CyberCast offers a different and thoughtful perspective on the cybersecurity issues facing industry and government today. 213656
The new year began with a new White House executive order on strengthening and promoting innovation in cybersecurity, building on previous efforts, like the National Cybersecurity Strategy, to enhance the security of the nation’s digital infrastructure.
Looking into 2025, Deputy Assistant Director of FBI’s Cyber Division Cynthia Kaiser said her division plans to leverage emerging technology like artificial intelligence to thwart cyber adversaries and better detect threats around critical infrastructure, while aligning with federal policies and directives. Kaiser’s division is also advancing patch management and other AI-enabled technology to boost resiliency.
Kaiser highlighted some of the top exploited vulnerabilities FBI has seen over the recent years, the agency's special partnership with CISA as well as the importance of the “Secure by Design” model to counter cyber attacks.
CyberCast, along with GovCast and HealthCast, will now be published in the GovCIO Media & Research Podcasts feed. Subscribe and listen today on the podcast platform of your choice.
The Department of Education is kicking off the second phase of its zero trust strategy by focusing on security orchestration and automation response to stay ahead of the evolving threat landscape.
Education CISO Steven Hernandez discusses how the agency is tailoring its cyber tools and technologies by automating manual processes and leveraging identity, access and credential management (ICAM) solutions to improve the user experience and further zero trust.
Federal agencies are modernizing their cybersecurity strategies as threats continue to evolve. Faced with the National Cybersecurity Strategy, zero-trust implementation and recruiting a cyber workforce, agencies are primed for a busy 2024 in cyber and IT.
Managing Editor Ross Gianfortune and Staff Writer/Researchers Nikki Henderson Whitfield and Jordan McDonald break down some of the biggest developments ahead for federal IT and cyber leaders.
Featured episodes include:
This episode is sponsored by Zscaler.
The White House released its National Cybersecurity Strategy in March and is ending the year with the first permanent National Cyber Director in nearly a year. On CyberCast, we covered it all.
Take a listen back to some of the highlighted interviews with federal IT leaders, officials and experts this year as CyberCast traveled to Hawaii, California and Maryland. Our team interviewed leaders from agencies including the Federal Emergency Management Agency, the Cybersecurity Infrastructure Security Agency, the Department of Veterans Affairs and the Environmental Protection Agency.
On this year-end episode of CyberCast, Managing Editor Ross Gianfortune, and Staff Writer/Researchers Jayla Whitfield and Jordan McDonald reflect on the most memorable episodes and cybersecurity topics of 2023.
Featured episodes include:
This episode we're diving into zero trust at the Defense Department. Specifically, how that is playing out for the Indo-Pacific region.
We recently had the opportunity to connect with several leaders at the AFCEA TechNet Indo-Pacific conference in Honolulu where they shared with us how they're thinking about this quickly changing landscape and what it means for cybersecurity. This includes an update on DOD's review of submitted zero trust implementation plans, and also a peek at some of those plans at the Air Force and Indopacom.
Featured interviews include:
Randy Resnick, Director, Zero Trust Portfolio Management Office, DOD. https://governmentciomedia.com/dod-zero-trust-chief-were-start-multi-phased-journey
Justin Stolpman, Director, Zero Trust Functional Management Office, Air Force. https://www.governmentciomedia.com/air-force-eyes-next-gen-gateways-amid-zero-trust-plan
Paul Nicholson, Deputy CIO and Executive Director of Coalition Communications, Indopacom. https://governmentciomedia.com/look-zero-trust-theater-indopacom
FEMA is developing prototypes for AI use cases in cybersecurity implementation amid a White House artificial intelligence executive order that directs agencies to establish and maintain standards for safety and security of the technology.
FEMA CISO Gregory Edwards discusses how the rapid pace of AI innovation is spurring partnerships across federal agencies to work together to leverage best practices for their missions.
He also provides an update on the agency’s zero trust journey, how his office is anticipating future of cybersecurity needs and how he’s balancing that with modernization initiatives.
The Environmental Protection Agency is honing in on multiple pillars from the National Cybersecurity Strategy to secure critical infrastructure at its water and waste-water operations.
The agency deems water security to be national security and is an area that needs critical attention. Efforts are underway to increase cyber awareness in the water sector and ensure systems remain resilient.
EPA cybersecurity leaders Douglas Vick and David Travers break down what the threat is to the nation's water systems and how two programs are helping mitigate risks and ensure water services operate without disruption. Additionally, the officials highlight some of the new tools that are helping the agency boost overall cyber resiliency across its workforce.
The U.S. Digital Corps is bringing innovation to government by placing early-career technologists at agencies. Operated by the General Services Administration (GSA) Technology Transformation Services (TTS), the Corps’ fellowship program gives individuals the chance to work on critical issues at the intersection of technology and public service.
Digital Corps fellow Brittney Wright is on the cybersecurity track, assigned to the National Institutes of Health (NIH). Wright is passionate about cybersecurity and said she wants to provide hope to others that are looking to pivot into the field. She discussed her journey to cybersecurity and the ongoing talent gap that the government faces.
