Feds At The Edge by FedInsider: Recent Episodes

FedInsider

Want to know what the most brilliant minds in government and the technology industry are working on behind the scenes? The federal government is pouring thousands of man-hours and billions of dollars into cutting edge projects for the military, civilian agencies and the intelligence community. Get a front row seat to all of that innovation and more with our Feds at the Edge (FATE) podcast.

Each episode of FATE features public and private officials who are changing the world with cutting edge technology. No topic is off limits or too technical for our guests to handle. Learn the inner workings of federal projects involving intelligence gathering, emergency management, modernization, artificial intelligence, cybersecurity, communications, encryption, cloud computing, robotics and much more. Don’t let FATE pass you by. Discover this exciting new podcast today!

View Details

History shows that nations often enter new conflicts relying on old, familiar tactics. It's only after those tactics fail that they adapt to something new.

Today, thousands of defense contractors and companies are making the exact same mistake with Cybersecurity Maturity Model Certification (CMMC). By applying outdated, static compliance tools to a modern, dynamic regulatory landscape, organizations face mounting delays, incomplete visibility, and soaring costs. In this week's episode of Feds At The Edge, we sit down with leading experts from GDIT, Axonius Federal, Red River and ComplAi, who have successfully navigated these pitfalls to streamline the journey to certification.

They highlight why traditional governance, risk, and compliance (GRC) tools built for commercial frameworks fail under CMMC standards, why continuous monitoring must replace periodic rule-checking, and how essential a complete data inventory is for long-term success.

View Details

Everyone has heard about fraud, waste, and abuse, but building an effective fraud prevention program requires more than identifying problems after they occur.

In this week's episode of Feds At The Edge, government and industry experts share practical strategies for helping federal agencies stop improper payments before funds go out the door.

Kim Brandt of CMS underscores the scale of the challenge, noting the agency processes roughly $1 million in claims every day. Justin Marisco from the Bureau of the Fiscal Service share how tapping into shared resources, such as Treasury's Do Not Pay list, the Social Security Death Index, and DHS databases can help validate individuals before funds are ever disbursed. Diligent's Jason Venner highlights why preventing improper payments is infinitely better than the traditional "pay and chase" approach and how the era of Big Data introduced agencies to analyzing massive datasets, while today's AI makes it possible to analyze entire datasets, rather than samples, to identify fraud risks.

Tune in on your favorite podcast platform to learn how modern technology and cross-agency data sharing are shifting federal fraud prevention from reactive damage control to proactive defense.

View Details

Permitting delays can increase construction costs, frustrate applicants and slow the delivery of much-needed housing. But modernizing the process requires more than simply replacing paper with technology.

In this week's episode of Feds At The Edge, we explore how government and industry leaders are combining policy reform, digital workflows, cloud technology and AI to reduce permitting backlogs and improve the building approval process.

John W. Lane of the Town of Caledon examines outdated bylaws, inconsistent processes and ways to accelerate reviews without sacrificing safety. Philip Mosher of the Municipality of North Grenville shares how updated zoning rules, integrated workflows and dashboards can help expose bottlenecks and move applications forward. James Nyhus of the District of Sechelt discusses moving from paper files to cloud-based permitting and tablet inspections, while Salesforce's Nadia Hansen explores how AI could support document processing, workload planning and routine applicant questions.

Tune in on your favorite podcast platform for a practical look at how government can connect people, processes and technology to deliver faster, more responsive services.

View Details

Identity is central to Zero Trust, making it one of the most attractive targets for cyber attackers. While multi-factor authentication has long been a reliable way to ensure identity, traditional MFA has critical gaps.

This week on Feds At the Edge, Mark Brennan from the New Jersey Department of Health, and YubiKey's Jeff Frederick, explore how phishing-resistant cryptography and hardware security keys provide stronger protection against modern identity-based threats while improving the user experience. The panel also examines why hardware-backed authentication is recognized in NIST SP 800-63 Revision 4 as a highly secure approach to cryptographic MFA and shares practical guidance for implementation, including starting with a phased rollout, engaging executive leadership early, and continuously refining the program to build user confidence and support long-term Zero Trust success.

