The federal government employs 1.8 million people and spends $90 billion on information technology products and services. John Gilroy sits down once a week to look at how companies solve complicated technology problems for the federal government. This is the only podcast that gives you ideas on reducing cost and improving quality for that massive expenditure.

In the summer of 2026, the SAS Innovate Tour arrived in Washington, DC, at Convene Hamilton Square. 50 years have gone by since SAS launched a contract from the Department of Agriculture just down the street. It seemed appropriate to sit down with Stu Bradley, VP, Fraud, Risk & Compliance, SAS, to discuss how SAS delivers trusted AI for the federal government. In a recent interview, Kim Brand from CMS stated they disburse one billion dollars a day in claims. If you have just a 1% fraud rate, that means $10 million a day of waste. Today, we asked how SAS can help. The discussion focused on the importance of robust fraud prevention in government programs, emphasizing the need for efficient data ingestion and decision-making. SaaS has a 50-year record of regulating $300 billion in transactions and saving $500 million in fraud. The conversation highlighted the significance of governance in AI, with organizations that prioritize trustworthy innovation generating 60% higher returns on AI initiatives. During the interview, Bradley details the importance of preventing fraud. Today, federal organizations should be asking "What do I need to do to be ready for whatever comes next?" The cost for a typical "pay and chase" approach is high, and the results are paltry. The speakers also discussed the critical role of data integration and real-time analysis in preventing fraud, noting that 5% of payments involve fraud. The importance of partnerships between federal and state agencies to combat fraud was also underscored.

In the summer of 2026, the SAS Innovate Tour arrived in Washington, DC, at Convene Hamilton Square. 50 years have gone by since SAS launched with a contract from the Department of Agriculture just down the street. It seemed appropriate to sit down with Caroline Baldwin, the Director, SAS Federal, to discuss how SAS delivers trusted AI for the federal government. Everybody reading this has seen reports of AI giving hallucinations. It is one thing to have a bad response for a doughnut company in Chicago; quite another to have the Department of War base decisions on bad data. Caroline Baldwin brings a refreshing splash of reality to the talk of applied AI to the federal government. Instead of evaluating the nuances of AI harnessing, she makes a blunt statement, "If government can't apply AI to outcomes for an agency or improve American lives, it's just a science project." Finally, we have a practical opinion. SAS has been working with sensitive federal data for fifty years and has the experience to ingest accurate data and use it to produce practical results for federal agencies. We have heard of the "black box" of AI. Don't ask for sources. In Baldwin's experience, an AI system must be able to produce sources for decisions that will be held up in court. During the interview, she mentioned that SAS can leverage synthetic data to produce more accurate models. She also describes how SAS partners with federal agencies to solve complex problems, adapt commercial innovations, and accelerate adoption. As AI evolves, agencies must balance enterprise strategies with mission-level needs while continuously updating models and maintaining trust.

Everyone has read about how much productivity AI can have for federal applications. That allure can lead you into a situation where you may not be as prudent as you should be. Today, we sat down with Jamie Holcomb, COO of Electrosoft, and Steve Riley, VP and Field CTO of Netskope, to better understand how to balance the promise of AIAI with practical application in the federal government. Steve Riley has looked at federal technology projects, and he thinks that the government must get out of their pilots and into operations, measuring results and impact that is meaningful to the taxpayer. They highlight the rapid advancements in AI, noting that government agencies struggle to keep pace with commercial innovation. Riley thinks agents are great for gathering, assimilating, and assessing information. It is probably not time for them to have independent agency. A survey reveals that 78% of federal leaders believe AI tools should be managed like users or devices within zero trust frameworks. Only 31% of federal IT leaders have high visibility into public AI tools. Because of Jamie Holcomb's experience at the United States Patent and Trademark Office, he thinks success comes down to action, not architecture. From his view, agencies need timely intelligence connected directly to operational decisions. The conversation emphasizes the need for federal agencies to balance innovation with security, particularly in predictive AI and zero trust strategies, and to prioritize AI discovery and integration.

For decades, software was "bespoke." Each application was carefully crafted to solve a specific problem. When this was applied to the federal government, they discovered that this process was slow and unpredictable. The solution: a software factory. From custom-built software to software that could be created in an organization that had a "bubble" that could standardize on federal security guidelines. From there, they could deliver safer, higher-quality software much faster. Today, we sit down with Jorge Lopez, Vice President of Security Operations and Trust and Safety at GitLab, to discuss the concept of software factories in the federal government. Lopez admits the importance of visibility, collaboration, and compliance in these factories. However, during the interview, he notes that gaps in DevSecOps often stem from organizational issues, such as miscommunication between security and development teams. He emphasizes the need for proper monitoring, incident response, and managing secrets to mitigate risks. Digging deeper, he states that if a federal organization does not have monitoring in place, they will only discover a problem after it happens. One approach is to go to the people responsible for defending the software. Lopez has seen success when security operations teams and software factory teams talk to each other. Lopes also discusses the impact of AI on code production and the importance of proactive measures to ensure software factory security.

Today, we sat down with Rajan Venkatachalam from Icertis to discuss the evolution of federal contract lifecycle management. The main takeaway is that contract management is becoming harder to ignore, even though many organizations still overlook it. Perhaps it is too difficult; perhaps changing management with compliance is too complex. Rajan begins the interview by putting AI into perspective. He coins a great phrase when he states that AI has gone from "Buzzword to Backbone." In other words, the value of AI is so clear that it should be applied across all aspects of running a federal agency. If you are asking for specifics, he gives them. Rajan states that agencies, contractors, and Icertis have seen up to 40% faster proposal-to-award cycles. Icertis has been in the contract management world since 2009. Building on that experience, they have honed their commercial skills to the point where they can examine every sentence in a contract to assess its limitations and strengths. If you sell to the federal government, Icertis can monitor rapid changes in compliance requirements and ensure your offering stays current. They highlight the shift from paper-based to automated and digital processes, driven by AI and compliance frameworks like FAR, DFAR, and CMMC. Finally, Rajan sees the future as autonomous contracting. He can see a future where a solicitation is reviewed and a proposal is generated. This increase in speed allows humans to review the process before submittal. This points to faster, more predictable, and compliant-friendly contracting, which is crucial for agencies under pressure to deliver quickly.

IT modernization carries unanticipated risks. Take operational technology, or OT, as an example. As modernization has increased the number of OT and IoT assets across many federal locations, it has also introduced new vulnerabilities. Federal leaders are warning that the situation has reached a tipping point. CISA maintains a growing list of vulnerabilities, and the NSA has issued warnings about OT and IoT risks. A recent SANS report indicated a 20% increase in confirmed OT attacks. To explore these challenges, we sit down with Chris Grove, Director of Cybersecurity Strategy at Nozomi Networks, to discuss the cyber-physical security challenges facing the federal government, particularly the modernization of older OT systems. He highlighted the difficulties in maintaining asset inventories, the impact of AI in both attacks and defenses, and the complexities of implementing zero trust in OT environments. During the interview, Grove addresses topics such as remote access, older technology not designed for updates, and OT devices that move around on ships and planes. Thirty years ago, "unified communication" was introduced by technology like VoIP. With the proliferation of OT devices, Grove recommends a unified security architecture. Grove emphasized the importance of resilience and the need for AI-enhanced tools to manage alerts and anomalies effectively. He also noted growing concerns about drone security and the significant workload expected to result from AI-discovered vulnerabilities.

