Cyber Strategy

September 16, 2026

Watch the Video




Read the Transcript


Brig. Gen. Greg Touhill, USAF (Ret.):

Good morning, everybody. Oh, come on, that’s pretty lame. Good morning. Happy Wednesday. Boy, you guys, didn’t you get enough caffeine out there? You know, gee whiz. Hi, everybody. I’m Greg Touhill. I’m going to be our moderator today, and it’s an honor for me to be here with you and our esteemed panel.

Just as a scene setter, introducing myself, I’m a retired Air Force Brigadier General, as you can see there. It’s just coincidence that I’m wearing the same tie in my photo that was displayed. But today is Purple Day, because we are all part of the Joint Force, and I’m an Airman, but I’m also somebody who wears not only the Master Cyberspace Wings when I put on my uniform, but also the Master Space Wings. I’ve been honored to command two squadrons, a group, a wing.

I’ve been a base commander. I’ve been a COCOM J6. I’ve been a MAJCOM A6. I’ve been a C6 in the coalition environment. I’ve also had the honor to serve the country as the Deputy Assistant Secretary of Homeland Security, running what is now known as CISA, and I concluded my federal career appointed by the President as the first Chief Information Security Officer of the United States Government.

Even more honored now to continue my service, I’m the Director of CERT at Carnegie Mellon University’s Software Engineering Institute, which is the Department of War’s Applied Research and Development Center for all things cyber, software, and AI. So that’s why I got tagged by AFA to moderate this panel.

But the real stars of the show today are these two ladies who are distinguished leaders in the cyber domain. And first I’d like to introduce the Honorable Katie Sutton. Ms. Sutton is the Principal Cyber Advisor to the Secretary of War for Cyber. And then further, she’s the Assistant Secretary of War with Cyber Policy as her domain, representing us all before the Secretary of War, but also integrating cyber effects and cyber impact, cyber assessments, the whole shoot and match. She sets the policy for across not only the Department of War, but the influence the Department of War has throughout the national security establishment. Is that a good introduction?

Katherine “Katie” E. Sutton:

It’s a great introduction.

Brig. Gen. Greg Touhill, USAF (Ret.):

But it’s not complete. Her background, she’s the real deal. Degrees in engineering from the University of Illinois and Stanford. She’s served in FFRDC’s, Federally Funded Research and Development Center at Sandia. She’s been in industry. She’s served in Cyber Command. She’s served on Capitol Hill as a professional staffer. This is a lady who’s the real deal and knows our business inside and out.

I’d also like to introduce Dr. Wanda Jones-Heath, whom I’ve known for a long, long, long time. We served together at the turn of the century. She’s been in the cyber business from day one. And a model career civil servant who’s served virtually in every civilian capacity in the cyber domain. True hero behind the scenes, but also front and center. Leading today’s efforts as the principal cyber advisor to our Secretary of the Air Force. Helping establish cyber policy in congruence with the Department of War. But also, making sure that our workforce is as strong and capable as it can be. Wanda, is that an accurate representation?

Dr. Wanda T. Jones-Heath:

Absolutely, thank you.

Brig. Gen. Greg Touhill, USAF (Ret.):

OK, thanks. Now I’m going to- I’ve got a couple of questions here that we’re going to- hopefully, we’ve anticipated all the different issues that you’d like us to address in the short period of time. But if we didn’t, we’ll be mingling around here afterwards. But we’re going to start the questions with- for years, we’ve viewed cyber as a support function. How has the threat landscape changed? And why is cyber now a key enabler of all domain operations? Ms. Sutton?

Katherine “Katie” E. Sutton:

So first of all, I just wanted to really thank AFA for the opportunity to have us here on the panel. Greg, thanks for moderating and setting the stage of I think what are going to be some really good discussion points and a lot of things that I spend pretty much my entire job in the Pentagon. A lot of words in my title- Assistant Secretary of War for Cyber Policy and the Principal Cyber Advisor to the Secretary of War. I really think of it more as just the funnest job in the Pentagon right now. So when you look at even the title of the conference we’re at today, Airspace Cyber, is really that recognition of the fact that cyber has fully evolved into its own domain of warfighting. Cyber is no longer a back office IT function.

