Cyber Resilience and Mission Assurance

September 16, 2026

Watch the Video




Read the Transcript


Dr. Wanda T. Jones-Heath:

Good morning, good morning. I am Dr. Wanda Jones-Heath. I am the Department of Air Force Principal Cyber Advisor and will serve as your moderator. I am joined by a distinguished panel of leaders, both in industry and federal government. I’ll start with introducing Lieutenant General (retired) Chris Wegemann. He is a strategic advisor at Deloitte Cyber Strategy and Transformation where he advises national security clients on cyber resilience, mission assurance, and all-domain integration. A retired Air Force Lieutenant General with 34 years of distinguished service, he spent 25 years as a combat-proven F-16 pilot with four combat tours. He is the founding architect of U.S. Cyber Comm Cyber Mission Forces and the DoD’s first Information Warfare Numbered Air Force, 16th Air Force, and previously commanded Air Forces Cyber and Joint Force Headquarters Cyber Air Force.

Next up is Dan Waddell. He is a partner at IBM Federal Cyber Security Service Line where he leads the growth strategy for post-quantum computing, PQC, and IBM’s Quantum Safe solution to address the PQC threat. He brings over 30 years of IT and cyber experience with a primary focus on supporting and securing U.S. federal government missions.

Next up, we have Ms. Candice Frost, who is the Vice President of Mission Engagement for High Consequence Missions at Parsons. Driving the delivery of Avant Cyber, IT and Intelligence Solutions, a retired Army colonel with 25 years of distinguished service, she is a combat decorated veteran and previously commanded the Joint Intelligence Operations Center at CyberCom. She also serves as an adjunct professor in Georgetown’s University Security Studies Program and is the Vice Chair of the INSA Cyber Council.

Lastly, we have Dan Feller, is the Vice President of Space and Embedded Cryptographic Solution at General Dynamics Mission Systems, where he leads strategy execution for securing critical data across all warfighting domains. With over two decades of experience in the U.S. government aerospace and defense mission, his expertise spans satellite technology, embedded cyber cryptographic and spacecraft systems engineering. Dan previously held key leadership roles at Millennium Space Systems and the Boeing Satellite Development Center.

Now that we have all those formalities out of the way, today we will explore ongoing efforts to build cyber resilience and guarantee mission assurance in an era of increasingly contested gray zone environment. Our panel of experts will discuss and debate how do we best strengthen our cyber resilience to ensure critical networks, weapon systems and enterprise can operate through attack and continue generating combat power. How can we continue, take that punch and keep going?

I’ll kick off with the first question over to you, Chris Weggeman. We know our adversaries are mapping our bases. That’s no secret. Specifically, physical utilities, power generation, flight line infrastructure is a target-rich environment that can halt sortie generations before an aircraft can even leave the ground. Given our limited budget, how do we practically weigh cyber risk of an unpatched 20-year-old water pump controller against vulnerability in a modern cloud-based IT systems? What should DAF leaders prioritize funding for the unsexy OT infrastructure versus that high-end IT system?

Lt. Gen. Chris Weggeman, USAF (Ret.):

Thank you, Dr. Heath, for that. I think it’s all sexy. And thanks for those kind words in the intro. Mainly, she has to read that ’cause really, she should just say it’s Wedge, the simplest tool known to man, ’cause everyone else here is eminently smarter than I am. But it’s a great question. And I’ll start it off by saying, I think at the highest level, we need to start or stop thinking about the complexity and the sexiness of the technology and jousting between IT and OT and always frame it in terms of the consequence to the mission. ‘Cause in our line of work, failure is not an option. So I think that’s the most important thing. What we need to do is focus our leadership, our investments and our resources on the things that generate the greatest consequence to mission success. And it’s very analogous for some of you or most of you that may be familiar with what we’ve had to do with functional mission analysis, Cyber FMAC. We really don’t need a new playbook. It’s really the same playbook. And it’s three questions. As a base commander, which I’ve had the honor of being one of those, you just gotta know what does this capability do in terms of enabling my mission, whether it’s flightline access, pumping fuel, pumping water, sort of generation, et cetera. What happens when an adversary takes it away from me and how long does it take me to recover and do I have the ability to fight hurt? Those are the three questions that I need to answer.

