Skip to content
Don't miss

Get the daily Cyber Briefing in your inbox

SIGN UP
Podcast

Who Should Control the Airspace Around Critical Infrastructure? with Scott Parker

Season 3 Episode 30 •

Show Notes

Drones are a serious operational concern for critical infrastructure owners and operators. In this episode of Cyber Focus, Frank Cilluffo sits down with Scott Parker, founder of Aerisq and former Chief of UAS Security at CISA, to discuss how drone capabilities have changed the risk picture for airports, utilities, chemical facilities, pipelines, prisons, and other sensitive sites.

The conversation examines the FAA’s Section 2209 rulemaking (open for public comment through August 5th, 2026), along with the limits of flight restrictions and the growing need for “Air Domain Awareness” alongside cyber and physical security. Parker also explains why counter-UAS strategy must balance technology, legal authority, proportional response, and the practical realities of defending infrastructure at scale.

Main Topics

  • Drone risks to critical infrastructure
  • Lessons from Ukraine
  • FAA Section 2209
  • Standard vs. special UASFRs
  • Air Domain Awareness
  • State and local counter-UAS authority
  • Cost and scale of drone defense
  • AI and autonomous drone risk
  • Secure-by-design drone capabilities

Key Quotes

“There is a huge imbalance between what it costs to take [a drone] down as opposed to what it costs to fly one.” — Scott Parker

“A vast majority of our critical infrastructure is open airspace. … Of the 90-something nuclear facilities, less than five have active flight restrictions over them.” — Scott Parker

“There are thermal sensors that can read how much oil is in a tank. There are LiDAR that can map an infrastructure’s detailed schematics. And there are also cyber tools that can be equipped to sniff out open networks around facilities.” — Scott Parker

“Someone who means to do harm, they can add real-time collection to what’s already out there using AI and… very likely develop a very structured plan on how to be successful.” — Scott Parker

“They [critical infrastructure owner-operators] are on the front lines. That’s what we’re concerned about. So they need the protection.” — Scott Parker

Relevant Links and Resources

About the Guest: 

Scott Parker is the founder and principal consultant of Aerisq, where he helps public and private sector organizations manage the cyber and physical risks posed by drones. He previously served as the Chief of UAS Security at CISA, where he built and led the agency’s first UAS Security Program and helped shape national guidance on drone risk management for critical infrastructure. Parker also served 27 years in the U.S. Army, culminating as Sergeant Major for the Special Operations Division at the Pentagon.

 