Tune in on your favorite podcast platform to discover how hardware-backed authentication can help agencies reduce identity-based attacks, strengthen security, and simplify the path to phishing-resistant MFA

View Details

Supply chain risk is about more than software and compliance checklists; it's about making informed decisions that strengthen security and support mission success.

This week on Feds At the Edge, Ryan Lewis of the Illinois Department of Innovation and Technology joins us to unpack the practical realities of managing supply-side risk in the public sector. Rather than getting bogged down in software bills of materials or endless certifications right out of the gate, Lewis advocates for a broader view of risk assessment, one that starts with developing vendor risk profiles and building genuine personal relationships with vendor representatives.

He shares his strategy for balancing tight budget constraints with strict security requirements, urging organizations to evaluate the actual value of their data before deciding how to protect it and to thoroughly examine their existing tools before wasting resources on yet another solution.

Tune in on your favorite podcasting platform today as Lewis highlights that securing the supply chain isn't just about compliance and technology. It's also about fostering an organizational culture of collaboration, integrity, and openness.

View Details

Ransomware has become a far more serious threat to government than many organizations realize, and it's no longer just about paying a ransom.

This week on Feds At the Edge, cybersecurity experts explore what agencies can do to strengthen their defenses, including adopting Zero Trust principles, improving network segmentation, and planning for recovery before an attack occurs.

Cesar Gamez from City of Roseville, CA explains how ransomware attacks have evolved, from encrypting files for financial gain to tactics that threaten to expose sensitive data or target victims' customers if demands aren't met.

And Travis Rosiek of Rubrik Public Sector, introduces an even more alarming trend: "wiper" attacks. Unlike traditional ransomware, these attacks - often associated with nation-state actors - are designed to permanently destroy or corrupt data, leaving organizations with nothing to recover even if they were willing to pay.

Tune in on your favorite podcast platform as our guests also examine the security challenges of hybrid and cloud environments and explain why collaboration and information sharing are essential to staying ahead of increasingly sophisticated cyber threats.

View Details

Technology is advancing at an astonishing pace. The number of connected devices per square kilometer is expected to grow from one million to ten million, and the transition to 6G is paving the way with dazzling new levels of speed and capability.

This week on Feds At the Edge, Arup Bhuyan from Idaho National Laboratory, Eric Freer from Sterling, and Jorge Escobar from Nokia explore how download speeds could increase from 1 GB per second to 100 GB per second, dramatically reducing latency and making it possible for federal agencies to monitor networks in real time and respond more quickly to cyber threats.

We'll also explore Integrated Sensing and Communication (ISAC) and its potential to transform everything from drone defense to intelligent network management. Hear why experts believe agencies will need creative approaches that leverage AI, advanced encryption, and zero-energy sensors to secure the next generation of networks.

Tune in on your favorite podcast platform as government and industry thought leaders discuss the need for international collaboration, significant investments in research and development, and the integration of AI to build faster, smarter, and more secure networks.

View Details

Artificial intelligence is evolving so quickly that agencies often find it difficult to plan for future implementations.

This week on Feds At The Edge, we dive into the importance of flexible infrastructure, realistic budgets, and thoughtful planning to successfully adapt to continuously evolving AI models.

Sumit Puri, CSO and Co-Founder of Liqid, shares that while 86% of data resides on-premises, leaders also need to understand how the other 14% is being managed. He breaks down the key security, privacy, compliance, and performance considerations organizations should keep in mind.

Ariana Tifft, Chief Data Scientist with the DoD Cyber Crime Center, explains how understanding existing resources and future requirements enables real-time planning and improved workload efficiency.

Tune in on your favorite podcast platform to hear their insights, along with perspectives from experts at Optiv + ClearShark, on balancing what you have, knowing what you need, and maximizing results.

View Details

When it comes to air-gapped networks, there is an assumption that this is the ultimate protection for Federal networks.

This week on Feds At the Edge, we speak with three federal experts who share their observations that challenge these assumptions and bring potential cracks in this seemingly impenetrable security measure to light.

We'll explore how air-gapped systems can still be exposed through compromised supply chains, why patching and upgrades become more difficult without internet connectivity, and how manual data transfers using USB drives and external media can introduce new vulnerabilities. The conversation also examines critical questions around Controlled Unclassified Information (CUI), software allowlisting, and strategies for blocking unauthorized executables.

