LTC Ellis Parks [00:00:07] Give them one more minute Ladies and gentlemen, thank you for joining us for the Cyber Shield 2026 Media Roundtable. Online, we understand we have a host of media groups, and in the audience here at the National Guard Bureau's Professional Education Center, we are joined by Channel 7 ABC News. Let me begin by first thanking each of you for joining here today. Cyber Shield of 2026 is the host for more than 1,000 cyber professionals. With more than 800 coming from a mix of military compositions to include the Space Guard, more than 44 states and territories, and 23 of our state partners from the National Guard State Partnership. Okay, and a dynamic blend of critical and global thinkers in the world of science before we begin This is being recorded, and a video and a transcript will be shared online afterwards. After introductions and the opening statements, we will go through the list of media participants, first online and then here in the room, to ask one question and one follow-up question. Please keep your lines muted. When not speaking. We are here for an on-the-record discussion regarding CyberShield 2026, and we appreciate if all participants focus their questions and comments on Cyber and CyberShIELD only. With that being said, first, our host for today's event, Lieutenant Colonel Seth Maron.
LTC Seth Barron [00:02:38] Good morning. My name is Lieutenant Colonel Seth Barron. I'm the exercise officer in charge. I just want to say thank you for being here. This is the 13th year of Cyber Shield that we've conducted and it continues to grow. This our biggest Cyber Shield so far with the most international participants. You know, this year, each year we focus on a critical infrastructure sector. This year, we chose to focus on the power sector. Um, and By doing that, it gives the participants in the exercise, not just the blue teams, the training audience, but also our opposing forces red team, the ability to deep dive into some of the threats and vulnerabilities that are in those particular systems. And I don't think there's an exercise that exists that does a better job of integrating the opposing forces and the training audiences in building a partnership and identifying those vulnerabilities and then building tactics, techniques, and procedures to try and remediate those. And they have the ability to then take that back to their states or countries and start to implement some of those things that they've learned and hardened the networks. So CyberShield is a defensive-focused exercise that allows everybody involved to learn something and benefit and network. So with that, I'll turn it over Brigadier General McGuire, the exercise director. Thank you.
Brigadier General Russell McGuire [00:04:11] Well good morning everybody and on behalf of General Nordhaus, the Chief of the National Guard Bureau, I welcome you all here and thank you for taking the time so we can highlight some of the amazing things these warriors are doing to protect the cyber domain. What I want to do is tell you a little bit about what I do, what the National Guard does, and sort of where we're going. So for General Nordhaus, I'm his vice director of operations for cyber for the 54 states and territories for the Army and Air National Guard. And where are we going with this? You know, warfare has been evolving since the beginning of time. If you just go back 125 years ago, there were no airplanes. There were no tanks. There were not automobiles. Warfare constantly changes and evolves. And the newest domain for warfare is cyber domain. And it has been rapidly evolving. For about 50 to 60 years. And now it's mainstay. As I grew up with the child, as a child, there were no computers in the house, but maybe one in a neighborhood. Now, not only is there a computer in every house, everyone walks around with a much more powerful computer with them all day long in their phone that has far more computing capacity than anything I saw in the 80s. So with that, gives opportunities to adversaries to try to harm the things that we do. And we're lucky to have people here like the gentleman sitting beside me, Tim Conway, who you will meet in a minute, who has done a tremendous amount as to help our country and countries around the world prepare for these threats. And what are these threats? You heard the director of the FBI talk about a couple of years ago, Christopher Wray, and General Nakasone talk about. The threat actors are already here. They're living on the networks. It's not about if they're on your networks and they're gonna execute, it's when that they are. So we need to be prepared to ensure that we can provide for our nations to make sure that they can continue to operate. And the cyber domain is the one that can really impact the ability to function. We've seen cyber attacks in the U.S. Whether it's the colonial pipeline incident. And if you think about that incident from a couple of years ago, I know because I was stuck in the outer banks because there was no gas. And it wasn't even no gas because of the ransomware. It was no guess because of the panic over the ransom ware. That's the impact that these attacks can have. So I thank you all for being here, but just know that just like technology and warfare evolves, So does the National Guard. And we continue with our motto that we're always there and always ready. And thank you.
LTC Ellis Parks [00:07:15] Thank you, sir. We are very lucky to have with us representing one of our private industry partners, Tim Conway.