Taylor Johnston, President of the Institute of Applied Engineering at the University of South Florida, discussed a secure research environment developed with AWS and the federal government. This initiative allows researchers to work with classified information, progressing from unclassified to top-secret levels. The partnership uses AWS GovCloud for multi-domain, multi-accessible research. Many organizations train models on unclassified data, but classified data has different nuances. Analysts need to build that model in IL6 using those data sets. Johnston highlighted the university's proximity to key military commands and its results-based research, emphasizing the importance of human performance and AI in military applications. During the interview, Johnston observed that AI is an enabler for productivity, not a job stealer. The university aims to bridge gaps among academia, the defense industrial base, and venture capital, helping enhance operational capabilities.

At one time, reacting to a cyber threat was enough; signatures and blocklists could cope. But AI is now amplifying every aspect of cyberwarfare, including speed and scope, leaving these traditional defenses in the dust. Today's threats can be numerous and personalized, making old approaches worthless. Patricia Titus, Chief Information Security Officer at Abnormal AI, discussed the challenges of transitioning from legacy to modern AI-driven security architectures at the AWS Public Sector Show. During the interview, she advised focusing on asset visibility, decision-making platforms, and non-human identities to enhance cybersecurity. So many federal organizations are deploying tools that it is difficult to get a baseline or inventory of what is on a system. Titus recommends starting with an accurate inventory to establish a "normal" baseline and detect abnormalities. She also stressed the necessity of modernizing security architecture in parallel with cloud migration and the dangers of relying on outdated tools.

The Department of War realized it was dealing with a supply chain risk of vulnerable vendors; back in 2019 they launched the Cybersecurity Maturity Model Certification. The goal was to ensure defense contractors protected sensitive unclassified information. Over the years it has transitioned from being a "checkbox" compliance to moving way beyond the minimum to pass. During today's interview with Travis Goldbach from Coalfire Federal, he gives us overview of how CMMC has made the transition to building a security program that protects the mission, supports growth, and earns trust. Goldbach continue by stating the cybersecurity is going to impact just about everybody – from sales, to legal, to operations, to finance and even executive leadership. Travis highlights the importance of CMMC for acquisition, noting that many defense contractors are unprepared. CMMC 2.0, implemented in November 2025, simplified the framework from five levels to three, focusing on basic cyber hygiene, CUI protection, and advanced protection. He also discusses the impact of remote work and AI on CMMC readiness and the importance of a robust ecosystem of trusted partners for sustained compliance. Rather than detailing the number of controls in the varying levels of CMMC, the discussion moved on to the concept of documentation. The challenge Goldbach sees is the conflation of documentation with readiness. More must be added to documentation to make it viable. For example, companies need ownership, governance, and accountability in a repeatable process.

In this episode of the Federal Tech Podcast, Robert Salvia of Fortress Information Security explains why agencies must move beyond a compliance mindset and adopt continuous risk management. One key insight stands out: "It's not what you find, it's what you fix," showing that mission impact should guide vulnerability priorities rather than compliance boxes. One insightful observation Salvia makes concerns observability. Many companies pride themselves on being able to see network details, including potentially unknown vulnerabilities. Salvia says the ability to find is important, but the ability to fix that problem is more valuable. He suggests that AI can assist in that endeavor, but it is a force multiplier, not an answer to everything. His main theme is to move from compliance to continuous risk management. Salvia explores the complexities of supply chain risk management (SCRM), emphasizing the need for comprehensive, enterprise-level solutions that address both hardware and software vulnerabilities. Salvia highlights the importance of collaboration, continuous monitoring, and adapting to new threats and regulations. He also discusses the role of AI, such as Mythos, in increasing the scale of vulnerability detection and the necessity of integrating AI with human expertise for effective risk management and remediation.

In this episode of the Federal Tech Podcast, John Gilroy interviews Justin Fessler, Vice President of Public Sector at LogicMonitor, about the growing role of autonomous AI and observability in federal government IT operations. Fessler explains that autonomous AI is not about replacing people but about automating repetitive operational tasks, correlating complex system events, and helping IT teams make faster, better-informed decisions. Rather than allowing AI to operate without oversight, LogicMonitor focuses on keeping humans "in the loop" while AI handles time-consuming analysis and routine remediation. A central theme is the importance of complete visibility across increasingly complex federal environments. LogicMonitor's agentless monitoring technology discovers devices, cloud resources, applications, and shadow IT without requiring software agents on every endpoint. This broad visibility enables agencies to identify unmanaged assets, reduce blind spots, optimize cloud costs, and strengthen security. The discussion also highlights observability's critical role in Zero Trust. Fessler notes that agencies cannot secure or verify assets they cannot see. By discovering everything connected to the network—including servers, cloud services, IoT devices, cameras, badge readers, and physical infrastructure—LogicMonitor helps agencies build a stronger Zero Trust foundation. Gilroy and Fessler examine the challenges of managing hybrid and multi-cloud environments, emphasizing that agencies require a single operational view regardless of where workloads reside. LogicMonitor integrates information across cloud providers and third-party platforms, including ServiceNow, Splunk, Dynatrace, Datadog, and IBM Watsonx, enabling AI-driven event correlation and faster incident response. The conversation concludes with the future of autonomous IT. Fessler predicts increased automation, AI-assisted self-healing infrastructure, and significantly reduced mean time to identify and resolve incidents. Rather than replacing IT professionals, autonomous AI will eliminate repetitive work, allowing skilled personnel to focus on higher-value mission objectives while improving operational resilience, reducing alert fatigue, and delivering better digital services to citizens. For more information, visit www.logicmonitor.com/solutions/federal-government.

Craig Bowman, Senior Vice President at Trellix, discussed Trellix's project to secure Ukraine's cyber environment against nation-state attacks, highlighting the rapid evolution of attack vectors from Ukraine to the U.S. He emphasized the importance of AI in cybersecurity, noting Trellix's use of AI to autonomously mitigate attacks, as seen during the 2025 cyber espionage campaign. Bowman also explained Trellix's detonation chamber technology, which isolates and analyzes threats without affecting live data, and its Agentic AI, which operates on-premises without data movement to provide real-time cybersecurity insights. Ukraine has become the world's most concentrated cyber battlefield, giving security teams unprecedented visibility into emerging attack techniques. In this interview, Trellix's Craig Bowman revealed that attack patterns once took six months to reach the U.S. after appearing in Ukraine—today, that gap can be as short as six seconds —highlighting why AI-powered cyber defense is becoming essential for federal agencies. It is essential because a human simply cannot fight an autonomous machine by clicking through alerts. It is time to use AI to fight AI.

