Making America Safe Again Through Cyber Defense
Kristi Noem (Secretary of Homeland Security · U.S. Department of Homeland Security), José-Marie Griffiths (President · Dakota State University)
RSA Conference 2025 · Day 2 · YBCA Stage · Keynote
Overview
Speaking on the eve of President Trump's 100th day in office, Secretary of Homeland Security Kristi Noem outlined her administration's vision for American cyber defense — one built on refocusing CISA on its core technical mission, strengthening public-private partnerships, and treating the ongoing Chinese threat to critical infrastructure as a genuine national emergency. In conversation with Dakota State University President José-Marie Griffiths, Noem presented a case for decisive action over bureaucratic process, drawing on her background as a governor who bet her state's economic future on cybersecurity education. ---

Key moments
- 1:55 DHS Secretary frames cybersecurity explicitly as national security priority
- 10:28 CISA barred from disinformation work, reset to core technical mission
- 11:28 China exploits weakest-link strategy: attacks small entities to reach federal systems
- 9:19 DHS admits officials still don't fully understand how Typhoon campaigns succeeded
- 13:18 Every U.S. governor mandated to establish SCIF for classified threat briefings
- 14:02 States required to name dedicated cyber coordinator for DHS rapid response
- 3:20 South Dakota cyber workforce model offered as national education blueprint
- 9:35 Intelligence agency silos block unified defense; breaking them is top DHS priority
Making America Safe Again Through Cyber Defense
Speakers: Kristi Noem, Secretary, U.S. Department of Homeland Security; José-Marie Griffiths, President, Dakota State University
Event: RSA Conference 2025 — April 28–May 1, 2025, Moscone Center, San Francisco
Track: Keynote — YBCA Stage
Watch: YouTube
Reading time: ~7 minutes
TL;DR
Speaking on the eve of President Trump's 100th day in office, Secretary of Homeland Security Kristi Noem outlined her administration's vision for American cyber defense — one built on refocusing CISA on its core technical mission, strengthening public-private partnerships, and treating the ongoing Chinese threat to critical infrastructure as a genuine national emergency. In conversation with Dakota State University President José-Marie Griffiths, Noem presented a case for decisive action over bureaucratic process, drawing on her background as a governor who bet her state's economic future on cybersecurity education.
Introduction
Kristi Noem arrived at RSA Conference 2025 as a relative newcomer to the security industry's annual gathering — but not as a newcomer to cybersecurity's strategic importance. As governor of South Dakota, she had spent six years aggressively building the state's cybersecurity education infrastructure, partnering with Dakota State University to develop programs that now train NSA employees and feed a national pipeline of security professionals. That background colored everything about her keynote conversation with DSU President José-Marie Griffiths: this was not a politician borrowing the language of the field, but an official who had lived its workforce dimensions at the state level before taking the nation's top homeland security post.
Her address came at a politically significant moment — the eve of President Trump's 100th day in office — and carried the weight of a policy declaration. The Department of Homeland Security under Noem's leadership is committed, she said, to moving from talk to action: operationalizing CISA's mandate, hardening the defenses of the most vulnerable organizations in the country, and breaking down the institutional silos that have long separated the intelligence community from the entities it is meant to protect.
DHS: Scope, Mission, and the Weight of Jurisdiction
Noem opened by defining the extraordinary breadth of DHS's jurisdiction — a canvas that, in her telling, covers every person entering or leaving the country, every good crossing the border, and every system connected to the digital infrastructure of the United States. That scope, she acknowledged, creates both immense responsibility and constant pressure to prioritize. ▶ Watch: DHS mission scope (0:00)
"Cybersecurity is national security," she said — echoing a formulation now common in Washington, but grounding it in a specific operational claim: that the nation's critical systems are under sustained attack from adversaries who understand the strategic value of what they are targeting. The 2025 Annual Threat Assessment from the Office of the Director of National Intelligence, released shortly before the conference, confirmed that China remains the most significant cyber threat facing the United States. Noem cited that finding directly and repeatedly.
Her framing of the DHS mandate was deliberately expansive: the department is not simply a technical agency. It is the coordinator of consequence — the entity responsible for ensuring that when something goes wrong at the intersection of digital and physical infrastructure, there is a unified, rapid response rather than fragmented confusion.
Putting CISA Back on Mission
The most substantive policy theme of Noem's address was the administration's commitment to refocusing CISA on its statutory mandate. ▶ Watch: CISA mission refocus (10:00)
Congress created CISA to hunt threats, harden systems, support state and local governments, help small and medium-sized businesses improve their cyber posture, and coordinate resilience across the critical infrastructure sectors. Under previous leadership, Noem argued, the agency had drifted — most conspicuously into content moderation and mis/disinformation adjudication. "It's not the job of CISA to be the ministry of truth," she said. "It is the job to be a cybersecurity agency that works to protect this country."
The administration is conducting a systematic assessment of CISA's current activities — returning certain functions to other agencies, realigning the workforce to the core mission, and restoring financial resources to operational priorities. Noem framed these changes not as cuts but as corrections: a bureaucracy that has grown diffuse can serve its actual mission more effectively when it is concentrated on what it was built to do.
The positive agenda she outlined for CISA is substantial. The agency will prioritize federal civilian network defense, scale support for small and medium businesses that currently lack the resources to defend themselves, improve services to state and local governments, and significantly enhance the speed and directness of threat information sharing. "Instead of just talking about cybersecurity, we're going to do it," she said.