Tune in on your favorite podcast platform to learn why an air gap alone is not enough, and what agencies must do to protect their most sensitive systems.

View Details

Innovation often follows a familiar cycle: rapid expansion, followed by consolidation. Federal agencies are experiencing this firsthand as AI tools and models proliferate across their environments.

This week on Feds At the Edge, technology leaders explore the challenge of rapid innovation and how agencies can regain control before the chaos of disorganized, duplicate data and tool sprawl compromises their missions.

Jim Smid, Federal Solutions Architect, Palo Alto Networks, explains how observability now extends beyond servers and IoT devices to include AI models, tools, and their interactions with agency data. Jessica Souder, AIRS Specialist / Director, Public Sector, Palo Alto Networks, emphasizes that agencies should carefully evaluate new AI tools, validating them in controlled environments, and establishing governance before deployment.

Tune in on your favorite podcast platform to hear why our panel of experts agree that any AI deployment should focus on the agency mission, valid data, and that all projects should commence with visibility.

View Details

AI is putting ransomware on steroids, and on this week's episode of Feds At the Edge we examine several approaches to reducing the impact of malicious actors through advanced protection strategies and smarter cybersecurity budgeting.

Michael Dent, Retired CISO with Fairfax County, shares how he takes cybersecurity training to the next level with what he calls "Challenge Point," rewarding employees for identifying signs of potential attacks. Glendon Schmitz, Virginia State Corporation Commission, discusses the importance of showing leadership the direct financial impact of an attack when seeking successful budget approval. Akamai Technologies' Douglas Holland explores the emotional tactics malicious actors use to pressure unsuspecting users into complying with urgent requests.

Tune in on your favorite podcast platform for more on this and ransomware-as-a-service, the long-term effects on public trust, leadership accountability, and the growing need for initiative-taking governance and budgeting.

View Details

In a recent Forrester report on federal technology, more than half of the respondents revealed they face significant negative impact from budget constraints, while a whopping 86% expect a breach.

This week on Feds At the Edge we sit down with experts from Centers for Medicare & Medicaid, and Carahsoft to discuss practical strategies for securing mission-critical systems, maximizing existing technology investments, and prioritizing the areas of greatest risk.

We also bring in a special guest from Forrester who shares how agencies can maximize limited resources by using shared enterprise services, streamlining overlapping AI security tools, and prioritizing critical areas such as network security, data protection, and incident response.

View Details

One common theme among technology leaders discussing AI deployment is the need for a "definitive source." Without trusted data, none of AI's conclusions are truly actionable.

This week on Feds At the Edge, two technology leaders share practical strategies for building trustworthy AI environments while strengthening security and compliance.

Jared Pane from Elastic discusses why organizations can't blindly trust AI outputs, highlighting both familiar data quality issues and emerging threats like hidden "white-space text" embedded in datasets that can carry malicious code into AI repositories.

Meanwhile, Chris Bunton from Texas Dept of Agriculture, explains how automation can simplify security and compliance, including the implementation of a policy bot that provides employees with 24/7 guidance on compliance best practices.

Tune in on your favorite podcasting platform for practical advice for agencies beginning their AI journey: start small, solve clear problems, and build a collaborative culture that supports long-term success.

View Details

Preparation is everything when it comes to AI in government.

This week on Feds At the Edge, experts from the Library of Congress, Fortinet Federal, Pryon, Dell Technologies and Data Evolution share practical insights on moving beyond "lift and shift" approaches, selecting the right tools, and ensuring data is truly AI-ready.

From treating AI tools as "perishable as tomatoes" to rethinking legacy data and modern migration strategies, the conversation highlights the importance of strong data foundations, thoughtful implementation, and continuous learning.

Tune in on your favorite podcasting platform for insights on how successful AI adoption depends less on the tools themselves and more on preparation, collaboration, and informed decision-making.

View Details

Data is the lifeblood of AI, and when it's incomplete, biased, or inaccurate, your results will be abysmal.

This week on Feds At the Edge, we sit down with Geoff Schaefer of Leidos and Susan Laine from Quest to discuss how to overcome the common pitfalls and data challenges of federal AI adoption.

Our guests explore the shift toward data platforms that include curated, reusable data products that improve visibility, assign trust scores, and clarify data sources and permissions.

