Admiral (Retd.) Mike Rogers

“AI doesn’t fundamentally change cybersecurity. It changes the speed and scale”

Former NSA chief Mike Rogers warns that artificial intelligence is lowering the expertise required to launch cyberattacks, while Iran’s targeting of U.S. water systems shows how even small communities can become strategic targets.

As Iranian hackers probe U.S. water infrastructure, the threat is less about shutting down the American water supply than demonstrating how widely an adversary can reach. Admiral (Ret.) Mike Rogers, a former director of the National Security Agency and commander of both U.S. Cyber Command and the U.S. Fleet Cyber Command, says the decentralized nature of America’s water systems creates both resilience and vulnerability, particularly among smaller municipalities with limited cybersecurity resources. And as AI begins to automate the discovery and exploitation of vulnerabilities, he warns that the speed and scale of cyberattacks are about to change dramatically.
Admiral (Ret.) Mike Rogers, a partner at Team8 and former director of the NSA and commander of U.S. Cyber Command. About two weeks ago, it was revealed that Iranian hackers had targeted U.S. water infrastructure. How unprecedented is this attack?
“This is not something new for the Iranians. I’m not downplaying this, but trying to put it in context. We’ve seen them around U.S. water systems before, we’ve seen them attack water infrastructure in Israel, and we’ve seen them around water infrastructure in the Persian Gulf. I’m not surprised by what we’ve seen.
“Beyond that, we don’t yet understand the full scope of their effort. You see anecdotal reports because, in the U.S., water is generally managed at the local level. There is no single water provider for a state or region; it’s a very decentralized system. It ranges from very large entities that provide water to urban areas with millions of customers to entities that provide water to towns and villages with hundreds or thousands of people.”
1 View gallery
מייק רוג'רס שותף ב Team8 ולשעבר ראש ה NSA
מייק רוג'רס שותף ב Team8 ולשעבר ראש ה NSA
Admiral (Retd.) Mike Rogers
(Elad Gershgoren)
The decentralized nature of the system has an advantage: an attacker cannot take it down in one fell swoop. But the disadvantage is that there are many more vulnerabilities that attackers can exploit.
“Right. If you look at it from a defensive perspective, we call it segmentation. That’s what you’re trying to create as a component of cyber resilience.
“The other side, as you mentioned, is that not only are there a lot more access points, but you’re dealing with a lot of really small towns and municipalities whose cyber expertise is very limited. They don’t have a lot of resources or knowledge. There’s a certain level of built-in vulnerability that the Iranians have shown interest in trying to exploit.”
How prepared is the U.S. for such attacks, even before we consider the new dangers posed by AI agents?
“I personally feel pretty comfortable with the big urban areas and the largest water systems, but also with those that have the greatest cybersecurity knowledge and access to resources. Our efforts there have been very reasonable.
“I say ‘reasonable’ because against a determined adversary, the chances are that you won’t be able to keep them out. On the other hand, there are a lot of smaller segments. In the latest FBI reports, it seems that so far the effort has tended to be focused on smaller communities, not New York, Los Angeles or Atlanta.
“That doesn’t surprise me. A smaller target, in the Iranian view, offers the highest probability of success. They want to create an impact across significant parts of the U.S. They are trying to send a message that, ‘Look, we can create a pretty broad geographic spread of impact.’”
So there is a psychological component. Numerically, the attacks affect a small portion of the U.S. population, but once you count seven countries, it looks more serious.
“Yes, that is a dimension of the event. It will not paralyze the American economy. Ninety-nine percent of our population will not be affected. That is not the point.
“In the Iranian view, it is an attempt to show that they can have a broad geographic impact, and they are trying to plant the seed: ‘We can do more of this. We can expand this.’ There is definitely a psychological dimension to it.”
We now see AI models that can find vulnerabilities in software code, as well as agents that have escaped their closed testing environments and attacked online targets such as Hugging Face. What are the dangers now that cyberattacks are becoming easier to plan and execute, and perhaps no longer require a state entity to carry them out?
“In terms of the dark web and the number of tools available to any user who wants to find them or pay for them, you don’t have to be a country to make a significant impact in cyber today, regardless of AI and advanced technology.
“That’s one of the reasons cyber is always interesting. You can carry out attacks with a targeted impact at a very low cost in terms of money, manpower and expertise.
“AI will only increase that. It doesn’t fundamentally change cybersecurity, but it brings a speed and scale that we’re not used to in this problem set. We’ve dealt with attacks in the past. We’ve dealt with vulnerabilities. AI takes that vulnerability and adds another dimension of speed by saying, ‘OK, so here’s this vulnerability. How do I actually launch a cyberattack to exploit it?’
“AI allows us to do all of this now in one automated set of actions. As we saw with Hugging Face, the AI agents did the whole thing. They gained access to the network, identified the vulnerabilities, developed the methods to gain access, and they did it all themselves in a very integrated and coherent way. It’s something new that we’re not used to.”
