Securing 700,000 Endpoints: Former Air Force CIO on Scale, Cyber Resilience, and AI

Posted on July 15, 2026
Author: RunSafe Security

Key takeaways

  • Compliance is only a starting point. At scale, training and audits can’t outpace the threat.
  • Know what you have first. Inventory the enterprise, then secure the top missions.
  • Manage as an enterprise. One consolidated Cisco contract saved ~$300M and improved security.
  • AI is the next transition. It finds and exploits flaws faster than patch cycles can respond.
  • Resilience is the answer. Map your software with an SBOM, prioritize by mission, and harden the code, which is the work RunSafe does alongside patching.

 

Ask most people how to secure 700,000 devices, and they reach for a bigger budget or a smarter tool. Bill Bender, former Chief Information Officer of the U.S. Air Force, says the answer starts somewhere far less glamorous: figuring out what you actually have.

On any given day, Lt. Gen. (Ret.) Bill Bender managed an endpoint footprint that rivals that of the biggest companies in the world, spread across legacy operating systems, industrial control systems, and equipment that must remain in service for 25 years or more.

In an episode of Exploited: The Cyber Truth, Bender joined Joe Saunders, Founder and CEO of RunSafe Security, to talk about what it takes to defend a system that big. 

While compliance gets you to the starting line, resilience is what keeps you standing as technology keeps changing beneath you. And right now, the technology changing fastest is AI.

 

The Scale Problem

When a retailer has a bad hour, some customers cannot buy shoes. When a military system fails, missions stall and lives are on the line. Bender calls these “no fail missions,” and they set the terms for everything else. The Air Force runs on the hard end of the spectrum, with hundreds of thousands of endpoints, decades of technical debt, and systems you cannot simply upgrade from one Windows version to the next. As he put it, “the scale is the issue.”

That scale is where a compliance-first mindset shows its limits. A compliance-only program leans on training, and in a workforce that turns over as constantly as the Air Force’s, the training bill alone becomes a non-starter. Bender calls for an “all-in approach” across the workforce and counts compliance as a genuine requirement, just not a sufficient one. 

Compliance is necessary, he argues, and still not the whole answer. What closes the gap is the combination. “It’s compliance plus the use of technology and better methodologies,” he said.

Start By Knowing Where You Are

If the answer is compliance plus better methodologies, the first of those methodologies is knowing what you are working with. Bender’s first move was to conduct an inventory. Before setting any direction, his teams worked down from major commands to wings to squadrons to understand the real state of their IT. 

“If you don’t know where you are, you’ll never know where you’re going,” Bender said. From there, the job is prioritization, securing the top missions first and letting the second- and third-order requirements wait.

The harder part was cultural. Bender calls the human half of this work a “chief education officer. Most of the resistance he hit came from individuals whose processes had not kept pace with the technology. One habit he had to break was the assumption that controlling the budget is the same as owning the architecture. “Money is power,” he said, describing the mindset that produces local control and worse outcomes.

The $300 Million Lesson

Replacing that local-control instinct with enterprise thinking paid off twice. The Air Force had been managing its network gear one base at a time, running roughly 2,200 separate Cisco contracts across the globe. Collapsed into a single enterprise agreement, that estate saved on the order of $300 million over five years. The money mattered, but Bender pointed to what the consolidation fixed operationally, with standardized equipment, faster response times, fewer gray-market parts, and one supplier held to one set of service commitments instead of thousands.

Getting there took a partnership, not a purchase order. Cisco was in from the beginning, Bender said, helping take accountability of what was actually deployed and delivering on the service commitments the new structure depended on. The lesson was less about any one vendor than about the model. Big, complex organizations get better security and better economics when they stop buying in fragments and start managing as an enterprise.

Borrowing From the Boardroom

Contracts were only half of it. The organization itself had to change, and Bender restructured it in ways the Pentagon had not tried. He was the first leader in the Department of Defense to stand up a Chief Information Security Officer (CISO) and a Chief Operating Officer (COO), roles borrowed straight from the commercial world, along with a Chief Data Officer and an innovation unit that became the forerunner to the Defense Innovation Unit. “The world around us has changed. We have to change, too,” he said.

He also went looking for ideas outside the building, spending time in Silicon Valley to see what was possible and standing up an innovation unit with the funding and the mandate to move quickly. Part of what he was fixing was the pace of government itself, which can be fatal to a young company.

 “If I’m an innovator and an entrepreneur, I’ll be out of business before I ever get my first contract with the Department of Defense,” he said, describing the gap he set out to close.

Modernize or Fall Behind

That same appetite for speed led to hard calls on legacy programs. A command-and-control weapon system had drifted toward a billion dollars and was about ten years behind schedule. The Air Force canceled it and rebuilt it around a software-defined approach that the commercial sector had used for fifteen years. The decision sparked a wave of in-house development, with 34 software factories now running across the service and a defense infrastructure that Bender describes as far more modern and capable as a result.

The through-line across all of it is a refusal to stand still. “You can never rest on your laurels. You can’t be complacent,” Bender said. Faster software delivery is a gift to the warfighter, but it also means more code to defend.

AI Is the Next Transition

That expanding attack surface is where AI changes the stakes. Having lived through the shift to software-defined systems, Bender sees AI as the next version of the same story. It was fortunate the Air Force went through the software journey when it did, he said, because AI is in front of everyone now and moving faster than the last transition did.

The security problem comes with it. The same speed that lets teams ship software lets adversaries attack it, and agentic AI can scan for weaknesses and, in some cases, write working exploits faster than defenders can respond. “You can’t build a wall high enough or fast enough to keep up with it,” Bender said.

That shift hits hardest for teams still relying on patch cycles as their main line of defense. AI can find vulnerabilities and write exploits, Saunders said, “faster than we can patch, even faster than DevOps pipelines can produce fixes.” When the gap between disclosure and exploitation collapses, patching remains essential but is no longer enough on its own. Something has to cover the window while the fix catches up.

Building Cyber Resilience When Patching Can’t Keep Up

That window did not open overnight. Bender argues the country spent years building the exposure AI now takes advantage of. “For many, many years, we have built ourselves into a box with software that isn’t entirely secure,” he said. AI now shines a light on every one of those weaknesses. His prescription is to point some of that same energy back at the infrastructure and to “take care of the big problems so that we can focus on the small problems.”

In practice, cyber resilience follows the same sequence Bender used at scale. Know the software you depend on, starting with a Software Bill of Materials (SBOM) that inventories what is inside your embedded and operational technology systems. 

Saunders calls the SBOM “a good enabler to understanding the software risk,” and the broader threat that follows if that software is compromised. Prioritize by mission. Then harden the software itself so whole classes of memory-safety vulnerabilities are far harder to exploit, even before a patch arrives. That last step is the work RunSafe does, and it complements patching rather than replacing it.

“Critical infrastructure is an extension of national security,” Saunders said, from energy to data centers to the systems that keep missions running. His read on AI was optimistic. If AI exposes these weaknesses faster than anyone can patch them, it may finally force the fixes, the way you never really understand algebra until you start learning calculus. The threat is real. So is the chance to build systems that hold.

Catch the full conversation with Lt. Gen. (Ret.) Bill Bender and Joe Saunders on Exploited: The Cyber Truth.

Guide to Creating and Utilizing SBOMs

Latest Blog Posts

CRA Readiness: 6 Steps Embedded Product Teams Should Take Now

CRA Readiness: 6 Steps Embedded Product Teams Should Take Now

The first major Cyber Resilience Act (CRA) deadline is nearly here. Beginning September 11, 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents affecting products with digital elements. The broader CRA requirements become...

read more