Tune in on your favorite podcasting platform for insights on governance, interoperability, and ethical use, as this conversation highlights how strong data foundations are essential to making AI reliable, scalable, and mission-ready.

View Details

Professional sports reward those who perform under pressure. In federal technology, the stakes are even higher.

This week on Feds At the Edge, we sit down with experts navigating the realities of securing federal systems in an environment where threats are constant and decisions carry real consequences. Gary Barlet, Public Sector CTO for Illumio, poses a critical question: "Do you have a plan for what happens when a malicious actor breaches your system?" He explains how segmentation can stop attackers from being able to "land and expand," and why "real-time" observability is essential to understanding actual network dependencies.

Mark Mitchell, Federal Security Architect at Netskope, highlights a familiar challenge: "If this alert is valid, what is my next step?" He introduces "Active User Coaching," which helps guide users with warnings and safer alternatives when risky actions occur.

Together, the conversation also explores aligning zero trust strategies with federal guidance and the importance of assuming breaches from the start.

Tune in on your favorite podcasting platform to hear how effective federal cybersecurity requires planning, real visibility, and clear action in the moments that matter most.

View Details

In order to determine its value, Federal Technology leaders know it's all about the workflow when it comes to the possibility of incorporating AI. Once they do, having a deeper understanding of the distinction between traditional and generative AI, as well as the importance of data cleanliness and security will be key for an effective adoption.

This week at Feds At the Edge, we outline the steps agencies should know and take to take as they prepare to expand into the newest digital landscape. From defining terms, to ensuring clean and secure data, to identifying and removing potential bias, we'll explore what the new lifecycle of information should look like.

Tune in on your favorite podcasting platform to hear how streamlining the data process can help optimize the value that AI can bring to the table.

View Details

We have all seen the power of AI; the question is, can it be implemented in a secure federal environment?

This week on Feds At the Edge, we sit down with three experts who are proving that powerful AI can be deployed securely in federal environments, without compromising compliance or mission outcomes. Leaders from the Library of Congress, Idaho National Lab, and Keysight share how responsible implementation, curated data, and private AI models are unlocking transformative results. You'll hear how agencies are navigating sensitive data repositories, building secure AI ecosystems, and fostering collaboration to accelerate innovation, while keeping privacy and security front and center.

Tune in on your favorite podcast platform for a practical look at how federal leaders are securely scaling AI from experimentation to real-world impact.

View Details

What if better visibility into your IT assets could unlock cost savings, strengthen security, and free teams to focus on the mission?

This week on Feds At the Edge, we explore how federal agencies are turning digital modernization into a strategic advantage by strengthening software and asset visibility. With a clearer understanding of existing licenses, agencies can eliminate duplication, retire unused tools, and collaborate across organizations to secure better pricing and maximize value.

The conversation also highlights how AI is elevating asset management, moving beyond static reporting to real-time insights, forecasting future needs, and uncovering hidden risks like shadow IT. At the same time, aligning asset and procedure management is enabling more proactive operations, where adaptive licensing and better data help teams shift from compliance-heavy tasks to mission-focused work.

Tune in on your favorite podcast platform to learn how a more connected, forward-looking approach is helping agencies cut costs, reduce risk, and operate smarter for the future.

View Details

Trust is difficult enough in an environment with strict controls and security; AI adds dimensions that make establishing trust even more challenging in the public sector. Over the last decade, if we have learned anything, it's that check box solutions never work.

This week on Feds At the Edge, we break down what it takes to build trustworthy AI in high-stakes government environments. From model transparency and "model cards" to the risks hidden in data and the importance of context, they explore how leaders can evaluate trust across the model, the data, and the monitoring processes.

Tune in on your favorite podcast platform to learn why continuous monitoring, strong governance, and thoughtful implementation are essential, and how agencies can move beyond checkbox compliance to deploy AI with confidence.

View Details

How do you upgrade a global fleet when failure isn't an option?

This week on Feds At the Edge, we dive into the Navy's "Operation Cattle Drive," an ambitious initiative to modernize technology across hundreds of ships in the world's most challenging environments.

We sit down with experts from the U.S. Navy and Red Hat to break down the three pillars of high-stakes digital transformation:

  • Development: Using digital twins to test systems in advance—eliminating risk where failure isn't an option.

  • Scaling: Building infrastructure that can support growing AI demands across a distributed fleet.

