Institute for Security and Technology

@istorg.bsky.social

We are the 501(c)(3) critical action think tank that unites technology and policy leaders to create solutions to emerging security challenges. https://securityandtechnology.org/

Recent cyberattacks on water utilities have highlighted our dependence on and the vulnerabilities in our critical infrastructure systems. For @huffpost.com, IST’s @joshcorman.bsky.social laid out how individuals and communities can prepare for potential short-term service disruptions. 🛡️ Read more:

Hackers Are Apparently Targeting U.S. Water Systems. Experts Share What You Should Do Now To Prepare

You don’t have to be a “prepper” to engage in some basic emergency preparedness.

huffpost.com

The FBI issued an urgent warning to water utilities across the country this week, following attacks in at least 7 states. IST Exec in Residence @joshcorman.bsky.social joined WJLA to lay out the threat this poses to our communities and share UnDisruptable27’s #CyberCivilDefense mission. ▶️ Watch:

Minnesota probes cyberattacks on water plants; Iran suspected, FBI warns utilities

A new FBI warning is raising concerns about the vulnerability of water infrastructure to cyberattacks, as authorities in Minnesota investigate what they say is

wjla.com

From record-breaking patches to the OpenAI breakout, it’s been a whirlwind month for #cyber defenders. IST friends & experts met today to unpack the latest developments in vulnerability management, AI, and more: “We may get to 5 million CVEs this year – is that good?” Lisa Olson said. ▶️ Watch more:

Vulns + AI = Oh My! From Sandbox Escapes to Record Patches

YouTube video by Institute for Security and Technology (IST)

youtube.com

🚨 NEW from IST: LLMs were never the whole of AI—only its first commercial frontier. Models like ChatGPT have captured the global spotlight, but text-based AI has inherent limitations. Enter world models. Today’s primer unpacks what these models do and why this transition matters. ❇️ Read more:

National Security and Policy Implications of World Models

LLMs were never the whole of AI—only its first commercial frontier. Though models like ChatGPT have captured the global spotlight, text-based AI has inherent limitations. Enter world models. This prim...

securityandtechnology.org

Over 30 communities in Minnesota saw water and wastewater utilities disrupted by a coordinated cyberattack this week, the state announced on Tuesday. IST Exec in Residence @joshcorman.bsky.social spoke to @statescoop.bsky.social on what’s novel – and what’s not – about this attack. 🛡️ Read more:

Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities | StateScoop

A cyberattack of undetermined origin disrupted water treatment plants in at least 30 communities in Minnesota, according to the state's technology bureau.

statescoop.com

In the Bay Area last week, IST's Andrew Carnegie AI-Nuclear Policy Accelerator brought together 25 of nuclear policy’s rising stars for 5 days of in-person, technical immersion trainings, discussions, and site visits to confront the intersection between AI and nuclear issues.

BildBild

🚨 NEW: Japan’s role in the Artemis program demonstrates what deeper U.S.-Japan space cooperation can achieve. In an era of strategic competition, this trust could prove transformative. Today’s report presents the case for this partnership to move to an integrated, strategic approach. 🚀 Read more:

From Artemis to Allied Advantage: Accelerating U.S.-Japan Space Cooperation Through Strategic Technology Partnerships

Japan’s role in the Artemis program demonstrates what deeper U.S.-Japan space cooperation can achieve. In an era of strategic competition, this trust could prove transformative for both. IST Distingui...

securityandtechnology.org

The New York Times has attributed the 2025 cyber attack on Jaguar Land Rover to Russia-based actors. If international adversaries can take down a massive manufacturer during peacetime, His Majesty’s Government must respond, IST’s Nicholas Leiserson writes for the #NatSpecs blog. 🛡️ Read more:

What’s in a Norm?

What’s in a norm? The New York Times’s recent reporting linked last year’s cyber attack on Jaguar Land Rover to Russia-based actors, but the UK government has remained silent. IST’s Nicholas Leiserson...

securityandtechnology.org

The Eleventh #RevCon of the Nuclear Nonproliferation Treaty ended with no consensus document, a concerning trend since 2015. But growing multilateral support for nuclear risk reduction and crisis comms tools like IST’s #CATALINK signals a path forward, IST’s Catherine Murphy writes. ⚠️ Read more:

RevCon Ended Without Consensus. Risk Reduction Did Not.

Despite the 2026 NPT Review Conference ending without consensus, growing multilateral support for nuclear risk reduction and crisis communication tools like IST's CATALINK Initiative signals a path fo...

securityandtechnology.org

What’s in a norm? The New York Times’s recent reporting linked last year’s cyber attack on Jaguar Land Rover to Russia-based actors, but the UK government has remained silent. IST’s Nicholas Leiserson calls on policymakers to act lest their silence encourage future attacks. 🛡️ Read more:

What’s in a Norm?

What’s in a norm? The New York Times’s recent reporting linked last year’s cyber attack on Jaguar Land Rover to Russia-based actors, but the UK government has remained silent. IST’s Nicholas Leiserson...

securityandtechnology.org

Understanding AI systems’ technical DNA is crucial to ensuring trust, resilience, and risk management. In Driving AI Transparency, IST Adjunct Allan Friedman and SVP Nicholas Leiserson make the case for establishing a shared vision of Artificial Intelligence Bills of Materials. ❇️ Read more:

Driving AI Transparency: Supply- and Demand-Based Paths Toward AIBOM

Understanding AI systems’ technical DNA is crucial to ensuring trust, resilience, and risk management. A new policy memo makes the case for establishing a shared vision of Artificial Intelligence Bill...

securityandtechnology.org

🚨 In 20 min, join us for a webinar unpacking the latest developments in the vulnerability management landscape. Is CISA’s BOD 26-04 the right approach? What are the initial reactions to the CVE bill? Bring your thoughts, hot takes, and questions! Register: securityandtechnology.org/event/vulns-...

Vulns + AI = Oh My!

AI is reshaping vulnerability management… and reshaping policy debates along with it. Join Institute for Security and Technology friends and adjunct advisors (and some CVE board members!) for a lively...

securityandtechnology.org

A provision to the Senate’s annual defense spending bill could give defense contractors direct access to U.S. #cyber operations. This morning, IST convened our friends and adjuncts to break down what this could mean for the future. “[This is] the riskiest path],” Nick Leiserson shared. ▶️ Watch:

Contractors at the Keyboard? Private Offensive Cyber Operations Authorities in the FY27 Senate NDAA

YouTube video by Institute for Security and Technology (IST)

youtube.com

IST CEO Philip Reiner joined the The Prode podcast for a conversation on the Quad partnership’s role in the Indo-Pacific, regional cooperation, tech & the growing partnership between the U.S. and India: "You don't have to militarize the Quad in order to…share information.” 🌐 Watch the discussion:

Former White House NSC Senior Director Philip Reiner on the QUAD and the Indo-Pacific | The Prode

YouTube video by The Prode

youtube.com

As AI becomes the backbone of modern infrastructure, how do we make sure the tech is secure? In a new memo, IST Adjunct Advisor Allan Friedman and SVP Nicholas Leiserson call for greater transparency in AI systems, and present their solution: Artificial Intelligence Bills of Materials. ❇️ Read more:

Driving AI Transparency: Supply- and Demand-Based Paths Toward AIBOM

Understanding AI systems’ technical DNA is crucial to ensuring trust, resilience, and risk management. A new policy memo makes the case for establishing a shared vision of Artificial Intelligence Bill...

securityandtechnology.org