POPULARITY
Six months after War Secretary Pete Hegseth directed sweeping acquisition reforms across the department, the Defense Information Systems Agency is accelerating its transition from government-developed cybersecurity tools to commercial technologies. On this episode of CyberCast, Brian Hermann, director of PAE Cyber at DISA, discussed how the agency is modernizing its cyber acquisition strategy by prioritizing commercial solutions, software-as-a-service offerings and more flexible contracting approaches. Hermann explained why DISA believes commercial technologies can deliver capabilities faster, reduce operational risk and better keep pace with evolving cyber threats. The conversation also explored how DISA is breaking down budget silos and consolidating resources to give portfolio leaders greater flexibility to adopt new technologies and retire legacy systems more quickly. As the department's acquisition transformation takes shape, Hermann outlines DISA's evolving role as an integrator of commercial capabilities — ensuring interoperability and mission effectiveness across contested, coalition and edge environments.
As artificial intelligence continues to reshape government technology, National Endowment for the Arts CIO and Chief AI Officer Jim Tunnessen said the technology has significant potential to accelerate modernization, streamline software development and improve operational efficiency. Tunnessen pointed to AI-assisted development as a fundamental shift in how agencies build applications, enabling smaller teams to deliver capabilities faster than through traditional development methods. He said agencies must balance those gains with strong governance, transparency and cybersecurity guardrails. At the NEA, Tunnessen views AI as a tool for enhancing back-office operations while ensuring human judgment remains central to evaluating artistic work.
The Department of Veterans Affairs' Office of the Inspector General serves as the agency's internal watchdog, and leaders are leveraging technology to improve oversight. The office's CIO Lance Jenkinson discussed how the OIG is using AI to strengthen oversight, improve operational efficiency and ensure the agency's IT systems meet security and compliance requirements. Jenkinson also discussed why strong governance, clear policies and thoughtful implementation are essential to maximizing AI's benefits while mitigating potential risks.
DODNet leaders say 90-day OTA cycles and flexible engineering models are helping DISA deliver capabilities at the speed of cyber threats. Guest: Kelli Garczynski, acting DODNet Deputy Program Manager, and Mike Butler, Chief Engineer, DODNet, DISA Description: As cyber threats evolve and technology advances at an unprecedented pace, the Defense Information Systems Agency is rethinking how it acquires and delivers capabilities. Acting DODNet Deputy Program Manager Kelli Garczynski and DODNet Chief Engineer Mike Butler joined CyberCast to discuss how DISA is adopting agile acquisition strategies and accelerating procurement timelines to strengthen network defenses and deliver mission capabilities faster. Butler said DISA must pair technical agility with contract agility to keep pace with rapidly changing threats across War Department networks. Traditional acquisition timelines, he noted, can leave critical engineering efforts lagging behind emerging mission requirements. To address that challenge, Garczynski said DISA is increasingly using Other Transaction Authorities (OTAs) to rapidly identify, evaluate and deploy the best technologies for warfighters. By leveraging OTAs, DISA aims to move from industry engagement to contract award in as little as 90 days, dramatically reducing the time required to field new capabilities. Garczynski added that modern architectures such as DODNet and DISA's zero-trust initiative, Thunderdome, cannot be developed through rigid, static requirements. Butler said continuous data collection and operational feedback allow DISA to adjust requirements in real time, enabling more responsive development and a stronger defense against active adversaries.
The U.S. Army is expanding its use of artificial intelligence across the enterprise, from administrative operations to battlefield decision-making and logistics. As AI adoption accelerates, Army leaders are also navigating the cybersecurity and governance challenges that come with integrating the technology into mission systems. Chief Warrant Officer 3 Jordan Duke, chief of the Cybersecurity Division at the Army Contracting Command, outlined his role overseeing cybersecurity and how AI is shaping the future of Army acquisition. Army Contracting Command manages procurement across the service, supporting everything from everyday office supplies to advanced weapons systems. Duke discussed how the organization is addressing cybersecurity risks across its vast acquisition environment and how AI is being integrated into contracting workflows, including solicitations, cybersecurity and enterprise operations.
