Episode #32
How Do You Rebuild Systems That Can't Go Offline? with Peraton's Tom Afferton
Tom Afferton [00:00:00]: If you're introducing security controls or a maintenance activity or modernization that interrupts that operation, then you're no better off than if there was a cyber interruption. Frank Cilluffo [00:00:16]: Welcome to Cyber Focus from the McCrary Institute, where we explore the people and ideas shaping and defending our digital world. I'm your host, Frank Cilluffo, and this week I have the privilege to sit down with Tom Afferton. Tom is president of the Cyber and Intelligence Service at Peraton, where he oversees a number of the most mission-critical entities inside the US government and has been there for a number of years. Prior to that, he also was at AT&T and many years at Northrop Grumman. Tom, thank you so much for joining us today. Tom Afferton [00:00:50]: Happy to be here. Frank Cilluffo [00:00:50]: So I thought I'd start at the beginning, and a lot of your clients are mission-critical. Tom Afferton [00:00:57]: Yes. Frank Cilluffo [00:00:57]: And very different than a traditional IT enterprise. And I'd be curious what that looks like. Why is that different and what your initial thoughts are there? Tom Afferton [00:01:07]: So when we look at a lot of the systems services that we protect, you have to think about the consequences of them not operating. When we think about, you know, a large-scale modernization as well, right, you have to think about the whole point of, of cybersecurity is to protect that institution, to protect its operability. So if you're introducing security controls or a maintenance activity or modernization that interrupts that operation, then you're no better off than if there was a cyber interruption, right? And so when we go through, again, thinking about something like a modernization, we take an approach we call sort of a layered uplift, which is you introduce that new capability in an incremental way. You make sure that it's instrumented so that as you introduce it, you're monitoring, is it doing what you expected it to do? And then over time, it takes on more responsibilities. And then ultimately, you can turn off the legacy environment. Now, there's of course prioritization involved, deciding, you know, where are you going to start? Where are you going to build in that resilience and redundancy? Something that Nick Andersen over at CISA has introduced, the term of ruthless prioritization. Frank Cilluffo [00:02:37]: Mm-hmm. Tom Afferton [00:02:38]: And I think that's helpful. It's helpful when thinking about resilience planning. It's helpful when thinking about planning resources up front, coordination, but it's then also helpful in thinking about incident response. And when I've heard him speak and he's explained it, what he's talking about is going beyond just prioritizing a category of critical infrastructure. It's understanding that, you know, the key mission, the crown jewel that we need to have keep operating, we need to understand the assets associated with it. Frank Cilluffo [00:03:13]: Mm-hmm. Tom Afferton [00:03:14]: So what GPU is that workload or that workflow operating in what cluster and what data centers powered by what part of the grid? And knowing that sort of connection between the critical infrastructure and the mission and the physical and the technical infrastructure allows you to then prioritize. Frank Cilluffo [00:03:32]: Because you really can't pause operations during an upgrade, right? Tom Afferton [00:03:36]: Absolutely. Frank Cilluffo [00:03:37]: So it's a challenge. These are— because you're also behind a number of critical systems that most Americans don't think about every day. Tom Afferton [00:03:44]: That's right. Frank Cilluffo [00:03:45]: One in particular that's gotten a little bit of news, and I know we can't get into great detail here, is FAA and the modernization. Tom Afferton [00:03:51]: Yeah. And that's an interesting one. Peraton's very proud to be part of that. The administration has framed that as one of the most important modernization projects in American history. And part of that is because, you know, our air travel depends upon it, right? It's critical to our economy, but it's also large and complex. One of my colleagues, Justin Sciaccio, is the one leading that for Peraton, and he recently met with stakeholders in the press along with Secretary Duffy to talk about the program. Frank Cilluffo [00:04:23]: Mm-hmm. Tom Afferton [00:04:23]: And what Secretary Duffy explained is that they were looking to do something radically different in terms of program management and bring in an integration partner. And Peraton were— we were fortunate to be selected to do that. And one of the reasons that they selected us is that we've brought a revolutionary agentic AI technology to the equation. Frank Cilluffo [00:04:44]: Mm-hmm. Tom Afferton [00:04:45]: And what Justin has been explaining that we're doing is we are ingesting I think it was like