  • Automation: Applying thoughtful automation can support patching, compliance, and faster updates. Moving toward a world where complex military networks are as seamless to update as a commercial smartphone.

Tune in on your favorite podcast platform as our experts highlight why strategy, enterprise platforms, and a culture of change are essential for mission success.

View Details

AI presents such a dazzling set of opportunities that federal leaders can be tempted to dive in without careful planning.

This week on Feds At the Edge, we move past the hype to explore the tactical realities of deploying AI within the unique constraints of the federal environment.

Ashley Billman, Cybersecurity Analyst, Pacific Northwest National Laboratory, explains why agencies must align AI architecture with mission and security needs, whether on-prem, hybrid, or cloud environments, and highlights a critical question: what's actually in the training data, and what might be missing?

The discussion also explores emerging risks. Experts Gary Bartlett from Illumio and Mark Mitchell from Netskope join the conversation to warn against the "agent" trend, sharing cautionary tales of AI inadvertently accessing sensitive information and explaining why robust governance is the only way to ensure your AI's conclusions are actually valid.

Tune in on your favorite podcast platform to learn why AI literacy is no longer an optional skill, but a strategic necessity for the future of federal cybersecurity. Stop chasing the headlines and start building a framework that turns AI from a risk into a mission-critical asset

View Details

AI has the power to transform government operations, but only if it's used wisely.

This week on Feds At the Edge, we dive into the high-stakes world of applied AI within public agencies, where the potential for massive efficiency gains sits right next to the risk of moving too fast without a map.

From Todd Sharkey of Lorain County, OH's look at the document "drowning" in many government organizations to Brandon Ragle at Illinois Department of Innovation and Technology's vital warnings on data privacy and strict procedural safeguards, we explore the thin line between innovation and liability. Brad Porter of Knowledge Lake joins us to bridge that gap, demonstrating how AI can classify and secure sensitive data at speeds once thought impossible.

Tune in on your favorite podcast platform for our experts' takeaways: start small, pilot carefully, and measure the impact. When implemented thoughtfully, AI can turn overwhelming archives into actionable insights.

View Details

I isn't here to replace government professionals, it's here to elevate them.

Artificial intelligence is still new territory for many public sector leaders, but understanding how to apply it effectively can unlock major gains in productivity and insight. This week on Feds At the Edge, we dive into the essential transition for government professionals: offloading routine tasks to AI so humans can reclaim high-level analytical work.

Dr. Nancy Washton breaks down the critical distinction between "deterministic" traditional computing and today's "non-deterministic" AI, explaining why the same prompt can yield different results and how to vet those outputs by asking the system to document its own logic. Alongside Alyssa Ashworth's insights on data security, human oversight, and productivity metrics, this discussion provides a roadmap for moving from simple applications to complex, scaled solutions.

Tune in on your favorite podcast platform as this discussion explores how to build professional confidence by starting small and scaling smart in the new age of intelligence.

View Details

What if the solution to our most daunting infrastructure challenges isn't just more concrete, but more clarity?

This week on Feds At the Edge, we explore how cutting-edge technology is turning budget constraints into opportunities for smarter, more sustainable growth.

Experts from VHB, Portland Bureau of Transportation, Georgia Department of Transportation, Bentley Systems, Inc, and Reynolds, Smith & Hills, discuss how leveraging digital twins - dynamic software-based replicas of physical projects - states can revolutionize the way they plan and build (avoid planning mistakes, enabling iteration cycles) allowing for precision-engineered spending and seamless workflows.

We will break down why Model-Based Design is more than just a fancy tool; it is a fundamental mindset shift to a single-source model that helps agencies navigate rapid technological change and severe resource shortages.

Tune in on your favorite podcast platform as this discussion reveals how moving to a single-source digital model can optimize every dollar spent, ensuring our communities get the modern, reliable infrastructure they deserve.

View Details

Citizens expect government services to work seamlessly on their phones, and agencies are moving quickly to adapt. But simply extending legacy systems to mobile can leave critical security and usability gaps.

This week on Feds At the Edge, experts from California DMV and SailPoint break down three key lessons for building trusted, modern access.

First, MFA alone is no longer enough. As attackers find ways around one-time codes, organizations are shifting from basic identity checks to stronger, continuous authentication approaches.

