HSDF THE PODCAST

Looking Back & Looking Forward CISA’s Core Mission & Emerging Cyber Threats Garbarino

Kevin Long

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 26:23

Welcome to our “TUESDAY EDITION of HSDF THE PODCAST,” a collection of policy discussions on government technology and homeland security brought to you by the Homeland Security and Defense Forum

 In this episode, we sit down to talk Homeland Security in 2025 terms, from CISA’s staffing and funding realities to what industry can do to rebuild support for the agency. We also wrestle with the hard truth that AI-driven offense may soon outpace human-speed defense, especially across aging critical infrastructure.

 Featuring: 

  This discussion took place June 10th, 2026, at HSDF’s Cyber Symposium

Follow  HSDF THE PODCAST and never miss latest insider talk on government technology, innovation, and security.  Visit the HSDF YouTube channel to view hours of insightful policy discussion.  For more information about the Homeland Security & Defense Forum (HSDF), visit hsdf.org.

Welcome And Threats Then Now

SPEAKER_03

Thank you very much. Can you hear us all okay? We have the dreaded slot right after lunch, so this should be real uplifting for you. But I appreciate being here. And it's nice to get back into the discussion of what I went to Congress for, and that was Homeland Security. And so we're gonna have a conversation with the Congressman and the chairman about all things Homeland Security. But I just want to preface it a little bit about my quick take on what it was like when I was there and what how it's changed. When I first got to Congress in 2014, ISIS-inspired acts of terrorism were the number one concern to Homeland Security. Cybersecurity was there, but it wasn't really where it is now. Within a few years, it was all cyber, right? And now it seems like, yeah, it's about cyber, but now the big concern is AI. And it's amazing how many times things have changed in the last few years with respect to the nature and quality of the threat landscape. So we're gonna kind of go back a little bit. When I got to Homeland, CISA didn't exist. So we stood it up and we funded it and got it going and then did some things like probably one of the most important is incident reporting, which of course is not even online yet. So we're gonna talk more with the congressman about that, the chairman. And I keep playing as Congressman Chairman, excuse me. And so let's start out with SISA itself,

CISA Today Leadership Hiring Budget

SPEAKER_03

Mr. Chairman. Tell us about what's your view, what the current state of CISA, what's working and what's not, and then we can drill down on that a little bit.

SPEAKER_04

Thanks, John, for being here. We're never serious, by the way. This is tough, right? I know, yeah, it is really and we're usually not when we're together, we're usually drinking.

SPEAKER_03

Yes, we are.

SPEAKER_04

That's how we got me to recommend it for chairman. Yeah, that's true. Actually, it was when I first got to Congress and I got on. John was ranking member, and I got on the Homeland Security Committee. He called me over to his office. He got me a bottle of vodka, actually. And he's like, Come over to my office, have a drink. I got something I want to talk to you about. So I go over his office and he says, I want you to be the ranking member on the cyber subcommittee in Homeland. And I'm like, I don't want to do that. I don't know anything about cyber. I'm like, I don't want to do that. No. And he goes, No, trust me, you'll love it. You have to do it. So begrudgingly, I said yes. And of course, he was right. And I I did love it. I learned a lot. And now what's been one of the major things I've been focusing on as chairman, thank you for putting me on the right, right path. But as for Sissa now, hearing that, hearing there's a nominee on the president's desk ready, it has not been official yet. But secretary made it sound like they're very close to nominating a full but full director. I think Nick Anderson, who's acting right now, is doing a good job. I think. I think he's he's got about four jobs he's doing right now, but I think he's doing a good job. They just announced, I saw this morning, that they're gonna be hiring, uh make an announcement for 100, 180 people. Since it's had a rough year, they lost a lot of people through rifts, through retirements, and through some transfers, a lot of brain power. And it really, I think it put us back. And so I'm happy naturally now they're gonna turn around and hire. Yeah, they're yes. So and I'm happy in the secretary. See, he he said last week he is supportive of the hirings. He wants to see Sissipy successful. Previous secretary, I don't think, was very supportive of the agency. So I'm happy with the new secretary. He's supportive. Nick is doing a great job. Supposedly, whoever they're gonna nominate is is gonna be great for the gig. And look, luckily, the White House came out with some cuts in their proposed budget. I didn't know what the final number is. They're marking the homeland bill up in in the House today, the Homeland Appropriations bill. So I don't know where that where the actual CISA funding number will be, but I do not expect it to include the major cuts that the uh that the White House proposed

Winning Support Through Industry Education

SPEAKER_04

in their budget.