Tim Conway [00:07:22] Good morning, everyone, and thank you for having me and allowing me to join this panel. I'm the only one here not in uniform. I stand out a bit, so I will introduce myself. My background, I formerly worked for utilities, combined natural gas and electric utilities for about 16 years in real-time system operations across control centers, generating stations, substation, distribution, transmission, market environments. We covered about 14 states throughout the United States. Throughout that career, And where I moved since then, I've had the opportunity to work and contribute to exercises as a industry partner. And as I moved into contracting roles for Department of Energy and other government organizations and into a training environment where we are trying to prepare war fighters and asset owners and operators to defend their systems, specifically in industrial control system space and operational technology. I've the opportunity to work with some of them throughout. This time on exercises like this and global throughout many different parts of the world and there are exercises where we are trying to learn from exercise constructs like CyberShield and others that have been underway for 15, 16 years and then appearing in a partner nation where they may be conducting their first exercise and really trying to take the lessons learned here, have information sharing and have that collaborative kind of training environments. And everywhere we go, what we can learn to then bring back to contribute to exercises here at home and continue to mature them. Even if we are in a nation where it is their first exercise, they may have undergone a significant number of direct attacks that we can from and enable in their exercise so it's threat informed and immediately bring that knowledge back into our exercises as if those attacks happened to us here in the U.S. As we prepare for a number of different scenarios. Impacts to service to our homes, impacts and services to our communities, and potentially impacts at a national strategic level, making sure that we have a public-private partnership that will function and be able to defend those systems at a time of need. Thank you again for having me.
LTC Ellis Parks [00:09:35] Thank you, Tim. We are also very lucky to have with us two of the 23 countries here at CyberShield this year on our panel today. As we know, the cyber or information domain has no borders. So to help us close that gap, first representing Portugal. Wanna introduce yourself?
Captain Goncalo Atanasio [00:09:56] Yes. So good morning to everyone. I'm Captain Gonçalo Tanazi. I am here representing the Portuguese Armed Forces Cyber Command. I m part of the Portuguese Mil-Sert, so I kind of am responsible for the defense part of Mil-sert capability. So first of all, I would like to thank the United States, the National Guard, the Illinois National Guard for starting this partnership with us. That allowed us to come here, participate in your exercise. It's been very good so far for us. Last week it was training, we learned a lot. And it's very good, like everyone is talking about, like cybersecurity has no borders, cyber defense has no border. We need to learn from each other. And right now, I think it's important to be aware of the focus of this exercise, like critical infrastructure. It's very important we learn how to defend our systems, like if it's gas problems or energy problems like we have had in Europe. So basically we don't know what's going to happen next. So we need to be prepared and we need change our mindset from being passive to being proactive. So everything about this the past week was always about threat hunting. The exercise started yesterday. We need to do a lot about that, threat hunting, like vulnerability management. So I think it's important. This partnership needs to keep growing. We are very happy that it started and we are hoping that it continues to grow in the future. So thank you. Excellent, thank you so much.
LTC Ellis Parks [00:11:45] Thank you very much. And representing Brazil.
Captain Renato Zaroubin [00:11:53] Good morning, everyone. I'm Captain Renato from Brazilian Army, representing the Brazilian Cyber Defense Command. First, I'd like to thank National Guard and all the efforts you bring to make this exercise possible. It's been a privilege for us to be in here to learn from you. Last few days, we were having instructions and trainings. We are delighted with what all efforts you did. No things would come up for us. One of the greatest things you bring for us is how the cyber attacks can come from the IT network for the OT environments. That can bring for real world's consequences. So something that starts on the digital world, it starts on computers, can cause harm and physical words like power grid disruptions and stuff like that. And starting these weeks, you can make the exercise even greater. Allowing us to see in the real time attacks and try to manage what's happening to environments and try figure out how the malicious actors are coming to our networks. So it's been really great. And I'll read it for them. Thank you.
LTC Ellis Parks [00:12:54] Thank you. At this time, for those introductions, thank you for those introduction, but at this time we are now ready to move to our media that's online.
Moderator [00:13:04] You ready? Yes, sir. First, we have Mark Palermo with Breaking Defense. If you have a question, go ahead.
Reporter [00:13:12] Good morning, can you hear me?
Moderator [00:13:14] We can.
