How the U.S. Can Survive a Large-Scale AI Cyberattack
Photo: miss irine/Adobe Stock
Picture this: The year is 2030 in the United States. Reports of mass power outages emerge, along with indications that Americans cannot retrieve money from banks or purchase food or gas. Flights are grounded; stoplights cease to function, causing major traffic jams; phone lines are down; hospitals have limited backup power, but it is only a matter of time before ventilators start shutting off. Americans begin to panic and worry they will not survive; chaos ensues. The U.S. government suspects an unidentified actor has just launched a massive cyberattack against it for an unknown purpose. It seems too well coordinated and widespread to be carried out by a single adversary—or did they have a new sophisticated weapon?
While the above scenario may sound far-fetched, advancements in AI make this future scenario unnervingly plausible. Anthropic recently announced it would not be releasing its newest frontier AI model, Claude Mythos, to the public due to its advanced hacking and vulnerability detection capabilities. According to the AI Security Institute, Mythos achieved an impressive 73 percent success rate in executing expert hacking tasks during capture-the-flag simulations. This suggests that AI will profoundly alter the cyber world as we know it. Future large-scale cyberattacks, with the help of AI, may not only be conducted by nation-state actors, but potentially now from terrorist organizations and individual actors as well.
Regardless of the actor, if a widespread attack like this were to occur against one or more of the 16 U.S. critical infrastructure sectors, it could prove devastating to the daily life and security for Americans and have massive economic implications. If the United States wants to survive the initial onslaught of a major AI cyberattack, it must seek to improve its whole-of-society partnerships and communication. Specifically, the U.S. federal government should focus its efforts on the following:
- optimizing interoperability between the various U.S. government entities and the military;
- expanding upon the Cyber Unified Coordination Group concept for times of national emergency;
- ensuring the free flow of communication with the private sector and state, local, territorial, and tribal (SLTT) governments;
- enhancing real-time cyber threat intelligence (CTI) sharing, combined repositories, and agreements with foreign partners and the private sector; and
- incentivizing the private sector to continue the development of advanced cybersecurity AI detection models and mitigation tools.
This framework for expanding U.S. cybersecurity will determine how ready it is for this new era of advanced AI cyber threats.
Interagency Interoperability Is a Must for Cyber Defense
During a national emergency from a major cyberattack, the Cyber Security and Infrastructure Agency (CISA) acts as the national coordinator. Its responsibilities include orchestrating all civilian U.S. government domestic cybersecurity actions and coordinating the defense of critical infrastructure with the private sector. CISA’s ability to generate interoperability now within the U.S. government and military will dictate how coherent the U.S. domestic response is to a major incident.
The Department of Energy (DOE), for example, plays a significant role in the defense of numerous critical infrastructure sectors. Without power generation and its uninterrupted transmission, which the DOE oversees, many other critical infrastructure sectors would struggle to function unless they had long-term backup power generation. As demonstrated in the beginning scenario, telecommunications, financial, healthcare, transportation, and many other sectors rely heavily on electricity, which comes from over 7,000 continental U.S. power plants spread across three independent interconnection grids that generate and transmit power. CISA and the DOE will need to be in lockstep to make certain that critical infrastructure remains functional.
One way the U.S. government intends to synchronize itself during a major cyberattack is through the Cyber Unified Coordination Group (UCG), which commences upon a national cyber emergency. The UCG is intended to be an informal coordination forum with multi-agency participation. While CISA is the national coordinator, it lacks clear authoritative powers to direct other government entities during times of crisis. This creates a gap in the federal government’s command and control during a cyberattack, reducing its ability to effectively coordinate a multi-department response.
An AI-enabled cyberattack across multiple sectors is likely to create a degraded digital communications environment, making the leadership gap even more apparent. To mitigate this, the U.S. government should plan to establish a physical space for a UCG operations center with representatives from CISA, the DOE, the FBI, the U.S. military, the intelligence community, and relevant SLTT government offices. This operations center would ensure the government’s unity of effort, timely private sector incident response, network reconstitution management, and CTI sharing to keep critical infrastructure up and running. In-person communication will be vital to ensuring timely cross-organization coordination.
The Joint Cyber Defense Collaborative (JCDC), currently run by CISA, establishes the foundation for an operations center concept. Its intended purpose is to synchronize U.S. government partnerships with foreign and industry partners in both steady state and in preparation for a major cyber incident. However, based on recent cyber incidents, the U.S. government’s performance in managing smaller scale cyberattacks requires improvement, specifically with its interagency coordination and centralized leadership management during times of national emergency. JCDC needs to be expanded to properly handle a sizable cyber emergency. Establishing a UCG operations center and a more authoritative lead organization, such as CISA, will enable the U.S. government to take on a major cyberattack.
