Dale Peterson Interviews Brian Scott on ONCD
Brian Scott
S4x24 - ICS Security Conference · Day 1 · Main Stage
Overview
This talk features an insightful interview with Brian Scott, a seasoned veteran of U.S. government cybersecurity, who discusses the critical role and evolving mission of the Office of the National Cyber Director (ONCD). Established in July 2021 with Chris Inglis as its inaugural director, the ONCD serves as the principal advisor to the President on national cybersecurity policy. With a staff of approximately 80 individuals, its primary function is to act as the central policy coordination body for the nation's cybersecurity posture, a task of immense strategic importance given the fragmented landscape of federal cybersecurity efforts.

Key moments
- 0:15 ONCD's core mission: advisor, policy coordination, federal coherence
- 2:04 Synchronizing interagency efforts: not disputes, but synergy
- 2:26 Collaboration with other White House policy councils
- 3:20 ONCD develops policy; interagency executes
- 4:51 National Cybersecurity Strategy: the nation's 'North Star' for cyber
- 5:30 69 initiatives in the National Cyber Strategy Implementation Plan
Dale Peterson Interviews Brian Scott on ONCD
Speakers: Brian Scott
Conference: S4
YouTube: https://www.youtube.com/watch?v=RyAkpzastAc
Overview
This talk features an insightful interview with Brian Scott, a seasoned veteran of U.S. government cybersecurity, who discusses the critical role and evolving mission of the Office of the National Cyber Director (ONCD). Established in July 2021 with Chris Inglis as its inaugural director, the ONCD serves as the principal advisor to the President on national cybersecurity policy. With a staff of approximately 80 individuals, its primary function is to act as the central policy coordination body for the nation's cybersecurity posture, a task of immense strategic importance given the fragmented landscape of federal cybersecurity efforts.
Scott, whose distinguished career spans roles at DHS (prior to CISA's formation), CISA, and the National Security Council before joining ONCD, brings a wealth of experience to the conversation. He elucidates ONCD's two overarching focus areas: fostering federal coherence across the U.S. government in cyber policy and ensuring the alignment of aspirations and resources. This discussion is particularly pertinent for the S4 audience, many of whom are deeply embedded in critical infrastructure protection, as it sheds light on the high-level strategic direction that underpins the operational security measures they implement daily. The interview emphasizes ONCD's efforts to synchronize and synergize the myriad cybersecurity activities undertaken by various federal agencies, aiming to present a unified and effective front against persistent and evolving cyber threats.
The talk underscores the inherent challenges of coordinating cybersecurity policy within a vast governmental structure, where multiple agencies possess distinct mandates and capabilities. Rather than viewing interagency interactions as "disputes," Scott reframes them as opportunities for synchronization to advance national security. The ONCD's development of the National Cybersecurity Strategy and its comprehensive Implementation Plan stands out as a monumental achievement, serving as the "North Star" guiding the nation's collective cybersecurity endeavors. This strategic framework, with its 69 focused initiatives, represents a concerted effort to streamline and amplify the impact of federal cybersecurity programs, ultimately enhancing the resilience and security of both government networks and critical infrastructure.
Background
▶ Watch: ONCD's core mission: advisor, policy coordination, federal coherence (0:15)
Before the establishment of the Office of the National Cyber Director (ONCD) in July 2021, the landscape of U.S. government cybersecurity policy was characterized by a distributed, albeit robust, network of agencies. Entities such as the Department of Homeland Security (DHS), the Cybersecurity and Infrastructure Security Agency (CISA), the Department of Energy (DOE), the National Institute of Standards and Technology (NIST), and the National Security Council (NSC) each held significant portfolios in cybersecurity. While these organizations performed vital functions—ranging from defending federal networks and critical infrastructure to developing cybersecurity standards and advising on national security policy—their independent operations often led to perceived overlaps, potential redundancies, and sometimes, a lack of cohesive strategic direction.