And that last question has a temporal definition or asymmetry that I think it’s important for us to consider. There is a time to recovery asymmetry between information technology and operational technology. For example, with IT, we’re really good at having cloud-based redundancy. We have gold disc. We can rapidly restore the last known good. We have multi-phenomenology of transport. We have zero trust principles. All of this stuff means we can typically recover to an IT state rapidly. OT, does anyone have that 1980s Siemens PLC on their bench in their basement? Okay, does anyone have the vendor-specific engineer that knows how to install it? How long does it take to find that part and that person and get ’em on your base to figure it out? So we do need to think differently about OT from a sexy perspective in that we are less prepared. We have less operational readiness to drive the mission back to where it needs to be from the OT perspective.

And I could go on and on here, but I just wanna reiterate, I think the things we’ve learned about Functional Mission Analysis Cyber is the quickest thing to do. And in terms of where do we spend the next dollar, again, I try not to think about the technology. I wanna start with the question, and I know you focus on this a lot in your role as our PCA. Where does the next dollar generate the greatest amount of combat power resilience? Start with that question. It’s an operational commander’s question. And I’ll close my thoughts on this question with kind of what I think is a really powerful metaphor, and that is we, this audience, everyone here, we have spent years protecting and defending the tip of the combat spear. But right now, ladies and gentlemen, our adversaries have decided to focus time, resources, and interest on the hand that wields the spear, and that’s where we have to focus.

Dr. Wanda T. Jones-Heath:

Ooh, I love that, the hand that wields the spear. And keeping in the theme of our operational technology, defense-critical infrastructure, and the consequences to the mission, I’ll pivot really quickly to you, Candice. You know, Chris talked about on the base, you know, the infrastructure on the base, right, that is very critical. Let’s talk about outside of the wire, right, outside of the fence, where we depend, especially our Space Force bases, that depend on that commercial utility that’s right outside the gate.

So how do we move beyond voluntary threat sharing and establish a real-time operational cyber defense posture with those organizations as well?

Candice Frost:

Well, thanks for that question, I appreciate it. And we at Parsons have understand that. Our company does a critical amount of the infrastructure itself, starting with the actual water locations, the power grids, and working with state, local municipalities. We’re a part of what the ONCD has started in Texas called Project Watershed. And that looks at where we’re securing the common grid. Kinetic effects in cyber are still kinetic. And even though it might not be the sexy part, I would really even say the hand or even the tail is the most vulnerable part where we have seen nation state actors try and target. So we really as a country have to look at building critical infrastructure, water power. You have to fund and manage IT and OT convergence. And you have to look at just different operational definitions by real-time managed detection response and for both ICS and SCADA systems and environments.

Another part that we’ve looked at on the industry side is really creating mission enclaves where we can look at either infrastructure segmentation, switching to secure means, and then potentially even localized microgrids outside of the base may be one option. Lastly, I think what’s really important is automation, machine-to-machine threat sharing. You know, the days of literally printing something off, taking it to someone else, or waiting for an announcement to come out, it’s just not fast enough.

And as General Caine just stated a couple of minutes ago, the character of warfare is changing. And if they’re starting to target those tail ends outside of the base, we really have to work together as partners, holistically with the government, but also with your industry partners who are out there providing that water and that power. So again, defend the ecosystem, not just the base, because the base is the stronghold, but the ecosystem supporting it is the area that we see in industry that needs the most support.

Dr. Wanda T. Jones-Heath:

Excellent. So Dan Waddell, let’s jump into post-quantum. We know that the National Security Directive, like OMB M2615, has a near-term mandate. Harvest now, decrypt later. How do we combat that? What are the tactics and techniques that we need to think about now? From IBM’s perspective, how can organizations operationalize crypto-agility across legacy systems?

Dan Waddell:

Thank you, Dr. Heath. I was hoping IBM would get the quantum question. We’ve obviously been in this quantum space for decades, really, and I’ll point back to some really inspiring words from General Kane earlier this morning, where he really emphasized the need to give our Airmen and Guardians the tools, the trust, and the freedom to combat the enemy, whether that’s on a kinetic or a cyber battlefield. And we know in the quantum space, we have nation-state threat actors that are devoting time, money, and resources to building a quantum computer that can and will break into our vulnerable cryptographic algorithms, like some of the classical algorithms such as RSA and ECC. So the Harvest Now, Decrypt Later is certainly a threat that I think most people can understand. But as we move forward and project an IBM’s own timeline and roadmap, we think by 2029, there will be a cryptographically relevant quantum computer that can break that encryption. And then now that opens up a whole new book of threats to include being able to manipulate digital signatures and really just erode the trust, which underpins everything that we do, not only in our daily lives, but certainly protecting both our national security systems and our non-NSS systems.

