1 00:00:02,440 --> 00:00:05,640 Yeah . Yeah . 2 00:00:06,640 --> 00:00:09,380 For you . Yeah , 3 00:00:13,440 --> 00:00:18,970 thank 4 00:00:18,970 --> 00:00:21,026 you for your time today . So we look 5 00:00:21,026 --> 00:00:23,081 forward to hearing about some of the 6 00:00:23,081 --> 00:00:25,192 priorities that the duty is facing in 7 00:00:25,192 --> 00:00:27,303 the area of cybersecurity . So one of 8 00:00:27,303 --> 00:00:29,359 things I want to talk about is if in 9 00:00:29,359 --> 00:00:31,750 2020 there was a solar winds attack . 10 00:00:31,760 --> 00:00:33,704 And it really highlighted from the 11 00:00:33,704 --> 00:00:35,816 evolving attacks that the D . O . D . 12 00:00:35,816 --> 00:00:37,871 is facing . And in February you guys 13 00:00:37,871 --> 00:00:39,927 released your reference architecture 14 00:00:39,927 --> 00:00:42,038 around zero trust . Can you tell us a 15 00:00:42,038 --> 00:00:41,970 little bit about what the priorities 16 00:00:41,970 --> 00:00:45,030 are in that architecture ? Uh Yeah , 17 00:00:45,040 --> 00:00:47,880 thank you for that question . Um when 18 00:00:47,880 --> 00:00:49,991 we released architecture we had seven 19 00:00:49,991 --> 00:00:53,840 pillars there and um the priority 20 00:00:53,840 --> 00:00:56,130 of all of the pillars working together 21 00:00:56,130 --> 00:00:59,610 and in harmony is that we're able to 22 00:00:59,620 --> 00:01:03,490 detect advanced persistent threats uh 23 00:01:03,500 --> 00:01:05,860 trying to attack our network , advanced 24 00:01:05,860 --> 00:01:07,471 persistent threats that have 25 00:01:07,471 --> 00:01:10,470 successfully hacked our networks and 26 00:01:10,470 --> 00:01:13,560 their their lateral movement inside of 27 00:01:13,570 --> 00:01:16,640 our networks . Um Well we've had 28 00:01:16,640 --> 00:01:20,250 historically uh we've been very good at 29 00:01:20,250 --> 00:01:22,417 perimeter defenses in the department . 30 00:01:22,417 --> 00:01:24,583 Um we've got a lot of tools that we've 31 00:01:24,583 --> 00:01:26,417 deployed there and I think we're 32 00:01:26,417 --> 00:01:29,560 successful with 99.9% of all attack 33 00:01:29,560 --> 00:01:32,450 vectors . But um there there is this 34 00:01:32,450 --> 00:01:35,090 advanced capability that uh . nation 35 00:01:35,090 --> 00:01:37,950 state actors have uh that they can get 36 00:01:37,950 --> 00:01:40,360 a foothold through a variety of means 37 00:01:40,360 --> 00:01:42,710 fishing brute force attacks on 38 00:01:42,710 --> 00:01:44,821 vulnerabilities that are on servers , 39 00:01:44,821 --> 00:01:48,720 web attacks , hacking the code . Um 40 00:01:48,720 --> 00:01:50,887 And once they get a foothold , what we 41 00:01:50,887 --> 00:01:52,920 found over time is is we have a 42 00:01:52,920 --> 00:01:56,700 struggle to find them . Uh and then 43 00:01:56,700 --> 00:01:59,100 finally eradicate them from the network 44 00:01:59,100 --> 00:02:01,211 and have confidence that they're gone 45 00:02:01,211 --> 00:02:03,322 from the network . So the goal of all 46 00:02:03,322 --> 00:02:05,433 of this is that these components will 47 00:02:05,433 --> 00:02:07,656 work together . Uh so that we can if we 48 00:02:07,656 --> 00:02:10,000 can't completely block them out of the 49 00:02:10,000 --> 00:02:12,720 network that we can quickly find them . 