Transcript

Scott Parker [00:00:00]: There is a lag between the drone and the capabilities to defeat drones. And so thinking about—
Frank Cilluffo [00:00:05]: And a cost, an economic balance too, right?
Scott Parker [00:00:08]: There is a huge imbalance between what it costs to take one down as opposed to what it costs to fly one.
Frank Cilluffo [00:00:14]: Welcome to Cyber Focus from the McCrary Institute, where we explore the people and ideas shaping and defending our digital world. I’m your host, Frank Cilluffo, and this week we’re in for a treat. I sit down with Scott Parker. Scott spent almost 3 decades in Army Special Operations. He stood up CISA’s first UAS security program, and he’s now a founder of Aerisq and is advising critical infrastructure owner operators how to deal with the counter-UAS challenge. Much has changed in this environment since I was steeped in it. It’s gone much further beyond a DJI issue and ET phoning home to much an operational set of issues that I think we’re just starting to come to grips with and couldn’t ask for a better guest than Scott to help us unpack some of the many challenges. Scott, thank you so much for joining us today.
Scott Parker [00:01:12]: Thank you for having me.
Frank Cilluffo [00:01:13]: You know, I think before we get into some of the policy and regulatory questions, which are significant, you’ve got rules coming out of FAA 2209, in particular, a section and the like. But I thought it would be good to sort of provide a bit of a story arc in terms of how the UAS, counter-UAS sets of challenges has changed. And in particular, if you could sort of paint the picture before we get into the warfighting environment, but what are we looking at today? It’s no longer just a hobbyist set of issues.
Scott Parker [00:01:45]: No longer a hobbyist set of issues. So I can tell you my own experience in DHS when I joined in 2017. I joined right on the heels of Congress preparing to pass the Preventing Emerging Threats Act, which was a direct response to what we were seeing more in the Middle East as we were starting to see some actors think about using drones as a weapon into our homeland. And so we, we worked with Congress and Congress passed that law to give DHS and the Department of Justice their counterterrorism authorities.
Frank Cilluffo [00:02:14]: Mm-hmm.
Scott Parker [00:02:15]: When we did that, the threats to critical infrastructure and mainly were airports.
Frank Cilluffo [00:02:20]: Mm-hmm.
Scott Parker [00:02:20]: And we were not seeing those, luckily, as we were seeing them overseas. But a lot of lessons were learned between when we started to implement that authority and started to use those authorities around SEAR events, ballgames, you know, marathons. And we started to see an uptick in the number of drones, mostly hobbyists, mostly careless and clueless, that were flying around these facilities, exponentially get more and more every year as we began to do operations. And so we started to see a lot of those also hit, fly around critical infrastructure. And that got us to thinking there is more to the problem set than just the hobbyist. And we started to see possible surveillance, possible theft of intellectual property concerns, and possibly weaponization, as, as you know, you were seeing that in the ether when it comes to malicious actors.
Frank Cilluffo [00:03:09]: Well, you teed up exactly where I wanted to go, and that is what is at risk when we think of critical infrastructure? Obviously, there’s the surveillance and espionage sets of challenges, but also kinetic concerns, right?
Scott Parker [00:03:25]: Kinetic. And the sensor arrays that drones bring now are extensive. So it’s not just collection of camera feeds or, you know, video.
Frank Cilluffo [00:03:36]: It’s not just a camera in the sky.
Scott Parker [00:03:37]: Not just that anymore. There are sensors, there’s LiDAR, there’s high definition, there’s thermal sensors that can read how much oil is in a tank. There are LiDAR that can map an infrastructure’s detailed schematics. And there are also cyber tools that can be equipped to sniff out open networks around facilities. And that also goes into payloads. They can carry all kinds of contraband or malicious weapons into an area where you wouldn’t—
Frank Cilluffo [00:04:07]: We’ve actually seen that in prisons, right?
Scott Parker [00:04:08]: Prisons is a major issue there. But they also can be weaponized from a kinetic piece, as you’ve seen in Ukraine and other places. They’ve been very successful there.
Frank Cilluffo [00:04:17]: You know, we discussed just prior to this interview that it’s almost democratized airpower, hasn’t it? So these are capabilities that historically would rest in the hands of national militaries. And even there, not every country would have some of those capabilities. That brings about a whole new risk posture for critical infrastructure owner-operator, right?