Dr. Bertha Hale obviously is the PQC lead for all of the Department of War. And she recently put out a really good five-pillar strategy, and one that IBM has followed, again, for a number of years. Really, a lot of questions that I get from organizations, not only across the Department of War, but also our partners in the IC and the Federal Civilian Executive Branch, is where do we start, right? And so governance is obviously a really important topic, being able to train your workforce on the risk. And not just your coders, not just your IT administrators, not just your security analysts that are manning your security operations centers, but also the ones that are managing your supply chain, the acquisition folks, the ones that are actually letting out the RFPs to be either to buy or build your systems to protect our nation. I think that’s absolutely critical to make sure that the products and the services that we buy as a nation will be protected against that threat, not if, but when it happens, right?

So governance is certainly an important part of it. Also, this really isn’t just a math problem or a technology problem. We’ve already solved that. We know this encryption can be broken. It’s just a matter of when that capability will be ready. I remember 5, 10 years ago in this space, people were saying, oh, it’s not going to be around until 2050. And now we’re actually saying it’s only a few years away. And this is a problem that cannot be solved with installing a patch, right? So the term crypto agility is really not only preparing for the harvest now, decrypt later threat today, but also the threat of when that cryptographically relevant quantum computer will be online in 2029 or whenever. And then also the next generation of the quantum computer, right? Being able to build a framework that will allow you to be resilient and protect against that threat. So risk management is obviously a very important topic. A lot of our conversations with our clients around, let’s start with protecting your crown jewels, your critical assets, building that inventory, and using technology, right? We’re talking about upgrading millions and billions of lines of code in a lot of these applications. That cannot be done by a human alone. We need technology to help solve that problem. So I think to close, I think just my advice is get started. It really doesn’t matter what piece of the puzzle that you start to put down on the map. But as long as you’re starting- and thank you, Dr. Heath, for starting this conversation- let’s get to work.

Dr. Wanda T. Jones-Heath:

OK, great. So we’ve talked about OT resilience, post-quantum readiness, crypto agility, right? So Candice, let me pivot to you. It would not be right to not talk about AI, right? How do we use AI in automation from a defense perspective? Airmen and Guardians need to make the right decisions. But we know that because of what the adversary is doing, the amount of data we have to sift through, we need tools like AI to be able to help. How do we design systems and threat intelligence sharing so we empower the human operator on the front lines, especially in cyber?

Candice Frost:

All right, so those of you who have the bingo card, we have now said OT, IT, AI, ICS, SCADA, Quantum. What have we missed yet? We’re trying to get them all. And cyber workforce. Oh, cyber workforce there. Somebody’s almost at bingo. No, it’s a little funny. Come on, guys. I know. I follow the chairman.

So what I’d really talk about, especially in artificial intelligence, is really the empowerment of the human operator in cyber. If we look at what General Caine just talked about, the character of warfare changing very rapidly, the one part that wasn’t mentioned but is really critical, and that’s the nature of warfare. And at the end of the day, there’s always a human as a part of warfare itself. Because warfare is a human endeavor, all right? I’ll take off the professorial hat and go back to why AI is so great and so important to the defensive part of what we do in the cyber workforce. It’s really the ultimate analyst that’s filtering out the noise.

If we look at artificial intelligence, it will continue to operate at a faster and faster pace. The machine’s speed will continue to accelerate. But that human is still a critical part and component. It’s not to replace the intuition. I think that’s one area that we have seen time and time again with every revolution of military affairs, what’s changed. The human remains the epicenter, kind of the cog, the center of warfare. But you’ve got to continue, and we’re seeing this with artificial intelligence, and it’s clearing the cognitive runway. I’m trying to use some Air Force terms. I’m an Army person. But I threw in– there we go– the runway itself. Again, another joke. This is a rough audience. We need to get more coffee. So next time, we will sponsor more coffee outside.

