Tech Transforms - Global technology is changing the way we live. Critical government decisions affect the intersection of technology advancement and human needs. This podcast talks to some of the most prominent influencers shaping the landscape to understand how they are leveraging technology to solve complex challenges while also meeting the needs of today's modern world.
Jason Miller is the Executive Editor of Federal News Network and has covered the federal technology space over the course of five Presidential administrations. He brings his wealth of knowledge as he joins Tech Transforms to talk about AI, the top things government agencies are working towards this year and his predictions around FedRAMP changes. Jason also pulls on his decades of experience as he discusses events that changed the nation's approach to cybersecurity and the longstanding need to have data that is better, faster and easier to use.
Key Topics* 00:00 AI's impact on texting and cloud's significance. * 04:17 Federal Enterprise Risk Management in government tech. * 07:20 AI trends shifting toward real-time application. * 11:22 2025 and 2027 deadlines for zero trust. * 13:31 CISOs and CIOs adapting to modern technology. * 16:45 Frustration with FedRAMP leads to reform efforts. * 21:39 Applying similar model to expand decision-making. * 23:37 GSA discussed OSCAL at private industry day. * 27:55 CISA's role has grown within DHS. * 30:33 Increased transparency in cybersecurity changed approach significantly. * 34:17 Reflecting on the 2006 significance of data. * 39:19 AFCEA events bring together good people. * 42:53 Fascination with government architecture and dedicated government workers. * 44:35 Promoting positivity and accountability in government industry.
Cybersecurity Evolution: Examining Technology's Political Neutrality and AI Commitment Through Administrative ChangesConsistent Focus on Cybersecurity Evolution Across Political AdministrationsJason expressed a clear conviction that technology issues are largely immune to political fluctuation and are a continuity in government agendas. Reflecting on his experience across five administrations, he noted that the foundational technological discussions, such as cloud adoption, cybersecurity enhancement and overall IT improvement are fundamentally preserved through transitions in political leadership. He highlighted that the drive to enhance government IT is typically powered by the resilience and dedication of public servants, who generally carry on valuable reforms and initiatives regardless of the sitting administration's politics. These individuals are essential to sustaining progress and ensuring that technology remains a key priority for effective governance.
Federal IT Policies Consistency: "No one comes in and says, I'm against AI, or cloud is bad, move back on premise, or cybersecurity, defund cybersecurity. I think those are the issues that stay the same." — Jason Miller
Executive Orders and AI AdoptionAddressing the specifics of executive orders, particularly those influencing the implementation and development of artificial intelligence (AI), Jason examined their historical persistence and their potential to shape operational practices in the government sector. He and Mark discussed how the stability of AI-related orders through various administrations is indicative of a broader governmental consensus on the integral role AI holds in modernizing federal operations. Despite changes in leadership, the incoming officials frequently uphold the momentum established by their predecessors when it comes to leveraging AI. Indicating a shared, bipartisan recognition of its strategic importance to the government's future capabilities and efficiencies.
Cybersecurity Evolution: Zero Trust Principles and Network Security Challenges in Federal AgenciesZero Trust and Cybersecurity BudgetingDuring the podcast, Carolyn and Jason delve into the current trends and expectations for federal cybersecurity advancements, with a particular focus on zero trust architecture. Their discussion acknowledged that agencies are on a tight schedule to meet the guidelines set forth by the Office of Management and Budget, which has highlighted 2025 as the target year for civilian agencies to embrace specific zero trust requirements. While the Department of Defense has until 2027.
Moving past the traditional perimeter defense model, zero trust principles necessitate an ongoing and multifaceted approach to security, which includes sizable budget implications. Jason underscored the importance of the 2024 fiscal year. Noting it as the first time federal budgets are being crafted with clear delineations for zero trust capabilities. This shift in focus is exemplified by the rollout of endpoint detection and response (EDR) technologies. Vital components in this architecture that ensure rigorous monitoring and real-time responsiveness to cyber threats.
Understanding the Cybersecurity EvolutionJason underscored the complexities of network security as federal entities confront the expanding cybersecurity landscape. Highlighted was the layered approach needed to fortify cybersecurity, starting with IAM. This segment illuminated the government's drive to update antiquated systems with modern identification and credentialing processes to better regulate access control. The discussion spilled into a critical analysis of data layer security, emphasizing the necessity for agencies to marshal their applications and data against unauthorized access. Furthermore, Jason hinted at the broader horizon of security measures, which now includes OT and IoT devices. The intertwining of these technologies with standard IT infrastructure adds layers of complexity for security protocols. The conversation shined a light on the massive task that lies ahead as agencies work to comprehend and safeguard the expanded network perimeters and develop strategies to encapsulate a variety of devices under a comprehensive cybersecurity shell.
The Evolution of AI in Cybersecurity: "We can take data that was 3 years ago or data over the last 3 years and look for trends that we can then use for our future. I think what they're looking for now is more real time, more immediate, especially if you think about, like, cybersecurity." — Jason Miller
Innovations and Challenges in Tech ReportingTimeliness in Problem ReportingJason believes that being proactive is vital when it comes to identifying and addressing potential issues within federal agencies. He highlighted that by the time an oversight report, such as those from the Government Accountability Office or an Inspector General's office, is made public, the concerned agency has likely been aware of the issue and has already taken steps to address it. This underlines the criticality of immediate agency reactions to problems. In the context of these reports, Jason suggested reading the agency's responses first. They provide the most current view of what's happening and the actions taken, often making them more newsworthy than the findings of the report itself.
ACT-IAC and AFCEA Gatherings Key to Cybersecurity Evolution DialogueWithout specifically endorsing any one event, Jason acknowledged the importance of various industry gatherings where government and industry leaders convene to discuss pressing topics. He emphasized the ACT-IAC and the AFCEA events as beneficial arenas that enable him to engage deeply in conversations that can lead to actionable insights and meaningful connections. He also mentioned that these events provide an opportunity to interact with federal agency leaders outside the formal constraints of an office setting. This can lead to more open and candid exchanges of ideas and experiences within the government tech community. The ACT-IAC conferences and AFCEA's branch-specific IT days, according to Jason, yield particularly high-value discussions that contribute to both immediate news items and broader thematic reporting.
Probing the Cybersecurity EvolutionJason's Insight on Federal Tech TrendsJason brings a wealth of knowledge specific to federal government technology trends. He highlights AI as a prevalent topic within current discussions. His emphasis on AI signifies the shift from its former buzzword status to a fundamental tool in federal IT arsenals, especially regarding applications in cybersecurity and immediate data analysis. Jason notes that this mirrors the pattern of past tech trends in the industry, where initial hype evolves into concrete implementations. The conversation underscores the fact that while AI is gaining traction in strategic planning and operations, it is critical to discern genuine AI adoption from mere marketing.
AI Shift Reflects Cybersecurity Evolution and Predictive Technology Integration in Government OperationsAs the conversation progresses, Jason, Carolyn and Mark explore how the vigorous enthusiasm around AI aligns with patterns observed during the advent of previous technologies. The cycle of tech trends typically begins with a surge of excitement and culminates with the practical integration of technology within government operations. Jason points out that although AI is the topic du jour, the government's drive towards embracing real-time and predictive capabilities of AI is indicative of its elevated role compared to earlier technology hypes. This shift spotlights AI's increasing value in enhancing operational efficiency and decision-making processes across various federal agencies.
Appreciating Government Employees: “There's so many great people who work for the government who want to do the right thing or trying to do the right thing, that work hard every day, that don't just show up at 9 and leave at 5 and take a 2 hour lunch." — Jason Miller
The FedRAMP Overhaul DebateRethinking FedRAMPFedRAMP's reform was a critical topic addressed by Jason, who noted industry-wide eagerness for revising the program's long-standing framework. Not only has the cost of compliance become a pressing issue for businesses aiming to secure their cloud solutions, but the time-consuming journey through the certification labyrinth has compounded their challenges. Advancements in technology and a shift towards better automation capabilities have supported the argument for modernizing FedRAMP. The white paper presented by the General Services Administration responded to such pressures with the goal of making the process more efficient. Jason also mentioned a legislative angle with Representative Connolly's involvement, marking the congressional ear tuned to the private sector's concerns about the program's current state.
Predicting the Future of FedRAMPMoving forward, while discussing federal efforts to enhance cloud security protocols, Jason described the nuances in predicting FedRAMP's evolution. He cited the Department of Defense's actions as a positive development, in which they suggested frameworks for accepting FedRAMP certifications reciprocally, depending on security levels. This reciprocity aims to foster mutual trust and reduce redundancy in security validations. However, Jason exercised caution in providing a timeline by which tangible reforms might materialize for businesses pursuing FedRAMP accreditations. Despite the uncertainties, he recognized automation, specifically via OSCAL, as a potential accelerant for the much-needed reform, bringing about quicker, more cost-effective compliance processes.
Tracking the Cybersecurity Evolution: From 2006 Data Breach to Contemporary Data Protection StrategiesAnalyzing the Cybersecurity Evolution Post-2006 Veterans Affairs Data MishandlingJason provided context on the evolution of cybersecurity. Drawing from an incident in 2006 when the Veterans Affairs department mishandled tapes containing sensitive data of millions of veterans. This episode, he explained, was an eye-opener, underscoring the importance of data security within the federal government. The aftermath was a pivot towards greater openness about cybersecurity issues. Moving away from a more secretive posture to one where sharing of information became essential for strengthening overall security. What we observe now is a more concerted effort within government circles to collaborate, engage with industry partners, and cultivate a proactive stance on cybersecurity threats, with agencies actively communicating about and learning from security incidents.
Emphasizing Data ProtectionThe conversation highlighted the criticality of data protection as it has become the nucleus of many governmental operations and decision-making processes. Since the intrusion into the Office of Personnel Management's records, there has been a palpable shift, gearing towards more robust data safeguards. Jason pointed out how being well-informed about such dynamics is crucial. Entailing an immersion in various activities such as attending industry events, networking with key players, and thorough analysis of inspector general and Governmental Accountability Office reports. Such proactive engagement helps in staying abreast of the current and emerging landscape of federal technology, especially the methodologies and strategies deployed to protect the troves of sensitive data managed by government entities.
About Our GuestJason Miller has served as executive editor of Federal News Network since 2008. In this role, he directs the news coverage on all federal issues. He has also produced several news series – among them on whistleblower retaliation at the Small Business Association, the impact of the Technology Modernization Fund and the ever-changing role of agency CIOs.
Episode Links* FedRAMP Memo * ACT-IAC Event * AFCEA Events
Can you spot a deepfake? Will AI impact the election? What can we do individually to improve election security? Hillary Coover, one of the hosts of the It’s 5:05! Podcast, and Tracy Bannon join for another So What? episode of Tech Transforms to talk about all things election security. Listen in as the trio discusses cybersecurity stress tests, social engineering, combatting disinformation and much more.
Key Topics* 04:21 Preconceived notions make it harder to fake. * 06:25 AI exacerbates spread of misinformation in elections. * 11:01 Be cautious and verify information from sources. * 14:35 Receiving suspicious text messages on multiple phones. * 18:14 Simulation exercises help plan for potential scenarios. * 19:39 Various types of tests and simulations explained. * 23:21 Deliberate disinformation aims to falsify; consider motivation. * 27:44 India election, deepfakes, many parties, discerning reality. * 32:04 Seeking out info, voting in person important. * 34:18 Honest cybersecurity news from trusted source. * 38:33 Addressing bias in AI models, historic nuance overlooked. * 39:24 Consider understanding biased election information from generative AI.
Navigating the Disinformation QuagmireDissecting Misinformation and DisinformationHillary Coover brings attention to the pivotal distinction between misinformation and disinformation. Misinformation is the spread of false information without ill intent, often stemming from misunderstandings or mistakes. On the other hand, disinformation is a more insidious tactic involving the intentional fabrication and propagation of false information, aimed at deceiving the public. Hillary emphasizes that recognizing these differences is vital in order to effectively identify and combat these issues. She also warns about the role of external national entities that try to amplify societal divisions by manipulating online conversations to serve their own geopolitical aims.
Understanding Disinformation and Misinformation: "Disinformation is is a deliberate attempt to falsify information, whereas misinformation is a little different." — Hillary Coover
The Challenges of Policing Social Media ContentThe episode dives into the complexities of managing content on social media platforms, where Tracy Bannon and Hillary discuss the delicate balance required to combat harmful content without infringing on freedom of speech or accidentally suppressing valuable discourse. As part of this discussion, they mention their intention to revisit and discuss the book "Ministry of the Future," which explores related themes. Suggesting that this novel offers insights that could prove valuable in understanding the intricate challenges of regulating social media. There is a shared concern about the potential for an overly robust censorship approach to hinder the dissemination of truth as much as it limits the spread of falsehoods.
The Erosion of Face-to-Face Political DialogueThe conversation transitions to the broader societal implications of digital dependency. Specifically addressing how the diminishment of community engagement has led individuals to increasingly source news and discourse from digital platforms. This shift towards isolationistic tendencies, amplified by the creation of digital echo chambers, results in a decline of in-person political discussions. As a result, there is growing apprehension about the future of political discourse and community bonds, with Hillary and Tracy reflecting on the contemporary rarity of open, face-to-face political conversations that generations past traditionally engaged in.
The Shadow of Foreign Influence and Election IntegrityChallenges in India’s Multiparty Electoral SystemIn the course of the discussion, the complexity of India's electoral system, with its multitude of political parties, is presented as an example that underlines the difficulty in verifying information. The expansive and diversified political landscape poses a formidable challenge in maintaining the sanctity of the electoral process. The capability of AI to produce deepfakes further amplifies the risks associated with distinguishing genuine content from fabricated misinformation. The podcast conversation indicates that voters, particularly in less urbanized areas with lower digital literacy levels, are especially vulnerable to deceptive content. This magnifies the potential for foreign entities to successfully disseminate propaganda and influence election outcomes.
Election Integrity and AI: "Misinformation and disinformation, they're not new. The spread of that is certainly not new in the context of elections. But the AI technology is exacerbating the problem, and and we as a society are not keeping up with our adversaries and social media manipulation. Phishing and social engineering attacks enhanced by AI technologies are really, really stressing stressing the system and stressing the election integrity." — Hillary Coover
Countering Foreign Disinformation Campaigns in the Digital AgeWith a focus on the discreet yet potent role of foreign intervention in shaping narratives, Hillary spotlights an insidious aspect of contemporary political warfare, the exploitation of media and digital platforms to sway public perception. This influence is not just limited to overt propaganda but extends to subtler forms of manipulation that seed doubt and discord among the electorate. As the podcast discussion suggests, the consequences of such foreign-backed campaigns could be significant, leading to polarization and undermining the foundational principles of democratic debate and decision-making. The potential for these campaigns to carry a vengeful weight in political discourse warrants vigilance and proactive measures to defend against such incursions into informational autonomy.
Addressing the Impact of Disinformation Through AI's Historical Representation BiasTackling Disinformation: AI Bias and the Misrepresentation of Historical FiguresThe discussion on AI bias steers toward concrete instances where AI struggles, as Tracy brings forth examples that illustrate the inaccuracies that can arise when AI models generate historical figures. Tracy references a recent episode where Google's Gemini model was taken offline after it incorrectly generated images of German soldiers from World War 2 that did not match historical records. Similar errors occurred when the AI produced images of America's Founding Fathers that featured individuals of different racial backgrounds that did not reflect the true historical figures. These errors are attributed not to malicious intent by data scientists but to the data corpus used in training these models. This segment underscores the significant issues that can result from AI systems when they misinterpret or fail to account for historical contexts.
The Necessity of Addressing AI BiasContinuing the conversation, Hillary emphasizes the importance of recognizing and addressing the biases in AI. She advocates for the vital need to understand historical nuances to circumvent such AI missteps. Both Hillary and Tracy discuss how biased news and misinformation can influence public opinion and election outcomes. This brings to light the critical role historical accuracy plays in the dissemination of information. They point out that to prevent biased AI-generated data from misleading the public, a combination of historical education and conscious efforts to identify and address these biases is necessary. The recognition of potential AI bias leads to a deeper discussion about ensuring information accuracy. Particularly with regard to historical facts that could sway voter perception during elections. Tracy and Hillary suggest that addressing these challenges is not just a technological issue but also an educational one. Where society must be taught to critically evaluate AI-generated content.
The Challenge of Community Scale Versus Online InfluenceCombating Disinformation: The Struggle to Scale Community Engagement Versus Digital Platforms' ReachThe dialogue acknowledges the difficulty of scaling community engagement in the shadow of digital platforms' expansive reach. Hillary and Tracy delve into the traditional benefits of personal interactions within local communities, which often contribute to more nuanced and direct exchange of ideas. They compare this to the convenience and immediacy of online platforms, which, while enabling widespread dissemination of information, often lack the personal connection and accountability that face-to-face interactions foster. The challenge underscored is how to preserve the essence of community in an age where online presence has become overpowering and sometimes distancing.
Navigating the Truth in the Digital Age: “Don't get your news from social media. And then another way, like, I just do a gut check for myself. [...] I need to go validate." — Hillary Coover
Impact of Misinformation and Deepfakes on Political DiscourseThe episode reiterates the disquieting ease with which political discourse can be manipulated through deepfakes and misinformation. Showcasing the capabilities of AI, Tracy recalls a deepfake scam involving fake professional meetings which led to financial fraud. These examples underscore the potential for significant damage when such technology is applied maliciously. Hillary emphasizes the critical need to approach online information with a keen eye, pondering the origins and credibility of what is presented. Both Tracy and Hillary stress the importance of developing a defensive posture towards unsolicited information. As the blurring lines between authentic and engineered content could have severe repercussions for individual decisions and broader societal issues.
Stress Testing and Mitigating Disinformation in Election Security StrategiesThe Role of Stress Tests in Election SecurityHillary and Tracy discuss the importance of conducting stress tests to preemptively identify and mitigate vulnerabilities within election systems. These tests, which include red teaming exercises and white hat hacking, are designed to replicate real-world attacks and assess the systems' responses under duress. By simulating different attack vectors, election officials can understand how their infrastructure holds up against various cybersecurity threats. This information can be used to make necessary improvements to enhance security. The goal of these stress tests is to identify weaknesses before they can be exploited by malicious actors. Thereby ensuring the integrity of the electoral process.
Mitigating the Impact of DisinformationThe conversation emphasizes the urgent need for preemptive measures against disinformation, which has grown more sophisticated with the advent of AI and deepfakes. As these technological advancements make discerning the truth increasingly difficult, it becomes even more crucial for election officials to prepare for the inevitable attempts at spreading falsehoods. Through stress tests that incorporate potential disinformation campaigns, officials can evaluate their preparedness and response strategies. Including public communication plans to counteract misinformation. By considering the psychological and social aspects of election interference, they aim to bolster defenses and ensure voters receive accurate information.
Election Security Concerns: "Other instances are going to happen where criminals are gonna be impersonating legitimate sources to try to suppress voters in that case, or steal credentials, spread malware." — Hillary Coover
Importance of Proactive Approaches to Election SafeguardingThe exchange between Tracy and Hillary reveals a clear consensus on the necessity of proactive strategies for protecting elections. Proactively identifying potential threats and securing electoral systems against known and hypothetical cyber attacks are central to defending democratic processes. By focusing on anticipation and mitigation, rather than simply responding to incidents after the fact, authorities can improve election security and reinforce public trust. This proactive stance is also crucial in dealing with the spread of disinformation, which may be specifically tailored to exploit localized vulnerabilities in the electoral infrastructure.
Reflecting on the Challenges of Election Security in the Digital EraThis episode serves as a thorough examination of the challenges posed by digital communication in modern democracies. They delve into the dangers of misinformation and the manipulation of public opinion, highlighting how biases in AI can affect the information that individuals receive. They underscore the importance of stress-testing election systems against digital threats and recognize the complexities inherent to securing contemporary elections. The episode ultimately helps listeners to better grasp the ever-evolving landscape of election security and the continued need for informed, strategic action to safeguard democratic processes.
About Our GuestHillary Coover is one of the hosts of It’s 5:05! Podcast, covering news from Washington, D.C. Hillary is a national security technology expert and accomplished sales leader currently leading product strategy at G2 Ops, Inc.
Episode Links* Billy Joel - Turn the Lights Back On * Deepfakes and AI: How a 200 Million Scam Highlights the Importance of Cybersecurity Vigilance * The Ministry for the Future: A Novel * It’s 5:05! Podcast
Deborah Stephens, the Deputy Chief Information Officer for the United States Patent and Trademark Office (USPTO), “grew up” so to speak in the USPTO. Deborah led the USPTO on its agile journey. As the agency took on its “New Ways of Working, '' by moving people and resources closer to the work, she helped empower employees to build and deploy software. Deborah shares how she guided the agency through this 4-year change journey, gaining buy-in from the organization, which was proved by an engagement rate increase from 75% to 85%. Deborah also talks about what it means to be a HISP, running USPTO as a business that is entirely self-sustaining, and, in honor of Women’s History Month, the women who have inspired her along the way.
Key Topics* 05:54 Some embraced digital change, others struggled with it * 08:53 Most employees were ready for telework * 10:59 USPTO shifts to agile approach for IT * 16:41 Gathering feedback led to 10% engagement increase * 23:50 Customers submit 600,000+ patent and trademark applications yearly * 26:51 Agency conducts outreach through webinars and trademarks * 31:06 Customer experience and UX processes are fundamental * 33:45 USPTO offers different fee structures for entities * 35:30 USPTO runs efficiently with prioritization and budgeting * 39:43 Acknowledging strong women, personally and professionally * 43:21 Seek guidance and practice for success
Growth in Patent and Trademark RequestsSurge in Applications at USPTODeborah Stephens highlights a significant increase in the number of patent and trademark applications received by the USPTO over the years. This growth, from approximately 350,000 to 400,000 applications in 2012, with numbers continuing to rise, underscores the vibrant culture of innovation and creativity in the United States. The upward trend of applications is a positive sign of the country's ongoing commitment to innovation. However, it also presents logistical challenges for the USPTO. Including the need to process a higher volume of applications efficiently while ensuring the quality of examination does not diminish.
Transition to New Ways of Working in U.S. Patent and Trademark Office: "And so in around late 2018, 19, we began our, what we referred to as our agile journey. We named it our New Ways of Working, which essentially is an entire USPTO effort. Including our business unit with 12 other business units, moving people and the resources closer to the work. Giving them that empowerment, to build, deliver, deploy software, product services for our business stakeholders, and that's both internally and externally." — Deborah Stephens
USPTO is Adapting to Increased DemandIn response to the growing demand for intellectual property protection, the USPTO has been proactive in seeking ways to maintain and improve service delivery. Deborah discusses the agency's approach to managing the influx of applications, focusing on scalability and efficiency. Despite the challenges posed by the increase in applications, the USPTO's designation as a High Impact Service Provider (HISP) has had minimal impact on its existing customer experience strategy. The agency's foundational commitment to delivering exceptional service to inventors and entrepreneurs remains steadfast. With an emphasis on continuous improvement and the adoption of new strategies to better meet the needs of the U.S. innovation community.
USPTO's Fee-Funded Model and Fiscal StrategyUSPTO’s Fee-Funded OperationsDeborah highlights the United States Patent and Trademark Office's (USPTO) operational model, which is uniquely self-sufficient. Relying entirely on fees collected from patent and trademark applications. This model ensures that the USPTO does not use taxpayer dollars, setting it apart from many other government agencies. By directly linking the agency's funding to the services it provides, the USPTO aligns its goals closely with the needs and successes of its primary users: inventors and businesses seeking intellectual property protection. This connection incentivizes the agency to continuously improve its processes and customer service. Additionally, Deborah mentions a tiered fee system that offers different rates for entities of various sizes. From individual inventors to large corporations. This structure is designed to lower barriers for smaller entities and encourage a wider range of innovation.
USPTO’s Budgetary Discipline and ManagementFacing economic pressures such as inflation, the USPTO's approach to budget management becomes even more pivotal. Deborah discusses the importance of prioritization and strategic decision-making in maintaining the agency's financial health. Despite rising costs, the USPTO strives to keep its budget stable and even reduce it when possible, demonstrating a high level of fiscal responsibility. This is achieved through careful analysis of projects and initiatives, focusing resources on areas that promise the highest impact. The USPTO's disciplined budgetary approach not only ensures its operations are sustainable but also serves as a potential model for other federal agencies. By showcasing how to effectively manage finances in a challenging economic environment, the USPTO underlines the value of strategic planning and prioritization in government fiscal strategy.
Telework Readiness and Agile Transformation at USPTOUSPTO’s Transition to Telework Prior to COVID-19Deborah highlights the USPTO's preparedness for telework well before the COVID-19 pandemic. With a significant portion of the workforce already equipped and familiar with remote working protocols, the USPTO had laid a robust foundation for telework readiness. This foresight into establishing a telework culture not only ensured the continuity of operations during unprecedented times. It also underscored the agency's commitment to leveraging modern work practices. The transition to a fully remote working environment, necessitated by the pandemic, was thus more seamless for the USPTO than for many other organizations. Demonstrating a proactive approach to business continuity planning.
Introducing Change in Remote Work Environments: "There were every 2 weeks of what we refer to as, lunch and learns. And in the beginning, I was the prime speaker, saying, here's our New Ways of Working. Here's the structure. Here's how we're gonna move our processes, our procedures, and people would join in. And it was all remote. I'd have a big TV like producer kind of studio, and I'd be in front of the blue screen and talking to them about this change at least every 2 weeks, if not, sometimes more." — Deborah Stephens
Agile Transformation and Cultural Shift at USPTOThe shift from traditional waterfall methods to agile methodologies marked a significant transformation within the USPTO. Deborah emphasizes that this transition was not merely about changing project management techniques. It involved a deeper cultural shift within the organization. Achieving buy-in from both individuals and teams was crucial to fostering an environment that embraced agility, empowered employees and encouraged rapid deployment of products. Key to this cultural transformation were regular remote meetings and employee engagement surveys. This played a significant role in understanding and enhancing employee satisfaction. The notable increase in engagement levels from 75% to 85% during this period of change illustrates the effectiveness of the USPTO's approach in not only implementing agile methodologies but also in cultivating a culture that is receptive and adaptive to change.
Tech Landscape and Patent Filing Insights at USPTOUSPTO’s "Fail Fast, Fail Forward" ApproachDeborah shares the USPTO's dynamic approach to technological innovation, encapsulated in the mantra "fail fast, fail forward." This methodology allows the USPTO to quickly test new ideas and technologies, while learning from any setbacks, and refining their strategies efficiently. By fostering an environment where experimentation is encouraged and failure is seen as a stepping stone to success, the agency ensures that it remains at the forefront of technological advancements. This approach is crucial in a rapidly changing tech landscape, as it enables the USPTO to adapt and innovate continuously. Deborah highlights how this philosophy has led to a more agile and responsive IT infrastructure within the agency. One capable of meeting the demands of modern patent and trademark processing.
The Value of Mentorship: "I think you need to establish your go-to network of mentors, and don't be afraid to become a mentor." — Deborah Stephens
Emphasizing Customer Feedback in Patent and Trademark SubmissionsCarolyn brings attention to the importance of customer feedback in the process of patent and trademark submissions at the USPTO. Deborah explains how the agency values the insights gained from customer experiences and actively seeks out feedback to improve services. Through a variety of channels such as webinars, outreach programs and direct communication through customer service teams, the USPTO gathers valuable input from those who navigate the patent and trademark submission processes. This dedication to understanding and addressing the needs and challenges of its customers has led to significant enhancements in the USPTO's support structures. Deborah further discusses educational efforts aimed at demystifying the complexities of the patent filing process. Thereby making it more accessible and navigable for inventors and businesses alike.
Digital Transformation at USPTOUSPTO’s Move from Paper-Based to Digital SystemsDeborah played a significant role in transitioning the agency from a paper-based application system to a fully digitized process. This monumental task involved not just the scanning of existing paper documents, but also includes integrating OCR technology to make historical patents searchable and accessible in digital form. Despite the sheer scale and potential logistical challenges of digitizing vast amounts of data, the initiative marked a pivotal moment in the agency's history. This transformation was not without its hurdles. Initial resistance to change was a significant barrier that needed careful navigation. However, through strategic planning and a commitment to modernization, the USPTO successfully overcame these challenges. Leading to a more efficient, accessible and streamlined patent application process.
Efficient Budget Management at the USPTO: "Being able to maintain our budget or even maybe decrease the overall budget by 1%, but yet inflation going up 8, 9%, we've been able to do that. And it's about prioritization, and that's part of our New Ways of Working." — Deborah Stephens
About Our GuestDeborah Stephens is the Deputy Chief Information Officer (DCIO) for the United States Patent and Trademark Office (USPTO). She has served at the USPTO for more than 30 years in multiple leadership roles, during which she has worked to improve the automated tools and informational resources that facilitate electronic processing of patent applications. In her current role, Deborah is the principal advisor to the Chief Information Officer (CIO) and responsible for managing day-to-day operations of the Office of the Chief Information Officer (OCIO) with significant oversight on information technology (IT) stabilization and modernization efforts. She guides teams towards continual improvements in IT delivery for maximum value to all stakeholders.
Episode Links* High Impact Service Providers (HISPs) * USPTO Fee Schedule * Women’s History Month Blog
As technology rapidly evolves we as a nation need to anticipate the attacks that may come about as a result of that innovation. Travis Rosiek, the Public Sector CTO at Rubrik and former Leader at the Defense Information Systems Agency (DISA), joins Tech Transforms to talk about how the government’s approach to technology and relationship with industry has evolved over the last twenty years. He also discusses compliance, including FedRAMP compliance, managing the vast amount of data that is generated daily across the government and industry, and the importance of the U.S. Government building cyber resilient systems. Catch all this and more on this episode of Tech Transforms.
Key Topics* 00:00 Government fielded and tested tech capabilities, explained compliance. * 05:23 Enhanced security collaboration, compliance, and risk minimization. * 09:14 Experience in government and commercial capabilities. Innovation. * 10:12 Commercial companies prioritize profitability over long-term planning. * 14:38 Challenges in public sector recruiting and retention. * 18:49 Outsourcing SaaS applications frees up resources. AI evolving, human input remains essential. * 22:33 Assessing incident response: Operational evaluation, not just compliance. * 25:57 Vendors and program office face process challenges. * 29:46 Secure cloud data access: visibility, risks, controls. * 32:27 Emphasizing need for security in IT systems. * 36:44 CISOs face challenges in evolving tech landscape. * 38:11 Support CISOs, recruit and retain talent, accountability.
Evolving Cybersecurity Practices: A Shift to 'Cloud Smart' StrategiesTravis's Perspective on Cloud MisconceptionsTravis discusses the early days of cloud adoption, which were often fueled by misconceptions about its benefits. The migration toward cloud computing was commonly believed to be a cost-effective solution that would reduce expenses and simultaneously enhance security. However, he points out that this was not always the case. Many organizations have since realized that the initial cost of moving to the cloud can vary greatly based on specific use cases and applications. This realization has led to a strategic shift toward what Travis refers to as a "cloud smart" approach. Highlighting the need for a more discerning and tailored evaluation of how cloud resources are utilized.
The Role of Commercial Companies vs. Government in Problem-Solving: "Industry is great about solving problems. You know, driving that capitalism type of culture, building capabilities, selling solutions. And they're quicker to implement, adapt and deploy capabilities where the government is very slow in implementation of these you know, they can figure out the problem." — Travis Rosiek
The 'Cloud Smart' Strategic ApproachTaking a "cloud smart" approach indicates a maturation in the perception of cloud services by government agencies and businesses alike. Rather than a blanket strategy of cloud-first, Travis indicates that there is now a more nuanced consideration of when and how to use cloud services. He underscores the importance of aligning cloud adoption with an organization's unique needs. Including the potential scalability, security and cost implications. This approach suggests a collaborative and informed decision-making process. Recognizing that the cloud offers a variety of solutions, each with different features, advantages and trade-offs that must be carefully weighed against organizational goals and objectives.
Navigating Cybersecurity Practices in Cloud MigrationThe Balance of Technical and Non-Technical Implications in Cloud MigrationTravis discusses the intricacies involved in organizational cloud migrations. Emphasizing that these undertakings are not solely about technological transitions but also encompass a variety of non-technical considerations. The shift to cloud-based services goes beyond mere data storage and infrastructure changes. It affects strategic business decisions, financial planning and operational workflows. Necessitating a comprehensive evaluation of both the potential benefits and the challenges. Organizations must be acutely aware of the detailed shared responsibility models that cloud service providers outline, which delineate the security obligations of the provider versus the customer. Understanding these responsibilities helps in effectively managing the risks associated with cloud computing.
The Importance of Human Oversight in AI: "But you still can't take the human out of the loop." — Travis Rosiek
The Demand for Advanced Cybersecurity Practices in Multi-Cloud EnvironmentsTravis highlights a significant challenge in the cybersecurity landscape, which is the scarcity of skilled professionals equipped to manage and protect complex multi-cloud and hybrid environments. As organizations increasingly adopt a mix of cloud services and on-premises solutions, the demand for cybersecurity practitioners with the necessary expertise to navigate this complexity grows. However, attracting and retaining such talent is difficult due to competitive job markets and the limitations of government pay scales. This is compounded by the extensive skill set required for modern cloud environments, including not only security but also knowledge of cloud architecture, compliance and various cloud-specific technologies. Travis underscores the need for specialized personnel capable of addressing the advanced cybersecurity concerns that arise from this intricate, dynamic infrastructure.
The Evolution of FedRAMP ComplianceFedRAMP Compliance: A Shared BurdenTravis sheds light on the evolution of the Federal Risk and Authorization Management Program (FedRAMP), a government-wide program that promotes the adoption of secure cloud services across the federal government by providing a standardized approach to security assessment, authorization and continuous monitoring. While it is often perceived as a costly and time-consuming barrier for vendors seeking to serve government clients, Travis emphasizes that the journey to FedRAMP authorization is not the sole responsibility of vendors. Government sponsors engaged in this process also bear a significant load. This dual burden requires commitment and collaboration from both parties to navigate the complexities involved in achieving FedRAMP compliance.
Strategic Cybersecurity Practices to Navigate FedRAMP Compliance ChallengesTravis goes into further detail regarding the collaborative challenges of attaining FedRAMP compliance. On the government side, a sponsor’s role in shepherding vendors through the process can be incredibly taxing due to staffing and resource constraints. Furthermore, the procedural nature of the FedRAMP framework can prove to be a linear and lengthy ordeal for all involved. Travis suggests that greater investment to ease the procedural efforts for government stakeholders could potentially improve the efficiency of the overall process, helping it to mature and ultimately relieving some of the burden for both vendors and government sponsors.
Addressing Data Volume and Security Risks in Modern Cybersecurity PracticesData Categorization and ClassificationCarolyn highlights the daunting challenge of classifying the vast amounts of data that individuals and organizations are responsible for. Travis acknowledges this burden, especially given the exponential growth of data in today's digital landscape. He underscores that as data multiplies rapidly and spreads across various platforms – from cloud services to mobile devices – accurately categorizing and classifying it becomes more critical yet more difficult. Ensuring the security and proper handling of this data is paramount as mismanagement can lead to significant security breaches and compliance issues.
Cybersecurity in the Era of Cloud and Mobile Computing: "If you can't answer some of those basic questions on visibility, you're gonna struggle protecting it." — Travis Rosiek
Adapting Cybersecurity Practices to Combat Data Volume SurgeTravis points to a report produced by Rubrik Zero Labs that sheds light on the continuous surge in data volume within organizations, often experiencing growth by significant percentages over short periods. This expansion amplifies the challenge of safeguarding critical information. Moreover, the need to provide accurate access control increases in complexity when data resides in a hybrid environment. This includes multiple clouds, on-premise servers, and SaaS applications. The continuous monitoring and protection of data across these diverse and dynamic environments present an ongoing challenge for data security professionals.
Complexities in Data Access ControlsCarolyn and Travis discuss the need for visibility in distributed data environments, as knowing what data exists, where it is stored and who has access to it is fundamental to securing it. Travis advocates for the NIST Special Publication 800-160 as an additional resource that can guide organizations toward building cyber resilient systems. Its principles of anticipating, withstanding, recovering and adapting offer a strategic approach to not just responding to cyber threats. It also prepares for and prevents potential data breaches in complex IT and data environments.
Strategic Alignment of Cybersecurity Practices with Governmental Objectives and Zero Trust PrinciplesAligning Cybersecurity Practices with Governmental ObjectivesWhen considering the acquisition of technology within government entities, Travis highlights the importance of aligning with governmental objectives. Especially when it pertains to national defense, scalability becomes a paramount factor, as the technology adopted must cater to expansive operations and adhere to rigorous standards of security and efficiency. In the military and defense sectors, technologies must not only serve unique and highly specialized purposes but also be viable on a large scale. Travis notes that achieving this balance often requires a nuanced approach that can accommodate the specific needs of government operations, while also being mindful of the rapidly evolving landscape of technology.
Cybersecurity and Organizational Resilience: "Having a false sense of security, you know, in anything we build, overly trusting things or having a false sense of security, is probably our Achilles' heel." — Travis Rosiek
Emphasizing Security Principles and Zero TrustTravis underscores the central role of security principles in the process of technology acquisition and he places particular emphasis on the concept of Zero Trust. An approach to cybersecurity that operates on the assumption that breaches are inevitable and thus requires constant verification of all users within an organization's network. Travis argues that adopting a zero trust framework is crucial for government agencies to protect against a vast array of cyber threats. By following this principle, organizations can ensure that their acquisition of technology not only meets current operational demands but is also prepared to withstand the sophisticated and ever-changing tactics of adversaries in cyberspace.
