# Institute for Security and Technology: Institute for Security \+ Technology > The Institute for Security and Technology \(IST\) is the 501\(c\)\(3\) critical action think tank\. IST unites technology and policy leaders to create actionable solutions to emerging security challenges\. Generated by Yoast SEO v28.0, this is an llms.txt file, meant for consumption by LLMs. ## Pages - [About the Institute for Security and Technology](https://securityandtechnology.org/about-ist/): The Critical Action Think Tank - [Contact](https://securityandtechnology.org/contact/) - [Privacy Policy](https://securityandtechnology.org/privacy-policy/) - [AI and Nuclear Command, Control, and Communications](https://securityandtechnology.org/ai-nc3/): Pioneering action\-oriented efforts to explore how advanced AI capabilities will be integrated into NC3 systems - [AI Antitrust and National Security](https://securityandtechnology.org/ai-antitrust-and-national-security/): Exploring how to more effectively account for national security considerations in AI antitrust cases while respecting precedent, scope, and the core principles of antitrust law - [AI Chip Export Control Initiative](https://securityandtechnology.org/ai-chip-export-control-initiative/): Safeguarding U\.S\. national competitiveness by closing critical compliance and enforcement gaps - [AI Risk Reduction Initiative ](https://securityandtechnology.org/ai-risk-reduction-initiative/): Assessing the risks and opportunities of AI foundation models and developing technical and policy\-oriented risk reduction strategies - [Combating Distributed Denial of Service Attacks](https://securityandtechnology.org/combating-distributed-denial-of-service-attacks/): Clarifying industry incentives and identifying best practices to combat threats posed by DDoS attacks - [Generative Identity Initiative \(GII\)](https://securityandtechnology.org/generative-identity-initiative/): Exploring how GenAI will affect social cohesion and the protection of public interest - [Our Team](https://securityandtechnology.org/our-team/): We unite technology and policy leaders to create actionable solutions to emerging security challenges - [Ransomware Task Force \(RTF\)](https://securityandtechnology.org/ransomwaretaskforce/): Combating the ransomware threat with a cross\-sector approach - [UnDisruptable27](https://securityandtechnology.org/undisruptable27/): Acting with Urgency to Save Lives in the Face of Unprecedented Cyber Threats - [Future of Digital Security](https://securityandtechnology.org/future-of-digital-security/): Examining the systemic security risks of societal dependence on digital technologies\. - [Innovation and Catastrophic Risk](https://securityandtechnology.org/innovation-and-catastrophic-risk/): Integrating novel technical expertise to increase global stability and assess emerging risks - [The Geopolitics of Technology](https://securityandtechnology.org/democracy-and-the-geopolitics-of-tech/): Taking on the implications of technology for global politics and security, which will shape innovation, supply chains, prosperity, and national and international security\. - [Analysis](https://securityandtechnology.org/analysis/): Explore our research - [Events](https://securityandtechnology.org/events/): View the Institute for Security and Technology's upcoming and past events\. ## Annual Reports - [2025](https://securityandtechnology.org/annual-report/2025/) - [2024](https://securityandtechnology.org/annual-report/2024/) - [2023](https://securityandtechnology.org/annual-report/2023/) - [2022](https://securityandtechnology.org/annual-report/2022/) ## Blogs - [RevCon Ended Without Consensus\. Risk Reduction Did Not\.](https://securityandtechnology.org/blog/revcon-ended-without-consensus-risk-reduction-did-not/): Despite the 2026 NPT Review Conference ending without consensus, growing multilateral support for nuclear risk reduction and crisis communication tools like IST's CATALINK Initiative signals a path forward for nuclear diplomacy\. - [What’s in a Norm?](https://securityandtechnology.org/blog/whats-in-a-norm/): What’s in a norm? The New York