Labor Department CIO and Chief AI Officer Mangala Kuppa joined GovCIO Media & Research at the Federal IT Efficiency Summit to discuss how the agency is integrating artificial intelligence across its operations to improve efficiency, modernize legacy systems and enhance customer services. As the department expands its use of AI, Kuppa said leaders are focused on ensuring new technologies support existing workflows while delivering measurable mission outcomes. AI is already supporting a range of use cases across the department, from helping employees refine documents and streamline workflows to assisting with software development and code generation. Kuppa also discussed the department's efforts to build AI literacy across the workforce as AI tools become increasingly embedded throughout the agency's technology ecosystem. Looking ahead, the department is exploring emerging technologies, including quantum computing, while advancing ongoing modernization efforts such as data center consolidation and digital experience improvements.
Misunderstandings about the Authority to Operate (ATO) process are slowing federal technology modernization efforts and driving up costs, according to David Raley, chief digital business officer for Operation StormBreaker in the Marine Corps. Speaking at GovCIO Media & Research's Federal IT Efficiency Summit, Raley argued that many delays stem from a fundamental misconception about what receives an authorization. Rather than granting ATOs to individual software applications, agencies authorize integrated systems operating within specific environments, taking into account mission context, infrastructure, users and data. Raley said this misunderstanding often leads to unnecessary delays for both government teams and industry partners. To accelerate software delivery, Raley highlighted the Marine Corps' Operation StormBreaker initiative, which leverages modern DevSecOps practices and continuous integration and continuous deployment (CI/CD) pipelines. By building applications on preauthorized platforms, teams can inherit the majority of required security controls, reducing compliance burdens and enabling faster, more efficient delivery of mission capabilities.
The Air Force's Cyber Resiliency Office for Control Systems (CROCS) is translating high-level Pentagon cyber directives into operational steps to secure control systems across the department. Technical Director Daryl Haegley said the office was created to close a long‑standing policy gap to secure operational technology (OT). The Department of the Air Force has spent more than a year assembling stakeholders from mission assurance, intelligence, operations and logistics to develop a 100‑point cyber plan. The office now tracks progress on each initiative and convenes more than 100 OT experts monthly to coordinate implementation. Haegley emphasized that missions depend on their continuous availability. No base can operate without electricity, water and other critical services. CROCS plays a central role in aligning those priorities and helping assign appropriate levels of cyber risk. The office is also pushing services to train for degraded conditions. Bases are conducting energy resilience exercises that simulate cyberattacks by disconnecting from commercial power and disrupting systems like HVAC. "Operating in a contested environment — and training and rehearsing that — is what CROCS is trying to coordinate," Haegley said.
Tommy Gardner, CTO of HP Federal, joined us at CyberScape: The Federal Cybersecurity Summit to discuss the growing risks of adversarial AI as agencies accelerate adoption of the tech across mission-critical environments. He outlined how how threat actors are exploiting vulnerabilities in AI systems, from manipulating training data to probing model weaknesses. He also shared how agencies and organizations can build resilient AI systems, protect algorithms and data, and embed security into the development lifecycle without stalling innovation as threats become increasingly complex.
The U.S. is facing a surge in advanced threats from nation-state actors like China and Russia, who are increasingly probing critical infrastructure vulnerabilities. David Travers, director of the Environmental Protection Agency's (EPA) Office of Water Emergency Response and Cybersecurity, noted how escalating risks to the nation's water sector has shifted over his 30-year career, how adversaries are leveraging emerging technologies like AI to improve attacks and how the agency is adapting. He also detailed how partnerships with Cybersecurity and Infrastructure Security Agency (CISA) and the FBI are improving incident reporting, plans for a new $9 million water system resilience grant and the top cybersecurity initiatives shaping 2026.