The Private Sector Has a Shared Responsibility for National Security
While the U.S. government and CISA have a responsibility to ensure the functioning of U.S. critical infrastructure, the private sector also plays a critical role in enabling the country’s national security in cyberspace. The private sector owns and operates most critical infrastructure in the United States. Besides a few cases of federal regulation, contractual responsibilities, and national emergency powers, the private sector is not required to cooperate with the government. “I’m from the government, and I’m here to help,” as the old adage from Ronald Reagan goes, does not always translate positively to the private sector. The government must identify ways to bolster its image with industry to generate collaboration prior to a major cyber incident.
Engaging industry in public-private partnerships through each sector’s risk management agency provides ample opportunities for government and industry collaboration. Creating new funding opportunities through these programs and cross-sharing information provides openings for the government to build trust with the public sector while preparing for a major cyber event. Additionally, the government should continue to solicit participation from key industry stakeholders to participate in simulated exercises, such as CISA’s biennial Cyber Storm exercise. By exercising the most likely and most dangerous cyber scenarios with key stakeholders of critical infrastructure, the government can identify where the country’s deficiencies are and how to improve them.
Intelligence Sharing Reduces Cyber Vulnerability to Follow-On Attacks
In an ideal world, every organization would share its information on CTI to improve cybersecurity for everyone and disincentivize cyber actors from continuing their exploitation. However, this is not the case. Not all organizations have an incentive to share information regarding malicious cyber activity, and many are bound not to share information due to the proprietary nature of the data. For example, Anthropic’s Mythos successfully identified numerous vulnerabilities from internet browsers and operating systems, but Anthropic chose not to publicly release most of that information. While every organization has a right to its data, not sharing threat information leaves other critical networks vulnerable to attack.
With the advent of frontier AI models that can scale offensive cyber, the private sector should look to build defensively minded AI models as well that can rapidly detect, remediate, and share anomalies, malware, and indicators of compromise. While Anthropic has not released Mythos’ detected vulnerabilities to the public, it did take a positive step forward in creating a new defensive AI initiative called Project Glasswing. Through that initiative, Anthropic offered $100 million in credits to over 150 companies and the U.S. government to test Mythos out. This provides major companies with the chance to identify new vulnerabilities and patch their networks before Mythos is eventually released. Projects like these should become standard practice for the private sector to ensure advanced capabilities match the growing threat from offensive AI systems. The U.S. government should also work to increase funding for these projects to incentivize private sector research and design.
CTI repositories are another critical aspect of cybersecurity interoperability. While there are numerous repository platforms that exist to improve general cybersecurity information sharing—such as LevelBlue OTX, MISP, VirusTotal, and many others—not all platforms are free to use or easily accessible. This can make it challenging for smaller private organizations to stay on top of the newest cybersecurity information given competing budgetary constraints. This provides an additional opportunity for the U.S. government to come in and support.
The U.S. government has attempted to find ways to provide free or low-cost information to industry stakeholders. Although some intelligence sharing programs, such as the Information Sharing and Analysis Centers, have been impacted by funding cuts and now require membership fees in some cases, other government-sponsored CTI sharing initiatives, such as the Automated Indicator Sharing program, remain free. However, according to a Congressional Research Service report, these programs have had a variable effect on private sector participation and overall value. Regardless, the federal government should prioritize funding zero-cost programs and work to develop improved mutually beneficial partnerships to ensure that private sector networks are secure. The harder it is for an adversary or its AI systems to infiltrate multiple critical networks at scale, the harder it is going to be for them to generate simultaneous malicious effects that constitute a major cyberattack.
The United States’ ability to survive the initial days of a major AI-facilitated cyberattack depends on its whole-of-society ability to function cohesively, from the company and network owner levels up through the SLTT and federal government levels. The U.S. government should continue to prioritize partnerships among internal government institutions, with its foreign partners, and especially with the private sector. While sharing information and building interoperability are imperative, engendering mutual trust and securing reliable communication paths between all stakeholders during the chaos of a major cyber incident are equally important. If the United States can perform these core tasks well, it can survive defensively and buy itself time to decide how to respond to the larger threat.
Andrew Faulhaber is a visiting fellow in the Intelligence, National Security, and Technology Program at the Center for Strategic and International Studies in Washington, D.C.