LTC Ellis Parks [00:13:14] Mark, go ahead.
Reporter [00:13:16] Super. Thanks so much for doing this. I know that you mentioned that you focused this year on a particular set of the critical infrastructure ecosystem. I'm just curious how this year has been different from years past and how you've sought to maybe up the ante or up the difficulty in terms of the training fidelity for the airmen and soldiers that participated.
LTC Ellis Parks [00:13:42] Yeah, count on Barry. You want to take that went on?
LTC Seth Barron [00:13:45] Sure, great question. It is a challenge every year to raise our game. And I think part of that is having world class up for opposing forces to try and do that. I can't give everything away because we haven't gotten to that part of the scenario yet, but I will say this year we've integrated. It's not just a digital environment, but there is a physical component to it this year. And I that adding that realistic piece to it while also improving our cyber range ability to simulate the power grid really brings a new level to the realistic scenario. At the same time, we also are taking real-world tactics, techniques, and procedures from malicious actors and integrating those into the exercise. So everything we do here is based on attacks that we have seen in the real world. So combining those two things a physical component as well as the latest trends and and attack vectors really gives us the ability to to up our Our skill set as well. As make it a little bit more challenging for the blue teams mark. Do you have a follow-up?
Reporter [00:15:00] Yes, was this the first year that you included a physical component in terms or in addition to the the virtual range?
LTC Seth Barron [00:15:10] We did it a few years ago, but this is our first year where it's fully integrated into the system. It was sort of a standalone thing previously, but now it's full integrated. Mark, thank you for.
LTC Ellis Parks [00:15:22] Your question. If we can, we'll come back to you.
Moderator [00:15:26] Yes, sir. Next we have Jade and Beard with Inside Cybersecurity.
Reporter [00:15:33] Hi, I was wondering if you could talk about kind of the differences between the exercise this year compared to last year and what's new. Thank you.
LTC Seth Barron [00:15:48] Lieutenant Colonel Barron again. So again, the exercise is bigger this year. We have more international partners. We also have more enclaves or participants than we've ever had. At the same time, you know, based on my last answer, we switch which critical infrastructure sector we focus on each year. And so this year, you're switching to the power grid. In the past, We've done transportation. We've done water and wastewater treatment. We've got election systems. So, and then last year we did critical agriculture. So it gives a new vision and a new focus year after year on how we're doing that. Also, bringing some of the physical components into it. But also, I think from my standpoint, upping the training value. This year we built a course. That was for international partners that set side by side with some of the their teammates that they're going to be on teams with this this year. We also did some more advanced training, in particular penetration testing on operational technology that help advance the skill set and bring that those those people with elite skills back to the exercise year over year.
Moderator [00:17:09] Excellent, thank you, sir. Next up, we have Carly Nelson with Army Magazine.
Reporter: [00:17:15] Good morning, everyone. Thanks so much for doing this. For my first question to lay the foundation, I was curious what the most pressing cyber threats that we're facing today are that we are getting after with CyberShield. Thank you.
Brigadier General Russell McGuire [00:17:33] Thank you for this question. I think that really what's important, this is General McGuire, if you could not see me, I think really what we're looking at is that OT. Looking at that, that is the threat vector. Just think about this, go back to pre-pandemic. Most of our workforce went to office buildings. And I saw at firsthand at that point that when I was the JTF cyber commander, is that as we transitioned to remote work, It created tremendous vulnerabilities. And our critical infrastructure, those employees wanted to work from home also. So we started having IT connected to OT, which created a new threat vector. And that's why we need people like Tim and his expertise and we need to replicate what he's doing across the board. So I would say that not just the exercise, but the National Guard Bureau has truly been focusing on OT. In fact, we've got a number of pilot programs going around the nation right now. To make sure soldiers and airmen can respond to those OT and provide that assistance to make sure the threat actors are off those networks. We've been building that up a little bit more the past couple of years, but this year is the most robust, because I do think that's probably the greatest threat and vulnerability. There's a lot of cybersecurity IT experts out there. There is not as many OT experts. And I also want to add one point about this exercise, in particular. Beneficial this year. We've done it in the past. We were able to bring sands back this year for net war So we had almost 400 Participants and I think it's so impressive Doing this that they do this on their own time on the weekends in the evenings This is time. They could be hanging out catching a movie Relaxing but the the knowledge that they build just being in that room with these other experts competing it With each other is what makes this such a great exercise for them to take back to their units, to their jobs, and that's why they keep coming back and growing each year. Thank you.