Today, we examine the strategy for filling technology roles in the federal government. Everyone reading this sentence knows that the federal government is competing with commercial organizations for tech talent. Combining that with an arduous federal hiring process, a reduced budget, and a drastic increase in cyberattacks heightens this concern. We sat down with Nav Singh, the Chief Marketing Officer at Eightfold.ai, to discuss the company's mission to match job candidates with roles based on skills. For example, Eightfold has analyzed 1.6 million skills and 1.6 billion career trajectories, enabling it to identify and upskill employees for roles like cybersecurity. Singh emphasizes the importance of reducing bias in hiring and leveraging AI to discover hidden talents within organizations. During the interview, he reviews the idea of training people who you already have on staff for cybersecurity positions. It is possible to assess talent and identify which candidates can make this transition. This "hidden talent" theme makes even more sense for the federal government. One may need a specific kind of security clearance. It may be easier to assign an existing employee with that clearance and train them rather than go through the whole vetting process again. Singh also mentions introducing an AI interviewer to enhance hiring consistency and efficiency. He states that the future workforce will be a combination of humans and agents. This is a scenario in which agents perform repeatable tasks, while humans set the strategy and exercise judgment.

John Gilroy and Josh Wilson, CEO of LMI, discussed the shift from traditional defense technology development cycles to rapid deployment, emphasizing the need for integrated hardware-software systems. For decades, the military would assemble detailed requirements, solicit bids, select a winner, and wait years for the contract to be completed. This approach can work with some hardware systems, but today's combat requires maximum flexibility and adaptability. This approach prompts the question of whether a company is judged by how perfect its product is on day one. What about day two? What about the pace? Can they figure it out based on what they learn? Wilson suggests a more flexible approach in which a combat system is proposed, evaluated quickly, defects are identified and replaced, and the system is then reassessed. He highlights LMI's approach, which combines software, hardware, services, data, and AI to deliver outcomes, citing examples like asset management in shipyards and the He stresses the importance of trust, earned through demonstrable solutions, and the cultural shift towards outcomes over ownership and the SHPRD program. Wilson also notes the success of the Ivy Sting exercises, which prioritize user feedback, and the potential for scaling rapid development models across the Army and other federal agencies. You can read the press release here: https://www.lmisolutions.com/press-release/anduril-partners-with-lmi-to-generate-battlefield-technology-for-the-u-s-army

Finding a needle in a haystack would seem like a minor endeavor compared to what today's federal systems managers must face. Let's take a stab at a correct farmyard analogy – the haystacks double in size every day and are moving. That sounds like an exaggeration, but recent reports show that nine million zero-day exploits are released every day. AI is putting malicious actors on steroids. Chris Townsend, Global Vice President of Public Sector at Elastic, discussed the company's role in federal cybersecurity and data management. His argument is, essentially, that cybersecurity is a data problem. If threats are viewed from that perspective, the more data you can bring into your security environment, the more effective you are at defending it. Elastic enables security operations analysts who are responsible for detecting threats to keep up with today's tlandscape and cyber-attack velocity. Elastic's platform and tools can reduce false positives and help federal security operations centers (SOCs) prioritize valid threats. Townsend highlighted Elastic's agentic AI tools, which help SOC operators prioritize and remediate threats, reducing mean time to detect and respond. Elastic's partnership with CISA for a managed Security Information and Event Management (SIEM) as-a- service was also mentioned, emphasizing the importance of standardizing data for effective AI-driven cybersecurity. Townsend goes on to articulate Elastic's launch of a SIEM-as-a-Service offering for federal civilian agencies, featuring Elastic Security on Elastic Cloud. SIEMaaS delivers a cloud-based platform for next-generation, AI-powered threat analytics, incident response, and open-standards-based cybersecurity data ingestion. Here is a link to Chris' blog describing CISA's SIEMaaS offering and how it supports federal agencies' cybersecurity posture while reducing costs

John Gilroy hosts Dennis Woo, Director of Federal Sales at Kong, to discuss the rise of API management in federal security. API management has been a slowly growing concern for the past decade. Cloud adoption has driven API adoption; now we see cheap storage and AI systems making many API connections. Voilà, API security is now a topic for federal security leaders. During the interview, Dennis Woo discusses the origin of Kong and brings up topics of major concern for cybersecurity: The perimeter is disappearing. Before the cloud, a perimeter might have been the walls of a data center. APIs caused that to increase dramatically. Today, we see agents talking to APIs, APIs talking to models, and models consuming MCP tools. Woo remarks that the last thing a federal agency wants is token consumption at enterprise scale. Kong offers an API and AI management tool to ensure compliance, avoid vendor lock-in, and reduce cost. If we fast-forward five years, Woo predicts systems that are semantically aware, systems that can understand intent and detail, and systems that can manage risk. This can extend to semantic guardrails, semantic compression, and even token management. Listen to the podcast to understand how to manage an AI environment that can get out of control

Today, we sat down with Snehal Attani from Horizon3.ai to discuss the impact of large language models (LLMs) like Mythos on federal cybersecurity. He makes a range of startling statements. First, he admits that AI tools like Mythos can find bugs in code. In fact, he claims that the effort to find it may drop to zero. He also warns of the potential for AI-generated exploits to overwhelm security operations centers. Attani predicts a surge in vulnerabilities, what some call a Vulnpocalypse, and stresses the importance of prioritizing remediation and building muscle memory for incident response. However, that does not mean the effort to exploit the vulnerability is also zero. Knowing vulnerability does not guarantee a successful attack. Second, this new information can overwhelm a system administrator. His call to prioritization can yield effectiveness. He makes statements like, "The hardest part of the job is deciding what not to fix." Finally, in a twist on the cybersecurity business, Attani admits that the attacker will get in. The best perspective is to see yourself as in the business of blast radius management. Attani advocates focusing on core cybersecurity fundamentals and cautions against chasing headlines to avoid organizational distraction. Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Everyone seems to have an opinion on AI. Today, we interviewed Levi Gundert, the Chief Security and Intelligence Officer for Recorded Future. He thinks that AI gives federal leaders an opportunity to fight back. For example, one aspect of cybersecurity is velocity; the number of attacks has expanded exponentially. Gundert thinks this is an opportunity to match this attack's velocity. Many will balk at this opinion. They will describe federal data as challenged in cross-domain sharing, data labeling, and data trapped in PDFs or legacy systems. During the interview, in a refreshing observation, Gundert observes that defenders have always been on the back foot. Always in defense. Finally, AI can give tools that level the playing field. One application of AI is the ingestion of the data provided to federal systems. AI can be used to provide actionable intelligence. In some systems, this deluge can result in false alerts. When used properly, AI can filter through the signal and identify what is critical. Gundert emphasizes the need for automation and decision advantages in threat intelligence, the challenges of data fragmentation and legacy systems, and the urgency of upgrading systems to address vulnerabilities. They also touch on the role of AI in insider threats, the potential of Mythos to increase vulnerabilities, and the importance of sharing threat information to enhance cybersecurity.