Second, "fire-and-forget" permissions create risk. Access must be monitored and adjusted over time as roles and responsibilities change.

Third, what good is a better mousetrap if nobody uses it? Even the best technology fails without adoption. Agencies must engage users, demonstrate value, and make secure tools easy to use.

Tune in on your favorite podcast platform because now is the time to act: evaluate your current systems and identify your gaps, strengthen access, and build the trust needed for successful digital transformation.

View Details

What does a massive county-based state like North Dakota have in common with a compact, town-centered state like Vermont? More than you'd think, and the stakes for their data have never been higher.

This week on Feds At the Edge, experts from North Dakota Information Technology, State of Vermont Agency Digital Services, and Palo Alto explore how states bridge geographical and administrative divides to secure their digital future. Despite stark differences in scale and structure, both faces universal challenges: managing massive data volumes and modernizing legacy systems.

We discuss three approaches that can improve services while reducing costs:

  • Scalable Operations: The benefits of a Joint Security Operations Center (JSOC) for multi-agency coordination.

  • Surface Management: Utilizing external perspectives to identify entry points and address vulnerabilities.

  • Incident Response: Moving past a "head-in-the-sand" mentality to develop actionable plans for when a state gets hit.

Tune in on your favorite podcast platform to learn how effective, team-based operations are helping leaders rise to the occasion and achieve the goal of doing more with less.

View Details

Most practitioners building cybersecure environments know the basics: simplify system procedures, invest in continuous education, and elevate visibility across the network.

But what happens when new mandates are applied to legacy systems? The "bolt-on" approach is often expensive, frustrating, and ineffective.

This week on Feds At the Edge, experts from NETCOM, DARPA, and Axonius discuss how automation, AI, and continuous learning are reshaping cyber defense, and what agencies must do to build security that works.

We examine patching challenges, attack surface reduction, and how AI can help ease "task saturation," along with why visibility and education remain essential.

Tune in on your favorite podcast platform to hear whether modern technology is enough to meet today's security demands.

View Details

Today, we hear how to leverage the much-vaunted AI and ML technologies to make practical cybersecurity improvements for the federal government. The analysis includes comments about setting a base line, prioritizing alerts and a quick dive into the characteristics of Operational Technology (OT).

BASELINE: Signature-based risk analysis has proven to be easy to deceive. Alex Maier from August Schell suggests that the solution is a move to a "behavior" based tool. In other words, see where a user's behavior varies from the norm. If that is the case, then you must know what "typical" is all about and begin by observing typical patterns to discern noticeable differences.

AERTS: Some estimates suggest that a Security Operations Center (SOC) can receive 10,000 alerts a day. It is no wonder operators suffer from "alert fatigue" and miss problems. Rubrik has technology that can establish a risk-based alerting system to filter out low-level concerns.

ELEMENTS OF OT: Mark Hadley of Pacific Northwest National Laboratory describes OT as deterministic. That is to say, given a signal, always produce the same output with a fixed set of rules. Given that understanding, a heighted importance must be given to the value of the specific commands given to OT devices.

The discussion also covered the need for transparency and accountability, as well as the potential risks of AI-based attacks.

View Details

One sensor can generate 1.3 million data points per minute. Now imagine hundreds of them on a single military aircraft. OT powers everything from sensors in Air Force fighter jets to floating ocean buoys, yet applying traditional data management strategies to these systems is anything but simple. While many understand that OT controls physical devices, far fewer grasp the scale, velocity, and complexity of the data these systems generate.

This week on Feds At the Edge, experts from US Coast Guard, US Strategic Command, Army Test and Evaluation Command, and BMC explore practical ways to bring Operational Technology (OT) into modern federal IT architectures, from using analytics tools to extract actionable insights, to adopting platforms that unify data across systems, and training people to use technology effectively.

Tune in on your favorite podcast platform to learn how federal agencies can turn overwhelming OT data into clarity, confidence, and smarter operational decisions.

View Details

As agencies look to modernize healthcare systems, technology leaders face a unique challenge: driving innovation while safeguarding sensitive personal data and meeting strict regulatory requirements.

This week on Feds At the Edge, we hear from two unique perspectives on how to modernize healthcare safely, strategically, and effectively.

