Home Newsletter Honored Guests Blog About Us Work With Us Sponsor & Advertise Be a Guest The Production Suite Get the Briefing
‹  All Episodes
BoardroomCybersecurity Jul 29, 2026

Raja Mikkili and Anne Herold Li on Why Nation States Target Small Biotechs

Raja Mikkili and Anne Herold Li on Why Nation States Target Small Biotechs

What you’ll learn

  • What a nation state actually wants from a biotech, and why it is not a ransom
  • Why small and mid-size companies are the more interesting target, not big pharma
  • How far down the supply chain you now have to audit, and who already has that infrastructure
  • The clauses to put in a vendor contract before you sign, and what to monitor after
  • Why your anonymized data set is the one a state actor wants
  • The four-sentence clause in collaboration agreements that quietly gives away data ownership

Most biotech executives picture a cyberattack one way: someone locks the servers and demands payment. Raja Mikkili opens this conversation by explaining why that picture is wrong at the level that matters most.

Mikkili is Vice President of Core Technologies and Security at Arcutis Biotherapeutics, and he has spent more than twenty years managing risk across aerospace and defense, private equity, construction, and pharma. A nation state, he says, is a different animal from the threat actors most companies plan for. They are not looking for tactical monetary extortion. “They’re not just after a company’s database, but they’re looking at a full roadmap for an organization,” he says. “They want to see where the science is going. They want to see where the company is vulnerable, what partners are they engaging with.” The objective is to skip the years of investment a biotech has already made and arrive at the same place faster.

Anne Herold Li takes the same problem from the legal side. Managing Partner of the New York office and Shareholder at Brownstein Hyatt Farber Schreck, she is a Chambers-ranked, first-chair trial lawyer who trained as an epidemiologist before she trained as a litigator, and she teaches biotechnology law at Fordham. Her framing is blunter. This is not company-versus-company competition, she says. “Nations are trying to jumpstart an industry in which the United States has such a lead, particularly United States and Europe, that there’s almost no way to get there without this jumpstart.”

The uncomfortable reframe: you are not too small to matter

What follows is the argument that gives the episode its spine, and it lands as a challenge to how most small and mid-size biotechs think about themselves.

“It takes a little bit of, I know this is going to come as a shock to some people, arrogance of the CEO to understand that their company is so interesting and impressive that they would give a nation state a head start,” Herold Li says. The instinct to assume you are beneath notice is the vulnerability. “It’s not a size thing. It’s a technology thing.”

The logic is straightforward once stated. Smaller companies do the innovative pivot, the new R&D, the latest technology. Large companies shop them for exactly that. “Because they’re the R&D labs for the big companies, they’re actually the more interesting target,” she says, “for a nation state trying to leapfrog into the industry.”

Mikkili adds the operational half of the asymmetry. A young biotech runs on cloud technologies, SaaS, and outsourced partners, which produces a comfortable and false conclusion. “It’s like, I don’t have anything to lose. It’s them, the third parties are actually taking care of all of those security things because we have hired them to do so.” The IP the company generates and holds is what makes it worth targeting, regardless of who administers the servers.

Herold Li’s practical counsel for the most valuable material is not a product recommendation. For unpatented protocols, benchtop science, and manufacturing know-how, she has started advising clients to keep it on paper. “Paper is safe and not hackable,” she says, calling it the old school Gen X response to hacking. Getting a human being inside a small research company is harder than attacking the cybersecurity that company bought.

West Pharmaceutical and the tier below the innovators

Lori Ellis turns the conversation to the West Pharmaceutical breach, and Herold Li treats it as the industry’s missed alarm. The company would not have thought of itself as an innovator worth targeting by a state actor. It was targeted anyway. What the case exposes is the exposure of the tier below big pharma: the companies that know a great deal about R&D, manufacturing, trials, and getting a product to market. “That’s already, you know, 80 percent of what you need to get to market right there,” she says, “in a company that may not think that they need to protect themselves because they’re not the innovator.”

Mikkili reads it as a supplier problem with industry-wide blast radius. West makes packaging and delivery systems for injectables, which makes it a shared third party to a large share of the sector. Exfiltrated data from a node like that maps the next attack against everyone connected to it. His conclusion cuts both ways: West owed its customers vendor risk management, and every customer owed itself a real program for managing a vendor that critical.

Auditing to the roots

Herold Li points out that the industry already knows how to do this work, just for a different statute. Companies certify to the U.S. government that no forced labor exists anywhere in their supply chains, and that obligation runs the whole way down. “If you’re making a pharmaceutical derived from fruit 17 vendors later, you’ve got to go all the way down and certify to the U.S. government that you are not using forced labor in your supply chain. This is a full level audit down to the roots.” Compliance teams have that infrastructure. It has not been pointed at cybersecurity.

Mikkili lays out what pointing it there looks like: classify vendors by the data they touch and the systems they reach, concentrate effort on the critical tier, and put the obligations in the contract before signature. A right to audit. A breach notification clause, which in the West case is the difference between a customer learning what happened and learning nothing. Then continuous monitoring rather than a one-time onboarding review, and a real off-boarding process that actually removes access when the relationship ends.

Recon at machine speed

On AI, Mikkili offers a domestic illustration. He told his eleven-year-old son to stop watching YouTube shorts and go build something with Claude. The boy built a fitness tracker app. “If an 11-year-old can actually do this, what can an attacker do with AI?”

