HSDF THE PODCAST

Congressional Cybersecurity Priorities Part 2

Kevin Long

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 13:57

Welcome to our “TUESDAY EDITION of HSDF THE PODCAST,” a collection of policy discussions on government technology and homeland security brought to you by the Homeland Security and Defense Forum

 In this two part episode, examine why vulnerability management is buckling under the scale of modern discovery and what it takes to modernize the CVE and NIST NVD pipeline without slowing down response. We also connect the dots between AI governance, public-private partnership, and quantum readiness so we can build trust and security before the next leap in capability.

Featuring:

  • Moira Bergin, Subcommittee Director/Counsel, Subcommittee on Cybersecurity and Infrastructure Protection, Committee on Homeland Security
  • Casey Dolen, Professional Staff Member, Subcommittee on Cybersecurity and Infrastructure Protection, Committee on Homeland Security
  • Alan McQuinn, Professional Staff Member, Subcommittee on Research and Technology, House Committee on Science, Space and Technology
  • Emily Park, Professional Staff Member, Senate Homeland Security and Governmental Affairs Committee 
  • Frank Cilluffo, Director, McCrary Institute (moderator)

 This discussion took place June 10th, 2026, at HSDF’s Cyber Symposium

Follow  HSDF THE PODCAST and never miss latest insider talk on government technology, innovation, and security.  Visit the HSDF YouTube channel to view hours of insightful policy discussion.  For more information about the Homeland Security & Defense Forum (HSDF), visit hsdf.org.

Analog Systems Meet Digital Speed

SPEAKER_05

I want to ask a follow-up. It is a challenging set of issues. We can't unilaterally disarm ourselves and let other countries, notably one pacing country, China, take the lead in eye deployment. But the flip side is there are legitimate security questions, and it's a tough balance. To think that we would have a unilat everyone would agree on anything, I think is actually troubling. Because this is, we talk about transform transformative technology. I think we're seeing it as we speak. And I'd be curious as a follow-up here, a lot of our systems and structures are analog when we're looking at a whole new world. Are we ready to absorb the Kev list, uh, the known exploited vulnerability list that SISA holds had about 1,500 vulnerabilities on that based on guests I've had on our podcast and others who've been part of Glasswing? That's quadrupled instantaneously. A lot of our processes are not ready for the change. So I'd be curious if you disagree with that approach. And then secondly, and this may be me, and I've never had an unspoken thought, and I have a lot of opinions, but but has the public-private partnership we've known, and I've always been a voice saying long on nouns, short on verbs, but it's being flipped on its head. The biggest breakthroughs are not necessarily going to come out of government now. It's going to come out of industry. And when I say industry, it's a small community within industry, yet our critical infrastructure owner operators that keep our lights on, that keep our economy going, that keep our war fighters ready are all dependent upon some of that. So I'd be curious what your thoughts are there in terms of whether that partnership needs to change, and if so, what that could look like. And Alan, I'll give you a chance to get out of that question to go a little deeper on quantum because I know you're doing some really interesting work there. Alan, why don't we start with you and then we'll, and then Casey, you're gonna get the first question next.

Automating CVE And NVD Workflows

SPEAKER_05

Go around.

SPEAKER_04

I'll take the first question you said first and then maybe talk about quantum. Please. What I'll say is yes, your the way that you presuppose that question is correct. We're starting to see a lot of the manual processes break down for vulnerability management. A core theme of the bill that Mora and I have been working on around CVE and MVD is how do you modernize and automate some of these existing processes for vulnerability management so that people, you don't have one person in double checking and rechecking CVEs when they come to the national vulnerability database at NIST, for example. And I think both agencies have taken that to heart and they're looking at how to automate, how to streamline those processes. A couple of weeks ago, NIST itself basically threw in the towel a little bit on a lot of their how they were enriching data that went into the NVD and said, we're only going to enrich ones that are like high priority, right? They themselves came to that decision because they were there was a massive backlog in the amount of vulnerability data that they needed to put into the database. Yes, we're seeing that in real time, and I would expect a significant tsunami of vulnerability discovery. Not typhoon, but you know you're preceding my next one. To come, and a lot of folks are not ready, and we're gonna have to