Bad actors accessing sensitive government data through vulnerable weak points is an ongoing concern for federal IT officials, who are making securing data a top priority amid digital modernization. Challenges in data security arise when you need to balance it with efficient data access while keeping threat actors out.
In this episode, we break down some of the best practices in this area and feature insights from federal leaders at the departments of Veterans Affairs and Defense.
Cited officials include:
Army Cyber Command’s Lt. Gen. Maria Barrett (https://governmentciomedia.com/live-afcea-technet-cyber-army-cyber-command-tackles-emerging-trends-cyber-workforce ) DOD Principal Director for Cybersecurity Mark Hakun (https://governmentciomedia.com/listen-dods-portfolio-management-office-accelerates-adoption-zero-trust ) VA Deputy CISO Jeff Spaeth (https://governmentciomedia.com/listen-look-inside-vas-zero-trust-first-cybersecurity-approach )
This episode is sponsored by Cohesity.
The U.S. Digital Corps is bringing innovation to agencies through early-career technologists. Operated by the General Services Administration (GSA) Technology Transformation Services (TTS), the Corps’ fellowship program gives individuals the ability to find themselves working on critical issues at the intersection of technology and public service.
Digital Corps fellow Jamila Crawford on the cybersecurity track in the program is assigned to the Cybersecurity & Infrastructure Security Agency (CISA). She discusses her work at CISA’s Shared Services Division, her career and cybersecurity priorities in government.
JCDC Partnerships International, which sits within CISA’s cybersecurity division, works with 150 partners worldwide with the goal of sharing and exchanging critical information allowing the U.S. to respond to cyber threats faster, protect the country’s critical infrastructure more effectively and relay that information to its international counterparts to do the same.
Patricia Soler, Section Chief for JCDC Partnerships International at CISA, discusses the mechanisms that a fast-growing organization like CISA needs to have in place to process large volumes of information that can be shared with public and private sectors and its international partners. She also talks about CISA’s ransomware notifications that alert organizations of a ransomware attack before the damage occurs.
The Department of Veterans Affairs is amid a cybersecurity modernization plan to put identity management and zero trust at the forefront of the biggest security threats facing technology teams.
Jeff Spaeth, deputy CISO and executive director of information security operations at VA, is a bit of a boomerang. A veteran himself and longstanding cybersecurity professional, he returns to VA under a new cybersecurity modernization strategy. Spaeth discusses what this “Zero Trust First” strategy looks like, the key tools the agency employs to stay ahead of threats and where he sees emerging technologies impacting the space most.
In its recently released National Intelligence Strategy, the Office of the Director of National Intelligence outlines the strategic direction for the Intelligence Community (IC) over the next four years. In it, Director of National Intelligence Avril Haines notes the dramatically changing environment in which the IC operates, including the IT environment. Innovation, information sharing and cyber workforce development are points of emphasis in the document, which reflects the input of officials from each of the 18 elements making up the IC.
The White House recently released it National Cyber Workforce and Education Strategy to enhance and unleash America's cyber talent. The plan addresses the workforce needs in the public and private sectors by introducing cybersecurity concepts throughout all levels of education. The document proposes making advanced occupational training in cyber more accessible and affordable. Agencies and industry partners have signed onto the document, which builds on longstanding White House workforce goals.
Staff Writer Anastasia Obis and Managing Editor Ross Gianfortune discuss the document's points of emphasis, its goals and the cybersecurity workforce challenges which the White House looks to address with the plan.
Military cyber leaders repeatedly say zero trust is critical, essential and integral to the Defense Department's Joint All-Domain Command-and-Control (JADC2) concept. A zero trust approach to cybersecurity helps organizations improve data security, manage users on the network and facilitate data interoperability, all key components of JADC2. Enjoy this preview of our upcoming GovFocus, “Zero Trust Enabling the Future Joint Force,” featuring leaders from U.S. Navy and industry. Register to watch at https://governmentciomedia.com/govfocus/zero-trust-enabling-future-joint-force
The Office of Management and Budget along with the Office of the National Cyber Director released a memo laying out cybersecurity investment areas that agencies will have to include as they make their budgetary decisions for the next fiscal year. We break down those investment areas, how it ties to the recently released National Cybersecurity Strategy and what to expect in the coming months.
Emerging technologies are proving to be very beneficial to the National Oceanic Atmospheric Administration when it comes to climate modeling, behavior analytics and its overall mission. Not only has automation technologies played a key role in NOAA's weather forecasting and environmental monitoring, but also machine learning has been a huge help in the areas of threat detection and vulnerability assessment. Longstanding cyber leader Chi Kang, deputy director for operations in NOAA's Cyber Security Division, highlights some of NOAA's cyber modernization goals for this year including how the agency is working to attract the best cyber talent and moving closer toward a zero-trust architecture.
Since 2018, the Department of Veterans Affairs has been on a journey to the cloud to streamline operations, drive down expenses, better protect data and improve business operations. The agency’s Deputy Director of Infrastructure Operations Kendall Krebs explains how VA is looking to not only use cloud to improve the speed and quality of its application development, but also secure this digital environment — leveraging platforms like VA Platform One (VAPO) to speed authority to operate and trim application deployment cycles. Throughout this journey, culture change is key. Krebs dives into next steps and latest updates.