something 5.7 million records of schedule data as well as historical information about projects that have completed, and then have the AI start to do analysis around that so that we can stress test schedules, you know, we can identify gaps and whatnot. And he had this quote that sort of went viral that he said, like, we're not looking to replace the humans. We want to enable them to have superhuman insights. And that's what we're really— what we're finding here. And it's just the schedule, all the interdependencies, all the suppliers, all the different sites. It's just too much for one person to consume. And so providing those insights has been part of the value add there. Frank Cilluffo [00:05:29]: And, you know, you can't escape without us getting into a conversation around AI and agentic AI. Tom Afferton [00:05:34]: Sure. Frank Cilluffo [00:05:36]: What it means for threat hunters. But before jumping there, I mean, you've got technology time cycles that are moving so fast, but a lot of the systems you're dealing with here are in very different timelines. And we've had a number of discussions around the energy sector and grid, and we don't have to go there, but a lot of their OT systems are 25, 30 years old, and they're being netted with IoT devices and it brings about a new attack surface. How do you reconcile sort of that balance between a fast-moving tech cycle and not always so fast critical infrastructure sector? Tom Afferton [00:06:13]: So I'll jump to the answer, but then I want to go back and I will give you an example of the type of work that our folks are doing because I think it illustrates the sort of both ends of the spectrum. Frank Cilluffo [00:06:24]: And your an EE background, right? Tom Afferton [00:06:25]: Right, thank you. Yes. Frank Cilluffo [00:06:26]: Stanford and UVA. Tom Afferton [00:06:27]: So go Hoos. So— Frank Cilluffo [00:06:30]: Blue and orange. You know the history between the football uniforms between Auburn, UVA, and Clemson. Tom Afferton [00:06:27]: No, I don't. Frank Cilluffo [00:06:36]: All right. This is— sorry, but— Tom Afferton [00:06:38]: That's okay. Frank Cilluffo [00:06:39]: We will include this in the episode. So initially, the first football coach at Auburn was a football coach at UVA, brought the uniforms because they were so expensive. And then he went to Clemson and brought the uniforms. That's why it turned less than blue. It was a little more purple. So true story. Tom Afferton [00:06:55]: I did not know that. Frank Cilluffo [00:06:56]: Yeah. Tom Afferton [00:06:57]: So going back to the question about sort of the pace of technology, right? So if, you know, we were to talk 6 months ago, we would have been talking about buying back time to the analysts. And that's still important and something that I do want to talk about. We look now within the age of Mythos and, you know, the ability for agentic AI to produce vulnerabilities at an unprecedented speed and scale, right, the cutting edge is now thinking about automating remediations and sort of the bottleneck has shifted down. But before we go to either of those, I think it's helpful to just have— let's have a practical example. Like, this is a day in the life of some of my folks. Frank Cilluffo [00:07:37]: Mm-hmm. Tom Afferton [00:07:38]: I have some folks that are supporting CISA in the Code and Media Analysis Team, and they are involved with malware analysis and ultimately incident response for critical infrastructure. So without getting into any details, right, one recent situation- they were brought in as a result of some classified intel to take a look at some malware. They did some analysis to determine kind of what vulnerabilities it was associated with. They determined that it was associated with some edge devices and sort of double alarm bells went off because number one, they were edge devices that could be used in a carrier network, that OT was being used, basically programmable logic controllers sitting behind these edge devices that had no inherent security in them. So if you penetrated this edge device, you could get access to the programmable logic controllers and control that environment. And then secondly, these edge devices were also in federal civilian executive branch. So from— and you go back to in a critical environment, what do you need to think about? Well, one is consequences. Frank Cilluffo [00:08:49]: Mm-hmm. Tom Afferton [00:08:49]: So, okay, This has potentially wide-ranging impact. The second then is sort of thinking about it from a risk standpoint. And so now these folks are going off and looking on— they know the right blog posts. There is some of the monitoring that CISA does. Combine that with some tradecraft on the dark web to say, are these exploits being published? You know, are there any IP addresses associated with it? You then enrich that with some of the classified intel to make a decision. Is this something that we really need to focus some energy around in analyzing and potentially producing