Quantum Timelines And Crypto Readiness

SPEAKER_04

work through that. Speaking of none of that, quantum. Next. Yeah, the we first moved a big quantum bill five, six years ago, the National Quantum Initiative Act. I guess it was in 2018, so over that. And I think the first iteration of this bill was really looking at what do we need to do to advance this technology that is so far away. It was very focused on simple, basic research. And now we're at the stage where we're trying to move to later TRL levels in advance of potential quantum-capable machines at sufficient scale that could, in theory, do Shore's algorithm. We're gonna start seeing major machines come online as soon as next year. And it's still to be determined whether that threat is real, but in advance of it, we really need to get our security ready, right? Not only for schemes that are collect now, decrypt later in the national security space, but also in case one of these systems comes online at a time scale that we're not prepared for. Starting in 2016, NIST did this process with everyone around the world to develop post-quantum cryptography algorithms. And they finished that, I think a little over a year and a half ago. Those algorithms are published in advance of those algorithms being published. We worked with the Oversight Committee and HisGAC to do a bill that would allow the federal government to be ready to move on those algorithms and adopt them in this their systems, but money never followed. A lot of the implementation has been sparing. And so we're looking at ways to help speed up some of that implementation. I would actually go to Emily to talk about her boss's bill to do some of this from a federal standpoint from a federal coordinative standpoint. But what I would say from our bill is it's more on the technical assistance side. How do we get more resources out there? How do we help sectors that are more at risk adopt these technologies quicker? And NIST is key to that. It's developing a grant and technical assistance program at NIST.

SPEAKER_05

Can I put you on the spot for ones? And obviously it's all of the above, but if you have to choose, is this a PQE issue, a PQC issue, or what where do you think? And I think there's this belief that wait till it comes, and obviously that's too late, but I still hear that. Oh, I don't have to worry about that right now. Where would you put if you had limited dollars you could spend right now, where would it be?

SPEAKER_04

It would be in sectors like financial services that are uniquely at risk of having their entire kernel owned in the event that these systems come online. It wouldn't necessarily be at your mom and pop water utility because really a lot of this will be about stealing information about the beginning. Yeah. And also other types of remediations can help.

SPEAKER_05

Casey, any thoughts on the

AI Governance Falling Behind Innovation

SPEAKER_05

initial question? I forgot what I asked already.

SPEAKER_01

So, in terms of meeting the moment and how quickly we're moving, I think, as I kind of mentioned at the offset, we're focused a lot on AI and national security matters, but it's really been from a perspective of educating our members, getting them in the room, giving them demos of new capabilities that are coming out of the frontier labs, giving them hands-on, I guess, experience with some of these models and seeing where jailbreaks can happen or kind of other risks to those models. So I think, frankly, it's this regulatory landscape is just not meeting the pace of the advancements that we're seeing. And so I think that creates so much uncertainty. And I think that's really the main challenge that I see, especially when you look it. This goes far beyond the federal government. This goes to state and local levels and critical infrastructure as well. Without kind of this idea of a governance model and something that's more coherent, we're seeing a patchwork, we're seeing people have a lack of trust in a lot of these new technologies. And I think ultimately that kind of puts us in bad footing in terms of deploying US-led technology internally, but globally as well. And so I think there's just a lot of questions that remain in terms of where are we going around governance? And then, yeah, how can we build trust and accountability into these systems? And then on the public-private partnership piece, I just want to say there is we've been really hyper focused on seeing Anchor CI, which is the CPAC public-private partnership framework, be restored. I think we really need that to get some consensus-driven decisions made between the public and private sectors, just putting in the plugs for that. And we hope to see that out of DHS soon.

SPEAKER_05

Extra points for bringing up Seek. Uh Maura, Emily, on this

Who Owns The Guardrails

SPEAKER_05

question.

SPEAKER_03

Yeah, I would just say that I agree with everything Casey said from a policy perspective. We're building the plane while we're flying it as we deploy AI models, and it's evolving faster than policymakers can keep up, which I think also feeds into your second question about the role of public-private partnership. Because right now we have public, the private sector taking on the role that the government normally would. So they have these frontier dual-use models that they're deciding how they're going to put the guardrails on, when they're going to release them. We don't know who's responsible for it when something goes wrong. And I think those are critical questions that we need answers to. And as we've been, I don't want to beat a dead horse on this, but the staffing issue in government continues to be a problem both for policy development and responsible deployment. What's the second part of the question? I keep forgetting. Yeah, I think I covered that. Yeah.