The Marine Corps is on track to being one of the most distributed forces ever with significant command, control, communications, intelligence and cyber capabilities. A unified network with modernized network equipment is critical to operating in this environment. Cyber Technology Officer Shery Thomas discusses the Marine Crops’ efforts to combine networks with multiple classification levels into a single enterprise, how the service plans to better secure its systems and bring those capabilities to the edge.
The ultimate goal of the Army’s recently established Zero Trust Functional Management Office is to have a secure unified network that is defended by a fully implemented zero trust framework that will enable multi-domain operations and accomplish the Army’s missions. Col. Michael Smith, director of this office, details next steps for zero trust implementation across the enterprise to get to the goal of full zero trust adoption for the Army by 2027.
The Pentagon has a cyber workforce problem: 30,000 cyber positions remain unfilled, but malicious cyber activity isn’t slowing down. Defense cyber leaders warn future conflicts will combine kinetic and information warfare, elevating the importance of a robust cyber workforce. DOD Principal Director for Resources & Analysis Mark Gorak joins us live from AFCEA TechNet Cyber 2023 in Baltimore to discuss these challenges and his plans to address them.
Defense Department CIO John Sherman joins us live from TechNet Cyber 2023 in Baltimore, Maryland, to peel back the layers of the Joint Warfighting Cloud Capability (JWCC) and the department’s zero trust strategy to show how they’re informed by JADC2 priorities and contribute to better data transport and interoperability with coalition partners. Sherman also discusses how cloud initiatives at the military services will complement JWCC efforts.
Live from TechNet Cyber 2023 in Baltimore, Maryland, Defense Department Deputy CIO Lily Zeleke and Chief Software Officer Rob Vietmeyer discuss software factories, DevSecOps, zero trust and the Joint Warfighting Cloud Capability (JWCC). These IT modernization initiatives are transforming the department to be more tech-savvy as information dominance becomes critical to winning future conflicts.
Operating and hardening the Defense Department’s networks is a highly complex undertaking. Training and retaining the workforce, keeping up with a constantly changing environment of technology and emerging capabilities and threats are continuous challenges not just for the Army, but also for all the services. Lt. Gen. Maria Barrett, commanding general of Army Cyber Command, discusses how Army Cyber forces are working globally to secure networks, responding to the needs of the warfighter and preparing for the future of cyber warfare.
The Defense Information Systems Agency (DISA) awarded a $7 million zero trust prototype, called Thunderdome, to Booz Allen Hamilton last year and recently completed the pilot. Cybersecurity & Analytics Director Brian Hermann discusses next steps for zero trust implementation across the Defense Department.
As security concerns grow, phishing attacks are threatening students and educators in schools across the country. The Cybersecurity Infrastructure Security Agency’s new K-12 Report outlines what schools can do to better protect their systems from cyber intrusions and overall risks. The report highlights three key areas, including investing in security controls, addressing resource constraints and focusing on information sharing. CISA is also collaborating with the Department of Education to boost security in technologies schools depend on. Kelly Thiele, chief of phishing assessments at CISA, discusses more about this report, as well as how the agency’s six core principles from its Cyber Essentials Guide provide simple, prioritized actions that other organizations can take to ensure their systems and workforce are cyber ready.
Faced with growing ransomware threats, phishing attempts and more, the Department of Veterans Affairs is reevaluating what it means to be “secure” in a hybrid environment. VA CISO Lynette Sherrill outlines the agency’s cybersecurity strategy and emphasizes the importance of identity management through multi-factor authentication and least privileged access to secure critical IT systems and veteran data.
Upon the release of the White House’s new National Cybersecurity Strategy, federal IT and cyber leaders reviewed current cyber risks and strategies at GovCIO Media & Research’s first in-person event of the year, CyberScape: Insider Threats. Managing hybrid cloud security vulnerabilities, reducing technical debt, limiting the spread of shadow IT and securing open-source software were major talking points.
Drawing on her experience as a CTO in the private sector, Assistant National Cyber Director for Technology Security Anjana Rajan centered national discussions around open-source software security against the backdrop of the Russia-Ukraine war. Rajan identified risk drivers and solutions for bringing cybersecurity to the forefront of IT per the Biden administration’s new National Cybersecurity Strategy during the closing fireside chat of GovCIO Media & Research’s CyberScape: Insider Threats event.
The Enduring Security Framework, a public-private partnership with NSA as its executive secretariat, released a new product examining the benefits, security risks, deployment, and benefits of 5G network slicing. Based on the previously published work “Potential threat vectors to 5G infrastructure,” the new document provides an executive overview of the risks involved with deploying network slicing, including potential management strategies. Learn about the Enduring Security Framework, the work they do, and their assessment of the threats to a network slice and the 5G infrastructure as a whole.
With a challenging maritime computing environment, the Coast Guard supports several missions for the departments of Defense and Homeland Security. Assistant Commandant for C4 & IT Rear Adm. Christopher Bartz discusses his workforce, cybersecurity and tech priorities, including how he’s approaching the service’s own take on interconnected data systems akin to DOD’s JADC2 as well as a new software factory.