This complex ecosystem, as Brian Scott implies, wasn't necessarily plagued by overt "disputes" but rather by the inherent challenge of ensuring optimal synchronization and synergy among numerous well-intentioned and effective initiatives. The absence of a single, authoritative policy coordination body at the presidential level meant that while excellent work was being done, there was a persistent need for a more unified approach to national cybersecurity policy. This need became increasingly acute with the escalating sophistication and frequency of cyber threats, which often transcend traditional agency boundaries and demand a whole-of-government response.
The creation of the ONCD was a direct response to this imperative, aiming to fill a critical gap in the government's cybersecurity architecture. Its mandate was to serve as the principal advisor to the President on cybersecurity policy and to be the central policy coordination body. Brian Scott's extensive prior experience at DHS (before CISA's inception), CISA, and the National Security Council provided him with a unique, firsthand understanding of these interagency dynamics. His career trajectory highlights the evolution of federal cybersecurity efforts, from early departmental initiatives to the more centralized and strategic coordination now championed by the ONCD. This historical context underscores the significance of the ONCD's mission: to bring coherence and strategic alignment to what was, by necessity, a multifaceted and often siloed approach to national cybersecurity.
Key Findings
▶ Watch: Collaboration with other White House policy councils (2:26)
The core revelation from Brian Scott's discussion is the ONCD's pivotal role in redefining the architecture of U.S. national cybersecurity policy. Its primary function is not merely advisory but distinctly as the policy coordination body for the nation's overall cybersecurity posture. This central coordinating authority is crucial for bridging the perceived gaps and overlaps among various federal entities. Scott emphasizes that the ONCD's mission is not to adjudicate "disputes" but to foster synchronization and synergy among the diverse and often excellent cybersecurity activities already underway across the government.
Two major strategic imperatives guide the ONCD's efforts: achieving federal coherence—a concerted drive to ensure all government agencies work together seamlessly on cybersecurity policy—and aligning aspirations and resources. This dual focus ensures that national cybersecurity goals are not only well-defined but also adequately supported and efficiently executed across the entire federal apparatus. The ONCD operates within the Executive Office of the President, collaborating closely with other influential White House elements such as the National Security Council (NSC), the National Space Council, the Office of Management and Budget (OMB), and the Domestic Policy Council. This collaborative model is essential for integrating cybersecurity considerations into broader national security, economic, and domestic policy frameworks.
A critical distinction highlighted by Scott is the division of labor between the ONCD and other agencies. The ONCD is responsible for developing policy, setting the strategic direction and overarching principles. In contrast, interagency bodies like the Department of Energy (DOE) and CISA are tasked with executing policy, translating the ONCD's strategic guidance into tangible actions and operational initiatives. For example, CISA's main functions—defending federal networks and critical infrastructure, and coordinating activities related to critical infrastructure security—are direct manifestations of policies developed at the ONCD level.
The most significant output of the ONCD's work to date is the National Cybersecurity Strategy, which Scott refers to as the "North Star" for the nation's cybersecurity efforts. Released approximately a year prior to the S4 conference, this strategy provides the foundational framework. Following its release, the ONCD subsequently launched the National Cybersecurity Strategy Implementation Plan in July, outlining 69 specific initiatives. While not exhaustive of all cybersecurity activities, these 69 initiatives represent the focused actions the ONCD is actively tracking and driving. This demonstrates a clear progression from high-level vision to concrete, accountable actions. An illustrative example of inter-council collaboration is the ONCD's leadership, alongside the National Security Council and the National Space Council, in efforts to address cybersecurity for space systems, highlighting a proactive stance on emerging and critical domains. The commitment to annually report on the progress and effectiveness of the strategy's implementation further underscores the ONCD's dedication to accountability and continuous improvement in national cybersecurity.
