Cyber Policy in a New Washington: Priorities from Pennsylvania Avenue
George Barnes (President, Cyber Practice · Red Cell Partners, LLC), Frank Cilluffo (Director, McCrary Institute for Cyber and Critical Infrastructure Security · Auburn University), Mark Montgomery (Executive Director · Cyberspace Solarium Commission 2.0), Alexandra Seymour (Staff Director, Subcommittee on Cybersecurity and Infrastructure Protection · U.S. House of Representatives), Moira Bergin (Staff Director (Minority), Subcommittee on Cybersecurity and Infrastructure Protection · U.S. House of Representatives)
RSA Conference 2025 · Day 1 · Policy · Policy & Government
Overview
As the first hundred days of the Trump administration concluded, a panel of former senior intelligence officials and active Capitol Hill staff directors gave an unusually candid assessment of where cyber policy stands in Washington — what the new administration will do, what it should do, and what the 119th Congress can realistically deliver. The conversation ranged from Volt Typhoon and Salt Typhoon prepositioning in U.S. critical infrastructure, to the contested question of separating NSA from Cyber Command, to the practical legislative calendar facing cyber bills with Senator Rand Paul in the Senate. ---

Key moments
- 3:23 Volt Typhoon brief triggered Waltz's 'more offensive' posture declaration
- 4:49 NSA/Cyber Command split warning: 'make before break' or Cyber Command will fail
- 12:35 500,000 open cybersecurity jobs nationwide — worst at state and local level
- 13:02 Cyber Pivot Act: community colleges, skills-based training, government service pipeline
- 14:18 Regulatory harmonization: duplicative regs pulling security staff onto compliance work
- 16:15 Typhoon wake-up call: nation-states prepositioning in critical infrastructure at scale
- 32:27 Bergin: cyber policy momentum ebbs and flows with crises — adversary sets strategy
- 44:03 Rand Paul will slow-roll all cyber bills — forcing bill-by-bill Senate passage
Cyber Policy in a New Washington: Priorities from Pennsylvania Avenue
Talk ID: RSA25-026
Speakers: George Barnes (Red Cell Partners, LLC), Frank Cilluffo (Auburn University / McCrary Institute), Mark Montgomery (Cyberspace Solarium Commission 2.0 / FDD), Alexandra Seymour (U.S. House of Representatives), Moira Bergin (U.S. House of Representatives)
Conference: RSA Conference 2025 — April 28–May 1, 2025, Moscone Center, San Francisco
Stage: Policy Stage | Track: Policy & Government
YouTube: Watch on YouTube
Reading Time: ~8 minutes
TL;DR
As the first hundred days of the Trump administration concluded, a panel of former senior intelligence officials and active Capitol Hill staff directors gave an unusually candid assessment of where cyber policy stands in Washington — what the new administration will do, what it should do, and what the 119th Congress can realistically deliver. The conversation ranged from Volt Typhoon and Salt Typhoon prepositioning in U.S. critical infrastructure, to the contested question of separating NSA from Cyber Command, to the practical legislative calendar facing cyber bills with Senator Rand Paul in the Senate.
Introduction
Frank Cilluffo, Director of the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University, opened the session with a deliberately calibrated observation: they were reaching the end of the first hundred days of a new administration and the early weeks of the 119th Congress. "A great time to take stock on where we are, where we hope to be, and how we get there."
The panel he assembled offered rare direct access to both the policy-making and legislative sides of Washington's cyber apparatus: Mark Montgomery, Staff Director of the Cyberspace Solarium Commission and now at the Foundation for Defense of Democracies; George Barnes, former Deputy Director of the National Security Agency; Alexandra Seymour, Staff Director for the House Homeland Security Subcommittee on Cybersecurity; and Moira Bergin, Minority Staff Director at House Homeland Security.
The session was among the most substantively policy-dense of the conference — and one of the more candid.
Section 1: What the New Administration Will Do, Suspects, and Hopes For
Montgomery structured his opening around three categories: what he knows the administration will do, what he suspects, and what he hopes.
▶ Watch: Montgomery's "knows, suspects, hopes" framework for the new administration (02:00)
What he knows: national security adviser Mike Waltz, upon receiving yet another brief on Volt Typhoon, said he was going to be "more offensive." Montgomery interpreted this as more aggressive about responding to attacks, more willing to attribute publicly, and more focused on imposing costs and consequences on adversaries. Attribution timelines in cyberspace, he noted, have compressed from months-to-years to weeks-to-months — but that remains orders of magnitude slower than conventional military attribution. "If I'm observing a cruise missile attack on my forces, I usually have attribution within thirty to forty-five seconds." Closing that gap is critical.
