Technology
Trending

Public-Private Partnership Must Move at the Speed of Cyber Risk 

By Huge Carroll, VP of Corporate Affairs & Head of Government Affairs at Fortinet 

At Black Hat 2026, Fortinet saw U.S. government agencies participating at a scale not seen in previous years. While the event is typically framed around what’s new in cybersecurity technology, the increased presence of the public sector was one of this year’s most consequential developments. It also contributed to greater participation by international cyber agencies, allied governments, standards organizations, and other institutional stakeholders. 

This change reflects both the heightened priority governments now place on cybersecurity and the critical role they play in the cyber ecosystem. Technology providers cannot secure today’s digital environment alone. At the same time, addressing the growing complexity of cyberthreats requires more than legislation, regulation, or law enforcement. To effectively disrupt cybercrime, both sectors must maintain ongoing relationships that enable information sharing, informed policymaking, and coordinated responses. 

Government Engagement Reaches a New Level 

Although countries have their own legal, economic, and security contexts, the threats they face readily cross borders. Cybercrime, supply chain risks, AI-driven attacks, and vulnerabilities in widely deployed technologies rarely remain confined to a single jurisdiction. Collaboration among governments and between the public and private sectors must be equally capable of crossing borders. 

During Black Hat, Fortinet executives, including Fortinet CISO Dr. Carl Windsor, met with officials from government cybersecurity agencies around the world, including CISA, the Cyber Security Agency of Singapore, and the European Union Agency for Cybersecurity (ENISA). Windsor also participated in an OpenPolicy discussion on product security with representatives from CISA and ENISA. 

Across these engagements, several recurring concerns emerged regarding how governments and industry can respond to a threat environment being reshaped by AI, emerging technologies, and increasingly complex regulatory requirements. 

AI Is Changing Both Defense and Attack 

AI was a key topic in many of these discussions, but it did not emerge as a single, clearly defined policy issue. Instead, governments and industry are addressing several interconnected challenges at once. 

While AI provides defenders with new methods for detecting vulnerabilities, analyzing threats, automating investigations, and accelerating response, threat actors are also using it to improve scams, fraud, impersonation, deepfakes, and other social engineering tactics. They are also using AI to coordinate more sophisticated attacks and industrialize their operations by automating and scaling activities that once required substantially more time, expertise, and personnel. As these tools become more accessible, governments and organizations will face not only a greater volume of attacks, but adversaries capable of operating with greater speed, coordination, and sophistication. 

As AI-enhanced tools detect potential vulnerabilities faster and at far greater scale, vendors face new challenges in validating, prioritizing, disclosing, and remediating them. Customers face a related challenge: determining which disclosures require urgent action without being subjected to a “death by a thousand cuts” from an unmanageable stream of patches. In regulated sectors such as financial services and healthcare, every change may require testing, approval, and carefully scheduled deployment. An unprioritized surge of disclosures can strain limited resources, disrupt operations, and make it harder to determine which risks require immediate action. 

The answer is not to slow vulnerability discovery. It is to pair faster discovery with risk-based prioritization, responsible disclosure, clear communication, and remediation processes that reflect customers’ operations. 

Quantum computing may be a less immediate concern, but it remains an important part of the discussion. Governments and organizations must begin preparing for its long-term security implications, even though the timeline remains uncertain. The transition to quantum-safe security will require cooperation among technology providers, standards organizations, governments, and critical infrastructure operators. Fortinet is a technology partner in the NIST National Cybersecurity Center of Excellence Migration to Post-Quantum Cryptography project, which is working to identify cryptographic systems vulnerable to quantum attacks and test implementations of NIST-standardized post-quantum algorithms. 

Regulation Must Remain Nimble 

The discussions also covered AI regulation, the EU Cyber Resilience Act, product certification and testing, and requirements related to national and regional sovereignty. Governments play a critical role in establishing accountability and protecting citizens, institutions, and critical infrastructure. However, cyber policy operates in an unusually fast-moving environment. Technology and threat methods can evolve significantly while regulatory frameworks are still being developed and enforced. 

This highlights the importance of regulatory agility. Rules should define clear outcomes and responsibilities while allowing flexibility in the tools and methods defenders can employ. Overly prescriptive requirements risk locking organizations into outdated assumptions that no longer match the current threat landscape. Regulations meant to enhance security should not hinder defenders’ ability to adapt. 

Ongoing industry engagements, such as those at Black Hat, help policymakers understand the operational consequences of different approaches before those approaches become difficult to change. They also give industry a clearer view of the public interests and national priorities that regulations are intended to protect. 

Sovereignty introduces an additional layer. Governments and regulated organizations are increasingly demanding proof that the technologies they adopt comply with regional standards for data management, product security, certification, and operational oversight. Satisfying these demands requires more than just a broad security guarantee. It relies on transparency, independently verified capabilities, and the capacity to assist customers in different regulatory settings. 

Trust Is Built Before a Crisis 

Public-private partnerships are sometimes discussed as if they only begin during a crisis. Effective coordination, however, depends on relationships established well before an emergency. Fortinet’s work with public- and private-sector partners, including CISA, NIST, INTERPOL, and the World Economic Forum’s Cybercrime Atlas, demonstrates what strategic relationships can achieve. Such collaborations combine government authority and convening power with private-sector threat intelligence and technical expertise to improve preparedness, information sharing, and coordinated action against cyberthreats. 

These partnerships provide more than an exchange of information. Trusted relationships also allow that information to be validated, placed in context, and turned into action. That trust is built through consistent engagement, responsible transparency, technical credibility, and candid discussion about what is and is not working. The increased presence of the public sector at Black Hat 2026 created an important opportunity to strengthen those relationships. 

However, participation is just the beginning. The true measure of progress will be whether these conversations lead to stronger information sharing, more effective product-security strategies, practical approaches to sovereignty and certification, and policy frameworks that can adapt to evolving threats. 

Cybersecurity now evolves too quickly and extends too far beyond national and institutional boundaries for any organization to operate alone. The future of cyber defense depends on collaboration between government and industry, grounded in trust, streamlined operational practices, and regulatory flexibility that enables effective coordination.

Related Articles

Back to top button

Adblock Detected

Please Turnoff the adblocker!