From Slide Rules to GenAI (Keynote)
Black Hat USA 2025 · Day 1 · Briefings
Overview
Chris Inglis — former Deputy Director of the NSA and the nation's first National Cyber Director — argues that cyberspace's persistent insecurity is not a technical problem but a strategic one: society has pursued innovation and market efficiency for fifty years while neglecting resilience. The path forward requires a shared model of collective defense where all stakeholders — individuals, private sector, and government — understand their roles, act like owners, and build systems that are defensible by design. ---

Key moments
- 5:00 Historical framing: slide rule-to-AI transition mirrors WWII codebreaking-to-computing shift
- 10:00 Inglis thesis: AI changes attacker economics but not the fundamental asymmetry problem
- 15:00 Policy argument: Cyber Safety Review Board must become permanent for systemic learning
- 19:59 Core challenge: defenders must shift from reactive incident response to designed-in resilience
- 25:59 Aviation analogy: safety culture requires mandatory failure reporting and shared root cause analysis
- 30:59 GenAI risk: AI lowers the barrier for nation-state-quality targeted attacks against enterprises
- 36:00 Call to action: cybersecurity must adopt medicine/aviation evidence-based practice culture
- 39:59 Conclusion: public-private cooperation and failure data sharing are existential imperatives for defense
From Slide Rules to GenAI
Speaker: Chris Inglis, Former National Cyber Director; introduced by Jeff Moss, Founder of Black Hat
Conference: Black Hat USA 2025 — August 6-7, 2025, Mandalay Bay, Las Vegas
YouTube: https://www.youtube.com/watch?v=bARa6fr8frU
Reading time: ~8 minutes
Type: Keynote
TL;DR
Chris Inglis — former Deputy Director of the NSA and the nation's first National Cyber Director — argues that cyberspace's persistent insecurity is not a technical problem but a strategic one: society has pursued innovation and market efficiency for fifty years while neglecting resilience. The path forward requires a shared model of collective defense where all stakeholders — individuals, private sector, and government — understand their roles, act like owners, and build systems that are defensible by design.
Introduction
When Jeff Moss founded Black Hat, the event was a technical gathering. When Chris Inglis arrived at the US Air Force Academy in 1972, his first computer was a slide rule. The fifty years between those two reference points form the spine of the Black Hat USA 2025 afternoon keynote: a clear-eyed accounting of how digital infrastructure grew faster than the doctrine, skills, and resilience needed to secure it — and what a workable model for collective defense actually looks like.
Inglis brings rare credentials to this argument. He spent three decades at the NSA, rising to Deputy Director during the Snowden era. He then became the first Senate-confirmed National Cyber Director, standing up the Office of the National Cyber Director (ONCD) from scratch. His vantage point spans intelligence, military operations, and national policy — and his central message at Black Hat 2025 is that the cybersecurity community has been solving the wrong problem.
▶ Watch: Introduction and Jeff Moss's Opening Remarks (00:00)
A Fifty-Year Architecture of Missed Opportunities
Inglis traces the current state of cybersecurity back to foundational decisions made over five decades. Beginning in the 1970s, Moore's Law drove exponential processor growth. Bandwidth and connectivity created the internet. A logic layer built protocols and coherence. Applications and services built on top. And throughout all of it, cyberspace developed in five layers: physical geography, logical infrastructure, applications, a persona layer of human identity, and the geographic jurisdictions that bookend everything.
The result, Inglis argues, is a system that operates vertically — any action ripples across all five layers — but is defended horizontally. "Very seldom do I see a solution that says, 'I actually have to worry about all five of these layers when I actually change something in the system.'"
The deeper problem is a fifty-year trade-off that was never resolved. Innovation and market efficiency received relentless investment; resilience and robustness were repeatedly deferred. "We promised we would come back and pick it up and bring it along for the ride. Stick that third leg under the stool. We've not done that."
▶ Watch: The Five Layers of Cyberspace and What We Got Wrong (06:00)
The State of Cybersecurity in 2025
Inglis offers a frank assessment of where things stand. Digital systems in 2025 are "largely not defensible" — not because defense is impossible, but because security was never built in from the start. Aftermarket controls and bolt-on defenses predominate. Users and operators routinely serve as the first and last line of defense with no meaningful support from supply chains or coalitions. Detection is slow, response is reactive, and recovery is treated as an afterthought rather than a designed capability.
The threat environment compounds this. Cyberspace is offense-persistent: attack costs are low relative to the value of targets, adversaries innovate faster than defenders, and nation-states increasingly use private sector infrastructure as a proxy battleground. Colonial Pipeline, SolarWinds, and a long list of similar incidents share a common structure: an adversary exploited a gap in doctrine or human behavior before ever touching a technical vulnerability.
Inglis's observation on adversary methodology is pointed: skilled adversaries almost never lead with zero-days. They look first for weak doctrine — open front doors — then for human mistakes. Zero-day vulnerabilities are a last resort. If defenders approach security in the reverse order, starting with technology, they will always be a step behind.
▶ Watch: The Threat Landscape and Adversary Methodology (20:00)
A Model for Collective Defense
The core of Inglis's keynote is a framework he calls a model — not a formal strategy, but a way of thinking about the problem that any organization can adopt. It rests on three premises.