Scott Parker [00:04:41]: It does. And it’s not just what you can purchase, it’s what you can build in your own basement with 3D printing. So you’re right, it’s not just those large drones that we’ve been accustomed to seeing and hearing about. There are ones that someone in their basement can bring to bear and surprise you.
Frank Cilluffo [00:04:57]: And, you know, we use, so critical infrastructure owner operators use it for so many different things, from agriculture all the way through to productivity to security of their own facilities. What is that right balance between sort of, and I know this is the $64,000 question. I guess I’m dated. $64,000 isn’t exactly what it was 30 years ago, but what does that look like and what are your thoughts on that?
Scott Parker [00:05:30]: There is a balance. The balance, I think, comes in the expertise. A lot of times you see organizations struggle with trying to figure out where drones fit into their system. They may be using them from an aviation perspective and they may lean on that expertise for a counter drone perspective. So there, but there’s, and there’s real equities there in the use of drones. And so balancing between being able to use them and using the expertise to inform security, both cyber and physical, I think is where you can start to see and strike a balance between the security of an organization and their use of drones.
Frank Cilluffo [00:06:02]: And I do want to pull the physical, cyber, and maybe a whole new domain, right?
Scott Parker [00:06:06]: Right.
Frank Cilluffo [00:06:07]: In terms of thinking about that momentarily, but sort of before jumping into that particular question, we’ve seen the transformation in real life in terms of the battlefield in Ukraine. And this isn’t a possibility. We’re seeing it utilized day in, day out.
Frank Cilluffo [00:06:28]: What, what, and you don’t want to overextrapolate in terms of lessons learned, but certainly there are some lessons learned, I think, that our critical infrastructure owner operators ought to consider. Anything come top of mind to you?
Scott Parker [00:06:41]: It does. And the first is there is a lag between the drone and the capabilities to defeat drones. And so thinking about—
Frank Cilluffo [00:06:48]: And the cost, economic balance too, right?
Scott Parker [00:06:51]: There’s a huge imbalance between what it costs to take one down as opposed to what it costs to fly one. But the critical lesson that we’re learning is the layered defense model. You have to think about protect, prevent in addition to mitigation. So this is not a technology solution in and of itself. We’ve learned that first and foremost in Ukraine. You have to think about what are your crown jewels to protect on the ground and start to harden or obscure those and build out from there. And so it really is an all-in approach to counter UAS and that doesn’t just rely on technology.
Frank Cilluffo [00:07:25]: You know, we’ve sort of made clear that the landscape has changed. Now let’s sort of pivot to what do we do about it? And I think for starters, and please shed some light for our viewers and listeners on FAA’s 2209 ruling, what it means, what it could mean, and what we ought to be thinking about there. So if you can paint that picture, that’d be great.
Scott Parker [00:07:54]: Yeah, happy to. So dating back to 2016 is when the, this is when Congress instructed FAA to come up with an application process for critical infrastructure to petition them for flight restrictions. It’s taken that long to really get something into rulemaking. So now, you know, a couple of months ago, the FAA released—
Frank Cilluffo [00:08:13]: A decade.
Scott Parker [00:08:14]: After a decade of waiting and a lot of working, we finally released a proposed rulemaking. And so what that is, though, and—
Frank Cilluffo [00:08:23]: Yeah, explain what Section 22 is.
Scott Parker [00:08:25]: Yeah. So what it is, is it’s an application process. So right now, and it’s kind of hard to believe sometimes, a vast majority of our critical infrastructure is open airspace. It’s not like an airport is protected or controlled airspace. It’s wide open. So an example would be, of the 90-something nuclear facilities, less than 5 have active flight restrictions over them.
Frank Cilluffo [00:08:45]: Wow.
Scott Parker [00:08:46]: So that’s just—
Frank Cilluffo [00:08:47]: That’s a sobering thought.
Scott Parker [00:08:48]: It’s a sobering thought. And it’s one I like to use a lot because that’s some of the challenges we’ve been facing. And then you get to the chemical and the oil and gas and petrochemical facilities. They’re even worse in the number they have. That’s compared to the number we have in our domestic space.