With generative AI introducing new challenges for digital security, Arun Vemury, director at the Department of Homeland Security's Science and Technology Directorate, explains how biometric technologies are enabling the agency to stay ahead of AI-driven identity fraud. The conversation explores how DHS verifies identities across complex environments — from border crossings to remote digital interactions. Vemury details the agency's collaborative approach, using cooperative research agreements and competitive evaluations to test and deploy cutting-edge biometric tools quickly. He also discusses how DHS balances strong security with seamless user experiences through multi-layered verification methods like advanced facial recognition, liveness detection and emerging video call authentication techniques.
The Export-Import Bank of the United States (EXIM) facilitates trades of exports of goods and services and, in doing so, deals with massive troves of data. From the Billington Cybersecurity Summit, EXIM CISO, Chief Privacy Officer, and Deputy Chief AI Officer Darren Death tells CyberCast that his agency is centralizing data about user access and behavior to detect potential cyber threats. Death says that balancing cybersecurity with privacy remains a challenge, especially in complex IT ecosystems involving financial institutions. He stresses the need to “shift left” by embedding privacy and security requirements early in the development lifecycle and include business leaders in conversations about cybersecurity, privacy and usability. He also says that the EXIM is using generative AI to simulate incident response scenarios, escalating threats to test team readiness. Death adds that EXIM is positioning AI as a force multiplier rather than a job threat.
Cybersecurity has been on the Government Accountability Office's (GAO) high-risk list since 1997. Federal agencies struggle with issues like cyber hygiene, cyber workforce shortages and strategic execution. While agencies put strategies in place to secure their systems, the implementation and execution can be ineffective, according to GAO Managing Director of IT and Cybersecurity Nick Marinos. Marinos says that evolving threats have reshaped the cybersecurity landscape over the years in government, making evolution a moving target. Agencies are adjusting their workforces accordingly, he says, but is is difficult to keep pace with emerging technology. He underscores the urgency of streamlining federal hiring processes to prevent losing top talent to faster-moving private sector opportunities.
The White House released a new executive order in July — Accelerating Federal Permitting of Data Center Infrastructure —calling on government to develop AI-ready data centers, streamline federal permitting and encourage private investment in critical infrastructure. Federal agencies are focusing on system resilience to withstand rising environmental and cybersecurity threats as data centers continue to grow. A joint report from the Department of Energy and Lawrence Berkeley National Lab reveals that electricity usage by data centers tripled over the past decade and could double or triple again by 2028 — potentially consuming up to 12% of the nation's electricity. Federal researchers and cybersecurity experts are exploring underground thermal energy storage systems like Borehole Thermal Energy Storage (BTES) to regulate temperatures and reduce grid stress. Leaders from federal/critical infrastructure operational support and National Renewable Energy Laboratory (NREL) are exploring how geothermal solutions can keep data centers operational during extreme weather events and power outages. As the U.S. races to expand its digital infrastructure, these innovations may be key to building a secure and sustainable future.
Cybersecurity is a critical component of organizational health no matter the federal agency. Yet, federal leaders across government are struggling to change culture, improve workflows and promote good cyber hygiene to prepare for the threats of tomorrow. The Government Accountability Office's Information Technology and Cybersecurity division assists Congress with assessing and improving the government's critical IT investments and develops best practices that are used across the government to guide decision-making. The division's Director Jennifer Franks breaks down where agencies fall short in implementing cybersecurity recommendations and discusses ways that federal leaders can improve their cyber hygiene through better hiring processes, stronger cybersecurity requirements and promoting an inclusive and team-oriented culture.
Edmon Begoli, Director of the Center for AI Security Research (CAISER) at the Energy Department's Oak Ridge National Laboratory, highlights how his team is ensuring safe and responsible AI deployment across government during the AI+ Expo in Washington, D.C., earlier this month. The research team is developing cutting-edge tools and methodologies to assess AI vulnerabilities, test models under extreme conditions and create energy efficient solutions for complex technological challenges. Begoli's team is focusing on two key innovations: comprehensive AI security assessments and TinyML, a revolutionary approach to developing small, energy-efficient machine learning models. By creating AI systems that can operate effectively in limited environments — such as surveillance drones or long-term sensor networks — the team is addressing both security concerns and environmental sustainability challenges facing the technology sector. The research goes beyond technical development, emphasizing education and public outreach to build AI literacy across diverse demographics. From high school students to senior citizens, the team is committed to demystifying AI technologies and demonstrating the potential to solve critical national security and infrastructure protection challenges. The team's work represents a proactive approach to technological innovation, ensuring that AI can be trusted, secure and strategically advantageous for the nation.