SPEAKER_03

So we we have a bunch of people here that throughout the industry in cyber. What can they do to help advance the mission of CISA from their vantage points?

SPEAKER_04

Um you all know uh the need of this of CISA and then the great work and the partnership, uh the public-private partnership that that the CIS is able to do with a lot of different people. Unfortunately, I have colleagues that focus on uh the CISA of the mis and disinformation part of CISA, and that that has turned them off to the entire agency. So anything CISA related that they want to oppose, unless the budget's cut, there are reforms put in. So the big thing is it's just pushing through that narrative and educating members. And I will tell you right now, Andy Ogles, who was my subcommittee chairman, was one of those members when he first came on the committee. And now, after having met with industry and CISA reps and learning more about it, he is now one of CISA's biggest supporters. And he actually carried, he was the lead of the Pillar Act, which gave CISA authority to do state and local grants. When the men when you educate the members that don't know, you can get them on board because once you explain what it does, it's it's fairly important. So for industry, when you go when you go talk to members who might be skeptical of the agency, just fill them in on all the good work it does. Because that is that is facts, believe it or not, facts help win an argument.

SPEAKER_03

Sadly, it seems like it's always necessity being a mother of invention. And we can't ever, when I was in officer, at least we couldn't get people to pay attention to cyber issues unless and until there was a major cyber attack, right? And then of course they all paid attention. I want to do something about it. So we can't wait till then. But they don't understand. Yeah, that's the problem.

SPEAKER_04

Once something really bad happens, it's going to be too late. Exactly. And we're listening, I've met with the head of uh the head of FIFA, I've met with the head of the Olympics LA 28, their security pre the partnership that SIS is doing with them, they are so reliant on that partnership, and they're thankful that they're able to have to work with them. People don't get that they should, but cyber touches everything. I mean, there's cybersecurity needs everywhere. And people don't some people unfortunately don't see it that way. We haven't had that, like you said, we haven't had that mash mass casualty event or mass of cyber event that caused by cyber that cyber attacks that has caused people to wake in.

SPEAKER_03

Yeah, the problem is you've had so much there, there's so much money invested in that people don't realize. And but it's not fungible, it's not you can't touch it, you can't feel it, you can't see it. It's not tactile, right? So trying to convince people this is a real threat is is it's hard sometimes, but that's a job of all of you, and it's a job of the chairman here.

SPEAKER_04

But listen, the AI is the AI race, though, right now, and some of the stuff happening, I think, is putting is now starting to show other members and getting them more interested in it.

SPEAKER_03

Yeah, because they're phoning under starting to understand what AI is. Yeah. So we're going quickly, just put a loop on the Pillar

Pillar Act Grants Reauthorization Fight

SPEAKER_03

Act. Where is it at now with reauthorization?

SPEAKER_04

So it was it was reauthorized temporarily when we did the the government funding bill. So it it's it the program is authorized through September 30th. We have a the Pillar Act passed the House. That's a seven-year, I think seven-year reauthorization that it passed the House. It's waiting for action in the Senate. But the big thing is the good news is we have the seven-year authorization that has passed the house. We also have convinced the White House and they're on board with keeping it as part of the whenever we do government funding, the rolling extensions. So we don't expect it to lapse again. That's on their, it's on their must-pass list. So getting it re-authored for a longer time is one thing they work on, but also getting funding for it is another. A program that is reauthorized, but there's no funding behind that doesn't do anything. So it was first the state local grant program was first funded, I think, under the infrastructure bill, which you and I both voted for.

SPEAKER_03

Oh, yeah, I remember that.