Frank Cilluffo [00:09:02]: Mm-hmm.
Scott Parker [00:09:03]: So this is the rule that’s going to allow those infrastructure owners and operators to go to the FAA, make a case, and actually have an enduring, not a temporary, but an enduring flight restriction over their facility. When Congress originally wrote the law, it was leaning in the direction of just a handful of sectors.
Frank Cilluffo [00:09:22]: Mm-hmm.
Scott Parker [00:09:23]: But this administration has leaned kind of harder into what that means within the law, and they’ve included all 16 sectors.
Frank Cilluffo [00:09:29]: Mm-hmm.
Scott Parker [00:09:29]: So what’s important about this rulemaking now is it opens the opportunity for all 16 of our critical infrastructure sectors to potentially have flight restrictions over areas that are most concerning.
Frank Cilluffo [00:09:42]: And, you know, it is still an application process, right? What would you be recommending right now to a utility, whether it’s an electric, an electricity entity or a chemical facility or nuclear? The fact that only 5%, I tend to come from the world that nuclear is always covered, but apparently not in this case.
Scott Parker [00:10:06]: No, they’re not. Two things come to mind. First and foremost is read the rule and comment. And we have until the 6th August before the public comment closes.
Frank Cilluffo [00:10:17]: And that’s why we want to get this, this, this particular episode out in time.
Scott Parker [00:10:21]: Now, and I appreciate you for that. And so you have some time and to get your comment done. And that way, and the FAA, to their credit, there are areas where they’re saying we need input from the critical infrastructure community. For example, food and agriculture, water, wastewater. It’s an open debate right now on what that criteria would look like because they said we need input, we don’t have it. Where other sectors, they’ve kind of put some parameters like oil and gas, you need 100,000 barrels of oil a day production. And so you need to look at the rule and you need to make sure your comments are there to help the FAA get the rule right. So the next thing is, if you do believe you will fall into the criteria, start setting the foundation today.
Scott Parker [00:11:03]: You want to be able to submit an application on day 1, whenever that is.
Frank Cilluffo [00:11:07]: Yep.
Scott Parker [00:11:08]: And the moment they approve it, you want to be able to operationalize that, that flight restriction. But that takes time. And there are some steps that are going to be required. But reading the rule and getting to understand it will give you those steps. The last thing I’ll say is one of the more controversial parts of this whole process is the need for Remote ID sensors. Many sectors right now, they’ve chosen not to get sensors for airspace awareness because there was no return on investment. You couldn’t do anything about the drones you did see.
Frank Cilluffo [00:11:38]: Mm-hmm.
Scott Parker [00:11:39]: Now you will be able to. And so I think now would be a time to start thinking about what sensor is best for your facility and start thinking about maybe getting them come out and doing some demonstrations before you actually have a flight restriction.
Frank Cilluffo [00:11:51]: And that takes time. So now is the time to act, right?
Scott Parker [00:11:56]: Yes.
Frank Cilluffo [00:11:56]: You know, one thing, and help me understand the difference here, and I’ve got a very simplistic view on this, sort of a no-fly zone, but explain the difference between standard UAFRs and special UAFRs.
Scott Parker [00:12:11]: Yeah. Again, once again, to the FAA’s credit, they’ve broken, they understand that some critical infrastructure has a national security nexus to it, right?
Frank Cilluffo [00:12:18]: Ad all times.
Scott Parker [00:12:18]: And maybe a little bit more important and critical or hazardous to operate over them. But in basics, the standard UAFR is what we expect most critical infrastructure to qualify for. It comes with certain things that the infrastructure owners and operators have to negotiate with, which is something called allowed operations, which means if you’re a commercial pilot, and you just happen to have a Part 107 license, then you’re allowed to fly over that facility so long as you give notice. And the owner and operator currently as written has no way to say no. They simply have to be able to track and monitor that. That’s with the standard UAFR. And any violation of a UAFR restriction would be a civil penalty alone.
Frank Cilluffo [00:13:00]: Mm-hmm.