CISA’s Joint Cyber Defense Collaborative (JCDC) announced a 2023 planning agenda to stay ahead of persistent cybersecurity threats to federal agencies, such as supply chain risk and open-source software. Learn why these threats are so high profile and how federal agencies across defense, health and civilian sectors are working together to share critical information about cybersecurity risks and incidents. Don’t miss a fascinating tangent where we decide which superhero represents which federal agency.
As the Coast Guard prepares to launch its first software factory later this year, Deputy CIO Brian Campo discusses how his prior experience as CTO for the Department of Homeland Security prepared him to lead the Coast Guard into a more cybersecure future with zero trust, a continuous authorization to operate (cATO) approach and a strong foundation in data management strategies.
Cybersecurity will always be a critical issue. In 2022 federal agencies developed targeted strategies and frameworks to stay ahead of the evolving threat landscape. Our hosts reflect on the top news and trends of last year, including new zero trust strategies out of the departments of Defense and Veterans Affairs, evolving tech and cyber workforce frameworks, plans to combat ransomware and more. Plus we discuss how these efforts will pave the way for progress in 2023.
The Vulnerability Disclosure Program (VDP) is the youngest directorate within the Defense Department (DOD) Cyber Crime Center. Established in 2016, it's the sole focal point for receiving all vulnerability reporting at the agency, and it is uniquely positioned as it engages private-sector white hat researchers to support its mission. In January 2021, it expanded its scope from only public-facing websites to all publicly accessible DOD information systems. VDP Director Melissa Vice briefs how the program engages the security research community to strengthen network defenses, highlights the recent year-long pilot program for the Defense Industrial Base, and talks through her priorities for the coming year.
Global dependence on technology blurs the lines between national and cybersecurity, elevating the importance that consistent collaboration and information-sharing has in the industry. ODNI Director of Cyber Threat Intelligence Integration Center Laura Galante discusses the prevalence of disinformation and how the rapidly shifting cyber landscape impacts the intelligence community.
Identity management is a key factor to creating a robust cybersecurity strategy. GSA’s newly published Privileged Identity Playbook helps federal agencies implement and manage a privileged user management function as part of an overall ICAM program. GSA’s Identity Assurance and Trusted Access Division Director Key Myers and CISA IT Specialist Ross Foard discuss the playbook’s implications and best practices around identity management.
Privileged Identity Playbook: https://playbooks.idmanagement.gov/playbooks/pam/
CDM Program Information: www.cisa.gov/cdm
The CyberCast Ransomware Miniseries comes to a close with advice from CISA, which serves as the federal hub for cyber training, awareness and resources for industry and federal agencies. CISA National Risk Management Center Assistant Director Mona Harrington discusses trends such as triple extortion and ransomware-as-a-service and how strategies such as network segmentation and cyber incident reporting can help.
The CyberCast Ransomware Miniseries comes to a close with advice from CISA, which serves as the federal hub for cyber training, awareness and resources for industry and federal agencies. CISA National Risk Management Center Assistant Director Mona Harrington discusses trends such as triple extortion and ransomware-as-a-service and how strategies such as network segmentation and cyber incident reporting can help.
Mobile devices have become a prime target for malicious actors and ICE is using zero trust to significantly improve threat detection and data protection. In this episode, ICE CISO Rob Thorne also highlights the importance of applying zero trust principles to enterprise mobility and how cyber hygiene activities are helping to propel the agency on its path to zero trust. This episode is sponsored by DataDog.
The Army has been testing an application that would let its soldiers and civilian employees access the Army’s network through their personal devices. It is ready to scale up from under a thousand users to almost 20,000 employees. Lt. Gen. John Morrison, Army deputy chief of staff, G-6, provides more details on lessons learned from the program’s pilot, associated cybersecurity concerns, and how zero trust principles play a crucial role in securing data access. Morrison also touches on the Army’s new Google Workspace partnership and laying the foundation for DevSecOps.
Hybrid cloud creates new efficiencies but can also cause new cybersecurity risks. The Defense Information Systems Agency (DISA), which helps lead cloud modernization for the Defense Department, needs strong partnerships with cloud vendors to maintain a strong security posture. Strategies such as "environment as code," DevSecOps and zero trust can help improve user experience while limiting vulnerabilities and strengthening overall cybersecurity. This episode is sponsored by ThunderCat and Dell Technologies.
GovCIO Media & Research has had a busy two weeks, hosting back to back CyberScape events on zero trust and data and automation security. Join deputy editor Kate Macri and staff writer/ researcher Sarah Sybert for a CyberScape double album, where they unpack the top takeaways from the sessions.
ICE is turning to its Homeland Security Investigations Cyber Crimes Center for assistance when it comes to getting a handle on the recent spike in ransomware, cyber fraud and other malicious attacks. ICE Division Chief of the HSI Cyber Crimes Center Matt Swenson also talks about a new cyber intelligence initiative that is providing ICE with a better way to make use of data and enhance the investigation process.
