Cybersecurity continues to pose a significant challenge for both public and private sector organizations. Given the wide-ranging impact of cyber threats from criminal groups, adversarial nations, and extremist actors, the issue receives considerable attention. However, in a rapidly evolving landscape, certain vulnerabilities often escape notice. We spoke with four cybersecurity experts to identify and evaluate an underappreciated threat to U.S. national security that policymakers and analysts frequently overlook.
Emily Harding
Director of the Intelligence, National Security, and Technology Program and Vice President of the Defense and Security Department at the Center for Strategic and International Studies
Determining the state affiliation of criminal organizations presents a complex challenge. The Trump administration’s recent memorandum on “transnational cyber-enabled crime” declared that industry can engage in offensive cyber operations against criminal groups. However, “state-associated” groups are off-limits, attempting to draw a clear distinction in an ambiguous environment. The Russian government, for example, maintains various relationships with hacking collectives—some are effectively extensions of the Kremlin, others consist of government employees operating as criminals on the side, and some are purely criminal entities that occasionally perform favors for the state. The question remains: which of these groups are legitimate targets? Paradoxically, the memo may inadvertently incentivize nations like China and Russia to cultivate relationships with hacking groups to better shield them from counterattacks. While increased private sector involvement in this fight is sound policy, its effectiveness depends on establishing clear criteria for affiliation and robust intelligence gathering on these relationships. Without such frameworks, industry will remain mired in legal complications rather than taking decisive action.
Caleb Withers
Research Associate for the Technology and National Security Program at the Center for a New American Security
Artificial intelligence may advance more rapidly in offense-oriented cyber operations—such as vulnerability exploitation, where results are immediately measurable—than in more complex defensive scenarios. This asymmetry could create new strategic vulnerabilities that adversaries might exploit while leaving defenders struggling to keep pace.
Also Read
- Grand jury concludes DeSantis administration misused Medicaid settlement funds
- American Airlines Announces Seven New International Routes for 2027
- The Geological Chain Reaction Behind Nepal’s Deadly Trishuli River Flood
- Streaming Subscription Savings: How Top Credit Cards Can Offset or Eliminate Monthly Costs