Everyone in this room here understands how it is really integral to how we’re going to fight and win our nation’s conflicts and wars going forward. As we have watched the threat evolve, we were having a discussion backstage before this about some of the experiences he had had when he was in the federal government, for example, responding to the OPM breach. And I think if you look back to that and compare it to where we’re at today is a really good indication of how much the threat has evolved.

Our adversaries, not only have they increased in the scope, the scale, and the sophistication of their attacks, but we’ve moved a long way from the days where cyber was just used as an espionage tool and now is fully integrated into conflict, into achieving a strategic advantage, and our adversaries really leveraging it as a way that they’re going to achieve their national objectives going forward.

From the Department of War perspective, we also are looking at that evolution and how cyber is no longer an enabler, but it actually is a warfighting tool in and of itself. Our most recent operations, Absolute Resolve and Epic Fury, showed how capable our force can be when we integrate cyber into our joint force planning from the beginning and provide our warfighters, as they’re going into harm’s way, with the cyber support that they need to make sure that they have that command and control and information advantage to really be successful and bring home our forces safely.

So as we look at where we’re going in the domain, shaped by our adversaries, we have really evolved our posture and are looking forward to continuing to go down that journey and integrate in as we go forward in this domain.

Brig. Gen. Greg Touhill, USAF (Ret.):

Thank you. Wanda, anything to add on that?

Dr. Wanda T. Jones-Heath:

I certainly agree with Honorable Sutton. We are here, right? Cyber domain is in the conversations everywhere we go. We’re at the table. We’re being asked to deliver capabilities, and we’re doing just that. Our mindset is changing that we’re not the afterthought. We are allowed to have the conversation up front. Part of the joint planning is, where is cyber? What capabilities can we bring to the table up front, fast, so that the warfighter can have that advantage going into the war?

Brig. Gen. Greg Touhill, USAF (Ret.):

Well, as we take a look to the future, there’s some efforts ongoing right now. And one of the more important ones is Cyber Command 2.0. Ms. Sutton, could you give us a rundown as to our efforts with Cyber Command 2.0, and how we’re doing our recruitment, and training, and making sure that we have that cyber capability in the workforce, the human element? I like to call that the wetware that complements and controls the hardware and the software. Where do we stand on that?

Katherine “Katie” E. Sutton:

Great way of phrasing that. And as many people in this room know or have seen, Cyber Command 2.0 is something that has been a top priority for our office and for the department. We’re really excited to have the secretary put out a message about it recently. It’s something that he’s been tracking and is really very enthusiastic about. As we built our cyber mission force and our cyber warriors throughout the department, we’ve leveraged historically traditional force generation model methods of how we build our force.

And while that’s been successful in getting a generalist population, we haven’t been able to really build and cultivate at the scale that we need and the speed that we need it, the deep technical skills, mastery, and specialization that we really need to be successful in this domain. So what Cyber Command 2.0 has done is to look across the entire talent management process and look at what we need to do and how we need to develop unique processes and unique pathways to make sure that we can build the cyber warriors that we need, not only to be successful in today’s fight, but in the future.

So to use an analogy that’s going to resonate really well in this room, the way we work today is we have cyber operators. That would be like saying we have cyber pilots. Imagine if I said to a pilot in the US Air Force that you’re a pilot, and therefore I expect you to be able to go and fly at any day anything that goes in the air. Might be a helicopter, might be a fighter plane, might be a bomber, might be a UAV. That’s not how we structure our pilots force. We really shouldn’t be doing the same thing for cyber operators. Instead, we’re looking more at a model like in the Air Force, a PJ, a para-rescueman, where they have an opportunity to build deep skills. They build combat medical skills. They build insertion skills. They build special operations skills. And we allow them to cultivate those skills, grow in their depth, grow in their mastery throughout their career.

