The Future of Tech Policy: Balancing Innovation, Security, and Regulation
Paul Nakasone (Director, Institute of National Security · Vanderbilt University), Chris Krebs (Former Director, CISA · Cybersecurity & Infrastructure Security Agency), Ted Schlein (Chairman & General Partner · Ballistic Ventures and Kleiner Perkins)
RSA Conference 2025 · Day 1 · Policy · Policy & Government
Overview
Former NSA Director and Cyber Command Commander General Paul Nakasone and former CISA Director Chris Krebs, in conversation with veteran security investor Ted Schlein, delivered a frank assessment of where the United States stands against its adversaries, what a more aggressive offensive posture would actually entail, and where policy on AI, software liability, and platform regulation is heading. The session was notably candid about the failures of the past decade's voluntary framework and the widening gap between China's capabilities and everyone else's. ---

Key moments
- 3:06 China intrusions up 150% year-over-year, 79% without malware — credential-only attacks
- 9:57 Volt Typhoon targets civilians to create panic and constrain U.S. force projection
- 18:14 Defend forward validated: Cyber Command in Ukraine feeding CISA real-time intelligence
- 20:39 First defend-forward deployment to Ukraine confirmed — offense and defense in dynamic loop
- 25:26 Krebs rejects private sector hack-back: letters of marque create unacceptable alliance risk
- 34:59 Software liability debate: adversarial exploitation makes blanket liability perverse
- 43:00 Cyber Safety Review Board must be reinstated — critical oversight mechanism now disbanded
- 44:02 Secure by Design initiative disappearing — voluntary accountability mechanism at risk
The Future of Tech Policy: Balancing Innovation, Security, and Democracy
Talk ID: RSA25-027
Speakers: Paul Nakasone (Vanderbilt University / OpenAI Board), Chris Krebs (Former CISA Director), Ted Schlein (Ballistic Ventures / Kleiner Perkins)
Conference: RSA Conference 2025 — April 28–May 1, 2025, Moscone Center, San Francisco
Stage: Policy Stage | Track: Policy & Government
YouTube: Watch on YouTube
Reading Time: ~8 minutes
TL;DR
Former NSA Director and Cyber Command Commander General Paul Nakasone and former CISA Director Chris Krebs, in conversation with veteran security investor Ted Schlein, delivered a frank assessment of where the United States stands against its adversaries, what a more aggressive offensive posture would actually entail, and where policy on AI, software liability, and platform regulation is heading. The session was notably candid about the failures of the past decade's voluntary framework and the widening gap between China's capabilities and everyone else's.
Introduction
Ted Schlein, managing partner at Ballistic Ventures and veteran of Kleiner Perkins, opened with a set of statistics drawn from the CrowdStrike threat analysis report and conversations with Kevin Mandia: China intrusions up approximately one hundred and fifty percent year over year. Seventy-nine percent of those incursions executed without malware — purely credential- and tool-based. More than fifty percent of breaches targeting U.S. critical infrastructure. Breakout time for adversaries now as low as forty-eight minutes. Salt Typhoon. Volt Typhoon.
"I've been doing this for forty years, so I feel like basically a complete and utter failure," Schlein said. "We don't appear to be winning."
The two guests he had brought to address that opening — General Nakasone, former director of the NSA and commander of U.S. Cyber Command, now at Vanderbilt and on the board of OpenAI; and Chris Krebs, the first CISA director and the official whose firing by tweet became its own policy inflection point — spent the next hour engaging with that premise in detail.
Section 1: Are We Winning or Losing?
Krebs pushed back on the framing immediately, not to be comforting but to be precise. "It's not an answerable question."
▶ Watch: Krebs on why "winning or losing" is the wrong frame — and what the right one is (04:00)
U.S. cyber defensive policy has been built on the same framework since the late Clinton administration's Presidential Decision Directive 58: a reactive, industry-voluntary approach rooted in the American political tradition of letting bad things happen first, then crafting policy. "Since '98, the first ISAC, the Financial Sector ISAC, was set up in the late nineties. We've been working on these things."
The adversary gets a vote, Krebs argued. China, Russia, and others are advancing their capabilities, sometimes in isolation, sometimes in direct reaction to U.S. defensive improvements. The defensive side is unlikely to ever "win" in a terminal sense — it is always a dynamic competition.