We really have looked at Parsons itself. How do we automate defensive and intel collection platforms? We understand, and we know, we’ve heard from service members, that context over collection, you just can’t aggregate data. You’ve got to correlate it. And that’s incredibly important, especially as we just spoke about. We also have to get to the point of explainable artificial intelligence. It’s a system showing mathematics, but it’s also trying to see and find the why, figuring out what’s the reasoning behind it. Because you can’t reverse engineer mid-firefight. That’s just not practicable. So you’ve got to be able to move at the pace of where the battle space and the battle itself is going.

And then the last, we have to understand human-centered interfaces. The same UX rigor that is done on a fifth-generation fighter has to be applied to artificial intelligence. And like anything, safety can’t be bolted on at the end. So it’s got to be continuing throughout the process. So congratulations to the person that got bingo in the back.

Lt. Gen. Chris Weggeman, USAF (Ret.):

Can I pile on to this? Oh, absolutely. I love what my cohort’s saying, my colleague’s saying. Zoom us out a little bit with AI. The conversations with AI all get into AI driving and outcome, AI enablement. But this conversation is ultimately about mission resilience, mission assurance. So just real quick to pile on to what Candice was saying, it’s important that we all think about AI at all times in a mission assurance and mission resilience. So we need to think about cybersecurity of, from, and with AI, full spectrum. You’ve got to think about how do you make sure you protect your data input and data stores that are driving your AI. You’ve got to make sure you protect from adversary attacks into your AI. So you’ve got to defend and actively defend your AI architecture and infrastructure. And then you have to, as we were talking about, figure out how you want to act with AI, as Candice just threw out there. How do we use it? So of, from, and with cybersecurity, of, from, and with AI, full spectrum approach will give us mission assurance and mission resilience with AI now as a teammate in how we conduct joint operations. Too often, I think we go right to the widget and the capability and what it can do for us and how humans need to learn about it. But we’ve got to make sure that we have cybersecurity of, from, and with it at all times. And that takes deliberate thought and action as well.

Dr. Wanda T. Jones-Heath:

Thank you. So let’s pivot to our space question. Considering the media and the announcement that we have now the first weapon in space, so General Dynamics is a leader in building secure systems for space domain, as our military increasingly relies on commercial low-Earth orbit constellations to conduct missions. How should our security mindset evolve? How can we ensure mission assurance when we don’t own the satellites, but are instead buying critical services from our commercial partners? So that’s a loaded question with like three embedded in one. So off you go.

Dan Feller:

I appreciate that. I think the two important questions there are can you trust commercial satellites, and how do you evolve your security posture? So I’m going to start with commercial satellites. They’re everywhere. We’re using them. And the important thing is to be diligent and deliberate with what missions and sensitive data and how they’re put into the national missions. So as long as those commercial satellites are handling the data and the security posture appropriately, we should be able to trust them. I also believe that as you start putting more important sorts of missions and data in their hands, you’ve got to make sure the vigilance is there, that they’ve got the right cyber defenses, they’ve got the sophisticated encryption, they’ve got the right supply chain, they’ve got the right chain of custody control, that you would apply to a defense satellite as well.

And I feel confident working at General Dynamics that that’s being done. We work with a number of commercial satellite providers to make sure that their cyber systems and their crypto systems are up to snuff when it comes to everything that they need to do to handle the national missions. So we don’t treat them differently. We treat them the same. And as long as the scrutiny is there, then I’m totally comfortable with commercial satellites.

The second part, how should we evolve our security posture and our mindset there is a really good question. One of the things that we know is that with quantum and with AI, the tools are out there right now to defeat the systems that are in place today. It’s easy to do. So there’s three things that I think we need to do to evolve our security mindset. First, make sure that the defenses that we’ve got in place with our cybersecurity solutions and with our encryption are as good as they can be. The NSA just came out with CERD 2.0, which are the standards for the robustness against crypto and AI that are out there today. General Dynamics has been investing in this heavily over the last several years. And we have today fieldable products that meet those CERD 2.0 requirements, not just for satellites, but for the ground as well. And so embrace those, that’s number one. Put the best defenses you’ve got available today to defend against the threat.

