President Trump’s national cyber director showed up at Black Hat with a supportive message for private industry: Your threat model doesn’t include us regulating you
“We want to make sure that we are working hand in glove and collaboratively with industry,” Sean Cairncross said at the start of an onstage interview here on Tuesday afternoon. “A regulatory regime, one, would not only strangle growth, development, and innovation and be enormously harmful to the industry…it would be obsolete 48 hours after going through whatever processes it had been doing through.”
That attitude could not have been news to anybody in the audience. The Trump administration has leaned heavily into the idea of liberating companies from perceived regulatory shackles, as seen in last July’s “AI Action Plan.” (Emphasis on “perceived”; the Biden administration’s approach to cybersecurity mainly involved detailed advice and encouragement to companies, backed up with new requirements for federal contracts.)
Trump’s executive order on cybersecurity, released in March, continued that free-market approach, notwithstanding its endorsement of federal action to accelerate the deployment of post-quantum cryptography. Cairncross said the EO was “designed to be non-regulatory.”
He also expanded on the order’s concept of “shaping adversary behavior,” but used more moderate language than his boss. Where Trump’s cover letter for the EO said attackers “will pay the steepest and most terrible price,” Caircross characterized that goal as “introducing the concept of deterrence in this space.”
He added: “Those who may seek to do us harm know that it will not be cost-free,” citing recent actions against the overseas instigators of “pig butchering” scams.
Speaking on a panel after Cairncross’s appearance, Brett Leatherman, assistant director of the FBI’s cyber division, cited the bureau’s “Operation Riptide” campaign as an example of that strategy in action, saying it has so far netted more than 200 arrests and six international extraditions.
A Few Careful Omissions
But the sales pitch Cairncross gave for Trump’s approach to cybersecurity also left out many points that should be on attendees’ minds. For example, in recent months, this administration has vetoed the release of Anthropic’s Fable 5, fearing that its security capabilities could be weaponized by opposing countries, and then required Anthropic to make changes to that model. Trump has also toyed with the idea of the government taking a partial ownership stake in OpenAI.
That sort of aggressive involvement could not have been what Cairncross had in mind when he said: “This is a relationship between government and industry that I don’t think has existed before.” But anybody in the audience working at an AI-security startup could be forgiven for hearing a different meaning in that sentence.
Cairncross also did not discuss the turmoil Trump has inflicted on the Cybersecurity & Infrastructure Security Agency (CISA) since last January. CISA, created in Trump’s first term, has seen a third of its workforce exit while the White House has disbanded its election-security efforts and tried to sandbag the careers of prior CISA directors Chris Krebs and Jen Easterly, both of whom upheld the integrity of the 2020 election despite Trump’s repeated lies about his own loss.
Recommended by Our Editors
White House Cybersecurity Strategy Is Light on Details, Big on Consequences
I Test Portable Power Stations for a Living. This FCC Ruling Might Put Me Out of Work
Black Hat 2026: From Rogue AI to Roblox Privacy, the Most Terrifying Warnings Coming to Vegas
Weakening the government’s lead information-security agency can have real-world consequences, as news of a run of hacking attempts on water utilities has made clear. Cairncross didn’t mention that, much less Trump’s evidence-free assertion that Minnesota Gov. Tim Walz (D) was somehow responsible for attacks on water departments in his own state.
CISA has begun hiring back to replace lost staffers and is prioritizing its infrastructure-security efforts. Acting Director Nick Andersen, speaking on the same panel as Leatherman, warned that the agency would have to practice “ruthless prioritization” of its efforts.
“We’re focused on things that are going to be most consequential,” he said. “We’re all going to have to make risk-tradeoff decisions here.”
On Wednesday morning, the founder of Black Hat told attendees that ignoring the political dimensions of their work was itself a risk. “Technology is political,” Jeff Moss said before the conference’s morning keynote. “If we don’t embrace it, politics will happen to us.”
About Our Expert
Rob Pegoraro
Contributor
Experience
Rob Pegoraro writes about interesting problems and possibilities in computers, gadgets, apps, services, telecom, and other things that beep or blink. He’s covered such developments as the evolution of the cell phone from 1G to 5G, the fall and rise of Apple, Google’s growth from obscure Yahoo rival to verb status, and the transformation of social media from CompuServe forums to Facebook’s billions of users. Pegoraro has met most of the founders of the internet and once received a single-word email reply from Steve Jobs.
- AT&T Is Raising Rates on Many Older Plans Again
- United Airlines Latest Carrier to Ban Humanoid, Animal-Like Robots
- Starship’s 13th Test Flight Ends With a Lucky Splashdown
- How Safe Is Your Waymo? Report Finds They Crash 68% Less Than Human Drivers
- Which US Wireless Carrier Is Best? 3 Recent Reports Crown Different Winners
- More from Rob Pegoraro