The China Threat and the Weakest-Link Problem
Noem's threat assessment centered on China, and she was specific about the attack pattern that concerns her most: adversaries beginning with the least-defended entities — small businesses, local governments, community utilities — and using those footholds to compromise larger, more consequential systems. ▶ Watch: China threat and critical infrastructure (10:00)
"They're going after, many times, the little guys first," she said. A federal IT system is only as secure as the smallest local government database connected to it. That dynamic creates a structural vulnerability that no amount of federal hardening at the top of the chain fully addresses. CISA's role in supporting subnational and private-sector entities is therefore not peripheral to national security — it is central to it.
She was candid about the knowledge gaps that remain. Briefed on the Salt Typhoon and Volt Typhoon intrusions before taking office, Noem said she was struck by a troubling reality: officials did not fully understand how those campaigns had succeeded, and therefore could not fully specify how to prevent a recurrence. That admission of uncertainty — unusual in political settings — was paired with a commitment to building the forensic and analytical capacity to answer those questions and translate the answers into actionable defense.
She also addressed intellectual property theft, credential access, and counterintelligence as distinct threat vectors requiring distinct defensive measures, arguing that the silos between intelligence agencies have historically prevented the unified picture necessary to address them comprehensively. Breaking down those silos — and bringing private-sector partners into the information-sharing environment at a meaningful level — is a stated priority for the administration. ▶ Watch: Silo-breaking and intelligence sharing (8:00)
Building State and Local Cyber Readiness
One of Noem's more concrete announcements concerned the state-level infrastructure for emergency response. Her administration recently sent a communication to all U.S. governors requiring each state to establish a Sensitive Compartmented Information Facility (SCIF) — a secure environment for receiving classified threat intelligence. Many states currently lack such facilities, which means governors receive time-sensitive national security information through channels that cannot carry the classification level the information requires. ▶ Watch: SCIF requirement for governors (14:00)
Beyond the physical infrastructure, Noem called for every state to designate a specific point person for cyber coordination with DHS — a named individual who can be reached immediately when a threat requires rapid, localized response. The model she described mirrors how the National Guard is integrated into emergency management: a clear chain of authority, a pre-established communication structure, and defined responsibilities before the crisis begins rather than improvised during it.
She also raised the question of blueprinting best practices for state-level cyber response — not mandating a single approach, but providing states with well-tested frameworks they can adapt to their own environments, infrastructure compositions, and institutional relationships.
A Governor's Perspective on the Workforce Pipeline
Noem's academic partnership with José-Marie Griffiths gave the conversation a dimension most DHS keynotes lack: a firsthand account of what it takes to build a cybersecurity workforce at scale. ▶ Watch: Cybersecurity education and workforce (2:00)
As governor, Noem decided that cybersecurity and technology would be the foundation of South Dakota's economic development strategy. Working closely with Dakota State University, she invested in programs that now produce a significant share of the state's security talent — including personnel who go on to work at the NSA. The approach treated education as economic infrastructure: a long-cycle investment whose returns compound over time rather than an immediate budget line item.
That perspective informed her broader argument at RSA Conference 2025: that the cyber skills shortage is not purely a market failure or a training problem — it is also a policy failure at the state and federal level to commit seriously to workforce development as a national security investment. The administration's engagement with universities and technical training programs, she suggested, will reflect that understanding.
Notable Quotes
"Cybersecurity is national security."
"It's not the job of CISA to be the ministry of truth. It is the job to be a cybersecurity agency that works to protect this country."
"Instead of just talking about cybersecurity, we're going to do it."
"Even the biggest systems in our entire federal government is only as strong as our weakest link, our weakest system that ties into those bigger systems that make us all vulnerable."
"The first thing I thought was, 'I cannot believe that I lived.' And the second thing was, 'I bet I can drive anything now.'"
Key Takeaways
- CISA is returning to its statutory core. The administration's review of CISA is not about diminishing the agency but restoring its focus: threat hunting, system hardening, support for subnational governments and small businesses, and critical infrastructure coordination. Activities outside that mandate are being wound down.
- China's infrastructure intrusions remain the primary national-level cyber threat. The DNI's 2025 Threat Assessment confirms China's position at the top of the adversary hierarchy. The specific pattern — starting with small businesses and local governments and working up to larger systems — reflects a deliberate exploitation of America's weakest links.
- Every governor now needs a SCIF and a cyber point person. The administration's directive to states formalizes a long-overdue infrastructure requirement: states must be able to receive classified threat intelligence and must have designated contacts who can act on it quickly. The cyber emergency response chain cannot function if half the nodes in it lack secure communications.
- Public-private partnership is the operating model, not a buzzword. Noem's repeated emphasis on bringing the private sector to the table with real information and real authority — not after-the-fact briefings but genuine collaboration — reflects a posture that views industry as a partner in national defense, not a regulated object of policy.
- Workforce development is a national security investment. The South Dakota model — sustained commitment to cybersecurity education as economic strategy — offers a template for what federal and state governments can do to address the skills shortage structurally rather than through short-term initiatives.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
Kristi Noem delivers the political version of what Bulazel already said better on a different stage — CISA needs to focus, China is the threat, public-private partnership matters. The South Dakota cybersecurity education angle is genuinely her lane and adds something, but this is a cabinet secretary keynote optimized for political messaging, not technical insight. You learn more about DHS in fifteen minutes with Bulazel than in forty-five here.
Heather Calloway (CISO) — STRONG ACCEPT
DHS Secretary Kristi Noem presents the administration's priorities for cybersecurity and critical infrastructure defense — focusing on public-private partnership, workforce development, and the Volt Typhoon threat. The political context makes this more significant than the content alone warrants.