50 00:02:12,750 --> 00:02:15,320 Eradicate them from the network and be 51 00:02:15,320 --> 00:02:17,153 sure that they are gone from the 52 00:02:17,153 --> 00:02:20,050 network . And and there's a lot of good 53 00:02:20,050 --> 00:02:23,800 things that we look at their the device 54 00:02:24,340 --> 00:02:26,950 the the individual themselves , uh 55 00:02:26,960 --> 00:02:29,016 protection of the data protection of 56 00:02:29,016 --> 00:02:30,682 the network protection of the 57 00:02:30,682 --> 00:02:33,270 application workloads and then uh 58 00:02:33,280 --> 00:02:36,970 orchestration uh of of events . Once we 59 00:02:36,970 --> 00:02:39,160 see something we don't have a human 60 00:02:39,160 --> 00:02:41,530 response to that , we want to have this 61 00:02:41,540 --> 00:02:43,762 automatic response that takes place and 62 00:02:43,762 --> 00:02:46,760 protects us as well as analytics to 63 00:02:46,760 --> 00:02:49,390 look for abnormal behaviors were very 64 00:02:49,390 --> 00:02:53,100 signature based and we want to look for 65 00:02:53,100 --> 00:02:56,600 behaviors because new signatures uh 66 00:02:56,610 --> 00:02:58,832 come up all the time and until somebody 67 00:02:58,832 --> 00:03:01,054 discovers them and tells everybody else 68 00:03:01,054 --> 00:03:02,888 about them , we we can't protect 69 00:03:02,888 --> 00:03:04,666 against them . So uh behavioral 70 00:03:04,666 --> 00:03:06,832 analytics is a big piece of this to to 71 00:03:06,832 --> 00:03:08,943 be able to call over all the logs and 72 00:03:08,943 --> 00:03:10,888 and understand what those logs are 73 00:03:10,888 --> 00:03:12,920 telling us that there's some odd 74 00:03:12,920 --> 00:03:14,920 behavior on the network and then be 75 00:03:14,920 --> 00:03:17,380 able to respond quickly to that . Yes , 76 00:03:17,390 --> 00:03:19,557 thank you for some of those insights . 77 00:03:19,557 --> 00:03:21,779 You know , we have Cisco , we're seeing 78 00:03:21,779 --> 00:03:23,779 a real increase in the volume . The 79 00:03:23,779 --> 00:03:26,001 sophistication of attacks . Um you know 80 00:03:26,001 --> 00:03:28,168 and over that you mentioned , I'd like 81 00:03:28,168 --> 00:03:30,279 to expand on one piece about the five 82 00:03:30,279 --> 00:03:32,520 pillars or the seven pillars that you 83 00:03:32,530 --> 00:03:35,290 that the duty has we know in the 84 00:03:35,300 --> 00:03:37,620 executive order that was released um 85 00:03:37,630 --> 00:03:41,570 esa's cyber or zero trust um maturity 86 00:03:41,570 --> 00:03:44,270 model as well as spices and R . And B . 87 00:03:44,270 --> 00:03:46,381 S . That there were five pillars . It 88 00:03:46,381 --> 00:03:49,830 was the user the device um at networks , 89 00:03:49,840 --> 00:03:52,240 application , workload and data . The D . 90 00:03:52,240 --> 00:03:54,407 O . D . Has two additional pillars and 91 00:03:54,407 --> 00:03:56,407 it was visibility and analytics and 92 00:03:56,407 --> 00:03:58,351 orchestration automation . Can you 93 00:03:58,351 --> 00:04:00,629 expand a little bit on the two pillars ? 94 00:04:00,629 --> 00:04:02,629 Um those two additional pillars and 95 00:04:02,629 --> 00:04:04,851 what's the importance to use your trust 96 00:04:04,851 --> 00:04:07,073 strategy ? Sure , sure . I think if you 97 00:04:07,073 --> 00:04:09,240 look at our reference architecture and 98 00:04:09,240 --> 00:04:13,030 oh MBS document uh well 99 00:04:13,030 --> 00:04:16,660 they didn't make orchestration uh 100 00:04:17,140 --> 00:04:20,930 and automation and visibility and 101 00:04:20,930 --> 00:04:23,940 analytics pillar . Uh they made it part 102 00:04:23,940 --> 00:04:26,100 of the foundation of their building . 