The ABCs of Technology ImplementationThe Adoption, Buying and Creating StrategyTravis reflects on a strategic approach he learned during his tenure at DISA, known as the ABCs. A methodology imparted by then DISA director General Charlie Croom. This strategy prioritizes the use of existing commercial technologies, emphasizing 'adoption' as the primary step. By leveraging commercially available tech, organizations can tap into advanced capabilities and integrate them into their operations swiftly. The 'buy' component encourages the procurement of already fielded technologies or platforms. This may not be commercially created but has been proven in practical governmental applications. Lastly, 'create' is seen as a last resort. Reserved for instances where the needs are so specialized or critical that a bespoke solution is warranted. Often due to unique use cases or strict national security concerns.
Strategic Balancing of Commercial Speed and Government Foresight in Cybersecurity PracticesIn discussing the rationale behind the ABCs framework, Travis reveals the nuanced balance required in government tech implementations. While commercial entities' speed to deploy novel solutions can address particular gaps, government institutions often play a crucial role in identifying and tackling long-term, complex challenges. Especially in defense, the need to build solutions from the ground up may arise when existing products fail to meet the stringent requirements of security-sensitive operations. Conversely, commercial technology's versatility is a critical asset. This marked a shift from the government's historical tendency to primarily develop its own technology solutions. Travis urges organizations to use this strategic framework to make informed, prudent decisions that consider both immediate needs and long-term strategic objectives.
About Our GuestTravis Rosiek is a highly accomplished cyber security executive with more than 20 years in the industry. He has built and grown cybersecurity companies and led large cybersecurity programs within the U.S. Department of Defense (DoD). His experience spans driving innovation as a cybersecurity leader for global organizations and CISOs, to corporate executive building products and services. His impact has helped lead to successful IPOs (FireEye) and acquisitions (BluVector by Comcast).
As a Cyber Leader in the U.S. DoD, he has been awarded the Annual Individual Award for Defending the DoD’s Networks. Travis currently serves as the Public Sector CTO at Rubrik helping organizations become more cyber and data resilient. Prior to Rubrik, Travis held several leadership roles including the Chief Technology and Strategy Officer at BluVector, CTO at Tychon, Federal CTO at FireEye, a Principal at Intel Security/McAfee and Leader at the Defense Information Systems Agency (DISA).
He earned a Certificate from GWU in Executive Leadership and graduated from West Virginia University with Honors while earning multiple Engineering degrees. He also was one of the first of ten students from across the nation to be awarded a scholarship from the DoD/NSA’s in cybersecurity. His pioneering mindset has helped him better secure our nation and commercial critical infrastructure. Additionally, Travis is an invited speaker, author (blogs, journals, books) and has also served on the NSTAC, ICIT Fellow and multiple advisory boards.
Episode Links* Rubrik Zero Labs * NIST 800-53 * NIST 800-160
Sebastian Taphanel has spent his life on the cutting edge of technology and innovation. This week on Tech Transforms, Sebastian is sharing tales and lessons learned from his 20 years in DoD Special Ops and intelligence and 20 years implementing sound security engineering practices focused on implementing zero trust and highly resilient environments. Join Sebastian as he recounts his time in Special Forces taking his units out of the dark ages from secure fax communications to setting up an intranet, and how he continued with that innovative spirit through his 40-year career. He also shares his new passion, encouraging the industry to utilize disabled veterans to help fill both the cybersecurity and AI workforce gaps. They, after all, already have a call for the mission.
Key Topics* 03:38 ODNI CIO responded quickly with Microsoft Azure. * 07:03 Protecting data via application container, expanding capabilities. * 11:01 Zero Trust redrawn cybersecurity model, data-centric approach. * 13:57 Developing zero trust plan for downstream organizations. * 18:50 Ensuring security while sharing information and protecting IP. * 21:35 APIs, containers enable fluid, flexible data access. * 24:20 Data protection systems allow secure sharing and storage. * 27:02 Addressing cybersecurity workforce gap and AI need. * 29:39 In 1998, new commander requests secure WAN. * 33:49 Applied for certified protection professional, highest security certification. * 36:28 Passionate about supporting disabled vets in cybersecurity. * 39:55 Mentoring government employees for cybersecurity and AI/ML. * 45:32 Using advanced generative AI solutions for copywriting. * 47:19 Update cybersecurity tools and systems for new threats. * 49:50 Respect for those dedicated to automation.
Enhancing Secure Communication and Cloud Environments in Special OpsSpecial Ops Agility: Adapting to Remote Collaboration with Secure Cloud-Based WorkspacesSebastian Taphanel’s experience spans twenty years in DOD Special Ops and Intelligence, followed by consulting in security engineering. The focal point of this episode is his role in advancing cybersecurity practices at the ODNI. Particularly emphasizing resilient cloud-based environments.
Sebastian describes the quick adaptation during the pandemic which led to the rollout of an ad hoc cloud-based workspace to ensure the ODNI's mission could endure despite the workforce being remote. GCC High, or Government Commercial Cloud High as conceived by Microsoft, is revealed as the successor to the initial setup. Providing a more secure platform managed strictly by U.S. persons. The approach highlighted the agility of cloud technology for remote collaboration within federal agencies.
Cybersecurity in Intelligence Sharing: "Essentially, reciprocity is a process and also a culture of accepting each other's risks. And that's really the bottom line on all that." — Sebastian Taphanel
Unfolding the GCC High EnvironmentThe intricacies of implementing Microsoft Azure and M365 (Office 365) are detailed as Sebastian underlines their pivotal use in creating an intranet with controlled document sharing and editing. These implementations include robust Mobile Device Management. Then a BYOD Mobile Application Management system that protects sensitive data in government and personal devices. Thereby, ensuring operational security and flexibility.
Special Ops Communication EvolutionSebastian advanced from using secure faxes for interstate communication within military units to establishing a multi-state secure WAN. This resulted in a significant leap in communication efficacy for special operations. Sebastian shared the potency of secure, cloud-based tools in streamlining and securing government communications. As well as their inherent adaptability to contemporary operational needs.
Zero Trust Implementation and Reciprocity in Security Controls: "Reciprocity, in some circles, it's a dirty word. Because everybody wants to do it, but nobody really wants to be first." — Sebastian Taphanel
The Shift to Cybersecurity Training and AI Special Ops to Cyber Ops: Training Disabled Veterans to Bridge the Cybersecurity Workforce GapSebastian recognizes the increasing importance of cybersecurity expertise in today's digital landscape. He points out the significant gap in the cybersecurity workforce and the untapped potential of disabled veterans who can be trained to meet this demand. This shift towards prioritizing cybersecurity skills reflects the industry's evolution as organizations increasingly rely on digital infrastructure. Thus, creating a fertile ground for cyber threats. By focusing on equipping disabled veterans, who already possess a strong sense of duty and protection, with the necessary technical skills to combat these threats, Sebastian believes that we can build a robust cybersecurity force that benefits not just the veterans but the nation's overall security posture as well.
Training Disabled Veterans for Cybersecurity and AIBuilding upon his own transition from a military career to cybersecurity, Sebastian is passionate about creating opportunities for disabled veterans in the field. His experience has shown him that these individuals, with their ingrained ethos of national service, can continue their mission through careers in cybersecurity and artificial intelligence. Sebastian advocates for collaborations with major tech companies and training providers to establish programs specifically tailored for veterans. These developmental opportunities can help translate military competencies into civilian technology roles. As AI continues to influence various industry sectors, including cybersecurity, the need for skilled professionals who can leverage AI effectively is critical. By providing appropriate training and mentorship, Sebastian sees disabled veterans playing an integral role in shaping the future of cybersecurity and AI.
Special Ops Veteran Illuminates Zero Trust as a Data-Centric Security Model and the Strategic Role of AI in CybersecurityZero Trust as a Data-Centric Security ModelIn the evolving landscape of cybersecurity, Sebastian brings to light the concept of zero trust. A framework pivoting away from traditional perimeter security to a data-centric model. He highlights zero trust as a foundational approach, which is shaping the way organizations safeguard their data by assuming no implicit trust, and by verifying every access request as if it originates from an untrusted network. Unlike the historical castle-and-moat defense strategy which relied heavily on securing the perimeters of a network, this paradigm shift focuses on securing the data itself, regardless of its location. Zero trust operates on the fundamental belief that trust is a vulnerability. Thereby, anchoring on the principle that both internal and external threats exist on the network at all times. It necessitates continuous validation of the security posture and privileges for each user and device attempting to access resources on a network.
Zero Trust as a Data-Centric Security Model:“Zero trust now has essentially redrawn the lines for cybersecurity professionals and IT professionals. And I will say it’s an absolutely data-centric model. Whereas in previous decades, we looked at network centric security models.” — Sebastian Taphanel
Implementing Zero Trust in Special OpsZero trust extends beyond theoretical formulations, requiring hands-on execution and strategic coherence. As Sebastian explains, the principle of reciprocity plays a vital role in the context of security authorizations among different agencies. It suggests that the security controls and standards established by one agency should be acknowledged and accepted by another. Thus, avoiding redundant security assessments and facilitating smoother inter-agency cooperation. However, applying such principles in practice has been sporadic across organizations, often hindered by a reluctance to accept shared risks. Driving home the notion that strategic plans must be actionable, Sebastian underscores the critical need to dovetail high-level strategies with ground-level tactical measures. Ensuring these security frameworks are not merely aspirational documents but translate into concrete protective actions.
Special Ops in Cybersecurity: Harnessing AI and ML for Enhanced Defense CapabilitiesAmidst rapid technological advances, artificial intelligence (AI) and machine learning (ML) are being called upon to bolster cybersecurity operations. Sebastian champions the idea that AI and ML technologies are indispensable tools for cyber professionals who are inundated with massive volumes of data. By synthesizing information and automating responses to security incidents, these technologies augment the human workforce and fill critical gaps in capabilities. The agility of these tools enables a swift and accurate response to emerging threats and anomalies. Allowing organizations to pivot and adapt to the dynamic cyber landscape. For cybersecurity operators, the incorporation of AI and ML translates to strengthened defenses, enriched sense-making capabilities, and enhanced decision making processes. In a field marked by a scarcity of skilled professionals and a deluge of sophisticated cyber threats, the deployment of intelligent systems is no longer a luxury, it is imperative for the preservation of cybersecurity infrastructures.
Looking Ahead: Collaboration, Reciprocity and AI/ML WorkforceAI/ML as a Cybersecurity Force MultiplierSebastian highlights the untapped potential of artificial intelligence and machine learning (AI/ML) as critical tools that can amplify the capabilities within the cybersecurity realm. As Sebastian provides his insights on the importance of AI/ML, it becomes clear that these technologies will serve as force multipliers, aiding overwhelmed cybersecurity professionals dealing with vast arrays of data. The envisaged role of AI/ML is to streamline sense making processes and facilitate prompt, accurate cyber response actions to threats and vulnerabilities. Sebastian portrays a future where strategic use of AI/ML enables swift and informed decision-making, freeing cybersecurity operatives to focus on critical tasks that require their expertise.
AI/ML as a Cybersecurity Force Multiplier: “I believe what’s going to be needed is the understanding, a training and culture that accepts AI/ML as an enabler.” — Sebastian Taphanel
Empowering Special Ops Veterans for the Future Cybersecurity and AI/ML WorkforceSebastian asserts the urgency to prepare and equip individuals for the cybersecurity and AI/ML workforce. He envisions an actionable plan to invigorate the employment landscape, creating a resilient front in the fight against cyber threats. Sebastian calls for a strategic focus on training and knowledge dissemination, particularly for disabled veterans, to incorporate them into positions where they can continue serving the nation's interests in the digital domain. Recognizing the fast evolving nature of these fields, he stresses the need for a workforce that not only understands current technologies but can also adapt to emerging trends. Ensuring that collective efforts in data protection and cybersecurity are robust and responsive to an ever-changing threat landscape.
About Our GuestSebastian Taphanel blends a more than 20-year DoD Special Ops and intelligence career with more than 20 years of sound security engineering practices focused on implementing Zero Trust and highly resilient environments through the use of innovative technologies and common sense business practices.
The real question is, what doesn’t Dr. Amy Hamilton do? She’s currently the visiting Faculty Chair for the Department of Energy (DOE) at National Defense University and the DOE Senior Advisor for National Cybersecurity Policy and Programs, and has had previous stops in the U.S. Army Reserves, NORAD and U.S. European Command, just to name a few.
At National Defense University, Amy draws on all of this expertise to educate the workforce on AI and finding the right balance between automation and workforce training. Amy also explores how she teaches her students that cybersecurity has to be more than a 9-5 job, the balance of security vs. convenience, and how it will take the entire country getting on board to make the implementation of cybersecurity best practices truly possible. In this episode, we also dive into the realm of operational technology and the need to look to zero trust as we allow more smart devices into our lives and government ecosystems.
Key Topics* 00:00 Importance of training, education and AI integration. * 06:52 Cybersecurity, AI and building codes challenges. * 09:47 Nuclear facilities need caution, open labs innovative. * 11:58 Helping students understand federal government and cybertech. * 15:37 Cyber college compared to traditional university programs. * 17:18 National Defense University offers master's degree programs. * 22:06 Addressing the urgent need to combat intellectual property theft. * 24:32 Passionate plea for cybersecurity vigilance and dedication. * 26:40 Using automation to streamline cybersecurity operations and training. * 32:06 Policy person struggles to tie guidance together. * 33:02 Collaboration is needed for addressing industry issues. * 38:25 Rethink security for devices in smart tech. * 41:16 Choosing sustainability as a guiding principle. * 43:22 Overcome writing and presenting challenges for success.
Leveraging AI and Automation for Cyber InnovationEmphasizing Efficiency in the Generation of AbstractsDr. Amy Hamilton underlines the capabilities of artificial intelligence to streamline time-consuming processes, specifically the creation of abstracts. This innovation allows for a transition from mundane, repetitive tasks to pursuits that require a deeper cognitive investment. Therefore, elevating the nature of the workforce's endeavors. Dr. Hamilton's discussion focuses on the practical applications of this technology, and she cites an instance from the National Defense University's annual Cyber Beacon Conference. Here, participants were challenged to distinguish between AI-generated and human-generated abstracts, often finding it challenging to tell them apart. This exercise not only highlighted AI's proficiency but also introduced the workforce to the safe and practical application of this emergent technology.
How do we use AI in a way that goes from low-value to high-value work? If I'm not doing abstract, what other things could I be doing and spending my brain calories towards? - Dr. Amy Hamilton
Preparing the Workforce for Cyber InnovationDr. Hamilton stresses the necessity for workforce education in the context of AI and automation. Aiming for a future where employees are neither intimidated by nor unfamiliar with the advancing technological landscape. She illustrates the Department of Energy's proactive role in integrating AI into its training programs. Thus, ensuring that employees are well-acquainted with both the operational and potential ethical dimensions of AI deployment. Acknowledging the diverse range of operations within the DOE, including nuclear and environmental management, Dr. Hamilton notes that the appropriateness of AI application varies by context. Signifying the department's nuanced approach to the introduction of these technologies. Through education and exposure to use cases within a controlled environment, Dr. Hamilton envisions a workforce that is not only comfortable with AI but can also leverage it to enhance productivity and safety in their respective fields.
Cyber Innovation and Collaboration in Government EnvironmentsDr. Hamilton's Role at National Defense UniversityAmy serves as a crucial beacon for educating Department of Defense personnel on comprehensive government functions. With a focus on the distinct agencies and their interaction within the broader governmental ecosystem, she acts as a conduit, clarifying for her students the intricate dance of interagency collaboration. Grants of knowledge on how certain branches, like the Treasury, interact during cyber events. Or the functions of varied components within the agency, serve to demystify the convoluted nature of interdepartmental cooperation. Her teaching elevates students' comprehension of the interconnected roles and responsibilities that propel our government forward.
Environment for Cyber InnovationAt National Defense University, there's a particular distinction made between no-tolerance environments. Such as nuclear facilities, where repetitiveness and extreme scrutiny are valued over experimentation and open science labs that thrive on creativity and incessant innovation. Dr. Amy Hamilton underlines this dichotomy. She established the need for both the rigid reliability of technology in some contexts and the unabated exploration for new horizons in others. These contrasting settings ensure the Department of Energy's multifaceted missions are maneuvered through a lens of both caution and curiosity. Across a breadth of projects from the highly sensitive to the openly experimental.
Attracting Talent to Federal GovernmentThe College of Information in Cyberspace, where Amy engages with the bright minds of the defense community, presents an academic path tailored for mid to senior career professionals. With a suite of master's degrees and certificate programs, the college not only imparts education but also fosters an ecosystem ripe for nurturing government leaders of the future. Despite the widespread perception of financial hurdles within government roles compared to private sectors, Dr. Hamilton articulates a potent alternative allure. The mission-driven nature of public service. This inherent value proposition attracts those who yearn to contribute to a greater cause beyond monetary gain, ensuring a continual influx of devotion and expertise within federal ranks.
So I think there's a huge amount of value of what flexibility of recognizing industry experience in cybersecurity can be very, very useful. But I also think, like, how do we attract people in the federal government when we don't have that kind of financial ability to reward? And I think it's reward by mission. - Dr. Amy Hamilton
Fostering Diversity and Cyber InnovationCyber Outreach and Advocating DiversityDr. Hamilton touches on the vital role of cyber outreach and advocating for diversity in the field of cybersecurity. She brings up Kennedy Taylor, who is making strides as Miss Maryland by combining her cyber expertise with her platform in beauty pageantry. She engages and educates young people, especially girls, about the significance of cybersecurity. Amy highlights the potential of such outreach efforts to challenge and change the stereotypes associated with cybersecurity professionals. By leveraging the influence of figures like Miss Maryland, there's an opportunity to inspire a diverse new generation of cybersecurity experts who can bring fresh perspectives to tackling the industry's challenges.
The Need for Cyber InnovationThroughout the discussion, Dr. Amy Hamilton stresses the increased frequency and severity of cybersecurity threats that have surfaced recently. Acknowledging that the traditional cybersecurity models are faltering under these new strains. She calls for innovative thinking and proactive measures to be adopted. Amy notes that measures used in the past, such as security through obscurity, no longer suffice due to the complex and interconnected nature of modern technology. This new reality requires the cybersecurity sector to evolve and embrace zero-trust principles among other modern strategies to safeguard against the continually evolving threat landscape.
How do we correct, just swiftly get around to being able to apply those patches and things that we need to do? And we have to get better out of it because our adversaries are. Our adversaries were taking advantage of this every single day. - Dr. Amy Hamilton
Addressing Risk Aversion in CybersecurityIn discussing the inherent risk-aversion in human nature, Dr. Hamilton points out that despite this tendency, convenience often trumps caution, leading to increased vulnerabilities. She suggests that the answer is not to shy away from innovation for fear of risks, but rather utilize it to enhance the safety and functionality of technological systems. Dr. Hamilton also highlights the crucial role that industry partnerships play in this context, suggesting that collaboration between government and private sectors is essential in developing effective and robust cybersecurity defenses. By working together, these entities can find the balance between convenience and security, ensuring a safer digital environment for all users.
Challenges in Implementing Cyber InnovationImportance of User Experience in Cyber InnovationDr. Amy Hamilton brings attention to the crucial role that user experience plays when incorporating automation into the workforce. She contrasts the tedious and often frustrating nature of conventional cybersecurity practices, such as manually sifting through logs, with the potential ease automation can provide. Amy uses the example of e-commerce, where users intuitively navigate online shopping without the need for training to illustrate her point that intuitive design is key to user acceptance of automated systems. By adopting user-friendly automation, employees' tasks can be streamlined allowing them to focus on more complex and engaging aspects of their work.
And so I think that we need to really realize that user experience is important. - Dr. Amy Hamilton
AI and Automation in Everyday LifeReflecting on her experience with AI in website design, Amy describes the simplicity and efficiency brought by AI-assisted tools that automatically generate content based on keywords. Thus eliminating the need for extensive technical knowledge in web development. This underscores the tangible benefits of automation for individuals without a background in coding. Moreover, Amy emphasizes the societal shift toward greater reliance on automated systems by referencing Disney World as a model of successful automation integration. The theme park's seamless integration of automated booking systems, fast passes and reservations highlight how well-designed automation can augment the customer experience and efficiency in large-scale operations.
Partnerships in Cyber InnovationThe dialogue shifts toward the collaborative effort required to tackle cybersecurity breaches. Dr. Hamilton mentioned the expansive SolarWinds incident as a key example where AI and automation have a role to play. Amy underscores the significance of industry partnerships and a unified national approach for enhancing cybersecurity. The incident illustrates that automated tools and AI are not only about convenience, they are instrumental in swiftly identifying and rectifying vulnerabilities in complex digital systems. By automating these processes, agencies can respond more effectively to cybersecurity threats, underscoring the need for automation that complements and enhances human efforts in maintaining security.
Educational TechnologiesAmy advocates for the use of educational tools like Khan Academy, which can benefit children by offering a controlled environment for learning. She stresses the importance of early cybersecurity awareness, suggesting that exposure to best practices should align with the first use of digital devices. This early introduction to cybersecurity principles, aided by educational technologies, is vital in preparing the next generation to navigate the expanding digital frontier securely. Automation in education, therefore, serves a dual purpose, streamlining the learning process while simultaneously fostering a culture of digital safety awareness from a young age.
Executive Orders and Collaboration for Cyber InnovationThe Administration's Challenges in Artificial Intelligence RegulationDr. Amy Hamilton discusses the executive order on artificial intelligence. She acknowledged the inherent challenges of being a government pioneer in regulating groundbreaking technology. She compares the order to earlier attempts at cybersecurity regulation and the long-standing effects those have on policy today. Dr. Hamilton predicts that in hindsight, we may perceive today's orders as early steps in an evolving landscape. Given her past experience at the OMB executive office of the president, she understands the complexity of crafting policy that will need to adapt as technology progresses.
Collaborative Efforts for Cybersecurity Workforce DevelopmentDr. Amy Hamilton underlines the need for collaborative synergy between government and industry to foster a robust cybersecurity workforce. With growing intellectual property theft, especially from China, she stresses that safeguarding proprietary information is not just an industry burden but also a national and allied concern. Dr. Hamilton points out that partnerships with non-profit organizations play a vital role in shaping a national response to cybersecurity challenges. Such alliances are vital for maintaining cybersecurity and counteracting espionage activities that impact not only the US but also its international partners.
Public Awareness and Cybersecurity BreachesCarolyn and Dr. Amy Hamilton echo a mutual frustration over the general public's lack of awareness regarding cybersecurity threats. They underscore the gravity of cybersecurity breaches and the espionage activities that target nations' security and economic well-being. Dr. Hamilton uses historical incidents to illustrate the ongoing battle against cyber threats and the need for heightened public consciousness. The discussion implies that bolstering public awareness and concern is pivotal in the collective effort to enhance national cybersecurity.
About Our GuestAmy S. Hamilton, Ph.D. is the Department of Energy Senior Advisor for National Cybersecurity Policy and Programs. Additionally, she is the Visiting Faculty Chair for the Department of Energy at National Defense University. She served two years as a senior cyber security policy analyst at the Office of Management and Budget, Executive Office of the President. She served in the Michigan Army National Guard as a communications specialist and was commissioned into the U.S. Army Officer Signal Corp, serving on Active Duty and later the U.S. Army Reserves. She has worked at both the U.S. European Command and the U.S. Northern Command & North American Aerospace Defense Command (NORAD) on multiple communications and IT projects.
She became a certified Project Management Professional through the Project Management Institute in 2007 and earned her Certified Information Security Manager certification in 2011. And she presented “The Secret to Life from a PMP” at TEDxStuttgart in September 2016. She taught Project Management Tools at Colorado Technical University and was a facilitator for the Master’s Degree Program in Project Management for Boston University. She is an award-winning public speaker and has presented in over twenty countries on overcoming adversity, reaching your dreams, cybersecurity, and project management.
Dr. Hamilton holds a Bachelor of Science (BS) in Geography from Eastern Michigan University, a Master of Science (MS) in Urban Studies from Georgia State University, Master in Computer Science (MSc) from the University of Liverpool, Master Certificate in Project Management (PM) and Chief Information Officer (CIO) from the National Defense University, and completed the U.S. Air University, Air War College. She completed her Doctor of Philosophy (PhD) at Regent University in its Organizational Leadership Program with a dissertation on “Unexpected Virtual Leadership: The Lived Experience of U.S. Government IT and Cybersecurity Leaders transitioning from physical to virtual space for COVID-19.” Amy’s motto is: “A woman who is passionate about project management, public speaking, and shoes.”
Episode Links* White House Executive Order on AI * The Cuckoo’s Egg * M-23-22 Executive Order
Have you heard? Data is the new oil. JR Williamson, Senior Vice President and Chief Information Security Officer at Leidos, is here to explain where data’s value comes from, the data lifecycle and why it is essential for organizations to understand both of those things in order to protect this valuable resource. Join us as JR breaks it all down and also explores the concept he dubbed “risktasity,” which he uses to describe the elasticity of rigor based on risk. As he says, “when risk is high, rigor should be high, but when risk is low, rigor should be low.”
Key Topics* 00:00 Migration to the cloud has increased vulnerability. * 04:50 People want decentralized work, including mobile access. * 08:14 Shift from application to democratizing access to data. * 10:53 Identify, protect, and manage sensitive corporate information. * 13:49 Data life cycle: creation, management, access, evolution. * 20:10 Computers augmenting humans, making good decisions, insights. * 23:19 The importance of data in gaining advantage. * 27:04 Adapting to AI to anticipate and prevent breaches. * 28:51 Adoption of large language models in technology. * 33:03 Identity and access management extends beyond authentication. * 36:33 Leveraging strengths, improving weaknesses in tennis strategy.
Tracing the Cybersecurity Evolution and Data's AscendancyEvolution of CybersecurityJR provided a snapshot into the past, comparing cybersecurity practices from the 1990s to what we see today. With 37 years of experience, he recalled a time when IT systems were centralized and the attack surfaces were significantly smaller. Contrasting this with the present scenario, he spoke about the current state where the migration to cloud services has expanded the attack surface. JR noted an increase in the complexity of cyber threats due to the widespread distribution of networks. Plus, the need for anytime-anywhere access to data. He stressed the transition from a focus on network security to a data-centric approach, where protecting data wherever it resides has become a paramount concern.
Data Life Cycle: "So part of understanding, the data itself is the data's life cycle. How does it get created? And how does it get managed? How does it evolve? What is its life cycle cradle to grave? Who needs access to it? And when they need access to it, where do they need access to it? It's part of its evolution. Does it get transformed? And sometimes back to the risktasity model, the data may enter the content life cycle here at some level. But then over its evolution may raise, up higher." — JR Williamson
The New Oil: DataIn the world JR navigates, data is akin to oil. A resource that when refined, can power decisions and create strategic advantages. He passionately elucidated on the essence of data, not just as standalone bits and bytes, but as a precursor to insights that drive informed decisions. Addressing the comparison between data and oil, JR stressed that the real value emerges from what the data is transformed into; actionable insights for decision-making. Whether it's about responding with agility in competitive marketplaces or in the context of national defense, delivering insights at an unmatched speed is where significant triumphs are secured.
Importance of Data SecurityJR Williamson on Data and "Risktasity"JR Williamson stresses the heightened necessity of enforcing security measures that accompany data wherever it resides. As the IT landscape has evolved, the focus has broadened from a traditional, perimeter-based security approach towards more data-centric strategies. He articulates the complexity that comes with managing and safeguarding data in a dispersed environment. Where data no longer resides within the confines of a controlled network but spans across a myriad of locations, endpoints and even devices. This shift has rendered traditional security models somewhat obsolete, necessitating a more nuanced approach that can adapt to the dynamic nature of data.
The Value of Data in Decision-Making: "The data in and of itself is really not that valuable. Just like oil in and of itself is not that valuable. But what that oil can be transformed into is what's really important, and that's really the concept." — JR Williamson
Data Security ExperiencesBoth Mark and Carolyn resonate with JR's insights, drawing parallels to their own experiences in cybersecurity. Mark appreciates the straightforwardness of JR’s "risktasity" model which advocates for proportional security measures based on the evaluated risk. This principle challenges the one-size-fits-all approach to cybersecurity, fostering a more tailored and efficient allocation of resources. Carolyn, in turn, connects to the conversation with her history of grappling with the intricacies of data classification and control. She acknowledges the tactical significance of understanding which data warrants more stringent protection. Plus, the operational adjustments required to uphold security while enabling access and utility.
Data Governance and Security StrategiesUnderstanding Data Security and LifecycleJR emphasizes the importance of understanding the data's lifecycle. Acknowledging that comprehensive knowledge about how data is created, managed and ultimately disposed of is a cornerstone of effective cybersecurity. This involves not only recognizing the data's trajectory but also identifying who needs access to it, under what conditions, and how it may evolve or be transformed throughout its lifecycle. By establishing such a deep understanding, JR suggests that it becomes possible to design governance systems that are not only effective in theory, but also practical and integrated into the daily operations of an organization.
Strategy and Organizational SupportTransitioning from a theoretical framework to practical execution, JR discusses the necessity of an effective data protection model that can operationalize the overarching strategy. To accomplish this, an organization must develop a structure that aligns with and supports the strategic objectives. JR identifies that existing structures often serve as the most significant barriers when agencies work on implementing new cybersecurity strategies. Organizations must be prepared to confront and renovate legacy systems and management frameworks. This is a challenge that became increasingly evident as organizations rapidly shifted to cloud services to accommodate remote work during the pandemic.
Insights from Data Security and AI ImpactTransformation of Data into Actionable InsightsLike oil, data's true value isn't in its raw form. It is in the conversion process, which transforms it into insights for decision-making. He reflects on the progression of data turning into information, which then evolves into knowledge, culminating in actionable insights. Just as the versatility of oil lies in its ability to be refined into various fuels and materials, the potential of data is unlocked when it is analyzed and distilled into insights that inform crucial decisions. JR emphasizes that the effectiveness of insights hinges not just on accuracy. It is also on understanding the context in which these insights are applied. He suggests that these refined insights are close to competitive advantages. They enable quicker and more informed decision making in mission critical environments.
The Importance of Data Insight in Business: "Getting the insight in and of itself is important. But combining that insight with understanding of the problem we're trying to solve is really where the competitive advantage comes into play." — JR Williamson
AI's Speed Impact on Cybersecurity and DefenseJR expresses apprehension regarding artificial intelligence's acceleration and its implications for cybersecurity and defense. This unease stems from AI's capability to operate at a pace vastly superior to human capacity. Such rapid capabilities could lead to a perpetual struggle for cybersecurity professionals, who are tasked with defending against AI-driven attacks that continually outpace their responses. For organizations to not only protect themselves but also remain competitive, JR advocates for the adoption of similar AI technologies. By leveraging advanced tools, organizations can preemptively identify vulnerabilities and secure them before they are exploited by adversaries. He alludes to an emerging arms race in cybersecurity, driven by AI advancements that necessitate a proactive rather than reactive approach to digital threats.
Shifting Mindset in Data Security and Zero Trust ArchitectureBroader Perspective on Defensive Data SecurityCarolyn and Mark, touching on the complexities of cybersecurity, speculate about a potential paradigm shift. Rather than focusing solely on prevention, they wonder if the strategy might pivot towards containment and control once threats are within the system. JR agrees that in today's vast and interconnected digital environment, absolute prevention is increasingly challenging. Though cybersecurity has traditionally been likened to reinforcing a castle's walls, JR argues that due to the dispersed nature of modern networks and cloud computing, this approach is becoming outdated. Instead, organizations need to be agile and resilient, with security measures embedded within the data and applications themselves, ensuring they can quickly detect, mitigate and recover from breaches.
Dissecting the Concept of Zero Trust ArchitectureJR expresses discontent with the term "zero trust" due to its implications of offering no trust whatsoever, which would stifle any exchange of information. He advocates for the terms "earned trust" or "managed trust" to more aptly describe the nuanced relationship between users and the systems they interact with. Security architecture, JR illustrates, should not solely rely on verifying users' identities. It has to account for the integrity and security posture of the devices and locations being used to access the data. By meticulously understanding which data are most sensitive and their lifecycles, organizations can ensure that access controls are rigorously applied where necessary. This is based on the type of data, the user's context and the access environment. This nuanced approach is fundamental in constructing a robust and adaptive zero trust architecture that evolves along with the organizational ecosystem.
About Our GuestsJR Williamson is accountable for information security strategy, business enablement, governance, risk, cybersecurity operations and classified IT at Leidos. JR is a CISSP and Six Sigma Black Belt. He serves on the Microsoft CSO Council, the Security 50, the Gartner Advisory Board, the Executive Security Action Forum Program Committee, and the DIB Sector Coordinating Council. He is also part of the WashingtonExec CISOs, the Evanta CISO Council, the National Security Agency Enduring Security Framework team, and is the Chairman of the Board of the Internet Security Alliance.
Episode Links* JR Williamson’s LinkedIn * The Billington Cybersecurity Summit * The Expanse * Dune: Part 2
What will 2024 have in store for technology development and regulation? Our hosts, Carolyn Ford and Mark Senell, sat down with Roger Cressey, Partner at Mountain Wave Ventures, Ross Nodurft, Executive Director of the Alliance for Digital Innovation and Willie Hicks, Public Sector Chief Technologist for Dynatrace, to discuss their 2024 predictions. Discover what the experts think will occur next year in terms of FedRAMP, AI regulation, Zero Trust and user experience.
Key Topics* 00:00 Revamping FedRAMP in 2024 leads to changes. * 06:40 Industry requests FedRAMP High; concerns about changes. * 08:20 Anticipating challenges but aiming for improvement. * 11:13 Pushing for reciprocity in government technology solutions. * 15:15 Ensuring human control in AI military use. * 19:06 Questioning AI use in defense and civilian sector. * 25:25 Increased investment in security and product regulation. * 27:21 Expect more AI news, less legislative involvement. * 30:30 Observability key for zero trust framework implementation. * 36:22 Prediction: Citizens will interface with AI technology. * 37:16 Focus on user experience in government systems. * 41:03 Election year brings unexpected black swan events.
2024 Predictions for the Public SectorRevamping of the FedRAMP ProgramRoss predicts that in 2024, FedRAMP will be completely reauthorized based on a pending OMB memo that is expected to be finalized in late 2023. This revamp is intended to streamline and improve the FedRAMP authorization process to facilitate faster adoption of cloud-based solutions in government.
However, Roger believes the changes could temporarily slow things down as agencies take time to understand the implications of the new FedRAMP structure on their systems and assess risks. This could require investments from industry as well to meet new requirements that emerge.
FedRAMP 2024: "I think it's going to have a lot of agencies take a hard look at their risk and decide where they want to elevate certain high-valued assets, high-valued systems, high-valued programs, and the authorizations themselves are gonna raise in their level." — Ross Nodurft
Shift From Moderate Baseline to Higher Baseline of ControlsAs part of the FedRAMP reauthorization, Ross expects many agencies will shift their systems from a moderate baseline to a higher baseline of security controls. With more interconnected systems and datasets, agencies will want heightened protections in place.
Roger concurs that the increased scrutiny on risks coming out of the FedRAMP changes will lead organizations, especially those managing high-value assets, to pursue FedRAMP High authorizations more frequently.
Increased Demand for a FedRAMP High EnvironmentGiven the predictions around agencies elevating their security thresholds, Willie asks Ross whether the pipeline of solutions currently pursuing FedRAMP High authorizations could face disruptions from new program requirements.
Ross believes there will be some temporary slowdowns as changes are absorbed. However, he notes that the goals of the reauthorization are to increase flexibility and accessibility of authorizations. So over time, the new structure aims to accelerate FedRAMP High adoption.
2024 Predictions: Navigating FedRAMP Changes While Maintaining Industry MomentumAs Ross highlighted, the intent of the FedRAMP reauthorization is to help industry get solutions to market faster. But in the short-term, there could be some complications as vendors have to realign to new standards and processes.
Willie notes that companies like Dynatrace have already begun working towards FedRAMP High in anticipation of rising customer demand. But sudden shifts in requirements could impact those efforts, so he hopes there will be considerations for solutions currently undergoing authorizations.
2024 Predictions on Cybersecurity TrendsZero Trust FrameworkRoger discusses how zero trust architectures are progressing forward in adoption, even though the concept has lost some of its previous buzz. The zero trust memo is still in place, people are budgeting for zero trust and funding is starting to be allocated towards implementation.
As Willie points out, every agency he works with is developing zero trust strategies and architectures. However, he notes these architectures can be extremely complex, especially when adding in cloud and containerized environments.
2024 Predictions: Observability Critical for Security in Complex Cloud EnvironmentsRoss echoes Willie's point that there is an increasing movement towards cloud-based environments. This is driving changes to FedRAMP to accommodate the proliferation of SaaS applications.
With more enterprise environments leveraging SaaS apps, complexity is being introduced. Ross predicts that to protect, understand and maintain visibility across such complex environments with many different applications, overarching observability will become a necessity.
Impact of the Shift Towards Cloud-Based Environments and SaaS ApplicationsThe shift towards cloud-based environments and SaaS applications ties back to the FedRAMP changes and predictions from Ross. As agencies move to the cloud and adopt more SaaS apps, they lose visibility and observability.
Willie predicts observability will become "connective tissue" across zero trust architectures to provide that much-needed visibility across various pillars like devices, networks and users.
The Rise of User Experience in Government Systems: "I think we're gonna see more and more, of a focus on user experience because I believe with all the things we're talking about, user experience could be impacted." — Willie Hicks
Importance of Observability for Visibility and UnderstandingRoger concurs that visibility is crucial for security because "you can't secure what you can't see." He notes that observability and understanding where data is and what apps are doing will become a prerequisite for achieving zero trust.
The Importance of Data Visibility in Security: "Well, I think it's gonna become table stakes, if you will, when it comes to security, because you can't secure what you can't see." — Roger Cressey
Carolyn highlights how visibility has been embedded in zero trust frameworks from the beginning. However, Willie predicts its importance will be even more prominent in 2024.
AI and Technology Innovations2024 Predictions: Navigating AI Promise and Pitfalls in the Public SectorRoger highlighted the tremendous upside that AI-enabled customer experience solutions could provide for government agencies in improving efficiency and service delivery. However, he also noted that any negative experiences resulting from these solutions would be heavily scrutinized and amplified. This indicates there may be cautious adoption of AI in government during 2024 as agencies balance potential benefits and risks.