The latest iteration of the National Institutes of Standards and Technology's (NIST) Cybersecurity Framework (CSF) helps organizations strengthen their security posture and align their cybersecurity efforts with enterprise-wide risk management. NIST's Steven Quinn, the project lead for the Cybersecurity Framework, provides a comprehensive overview of the key updates and transformative features in the 2.0 version. At the center of the new framework is the introduction of the "govern" function, which empowers executives and risk management professionals to seamlessly integrate cybersecurity risk into their existing enterprise-level decision-making processes. By bridging the gap between technical security controls and business objectives, the framework enables organizations to make more informed, strategic investments in their cybersecurity programs. Additionally, the framework has been enhanced to address emerging technologies, such as quantum computing and artificial intelligence, ensuring an organization is prepared to navigate the evolving threat landscape.
The new year began with a new White House executive order on strengthening and promoting innovation in cybersecurity, building on previous efforts, like the National Cybersecurity Strategy, to enhance the security of the nation's digital infrastructure. Looking into 2025, Deputy Assistant Director of FBI's Cyber Division Cynthia Kaiser said her division plans to leverage emerging technology like artificial intelligence to thwart cyber adversaries and better detect threats around critical infrastructure, while aligning with federal policies and directives. Kaiser's division is also advancing patch management and other AI-enabled technology to boost resiliency. Kaiser highlighted some of the top exploited vulnerabilities FBI has seen over the recent years, the agency's special partnership with CISA as well as the importance of the “Secure by Design” model to counter cyber attacks.
Technology has made cyber threats more complex and difficult to discern for defense intelligence operations and combatant commands providing insights to decision-makers across the globe. The North American Aerospace Defense Command (NORAD) and U.S. Northern Command (Northcom) work with industry, allies and other combatant commands to secure all domains for the U.S. and Canada. Director of Intelligence and Information Brig. Gen. Maurizio Calabrese discussed the evolving role of defense intelligence, the importance of cyber warfare and the need for global threat awareness. He also addressed the growing importance of the Arctic region, citing increased international interest and the need for advanced tech capabilities.
The new year began with a new White House executive order on strengthening and promoting innovation in cybersecurity, building on previous efforts, like the National Cybersecurity Strategy, to enhance the security of the nation's digital infrastructure. Looking into 2025, Deputy Assistant Director of FBI's Cyber Division Cynthia Kaiser said her division plans to leverage emerging technology like artificial intelligence to thwart cyber adversaries and better detect threats around critical infrastructure, while aligning with federal policies and directives. Kaiser's division is also advancing patch management and other AI-enabled technology to boost resiliency. Kaiser highlighted some of the top exploited vulnerabilities FBI has seen over the recent years, the agency's special partnership with CISA as well as the importance of the “Secure by Design” model to counter cyber attacks.
Adam Rak is the executive director of CyberUSA, a community of cyber communities focused on information sharing, programs, and best practices to improve our nation's cyber resilience. In this episode, he joins host Heather Engel to discuss the relaunch of CyberUSA and how the organization is providing access to a national threat-sharing platform, as well as the value of education and workforce development, and more. The Federal Business Council is a producer of events to foster meaningful engagement for Federal Government Agencies, the Department of Defense, and the Intelligence Community throughout the United States. To learn more about our sponsor, visit https://fbcinc.com.