Ep. 322 Mattermost Secures Mission Critical Federal Collaboration Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com The federal government has an unbelievably wide network. We all know about the IRS citizen-facing websites. We log in from our homes, the server is in the cloud somewhere, and we file our taxes. At the other end of the spectrum is the military and intelligence community. The military talks about a "contested" environment. This can be in Low Earth Orbit or can be underwater in a submarine. There are no simple connections in that world. Yet users demand security in a world constantly under attack and disconnected. Resilience means they must not lose packets of information. Also, just to make it interesting, this can be a life-or-death situation. Into this demanding world steps Corey Hulen, founder and CTO of Mattermost. Their mission is to provide collaboration software designed for high-trust, high-risk environments, including even air-gapped network components. The software emphasizes resilience in contested environments, ensuring collaboration continues even when network connections are lost. Hulin highlights the importance of both security and compliance, noting the challenges of meeting multiple regulatory standards. He also addresses the need for AI to support human decision-making in mission-critical scenarios, ensuring quick, informed responses.

https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com Today we sit down with an HR company, Workday, to see if it can transfer the success it has had in the commercial world into helping federal agencies reach ambitious goals. Matthew Cornelius works for Workday, but he has spent mor than a decade working in a wider variety of federal agencies. The interview covers topics like the shift towards skills-based hiring, the challenges of outdated HR systems, and the need for comprehensive workforce data. One concern is that the applicant can report skills. One candidate's Python experience may differ greatly from another's. Presidential administrations have encouraged the concept of skills-based hiring. However, this is a subject that is difficult to implement. For example, it can clash with the standard GSA classification system. Today's AI skills are changing so rapidly, it would be almost impossible for an HR person to understand what skill sets are important. Cornelius has firsthand experience in federal HR systems that are dated. He references using Excel spreadsheets that can have issues with version control and backup. One great place to start is to use a system than can give an HR manager a "birds eye" view of the skills of their current employees. He emphasizes the importance of communication, empathy, and leveraging modern HR technology to improve federal HR processes and outcomes.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com Two of the least well-known, but most important acronyms in federal technology are ITSM and ITOM. IT Service Management focuses on services and user experience, while IT Operations Management focuses on technical performance and monitoring. These two concepts are the backbone for maintaining the massive federal IT systems we see everywhere. Today, we sat down with Seth Gardner from BMC Helix, who details how BMC Helix can provide insights for service management. He starts with the importance of visibility and generating clean, reusable data for AI. Gardner maintains AI is only as good as the data behind it—and most federal agencies are still "re-wrangling" fragmented systems. In this episode, BMC Helix explains how correlating incidents across 12+ tools can pinpoint root cause and dramatically reduce mean time to resolution. He also touches on the importance of data sovereignty and security in multi-tenant environments. The conversation concludes with Seth outlining BMC Helix's differentiator in adapting to rapid technological changes.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com Angel Smith, President of Global Public Sector at Virtru, discussed the challenges of data interoperability in federal agencies, emphasizing that trust and policy issues often hinder data sharing more than technology. It took several years, but the federal government has realized that its defenses are not perfect and has had to adopt a zero-trust approach to limit access to important information. Zero Trust is Missing the Point During the interview, Angel Smith argues that Zero Trust seems to focus on the network and identity, rather than on data. While intended to secure infrastructure, these changes can create new attack vectors. Data Sovereignty is broken. Traditionally, a data set would reside in a hard drive in a server room down the hall. Because of this, thinking about security can be focused on the physical location of the data or its sovereignty. Sometimes, a strategic approach is necessary to protect data. This is an outdated approach because data can be protected by the data object itself, which can carry control. Security vs. Speed is a False Tradeoff. This legacy thinking also applies to security. Some will exist to control data because it has been viewed as too time-consuming. Smith also stressed the need for modern data governance to enable AI and other advanced technologies, advocating for a rethinking of legacy practices to enhance data security and usability without compromising mission speed.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com There is a popular podcast in the Washington, D.C. area called "Feds at the Edge." The title alone acknowledges the importance of edge devices for the sprawling federal government. Today, we sat down with Tommy Gardner from HP to discuss the challenges of securing millions of endpoints in the federal government, including legacy systems and operational technology (OT). When it comes to OT, Gardner makes a shocking observation: if you take an endpoint, like a sensor in a boiler, and it gets compromised, it could shut down the refinery, and people could get hurt. That is why HP has developed a system called the Workforce Experience Platform (WXP), which manages diverse devices and applies updates remotely. One little-known fact Gardner brings up is that, when malicious actors assess vulnerabilities, the easiest way to get into a network is through the printer. In fact, HP now offers printers with defenses against post-quantum encryption. Given that a company like HP has thousands of products, the supply chain is a major consideration. During the interview, Gardner mentions that HP has over 10,000 vendors in its supply chain. He addresses the complexities of supply chain security, emphasizing the need for rigorous vendor verification and compliance with the Trade Act. He concludes by advocating for AI at the edge for real-time decision-making and cost efficiency.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com The Veterans Administration is a system with nine million enrolled veterans across 1,300 facilities. In a system like that, downtime is not an option. Today, we look at how a company successfully reduced documentation time, increasing adoption in one part of this massive system. We sat down with Nilanjan Sengupta from Thoughtworks to learn which methods proved successful. He began by stating the focus must not be on bits and bytes, but on mission outcomes. For example, for years, clinicians spent 10–20 minutes per patient on documentation, often taking 2 or more hours to leave their shift. Sengupta highlights a successful pilot of AI ambient scribe technology at the VA to address this issue. It was so successful that it achieved an 86% adoption rate among primary care providers. During the interview, Sengupta outlined topics such as the importance of data governance, trust infrastructure, and a responsible AI strategy. He emphasized the need for a well-governed data discovery process and a cultural shift towards treating data as a mission-critical product.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com Interest in technology comes in waves. Back in 2022, managing the supply chain became number one on the list of priorities for federal technology leaders. Since then, we have seen a huge cycle of AI dominating the federal government's attention span. This shift in focus may be causing you to overlook other critical supply chain concerns. Today, we sat down with Bob Kolasky from Exiger. His company got its start by helping the Department of Justice monitor HSBC, a large financial management company. That led to a successful reputation, prompting other federal agencies to ask for their help. During today's interview, Kolasky gives an overview of due diligence, continuous monitoring, and risk management. He argues that AI-driven supply chain insights reveal hidden risks, fraud, and vulnerabilities that impact federal agencies and contractors. With attacks occurring so rapidly, Kolaksy expands on the application of continuous monitoring across the entire supply chain. He uses the term "illuminate" to describe the technology Exiger offers that can carefully examine all aspects of the supply chain. Exiger's technology is so advanced that it can look at unstructured data, sanctions lists, adverse media, ownership records, and trade data. With that amount of information, systems must be put in place to ferret out abnormalities and prepare for the next wave of supply chain attacks. = = =

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com Sending deceptive email has been around for decades. It has gone from a Nigerian prince asking for financial assistance to 10,000 people. Today, phishing isn't 'spray and pray' anymore—AI is creating hyper-personalized emails that look exactly like someone you trust. Today, we sat down with Patricia Titus from Abnormal AI to learn how the correct response to an enhanced AI phishing attack. Some may shock you. Voices are being emulated, hyper personalized threats are being developed, and threat actors are using AI faster than humans can respond. This deception is getting increasingly difficult to defend. One approach that Patricia Titus recommends is to start off being AI-native and using behavioral techniques to defeat the massed attacks. During the interview, Patricia Titus explains that the Abnormal AI system will look at normal behavior over 15-30 days and flags anomalies. Abnormal AI partners with major SaaS providers and offers a free 30-day proof of value. The technology aims to reduce alert fatigue and operational drag, enhancing cybersecurity efficiency.