The Importance of Reciprocity in Government Technology: "I just hope they have the wherewithal and the focus to push the right people in the right parts of both the Department of Defense and to the federal civilian side to think about how reciprocity impacts their availability in the marketplace technology or commercial technology solutions out there." — Ross Nodurft
Willie predicted there would be carefully orchestrated success stories around AI implementations, supporting Roger's point. This suggests that while innovation will continue, government agencies will likely roll out AI solutions slowly and target opportunities where impact can be demonstrated.
Increased Investment in Security and Product InnovationRoger predicted that defensive cyber capabilities enabled by AI will draw greater attention and interest in 2024. Willie noted that AI is also being used in more advanced cyber attacks. Together, these trends indicate there will be an increased focus on using AI responsibly to enhance security while also defending against malicious uses.
On the commercial side, Ross predicted venture capital investment into AI will accelerate in 2024, driving constant product updates across language models and other platforms. This rapid product innovation seems likely to widen the gap with public sector adoption.
2024 Predictions: Balancing AI Progress and Governance in the Public SectorWhile the panelists disagreed on the likelihood of major AI regulations from Congress in 2024, Willie predicted that high-profile incidents involving AI could build pressure for new laws, even if passage takes time. He and Ross suggested implementation of AI guidance for government agencies is more likely in the near term.
The Future Impacts of AI: "I think that the developers of AI are gonna continue to set the agenda, and the deployers, in other words, all the sectors as well as industry sectors, the developers, the deployers are still gonna be playing catch up." — Roger Cressey
Roger noted that negative experiences with AI in government would also spur calls for regulation. However, he said acting prematurely without understanding the impacts could pose challenges. Together, these perspectives indicate oversight and governance guardrails for AI will increase but could slow adoption if not balanced thoughtfully.
2024 Predictions: AI Policy Progress and Global Technology LeadershipPotential Dysfunction in Congress Impacting Regulatory ProgressRoger points out the significant disagreement between the House and Senate that could prevent Congress from finding common ground on AI regulation in 2024. The divide relates to whether the focus should be on continuing innovation or implementing more safeguards and oversight. Meaningful AI legislation at a national level would require lengthy deliberation and consensus-building that likely won't occur in an election year.
Potential Motivation for U.S. Innovation by China’s Advancements in AIAccording to Roger, China's rapid advances in AI development and utilization could light a fire under the U.S. administration and Congress to accelerate American innovation in this area. However, the U.S. policy community also wants to ensure AI progresses responsibly. Roger argues China's AI capabilities could be an impetus for shaping U.S. strategy in 2024, balancing both innovation and risk management.
The Global Race for AI Dominance: "Where China is moving rapidly and creatively on AI development, adoption and deployment will be a jet fuel for motivating the administration and congress to do more regarding how can innovation on the U.S. side regarding AI move quicker." — Roger Cressey
Industry Adaptation to Change2024 Predictions: Navigating Changes to FedRAMP and Industry AdaptationRoss discusses some of the challenges the industry may face in adapting to the changes outlined in the anticipated 2023 FedRAMP reauthorization memo. He notes that while the intent of the memo is to streamline and open up the authorization process to allow more applications into the pipeline faster, implementing these changes could initially cause some disruption.
Ross predicts there may be a "learning curve" as agencies and vendors figure out how the changes impact their specific systems and day-to-day operations. This could temporarily slow things down until the new processes are fully understood. However, Ross expects that after this initial bumpy period, the changes will ultimately enable faster movement of applications through the FedRAMP process.
The Government’s Aim to Create a Process for a Smoother TransitionRoss highlights that the government's aim in revising the FedRAMP authorization process is to make it easier for agencies to access and leverage innovative cloud-based technologies. The memo revisions seek to create multiple pathways for obtaining authorizations, rather than just one narrow pipeline that applications must move through.
Discussing the Future of AI: "We gotta talk about, whether it's AI governance, whether it's innovation in AI, it's AI risks, and really understanding how do we balance all 3 of those in a way while we're still moving forward." — Roger Cressey
The hope is that these process improvements will pave the way for more small and medium cloud-based software companies to get their products authorized for use in government. This will give agencies more options and flexibility in adopting modern solutions. However, Ross cautions that in the short-term there may be some disruptions as outlined above.
Predictions for Significant Impact in 2024In terms of predictions for 2024, Ross expects that the FedRAMP changes, combined with broader cloud migration efforts underway in government, will lead more agencies to request higher baseline security authorizations. Where they may have been comfortable with a FedRAMP Moderate authorization previously, Ross predicts agencies will now ask vendors for FedRAMP High in more and more cases. This will likely impact software providers who will have to adapt their systems and applications to meet the more stringent security controls.
About Our GuestsRoss NodurftRoss Nodurft is the Executive Director of the Alliance for Digital Innovation (ADI), a coalition of technology companies focused on bringing commercial, cloud-based solutions to the public sector. ADI focuses on promoting policies that enable IT modernization, cybersecurity, smarter acquisition and workforce development. Prior to joining ADI, Ross spent several years working with industry partners on technology and cybersecurity policy and several years in government, both in the executive and legislative branches, including Chief of the Office of Management and Budgets cyber team in the White House.
Roger CresseyRoger Cressey is a Partner with Mountain Wave Ventures. He previously served as a Senior Vice President at Booz Allen Hamilton, supporting the firm’s cyber security practice in the Middle East. Prior to joining Booz Allen, he was President and Founder of Good Harbor Consulting LLC, a security and risk management consulting firm.
Mr. Cressey’s government service included senior cyber security and counterterrorism positions in the Clinton and Bush Administrations. At the White House, he served as Chief of Staff of the President’s Critical Infrastructure Protection Board from November 2001 – September 2002. He also served as Deputy for Counterterrorism on the National Security Council staff from November 1999 to November 2001. He was responsible for the coordination and implementation of U.S. counterterrorism policy and managed the U.S. Government's response to multiple terrorism incidents, including the Millennium terror alert, the USS COLE attack, and the September 11th attacks.
Willie HicksWillie Hicks is the Public Sector Chief Technologist for Dynatrace. Willie has spent over a decade orchestrating solutions for some of the most complex network environments, from cloud to cloud native applications and microservices. He understands tracking and making sense of systems and data that has grown beyond human ability. Working across engineering and product management to ensure continued growth and speed innovation, he has implemented Artificial Intelligence and automation solutions over hundreds of environments to tame and secure their data.
Episode Links* FedRAMP * Alliance for Digital Innovation * DoDIIS Worldwide
On this special So What? episode we go deeper in to some of the top stories being covered on the It’s 5:05! podcast with It’s 5:05! contributing journalist, Tracy Bannon. How are cybersecurity stress tests battling misinformation and aiding in election security? Is AI contributing to election disinformation? How is the CIA using SpyGPT? Come along as Carolyn and Tracy go beyond the headlines to address all these questions and more.
Key Topics* 04:20 Proactive approach needed for software voting security. * 09:12 Deepfake technology can replicate voices and videos. * 12:38 Politics focuses on presidential level, ignores others. * 15:53 Generative AI creates new content from data. * 17:19 New tool aids intelligence agencies process data. * 20:13 Bill Gates discusses future AI agents on LinkedIn. * 25:24 Navigating biases in AI towards democratic values. * 29:13 CISA promotes continuous learning and holistic approach. * 30:51 Demystifying and making security approachable for all. * 33:33 Open source, cybersecurity, diverse professional perspectives discussed.
Importance of Cybersecurity and Responsible AI UseEmbracing Cybersecurity Measures and Privacy ProtectionsIn their conversation, Carolyn and Tracy discuss the imperative nature of both individuals and organizations in embracing robust cybersecurity measures. As we live in an era where data breaches and cyber attacks are on the rise, the implementation of effective security protocols is not just a matter of regulatory compliance, but also about safeguarding the privacy and personal information of users. Tracy emphasizes the continuous need for cybersecurity vigilance and education, highlighting that it is a shared responsibility. By making use of resources like the CISA cybersecurity workbook, Carolyn suggests that individuals and businesses can receive guidance on developing a more secure online presence, which is crucial in a digital ecosystem where even the smallest vulnerability can be exploited.
Addressing Biases in AI to Align With Public Interest and Democratic ValuesTracy expresses concerns over the biases that can be present in AI systems, which can stem from those who design them or the data they are trained on. Such biases have the potential to impact a vast array of decisions and analyses AI makes, leading to outcomes that may not align with the broad spectrum of public interest and democratic values. An important aspect of responsible AI use is ensuring that these technological systems are created and used in a way that is fair and equitable. This means actively working to identify and correct biases and ensuring transparency in AI operations. Plus, constantly checking that AI applications serve the public good without infringing upon civil liberties or creating divisions within society.
Demystifying Cybersecurity: "We need that public understanding, building this culture of security for everybody, by everybody. It becomes a shared thing, which should be something that we're teaching our children as soon as they are old enough to touch a device." — Tracy Bannon
The Proliferation of Personal AI Use in Everyday TasksThe conversation shifts towards the notion of AI agents handling tasks on behalf of humans, a concept both cutting-edge and rife with potential pitfalls. Carolyn and Tracy discuss both the ease and potential risks of entrusting personal tasks to AI. On one hand, these AI agents can simplify life by managing mundane tasks. Optimizing time and resources, and even curating experiences based on an in-depth understanding of personal preferences. Yet, Tracy questions what the trade-off is, considering the amount of personal data that must be shared for AI to become truly "helpful." This gives rise to larger questions related to the surrender of personal agency in decision-making. The erosion of privacy, and the ever-present threat of such tools being exploited for nefarious purposes.
CISA's Cybersecurity WorkbookEnhancing Accessibility with AI Use: Summarizing Complex Documents through Generative ToolsTracy introduces the concept of leveraging generative AI tools such as ChatGPT to summarize lengthy documents. This innovative approach provides a way to digest complex material quickly and efficiently. For instance, users can feed a PDF or a website link into ChatGPT and request a summary which the tool will produce by analyzing the text and presenting the key points. Tracy emphasizes this method as a step toward making dense content like government reports or lengthy executive orders, more accessible. She also transitions to discussing CISA's cybersecurity workbook. Illustrating a movement towards the dissemination of important information in a format that a broader audience can understand and apply, not just tech experts. Tracy appreciates the effort by CISA to create resources that resonate with everyone's level of technical knowledge.
Comprehensive Guidance for Security MeasuresThe comprehensive guide provided by CISA, Tracy notes, is robust in offering detailed strategies for planning and implementing cyber security measures. The workbook does not shy away from diving deep into the assessment of potential cyber risks. It details leading practices that organizations can adopt. Planning for incident response is a highlighted area, acknowledging that security breaches are not a matter of if but when. The workbook thus serves as an invaluable reference for initiating proactive steps to fortify against cyber threats. This level of comprehensive guidance serves not only as a tool for implementing robust security measures. It is also a learning resource that promotes a widespread understanding of best cybersecurity practices.
Government's AI UsePotential Introduction of Generative AI by the CIATracy and Carolyn discuss the CIA's plans to potentially introduce generative AI through a program dubbed "SpyGPT." The idea behind this integration is to enable the parsing and understanding of extensive open-source data more efficiently.
Generative AI, similar in concept to models like ChatGPT, could revolutionize how intelligence agencies handle the vast amounts of data they collect. If implemented, this AI would be able to generate new content based on massive datasets. Providing insights that could be invaluable for intelligence processing. Carolyn raises comparisons to traditional methods of intelligence gathering, noting that such technological advancements could have helped in past events had they been available. In response, Tracy emphasizes the historic struggle of intelligence agencies to rapidly sort through surveillance information. A challenge that tools like SpyGPT could mitigate.
The Double-Edged Sword of AI Use in Predictive AnalysisA tool like SpyGPT has the potential to rapidly identify patterns and connections within data. This could lead to quicker and more accurate intelligence assessments. Carolyn points to the use of crowdsourcing information during the Boston Marathon bombing as an example of how rapid data correlation and analysis can be critical in national security efforts. The ability to predict and possibly prevent future threats could be significantly enhanced.
The Dangers of Internet Era Propaganda: "I can take any idea, and I can generate vast amounts of text in all kinds of tones, from all different kinds of perspectives, and I can make them pretty ideal for Internet era propaganda." — Tracy Bannon
However, as Tracy notes, the power of such technology is a double-edged sword, raising concerns about privacy, the potential for misuse and ethical implications. The conversation raises the specter of a "Minority Report"-esque future, where predictive technology verges on the invasive. Both Tracy and Carolyn agree on the tremendous responsibilities that come with the implementation of generative AI when it intersects with privacy, civil liberties and security.
Election SecurityThe Critical Role of AI Use in Election Security Stress TestingStress testing in the context of election security revolves around rigorously probing the voting system to uncover any flaws or weaknesses. This process requires collaboration between various stakeholders, including the manufacturers of voting machines, software developers and cybersecurity experts. Tracy emphasizes the crucial nature of these simulated attacks or real-world scenarios that help reveal potential points of exploitation within the system. Identifying these vulnerabilities well before an election can give officials the necessary time to address and reinforce weak spots. Ensuring the reliability and resilience of the electoral process against cyber threats.
The AI Use in Unveiling Election System VulnerabilitiesTracy discusses the necessity of not just identifying but also openly revealing discovered vulnerabilities within election systems as a means to foster trust among the populace. Transparency in the security measures taken and the clear communication of vulnerabilities found, when managed properly, instill a higher sense of confidence in the electoral system's integrity. This approach also plays a pivotal role in countering misinformation. By proactively conveying the true state of system security and the efforts being taken to remedy issues. It can help to dismantle unfounded claims and skepticism about the election infrastructure from various sectors of society.
Exploring the Impact of AI Use in Deepfake Technology and Artificial Persona CreationCapabilities of Deepfake Technology and AI-Language ModelsRecent advancements in AI and deepfake technology have brought breathtaking capabilities. Primarily the power to manipulate audio and video content with astounding realism. Tracy emphasizes the profound implications of this tech. Specifically pointing to language models such as "Vall-E," which can simulate a person's voice from just a few seconds of audio input.
The Rise of Deepfakes: "Imagine what's gonna happen with the deepfake. Take a right? I can take your video. I can take your voice." — Tracy Bannon
This technology uses sophisticated algorithms to detect nuances in speech patterns. Allowing it to generate new audio that sounds like the targeted individual, effectively putting words into their mouths that they never actually said. This ability extends beyond simple mimicry. It propels the potential for creating audio deepfakes that can be nearly indistinguishable from genuine recordings. Such capabilities raise significant concerns about the reliability of auditory evidence and the ease with which public opinion could be manipulated.
Creation of Artificial Personas Using AI ToolsTracy brings to light the increasingly effortless creation of false personas through AI tools such as ChatGPT, which is an iteration of AI language models capable of generating human-like text. These tools can fabricate compelling narratives and even mimic specific writing styles. It can create non-existent but believable social media profiles or entire personas. Tracy points out how these synthetic entities can be programmed to deliver credible-sounding propaganda, influence political campaigns, or sow discord by spamming internet platforms with targeted misinformation. The creation of these artificial personas signifies a dramatic shift in how information can be disseminated. Posing risks of eroding trust in digital communication and complicating the battle against fake news.
About Our GuestTracy Bannon is a Senior Principal with MITRE Lab's Advanced Software Innovation Center and a contributor to It’s 5:05! podcast. She is an accomplished software architect, engineer, and DevSecOps advisor having worked across commercial and government clients. She thrives on understanding complex problems and working to deliver mission/business value at the speed. She’s passionate about mentoring and training and enjoys community and knowledge-building with teams, clients, and the next generation. Tracy is a long-time advocate for diversity in technology, helping to narrow the gaps as a mentor, sponsor, volunteer, and friend.
Episode Links* It’s 5:05! Unmasking Election Security: How Cybersecurity Stress Tests Battle Misinformation * It’s 5:05! AI Election Disinformation * It's 5:05! SpyGPT * Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence * Allan Friedman’s Tech Transforms Episode * It’s 5:05! More CISA Leadership: Security Planning Workbook * CISA’s Security Planning Workbook
As technology rapidly innovates, it is essential we talk about technology policy. What better way to get in the know than to have an expert break it down for us? Meet Ross Nodurft, the Executive Director of the Alliance for Digital Innovation. Ross dives in, explaining the evolution of FedRAMP controls and the recent, giant, AI Executive Order (EO) from the White House. Listen in to find out what this EO means for the government, the industry and the workforce as the U.S. attempts to implement policy ahead of AI innovation.
Key Topics* 04:25 Increasing security controls for cloud migration * 07:51 Discussion about customer feedback and cloud migration. * 12:17 Encouraging commercial solutions into federal government securely. * 15:39 Artificial intelligence shaping policy for future technology. * 16:54 AI EO covers critical infrastructure, AI, data, immigration. * 22:34 Guidance on AI impact assessment and testing. * 27:02 AI tools adoption must not be delayed. * 30:03 Ensure AI technologies have fail-safe mechanisms. * 32:08 Concern over rapid pace of technological advances. * 34:29 AI and technology advancing, policy aims control. * 39:37 Fascinating book on technology and chip history.
The Future of Government Technology: Shifting to FedRAMP High and Accelerating Cloud AdoptionShift from FedRAMP Moderate to High for Sensitive WorkloadsWhen FedRAMP was established over a decade ago, the focus was on managing the accreditation of emerging cloud infrastructure providers to support the initial migration of workloads. The baseline standard was FedRAMP Moderate, which addressed a "good amount" of security controls for less risky systems. However, Ross explains that increasing volumes of more sensitive workloads have moved to the cloud over time - including mission-critical systems and personal data. Consequently, agencies want to step up from moderate to the more stringent requirements of FedRAMP High to protect higher-risk systems. This includes only allowing High-cloud services to interact with other High-cloud applications.
The Evolution of Cloud Computing: "So right now, we're at the point where people are existing in thin clients that have access to targeted applications, but the back end compute power is kept somewhere else. It's just a completely different world that we're in architecturally." — Ross Nodurft
The Future of Government Technology: Streamlining FedRAMP for the SaaS-Powered EnterpriseAccording to Ross, the COVID-19 pandemic massively accelerated enterprise cloud adoption and consumption of SaaS applications. With the abrupt shift to remote work, organizations rapidly deployed commercial solutions to meet new demands. In the federal government, this hastened the transition from earlier focus on cloud platforms to widespread use of SaaS. Ross argues that FedRAMP has not evolved at pace to address the volume and type of SaaS solutions now prevalent across agencies. There is a need to streamline authorization pathways attuned to this expanding ecosystem of applications relying on standardized baseline security controls.
High-level Security Controls for Sensitive Data in the CloudAddressing Data Related to Students and ConstituentsRoss states that as agencies move more sensitive workloads to the cloud, they are stepping up security controls from FedRAMP Moderate to FedRAMP High. Sensitive data includes things like personal HR data or data that could impact markets, as with some of the work USDA does. Willie gives the example of the Department of Education or Federal Student Aid, which may have sensitive data on students that could warrant higher security controls when moved to the cloud.
Ross confirms that is absolutely the case - the trend is for agencies to increase security as they shift more sensitive systems and data to the cloud. Especially with remote work enabled by the pandemic. So agencies with data related to students, constituents, healthcare, financial transactions etc. are deciding to utilize FedRAMP High or tailor Moderate with additional controls when migrating such workloads to ensure proper security and rights protections.
The Future of Government Technology: Navigating the Tradeoffs Between Cloud Innovation and Data SecurityAs Ross explains, FedRAMP High means you can only interact with other cloud applications that are also FedRAMP High. So there is segmentation occurring with more sensitive data and workloads being isolated via stricter security controls. However, he notes it is not a "bull rush" to FedRAMP High. Rather agencies are steadily moving in cases where the sensitivity of the data warrants it.
Willie then asks about the costs associated with these stricter cloud security authorizations, given even Moderate is expensive. Ross explains there are currently policy discussions underway about making FedRAMP more streamlined and cost-effective so that innovative commercial solutions can still sell to the government without having to completely re-architect their offerings just for these processes. The goal is balancing the accessibility of cloud solutions with appropriate security based on data sensitivity.
Modernizing Federal Government IT: "We need to stop requiring companies to have their own completely separate over architected environment. We want commercial entities to sell commercially built and designed solutions into the federal government." — Ross Nodurft
Laying the Groundwork: The AI Executive Order and the Future of Government TechnologyRobust Framework for Future Policy and Legal DevelopmentRoss states that the AI Executive Order is the biggest and most robust executive order he has seen. He explains that it attempts to get ahead of AI technology development by establishing a framework for future policy and legal development related to AI. Ross elaborates that there will need to be additional regulatory and legal work done, and the order aims to "wrap its arms around" AI enough to build further policy on the initial framework provided.
According to Ross, the order covers a wide range of topics including AI in critical infrastructure, generative AI, immigration reform to support the AI workforce, and government use of AI. He mentions the order addresses critical infrastructure like pipelines, hospitals, transportation systems and more. It also covers immigration policy changes needed to ensure the U.S. has the talent to advance AI. Additionally, it focuses heavily on government consumption and deployment of AI.
Mapping the Future of Government TechnologyNavigating the Future of Government TechnologyThe AI executive order tasks the Office of Management and Budget (OMB) with developing guidance for federal agencies on the safe and secure adoption of AI. Specifically, Ross states that the order directs the Federal CIO and other administration officials to establish rules that allow government consumption of AI in a way that protects safety and rights. Before writing this guidance, the order specifies that OMB must consider the impacts of AI on safety-critical infrastructure as well as rights like privacy and fairness.
Ross explains that OMB recently released draft guidance for public comment. He says this draft guidance contains several key components. First, it establishes AI governance requirements, directing every major federal agency to appoint a Chief AI Officer and create an AI council with agency leadership that will oversee adoption. Second, it mandates that agencies take inventory of existing AI use and develop plans detailing how they intend to utilize AI going forward.
Requirements for Agencies to Appoint a Chief AI Officer According to Ross, a primary governance requirement in the OMB draft guidance is that all major agencies assign a Chief AI Officer to spearhead their efforts. Additionally, he notes that the guidance orders agencies to construct AI councils with membership spanning functions like IT, finance, HR and acquisition. Ross specifies that these councils will be led by the Deputy Secretary and Chief AI Officer of each department.
The Uncertain Future of Government TechnologyCollaboration, Prioritization of Assessments, Compliance, Monitoring and ValidationRoss highlights the need for collaboration between industry and agencies to address issues like prioritization, timing, specifics of compliance, attestation and who pays for and validates assessments. The order pushes the use of AI but lacks specifics that could slow adoption of widely-used technologies with AI. Ross notes this could introduce friction, slowing productive technologies when faster digital services are demanded. Better defining compliance pathways is needed to avoid nervousness using AI.
AI Ethics and Regulation: "You've got to run as close to live testing as possible, you've got to have human people factored into the decision-making engines." — Ross Nodurft
While embracing AI, the order does not detail how to facilitate adoption. Ross says this could cause confusion across agencies. His trade association ADI sees the need to add specifics around governance mechanisms to avoid inconsistencies. The lack of clarity risks friction and slowing AI incorporation, which Ross believes is imperative.
Balancing Innovation and Responsibility in Emerging TechnologiesDemand for a Digital Environment and the Importance of ObservabilityRoss states that there is a quick move towards a digital environment across all services, driven by demand from millennials, Gen X and Gen Z. He emphasizes that everything needs to have an app or digital access now to engage users. Ross then highlights how Dynatrace provides important observability of these new cloud-based architectures, allowing agencies to understand usage, interactions and performance. He argues this is essential to properly managing digital services.
Ross worries that the new AI executive order guidance lacks specifics around compliance, which risks creating friction in adopting widely-used technologies like Dynatrace that have AI components. He states there is uncertainty whether tools like Dynatrace must be inventoried and assessed under the new policy. If so, there are many open questions around prioritization, timing, specific compliance activities, and who pays associated costs. Ross emphasizes that this uncertainty could hinder cloud adoption without more clarity.
Responsibility and Control Over the Use of AI TechnologyRoss stresses that while AI technology enables incredible things, we have full control and responsibility over its uses. He states we must consider processes and safeguards that provide oversight and allow intervention over AI systems. Ross argues we cannot afford to deploy AI blindly, but highlights it is in our power to leverage these technologies to benefit humanity with appropriate guardrails.
Shaping the Future of Government TechnologyThe Future of Government Technology and Managing Change for Emerging FieldsRoss asserts today there is greater intention around anticipating risks from emerging technology compared to past eras. He advocates for building off switches and review processes that allow understanding and course correction around new innovations like AI. Ross states this considered approach is essential for nanotechnology, quantum computing and other exponentially advancing fields.
The Influence of Artificial Intelligence in Policy and Legal Development: "But artificial intelligence is now more than ever being built into everything that we do technologically." — Ross Nodurft
Ross disputes the concern that AI will replace jobs, arguing instead it will shift skills required by humans. He provides examples of comparable historical technology shifts requiring new expertise, like transitioning from horses to locomotives. Ross states AI moves job responsibilities in different directions rather than eliminating careers, necessitating learning new tools and approaches.
Establishing Processes and Organizational Structures for the Future of Government TechnologyRoss highlights how the AI executive order establishes agency governance bodies to oversee adoption. He details required personnel like Chief AI Officers that must review and approve AI use. Ross states these processes aim to identify risks in using innovations like AI while still encouraging adoption. He argues this organizational oversight is a new paradigm essential for emerging technologies.
About Our GuestRoss Nodurft is the Executive Director of the Alliance for Digital Innovation (ADI), a coalition of technology companies focused on bringing commercial, cloud-based solutions to the public sector. ADI focuses on promoting policies that enable IT modernization, cybersecurity, smarter acquisition and workforce development. Prior to joining ADI, Ross spent several years working with industry partners on technology and cybersecurity policy and several years in government, both in the executive and legislative branches, including Chief of the Office of Management and Budgets cyber team in the White House.
Episode Links* Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence * FedRamp * Turkey Gumbo Recipe * Chip War by Chris Miller
Have no fear, your new wingman is here! AI is by your side and ready to help you multiply your abilities. Patrick Johnson, Director of the Workforce Innovation Directorate at the DoD CIO discusses how his team is working to further implement AI ethically and safely in areas such as human capital to expedite finding talent. Patrick also shares his passion for building cyclical pipelines to ensure that talent, and ideas, flow seamlessly between the government and private sector. Join us as we dive further into AI’s benefits and how government and industry can be cyber workforce innovation partners.
Key Topics* 02:06 Lag in civilian workforce training upscaling needed. * 03:19 Balancing talent, training and automation for better security. * 08:22 Leaders understand AI as a force multiplier. * 12:15 Our motivations are different; utilizing AI for advancement. * 15:25 AI used for maintenance, scheduling, monitoring issues. Embracing technology. * 18:35 Questioning impact of technology on workforce integration. * 21:45 Knowledge, skills, ability, competency. Task-focused performance. Workforce coding. Qualification program ensures necessary skill sets. Tracking mechanism being developed. Vast department with skill spread. * 25:26 Real-time data for proactive leadership and action. * 27:05 Retention strategy includes talent competition and permeability. * 30:36 Improving marketing for civilian DoD jobs. * 33:49 It works for all sectors, find talent. * 40:19 Government employees and veterans bring valuable skills. * 41:27 Promote supply, train, partner for innovation. * 45:33 Virtual reality: future of government services and museums.
The DoD's Cyber WorkforceCyber Workforce Improvement Is CrucialPatrick states that the Department of Defense's (DoD's) total cyber workforce, comprising military, civilian and industry partner contractors, is around 225,000 people. He notes that the DoD has the biggest gap in the civilian cyber workforce, which makes up about 75,000 people. According to Patrick, one of the key problems when bringing new cybersecurity technologies online is failing to adequately train the existing workforce on how to use and get value from those technologies.
Training and Upscaling the Current Cyber WorkforceRather than pursuing full re-skilling of employees which can set them back, Patrick advocates for upskilling the current DoD cyber workforce. This involves assessing talent and capability gaps. Then providing the workforce with the necessary training to perform new technologies appropriately. Patrick states that partnering workforce members with automated processes like AI can help them become more effective by highlighting key info and threats.
The Importance of Training and Upscaling in the Cyber Workforce: "Well, it's great to put new technology on the table. But if you don't take the time to train the workforce you have in the programs or the systems you're bringing online, you lose that effectiveness and you don't really gain the efficiencies or the objectives that you need to be."— Patrick Johnson
Automation and AIAI Is Seen as a Partnership With the Human Cyber WorkforcePatrick views AI as a partnership with the human workforce rather than a threat. He emphasizes that AI should be seen as a "wingman or wingperson" that boosts productivity and acts as a force multiplier. Patrick explains that AI excels at rote, tedious tasks allowing the human workforce to focus more on creativity.
AI Helps With Rote and Tedious TasksAccording to Patrick, AI is adept at attention-to-detail tasks that would be tedious for a human to manually perform. He provides the example of a cybersecurity analyst or defender whose productivity can be enhanced by AI highlighting anomalies in data that they should pay attention to. This allows them to catch more threats and intrusions coming through their systems.
The Rise of AI and the Fear of Job Loss: "AI can expedite that and do it really fast. It's about how do you fit in and use the technology that is there. So for individuals that are bent on just being one thing or doing a particular way, it's gonna be a struggle."— Patrick Johnson
AI as a Productivity MultiplierPatrick argues that all organizations are understaffed and says AI is like "adding a person and a half" to your existing workforce. In his view, this boosts productivity significantly if the technology is utilized correctly. He believes AI's capabilities in assisting with repetitive tasks allow human workers to focus more on creative problem-solving.
AI as a Cyber Workforce MultiplierAI Applied in Various Industries With New Jobs and OpportunitiesPatrick explains that AI excels at automating repetitive, detail-oriented tasks, freeing up humans to focus on more creative responsibilities. As AI develops, Patrick believes new industries and opportunities will emerge. He references how industrial automation led to new maintenance jobs. Similarly, current AI advances likely indicate the rise of new industries needing workers to oversee AI systems.
Harnessing Talent in the Digital Age: "It'll work. If it works for cyber, why wouldn't it work for aviation, or why wouldn't it work for logistics? It's gonna work for just about any approach you wanna take."— Patrick Johnson
Current AI Advancements Focused On Non-creative TasksWillie agrees that true general AI with human-level creativity remains a distant prospect. He characterizes current AI as skilled at rote, non-creative work. While AI can simulate creativity by aggregating data, Willie argues it cannot independently demonstrate innovation as humans do. He believes consciousness and creativity constitute scientific frontiers we are far from unlocking in silicon.
Ethical Use of AI in Western SocietiesEthical Considerations in Western SocietiesPatrick discusses how there is an ethical piece when it comes to AI and its use in Western societies. He notes that the DoD's Chief Digital and Artificial Intelligence Office, and their principal staff assistant, are really looking hard at the ethical use of AI. Patrick contrasts this to some of the department's peer competitors, without naming specific countries, who are not as worried about using AI ethically. He explains that in Western societies that have operated in a prosperous, peaceful way for almost 90 years, there is more concern about ethics with emerging technology like AI.
U.S. is Known for Creativity and InnovationPatrick talks about how one of the strengths of the U.S. as a nation is the focus on creativity, innovation and free thinking. He says these characteristics allow new technologies to fully prosper and reach their potential. Unlike in some other systems where there may be more ulterior motives from the state or ruling party that limit capabilities. Patrick notes that some other countries utilize AI for better understanding their citizens, monitoring people and tracking behaviors without as much ethical concern.
AI in the Defense DepartmentDoD Exploring AI in Maintenance Schedules and Issue TrackingPatrick notes that the Defense Department is currently using AI in enclosed systems to improve maintenance schedules and track issues. He explains that this allows them to leverage AI to expedite when certain maintenance actions need to be taken and monitor problems. While the department is still in the early stages of incorporating AI, Patrick emphasizes they are embracing it for these types of automatable tasks rather than avoiding it due to security concerns.
Embracing AI While Avoiding Security RisksWhen discussing AI, Patrick acknowledges there are legitimate security worries given the sensitive nature of the Defense Department's systems and environment. However, he states these concerns should not deter the department from bringing AI capabilities to the forefront. Patrick argues the department needs to find ways to ethically and safely integrate AI so it does not pose risks. He mentions this is an area of focus for the Chief Digital and Artificial Intelligence Office.
The Role of AI in Cybersecurity: "It really is about looking at your talent and your gaps and then giving them the training they need to execute the new technology, appropriately."— Patrick Johnson
AI Used to Automate Human Capital TasksIn terms of human capital functions, Patrick highlights how the department is already employing AI to streamline and automate certain talent management processes. For example, he explains they are using AI-enabled systems to expedite applicant-job matching and make hiring more efficient. Additionally, Patrick notes AI is helping align training offerings and certifications to the workforce skill gaps the department needs to fill. He emphasizes these applications demonstrate the promise of AI in automating tedious tasks that would normally take humans much longer to accomplish manually.
Measuring Impact and Maintaining Cyber Workforce Technology BalanceUsing AI to Measure Program ImpactPatrick explains that they are using AI to track metrics like attrition rates, vacancy rates, losses and gains. This allows them to do predictive analysis to project future vacancy rates and take proactive action when needed. For example, Patrick can put up real-time data for leadership showing that if no action is taken, vacancy rates could rise from 17% to 37% in two years. This prompts leadership to address gaps proactively before problems become severe. Patrick envisions AI having an even greater impact by identifying talent gaps across the department and giving the services enough lead time to ramp up training programs accordingly.
Balancing Cyber Workforce and TechnologyTo balance workforce and technology, Patrick emphasizes the need to train the current workforce on new systems and technologies rather than expecting them to instantly adapt. He uses the example of implementing Zero Trust security, noting that deploying the technology alone is not enough if the workforce is not properly trained to leverage and maximize it. Patrick believes AI should be viewed as a "wingman" to augment human capabilities rather than replace jobs. Proper AI integration requires change management and culture change around utilizing automation.
Tracking Skills With 8140 Qualification ProgramThe 8140 qualification program tracks skillsets needed to perform critical cyber work roles across the department. By coding the entire military and civilian cyber workforce with work roles rather than just competencies, they gain visibility into the location of talent gaps. Work roles also allow them to incentivize critical positions rapidly. As they collect more workforce data, this program will enable sophisticated predictive analytics to get ahead of future talent and skill deficits.
About Our GuestMr. Patrick Johnson serves as the Director of the Cyber Workforce Management Directorate in the Office of the Deputy CIO for Resources and Analysis, Department of Defense (DoD) CIO.
In his role as Director, Mr. Johnson leads a dynamic team responsible for the Directorate’s expansive workforce management portfolio and program development supporting the broader talent management lifecycle for the Department’s cyberspace workforce. Directorate initiatives include the DoD Cyber Workforce Framework (DCWF) expansion, training and education program development (Cyber Scholarship, Cyber Exchange, etc.), Cyber Workforce Management Board (CWMB) facilitation, Cyber Excepted Service (CES) Personnel System, and the 8140 policy series implementation which establish enterprise baseline standards and requirements according to DCWF work role(s). At the OSD level, the Cyber Workforce Directorate's role is to leverage authorities and provide Department stakeholders with policies, programs, and tools to effectively recruit and retain a highly skilled cyberspace workforce.
Mr. Johnson previously served as the Chief, DoD Cyber Excepted Service where his leadership played a pivotal role in the development and implementation of the Cyber Excepted Service Personnel System, and ultimately mission expansion into today’s Cyber Workforce Directorate.
Mr. Johnson entered federal service in 2011, following more than 24 years of service in the U.S. Army. Prior to becoming the Director of the DoD CIO Cyber Workforce, Mr. Johnson served in a variety of positions in the Department, rising to his position today from his first role as Intelligence Combat Developer, with the U.S. Army Intelligence and Security Command (INSCOM). In his expansive civil service career Mr. Johnson has also served as Deputy Director, Military Personnel DLA; Cyber Integrator, OSD Personnel and Readiness (P&R); Senior Program Manager (Retention), Deputy Chief of Staff Army G-1.
Mr. Johnson spent his early career in the U.S. Army, serving as a Military Policeman, Protective Service Agent, Military Police Investigator, and Career Counselor culminating in his role as Special Liaison with U.S. Army Intelligence Support Activity within the Joint Special Operations Command (JSOC).
Episode Links* Tech Transforms Ep. 69 with Jon Pelson * Guardians of the Galaxy Vol. 3 * Star Wars VR Games
Meet the man on a mission to make software bill of materials (SBOMs) boring. In this So What? episode, Tracy Bannon and Carolyn Ford sit down with Allan Friedman the Senior Advisor and Strategist at the Cybersecurity and Infrastructure Security Agency (CISA). Allan tells us about how he is working to change how all software on the planet is made and sold, no big deal right? Join us as we dive into the world of SBOMs, xBoMs, and Secure by Design.
Key Topics* 03:59 Track open source licenses, establish shared vision. * 08:47 Discussing US government requirements, diversity in software. * 12:07 Framework helps organizations with secure software development. * 13:49 Organizations unaffected, prepare for impending software changes. * 17:40 Concerns about sharing software with potential security risks. * 20:59 Concerns about network security and regulatory pushback. * 24:14 Enhanced security measures save thousands of hours. * 27:53 Applying AI and data bombs in conversation. * 32:38 Discusses the importance of SBOM in cybersecurity. * 36:29 Rewriting global code is a complex task. * 39:39 At RSA, little focus on secure design. * 41:53 Organization's need for SBOM, call to action. * 43:55 Cooking for diverse family, diverse food requirements.
Challenges and Implementation of SBOMsSelf-Attestation for SBOMsAllan Friedman explained that there is currently a self-attestation model for SBOMs, where companies can sign a form stating that they have implemented SBOMs, rather than providing the actual SBOM data. This allows flexibility for organizations that are not yet ready to fully comply. However, it means buyers have to trust the attestation rather than seeing the SBOM details directly.