The Centers for Medicare and Medicaid Services (CMS) Cyber Integration Center (CCIC) is the hub of cybersecurity strategy and response at the agency. The collaborative center focuses on internal assessments to protect sensitive patient data and improve threat detection. Acting CISO Keith Busby explained how CCIC red, blue and purple security engagements teams are conducting Penetration Testing (PenTesting) to monitor the agency's critical infrastructure and prevent malicious actors from causing devastating cyber attacks. Busby shared details about the agency's Risk Management Strategy, which uses secret scanning and other enterprise level technologies to mitigate risks. He also highlighted the Department of Health and Human Services (HHS) cyber performance goals agencies should be prioritizing to boost their resiliency.
Larry Silver is the CEO of Superus Careers, which is known for its innovative cyber apprenticeship methodology. In this episode, he joins host Heather Engel to discuss workforce development for cybersecurity positions, and some of the problems and solutions for filling cyber workforce roles. The Federal Business Council is a producer of events to foster meaningful engagement for Federal Government Agencies, the Department of Defense, and the Intelligence Community throughout the United States. To learn more about our sponsor, visit https://fbcinc.com.
Larry Silver is the CEO of Superus Careers, which is known for its innovative cyber apprenticeship methodology. In this episode, he joins host Heather Engel to discuss cyber apprenticeships in detail, including why they're so valuable, how they benefit both the apprentices and employers, and more. The Federal Business Council is a producer of events to foster meaningful engagement for Federal Government Agencies, the Department of Defense, and the Intelligence Community throughout the United States. To learn more about our sponsor, visit https://fbcinc.com.
The Advanced Research Projects Agency for Health (ARPA-H) has launched a new program providing health care organizations a rapid and secure cyber solution that will protect their infrastructure from threats and prevent disruptions in patient care. ARPA-H Resilient Systems Program Manager Andrew Carney discusses the Universal Patching Intermediation for Autonomous Defense (UPGRADE) program and how it offers medical facilities protection from ransomware attacks by automatically providing proactive and scalable updates to their IT systems. Carney highlighted another ARPA-H program called the Digital Health Security Initiative (DIGIHEALS) that's addressing vulnerabilities in data security. He also shared details about the agency's collaborative efforts with its defense counterpart, DARPA.
Explore how CISA and CMS are tackling open source software (OSS) security in government. CISA Technical Advisor Jack Cable shares insights on CISA's roadmap, best practices and efforts to secure OSS and promote open source program offices. CMS Digital Service Open Source Lead Remy DeCausemaker also discusses the strategic approach to creating an open-source program office, focusing on stakeholder engagement, security measures and regulatory guidance. Hear how these strategies are shaping the future of open source security and fostering collaboration.
Government's recent efforts to coordinate cybersecurity regulations have evolved as the threats have. A recent Government Accountability Office report examines the work that remains to support a longer-term strategy for juggling these policies across agencies. Dave Hinchman, director in GAO's IT and cybersecurity team, oversees the IT and cybersecurity workforce, cloud computing and IT modernization efforts. He discusses the recent report on cybersecurity, current cyber regulatory policies and how he's seen IT policy evolve.
Heather Engel is the Managing Partner at Strategic Cyber Partners. In this episode, she joins host Amanda Glassner to discuss the White House's called for a surge in AI talent across federal agencies, aiming to add 500 experts in artificial intelligence by the end of 2025. The Federal Business Council is a producer of events to foster meaningful engagement for Federal Government Agencies, the Department of Defense, and the Intelligence Community throughout the United States. To learn more about our sponsor, visit https://fbcinc.com.
Diane M. Janosek, PhD, JD, is the former training director/commandant at the National Security Agency's National Cryptologic University, and most recently deputy director of NSA Compliance. Today, she is the CEO at Janos LLC and award-winning cybersecurity leader, author, and sought-after speaker. In this episode, she joins host Heather Engel to discuss a LockBit breach that hit the Indonesian government and how the situation parallels the United States' response to ransomware. The Federal Business Council is a producer of events to foster meaningful engagement for Federal Government Agencies, the Department of Defense, and the Intelligence Community throughout the United States. To learn more about our sponsor, visit https://fbcinc.com.