LTC Ellis Parks [00:19:37] Charlie, that's a great question. I'll expand this question or allow this question to be answered by other panelists as well. And sir, thank you for that answer.
Tim Conway [00:19:44] I'll jump in. This is Tim Conway. Thanks for the question. Just a couple of things that I've seen and exercises and this is no different. As we look at threat-informed scenarios of what are we trying to prepare for, we are obviously looking at the threats and attacks that have occurred. So as you look to sectors of target, there is a need to continue to come back to the electric sector as attacks on the electric factor impact all sectors instantaneously. Many other sectors have the ability to operate for three days, kind of 72 hours. But over time the attacks on the electric sector will impact all. And that is a reason even after you've exercised it once, you can go off in another year and look at impacts to data centers, you could look at impact to water, but it's really important to continue to come back to the electric factor as a common target. And that has absolutely been in the adversary nation space of what is being targeted over and over and again. So choosing the electric is extremely important. Then looking at what parts of the electric sector, whether it's generation, transmission, distribution, we've now seen attacks across all of them that have occurred in the real world and they continue to change and how they're changing from a impacts of in the previous years of just outages to equipment destruction, making it longer term outages and harder to recover from. Making sure that is informed in the scenario and making sure the people working the scenario understand how to go recover those systems because they're very different than IT. Attacks within an IT environment, how you run your company and the tools and systems you use are very different that attacks that are impacting industrial control systems and operational technology, which is the equipment that you use to generate why you exist as a company, whether you're producing a megawatt or moving it for delivery in the electric space, very, very different targets than IT, I would also just comment on the learning approach that has been taken here at Cyber Shield. Where we get the opportunities to sort of work through and train individual skill sets in a classroom Where they follow notes and they follow the lab instructions and they do a thing to achieve an outcome but then they have the opportunity to walk through an exercise and see what it would look like in the real world and then as mentioned the opportunity come in net wars and Put all of that learning into practice as if it's a real-world attack It's happening working in teams the same way they would in the Real World and in unstructured way No lab notes, no direct instructions, but responding dynamically to attacks that are occurring is a very unique combination of training environments.
LTC Ellis Parks [00:22:16] Carly, we want to continue that trend and allow our international partners to answer if they would like. So Portugal or Brazil? Talking about the right actors.
Captain Goncalo Atanasio [00:22:27] So I think what Tim said is very important. So the electrical sector is one of those sectors then when you impact it, it's like a snowball. So everything goes bad in all the sectors. But one critical thing here is these systems, not all of them, but some of them are not secure by default. So... You need to know really what you are looking at and how you can secure them, not even only reactive, like being reactive to an attack, but being proactive how to secure them. Because it's the little things that make the biggest difference. And if we are not only talking about the power grid, if we talk about simple systems like card readers and stuff like that we have at our buildings where we work. Uh, every like electrical thing that's as a low level and doesn't haven't been updated for probably two, three, four years, it's going to be vulnerable. So if they get into your card system, they can get into you or not network. They can get wherever and then can escalate. So we need to be aware of these low level.
Captain Goncalo Atanasio [00:23:45] Sorry about that. So that's it. So I think we need to be careful about these little things that sometimes go unnoticed. And we need things that are not secured by default. That's my biggest thing. Brazil? Thank you.
Captain Renato Zaroubin [00:24:08] I think one of the great things about the electric sector is IT isn't core business of electrical sector. They have lots of telemetry. They have a lot of things run inside it. But when, as Brad said, when COVID comes, people go outside from their business. They have to work from home or work from other places. And we have a very fast shift from, oh, I work with this at the side of my equipment, so now I work from the home. And now internet has access to something that is in my network. And that brings a lot of breaks, a lot of fails that could be exploited. And the electrical system, electrical power grid is a very critical system for all the country, for civilians, and for everything else. So that's something that's really important when you look for electrical systems.
LTC Ellis Parks [00:24:57] Carly, I know that we went through the entire panel with that question, but do you have a follow up?