103 00:04:26,110 --> 00:04:29,150 Uh so the other five pillars sit on top 104 00:04:29,150 --> 00:04:31,810 of that so it's there uh it's just in 105 00:04:31,810 --> 00:04:35,130 how they're depicting it . Um it is of 106 00:04:35,130 --> 00:04:37,960 great importance because uh we want to 107 00:04:37,960 --> 00:04:40,360 log everything that's going on in the 108 00:04:40,370 --> 00:04:42,560 in the other five pillars . Uh we want 109 00:04:42,560 --> 00:04:44,782 to be able to do analytics over that as 110 00:04:44,782 --> 00:04:48,250 I discussed in my first answer to find 111 00:04:48,260 --> 00:04:51,550 anomalous behavior . Uh and again uh 112 00:04:51,560 --> 00:04:53,560 we've had lots of tools in the past 113 00:04:53,560 --> 00:04:56,960 where uh we see events in a sim 114 00:04:57,340 --> 00:05:00,990 um we didn't have sore to take an 115 00:05:00,990 --> 00:05:03,400 automatic response , we want to add 116 00:05:03,400 --> 00:05:06,300 that layer on to where we have a 117 00:05:06,310 --> 00:05:08,920 calculated orchestrated response to the 118 00:05:08,920 --> 00:05:11,380 threat uh and take the human out of the 119 00:05:11,380 --> 00:05:13,491 loop . We know that this action needs 120 00:05:13,491 --> 00:05:15,602 to be taken so go ahead and take it . 121 00:05:15,602 --> 00:05:19,150 Um so we also believe 122 00:05:19,160 --> 00:05:22,620 that the aggregate logs now the other 123 00:05:22,620 --> 00:05:24,842 five pillars are going to generate logs 124 00:05:24,842 --> 00:05:27,064 of their own for whatever the tools are 125 00:05:27,064 --> 00:05:29,287 that are being used and we believe that 126 00:05:29,740 --> 00:05:32,240 orchestration can occur within that 127 00:05:32,240 --> 00:05:34,930 tool . Automatic responses can occur 128 00:05:34,930 --> 00:05:36,930 there . But there's also this layer 129 00:05:36,930 --> 00:05:39,152 when you aggregate all of that data and 130 00:05:39,152 --> 00:05:41,590 you can start making connections of the 131 00:05:41,590 --> 00:05:43,757 data . You're seeing across all of the 132 00:05:43,757 --> 00:05:46,000 tools that you can do an orchestrated 133 00:05:46,000 --> 00:05:48,830 response there based on on all of the 134 00:05:48,830 --> 00:05:51,560 data from all of the sensors . So in 135 00:05:51,560 --> 00:05:54,170 essence uh we're both saying the same 136 00:05:54,170 --> 00:05:56,510 thing . Um I think both of us feel that 137 00:05:56,510 --> 00:05:58,454 it's important . We just made it a 138 00:05:58,454 --> 00:06:02,090 pillar and uh we want it not only uh to 139 00:06:02,090 --> 00:06:05,390 happen within a particular product line 140 00:06:05,390 --> 00:06:08,650 or uh defensive mechanism 141 00:06:08,940 --> 00:06:11,150 but we want to aggregate that and and 142 00:06:11,150 --> 00:06:13,770 be able to respond to things that sort 143 00:06:13,770 --> 00:06:15,770 of are connecting the dots for us . 144 00:06:15,770 --> 00:06:18,790 Okay . Yeah and I can see is with 145 00:06:18,790 --> 00:06:21,140 threats moving at machine speed now you 146 00:06:21,140 --> 00:06:23,251 know why the cross cutting capability 147 00:06:23,251 --> 00:06:25,307 of visibility in automation would be 148 00:06:25,307 --> 00:06:27,418 would be critical and we're seeing an 149 00:06:27,418 --> 00:06:29,529 ever changing I . T . Environment and 150 00:06:29,529 --> 00:06:31,696 Covid certainly accelerated it in some 151 00:06:31,696 --> 00:06:33,640 cases we're seeing the adoption of 152 00:06:33,640 --> 00:06:35,696 hybrid cloud , we're also seeing new 153 00:06:35,696 --> 00:06:37,807 network technology solutions five g . 