Back to MCSC_2026

MCSC 2026: Intelligence View – Cyberspace as the Future Arena of Political Conflicts?

240 lines English Added about 1 month ago

Transcript:

240 lines
(speaker_0)

Good afternoon, everyone.

(speaker_0)

How wonderful to be here and have the opportunity to be with you.

(speaker_0)

From Brunswick Group, a partner of the Munich Cybersecurity Conference, and I'm a former British national security official and led on cybersecurity, the cybersecurity program of the UK.

(speaker_0)

At the moment, I'm short two generals.

(speaker_0)

So, u- unless they come up, I- you're going to have...

(speaker_0)

Uh, please, please come up.

(speaker_0)

Who have I got?

(speaker_0)

Here we, here we are.

(speaker_0)

Come on up, and I'll introduce you when you're here.

(speaker_0)

How are you?

(speaker_0)

Nice to see you.

(speaker_0)

Fantastic.

(speaker_0)

So the title of this, um, the title of this session is Cyberspace, Uh, the Future Arena of Political Conflict.

(speaker_0)

I think we might argue that, uh, it isn't the future, it's the present.

(speaker_0)

But there we are.

(speaker_0)

And, um, uh, who better to speak to this than two senior, uh, intelligence leaders with practical experience of conflict in the cyber domain and beyond?

(speaker_0)

Um, Vice President of the German Intelligence Service, the BND, Dag Baer, and, uh, General Paul Nakasone, who is former commander of the US Cyber Command and of the National Security Agency.

(speaker_0)

So, um, I'm gonna ask a few questions just to get, get you going, then we'll see what dialogue we get.

(speaker_0)

Um, Dag, maybe I could start with you.

(speaker_0)

I mean, governments are the actor of last resort in this domain, and what's having greatest deterrent effect from your perspective?

(speaker_0)

What balance are you making between capability, attribution, alliances, or resilience?

(speaker_1)

Yeah.

(speaker_1)

Paddy, thanks, thanks a lot.

(speaker_1)

Um, in the weeks preceding that particular conference, Paul and myself were trying to catch up.

(speaker_1)

Little did we know that we would do so with all of you attending our catch-up.

(speaker_1)

Um, so, but starting with your question, Paddy, I mean, it's pretty loaded at the very moment.

(speaker_1)

And knowing about your background, uh, no wonder as why you're just putting me on the spot with that one.

(speaker_1)

Because talking about deterrents, uh, at the very moment, uh, we have an ongoing discussion in Germany to put active cyber defense into legislation.

(speaker_1)

So publicly discussing what you're able, uh, to do against cyber threats, uh, and being restricted by law is, uh, not a very clever way in exposing your strengths and weaknesses.

(speaker_1)

Uh, but however, here we are.

(speaker_1)

Um, I think we heard in one of the preceding panels that, uh, resilience is important.

(speaker_1)

I still w- would say so.

(speaker_1)

It, uh, it is.

(speaker_1)

Um, it's a base layer you need to be resilient.

(speaker_1)

But I would s- argue that from a German perspective, we're still not up to standard.

(speaker_1)

And however, uh, just being resilient alone, you can't absorb all of the threats by just being simply resilient.

(speaker_1)

You need to be active in defending.

(speaker_1)

Whether you call it active defense or just active measures, I think i- is just semantics, uh, not capabilities.

(speaker_1)

Um, so you require capabilities, uh, from a national perspective to fight cyber threats.

(speaker_1)

Um, and openly talking about those is a very difficult, uh, subject, because you're losing a point in deterrents.

(speaker_1)

Yeah.

(speaker_1)

Um, uh, a part of deterrents is creating ambiguity.

(speaker_1)

Uh, so leave your opponent, um, guessing what you're able to do against the threats, uh, especially when they're more upstream.

(speaker_1)

And it's not, I would say, not desirable to having red lines, um, discussed in public, especially when those red lines only apply to your own actions.

(speaker_1)

So, i- if you publicly state what you not do, it's not very deterrent.

(speaker_1)

Uh, because then you just, uh, elaborate on a plan that others can use to circumnavigate your capabilities.

(speaker_1)

Um, so that's, uh, the, I would say, sort of the strategic advice I would give for free.

(speaker_1)

Um, uh, uh, uh, the thing is...

(speaker_1)

I mean, and that there's, there's a reason to that.