SPEAKER_04

Five years ago. And that money's out. That money is out at the end of this year. Chairman Amade, who's retiring, another big supporter of CISA, was great to work with. We were able to get him to first time ever, by the way, fund this program through it is being marked up today. There's 50 million. I know it's I asked for half a billion, but it's 50 million in the Homeland Security Appropriations Bill is being marked up today for that program for next year, which is huge because it is the first time it's been a line item appropriations in an appropriations bill. And we are now, I think, working with the Senate to see if they can plus that number up. I think CISA has told us they have the ability to work with about for next year that they'd be they would be good to do about 85, 87 million. So if we can get it plused up, that would be amazing. But the fact that we got it in the House Homeland Appropriations Bill is great, and we would not have been able to do it without Chairman Abede. Getting it funded is going to be is the big part of the battle. And as long as it's funded, well, whether if we get the long-term authorization, great. Senate has to act on it. If not, we'll continue to do it through government funding.

Incident Reporting Rules Getting It Right

SPEAKER_03

Last thing I'd just on that is the something near and dear to my heart is the incident reporting requirements from Circea. We passed that bill when I was in office, and it still hasn't been implemented yet. And when I was a federal organized crime prosecutor back in the day, and uh 9-11 hit, it completely changed the way we did things. We realized that then the biggest failure leading up to 9-11 was lack of exchange of information. That's really the genesis of what Circe is all about. So, where are we at with it finally being implemented at some point in the near future?

SPEAKER_04

Um look, I'm actually happy it is not implemented yet because what they were the way they wanted to implement it was it was not good. Under the previous the shutdowns have really screwed up everything, and the loss of staff over there has screwed up everything and really delayed a lot. The the this previous secretary, I believe, opened it up for Kaylee. X was it Ex parte, she did that. Was there an ex parte processor? I think she opened it up, and we were getting more information. Industry was supposed to go and give more comments on how they would like it to be uh the regs to be set up. I believe we are waiting for final again. Shutdowns really slowed everything down. We are waiting for final proposed language from them, which is not, I don't think, done yet, but it should be soon. What are we? What was the last kind of? It should be soon. But again, between not having a director and the shutdowns, we have not been given a clear time. Um we we're hearing they're hopeful that it'll be soon. But yes, it has been. Yeah, the good news is like I said, what they had last year was no good. So the fact that it's not implemented yet, that was unimplemented is good because there's nothing worse than having a program that you you had me co-lead it with you that we were so happy to get done, and then all of a sudden it's not what we yeah, what we intended. And so making sure that it is what we intended. Because I wanted this, we want I remember we wanted this. There were so many reporting regulations out there. We wanted this to be the one, not just one another one. So getting it done right was is very important to me because that's part of that's our legacy.

SPEAKER_03

Yeah, getting it right is far more important than getting it done quickly. Yeah, getting it

AI Models And The Race To Defend

SPEAKER_03

done right. When you think about AI, I think about AI the same way I thought about cyber when it was developing. And it's like cyber developed like a car manufacturer would develop a car with all the fast things on it, all the cool things on it, and they have no safety features, no brakes, no airbakes, no nothing, right? No collision control, nothing. They just built this. It's like building a car as fast as you can without any brakes, and no one gave a shit, right? And it seems like they're finally figuring out cyber, cyber's now backfilling and all that. It seems like we're in right back to it again with AI, where it's going, it's developing so fast and we can't keep up with it. And especially in the cybersecurity realm. So, what's your concern with respect to AI and cyber?

SPEAKER_04

Very, I'm very concerned about what the protections that are, the guardrails that are being put on these AI models. I'm concerned about what what our cyber uh what our vulnerabilities are. If an adversary gets access to a methos type model before we were have the ability to shore up our vulnerabilities, which we're not going to be able to do unless we actually use AI, because there actually anthropic came and gave the committee a demonstration of methos and what how it how it can be used. And the way it can find vulnerabilities is astonishing and how quickly it can do it, and it can find things that humans have missed, lots of humans have missed.

SPEAKER_03

Well, if they can find the vulnerabilities, can't the bad guys using AI do the same thing? Well, that's the thing.