What he suspects: the administration will separate NSA and Cyber Command — a decision Montgomery called premature. "You have to invest before you break. This is what we call in nuclear power, 'make before break.' You've got to make Cyber Command whole before you break it from NSA, or you're going to have a crap show of Cyber Command." His hope is that, if the separation happens, it is accompanied by a serious investment in building a Cyber Force with its own force generation model.
What he hopes: the incoming CISA director and ONCD director will do what Cilluffo and Montgomery have argued for passionately for three years — stop producing lists of a hundred priorities and focus on a small number of sectors where the government will establish minimum security requirements, third-party assess compliance, and provide benefits in return.
Section 2: NSA's Cybersecurity Collaboration Center — Symbol and Substance
George Barnes offered a defense and diagnosis of NSA's Cybersecurity Collaboration Center, which he helped build.
▶ Watch: Barnes on the NSA Collaboration Center — symbol and substance (06:00)
The Center is both an operational capability and a symbolic statement about where government-industry relationships needed to go. "Where we started was: government did X, and the outside commercial world did Y, and never the twain shall meet." The Center created a trust relationship with industry built on transparency, acknowledging the value each party brings, and focusing each on what only they can do best.
NSA's unique contribution is access to the foreign environment — not just what is hitting domestic networks in real time, but what is being built and tested against other nations before it arrives. "Most of what industry gets is what's actually hitting their environment. What NSA can do is actually get out there when things are being built or being tested against, unfortunately, other nations."
The Center's limitation is jurisdictional: its authorities have been constrained primarily to the defense industrial base and DIB-supporting service providers. Critical infrastructure sectors — energy, water, transportation — outside that scope have not fully benefited from NSA's visibility. Barnes called this a gap that legislation needs to address.
Barnes also noted a specific policy failure: CISA's enhanced security framework authorities had become entangled with CISA's CPAC-funded programs, and when that funding was cancelled, those critical authorities were lost. "We've lost these critical authorities. Do you think we should just write them into the next NDAA to sit right at NSA?"
Section 3: The 119th Congress — Priorities and Constraints
Alexandra Seymour laid out the House Homeland Security Committee's three cyber priority areas for the 119th Congress.
Workforce: Chairman Green's top priority. With over five hundred thousand open cybersecurity jobs nationwide — concentrated disproportionately in state and local government, where competitive salaries and critical infrastructure proximity create a particularly acute problem — the committee has introduced the Cyber Pivot Act, targeting two-year institutions and community colleges, requiring hands-on exercises, internships, and two years of government service.
Regulatory harmonization: The current regulatory landscape is cumbersome, duplicative, and sometimes contradictory. Organizations are pulling security talent off security work to satisfy compliance requirements. The committee's goal is to identify where regulations overlap, streamline reporting requirements, and use technological solutions to reduce the compliance burden.
Changing the economics of cybersecurity: This bucket covers critical infrastructure protection against the Typhoon-class nation-state threats, addressing the first-to-market problem (building security in at the design stage), and raising the cost of attacks on adversaries.
Seymour also flagged the committee's oversight of CISA's reauthorization and the Cybersecurity Information Sharing Act of 2015.
Bergin, speaking from the minority perspective, named CISA's decimated workforce as the defining constraint on everything else: "Over the past one hundred days, we've seen its workforce decimated, and the people who work on the most important priorities leave one way or another." The challenge is that CISA is the agency the committee oversees, and its current condition shapes what cooperation, intelligence sharing, and critical infrastructure protection are actually possible.
Section 4: CISA's Future — From Information Sharing to Operational Collaboration
▶ Watch: Cilluffo on translating information sharing into operational collaboration (10:00)
Cilluffo named the central challenge bluntly: he and his colleagues have been talking about public-private partnership since the Clinton administration's Presidential Decision Directive 63 in 1998. "Twenty-five years ago. That is a sad statement."
The aspiration now is translating that discussion from information sharing to operational collaboration — active, real-time joint action rather than coordination meetings and shared reports. Montgomery argued that the Joint Cyber Defense Collaborative, authorized in legislation, has not been properly funded for its intended mission, and that the Joint Cyber Planning Office beneath it needs to be empowered with its own authorization and appropriations to grow effectively.
▶ Watch: Montgomery on empowering JCDC and restoring cyber operational institutions (30:02)
The panel broadly agreed that the National Cyber Director should function as head coach — not offensive coordinator or defensive coordinator, but the person who integrates both and holds a coherent national strategy. The current moment, with CISA weakened and the ONCD's role still being defined, is not that.