Technical Deep Dive
▶ Watch: ONCD develops policy; interagency executes (3:20)
This discussion with Brian Scott focuses on high-level policy, strategic coordination, and the organizational structure of national cybersecurity rather than specific technical vulnerabilities, exploit techniques, or deep dives into system architectures. Therefore, a traditional "technical deep dive" in the sense of analyzing code, protocols, or specific security tools is not applicable to the content of this interview.
However, it is crucial to understand that the policy and coordination efforts championed by the ONCD have profound downstream technical implications. The overarching National Cybersecurity Strategy and its Implementation Plan, which includes 69 distinct initiatives, directly shape the technical cybersecurity posture of the entire nation. For instance, policies developed by the ONCD regarding the defense of federal networks or the security of critical infrastructure will dictate the types of security controls, architectural requirements, and defensive technologies that agencies like CISA and DOE are mandated to implement. CISA's core functions, such as defending federal networks and coordinating critical infrastructure security, are inherently technical tasks. The effectiveness of these operations, from deploying advanced threat detection systems to implementing secure development lifecycles, is directly influenced by the coherence and clarity of the national policy framework set by ONCD.
Furthermore, the specific mention of efforts to address cybersecurity for space systems underscores a focus on securing highly complex and technically sophisticated environments. While the interview does not detail the technical specifics of securing satellites or ground control systems, the policy coordination efforts are essential to ensure that appropriate technical standards, threat intelligence sharing mechanisms, and incident response protocols are established across government and private sector stakeholders involved in space operations. These policy directives will inevitably translate into requirements for specific technical implementations, such as secure communication protocols, robust encryption standards, and resilient system architectures designed to withstand sophisticated nation-state attacks. Without the strategic guidance and coordination provided by an entity like the ONCD, technical implementations across diverse agencies and critical sectors could become disparate, inefficient, and ultimately less effective against a unified adversary.
Demo / Proof of Concept
▶ Watch: National Cybersecurity Strategy: the nation's 'North Star' for cyber (4:51)
As this discussion was an interview focused on national cybersecurity policy, strategic coordination within the U.S. government, and the mission of the Office of the National Cyber Director, it did not include any live demonstrations, technical walkthroughs, or proofs of concept related to specific vulnerabilities, exploits, or security tools. The content remained at a high policy and organizational level, discussing mandates, strategies, and interagency collaboration.
Defensive Implications
▶ Watch: 69 initiatives in the National Cyber Strategy Implementation Plan (5:30)
The work of the ONCD, as articulated by Brian Scott, carries significant defensive implications for both government entities and critical infrastructure operators, despite the interview's focus on policy rather than technical specifics. The overarching goal of federal coherence and the National Cybersecurity Strategy directly impact how defenders operate and what resources they can leverage.
For government agencies, the ONCD's role as the central policy coordinator means a clearer, more unified strategic direction for cybersecurity. This should reduce instances of conflicting guidance from different departments, allowing agencies to allocate their defensive resources more efficiently and effectively. Agencies like CISA, which are responsible for defending federal networks and critical infrastructure, will benefit from streamlined policy development, enabling them to focus more on the execution of those policies. This translates into more consistent deployment of security controls, better-coordinated incident response protocols, and a more harmonized approach to threat intelligence sharing across the federal enterprise. The 69 initiatives outlined in the National Cybersecurity Strategy Implementation Plan provide a concrete roadmap for defensive action, offering specific areas of focus for agency-level security programs.
For critical infrastructure operators in the private sector, the ONCD's efforts are equally impactful. While the ONCD does not directly regulate or enforce security measures on private entities, its policy work shapes the environment in which critical infrastructure operates. Policies developed by the ONCD, and subsequently executed by agencies like CISA and DOE, directly influence:
- Guidance and Standards: The development of national cybersecurity standards (e.g., NIST frameworks) and sector-specific guidance will be more coherent and aligned with national priorities.
- Information Sharing: Improved federal coherence can lead to more effective and timely sharing of threat intelligence, vulnerabilities, and defensive best practices from government to the private sector.