Reporter: [00:25:02] Yes, sir. Thank you. This won't be a quicker one Thank you so much to everyone for your responses on that Several of you have mentioned this more proactive approach called threat hunting. So I was curious What is that more aggressive proactive approach to threats look like in a practical sense? Thank you
LTC Ellis Parks [00:25:22] Anyone burning to take that one? All right, Portugal, go ahead.
Captain Goncalo Atanasio [00:25:26] Yeah, I can take that one since I was the one that talked about threat hunting. So, uh, so basically, uh threat hunting, uh it can be one of two ways. It can be behavior driven or hypothesis driven. Uh, I think the hypothesis driven is the most common one. So you basically, you have threat profiles. We are a whole here truck talking about threats and when you know, when you've identified the threads that can. Basically target you, you can get those profiles, understands what they do and ask questions about your infrastructure. Like, like, Uh, not said, uh, he was talking about, it's the little things on your IT network that can shift from the IT infrastructure to the OT infrastructure. And you can ask those questions to yourself. So you can, I have an exposed web server on the internet. Is this web server, if it's compromised, if they compromise the server, is it possible for them to go into our OT network in some way? So when you start asking yourself those questions you start threat hunting. So you can have that hypothesis, and then you will start to elaborate your plan to threat hunt on those hypothesis and to check if it's possible. If a malicious actor compromised your web server, public face web server. If he can like shift from that network segments to your OT network segment. And if that hypothesis is proven, it's not about finding the threat, but proactively. Protecting yourself. So you basically understood that it's possible you are going to secure our network even if you are not compromised. So threat hunting is not only about finding threats in your network, it's a good approach to improve yourself. And we have to assume breach at all times. So if we assume breach, basically you will be improving yourself.
LTC Ellis Parks [00:27:33] Portugal, thank you so very much. And for the rest of the panel, we can address that in your closing comments if you would like to follow up. Our next.
Moderator [00:27:40] Next up, we have Dan Barkin from Business NC.
LTC Ellis Parks [00:27:44] Dan, you have a question for us?
Moderator [00:27:51] All right. Now we have John Harper with Defense Scoot.
LTC Ellis Parks [00:27:57] John, go ahead with your question.
Reporter [00:27:59] Great, thank you. What is your overall assessment of how well the blue teams performed during this exercise, particularly when it comes to protecting that OT that you talked about? Terrell and Colonel Barron.
LTC Seth Barron [00:28:15] Lieutenant Colonel Barron again. So luckily, year over year we show we show great improvement. Um, you know, we Part of the reason we switch sectors each year is it brings a new chance to get training on that. We're very clear about cyber shield not being a validating exercise because we want people to make mistakes and get exposed to new ideas. We also wanna test new ideas, so blue teams, we bring a wide variety of blue teams. Some have been together for a long time, some like my own in North Carolina. I take my subject matter experts and I move them onto the. To the opposing forces, the red team. And I let my sort of beginners or newer people be onto the blue team so that they can learn and develop those skillsets and in threat hunting and incident response. So blue teams are continually showing improvement year over year, especially the ones that stay together. And I think if you ask anybody that participates in the exercise, what they knew on last Saturday when they arrived versus what they're gonna know. Next Friday when they leave is critically important. And from my opening comments to the exercises, everybody here should learn something, should meet somebody new and learn something from them, and then also enjoy the experience. And I think across that, that's the best learning environment that we've had for them. So I think, again, to answer the question, Blue Team showed great improvement from the beginning and then year over year, but we do continually look. To move those people that have been to CyberShield multiple times onto a different team so that they get a different experience and learn a new skill set.
LTC Ellis Parks [00:29:59] Thank you for that question. Do you have a follow-up?
Reporter [00:30:02] Yes, I do. Did you identify any capability gaps or particular areas of improvement that you're looking to build on going forward? What's kind of your overall takeaway from this exercise.
LTC Seth Barron [00:30:25] So for Cyber Shield, we invest a significant amount of resources into the assessment process. And so we have a full assessment team that spends the first week of the exercise just learning how to do a cyber exercise assessment. They go through the process. And so each team at the end of the exercises, what they'll get within 30 days after they leave is a customized report for that particular enclave that shows them, Hey, here's where you were. Where you were strong, here's where you're deficient, here are the areas that you can work on. And that's based on the exercise goals and objectives. And so overall, there's always a need to increase our operational technology learning. It's still new to a lot of our participants. And just investing in the training is critical. But each team will get a custom report. They can take away and then build their training plan for the next year so that when we come back to Cyber Shield 2027, they're much more prepared for what we'll see next year.