Times’s recent reporting linked last year’s cyber attack on Jaguar Land Rover to Russia\-based actors, but the UK government has remained silent\. IST’s Nicholas Leiserson calls on policymakers to act lest their silence encourage future attacks\. - [Building Towards a Beneficial Future Together: IST Engages with Partners on the Recent Vatican AI Encyclical](https://securityandtechnology.org/blog/building-towards-a-beneficial-future-together-ist-engages-with-partners-on-the-recent-vatican-ai-encyclical/): How can we ensure AI fosters human flourishing, instead of shaping us? IST’s Elizabeth Vish and Fatima Faisal Khan joined a DC gathering exploring religion and AI, centered on the Vatican's Magnifica Humanitas encyclical and its call for "digital sobriety\." - [IST, industry and civil society contributors release report assessing risks of increased access to AI foundation models ](https://securityandtechnology.org/blog/ist-industry-and-civil-society-contributors-release-report-assessing-risks-of-increased-access-to-ai-foundation-models/): In recent months, a number of leading AI labs have released advanced artificial intelligence systems\. While some models remain highly restricted, limiting who can access the model and its components, others provide fully open access to their model weights and architecture\. The potential benefits of these more open postures are generally well understood\. As a result, this effort turned our attention to the risks, seeking to answer the question: how does access to foundation models and their components impact the risk they pose to individuals, groups, and society?  - [How China Builds AI Power: IST Hosts Panel at the AI\+ Expo](https://securityandtechnology.org/blog/how-china-builds-ai-power-ist-hosts-panel-at-the-ai-expo/): How is China building AI power, and what does the United States still misunderstand about the systems and actors driving it? At the AI\+ Expo this month, hosted by the Special Competitive Studies Project \(SCSP\), IST convened a firestarter brief and panel with China experts to unpack one of the most consequential questions shaping technology and national security\. ## Events - [A Policy Response to the Mythos Moment: Breaking down the AI and Cybersecurity EO](https://securityandtechnology.org/event/a-policy-response-to-the-mythos-moment-breaking-down-the-ai-and-cybersecurity-eo/): What does the newly\-released AI and cybersecurity Executive Order mean for cyber defenders? How does it respond to the "Mythos moment"? On June 8, IST hosts a pop\-up webinar to explore these questions and more\. - [Contractors at the Keyboard? Private Offensive Cyber Operations Authorities in the FY2027 Senate NDAA](https://securityandtechnology.org/event/contractors-at-the-keyboard-private-offensive-cyber-operations-authorities-in-the-fy2027-senate-ndaa/): Defense contractors play a vital role in U\.S\. national security, but do not currently execute "hands\-on\-keyboard" cyber operations\. That role might be about to change with the Senate\-reported NDAA for FY2027\. On Tuesday, June 30, IST and friends had a discussion on the implications of this potential shift\. - [Vulns \+ AI = Oh My\!](https://securityandtechnology.org/event/vulns-ai-oh-my/): AI is reshaping vulnerability management… and reshaping policy debates along with it\. Join Institute for Security and Technology friends and adjunct advisors \(and some CVE board members\!\) for a lively conversation on Wednesday, July 1 at 11 am ET\. - [From Funding to Foundries: How China Builds AI Power](https://securityandtechnology.org/event/from-funding-to-foundries-how-china-builds-ai-power/): On May 7, at the AI\+ Expo hosted by the Special Competitive Studies Project \(SCSP\), IST convened a panel on one of the most consequential questions shaping technology and national security today: how is China building AI power, and what does the United States still misunderstand about the systems and actors driving it? - [Critical Effect 2026](https://securityandtechnology.org/event/critical-effect-2026/): Presented by ICS Village, in partnership with IST’s UnDisruptable27 