But number one by itself is not sufficient. You’ve already heard from my colleagues up here today that the threat’s gonna keep accelerating. So the best way to make sure that you can defend against an accelerating threat is test the best available attacks on yourself. Find those vulnerabilities before your adversaries do and patch them as quickly as possible. This is something that’s absolutely embraced as part of the fabric of how we design secure systems at General Dynamics and requires us to spend lots of money trying to break our own stuff. And we’re good at it. We’re also good at fixing it as well. So do that red teamwork. Make sure that you’re throwing the most sophisticated frontier AI attack models at your systems. Make sure that you’re using quantum computing to hack your systems and then fix it.

Those first two things are good, but I also don’t think they’re sufficient. There’s a third thing that we have to do as well. And that’s, we have to start thinking that it’s not about building the best bank vault to protect our precious treasure. You do do that, but you also need to start assuming that somebody’s already inside. So if somebody is inside, how do you detect them? How do you deny their ability to make good on whatever they’ve found? And how do you contain whatever they’ve been able to get access to?

And so this is where you fight fire with fire. You start using your AI systems to monitor data traffic. You start using your data systems to see the patterns that are going on within your satellite or your ground system, or any of the attack surfaces that are now proliferated with these giant systems of systems. And when you detect anomalous behavior, you throw a circle around it and you say, stop. This is out of family, we’re gonna respond. Thank you.

Dr. Wanda T. Jones-Heath:

Okay, I’m gonna keep you on the mic, Dan. So you mentioned partnerships, right? And we know that we depend on our industry partners a lot, right? We talk about the commercial partnerships from a utility perspective. So there’s no one single stakeholder that holds the key to success. How do we reshape incentives structure between the Department of the Air Force and our defense and industrial base partners to foster proactive real-time threat sharing? No more of the compliance reporting approach.

Dan Feller:

I think that’s a great question. And this is one that’s near and dear to me because I don’t think the answer is to dangle a carrot in front of people to get them to behave differently. It’s to recognize that you’re only as strong as the weakest link in the chain. And we are all holding up the defense of this country together. And I believe that everybody that’s involved in this entire exercise does not wanna be the weakest link in that chain. And so to do that, we’ve gotta listen, learn, evolve, and it’s a cultural response. It’s about asking what’s going on. It’s about sharing what you just experienced. It’s about that culture, that village mentality, that we’re gonna defend ourselves as a team, the government team, the defense team, the civilian team. All of the people that are involved in the defense of this country have the same thing at stake. And so we absolutely wanna embrace that as a team, build that culture and respect that at the end of the day. If one of us loses, we all lose.

Dan Waddell:

Yeah, can I jump in on that, Dr. Heath? Absolutely. I think, in addition to what Dan just said, agree 100% on it, I just wanna point out some of the great work that Department of War and the Air Force specifically has done to shrink the time it takes to get to industry for a lot of the innovation, right? So Platform One, Tradewinds, OTAs, CSOs, SBIRs. Gone are the days when you put out a requirement and then two to three years later, once you go through the RFP process, the evaluation, the protest, then finally the requirement is satisfied, but guess what, now the requirement is OBE, right? It’s been overtaken by events. Through a lot of these innovative approaches to get to industry quicker, we are now able to respond and to provide the innovation necessary to satisfy the requirement in a much way.

So it’s, yes, not necessarily the carrot dangling, but also the ability to support you and the warfighter to be able to say, yes, we have a solution, we can develop it and deliver it in a much quicker fashion.

Dr. Wanda T. Jones-Heath:

I mean, absolutely, great point, because waiting until the requirement’s fully baked is not the approach we need now. We need to be able to partner with industry from the beginning, find the right solutions, and then implement ’em as fast as we can. The adversary doesn’t wait for us to figure it out, and we shouldn’t either anymore, so glad you were able to add that point.

Now, we’ve heard a lot. We’ve talked about AI, we’ve talked about OT, DCI, we’ve talked about satellite security, and now let’s go down the line, starting with Dan Waddell, Candace, Dan Feller, and then we’ll end with you, Chris. Thank you for your insight so far. Certainly have given us a wide range of things to think about as we leave this panel. To ensure we have final perspectives from each of our panelists, think about what would you say to the audience on the most critical actions the Department of Air Force should take to enhance cyber resiliency and mission assurance?