(speaker_1)

Um, I just see that talking about deterrents, uh, at least, uh, for almost two decades, for historical reasons, has become sort of a lost art.

(speaker_1)

Um, when it comes to, um, how you deter, is cross-domain deterrents working?

(speaker_1)

So can you deter cyber r- risks by switching to a different domain?

(speaker_1)

Uh, it would be very interesting, uh, question.

(speaker_1)

But, uh, coming back to, to capabilities, not being too, um, overly elaborate on that one.

(speaker_1)

Um, if you actively apply your capabilities, um, you, to some extent, uh, have a de- disclosure of what you're able and doing.

(speaker_1)

Not only what you're allowed to do, what you're capable of doing.

(speaker_1)

So, um, I'll use an example how you try to deal with that particular problem.

(speaker_1)

So in NATO, they have this so-called SCPA process, sovereign cyber, um, provided by, uh, voluntary allies.

(speaker_1)

Uh, it's, for those of you not in the know, um, im- imagine a dark room painted black.

(speaker_1)

It's pitch black, no windows.

(speaker_1)

There are mice in there you are trying to catch.

(speaker_1)

And now you get in with five different people, uh, bringing in black cats.

(speaker_1)

So, and those black cats are hunting mice in that room.

(speaker_1)

So, uh, and of course, they are successfully doing so.

(speaker_1)

But, uh, in the aftermaths, everybody can claim, "Is- wasn't my cat."

(speaker_1)

Um, or, "It was my cat."

(speaker_1)

So how you disguise your capabilities in a construct like this is a very interesting problem, because you're going to want have your opponents just being there.

(speaker_1)

And my last point is attribution.

(speaker_1)

...

(speaker_1)

um, I think that's a very difficult subject, especially i- in Western democracies, eh, to have lawful actions a- against your opponents if you're restricted by l- legal framework requiring you to attribute whom you're acting against it.

(speaker_1)

So, that's a problem with, uh, us covering several dilemmas.

(speaker_1)

And I'll leave it to that.

(speaker_0)

Uh, t- that's great.

(speaker_0)

Paul, can I, can I bring you in?

(speaker_0)

I, you were a great advocate of collaboration, practical collaboration, to counter cyber adversaries, including sending US folk forward in a way that hadn't been done before.

(speaker_0)

H- how do you see that partnership and collaboration now at a time of, you know, uh, unprecedented geostrategic tension?

(speaker_2)

Well, I think first of all, let me, uh, congratulate Peter and, uh, all the organizers.

(speaker_2)

First time I've ever stood in line to come into the m- Munich Cyber Security Conference.

(speaker_2)

Fantastic.

(speaker_2)

It's great.

(speaker_2)

Um, but three o- three thoughts here.

(speaker_2)

So, first of all, I, I think the national cyber director this morning, Cain Cross, said very, very well.

(speaker_2)

Sean said, "Hey, we don't want to be alone.

(speaker_2)

Uh, we don't want to be alone, no one wants to be alone in cyberspace.

(speaker_2)

You are much better together than you are alone."

(speaker_2)

That's the first piece that we should always remember.

(speaker_2)

The second is that, um, you know, working together doesn't mean just governments, armies, militaries working together.

(speaker_2)

It also means working with the private sector, working with academia, working with others that are in every single day operating in cyberspace.

(speaker_2)

And the last thing I would just share with you, Paddy, is just, uh, again, there are a number of different options in terms of what you want to do in cyberspace, but it begins with information and sharing information.

(speaker_2)

And information goes to intelligence, and intelligence goes to techniques, and techniques goes to common baseline upon which we operate.

(speaker_2)

You have to begin, though, with that first part is, we're gonna share information.

(speaker_0)

So, so you've referred to the private sector role, which I, I strongly agree with you.

(speaker_0)

And, and Dag, I wonder, um, whether you could comment on, o- on how you're seeing that evolve, the public-private partnership and, uh, and the weight we put upon private actors to, uh, eliminate tasks for you, so to speak.

(speaker_1)

I have to be very candid about this.

(speaker_1)

I mean, and it's speaking for, uh, an organization which is, um, at least born out of, to some extent, um, governmental, um, actions, uh, thereby, you know, subject to a certain level of

(speaker_1)

bureaucracy, of fighting for funding, uh, for size, uh, and the ability to scale, uh, which is r- by that threat's landscape we are just addressing over here, uh, is something which is a core capability.