Secure Software Development Model Compliance: "The challenge there is turning the framework back into a compliance model. Because, again, at the end of the day, everyone wants to think about things. Right? Understand your risk, but you still need to make that yes or no decision."— Allan Friedman
Tracy Bannon noted some companies have concerns about sharing their SBOM data with customers, worrying that the customer may not have secure enough practices to properly protect the SBOM. Allan Friedman explained SBOMs do not need to be public - they can be shared privately between supplier and customer. Known unknowns in the SBOM can also help address concerns about revealing proprietary information.
Debate About the Risk of Sharing SBOMs as a Road Map for AttackersAllan Friedman argued that sophisticated attackers likely do not need the SBOM, as they have other ways to analyze and reverse engineer software. Automated attacks also do not leverage SBOMs. He noted defenders actually need the visibility an SBOM provides into components and dependencies. There may be some risk of exposing attack surface, but the benefits seem to outweigh that.
The Importance of SBOM for Product Security: "If we had this, we had SBOM across our products today, it would save us thousands of hours a year Because whenever the next Log4j comes out, if you have a centralized machine readable, scannable system, It's not that hard." — Allan Friedman
Allan Friedman noted there has been some lobbyist pushback against SBOM mandates, often coming from trade associations funded by companies already implementing SBOMs. He said while healthy debate is good, many of the lobbyist complaints seem misguided or overblown.
The Potential Role of AI in Creating SBOMs and Its Implications for SecurityCarolyn Ford asked whether AI could help automate SBOM creation, especially for legacy systems. Tracy Bannon cautioned that AI is not yet at the point where it can reliably generate code or understand large complex contexts. AI may eventually assist, but currently is not ready to take on SBOM tasks. As AI is software, it needs to be secured using the same best practices as other code.
Tracy Bannon explained SBOM implementation may be harder for organizations with large legacy codebases and multiple complex or siloed systems. However, even newer companies can struggle if they have not built SBOM processes into their SDLC. Allan Friedman noted while costs exist, especially for older systems, SBOMs ultimately save defender time and money.
Benefits of Better Engineering ProcessesAllan Friedman said some organizations view SBOM mandates positively, as it gives them budget and justification to reengineer antiquated processes. Overall, SBOMs provide incentives and reasons to follow modern secure software practices.
Tracy Bannon emphasized that any mandated change involves costs, which need to be acknowledged. But driving adoption of SBOMs and secure development practices is still an important improvement goal. Organizations should be supported in this transition.
Government Requirements and StandardsComplexities of US Government Requirements for SoftwareAllan explains that the executive order issued requirements that all software sold to the US government would need to meet certain security practices, like having separate development and build environments and using multi-factor authentication. While these may seem basic, turning the NIST framework into concrete compliance requirements has been challenging. The government pushed for a quick definition of SBOMs, while agencies said it would take months. There's a need to balance the push for progress with the realities of implementing changes across complex legacy systems.
Open Source License Tracking: "And if you're an organization, you need to track which open source licenses are you using both in your open source and your code because there are strong rules for some of them."— Allan Friedman
For some parts of the software world, Allan notes that SBOMs are already considered standard practice. Modern developers with continuous integration pipelines can easily generate SBOMs automatically. The challenge is bringing along the organizations still using legacy tools and processes. Widespread adoption will take time. The goal is for SBOMs to become a boring, expected part of software delivery that doesn't require much discussion.
Timeline and Process Following the Executive OrderThe 2021 cybersecurity executive order mandated the use of SBOMs but didn't define what they were. After pushing for a faster timeline, the government issued a minimum definition of SBOMs within 60 days. NIST then updated their secure software development framework with guidance. The next step is moving from framework to compliance model, with self-attestation as a starting point until more formal requirements are in place across agencies.
The executive order mandated SBOMs but didn't define them, so the government had to quickly issue a minimum definition of what constitutes an SBOM. This was a challenging process that required balancing perspectives from across government and industry. The public and private sectors need a shared understanding of what SBOMs are as adoption spreads.
Concerns and SolutionsConcerns From Corporations and Suppliers About Revealing Proprietary InformationAllan acknowledges there are concerns from some corporations and suppliers that providing an SBOM could reveal proprietary intellectual property or special sauce in their software products. Many organizations want to avoid exposing their competitive advantage or secret methods. Allan says the SBOMs do not need to be public - they can be shared directly and privately with the customer purchasing the software. There are also ways to designate known unknowns or gaps in the SBOM data.
The Importance of Software Bill of Materials (SBOM): "We're building the plane while we're flying it."— Allan Friedman
Tracy raises the concern she has heard that requiring companies to share SBOMs with customers could potentially expose their intellectual property if those SBOMs are not properly secured. She notes there have been many high-profile data breaches lately. This means vendors may be wary about sharing an SBOM with a customer if they lack confidence in that customer's data security practices. There needs to be trust between the entities exchanging SBOMs.
Claims Regarding the Majority of SBOMs Content Not Being SecretiveIn response to concerns about IP exposure, Allan argues that for most large software projects, the bulk of what is contained in an SBOM does not represent core proprietary IP or secret sauce. As an example, he says that just listing common third-party libraries used does not reveal a competitive advantage. So fears may be overblown about SBOMs leaking meaningful intellectual property.
Given the valid concerns around proprietary code exposure and SBOM generation limitations, Allan advocates for the concept of designating "known unknowns". This would allow software providers to specify areas of the codebase or supply chain that have incomplete SBOM data due to proprietary restrictions or tooling gaps. Known unknowns enable transparency about the boundaries of SBOM coverage.
Software Supply Chain Security and SBOMsBuffer Overflows and Memory Unsafety in Programming LanguagesAllan Friedman explained that a large percentage of vulnerabilities arise from memory issues. Buffer overflows are a simple example, but there are thousands of variants that allow attackers to execute malicious instructions by tricking a system into accessing attacker-controlled memory regions. This memory unsafety occurs primarily in languages like C and C++ that lack memory safety protections.
Given the risks from memory unsafety, Friedman discussed CISA's vision of pushing more secure software development through the use of memory-safe languages. Languages like Rust and Go provide memory safety protections that prevent common categories of vulnerabilities. However, rewriting major legacy codebases will take time. CISA is exploring partnerships and incentives to accelerate adoption of memory-safe languages over the long term.
Group Dealing With a Large ADA Code Base and Other LanguagesTracy Bannon noted that some organizations, unfortunately, cut budgets by avoiding automated testing in favor of manual testing. But requirements like SBOMs remove excuses to not invest in automated processes and improved engineering.
Tracy Bannon mentioned there are ongoing conversations with the Department of Defense around extending the SBOM concept to data through "data bombs." While AI and algorithms are software, data artifacts like model cards and data cards also need supply chain transparency.
Bannon highlighted that she works with a group managing a complex codebase including not only a substantial amount of ADA, but 13 other languages layered onto the system. This exemplifies the challenges of legacy systems.
Friedman explained that CISA's director and CISO have been pushing the secure by design initiative to make software more inherently secure out of the box. He provided examples like moving away from hardening guides and instead selling software locked down, with optional integration instructions.
About Our GuestAllan Friedman is a Senior Advisor and Strategist at the Cybersecurity and Infrastructure Security Agency (CISA). He coordinates the global cross-sector community efforts around software bill of materials (SBOM). He was previously the Director of Cybersecurity Initiatives at NTIA, leading pioneering work on vulnerability disclosure, SBOM, and other security topics. Prior to joining the Federal government, Friedman spent over a decade as a noted information security and technology policy scholar at Harvard’s Computer Science Department, the Brookings Institution, and George Washington University’s Engineering School. He is the co-author of the popular text Cybersecurity and Cyberwar: What Everyone Needs to Know, has a C.S. degree from Swarthmore College, and a Ph.D. from Harvard University.
Episode Links* Executive Order on Improving the Nation’s Cybersecurity * CISA’s Software Bill of Materials (SBOM) Page * CISA Blog from Christine Lai and Dr. Jonathan Spring * Allspice Dram in Cocktails
In the final, crossover episode of our three-part Halloween series, Eric Monterastelli, Public Sector SE at Delinea, Founder, Crew Chief of Gran Touring Motorsports and Host of the Break/Fix Podcast, joins Carolyn Ford and Tracy Bannon to discuss the scary reality of car security. Is your car spying on you? Can a nefarious actor take over your car? Does your car know your deep personal data like your immigration status, race and more? Hint: It can and it does.
Key Topics* 00:02:05 Technology advances put vehicles at risk. * 00:06:25 Hijacked Jeep's wireless signal, turning it off. * 00:07:35 Chrysler systems hacked due to digital admission. * 00:10:47 New EV platforms streamline technology for efficiency. * 00:15:13 Disconnect, purge and be careful: data can be accessed. * 00:18:58 Using TrueCar, author obtained personal information illegally. * 00:21:54 Pre-OBD2 Mercedes is OBD1. * 00:25:12 Mozilla uncovers alarming auto data collection. * 00:28:29 Future vehicles will have integrated alcohol-detection systems. * 00:32:48 Routers, cars can be hacked, collect data. * 00:35:42 Read your vehicle's owner's manual for instructions. * 00:36:55 Speak to rental clerk about removing data.
The Intersection of Cybersecurity, Car Security and the Ghostbusters MissionGhostbusters Mission: Car Security & Car HackingEric Monterastelli talks about how cars have evolved to include more computing technology, which opens them up to potential attacks. He gives the example of a Jeep that was hacked to shut off while driving, demonstrating the real dangers.
Tracy Bannon contrasts U.S. car manufacturers that use many third-party components versus Tesla's more integrated system. She argues Tesla's approach may lend itself to more car security. The hosts explore different potential attack vectors into vehicles, like Bluetooth connections.
Mozilla Participants Share Automotive InfoSec InsightsEric Monterastelli shares findings from a Mozilla report about the wide range of deep personal data that can be collected from cars. Including things like facial expressions, weight, health information and more. The hosts are alarmed by the privacy implications.
Tracy Bannon advocates that car manufacturers need to make cybersecurity a priority alongside traditional safety. She indicates cars are data centers on wheels, collecting information that gets sent back to big cloud data centers. They emphasize the need for vigilance from car owners about what information they allow their vehicles to collect.
Concerns About Data Collection in Modern VehiclesModern Car Security: Braking, Speed and Steering PatternsEric discusses the extensive data that is now collected by modern vehicles, especially EVs. He notes that information is gathered on things like stopping distances, brake pressure applied, vehicle speed and overall driving habits. This data is no different than the type of driver performance analysis done in race cars. Automakers are collecting real-world usage data from customer vehicles to analyze driving patterns and vehicle responses. Tracy adds that the average new vehicle contains over 100 different computers and millions of lines of code that are all networked together. This networked data covers areas like powertrain functions, safety features and infotainment systems. All of this interconnected data presents opportunities for tracking very detailed driving behaviors.
Privacy Risks in Driving: Collecting Personal Data and ConcernsEric cites a concerning report that modern vehicles can potentially collect extremely sensitive personal data simply through normal driving. Including information on immigration status, race, facial expressions, weight, health conditions and even genetic data. He explains that optical facial recognition software could be applied to cameras already present in many vehicles. Other data like weight and health metrics can be gathered from sensors in seats or wearable devices synced to the vehicle. The interconnected nature of modern vehicle computers and far-reaching data collection enables mining of very private user information that goes well beyond basic driving statistics. Carolyn reacts with disbelief at the potential extent of personal data gathering described.
Car Security Comparisons Between Traditional Manufacturers and TeslaChallenges in U.S. Car Manufacturing Component CompatibilityTracy explained that traditional U.S. car manufacturers have said they use components from hundreds of different distributors and providers. These components were not necessarily created to work together, unlike the approach taken by Tesla. Since traditional manufacturers are buying piece A and knitting it together with piece B, piece C and piece D, there can be integration challenges. The components may not align well since they were not designed under the same umbrella with a holistic approach.
Comparing Tesla's Integrated Approach to Enhance Car SecurityTracy contrasted the traditional manufacturers' approach with Tesla, which has created everything under one umbrella. Tesla told any component providers what the requirements were and how the components needed to align to what Tesla needed. This holistic approach within Tesla results in more seamlessly integrated and likely more secure vehicles compared to cobbling together components from many different organizations.
Tesla's Privacy Concerns: "But Tesla, there's been reports and there's been investigations showing that they can turn on the cameras inside the car and see what you're doing. They've been spying on people. There's been all sorts of allegations that have been thrown out there." — Eric Monterastelli
Combining Car Parts from Various Sources Raises Security RisksEric and Tracy discussed how having disparate systems talking over a common bus and language can introduce vulnerabilities. While a proprietary closed system like Tesla's may have risks if it is fully hacked. Assembling many components from different providers can also have downsides. There are more potential holes or vulnerabilities when piecing together parts from various organizations. Compared to having everything designed and built under one umbrella.
Integration of Systems in Modern CarsUnified Mainframe Powers Modern Electric Vehicles, Replacing Separate ComponentsEric discusses how newer electric vehicles like Teslas, Ford Mach-Es, and Porsches have a single mainframe that controls and interacts with all the components of the vehicle. In contrast, older cars had separate systems for the engine/drivetrain and infotainment that did not necessarily communicate with each other. For example, in a 2000s Chrysler, the infotainment system running the radio was separate from the encrypted Bosch system controlling the engine. Integrating all these components into one mainframe makes the new electric vehicles more convenient but also introduces potential vulnerabilities.
Single Computer Control and Car Security Vulnerabilities ExploredTracy elaborates that the average new car today has over 100 different embedded computers. plus modules networked together and communicating via a CAN bus system. So there is one central computer that can interact with the engine, transmission, safety systems and infotainment features. While this integration is designed for efficiency and effectiveness of the software systems, it also means one access point can potentially control multiple components of the car. This is different from older cars where systems were more isolated from each other. The interconnectedness makes modern vehicles potentially more susceptible to cyber attacks.
The Vulnerabilities of Modern Vehicles: "For me, that's a scary reality. And it actually has shied me away from buying the newest of the new cars even though there are some really exciting things out there because what am I opening myself up to, if I buy a Ford Mach-E or a Tesla Model 3 or something else." — Eric Monterastelli
Vulnerabilities and Risks in Modern CarsIntegrating ML and AI into Cars through Computing AdvancementsEric discussed how cars have evolved significantly in engineering since the early 1900s. He highlighted that around 2000, more powerful computing technology like ML and AI computers were integrated into vehicles to make decisions about engine performance and interact with various systems. This advancement allowed for additional "creature comforts" in cars. But also opened them up to potential attacks and vulnerabilities that older cars did not face.
Future of DUI Prevention: "It's gonna become standard issue like power windows and remote locks and things like that where you're not even gonna be able to drive and operate a vehicle if it senses that you're in any way inebriated or under the influence." — Eric Monterastelli
Modern Vehicles' Complexity Heightens Vulnerabilities and Security RisksEric further acknowledged that consolidating disparate systems into one mega computer, while making things more convenient, also introduced vulnerabilities. With everything controlled by one mainframe, the attack surface is larger. He contrasted modern vehicles to cars from the mid-2000s, where engines were still separate from entertainment systems. Now they are fully integrated, which provides more connectivity but less isolation among components.
The Electric Vehicle Boom and Its Impact on Digital SystemsAccording to Eric, the rise of electric vehicles has led to even more potential issues, as they rely even more heavily on electrical systems and digital connectivity like over-the-air updates. Features that make EVs exciting also make them more susceptible to cyber threats compared to traditional internal combustion cars. The reality that EVs open owners up to unknown risks has made Eric shy away from the newest vehicles.
Differences in Car Security Among Manufacturers Contrasting Tesla and Porsche Systems: Unified Communication vs. Proprietary ApproachEric compared Tesla's interconnected systems to Porsche's components from various suppliers like Bosch. He said Tesla has full access to proprietary systems through the air, while Porsche uses a CAN bus for disparate systems to communicate. The closed nature of Tesla's system makes it completely open to them.
Tracy added more context, mentioning Porsche is connected to VW and Audi, who work with Bosch for many electromechanical parts like sensors and multifunction interfaces. She reiterated that these disparate systems in Porsche communicate via a CAN bus system.
Eric acknowledged Tracy's point that both brands use a CAN bus for the back-end electrical system. However, he still sees more risks with Tesla having full access to a closed proprietary system through the air versus Porsche's various supplier components that don't directly communicate beyond the CAN bus.
Risks of Personal Data Storage in CarsStoring Personal Data in Car Infotainment Beyond Phone DisconnectTracy explained that even after disconnecting your phone from a car's infotainment system, personal data like contacts and GPS history can remain cached in the system. She warned that simply pressing "disconnect" does not purge the infotainment system of your data. Eric added that unless you fully wipe the system, your data remains stored even after trading in or selling your car. He gave the example of someone pulling a used head unit from a junkyard car, and upon powering it up having full access to the previous owner's contacts and address history.
Cyber Security Perspective on Data Collection in Cars: "They can collect deep personal data such as sexual activity, immigration status, race, facial expressions, weight, health, and genetic information while you're driving." — Eric Monterastelli
Car Disposal Doesn't Ensure Personal Data Erasure from Head UnitTracy shared that her husband takes extensive precautions to prevent others from accessing personal data, such as degaussing old hard drives before disposal. She explained these same precautions should be applied to cars, since simply trading in or scrapping a car does not mean personal data is removed from components like the infotainment system. Eric affirmed this concern, stating that short of an EMP blast, data remains recoverable from the car's memory chips even after the car changes owners. He advised thoroughly wiping car systems before sale to prevent exposing personal information.
About Our GuestEric Monterastelli is the Public Sector SE at Delinea, Founder and Crew Chief of Gran Touring Motorsports and Host of the Break/Fix Podcast. He has more than 18 years of experience in information technology, specializing in systems engineering, virtualization and software development. His previous stops include Dynatrace, BAE Systems, Raytheon, the Department of Defense, LogRhythm and Symantec, among others.
Episode Links* Break/Fix Podcast * Andy Pilgrim Episode of Break/Fix Podcast * Mozilla Article on Car Privacy * Tech Transforms Halloween Series Episode 1 * Tech Transforms Halloween Series Episode 2
In the second episode of our 3-part Halloween series, Grant Schneider, Senior Director of Cybersecurity Services at Venable and former federal CISO, discusses the frightening implications of insider threats, how we are protecting critical infrastructure, and what it was like working on cybersecurity in the White House under both President Obama and President Trump.
Key Topics* 00:03:59 Increased consequences led to rise of cybersecurity * 00:08:47 Insider threat, screening, hiring, malicious actor, Manning, Snowden * 00:09:53 Snowden challenges legality of government surveillance * 00:15:00 Adversary gains access, steals information, demands ransom * 00:19:19 Different levels of readiness present challenges * 00:23:15 Helping clients & coalitions for cybersecurity policy * 00:24:58 Consistency in technology and cybersecurity under past presidents * 00:27:47 Cybersecurity is like warfare or terrorism * 00:32:30 AI tools and data drive persuasive information * 00:34:50 National Cybersecurity Awareness Month raises awareness on cybersecurity and encourages action to protect businesses * 00:42:40 Diversity of experiences leads to career growth * 00:44:01 Adaptive, willing, and able to learn
Introduction to National Cybersecurity Awareness MonthPurpose of Raising Awareness About CybersecurityGrant explained that one of the great things about National Cybersecurity Awareness Month is exactly raising awareness and providing an opportunity to hopefully spend time thinking about and discussing cybersecurity. He noted that for organizations already focused on cybersecurity daily, the awareness month may not raise their awareness much more. However, many organizations don't constantly think about cybersecurity, so for business leaders and executives who may now recognize the existential threat a cyber incident poses, the awareness month offers a chance to have important conversations they may have previously avoided due to lack of understanding.
National Cybersecurity Awareness Month: "You're only one bad kind of cyber incident away from your organization not existing anymore."— Grant Schneider
Opportunities for Organizations to Have Conversations About CybersecurityAccording to Grant, leaders who don't grasp cybersecurity risks may personally fear initiating conversations to ask what the organization needs to do to address risks. National Cybersecurity Awareness Month provides an opportunity for these leaders to have the necessary conversations and gain education. Grant said the awareness month is a chance to discuss basics, like implementing multifactor authentication, patching and updates. He observed that much of the content produced for the awareness month focuses on cybersecurity fundamentals, so it allows organizations to dedicate time to shoring up basic defenses. Overall, Grant emphasized National Cybersecurity Awareness Month facilitates essential cybersecurity conversations for organizations and leaders who otherwise may not prioritize it consistently.
Evolution of Insider Threat in the Intelligence CommunityScreening Out Bad Actors During the Hiring ProcessGrant explains that in the early days of his career at the Defense Intelligence Agency (DIA), insider threat mitigation focused on screening out bad actors during the hiring process. The belief was that malicious insiders were either people with concerning backgrounds trying to get hired, or nation-state actors attempting to plant individuals within the intelligence community. The screening process aimed to identify and reject potentially problematic candidates.
Nation-State Actors Planting Individuals Within the CommunityHe mentions the possibility of nation-state actors attempting to plant malicious insiders in the intelligence community through the hiring process. This underscores the perceived risk that foreign governments would try to insert spies or saboteurs into the ranks of U.S. intelligence agencies.
Shift Towards Insiders Becoming WhistleblowersGrant then discusses how over time, the nature of insider threats shifted more towards insiders becoming whistleblowers driven by ideology or moral objections. He cites the Manning and Snowden cases as examples of this shift. Rather than foreign plants, these were trusted insiders who went on to leak classified information out of claimed conscience.
Importance of Not Making Negative Generalizations About WhistleblowersWhile describing this evolution, Grant is careful not to make generalizations condemning all whistleblowers. He maintains that whistleblowing serves an important function in society.
Snowden’s Different View on the Community’s Work and His ActionsIn Snowden's case specifically, Grant characterizes his mindset as believing the intelligence community's lawful work was actually wrong. This led Snowden to take matters into his own hands by leaking classified materials.
Importance of Diversity of Experiences for Personal and Professional GrowthActively Seeking Out Different Experiences Within Current RoleGrant emphasized the importance of seeking diversity of experiences, even within one's current job. He advised not constantly changing jobs, as that may look unfavorable on a resume. However, within a role, one should actively volunteer for new projects and tasks that provide exposure to different skills. Being willing to say "yes" and take on unfamiliar work leads to becoming a more versatile, well-rounded employee.
Saying Yes to New OpportunitiesGrant recommended that when presented with new opportunities at work, such as a manager asking for someone to work on a certain project, the best approach is to always say yes. Even if the work does not seem interesting or relevant, accepting the challenge provides a chance to learn new skills. Saying yes demonstrates eagerness to expand one's capabilities.
The Importance of Diversity of Experiences: "Diversity of experiences, and whatever it is you're working on, when your boss, your coworkers say, hey, we're looking for someone to work on this, always say YES. I wanna go work on that as well."— Grant Schneider
Becoming a Well-Rounded Employee and LeaderAccording to Grant, embracing diverse experiences allows professionals to build unique skill sets and make themselves stand out. Having broad exposure equips individuals to work effectively on varied teams and projects. It enables adaptability that makes one a more valuable contributor. Grant emphasized that diversity of experience helps shape well-rounded leaders who can thrive in any environment.
View Work and Life as a Scavenger Hunt for Acquiring SkillsGrant suggested viewing one's career progression as a scavenger hunt to collect talents and capabilities. Being strategic and purposeful about pursuing different opportunities maximizes growth. Grant urged professionals to reflect on the skills they want in their toolbox and then leverage jobs and other life experiences to intentionally develop expertise across multiple areas.
The Consequences of Cyber Incidents and the Growth of CybersecurityIncreased Consequences of Cyber IncidentsAs Grant explained, when he first joined DIA, there were no connections to the unclassified internet in the building. Over time, every employee had both unclassified and classified computers to connect to various networks. As more devices were connected to networks, the potential consequences of a cyber incident grew. With more reliance on technology and interconnected systems, a cyberattack could cause major disruptions to operations. Grant noted that this increase in risk led to a greater focus on cybersecurity within both government and private sector organizations.
The Consistency of Approach Towards Technology and Cybersecurity across Administrations: "In my opinion, technology and cybersecurity has not been very politicized. And really going back from Bush to Obama, to Trump and to Biden, in my opinion, we've seen a good bit of consistency around the directions, the people have been headed."— Grant Schneider
Creation of Dedicated Security Operations CentersGrant discussed how the growing risks from cyber incidents led to the creation of security operations centers focused on monitoring threats. Whereas IT operations teams had previously handled security, cybersecurity emerged as its own discipline requiring specialized skills and 24/7 vigilance. Organizations established dedicated security operations centers tasked with detecting and responding to security events around the clock. This represented a major shift as cybersecurity transitioned from a purely policy function to an operational capability within organizations.
Cybersecurity as a Distinct Operational Entity in Public and Private SectorsOver the years, cybersecurity evolved from an information security policy role to a distinct operational entity, according to Grant. This transition occurred in both the public sector and private sector as the nature of threats changed. Cybersecurity is now recognized as requiring its own set of skills and continuous monitoring separate from traditional IT operations. Grant noted that this shift has continued with cybersecurity capabilities and staffing growing significantly across sectors.
Understanding and Manipulating Information in CyberspaceIncreasing Availability of Data and AI ToolsGrant discussed how there is more and more data available now as compared to the past. He also mentioned how AI tools allow people to analyze and understand this data in new ways. For example, AI can help determine what information or messages are most likely to resonate with someone based on what is already known about their views and preferences. Grant suggested that the combination of more data and better AI-enabled analysis means information can be tailored and targeted to individuals in new ways, for good or bad purposes.
Delivering Messages That Resonate With Individuals, Regardless of TruthBuilding on the availability of data and AI tools, Grant noted how messages can now be crafted in a customized way for each person. He said that tools allow understanding of what is believable to each individual. Then messages can be created that align with existing beliefs and preferences, regardless of whether the messages are factually true. Grant gave the example that false information could potentially be spread this way if the content resonates with what someone already thinks.
Society’s Acceptance of Divisive and Blunt OpinionsGrant suggested that technology capabilities enabling tailored messaging are emerging alongside the increased societal acceptance of divisive, controversial and blunt opinions being shared publicly. He noted that norms seem to have changed from when there were more things people didn't express out loud. Grant proposed that this societal shift combined with technological capabilities that can take advantage of divisions creates risks in terms of information manipulation.
About Our GuestGrant Schneider’s entire 30-year career has focused on our nation’s security. Grant spent more than 20 years at the Defense Intelligence Agency, seven of which he served as the CIO. He then spent six years in the Executive Office of the President during the Obama and Trump administrations, focused on all aspects of federal and critical infrastructure cybersecurity. During that time, he served as a Senior Director for Cybersecurity Policy on the National Security Council staff and most recently as the Federal CISO. For the past three years, Grant has served as Senior Director of Cybersecurity Services at Venable, helping companies from across all sectors enhance their cybersecurity programs through the development and implementation of risk management programs as well as assisting with the preparation, response, and recovery from various cyber incidents, including ransomware.
Episode Links* Colonial Pipeline hack * Live Free or Die Hard * Alliance for Digital Innovation
In the first episode of our 3-part Halloween series, Dave Egts, Mulesoft Public Sector Field CTO at Salesforce, details what's scaring the public sector most and how Salesforce is utilizing - and securing - AI to improve customer experience with their Einstein Trust Layer. Additionally, Carolyn and Dave dive into the spooky worlds of brain cell chips, mind-reading AI and more.
Key Topics* [02:17] Starting the Dave & Gunnar Show * [04:14] Dave's Role At Salesforce * [05:18] What's Scaring the Public Sector Most? * [10:22] Ways Agencies are Attracting Talent * [13:56] How Agencies Are Handling Legacy Systems * [15:45] What MuleSoft Does & Generative AI's Role * [22:44] Salesforce's Einstein Trust Layer * [29:21] PoisonGPT * [36:07] Brain Organoids & Other Spooky, Ethically Questionable Experiments * [42:15] Tech Talk Questions: Halloween Edition
Quotable QuotesConsiderations for the Public Sector While Using AI: "As you're going on your AI journey, you've got to be looking at the EULA [End User License Agreement] and making sure that, okay, if I give you data, what are you going to do with it?"
On Bias & Disinformation in Generative AI: "There were some previous studies that show that people are more likely to go with the generative AI results if they trust the company and they trust the model. So it's like, 'Oh, it came from Google, so how can that be wrong?' Or 'I'm trusting the brand,' or 'I'm trusting the model.'"
About Our GuestDavid Egts is MuleSoft’s first-ever Public Sector field CTO. Outside of MuleSoft, David is the founding co-chair of the WashingtonExec CTO Council, where he advises numerous companies on working with the public sector. David has received numerous industry-wide recognitions, including as an FCW Federal 100 winner, a FedScoop 50 Industry Leadership awardee and one of WashingtonExec’s Top Cloud Executives to Watch. He has won multiple employee honors from Red Hat, Silicon Graphics and Concurrent Technologies Corporation.
Episode LinksDave & Gunnar Show Episodes
Additional Links
In this So What? episode, Jon Pelson, author of the best-selling book "Wireless Wars," discusses China’s impact on the telecommunications space. He also shares the frightening security concerns around Chinese components in 5G networks and discusses why the FCC's ban on these components may not be enough.
Key Topics* [01:30] China's Success in the Telecom Industry * [05:12] China's Grip on 5G * [08:29] Are Your Communications Ever Private? * [13:00] The Influence of Technology * [15:53] What Would Happen if China Got Control? * [19:20] FCC Ban on Chinese Components * [24:50] Huawei's Placement Strategy * [30:05] Is the FCC Ban a Good Start? * [38:42] How America Takes Back Control * [44:51] Tech Talk Questions
Quotable QuotesOn Huawei's Tower Placement: "Our nuclear missile bases, our special operations command at the nuclear sub base are all served by Huawei cell equipment." I said, 'That's impossible. They have like 0.1% market share. How could they have every nuclear missile site?' I started looking into it. The reason I called the book 'Wireless Wars' is because it's a war that's being fought through what appears to be business means. This is not business." -Jon Pelson
On Why We Should Protect Data: "People say, 'I have nothing to hide.' Especially the younger generation says, 'Look, my privacy, in that regard, is not that important.' I was asked at the end of an interview, 'What would happen if China got control over us the way they're trying to?' I said, 'You don't have to scratch your head and do scenario planning. Look at places where China has control over the population.' -Jon Pelson
About Our GuestJon Pelson spent nearly 30 years working as a technology executive, including serving as vice president at Lucent Technologies and chief of convergence strategy for British Telecom. His work with China’s telecom industry during this time led Pelson to write his best-selling book "Wireless Wars" China’s Dangerous Domination of 5G and How We’re Fighting Back."
Episode Links* The Kill Chain by Christian Brose * Paul Scharre's Tech Transforms Episode * Focus * Breaking Bad * Boyd by Robert Coram * Undaunted Courage by Stephen Ambrose
On this special episode, Willie Hicks and Carolyn Ford discuss the Billington Cybersecurity Summit, as well as insights from panels, led by Willie, on workforce automation and zero trust.
Key Topics* [00:22] Willie's Workforce Automation Panel Highlights * [03:28] The Difference Between Training & Education * [11:11] Securing Data In A Zero Trust World Panel Highlights * [16:31] Willie's Experience with Constant Reverification While Working in Financial Data Protection * [20:44] Overarching Impressions from the Billington Cybersecurity Summit
Quotable QuotesOn the Human Factor: "I think this is always the case, that the human's usually going to be the weakest link. We're always the weakest link. But that's why that constant reverification is so critical."
On Generative AI: "We can't fear these things like generative AI. We've got to embrace it. We've got to use it. We've got to figure out how to use it and use it right and use it appropriately. But we have to figure out how to use it because you know who's using it? Our adversaries."
About Our GuestWillie Hicks is the Public Sector Chief Technologist for Dynatrace. Willie has spent over a decade orchestrating solutions for some of the most complex network environments, from cloud to cloud native applications and microservices. He understands tracking and making sense of systems and data that has grown beyond human ability. Working across engineering and product management to ensure continued growth and speed innovation, he has implemented Artificial Intelligence and automation solutions over hundreds of environments to tame and secure their data.
Episode Links* Billington Cybersecurity Summit Speakers * Tech Transforms with Tom Billington * Tech Transforms with Ann Dunkin * Mission Impossible
Sandi Larsen, Vice President, Global Security Solutions at Dynatrace, joins our host Carolyn Ford to share her perspectives on the relationship between zero trust and defense in depth. She also discusses her storied career, leadership and what it's like to be a woman in technology (although she dislikes the term). Additionally, Sandi shares her advice on identifying mentors, finding your voice and battling imposter syndrome.
Key Topics* [00:00] Introduction * [01:10] Sandi's Role at Dynatrace * [03:11] Sandi's Take on Zero Trust & Defense in Depth * [09:21] Sandi’s Career Path * [19:01] People in Technology and the Gender Gap * [25:26] Sandi's Key Takeaway for Listeners * [27:37] Tech Talk Questions
Quotable QuotesOn Finding Inspiration: “You just can't sleep on these pivotal people in your career whether they're ahead of you or beside you or even behind you, I’ve been inspired by people that I am mentoring.”
On Having Mentors: “Find mentors, they are just invaluable and will be throughout your whole entire career, no matter what stage you're in. At the beginning, at the middle, later in your career, they will always be indispensable for you.”
On Using Your Voice: “Speak up. Just have a voice. And if that voice in your head is planting doubt, don't listen to it. If it's coaching you on what to say and what not to say, and being wise about that, listen to that. But if it's planting seeds of doubt, you've got to you have to push it aside. And you have to take that step. Because if you don't, you might be missing out on the next best thing.”
About Our GuestSandi Larsen currently serves as the Vice President of Global Security at Dynatrace. Prior to joining Dynatrace in November 2020, Sandi held various positions, including sales and systems engineering roles in cybersecurity and financial services organizations.
Episode Links* The Bear * The John Maxwell Leadership Podcast * The Tim Ferriss Show
Tom Billington, CEO of Billington CyberSecurity and Producer of the Billington CyberSecurity Summit, joins Carolyn and co-host Mark Senell to discuss the upcoming 14th Annual Billington CyberSecurity Summit, what goes into creating a valuable community for both the government and the commercial sector, and the important topics that will be the basis for this year's conference.
Key Topics* [02:58] - Founding the Billington Cybersecurity Summit * [09:59] - Developing Conference Topics * [12:43] - Bridging Federal and Commercial Cybersecurity * [16:02]- Critical Infrastructure at Billington * [19:04] - Commercial Industry at Billington * [21:45] - Registering for The Summit * [22:49] - Preparing Key Conference Themes * [24:46] - Hottest Topics at Billington This Year * [27:03] - What’s New About Zero Trust * [28:22] - Tech Talk Questions
Quotable QuotesOn Founding Billington Cybersecurity Summit: "I really started this business to be distinctly patriotic, to provide a serious dialogue in a way that I felt wasn't really being done at that time...So breaking into the federal cybersecurity community, to be honest, was hard as an entrepreneur. We had to build trusted relationship after trusted relationship. Over the course of 14 years, it's become decidedly easier now, now that we have had the privilege of having those trusted relationships."
On Zero Trust: "Many of the areas that zero trust encompasses have been around since the profession has existed in cybersecurity. But at no other time has the U.S. government proclaimed the importance of this overarching field as it has in the last few years. So it becomes important for the government. It becomes important for the industry leaders who serve them."
On International Cyber Collaboration:"So it's not just the U.S. team sport. It's an international team sport. The partnership with our international allies is crucially important."
About Our GuestBefore launching his company in 2010, Tom Billington spent nearly two decades producing hundreds of events, publications and articles for four of the world’s leading media companies: Reader’s Digest, Phillips Business Information, BNA (now Bloomberg BNA) and Thomson Reuters. Now, Tom is the CEO and Founder of Billington CyberSecurity, a leading independent education company founded in 2010 with an exclusive focus on cybersecurity education. Every year, he hosts the Billington Cybersecurity Summit, which is known as the world's leading government summit on cybersecurity with the unique educational mission of convening the who's who in cybersecurity: the senior leadership from the U.S. government, our allied partners, and their industry and academic partners.
Episode Links* 14th Annual Billington Cybersecurity Summit Agenda * Ann Dunkin on Tech Transforms * Books By Kevin Mitnick
Ann Dunkin, Chief Information Officer (CIO) at the U.S. Department of Energy (DOE), joins Carolyn and guest host Willie Hicks to discuss the National Cybersecurity Strategy and what it takes to secure a large agency like the DOE, as well as how agencies balance cybersecurity compliance and risk management. She also highlights the DOE's role in the Partnership for Transatlantic Energy and Climate Cooperation (P-TECCC) and the agency's relationship with its industry partners.
Key Topics* [01:47] - Affect of the National Cybersecurity Strategy on DOE Modernization Initiatives * [07:59] - Risk vs. Compliance * [14:17] - Protecting a Large Agency like DOE vs. Smaller Agencies * [16:49] - P-TECC Overview & DOE's Work with P-TECC * [23:14] - Implementing Lessons Learned from the Global Community * [26:11] - DOE Modernization Efforts & The Role of Public-Private Partnerships * [30:26] - Where Industry Can Improve * [36:03] - Tech Talk Question
Quotable QuotesOn the Collective Defense: "The principles of collective defense, which underlie the cybersecurity strategy are incredibly important. That concept that we can't individually be safe, we have to work together. Once upon a time, you'd say, oh, if my cybersecurity's better than the guy down the street, they'll go down the street and forget about me. And we just can't do that. We're too interconnected. There's too much work we do together. There's too many interconnections between our systems. We absolutely positively have to develop that collective defense. In addition, part of that collective defense is ensuring that the burden of defense falls to those most able to deliver on that." - Ann Dunkin
On balancing risk vs. compliance: "The reality is we can't do all the compliance. And so we absolutely have to look at risk to prioritize it. But I would argue that you should always look at your risk and balance that against your compliance exercises. Because number one, if you do all the compliance and then you start risk mitigation, you may be missing something big. But number two, because you probably don't have enough money to do all the compliance anyway." - Ann Dunkin
On workforce development: "I firmly believe that we need pathways to move people in between the private and public sectors. And we need to make it easier for people to cycle between those places over the course of their career to leave government, to come back to government and to learn from each other. And also for the government through DOE and through other places to help build a workforce within the government that looks like America. And then to help the rest of America grow their workforce capabilities." - Ann Dunkin
About Our GuestAnn Dunkin serves as the Chief Information Officer at the U.S. Department of Energy, where she manages the Department’s information technology (IT) portfolio and modernization; oversees the Department’s cybersecurity efforts; leads technology innovation and digital transformation; and enables collaboration across the Department. Ms. Dunkin is a published author, most recently of the book Industrial Digital Transformation.