154 00:06:37,807 --> 00:06:40,990 Private five G being similar one as 155 00:06:40,990 --> 00:06:43,157 well as the convergence of I . T . And 156 00:06:43,157 --> 00:06:45,379 O . T . How are you looking to industry 157 00:06:45,379 --> 00:06:47,490 to help assist you guys in addressing 158 00:06:47,490 --> 00:06:49,546 the complexities both now and in the 159 00:06:49,546 --> 00:06:51,670 future ? Well we always turn to 160 00:06:51,670 --> 00:06:55,350 industry for uh great solutions 161 00:06:55,360 --> 00:06:57,230 uh whether they're operational 162 00:06:57,230 --> 00:07:00,020 solutions uh with the new technologies 163 00:07:00,020 --> 00:07:02,310 that you're talking about five G uh 164 00:07:02,320 --> 00:07:05,850 cloud . Um We're also looking to them 165 00:07:05,860 --> 00:07:08,460 to one when they build a new 166 00:07:08,460 --> 00:07:10,770 operational technology kind of bake in 167 00:07:10,770 --> 00:07:13,030 cybersecurity and the censoring that 168 00:07:13,030 --> 00:07:15,086 we're going to need to protect those 169 00:07:15,086 --> 00:07:18,890 devices but going forward . 170 00:07:18,900 --> 00:07:22,570 Um I think we we also are 171 00:07:22,570 --> 00:07:25,090 looking at cybersecurity solutions that 172 00:07:25,090 --> 00:07:28,670 we could purchase at scale from vendors . 173 00:07:28,680 --> 00:07:31,620 Uh Many of them are components of zero 174 00:07:31,620 --> 00:07:34,430 Trust the five pillars . Uh So we're 175 00:07:34,440 --> 00:07:37,360 actively looking at where we can 176 00:07:37,440 --> 00:07:39,162 partner with industry on those 177 00:07:39,162 --> 00:07:41,660 solutions to overlay on top of whatever 178 00:07:41,660 --> 00:07:45,580 our network infrastructure is . Um S 179 00:07:45,580 --> 00:07:48,390 D win is being looked at as a way to 180 00:07:48,400 --> 00:07:51,710 segment the networks . Um So all of the 181 00:07:51,710 --> 00:07:53,710 things that that you mentioned , uh 182 00:07:53,710 --> 00:07:55,821 we're looking at and figuring out how 183 00:07:55,821 --> 00:07:58,500 we can employ them at scale and we do 184 00:07:58,500 --> 00:08:00,611 need to partner with industry so that 185 00:08:00,611 --> 00:08:02,389 they can help us provide better 186 00:08:02,389 --> 00:08:05,790 security solutions in the area of cloud . 187 00:08:05,790 --> 00:08:07,957 We've spent a great deal of time , our 188 00:08:07,957 --> 00:08:10,950 journey to the cloud has been Uh pretty 189 00:08:10,950 --> 00:08:14,940 strong of late . We've adopted 0365 . 190 00:08:14,950 --> 00:08:17,930 Um we've migrated a vast majority of 191 00:08:17,930 --> 00:08:19,930 our users there . We partnered with 192 00:08:19,930 --> 00:08:23,510 Microsoft um uh to work on the 193 00:08:23,510 --> 00:08:26,040 security concerns over time and we 194 00:08:26,040 --> 00:08:28,520 continue to to work on those . Uh There 195 00:08:28,520 --> 00:08:30,631 are other infrastructure as a service 196 00:08:30,631 --> 00:08:33,740 providers , a . W . S . Um that we've 197 00:08:33,740 --> 00:08:35,907 partnered with to and there are always 198 00:08:35,907 --> 00:08:38,850 good partners to help us sort through 199 00:08:38,860 --> 00:08:41,180 the security issues that we identify . 