(speaker_1)

You need to able, to be able to scale, uh, to answer the threat.

(speaker_1)

Um, so that's, that's, uh, the first remark I would, um, offer, Paddy.

(speaker_1)

And the second one is, um, we are at a structural inflection point, I would say, uh, because most of the technologies which, uh, in the nearer future or even in the present are already required to address a threat

(speaker_1)

landscape is not owned by governmental agencies.

(speaker_1)

So, I mean, you've been, at least touched on AI already.

(speaker_1)

So, most of the capabilities we will require in the future, eh, eh, from an intelligence agency perspective is not owned by us.

(speaker_1)

Yeah?

(speaker_1)

It could be made available to us, and what kind of mandate and contract, uh, remains to be seen.

(speaker_1)

But most of the knowledge with its, uh, provided to intelligence in the future, uh, will be gained through any kind of AI, AGI, uh, and provided to, uh, intelligence

(speaker_1)

agencies.

(speaker_1)

So, how you gonna manage, um, I would say, uh, governance of knowledge and how it is gonna be applied?

(speaker_1)

It has to be a subject of intense collaboration between intelligence agencies, uh, in the industry.

(speaker_1)

And, you know, you have been listening to Sean talking about technology stacks.

(speaker_1)

Most of those technology stacks, uh, if I w- if I like it or not from a BND perspective, i- it's still owned by the US.

(speaker_1)

Any kind of large language model, uh, most of our opponents can use for free, uh, is located, uh, either in Silicon Valley or, or where else.

(speaker_1)

Um, so, and I have to come to terms with that particular, uh, uh, s- very simple fact and just make it work in our advantage as well.

(speaker_1)

How you gain knowledge, um, how you govern it, and how you just make the governance into your advantage in covering it, uh, will be of, I would say, the highest priority for almost any intelligence agency.

(speaker_1)

And if you just go back to classical cyber threat intelligence, um, we already are there, that we just require corporate business providing, uh, cyber threat intelligence, um, to make it manageable, uh, from our perspective.

(speaker_1)

So, there are many companies, uh, in the room already, uh, I'm not naming them, uh, who provide substantial support to what intelligence agencies do use nowadays.

(speaker_2)

S- can I just follow up on that?

(speaker_2)

I think it's important.

(speaker_2)

Um, we've talked about public-private partnership for many, many years.

(speaker_2)

We've done more, I think, over the past couple years than we had done in the previous five years.

(speaker_2)

But we're not at a level that we should be happy with.

(speaker_2)

The scope and the scale and the speed of what we're doing now does not help us enough to be able to address what our adversaries are doing to us.

(speaker_2)

And so we have to think, I, I believe, much more creative in terms of what we're doing.

(speaker_2)

So, l- let me give you an example.

(speaker_2)

Um, let's figure out what our competitive advantages are on the public side and what are the competitive advantages on the private side.

(speaker_2)

I will tell you, on the public side, one of the things is we have incredible intelligence, and we have incredible ability to provide that to a number of different partners.

(speaker_2)

You know, how do we do that in a way that we share and we protect our sources and methods?

(speaker_2)

The second thing is, I would, I would give you an example.

(speaker_2)

One of the things that we had done quite readily at the National Security Agency and US Cyber Command is provide free scanning to the defense industrial base that wanted to have it- ...

(speaker_2)

scanning, scanning.

(speaker_2)

It's just incredible in terms of what you're able to do with just a simple thing like that, or protective DNS, any of that type of work.

(speaker_2)

This is what we have to do, and we have to do it at a much greater scale and much quicker than we're doing, you know, than we've, we've ever done before, Paddy.

(speaker_1)

So, uh, uh, if I may come, um, so there is a, a general transformation in intelligence going on anyway.

(speaker_1)

So what I would call sort of a democratization based in capabilities as well as in targets.

(speaker_1)

Yeah.

(speaker_1)

Because we are just, uh, that's not, we're not talking about a classical threat landscape.

(speaker_1)

It's evolving, you know, it's all encompassing.

(speaker_1)

It's a whole of government threat landscape already.

(speaker_1)

So the citizens are a target.

(speaker_1)

Corporate business is target.

(speaker_1)

Critical infrastructure is target.

(speaker_1)

So, um, uh, you have to have corporate business industry, uh, a- and private business subscribe to the simple fact that they require intelligence as well.