SPEAKER_04

We're lucky that we have yeah, so we need to that's the that's the sole point. Yeah. We've had round tables. The committee, we just finished one yesterday. We had Palo Auto and OpenAI and a couple other people there, and we've had this our third one, and everybody is talking about how we need to we need to shore up, we need to use AI to shore up our vulnerabilities before the bad guys get it. And yesterday the estimate was now two to five months. China might have capabiliti of a methos type AI model. So they're saying if we don't, if we don't shore up our vulnerabilities by then, game over, pretty much. And we're there's a big push to get it working. Unfortunately, White House hasn't signed off on the administration on some of the agencies using it yet, even though it's been offered to help show up the vulnerabilities. So we're we're working on that. But I am I'm very concerned about what can be done. I we saw it. They showed us in a presentation the power of this, and right now it's they explained it. Right now it's human speed on defense versus human speed on offense. Once it turns to human speed on defense versus computer speed on offense, we are that's we can't keep up. So that's you know, yep.

Jurisdiction Gridlock And Slow Lawmaking

SPEAKER_03

It was my experience, and I know you've got the same experience. There's so much multi-jurisdictional overlap with homeland that it's hard to get anything done because it has to go through six committees after, and no one wants to give up things obviously within the realm of homeland. But with that being said, I do you find that some of these committees are on the same page with respect to AI policy and how to defend our networks, or are is it still in philosophy?

SPEAKER_04

Luckily, I also serve on the ethics committee, so I have files on everybody. Just kidding. I served on the ethics committee too. That was no picnic. That's not an easy stuff. It's still you still have that, you still have that jurisdictional tug of war with it's more uh you see it a lot amongst the staffers, but if you have the one, you have the conversation with the chairs. I think I tell them, look, I just care about the cybersecurity part of it. Uh, you guys, you handle your jurisdiction. I just need I care about the cybersecurity part of it. You want to do you want to move a bill? I'll waive my jurisdiction. Just let me just make sure. And we did that. Jay Obernolti is working on his bipartisan bill. I don't know. It sounds like a lot of people are coming out in Congress against it, they're not happy with it. He called me up. He wanted to include some of he knew some stuff was gonna come through us. So he wanted us to, he wanted to head off the problem and say, hey, putting this language in, why don't we work together? It doesn't have to, it doesn't have to be marked up to your committee, you get it through. And I said, Yeah, absolutely, we'll work together and make sure he takes care of you when you have a priority down. We did, though. We did get a priority in the NDAA. I'm not gonna say it out loud because I don't want to try to keep it down low, but we got some stuff down. I had to give a lot of favors away to get that, get a lot of sign-offs. But we got it, which is a good thing. But yeah, it's there is you still have the jurisdictional tuck of war, but honestly, you they can't, we can people can't, we are too slow. You know this. I mean, Congress is too slow to pass a law, and then we're even slower if we need to, if we do it wrong, we need to change the law.

SPEAKER_03

Sir Shea is a great example. Right? I mean and it's still not implemented. But again, but again, it took us forever to pass it.

SPEAKER_04

I'm happy that the White House came out with an EO. I'm not totally thrilled with everything in it. I I'm not sure Treasury should be taking the lead. I think my system was, but I'm happy they did something because something they had to start somewhere. And I'm happy that they did something. But we are very and I'm happy that Jay Urbonotti and Lori Tron are working on it, working on legislation because I feel like we do need to do something, but we are very slow, and unfortunately, this tech innovation is not. So it's people can't wait for us to act, but we do need to do something.

SPEAKER_03

So I don't know how we're doing time-wise, but I got one more question before we can open up for some questions from you all. So don't be afraid to ask questions from Hampton. Nothing's off limits, but almost nothing. But let's finish where we kind of

Critical Infrastructure Risks Water Systems

SPEAKER_03

start. That's critical infrastructure, really. That's really where it's all at. And that's kind of is woven through everything here. I was just in the green room when we were talking about an example of some water systems that we know have Chinese malware and embedded in, just like all of our critical infrastructure is doing. Um, predictions about how AI can help us strengthen those systems or how we can what the final rules are gonna look like with respect to the honestly, part of the structure.