- Incident Response Coordination: In the event of a significant cyber incident affecting critical infrastructure, a well-coordinated federal policy framework ensures a more unified and effective government response and support structure.
- Resource Allocation: The ONCD's focus on "aligning aspirations and resources" means that federal support programs, grants, and initiatives aimed at enhancing critical infrastructure security are likely to be more strategically targeted and impactful.
The specific mention of leading efforts in cybersecurity for space systems highlights a proactive defensive posture for emerging and vital domains. As space infrastructure becomes increasingly critical for national security and economic functions, coordinated policy ensures that defensive measures—from supply chain security to operational resilience—are integrated from the outset. Ultimately, the ONCD's work aims to build a more resilient and defensible national cyber ecosystem by fostering a cohesive, synchronized, and well-resourced approach to cybersecurity across all relevant stakeholders. Defenders should pay close attention to the annual reports on the National Cybersecurity Strategy's progress, as these will indicate evolving priorities and areas of focus for national cyber defense.
Key Takeaways
- Centralized Policy Coordination: The Office of the National Cyber Director (ONCD) serves as the principal advisor to the President on cybersecurity policy and acts as the central policy coordination body for the U.S. national cybersecurity posture.
- Federal Coherence and Resource Alignment: ONCD's two primary focus areas are championing federal coherence across the U.S. government in cyber policy and ensuring the alignment of aspirations and resources for national cybersecurity efforts.
- The National Cybersecurity Strategy: The National Cybersecurity Strategy is the "North Star" guiding the nation's cybersecurity efforts, supplemented by the National Cybersecurity Strategy Implementation Plan which contains 69 focused initiatives.
- Policy Development vs. Execution: The ONCD's role is to develop policy, while interagency bodies such as CISA and DOE are responsible for executing those policies, translating strategic guidance into operational actions.
- Interagency Collaboration: ONCD works closely with other White House elements (e.g., National Security Council, National Space Council, OMB) and interagency partners to synchronize and synergize cybersecurity activities, including leading efforts on space cybersecurity.
- Accountability and Progress Reporting: The ONCD is tasked with annually reporting on the progress and effectiveness of implementing the National Cybersecurity Strategy, demonstrating a commitment to accountability and continuous improvement.
About the Speaker(s)
Brian Scott is a highly experienced and distinguished figure in U.S. government cybersecurity, with a career spanning several critical federal agencies. His extensive background includes working at the Department of Homeland Security (DHS) before the establishment of CISA, then moving to CISA itself, and subsequently serving with the National Security Council. Currently, he holds a key position at the Office of the National Cyber Director (ONCD), the central policy coordination body for national cybersecurity. This unique trajectory across various pivotal organizations has provided Mr. Scott with an unparalleled understanding of the complex interagency landscape, the challenges of federal coherence, and the strategic imperatives for securing the nation's cyber posture. His insights are informed by years of direct involvement in shaping and implementing cybersecurity policy at the highest levels of government.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Brian Scott's interview provides a direct and unvarnished look into the Office of the National Cyber Director (ONCD), a critical but often opaque entity in US cybersecurity. He clearly articulates ONCD's core mission to drive federal coherence and align resources, moving beyond platitudes to detail the National Cybersecurity Strategy and its 69-initiative implementation plan. For those operating in critical infrastructure or tracking national policy, this offers significant insider signal on the strategic "North Star" and the actual mechanisms of interagency coordination, coming from a speaker with unparalleled credibility.
Heather Calloway (CISO) — STRONG ACCEPT
This interview with Brian Scott provides essential clarity on the Office of the National Cyber Director (ONCD), a critical but often misunderstood entity in the U.S. cybersecurity landscape. It meticulously outlines ONCD's mandate as the central policy coordination body, emphasizing federal coherence and the strategic alignment of resources for national cyber defense. For any CISO or security leader, particularly those in critical infrastructure, understanding this overarching national strategy is paramount, as it dictates the environment, priorities, and regulatory trajectory that will inevitably impact their own programs and risk posture.