If you go to Google Trends and type in API threats, you get a classic hockey stick. This is probably caused by the proliferation of connectors to cloud solutions paired with the popularity of AI. Today, we sat down with Brian Dennis from Akamai to talk about the problem this can present to federal systems. He begins by telling the audience that API attacks have increased by over 1,200 percent, reflecting the Google data. The shock is that many organizations, federal included, do not even know how many API's they actually have. There may be APIs that were designed in earlier systems; there could have been APIs designed, used, and now dormant. Worse, it is possible that individuals have launched independent systems, called Shadow APIs, which can present unimagined vulnerabilities. The fact is malicious actors know this is a current vulnerability. It is a matter of knowing what to do when you get attacked. During the interview, Brian Dennis makes some suggestions that can help overcome some of these challenges. Microsegemetation will allow any breach to be blocked off. Traditionally, microsegmentation has been a time-consuming task but today's AI can make it a trivial concern. Akamai has recently merged with a company called Guardicore that can provide enhanced network visibility. Today, developers are grabbing code off the shelf and plugging it in. There may be insecurities in this approach. Dennis explains how Akamai's No Name can help identify and secure APIs at the code level, enabling operational security from development to runtime. Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com

This is an interview at the Salesforce Agentforce World Tour in Washington, D.C., held on March 29, 2026, at the Washington Convention Center. Mia Jordan was the federal CIO twice and brings a unique view to the discussion of challenges and solutions around federal technology. She sat down with Federal Tech Podcast at the Salesforce Agentforce World Tour to give her thoughts on AI and innovation in the federal government. Jordan notes the federal government has used AI for a decade, but now faces pressure to move rapidly from concept to production. Although there is a sense of urgency from federal leaders, Jordan cautions that a human being should be in the loop when deploying AI. One way to accomplish this goal is to use tools that assist with it. One example she uses is the Salesforce tool Einstein Next Best Action. It can look at a workflow and make suggestions for a human to select. Jordan also addressed how the Informatica acquisition lets agencies track data lineage—who created it, when, and how it is used—so they can defend decisions during audits. touches on the role of low-code tools in automation and the need for reimagining workflows. Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com

Today, we sat down with Paul Tatum, Executive Vice President, Global Public Sector at Salesforce, to hear how Salesforce can help federal agencies reach ambitious goals with Agentic AI. By now, everyone has played around with AI, and possibly some agents. Viewed independently, they can dazzle. Unfortunately, the federal government expects action based on data. If you isolate Agentic AI, you can fall into the trap of lacking the ability to scale, ensure security, and maintain control. In those several weeks, notable technology leaders have jumped headfirst into some agentic offerings from new vendors. What is not reported is that many have jumped back out because of privacy concerns. Salesforce can serve as the "adult in the room," enabling federal leaders to leverage agentic technology in a secure and compliant manner. The good news: agents can connect just about everything. The bad news: agents can connect with everything. In the federal government, one needs trusted, mission-specific data through controlled interfaces. During the interview, Paul provides insight into innovation and security while using Agentic AI in a federal environment. He envisioned future AI evolving from reactive to initiative-taking and personalized, potentially becoming a concierge for citizens. Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com

Today, we sat down with Charles Fiery from Excella to discuss the complexities of improving federal agency processes. He shared insights on the challenges of process discovery, change management, and data transformation. It is always difficult to assess a large enterprise, whether public or private, to determine how to improve complex processes. One approach is to look at duplicative systems; the federal government provides a notable example. The federal government has evolved into new agencies over the years. Because of technical and legal challenges, they have mostly remained siloed. As a result, we have human resource systems that do remarkably similar tasks. A consolidation effort would reduce costs, improve speed, and assist in interagency collaboration. The OMB mandate requires agencies to integrate core HR functions while maintaining ancillary services like payroll and benefits. The transition involves mapping current systems, identifying essential functions, and ensuring data compliance. Current systems need to ensure the data they provide is accurate and error-free. Each agency has unique data, and structuring that data is important. Visibility into system components is much more difficult. Connectors and integration are complicated by shadow IT and AI. Charles Fiery concludes that although the transition is challenging, completing the necessary groundwork will lead to stable and compliant improvements in federal HR systems. Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com

In the 1990's, the World Wide Web was so popular that it was facetiously called the Worldwide Wait. Centralized servers handled a small workload but bogged down as volumes increased. As a result, Content Delivery Services sprang up to distribute the workload worldwide. By 2001, large news organizations could manage unpredictable increases in traffic. The past decade saw a drastic increase in traffic and threats to it. During the interview, Omeed Nosarti describes how companies like Fastly began offering proprietary methods to deliver content faster. Nasrati highlights Fastly's proprietary technologies, such as Smart Parse, which reduces false positives in web application firewalls (WAFs), and its network architecture optimized for low latency and high cache hit ratios. Included in this conversation is the appearance of many remote points on many federal networks. These can function by increasing the attack surface and including the possibility of attacking the Application Programming Interface (API). Nasrati also mentions Fastly's API security features, including schema enforcement and discovery, and its significant ROI in terms of infrastructure and human capital costs. Nasrati emphasizes the importance of real-time traffic analysis and the evolving nature of DDoS attacks. Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com

In 2026, we are seeing an increase in cyberattacks targeting defense contractors and defense production. Today, we met with Tim Miller, Field CTO at Dataminr, who explained how the company is helping the federal government address this growing threat. Traditionally, cyber threats could be classified as "Zero Day." Essentially, this meant an attack targeting a software or hardware vulnerability that was unknown to the public. They were effective because no security patch existed, and they could bypass defenses. AI has compressed this 24-hour window to minutes. If your opponent is speeding up attacks, then the defender must use similar tools to prevent a breach. Dataminr has developed something called "real-time intelligence." This concept can provide early warnings, help separate nuisance attacks from serious malware, and address today's workforce gap in cyber defense knowledge. During the interview, Miller noted that the company also launched a new product for cyber defense that integrates threat intelligence with internal data. It is called Dataminr for Cyber Defense and leverages AI and Agentic AI to neutralize threats. = = Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com