some remediation? And then you get to that step and now you've got to reproduce it. So a lab environment where we— I call it exploding the malware in a sandbox. Frank Cilluffo [00:09:34]: Mm-hmm. Tom Afferton [00:09:34]: See what it does, what its signatures look like, and then ultimately producing reports. And there's a lot of discussion. You think about who are we reporting to, what are we disclosing on all that. So that whole cycle, right, we have anywhere from 5 to 20 folks. That's it. All of critical infrastructure. So that goes back to what Nick Andersen's talking about, ruthless prioritization, right? So you got to think about consequence. You got to think about that risk. Tom Afferton [00:10:02]: So if we think about now AI in that process, one area is the sensemaking, and that goes back to buying back time from the analysts. All of that monitoring data is coming in from disparate sources. So how do we help them prioritize? Frank Cilluffo [00:10:20]: Mm-hmm. Tom Afferton [00:10:21]: And that can be an initial prioritization, but then you can go back and have the AI running in the background and continuing to correlate. Are new events coming and suddenly this was an isolated thing and now it's not? And so that's something we want to prioritize. We also think about it in terms of malware reporting and again, sensemaking of we're getting all this malware in, what should we prioritize? Frank Cilluffo [00:10:42]: Mm-hmm. Tom Afferton [00:10:43]: If I go to the backend, we think about building that remediation for the vulnerability and can AI help? We've had some really interesting discussions with CISA thinking about what's the right model or engagement with AI, meaning do they engage with tools that are available in, you know, a cloud environment or, going back to exploding it in a sandbox, right, do we have- and we've looked at this and helped them with this, is actually buy some GPUs and have a good old-fashioned on-prem environment that you're not paying for tokens. You bought the GPU and now you have a locally hosted environment that now you can unleash the malware on. So, you know, those are just examples of thinking through the practical day-to-day on where we can help. Frank Cilluffo [00:11:36]: That's actually a really interesting analogy. And something that just dawned on me is these are also lessons from a counter-IED perspective where we're applying in a cyber domain or a BSL-3 kind of lab approach. And, you know, Peraton has visibility across a wide range of customers, not only in the civilian agency department, which we've discussed here, but also the national security and Title 50 intel world. Any lessons from that work that you think pops up loud and clear in a civilian environment? Tom Afferton [00:12:16]: So one area that— it's interesting, as we brought the company together and as we brought my organization together, it was, you know, one of the first times— at the time it was actually as Chris Inglis was standing up the first Office of the National Cyber Director. Frank Cilluffo [00:12:34]: National Cyber Director. Yep. Tom Afferton [00:12:34]: I, when I met him, I described my organization and I said, we're kind of mirroring what you're trying to do in the government, which is promote that cross-collaboration across different stakeholders, right? Frank Cilluffo [00:12:46]: Mm-hmm. Tom Afferton [00:12:46]: All the customers that you want to interact, all the agencies I am supporting from one organization. Frank Cilluffo [00:12:51]: Mm-hmm. Tom Afferton [00:12:52]: And so one of the first things that came out was we talked earlier about the tidal wave of data and we help one of our customers in the I.C. deal with some of the largest datasets on the planet. Frank Cilluffo [00:13:06]: Mm-hmm. Tom Afferton [00:13:07]: And helping them take that mindset and approach and governance and bring that now into a civilian environment to say, hey, there's another organization that has dealt with this. Here is a roadmap for maturing through your data governance. Here are, you know, some data structures and here's a stack you can think about and all those different things. So that's something that I have seen carried from the I.C. environment over to the civil environment. Frank Cilluffo [00:13:36]: And it aligns well to Nick's approach for ruthless prioritization because it really is a signal-to-noise set of challenges. I mean, there's a lot of telemetry and there's a lot of data and sometimes you can drown in data if you don't know what you're looking for. And I do want to pull the thread on that in a second. But prior to that, you know, when you look at some of these mission-critical sectors, and I love the environment 'cause it really is an environmental set of issues. It's not just a tech issue. It's a governance issue, it's an integration issue, it's everything across the board. But what do most people underestimate in terms of the complexity? Is it the technology itself? Is it supply chains and, dare I say, lack