Bergin's contribution was the most structurally important: "Momentum for cyber policy ebbs and flows with crises. We respond to what we see." The adversary defines the strategy. That passivity is a genuine policy failure, but it is the honest description of how legislatures function. The implication for the security community: advocacy and engagement between crises is not optional.
Section 5: The Senate Problem, Volt and Salt Typhoon, and Allied Cooperation
▶ Watch: Montgomery on Rand Paul, the Senate, and the realistic legislative timeline (44:03)
Montgomery offered a frank assessment of the Senate obstacle: Senator Rand Paul will vote no on most cyber bills, but more importantly, he will force everything to go bill-by-bill rather than packaged into an NDAA or omnibus. "He understands that [these things] will happen, but they are going to happen slow." Combined with Senate leadership time constraints, minor cyber bills will face a difficult calendar.
The Volt Typhoon and Salt Typhoon intrusions into U.S. critical infrastructure received extended discussion. Krebs, cited by the moderator, has argued that Volt Typhoon — PLA military prepositioning in civilian critical infrastructure — is the threat that keeps him up at night most. The purpose is not intelligence collection but the creation of leverage: the ability to cause panic, chaos, and potentially casualties in a crisis scenario to constrain U.S. force projection decisions.
Barnes and Montgomery returned to a structural point: a municipal water facility has no IT security to speak of. The CISA workforce shortfall is measured in hundreds, not hundreds of thousands. The gap between the scale of the Volt Typhoon problem — embedded in forty thousand miles of strategic rail, sixty-nine strategic airfields, seventeen seaports — and the resources available to address it is not closeable through voluntary information sharing alone. Some form of DOD engagement with the critical transportation infrastructure that enables force mobilization is the logical next step, Montgomery argued.
Bergin closed on allied cooperation: "Our allies are our friends. They're incredibly important partners for cybersecurity. Any change in our behavior doesn't happen in a vacuum. We have to bring our allies with us. We can't afford to alienate them."
Notable Quotes
"You have to invest before you break. Make Cyber Command whole before you break it from NSA, or Cyber Command will just suck." — Mark Montgomery
"I am tired of the public-private partnership discussion. You and I were talking about this in the Clinton administration — twenty-five years ago." — Frank Cilluffo
"Momentum for cyber policy ebbs and flows with crises. Wherever the fire is, that's the fire that gets put out." — Moira Bergin
"The adversary gets a vote. We respond to what we see. Why do we let the bad guys define our strategy?" — Panel exchange
"Trust arrives on foot, leaves on horseback." — Chris Krebs (referenced by panelists)
Key Takeaways
- The new administration is expected to be more aggressive on attribution and offensive operations — but the speed and scope of NSA/Cyber Command separation remains a contested and potentially premature decision.
- The 119th Congress has a defined cyber agenda — workforce pipeline through the Cyber Pivot Act, regulatory harmonization, and critical infrastructure economics — but realistic passage requires navigating a Senate where Senator Paul will slow-roll most standalone cyber bills.
- CISA's workforce decimation is the single largest near-term setback — the operational capacity for public-private operational collaboration cannot be rebuilt quickly, and its absence affects everything from Volt Typhoon response to international partner coordination.
- Volt Typhoon is the defining strategic threat — PLA prepositioning in civilian critical infrastructure is designed not for espionage but for strategic leverage, and the jurisdictional gaps between NSA's authorities, CISA's capacity, and DOD's focus create exactly the seams adversaries need.
- The operational collaboration moment requires institutional investment — the JCDC needs proper authorization and appropriations, the PIVOT Act and related bills need to pass, and the pattern of reacting to crises rather than building durable capability must be broken.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
The most candid Washington insider panel RSA 2025 produced. Montgomery's three-category framework for the new administration is immediately useful. Bergin's minority-voice observation that 'momentum for cyber policy ebbs and flows with crises' is the most honest political diagnosis of the conference. Barnes on NSA's Cybersecurity Collaboration Center, Seymour on the Cyber Pivot Act, and the Rand Paul legislative reality check are all substantive. Watch this if you need to understand what the next two years will and won't deliver.
Heather Calloway (CISO) — STRONG ACCEPT
Former NSA Deputy Director, Cyberspace Solarium Commission staff, and active House Homeland Security staff directors give a candid assessment of the 119th Congress cyber agenda — workforce, regulatory harmonization, critical infrastructure economics — and the structural constraints: CISA's decimated workforce, Rand Paul's Senate blocking position, and 25 years of public-private partnership discussion that has not yet produced operational collaboration.