Supporting the National Cyber Strategy Part 2: How TrendAI™ Helps

The second installment of this series offers an in-depth look at the next three pillars of the strategy and demonstrates how our capabilities help government agencies with secure implementation.

By Jon Clay, Vice President of Threat Intelligence, TrendAI™

In our previous blog, we took a deeper look at the first three pillars of the National Cyber Strategy, released by the White House Office of the National Cyber Director (ONCD). We outlined how TrendAI™ directly supports government agencies working to bring this strategy to life. Today, we’re continuing that conversation by focusing on the fourth, fifth, and sixth pillars. They cover protecting critical infrastructure, sustaining U.S. leadership in emerging technologies, and building the cyber workforce this country needs for the long term.

These three pillars speak to some of the most consequential long-range challenges in cybersecurity right now. Critical infrastructure attacks are accelerating. Artificial intelligence (AI) is being adopted faster than it can be secured. The talent gap is not closing. Getting these right matters enormously, and TrendAI™ is uniquely positioned to help.

Pillar 4: Secure critical infrastructure

The strategy identifies energy, financial services, telecommunications, data centers, water utilities, and healthcare as priority sectors for hardening.

The challenge

This is not theoretical: the last several years have brought a steady escalation of attacks on these sectors. The Colonial Pipeline ransomware attack in 2021 disrupted fuel supplies across the U.S. East Coast. Healthcare organizations have been repeatedly targeted by ransomware groups that understand the life-or-death pressure to restore operations quickly. Attacks on water treatment facilities in Florida and elsewhere demonstrated that even smaller utilities can become targets with significant public safety implications.

The strategy also highlights the need to secure supply chains and, if possible, move away from products and vendors targeted by adversary nations. This is a direct response to years of documented compromise via hardware and software supply chain intrusions, from the SolarWinds campaign to telecommunications backdoors attributed to nation-state actors. The risk is real; the exposure is broad, and the consequences of getting it wrong extend well beyond individual organizations.

Complicating matters further is the convergence of information technology (IT) and operational technology (OT) networks. Industrial control systems (ICS) and supervisory control and data acquisition (SCADA) environments that once operated in isolation are now connected to enterprise networks and, increasingly, the internet. That connectivity creates efficiency and visibility but also expands the attack surface dramatically.

How TrendAI™ helps

OT and ICS security

TrendAI™ has deep expertise in securing OT environments. Our industrial network security solutions provide passive, nondisruptive monitoring of ICS and SCADA networks, delivering visibility into assets, communications, and anomalous behavior without disrupting operational processes. For critical infrastructure operators managing legacy control systems that cannot be easily patched or replaced, this kind of passive detection capability is essential. We identify threats at the network level before they can propagate from IT environments into OT, protecting the physical processes that underpin energy, water, and manufacturing operations.

TrendAI™ Zero Day Initiative™ (ZDI) and ICS vulnerability research

TrendAI™ ZDI, the world’s largest vendor-agnostic bug bounty program, includes bounties for ICS and SCADA vulnerabilities. We have discovered and responsibly disclosed hundreds of critical vulnerabilities in industrial control software and hardware over the years, stripping adversaries of the tools they would otherwise use to compromise critical infrastructure. This proactive research directly serves the strategy’s goal of hardening these sectors before malicious actors can exploit known weaknesses.

Healthcare security

Healthcare is one of the most targeted sectors in today’s threat landscape, and for understandable reasons. The combination of sensitive patient data, life-critical systems, and historically underfunded security programs makes it an attractive target. TrendAI™ provides comprehensive protection across the healthcare attack surface, from connected medical devices and clinical workstations to hospital networks and cloud-hosted electronic health record (EHR) systems. Our extended detection and response (XDR) capabilities help healthcare security teams, many of which are small and under-resourced, identify and contain threats before patient care is disrupted.

Supply chain risk management

We understand that the supply chain is increasingly the preferred attack vector for sophisticated malicious actors. Our threat intelligence capabilities help organizations assess the risk profile of their technology vendors and identify indicators of supply chain compromise across endpoints, network traffic, and cloud environments. By tracking adversary campaigns targeting software development pipelines and managed service providers, we give critical infrastructure operators the context they need to make informed procurement decisions and detect intrusions that arrive through trusted third parties.

