Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Deterrence And Policy topic

No spam. Unsubscribe anytime.

Think-tank director urges 'cost imposition' and persistent engagement; warns AI and supply-chain risks to U.S. cyber defenses

Ahead of the Threat (podcast) · July 23, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Frank Salufo of the McCreary Institute told the FBI podcast the U.S. must pair denial (defense) with deliberate cost imposition—diplomatic, economic and law enforcement measures—and warned that AI, supply-chain gaps and preplaced capabilities (e.g., Volt Typhoon) raise new risks to critical infrastructure.

Frank Salufo, director of the McCreary Institute for Cyber and Critical Infrastructure Security at Auburn University, told Ahead of the Threat that the United States must pair defensive measures with deliberate efforts to impose cost on adversaries.

"If you look at one and not the other, you're missing out on the opportunity to ultimately influence the behavior of our adversaries," Salufo said, arguing that denial (hardening systems) and cost imposition (diplomatic, economic, law-enforcement and, as a last resort, military options) must be mutually reinforcing.

Sal ufo discussed McCreary's recent "code red" analysis, which grouped multiple PRC campaigns — referenced on the show as Salt, Flax and Volt Typhoon — and warned that Volt Typhoon "crossed a line" by preplacing capabilities on critical infrastructure. "This was a red line," he said, adding the campaigns collectively signal intent and capability and therefore warrant a coordinated national response.

The conversation turned to artificial intelligence. Salufo said frontier-model companies and responsible disclosure can help defenders, but warned that AI lowers the bar for attackers, citing voice cloning and more convincing fraud techniques. He said the government's known-exploited-vulnerabilities list has grown rapidly and that defenders must move toward continuous vulnerability management rather than monthly patch cycles.

Salufo emphasized workforce and education, praising experiential K–12 programs such as the Alabama School for Cyber Technology and Engineering (ASCTE) and urging earlier, hands-on exposure to build a sustainable talent pipeline. He also previewed a McCreary task force report with the U.S. Chamber of Commerce on regulatory harmonization that aims to reduce compliance burdens so companies can focus time on security.

"We need persistent engagement," Salufo said. He added that integrating military, intelligence and law-enforcement authorities and expanding operational collaboration with industry and allies is critical to shaping adversary behavior over time.

Leatherman closed by noting the FBI is building tools and partnerships to support a more proactive posture and invited industry and academic partners to participate in implementation discussions.