Today, we sat down with Trey Ford from Bugcrowd to talk about ethical hacking. One of the most memorable phrases from ancient Rome is Quis custodiet custodes? (Who Watches the Watchman?). This ancient admonition has direct application to federal cybersecurity. We know federal agencies spend millions of dollars to protect data. How does one ensure the contracted companies are doing their jobs? Traditionally, an organization would use penetration testers, contractors, or basic scanning methods. However, today's attack surfaces are expanding, and malicious actors are innovating so rapidly that we are being forced to consider more creative options. In other words, an annual penetration test against an AI-inspired attack is too focused to be effective. The innovation Bugcrowd brings to the table is a community of researchers who can attack a system from many perspectives. During the discussion, you will learn about federal vulnerability disclosure programs, how to overcome talent shortages, and how Bugcrown vets its research community. Trey Ford also touches on the FedRAMP journey, AI integration, and the evolving cybersecurity landscape, stressing the need for human creativity and dynamic responses to threats. Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com

The word "deplorable" signals something shockingly bad. Often used for the truly awful or dreadful, Todd Harbour, with decades of federal data experience, applies it specifically to data quality. That may be an overstatement, but the description certainly makes the point that today AI is based on fragmented, incomplete data sets. The bright, shiny thing called AI is so much in focus that federal leaders may not pause to ask what data is being used to train today's models. During the interview, Harbour acknowledges that nobody is seeking perfection here. He has coined the term "mission-ready" to describe the kind of data that should be used for decision-making in the federal government. This would indicate a serious attempt to include siloed and poorly structured data. In a fascinating digression, he refers to MIT's Project Iceberg. This initiative suggests that AI is only the "tip of the iceberg" of its economic impact. The majority are in the future and beneath the surface. If that is the case, the case for mission-ready data is even stronger. Harbour urges immediate initiative-taking measures to confront these challenges and proactively prepare for rapid AI-driven changes to cybersecurity and national defense. Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com When people look back on 2025 they will see many changes in the FedRAMP process. It looks like a new administration examined the process, got feedback from companies, and launched new initiatives to speed up the process. During today's interview, Irina Denisenko (Knox CEO) details FedRAMP's challenges and something called "FedRAMP 20x." Knox runs the largest FedRAMP-managed cloud, enabling 90-day authorizations by hosting customers' production environments. Denisenko explains the story of the origin of Knox Systems: she was running a training company and the Air Force wanted to use her product. It would have taken so long to complete the FedRAMP requirements that she just bought a company that was FedRAMP compliant. It is hard to believe that the process is so frustrating that fewer than 500 apps are authorized at moderate/high FedRAMP The initiative from the GSA is called FedRAMP 20x It shifts to continuous monitoring and continuous authorization, moving from annual audits (sampled every 3 years) and monthly CVE spreadsheets to real-time, machine-readable data. What Knox offers is a tried-and-true platform that has reduced time for compliance in order to better serve federal needs.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com Way back in 2011, one of the goals of FedRAMP was to eliminate software redundancy. The federal government had evolved to the point where one agency would spend millions of dollars on the same application program that the agency in the same zip code had just invested heavily in. The theory proposed by luminaries like Vivek Kundra was to move to the cloud to share services. Reducing cost and improving resilience. FedRAMP was the initiative that established a safe environment for federal cloud use. Companies can comply with regulations outlined in an Authorization to Operate (ATO). Well, fifteen years later, and we are seeing the same duplication not in the application programs, but in the process to get the ATO itself. For example, FedRAMP, RMF, and agency internal policies may require specific artifacts to satisfy one or the other. During the interview, Travis Howerton paints the legacy model—static documentation, annual/3-year audits, spreadsheets. His solution is to have AI assist with documentation, which will drastically reduce compliance time; he cites an example of reducing a process from 52 weeks to 356 weeks. RegScale uses OSCAL (XML/YAML/JSON) to auto-generate RMF artifacts and integrate with SIEMs (Splunk, Elastic), Axonius, ServiceNow, and APIs. Howerton understands the limitations of many automated systems and suggests that a human is a key component after the machine language has assembled the data to make the decision.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com Cybersecurity is a rapidly evolving field, where every effective defense technique is quickly noticed and adapted to by malicious actors. The real question is how fast each side of this ongoing cat-and-mouse game can respond. Let us take an example of web applications. In the decade-long slog of the cloud, federal users migrated to web-based applications protected by Web Application Firewalls (WAFs). firewalls. As that method matured, malicious observers noted that the Application Programming Interface (API) allowed these software programs to communicate and exchange data. Voila, another attack vector was born. During today's interview, Joe Henry from Akamai Technologies notes that 80% of their customers report API attacks. Henry details a curious term called "Broken-Object Level Authorization." In this attack, an application fails to check if a user is authorized to access specific data objects. The ID is manipulated, and the malicious actor gets access. Akamai's API Security performs behavioral analysis beyond WAFs, flags PII exposure, and supports a zero-trust posture. Software developers talk about a "shift left"; we apply that to the Akamai approach. They have a worldwide network of Points of Presence (POPs) and data centers where they can observe attacks as they develop. It is so strong that it provides fail-open resilience with a 100% SLA. Akamai provides a State of the Internet Report (quarterly). If you would like to stay connected with the next manifestation of attack, consider subscribing or visiting their website to stay informed about the latest trend

Twenty years ago, the concept of Bring Your Own Device (BYOD) entered the federal IT landscape with the advent of network-connected devices like Blackberries—sometimes even within secure federal networks. This slow start has exploded into a federal information technology system with sensors on satellites, submarines, and everywhere in between. That "in between" can include on-prem networks, multiple clouds, and hybrid clouds. Today, we sit down with Ryan Leiws, the CEO of Rancher Government Solutions, to look at some of the challenges in managing this dispersed environment and how to manage it. Lewis describes how Rancher connects hybrid environments using containers and Kubernetes for secure orchestration. Lewis emphasizes continuous compliance and DevSecOps via Rancher's Carbide stack, SBOM-level visibility, and rapid recovery in contested, denied/disconnected/intermittent/limited (DDIL) environments. Lewis notes that Rancher's declarative stack reduces maintenance and allows simple app redeployment. They also emphasize portability, cost efficiency, and alignment with zero-trust principles, with upcoming hardened features. = Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com

We began the interview with a startling fact. Maximus' federal systems interface with one in three Americans each year—about 110 million people. Building on Maximus's broad reach, Pledger says the company's core is designing world‑class digital experiences by starting with the end goal (e.g., veterans' benefits) and using automation, AI, analytics, and omni‑channel outreach. We have all heard about improvements in systems; today, Pledger offers specifics on how health care can improve. He cites his own 2008 Iraq injury and notes veteran case durations historically ran three hundred to four hundred days; Maximus has reduced that to two hundred to 270 days, but still deems it too long. Maximus' success is due to its unique ability to leverage AI to drive this transformation. One approach is to partner with companies with vertical-market expertise. For instance, Maximus partners with Salesforce (CRM) and Genesis (telephony) to respond to complex medical cases. Example: outbound campaigns (text, email, AI‑generated calls) cut lapses; proactive engagement improves experience and reduces call‑center burden. Maximus is a story about a complex environment being tamed through understanding processes, applying technology, and making the right partnerships. Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com