Cyber is the great equalizer. When you add AI to the equation, it becomes an even bigger equalizer.
“Before AI, you had to find someone who had the knowledge. So, for example, if you’re surfing the dark web and you want to get into ransomware, you’ll find people who will say, ‘I’ll write malware for you. I’ll run a Bitcoin exchange for you. I’ll negotiate for you.’
“With AI, we don’t have to go to other people with the knowledge. It creates it itself. It takes a lot of the existing challenges that are already there, but puts them at a pace and scale that we’re not used to.”
Does that mean we’re going to see many more attacks on critical infrastructure carried out by a much broader range of actors, from state-sponsored and state-affiliated groups to private individuals, such as someone in Tehran or France who identifies with Iran and wants to attack the U.S. or other targets?
“You’re going to see a whole range of actors out there. Also individuals who are dissatisfied, frustrated, or maybe they just want to show they’re smart and subdue the local authority where they live.
“You’ll also see countries that want to carry out very orchestrated, targeted, strategic, large and comprehensive programs against infrastructure.
“Part of the challenge in cybersecurity is that we can’t optimize ourselves for just one actor, one methodology or approach, or one level of technology. There’s a whole range out there, which has always been part of the complication.
“The thinking was that if you optimize yourself to defend against actors with the most advanced capabilities and technologies, then everything else becomes an easier case for you to deal with. But we must recognize that there is a huge range of players out there with different motives, goals and risk considerations.”
How should countries and infrastructure operators, such as cities, adapt to this new reality?
“It’s a combination of things. There’s no one thing here that, if you do it, everything will be perfect.
“Number one, cyber resilience is becoming more and more important. There’s a high probability that this group of actors has a pretty good chance of gaining access to your network structure. So you have to ask yourself, ‘What does my cybersecurity framework look like if this is true?’
“What are you going to do to improve your network and your internal processes when an intrusion occurs? How are you going to stop the attacker from moving laterally within your network? How do you ensure that you have situational awareness of what’s going on in your network? How are you going to prevent the adversary from uploading malware to your system or downloading data to get information out of your network?
“It’s a different thought process than if your sole focus is, ‘I’ve got to stop this guy from getting in.’
“Number two, it’s the reality of the world we live in. What we see from the set of events that started our conversation is that it doesn’t matter how small you are, and it doesn’t matter where you are.
“You can’t say to yourself, ‘I’m a small town of 1,500 people in Minnesota. We’re so small, no one will come after us.’ The reality is that cybersecurity and cyber resilience must be a core component of every automated, interconnected network structure that we operate today.”
How concerned are you about the risk posed by open models? We’ve seen a lot of highly capable models coming out of China, and almost all of them are open models that can run locally. Are they more consequential than closed models such as Claude or GPT?
“That’s not the right way to look at it, as if one is more important than the other. We have to look at it as an ecosystem, and both will be out there.
“It’s not ‘either/or,’ both in terms of exploitation and in terms of the threat or impact. They’re different, but they’re still out there. There’s still a threat and a challenge across that spectrum.”
Do you think the current federal administration is aware of and taking this type of risk seriously? I ask because The New York Times reported that, in a Cabinet meeting about the attack on water infrastructure, Trump said: ‘I think Minnesota is behind this, I think the governor is behind this. I don’t think there was an Iranian cyberattack.’
“I don’t think there’s anyone in the world who would say they’re exactly where they want to be in cybersecurity. It’s not just an American challenge, and it’s not just an Israeli challenge. No country in the world is where it wants to be right now in cybersecurity.
“The question is: What is the most effective strategy given the challenges that we’ve talked about? What is the role of the private sector, and what is the role of government?
“This government thinks that the network owner has the primary responsibility for protecting and securing their network. I’m not sure that’s the best approach in certain areas, such as critical infrastructure.
“And I define critical infrastructure as anything that inherently has a significant impact on national security, economic competitiveness, or the safety and well-being of our citizens.
“Critical infrastructure requires a different approach than a small neighborhood laundromat or a tractor manufacturer. We’re trying to figure out what criteria we should use to decide what the role of the network owner is, what the role of government is, and how we’re going to allocate resources — money, people and prioritization.
“You have to develop a framework that will help you do that. Using this critical-infrastructure model is one good way to do that.”