ICE is turning to its Homeland Security Investigations Cyber Crimes Center for assistance when it comes to getting a handle on the recent spike in ransomware, cyber fraud and other malicious attacks. ICE Division Chief of the HSI Cyber Crimes Center Matt Swenson also talks about a new cyber intelligence initiative that is providing ICE with a better way to make use of data and enhance the investigation process.
Federal agencies are accelerating cyber programs and initiatives to stay up to speed with the quickly changing landscape. Deputy Editor Kate Macri and Staff Writer Sarah Sybert unpack top takeaways from the summer, including upcoming cybersecurity workforce strategies, DOD's new five-year zero trust strategy and new directives around supply chain security.
Federal agencies are accelerating cyber programs and initiatives to stay up to speed with the quickly changing landscape. Deputy Editor Kate Macri and Staff Writer Sarah Sybert unpack top takeaways from the summer, including upcoming cybersecurity workforce strategies, DOD's new five-year zero trust strategy and new directives around supply chain security.
The Defense Department's second iteration of CMMC will soon be released with a focus on cyber hygiene and cybersecurity basics. DOD's CMMC lead, Stacy Bostjanick, discusses the importance of the guidelines and DOD's cyber expectations for the Defense Industrial Base — live from the Billington Cybersecurity Summit.
The Defense Department's second iteration of CMMC will soon be released with a focus on cyber hygiene and cybersecurity basics. DOD's CMMC lead, Stacy Bostjanick, discusses the importance of the guidelines and DOD's cyber expectations for the Defense Industrial Base — live from the Billington Cybersecurity Summit.
Federal cyber leaders want more women in cyber and national security roles, but many women don't know where to start. CYBERCOM Commander Col. Candice Frost discusses the importance of mentorship and offers practical advice for closing the cybersecurity workforce shortage and bringing more women into those roles.
Federal cyber leaders want more women in cyber and national security roles, but many women don't know where to start. CYBERCOM Commander Col. Candice Frost discusses the importance of mentorship and offers practical advice for closing the cybersecurity workforce shortage and bringing more women into those roles.
Retirement plan data is vulnerable to a variety of threats, including malware, ransomware, phishing, spoofing, business email compromise, social engineering, account takeover and privilege abuse, making it a critical priority to protect. Department of Labor Acting Assistant Secretary for Employee Benefits Security Ali Khawar discusses how new cybersecurity guidance over the past year has helped keep information secure.
The Defense Department’s 5G-to-Next G Initiative will help strengthen networks and pave the way for 5G implementation to securely operate at the edge. The “Operate Through” portion of the initiative is leveraging infrastructure already in place for enhanced communication while preventing adversaries from obtaining sensitive mission details — with the millimeter wave spectrum playing a key part in this effort. Director of the Operate Through 5G Initiative Dan Massey provides more details about how this new program is taking DOD’s network security to the next level.
The FBI has been keeping tabs on the evolution of ransomware, and in recent years ransomware attempts and incidents have risen significantly in both sophistication and severity. The latest in this ransomware miniseries talks to FBI's Cyber Section Chief Bryan Smith on how the agency's investigation and mitigation tactics have advanced alongside these cyber crimes — including best practices to make your organization resilient amid growing threats.
With a region spanning Northeast Africa, Middle East and Central and South Asia, CENTCOM is preparing for the Defense Department's JADC2 effort to better connect data capacities around the world. DISA Central Field Command's Tania Wilkes shares some of her top cyber challenges and how she believes cyber education will make or break cybersecurity for military operations. Expect to hear about satellite communications, 5G security, zero trust and more in this episode.
Faced with increased threats from ransomware, the health care industry is growing its security priorities with technology and data. Dr. Kevin Fu, acting director of medical device cybersecurity at the Food and Drug Administration's Center for Devices and Radiological Health, discusses FDA's recently updated draft of its premarket cybersecurity guidance and how medical device developers can leverage capabilities like threat modeling to drive a proactive approach to cybersecurity.
A new Zero Trust Portfolio Management Office is putting the Defense Department on track to improve its overall cybersecurity posture. While this will be a major task for DOD, a zero-trust roadmap will ensure the proper training and workforce are in place for greater interoperability across the entire department. The portfolio management office will also help accelerate the adoption of zero trust throughout DOD and make it an embedded way of life. DOD’s Principal Deputy CIO for Cybersecurity Mark Hakun talks about culture change and the integration of zero trust, the challenges the department is facing and the capabilities DOD hopes to deliver later this year.
The Cybersecurity and Infrastructure Security Agency promotes a variety of best practices and resources across the cyber space, and the software bill of materials — otherwise known as SBOM — is a rising area of importance. We speak with one of CISA's top promoters of SBOM development at the 2022 RSA Conference to dive into the different components of SBOM development, the benefits SBOMs bring to your security posture and how you can work on developing your own SBOMs today.
The Defense Department's Cyber Crime Center (DC3) is a federal cyber center and serves as a center of excellence for digital and multimedia forensics. Its training academy also trains thousands of DOD personnel every year. Acting Executive Director Joshua Black, a longstanding cyber expert, discusses the ransomware trends and threats facing the Defense Industrial Base in this kickoff episode in CyberCast's Ransomware Miniseries.