(speaker_1)

So, and as just Paul elaborated, if you can provide methodology to do so, uh, that- that's- that's fair.

(speaker_1)

Uh, we require, you know, the, the corporate business capabilities to be able to scale, uh, where the classical target set is attacked, um, and the, you know, the abundancy of data, which is just provided by having a democratization of

(speaker_1)

target sets is just flabbergasting.

(speaker_1)

Yeah.

(speaker_1)

So I have to, to, to cope with that, uh, as a society, not only as an intelligence agency.

(speaker_2)

Yeah.

(speaker_1)

So-

(speaker_2)

But I think it, but I think it's even simpler than that.

(speaker_2)

I just, uh, you know, I, I firmly believe that it's, you know, in terms of how do we set this up between what our government is doing and what we can provide.

(speaker_2)

A- again, coming back to what we've done at NSA and Cyber Command, two different organizations, cybersecurity collaboration center under advisement, utilizing Slack channels to be able to provide this information in an unclassified facility, doing this from a number of different locations, and just having a conversation ongoing.

(speaker_2)

One of the most important things is, you know, there are things that the private sector sees that we certainly don't see.

(speaker_2)

We don't have the authorities and, and sometimes the policies to do things in different parts of the world to include our own country for very good reason.

(speaker_2)

But boy, they do.

(speaker_2)

And wouldn't it be nice to be able to understand what's going on?

(speaker_2)

And then we could say, "Hey, this is what we're seeing as well."

(speaker_0)

So-

(speaker_1)

You got us all, you know, up and running, Paddy, with that one.

(speaker_1)

Um, there are two things I just, uh, want to sort of re- no, one, uh, simple fact I'm gonna re-address that is, um, especially if you look down and in, into the nations, um, and I, we just started off by,

(speaker_1)

uh, we should be able to share information.

(speaker_1)

So we are still in silos and stove-piped, um, whether it's government, whether it's non-governmental, whether it's within the government, uh, how are you gonna share information with other governmental agencies?

(speaker_1)

I mean, it's so over-regulated.

(speaker_1)

Um, e- even if I just be, I'm able to obtain information, um, it's not simply, uh, allowed to share it.

(speaker_1)

So that's, that's, we are living in silos.

(speaker_1)

We continue to do so.

(speaker_1)

Um, and this is detrimental to one important factor, which hasn't been, uh, brought out, uh, I would say, to, to the right level.

(speaker_1)

This is speed.

(speaker_1)

Uh, um, we are just living in an area of continuous contestation under ever-more time constraint.

(speaker_1)

So the, the timelines are compressed evermore, and the more we see in AGI, timeline's getting ever smaller, and especially for Western democracies, w- when you see your decision cycles, uh, um, it, it's, they're not adaptive to the

(speaker_1)

speed we're seeing over there.

(speaker_1)

So talking about attribution in the first question, how much time it does take to have at least, um, a lawful attribution.

(speaker_1)

I mean, that's, uh, that may take a year.

(speaker_1)

Um, we are talking about, uh, a fracture of a day, which is required to attribute something to, to cope with that.

(speaker_1)

So, uh, this is just, uh, I'm always puzzled by the simple fact that we don't talk timelines, uh, very much.

(speaker_1)

Of course, I have a military background as, as well as Paul.

(speaker_1)

So we are, you know, well-versed in just treating timelines appropriately, but, um, we had, we had a popular saying in one of the operational theaters, we have been years of shared enterprise.

(speaker_1)

Um, and you have the watches, we have the time, uh, I think we should reconsider those sayings because there is not time enough.

(speaker_0)

So, so an elephant in the room, uh, whenever Europeans and Americans are getting together, is the question of sovereignty, and in particular technology sovereignty.

(speaker_0)

And I'm not gonna put Dag on the spot because it's deeply unfair to do so.

(speaker_0)

But Paul, I am gonna put you slightly on the spot, and I'm really interested in how we capture the advantage we get through the technology partnership with US companies.

(speaker_0)

And I'm thinking of the lesson of Ukraine, where Ukraine, in a digital sense, was saved in part because of its partnership with great American companies like-

(speaker_2)

With Starlink, with Microsoft-

(speaker_0)

...

(speaker_0)

Paul-

(speaker_2)

...

(speaker_2)

a number of different pla-

(speaker_0)

Yeah.

