSA Conference 2025