Episode Links* National Cybersecurity Strategy
Dr. Aaron Drew, Technical Director for the Supply Chain Management (SCM) Product Line at the U.S. Department of Veterans Affairs Office of Information and Technology, joins Carolyn to discuss the challenges of supply chain, modernization and risk management. Dr. Drew outlines the steps an organization can take to modernize and maximize applications for end users as well as capitalize on data analytics to better prepare our nation for times of need.
Key Topics* [01:15] - Scale of Veterans Affairs * [05:21] - Supply Chain Tools and Challenges * [13:54] - Advice for Supply Chain Management * [20:24] - Tech Procurement * [24:10]- User Acceptance * [27:37] - Risks of not Modernizing * [32:29] - Security Requirements * [36:13] - Steps to Acquisition * [40:10] - Tech Talk Questions
Quotable QuotesOn identifying a need for a new tool: "If the tools you had before don't address that shift [in business], that change of dynamics, then that's when we have this gap. That's that delta between how you did business then and how I expect to do business tomorrow that will signify or call that ignition of this solution acquisition process." - Dr. Aaron Drew
On understanding user needs: "Either you are meeting them [users] where they are, which is very important, or you've lived it, which allows you to relate and commiserate with those who are working across a day-to-day basis, that's what's going to bring you organically to the problem. That's going to allow both parties then to own the solution." - Dr. Aaron Drew
About Our GuestDr. Aaron J. Drew is the Technical Director for the Supply Chain Management (SCM) Product Line at the U.S. Department of Veterans Affairs. Previously, Dr. Drew simultaneously served as the Chief Engineer & Chief Architect for the Financial Management Business Transformation Special Program Office (FMBT-SPO) and the Chief Engineer & Chief Architect for the Supply Chain Modernization Program.
Episode Links* MITRE * Smithsonian Museums * Holocaust Museum
Tracy Bannon, Senior Principal/Software Architect & DevOps Advisor at MITRE, returns to Tech Transforms for our So What segment to discuss all things generative AI. Following Tracy's presentation at the RSA Conference 2023, she and Carolyn discuss everything from software development lifecycle to the potential that various AI models may have.
Key Topics* [01:29] - Software Development Lifecycle: RSA Conference Recap * [04:48] - Generative AI as a Service * [07:36] - Potential for Disinformation * [12:04] - Potential of AI for Developers * [17:15] - Low Code / No Code Capabilities * [26:14] - Discussion Roundup * [31:14] - Tech Talk Questions
Quotable QuotesDefinition of generative AI: "Generative AI is under the umbrella of large language models. And a large language model is just that. It is a model where vast amounts of text data have been fed in and it uses statistical analysis to figure out the likelihood that words or phrases go together." - Tracy Bannon
On generative AI models: "It's only as good as the information that's going in, garbage in, garbage out." - Tracy Bannon
Generative AI advice: ''Know that we have to really get focused on the ethics of using these tools. Know that there are big security risks, but get familiar. Get familiar. It isn't going to take your job today. It is going to augment many jobs, but it's not going to take them completely away." - Tracy Bannon
About Our GuestTracy Bannon is a Senior Principal with MITRE Lab's Advanced Software Innovation Center. She is an accomplished software architect, engineer and DevSecOps advisor having worked across commercial and government clients. She thrives on understanding complex problems and working to deliver mission/business value at the speed. She’s passionate about mentoring and training, and enjoys community and knowledge building with teams, clients and the next generation. Tracy is a long-time advocate for diversity in technology, helping to narrow the gaps as a mentor, sponsor, volunteer and friend.
Episode Links* So What? Tech Transforms Federal News Roundup with Katy Craig * Applying AI to the SDLC New Ideas and Gotchas * It's 5:05 * The Kill Chain * Project to Product * Real Technologists Podcast * Greenlights
Alan Gross, Solutions Architect & Tech Lead at Sandia National Laboratories, joins Carolyn to talk about how DevOps is being leveraged to support the Department of Energy's contractor operated research lab. Alan dives into some of the initiatives at Sandia National Laboratories, and how he is applying his personal philosophy around user experience ops, or "UX Ops," to support the mission.
Key Topics* [01:12] About Sandia National Laboratories * [03:50] Sandia's role in national security * [06:25] DevOps versus DevSecOps * [13:45] Department of Energy and Sandia * [17:40] Sandia initiatives: a year of climate in a day & Hypersonic weapons * [21:00] Alan's DevOps journey and advice for developers * [33:55] Tech Talk questions
Quotable QuotesAlan on DevOps: " DevOps is about trying to deliver quickly and learn from your mistakes as fast as you can. So shifting left is part of that philosophy. If you have security issues with your software, you want to know about that as quickly as possible, because if you've already deployed to production, it's almost too late." - Alan Gross
On what advice Alan would give to new developers: "It's about failing fast and failing forward...How quickly can you learn new things, get new code and new products out in front of your users, and understand how they engaged with that." - Alan Gross
About Our GuestAlan works as a full stack developer and technical lead at Sandia National Labs, with six years of experience in web technologies development. He develops within Python, Angular and .NET ecosystems, with a focus on enabling the developer experience at Sandia with novel solutions for the labs’ diverse development, software governance, security and business intelligence needs. Alan leads a team that is committed to reducing technical debt by emphasizing DevSecOps, modern application architecture (such as microservices) and data-driven outcomes.
Episode Links* Mollie Rappe * Planning and Implementation Tool * Tech Transforms Podcast with Dr. Stephen Magill * Pattern and Anomaly Detection in UX * Adam Grant Podcast * Project Ceti
Paul Scharre, Vice President and Director of Studies at Center for a New American Security (CNAS) joins Carolyn and Mark to dive into his newest book, Four Battlegrounds: Power in the Age of Artificial Intelligence. From the first time he recognized the power AI could hold, to the ways AI may put us on a path to global peace, Paul offers valuable insight and perspective on the field of artificial intelligence and machine learning.
Key Topics* [01:44] About Paul Scharre * [02:50] When Paul Scharre recognized the power of AI * [07:17] The 4 Elements of the Battlegrounds * [12:57] Paul Scharre's take on the technological divide in the United States, and how we can solve it * [20:10] U.S.'s standing in comparison to Nation-State adversaries * [26:18] Establishing globally agreed upon AI guardrails * [31:45] The exponential growth of AI * [42:12] Top requirements to achieve global peace
Quotable QuotesOn Paul's main focus when working at the Pentagon:"how can we use robotics to help create more distance between our service members and threats?" - Paul Scharre
Role of humans in AI: "Having data and computing hardware, having chips alone, doesn't get you to some meaningful AI tool. You also need the human talent" - Paul Scharre
On adversary AI advancement: "Fundamentally, both the US and China are going to have access to AI technology, to robust AI ecosystems, big tech companies, startups within each country, and the bigger challenge is going to be: How does the military take this technology, work with its civilian AI scientists, and then translate this into useful military applications?" - Paul Scharre
About Our GuestPaul Scharre is the Vice President and Director of Studies at the Center for a New American Security. Prior to this role and becoming an award-winning author, Scharre worked in the Office of the Secretary of Defense (OSD) where he played a leading role in establishing policies on unmanned and autonomous systems and emerging weapons technologies. He led the Department of Defense (DoD) working group that drafted DoD Directive 3000.09, establishing the department’s policies on autonomy in weapon systems. He also led DoD efforts to establish policies on intelligence, surveillance, and reconnaissance programs and directed energy technologies.
Episode Links* Project Maven * Army of None
This week, Michael Edenzon, Co-Founder of Fianu Labs, joins Tech Transforms to talk about why automated governance is so critical to mission success. Michael also provides some great insight into his recently co-authored book Investments Unlimited.
Key Topics* [02:08] About Fianu Labs * [04:54] What passes as evidence and how does it play into automated governance? * [09:29] Michael's book: Investments Unlimited * [16:50] Automated governance vs. Authority to Operate * [28:33] Taking software asset inventory * [35:40] Tech Talk Q&A
Quotable QuotesOn what counts as evidence in the context of software governance:"Our real focus in that regard is trying to get people to realize that evidence isn't just this random metadata that's captured from here and there, but instead it's going through all of the enrichment and providing all of the context that's necessary for an auditor to come and reproduce those results that you're using to base your enforcement off of." - Michael Edenzon
On how automated governance relates to Authority to Operate:"It [automated governance] is a method for achieving the ATO. So it can accelerate your ATO process and it can help you reach it faster, but what automated governance really is, is a means of achieving continuous ATO." - Michael Edenzon
About Our GuestMichael Edenzon is a senior IT leader and engineer that modernizes and disrupts the technical landscape for highly-regulated organizations. Michael provides technical design, decisioning, and solutioning across complex verticals and leverages continuous learning practices to drive organizational change. He is a fervent advocate for the developer experience and believes that enablement-focused automation is the key to building compliant software at scale.
Episode Links* Investments Unlimited * Toyota Kata * Failure is Not an Option
In this episode of Tech Transforms, Nihal Krishan, tech reporter at FedScoop, discusses how and where the American government is lagging behind in technology, but there is a focus on modernization to improve the situation. We also talk about the need for comprehensive data privacy legislation and how budget caps may impact government agencies' modernization initiatives. Additionally, we explore concerns surrounding TikTok's ownership and data privacy, as well as the addiction and potentially harmful effects of the platform. We also touch on the importance of respecting sources as a journalist and provide a few podcast recommendations. Finally, we look at the challenges in understanding algorithms used by TikTok and how they could be used to promote divisive content. Join us to learn about these transformative topics in the tech world!
Introducing Our Guest, Nihal KrishanNihal Krishan is a journalist who has covered the controversies surrounding TikTok. He highlights the privacy violations committed by the company when it accessed journalists' personal information to control their narrative. Krishan also acknowledges the legitimate fears surrounding the app since TikTok's parent company is based in China. However, he notes that there is no objective evidence of the Chinese government misusing American data obtained through TikTok. He raises the question of whether American social media companies are any better at safeguarding data than TikTok. Krishan argues that the debate over TikTok highlights the need for data privacy legislation in Congress.
Key Topics:* Government Budget and IT Modernization * Privacy and Security on TikTok * Social Media and Data Privacy
Episode Highlights:* [00:00:57] TikTok has been criticized for invading journalists' privacy to control their perceptions of the app, but the evidence for harm is primarily based on perception and politics. There are concerns about Chinese government access to American data, but it has not been proven yet. The issue of data privacy is a larger problem for social media companies in general and calls for legislation. * [00:06:04] TikTok is a popular Chinese-owned social media platform with almost a billion users, mainly Gen Z, and its popularity has caused concerns about national security and data privacy in the US. * [00:10:13] Understanding TikTok's algorithms is like understanding Facebook and Google's algorithms. The government is concerned that TikTok could sow seeds of discord like how Russians did in 2016 on Facebook. It's a complicated problem faced by all social media platforms. * [00:12:29] TikTok is highly addictive and has a powerful algorithm that tailors to a user's preferences. Instagram and other apps are trying to copy its success. Concerns arise over its safety and effects on users, especially children and those with attention issues, requiring regulations. * [00:14:57] Data privacy laws are crucial for people who don't have time to limit their phone and social media use. Bipartisan support exists for Children's data and app time protection, but comprehensive legislation is still needed. * [00:18:54] US government lags behind in technology; modernization is a key issue for federal agencies and Congress has formed an IT Modernization Committee to improve it, but bureaucracy and political battles affect appropriations for IT modernization. * [00:22:31] Caps on spending for agencies may hamper modernization efforts. * [00:24:18] Budget cuts expected on unspecified agencies and programs; impact and details unknown. Reporting on changes to come. Cybersecurity noted. * [00:25:50] Journalists rely on trust to get information and protect sources. Most people's comments are not newsworthy, and journalists don't report everything they hear. Building relationships and protecting sources is important for breaking good stories.
Quotable Quotes From Nihal KrishanTikTok and the potential for social media manipulation: "If we allow this to go forth unchecked, it could reach a point where TikTok just continues to get more and more popular. And then they start sowing seeds of discord." — Nihal Krishan
"The Addictive Power of TikTok": "It is highly, highly addictive... hours, days, years, it just gets better and better at giving you exactly that little delicious treat that makes your mind go gaga with pleasure or go dark with fear and play at the human mind." — Nihal Krishan
The Importance of IT Modernization in Government: "I think it's important to remember that from the industry's perspective and for many Americans, the American government is still severely lagging behind when it comes to technology." — Nihal Krishan
Nihal Krishan, Tech Reporter at FedScoop joins Carolyn for a special two-part episode to talk about some of the hottest topics in government tech. In Part 1, Nihal gives some eye-opening insight on all things ChatGPT including security, privacy, and national bans.
Episode Table of Contents* [0:25] Introducing Our Guest, Nihal Krishan * [7:39] We Need to Upskill * [15:45] How the U.S. Government Is Dealing With ChatGPT * [23:00] Stanford University Human Center Artificial Intelligence Index Report of 2023 * Episode Links and Resources
Episode Links and Resources* Nihal Krishan * FedScoop * Stanford University Human Centered Artificial Intelligence Index Report
Col. Candice Frost, JIOC Commander at United States Cyber Command joins Carolyn and Mark to talk about her journey as a lifelong-learner, and how she is applying her skills to the innovative work at Cyber Command. From the importance of public-private partnerships, to teaching our kids healthy cyber security habits, Col. Frost offers her valuable insights on how we can all think innovatively and better secure our nation.
Episode Table of Contents* [0:29] Col. Frost’s Journey to Being the JIOC Commander at US Cyber Command * [8:04] How US Cyber Command Came to Be * [16:04] Understanding the Nature and Psychology of War * [23:35] The Parts Played by US Cyber Command in Our Security * [30:46] The Thrill of Working at US Cyber Command * [37:55] How US Cyber Command Keeps Everyone Safe * [44:31] Nothing is True and Everything is Possible
Episode Links and Resources* Col. Frost LinkedIn * U.S. Cyber Command * Afternoon Cyber Tea * Click Here Podcast * Spies Lies and Algorithms * Nothing is True and Everything is Possible * The Wires of War
Commander Jonathan White, Cloud and Data Branch Chief at the United States Coast Guard joins Carolyn and Mark to talk about the groundbreaking developments his team is doing with C5I. Commander White stresses the importance of public-private partnerships, and gives tips on how agencies can better approach the future of technology.
Episode Table of Contents* [0:33] What Is C5I? * [7:54] What Are the Goals of C5I * [15:12] What the Future Holds for C5I * [22:35] Commander White’s Favorite Project Pre C5I * [29:39] What Role Has Industry Played for C5I * [35:14] Pieces of Advice * [40:23] From the First Piece of Technology to C5I * [45:16] Introduction to AI * Episode Links and Resources
Episode Links and Resources* Commander White * USCG * Hack Your Bureaucracy
Stephen Magill, Vice President, Product Innovation at Sonatype dives into the complexities of open source and software security. Find out how government agencies are utilizing open source, and what Sonatype is doing to help secure our most trusted software.
Episode Table of Contents* [0:23] The Core Focus Area of Open Source Technology * [7:24] The Security Measures Open Source Implements * [14:32] A Vulnerability in the Open Source * [21:42] The Vulnerability Log4j Poses in the Open Source * [29:06] Identifying the Root of the Problem * [36:01] Watching Out for Malicious Code
Episode Links and Resources* Stephen Magill * Sonatype * Sonatype Safety Rating * Maven Central
Billy Mitchell, Editor-in-Chief at FedScoop joins Carolyn to discuss surveillance, national intelligence, the benefit of partnerships, and more. Billy gives his perspective on today's hot topics in federal technology, and what he thinks may be coming next.
Episode Table of Contents* [0:23] Federal Technology and Its Battle Against Balloons * [7:18] Varying Opinions Towards Federal Technology Problems * [14:41] Federal Technology Embraces Industry Technology * [21:56] Federal Technology Means Business * [29:33] Implementation of Zero Trust in Federal Technology * [36:54] Billy Mitchell’s First Encounter With Technology
Episode Links and Resources* Billy Mitchell * FedScoop * The Last of Us
Dan McCune, Deputy Chief Information Officer at U.S. Department of Veterans Affairs joins Carolyn and Mark to discuss the transformative work happening at the VA. With millions of end users, Dan explains how his dedicated teams are working to make the VA better, faster, and safer for our veterans.
Episode Table of Contents* [0:29] The Place to Go for Veterans Affairs * [7:51] Veterans Affairs Approach Towards Modernization * [14:53] The Forcing Function of Veterans Affairs * [21:48] Veterans Affairs Makes Things Easy for Veterans * [31:29] How AI Can Improve Veterans Affairs Services * [40:44] The Next Big Leap in Technology
Episode Links and Resources* Daniel McCune * VA * Competing in the age of AI * Innovator’s Dilemma * Atomic Habits * The Power of full engagement * Axis of Awesome
Dimitris Perdikou, Head of Engineering at the UK Home Office, Migration and Borders joins Carolyn and Mark to discuss the innovative undertakings of one of the largest and most successful cloud platforms in the UK. With over 3,000 technical users, and millions of end users, Dimitris sheds some light on his experience with SRE, User Experience, and Service Monitoring.
Episode Table of Contents* [0:21] Inside the Massive Programs That the UK Home Office Offers * [7:00] The Importance of Observing Cost Efficiency * [12:25] The Monitoring Pack of the UK Home Office * [17:59] UK Home Office Take on a Good User Experience * [24:09] Why UK Home Office Didnt Have to Reinvent the Wheel * [30:20] Let the Experts Do Their Job * Episode Links and Resources
Episode Links and Resources* Dimitris Perdikou * UK Home Office * NCSC * The Happiness Lab * The Art of Happiness
Jamie Holcombe, Chief Information Officer at USPTO joins Carolyn and special guest host Willie Hicks to talk about Zero Trust, PMO, encryption and more. Listen in to learn about the innovative steps USPTO has taken to develop New Ways of Working.
Episode Table of Contents* [0:41] Zero Trust According to Jamie Holcombe, CIO of USPTO * [7:56] The Effects of Reauthentication * [13:09] You Need to Have a Focus and a Mission * [18:46] New Ways of Working * [25:43] Not Everything Needs to Be Protected * [32:59] USPTO’s Four Pillars of Intellectual Property * Episode Links and Resources
Episode Links and Resources* Jamie Holcombe * USPTO * For All Mankind * Foundation
Willie Hicks, Dynatrace’s Federal Chief Technologist recently appeared on the Federal Tech Podcast. It is such a great interview we wanted to make sure our Tech Transforms audience got to listen. Enjoy this crossover episode with Federal Tech Podcast!
Episode Links and ResourcesEp. 42 Vulnerability Management for Federal Systems
Federal Tech Podcast
Willie Hicks
Nicolas Chaillan joins Carolyn and Tracy to shed some light on his experience in the Air Force and gives his thoughts on government movement in the past year. Nicolas talks about the importance of social media privacy and protection.
Episode Table of Contents* [0:59] Introducing Our Guest, Nicolas Chaillan * [10:06] Have We Regressed in Cyber? * [17:58] There Is a Reward for Not Taking Risks * [24:29] The Worst Thing That Ever Happened Was Agile * [31:46] The Amount of Information TikTok Gather * [40:17] We Need to Teach the Basics of Life to Kids * Episode Links and Resources
Episode Links and Resources* Nicolas Chaillan * LinkedIn * In goodbye message, Chaillan unloads his frustrations over DoD’s technology culture, processes
John Curran, Executive Editor at MeriTalk joins Carolyn to discuss 2022 technology trends and shares his predictions for federal technology in 2023.
Episode Table of Contents* [0:25] The Armchair Quarterback * [8:08] Are There Agency Efforts in 2022? * [15:45] Technology Trends on Implementing DevSecOps * [21:36] The Big Technology Trends Coming on 2023 * [26:56] Technology Trends Need to Be User Friendly * Episode Links and Resources
Episode Links and Resources* John Curran * MeriTalk * Max Hastings
Andrey Zhuk, Federal Security Architect at CTG joins Tech Transforms to unpack the topic every agency is talking about: cybersecurity mandates. Listen in to learn more about Andrey's recent eBook breaking down who mandates affect, why they are important, and how agencies can successfully meet requirements.
Episode Table of Contents* [00:24] Introducing Our Guest, Andrey Zhuk * [08:48] The Rate of Change in Cybersecurity Mandates * [18:43] Break and Inspect * [28:26] Show Progress on Cybersecurity Mandates * Episode Links and Resources
Episode Links and Resources* Andrey Zhuk * Conversational Application Management for Federal Government eBook * Mandates - 1428 * OMB 2209 * Ray Dalio Principles * We Crashed
Duong Hang, Deputy Director at the Department of Defense Platform One joins Tech Transforms to address a topic that's been circulating recent headlines: Psychological Safety. Listen live as Carolyn and Tracy learn how agencies and organizations can implement psychological safety to improve retention and operations. Episode Table of Contents[04:00] What Is Psychological Safety [10:35] The Challenge of Safeguarding Employee’s Psychological Safety [19:48] Command and Control [28:56] Closer Proximity Help Build Psychological Safety [35:56] Psychological Safety Starts From the Top [44:14] Psychological Safety Can Be Observed
Episode Links and Resourceshttps://www.linkedin.com/in/duong-hang/ (Duong Hang) https://software.af.mil/dsop/services/ (DoD Platform 1) https://adamgrant.net/book/think-again/ (Think Again)
Paul Puckett, Director of the Army’s Enterprise Cloud Management Agency joins Tech Transforms to shed some light on one of government technology's most used buzzwords: Zero Trust. Listen in as Carolyn and Tracy learn what it really means to remove implicit trust and how agencies are prioritizing user experience and data protection. Episode Table of Contents[01:03] The Enterprise Cloud Management Agency [10:41] The Context of Zero Trust [19:55] A Zero Trust Reference Architecture [29:28] Protecting the Data that Falls to the Zero Trust Architecture [39:00] The Traditional Dogma [50:07] Data Sharing on Zero Trust Episode Links and Resources
Episode Links and Resourceshttps://www.linkedin.com/in/paulbp3/ (Paul Puckett) https://www.army.mil/ecma (ECMA) https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-09.pdf (White House Memo on Zero Trust) https://csrc.nist.gov/publications/detail/sp/800-207/final (Zero Trust Architecture)
Ross Wilkers, Senior Staff Reporter at Washington Technology talks to Carolyn and Mark about some of the hottest topics in government technology news. With insight on the 2023 Defense Funding Bill, government contracting and Alliant 3, Ross provides a unique perspective on what defense IT teams may see in the coming months. Episode Table of Contents[00:56] Government Contracting and Government Technology News [09:21] Programs to Help Agencies [20:08] Fishing on a Boat for Government Technology News [31:37] Government Technology News Just Dominate [41:03] Trying to Capture HQ2 Episode Links and Resources
Episode Links and Resourceshttps://www.linkedin.com/in/ross-wilkers-9256a371/ (Ross Wilkers) https://washingtontechnology.com/podcasts/ (Project 38) https://appropriations.house.gov/news/press-releases/appropriations-committee-releases-fiscal-year-2023-defense-funding-bill (2023 Defense Funding Bill) https://washingtontechnology.com/contracts/2022/08/gsa-sketches-out-timeline-alliant-3-first-glimpse/375970/ (Alliant 3)
Amy Belcher, Independent Software Vender Sales and Go To Market Leader at Amazon Web Services joins Tech Transforms to talk about her team's mission to satisfy compliance for agencies across the globe. With speed to deployment, flexibility and security, Amy and her team support organizations maximizing local control and global reach. Episode Table of Contents[00:52] The Importance of Industry Partnerships [08:19] Productive and Creative Partnerships [18:24] The Depth of Partnerships Episode Links and Resources
Episode Links and Resourceshttps://www.linkedin.com/in/amybelcher/ (Amy Belcher) https://aws.amazon.com/government-education/ (AWS) https://www.amazon.com/Five-Dysfunctions-Team-Leadership-Fable/dp/0787960756 (The Five Dysfunctions of a Team) https://www.amazon.com/Never-Split-Difference-Negotiating-Depended/dp/0062407805 (Never Split the Difference)
Colin Demarest, Defense Networks and Cyber Reporter at C4ISRNET joins Tech Transforms to talk about some of his recent articles focused on 5G, aerial networks, and upcoming Capability Sets. Listen in as Carolyn and Mark learn about the ever-evolving field of defense and what emerging technology can do to support the mission. Episode Table of Contents[00:30] Getting to Know Colin Demarest, a Defense Networks and Cyber Reporter [08:45] 5G Defense Investigation [12:28] Issues of Compatibility in the Defense World [17:51] Capability Sets 21 and 23 [25:25] Another Layer of Defense Episode Links and Resources
Episode Links and Resourceshttps://ctdemarest.wordpress.com/photography/ (Colin Demarest) https://www.c4isrnet.com/ (C4ISRNET) https://www.ronaldcwhite.com/books/american-ulysses/ (American Ulysses) https://jonathanalter.com/work/his-very-best-jimmy-carter-a-life/ (His Very Best)
Daniel Chenok, Executive Director at IBM Center for The Business of Government joins Carolyn and Mark to talk about the importance of AI in the field. From democratizing data to improving office operations, application research is a key component for any government agency looking to integrate artificial intelligence into their mission. Episode Table of Contents[01:02] A Top Government Story [08:33] How AI Enables Us to Do Our Jobs Better [17:36] The Challenges We Have on Cybersecurity [28:47] What Does Research Tell Us About AI? [36:29] How AI Can Solve Problems at a National Scale [44:40] How to Implement AI Episode Links and Resources
Episode Links and Resourceshttps://www.linkedin.com/in/chenokdan/ (Daniel Chenok ) Email: chenokd@us.ibm.com https://www.businessofgovernment.org/ (Business of Government ) https://www.ibm.com/security/services/us-federal-cybersecurity-center (Center for Government Cybersecurity) https://governmentciomedia.com/socom-cdo-digital-transformation-depends-ai (SOCOM CDO: Digital Transformation Depends on AI) https://www.nextgov.com/ideas/2022/02/building-cybersecurity-workforce-america-needs/361514/ (Building the Cybersecurity Workforce America Needs)
Rick Stewart, Chief Software Technologist at DLT Solutions joins Tech Transforms to give insight on Open Source, Platform One, and DORA initiatives. Listen in as Carolyn and Mark learn about the importance of focusing on the right metrics when managing security bottlenecks. Episode Table of Contents[00:48] Old Ways of Doing Things [11:55] Security Metrics That Need Improvement [22:54] Deploying Security Metrics Using Scheduling Techniques [33:19] Continuous Authority to Operate Security Metrics Episode Links and Resources
Old Ways of Doing ThingsCarolyn: Today, we get to talk to https://www.linkedin.com/in/rick-stewart-09618015/ (Rick Stewart), a good friend. Rick Stewart is a Chief Software Technologist at DLT for more than 34 years. Do you really want me to tell people that Rick? That makes you sound super old? Rick: No, it has some relation to the old way of doing things, traditional ways. Carolyn: He knows the old stuff and the new stuff with 34 years of diverse experience in the IT industry. He’s progressing through technical and leadership roles in telecommunications, mobile entertainment, the federal government, and the manufacturing industries. Today, Rick is joining us to talk about DevOps research and assessments, or DORA, a term that is new to me. He’ll also talk about the four key metrics for increasing efficiency and delivering service. He will discuss how Platform One has advanced the cultural transformation to DevOps. Mark: Welcome Rick. By the way, Rick started this when he was six. Carolyn: That's right. I'm going, to be honest. I've been in the industry for a while, and I have never heard the term DORA. DevOps Research and Assessments make sense. I just haven't heard the acronym. They have four key metrics for increasing efficiency in delivering service. Those metrics are deployment frequency, lead time for changes, change failure rate, and time to restore to service. Will you unpack those for us? Rick: It's interesting that you say that because I attend several different events and conferences where we have, especially in the public sector, astute people that have lots of experience. Security Metrics As a First-Class CitizenRick: They're on this journey of DevOps or in the public sector. It's more DevSecOps, bringing security up as a first-class citizen. They were talking about the things that they capture, the journey that they're on, and their improvements. On one of these occasions, DORA was brought up. I think it may be a Q&A panel. It was surprising that a lot of them didn't know what this organization does, especially being so well versed in the cultural transformation, not knowing some of the things to focus on. I thought it was really important to shine a light on. Carolyn: Is it a federal organization? Rick: No, it's more of a community-based organization, an industry-based organization. We've got people like Jez Humble and Gene Kim and others that are involved with this. What they do is, they go out and they do surveys of not just the public sector, but the private sector, all organizations globally. They basically give them surveys and they talk about their experience, where they're at in the spectrum of their journey, and what they have discovered through this analysis. It's a really deep, long analysis. There's a book called Accelerate that was done by Nicole Ferguson. She has a PhD and took lots of painstaking analysis of these organizations and these teams and asked them a series of questions. What it boiled down to is there are a lot of traditional metrics that have been ingrained in the industry that are useful somewhat, becoming less useful over the years, like lines of code when we're talking about mainframe and the complexity and function points, etc. As the industry has changed into more service-oriented or even micro-service-oriented architectures, those types of metrics are less useful. Development Teams and Operations Teams in UnisonRick: So, when you're...
Willie Hicks, CTO of Public Sector at Dynatrace joins Carolyn and Mark to unpack the recent ATARC event: Improving the User Experience in a Zero Trust World. At this federal breakfast summit, sponsored by Dynatrace and Amazon Web Services, we heard from some of the most prominent technology leaders focused on Zero Trust including Nicole Willis, Jamie Holcombe, Mickey Iqbal, and more. Listen in as Mark and Willie give highlights and takeaways from the event. Be sure to follow the link in the show notes to see the full event On-demand! Episode Table of Contents[00:30] Guest Speakers at the ATARC Event: Improving the User Experience in a Zero Trust World [07:55] Zero Trust Should Be a User Experience Enabler [14:41] OMB Is Pushing to Move Too Fast [20:05] How to Ensure Zero Trust Does Not Disrupt the Employee User Experience Episode Links and Resources
Guest Speakers at the ATARC Event: Improving the User Experience in a Zero Trust WorldCarolyn: So today we're reviewing top takeaways from ATARC 's Federal Breakfast Summit, Improving the User Experience in a Zero Trust World. Which those two things, user experience, and zero trust, are kind of a direct conflict for me, but we'll get to that. The conference was sponsored by AWS and Dynatrace, and it's available on-demand for our listeners at ATARC.org. Also, we have Willie Hicks, our Federal Chief Technologist at Dynatrace. Willie, you were a keynote speaker at the event. I'm too biased to say you were my favorite so I won't say that. I mean, everybody was really good. Jamie was super exciting. Let me just review who our speakers were. So our keynote speaker around zero trust was Grant Schneider. He brought a really interesting perspective because he's former white house. So he was the senior director of cybersecurity services. So former federal CISO, and now he's in industry at Venable. Then we had our next keynote around the user experience was the very entertaining Jamie Holcomb. He's the CIO at U.S. Patent and Trademark office. And then my favorite, Willie, Federal Chief Technology Officer here at Dynatrace. Then we had a panel that brought the user experience and zero trust together and how we reconcile those two and how they work together. And on that panel, we had Nicole Willis, Chief Technology Officer, OIG, at the U.S. Department of Health and Human Services. Is User Experience Unrelated to Zero Trust?Carolyn: Jamie came back on the panel. We had Mickey Iqbal, he's the Public Sector Solution Architect and Chief Technologist at Amazon Web Services. Willie on the panel. And then we had our moderator, Tom Suder, who's fantastic. He's been in this business so long that he had a lot of really good insights too. Now that I've given our listeners the overview of who participated, first of all, I was thrilled to see that we had a packed room. We had a standing room only, and that was really, really nice to see. It was lovely to have people in person and to be able to interact with one another personally. So, all right, let's get to the first question. Today, Mark, you're less of a co-host. I want to hear your opinions about what your takeaways were from that day. So around the user experience and zero trust, did you have any aha moments? What were your favorite moments? Tell me your feelings about the day. Mark: Well you know, from my perspective, coming from industry and Dynatrace, I think we think of end-user experience as something different related to zero trust. So we think of it differently. Carolyn: And at odds with each other. Mark: Yes. Well, I get the feeling more and more, it's more how the end-user navigates the security protocols and processes to accomplish the end goal. Which is not their problem of zero trust, which would be the agency's problem. How the End-User Navigates the Security ProtocolsMark: And so the agencies think of end-user experience in that light as opposed to we think of it in a different way as it relates to somewhat the...
This week, Carolyn is joined again by Bob Stevens, AVP Public Sector at GitLab, this time to talk about the power of hyperautomation. Listen in as Carolyn learns what can be gained through fast, accurate application security. Episode Table of Contents[00:32] What is Hyperautomation [09:02] What Has Changed in Hyperautomation Episode Links and Resources
What is HyperautomationCarolyn: I'm excited to welcome back Bob Stevens, Area Vice President of Public Sector at GitLab. Bob is a seasoned veteran in public sector technology with over 36 years of experience. As the AVP at GitLab, he is responsible for helping government organizations become more productive, efficient, and effective. Bob has experience on both the industry and the government side of things. Prior to industry, he served in the United States Air Force as a computer specialist at the White House Communications Agency. Today, we are going to talk about artificial intelligence, machine learning, and what hyperautomation is exactly. Why Bob thinks it will be 2022's biggest trend. Bob, welcome back to Tech Transforms. Bob: I'm happy to be here. Thank you. Appreciate it. Carolyn: I'd like to talk about an episode that you just did with GovExec Daily. And on this episode, you mentioned that hyperautomation will be 2022's biggest trend. I'm going to be honest. I haven't really heard hyperautomation. And I get automation. I can deduce what hyperautomation is, but I would love for you to explain it to me. What's the difference between automation, hyperautomation, DevOps, all of that? Bob: Yes, I mean, it's the strict definition of the word. It's rapidly identifying, vetting in automated processes in order to produce whatever it is that you're working on as fast as you possibly can. And it trends today because if you think about the government space, they have a lot of compliance issues that they need to deal with. The Benefits of HyperautomationBob: If they can automate those compliance processes and ensure that when they build software, in the end it's going to be compliant and they don't have to go back and vet it. I mean, that's going to save them a world of time. Carolyn: Are you talking about missed compliances, automating some of those missed controls? There's 300 of them, I think. Bob: Yes, those. I think you're talking about FedRAMP. Carolyn: Yes. One of. Or authority to operate has all of those. Right? I mean, I don't know all the details. Bob: Yes, no. There's the STIGs. That the government has to put all software through and that's all about compliance. The government has to get the authority to operate, ATOs, for everything that they run. Carolyn: And renew them every two or three years. Bob: Or sooner. It depends on how much of a change occurred in the application. If you can hyperautomate all of that by the use of AI or machine learning. Again, and so by the time you produced that software, all those compliance issues are addressed. You know they're addressed because you've got confidence in the system and the way that it was done. It didn't require as little human intervention as possible, which is unfortunately, where some mistakes are injected. Then you've saved a world of time and you've made life really, really easy for the folks that are doing the development. As well as the folks that are using the applications in the end. Because they don't have to sit and wait to get the authority to operate, which sometimes can take a year.The Bad News: We Haven’t Tried HyperautomationCarolyn: Is the differentiator between automation, DevOps, and hyperautomation really adding in, automating those compliances? And are you telling me that that hasn't happened before now? Bob: Unfortunately, it has not happened. I mean, that's evident by the fact that the government still has to produce ATOs and they still are doing STIGs at the end of the development cycle. Unfortunately, it hasn't happened. I think the government will embrace it and has...
Sara Jones, CEO of InclusionPro joins Carolyn and Mark to talk about all things diversity, equity, and inclusion. Sara explains gaps in authenticity and perception and gives tech leaders everywhere new goals to strive for when it comes to company culture. Episode Table of Contents[00:54] Why We Always Go Back to Company Culture [10:38] How Leaders Respond to Employees’ Desire [23:03] What Attracts People of Color to Apply [30:54] Why Leaders Avoid the Important Things About Company Culture [41:37] What Technology Can Never Replace Episode Links and Resources
Why We Always Go Back to Company CultureCarolyn: Today I am really happy to have Sara Jones with us. Sara's a friend and we've spoken before. Almost all of our guests, even though we're talking about tech, they always go back to culture. We're going to talk about that with Sara today. Sara Jones is the CEO of InclusionPro. She has over 20 years of experience in technology, business development, law, and leadership. You were a practicing attorney, right Sara? Sara: For 10 years. I'm still recovering. Carolyn: So as the CEO of InclusionPro, her mission is to guide leaders in building inclusive company culture that promotes team performance and team innovation. She's written a book recently called Inclusive Leadership and the Authenticity Gap, that we get to talk about today. Sara: Thank you. And this is a fun opportunity for me to merge my love of technology with diversity, equity, and inclusion. As most folks know, it is pretty hard to do. I've had a couple of decades talking about this, so hopefully, we can share some really great learnings. Most importantly, I think for the folks listening that might be thinking "DEI again." Carolyn: Which stands for? Sara: Diversity, Equity, and Inclusion. A lot of things have shifted. I think a lot of folks come to this type of conversation with the old thinking in mind. I'd just like to invite listeners to get rid of what you know. Just be open to hearing some new thoughts around diversity, equity, inclusions, and things that we're able to do now that we weren't able to do even five years ago. That's my little plug for saying, "Open-minded today?" InclusionProCarolyn: That leads really nicely into my first question about being a recovering attorney, your love for tech. What inspired you to create InclusionPro? Sara: InclusionPro is the end of a long 20-year journey having diversity, equity, inclusion as part of my personal career journey. Now, it may not be part of everyone's and a significant part of that is because I did start in patent law. Having an engineering degree and a law degree, put me in an industry that had only 5% women and people of color. I get a lot of people that are like, "Oh, our industry has no women." I'm like, "Yes, I've been there." I actually know what it's like. It's not like I came from academia or some area that was just flushed with a lot of diversity. I have lived this and I understand the impacts of it at a very personal level. But I also have been an executive. I know the challenges of being an executive, those operational aspects and how it really works in business. There's some big misalignments that can happen that we need to talk about when we get to this idea of authenticity. What is the individual need versus the larger organizational needs? Those can be very complex, very hard. I think it's something unique that I've been able to understand over my time. That makes me uniquely positioned to be able to help executives in this journey where most of them haven't been in this conversation.I think white men are more recently joining the conversation, which is very exciting. But you got a lot of employees saying, "What about social justice? What about this? I'm not seeing this statement. Where's this ERG, where's this, you're not committed." How Company Culture Makes It Challenging to Be a LeaderSara: It can be really challenging to be a leader. Being able to frankly, make a...