Everyone reading this has had minor delays at the airport. It is remarkable that more problems have not developed. Look at Chicago O'Hare International Airport—it has 857,392 takeoffs and landings in a year. Each one has passengers, and most have luggage. The opportunities for problems are overwhelming. Now add an increasing number of sensors and interlaced networks, and you have an attack surface of biblical proportions. All an adversary needs is one single point of vulnerability to attack a system. Think what could happen if an airport network were disabled by a ransomware attack. During today's interview, Lou Karu makes suggestions for defense that include a multi-layered strategy emphasizing zero trust and network segmentation. However, Karu reminds us that a cybersecurity strategy is not complete without a robust recovery plan. For example, if a basic recovery plan was deployed, it is possible that a system can have compromised code locked into a backup. An airport suffers an attack, pays the ransom, and the recovered data has more attacks built in. Best practice here is to have a backup system that is rapid and accurate, and that restores the code without it being hot-infected with additional malicious code. Systems like this from Rubrik call these backups "immutable." The next time you go to the airport, try to imagine the numerous attack points that an airport must contend with. Even the most robust cyber defense must include plans for safe, secure recovery. Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com

Technology is changing so fast that it is impossible to predict the next twelve days. Despite that, we have asked Travis Rosiek, Public Sector CTO at Rubrik, to gaze into his crystal ball and make some predictions for the next twelve months. The good news is that Rosiek sees a shift from intellectual property theft to disruptive attacks on critical infrastructure. The bad news is that Rosiek thinks attacks are increasing to the point that an event will light a fire under the current cybersecurity plans. During the interview, the concept of Zero Trust was unpacked. The idea is that federal systems have already been breached. As a result, the focus must be on microsegmentation, with permission as the limiting factor. Roseik's opinion is that malicious actors have planted code into systems that are acting as "sleepers." At one time in the indeterminate future, this code can be invoked, and severe damage can take place. If this nightmare situation occurs, the best defense is to have recovery built in. Today, leaders must have a system in place to restore data from backups. Unfortunately, malicious actors know this plan as well and have been known to insert code into backups that renders them useless. In a complex game of attack and counterattack, Roseik believes that a recovery strategy that includes immutable backups and an audit mechanism is the best approach in the 21st-century world of threats and countermeasures. He also stressed the necessity of reducing complexity to enhance cybersecurity and the need for initiative-taking measures, including regular stress testing and resilience training. = = Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com

It is always tricky to compare commercial networking challenges with those faced by federal leaders. For example, the military and intelligence agencies require traffic encryption. How can an organization detect threats while observing this traffic? Today, we discuss Vectra AI's network threat detection capabilities with Wes Nagel, DoD sales manager, and Gage Cowger, a security engineer. With technology from Vectra AI, network traffic can be analyzed for timing, size, direction, and protocol use. These can give behavioral patterns for network visibility without worrying about encryption. Cowger will argue that behavioral patterns are more effective than signatures, especially in mitigating alert fatigue. Signatures can overwhelm monitors with false positives; Vectra's AI and ML capabilities provide trustworthy alerts. This ability positions Vectra AI to adapt to new networking initiatives, such as software-defined and OT/IoT networks, which will be prevalent in the future. The discussion also touches on the future of network detection, emphasizing the need for real-time, behavior-based detection to counteract advanced threats and adapt to evolving networks. Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com

One of the biggest trends in software development over the past 10 years is the shift from writing code to "assembling" code from off-the-shelf components. During today's interview with Javed Hasan from Lineaje, we learned that 70% of that pre-assembled code is open source. In other words, an anonymous person in some countries modified software instructions. This casual approach may be fine for small businesses, but an organization like the federal government must be highly cautious. Hasan describes how his company was one of the first to work with the federal government to set standards for this existing code. These initial efforts began ten years ago and resulted in Executive Order #14028, which requires a Software Bill of Materials for any organization selling to the federal government. This initiative expanded in 2021-2022 when NIST published related guidelines. These efforts are a good start. However, federal leaders must evaluate SBOM technology from many perspectives. For example, how to incorporate this mandate into air-gapped networks, legacy COTS, or even in a classified environment. System administrators also need to know if they are exposed. Further, every organization has a varying definition of what "deep software transparency" is. Hassan also discusses Lineage's innovative approach to creating "Gold open source" software, ensuring it is free of malware and vulnerabilities. If you are interested in seeing a demonstration of how Lineaje can help with software forensics, there is an event at the Carahsoft office in Reston, Virginia, on January 30 = = Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com

In the past 10 years, Amazon Web Services has gone from a niche player in the federal government to being responsible for billions in sales. One key aspect of this is how Amazon integrates leadership with innovation to address complex federal requirements. Today, we sit down with Andrew Christian to get an overview of concepts like customer obsession, working backwards, and the sixteen leadership principles that AWS implements to accomplish that drastic growth. ONE Customer-focus In the commercial marketplace, the concept of being "customer-focused" is certainly not breaking news. However, as Christian explains, AWS tries to understand (almost obsessively) what the requirements are for federal systems. No, technically, they are not "customers," but they are the end users for any technology project. This focus has given AWS remarkable success in the commercial world, and when they apply it to federal technology, they can succeed where others have failed. TWO Working Backwards Christian explains that "working backwards" is a concept where a team is forced to write a mock press release and FAQ for a future project. This is before they build anything. This helps to clarify the customers' needs by identifying gaps early. THREE encouraging innovations Many describe innovation as failing fast, then recovering. That may hold up in a commercial application where lives are not at stake. During the interview, Andrew Christian differentiates between the importance of making quick, reversible decisions (two-way doors) versus long-term, impactful ones (one-way doors). He encourages federal agencies to adopt these principles to enhance their innovation and adapt to a world co constantly changing technology. Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com