SPEAKER_05

Emily, and if I can ask quick, because I want to make sure we have a little bit of time for one question in the audience, is where we're going to be.

SPEAKER_02

Absolutely.

Rebuilding Public-Private Coordination

SPEAKER_02

So very quickly, public-private partnership is really key for what we see, the future when it comes to quantum, when it comes to AI, when it comes to cybersecurity. You can't just have one sector racing forward without working alongside and in betwixt and between the federal agencies and other sectors as well. So that is one of the biggest things that Senator Peters has been pushing for with his administration, is making sure that you have there is that communication back and forth and ability to work with various different sectors across the nation through CIPAC and others, making sure there's an opportunity there for industry folks to weigh in, for state and local governments to weigh in. Those are critical when it comes to federal agencies making decisions about how they want to react, how they want to deal with some of these emerging tech issues, such as some of these really advanced AI models and quantum as well. So just quickly on the quantum bill, that is definitely one of the things that we're looking for with Senator Peters and National Quantum Readiness and Innovation Act, is trying to use federal agencies to drive the model for what quantum preparedness looks like. And what we've seen is that some of the federal agencies are hesitant to potentially adopt post-quantum cryptography. They're not really certain how to procure it, how to implement it, how to deal with it as like a bigger question. So this would require some of those implementation pieces and procurement pieces over a timeline, focusing on some of the most critical systems first.

SPEAKER_05

Emily, thank you. And I had 10 other questions I wanted to get through, but I want to make sure we have time for a question from

Audience Question On Defensive Momentum

SPEAKER_05

the audience. But let me ask Lightning Round. If China had come out with Mythos, would there be a press conference? Would we have responsible use or would we find out after we're owned? Yes, no? Simple.

SPEAKER_02

I think you would see quite a few people in government running around DC. We would be scared.

SPEAKER_05

All right. One question from the audience. Anyone brave enough to jump up real fast? If not, I will ask one last question. Okay, please.

SPEAKER_00

Yeah, like the intro that Alan made being an engineer or scientist in the midst of cyber technologies. But as we see forward looking, we have so many scientific developments, we call it applied science, merging with technology. So 6G is coming up, Oscon and computing, and thanks to Delphi did a lot there. And so there's a convergence of science and technology, and of course the threat actors are more so more capabilities are being developed, but of course the exposure is a bit more maybe stronger in terms of maybe vulnerabilities or attacks, and how is policy going to shape maybe the capability for the government to actually build momentum within both the industry and government and policies to enhance to encourage funding in private partnership so that the threat actors that we see from external are not well above our capabilities. In other words, uh defensive systems strong enough to overcome the offensive threats out there.

SPEAKER_05

Good question, Alan. I think that was aimed largely and anyone else who wants to jump in.

SPEAKER_04

I'll take a little bit of that question. You asked, like, how do we reduce the asymmetric advantage of yeah, it's very hard, right? It's an incredible challenge. We've actually tried to like for yeah, uh one of my kind of things that I often find upsetting when people talk about AI for cybersecurity, is a lot of my colleagues are like, yeah, but it'll improve defense just as much as it'll prove it. Yeah, but you have to implement it. And we don't have confidence in how some of these systems are designed to do defense, and there's huge asymmetric advantage. Anyway, we have over the years tried to do some band-aids to solve some of these problems, but they are just that. They're band-aids, right? And so it's a really hard challenge. One of the ones that we're currently looking at is in OT cybersecurity, where you have basically a bunch of water utilities that are leaky buckets for cybersecurity challenges, right? How much can you actually patch to solve these problems? Maybe you have to just not do cybersecurity solutions and engineer your way out of catastrophe. And so we're trying to look at take a kitchen sink approach to some of these things, but how can we move the ball forward on engineering to deal with cybersecurity? That's one example. But there, it's gonna defer, it's gonna change depending on the technology, depending on the actor, the context. It's a really hard challenge.

SPEAKER_05

Anyone else want to jump on that real quick? Awesome. I'm gonna answer it just real fast because I think first mover matters here. There's no question in my eyes that the initiative remains with the attacker, but that's okay because you learned from the attacker to improve

First-Mover Reality And Closing

SPEAKER_05

blue. Please join me in thanking an amazing panel here doing important. So thank you.