Lawfare Daily: How Our Growing Software Dependence Threatens National Security | Lawfare
The upcoming main navigation can be gotten through utilizing the tab key. Any buttons that open a sub navigation can be triggered by the space or enter key.
Search Lawfare
Search
Advanced Search
Jonathan G. Cedarbaum
Chad Serena
Colin P. Clarke
@ColinPClarke
Jen Patja
Meet The Authors
Subscribe to Lawfare
Lawfare Book Review Editor Jonathan Cedarbaum sits down with the Soufan Center’s Executive Director Colin Clarke and Senior Research Fellow Chad Serena, to discuss the Center’s recent report, “Closing the Gap: Software Understanding and U.S. National Security.” They explore what the authors call the “software understanding gap”—the growing disconnect between the rapid pace of software development and our ability to fully understand, assess, and secure increasingly complex systems. They discuss how adversarial state actors and criminal groups can exploit this gap, the ways in which it poses a national security challenge, and what government agencies, private industry, and software developers can do to better mitigate risks and strengthen U.S. cybersecurity.
Additional reading:<br>Douglas Ghormley, Tod Amon, Christopher Harrison, and Tim Loffredo, “The National Need for Software Understanding: The Present Crisis, Technical Capability Gaps, and Path Forward,” Sandia National Laboratories (March 2025)
To receive ad-free podcasts, become a Lawfare Material Supporter at www.patreon.com/lawfare. You can also support Lawfare by making a one-time donation at https://givebutter.com/lawfare-institute.<br>Click the button below to view a transcript of this podcast. Please note that the transcript was auto-generated and may contain errors.
Transcript<br>[Intro]<br>Chad Serena: 40 years ago, would you have noticed if there were two cameras inside your house, one on your computer, three on your neighbor's house, one on a doorbell? You'd have said, "Yeah, would've stood out like a sore thumb." Now you probably walk into your office at any point in time and you don't even notice those things. You wouldn't even be aware that there's microphones or that somebody's phone's laying there that could potentially be recording you.<br>Jonathan Cedarbaum: It's the Lawfare Podcast. I'm Jonathan Cedarbaum, Lawfare's Book Review editor, with Colin Clark and Chad Serena, senior researchers at the Soufan Center.<br>Colin Clarke: You think about what the Chinese did with Volt Typhoon, pre-positioning itself within various U.S. utilities, transportation hubs. But instead of just immediate disruption, these kind of penetrations are more likely to, you know, precursors to a future pre-positioned cyberattack.<br>Jonathan Cedarbaum: Today we're talking about their new report, “Closing the Gap: Software Understanding in U.S. National Security.”<br>[Main Podcast]<br>Your report talks about the software understanding gap. What do you mean by that term?<br>Colin Clarke: Yeah, I would say just very briefly, that's our ability to, the, the way we've explained it, to understand, to verify to reason about software, which has been, you know, dramatically outpaced by its production and uptake and implementation. That, that's created a gap, and in our in our report we h- we have a graphic that kind of shows this.<br>And because of the increasing prevalence and importance of software to really everything we do, right? U.S. national security interests U.S. military, U.S. intelligence agencies, but also every civilian function you can think of there's tremendous risk that is built into this gap. And the gap continues to grow. It is exacerbated by a number of different factors. The newest monkey wrench is, is artificial intelligence and, and how we conceive that.<br>Jonathan Cedarbaum: Very good. So is the problem of the software understanding gap principally about the quality of software and how it's developed, or is it one about how users of software have limited understanding of how software works?<br>Chad Serena: I think it's a, I think it's an all, all of the above, Jonathan, in, in terms of the, not ju- on the understanding side, it's the what is the software going to do? How is it gonna perform under different circumstances, as Colin talked about. But it's also then how is it what are user expectations? What do users do with it? What do different types of users do with it?<br>And I see this spanning across a range of different types of users and organizations. So if you have chief technical officers or engineers or software engineers at one place, they're gonna understand this problem very well. If you have your individual users, like, say, any of us that are on this podcast right now, our understanding of how this works is going to be radically different.<br>And I see that, I see that in terms of thinking about the differences again between how security professionals would deal with this subject and how...