of visibility into what that looks like? Frank Cilluffo [00:14:27]: Is it legacy infrastructure? Is it a people challenge or is it all of the above? And clearly it is a little bit of all of the above. Tom Afferton [00:14:34]: A little of all the above, but I'm going to pick the people challenge and I'm going to go back to one of my first programs at Northrop Grumman. We were doing a technology demonstrator on— it was actually critical infrastructure, state and local emergency service interaction. And we built a platform that would allow different emergency services at different echelons to be able to all interoperate. Frank Cilluffo [00:15:03]: Mm-hmm. Tom Afferton [00:15:04]: And we set up this whole demonstration environment. We had this, this whole exercise. It was at a university campus and there was a mock explosion and everything. And at the end of the day, we had this amazing technology. And in the middle of this crisis, all the different folks would do is radio check. Hey, look at that. We can talk to the police. We had not gone through and done the operational elements to say, how do we take advantage of this technology? And I remember being elated at first that, holy cow, look at how we did all these technical achievements. Frank Cilluffo [00:15:41]: Yeah. Tom Afferton [00:15:41]: And then quickly realized that the part that was missed was enabling the people to take advantage of that technology. Frank Cilluffo [00:15:49]: Well said. And our first preventer community and first responder community, that was a real-world set of issues as we come to the 25th year of the anniversary of the horrific attacks of 9/11. I think some of those lessons are still being learned and hopefully earned and learned along the way. I do want to sort of- since you brought up some of the AI discussions in different ways, from a threat hunting perspective, there's a big signal-to-noise challenge there as well. How are you looking at ways to, A, apply it yourselves or for customers to be able to enhance that capability? Tom Afferton [00:16:36]: So, a couple of thoughts there. One is that, you know, we're recognizing that what we've gotten good at is recognizing humans and what they are doing. And now we have to also be thinking about agents and what they're doing. Frank Cilluffo [00:16:57]: What does an insider threat model look like for AI agents? Tom Afferton [00:17:00]: Exactly. Exactly. The- you know, one of the things that we've looked at there, and it's a program that we have done with one of the research organizations in the DOD, along with one of our customer sponsors. Frank Cilluffo [00:17:20]: Mm-hmm. Tom Afferton [00:17:22]: Is having— we call it a wingman for red teaming. And so having AI kind of sit alongside and monitor what's being done, capture some of that, learn from it, and then make recommendations. So that's not a case where you have AI in the loop and you're displacing the human. You're kind of watching what they're doing, watching the experienced folks do it, capture that, and then capture— then come back and make some recommendations. Frank Cilluffo [00:17:52]: Is this an Air Force contract? Wingman, love it. You don't have to. Tom Afferton [00:17:56]: No, it was not. But in some ways, is that becoming obsolete because Mythos can just do it now? Again, I think that's at the cutting edge. And yet I look across the customer community and, you know, folks are still crawling, right? And there's a variety of challenges, some of which we talked about in terms of the human element and are people— do they have the AI fluency? Do they have the, the comfort level? Frank Cilluffo [00:18:28]: Mm-hmm. Tom Afferton [00:18:29]: But there's also some practical matters. A lot of, you know, when I poll some of my teams that are on the front lines supporting customers in day-to-day cyber operations, there's still a lot of data jockeying going on, you know, and getting the data in the right place and making sure that you have data integrity and whatnot. There's also the clear demand signal that, you know, meet us where we are. Don't give us a tool that's going to operate in a commercial environment. Frank Cilluffo [00:19:03]: Mm-hmm. Tom Afferton [00:19:04]: You need to be able to operate in our environment. And, you know, there are different ways to do that. You can do some things on the low side and go through cross-domain, bring some products up, further enriched on the high side. But it also means meet us where we are from an operational process standpoint. And I know that, you know, you could roll your eyes and say, well, no, your whole point of AI is you need to build new processes. But, you know, we're, we're talking about sergeants and folks that— Frank Cilluffo [00:19:31]: Absolutely. Tom Afferton [00:19:31]: That they, they are, what they are taught is to follow the procedure. Now, we do need to work to help modify those procedures to take advantage of the technology. But you can't just throw this over the wall and say, isn't this