Suresh Soundararajan, CIO for the Virginia Department of Health, explains why technology initiatives fail when they aren't aligned with organizational strategy, and why success should be measured through meaningful outcomes like patient satisfaction and reduced processing times, not change for change's sake.

Nasheb Ismaily, Principal Solutions Engineer, Public Sector at Cloudera Government Solutions, introduces the concept of "precision health," showing how predictive analytics can help identify risks earlier, shift care away from costly emergency interventions, and improve long-term outcomes.

Tune in on your favorite podcast platform for this conversation that underscores the importance of shared vision, cultural change, and a deliberate, strategic approach to technology adoption in healthcare.

View Details

All government agencies face the challenge of achieving ambitious IT modernization goals while juggling limited resources and seemingly endless needs.

This week on Feds At the Edge, experts explore practical strategies to make modernization both achievable and cost-effective.

Christine Maii Sakuda, State Chief Information Officer (CIO) and administrator of the Office of Enterprise Technology Services for Hawaii, shares how a dedicated change management advocate and early practitioner engagement can transform digital initiatives, emphasizing that investing in people upfront leads to smoother, more efficient transitions. And Abe Rosloff, Senior Sales Engineer at Datadog, adds that not every system needs to be included in a transition. Understanding priorities, cataloging applications, and involving the team early are key steps to achieving cost-effective modernization.

Tune in on your favorite podcast platform to hear actionable insights that can help your agency modernize IT without breaking the budget.

View Details

Cloud adoption is accelerating, data is exploding, and agencies are under pressure to understand where cloud provider responsibility end, and where theirs begins.

This week on Feds At the Edge, experts from the State of Kansas, GovRAMP, and Palo Alto Networks share practical guidance for navigating today's cloud landscape.

Jeff Maxon, CITO for the State of Kansas, shares how to differentiate between infrastructure and applications and why responsibility shifts to the customer once you move into the application layer.

Michael Gregg, Field CIO at Palo Alto Networks, highlights why configuration isn't the same as security, the importance of continuous compliance testing, and why every organization needs a solid recovery plan.

Tune in on your favorite podcast platform and learn how collaboration, clarity, and continuous improvement drive stronger cloud security.

View Details

What if decades of security headaches could be solved with one framework?

In 2011, FedRAMP was created to end the repetitive, time-consuming security audits across federal agencies, standardizing security to cut costs and accelerate cloud adoption. Fast forward ten years, and state governments faced the same challenges. Enter GovRAMP: a standardized, transparent framework based on NIST 800-53 rev5, designed to bring states together around shared security practices.

This week on Feds At the Edge, data security experts break down the practical steps of implementing compliance, the importance of continuous monitoring, the role of cloud service providers, and why allocating the right resources is critical to protecting sensitive data.

Tony O'Neill, CISO & Chief Risk Officer from the Commonwealth of Massachusetts, noted that a consistent baseline doesn't just save money, it frees leaders to invest in people.

Tune in on your favorite podcast today and discover how GovRAMP is making state-level cybersecurity simpler, smarter, and more resilient.

View Details

Making the transition from on-prem to the multi-cloud can be tough, and the real challenges often emerge long after the migration plan is written.

This week on Feds At the Edge, three experts in the multi-cloud world break down the assumptions, surprises, and security realities organizations face along the way.

Jessica Van Eerde, Chief of Operations for GovRAMP, offers three essential, practical suggestions for anyone considering a move: assessing security compliance, validating support and training needs, and using the "Customer Responsibility Matrix" to ensure your expected cost savings are real. Dan Wilkins, CISO at the Arizona Dept of Economic Security, builds on this advice by recommending organizations define their minimum cloud requirements upfront and run a true gap analysis to compare vendors on more than just marketing claims.

And Nick Peters, Information Security Program Manager, Rubrik, highlights the hidden costs that can surprise even experienced teams.

Tune in on your favorite podcast today, whether you're planning your first cloud migration or refining a multi-cloud strategy, as this episode offers a grounded look at what it really takes to make the transition successfully.

View Details

As technology evolves, so does our understanding of its strengths and weaknesses.

This week on Feds At the Edge, we break down how artificial intelligence is transforming cybersecurity, where it can meaningfully improve defense, and what agencies should consider before deploying it.