Army Software Factory CISO Angel Phaneuf discusses how she's working to foster zero trust interoperability and a healthy cyber culture throughout the Defense Department. She also tells the story of how Army Software Factory discovered the Log3j vulnerability and mitigated it in only 24 hours.
GovCIO Media & Research returned to in-person events on Thursday with Infrastructure: Cloud Modernization. Our senior researchers are joined by staff writer Adam Patterson to break down top takeaways from the event, including critical approaches to cloud implementation, the role of the user in cybersecurity, data literacy and more. Featured perspectives include leadership from DISA, GAO, VA, GSA, U.S. Army and more.
Hear from Col. Ken Kuebler about the importance of modular, open-systems architecture and his top cybersecurity and IT modernization challenges for the Fixed Wing program office at USSOCOM.
USSOCOM Networks and Services COO Col. Joe Pishock sits down with GovCIO Media & Research to discuss the importance of commercial cloud-hosted collaboration tools for network modernization and the cybersecurity challenges, such as overclassification, that hinder successful implementation.
AFCEA TechNet Cyber 2022 marks another return to in-person events, and Senior Researcher Kate Macri is here to discuss top takeaways and themes from the conference. Topics include ICAM solutions, zero trust, cyber operations and what it's like to be in-person again after two years of online panels.
The U.S. Air Force's BESPIN software factory provides mobile application development as a service to airmen, but mobile technologies are notoriously difficult to secure. BESPIN CISO David Cantrell discusses the cyber challenges he faces and why he has a love-hate relationship with tools like software bills of materials (SBOMs).
U.S. Air Force software factory Kessel Run relies on a unique blend of tech tools to address new cyber threats. This includes DevSecOps, APIs and even something called "chaos engineering." Hear from Kessel Run Chaos and Performance Tech Lead Omar Marrero about how the organization quickly identifies and remediates threats to Air Force weapons systems.
The 16th Air Force is responsible for all Air Force networks for warfighting, and is the combatant command responsible for all of the Air Force’s offensive and defensive cyber operations. Deputy Commander Brig. Gen. Brad Pyburn discusses top cyber concerns and challenges as malicious cyber activity surges, and the "secret sauce" to cybersecure implementation of JADC2.
As the U.S. Navy gears up for 5G, a number of pilots are underway to evaluate the risks that come with this faster network capability that unlocks the path to many emerging technologies like AI. The Navy’s first order of business is to modernize its environment for 5G. It is also looking at the best ways to protect its systems and maintain good cyber hygiene along the way. Navy Chief Digital Innovation Officer Michael Galbraith talks about the Navy’s efforts to mitigate vulnerabilities as it gets its networks ready for 5G.
Blue Cyber Lead Kelley Kiernan tells the story of how she developed an initiative to support small businesses navigating tricky cyber questions as cyberattacks against the Defense Industrial Base skyrocket. She is now detailed to the Air Force’s CISO office, where she's breaking down cyber roadblocks for small businesses to participate in top opportunities with the service.
With the ever increasing number of data breaches and hacks, cybersecurity has become a focal point for many federal agencies. Quantum computing could play a major role in helping organizations identify and avert cyberattacks even before they arise. DARPA Program Manager Joe Altepeter from its Defense Sciences Office talks about how DARPA is examining the great possibilities of this new technology for applications in defense and beyond.
As the cybersecurity and privacy field continues to grow in the health care space, so does the need to better protect patient data. For IT leaders at Penn Medicine, this means tackling deep-rooted challenges in recruiting to remove bias and also implementing careful strategies for safeguarding against ransomware threats of this sensitive data. Penn Medicine Senior Application Manager of Clinical Research Information Security Jessica Chen from HIMSS along with Director of Information Security Seth Fogie, joining virtually, break down this issue and discuss how others can learn from it.
It's time to take it up to zero — zero trust, that is. Senior researchers Melissa Harris and Kate Macri return to discuss the outcomes from our latest virtual event, CyberScape ID. Topics include the role of identity in zero trust, data management and identity solutions. Featured perspectives include leadership from OMB, HHS OIG, Fortinet and more.
National Cyber Director Chris Inglis believes current cyber leaders are uniquely qualified to transform federal cybersecurity and can work together to solve anticipated challenges like workforce shortages. The nation's top cybersecurity chief discusses his cyber priorities for 2022 and what federal agencies can do to strengthen their cyber postures in an increasingly volatile cyber landscape.
USCIS was an early adopter of zero trust and artificial intelligence for cybersecurity. CISO Shane Barney discusses how the agency continues to innovate and improve its cyber strategies in an increasingly hostile cyber environment.
Government agency leaders discussed how their organizations are approaching increasing modernization around artificial intelligence and data management, and key considerations for how these systems ensure strong national security. Issues include cyber warfare, workforce upskilling, high-performance computing and current research and features leaders from the Defense Department, NASA, Department of Homeland Security and more.
Highlighted remarks featuring:
The next generation mobile network is on its way in, but 5G's impact lies in more than cellular connectivity. The technology will be central to digital innovation supporting artificial intelligence, cloud computing and data sharing. NIST IT Specialist Jeff Cichonski unpacks the security implications of this movement and how NIST's center of excellence is exploring ways to remove or reduce these threats to 5G infrastructure.
