Skip to main content
Jen Easterly

Jen Easterly

Former United States Director of the Cybersecurity and Infrastructure Security Agency

Aug 20, 2026

8:39
two
8:40
minutes was a big deal.
8:41
It actually took Erno Rubik a full month to solve the cube, and he invented it.
8:45
So I was able to amass this collection of Rubik's Cubes.
8:48
But it's kind of amazing.
8:50
I still think back to that period of time as the people looking at this little kid were you know, not believing that I could actually solve this puzzle.
8:58
And it told me a lot from a very young age about defying stereotypes and setting very high expectations.

9 MINS LATER

18:06
Yeah, exactly.
10:06
Like, are we at a sweet spot right now? What's your take on it?
10:11
Well, look, there's a quote that I love.
10:14
by a guy called Edward Wilson.
10:16
He was a Pulitzer Prize-winning biologist, and I read some of his books when I was at grad school in Oxford.
10:22
He had this great quote.
10:23
He said it in the 90s, but it's so relevant today.
10:26
So the problem with humanity is that we have Paleolithic emotions, medieval institutions, and God-like technology.

8 MINS LATER

18:16
What's my role as a practitioner, as a leader, when all the AI is taking my job?
21:42
How, uh, woeful a state is, is CISA in, and how, how much does that, as well as other changes the administration made, um, leave us more vulnerable or, or less able to address the vulnerabilities that you talked about?
21:54
CISA, when I became the director in twenty twenty-one, was actually the newest agency in the federal government.
22:00
So it's a pretty new entity.
22:02
It was stood up, um, wisely in the first Trump administration in November of twenty eighteen to fill two roles, really to serve as America's civilian cyber defense agency and the national coordinator for critical infrastructure resilience and security.
22:17
So the idea was, um, CISA played the lead role in understanding, managing, and reducing risk to critical infrastructure.
22:25
And CISA was not a regulatory agency, didn't collect intel, didn't do law enforcement.
22:30
It was really all about working by, with, and through partners to catalyze an understanding of the threat environment and then through technical expertise, reduce risk to that infrastructure.

9 MINS LATER

31:21
Yeah.
1:13
Jen, let's start with you.
1:14
Awesome.
1:14
Thanks so much, Casey and Peter.
1:16
I'm so excited to be here with you.
1:18
It's great to see you again.
1:20
Um, so you and I, I think, first, uh, got acquainted almost four years ago when you launched Cybermindz.
1:27
And just my kinda journey on this, uh, when I first got to CISA, it was the summer of twenty twenty-one.

5 MINS LATER

6:43
-for the first time, and that's effectively we built Cybermindz, the organization, around this principle methodology that we're now bringing to teams around the world.
43:17
To further that sort of conspiracy in the next election, maybe that's one of the reasons why they're not being as, I don't know, forthcoming or as visible as they have been, as your agency has been in the past?
43:30
Look, the truth of the matter, Katie, is—and obviously I've been out of CISA since January of 2025— But they've effectively decimated CISA's capability and capacity, and certainly its capability and capacity to provide support to state and local election officials, both from a cybersecurity and a physical security perspective.
43:51
So much of the capability that we've built no longer exists.
43:55
Now, I think it's really important to recognize, though, that Americans, just because CISA does not have its capability, that Americans should not have confidence at the state and local level.
44:07
And just to be clear, there are a lot of reasons why Americans should have confidence.
44:11
Look, over 97 percent of jurisdictions have paper ballots, right? Paper ballots that can be counted, recounted, audited.
44:19
Election infrastructure is largely not connected to the internet, so it's very hard to hack.
45:25
What is your argument?
16:57
Uh, it's been in the headlines, cybersecurity, because of the announcement by Anthropic of a new model called Mythos, uh, Jen, which you referred to, which was quickly followed by a similarly capable model from OpenAI called GPT 5.5. W- what do you make of these models, uh, for cyber threats specifically? How big of a game changer is this even just compared to the previous generation of models, and how do you think about how the government is handling the onslaught, the advent, I should say, of, of these models, uh, so far?
17:30
Yeah, I mean, I, I think it is a step change.
17:32
You know, I, I do not have direct access to these models, but I've spent a lot of time over the last month having, um, conversations with folks who are actually using them and employing them, and everything that I have heard is they are a step change in the ability to find vulnerabilities in infrastructure.
17:52
And again, going back to sort of the canonical issue that has led to the cybersecurity problem set, it's all about these flaws and defects which we have normalized to call vulnerabilities in the code.
18:06
And so these capabilities, Mythos Preview, which was released, a constrained release as part of An- Anthropic's, um, what's called Project Glasswing, and then shortly followed by, uh, OpenAI's 5.5 GPT, uh, released in a, uh, also a constrained way through their trusted access for cyber.
18:28
The key thing to know about these is they have a, uh, extraordinary ability at sc-Speed and scale to find those flaws and defects in code bases, right? Now, I think the really important thing, and actually like the fascinating thing to me, you guys, is the fact that you had a private sector companies, first Anthropic and then OpenAI, voluntarily decide to constrain deployment.
18:56
I, I think that is pretty incredible when you think about the history.

7 MINS LATER

25:49
But as you look out over the next two to three years, during this window where we could see disruption, does offense or defense have a greater advantage in this new age of AI-enabled cyber a- as these capabilities continue to develop?
29:29
Dan Driscoll.
29:29
So- so, y- you know, and I don't know Secretary Driscoll.
29:33
I've actually heard very positive things about him, but I don't know him.
29:37
But your point is a really good one, because we're in such a unique moment in history.
29:41
When I was a cadet, I saw the fall of the Berlin Wall.
29:44
When I was an instructor there, it was the fall of the Twin Towers.
29:47
Now we're at this incredible moment in history, right? And the class that I was gonna teach was called Warrior X.
32:52
How real is the threat of not having the energy to push AI forward at the pace necessary?
10:09
Dan Driscoll?
10:09
So, so, y- you know, and I don't know Secretary Driscoll.
10:12
I've actually heard very positive things about him, but I don't know him.
10:17
But your point is a really good one, because we're in such a unique moment in history.
10:21
When I was a cadet, I saw the fall of the Berlin Wall.
10:24
When I was an instructor there, it was the fall of the Twin Towers.
10:27
Now we're at this incredible moment in history, right? And the class that I was gonna teach was called Warrior X.
13:30
How real is the threat of not having the energy to push AI forward at the pace necessary?
28:44
Dan Driscoll?
28:44
So, so, y- you know, and I don't know Secretary Driscoll.
28:48
I've actually heard very positive things about him, but I don't know him.
28:52
But your point is a really good one, because we're in such a unique moment in history.
28:56
When I was a cadet, I saw the fall of the Berlin Wall.
28:59
When I was an instructor there, it was the fall of the Twin Towers.
29:02
Now we're at this incredible moment in history, right? And the class that I was gonna teach was called Warrior X.
32:05
How real is the threat of not having the energy to push AI forward at the pace necessary?

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.