project and Akin, the two\-day Critical Effect conference is coming back to Washington, DC on June 17 and 18\. With 2027 getting closer, we are prioritizing ideas that lead to real, actionable impact\. ## People - [Nicholas Leiserson](https://securityandtechnology.org/person/nicholas-leiserson/) - [Trista Aultman](https://securityandtechnology.org/person/trista-aultman/) - [Catherine Murphy](https://securityandtechnology.org/person/catherine-murphy/) - [Ritika Verma](https://securityandtechnology.org/person/ritika-verma/) - [Elsa B\. Kania](https://securityandtechnology.org/person/elsa-kania/) ## Podcasts - [Episode 52: Kindness and Critical Infrastructure: Rethinking OT Security](https://securityandtechnology.org/podcast/episode-52-kindness-and-critical-infrastructure-rethinking-ot-security/): “Security is not convenient\. Nobody likes change\. But at the same time, we have to be secure\. Finding that middle ground is the challenge in my position\.” In Hack the Plan\[e\]t episode 52, "Kindness and Critical Infrastructure," Andrea Haddad sits down with host Bryson Bort to discuss how to rethink OT security\. - [Episode 51: Cyber\-Informed Engineering: Moving Beyond the Firewall](https://securityandtechnology.org/podcast/episode-51/): For the last episode of season 5, host Bryson Bort sat down with Andrew Ohrt, Resilience Director at West Yost Associates to walk through the "invisible" nature of water systems, the impact of data centers on utility resilience, and how Cyber\-Informed Engineering protects our most essential resource\. - [Episode 50: Systems Engineering for Survival: A Physician's Guide to Emergency Management](https://securityandtechnology.org/podcast/episode-50/): Our host Bryson Bort welcomes Dr\. Natalie Sullivan, Medical Director of the Emergency Response Medical Group and an emergency medicine physician at a D\.C\. area hospital\. Trained in EMS and disaster and operational medicine, Natalie turned her attention to the critical intersection of clinical medicine, patient safety, and cybersecurity resilience after experiencing a prolonged ransomware attack on a major hospital\. - [Episode 49: Bridging the IT/OT Divide in Oil and Gas](https://securityandtechnology.org/podcast/episode-49/): Bryson Bort is joined by Dd Budiharto, Microsoft’s Customer Security Officer for the Oil, Gas, and Energy sectors, as she shares her experience bridging the IT/OT divide in the energy sector\. - [Episode 48: AI and the Future of Maritime Cybersecurity](https://securityandtechnology.org/podcast/episode-48/): In a new episode of the ICS Village and IST podcast Hack the Plan\[e\]t, retired maritime cybersecurity professor Gary Kessler joins Bryson Bort to walk us through the ins and outs of cybersecurity at sea, automated identification systems, and AI’s current and future role in maritime operations\. What is AIS spoofing, and why is it dangerous? What are the unique challenges posed by cybersecurity at sea? Is the maritime industry ready for artificial intelligence integrations?  ## Resources - [Securing the Frontier: Moving Past AI Fear and Toward Systemic Incentives](https://securityandtechnology.org/virtual-library/in-the-news/securing-the-frontier-moving-past-ai-fear-and-toward-systemic-incentives/): As AI models become more advanced, concerns over national security, cyber threats, and loss of control continue to rise\. In her latest analysis for Claroty, IST’s Megan Stifel argues that we don't need to panic—we need to prepare\. - [A Lifecycle Approach to AI Risk Reduction: Tackling the Risk of Malicious Use Amid Implications of Openness](https://securityandtechnology.org/virtual-library/report/a-lifecycle-approach-to-ai-risk-reduction/): A Lifecycle Approach to AI Risk Reduction introduces a novel framework for addressing the complex risks associated with AI, and applies this framework to the risk of malicious use\. - [Hotline Between Two Koreas: Status, Limitations and Future Tasks](https://securityandtechnology.org/virtual-library/report/hotline-between-two-koreas-status-limitations-and-future-tasks/): In this paper, Moon Chung\-in and Boo Seung\-Chan