His answer is that AI collapses reconnaissance. Studying a company, mapping its architecture, identifying its partners and people, work that consumed weeks or months, now happens far faster and well. Worse, the economics invert. “The cost of failure is also so low,” he says, so an attacker can iterate endlessly, and every failure trains the agent doing it.

Herold Li’s addition is one most AI users have not considered: the systems are learning from millions of people at once, and privilege is not preserved. “You’ve waived it if you put it in AI to be clear.”

Why anonymized data is the point

The conversation turns to China, the BIOSECURE Act, and the COINS Act. Herold Li, who worked through the Act’s deal-structuring mechanics in her first appearance on Open Door Salon, corrects a common political misread. BIOSECURE is not a recent partisan measure. It began as a bipartisan, Biden-era effort out of a security intelligence briefing, and it works by removing a carrot rather than adding a stick: deal with a company of concern and government business closes to you.

Then comes the observation that reframes a decade of privacy practice. Companies believe anonymizing patient data discharges the risk. It discharges the individual risk. “It’s actually that anonymized large data set, which is what the government is worried about,” she says. Speaking as an epidemiologist, she notes that population-level data is precisely what is analytically valuable, and it is precisely what a state actor wants. Current rules protect the person. Nothing protects the population.

The four sentences nobody read

Asked to name the single biggest challenge facing CEOs and CIOs, Herold Li chooses data ownership.

Collaborations generate new data, and unless the contract was written in the last two or three years, it likely says almost nothing about who owns that data or what either party may do with it. She describes the provision as something buried deep in a joint development agreement that an IP lawyer had seven minutes to review the night before signing.

“No one realizes that that little four sentence vulnerability exists and they’re just not paying attention to it until it’s too late,” she says. “Prevention is worth more than the cure really here because there is no cure. There’s no cure once that data is leaked. It’s been put into another AI model. It’s out there in the world. There’s no getting it back.”

It's not a size thing. It's a technology thing.
Anne Elise Herold Li, Managing Partner, New York, Brownstein Hyatt Farber Schreck

Key takeaways

  1. Nation states want the roadmap, not the ransom. They are after where the science is going, where the company is vulnerable, and which partners they can pivot through.
  2. Small biotechs are the bigger prize. They do the innovative pivot and the newest R&D, which makes them the R&D lab a state actor wants to leapfrog through.
  3. Paper is not hackable. For unpatented protocols, benchtop science, and manufacturing know-how, Herold Li counsels keeping it off the network.
  4. West Pharmaceutical was the missed alarm. The exposed tier is the one below the self-identified innovators, and it is a shared third party to much of the industry.
  5. The audit goes to the roots. Companies already certify no forced labor to the bottom of the chain. That infrastructure has not been pointed at cybersecurity.
  6. Contract first, monitoring always. Right to audit and breach notification before signature, continuous monitoring after, and a real off-boarding process at the end.
  7. AI collapsed the recon phase. What took months compresses to days, failure costs the attacker almost nothing, and every failure trains the agent.
  8. Anonymized does not mean safe. Population-level data is exactly what a state actor wants, and current rules protect the individual rather than the population.

Key Questions, Answered

What do nation states target in a biotech?
They're not just after a company's database, but they're looking at a full roadmap for an organization.

Mikkili distinguishes nation-state actors from ordinary threat actors: the goal is the company's direction, not a ransom.

Why are small biotechs a bigger target than big pharma?
the smaller companies are doing sort of the innovative pivot, the new R&D, the latest technology, and big companies are shopping them for that

Herold Li reframes target selection around technology rather than company size.

How do you protect trade secrets that are not patented?
paper is safe and not hackable

For unpatented crown jewels, Herold Li now counsels keeping the material off the network entirely.

What did the West Pharmaceutical breach reveal?
the West Pharmaceutical cybersecurity breach should be a wake up call for the industry

The exposed tier is the one below the self-identified innovators, which already holds most of what it takes to reach market.

How far down the supply chain do you have to audit?
This is a full level audit down to the roots.

Companies already certify no forced labor to the bottom of the chain; that same infrastructure has not been pointed at cybersecurity.

What should a vendor contract require?
have the right to audit so that you can go back and then review and examine certain processes

Mikkili's contract floor: right to audit, breach notification, and obligations agreed before signature.

Is vendor risk a one-time review?
It's not a one-time exercise, but a continuous monitoring because things change, landscapes change, systems change, people change.

Onboarding review is not a program. Monitoring runs continuously and off-boarding must actually remove access.

How is AI changing attack reconnaissance?
If an 11-year-old can actually do this, what can an attacker do with AI?

Recon that consumed weeks or months now compresses dramatically, and failure costs the attacker almost nothing.

Is the BIOSECURE Act an anti-China measure from one administration?
this was a Biden era effort and it was a bipartisan effort

Herold Li corrects the common political misread and explains the mechanism: removing access to government business.

Who owns the data in a collaboration agreement?
they have very little contractual language about who owns the data and who owns what rights to do what with the different data sets

Contracts written more than two or three years ago rarely address ownership of the data a collaboration generates.

Resources

The Briefing

Need the life-sciences signal but short on time?

Get the free quarterly briefing: every guest from the quarter, in one sitting. What decides whether a therapy reaches a patient, gets funded, and can be trusted.