And that’s really what we’re doing with Cyber Command 2.0, is putting together a purpose-built system that will allow us to foster those unique skills and allow those skills to keep up with the pace of the domain. In that plan, we’ve come up with seven primary attributes, we call them. Basically, seven lines of effort with about 97 tasks. So we’re really looking at the entire plan. I just wanted to highlight for this community a few of those today. One of them is looking at how we bring people into our force. So we will be driving some larger pilots about how we do in-service accession to look at people who have the right skills but might not have been initially brought in as a cyber career field. So how can we make it easier to recruit within the service as well as from outside the service to have opportunities for people who have those innate skills or perhaps code at home on weekends or have had a lot of experience working with AI to be able to bring them in and to transition them into our cyber community?

To do that, we’re developing a cyber assessment battery, a suite of assessments to really judge our cognitive skills, to make sure that we have the problem-solving skills, the ability to handle hard decisions. You know, one of the most important things I heard recently from a former operator in our field of our operators is not just what they need to do, but how, as they’re navigating through cyberspace, understanding what they shouldn’t do.

So how we have people who have those decision-making skills already built into them, we’re feeding all those into a comprehensive cyber assessment battery that will be standard across all of our services to be able to make sure we have the right talent coming in and also match them to the appropriate work roles since there is a variety of skills necessary to be successful in the cyber domain. Then we’re looking at how we can, sort of a simple term, how do we keep our hands on keyboard for our career? What sort of assignment management do we need to do to make sure that we can reward and promote people who are dedicated to building those skills and keeping them on mission? Because in the cyber domain, coming off mission for even one assignment can make it very difficult to get back in given how fast this domain moves and how continuously our skills need to evolve. So we’re building out across all of the services a talent management process, an assignment management process that will allow us to deliberately build those technical skills as we’re continuing to allow people to progress and to stay technical as they move forward for their promotion path. And then one of the things that I’m most excited about is our Cyber Mastery Incentive Pay. So how can we actually reward the top talent that have spent years, even decades, honing deep technical skills?

And so we have the Undersecretary for Personnel and Readiness has approved the framework and the Cyber Mastery Incentive Pay structure that we will be rolling out very imminently where we’re gonna reward our top talent who have spent the time, have put in the hours, have demonstrated the experience and done the operations to build those deep skills. This is not a situation where everybody’s gonna get, in cyber, gets a bonus. It’s not meant to be a retention tool. It’s not meant to change our pay. It’s meant to reward those who have built the skills that we want. So, you know, this is not an Oprah moment where you get a bonus and you get a bonus and you get a bonus. It’s really the structure of this framework is to reward those who have moved to our top tier operators. And when we reward them, we are gonna reward them significantly at the maximum allowed by law to allow for people to get recognized for that deep expertise and mastery that they’ve built. So we’re really looking forward to kind of pulling all these initiatives together. They’re all intertwined. We run into a lot of chicken and the egg problems of well, we need to do this and we need to do that.

So we’re just doing them all together. We’re doing not an incremental approach to how we do talent management. We’re renovating and basically tearing down the house and building up the whole new first generation model all at once and looking forward to being able to really reward and support our cyber warriors that are very motivated to contributing to this mission going forward.

Brig. Gen. Greg Touhill, USAF (Ret.):

Thank you, ma’am and Dr. Wanda, you’ve been a leader in looking beyond just the IT but looking across the cyber domain with the lens of mission assurance. Following on the Honorable Sutton’s introduction, how are you operationalizing cyber resilience so that we can take that cyber punch and execute the mission?

Dr. Wanda T. Jones-Heath:

Yes, thank you for that. We often spend a lot of time talking about IT, right? We’ve invested in the people, we’ve invested in tools, totally focused on IT. If you look at the OT piece of it, now we’re coming forward and saying that our defense critical infrastructure is just as important. It doesn’t fit the normal model of standardization of tools. So we have to recognize where those tools work and where those tools do not work. And so the workforce piece of that, although Cybercom 2.0 is a great program and we support it 100%, we’re all in, the OT piece of it is another priority that I’m focusing on with our Crocs organization, being able to have that organization be the front door to everything we do for DCI and OT. We’re investing in it, we’re looking at our workforce, we’ve also been the lead for DOW in identifying those subject matter experts and the skills needed in our cyber workforce code that has been on the docket and will be released soon. Secondly, how do we take advantage of understanding the visibility needed in our DCI?

