Intelligence Squared
Intelligence Squared

The Cyber Weapons Arms Race, with Nicole Perlroth and Josh Glancy

Zero day: a software bug that allows a hacker to break into your devices and move around undetected. One of the most coveted tools in a spy's arsenal, a zero day has the power to silently spy on your iPhone, dismantle the safety controls at a chemical plant, alter an election, and shut down the

Featured Speakers

Nicole Perlroth Guest

Topics Discussed

Episode Summary

Executive Summary: Nicole Perlroth argues that cyber conflict has moved from espionage to potential physical harm, with the U.S. still a leader but increasingly exposed by its digitized infrastructure, offensive-first strategy, and weak defense. The conversation traces Stuxnet, SolarWinds, and rising threats from Russia, China, Iran, and ransomware actors.

Main Topics: Nicole Perlroth’s path into cybersecurity reporting (Priority: 4/5): Perlroth explains how she moved from tech/venture capital journalism into cybersecurity reporting at The New York Times, initially underestimating the field before realizing its scale and seriousness. Stuxnet as triumph and Pandora’s box (Priority: 5/5): The discussion frames Stuxnet/Olympic Games as a brilliant short-term success against Iran’s nuclear program that also demonstrated code could be a weapon, accelerating global cyber militarization. America’s vulnerability through digitization and openness (Priority: 5/5): Perlroth argues the U.S. is highly targeted because it is the most digitized country and because democratic/privacy constraints limit aggressive defensive monitoring and response. SolarWinds and supply-chain compromise (Priority: 5/5): SolarWinds is presented as a pervasive espionage breach that exploited trusted software distribution and showed how deeply adversaries can penetrate government and corporate systems. The failure of offense-only cyber strategy (Priority: 4/5): Perlroth critiques the belief that active defense and offensive cyber operations alone can deter adversaries, arguing SolarWinds proved private-sector warnings—not government offense—revealed the breach. Everyday cyber hygiene and infrastructure risk (Priority: 4/5): The interview closes on practical advice for individuals and a warning that weak passwords, phishing, insecure IoT devices, and underprotected municipal systems remain major attack surfaces.

Key Arguments: Cybersecurity moved from niche nuisance to national-security crisis as attacks became more destructive and linked to hospitals, utilities, elections, and critical infrastructure. Stuxnet was tactically effective but normalized cyber weapons and encouraged other states to build offensive capabilities. The U.S. is both the most advanced cyber power and the most vulnerable because so much of its infrastructure is connected to the internet. Russia and China exploit U.S. openness, legal constraints, and privacy protections by using American infrastructure or trusted vendors as staging grounds. SolarWinds demonstrated the limits of offense-heavy doctrine: the breach was found by a hacked private company, not by government early warning systems. Domestic terrorism now rivals or exceeds cyber in immediate threat, according to Perlroth’s updated assessment after January 6. Most real-world cyber risk still comes from low-effort attacks like phishing and password theft, meaning basic security practices could prevent many incidents. A formal cyber “Geneva Convention” is appealing but difficult because states use proxies, contractors, and deniability, and the U.S. itself conducts offensive cyber operations.

Data Points: Cyber lead time / superiority: 10+ years - Perlroth says the U.S. remains the most advanced cyber superpower, but its lead has slipped over roughly a decade. Stuxnet impact: 1,000 uranium centrifuges - She says the operation took out about 1,000 Iranian centrifuges and set back Iran’s nuclear ambitions. Stuxnet delay: 27 days - During the attack, the code alternated between speeding up and slowing down centrifuges while operators saw normal readings. Fortune 500 exposure: More than 400 companies - SolarWinds software was used by more than 400 of the Fortune 500, underscoring the supply-chain reach. Water-treatment tampering: From 100 ppm to 11,000 ppm - A Florida water facility’s lye level was reportedly increased dramatically before being caught in time. Private-sector ownership of infrastructure: 80% - Perlroth says about 80% of U.S. infrastructure is owned and operated by the private sector. Password example: "SolarWind123" - She cites the reported SolarWinds password as an example of poor security hygiene. Ransom demand example: $200 - Perlroth references early ransomware cases in Eastern Europe demanding about $200, contrasting with modern multimillion-dollar extortion. Modern ransomware demands: Double-digit millions - She notes hospitals now face ransomware demands in the tens of millions.

Pivotal Quotes: "There are obviously a lot of threats we think about. Why is this one the most grave?" — Josh Glancy: Sets up the central question of why cyber is so dangerous compared with other national-security threats. "We are the most advanced, we are also the most vulnerable and targeted." — Nicole Perlroth: Summarizes her core thesis about the United States’ position in cyberspace. "This is why it's called This Is How They Tell Me the World Ends, not This Is How the World Will End." — Nicole Perlroth: Explains her framing of the book as a warning based on escalating close calls rather than a prophecy.

Implications: Listeners should expect cyber risk to keep rising, especially for critical infrastructure and supply chains. Defense, not just offense, needs urgent investment, while individuals should use strong passwords, 2FA, and less connected devices.

🔓 Sign Up for Unlimited Episode Search

About Intelligence Squared

View all episodes from Intelligence Squared