First: Everyone is implicated. Cyberspace security is not the province of IT and security specialists. Every person who depends on digital infrastructure — which is everyone — has a stake. The submarine analogy from Inglis's son captures this well: "The sub's always trying to kill its crew. But it's also our home." Cyberspace is simultaneously the platform that enables modern life and the persistent threat to it.
Second: Everyone must know their contribution. A successful collective cannot function if participants do not understand what role they play. CISOs must align their work to business propositions, not just threat models. Non-technical executives must understand what digital infrastructure enables and what it risks. The best security operation center Inglis ever observed was in a New York bank: on one wall, customer commitments; on another, the capabilities defending them. Every analyst in the room understood the connection.
Third: Everyone must act like owners. Top-down strategy cannot anticipate edge-case questions at the perimeter. People at the edge must be empowered to make decisions within a framework, not wait for instructions. This is what Inglis means when he cites the OODA loop — the observe-orient-decide-act cycle from military doctrine: the defender who can close that loop faster than the adversary wins.
▶ Watch: The Collective Defense Model (22:00)
Ukraine as a Case Study in Defensible Architecture
Inglis offers Ukraine as the most compelling real-world demonstration of collective defense working. Against sustained Russian cyber operations over three years, Ukraine has protected its digital infrastructure through three investments:
- Defensible architecture — not perfect, not secure, but structured so that competent defenders can hold ground
- Technical skills — people who know their own systems better than any adversary could
- Coalition — a broad alliance of national security agencies, governments, and private sector institutions that forces Russia to fight a coalition, not just Ukraine
"You're gonna have to go a long way to beat the Ukrainians in their hometown on their architecture." The lesson is not that Ukraine's systems are excellent. It is that defensibility is a function of architecture, people, and coalition together — not any one element in isolation.
▶ Watch: Ukraine and the Coalition Defense Model (34:01)
On Artificial Intelligence
Inglis devotes brief but pointed remarks to generative AI. His framing cuts against both the hype and the alarm: the most remarkable thing about GenAI is not its capabilities but the speed of its arrival.
From the slide rule to the calculator took three hundred years. From the calculator to the mainframe to the PC to the smartphone took fifty. GenAI arrived in what feels like an instant, and more disruptive technologies are visible on the horizon. The question is not whether to adopt them — adversaries already are — but how.
Inglis's framework for AI echoes his broader argument: non-technical operators must make choices about what AI's role is, not delegate that to technologists. "Buyers, operators need to make the choices about what its role is in your company, not technologists." The analogy he uses is the modern automobile — fifty million lines of code under the hood, but the driver knows what they asked it to do, has a dashboard that shows performance, and has controls to bring it back into alignment. That is the relationship organizations need to build with AI.
His closing image is of a tsunami wave approaching the shore. There are three choices: try to stop it (impossible), run from it (unsustainable), or learn to surf it. The surfboard is the model: a clear understanding of what you want from digital infrastructure, who is responsible for what, and how to act collectively when something goes wrong.
▶ Watch: Artificial Intelligence and the Tsunami Analogy (40:02)
Notable Quotes
"We've pursued ruthlessly innovation and market efficiency — two great goods. But we very seldom gave equal fealty to resilience and robustness, because we thought we promised we would come back and pick it up and bring it along for the ride. We've not done that." — Chris Inglis ▶ 20:00
"Cyberspace is the sum of technology and people and doctrine. But it exists eternally in the presence of adversaries. They're always there." — Chris Inglis ▶ 10:00
"Skilled adversaries almost never think of technology first. If the front door's open, they walk right through — SolarWinds. If that's shored up, they find a mistake in people — Colonial Pipeline. Only if they really have to will they use a zero-day." — Chris Inglis ▶ 24:00
"You gotta beat all of us to beat one of us. Thanks very much, and good luck to us." — Chris Inglis ▶ 44:02
Key Takeaways
- Resilience has been systematically underfunded for fifty years. Innovation and market efficiency are legitimate goals, but they cannot substitute for building defensible architecture. The third leg of the stool — robustness — must be added now.
- The problem is strategic, not just technical. Adversaries lead with doctrine and people before reaching for technology. Defenders who start with technology will always lag.
- Collective defense requires everyone to know their role. The CISO who walks into the boardroom speaking the language of the business plan — not the threat matrix — is the one who gets resources and drives outcomes.
- Ukraine demonstrates that defensible is achievable. Perfect security is impossible, but defensible architecture plus skilled people plus a coalition is sufficient to hold ground against sophisticated nation-state adversaries.
- On AI: surf the wave, don't stop it. Organizations that understand what they are asking AI to do, build a dashboard to know how it is performing, and retain controls to correct it will benefit. Those who abdicate those choices to technologists — or to the AI itself — will not.
Slides PDF: Not available at time of publication.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
Chris Inglis is a credible voice and the collective defense framework is coherent, but this is a keynote for conference organizers to check a policy box, not a talk that changes how any practitioner thinks or works. The adversary methodology observation — zero-days are a last resort after doctrine failures and human mistakes — is the one genuinely useful data point, and it's buried in forty-five minutes of slide-rule-to-GenAI arc.
Heather Calloway (CISO) — MUST SEE
Inglis did not come to discuss technology. He came to argue that fifty years of choosing digital convenience over resilience is a governance failure with names on it, and that Ukraine proved a defensible architecture plus skilled people plus coalition support is sufficient against nation-state adversaries. That case study should be in every board presentation on cyber resilience this year.