Scott Parker [00:13:01]: You go to the special UAFR, it’s a little bit more difficult. You can still navigate over, but only with special permission from the FAA in coordination with the special UAFR facility. And a penalty for violating that not only would be civil, but would be criminal in nature as well. So it kind of elevates the, you know, concern to where if you do something wrong over a special, then there’s real consequence.
Frank Cilluffo [00:13:27]: Thank you. Yeah. And there are grades and differences and consequences and penalties based on all of that, right?
Scott Parker [00:13:35]: There is. Yes.
Frank Cilluffo [00:13:36]: You know, any major misconceptions on 2209?
Scott Parker [00:13:43]: Yes. So one, I’ve spoken a lot about this recently. One is it doesn’t stop an aircraft from flying over your facility.
Frank Cilluffo [00:13:48]: And I want to hit that point home. Yes.
Scott Parker [00:13:51]: Yes. It is akin to a no trespass sign. Right? So it just tells someone that you should not be flying over. If you do, there’s consequence. So what it does not do is it does not prevent someone who has malicious intent, who would not care about a civil or criminal penalty from actually flying into airspace and doing something bad. And that goes back to what we’ve learned from Ukraine is that it takes a layered defense posture to really defeat a UAS issue. But the UAFR right now is a no trespass sign that gives warning and notice to anyone and hopefully clears the skies and anyone flying either would be allowed or they would be malicious.
Frank Cilluffo [00:14:28]: Assuming you identify it, right?
Scott Parker [00:14:29]: Assuming you have the technology and sensors to be able to make that determination, yes.
Frank Cilluffo [00:14:33]: Just a little more concrete. If you were running a major pipeline operator or electric utility, how would this rule change your day-to-day? Or does it?
Scott Parker [00:14:49]: It does. I think it really does. And this comes with the burden this places on the critical infrastructure on an operator, which is built within the rule for comment, and people should be thinking about it. One, it gives you real, a real ability to say people can’t fly over your facility and report it to law enforcement and then allow law enforcement to actually do something about it. Currently, you can’t. It’s open airspace. It’s a public right. And so unless they’re doing something that’s a public safety issue, they can, they’re well within their right to fly over.
Scott Parker [00:15:16]: This stops that. Right?
Frank Cilluffo [00:15:18]: So it’s like putting speed signs and, and no trespass signs. You need that. You need that. But that doesn’t stop people from speeding, right?
Scott Parker [00:15:27]: But it allows you to hold people accountable.
Frank Cilluffo [00:15:29]: Yep.
Scott Parker [00:15:30]: The other thing it does for those pipeline owners and operators, like you suggested, was it puts the onus on them to have Air Domain Awareness. So it’s another tranche of security that they have to take accountability for. Outside of the physical security and the cybersecurity that they’re already doing, there’s this new Air Domain Security apparatus that has to be applied to that. So there’s negotiation with who, when’s flying, and what do you do when they’re flying over your facility?
Frank Cilluffo [00:15:55]: Well said. And I want to get to that point because rulemaking, regulation, policy, all essential, but it doesn’t actually operationalize some of this. So I’d like to sort of get into that. Today, if a drone did enter restricted airspace, especially in, let’s say, critical infrastructure, since you’ve done such great work in that space, who knows, who responds and what are the possible consequences here?
Scott Parker [00:16:23]: Today?
Frank Cilluffo [00:16:23]: Yeah.
Scott Parker [00:16:25]: Very few people know unless someone sees it with their eye. When you do call local police, there’s nothing they can really do about it because oftentimes it’s public right. And, and so nothing happens. Right? And that’s been a major concern. There are a few states that have tried to self-regulate and kind of create airspace rules that in some way get in front of the federal rules, the FAA’s regulatory power. And so sometimes states take some action, but those rarely end up in prosecution because of preemption issues. So there is something that people are trying to do absent real authority.
Scott Parker [00:17:04]: And that’s where now—
Frank Cilluffo [00:17:05]: That’s too unacceptable.
Scott Parker [00:17:06]: It is. It’s, considering the places that fly over sometimes, chemical plants where there’s hazards.
Frank Cilluffo [00:17:11]: Yeah. And during like national security special events, we have lots of unique capabilities, but those are one and done. The day ends, you unplug, right?
Scott Parker [00:17:20]: Exactly.