Federal agencies are taking charge in implementing zero trust strategies amid a Biden executive order to boost security amid recent incidents. The Department of Health and Human Services' Office of Inspector General's new CIO, Gerald Caron, discusses how zero trust and software supply chain risk management anchor not only his cyber strategy around agency audits, but also that of the entire federal government.
Acting CISO Greg Edwards sees identity, credential and access management (ICAM) and zero trust as key strategies for combatting ransomware and other cyberattacks that are afflicting government agencies nationwide. Edwards also discusses the collaboration between FEMA and state, tribal and local governments, as well as lessons learned throughout the pandemic on future cybersecurity approaches.
Cybersecurity is increasingly becoming synonymous with national security. As we become more connected, integrate technology into our infrastructure, and work to ensure our supply chains are secure, leaders in federal government and industry discuss working toward securing our nation from the Aug. 19 CyberScape event series, kicked off by fireside chat keynote Chris Inglis.
Women make up less than one-third of all STEM-related jobs. Additionally, the Department of Homeland Security estimates there are at least 500,000 unfilled cybersecurity positions, which the agency deems a risk to national security. NIH's Jothi Dugar, NIST's Danielle Santos, and Okta's Michelle Tuggle from the Women Tech Leaders event discuss how they are encouraging and educating women to help fill the cybersecurity workforce gap and the gender STEM gap at the same time.
CISA COVID-19 Task Force Lead Steve Luczynski, Presidential Innovation Fellow Michelle Holko and CISA Senior Advisor Josh Corman tell the unlikely story of how they created a team with diverse backgrounds to help keep America running, informed and safe during the pandemic. The experts discuss the roles they played in the early approaches to the pandemic response and subsequent security implications.
The COVID-19 pandemic made health IT more vulnerable than ever as cyberattacks on hospitals, public health organizations and research initiatives soared. Featured panelists from the CyberScape: Health Care event highlighted ways federal health IT leaders are securing their networks and sensitive information, and also look back on cyber lessons learned from the COVID-19 pandemic. Featured commentary from the Defense Digital Service, CISA, HHS and more.
Jennifer Franks offers a unique outlook on the state of federal cybersecurity thanks to her oversight role at the Government Accountability Office. Franks discusses some of the top cyber issues facing federal agencies and how President Biden's cyber executive order can address them.
Newly promoted Wanda Jones-Heath talks about her position as principal cyber advisor for the Department of the Air Force and what a holistic approach to cybersecurity looks like. This includes taking hold of data interoperability efforts and ensuring all teams are operating in a cohesive yet still safe and secure infrastructure amid recent concerns with supply chains and data breaches.
Amid software hacks like the SolarWinds incident, the FDA works with manufacturers and other agencies to ensure medical devices are secured and personal data is kept safe. Jessica Wilkerson, cyber policy advisor at the FDA, discusses the shared responsibility of cybersecurity and the need to secure the entire supply chain.
Securing the federal supply chain is among government's top priorities right now. Lisa Barr, CISA's cybersecurity supply chain lead whose prior role involved the recently established Federal Acquisition Security Council, discusses the whole-of-government approach to supply-chain security threats and how varying agency missions and needs come into focus around established risk management standards. Barr gives us a look at the biggest challenges ahead and the current efforts underway to ensure security from threats.
The Cybersecurity Maturity Model Certification (CMMC) standards require third-party assessments on security requirements for contractors to bid on DOD contracts. Rocky Thurston of Perspecta and Seth Storie of ArdentMC look at how much CMMC will impact contractors, plus share perspective on ways it could change federal contracting overall.
The Criminal Investigations and Network Analysis Center, a Department of Homeland Security S&T Center of Excellence, supports the agency with research and tools for fighting cybercrime. Jim Jones, CINA's director, details how researchers are working to intercept cybercriminals and educate a new generation of cybersecurity professionals.
Suzanne Spaulding, former DHS undersecretary for cyber and infrastructure, now a member of the Cyberspace Solarium Commission and CSIS, draws on her deep well of knowledge and experience in cyber and the intelligence community to frame our nation's biggest cyber risks — and how to address them.
CDM Deputy Program Manager Betsy Kulick describes how and why CISA started the famed cybersecurity program, how it's going, and what's next for federal agencies seeking to protect their networks in 2021.
Federal leaders gathered to discuss innovations and capabilities of cloud computing during our Nov. 19 Cloud Summit. Catch up on these highlights from leaders at the Department of Homeland Security, Defense Logistics Agency, FedRAMP and learn more about zero trust capabilities and streamlining ATO processes.
Cybersecurity expert Trey Herr, director of the Cyber Statecraft Initiative at the Atlantic Council, explains why IT and cloud supply chain security is a national security issue — and what federal agencies can do about it.
Securing IT supply chain means preventing counterfeits, end-user malware and vulnerable components as federal agencies modernize their IT and infrastructure. From our Oct. 7 virtual event, hear from CISA National Risk Management Center Associate Director Daniel Kroese and Dell Technologies' Dan Carroll on how agencies are working together to secure the supply chain.