I talked about earlier of the partnerships and what we need to understand is what is the associated DCI attached to every mission set? We’re getting there and so we’re not there yet, but I am certainly pleased with the efforts that we’re doing so far. More to come on that.

Brig. Gen. Greg Touhill, USAF (Ret.):

Good deal. Well, I tell you, we’ve delayed the talk about the dreaded two-letter acronym, but just quick Jeopardy moment. Anybody in the audience know when the first AI, the artificial intelligence system was produced? Anybody, anybody? Jeopardy moment here. 1972 at Carnegie Mellon University. That was the first AI and AI is an overnight sensation, 70 years in the making. As we take a look at, yeah, you didn’t know that, did you? 1972, not many people do, but now you do when you’re ready for Ken Jennings. As you go take a look at AI, I think it’s mislabeled. It should have been labeled augmented intelligence. It should augment the human. And I think as we look forward across the department in our mission sets, it’s important to recognize that AI has significant effects on cyber for AI, AI for cyber, but also cyber with AI.

So we’re gonna start with Wanda this time and then come to Ms. Sutton. So Wanda, as the Department of the Air Force adopts AI, how is AI security different from traditional cyber security and how will the Department of War and the Department of Air Force leverage AI to defend America and defeat our adversaries?

Dr. Wanda T. Jones-Heath:

You know, lots of conversation on AI and if you’re watching the news, there’s a lot of conversation about how do we actually protect ourselves from AI in some cases, right? And so, you know, you’re listening to how AI can be augmentative to our workforce. We have the most talented workforce, but data, data, data is really an issue of how do we identify those patterns really quickly and then make the right decisions. And so the intersection of AI and cybersecurity, you know, from a defense perspective is something that we have to do. We have to understand what tools within the AI suite do our operators need, and then be able to integrate those quickly, understand we need the policy, the governance around how we integrate that into our SOCs. And, you know, we have to invest in the training of that at every level, but specifically for our operators. They need the advantage. And I think AI will give us that.

Brig. Gen. Greg Touhill, USAF (Ret.):

Yeah, thank you so much. I would contend that every military member now is a cyber operator because they can’t do their job without touching cyber and cyber touching them. Ms. Sutton, same question to you. What is your view on the topic of where we’re going here and how is AI and cyber and cyber operations all melting together in the department?

Katherine “Katie” E. Sutton:

Great question. So I’ll start off with a quick personal fun fact. I may not have known that the first model was in the ’70s. I actually would have guessed earlier than that because I recently found in helping my parents clean out my old childhood room that actually in middle school, I wrote a paper on artificial intelligence. So artificial intelligence is not a new concept and it’s not something new for our cyber workforce. Although it’s become, it’s hit the press in the last year or so very aggressively, it’s actually something that the command and many of our team have been working on, developing cyber roadmaps, cyber task, there’s been an AI task force at the command for many years.

We’ve been experimenting with AI, including it in operations for a long time. What’s changing now is just how much faster it’s going and how we no longer have the luxury of waiting every few years for an update on something. Since May, I think most of the frontier models are on like their third release each. That’s a very different cadence than we know how to operate. As we look at how cyber is gonna be used, it’s, I think a lot about the OODA loop. And as Wanda mentioned, data is gonna be fundamental to our, how we operate. And in the cyber domain, everything is based on data. We’re an inherently digital domain. Everything is zeros and ones. So being able to analyze that at a speed that humans just can’t possibly do is gonna be essential. AI is gonna be necessary for us to be able to identify in real time threats on our network, identify those vulnerabilities, identify where there’s abnormalities, and then be able to mitigate those at speeds that just aren’t gonna be practical for a human to be able to respond.

