Billington Summit highlights blurring public-private cybersecurity lines
At the Billington Cybersecurity Summit, public sector security experts address a threat landscape that no longer distinguishes between government and private targets.
As nation-state actors target commercial networks alongside government systems, public-private collaboration is no longer optional -- it is an operational imperative. That was a central message at the 17th annual Billington Cybersecurity Summit in Washington, D.C., where public-sector defenders and private enterprises gathered to tackle an increasingly interconnected threat landscape.
Cybersecurity leaders at the federal, state and local levels, along with defense and intelligence agencies, operate at the bleeding edge of cybersecurity. While these public defenders face many of the same types of cyberattacks as private industry, they also carry a dual mandate: safeguarding agency systems and protecting critical infrastructure.
Closing the gap between public-sector insights and private-sector defenses was the primary focus of the summit's opening sessions this week, where officials called for a fundamentally new approach to collaboration and information sharing across government and industry.
A call for collaboration
"In terms of the relationship between government, industry and other partners, collaboration is absolutely essential," said David Imbordino, director at the NSA Cybersecurity Directorate, in a panel discussion.
According to Imbordino, cooperation between government cyber agencies and private industry is critical to effective cybersecurity defense. Threats transcend organizational boundaries, with adversaries targeting both public and private sectors simultaneously. Government agencies possess unique intelligence on nation-state actors, emerging threat patterns, and strategic vulnerabilities, while private industry holds valuable insights into real-time attacks, innovative defense technologies and sector-specific risks.
This partnership can enable faster threat detection and response. When organizations share indicators of compromise and attack methodologies, they create a collective defense that benefits all participants. Private companies often own and operate critical infrastructure such as energy grids, financial systems and healthcare networks, making their security essential to national resilience.
Without collaboration, Imbordino explained, both sectors operate with incomplete information, leaving dangerous blind spots that adversaries exploit. Coordinated information sharing accelerates incident response and prevents duplicate attacks. Policymakers are clear that, in an interconnected digital ecosystem, unified defense through public-private collaboration is an essential national security aim.
Nation-state lessons inform enterprise defense
Government agencies and geopolitical flash points have much to teach enterprise CISOs. During the Billington Cybersecurity Summit's opening session, Ivan Kalabashkin, deputy head of the Cyber Department of the Security Service of Ukraine, painted a vivid picture of the types of cybersecurity threats used in a battlefield situation. Rather than attacks solely on military targets, all infrastructure -- both public and private -- became potential targets and, in the eyes of the adversary, intricately linked.
Kalabashkin described attacks against energy systems in which AI agents were tasked with mapping the flow of power through substations. The goal was to understand where on the power grid a missile attack would do the most damage.
While it is unlikely that U.S.-based CISOs will face a cyberattack preceding a missile strike, Kalabashkin's scenario underscores the sometimes-cryptic motivations behind threat actors' efforts and the growing interdependence between critical infrastructure and all points along the supply chain. The defenses mastered by professionals in these worst-case cybersecurity environments can educate and inform enterprise security operations not yet confronting such complex threats.
Enterprises are the new national infrastructure
Enterprises are recognizing that, in the eyes of nation-state adversaries, their corporate networks are the infrastructure. Because critical national systems and communications are predominantly owned and operated by the private sector, they represent strategic targets for foreign actors seeking to undermine U.S. interests without directly attacking government systems.
Nation-state hackers exploit this reality, infiltrating private companies to disrupt essential services, steal sensitive data or establish persistent access for future operations. An attack on supply chain networks or data is more than a business problem; according to policy experts, it's a national security threat.
As such, an independent company's cybersecurity posture directly impacts America's economic stability, public safety and geopolitical standing. In this new threat environment, corporate SOCs have effectively become the front lines of national security.
A global forum for public-private defense
The 17th annual Billington Cybersecurity Summit, held September 8-10 in Washington, D.C., brings together more than 4,000 government and private sector leaders to address the nation's most pressing cybersecurity challenges.
This annual event facilitates critical dialogue between federal cyber agencies, military officials, industry executives and technology innovators, fostering the public-private partnerships essential to national security.
TechTarget Cybersecurity will be on the ground at Billington throughout its three-day run.
Richard Livingston is an editor for TechTarget Cybersecurity, covering news, trends and analysis. Livingston's professional background includes editorial positions in the national defense industry covering the U.S. Army Medical Department, as well as offensive and defensive cyber strategy for military and government audiences.