NIST Fellow Ron Ross discusses how federal agencies can maintain best cybersecurity practices while working remotely, plus how standards and practices like FISMA, zero trust and privacy play into federal strategies.
Federal officials came together during our Sept. 2 CyberScape virtual event to discuss priorities in security and hiring the next generation of leaders, including a conversation on women in tech with Katie Arrington, Jothi Dugar and Venice Goodwine. Looking ahead, standards like TIC 3.0 and CMMC will have lasting impact on federal security strategies.
The Department of Homeland Security Science and Technology Directorate in partnership with the National Information Assurance Partnership sponsored a pilot effort to determine to what extent NIAP evaluations of mobile app software could be automated. Vincent Sritapan, program manager for Mobile Security R&D at DHS S&T, and Michelle Brown, deputy director at NIAP, discuss these innovations for certifying mobile apps in government.
NUSTL Director Alice Hong discusses the lab's coordination with our nation's first responders on testing and evaluating cutting-edge technologies, from protective gloves to in-suit communication devices. We also talk about training exercises for radiological and nuclear incidents and active shooter scenarios, as well as how NUSTL is aiding in COVID-19 response efforts.
Adrian Monza discusses the strategy behind securing endpoints, users and data by getting rid of passwords and running anti-phishing exercises. He also talks about penetration testing, containerization and the importance of educating your entire organization about their role in cybersecurity.
Janet Vogel and Christopher Bollerer discuss the current challenges and opportunities in health cybersecurity, especially information-sharing across the public and private sectors, workforce training and education, and the cyber hygiene essentials underpinning security innovation.
CISA Assistant Director of Stakeholder Engagement Daniel Kroese and Marsh Senior Vice President Stephen Vina discuss the importance of partnerships in federal government in tackling some of the most pressing cybersecurity concerns. For more episodes, head over to https://governmentciomedia.com/cybercast.
Oki Mek discusses his priorities in his new position at the agency, including automating the authority to operate (ATO) process, educating the workforce on cybersecurity hygiene, the importance of blockchain and why innovation is not always about the technology.
Gerry Connolly discusses government progress on the standards and directives codified in FITARA, IT modernization and FedRAMP. We look at IT modernization efforts and discuss both the Modernizing Government Technology Act and the associated Technology Modernization Fund.
Stacie Alboum discusses her background in security at previous agencies plus how the "Optimize NIH" initiative and business management play into her current security priorities at the National Institutes of Health.
For more episodes: https://www.governmentciomedia.com/cybercast
Servio Medina discusses the importance of cybersecurity in defense health records and activities. He is a proponent of maintaining a "cyber fit" regimen at home and professionally.
With the Department of Veterans Affairs' nationwide footprint, much consideration goes into its security posture. CISO Paul Cunningham discusses his risk-based approach to securing the agency's data and even touches on how his background as a naval safety aviator impacts his work today.
Castillo leads the FBI's efforts to develop and implement the best cybersecurity tools and practices. He discusses the agency's ongoing efforts that include cloud migration, risk management strategy and the promises and limitations of emerging technologies.
John Zangardi discusses the importance of security for the agency's end-to-end IT and his strategy for the implementation of technical refresh of network and consolidation of the Security Operations Center.
Nov. 12, 2018 | Grant Schneider, U.S. CISO, joined CyberCast podcast hosts Kiersten Todt and Roger Cressey. Schneider discussed the outsized role social media platforms can play, the government’s policies on offensive cyber capabilities, cyber tools, and the need for streamlined procurement processes. He also talked about how cloud needs to be considered a piece of critical infrastructure that must be protected since so many government agencies depend on the cloud for IT support.
Oct 29, 2018 | Karen Evans, the Department of Energy’s first Assistant Secretary for Cybersecurity, joins Todt and Cressey to discuss Secretary Perry’s greatest cyber fear, government's coordination with industry on energy safety, the role of DoE in responding to cyber and natural disasters and the role of the national labs in building the next generation of secure energy systems.
Sept 12, 2018 | Pulitzer Prize-winning reporter Ellen Nakashima from The Washington Post joins Todt and Cressey to discuss Russia’s activities in the mid-term elections, US military operations in cyberspace, Federal Government and social media companies efforts to counter Russia influence operations, privacy in the age of social media, the realities of reporting in a digital media world and how The Washington Post deals with Trump’s attacks on the media.
Aug 27, 2018 | Jim Miller, former Undersecretary of Defense for Policy, sits down with Todt and Cressey to discuss Congress' role in delivering effective sanctions, cyber-deterrence, influence operations, and how policy makers can increase defenses and raise the costs of misbehavior. Where is cyber defense policy headed? Join us for more!
Aug 1, 2018 | Dave McCurdy, President and CEO of the American Gas Association sits down with Todt and Cressey to discuss the role of Congress in bolstering cyber defenses, national security, natural gas, cyber risk, and how cyber and emerging tech are shaping American industry.
July 25, 2018 | Chris Krebs, DHS Undersecretary for National Protection and Programs Directorate joins the show to talk with Todt and Cressey about his cybersecurity priorities, next week's DHS National Cybersecurity Summit, and the renewed focus on risk management.