- Tim Kosiba is warning the audience about how Chinese threats are infiltrating many technical domains
- He said Chinese companies have worked with Iran to target US forces in the Middle East
- Hear directly from Kosiba about intel business opportunities during his keynote at the 2026 Intel Summit on Sept. 24!
Tim Kosiba, deputy director of the National Security Agency, is sounding the alarm about Chinese intelligence capabilities. He recently told an industry gathering how Chinese threats have infiltrated almost every technical domain while Chinese companies are working with Iranian forces during combat in the Middle East.
“China has its hands in most every national security priority we are dealing with today, and it’s a hot competition,” said Kosiba, according to Breaking Defense. “For example, it’s no secret that Chinese companies provided [geospatial intelligence] to the Iranians to help hit our bases and our allies.”
Kosiba is no stranger to the NSA’s most sensitive operations. He’s held leadership positions in the agency’s Tailored Access Operations, a highly classified division responsible for offensive cyber operations and achieving covert access to foreign computer networks, GovExec reported. His career has also featured roles as chief of computer network operations and as deputy commander of NSA Georgia, the agency’s largest field site.
Discover how Kosiba and the NSA are better evaluating and procuring cutting-edge commercial technologies during his keynote at the Potomac Officers Club’s 2026 Intel Summit on Sept. 24. Get exclusive investment insights and requirements before they’re published on intelligence capabilities like offensive and defensive cyber operations, signals intelligence and agentic AI in cybersecurity. Secure your seat today!
Let’s explore four ways Kosiba and the NSA are countering Chinese intelligence threats.
What Are Four Ways Tim Kosiba and the NSA Are Countering Chinese Intelligence?
1. Cybersecurity Collaboration Center Partnerships
Kosiba and the NSA have formed partnerships with more than 1,000 private- and public-sector organizations to better combat burgeoning cyber threats, particularly from China, according to GovInfo Security. The agency in 2020 specifically established the Cybersecurity Collaboration Center to grow public-private alliances to improve threat detection, information sharing and incident response management, said Jami Wise, deputy chief of the NSA’s China Strategy Center.
In 2024, the agency leveraged the collaboration center to address a threat exploiting a vulnerability in a vendor’s system. The program enabled the NSA to partner with the vendor to reduce the threat and work with foreign partners to deploy protective measures at scale.
The NSA has also collaborated with international counterparts to inform network operators about Chinese threats. In July 2024, the agency and allies, such as the Australian Signals Directorate, issued case studies on Chinese cyber tactics, including how a hacking group variously known as APT40, Kryptonite Panda and Gingham Typhoon evolved its methods to exploit novel vulnerabilities in widely used software to target government networks.
“NSA is not doing it alone,” Wise told the Billington CyberSecurity Summit. “[The collaboration center is] a mechanism for us to be able to work with our partners and try to be able to deliver cybersecurity outcomes at scale.
2. Joint Advisories With Allies
The NSA, led by Kosiba, has issued a trio of joint advisories to build awareness of Chinese efforts to secretly perform cyber activity at scale. The NSA, most recently in April, worked with the U.K.’s and Australia’s national cybersecurity centers to release the joint Cybersecurity Advisory, “Defending against China-nexus covert networks of compromised devices.”
This CSA explains how a variety of China-nexus threat actors are leveraging external covert networks to conduct malicious cyber activity strategically, at scale. These innovative covert networks include botnets that take advantage of many compromised devices to connect across the web in a cheap, low-risk and deniable fashion, masking the origin and attribution of malicious activity in the process.
These botnets regularly include compromised small home/office network infrastructure, such as:
- Routers
- Firewalls
- Network-attached storage
This communication built upon an earlier CISA advisory, “Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System,” which named specific Chinese companies, including Sichuan Juxinhe Network Technology, Beijing Huanyu Tianqiong Information Technology, among others, linked to APT activity dating as far back as 2021.
Are you a GovCon technology professional looking to boost intelligence revenues? Then you can’t afford to miss the Potomac Officers Club’s 2026 Intel Summit on Sept. 24. Tim Kosiba’s keynote will arm you for contracting success on the emerging technologies transforming the intelligence, such as:
- Cross-agency and Five Eyes intelligence sharing
- Open-source intelligence
- Data governance
And more! Get your burning questions answered by Kosiba following his keynote. Take advantage of this rare opportunity to hear directly from the NSA’s number-two leader and get an edge on your competition. Buy your ticket now!
3. Building Out Talented Personnel
The NSA made multiple strategic hires in June, in addition to Kosiba, to improve its cyber work, NextGov/FCW reported. David Imbordino, who was overseeing the NSA’s Cybersecurity Directorate in an acting role, was chosen to command the office permanently.
Holly Baroody, a U.K.-based NSA official and previous civilian leader in U.S. Cyber Command, was selected to serve as Imbordino’s deputy. Bruce Jones, a long-time NSA staffer with a background in both operational and technical roles, will direct the NSA’s Cybersecurity Collaboration Center.
Wash100 Award winner Gen. Joshua Rudd was confirmed in March to direct U.S. Cyber Command and the NSA in its dual-hatted role, with Kosiba joining the NSA soon after.
4. Improving Business With Industry
The NSA has undertaken several initiatives to improve how it acquires critical emerging technologies from industry. The agency created an Acquisition Resource Center, a novel business registry database that gives industry a one-stop source of acquisition information. It also serves as a market research tool for NSA personnel and for distributing acquisition documents to industry partners.
The agency also has its GreyBox, an application that helps developers build technologies that can work within the agency’s technical ecosystem. GreyBox includes mockups of interfaces for several common services that are dependencies for multiple mission applications in NSA classified environments.
A third effort is the Provisional Industrial Security Approval, or PISA, program. PISA provides a mechanism for companies to obtain the necessary personnel clearances to engage in classified discussions with NSA personnel. The ability to participate in these high-level discussions should provide companies with an understanding of current and potential agency needs.
The PISA program specifically sponsors clearances for NSA sensitive compartmented information, or SCI, access for a limited number of individuals, including key management personnel and employees.