Protecting sensitive information is critical to cybersecurity, but agencies need to learn to operate with fewer secrets in the aftermath of cybersecurity incidents. Sharing information about attacks within the community can help protect against future ones, according to Suzanne Spaulding, who formerly led the National Protection and Programs Directorate at the Department of Homeland Security. Spaulding discussed how a focus on transparency will be advantageous for national defense. She explained why this approach is necessary by highlighting the risks associated with keeping secrets. Spaulding also discussed the impact of CISA's Secure by Design Pledge on the global cybersecurity environment, noting how recent commitments from companies further contribute to the idea of transparency.
The Bureau of Intelligence and Research (INR), both a bureau in the State Department and a member of the Intelligence Community, is the only U.S. intelligence organization with the primary responsibility of providing intelligence to inform diplomacy and support U.S. diplomats. The bureau, like many government agencies, has focused on modernizing the enterprise by upskilling the workforce and modernizing IT. CIO Jimmy Hall, also director of the Technology, and Innovation Office (TIO), spoke about this progress, what makes some of his technology challenges unique and what it all means for ongoing diplomacy priorities.
Heather Engel is the Managing Partner at Strategic Cyber Partners. In this episode, she joins host Amanda Glassner to discuss a recent convening at the White House, hosted by the White House Office of the National Cyber Director, where representatives from more than 30 companies and institutions, representing a dozen industries, committed to expand opportunities for Americans and build a stronger cyber workforce. The Federal Business Council is a producer of events to foster meaningful engagement for Federal Government Agencies, the Department of Defense, and the Intelligence Community throughout the United States. To learn more about our sponsor, visit https://fbcinc.com.
Following its “Secure by Design” initiative and pledge, America's cyber defense agency, CISA, is supporting the movement for software manufacturers to build security into their products at the start. The movement is part of a White House priority to shift responsibility for cybersecurity away from end users and toward manufacturers. CISA Senior Technical Advisor Jack Cable and Senior Policy Advisor Lauren Zabierek examine the impact the strategy and pledge will have on federal and industry leaders in the pursuit of creating a more secure world. Featured audio: https://youtu.be/R6RW-DemWbQ?si=_zLigtIZ-OZGd46a
Debra Baker is the vCISO at TrsutedCISO. In this episode, she joins host Heather Engel to discuss the latest updates on federal compliance mandates, including the Biden Administration's AI executive order, the SEC's cyberattack disclosure guidelines, and OMB's M-24-04 memorandum. The Federal Business Council is a producer of events to foster meaningful engagement for Federal Government Agencies, the Department of Defense, and the Intelligence Community throughout the United States. To learn more about our sponsor, visit https://fbcinc.com.
NIST's new Cybersecurity Framework published earlier this year gives organizations a new set of harmonized cybersecurity guidelines and best practices. It's the first major update in 10 years and broadens its scope beyond critical infrastructure entities. Cherilyn Pascoe, director of NIST's Cybersecurity Center of Excellence, had a large role in developing the new framework. She said the plan emphasizes the importance of cybersecurity in an evolving technological environment and discusses how others can tailor it to their organizations across missions. Pascoe also highlights a growing focus in broader cybersecurity priorities around post-quantum cryptography and AI, and explains how NIST's Center of Excellence is developing additional guidance for the community.
Heather Engel is the Managing Partner at Strategic Cyber Partners. In this episode, she joins host Amanda Glassier to discuss securing the federal technology landscape in light of Deltek's recent report, "Federal Cybersecurity Market, 2023-2027." The Federal Business Council is a producer of events to foster meaningful engagement for Federal Government Agencies, the Department of Defense, and the Intelligence Community throughout the United States. To learn more about our sponsor, visit https://fbcinc.com.
In light of the National Institute of Standards and Technology's new second iteration of its cybersecurity framework, Rubrik Public Sector CTO Travis Rosiek breaks down the framework's importance across public and private sector organizations. Rosiek discusses the framework's backup durability provisions, how artificial intelligence is helping protect data integrity and some of the evolving cybersecurity threats for federal agencies to be aware of. The framework is a critical component that ensures organizations can mobilize their data while also keeping it secure, but also recoverable, in the event of an attack or breach.