Join us on Tech Transforms Federal News Round-up segment, So What? Hosted by Carolyn Ford and Tracy Bannon. This week, we talk to Elizebeth Varghese, Global and Americas Leader – HR Transformation Client Offerings at IBM about one of the biggest topics in federal news: remote work. Listen in to find out how agencies can implement a smarter protocol, how remote work impacts the trust equation and the role technology can play in the workforce culture. Episode Table of Contents[00:40] The Future of Work for Federal Employees [11:28] Work-Life Balance Expectations in a Remote Work [19:01] Big Push in In-Person Protocol [26:12] Do You Need a Home Office for Remote Work? [32:01] Provide Options to Persuade People to Stay and Junk Remote Work [39:04] The People Who Are Not Approving Remote Work Episode Links and Resources
The Future of Work for Federal EmployeesCarolyn: This month, we're hosting Elizebeth Varghese, Global & America's Leader: Client Offerings in Talent and HR Strategy at IBM. And outside of IBM she's an active board member at South Asian Youth Action, a nonprofit providing after-school programming, education, and college support. She was recognized as Global Top 100 Influencer in HR for 2020. And we are glad to have you joining us today, Elizebeth, to discuss returning to the office, the great resignation, and companies potentially switching to a four-day workweek hybrid, all of that. Welcome Elizebeth, how are you? Elizebeth: Great, thank you so much, Carolyn. Wonderful and delighted to be here. Great to be back on here with Tracy as well, friend from a couple of years ago as we've been going through some of these pandemic podcasts. So thank you for inviting me and I am looking forward to this. Carolyn: Yes, well this one's going to be a fun one and it might get a little heated. I've already seen some stuff on LinkedIn. I'm like, oh, that gets my blood boiling about returning to the office. And I want to start off with a question, there's an article called "Three ways the future of work must change for federal employees." The article states that at the end of the day, we need to have an IT and HR Alliance. This was due to exceptional communication between the agency's chief information officer and HR functions. In your experience, is the relationship between IT and HR something government agencies need to improve on? And industry too? Does the Relationship Between IT and HR Need Improvement?Elizebeth: Now what we've seen, the pandemic is highlighted so nothing new. This was happening for a while. I have to preface it with that. Because I think in lots of our conversations we hear this thing about, hey, this is what the pandemic caused. The pandemic caused a lot of suffering and hardship for many people, but it highlighted things that were in play for many years. And the fact the intersection of HR data and how IT's using it and accessing it has been an eternal problem. It's been going on for many years. But things came to a head when we were forced to be virtual in the federal sector and in the commercial sector. People realized that that intersection hadn't really been explored. It hadn't been addressed. It hadn't been managed in a sufficiently coherent fashion. There were a couple of reasons for that and some folks in the federal sector or commercial, the reason I say that is because this is a universal problem. It's not endemic just to one sector and we should take that. But when the pandemic hit, there were lots of tropes. Even before that around what can be done remotely, what data can be accessed in what fashion, what is secure and not. What the pandemic highlighted is that those issues were not really based upon real cybersecurity issues or access issues or single sign-on issues. They were really managed or impacted by cultural constructs of where work can be done. A great example of this is if you think about our friends on Wall Street, you could not do investment banking or
Bob Stevens, AVP Public Sector at GitLab joins Tech Transforms to talk about the imperative mission of DevOps to combine efficiency, speed and security. With emphasis on empowering teams to fail fast, moving security to the left, and a deep dive into Platform 1, you won't want to miss this episode! Episode Table of Contents[00:27] DevSecOps’ Speed of the Mission [09:02] The Cultural Shift That Needs to Occur to Upgrade the Speed of the Mission [19:21] The Future of DevOps Episode Links and Resources
DevSecOps’ Speed of the MissionCarolyn: This week Bob Stevens, Area Vice President of Public Sector at GitLab is joining me. Bob is a seasoned veteran in public sector technology with over 25 years of experience. As the AVP at GitLab, he is responsible for helping government organizations become more productive, efficient, and effective. Bob also has experience on both the industry and the government side of things. Prior to industry he served in the United States Air Force as a computer specialist at the White House Communications Agency. I am excited today to dive in and talk about the ways that we can use DevOps to modernize and secure government IT, and what the outlook for DevOps is. How are you doing, Bob? Bob: I'm doing great. The weather's getting better in DC, so it's good to see the sun from time to time versus what we've had. But yes, doing fantastic. Carolyn: Well, good to hear it. So let's just dive in. And let's walk through what DevOps is and why implementing these practices is critical to helping modernize and improve government IT? Bob: Great. So I guess DevOps is combining efficiency, speed, and security all into one. And creating software at what I like to refer to as the speed of the mission for the government. The business side is a little different. But for the government, it's all about the mission and you being able to accomplish the mission faster and stay ahead of our adversaries. In the case of DoD and on the civilian side, it’s to ensure that all of the citizens that any given agency supports gets the best possible support that they can. If you look at the organizations like the Veterans Administration. You can imagine they've got a lot of applications that they've written. The Platform the Government Is Looking For to Improve the Speed of the MissionBob: To help the vets accomplish what they need to accomplish in a timely manner. So DevOps really will help them to produce the software at speed, more securely, more efficiently, and provide the most or the best service that they possibly can to all of the veterans out there, just as one example. Carolyn: So, you know Tech Transforms is vendor agnostic. And I would love for you to just take a couple of minutes and talk about how GitLab helps with that. And just what GitLab does. I've read the marketing statements and it's a little nebulous for me. I would love to have you explain what GitLab does and how it's helping agencies achieve this? Bob: I appreciate that you're letting me do this in a vendor-agnostic community. I mean, there are a lot of tools that are required to produce software. But the way that the industry or the government in particular is heading, and you can see this in some of the articles that DoD has recently released. Is they're looking for one platform that encompasses the entire software development life cycle. As you can imagine right now, I know agencies that have anywhere from 14 to 20 different tools that they're using. And the issue with that is that there's developers that like the tool that they like. So they bring their own and they develop their portion of the software. Unfortunately, when it all comes together, it doesn't always work because they've used different tools across the development organization. And so, with the use of a single platform, you can ensure that at the end, everything is going to work. The nice thing is you can continue to bring some of those other tools. Because they integrate...
Mike Maciag, Chief Marketing Officer at Dynatrace joins Tech Transforms to talk about the power of observability. Careful monitoring is of paramount importance for any successful operation, and observability can take your agency to the next level. Listen in as Carolyn and Mark get some tips and tricks for improving cybersecurity posture with the most accurate technology. Episode Table of Contents[00:31] The Vital Role That Observability Plays in IT [10:40] Observability: When You’re Asking the Systems to Share [22:48] The President’s Memo on User Experience [34:01] Let Machines Do the Stuff That Doesn’t Matter Episode Links and Resources
The Vital Role That Observability Plays in ITCarolyn: Today, we get to welcome Mike Maciag, who is Chief Marketing Officer of Dynatrace. One of our own, one of the clan is here with us today. And as CMO, Mike is responsible for Dynatrace's global marketing organization. We're really excited to hear his expert opinion on observability and the vital role that it plays in IT, and especially the cloud. Mike: Thank you, Carolyn. Mark, nice to be with you both today. And I know this is a long time in coming, but I'm excited to be sitting down and talking to you today. Carolyn: We've been able to talk to a few of our guests a little bit about APM. And just recently we talked to a former CIO at VA. He is very bullish on APM, and he talked a lot about the advances that they were able to make in the VA with APM. Just that at least within the VA, APM moved from a nice to have to a must-have. And what I'd really like to hear you talk about, just to dive right in, Mike, is so there's the APM part. But then in my mind and I might be positioning this wrong. In my mind, I think that observability is like APM 2.0. But can you speak to that APM versus observability? What's the difference? Mike: As long as we're talking about terms, we might want to mix monitoring in there as well. All terms that are thrown around, is it monitoring, is it APM, is it observability? And it's changed, it's changed a lot. Let me start with the simplest definition, then maybe we can unpack it from there. Think of observability as the umbrella term, as the broadest umbrella term that goes above all of this. Monitoring, APM, ObservabilityMike: Observability fully includes APM, and observability also subsumes monitoring, both of the things that we've been doing. There are kind of two megatrends in the industry that have been driving this move towards observability. One is the move to the cloud.More and more systems are moving to cloud architectures, probably more important digitally native architectures. We're going from monolithic systems that we could understand, that we could see, that we could touch. We could understand what's happening with them into cloud increasingly complex, even multi-cloud architectures that are driven by microservices and the like. The reason for that movement is it has made digital transformation, application development faster and easier in that regard. Which is this digital transformation fundamentally looking at everything that I've been doing in every aspects of my business. Whether it be on the front end or in the services I provide. Whether it be on the front end or in the backend machine to machine conversations is happening in cloud architectures. And we're trying to figure out how we can automate more of it and things are happening that way. Does that make sense, just from a starting point, from observability’s umbrella, fully subsumed monitoring, fully subsumed APM, kind of in that the drivers being cloud and digital transformation making that happen. And I can get into more details. Mark: That absolutely hits the mark. And we also say end-user performance or experience. Mike: That's right. Carolyn: Yes, that sets me straight. Because me saying that observability is APM 2.0 is wrong. APM, like you said, it's underneath observability. It might be, I guess, one way into...
Richard Ford, Chief Technology Officer at Praetorian joins Tech Transforms to talk about the cyber security threat landscape. Red team versus Blue team is a common and effective threat protection practice, but what could cyber security experts gain from team Purple? Listen in as Carolyn and Mark learn about the importance of managing your attack surface, implementing multi-factor authentication, and protecting against cyber phishing attacks. Episode Table of Contents[00:30] Our Biggest Cybersecurity Threat in the Last Quarter [07:39] Which Is Easier: Defense or Offense [16:40] Why Do We Need Single Sign-on [24:54] The Team Purple Idea Episode Links and Resources
Our Biggest Cybersecurity Threat in the Last QuarterCarolyn: So today our guest is actually an old friend, https://www.linkedin.com/in/dr-ford/ (Richard Ford), who is https://www.praetorian.com/ (Chief Technology Officer at Praetorian). For over 25 years, Richard has been able to design and implement NextGen product strategies and provide customers with the best threat detection available. Today, we're going to talk to Richard about the cyber threat landscape and what a good defense looks like. Richard: Hi, it's nice to be back on a call with you Carolyn, and Mark, it's good to see you. Carolyn: Yes, really good to have you today. So let's just jump right in. I want to know what your view is, what are our biggest cybersecurity threats? What does the cyber security threat landscape look like and how do we defend ourselves from it? So there's like three-part question there. Richard: So, we're starting with an easy question. I think the threat landscape is incredibly messy and I think that the most important part to think about is change. So if you think about just the last quarter or two that we've gone through you had, like log4shell someone we're all running around looking for log4j vulnerabilities. Then it's Spring4Shell, which wasn't as serious, but was still pretty nasty if you were impacted. The problem, we have this tremendous rate of change so the thing that was important to you yesterday may not be the thing that's important to you today. It's unlikely to be the thing that's most important for you tomorrow. So when we think about the threat landscape, the first thing to say is, if I give you an answer, it's like looking at a single, still image from a movie and telling you've watched the movie, right?Cyber Security Threat LandscapeRichard: Then as soon as we go click, you know that threat landscape will change. With that said, I do think there are some common themes that keep coming back, right? So there's a threat we have around being desperately short of people. There's a threat around, we don't know what assets we have. Even if we did know what assets we have, we don't know what they're running. Then the business conditions are driving us forward so quickly that it's difficult to keep security on the front burner. It sometimes drops to the back burner so we don't think about security as much. Perhaps, as how do I meet these business objectives that we have. I think this has created this sort of very unpleasant, perfect storm that will keep us well on our toes. I don't know, for the next couple of decades, it feels like. Carolyn: So when you say that we're constantly moving forward, changing, at the same time, I mean, are we still dealing with like SolarWinds? So as we're having to look to the future, we're still dealing with all the shit that's happened even a year, two years ago. Is that true, or like, are we good? We took care of it? Richard: No, it's definitely correct right, so all vulnerabilities never really go away. So you have all those things sort of trailing behind you like the comet has a tail, and new stuff coming at you. I think to be a successful CISO or to operate the business successfully, what you need to be really good at is prioritization. So it's about dealing with what is the biggest risk for you right now. Cyber...
Join us on Tech Transforms Federal News Round-up segment, So What? Hosted by Carolyn Ford and Tracy Bannon. This week, we talk to Katy Craig, retired Navy Chief, now Adjunct Faculty at National University, & Director, Security Architecture at Aquia, Inc. about some of the biggest news in the federal space. Listen in to hear her thoughts around deep fakes, non-traditional warfare, and President Biden's recently released announcement to protect against cyber attacks. Episode Table of Contents[00:25] Monthly Federal News Roundup [02:20] Federal News #1: President Biden’s Cyber Security Fact Sheet [10:12] The Catalyst [14:24] Federal News #2: Zelenskyy’s Deepfake [20:55] Federal News #3: The Threat Model [25:26] Federal News #4: Russia Is Running Out of Storage Space Episode Links and Resources
Monthly Federal News Roundup Carolyn: This week, we are launching our newest series, 'So what?' It is Tech Transforms' federal news roundup. Every month, Tracy Bannon, senior principal at MITRE joins me to unpack some of the biggest trending news topics in federal technology. Tracy, we've been trying to do this, make this happen for a while. I am so happy that this is our inaugural episode. Tracy: Thank you. I'm really excited because there's so much incredible stuff going on and we keep talking and now we want to talk with others and I'm doubly excited to have a good friend and mentor with us today for our first episode, Katy Craig. Carolyn: Yes, and Katy is a return guest. We've had her in the past on Tech Transforms and Katy is Acquia's chief of staff, cyber security expert, and retired Navy chief. Today, we're going to talk about, really the number one headline in the news these days. We keep hearing terms like nontraditional warfare, which is essentially the fifth domain of cyber, and President Biden's recent cyber security fact sheet. And just what it all means, like why is it all happening right now? And I want to just go straight to President Biden's recent announcement, this fact sheet that is. https://www.whitehouse.gov/briefing-room/statements-releases/2022/03/21/fact-sheet-act-now-to-protect-against-potential-cyberattacks/ (It's titled 'Act Now to Protect Against Potential Cyberattacks'.) I want to go to you Tracy, and just unpack this for us. What does it mean? Federal News #1: President Biden’s Cyber Security Fact SheetTracy: So I believe it was March 21st, the White House released this set of guidance and it is really practical, general guidance. And it really is focused on two different areas. It's kind of like for everybody, for corporate America back up your data, use multifactor authentication, encrypt your data. There's also a call to arms, to tech companies and software organizations that says, you know what, there's a NIST standard and we have an order out here, it's order 14028. We can provide all the links later. But those two things, they're saying we got to get real about this. And the reason that it came out now is that we need to hear it now with all of the things that are going on in the Ukraine. It was an opportune time. We've had all kinds of security incidents and breaches and other things over the last year or two, but there are some shockers that are coming to the surface that made this very timely for the White House to release this guidance.Carolyn: So you really feel like this guidance came out because of the war in Ukraine? Tracy: I think it was probably teed up before that, probably for quite a while. None of goes very quickly. Any kind of guidance that comes out in this way has good generalized information. I would've put it out a year or two ago at least, if not before that. So for me, a little late to the game, but I'll take late because it's there and we've got to have a full-court press around this. A Call to Federal Agencies, Industry, & CommercialTracy: I'll say the one thing that I found super curious in the entire set of materials was that there is a call that
Listen in for part 2 of our women's panel with Kris Saling, Chief Analytics Officer for the Army Talent Management Task Force and Director of People Analytics in the office of the Assistant Secretary of the Army (Manpower & Reserve Affairs), and Jazmin Furtado, Liaison at AI Accelerator and Data Strategy Lead at US Space Force. In this episode, Carolyn, Kris, and Jazmin get real about the power of the collective, emerging solutions, and the importance to assess and provide within federal government technology. Episode Table of Contents[00:31] Meditation Is Really Good [07:40] Where Are We Going With AI [13:14] Are Women in Tech Paid Equal Like Their Male Counterparts [20:40] Tell People How Much You’re Making Episode Links and Resources
Meditation Is Really GoodCarolyn: We are in part two of our women in technology panel, with Kris Saling, Deputy Director of Army People Analytics, and Captain Jazmin Furtado a Data Strategy Lead at the US Space Force and Space Force Liaison at the MIT AI Accelerator. On today's episode, we're going to dive more into government technology in general. I get Kris and Jazmin to do a little fortune-telling on where tech is headed. What advancements they've seen in their careers. And we get real with some salary talk. Just a little reminder, the views of Kris and Jazmin are their own and do not necessarily reflect the views of their agencies. Now let's get to it on Tech Transforms with our women panel. I know that meditation is really good for the monks that live in caves in India. And I know that I should probably do it. Until I saw the science behind it and what it can really do for my brain. I dabbled in it. I never fully embraced it. And once I started understanding why it was working and that there was true science behind it, man, I'm all in. I'm just thinking of just one example of things that are good for me in my life, that I've been able to embrace and bring into my life because I understand them. I understand how they work rather than like you said, Kris, the leadership saying, "No, we don't give a shit about how you got there. Just give us the answer." Make The Process More EfficientCarolyn: But now you're getting people who really want to understand why. I would imagine that the program for the answers that you've been spoonfeeding them. The programs are becoming a lot more powerful and effective. Because the people who are taking those in the past spoonfed answers. Now really understanding them can truly implement them at a level that is a lot more powerful. Is that true? Kris: I would say that's definitely true because we're working on a couple of projects right now where we are trying to integrate machine learning into promotions and selections as a decision support tool. I'd never in a million years, would've thought we'd get a chance to work on that data and introduce something that is an algorithm into a just intrinsically human process. But we have enough people thinking along this vein. We have enough people looking at the data we've collected about how we read records and how we read files. And they're like, "There's got to be an easier way to do this. There's got to be something we can do to support the board, to pull out the key insights. To package them differently, to display them differently, to sort." And they came to us with the question of how can we make this process more efficient? And I just came back with exactly what the computer is supposed to do. It doesn't get tired, it doesn't get bored. Its attention doesn't wonder, and it can read things a whole heck of a lot faster than we can. So let's see how we can crunch your data a little bit better into more digestible packages for you to review. A Long Way to Go For AIKris: So we keep the human in the process. We keep that comfort level, but now the humans have enough comfort with the machine process. It's not quite human-machine teaming yet. I'm hoping that we'll get to some true instances of
Women in tech unite on this special episode of Tech Transforms featuring Kris Saling, Chief Analytics Officer for the Army Talent Management Task Force and Director of People Analytics in the office of the Assistant Secretary of the Army (Manpower & Reserve Affairs), and Jazmin Furtado, Liaison at AI Accelerator and Data Strategy Lead at US Space Force. Carolyn, Kris and Jazmin discuss the impact of self-awareness and the importance of data education and fostering change when it comes to government technology. Episode Table of Contents[00:27] Introducing the Women in Tech: Kris Saling & Captain Jazmin Furtado [10:32 ] Take It From a Human Approach [17:27] Pulling Other Women in Tech Into the Circle [24:45] Women in Tech Are Influencing One Another [30:14] Women in Tech Are Making Sure They’re Helping Everybody Episode Links and Resources
Introducing the Women in Tech: Kris Saling & Captain Jazmin FurtadoCarolyn: This week we are going full girl power, so Mark got uninvited. Today we have our Women In Tech panel featuring a couple of guests who have previously been on our show, Kris Saling, Deputy Director of Army People Analytics, and Captain Jazmin Furtado, a Data Strategy Lead at the U.S. Space Force and Space Force Liaison at the MIT AI Accelerator. Welcome back Jazmin and Kris to Tech Transforms to talk about your journeys in government technology. I'm really excited to talk to both of you again, but before we get into that let me do a little housekeeping. So I just want to remind our listeners that the views of both Kris and Jazmin are their own and do not necessarily reflect the views of their agencies. I'm just going to say that for myself, too. Because I warned this, too, before we started. I'm like, "I got some stuff I need to get out." And I want to be able to talk freely today. Let's start talking about challenges that both of you have faced being a woman in the technology space. The fact that we even have to say, "Being a woman in the government technology space," other than, we're in the technology space and we kick ass. I hate that we have to do that but I still feel like we do. I'm already getting up on my soapbox. But, let's start with you, Kris. Some of the challenges that you've faced. Kris: So, it's one of those where I don't want to say there aren't any challenges. But I've encountered so many of these challenges throughout my career. I just hit 20 years last summer, I'm going to hit 21 years this coming summer. Yes, it's almost the summer again. Kris Saling’s Challenges for Being One of the Women in TechKris: So it's been a long time of sitting there with the typical, the anxieties, the imposter anxiety, the "What is my balance between being assertive. And how do I not come off as, "Insert your," kind of "The common anxieties"? It really hasn't been all that different. I've been trying to figure out the right balance of how to present different things. How to present facts so that they are listened to. How to present data to an audience where not only do we have the schism between having an audience that's operational and I'm on the technical side. But sometimes it's very obvious that I know quite a bit more about the subject than the people I'm talking to. I think one of the biggest challenges is I really didn't get to know myself and how I wanted to present these things. Because I was very much fixed on how to present that particular image until I really got into data education and started teaching people. That really helped me find a balance in how I wanted to talk about very technical subjects, both with a technical and a lay audience.So I won't say it's overcome all the challenges. You still go out a lot of times, still the only woman sitting in the room. I do have a little bit of a reputation now that I can trade on. So I come into the room with a certain amount of that reputation. But I've seen a lot of cases where that hasn't been the case. Where people have come in...
What does it mean for an agency to monitor applications with empathy to achieve successful mission outcomes? Bill James is the President of Federal Business LLC and FedSmarts LLC. He is also a former Deputy Assistant Secretary of Development and Operations in the Office of Information and Technology at the Department of Veterans Affairs. He joins Carolyn and Mark to talk about the importance of application monitoring, culture, and empathy when executing a mission. Episode Table of Contents[00:30] Introducing Our Guest, Bill James [09:29] The Onus of the User Experience [20:33] Applications Monitoring Is Integrated into the VA Process Episode Links and Resources
Introducing Our Guest, Bill JamesCarolyn: So today, our guest is https://www.linkedin.com/in/bill-james-644039192/ (Bill James). He is president of Federal Business LLC. In his previous role as Deputy Assistant Secretary of Development and Operations in the office of Information and Technology at the Department of Veterans Affairs, Bill led the VA's largest information technology organization to deliver enterprise-wide technology products and services to veterans. He has been able to carry those skills into his current role as president of Federal Business LLC. And today, we're going to get Bill's perspective on why Application Performance Monitoring or APM is no longer a luxury, but a necessity. And he just recently put out a blog that, I'm going to nerd out here, I really like the blog. It's easy to understand. One of the things he says in it, or some of the perspectives we're going to get from him, is how APM for VA software applications is necessary now and critical for the future. And how it helps the VA, and I'm going to throw in there, like any organization, any agency, avoid or recover from outages, increase VA OIT productivity and observability, offer insights into investments needed for innovation and understand and improve the customer experience of veterans. I love that last bit. The customer experience. Bill: Thank you very much, Carolyn and Mark. I'm really happy to be here today, and you've touched one of my hot buttons. I'm really interested in all of it, how the technology ultimately relates and improves the end-user experience. Specifically and particularly, our veterans. And that's why I loved working at the VA so much. Focus On Veterans’ ExperienceCarolyn: Well, and that topic I feel like is especially timely Mark. Especially with the presidential executive order around user experience. I mean, you're kind on the cutting edge, Bill. I mean, you've been doing this before it was cool. You've been worried about the customer experience. Bill: That's right. I grew up as a programmer, a coder, and as a mathematician. It was always interesting to me how we could build a code and write it. And we thought our job was done when we hit the end card, back in the day when we had punch cards. But that wall, was frankly was a false wall, and what we never thought through, I think clearly enough into what that code actually did for the end-user. So I think with the new executive order and clearly the focus on the veterans' experience in the VA, that wall came crumbling down for me particularly. It was really a great place to work and a great place to exercise this whole idea of customer experience from the IT perspective specifically. Carolyn: We're definitely going to dive more into that. Before we go there, for our listeners that may not be as familiar with application performance monitoring or APM, will you give us a quick definition of what that is? Bill: Yes. It's the heartbeat of your systems, and specifically of software. So, many folks have gone to the doctor or seen these electrocardiograms, where they put these things on your chest and you have the little needle that draws how your heartbeat beat is beating. What Is Application Performance MonitoringBill: Software needs that very same type of telemetry, where it can show everybody...
Consolidation, innovation, and perspective all need to work together in government IT according to Eric Trexler, VP of Global Governments and Critical Infrastructure Sales at Forcepoint. IT acts as an enabler of business in the challenging landscape of government technology. Listen in to find out what Eric believes the United States IT space should be focusing on in order to stay ahead of the adversaries. Episode Table of Contents[00:25] All About Innovation with Eric Trexler [10:39] An Enabler of the Business [18:27] We Haven’t Seen Consolidation [21:37] Choosing Fiefdom Over Consolidation and Innovation [27:49] The Commercial Component of Innovation [32:32] There Are Productivity Gains Out of Innovation Episode Links and Resources
All About Innovation with Eric TrexlerCarolyn: Today, our guest is Eric Trexler, Vice President of Global Governments and critical infrastructure at Forcepoint. Eric is an expert in the technology industry with more than 25 years of experience with both the public and private sectors. And Eric and I used to host To The Point Cybersecurity podcast together. So today is actually a real treat for me to see your face again, Eric. So, good morning. Eric: Good morning. And it's bizarre being back on the air with you, Carolyn. Carolyn: So, today, we're going to talk about the perplexing and growing cost of cybercrime and how we can shift the paradigm. But before we jump into that, Eric, you have actually a pretty fascinating background. So, can you just tell us a little bit about your journey? Eric: My journey in IT? Or where would you like me to start? Carolyn: Let's not go all the way back to birth. Let's start at your Airborne Ranger days. How about that? And then how you got to where you are today. So yes, technology. Eric: So, I was an aimless kid at about 17 with no potential to pay for college. No easy path at the time. And I said, I'm joining the army against my mother's wishes to become an Airborne Ranger. The Requirement to Be a Navy SEALCarolyn: At 17? Eric: Yes. She had to sign the paperwork so I could join the delayed entry program. The military throws at you when you have a high ASVAB score, that's the entrance. And I had a high ASVAB score. So, I saw the Navy and they wanted me to be a nuclear engineer. And I just wanted to be a Navy SEAL back in the day before people knew what the Navy SEALs were. But you had to pick a rating, I believe they call it in the Navy. So, I'm sitting in front of the recruiter, and he's like, "Okay, but what do you want to do?" And I'm a dumb kid, I'm 17 years old. "I want to be a Navy SEAL." "Well, you can't do that. You have to have a rating. You have to have this skill at trade." And nothing, absolutely nothing was interesting to me. So, I left. I went to the army recruiter and enlisted. Because they'd let me be an airborne, I was unassigned airborne, technically. How I became an Airborne Ranger? I didn't want to be normal and I was in jump school and talked to a gentleman and I didn't want to wear chemical gear. This was right at the end of the first Gulf War, and everybody was running around in MOPP suits. If you remember that MOPP suits? Hot, heavy, you can't see. MOPP GearMark: You can't breathe. Eric: Same reason I didn't want to be in a tank or a ship or a plane. I wanted to be on my feet and I wanted to be able to move. And I was like, "I don't want to wear MOPP gear." The guy said, "Here's what you do." And that's what I did. So, I literally made the choice because I did not want to wear a helmet and I didn't want to wear MOPP gear. Carolyn: You sound like my six-year-old niece, how she chooses what she wants to do is whatever that doesn't require shoes. Eric: I was probably about as evolved at that point in time. Mark, you know what it's like to be a 17-year-old boy. I mean, you're really pretty low on the intelligent decision-making maturity scale, right? Mark: Maturity scale. Eric: I mean, you're just not there. It was...
Jennifer Ewbank, Deputy Director for Digital Innovation at Central Intelligence Agency joins Carolyn and Mark to talk about the unparalleled work in integration and integration she and her teams are doing. Jennifer talks about the importance of partnerships in IT, data and cybersecurity and how Digital Innovations, the newest branch of the CIA, is transforming security. Episode Table of Contents[00:58] Jennifer’s Opinions on DDI’s Unparalleled Innovation [08:35] Integration of Digital Capabilities and Unparalleled Innovation [16:06] Unparalleled Innovation on Cloud Computing [24:04] Unparalleled Innovation in the Digital Landscape [32:00] Applying Unparalleled Innovation Into Our Mission [39:44] A Space Nerd With Unparalleled Innovation Episode Links and Resources
Jennifer’s Opinions on DDI’s Unparalleled InnovationCarolyn: Today, our guest is https://www.linkedin.com/in/jennifer-ewbank-534779224/ (Jennifer Ewbank), Deputy Director of CIA for Digital Innovation, also known as DDI. Jennifer is responsible for accelerating the development and integration of digital and cyber capabilities across all of the CIA's mission areas. We're so excited to hear from you today, Jennifer, and get your opinions on the DDI and its contributions to the CIA. Jennifer: Thank you so much for the invitation, I'm really excited about our conversation today. I love nothing more than sharing a little bit about the great work that the men and women of the CIA are doing on behalf of the American people. To talk about how this intelligence landscape is changing dramatically along with the digital transformation we see around the world. We're here on the 1st of March. I wanted to acknowledge that, as we have a conversation today about one of these topics I love tremendously. It's really critically important for the intelligence business, it is taking place against the backdrop of events unfolding in Eastern Europe. So, just about a week ago, Russian troops invaded a sovereign nation and brought war back to the European continent in a completely unprovoked act. I just wanted to assure anyone who might be listening to the podcast that the CIA is intensely focused on our national security around the world. We're focused on that crisis and working as part of an integrated US government team to do what we can to bring about a rapid end to these senseless hostilities and the return of Russian troops to the Russian Federation.Unparalleled Innovation on What Matters MostJennifer: I just wanted to ensure, whenever people listen to this, that they understand that we are focused on what matters most at the moment. I'm taking a few minutes out of an otherwise very hectic day to talk about this topic. It’s really important from a strategic perspective but is perhaps not the most urgent topic on our plates today. Carolyn: Honestly, what you do is integral and so important to everything that you just mentioned. Let me see if I can get the words out right but in supporting the sovereign nation. What you do with the digital side of things and this mission, that cyber domain is incredibly important. Jennifer: Yes, we've seen it play out a bit so far in unprovoked attacks on Ukrainian entities. Our role, sometimes, may not be known to those outside of the intelligence community and that's most of America. We work for the US government, we work for the US people, absolutely. But we also support our allies and partners around the globe. Any major challenge requires those partnerships to succeed. Anyway, that was my little PSA at the beginning. Carolyn: Let's talk about your story. Let's talk more about your background, your role at the CIA. Describe the position and what the DDI is. Jennifer: I can't imagine that most people would know what it is. I certainly knew very little about the CIA before joining it. Generally speaking, I lead the Directorate of Digital Innovation at CIA. It’s one of the five large directorates that comprise the whole of CIA. Some
Mike Gruss, Editor-in-chief at Sightline Media Group has eyes on news related to all things DOD. He and his reporters are asking the smart questions when it comes to government defense technology. IT savvy leadership, user experience, and gamification are just some of the topics Mike unpacks in this episode of Tech Transforms. Episode Table of Contents[00:38] The Biggest Trending Topics in Government Technology [09:11] The Lethality of Government Technology [20:05] Predictions for Government Technology in 2022 [31:22] How the Government Technology Is Put Together Episode Links and Resources
The Biggest Trending Topics in Government TechnologyCarolyn: Today we get to talk to https://www.linkedin.com/in/mike-gruss/ (Mike Gruss), editor-in-chief at Sightline Media Group. He’ll discuss some of the hottest topics in the IT industry. Sightline Media Group is the leading news organization covering military, defense, public sector, federal technology, C4ISR, and cyber defense. Today, Mike unpacks some of the biggest trending topics in government technology. We also get his perspective on the DoDs advancement in technology. Mike, I love having you on the show because you have such a broad knowledge. You really have your finger on the pulse of what's happening in the government. So you're over a lot of publications. Can you tell our listeners briefly about your role as editor in chief of Sightline Media Group and the different publications you oversee? Mike: Sightline oversees a number of brands, as you mentioned. I like to think of us as the largest national security newsroom in the country. We have two or three different buckets that our publications fall into. What we've really concentrated on the last year or so is working collaboratively across the newsroom. You may recognize specific brands, but I think our reporters are working across several brands or across the newsroom. There's the military times brands, which are Military Times, Army Times, Air Force Times, Navy Times, and Marine Corps Times. Those are geared toward the troops and you'll see those publications, obviously online. They're available at commissaries, and then there's also our business to government groups. What’s Happening With the Government TechnologyMike: Those are publications like defense news, which covers the defense industry and what's happening at the Pentagon and on Capitol Hill, the business and politics of defense acquisitions. And also C4ISR net, which focuses more on that network warfare aspect of the defense industry. The last publication we have is Federal Times. It focuses on the federal workforce and what they need and what's happening there on a day-to-day basis. It's a lot, but we have a really passionate and skilled newsroom that thinks hard about these issues. They work really hard to get scoops up and to get enterprise news stories that will help people understand what's happening at their job and make better decisions every day at work.Carolyn: I love the specialization. Obviously, you get a lot of stories that are going to be broad across. But when you take it and get specific to the mission of the different branches and the different missions, I really appreciate that. Mike: I don't like to use the word expert because I think it's overused. But I'd say all of our reporters have a tremendous amount of knowledge in their field. They work really hard to ask smart questions, to be able to explain issues clearly and to know the nuances. I think that comes through in our reporting. Carolyn: I definitely agree and I would absolutely use the word expert. Talk about your perspective on how the DoDs are making advancements in government technology. Do you think they're taking the right steps right now? Mike: This is a difficult question and I think there's such a push-pull that we have to do here. I'm curious how you think of it too. What DoD Has to Do With ITMike: On one hand, I think we have to recognize the complexity of...
Sandy Carter, Unstoppable Domains SVP and Channel Chief again joins Carolyn and Mark, this time to discuss the importance of diversity in technology. She gives us an exciting inside look at her event, Unstoppable Women of Web3. Sandy walks the walk when it comes to getting women and girls involved in tech. Follow her on social media to get the latest updates! Episode Table of Contents[00:55] The Vision for Unstoppable Women [05:42] Unstoppable Women Are Learning About IOT and Machines [11:09] A Dream to Start the Groundswell With Unstoppable Women Episode Links and Resources
The Vision for Unstoppable WomenCarolyn: So we have https://www.linkedin.com/in/sandyacarter/#experience (Sandy Carter) back. The last time we talked to her, she gave me the 101 on Web3 and FTs, crypto. My head's still swimming a little bit but I'm actually really excited about it. She did a great job and one of the key things that Sandy talked about was for Web3 to be the vision that she has for it and to be really strong, it needs diversity. Today, we're back with Sandy Carter, renowned technologist, bestselling author, and current senior VP at Unstoppable Domains. She's one of the leading pioneers in the digital business and also a former Fortune 25 business executive. She is a leader focused on helping companies with innovation and digital transformation through culture and technology like AI and the internet of things. So let's jump into it. As an advocate for diversity and women in technology and your involvement within girls in tech, what advice would you give to women pursuing roles in technology today? Sandy: There's a couple of things. Technology is moving at such a pace that I think you need to develop this learn and be curious notion. Probably, what you're studying today in school or what you're doing today at your job will change significantly. Top Jobs Today for Unstoppable WomenSandy: I was on the diversity group for the World Economic Forum and one of the interesting pieces of data that they shared with us was that the top jobs today in technology didn't exist five years ago. So unless you're going to be stuck in an old legacy role which will decline over time, you've got to be continuously learning and curious about what's coming so that you're ready to go in a lot of those new areas and those new fields. Carolyn: How do we stay current? Getting a degree is a good foundation and things are changing so often. What are some conferences or certifications that you would recommend for women in tech? Sandy: There is a lot of really good material out there. There's so many classes and things that you can take just to refresh yourself, like YouTube. One of the things I do is to dedicate time every week. I mark an hour in my calendar every week. It probably could be more, but at least, an hour every week to check out something that I don't know about. Maybe it's quantum computing or spatial computing or a new thing that's happening in Web3. I'm always constantly on that front edge.I still remember when I was with IBM and I got selected to lead a lot of our artificial intelligence work. People were like, "Wow, you're so lucky to get to do artificial intelligence." I would say, "No, I'm not lucky. I've been studying this. I took two classes at MIT. I've been playing around with this. I was learning and being curious about it so that when this opportunity came, I was ready." Where We Are Today With TechnologySandy: So if you're just doing your day job today, I don't think it's enough. In fact, I have two daughters and they love Alice in Wonderland. One of the parts I love so much about that book is, Alice said, "I had to run twice as fast just to stay in place." And that's where we are today with technology. I think you can't just focus on your current role. You always had to be learning about what that next role might be or might hold.Mark: You got your degree in computer science at Duke University. It's not surprising to me...