Moderator [00:31:33] Thank you sir. Next question. We do now have a question from Dan Barkin with Business NC. Go ahead. Right Dan.
LTC Ellis Parks [00:31:42] Lieutenant Colonel, can you hear me? We can.
Reporter [00:31:45] Okay, in North Carolina, particularly the National Guard has a very important role to play in many different areas of cyber security, and I'm just wondering, how well do you think the business community and the institutions K-12 schools, how What steps could be taken to try, if you don't think that there's enough awareness, you know, to consult with you before there's a breach or right when there is a breach. How do you raise that level of awareness?
LTC Ellis Parks [00:32:32] Then we're going to let Lieutenant Colonel Barron start, but then we'll also take it globally, and we'll ask, if you don't mind, Tim, can you approach that question?
LTC Seth Barron [00:32:43] Again. Um, so that's a great question. Um I never think we have enough awareness in North Carolina. I'm always surprised that that there are still K through 12 school systems or, um, you know, universities out there that that are not familiar with our with our ability in North Carolina, the Joint Cyber Security Task Force that we've established. I could tell you from from our standpoint, we're hosting, um you know exercises. Operation Tobacco Road is one. Where we try to get the word out. We hosted multiple capture the flag competitions for universities and high schools to try to start the education younger. We also do a number of speaking engagements from threat intelligence briefs to capabilities briefs across the state. And I think one of those things is really just trying to stay in the community and keep the word it out there. And we continue to invite. More and more partners to our events and keep trying to expand those and do more events that bring awareness to the program. But I'll defer to Tim to talk globally.
Tim Conway [00:33:53] Yeah, great question. From my perspective, I would say there's no shortage of activity in any state. So there are a number of different exercises that are happening and public-private partnerships across different sectors, different industries, from national level exercises to cyber storm to grid ex to all of the great exercises that the National Guard conducts in their home states. And they bring in multi-state exercises like Cyber Shield. The awareness from the individual kind of private sector, commercial entities, they have the first mode of operating where they have contracts with other commercial entities for incident response. And as we look at national level exercises and we say, if there was a impact across multiple organizations, there would be a resource availability challenge. And what type of force multiplier do we have? And what are we prepared for when those individual contracts are exhausted and there's no responders available? The different types of sectors, whether it's state, local resource, who could come to fight. And that is where the National Guard has a very unique position. And making sure that the training exists from a cyber domain, from an industrial control system and OT perspective, that is a key mission area for National Guard to focus on at the moment. And then again, continuing to prepare and practice as the utilities run their own exercises to ensure that the National Guard is in that room. Understanding what their authorities and what their roles and when they might be called to action, especially in times where we are in a societal chaos, some type of attack from an adversary nation as a deterrent from us getting involved in other geopolitical events. And as we look to our partners from other countries, how we can cooperate and have this mutual aid from country to country where some of our responders can assist in attacks occurring in their country. But... As you think of your local hospitals, your local schools, there is an absolute awareness because the activities are occurring. There was no shortage of activities. There's many people out there from a training perspective, from a capability, from exercises and opportunities to practice the way we play. We just need to make sure that messaging is getting out. And to be honest, that is why events like this really matter. The media plays an enormous role and making sure people are aware. Of the importance of this and the availability of it so they can participate as it happens.
LTC Ellis Parks [00:36:24] Tim, thank you for that shout out for public affairs and public information. We appreciate that. And Dan, thank for that question. Do you have a follow up?
Reporter: [00:36:32] No, thank you very much.
Moderator [00:36:35] Next up, we have Jane Pack, USA Journal.
LTC Ellis Parks [00:36:40] Go ahead with your question.
Reporter: [00:36:45] All right. Hello, can you hear me?
LTC Ellis Parks [00:36:48] We can, we can. You came in to step.
Reporter: [00:36:51] Thank you very much. Regarding cooperation with the allies, South Korea is highly vulnerable to cyber attacks from North Korea. Unfortunately, the cyber command has been downsizing. How is the cybersecurity cooperation currently processing between the United States and the allies of South Korea? Thank you.
LTC Ellis Parks [00:37:23] Do you want to approach that question?
