Chris Painter on Why Victims Never Get the Headline

Chris Painter was the United States’ first cyber diplomat—the inaugural Coordinator for Cyber Issues at the State Department—and before that, a federal prosecutor who built some of the country’s defining cybercrime cases. He spent decades shaping cyber policy, from the State Department to the White House to international negotiations with China and India. He now advises the boards of leading cybersecurity companies and nonprofits, and has supported Critical Cyber since its earliest days. As AI lowers the barrier to attack faster than accountability can respond, Painter argues the deeper failure isn’t technical—it’s narrative: the public has never been asked to feel a threat it is only ever shown in numbers.


“When people had to wait in line for gas after the Colonial Pipeline attack, cyber issues transformed from a technical threat into a political priority.”


You prosecuted some of the earliest, highest-profile cybercrime cases in U.S. history. Cybercriminals have only gotten faster and more organized since. Has accountability kept pace?

It’s always been a game of cat and mouse. Criminals adopt new technology, and the smart ones use sophisticated methods to both enhance their attacks or intrusions and hide their trail to evade law enforcement. Criminals have also become adept at using proxies and cryptocurrency, especially the ransomware groups, to make it harder for law enforcement to identify them, and often operate from safe havens to escape accountability. Though this isn’t new, it has accelerated with the increasing use of AI by criminals for everything from crafting a better phishing email to automating exploitation of targets.

At the same time, law enforcement has become far more sophisticated at tracing cyber intrusions, tracing financial transactions, and cooperating internationally to coordinate cross-border investigations and execute multi-country takedowns. Still, progress among law enforcement entities, particularly in developing countries, remains uneven, and criminals exploit these seams. So cybercrime is hardly a risk-free enterprise these days, but ensuring accountability remains a constant battle.

One of your cases was Kevin Mitnick’s—a cybercriminal who went on to become a security consultant. The public gave him a redemption arc. Most survivors get no arc: no closure, no named responsible party, just a life that continues alongside the damage. What does it say about cybercrime that the attacker gets a story, and the victim doesn’t?

Mitnick was a controversial figure, and I don’t think it's true that the public as a whole gave him a redemption arc. Though some thought him rehabilitated, others never trusted him or forgave him for his activities, and he never fully accepted responsibility. That said, you are totally right that the press and public are seemingly more interested in sensationalizing the sometimes-fanciful stories of the cybercriminals rather than focusing on the victim stories that they see as more mundane. That’s a hard dynamic to break—there are many movies about bad guys in physical space but few about the victims. But it is essential we change the narrative and shift attention to victims if we are ever going to do what we need to: not just reduce the crimes, but reduce the harm.

AI can make reducing harm harder. The models are now used at every stage of an attack, from reconnaissance to execution. It no longer takes a nation-state’s resources to cause nation-state-level damage. As U.S. Coordinator for Cyber Issues, you helped build the rules of the road in cyberspace for state actors. Do those rules still hold when the attacker could be almost anyone?

The stability framework at the UN and the agreed—though often not followed—norms of responsible behavior are explicitly norms of “responsible state” behavior. If we’re talking about non-state criminal actors, criminal rules and liability apply, and now many states, though not all, have sufficient laws to cover cybercrime. States can also be held responsible if private actors are acting as proxies at the direction of a state, or if the state is providing them a safe haven. So the rules, sometimes different ones, apply whether the actor is a state or non-state.

The bigger problem has been accountability for violating these rules. It’s great to have agreed frameworks, but they are just words on paper if there are no consequences when they’ve been crossed. We’ve improved, though we still have a long way to go, in ensuring that criminal consequences are certain and swift. On state accountability, consequences for bad actors have been inconsistent, and ultimately haven’t altered their calculus. This needs to change.

One thing toward greater understanding would be making the stakes relatable to the public. Governments and security companies too often disclose a threat without translating it into human consequence—and leaders who can’t make cyber risk feel real to the public don’t get the mandate to act on it. Can survivor testimony do that translation work?

We’ve been trapped in an ineffective narrative cycle for years. Threats are detailed in technical terms or in terms of large financial losses, and, frankly, the public and policymakers don’t understand the former and are numb to the latter. They’re also numb to extreme but unrealized claims of a cyber Pearl Harbor or a cyber 9/11, even though victims are suffering real, if less dramatic, harm every day. When a significant malicious cyber event occurs, most policymakers and the public pay attention for a short time and then go back to ignoring the problem.

One of the phrases I hate the most is calling whatever the cyber event of the day is “a real wake-up call.” History shows us that we wake up for about an hour and then go back to sleep. Why? Because the way we talk about these events is devoid of the emotional content and real-life impact that the public and non-cyber policymakers understand, can identify with, and can use to craft policies that make a real difference in addressing the substantial harm that happens every day. So yes—survivor and victim testimony helps break this cycle, and unlike financial losses, it has real staying power and impact that can drive solutions. That is why I’ve strongly supported Critical Cyber from its beginning.

You now advise several boards of leading cybersecurity companies and international nonprofits. Does survivor testimony ever reach those rooms, or is it filtered out before it arrives? What would it take to put this evidence in front of a boardroom?

When a company or a nonprofit is a victim, their immediate concern is stopping the bleeding and restoring operations. Though if they were aware of how other victims were impacted, how they responded, including the challenges they faced, and how they got back on their feet, if they did, that would be of great help to these new victims in mitigating harm. For non-cyber companies or nonprofits, real stories of victims can make the risks of a malicious cyber event real for a board where there is often little understanding of the threat. Cybersecurity companies are more attuned to survivor testimony, both because it helps them design better products and because it provides a compelling narrative for why their services are necessary.

Name one reform that would close the accountability gap fastest for the people living through these attacks today.

Policymakers embracing this area as not just an occasional priority but an enduring one—one that requires sustained and intelligent effort, both in devising appropriate policy and in resourcing and executing those policies. I’ve often cited several real-life impacts of ransomware to make this point. When people had to wait in line for gas after the Colonial Pipeline attack, or couldn’t trust their food supply when a meatpacking plant was targeted, or didn’t feel secure in their healthcare after the attack on Ireland’s health service, cyber issues transformed from a technical threat into a political priority, and, for a time, real leader-level action followed. Transforming cyber from a technical subject into one that encompasses the real-world, often long-term, suffering of ordinary victims and institutions is exactly what Critical Cyber is trying to achieve, in order to focus attention and lead to more effective, survivor-centered solutions.

Next
Next

Natalie Sullivan on What Happens When Hospital Goes Dark