SPEAKER_04

Part of the discussion yesterday that came up at our roundtable was some of these water systems and old utility systems, pipelines, they were designed before things were digital. So they were never meant to be digital. And they've been kind of jerry-rigged to be digital. And and one of the one of the panels yesterday said they might have they they might have to pull these things offline because to put these OT systems offline because they might not be able to be fixed, even with AI. And AI actually, we might not be able to fix it, but AI might tell us that you can't this, we can't fix this. We're using other defense, and you might have to take them down off of this off the OT systems down before China has the ability to use it offensively. Because it is it's scary enough to think that you have there might not be a way to fix some of these systems because they were never meant to be like that, and you might have to take them down and not probably start from scratch or keep them offline for good. So the fact that I we had experts saying that yesterday is concerning, but it's also good to know because AI as a as an offensive tool, especially something like the Mythos, it really could do some major damage on a lot of different, not just on a cyber attack, it could do a lot of, it could come up with a lot of different things. And so when it comes to the critical infrastructure, we you might there's some stuff that just might not be able to be fixed and you have to take it down.

SPEAKER_03

Yeah, just to give you a just a finer point on that, just and we'll finish and then I'll go to ask open for questions. In my district, we have water districts everywhere. I don't know how it is in every other state, but each hamlet has their own water district. And each hamlet, some of them have they've ignored their system is so bad that the pipes are over 100 years old, right? So if the then you're gonna try and tell them to have updated computer stuff, they don't even know how half people don't they don't understand anything about computers, right? So it's an it's a very vulnerable, it's a huge vulnerability for us, and that's just one of the many critical.

SPEAKER_04

It was a huge vulnerability for us when we did when AI wasn't a problem, and you just had people in their basements hacking into it or nation states. This is this is gonna be a millionfold. So I have a good afternoon, everybody.

SPEAKER_03

No, yeah, questions, drink bottled water. We got a chance to ask the big dog questions. So yes, go ahead.

Audience Q And A Senate Roadblocks

SPEAKER_00

Mr. Congressman. Hello, Mr. Congressman. You had mentioned that one of the key issues with passing and amending laws is you called it jurisdictional tug of war. What would you say is the greatest barrier to being able to come to a bipartisan agreement on these kinds of issues? And what are some solutions that you some solutions that might be presented?

SPEAKER_03

I can't say it's a damn Democrats, right?

SPEAKER_04

Yeah, yeah. Actually, it's not we we passed several cyber bills out of committee, the CIS extension, the pill, the pillar bill. We passed them all out of committee unanimously or almost unanimously and on the floor. I think we had several cyber bills that passed by voice vote. So it's not, I honestly have to say it's the Senate has the Senate rules, and uh, this is what I I'm sorry, Senate friends. This is when I the Senate rules really stop us from being able to move a lot of the bills that we pass out of the House because the way they run their clock, the way they run the floor, it takes a long time without without unanimous consent on a clock and debate time, it takes a long time to move things. So they don't move much legislation. There are must-pass bills like the NDAA and government funding and other things that we try to get to try to attach things to to get them done. But I'd say the biggest problem right now is the Senate rules because one person over there can stop something from moving forward, even if they don't care about that bill. They might say other people do. So I'm gonna hold that up until I get my way on something else, which we are actively seeing right now when it comes to certain cyber legislation. But I know my good friend Senator Peters is doing what he can to move some bills. He's is he retiring? He's retiring. Losing another giant when it comes to cybersecurity. He's doing what he's doing what he can over there to get move some cyber bills through. So he's been a good partner. Anyone other questions?

SPEAKER_03

Please don't be shy.

Using AI To Ingest Security Data

SPEAKER_01

I wanted to ask you, gentlemen, and thank you so much for the first time. Right here?

SPEAKER_03

Yeah, good.

SPEAKER_01

Okay, sorry. Thank you very much for your service. I am wondering if in some of your debate back and forth, which I know happens pretty frequently, if as looking at CIS's core mission and the way the cyber threat has emerged since it was created, arguably in 2000, the Homeland Security Act, would now be a good time to really get to the point of that cyber physical OTIT discussion and pull in using our friends' AI agenda agents, a lot of the data that has been accrued over time, vulnerability assessments of a site or a plant, the perimeter, a water treatment facility, all the records that are on file for permitting, for right of way, for insurance purposes, for mapping floodplain, for example. I just wonder if, in the calculus of the possible, if AI wouldn't be a help to ingesting data so that emerging threats and mitigating solutions could be arrived at a little better and a little quicker than we have in the past.