One of the things though I’d like to pivot a little bit to that we think about a lot from in the policy world is how do we need to think about that from a policy perspective and most importantly from a security perspective. So from a policy perspective, there’s been a lot of talk about agentic AI. And I think many people immediately go to agentic AI means we’re gonna have some bot on our network that’s gonna run around, we’re gonna set it off and just hope for the best. And I think that’s a little bit of a misnomer. AI is really gonna be a fundamental tool that our forces use, but ultimately it’s just a tool. And as I highlighted so much in the previous discussion about Cyber Command 2.0, it still goes back to our people and having the best trained and most capable people to operate those tools.

Our whole system of the military is based on authorities and accountability. And nothing about AI is gonna change that. We still are gonna have delegation of authorities to perform functions within our military and then hold those people that the authority is delegated down to responsible. We are still gonna be having our human operators responsible for their AI tools that they’re using. And so that’s one of the areas we look at for adoption. The other thing that is really important and we really need to take some of the lessons learned we had about cyber and put them forward to AI is that we can’t think about security of our AI systems as an afterthought.

We have to think about it from what we need to do to secure the systems upfront. We’ve sort of been chasing behind the ball with cybersecurity for the last few decades. And with AI, we just are not gonna have the opportunity to do that. When we think about securing AI, it’s not just simply securing the networks that these tools run on, that is required. But we also need to think about the unique vulnerabilities and the unique attack surfaces that AI will present.

So for example, as we think about adopting AI to use in mission planning, to use in controlling satellites, however, you know, weather planning, all of the things that are fundamentally talked about here at AFA, we need to think about what would happen if someone was able to poison the data and be able to change a different outcome in a tool that you’re relying on. Those are the types of threats that we really need to start thinking about how we protect against upfront.

We wouldn’t think about deploying an aircraft without verifying its flight control software before it leaves. We similarly wouldn’t put someone on a plane in harm’s way with a parachute without doing an inspection on that parachute. We have to adopt that same culture of how we deploy AI. And just like those examples I give, the verifications were very different from each other. We need to really understand what specifically needs to be done so that AI can be secure and that AI can be resilient as we can intend to use it in contested environments going forward.

Brig. Gen. Greg Touhill, USAF (Ret.):

Well, you know, as the director of the lab that’s doing that research and development to answer some of those questions, I’ll share with our audience a couple of data points from what we’re learning from the academic and research side of the house. You know, seven years ago, the life cycle for a new generation of cyber technology was about a three-year development cycle, three years to develop new capabilities. Now it’s about 6.2 months and it’s accelerating. So as we take a look at how we are looking at developing capabilities, but also the forward vision that sets the table for our policy and making sure that we maintain dominance in the cyber battlefield as well as any battlefield that the nation calls us to engage in. The time is so precious. And we heard the chairman earlier today talk about time being one of the most precious factors in making decisions and being able to see, sense, decide, act.

As we look at how do we maintain that vision in a rapidly changing environment, that’s gotta be a really daunting challenge for you, Ms. Sutton, as well as across the department. And what’s your vision for what we need to do in the future to maintain that cyber dominance that our war fighters need?

Katherine “Katie” E. Sutton:

As I came into this role almost a year ago, one of my biggest challenges was to try to figure out what the biggest changes we needed to do in the department. And we’re at a pivotal moment in the cyber domain where our adversaries are evolving rapidly, technology is changing very quickly. The comment about time that General Kane made is so important because we have to prioritize what we wanna focus on in the cyber domain going forward. We also have built up a lot of operational experience where we understand where things are going in this domain. But just like it took many years for us to understand the war that, or the role that aircraft would play in conflict and it’s still evolving, the cyber domain and understanding how we’re gonna contribute to warfare going forward is also evolving. The difference is instead of evolving over several decades, we’re gonna have to evolve over a much shorter amount of time. So I’ve come in and set one north star for my organization and for the department. And that is that we have to develop a more robust set of capabilities for the president and the secretary. Very simple vision, but we need to bring, we need to really set forth what tools are gonna be available for our leaders to use and we need to give them more options.

To do that, we’re focusing on three main areas. First, as I mentioned earlier, how do we integrate cyber into all domains? The last decade or so, we’ve primarily focused on cyber as a tool to combat other cyber malicious actors and not on how we can leverage cyber as a strategic advantage to make sure that as data and information and command and control becomes increasingly important in future warfare, how do we make sure that we’re dominating that information and environment, making sure that we protect and have access to our ability to do those things and deny our adversary the ability to do that when we are at a time and place of our choosing.

