Understanding and advising on cyber and physical risks to the nation’s critical infrastructure.
Originally published by AI Trends on October 22, 2020. This restored edition preserves the interview as a period document. Relative references such as “the past month” refer to the weeks preceding that date. ([aitrends.com](https://www.aitrends.com/?trk=public_post_main-feed-card-text))
Brian R. Gattoni was Chief Technology Officer of the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA). He was responsible for the technical vision and strategic alignment of CISA’s data and mission services. Previously, he was Chief of Mission Engineering and Technology, developing analytic techniques and approaches intended to increase the value of DHS cyber-mission capabilities. Before joining DHS in 2010, Gattoni served in positions at the Defense Information Systems Agency and the United States Army Test and Evaluation Command. He holds a Master of Science in cyber systems and operations planning from the Naval Postgraduate School and is a Certified Information Systems Security Professional.
Historical note: Official CISA material corroborates this biography and identifies Gattoni as the agency’s CTO during this period. The title is retained as of the interview and should not be read as a claim about his current position. ([cisa.gov](https://www.cisa.gov/resources-tools/resources/zero-trust?utm_source=openai))
AI Trends: What is the technical vision for CISA to manage risk to federal networks and critical infrastructure?
Brian Gattoni: Our technology vision is built in support of our overall strategy. We are the nation’s risk advisor. It is our job to stay abreast of incoming threats and opportunities for managing general risk to the nation. Our efforts are directed toward understanding and advising on cyber and physical risks to the nation’s critical infrastructure.
It is all about bringing in the data, understanding what decisions need to be made and can be made from that data, and determining what insights are useful to our stakeholders. The potential of AI and machine learning is to expand operational insights with additional data sets and make better use of the information we have.
What are the most prominent threats?
Among the threats we frequently discuss are adversarial actions by nation-state actors, and by groups aligned with nation-state interests, intended to disrupt national critical functions in the United States.
Just in the past month, we have seen increased activity from elements supporting what the government refers to as Hidden Cobra—malicious cyber activity attributed by the U.S. government to North Korea. We have also issued alerts with government partners highlighting activity associated with Chinese actors. On CISA.gov, people can find CISA Insights, which provide background on particular cyber threats and the vulnerabilities they exploit, together with mitigation activities that non-federal partners can implement.
October 2020 verification note: On August 26, 2020, CISA, the Treasury Department, the FBI and U.S. Cyber Command issued the FASTCash 2.0 advisory concerning the BeagleBoyz, described as a subset of Hidden Cobra activity. On September 14, 2020, CISA published an advisory, with contributions from the FBI, concerning Chinese Ministry of State Security-affiliated cyber activity. These records corroborate the interview’s immediate threat context, although they do not establish every partnership detail recalled in the answer. ([cisa.gov](https://www.cisa.gov/sites/default/files/publications/AA20-239A_FASTCash%25202.0_North_Korea_BeagleBoyz_Robbing_Banks_S508C.pdf.pdf?utm_source=openai))
What role does AI play in the plan?
Artificial intelligence has a significant role to play in supporting the decisions we make as an agency. Fundamentally, AI will allow us to apply our decision processes to a scale of data that humans cannot keep up with, especially in the cyber mission.
We remain cognizant of how we make decisions in the first place, and we target artificial-intelligence and machine-learning algorithms that augment and support that decision-making process. We will be able to use AI to provide operational insights at greater scale and across a broader mission space.
How far along are you in implementing AI at CISA?
Implementing AI is not as simple as installing a new business-intelligence tool or introducing a new email capability. Truly augmenting current operations with artificial intelligence requires a mix of changes.
It is a culture change: humans must understand how AI is supposed to augment their operations. It is a technology change: you must have scalable computing and the right tools to perform the mathematics involved. And it is a process change. We want to deliver artificial-intelligence algorithms that support and augment our operators’ decisions.
Where we are in the implementation is closer to understanding those three things. We are working with partners in federally funded research and development centers, national laboratories and the department’s own Science and Technology Directorate Data Analytics Technology Center to develop capability in this area. We have developed an analytics meta-process that helps systematize how we take in data and puts us in a position to apply artificial intelligence to expand our use of that data.
Verification note: DHS records confirm that its Science and Technology Directorate operated the Data Analytics Technology Center in 2020 to evaluate advanced analytics and computational capabilities for homeland-security missions. ([dhs.gov](https://www.dhs.gov/sites/default/files/publications/privacy-pia-st040-datc-august2020_updated.pdf?utm_source=openai))
Do you have an example of how AI is being applied in CISA or elsewhere in the federal government—or what you are working toward?