provide historical context on the hotlines linking South and North Korea and point to the lessons that can be learned from the decades\-long effort\. - [Formal Methods for NC3 Systems](https://securityandtechnology.org/virtual-library/report/formals-methods-for-nc3-systems/): What if we told you there is a very concrete way of updating and securing the most complex NC3 systems? Adam Wick makes the case for future NC3 protocol descriptions "to include not only a broad description of the protocol and its goals, but also an executable specification of the protocol\. He continues, "Given the sensitivity of these systems, we believe that the use of proof is critical\." - [The AES Project: Any Lessons for NC3?](https://securityandtechnology.org/virtual-library/report/the-aes-project-any-lessons-for-nc3/): Thomas Berson details how lessons from the Advanced Encryption Standard Competition can aid the development of international NC3 components and even be mirrored in the creation of a CATALINK community\. ## Categories - [Blog](https://securityandtechnology.org/category/blog/) - [Announcement](https://securityandtechnology.org/category/announcement/) ## Event Types - [Virtual Webinar](https://securityandtechnology.org/event-type/virtual-webinar/) - [All\-Day Event](https://securityandtechnology.org/event-type/all-day-event/) - [Side Event](https://securityandtechnology.org/event-type/side-event/) - [AMA](https://securityandtechnology.org/event-type/ama/) - [Cyber Policy Awards](https://securityandtechnology.org/event-type/cyber-policy-awards/) ## Pillars \& Projects - [Future of Digital Security](https://securityandtechnology.org/pillar_project/future-of-digital-security/) - [Innovation and Catastrophic Risk](https://securityandtechnology.org/pillar_project/innovation-and-catastrophic-risk/) - [The Ransomware Task Force \(RTF\)](https://securityandtechnology.org/pillar_project/future-of-digital-security/the-ransomware-task-force-rtf/) - [CATALINK](https://securityandtechnology.org/pillar_project/innovation-and-catastrophic-risk/catalink/) - [The Geopolitics of Technology](https://securityandtechnology.org/pillar_project/the-geopolitics-of-technology/) ## Resource Types - [Report](https://securityandtechnology.org/resource_type/report/) - [In the News](https://securityandtechnology.org/resource_type/in-the-news/) - [Op\-ed](https://securityandtechnology.org/resource_type/op-ed/) - [AAR](https://securityandtechnology.org/resource_type/aar/) - [Testimony](https://securityandtechnology.org/resource_type/testimony/) ## Sources - [IST publications](https://securityandtechnology.org/resource_source/ist-publications/) - [External publications](https://securityandtechnology.org/resource_source/external-publications/) ## Teams - [Critical Effect 2026](https://securityandtechnology.org/team/critical-effect-2026/) - [Adjunct Advisors](https://securityandtechnology.org/team/adjunct-senior-advisors/) - [2026 Andrew Carnegie AI\-Nuclear Policy Accelerator Cohort](https://securityandtechnology.org/team/2026-andrew-carnegie-ai-nuclear-policy-accelerator-cohort/) - [Team](https://securityandtechnology.org/team/our-team/) - [CATALINK Technical and Policy Advisors](https://securityandtechnology.org/team/initial-technical-and-policy-advisors-catalink/) ## Topics - [cybersecurity](https://securityandtechnology.org/resource_topic/cybersecurity/) - [Ransomware](https://securityandtechnology.org/resource_topic/ransomware/) - [artificial intelligence](https://securityandtechnology.org/resource_topic/artificial-intelligence/) - [NC3](https://securityandtechnology.org/resource_topic/nc3/) - [critical infrastructure](https://securityandtechnology.org/resource_topic/critical-infrastructure/) ## Years - [2022](https://securityandtechnology.org/resource_year/2022/) - [2019](https://securityandtechnology.org/resource_year/2019/) - [2025](https://securityandtechnology.org/resource_year/2025/) - [2024](https://securityandtechnology.org/resource_year/2024/) - [2020](https://securityandtechnology.org/resource_year/2020/) ## Optional - [Sitemap index](https://securityandtechnology.org/sitemap_index.xml)