(speaker_2)

So this is, this is the whole idea of speed, right?

(speaker_0)

But how do we measure that-

(speaker_2)

And ex-

(speaker_0)

...

(speaker_0)

and express it in a way that policy-making can?

(speaker_2)

But, but I, I think this is a, this is a really good, uh, exemplar.

(speaker_2)

Take a look at what companies like Microsoft have said with regard to their principles and how they're going to operate.

(speaker_2)

Those are important ways upon which we look at that.

(speaker_2)

They're saying, you know, we value the idea of securing our information and yours.

(speaker_2)

We value the idea of being able to work with trusted partners.

(speaker_2)

These are a series of principles, and I think, uh, American companies have done a very, very good job at that.

(speaker_2)

And, and you pointed out one example.

(speaker_2)

There are others that I would say, but as we look at artificial intelligence, as we look at quantum computing going forward, you know, I think that this is going to be the area upon which, you know, like it or not, you're going to, you're gonna work very, very closely with a series of American companies that are on

(speaker_2)

the forefront for doing this.

(speaker_2)

And I think those companies have been very forthright in being able to develop these type of principles to work with the broader world.

(speaker_0)

So I'm interested in capturing the risk in any kind of decoupling.

(speaker_0)

That's the bit that's really interesting on the previous panel.

(speaker_0)

If you're beginning to see people saying, "Well, we're not going to be able to work with some American partners in some fields," that question of how you calculate the loss you get in shared cybersecurity, that's the thing I think would almost be of most value to policymakers.

(speaker_0)

Do you want to have a go?

(speaker_2)

So in the United States, two friendly nations to our north and south, two large oceans to our east and west, do not protect us from, you know, the malware, uh, the attacks, uh, the domain of cyberspace today.

(speaker_2)

And so if we are going to couple, we, our nations are going to decouple, we do so at our own risk.

(speaker_2)

We are much better working together.

(speaker_2)

And so the idea of decoupling technology, decoupling information sharing, for someone that had done this in the public sector, it's something I'm very concerned about.

(speaker_0)

And now I'm going to put you on the spot.

(speaker_0)

You have 52 seconds- ...

(speaker_0)

in which, in which, just to give, knowing what you're doing now that you're a- you're after, o- out of service, and you're, and you're, or out of the service and are, are, are working now with the, in the private sector, how should this audience be thinking about

(speaker_0)

that challenge of AI and quantum as it comes towards them?

(speaker_0)

What, what, how should they prepare, be preparing themselves this year to do something different?

(speaker_0)

Go ahead.

(speaker_2)

So in 30 seconds, I will tell you that, uh, I am also at Vanderbilt University where I head the Institute of National Security.

(speaker_2)

We welcome all to our spring summit, '23/'24, where the chairman of the Joint Chiefs will be talking along with former Secretary of Commerce Gina Raimondo and former CENTCOM commander Erik Kurilla.

(speaker_2)

In terms of quantum computing, as we think about 2026, I would offer to all of you, I think this is the first year, and I, Recorded Future captured this very, very well, this is the first year we're going to start seeing nations expand more, more capital into

(speaker_2)

post-quantum cryptography.

(speaker_2)

We have to ensure that our national security systems, our financial systems, our ability to communicate are going to be secure in a quantum future.

(speaker_2)

And whether or not that's 2035 or it's sometime before that, Paddy, this is what you're going to see, I think, in 2026 is a movement towards that type of security.

(speaker_0)

You've got to admit, I covered a lot of ground, eh?

(speaker_1)

Ye- yeah.

(speaker_0)

So-

(speaker_1)

Do you have five seconds, Paddy, before we just-

(speaker_0)

Oh, fine, fine.

(speaker_0)

If no, I don't.

(speaker_0)

You have five.

(speaker_1)

...

(speaker_1)

crown it?

(speaker_1)

So not putting me on the s- spot with regard to politics.

(speaker_1)

So as an intelligence professional, I can afford to be very pragmatic.

(speaker_1)

So I'm not overly concerned about politics, but about de-risking and not decoupling.

(speaker_1)

Thank you.

(speaker_0)

Yeah.

(speaker_0)

No.

(speaker_0)

Fantastic.

(speaker_0)

So, um, we've covered a lot of ground.

(speaker_0)

I'm sure you'd like to join me in thanking the two, uh, excellent generals, uh, in our conversation.