Dan Waddell:

Yeah, just piggybacking on some of the words that I started with, it’s really just kind of getting started and looking at what areas require the most attention and prioritizing there, right? ‘Cause we cannot do everything at once. It really boils down to picking those, the data and the systems that absolutely you need to protect, that life and limb depends on it, our national security depends on it, and then building a framework where you can be agile and respond to the threat, whether that’s from a governance perspective, whether that’s doing a PQC readiness assessment to start to do some inventory to see what vulnerable crypto algorithms you have in your environment, and then what’s the roadmap to get there.

So I would just emphasize, just get started somewhere along the journey. Obviously, from a quantum safe perspective, IBM has, everybody has kind of like a four-step approach on how to get started. It doesn’t have to be serial. You can really just enter the process somewhere along the way and prioritize and roll up the sleeve and let’s get to work.

Candice Frost:

So I’d say something specifically with the Air Force and the Airmen that we’ve worked with in 16th Air Force, and we’ve seen a substantive positive result of using one of the tools that we have called Envy is really understanding the network itself. Like you can’t understand the entire battle space in the cyber world if you don’t understand where every vulnerability is. And so it’s not just the vulnerability of the endpoints, but then I’d also say there’s a really big part of on the counterintelligence side, but it’s the threat from the inside. And so understanding that as well, it’s almost gotta be a layered approach that industry can oftentimes help with because we’ve done this with different services.

The joint force is fantastic to be able to pull and see from different aspects in different areas. And so that’s what I’d ask is to really understand the entire network that exists, work with your industry partners to figure out what’s really out there ’cause they’ve pretty much seen it all.

Dan Feller:

I think that’s a great answer. And understanding the network and all the different attack surfaces is key. One of the things that we’re really focused on is it’s not enough to identify new solutions, build those solutions and make those solutions available. It’s also about deploying those solutions, installing those solutions, retrofitting what needs to be retrofitted. So my advice, or at least my plea would be to everybody that’s working this problem, make sure that the demand signal is very, very clear that not only do you need the right kit to fight today, you need the right kit to fight tomorrow, you need it now. You can’t wait for two years from now solution. You need something today. And just because you can go buy it doesn’t mean it’s installed, implemented correctly and set up for success. That entire logistics chain has to be planned and executed with speed.

Lt. Gen. Chris Weggeman, USAF (Ret.):

I think I have two things I would offer to the mission owners, commanders, operators. The first one is, if there is a commercial dependency to your mission or your base that can cripple or make you combat ineffective, that’s our battle space. Even if it’s not on the DoDIN, that is our battlespace. And so the first thing I would say is we have to operationalize the mission dependency seams we have in our power projection platforms, which is our installations, whether they’re the hard ones, big ones we have on CONUS or the ACE locations we have that in terms of our force projection CONOPS. So operationalize the mission dependency seams, which gets to everything we’ve talked about, the public-private partnership, incentives, how we share more than information. It’s not just share and hope. We actually have to have integrated operational teams, pre-scripted missions. We have to have trust. We have to rehearse and exercise. And we have to bring capabilities to these 40-person small utility teams that you can’t just say, hey, you guys need to create a SOC in two weeks. They can’t do it. We have to bring the game to them and operationalize the mission dependency seams. And the second one is pretty simple from my perspective, and that is defend the mission, not the network boundary. We have to think about it that way. And I think that is the fastest path to advocacy and resource priority in the palm drill too. We gotta talk about defending the mission and the mission outcomes, not necessarily the tech stack and the network boundary. We have to translate to the mission owners.

Dr. Wanda T. Jones-Heath:

Oh, absolutely. Great walk off the stage advice. Getting started. If we haven’t started now, we’re behind, right? Post-Quantum is here now, right? They are taking our data and harvesting it and waiting to later. We need to clearly understand that. Understanding our networks and what it looks like so that we can invest properly, get the right solution that fits the problem, not just any tool or any solution. And certainly our dependency on our commercial partners and info sharing for the right information, not just all of the information. And lastly, we have to be agile and responsive to what’s happening in this environment now so that the future is not as dire as we think it could be. Thank you for attending today’s panel session. Thank you to our wonderful panelists for providing that type of information. And it has certainly been a pleasure moderating the panel and getting to hear all you had to say. Thank you.