Frank Cilluffo [00:17:21]: So the question is, is what do we need in place all the time? And I wanna touch a little more on what you referred to as Air Domain Awareness, ’cause I think that is essential and it assumes you know, but you need some capabilities to get into that, to calibrate accordingly. And we discussed a little bit how IT/OT, physical, cyber, all that’s converging. But there’s a whole new element to that in this thinking, right?
Scott Parker [00:17:55]: There is. There is.
Frank Cilluffo [00:17:56]: So if you’re an owner-operator, yeah.
Scott Parker [00:17:57]: If you’re an owner-operator and it’s complicated. So there are about 4 different types of sensors that people use now, right? Acoustic, EO/IR, radar, or infrared, not infrared, but a radio frequency technology.
Frank Cilluffo [00:18:12]: RF. EW, where do you throw that?
Scott Parker [00:18:14]: On the mitigation side. But just to know who’s flying over-
Frank Cilluffo [00:18:17]: Yeah, yeah, yeah, exactly
Scott Parker [00:18:18]: Right? That’s what they have. But, but, but now private sector companies have a real issue and legal ambiguity with operating RF because they’re not allowed to demodulate signals. There’s a Pen Trap and Wire Trace Act issue there. And we’re just now on the cusp of having state and local law enforcement with the ability to actually do what DOJ and DHS have been doing for 6 years, which is actually intercept and, those frequencies and demodulate to know who and where they’re flying. And so right now with the critical infrastructure, they still can’t do as much RF as they would like, but they’re going to hopefully have some local law enforcement that can supplement them in the near future as that authority under the Safer Skies Act becomes real.
Frank Cilluffo [00:19:04]: So in a very simplistic kind of way, if you’re an owner-operator, you want to be able to have visibility across your physical, your cyber, and now air, right?
Scott Parker [00:19:15]: Yes.
Frank Cilluffo [00:19:16]: And converging all that, there’s some capability gaps, right?
Scott Parker [00:19:21]: There are.
Frank Cilluffo [00:19:22]: Not just authorities, but actual capability gaps.
Scott Parker [00:19:25]: Actual capabilities. And I think actual methodologies. And so—
Frank Cilluffo [00:19:28]: And what is the smartest methodology? Now you set yourself up there.
Scott Parker [00:19:31]: I did. I did. So in CISA, I was working a lot on convergence of cyber and physical. After the Colonial Pipeline, it was a real aha moment for us. And we started to think that the CISOs and CIOs and the CSOs really need to be in the same room.
Frank Cilluffo [00:19:45]: Yeah, and they don’t always sit in the same room.
Scott Parker [00:19:46]: They don’t. They sit in the silos and there’s different cultures. And so, you know, that’s, so for me, that’s real, after spending 4 or 5 years doing that. As I get into the air domain, I’m starting to see the same type of silo created with the air domain and with the aviation assets and those who understand drones.
Frank Cilluffo [00:20:03]: That’s what I’m afraid of. That’s why I asked. Yep.
Scott Parker [00:20:04]: And so I’m really trying to advocate for all those organizations who are standing up a counter-drone program or air domain awareness program to not allow that to be something on the outside of the physical and cybersecurity team, but integrate it right in the middle because it affects both of them and they affect it.
Frank Cilluffo [00:20:22]: That’s, that’s really well said. And, and, and again, not to oversimplify it, but we need the situational awareness, right? I mean, otherwise you’re reacting to whatever you’re seeing in a onesie and twosie kind of effect, which I don’t feel confident we’re going to get those. So it’s providing that full picture. Is anyone doing that well right now?
Scott Parker [00:20:48]: Some of the larger organizations I’ve visited. They’ve integrated air domain awareness into their security operations center. And so they account for the fact that a drone flying over a facility is going to affect either a cyber or a physical asset.
Frank Cilluffo [00:21:01]: Because the payload could be kinetic or cyber.
Scott Parker [00:21:04]: It could be. It could be a number of things. But the outcome would be hitting an asset.
Frank Cilluffo [00:21:08]: That’s what we should be looking at.
Scott Parker [00:21:09]: And those assets are all—
Frank Cilluffo [00:21:10]: Exactly. Agnostic.
Scott Parker [00:21:11]: Yes.
Frank Cilluffo [00:21:12]: Yep.
Scott Parker [00:21:12]: So making sure that you see that and you know when something’s being affected is important and you won’t see that if you’re siloed.
Frank Cilluffo [00:21:18]: Well said. Also on the policy side, and this is sort of an unfair question because I don’t think there’s an easy answer, but who ultimately owns this problem? Is it FAA? Is it DHS? Secret Service within DHS? FBI? State, local law enforcement? infrastructure owner-operator? Who, where do we pin the tail on the donkey here?