Sandy Carter, SVP and Channel Chief at Unstoppable Domains and former Vice President at Amazon Web Services talks about the groundbreaking work she is doing with Web3. Listen in to get more information on Web3 capabilities and hear about the chaotic creation that Unstoppable Domains is taking on. Episode Table of Contents[00:53] A Leading Pioneer in Web3 and Digital Transformation [08:280] A Hot Topic Element of Web3 [15:12] Women Are Getting Involved With Web3 [23:04] What Web3 Means for the Government Episode Links and Resources
A Leading Pioneer in Web3 and Digital TransformationCarolyn: Today, we're talking to https://www.linkedin.com/in/sandyacarter/#experience (Sandy Carter), and I'm excited to have her all to myself. Sandy is a renowned technologist, bestselling author, and current senior VP at Unstoppable Domains. She is one of the leading pioneers in the digital business, and a former Fortune 25 business executive. She’s a leader focused on helping companies with innovative and digital transformation through culture and technology, like AI and Internet of Things. Sandy, you have an incredible background. You've been with IBM, recently with Amazon Web Services, and now you're working with Unstoppable Domains. I would love for you to tell us your story. What is the journey that you've had with your career? How did you get to Unstoppable Domains, and what is it? Sandy: Well, it's really interesting. You'll notice in all of my companies, IBM, and then you missed a startup. I had a startup in between and then AWS, and then now a startup with Unstoppable. All of those companies were on the leading or bleeding edge of technology. At the time I was at IBM, we were bleeding edge for social media and business, which was that Web 2.0 era. I then went to form my own company and I was doing artificial intelligence. In fact, I thought it was so cool. I was doing like a Myers-Brigg on companies to determine their culture so that we can match them with the right innovation tactic. That way, they didn't go and try something that didn't fit their culture, because culture eats strategy for lunch.Developing the Right Processes for Web3Sandy: Then I moved on to Amazon, and Amazon was all about the cloud, another tech transformation that was going on. I learned so much from each of these companies. Leadership principles from Amazon and how to develop the right processes and mechanisms from IBM. From my startup, how to be really scrappy and to do things that 80/20 rule; not perfect, but good. Good for the customer, valuable for the customer, but not necessarily reaching that perfection mark. When Web3 started out, I was really interested in it. I’ve done some blockchain at Amazon Web Services and I was fascinated with the new technology. So I started doing all of these side projects on NFT, setting up my wallet, doing all this stuff on the side. It turned out that a company approached me called Unstoppable Domains. I was fascinated by what they were doing in the marketplace. They’re focused on digital identity and how, in the Web3 world, you take your identity with you. It's not linked with a particular application. I thought that was fascinating given my history. Looking at Web3, I was like, why would I keep doing these side projects when I could do this full time? So, I came on with Unstoppable. The founding team is great, the portfolio of products is really fascinating to me, and the partners are all the who's who of Web3. So, here I am and I'm having a blast. Web3 Centralization and DecentralizationCarolyn: You talked about several things that are a little baffling to me. First of all, Web3. I'm embarrassed to say that I really haven’t heard that term until I knew that you were a guest. I started looking at some stuff that you've talked about, and I was like, okay, what is this? So, I read some articles over the weekend and I'm still not sure exactly what it is. It's decentralization and centralization and then...
American culture and history is meant to be shared, according to senior application developer at the National Museum of African American History and Culture, and Army veteran Rayvn Manuel. She talks with Carolyn and Mark about some of her goals in her work at the Smithsonian and the importance of sharing our stories and understanding our history. Episode Table of Contents[00:36] On the Record With an Army Veteran [09:18] A Change of Name on the Record [16:35] Growing up in a Lot of Racism Episode Links and Resources
On the Record With an Army VeteranCarolyn: We had the pleasure of speaking with https://www.linkedin.com/in/rayvnkm/ (Rayvn Manuel) in November of last year. She’s a senior application developer at the National Museum of African American History and Culture and an army veteran. Following our regular recorded episode, Rayvn spoke to us about her opinion on some topics surrounding our history and culture in America. I went to the museum. When I got there, I felt a little bit like an intruder. It’s like I had no right to be there. Can you talk about that? Have you talked to other people who have felt that? Rayvn: Yes, I have. One of my really good friends, Chelsea, we were talking. I make costumes, and I make costumes for Renaissance Fair. Carolyn: I want to see pictures. Rayvn: I don't even let my kids see pictures of me in my costumes, but I love it. I was making her costume and she was just telling me how uncomfortable she feels. She's not African American, she's Caucasian American. She was telling me how she is confused about what to do because she has so much empathy for what's going on with Black Lives Matter. There are certain people in the African American community that will embrace people who are trying to understand. Then there are also other people who actually will make you feel like you feel, Carolyn. It’s like, you'll never understand so don't even try to understand. She's like, "Well, what do I do? So I don't want to come like I'm condescending and I don't want to feel like whatever." I think that what you do, part of that is guilt. A Big HeartRayvn: That you feel some sort of guilt for something that you had nothing or have anything to do with. You have a big heart and so much empathy that you just want to understand. Not only understand, because I don't think I could ever understand anyone that went through the Holocaust. I didn't feel like I didn't belong in that museum because it was an experience that I wanted to see. And I was in the army and I was stationed, actually, in Germany. I went to Dachau, and that is a place to get a better understanding of the culture, of the society. That culture and that society makes up our culture and our society, and we engage. I engage. In New York, I engaged with people who had grandparents that had to deal with things from the fallout from the Holocaust. I learned that my grandmother, this hurt me to my soul, this is why I became what's called woke. My grandmother told me that they were in North Carolina, her and my mom. My mom was little, and my uncle, they were not allowed to sit in the front of the bus. Up until that point I understood that that's what happened. I understood that from an educational perspective. When my grandmother told me about her and my mother, things changed. Mark: It became personal. Rayvn: Yes, I did. I couldn't because that's the generation before me. You can't feel that you don't belong. Because wherever your background is and where most of us are all mutts most of it, we're totally mixed. Carolyn: I'm a complete mutt. Your Background Is Your History on the RecordRayvn: I am, too. My father's side is Portuguese. Carolyn: Well, I feel like your eyes are green, aren't they? Rayvn: They're blue-ish, but they change colors depending on what I'm wearing. Whatever your background is, that's going to be your history. Ford is actually British, isn't it? That's what it'd be, probably. Carolyn: Well, it traces all...
Willie Hicks, CTO of Public Sector at Dynatrace, joins Carolyn and Mark to discuss the top Cybersecurity news stories so far in 2022. Willie offers his expert opinion on the White House Executive Order on Improving the Digital Government Experience, the recent Log4j vulnerability, and the Pentagon's new Zero Trust office. Episode Table of Contents[00:43] Unpacking the Biggest Headlines in Cybersecurity News [08:21] Major Catastrophe [16:03] Cybersecurity News Highlights the Highest Level of Vulnerability [23:59] A Quantum Shift in Cybersecurity News Episode Links and Resources
Unpacking the Biggest Headlines in Cybersecurity NewsCarolyn: Today we talked to https://www.linkedin.com/in/williehicksee/ (Willie Hicks), Dynatrace public sector CTO. He’ll unpack some of the biggest headlines of late from the Executive Order on Transforming Federal Customer Experience and Service Delivery to Log4j. I know Willie, you're so sick of this topic, but we're going to cover it anyway, and then Zero Trust Thunderdome Awards. I want to go first to the Executive Order requiring improving the digital government experience. Willie, will you give us the big takeaways from this Executive Order? What does it mean for our agencies? Willie: First of all, I think that the Executive Order on Transforming is transforming the federal customer experience. It is going to impact the agencies, but I also think it's going to impact the digital citizens of the day, the real customers of the federal government. I think President Biden reiterated this, it’s supposed to be a government for the people, by the people. We're trying to put people back into the equation. I think the big takeaway for me is that the federal government is coming back into or getting to a point where they're really understanding that customer experience, well, they already understood it. But they’re really starting to internalize and figure out how to make customer experience like the customer experience most citizens expect to see with anybody who shops on Amazon, anyone who does a Google search.A Fundamental Shift in Customer ExperienceWillie: They expect, with the push of a button, that they got all the groceries shipped to them the next day or the same day. That kind of experience you do not get with the federal government today. I think that we're seeing a fundamental shift now, not just that kind of digital experience, but I think across the board. Like when you even walk into a brick or a mortar building, when you interface on the phone with a government employee, I think we're going to start, hopefully, seeing more customer-focused, customer-centric type attitudes. This is really long overdue. I've been in this business for many years. I remember one of my early visits to a federal agency that will remain nameless, but I was speaking to this agency about what we call our digital user experience. How we need to focus on the real metric who's the end user. Right now, you are focused on the back end. You're focused on, is the server up or down? Is this process running? Do I have availability for this device? No one's actually really looking at the end user. So how do you know they are getting a good experience? Not only are the systems running, but are they running efficiently? Are they getting transactions back in a timely manner, or are they frustrated?I remember one engineer saying, "Well, why does that matter?" I'm like, "It does matter because they're your number one responsibility. That is who pays your salary." This person, an engineer, actually said to me, "Well, there's not another X agency. It's not like they're going to go somewhere else. This isn't Amazon or another commercial entity. If it doesn't work, they'll come back later." That was the response. And I was like, wow! Smooth Government TransactionsCarolyn: It makes me think of when my dad died a few years ago. We wanted to give him a full military burial, but we couldn't find the papers that we...
What does it take to secure 160 million Americans privacy? Greg Crabb, former Chief Information Security Officer at US Postal Service joins Tech Transforms to talk about his experiences from his time as Projects Coordinator for International Fraud to his role in the 2020 US Presidential Election. Episode Table of Contents[00:42] Greg Crabb in the House, Founder of 10-8 Cyber [10:33] Good Guys Get Together With Greg Crabb [20:05] They Want To Do the Right Thing [29:32] Greg Crabb Had a Long, Deep, and Intense Service Episode Links and Resources
Greg Crabb in the House, Founder of 10-8 CyberCarolyn: Today, our guest is a rockstar. His background just blew me away.https://www.linkedin.com/in/gregorycrabb/ ( Greg Crabb), founder of 10-8 Cyber and strategic advisor to several organizations, but that doesn't even scratch the tip of the iceberg of who our guest is today. Greg: Thank you, Carolyn. I enjoy the opportunity to chat. Carolyn: You recently retired after 20 years with the US Postal Service where you wore many hats. From being a project coordinator for international fraud, assistant director of economic crimes, you ended your career as the chief information security officer and vice president of USPS. That's the very tip of the iceberg of your career. I want to kick it over to you and have you tell us your story. Greg: The mission of my life has been to protect others and drive benefits for society. I was grateful enough to have the opportunity to retire last year after 30 years of federal service. When I joined the postal service in the mid-90s, I spent the first several years of my career being an auditor. I was responsible for the old electronic data processing controls portion of the financial audit. There I learned an amazing amount of information about how computers work, mainframes, networking, and all that sort of thing. In 2000, I transitioned to spend seven years investigating the origins of Eastern European organized cyber crime. That was an amazing experience. I got the opportunity to really attack an organized crime group. It was based out of Ukraine and had splinters all over the world. I worked with Europol and Interpol, the Secret Service, the FBI, and many other organizations in between. Bigger and Better Things for Greg CrabbGreg: In about 2005, I moved to Washington to take on bigger and better things. Then in 2010, the international supply chain was attacked with some parcel bombs from AQAP. AQAP put PETN, it's the liquid explosive that we all know as why we can't carry water bottles onto airplanes. It completely changed the security model of how international supply chains work for moving parcels. I spent a number of years working with an international community of 190 countries to develop new standards. Worked with civil aviation authorities to properly secure the supply chain from a commercial aviation perspective for parcel security. In 2014, I got tapped to respond to a pretty significant breach at the US Postal Service. In that moment, I transitioned from being the law enforcement officer who was the hunter to the chief information security officer who was the hunted and responsible for an amazing network. I was grateful to provide security for 160 million delivery points, private communications, and parcels for all of America for six years. As we talked before the show, I was really grateful to have the opportunity to help protect the 2020 election. It was just an amazing collaboration with the folks at CISA and many other organizations across the country in order to pull that off.Carolyn: Can you talk about what you did to prepare for that? Talk about pressure. You'd been preparing for 20 years. Greg: I had been preparing. I wouldn’t have been as successful in protecting the technology assets the postal service relied on to move 70 million ballots if I had not had those experiences. Greg Crabb Is Dealing With Eastern European Organized Cyber CrimeGreg: I’ve been dealing with...
Technology is paramount when it comes to securing our nation according to Pete Tseronis, CEO of Dots and Bridges, former CTO of the US Department of Energy and US Department of Education. On this episode of Tech Transforms, Pete explains the critical role technology plays in our lives, and how innovation underpins that foundation. Episode Table of Contents[00:38] Pete Tseronis: From Fed to Dots and Bridges [05:50] Why It Matters To Translate the Tech [12:22] Who Are Keeping the Lights On [22:00] How Pete Tseronis Responds to the Mission [29:33] Information at Your Fingertips Episode Links and Resources
Pete Tseronis: From Fed to Dots and BridgesCarolyn: Our guest today has got quite the pedigree, https://www.linkedin.com/in/ptseronis/ (Pete Tseronis), CEO of Dots and Bridges. Before Dots and Bridges, Pete served as a Cabinet-level federal CTO, not once, but twice. First at the US Department of Education for eight years, and then at the US Department of Energy for seven and a half years. Before those two, he was actually with the DoD since the beginning of things. Pete: It's nice to be on the other side of the mic. I have all the respect in the world for what you're doing, in addition to your other jobs and incredible pedigree you have. But I love the conversations and it's a treat to be able to tell my story a little bit, at least. Carolyn: Your unique perspective on technology and federal agencies, as well as from the commercial side, it's going to be a great conversation. Let's just start with your story. Will you give us an overview of Dots and Bridges and how it came about? Then share your journey in the government and where you are now. Pete: I tell folks I can do five hours or I can do it in about a minute. But there's about 32 years there, wrapped up. I'm a Washingtonian native. I grew up in the Washington DC area, in the suburbs of Maryland, Montgomery County and went to high school in Washington DC. It took me to Villanova University for my undergrad, where I studied liberal arts and communications. I wanted to be a sports broadcaster. Pete Tseronis Had the Coolest Job in the WorldPete: I’m 54, and I do have a nine-year-old. So a little bit of a late bloomer. Four kids, a great wife from Pittsburgh, and yes, I have an Australian Labradoodle named Phineas Maximus Tseronis. So that is my life, my family. I came out of college, I ended up back here in DC, and interned at the Pentagon. One day, I woke up and I'm working in the Pentagon. I thought it was the coolest thing in the world. Didn't have a plan to work for the government. I didn't know much about it, even though it was in my backyard. But it put me on my journey. The time was '91. I had the chance, when I was working as a civilian, the Department of the Army, to dabble in some of the work that the DARPA community was working on. The internet work was what it was called. Before I knew it, I had a bug, an itch that I scratched. And I was like, "This is going to be a big deal." I was that guy typing in on a text-based, character-based, if you will, screen: www.espn.com. I'm like, "Whoa, I can see all this news before it's in the paper tomorrow." The itch was there. I said, "I'm going to go learn this internet thing." At that point, it was three years at DoD. I had a chance to move over to the Department of Education and do some computer security work. That was becoming a thing, like if you're going to use this tool, security matters. So we'll talk a little bit about that today and its evolution, but I jumped back to school. Pete Tseronis Got the Coolest Education for Three YearsPete: I enrolled at Johns Hopkins University and got my master's degree in telecommunications. I’ve wanted to know how this worked. How do you type something in and then it's there on your screen? That was the coolest education for three years. Every time I'd go back to class, it was like the material we learned was outdated. For three years it was like all of us were...
With transformative technologies such as AI and Machine Learning, government agencies can help achieve goals, detect fraud, and create data-driven strategies. Chief Data Scientist and ODS Acting Associate Director at NTIS, US Department of Commerce Chakib Chraibi joins tech transforms to discuss his insights on helping the US Federal agencies and citizens use data to enhance any mission. Episode Table of Contents[00:53] Delivering Transformative Data Solutions [09:00] AI Has Very Transformative Data and Technology [18:12] How Transformative Data Identifies Fraudsters [29:10] Virtual Reality Episode Links and Resources
Delivering Transformative Data SolutionsCarolyn: Today, we got to talk to https://www.linkedin.com/in/chakibchraibi/ (Dr. Chakib Chraibi). He’s the Chief Data Scientist in the US Department of Commerce, National Technical Information Service, or NTIS, and acting associate director for the Office of Data Services. He provides expertise and assistance to government agencies in harnessing innovative technologies and delivering data-driven solutions to achieve mission impact within the NTIS framework. Chakib, welcome to Tech Transforms. Let's start with a brief overview of your role at NTIS as well as the role of NTIS within government agencies. Chakib: NTIS is a bureau within the US Department of Commerce. We want to think about NTIS as the best-kept secret in government. What I'm going to say about NTIS is going to resonate with a lot of our listeners. NTIS is a very interesting agency that is focused on data science and data innovation. It was created shortly after the Second World War. The main task at that point was to gather all the information collected from the Second World War that dealt with technical research, et cetera. It became a repository of information for the government. They dealt with any technical papers or publications from the civilian side. But in the 1990s, the internet happened. And so, we're still doing that. We have one of the largest libraries. We're continuing collecting that information, but Congress has thought about focusing us on a different mission at that time. It is actually a great idea, and which is about data science. Our Main Focus at NTISChakib: Currently, that's our main focus at NTIS. We provide a unique pathway for federal agencies towards innovation and digital transformation. We have an authority from Congress that allows us to seek out their partners from the industry, from academic institutions, nonprofits, to help federal agencies address national data center challenges. It's available to all federal agencies seeking an agile capacity to scale. It has quick access to private sector ingenuity, and expertise, to meet critical mission data priorities. We also use a very innovative framework. It’s based on agile methodology to be able to harness emerging and cutting-edge technologies. We operate outside the Federal Acquisition Regulation, outside of FAR. It’s in the innovation space, and it's really exciting. Whenever you want to innovate, you are not sure about how to go about it. All federal agencies want to be effective and efficient in accomplishing their missions and addressing data priorities. But, sometimes they don't know how to go about it. They have an idea about the business problems and what they want to achieve, but they don't have all the details, and the steps to go about it. That's because that's part of any innovative work that you're going to do. That is where we can help them with. We have a very agile framework where they can come and discuss their business problems with us at a very high level and what they want to achieve. What is their mission? What's the most important thing that they want to accomplish? Based on that conversation, we can actually develop a problem statement. It’s a very high level scope statement that tries to address data innovation goals they want to achieve.A Free-Flowing Discussion on Transformative...
In an AI driven world, the role of intuition and experience can be hard to define. Kris Saling, Chief Analytics Officer for the Army Talent Management Task Force and Director of People Analytics in the office of the Assistant Secretary of the Army M&RA joins Tech Transforms to give insight on talent management within government agencies. Episode Table of Contents[00:41] The Analytic and Technology of Talent Management [07:35] Ensuring Unbiased Data Talent Management [16:28] Talent Management Prediction Vectors [22:21] Quality of Life [31:58] Talent Management in AI Analytics [38:39] How Do We Ensure Trust in Talent Management Episode Links and Resources
The Analytic and Technology of Talent ManagementCarolyn: https://www.linkedin.com/in/kristin-saling-a8604b19/ (Kris Saling) is Deputy Director Army, People Analytics, and the Chief Analytics Officer for the Army Talent Management Task Force. She coordinates analytic and technology solutions, rights policy, and resources innovation to promote data-driven decision-making across the Army's people enterprise. Kris, welcome to Tech Transforms. Kris: Thanks so much, and I'm really happy to be here. This is going to be fun. Carolyn: So I want to start off with a two-part question. Let's start with the awesome poster behind you, of Sherlock Holmes. Tell us the story behind that. Kris: There are a bunch of stories behind that. The big one is people ask me why I went into data science out of all the things I could have gotten into. My usual answer for them is because I read too much Arthur Conan Doyle when I was growing up. I just love the idea of sifting through all this information, finding clues, and solving problems, and that just persisted. That's up there for some motivation, but also a huge Robert Downey Jr. fan. He established a smart AI, a corporation that specializes in sustainability work through AI. It's called Footprints. He took the whole Tony Stark thing and decided he was going to make that his real life. Carolyn: I'm loving him even more. I've always been a big fan. How can you not be? Kris: Yes, save the planet through AI, how can you not love that? Carolyn: Before we move on to your job, do you have a favorite Arthur Conan Doyle story? What's your favorite Sherlock Holmes? A Long and Unusual StoryKris: There's so many of them that stick, but I'm trying to remember the title of it. It's one of the first ones where he first meets Watson and just some of their banter. It is a really long and unusual story. Half of the story is a flashback where he's talking to the perpetrator, one of these crimes. He is talking about his migration across the wild west frontier. Going to have to try and remember what that was, but it's just the meeting between him and Watson. Just the dynamic of this very straight-laced professional, trying to sit there and figure out what the heck he has in this certifiably, insane new roommate. But the fact that they connect on the intellectual level, it just makes that dynamic all kinds of fun. Carolyn: Do you remember? Mark: It's like Jarvis. Carolyn: Do you remember how old you were when you first got hooked? Your first story? Kris: 12 or 13 I think? Carolyn: So now we know what inspired you to get into the line of work that you're in? Mark and I are really intrigued by your titles. Is it HR or is it operations? It's super cool. You have a quote that says you're leveraging AI to leverage AI. Will you unpack what it is that you do to include how the USA fits in? Kris: I have two bosses. One of them is the assistant secretary of the army for manpower and reserve affairs. The other is the director of the army talent management task force. In both of my roles, I essentially have the same portfolio. Applying Talent Management in People AnalyticsKris: My short way of explaining it is it's all things talent data and data talent. So doing a lot to revitalize how the army is looking at its personnel management systems. I’m...
Logistics of supply chain could be the difference in a successful mission for on the ground forces or the cyber warfighter. Scott Hume, managing director of operations in contested environments at MITRE, speaks to the importance of tactical planning and innovation to assist our troops. Carolyn and Mark discover the best ways industry can assist the warfighter. Episode Table of Contents[00:47] Globally Contested Logistics Strategy [07:17] Supply Chain Challenges [13:47] Constant Intellectual Property [21:28] Globally Contested Supply Chain [30:27] Robot Dogs Episode Links and Resources
Globally Contested Logistics StrategyCarolyn: Today's guest, https://www.linkedin.com/in/scott-hume-43610a1/ (Scott Hume), is the managing director of operations in contested environments at MITRE. Scott has been with MITRE for more than 20 years. He’s responsible for shaping the company's globally contested logistics strategy, particularly for one of its sponsors, the US Air Force. Today we're going to talk to Scott about how our government and our military enhance their capabilities in contested environments through partnerships with industry and academia. We’ll also discuss how the industry can best connect with the DOD to help safeguard our nation and support our military. Let's start out Scott with how MITRE does a lot of work with the Department of Defense. Can you tell us what areas and with which military branches you do work with? Scott: Let me first start out because some of the audience may not be aware of MITRE. In fact, when I came to MITRE over 20 years ago, I was disappointed that we weren't the company that made soccer balls and soccer cleats. I quickly learned that MITRE operates R&D centers for the government. One in particular is the Department of Defense, which is our National Security Engineering Center. Particularly of the 20 years, I spent the majority working with the Air Force. But MITRE works across all branches of the Department of Defense as well as the combatant command and the joint Chief of Staff. Throughout the Air Force, I always say that I've had seven different careers. At MITRE, I've been able to work in IT, cyber, command and control, programs, as well as counter improvised explosive devices. So counter IEDs during the war on terrorism. Remembering Pearl HarborCarolyn: What area of the military and the branches are you working with? Scott: Primarily I'm working with the Air Force, leading an opportunity to develop MITRE's globally contested logistics. Let me break that apart for you. When we talk about logistics, it's really anything from fuel, water, ammunition to food. It’s getting equipment as well as our forces to the locations that they're going to have to fight in. The contested pieces, I'll pause for a second and remember the day of December 7th, 80 years ago. So on this day today, an adversary decided to bomb Pearl Harbor and our forces there. That was the last time that we actually were in a contested environment across the globe. Where we didn't have freedom of maneuver, freedom of navigation and we're in that environment today with our pure adversaries. We no longer have the full freedom to move our forces or supplies, like some would call the greatest generation. Perhaps we can meet that same call as we look at how to, first of all, develop the capabilities our DoD needs to deter that fight with a pure adversary. But if that pure adversary chooses to fight, we have the capabilities to win and execute that fight. If you look at the logistics piece of it, it goes all the way back to the Napoleon wars. Napoleon once was quoted as saying, "Logistics wins the wars." MITRE is not a logistics company nor are we looking to get into that business. We're looking at how we provide our system engineering and integration expertise to this domain. If you read the 2018 national defense strategy, you don't have to read the classified version. There's an unclassified version that's out...
"Technology is easy: Everyone is doing it, culture is the challenge” says retired Navy Chief, now Defense Consultant, & Cyber Educator at Deloitte, Katy Craig. When it comes to implementing new technology, a trusting environment can make all the difference. In this episode, Carolyn and Mark learn why prioritizing people is always a step in the right direction. Episode Table of Contents[00:48] Helping Teams Accelerate [09:34] The Point of the Mission [20:08] Better Minds on People Problem [29:09] Technology Is Transforming People Problem Episode Links and Resources
Helping Teams AccelerateCarolyn: Our guest today is https://www.linkedin.com/in/katycraig/ (Katy Craig), a retired Navy chief. She's now a defense consultant and cyber educator at Deloitte. We're going to talk about her work, helping teams accelerate to deliver value safely and securely to customers. She provides guidance on tools, technologies, and methods such as cloud security, agile methods, SDX, Zero Trust, and DevOps practices. One of my favorite topics and Mark's as well, is shifting security left for DevSecOps and continuous everything. Today, we're going to dial into how she helps teams embrace a DevSecOps culture, some of the biggest pitfalls, as well as best practices. I read something on your bio and I was like, "I love that!" You say in your bio, "Technology is easy. Everyone is doing it. Culture is the challenge and where I can help most." Talk to us about that. Katy: I'm trying to think if I can legally hashtag it, the people, s. I actually Googled it. Somebody did back in the '90s after President Clinton said, "It's the economy, s." Somebody actually said, "It's the people, s**." But I want to bring it back into the lexicon and into the vernacular. Because a lot of these buzzwords that we're hearing in the zeitgeist, DevOps, I need to go buy some agile. We're going to do some DevOps. They're selling Zero Trust, let's go buy that. It is rarely turnkey solutions out of the box. It's rarely the technology that all these vendors are selling on the internet and promising it’s going to be the panacea. People Problem You Have to Deal WithKaty: No matter how great your tool, your weapon, or your process, if the people don't embrace it, they aren't brought along, and aren't included in deciding that's the tool we're going to use, that's the process we're going to embrace, they're going to fight you. They're not going to adopt it. Maybe even in a bureaucracy, they might eventually go along to get along, but it will be delayed. It will be less of a quality approach. It's always going to come down to the people. We always have to remember that our reason for being here, for being in tech, for doing all this work has to come back to the people. I always go back to Gene Roddenberry and Star Trek. I'm a Trekker, sort of directive. You can do no harm.What are the Boston Dynamics people doing? I worry about the robots. It's got to come back to the people. If we're doing this tech and pursuing all these areas, it's got to come back to: is it going to be good for the people? Is it going to make our lives better, make the planet better, or our country better? That's why I say, "You know what, everybody's out there peddling technology. Promising that if you install my platform, I'm going to solve all your cyber problems." It's just not true. Mark: Are you talking about the mission? Or are you talking about getting the people on board with the technology to be able to leverage and use it? Is it the people as it relates to the mission, or is it the people as it relates to getting them on board with the technology, and how it can help them? Unique People Problem of the MilitaryKaty: It does go to the unique problem of military teams, for example. We have administrative control and operational control. Then we have organizations in the military that acquire their technology. They decide whether to make or buy the technology to serve the warfighters
Lonye Ford, CEO of Arlo Solutions speaks to some of the challenges she faces as a woman in the government technology workforce. Lonye has had success and challenges from her time at the U.S. Air Force help desk, to her current role of CEO at Arlo Solutions. Carolyn and Mark get a uniquely human perspective surrounding government technology. Episode Table of Contents[01:18] Bringing the Women in Technology Together [06:24] Women in Technology Are Creating Their Own Lane [09:36] Issues Women in Technology Have to Deal With Episode Links and Resources
Lonye Ford Brings the Team TogetherCarolyn: Today, we have https://www.linkedin.com/in/lonyeford/ (Lonye Ford), CEO of ARLO Solutions. Lonye served for over 10 years in the US Air Force. Thank you for your service, Lonye. She was named one of the Top 50 in Tech Visionary at InterCon 2021. You talked about your superpower which is to get the teams, all these experts with these egos, to come together. I'm wondering, when you walk in a room you have to be a little bit disarming. You look super young, you're a woman and you're African-American. When you walk into a room, do you think those things help you with bringing the teams together? Have you seen it played against you? Lonye: It's so important to ask those questions. To be honest, I have been feeling weird about addressing that directly. You come up in the military and you don't talk about sex, religion, color. Now, I'm asking a lot of diversity questions this year, because diversity has really been pushed to the forefront. It's really the first time I have been asked those questions before. We talk about it, but not in the open forum. I'm getting more comfortable with addressing it. When I first started, it did not help me. It was very difficult to gain respect. So when I walked into the room, I would tell people I had to be over-prepared. Not Because I’m a WomanCarolyn: Dismissed because of the way you look. Tracy and I talked about this a little bit. I want to be known for what I can do, not because I'm a woman. So I haven't even wanted to address those questions. It's like you know what, it's not about me being a woman. It's about me being capable. Lonye: I struggle with that. I'm going to give you an example. We're in an award for Moxie Group for DC, we're finalists. The category that we're in is women owned. My partner went back and she said, "Actually, I don't want to be in this category." That's how much we struggle with it. She was like, "I don't want to be in this category." We went back and forth. She's like, "Why would we get an award based on our gender?" So then, we went back and explained, this is where we're struggling too. I told her to think about the message also, that people are trying to integrate and highlight the work that women are doing. Is it perfect? No. Sometimes it'll come across as odd. No, but you also don't want to always push back when someone is trying so hard, explain to them. And then, we're still competing with other women.But her thing is, "I don't want to compete with other women, I want to compete with everyone. I don't want to be put in that category." I'd say that we struggle with that, too. We do. Lonye Ford Probes for the IntentCarolyn: I don't want to be on a panel for women in technology. I want to be on a panel for superheroes in technology. Lonye: It's important if we think about the intent. Personally, I don't. But if you think about it, if our intent is to serve and to provide this ability, there are a lot of women and young women that are looking at that. That has a very positive impact on them. So if you take out how you feel about it and if you look at it more as, "How am I serving the community," that'll help us change. We'll continue to mature. Right now, people are trying.People are trying to integrate women and highlight women. The intent is right. As we mature, we start saying, "Hey, guy that's running this, maybe it's better to integrate us in this...
On this special episode of Tech Transforms, Carolyn and Mark look to the new year with trends and predictions for government technology. Willie Hicks Public Sector CTO at Dynatrace, Lonye Ford CEO at ARLO Solutions, Jazmin Furtado Military Captain at Space Force, Rayvn Manuel, Senior Application Developer at NMAAHC and Tracy Bannon, Senior Principal / Software Architect & DevOps Strategic Advisor at MITRE talk about their predictions as we move into 2022. Episode Table of Contents[00:32] Willie Hicks’ 2022 Predictions for Government Technology [09:07] Lonye’s 2022 Predictions on the Acquisition Process [17:09] Jazmin’s 2022 Predictions for This Day and Age [21:31] Rayvn’s 2022 Predictions in Technology Will Never Be the Same [24:03] Tracy Bannon’s 2022 Predictions on New Technology Episode Links and Resources
Willie Hicks’ 2022 Predictions for Government TechnologyCarolyn: Today, we have a special episode to cover some topics of tomorrow. We asked a few of our guests their predictions for the U.S. Government technology in 2022. First, we have Willie Hicks, public sector CTO at Dynatrace. The AI arms race. Will you talk about that a little bit and talk about where you see the U.S.' position in the AI arms race? I know this ties into the massive, National Security Commission's on Artificial Intelligence final report. Willie: Yes. The term AI arms race is actually in academia and industry, it's a debated term. Are we in an arms race? Some people are more purists when they think of an arms race. You think about the Cold War, you think about past arms races. There are certain criteria around that. Like the money that's being spent on, if you think of a conventional type arms race, both sides. Or multiple sides are investing millions, billions of dollars on arms, on different weapon systems, on trying to keep up, or keeping a step ahead of the adversary. You could argue two things. One, that you don't see that kind of spending today in AI, at least from the government. You do see spending across the board, industry-wise, a higher increase on spending. But some would argue that just by that definition, it's not really an arms race. You can make the argument that AI itself is not a weapon. AI is a tool that could be used to make weapons more lethal, more effective, but in itself, AI is not a weapon. By the textbook, there's some debate if there is, but let's just set all that aside to answer your question. How to Stay AdvancedWillie: Leave out spending. There is definitely increased competition. If we want to say that there is a race from a technology standpoint, that's from industry and from the government, and that's underway today. We see that daily in the advances and the money that's being spent in AI. But also you see that in the national security report that you had mentioned. There are a lot of studies going on. How do we technologically stay advanced or ahead of our adversaries? Or, at least, we've got to make sure that we stay on top because at the end of the day, AI could be just like anything. AI could be used for many wonderful things. Like I was saying in medical applications, we saw this during COVID. People often think about, "Wow, the vaccines that we have, they came out really rapidly." Some people say not fast enough, but how long vaccines usually take? It came out very rapidly. A lot of that is due to some new techniques for the whole RNA type of vaccine. But also, there was a lot of AI. There was a lot of compute horsepower that went behind the analysis of a lot of these drugs, a lot of the virus, DNA strains and all that. There is a lot of good. But then, AI, this technology arms race, this competition could also be used by state actors. I even hesitate and sometimes I don't even like to think about it. It could make war more lethal, more kinetic. Let's just say it can make weapon systems run out of control. We're not going to the Skynet world where things just take over. But what you...
Senior application developer at the National Museum of African American History and Culture, and Army veteran Rayvn Manuel explains why her job is the best job. From serving our country as a soldier, to serving our history through dynamic storytelling, Rayvn has a passion for development that shows in her work. Listen in as Carolyn and Mark learn about the innovative technology behind the newest addition to the Smithsonian. Episode Table of Contents[01:46] The Purpose of Technology Is Huge [08:54] The Purpose of Technology Is Transformative Inclusion [17:49] They Take Cybersecurity and the Purpose of Technology Extremely [28:26] What I Wish the Purpose of Technology Can Do Episode Links and Resources
The Purpose of Technology Is HugeCarolyn: Today we have a guest who, as soon as I heard about this guest, I'm like, I want to talk to her. We've been trying for a little bit. Ravyn Manuel, welcome and thank you so much for being here. Ravyn: Thank you for having me here. This is actually exciting. Carolyn: https://www.linkedin.com/in/rayvnkm/ (Ravyn Manuel) is Senior Application Developer at Smithsonian Institute National Museum of African-American History and Culture. The NMAAHC is the 19th museum of the Smithsonian that has been open since 2016. Since opening, it has collected over 36,000 artifacts and gained nearly 100,000 members. It was awarded the People's Voice Webby Award in 2017. Mark: Can you describe your role in the context of a modern museum experience? What that means and what your role is at the museum? Carolyn: Why do we even need an application developer? Having been through it, I have to look back and I'm like, oh yes, the technology was huge. I didn't notice it at the time. Looking back on it, the technology is what really bathed me and immersed me a lot in the experience, especially as I moved up. Ravyn: That is awesome. It was so integrated, that you felt it was just part of that experience from what I was hired for. Our museum is not just the only one that has application developers. There are other museums because every museum and gallery has a website. We have to have somebody on staff to actually maintain the website. I don't work on the website, I actually have three hats. The Whole Purpose of SmithsonianRavyn: One, when there are smaller exhibits and they are interactive. Those things that you touch, which are going to be contactless, moving forward. Those are the things that I develop. Or I will work with a designer like the UI, UX designer then develop these interactives. These will bring home the message that the education department would like people to take away from an exhibit. The whole purpose of the Smithsonian itself is for education. When we make an exhibit, it isn't just to have you have a feeling. It's also for you to have an opinion for you to be immersed in that history. To walk away with some knowledge that you didn't know before, or to change your opinion about what you felt before. My role as an application developer is the R and D person. I look at spaces in our museum and I go, how can we get the message across better here? What would help make this, not only a fun engaging process but also help people learn? My particular interest is in accessibility. I’m always looking for ways to make our interactions or the museum visit accessible for people who may not be able to experience it with their eyes. For people who may not be able to hear the audio that's going on or have cognitive differences and how they actually interpret. That's what I do. I'll make a prototype, show it to my supervisor and say, what do you think about this? Most of the time, what I feel isn't going to go there. But it gives me a chance to say, “here's how we can use technology to actually assist people in their experience and to tell the story in an engaging way.” Interactive ExhibitsRavyn: A lot of our exhibits are interactive, some of them are really huge. So we hire out for that. We have...