200 00:08:41,190 --> 00:08:43,230 Um and then they're even willing to 201 00:08:43,230 --> 00:08:45,430 allow our red teams to go in there and 202 00:08:45,440 --> 00:08:47,960 take a peek and uh whenever something 203 00:08:47,960 --> 00:08:49,940 is found that they're very good at 204 00:08:49,950 --> 00:08:53,070 helping us resolve those . So again 205 00:08:53,070 --> 00:08:54,990 we'll continue to adopt what what 206 00:08:54,990 --> 00:08:57,250 industry is putting out . Uh We do need 207 00:08:57,250 --> 00:08:59,120 that that helped to bake in 208 00:08:59,120 --> 00:09:02,270 cybersecurity not have it be uh an add 209 00:09:02,270 --> 00:09:04,980 on feature for a you know an additional 210 00:09:04,980 --> 00:09:07,091 price . But it would be great to have 211 00:09:07,091 --> 00:09:09,091 it baked in from the beginning with 212 00:09:09,091 --> 00:09:11,202 with all the logging and everything . 213 00:09:11,202 --> 00:09:13,313 Yeah . Yeah and we we see the similar 214 00:09:13,313 --> 00:09:15,369 challenge with cybersecurity being a 215 00:09:15,369 --> 00:09:17,313 bolt on um as well as your comment 216 00:09:17,313 --> 00:09:19,258 about functionality and capability 217 00:09:19,258 --> 00:09:21,369 taking precedence over cyber security 218 00:09:21,369 --> 00:09:23,591 and cyber security kind of coming after 219 00:09:23,591 --> 00:09:25,480 which kind of spills over in some 220 00:09:25,480 --> 00:09:27,536 industries for us like manufacturing 221 00:09:27,536 --> 00:09:29,758 and the manufacturing companies we work 222 00:09:29,758 --> 00:09:31,980 with but that also spills over into the 223 00:09:31,980 --> 00:09:33,813 D . O . D . Were in the areas of 224 00:09:33,813 --> 00:09:35,924 shipyards and others . So that brings 225 00:09:35,924 --> 00:09:38,147 up the question when you start thinking 226 00:09:38,147 --> 00:09:39,980 about combat systems and weapons 227 00:09:39,980 --> 00:09:42,147 systems I . T . Is usually not thought 228 00:09:42,147 --> 00:09:44,313 of . Right . And now we're starting to 229 00:09:44,313 --> 00:09:46,480 see in the budget that there's a focus 230 00:09:46,480 --> 00:09:48,536 on combat and weapon systems . We're 231 00:09:48,536 --> 00:09:50,369 starting to see uh in the budget 232 00:09:50,369 --> 00:09:52,591 there's a focus on modernization of the 233 00:09:52,591 --> 00:09:54,813 advanced warfighting network at the NTC 234 00:09:54,813 --> 00:09:56,647 three system . We're also seeing 235 00:09:56,647 --> 00:10:00,160 funding for uh the uh sensing 236 00:10:00,160 --> 00:10:02,382 grids . And so it's becoming clear that 237 00:10:02,382 --> 00:10:04,493 the duty is trying to network censors 238 00:10:04,493 --> 00:10:06,660 platforms and weapons . So how are you 239 00:10:06,660 --> 00:10:08,827 going to address those weapons systems 240 00:10:08,827 --> 00:10:10,910 and those mission initiatives ? Yeah 241 00:10:10,910 --> 00:10:12,750 we're hitting that on a lot of 242 00:10:12,760 --> 00:10:15,670 different fronts . Um Congress has been 243 00:10:15,680 --> 00:10:19,670 guiding us since 2016 to uh do 244 00:10:19,670 --> 00:10:21,503 weapons systems cyber vulnerable 245 00:10:21,503 --> 00:10:24,140 vulnerability assessments . Uh many of 246 00:10:24,140 --> 00:10:26,418 those have been done in the department . 