I have a recent use case. We have been working with partners over the past couple of months to apply AI to a humanitarian-assistance and disaster-relief mission. Within CISA, we also have responsibilities for critical infrastructure. During hurricane season, we have a role in advising on potential effects on critical-infrastructure sites in a hurricane’s path.
We prepared an experiment using AI algorithms and overhead imagery to determine whether we could analyze data from a National Oceanic and Atmospheric Administration flight over an affected area. We compared that imagery with baseline imagery from Google Earth or ArcGIS and used AI to identify affected critical infrastructure.
We could see the extent to which assets such as oil refineries were physically flooded. We could assess whether an asset had reached a damage threshold warranting additional scrutiny, or whether we did not need to apply resources because its resilience remained intact and its functions could continue.
That is a useful example of letting a computer perform comparisons and make a recommendation to human operators. We found that it was very good at telling us which critical-infrastructure sites did not need additional intervention.
To use a needle-in-a-haystack analogy, one useful thing AI can do is blow hay off the stack in pursuit of the needle. That is a win, too. The experiment was very promising in that sense.
Evidence note: The preceding account remains Gattoni’s description of an experiment. The interview provides no storm name, model documentation, sample size, accuracy rate, error analysis or independent evaluation, so it does not establish effectiveness at operational scale. As of September 4, 2026, DHS’s AI inventory describes a separate FEMA geospatial-damage-assessment use case in which AI prioritizes imagery for review while human analysts retain judgment; that later program is analogous but does not independently validate the CISA experiment described here. ([dhs.gov](https://www.dhs.gov/ai/use-case-inventory/fema?utm_source=openai))
How does CISA work with private industry?
We have an entire division dedicated to stakeholder engagement. Private industry owns more than 80 percent of the nation’s critical infrastructure. CISA therefore sits at the intersection of the private sector and government to share information and ensure that resilience is in place for both government and private entities, in support of national critical functions.
Over the past year, we have defined a set of 55 functions that are critical to the nation. When we work with private industry in those areas, we try to share the best insights and make decisions that will ensure those functions continue in the face of a physical or cyber threat.
Historical note: The fixed “more than 80 percent” estimate appeared in federal policy material as early as 2003. CISA material published in 2020 used the more cautious formulation that a majority of U.S. critical infrastructure was privately owned and operated. The percentage is therefore retained as a period estimate, not presented as a current measured statistic. CISA records also confirm that the agency identified and validated 55 National Critical Functions in 2019. ([cisa.gov](https://www.cisa.gov/sites/default/files/publications/LRTF%20Information%20Sharing%20Report%20%28Sept%202003%29_0.pdf?utm_source=openai))
Cloud computing is growing rapidly. We see strategies involving multiple public-cloud vendors or a hybrid of private and public clouds. What is the best approach for the federal government?
In my experience, the best approach is to provide guidance to chief information officers and chief information security officers across the federal government, while allowing them the flexibility to make risk-based determinations about their own computing infrastructure rather than prescribing a one-size-fits-all approach.
We issue use cases that describe, at a high level, reference architectures for types of cloud implementation, where security controls should be implemented, and where telemetry and instrumentation should be applied.
Some departments and agencies have a public-facing portfolio of citizen services for which access to information is a primary responsibility. Public clouds and their ease of access may be most appropriate for those agencies. Other agencies have more sensitive missions and high-value data assets that must be protected in specific ways. Our focus is giving each agency the guidance it needs to handle its use cases.
Contemporaneous note: CISA’s July 2020 Trusted Internet Connections 3.0 reference architecture defined use cases that included conceptual architectures, security patterns, implementation guidance and telemetry guidance. CISA’s 2020 cloud-interface architecture likewise addressed common cloud configurations and the collection of security telemetry. ([cisa.gov](https://www.cisa.gov/sites/default/files/2023-02/cisa_tic_3.0_vol._2_reference_architecture.pdf?utm_source=openai))
How are you defining AI-related job roles at CISA, including data scientists and data engineers?
I could spend the remainder of our time on job roles for artificial intelligence; it is a favorite topic of mine. I am a strong proponent of treating data science as a team sport.
We currently have engineers, analysts and operators. The roles and disciplines of data scientists and data engineers have been evolving from additional duties assigned to analysts and engineers into their own subsector and discipline.
We are looking at a cadre of data professionals who serve almost as a logistics function for the operators conducting mission-level analysis. If you treat data as an asset that must be moved, prepared, cleaned and made ready, you begin to realize that this work requires logistics functions similar to those required for any other asset that must be moved.
If you have professionals dedicated to that work, you can scale to the data problems you face without overburdening the engineers building computing platforms or the mission analysts interpreting the data and applying insights for stakeholders. You will have more team members moving data to the right places and enabling data-driven decisions.
Are you able to hire the people you need? Where are the gaps?