Find out how the DoD's Kessel Run Office is digitalizing longtime manual processes through AI, taking the military to the next level of its digital transformation. Listen as Captain Jazmin Furtado talks about her experience with Kessel Run, and now Space Force, spreading a culture of data driven communication. Disclaimer The opinions expressed in this episode are those of Jazmin Furtado, our presenter, and do not necessarily reflect those of the Department of Defense, U.S. Air Force, or U.S. Space Force. Episode Table of Contents[00:40] Captain Jazmin Furtado of the US Space Force [11:19] The Important Contribution of Kessel Run [19:34] Learning From the Kessel Run Role Episode Links and Resources
Captain Jazmin Furtado of the US Space ForceCarolyn: Our guest this morning is https://www.linkedin.com/in/jazminfurtado/ (Captain Jazmin Furtado). She’s a military officer with the US Space Force and a data science and artificial intelligence leader. Before joining the Space Force, Jazmin worked as a military officer for the United States Air Force for over four years. The information expressed in this episode are those of Jazmin, our presenter. They do not necessarily reflect those of the Department of Defense, US Air Force, or US Space Force. So Jazmin, talk to us a little bit about your journey. How you started with the Air Force, what you did there and how you ended up with the US Space Force. Jazmin: I went to the Air Force Academy and graduated there in 2016. The reason I entered was because the challenge was very enticing to me. I like the idea of being challenged, not just academically, but also militarily and physically. There was a big focus on leadership that I think is pretty invaluable. After I graduated from there, I was able to go to MIT and continue with my degree in operations research. I got my master's there. Afterwards, I am a program manager in the military in the Air Force. That's a little bit of a different background than most program managers have in the military. A lot of times you'll have a management background or an economics background but I had more of a tech background. The military is trying to figure out what to do with me for a little bit. From a Traditional Program to Kessel RunJazmin: After a year of being in a more traditional program management role, I was pulled into Kessel Run. I was there for two years. So I was plopped into that organization just to do AI because I had some sort of background. One thing about this space and you see this in a lot of the organizations like Kessel Run, is that you just figure things out as you go. You're put there with a very vague job description and you just have to figure things out. So I went in there initially with my operations research cap on knowing stuff about data science, machine learning, and AI. I was like, this is great. Then really quickly realized, that's just the tip of the iceberg in terms of capabilities that are needed to make AI actually applied. You need to put in, invest in the other 90% of the iceberg, which is the data infrastructure and that architecture piece. I spent a lot of time, the two years I was at Kessel Run, building a data portfolio. It consists of data scientists, software developers, and data engineers to build the things needed for analytics. That was really the goal there. When the Space Force was created, I had the opportunity to move over. I put my name in the hat because I really liked the idea of space.I've always been inspired by space. I wanted to be an astronaut when I first graduated from high school. I've been very inspired by Star Trek. I have a little Star Trek thing I drew over my desk to remind me of where I came from, Star Trek. Kessel Run Is a Star Wars ThingJazmin: Kessel Run is a Star Wars thing, but I will forgive them for that. But now in the Space Force, I was very excited. It's just such an inspirational place to be. It's like The Next Frontier. And to be able to influence...
When it comes to industry and government technology, who is the glue that holds it all together? Lonye Ford joins Carolyn and Mark to give her insight on roles and responsibilities within the cybersecurity field. From Lonye's time at the U.S. Air Force help desk, to her current role of CEO at Arlo Solutions, she offers a unique perspective on cybersecurity career path. #CybersecurityAwarenessMonth Episode Table of Contents[01:02] The Ever-Evolving Landscape of a Secure Foundation [09:20] Understanding the Importance of a Secure Foundation [16:37] The Secure Foundation of the People [26:28] A Secure Foundation Is Void of Decision Fatigue Episode Links and Resources: Secure Foundation
The Ever-Evolving Landscape of a Secure FoundationCarolyn: Today, we have https://www.linkedin.com/in/lonyeford/ (Lonye Ford), CEO of Arlo Solutions. Lonye served for over 10 years in the U.S. Air Force and was named one of the top 50 in tech visionary at Intercom 2021. Since it's cybersecurity awareness month, we're super excited to talk to Lonye about her 20-year career in the cybersecurity field. Her experience on both the government and industry teams, and insights on the ever-evolving landscape of government cybersecurity. Lonye: Thank you Carolyn, for having me. Hi, Mark. When I heard the intro, I think I'm going to ask next time to move out with that 20-year experience. Makes me sound super old. Carolyn: You caught Mark and I discussing your age because we looked you up on LinkedIn, we're like, there's no way she's been doing this for 20 years. Lonye: I appreciate being invited, so thank you, I'm looking forward to this conversation. Carolyn: It's October. We have the best holiday of the year, which is Halloween, but also, super important, cybersecurity awareness month. We'd like to start out with you talking about your cybersecurity career journey. Why do you think it's such an important component of our lives? Lonye: Halloween is actually my favorite holiday as well. I have two little ones and so I get all into Halloween. Carolyn: What's your costume this year? Lonye: We're going to be the Space Jam family and I'm going to be Lola Bunny. Carolyn: We got Alice in Wonderland theme going on at my house, I will be the Cheshire cat. A Proud VeteranLonye: COVID messed Halloween up for me because, we get into it, as far as in our house and a holiday party. We open our bottom floor, so whenever the kids come through, we do a scary, little, haunted house and give. They'll have to come in and have scary movies playing. I missed that, I can't wait till we can open back up that way. My journey started in the Air Force, I am a very proud Air Force veteran. When I started at the Air Force, I started at the help desk. I like to tell people I started from the bottom, literally. No offense to help desk technicians, but working on a help desk gave me an amazing place to start. You get experience, visibility just across the gamut. I’m a service type of person, I like to service people. I am a person that really likes to help in every capacity, so I love the help desk when others hated it. Started at the help desk, then I did more network admin stuff, SOS admin, and network admin. I've been a cable dog, I've pulled cable through buildings. Then I went on to work for the program offices within the Air Force, doing things still in cybersecurity. I like to be very specific in what part of cyber I'm in, because cyber is such a huge domain. My focus is more on assessment and authorization of systems, so we started at a system called Disc Cap. It's the way that they used to do it back in the day, and then it matured into a program called Dye Cap. Now you hear people talk about RMF, Risk Management Framework, so that's what we're doing now.A Secure Foundation Focuses on Risk Assessment and AuthorizationLonye: So, that was my journey in the Air Force, I got out of the Air Force and I supported the government via contract. I was contracting...
AI capabilities range from providing on-the-ground safety for US soldiers, to removing the time delay of the Mars drone. But what misconceptions are there about Artificial Intelligence and Machine Learning? Join as Carolyn and Mark welcome Willie Hicks Public Sector CTO at Dynatrace on to debunk myths and confirm beliefs about the power of AI. Episode Table of Contents[00:41] Willie Unpacks What AI Is [09:22] What AI Is in the Medical Field [16:44] When AI Starts to Become Practical [23:38] Staying in the Vein of What AI Is Episode Links and Resources
Willie Unpacks What AI IsCarolyn: Today, we get to talk to https://www.linkedin.com/in/williehicksee/ (Willie Hicks), CTO of Dynatrace public sector, on the very hot topic of artificial intelligence. Willie is going to unpack what AI really is and isn't. Apparently, I will not be having an in home version of Star Trek's Data to do light chores anytime soon, spoiler alert. But we also get into the nuances of AI versus ML, how the government is developing and using AI. Willie is going to tackle the recent National Security Commission on artificial intelligence final reports. He's going to share his biggest takeaways from the 800-page report. That's going to save us from actually having to read anything. Finally, we're going to discuss how he has seen the industry and the government partner in AI, the wins, the losses, and how we can do better. I want to go straight to our topic of the day and just have you level set us on AI. Define what we're talking about here. Willie: When I think about and talk to people about AI, often I get the question, "What is AI?" We can talk about it from the strict definition of AI, if you wanted me to rattle off the Oxford English dictionary version of it. It is a theory in the development of computer systems that can perform tasks. These are normal tasks that humans would do, so it's artificial intelligence. But in reality, AI is more than that definition.A Task-Oriented Type of AIWillie: Most people have heard or directly experienced AI in one fashion or another, and they don't even realize it. Every time you call into Amazon or some company to chat about a product that didn't arrive, or you're calling to pay a bill, you'll get an automated chatbot or an automated service. A lot of times, it asks you to speak to it, in a natural language. It is processing that information and giving you back some type of feedback. That's a very task-oriented type AI that you're interacting with. We actually interact with AI all the time, and that's growing day in and day out. If you've got devices, smart speakers in your home, you're interacting with a type of AI. Or if you are using a lot of systems today on computers that are trying to keep you from gaming the system, like they're getting a lot more complex. The CAPTCHAs and things like that are getting more complex to try to understand when other bots are trying to get into the system. All of these types of systems are some types of AI. Now, we'll get into this later. There are different types of AI. There's what you were just talking about, Data. I would love to have Data in my house, or Jarvis. Not Skynet, but one of those AIs that has a more general purpose that doesn't exist. Those types of AI don't exist today, except in science fiction. Carolyn: At all? Willie: Not really, at least not that we know of. If they're in a secret lab somewhere, we don't know about it. How People Misuse What AI IsMark: They probably do at Bill Gates' house. It seems like the use of the term AI is all over the place. Everybody uses it pretty ubiquitously, but it means so many different things based on the description that you just laid out. Literally, the spectrum is massive. But people use the term, it sounds like artificial intelligence to mean just about any of that. Willie: Also, they misuse terms a lot of times too. Some people say machine learning is AI. A lot of sci-fi and a lot of what we see on TV...
Building a culture starts with communication and a willingness to change. Tracy Bannon Senior Principal / Software Architect & DevOps Strategic Advisor at MITRE and ambassador for the DevOps Institute talks with Carolyn and Mark about her recent event #StraightTalk4Gov hosted by the DevOps Institute. Listen as Tracy outlines ways to create a culture of comfortability in the government technology workspace. Episode Table of Contents[01:11] A Straight Talk Featuring a Culture Built on Moxie [06:34] Acquisition in Government Is a Culture Built on Moxie [13:34] A Collaboration Between the Industry and the Government [20:17] A Common Theme in a Culture Built on Moxie [28:14] Sisyphus Moments Episode Links and Resources
A Straight Talk Featuring a Culture Built on MoxieCarolyn: Our guest today, Tracy, is a returning guest. She's senior principal, software architect, and DevOps strategic advisor at MITRE. Tracy Bannon is just an all-around badass. She’s an ambassador for the DevOps Institute. We had her a few weeks ago, we talked a little bit about a conference that was her brainchild. She facilitated it. https://www.continuouslearningevents.com/ (Straight Talk), that's what we want to talk about today. Which, by the way, the conference is still on demand. You can rewatch these sessions that we're about to talk about. Tell us how it went overall, and what was some feedback that you've been getting from attendees? Tracy: Overall, it went very well. We didn't expect the spike in folks who registered for it. Even during special sessions, when folks saw the different sessions happening. We're getting real-time registrations happening and people joining. There's such a thirst for going beyond the technology. That's what this was all about, taking a step past the technology. Overall, it went very well. The feedback that we're getting has been, I want more, can I meet with X, Y, Z, I want to talk to Brian directly. So, folks who have done the different sessions, where they want to talk to Don, they want to meet up. They want to keep going, which is exactly what we wanted to have happened. We wanted to start those organic connections with people. Mark: What made Straight Talk for government different than other events that you've participated in? A Shiny Quarter Organization with A Culture Built on MoxieTracy: Let me track it back to why I was so passionate to get this going in the first place. Every time I deal with a government sponsor, with the government client, they'll often say, I need to do some DevOps. I need to be like this group over here. It's almost always, exclusively, pointing at something in the commercial area that's a shiny quarter organization, I want to be like Netflix. Well, do you really need to be like Netflix? What's important about that? But there's also a focus on the technical pieces of it. I can go and get an excellent Udemy course, I can go to Cloud Guru. And I can get really awesome technical advice on how to accomplish the building of the pipeline. But what's missing is the front matter, the architecture, the engineering, the people, the process, and culture. Because I always say, people, process, tech, culture. The underpinnings of this was to pivot away from the technical pieces. Start to build out of a community that is really focused on opening the doors with the government and with industry and with academia. We've got to make sure that everybody is on a level set. What are the real problems, what are the challenges? How is it similar? How's the government similar to industry? How is it different? Because in understanding the differences and in opening the door up and letting industry know, letting academia know, they're going to help us solve those problems that much more. We're going to build this cohesive set of examples. Real examples, that have to do with the government, instead of, I want to be just like Netflix. I want to be like Carnival Cruise, I want to be like...
Mary Hagy went from serving in the U.S. Army, to showing our future generations that the sky is not the limit. Carolyn is joined by guest host Eric Monterastelli to learn about Moon Mark's mission and have imagination personified in Mary Hagy. Episode Table of Contents[00:45] I Want to Be Mary Hagy [08:37] Where Humans Have Never Been [17:55] One of the Things Mary Hagy Is Proudest Of [28:11] The Leap That Mary Hagy Hopes For Episode Links and Resources
I Want to Be Mary HagyCarolyn: I have Eric Monterastelli as my co-host. Thanks for being here. You actually introduced me to today's guest, https://www.linkedin.com/in/maryhagy/ (Mary Hagy). I listened to your podcast. You interviewed her on Break/Fix. Honestly, I'm telling you right now, I want to be Mary Hagy. She's cool. Like she has one of the coolest jobs ever. https://www.linkedin.com/in/maryhagy/ (Mary Hagy) is a veteran of the U.S. Army. She is a creative entrepreneur, storyteller, and civic enthusiast. She conceives, capitalizes, and executes profitable projects that have inspirational, entertainment, and educational impact across broad audiences. Her current project is Moon Mark. What we're here to talk about today will capture global audiences. With the stories of six teams of high school explorers who compete to become the final two that will design, build, land, and race to autonomous vehicles on the moon. Let me just repeat that. She's got a project that has six teams of high school kids who are going to compete. To become two teams of finalists that will design, build, land, and race two autonomous vehicles on the moon. They'll communicate peer-to-peer with young people who will become explorers in space and on earth. And open a talent pipeline for the workforce of the future. Welcome, https://www.linkedin.com/in/maryhagy/ (Mary Hagy), CEO of Moon Mark. Mary: Thanks so much, Carolyn. I really appreciate that introduction. Carolyn: Let's start with, what is Moon Mark? Can you give us an overview? Mary: What you just described is very much a capsulation, if that's a word of what we're doing. When you think about Moon Mark, the idea really came from the notion that humans right now are on the precipice of commercialization of space. The DNA of Moon MarkMary: Yes, governments will be involved. They have been involved for 60 years. But also, the way that the opportunity for really getting to whether it's the moon or an asteroid or Mars or Pluto or whatever, we're on that precipice. It's the commercial industries that are going to get us there. We came up with Moon Mark and the DNA of Moon Mark remains that of the high school kids that happen to be that age. Human beings that happen to be that age, wherever they are on the face of the earth, they’re going to accept stewardship of space exploration. There are aspects to space exploration that are, I'm going to call them mistakes and paradigms. The space industry has really been all about the agencies of countries. Whether it's NASA, the Canadian Space Industry, the European Space Industry, whatever agency it is. What has occurred is that young people, there's no real access for them to be able to understand that they can be a part of this. Until now, it's been very much about, "If you want to go to space, you have to be an astronaut. And if you have to be an astronaut, you have to go through this excruciating process with very high attrition and likely you won't make it," and all of that stuff. That's just not true anymore, that's the good news. It's not true. With Moon Mark, at our DNA level, we are creating experiences and opportunities for young people. For them to understand that the game has changed, that they can have access to space exploration. It doesn't have to be one astronaut out of 30,000 applicants.Exploration in GeneralMary: There are all kinds of ways to reach their potential if they're interested in space exploration, or exploration in general. That's kind of what we're really...
On this crossover episode Carolyn and Mark learn about the power of racing. Eric Monterastelli, Public Sector SE at Dynatrace and host of Break/Fix: The Gran Touring Motorsports Podcast, joins the Tech Transforms team to talk about where the rubber meets the road in government technology. Episode Table of Contents[00:51] Across the Side of Racing [06:59] All Racing Cars Have Self-Correcting Computers [14:16] From the Performance Racing Side [20:09] The Rule of Three in Racing [27:00] International Racing of Champions [33:01] Unlimited Funds To Fill a Racing Car Garage Episode Links and Resources
Across the Side of RacingMark: We have invited our friend, https://www.linkedin.com/in/eric-monterastelli-8197b246/ (Eric Monterastelli) to join us on a crossover episode for this morning's Tech Transforms. Carolyn: His podcast is Break Fix. Thanks for being here, Eric, and we're super excited to talk to you today. Eric: That's right, folks. It's not uncommon to see IT branding plastered across the side of race cars in many motor sports disciplines. Names like AWS, CrowdStrike, and SailPoint immediately come to mind. But for application performance monitoring and artificial intelligence, the relationship between technology and racing goes far beyond stickers and sponsorship dollars. As Carolyn pointed out, this is a crossover episode between Break Fix and Tech Transforms. I'd like to personally thank Mark and Carolyn for having us on their show to explore this idea. Carolyn: It's a little bit geeked out for me, so let's just get really basic. Talk about cars and racing first. Tell me how you got into cars and racing in general. Eric: I'll keep it brief because I think that could be a whole episode into itself. Gran Touring Motorsports was founded in late 2013, officially 2014. Our mantra is to continue to spread motorsports enthusiasm. The idea is that people understand that there's multiple disciplines to racing. Racing is a big part of our world, whether you believe it or not. The chemistry, the science, the technology, the engineering that trickles down into your daily car is incredible. It all stems from manufacturers using the racetrack as their test center. Think about it from that perspective. Here at GTM, we want to continue to spread that enthusiasm because if we don't, racing will dry up.Tied Into the Racing CommunityEric: That advancement in technology ceases to exist. We've been around now for almost eight years. We have our own podcast, Break Fix, we talk about all sorts of different things. Ranging from these super technical episodes, all the way up to advice episodes. Like, what should I buy, and things of that nature. Personally, I got into cars by way of genetics. From my grandfather to my dad, and to me. Hopefully I get to pass it onto my daughters along the way. We've been tied into the racing community for a very long time. I’ve been a high-performance driving instructor for almost a decade. Before autocrossing, I was a cart racer nationally. It's unfortunately in the blood. What I find most interesting about it is that there's a huge intersection between the automotive and the IT world. I also followed in my father's footsteps, who was a mainframe programmer. I’ve had the IT side, and also the racing side. As a younger racer, I was involved in things like timing and scoring. I went to work for British Aerospace, where I tried desperately to get in on their helicopter division. Because I was actually working on engine management systems at another company. So, data, technology, IT, racing, it's all very intertwined. As I grew more into ProAm racing, time trials, and other disciplines, I started to realize how valuable the data that we collect. Not just from the cars, from the track, and from the motors and all this stuff related to what I was doing in the SIM and threat intelligence world and also in the APM and artificial intelligence space. There's this huge crossover there. I want to be...
The U.S. Government is leveraging technology to improve and accelerate the citizen experience. Listen as Carolyn and Mark learn more about the ecosystem of the mission from Troy Schneider, Editor-in-Chief of FCW and General manager of GCN. Episode Table of Contents[01:35] The Oldest and Most Influential Publications United by the Mission [11:07] The Physicians and the Patients Are United by the Mission [18:43] The Industry and the Government Are United by the Mission [26:17] Not as Sexy as Machine Learning Episode Links and Resources
The Oldest and Most Influential Publications United by the MissionCarolyn: Today's guest is Troy Schneider, Editor-in-Chief at Federal Computer Week, FCW, and Government Computer News, GCN. Troy began his career in print journalism, and has written for a wide range of publications, including the New York Times, Washington Post, Slate, and Political. Troy, I would love to hear about your professional career. How did you become the Editor-in-Chief at FCW and GCN, two of the oldest and most influential publications in the public sector IT? You've had this long career. I'm really interested to know how you got into the government side of things, especially. Troy: I started in what most people think of as more of the traditional Washington journalism, more of the politics, and the campaign, the lobbying side of things. I worked for National Journal almost straight out of college, and was there when it was a weekly print magazine, not much else, and just starting to tiptoe into the digital space. I’ve spent about a decade, a little more than that, with different parts of National Journal, which grew into Atlantic Media Company over the years. I was lucky enough to be there at the creation of the digital business, moving to publishing and even online publishing before websites were the settled-on channel. Covered Congress, covered campaigns, all of that sort of work, and then made a pivot to a think tank. I’ve worked for A New America Foundation, which is now called New America, and went there to help them with their publishing efforts. The Policy SideTroy: I really liked the ideas and the policy side of things. It’s a very media-centric organization, where they knew they couldn't just be contributing op-ads to places, but really needed to have their own publishing channels. I did that for seven years or so, and got a call about a job with FCW, to come on as the number two editor. If everyone liked each other, to move into the senior role. It’s a little bit of a daunting transition to focus on the true government side. My focus for the first part of my career had been about all the stuff that happens to figure out what goes into the budget. To figure out what goes into the laws, to figure out who's going to be elected to those positions. In that politic-centric view, "What happened after the bill was signed?" The agencies got it. That’s just implementation details. Then you dive in, you realize just how big that set of details is, and just how important the operations are. FCW at the time, they wanted to be less about computers, because IT is so much more than that now. More about the policy, the business, and the leadership side. I’ve done a lot of work with emerging technology during my time at New America. We’ve crept a lot closer than we would have been when I was at National Journal. We would've seen each other in two completely different spaces, but there was enough overlap that it was interesting to both parties. I came in, in 2012, as the Executive Editor of STW. Stepped into the Editor role about a year and a half later, then took the similar role at GCN a couple of years after that. We've just been rolling ever since. What Agencies Have Done to Be United by the ProcessCarolyn: Early on, you had a government beat, but there was a transition for you. Troy: There was. I knew the government, I knew Congress, I knew the budget process, I knew nothing about things like FedRAMP or...
Tracy Bannon Senior Principal / Software Architect & DevOps Strategic Advisor at MITRE and ambassador for the DevOps Institute talks through the original DevOps timeline. Join as Carolyn and guest host Steve Mazzuca find out what happens when Dev fraternizes with Ops. Episode Table of Contents[00:48] DevOps Strategic Advisor and Ambassador [10:34] Respected DevOps [18:35] The DevOps Pipeline [24:05] DevOps Institute Episode Links and Resources
DevOps Strategic Advisor and AmbassadorCarolyn: Today, I have Steve Mazucca or The Mas as I like to call him, co-hosting with me. It's always fun to have a conversation with you Steve. The hard part is going to be getting you to be quiet, so we can get our guest Tracy Bannon. He is Senior Principal, Software Architect and DevOps Strategic Advisor at MITRE, as well as an ambassador for the DevOps Institute. So welcome Tracy. Tracy: I'm thrilled to be here today. It's always fun to have these conversations. Carolyn: You are a striking woman with pink hair and you were in development, which makes you in my mind, kind of a unicorn. I would really love to hear your story. Tracy: I'll start with the pink hair and go backwards from there. I've had little bits of color in my hair for years. My mom was an art teacher. My dad's more on the math and the sciences side of it. I kind of have that left brain, right brain, need to express myself. Over probably the last two or three years, as I've been doing more remote work, I was having more fun with the pink and decided that it's the pandemic. Let's stretch things a little bit more. I'm just loving it. So that's a little bit about that piece of it. But as for me being a woman in technology, I actually like to come at it in reverse. To say that I'm a real technologist and not say I'm a woman technologist. It matters, but it doesn't matter. What's important to me, is I've always been so interested in tech.A Woman DeveloperTracy: Someone asked me, "When was the first time you realized that you liked computers and that you were into computers?" It's a long story, but I'll make it very short. I can remember building a computer out of a box and cutting and putting mag tapes on the outside. Yes, I just told you how old I was. And arguing with my brother on who got to sit inside it and be the brains. So I remember being real and I couldn't read yet. I remember that very vividly. It goes a long way back. Carolyn: Did you end up being the brains? Tracy: Yes I did. I happened to be a little bit bigger than him. Even though he's two years older, I happened to have the weight advantage. As for being a woman developer, I've always been in tech. I never thought anything about the makeup of the team. That’s because I always tagged around with my older brother and his buddies. I considered myself one of the guys. One of the gang would be a better way to put it. I realized about midway through my career that there was a little bit of uniqueness to it. As I would look around the room, I would be the only woman on the team. Now, occasionally there would be fantastic women involved, more on the database side of things, who had grown into that. Very few from a development perspective. We did see some spikes in industry, we saw that. But we're seeing that decline recently. But across my career, I tend to come at it that I'm a technologist. If you need to give me an adjective, make it real, instead of woman. But that's a little bit about me. A Technologist at DevOps Who Happens to Be a WomanCarolyn: I love that you want to take the emphasis off women. That you're a technologist, you're a developer and you happen to be a woman. You're often the only woman in the room. I'm often the only woman in the room and it will be a room of many people. But I do love that you've always just thought of yourself this way. What was your first development? Well, what was your first job actually? Tracy: First paying job, was actually a lifeguard, but we won't go that...
What matters most when it comes to providing the better experiences for our citizens? Listen as Jonathan Alboum of ServiceNow outlines the importance of preventing information from getting lost in the sea of data. Episode Table of Contents[00:45] Moving Fully Into Better Experiences [09:15] Providing Better Experiences More Effectively [14:41] A Control Tower Approach Episode Links and Resources
Moving Fully Into Better ExperiencesCarolyn: We're excited to have Jonathan Alboum, who is the federal CTO of ServiceNow. He was formerly the CIO of the U.S. Department of Agriculture before moving fully into the service industry in 2019. I don't like that term, "moving fully into the service industry". When I read through your bio, I feel like you've been in the service industry your whole career. Jonathan: Good point, I began my career after college. I went to UVA, same place that Mark went to school, but he went a few years before I did. Mark: You had to point that out Jonathan, thank you. Jonathan: He went when it was really, really fun. I went when it was just fun. But you know, when I exited college with a systems engineering degree, I joined a professional services firm. I worked at Pricewaterhouse and I learned management consulting, and we were doing services. We were implementing systems and different technologies for customers. Eventually, I moved to a smaller company. I was working on the same kinds of projects, doing professional services, helping organizations do modernization. We weren't focused on this big grandiose term of IT modernization or digital transformation, which were the same kinds of things we were doing. We wanted people to have better access to data and systems so things could happen more efficiently.It's the same kinds of things we're doing today, even if we use different words. I was in a service role before the government. When I joined the government at the food and nutrition service part of USDA versus the deputy CIO and then the CIO for that agency. Providing a Strong Service and Better ExperiencesJonathan: We're a service provider to the programs at the food and nutrition service. So if the office of information technology at food and nutrition that I was responsible for wasn't providing a strong service, the programs would find another way to get their job done. We could be shut out of that conversation. That's a terrible place for a CIO to be at. Cut out of the technology or the core business processes or the budget. So I always had a strong focus on service and that reality continued through my career. As I moved to general services administration, or back to the department of agriculture, to be the CIO for the entirety of the department, you have to be able to provide a service. I eventually exited government and found my way to ServiceNow. I’d say the lessons I learned along the way are in terms of what it takes to provide a service that people want to use, and that they will partner with you on. Those things really informed the way I go about doing my job at ServiceNow. ServiceNow, it's a technology provider that supports this idea of service management. It's not customer relationship management. We have tools for that, but you have customers, you want to provide them a service. Well, you have to think about the end to end workflow. How does the person interact with the system and what are they trying to get out of it? You think about it comprehensively. I feel like I'm well positioned to do that based on these other roles that I've had. I've either been the creator of a service or the provider of the service. Now I can really think about it in a holistic manner.A Pioneer of Digital TransformationCarolyn: I like what you said about digital transformation. We didn't call it that at the beginning of your career, but really you're a pioneer of digital transformation. So not to call you old. You've really built your career, figuring out how to make things better and faster...
Listen in as Carolyn and Willie find out the true power of data. Sean Applegate, CTO of SwishData, explains how data can be utilized across an entire mission to empower the warfighter. Episode Table of Contents[01:00] Smart People With Great Ideas [07:29] Your Data Can Work for You up to Some Extent [14:15] Securing the Application So Your Data Can Work for You [22:08] Eight Guiding Principles [28:03] Applicability of AI Episode Links and Resources
Smart People With Great IdeasCarolyn: I'm Carolyn Ford and this week, my guest co-host is Willie Hicks, public sector CTO at Dynatrace. I'm super excited that we get to talk to Sean Applegate, CTO of https://swishdata.com/2021/05/qlik-insights/ (SwishData). Sean: I'm excited to be here, it should be a blast. Carolyn: Honestly, this is the best part of my week. This is the best part of what I do. I love talking to really smart people with great ideas about how technology can better our lives and how the government specifically can do that. So, Sean, you've written a lot of stuff. You're a pretty prolific writer, blogs articles, and a recent blog that I saw, I'm not going to lie, it kind of broke my head. It was a lot of technical stuff, but there were a couple of things in it that were kind of gotchas for me. I'd love for you to drill down into a little bit. At the beginning of your blog, you write, the name of the blog is Optimizing Mission Outcomes with Intelligent Insights. In one of the beginning paragraphs, you say transforming the DoD to a data-centric organization requires that data is visible, accessible, understandable, linked, trustworthy, interoperable, and secure. So I would love for you to dive into that. Sean: I would say the one thing that DoD is noticing, and you'll see this with some of their DevSecOps reference architectures is it requires culture change. Whether that's the business leaders or the mission leaders, the contractors, the developers, the people running infrastructure, or delivering a service. Your Data Can Work For You But It Has To Be AccessibleSean: They've identified that the data has to be accessible across all of those different parts of the mission. That getting that data collectively together is extremely important. It's valuable for both mission velocity and a competitive advantage around the world, whether that's DoD or civilian agencies, we see that as well. So data is critical, be able to find it first.Carolyn: If you've got the data, what do you mean it's not accessible? Do you mean like across agencies or across groups? Sean: A lot of it is making it not just within your command, but outside the command. So it's trusted. For example, I'm using an application performance management issue. I'm delivering an application, I have lots of stuff on the application. I may not have a lot of stuff on the user community, or maybe somebody wants to analyze the success of my mission. That mission can be measured, lots of different ways. How do I merge those data points together? So I can draw, make a business decision from that, that's very impactful. That may be something at a very strategic echelon such as the Pentagon. Or maybe very tactical, down at the tip of the sphere, the unit deployed overseas. I need to make a decision right this minute. How do we do that? That's very complex. Carolyn: One of the things that gets bounced around a lot these days, you guys have both talked about AIOps. Using AIOps to get us to this place, all of these things that you list. Can you talk about how AI ops enables this? Your Data Can Work for You Through Problem Solving Complex ThingsSean: On the AIOps side, what we find is, it allows our human workers to better focus on problem-solving and the complex things you can easily do with the computer. The AI piece allows us to typically make linkage. If you think of linked data, it's the dependencies between data points or systems. In many cases, when we look at application performance management, a
Risk taking is unavoidable when it comes to modernization. Best selling author and retired four-star U.S. general Stan McChrystal outlines 10 control factors to help citizens and agencies alike take smarter risks. Carolyn and Mark also get some early insight on Stan's upcoming book Risk: A User's Guide. Episode Table of Contents[01:44] Stan McChrystal of the Team of Teams [10:54] A Story of a Defensive System by Stan McChrystal [18:26] Stan McChrystal Talks About Inertia [25:57] Why Stan McChrystal Doesn’t Want to Worry About External Threats [35:40] Artificial Intelligence Based Episode Links and Resources
Stan McChrystal of the Team of TeamsCarolyn: We are joined this morning by retired four-star U.S Army General Stanley McChrystal. We've had the pleasure of talking to General McChrystal on a few occasions. Good morning, General McChrystal. Stan: Call me Stan, and it's an honor to be with you again. Carolyn: Let me give our audience for those that have been living under a rock, just a few more of your credentials. So Stan is a former commander of the U.S and International Security Assistance Forces, ISAF Afghanistan. He’s the former commander of the nation's premier military counter-terrorism force, JSOC. He is best known for developing and implementing a comprehensive counter-insurgency strategy in Afghanistan. For creating a cohesive counter-terrorism organization that revolutionized the inter-agency operating culture. Is it fair to say, Stan, that’s the basis for your book https://www.amazon.com/Team-Teams-Rules-Engagement-Complex/dp/1591847486/ref=pd_sbs_3/142-9463856-7907441?pd_rd_w=vGUvO&pf_rd_p=0f56f70f-21e6-4d11-bb4a-bcdb928a3c5a&pf_rd_r=M3XJVJ4F55G3HSFFJK9Q&pd_rd_r=591fbfaa-e089-4f6e-9adf-3fa401273d69&pd_rd_wg=G2DSo&pd_rd_i=1591847486&psc=1 (Team of Teams)? Stan: It was certainly the foundation of it, and then our study beyond that. Carolyn: Honestly, https://www.amazon.com/Team-Teams-Rules-Engagement-Complex/dp/1591847486/ref=pd_sbs_3/142-9463856-7907441?pd_rd_w=vGUvO&pf_rd_p=0f56f70f-21e6-4d11-bb4a-bcdb928a3c5a&pf_rd_r=M3XJVJ4F55G3HSFFJK9Q&pd_rd_r=591fbfaa-e089-4f6e-9adf-3fa401273d69&pd_rd_wg=G2DSo&pd_rd_i=1591847486&psc=1 (Team of Teams), just a little plug here, is the best book on leadership that I have read. If you haven't read that one, do that. But we're here to talk about a new book that will be out this October that is also sure to be a bestseller. Mark and I got to have a sneak peek. We got to read an early copy of the manuscript. We're here to talk about your new book, https://www.amazon.com/Risk-Users-Guide-Stanley-McChrystal/dp/0593192206 (Risk: A User's Guide). We’d like you to talk to us a bit about the 10 risk control factors, and the four measures that are the foundation for your new book Risk. Calculating RisksStan: We decided to take on Risk as a subject because through my career, there had been processes to follow. Calculating risk and acting on that too, to be able to measure the threats or risks to your organization. But it never connected with how we actually did it. Now, certainly there are some financial firms that use financial models that theoretically do this. But if you look at so many things in our lives, there's one way we talk about risk. Then there's another way we actually respond to it. I wanted to understand what the disconnect was. Of course, that had been my experience as well. In most cases in my career, we had done checklists or matrices, and calculations to come out with a risk score. But the reality was most of our reaction was intuitive. And so we decided to study risk. What we came away with was the idea that each organization and individual actually, but organizations particularly have something which I'll call a risk immune system. It's a system consisting of 10 factors, such as communication, diversity, bias, timing. Those things interact together to...
When you have billions of data dependencies, and one goes amiss, how do you figure out where the issue is? Listen as Mark and Carolyn are joined by Andrey Zhuk of CTG Federal to discover how artificial intelligence is opening new doors for data security and recovery. Episode Table of Contents[00:46] The Road to AIOps [09:07] Overarching Umbrella [17:25] Knowing the Unknown From Poorly Written Codes [27:55] Knowing the Unknown in the World of Tech
The Road to AIOpsCarolyn: I'm excited to introduce today's guest, , principal solutions architect at https://www.ctgfederal.com/ (CTG) and author of several eBooks. Today, we're going to talk about one of his latest eBooks, https://info.dynatrace.com/noram_federal_wp_optimizing_mission_critical_apps_16988_registration.html?_ga=2.40639266.1295383075.1623441146-1185377699.1610480138&_gac=1.190116313.1621959090.Cj0KCQjwwLKFBhDPARIsAPzPi-ILvMsu0SYErYD7wdHad-bxS0F4Xr-4OOhB-kVQdagr6olqUErgbTwaAi5_EALw_wcB (Software Intelligence for the Federal Government: The Road to AIOps). It focuses on cloud development migration in the federal government. Carolyn: Let's start with the easy stuff. Tell us your story. What do you do? Where are you talking to us from? How did you get to where you are now? Andrey: Sure. My background is actually electrical engineering. I used to design satellite systems and the networks that go along with them for the Department of Defense. From that, I went to the side of sales. I was actually selling a lot of Palo Alto products and some optimization solutions. From there, I transitioned to the world of cloud. That's kind of where I got into the whole application performance management space. I was at a startup called Skyhigh Networks. They were one of the early cloud X security brokers. We were dealing with cloud apps and security cloud apps for government customers. That's where I had the experience of dealing with the federal government workers, trying to modernize their applications. Then Skyhigh Networks got bought by McAfee. I was a solutions architect for cloud technologies with McAfee for a year or so. Then I moved on to https://www.ctgfederal.com/ (CTG Federal) to take on a principal architect position to help build their cybersecurity business with a little bit of the APM sprinkled in. We had a Dynatrace partner. Knowing the Unknown About Satellite StuffCarolyn: Yes, we wish we could say that right upfront that we are partners. But before we get into it, I got to go back to the satellite stuff. How does that compare to what you're doing now, how long did you do that? Andrey: Wow, probably six years, but ultimately everybody needs Facebook and satellite platforms get outdated like once every 10 years. So it's all about software. Carolyn: Oh, so this is a lot faster for you then like, quicker pace. Andrey: Yes. Mark: The world that you're playing in now, Andrey, is it more high-level conceptual as opposed to the engineering work that you might have done, working on satellites? Andrey: So it's interesting. The world is more about software now than it ever was before. Just to give you an example, YouTube platform. They're the one that when it got shut down by the Soviets, that is still in operation. So that airborne frames still exist, but the internals get modernized. The internals get modernized with new circuits, new equipment, but the software on those circuits gets changed quite frequently.Mark: We truly are living in a software world, are we? Andrey: Yes. Which makes application performance management and software intelligence that much more important. Carolyn: It gets us right to one of the first things we want to talk to you about is the title of this eBook that you wrote,...