One famous cartoon featured two vultures sitting on a fence; one turned to the other and said, "I am sick of waiting, let's kill something." When it comes to preventing cyberattacks, the federal government is well known for a defensive approach. They have security systems, air gap systems, and even a zero-trust approach. This defensive approach is essential but may not give the federal government a complete view of how to protect data. Today, we sat down with Chris Jones, Nightwing's Chief Technical Officer. He outlines some of the characteristics of a concept called "offense informs defense." This is a method that Nightwing has developed through over 40 years of working with federal technology leaders. For example, they developed their Counter Trace service, which uses offensive cyber strategies to defend critical infrastructure. The service involves proactively hunting for vulnerabilities, identifying access points, and analyzing digital evidence to expose cyberattacks. During the interview, Jones mentions that the GSA has received this approach well. In fact, Nightwing recently won all six GSA Highly Adaptive Security Services categories. These handle security aspects like Penetration Testing, Incident Response, Risk Assessments, Cyber Hunt, and High Value Asses Assessments. Jones emphasizes the importance of initiative-taking, cybersecurity, AI integration, and collaboration across agencies to adapt to protect federal data.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com Today, we have an experienced tech veteran, Bob Stevens from GitLab, offering insights on how he sees the federal government overcoming three main technology challenges in 2026. Challenge ONE: Software improvement on scale. Stevens observed that everyone has seen AI's ability to review code. It has passed the basic phase, and now, in 2026, it cannot only review code but also identify security vulnerabilities, ensure compliance, and even generate documentation. This means that older, expensive-to-maintain systems can be transitioned to more flexible, economical cloud models. Challenge TWO: Going away from reacting. The word "continuous" has been the goal for cyber defenders for the past several years. Fortunately, AI is allowing that noble goal to be put into practice. When applied appropriately, newer technology can achieve lower breach rates and faster threat response times. Challenge THREE: emergence of a "universal" developer. Traditionally, requirements would be gathered by an intermediary and then translated into instructions for software developers. Stevens shows how newer AI-based approaches can eliminate that intermediary step. In other words, a pilot can precisely describe what they want in an avionics system, and the developers can work from that description. That means solving domain-specific problems with traditional development skills. Ideally, subject matter experts directly translate their knowledge into functional software systems. Some call this the "universal" developer approach. Stevens emphasized the importance of AI, security, and flexibility for future developers. GitLab's DevSecOps platform integrates AI across the entire software development process.

(We recorded this interview at Monk's BBQ in lovely downtown Purcellville, VA) Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com Defrauding the federal government is like the weather; everyone wants to complain, but nobody can do anything about it. For example, a joint DOL-SBA report from December 2024 revealed $2.3 billion in potentially fraudulent payments. Today, we sat down with Jeff Gallimore from Excella, where he will diagnose the problem of federal waste, fraud, and abuse. From there, he presents a solution that has already saved millions of dollars. The problem: too many silos From a data management perspective, most enterprise computational capabilities evolved through a federated approach. From a historical perspective, it makes sense that each agency would have its own computers and storage. It makes sense that individual data stores in this environment would be separated, or perhaps the word "siloed", into distinct areas. Now, if you have one silo, you can protect it; if you have a thousand, then there is a problem. During the interview, Gallimore mentioned an agency that manages 9,000 grants. That is a lot of data to coordinate when it is stored in its "silos." The solution: gap analysis Silos can be secure, but the architecture can allow for gaps in security coverage. These gaps, or seams, can allow fraudsters to exploit this structure. For example, an agency may have a division that has identified a person as a fraudster. If that information is not shared, this person can use the same exploit on another area of the agency. Further, interlinks between federated systems can allow adversaries to gain access. Excella has a profile of how they have managed to fill in the gaps in siloed data architecture.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com When cloud computing was introduced, it was quite a simple concept: leverage other people's hardware to scale easily. Not too much to manage. However, today's cloud world has metastasized. Today, federal leaders live in a world of on-prem, multiple clouds, private clouds, hybrid clouds, and even sovereign clouds. Complications arise when they are burdened with compliance requirements and staff reductions. Today, we sat down with Ryan McArthur from Zscaler to discuss how to effectively manage a cloud environment when challenged with deploying Zero Trust. He begins by sharing his experience helping federal leaders understand the inherent risks of the VPN system. Few realize that VPN technology was first introduced by Microsoft back in 1996, and then popularized with Windows 4.0, which included built-in support. Thirty-year-old technology can present severe limitations. Unfortunately, the popularity of VPN technology increased with the demands of remote computing during COVID. We are now in a situation where many enterprises have built their architecture on this dated technology. Ryan mentions that one key to juggling clouds is to focus on the applications themselves. He emphasized Zscaler's ability to securely connect users. If you want more information about Zscaler, you should attend the Zscaler Public Sector Summit in March, where you can discuss and collaborate further.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com We are at the point where AI is almost expected in any technology offering. Today, we sat down with John Kindervag from Illumio to learn how AI can be applied to the world of federal Zero Trust. Some have characterized today's current cybersecurity situation as an arms race; some call it a whack-a-mole game. An innovative technology, such as AI, becomes popularized, and adversaries use it to improve attacks. As a result, the defenders of data must bolster their response, and they, in turn, use AI to defend. He highlights the importance of visibility, using AI to quickly parse logs, and the concept of dwell time, in which attackers can remain undetected for extended periods. To protect valuable data, Kindervag distinguishes between the attack surface and the defense surface. Although a malicious actor can instigate AI-driven attacks across any surface, sensitive information can be protected by thorough segmentation of the protected surface. During the interview, Kindervag provides tactics to manage legacy technology, fragmented data, and the critical topic of risk-averse culture.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com It is rare to see AI applied to federal cybersecurity mandates. However, today, we will sit down with Louis Echenbaum from Color Tokens. He will unpack the concept of using AI to help federal leaders improve their ability to implement microsegmentation. We all know about Executive Order 14028 and the OMNB Memo M-22-09, which are forcing federal agencies to deploy a robust Zero Trust framework. The key components include identity and access management, asset management, continuous monitoring, and micro segmentation. During the interview, Louis Echenbaum expands on current challenges like legacy systems and visibility. For example, what happens once a malicious actor breaches a federal system? Some call this east-west traffic. The general response is to prioritize and segment data so the intruder is denied access. This concept looks good on paper, but in the real world, leaders encounter some issues. First, how can they know exactly what is on their network? This is perplexing in environments where endpoints are in areas that cannot be upgraded. Further, the move to a hybrid cloud offers varying levels of data segmentation. One system administrator may be competent with a specific cloud service provider but does not know all the details of another company. This skills gap can lead to coverage gaps and opportunities for attack. The solution Echenbaum suggests is to leverage AI to improve visibility and give leaders ways to prioritize datasets into appropriate microsegments.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com In the world of federal technology we are being deluged with so much information about Artificial Intelligence that we may not see what some of other technologies that may have as great an impact as AI. The White House, the OMB (M-23-02), the Office of the National Cyber Director have made it clear that the time to prepare for post-quantum cryptography is now. Agencies are required to inventory cryptographic systems, prioritize high-value assets, and build migration plans in line with NIST standards. Today, we sit down with Eric Hay from Quantum Xchange to look at making this transition. During the interview, Hay handles issues like technology, operations and appropriate strategy. He highlights the role of NIST in developing and approving new algorithms like NIST PQC Post Quantum Encryption, ML, and CHEM. Eric explains the five-step process for transitioning to these new standards: discovery, prioritization, deployment, monitoring, and management. Rather than spending time evaluating algorithms, Eric Hay stresses the importance of a network-centric approach, suggesting that agencies focus on securing data transport first. Eric predicts Q day, when current encryption methods could be compromised, within 3-5 years, with some European partners aiming for 2029.