247 00:10:26,418 --> 00:10:28,750 Additionally critical infrastructure uh 248 00:10:28,760 --> 00:10:32,560 in 2017 n . d . a . We were told to go 249 00:10:32,560 --> 00:10:35,540 look at critical infrastructure and uh 250 00:10:35,550 --> 00:10:37,850 we've looked at you know many many 251 00:10:37,860 --> 00:10:40,120 bases and critical infrastructure there 252 00:10:40,120 --> 00:10:42,800 to uh so we we've done a great deal of 253 00:10:42,800 --> 00:10:46,410 assessments . Uh There is also um a 254 00:10:46,420 --> 00:10:48,587 great partnership going on here in the 255 00:10:48,587 --> 00:10:50,142 D . O . D . Between all the 256 00:10:50,142 --> 00:10:53,230 stakeholders and ends N . S . A . The 257 00:10:53,230 --> 00:10:56,370 principal cyber Advisor , the C . I . O . 258 00:10:56,380 --> 00:11:00,250 I N . S . Um to uh 259 00:11:00,260 --> 00:11:02,371 and joint staff as well . Joint staff 260 00:11:02,371 --> 00:11:04,260 helps us prioritize based on the 261 00:11:04,260 --> 00:11:07,630 mission commanders uh priorities 262 00:11:07,640 --> 00:11:09,696 what systems we should be looking at 263 00:11:09,696 --> 00:11:11,600 first and then also help them 264 00:11:11,600 --> 00:11:14,400 prioritize uh whether or not they 265 00:11:14,400 --> 00:11:16,622 should be fixed or whether risks should 266 00:11:16,622 --> 00:11:18,678 be accepted . But we've got a really 267 00:11:18,678 --> 00:11:21,090 good process that we've teamed together 268 00:11:21,090 --> 00:11:24,600 to build . We've briefed the depth sec 269 00:11:24,600 --> 00:11:28,390 def on several occasions . Um There has 270 00:11:28,390 --> 00:11:31,460 been guidance that the services are to 271 00:11:31,470 --> 00:11:34,970 put dollars in their palms to 272 00:11:34,970 --> 00:11:37,026 perform vulnerability assessments on 273 00:11:37,026 --> 00:11:38,637 weapons systems and critical 274 00:11:38,637 --> 00:11:41,890 infrastructure . And also to remediate 275 00:11:41,890 --> 00:11:45,320 the findings . The remediation of the 276 00:11:45,320 --> 00:11:47,487 findings can be problematic at times . 277 00:11:48,240 --> 00:11:51,470 Many of these systems are sort of aged 278 00:11:51,480 --> 00:11:54,940 and replacing them is extremely costly 279 00:11:54,950 --> 00:11:57,460 and fixing some of them due to the fact 280 00:11:57,460 --> 00:11:59,682 that you know they may be space born or 281 00:11:59,682 --> 00:12:02,750 you know hard to get to um is also 282 00:12:02,750 --> 00:12:04,639 problematic but but we're working 283 00:12:04,639 --> 00:12:07,560 through that and I think um 284 00:12:08,240 --> 00:12:10,800 money is probably you know the key 285 00:12:10,800 --> 00:12:12,967 issue here . So we're going to have to 286 00:12:12,967 --> 00:12:15,330 make a risk based decisions and we're 287 00:12:15,330 --> 00:12:17,730 putting those risks based decisions in 288 00:12:17,740 --> 00:12:19,907 the hands of the senior leaders of the 289 00:12:19,907 --> 00:12:23,460 department . They are aware of where 290 00:12:23,460 --> 00:12:25,680 vulnerabilities exist and are actively 291 00:12:25,680 --> 00:12:28,130 helping to work through how we resolve 292 00:12:28,140 --> 00:12:30,810 those . Uh huh . So you mentioned 293 00:12:30,810 --> 00:12:32,810 critical infrastructure and we have 294 00:12:32,810 --> 00:12:35,032 Cisco obviously have a lot of customers 295 00:12:35,032 --> 00:12:37,270 in different industries and we see that 296 00:12:37,270 --> 00:12:39,326 they have critical infrastructure to 297 00:12:39,326 --> 00:12:41,492 support systems for their operations . 