Nakasone focused on three things required to change the trajectory: raising the baseline so credential-stuffing and known vulnerabilities stop providing easy access; maintaining persistent operational presence so adversaries understand they are engaged every day, not just reacting after incidents; and building the partnerships — both government-industry and international — required to synchronize defensive and offensive action.
"Fifteen percent increase in ransomware last year. We need different partnerships. We need to figure out how those partnerships are gonna come together and how we're gonna synchronize a better action against these adversaries," Nakasone said.
Section 2: Volt Typhoon — The Strategic Threat Hiding in Plain Sight
▶ Watch: Krebs on Volt Typhoon — not espionage but warfighting prepositioning (08:00)
Krebs offered the most clinically precise characterization of Volt Typhoon in the session. The Chinese military — the PLA — has been found not in strategic military assets but in civilian critical infrastructure: water, power, transportation. The target selection is deliberate.
"They're going after civilian stuff with the intent to create panic, chaos, and — I would posit — to kill people. To create a situation where political leadership has to address that rather than projecting force elsewhere." The strategic logic is not intelligence collection. It is the creation of leverage: at a moment of military crisis over Taiwan, the ability to create domestic chaos in the United States constrains U.S. decision-making.
The policy gap is stark. Krebs described the typical scenario: a municipal water facility with no IT security. "When you talk about IT security at a municipal water facility, it does not exist." The CISA workforce gap is measured in hundreds, not thousands. The multi-state ISAC and election infrastructure ISAC — the shared service mechanisms designed to extend coverage — "have been gutted."
Nakasone's response was to argue for a different model: rather than waiting for voluntary uptake of hygiene practices, the government should be providing scanning services, protective DNS, and other baseline capabilities directly to underresourced critical infrastructure operators. "Why are we not providing scanning? Why are we not providing protective DNS? Things that will raise the bar?"
Section 3: Offense, Defend Forward, and the Cyber Letters of Marque Question
▶ Watch: Nakasone on prioritizing China and what "more offensive" actually means (20:01)
Schlein pressed Nakasone on what a more aggressive posture would actually look like if he were still in command. Nakasone's answer was direct: China is the pacing challenge. The operations would range from hunting in adversary networks to expose their presence, to information operations, to working with industry to ensure anomalies are reported and actioned, to offensive action if necessary. "That whole scale of different activities gives you a lot of different options."
The "defend forward" model — Cyber Command teams operating in partner countries during their elections, identifying Russian interference activities in real time and passing that intelligence back to CISA for domestic defensive action — was described by Nakasone as a validated model of offense informing defense informing offense in a seamless, dynamic loop. "One plus one equals two. It was a multiple event."
▶ Watch: Krebs rejects cyber letters of marque — the private sector hack-back question (24:01)
Schlein then raised the question of private sector offensive action — "cyber letters of marque." Krebs, though characteristically direct, was unambiguous: not yet, and possibly not ever in the current form. The attribution problem alone is disqualifying: "What if a Volt Typhoon actor is sitting on a pivot point in Germany? What does that private sector company do?" The risk to alliances, the inability to guarantee attribution quality, and the absence of synchronization infrastructure for private offensive action make the concept premature.
Nakasone added the operational concern: these operations require synchronization, high-confidence intelligence, and the ability to manage escalation — capabilities that exist within NSA and Cyber Command specifically because they were built for exactly these requirements. "That's something our government does. That's something the DoD does."
Section 4: AI Policy — Competition, Regulation, and Guardrails
▶ Watch: Nakasone on U.S. AI lead and the need for a strategy, not just innovation (28:01)
Nakasone, speaking from his position on the OpenAI board, framed AI policy primarily as a competitiveness challenge. The United States currently leads in frontier AI development, but that lead is not guaranteed and the gap is not growing. "Our focus needs to be how do we ensure that lead continues, not only to diminish but to grow."
His specific concern is the absence of a coherent national strategy translating AI innovation into implementation — with adequate resources for chips, data, energy, and talent. OpenAI's preparedness framework, which includes safety and security review before model release, was offered as an example of responsible internal governance.