Brigadier General Russell McGuire [00:37:27] I'll just say that we're only talking about CyberShield today. We leave those sort of issues for cybercom to address, but what we're preparing all of these soldiers and airmen, our international partners, that if they are called to action in their state or their nation, they're prepared to deal with the threats.
LTC Ellis Parks [00:37:44] Thank you, sir. Dan, do you have a follow-up question? And remember, once again, we are only focused on Cyber and Cyber Shield 2026 with our questions. All right, hearing no, we move on.
Moderator [00:37:59] Next, we have Courtney Vendetto from Signal Media.
LTC Ellis Parks: [00:38:04] Courtney, go ahead with your question.
Reporter: [00:38:05] Hello! Thank you so much for your time today. I was wondering if any of the panelists could touch on some of the key technologies or techniques used in this year's exercise.
Tim Conway [00:38:23] I will start the discussion. Thanks for the question. Definitely this one will land back to Lieutenant Colonel Souther Baron. But as we look at any of these exercises and we consider what we want to train when we bridge this gap between IT and OT, there needs to exist an IT infrastructure that can emulate what an adversary will get an initial foothold in. And depending on the adversary that is being emulated, we might be looking at criminal actors, you might be look at intellectual property theft, you might looking at a number of different things that could just live in that IT space alone. But as we begin to talk about impacts in the cyber physical world, so the delivery of clean water, the delivery natural gas for your home heating, the delivery electricity for essential services and key resources, you have to begin to understand this pivot from the IT to the OT world. And all of the interconnected systems and interdependent systems. And in order to simulate that, you need to then make all of those extended OT systems as part of this exercise. Then you need move down to the final control elements in the actual OT and industrial control system. So this becomes a very complex exercise environment to make sure that you are training resources in an adequate fashion and in a way that reflects the real world. As you build that entire architecture and then you look at threat informed what adversaries are doing. If an adversary living in the IT networks is making a tremendous amount of noise, most of these target environments, that's where they have tremendous amounts of detection. So they're doing everything they can from an adversarial perspective to evade detection and the phrase of living off the land and sort of using the tools and the capabilities that are already in all the information technology networks. To leverage them to pivot and navigate paths down into the OOT environments, and then begin to operate based on a commander's intent, that is what is being simulated. Not only all of the technology stacks, but how adversaries are targeting them and manipulating them to achieve an outcome.
LTC Ellis Parks [00:40:31] Thank you, Tim. Sir, do you have a follow-up?
LTC Seth Barron [00:40:36] Yeah I think probably the smartest thing we do when we plan an exercise like this is we bring Tim in and he helps us map out the technology that we need to use and sort of the threat factors that are out there. And so we also try to train on open source tools that are our there. I'll give you an example, Security Onion is one of the big ones that is in all of the enclaves so that it gives. The team's exposure to a tool like that that they can train on. Also this year, we're talking about home smart meters and then some of the UAS stuff is going to be integrated into the exercise. So it's really an evolution, but it starts with a conversation with a subject matter expert in that particular field. And that's how we build our scenario and build the technology into the exercises.
LTC Ellis Parks [00:41:33] Courtney, thank you for that question. Do you have a follow up?
Reporter: [00:41:37] Not at this time. Thank you so much.
LTC Ellis Parks [00:41:39] Thank you. Go to our next question.
Moderator [00:41:42] Next, we have Matthew Olay, Pentagon News.
LTC Ellis Parks [00:41:45] Matthew, do you have a question? All right, we'll go to our next question.
Moderator [00:41:53] Next we have Brendan Stevens.
LTC Ellis Parks [00:41:56] Brendan, do you have a question? Go ahead. A question? All right. So we will now, once again, go around online to find out that we have any follow-up questions from our online audience. Online, do you have any follows-up questions at this time? Hearing none, thank you. We will now take questions or any questions from those in the room. Reminder, please wait for the microphone, say your name and news affiliation before stating your question. Channel 7, do you have any questions for us? All right. Well, we do have some from the panel. Can we walk our microphone over, please? One of our international partners have a question for the panel.
Reporter: [00:42:59] Hello, gentlemen. Thank you for hosting us here in the third time in CyberShield. I want to ask if you're planning to involve AI in the challenges in the next practicing training and to see how the blue team handle with AI and try to solve the issues.