Scott Parker [00:21:41]: This was the biggest debate we had between our Homeland Security apparatus, FAA, and then the FCC because there’s spectrum issue at large here because these drones operate based on spectrum. And neither can own it fully, right? Aviation has, FAA has air safety and access to the NAS concern, and there’s a national security concern for all those on the ground. Allowing one to be the sole owner, it just doesn’t work. And we’ve worked through a lot of the scar tissue at this point, I think, where that’s no longer the case. That was the case in the beginning where it was an FAA aviation-only concern.
Frank Cilluffo [00:22:19]: Mm-hmm.
Scott Parker [00:22:20]: I think now, when you look at who’s in the room making decisions, at least when I was in, was there, it was Homeland Security, whether it’s DHS or DOJ and FAA having equal voice. And it has to be that way throughout.
Frank Cilluffo [00:22:34]: But if it’s a fluid environment and state and locals closest to the scene, they, they have to be plugged in, don’t they? More than plugged in.
Scott Parker [00:22:45]: They do. They have to be the ones who are operating.
Frank Cilluffo [00:22:47]: They’re the ones who are actually doing it.
Scott Parker [00:22:48]: They will be. And so the Safer Skies Act just passed. And actually, we have another rule that’s out for public comment. It’s the interim final rule for the Safer Skies Act, which are the guardrails developed by DHS and DOJ for how state, local, tribal, and territorial law enforcement will operationalize counter-UAS authorities the same way DHS and DOJ has. So that’s through September. I would advise anyone else who’s listening-
Frank Cilluffo [00:23:13]: Anything, anything you would recommend?
Scott Parker [00:23:15]: Look at it because it does have a real impact on how state and locals will operate this in your communities and in coordination with critical infrastructure. And so it’s a real opportunity. And that is where we’re starting to see this issue of scaling counter-UAS outside of the federal space down into the state and local level where it’s badly needed.
Frank Cilluffo [00:23:38]: And we’re seeing in real battlefield environments now the cost analysis to takedown versus launch. We can’t do that forever. Are there simple means and any that you would prefer for us to be able to, and I know it’s not a one-size-fits-all approach, it never is. But I mean, if you look at even from a missile defense standpoint, the economic give and take ain’t adding up in our favor.
Scott Parker [00:24:13]: No.
Frank Cilluffo [00:24:13]: So how should we be thinking about this? Because we know we have vulnerabilities, but we’re never going to be able to protect everything everywhere all the time from every perpetrator and every modality of attack or we’ll be bankrupt. What is that right sort of balance there from your eyes, from your perspective?
Scott Parker [00:24:29]: It’s a hard question to answer because you have to separate what’s happening in the wartime environments or theaters of conflict.
Frank Cilluffo [00:24:36]: But that could come to a theater near you, right?
Scott Parker [00:24:39]: It could very well. It could be our problem, you know, in the very short horizon. But right now we have the domestic space and we are laser-focused on making sure that the response is proportionate to the threat. So the threat right now are a lot of the smaller drones and focusing on cyber takeover or focusing on other non-kinetic ways in which you can render safe those drones, is been the principal focus. We’re seeing kinetics, as you saw in Texas recently, starting to be used with high-power microwaves or lasers or directed energy, starting to be utilized in the domestic space, thinking that that battleland approach could easily be our domestic issue in the future. So the testing is happening now, but it’s being done, I think, in a very iterative way so we don’t cause more problems than we’re trying to solve.
Frank Cilluffo [00:25:30]: And it has to scale whatever it is, right? Because it’s a big country.
Scott Parker [00:25:34]: It is.
Frank Cilluffo [00:25:35]: And everyone has their unique, and if you’re state and local, you have a responsibility, obviously, to your communities and citizens. So not easy, but hopefully we can get our arms around that and I think scale and learn and scale and learn. Along those lines, you can’t escape Cyber Focus without a brief discussion around AI. AI is making every technology more autonomous from a speed perspective, from you name it. What are your thoughts there, both from a red and a blue, a defensive perspective and an offensive perspective that we need to be protecting ourselves from?