Cloud security for critical infrastructure

As critical infrastructure operators migrate workloads to cloud environments, TrendAI™ provides the security capabilities they need to do so safely, as detailed in our 2025 Defenders Survey Report. Our cloud workload protection and cloud security posture management solutions extend continuous protection across Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform, ensuring that the shift to cloud does not introduce new blind spots. For regulated sectors, our FedRAMP-authorized solutions provide a path to cloud adoption that meets federal compliance requirements.

Pillar 5: Sustain superiority in critical and emerging technologies

The strategy’s fifth pillar places U.S. leadership in AI and quantum computing at the center of the national security agenda.

The challenge

This approach makes perfect sense, and not only because these technologies are strategically important in their own right. The reality is that adversaries are already weaponizing AI. We are seeing AI-generated phishing content that is more convincing and personalized than anything produced before. We are seeing malicious actors use AI tools to automate reconnaissance, accelerate vulnerability discovery, and scale social engineering campaigns in ways that would have required entire teams just a few years ago.

At the same time, the rapid adoption of AI across both the public and private sectors is creating new attack surfaces that most organizations are not yet equipped to defend. Generative AI (GenAI) models, AI application programming interfaces (APIs), model training pipelines, vector databases, AI agents, and retrieval-augmented generation (RAG) systems all introduce novel security risks. Prompt injection attacks, model poisoning, and sensitive data exfiltration via AI assistants are threat categories that did not exist five years ago and are now active concerns.

Quantum computing adds a separate but equally serious dimension. The cryptographic foundations that secure virtually all digital communications today are vulnerable to sufficiently powerful quantum computers. While cryptographically relevant quantum systems are not yet operational, the timeline is shortening. Adversaries are likely harvesting encrypted data today with the intent to decrypt it when quantum capability arrives. This "harvest now, decrypt later" strategy makes the transition to post-quantum cryptography (PQC) an urgent priority, not a future-state concern.

How TrendAI™ helps

Securing the AI stack

TrendAI™ has invested significantly in understanding and securing AI systems. The TrendAI Vision One™ AI Security solution addresses the full lifecycle of AI deployment. It protects training data and model infrastructure and monitors AI applications in production for adversarial inputs and anomalous outputs. We help organizations understand what their AI systems are doing, what data they are accessing, and where they are exposed to manipulation. As federal agencies and critical infrastructure operators accelerate AI adoption, this kind of security-first approach to AI deployment is essential.

AI-native threat defense with proactive AI

We are not just securing AI systems used by others. We have built AI into the core of our own platform in a way that meaningfully changes what defenders can do. Using our proactive cybersecurity AI, TrendAI™ moves beyond reactive detection to anticipate threats before they materialize. It continuously analyzes attack patterns, adversary behavior, and environmental context to identify risk and take autonomous protective action. For agencies looking to the strategy’s call for AI-powered defense tools, this represents a fundamentally different model from simply adding an AI layer on top of legacy security products.

AI governance and compliance support

The strategy calls for promoting a secure AI technology stack and ensuring responsible innovation. We are actively engaged in the AI governance space, participating in industry working groups, contributing to AI security standards, and building compliance monitoring capabilities into our platform. Our TrendAI Vision One™ AI Security solution provides visibility and control over every GenAI service, user, and interaction within an organization. This enables agencies to implement appropriate use policies and prevent sensitive data from flowing into unauthorized AI systems.

PQC readiness

We are tracking the National Institute of Standards and Technology (NIST) post-quantum cryptography standards closely and incorporating PQC readiness into our product roadmap. We are committed to ensuring that agencies using our platform can execute the migration away from quantum-vulnerable cryptographic algorithms without creating security gaps in the interim. Our guidance and tooling help organizations inventory their current cryptographic posture, prioritize the systems most at risk, and plan a managed transition to quantum-resistant algorithms aligned with federal mandates.

Supporting U.S. technology leadership

TrendAI™ is deeply committed to supporting the strategy’s goal of sustaining American leadership in critical technologies. Our research teams contribute to the open security community through vulnerability disclosure, threat intelligence sharing, and published research that advances the collective understanding of emerging threats. We actively collaborate with the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and other federal partners to ensure our capabilities align with national priorities. These partnerships ensure our threat intelligence informs government defensive operations.

Pillar 6: Build cyber talent and capacity

As demand for cyber talent remains strong, the U.S. recognizes the need to address workforce gaps.