LTC Ellis Parks [00:43:29] Great question. Panel, do you want to take that on?
LTC Seth Barron [00:43:32] Absolutely, AI is going to be involved in this year's exercise to a certain extent. I can't talk too much about it. But absolutely, it's integrated two of the areas that we really want to lean more heavily into the cloud environment, which exists, but not probably as much as we'd like it to, and then AI. So it's definitely in future plans. It is a small part of this year. But I think as we evolve. Um, you know, the exercise, I think that will certainly, uh, next year, um, become a bigger, a bigger portion of it.
LTC Ellis Parks [00:44:09] Sir, do you have a follow up question? No, thank you. All right, thank sir. Once again, is there any media or any questions from our international partners at this time? All right. Hearing none, representatives from the panel, I will turn it over to you for closing comments. Lieutenant Colonel Barron will start with you.
LTC Seth Barron [00:44:32] Oh. I would just, again, reiterate thank you so much for joining us today. You know, this is my eighth Cyber Shield, and I'm very proud of the work that goes into everything that we do. It's a huge planning cycle. You know we have 150 people on the staff just to get the exercise planned and executed. And then, you know, we have probably another 300 that are in the supporting cells to make everything go. And it's really a tremendous effort, and I think. Everybody will will take multiple learning experience from this. And I think we continue to evolve and make the exercise better every year. But again, thank you so much for for joining us. General McGuire.
Brigadier General Russell McGuire [00:45:17] Yeah, I just want to say first of all, thank you to Brigadier General Jeff Wood, who's back there hiding in the back, who has been one of the really proponents of bringing this exercise back to Arkansas and making sure it runs smoothly for for him. And General Bridges, the tag just really appreciate all that you all done opening up the doors and making this work. So we made it all successful. And it illustrates the point for all this. No person can do it alone. It's that collaboration It's that constant communication, and that's what's gonna help us face the threats that are facing us all. Thank you.
LTC Ellis Parks [00:45:52] Thank you, sir.
Tim Conway [00:45:53] Again, I'd just like on behalf of SANS to just thank everybody for allowing us to be a part of this. I would highlight the key missions as this continues. The information sharing doesn't end when this exercise ends. The ongoing collaboration as people return back to their home countries and nations. The importance of the media role to drive awareness for exercises and capabilities that have been developed within the National Guard to be pursued by all the states. And last. From a training and exercise environment. I'm a Chicago kid, grew up in Chicago my whole life. Fan of the Chicago Bulls and a phrase that I'm gonna butcher, but Michael Jordan quoted as saying, lose every practice and win every game. This is our opportunity to lose here. This is an opportunity to learn, so we.
LTC Ellis Parks [00:46:36] Free game. Thank you. Tim, thank you very much for that, especially quoting a North Carolina hometown boy. To our international partners, first Portugal.
Captain Goncalo Atanasio [00:46:46] So, yeah, as we are closing, I just want to thank everyone that is here, all the countries that made here, and all the media to be interested in this subject, it's very important. And I just wanted to say that this exercise is not only about technical stuff. It's mostly about people knowing each other, because in Portugal, if we need something right now, I know. Who I can talk to. So even if we need to go through the chain of command, I have a lot of points of contact right now here, these kind of relationships is very good in the cyber world, not only with civilians, but with military, whatever that is like, we need those connections. So it's a lot about people and as the AI keeps growing, we need even more expertise on this subject, because we need the capacity to question AI. And that's even harder than the thing for ourselves, because before AI we thought by ourselves, but now we need to question what AI is telling us. So it's even hard. So we need it to be even smarter, as I can say that. So, Yes, my closing remarks goes towards that low. So partnerships, very important. Thanks to all of you. Thank you so very much.
LTC Ellis Parks [00:48:22] Turn it over to you.
Captain Renato Zaroubin [00:48:24] Once again, I'd like to thank you for inviting us. This has been a great opportunity to collaborate with you guys, learn new things, and all those figures certainly are going to be used back then in our country to improve our network security and improve our general workspace. Thank you.
LTC Ellis Parks [00:48:40] Thank you so very much to the panel. Thank you. Thank you for those joining us online and here at the amazing National Guard's Professional Education Center. This concludes our Cyber Shield 2026 Media Roundtable. Please remember, check us out on Flickr and Divvitt's Cyber Shield, 2026. Thank y'all so very.