The White House's port cybersecurity executive order tasks the Coast Guard with monitoring the cybersecurity of vessels, facilities and harbors. Threats could target the global supply chain, national security interests and other vital systems. Rear Adm. Wayne Arguin, the Coast Guard's assistant commandant for prevention policy, discusses how the executive order will affect the service and why cybersecurity matters to the Marine Transportation System. He explains his shifting priorities as the Coast Guard assesses risks and provides cybersecurity services to ports, vessels and partners.
Mitigating cross sector risks and recognizing vulnerabilities in the supply chain remain top priorities for the National Risk Management Center (NRMC) at the Cybersecurity and Infrastructure Security Agency. NRMC Assistant Director Mona Harrington said the team of experts is responsible for creating realistic and actionable recommendations to manage risk to the global information and communications technology supply chain. Harrington said NRMC also utilizes the Secure Tomorrow Toolkit to help stakeholders get a better understanding of the future threat landscape across the information domain. She also highlighted the agency's use of artificial intelligence as well as the Joint Cyber Defense Collaborative's work to reduce the nation's cybersecurity risk. This episode is sponsored by Zscaler.
David Powell is the director of the Federal Business Council (FBC). In this episode, he joins host Paul John Spaulding to discuss rising cybersecurity trends, including those highlighted at the 2023 CyberMaryland Conference, such as quantum computing, artificial intelligence, and more. The Federal Business Council is a producer of events to foster meaningful engagement for Federal Government Agencies, the Department of Defense, and the Intelligence Community throughout the United States. To learn more about our sponsor, visit https://fbcinc.com.
HealthCast, along with GovCast and CyberCast, will now be published in the GovCIO Media & Research Podcasts feed. Subscribe and listen today on the podcast platform of your choice.
Cyber threats from China have been the subject of recent high-profile Congressional hearings lately. Analyst Jack Corrigan from Georgetown University's Center for Security and Emerging Technology (CSET) spoke to the U.S.-China Economic and Security Review Commission Feb. 1 about the risks that Chinese information and communications technology and services (ICTS) have on U.S. national security and critical infrastructure. Corrigan joins CyberCast to break down these threats and what they mean for government agencies, what CIOs can do about them and the role of procurement regulations in strengthening those defenses.
CyberCast, along with GovCast and HealthCast, will now be published in the GovCIO Media & Research Podcasts feed. Subscribe and listen today on the podcast platform of your choice.
The Department of Education is kicking off the second phase of its zero trust strategy by focusing on security orchestration and automation response to stay ahead of the evolving threat landscape. Education CISO Steven Hernandez discusses how the agency is tailoring its cyber tools and technologies by automating manual processes and leveraging identity, access and credential management (ICAM) solutions to improve the user experience and further zero trust.
Federal agencies are modernizing their cybersecurity strategies as threats continue to evolve. Faced with the National Cybersecurity Strategy, zero-trust implementation and recruiting a cyber workforce, agencies are primed for a busy 2024 in cyber and IT. Managing Editor Ross Gianfortune and Staff Writer/Researchers Nikki Henderson Whitfield and Jordan McDonald break down some of the biggest developments ahead for federal IT and cyber leaders. Featured episodes include: 7:05: The National Cyber Strategy https://governmentciomedia.com/listen-open-source-software-national-security-priority 10:28 The 6 Core Principles Vital to Building a Robust Culture of Cyber Readiness https://governmentciomedia.com/listen-6-core-principles-vital-building-robust-culture-cyber-readiness 16:33 How the Pentagon Plans to Fill 30,000 Open Cyber Positions https://governmentciomedia.com/live-afcea-technet-cyber-how-pentagon-plans-fill-30000-open-cyber-positions 21:34 National Cyber Strategy Supports a More Resilient Water System https://governmentciomedia.com/listen-national-cyber-strategy-supports-more-resilient-water-system 17:15: FEMA is Leveraging AI to Secure Networks https://governmentciomedia.com/listen-fema-leveraging-ai-secure-networks This episode is sponsored by Zscaler.