SPEAKER_04

Absolutely. And I I think there is support to have, at least I think there's congressional support to have the administration, the agency. Using the tools that are now available to it. We do know that Anthropic has made Mythos available to it, as well as other companies have made their AI. There are AI tools available to the agency. There is a delay, though, in the agencies administration taking them up on that offer right now. And I think the focus would be we need to get, we need to get, and I think I said this when I started, we need to get the White House to sign off on this because the clock is ticking. And we need to we need to be using this to show ourselves up. And we're not right now. There is support for to use these to defend ourselves, absolutely.

SPEAKER_03

Last question, anybody?

Rebranding CISA And Rebuilding Trust

SPEAKER_03

Yeah, sir, please. Mr.

SPEAKER_02

Garbarino, it seems like CISA, one of the problems they have is their Yeah, one of the problems they have is their branding, their image. With advent of AI, with kind of a retooling of the mission at CISA, where they done away with some of the more controversial elements, and now they're focused square on the things they're best at. Is this the change? Is there some way that you can help re rebrand it? So it's not just automatically people are like, oh, SISA, that's a trouble agency.

SPEAKER_04

Yeah. I think I honestly, Sean Plankey, I think, would have been perfect at that. I was very excited about his nomination. I think he could have gone into the room with the Freedom Caucus or whoever and actually explained to them what the agency did and would have they wouldn't. I think they would, he would enhance a lot of their concerns. He's not, he is now doing bigger and better things. Good for him. I'm still upset he's not the director. I think that will be the role of whoever they dominate to go in. And it's really the they're gonna have to go and convince some of the policymakers that they're just wrong. And we have the facts to show them that they're wrong and we have and we know it. Look, but we're getting, we've come a long way. Two years ago, we had appropriators, we have people putting up amendments to cut their funding by 25%. That's not happening anymore. There was a vote on the floor. I think a hundred Republicans voted to cut Simpson's funding by 25%. It failed, thankfully. But we're now we're past that, but we still have holdouts. My counterpart in the Senate is still would like to see some reforms happen over there when it comes to the agency. But I think whoever the next director is is going to have a that's gonna be a main part of their job is meeting with policy makers and the skeptical ones and convincing them that look, we understand you had a concern from 2020, but that's not the case. This is not what this is what we're doing. That's that was a very tiny part of work that Sissa did. This is everything else we do. And the more and more I think people are seeing that it is partnering with everybody on all different in every critical infrastructure sector in the FIFA World Olympics. I think more and more people are realizing that it's the ABC is doing some great work. So there's still holdouts, but that's gonna be the job of the I can't convince them. They think I'm a rhino. So it's I have to think you're a rhino or they know I'm a super rhino. Yeah, so they that's that's gonna be one of the jobs and I'll make sure when they finally when they finally nominate the person, I will make sure that meeting in that meeting I have with that person is is to let them know that's part of their duty. Is you gotta go into you gotta go into lines then and convince them that you're doing the right thing.

SPEAKER_03

Yeah, and I'll just let this my observation on that is when they get a permanent director of CISA, they may go in with the apartheid bent to them and then they'll see the threat landscape that's before them that didn't know about before they got there. And that's gonna change your attitude and it's gonna change your advocacy for the agency. And that that in time heals all wounds. And I think more time elapsed, the better off it's gonna be for SISA.

SPEAKER_04

Look, the fact that the president is look, he tried to cut some money in the budget again, but the fact with the budget, the fact that the president is nominating someone to be director, secretary is supportive of it's a it's a those are good signs. Those are good signs.

SPEAKER_03

Yeah.

Final Thoughts And Closing Banter

SPEAKER_03

Thank you very much for the conversation. Thank you for the questions and uh wish we had more time to talk about. Thank you very much for having me. I hope it was it was a form of I gotta say something. He does look like John Ratcliffe. Are you John? Are you John Ratcliffe? Long brother. Thank you very much. Thank you.