The challenge

The cybersecurity workforce shortage is one of the most persistent and difficult issues in the industry. According to the ISC2 Cybersecurity Workforce Study, there are approximately 4.8 million unfilled cybersecurity positions globally, with the U.S. accounting for a significant share. This challenge cannot be solved solely by increasing the number of people entering the field, though that matters. More importantly, it is a skills problem: The threat landscape evolves so quickly that even experienced practitioners must continuously expand their knowledge. Many organizations struggle to attract and retain the talent needed to operate modern security tools effectively.

The strategy’s proposed U.S. Cyber Academy, paired with a commitment to removing unnecessary regulatory barriers to training and creating venture capital incubators to support cyber startups, reflects an understanding that addressing this challenge requires action at multiple levels. I support this direction fully. The gap between the demand for security expertise and the available supply has real consequences. I have seen those consequences firsthand across the organizations I have worked with over nearly three decades in this industry.

There is also a less frequently discussed dimension to this challenge: the complexity of today’s security tool environments. Many security operations center (SOC) teams are not just understaffed; they are overwhelmed. The average enterprise security team manages dozens of point solutions, processes thousands of alerts daily, and spends an enormous proportion of time on manual tasks that could and should be automated. Hiring more people into a broken workflow does not solve the problem.

How TrendAI™ helps

AI that amplifies what analysts can do

The most direct way we address the talent shortage is by making each security analyst substantially more effective. Our TrendAI Companion™ AI assistant enables analysts to investigate complex threats using plain-language queries, surfacing relevant context from across the attack surface without requiring deep expertise in every telemetry source. Automated alert correlation, attack chain summarization, and AI-guided response recommendations dramatically reduce the manual workload on SOC teams. This allows smaller teams to operate at a level previously possible only for large, well-resourced organizations. This is not about replacing human analysts; it is about removing the friction that burns them out and drives them out of the field.

Simplified platform that reduces the learning curve

Platform consolidation is another meaningful contribution to the talent problem. When agencies can replace dozens of point solutions with a single integrated platform, they reduce the training burden and simplify operations. Analysts can also develop deep expertise in one environment rather than shallow familiarity with many. The TrendAI Vision One™ platform is designed precisely for this. It provides endpoint, network, email, cloud, AI, and identity security in a consistent interface, backed by shared threat intelligence and a unified data model. This makes onboarding faster, analyst development more structured, and incident response more coherent.

Threat intelligence as a training asset

Our published research, threat briefings, and regular threat intelligence content serve an educational function that goes beyond informing specific detections. When analysts read a detailed TrendAI™ analysis of an advanced persistent threat (APT) campaign, they are learning how adversaries think, what tools they use, and how defenders should respond. This kind of threat-informed education is one of the most effective ways to build practitioner-level skills. We are committed to continuing to share our research as a public good for the broader security community.

Support for government training and workforce initiatives

We actively support government-led workforce development initiatives, including CISA’s cybersecurity workforce programs, and we are prepared to deepen that collaboration as the U.S. Cyber Academy and related initiatives take shape. We believe the private sector has both a responsibility and a direct interest in helping government build the next generation of cyber defenders. TrendAI™ stands ready to contribute our expertise, tooling, and threat intelligence to those efforts.

Looking ahead

Taken together, pillars four, five, and six of the National Cyber Strategy address the foundational questions. Where do our most critical risks live? What technologies will define the next decade of security? And do we have the people and capacity to defend against what is coming? These are not easy problems, and no single organization solves them alone. TrendAI™ is well positioned to be a meaningful partner to government agencies working to put this strategy into practice.

We look forward to continuing this conversation as the administration moves from strategy to implementation. If you want to learn more about how TrendAI™ supports federal and critical infrastructure organizations, see our proactive cybersecurity solutions for government or contact your TrendAI™ account representative.

And as always, feel free to share your thoughts and reach out to me directly on X (formerly Twitter) at @JonLClay.

Take care and have a safe and secure future.

HIDE

Like it? Add this infographic to your site:
1. Click on the box below.   2. Press Ctrl+A to select all.   3. Press Ctrl+C to copy.   4. Paste the code into your page (Ctrl+V).

Image will appear the same size as you see above.

Veröffentlicht in Cybercrime & Digital Threats, AI