Scott Parker [00:26:18]: Yeah, so I think the issues with AI right now is really troublesome because it does 2 things in my mind. The first thing is it really enables things like machine learning and machine vision to take hold, and drones can fly in a more autonomously way, more autonomous way, and do more with the data they collect. On the other side of that is when, when someone uses a drone to collect data, they can now put it into an an AI platform and really get rich information from real-time data collected based off what they see in the infrastructure land. There’s a lot of, regulations require infrastructure to put a lot of information out there in the ether.
Frank Cilluffo [00:26:55]: Mm-hmm.
Scott Parker [00:26:56]: And that information is sitting there. So someone who means to do harm, they can add real-time collection to what’s already out there using AI and probably, well, very likely develop a very structured plan on how to be successful.
Frank Cilluffo [00:27:08]: You know, looking ahead, and I like to say since the end of the Cold War, threat forecasting has made astrology look respectable. So I’m not asking you to look directly into a crystal ball, but where does this debate go 5 years from now?
Scott Parker [00:27:22]: I’m hopeful. I’m hopeful Section 20209 rolls out very well and that we start to see infrastructure owners and operators able to manage airspace in a very proactive and reactive way that is safe and secure.
Frank Cilluffo [00:27:36]: Mm-hmm.
Scott Parker [00:27:36]: I’m also hopeful that the Safer Skies Act and the state and locals actually are able to conduct counter-UAS operations in the same way Justice and Homeland Security has done over the last 6 years, where they build confidence in their communities and they build confidence among their operators. If we can do those 2 things very well, I can see in the next 5 years Congress being amenable to delegating that same authority down to the critical infrastructure security staff. Where the problem is and where the solutions must be resident.
Frank Cilluffo [00:28:05]: The owner-operator, just like cyber, they’re on the front lines of this war.
Scott Parker [00:28:08]: They are on the front lines. That’s what we’re concerned about. So they need the protection.
Frank Cilluffo [00:28:11]: Well said. And last question. What question didn’t I ask that I should have?
Scott Parker [00:28:18]: Oh, goodness. I think the one challenge that we didn’t really address is where our capabilities are coming from. And so there is a huge lag between the drones and the mitigation or detection technologies that we’re seeing. And so, so there needs to be unification. There needs to be more of a domestic secure-by-design drones that, that populate our airspace more so than the other types of drones. And I know that’s a, that’s a huge ask from where we are today.
Frank Cilluffo [00:28:50]: It is.
Scott Parker [00:28:50]: But that helps with threat determination, discrimination. And then there needs to be counter or mitigation and detection technology that is connected to those type of drones in a way that makes it seamless. So right now they’re very bifurcated where one’s chasing the other. Those things need to be integrated in a way where it’s one industry. And I would love to see that. I don’t have the answer for that, you know, but that’s the one thing oftentimes that I don’t hear people talking about is what the future holds. And I think we’ve had to find a way to unify those a little bit closer.
Frank Cilluffo [00:29:20]: That’s well said. The bar to entry seems to be getting lower and lower. And at the end of the day, the solution sets are complicated. They bring in so many moving parts and pieces, but they have to be synthesized.
Scott Parker [00:29:35]: Yes.
Frank Cilluffo [00:29:36]: Scott, thank you so much for spending so much time with us today. Thank you for informing our viewers and listeners on a critical set of issues. When we think of critical infrastructure, we spend a lot of our time talking cyber and AI, but you can’t do that without having a discussion around autonomous vehicles and UAS and the like. And honestly, I almost feel like that conversation shouldn’t be had separately. I think it has to be part of that same conversation. And thank you for all you’ve done to advance our national security over these years and you continue to do. Thank you.
Scott Parker [00:30:12]: Thank you. I appreciate it.
Frank Cilluffo [00:30:14]: Thank you. Thank you for joining us for this episode of Cyber Focus. If you liked what you heard, please consider subscribing. Your ratings and reviews help us reach more listeners. Drop us a line if you have any ideas in terms of topics, themes, or individuals you’d like for us to host. Until next time, stay safe, stay informed, and stay curious.

Related Content