The White House released its National Cybersecurity Strategy in March and is ending the year with the first permanent National Cyber Director in nearly a year. On CyberCast, we covered it all. Take a listen back to some of the highlighted interviews with federal IT leaders, officials and experts this year as CyberCast traveled to Hawaii, California and Maryland. Our team interviewed leaders from agencies including the Federal Emergency Management Agency, the Cybersecurity Infrastructure Security Agency, the Department of Veterans Affairs and the Environmental Protection Agency. On this year-end episode of CyberCast, Managing Editor Ross Gianfortune, and Staff Writer/Researchers Jayla Whitfield and Jordan McDonald reflect on the most memorable episodes and cybersecurity topics of 2023. Featured episodes include: 1:45: The National Cyber Strategy https://governmentciomedia.com/listen-open-source-software-national-security-priority 7:00 Where the White House Wants Agencies to Prioritize Cybersecurity Investments https://governmentciomedia.com/listen-where-white-house-wants-agencies-prioritize-cybersecurity-investments 12:45 How the Pentagon Plans to Fill 30,000 Open Cyber Positions https://governmentciomedia.com/live-afcea-technet-cyber-how-pentagon-plans-fill-30000-open-cyber-positions 17:15: The White House Wants to Fix the Cybersecurity Workforce https://governmentciomedia.com/listen-white-house-wants-fix-cybersecurity-workforce
This episode we're diving into zero trust at the Defense Department. Specifically, how that is playing out for the Indo-Pacific region. We recently had the opportunity to connect with several leaders at the AFCEA TechNet Indo-Pacific conference in Honolulu where they shared with us how they're thinking about this quickly changing landscape and what it means for cybersecurity. This includes an update on DOD's review of submitted zero trust implementation plans, and also a peek at some of those plans at the Air Force and Indopacom. Featured interviews include: Randy Resnick, Director, Zero Trust Portfolio Management Office, DOD. https://governmentciomedia.com/dod-zero-trust-chief-were-start-multi-phased-journey Justin Stolpman, Director, Zero Trust Functional Management Office, Air Force. https://www.governmentciomedia.com/air-force-eyes-next-gen-gateways-amid-zero-trust-plan Paul Nicholson, Deputy CIO and Executive Director of Coalition Communications, Indopacom. https://governmentciomedia.com/look-zero-trust-theater-indopacom
FEMA is developing prototypes for AI use cases in cybersecurity implementation amid a White House artificial intelligence executive order that directs agencies to establish and maintain standards for safety and security of the technology. FEMA CISO Gregory Edwards discusses how the rapid pace of AI innovation is spurring partnerships across federal agencies to work together to leverage best practices for their missions. He also provides an update on the agency's zero trust journey, how his office is anticipating future of cybersecurity needs and how he's balancing that with modernization initiatives.
The Environmental Protection Agency is honing in on multiple pillars from the National Cybersecurity Strategy to secure critical infrastructure at its water and waste-water operations. The agency deems water security to be national security and is an area that needs critical attention. Efforts are underway to increase cyber awareness in the water sector and ensure systems remain resilient. EPA cybersecurity leaders Douglas Vick and David Travers break down what the threat is to the nation's water systems and how two programs are helping mitigate risks and ensure water services operate without disruption. Additionally, the officials highlight some of the new tools that are helping the agency boost overall cyber resiliency across its workforce.
The U.S. Digital Corps is bringing innovation to government by placing early-career technologists at agencies. Operated by the General Services Administration (GSA) Technology Transformation Services (TTS), the Corps' fellowship program gives individuals the chance to work on critical issues at the intersection of technology and public service. Digital Corps fellow Brittney Wright is on the cybersecurity track, assigned to the National Institutes of Health (NIH). Wright is passionate about cybersecurity and said she wants to provide hope to others that are looking to pivot into the field. She discussed her journey to cybersecurity and the ongoing talent gap that the government faces.