The second major area that we’re driving very significant change is how we think about cyber as a unique tool of national power. Cyber, for those of you that have been involved in the cyber domain, is not best suited to be a one-for-one replacement for a kinetic capability. However, it brings very unique capabilities for our leaders to have additional options that they can use below the level of armed conflict to have a strategic advantage and accomplish their goals. And to do that, we need to make sure that we’re setting strategic objectives and looking at where cyber can have that strategic outcome and not just a tactical result. To do that, we’re gonna have to shed some of the risk aversion that we’ve had in this space and really look at using this as a tool rather than building a tool that we look at and think about and talk about, maybe in closed spaces. But how do we shed some of that risk aversion and really provide options for our leaders? It was a tremendous step forward and I was so proud that the day after Operation Absolute Resolve, the chairman came out and was briefing the operations and he talked about what was done in the air domain, what was done in the land domain, and yes, cyber was a part of those effects. Huge step forward in how we think about using these tools.

And then, so how do we move forward where cyber’s no longer measured by how many mission packages we did or how many operations, but what was achieved for our joint force, whether it be integrated with other kinetics and non-kinetics or as a standalone tool for our leaders to use? That’s really what cyber’s gonna bring to the fight going forward and we need to build that in. And then, the final priority is something that we talk about a lot is organized to dominate. As I mentioned earlier, the strength of our cyber power and the strength of us having a decisive advantage over all of our cyber adversaries going forward is not the tools and platforms that we build, although those are incredibly important, but it’s our people and our cyber warriors.

And so, how do we build the force that is structured, that has the people and is structured for the fight and how we fight in cyber? We’ve learned a lot since Cyber Command was first stood up, since we first architected the Cyber Mission Force. And so, how do we take those lessons learned and really build the force into the organization that it needs to be? The first pillar of that, as I mentioned, was Cyber Command 2.0, getting after the force generation, but we also need to look at how we design and how we employ that force. We need a force that’s gonna be agile, that’s gonna be able to bring the best athletes, both from across our force, perhaps from our allies and partners, or perhaps from our interagency partners.

How do we bring all of our authorities together to leverage that collective cyber power to be able to achieve the advantages we need? To do all of that, we’re moving very quickly at how we need to drive change in the department, and really excited to be able to lead that and bring all of you along with us over the next few years.

Brig. Gen. Greg Touhill, USAF (Ret.):

Thank you. Dr. Wanda, same question to you.

Dr. Wanda T. Jones-Heath:

Okay, great. So, Honorable Sutton talked about risk aversion, right? We have got to get over the fact that we’ve always done something the same way every time. This domain and the adversary is really pushing the envelope. We have to be more flexible. We have to be more understanding that what we did yesterday may not work for tomorrow. So, I would say that from a partnership with Honorable Sutton and her team, CyberCom has really given us an opportunity to change the story so that at the end of that journey that we have the advantage. And the Department of Air Force is really excited about that using CyberCom 2.0 initiatives to provide what we need for our cyber workforce.

Brig. Gen. Greg Touhill, USAF (Ret.):

Thank you. Now, ladies, we’re getting close to final approach here. But I think it’s really important since we have a lot of folks from industry that are in the audience. I’d like your views as far as what’s your wishlist from the industry partners here on how they can better support the department’s mission, our Guardians, our Airmen that are here in the audience, as well as our joint and coalition partners that are here as well. And Dr. Wanda, I’d like to start with you.

Dr. Wanda T. Jones-Heath:

Okay. So, this is a team effort and understanding that our partnerships are very important with industry. We don’t have all the answers, but together we can come up with solutions. But I would caution you that solution must fix the problem. Don’t bring me a rock. Don’t bring me a new rock, a old rock. But understanding where we are and where we’re trying to go, eventually we will have a great DOW, OSW cyber strategy. The Department of Air Force is also working at a cyber strategy. But what we do have is the National Cyber Strategy, and it is a great roadmap to kind of lead us to what you will see within the Department of Air Force.