298 00:12:41,492 --> 00:12:43,381 So nontraditional I . T . Systems 299 00:12:43,381 --> 00:12:45,548 whether it's in the financial industry 300 00:12:45,548 --> 00:12:47,381 and massive amounts of financial 301 00:12:47,381 --> 00:12:49,548 transactions . We're seeing autonomous 302 00:12:49,548 --> 00:12:51,270 vehicles and the importance of 303 00:12:51,270 --> 00:12:53,548 cybersecurity certainly in those areas . 304 00:12:53,548 --> 00:12:55,610 Space the privatization of space and 305 00:12:55,610 --> 00:12:57,420 space launches . What are some 306 00:12:57,420 --> 00:12:59,642 industries that you guys are looking to 307 00:12:59,642 --> 00:13:02,980 um for best practices and and ideas to 308 00:13:02,980 --> 00:13:06,040 help really drive your adoption of zero 309 00:13:06,040 --> 00:13:08,151 trust and cybersecurity initiatives . 310 00:13:08,151 --> 00:13:10,340 Yeah , out of that list that you just 311 00:13:10,340 --> 00:13:13,210 described , I would say that , you know , 312 00:13:13,220 --> 00:13:15,053 historically we've looked at the 313 00:13:15,053 --> 00:13:17,890 financial community there kind of 314 00:13:17,890 --> 00:13:21,360 parallel the D O D and that they have a 315 00:13:21,740 --> 00:13:23,684 critical resource , you know , the 316 00:13:23,684 --> 00:13:25,907 finances that they're trying to protect 317 00:13:25,907 --> 00:13:28,129 and they come up with some really great 318 00:13:28,129 --> 00:13:32,040 technologies , excuse me . Um , but I 319 00:13:32,040 --> 00:13:34,262 can see all of the others that you have 320 00:13:34,262 --> 00:13:36,429 on the list , emerging . Uh , they are 321 00:13:36,429 --> 00:13:39,470 important to us . Um , I think we're 322 00:13:39,470 --> 00:13:43,070 behind um In how we 323 00:13:43,070 --> 00:13:45,660 secure uh many of those technologies 324 00:13:45,660 --> 00:13:48,300 that you're talking about , um whether 325 00:13:48,300 --> 00:13:51,350 it be ICSK two systems , um 326 00:13:51,920 --> 00:13:54,600 internet of things , operational 327 00:13:54,600 --> 00:13:58,150 technologies , historically , what we 328 00:13:58,150 --> 00:14:00,372 found through our analysis , you know , 329 00:14:00,372 --> 00:14:03,250 through various labs that we have , 330 00:14:03,820 --> 00:14:06,300 there's not a lot of security built 331 00:14:06,300 --> 00:14:09,530 into to some of those devices and and 332 00:14:09,530 --> 00:14:11,697 in order for us to use them in the way 333 00:14:11,697 --> 00:14:13,919 that we want to use them . We need that 334 00:14:13,919 --> 00:14:15,641 cybersecurity built in , so we 335 00:14:15,641 --> 00:14:17,752 definitely want to partner with those 336 00:14:17,752 --> 00:14:19,752 other industries that you mentioned 337 00:14:19,752 --> 00:14:23,460 going over time . Um but uh 338 00:14:23,840 --> 00:14:27,280 yeah , finance was was definitely the 339 00:14:27,280 --> 00:14:29,440 one that I would point to the most , 340 00:14:29,450 --> 00:14:31,530 but the others , we we we definitely 341 00:14:31,530 --> 00:14:33,641 need to partner with them and every , 342 00:14:33,641 --> 00:14:35,752 every one of the industries out there 343 00:14:35,752 --> 00:14:37,863 has something to offer , I believe to 344 00:14:37,863 --> 00:14:39,752 us uh if we're paying attention . 