As the domain matures and we understand more about its different roles, we begin to see gaps in education and training programs that need to be developed.
Three or five years ago, you might have seen higher-education certificate programs in data science. Now we are starting to see full-fledged degrees and concentrations within computer science or mathematics. Those graduates are the pipeline that will help us fill current gaps.
As for our immediate problem, there are never enough people. It is always hard to recruit good candidates and retain them because the competition is so intense.
At CISA, we continue to invest not only in retraining our own people but also in developing a cyber education and training group that works with academic partners to strengthen that pipeline. It continually improves.
What should high-school or college students interested in an AI career study?
My message is similar to the one I give the high-school students who live in my house: do not give up on math so easily.
Mathematics and science—the STEM subjects—provide foundational skills that may apply to your future career. That is not to discount the diversity and variety of thought that come from other disciplines. I tell my children they need a mathematical foundation that will let them apply the thought processes they learn from studying music, art or literature, and the different ways those disciplines help them make connections. But they need the mathematical foundation to represent those connections to a computer.
One fallacy surrounding machine learning is that it will simply learn by itself. That is not true. You have to be able to teach it, and at the base level you communicate with computers through mathematics.
If you have the mathematical skills to relay complicated human thought processes to a computer, allowing it to replicate patterns and identify what you are asking it to do, you can succeed in this field. If you give up on mathematics too early—it is a progressive discipline—and then return years later to jump from Algebra II directly into calculus, success will be difficult, although not impossible.
You sound like a math teacher.
A simpler way to say it is this: if you say no to mathematics now, it is harder to say yes later. If you say yes now, you can always say no later if data science turns out not to be your field.
Are there incentives for a recent college graduate to work for the government, such as loan forgiveness?
We have a variety of programs. One that I particularly like, and with which I have had considerable success as a federal hiring manager—especially during my past 10 years at DHS—is Scholarship for Service.
It is a CyberCorps program through which students who complete the selection process can receive support for a degree in exchange for a period of government service. It used to be two years; it might be longer now, but recipients owe a period of service to the federal government after completing their degrees.
I have seen many successful candidates emerge from that program and go on to excellent careers, contributing in cyberspace throughout the field. I have interns whom I hired nine years ago who are now senior leaders in this organization, or who have moved into private industry and are making a difference there. It is a fantastic program for young people to know about.
September 2026 update: The current NSF program is named CyberAICorps Scholarship for Service, an extension of CyberCorps. Its scholarship track requires recipients to work in the AI or cybersecurity mission of a government organization for a post-graduation period at least as long as the scholarship period. Gattoni’s uncertain recollection of a two-year rule should not be treated as current program guidance. ([nsf.gov](https://www.nsf.gov/funding/opportunities/cyberai-sfs-cyberaicorps-scholarship-service/nsf26-503/solicitation?utm_source=openai))
What advice do you have for government agencies just beginning to pursue AI?
My advice to peers, partners and anyone else willing to listen is this: when pursuing AI, be very specific about what it can do for you.
I return to the decisions you make and what people are counting on you to do. You bear responsibility for knowing how those decisions are made if you are going to use AI and machine learning to make them faster, better or otherwise improve their quality.
The speed at which you make decisions can work both ways. You must identify the benefit if a decision is positive and define the regret if it is negative. Then create a simple high-low matrix. The target is the quadrant containing high-benefit, low-regret decisions. Those are the decisions I would like to automate as much as possible. If artificial intelligence and machine learning can help, that is valuable. If not, you have another decision to make.
I use two examples from our cyber mission to illustrate the extremes.
One is incident triage. When a cyber incident is detected, we have a triage process to determine whether it is real and present information to an analyst. If that process is performed correctly, it has a high benefit because it can remove a significant amount of work from analysts. It has low-to-medium regret if performed incorrectly because the decision is merely to present information to an analyst, who can apply an additional filter. That is high benefit and low regret—a clear candidate for as much automation as possible.
At the other end of the spectrum is protecting next-generation 911 call centers from a potential telephony denial-of-service attack. One possible automated response would be to cut off incoming traffic to a 911 call center to blunt the attack.
The benefit is that you may prevent the attack. The regret is that you may cut off legitimate traffic to a 911 call center, creating life-and-safety consequences. That is unacceptable. It is an area where automation is probably not the right approach.
Those are extreme examples, but they are easy to understand and illustrate how the benefit-regret matrix can work. Understanding how you make decisions is the key to deciding whether AI and machine learning should help automate them using the full breadth of available data.
Portable principle: Automate high-benefit, low-regret decisions first. Retain accountable human control where a false decision could interrupt essential or life-safety services.
Learn more about the Cybersecurity and Infrastructure Security Agency.
Responses