Krebs argued the Biden administration's AI executive order was more reasonable than its critics suggested — not highly restrictive, primarily requiring red-teaming reports above a computation threshold — and that the regulatory conversation should focus on high-stakes applications: healthcare decisions, financial decisions, housing decisions, and autonomous systems. The European model's broad regulatory approach risks innovation flight, but some targeted governance is both legitimate and necessary.
▶ Watch: Deepfakes as the most immediate AI threat to social trust (30:01)
Both agreed that deepfakes represent the most immediate AI threat to social stability — harder to address than cyber intrusions because the harm is informational and the policy toolkit is less developed.
Section 5: Software Liability and the Cyber Safety Review Board
▶ Watch: Krebs on software liability — necessary but genuinely hard (40:02)
The software liability question received nuanced treatment. Schlein posed the foundational issue: an entire industry grew up with no liability for security flaws, charging customers to fix mistakes via annual maintenance contracts. Should that remain?
Krebs' answer acknowledged the legitimacy of the concern while flagging the difficulty: "There is no other product space where you have an intelligent adversary that is every second of every day picking apart that product." Blanket liability frameworks that don't account for sophisticated nation-state exploitation may punish vendors for being targeted rather than for being negligent.
The path forward, both argued, runs through transparency and oversight rather than direct liability. The Cyber Safety Review Board — now disbanded — was described as a genuinely valuable institution: "Shining a light on what the root problem was. The question is should that then yield liability?" Nakasone called for the Board's reinstatement in some form. Given that a small number of major software vendors are responsible for vast swaths of national security-adjacent infrastructure, independent review of significant incidents is a minimum accountability mechanism.
The Secure by Design initiative from CISA was also highlighted as a successful voluntary mechanism that pulled corporate responsibility strings without requiring litigation — and both expressed concern that it appears to be going away.
▶ Watch: NSA/Cyber Command integration — why breaking them up is risky now (26:01)
Notable Quotes
"China intrusions are up one hundred and fifty percent year over year. I've been doing this for forty years and I feel like a complete and utter failure." — Ted Schlein
"Volt Typhoon is going after civilian stuff with the intent to create panic, chaos, and — I would posit — to kill people." — Chris Krebs
"The future of modern conflict starts in cyberspace. Everything going forward is unthinkably complex." — Paul Nakasone
"The moment that worries me the most: trust arrives on foot, leaves on horseback." — Chris Krebs
"Policy that doesn't go anywhere is just a position paper." — Chris Krebs
Key Takeaways
- China is the pacing challenge, separated from all other adversaries by scope, scale, and sophistication — Volt Typhoon's civilian critical infrastructure prepositioning is designed to constrain U.S. force projection, not gather intelligence.
- "Defend forward" is a validated model — Cyber Command operations in partner countries during their elections demonstrated that offense, defense, and intelligence can operate as a dynamic, real-time loop rather than sequential phases.
- Private sector offensive action (cyber letters of marque) is premature — attribution uncertainty, alliance risks, and the absence of synchronization infrastructure make civilian hack-back frameworks legally and strategically unready.
- AI policy should focus on competitiveness and targeted governance — the U.S. lead in frontier AI is real but not guaranteed; a national strategy for implementation is more urgent than broad regulatory constraints, though high-stakes applications require targeted guardrails.
- Software liability reform requires the Cyber Safety Review Board — transparency and independent oversight of significant incidents is the near-term priority, providing the evidentiary basis for eventual liability frameworks without creating perverse incentives that punish vendors for being targeted.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Nakasone and Krebs are the highest-caliber combination of cyber principal and cyber operator RSA 2025 put on stage, and they don't waste the opportunity. The China threat quantification is stark. The defend-forward validation with Ukraine confirmation is policy-relevant. Krebs on Volt Typhoon's strategic purpose — not espionage but leverage for force projection constraint — is the clearest framing of that threat at the conference. The AI and software liability sections are thinner but honest about complexity.
Heather Calloway (CISO) — MUST SEE
General Nakasone and Chris Krebs, in conversation with Ted Schlein, deliver the most candid senior-level assessment of where the US stands against its adversaries: China is the pacing threat, 'defend forward' is the validated model, and 25 years of voluntary frameworks have not closed the gap. Krebs: Volt Typhoon is designed to create panic, chaos, and potentially to kill people.