345 00:14:39,752 --> 00:14:42,130 Absolutely . So Dave you covered a lot 346 00:14:42,130 --> 00:14:44,352 of ground today , you've given us great 347 00:14:44,352 --> 00:14:46,130 insights into some of the cyber 348 00:14:46,130 --> 00:14:48,352 security challenges , the duties facing 349 00:14:48,352 --> 00:14:50,519 and some of your key initiatives . Are 350 00:14:50,519 --> 00:14:50,260 there any last thoughts you want to 351 00:14:50,260 --> 00:14:53,860 leave ? Uh leave us with today ? Um 352 00:14:54,540 --> 00:14:56,207 First of all , thanks for the 353 00:14:56,207 --> 00:14:58,050 opportunity to speak today . Um 354 00:14:58,060 --> 00:15:00,970 obviously Zero Trust is near and dear 355 00:15:00,970 --> 00:15:03,640 to my heart as a former defender . I 356 00:15:03,650 --> 00:15:06,320 wanna be able to combat these 357 00:15:06,320 --> 00:15:08,640 adversaries that are hacking our 358 00:15:08,640 --> 00:15:11,110 networks and do so in a real time 359 00:15:11,110 --> 00:15:13,940 manner . Um you know , the strategic 360 00:15:13,940 --> 00:15:15,662 cyber security program which I 361 00:15:15,662 --> 00:15:18,600 mentioned is also vital to our nation's 362 00:15:18,610 --> 00:15:21,670 uh ability to deliver a defensive 363 00:15:21,670 --> 00:15:24,890 posture and offensive if needed . Um 364 00:15:24,900 --> 00:15:27,230 We're really getting after that uh in a 365 00:15:27,230 --> 00:15:31,170 strong way . Um adoption of all of 366 00:15:31,170 --> 00:15:32,948 the different technologies that 367 00:15:32,948 --> 00:15:35,114 industry has to offer is definitely on 368 00:15:35,114 --> 00:15:37,114 our radar . We We want to meet with 369 00:15:37,114 --> 00:15:39,170 industry , we want to know what they 370 00:15:39,170 --> 00:15:41,390 have but we do want them to be uh 371 00:15:41,400 --> 00:15:44,270 cognizant of the fact that we we we 372 00:15:44,270 --> 00:15:46,890 really kind of demand a secure solution 373 00:15:46,890 --> 00:15:49,160 coming in the door . Uh and I think 374 00:15:49,160 --> 00:15:52,440 from the executive order 14 0-8 that 375 00:15:52,440 --> 00:15:55,460 came out earlier this year . uh there 376 00:15:55,460 --> 00:15:58,560 is a drive to at the federal level two , 377 00:15:59,140 --> 00:16:02,850 maybe up the game uh for industry . 378 00:16:02,860 --> 00:16:05,560 Um and we're also working on the 379 00:16:05,560 --> 00:16:07,560 capability maturity model for cyber 380 00:16:07,560 --> 00:16:10,550 security uh which uh you know , we we 381 00:16:10,550 --> 00:16:12,717 put on pause , we're making some edits 382 00:16:12,717 --> 00:16:15,990 right now , too . Um Streamline that 383 00:16:15,990 --> 00:16:18,157 make it more efficient and effective . 384 00:16:18,157 --> 00:16:20,323 But that's another key initiative that 385 00:16:20,323 --> 00:16:22,323 we're working with industry to make 386 00:16:22,323 --> 00:16:24,170 sure that D . O . D . Data is uh 387 00:16:24,180 --> 00:16:26,870 protected when in the hands of industry 388 00:16:26,870 --> 00:16:29,920 partners . So , um I appreciate the 389 00:16:29,920 --> 00:16:31,698 partnership and look forward to 390 00:16:31,698 --> 00:16:33,950 continuing the dialogue with industry . 391 00:16:33,960 --> 00:16:36,030 And uh I think that's all I have . 392 00:16:36,040 --> 00:16:38,151 Thank you . Thank you . Thank you for 393 00:16:38,151 --> 00:16:39,150 your time today . Yeah .