Katherine “Katie” E. Sutton:

As Wanda mentioned, National Cyber Strategy is very clear about how we need to be much more aggressive in leveraging industry. The National Defense Strategy has the fourth pillar of supercharging the defense industrial base. There is no place that that is more important than cyber. And as we look at how we’ve partnered with industry in the past, we have got to change how we do business. Our traditional model of working with industry is a late to need acquisition model for bringing us tools. It’s threat information sharing. It’s bolting cybersecurity on after the fact. What we really need to think about and how I view partnerships with industry and have spent quite a bit of time in my role engaging with industry, looking at how we can do better with that, how we can leverage what they bring, is we have to move from a contractual relationship to an operational partner.

We are jointly responsible for the success of our forces and our missions going forward. From an industry perspective to break that down and if I had a wishlist of what you could do, well, you go downstairs and there are a tremendous number of capabilities that we’re bringing to bear for our Airmen and Guardians. How do we make sure that those are secure by design, that we’ve thought about security upfront, the way we think about safety and reliability and other type of functions? How do we ensure that we have a secure supply chain, that we know what we’re buying and that there aren’t any inherent vulnerabilities in that? And then how do we make sure that we can get that, that we are continually learning from that? We talk a lot about frontier AI and how it’s gonna impact cybersecurity, but one of the narratives that’s not talked about nearly enough is the tremendous benefit that it’s bringing forward.

Frontier models are based on large language, are large language models. When you break that down, it means they’re really good at doing things with languages. One of the most predictable languages is software, and that’s why it’s so good at identifying vulnerabilities of software. So one of my charges to industry is we should be leveraging those models to be from the beginning of your software development, to build the most secure codes that we don’t have to spend years patching vulnerabilities as they come out, but that we’re truly leveraging these really powerful tools to build that secure software from the beginning.

And then my other challenge to industry is your, as I mentioned, cyber is a digital domain inherently. It is manmade. This, our industry is the one that builds our digital battlefield that we fight on. We need to work together on how we leverage all of our authorities and all of our capabilities to provide us the best advantage on that battlefield going forward, so that we make sure that we have not networks and platforms that are vulnerable to our adversaries, but our hostile terrain that we can make, that we can impose costs on our adversary. So really looking forward to that opportunity to partner with industry more going forward.

Brig. Gen. Greg Touhill, USAF (Ret.):

And thanks for the plug on the software. From a department standpoint, my organization is Software Engineering Institute. One of the things we do is we work with industry, so you can come to us and we can help make sure that your software is secure by design, you’ve got the best practices in place, and we can work with you to make sure that your software, your cyber, your AI capabilities are built to take that cyber punch and keep on going on behalf of our Soldiers, Sailors, Airmen, Marines, and Guardians, and even the coasties as well.

Dr. Wanda, same thing. You know, as a professor at Carnegie Mellon, I always like to make sure that my students leave with homework assignments. What’s the homework assignment that you’d give industry and our audience members?

Dr. Wanda T. Jones-Heath:

We have to start now. We are behind. Our adversary is watching, they’re waiting, and they’re ready to execute. We have to be able to do the same, but faster. Our people are our most important resource. We have to take care of them, not just from a training perspective, but how do we take care of them to make sure that they are taken care of to do the mission? We ask a lot of them. We should do the same for them.

Brig. Gen. Greg Touhill, USAF (Ret.):

Well, ladies and gentlemen, once again, I’d like to thank Assistant Secretary Katie Sutton here for your continued leadership and breaking out from a very busy schedule that’s not only looking to the future, but busy with the operations of today in the department. Same, Dr. Wanda Jones-Heath, Principal Cyber Advisor to the Department of Air Force, thanks for your service to our Guardians, our Airmen, as well as the Joint Force, and doing what you do to make the digital world a safer, more secure, and trustworthy place that enables the missions of everybody here in the room. So once again, thank you very much, and thanks to our audience for attending today’s discussion. We look forward to continuing conversation with you.