LCDR Ian Roessle, Deputy Director, Center for High Assurance Computer Systems at the Naval Research Laboratory, explains why vulnerabilities don't always translate to real risk and emphasizes knowing your systems inside and out. He also notes that AI can introduce new exposures.

Martin Stanley, AI & Cybersecurity Researcher at NIST, outlines the Assessing Risks and Impacts of AI program, which is designed to help leaders validate and secure AI-enabled systems.

Jarrod Vawdrey, Field Chief Data Scientist at Domino Data Lab, discusses how agencies can move toward AI-driven cyber defense by assessing data readiness, isolating high-value targets, and shifting away from static, rules-based tools.

Tune in on your favorite podcast today as we explore practical guidance for deploying AI in cybersecurity while managing the risks it introduces.

View Details

Today, we take a nuanced look at automating cyber risk management.

Let's start with ingress of data. Kemp Jennings-Roach from the DoD understands the concept of having a complete inventory of an agency's data. Still, his experience shows that data coming in from multiple missions, potentially with various classifications, can be challenging.

Combine that with varying kinds of reporting requirements, and you get a process that can overwhelm even the most experienced individuals. His recommendation is to consider a platform approach that can help normalize data, allowing it to be used in a meaningful way.

Matt Goodrich from Diligent expands on some of the benefits of automation. For example, you may have a shortage of talent that can be compensated for with an automated platform. Automation reduces human error and can speed up the time to report.

Goodrich makes a great point about summarizing information. The goal of reviewing logs for anomalies is not to create a report, but to increase speed to action.

Rather than arbitrarily selecting an automated system, Goodrich suggests looking for tools that can integrate with existing systems and align with compliance frameworks, such as FedRAMP and NIST CSF.

View Details

Zero Trust isn't just about defense - it's about unlocking new capabilities across even the most legacy-heavy federal systems.

When agencies move to a Zero Trust Architecture, the benefits go far beyond stronger cybersecurity. Integrating decades-old systems into a Zero Trust framework can actually centralize data, create consistency, and open new paths to modernization.

This week on Feds At the Edge, Sean Phuphanich, Principal Technologist at AWS, explains how synthetic data can safely demonstrate cloud scalability in non-production environments, while Richard Breakiron, Senior Director, Strategic Initiatives, Americas Public Sector, Commvault, offers candid insight into why no single vendor has all the answers. His advice? Collaborate across agencies to tap into shared experience and proven solutions.

Tune in on your favorite podcast today as we explore how Zero Trust can be both a security strategy and a powerful engine for modernization across government. Plus, learn about a free AWS assessment tool that can help your agency gauge its Zero Trust maturity and chart a clear path forward.

View Details

AI promises efficiency and better public service delivery, but how realistic is that promise today?

This week on Feds At the Edge, our panel of experts take a grounded look at what it really takes to implement AI responsibly and effectively across government.

Chris Bunton, CIO, Texas Dept of Agriculture, cautions that past technology shifts - like the move to cloud - often took years to deliver a return on investment, reminding agencies to weigh AI's costs and sustainability.

Natalie Buda Smith, Director of Digital Strategy, Library of Congress, shares how the nation's largest data repository—over 193 petabytes—underscores the need to capture the right data and ensure systems can talk to each other. And Jonathan Alboum, Federal CTO, ServiceNow, stresses that real change starts at the top, with leaders who empower users and drive change through vision and accountability.

Tune in on your favorite podcast today as we explore why strong governance, clear policy, and constant reevaluation are essential to realizing AI's promise in the federal space.

View Details

Implementing Zero Trust in federal environments requires more than technology, it demands a clear strategy for managing and protecting data.

CISA recently updated its Continuous Diagnostics and Mitigation (CDM) Data Model Document (DMD), highlighting the most critical changes without requiring a full review of the entire framework.

This week on Feds At the Edge, our panel of experts unpack some of the expanded concepts and explore some of the challenges and practical strategies for implementing DMD.

Daniel Bane, Supervisory IT Specialist, TSA, highlights the complexity of reporting data from dozens of diverse systems and the tools needed to do it efficiently. While Mark Hadley, Chief Cybersecurity Researcher, Pacific Northwest Labs, explains the limitations posed by privately-owned critical infrastructure. And Brian "Stretch" Meyer, Field Chief Technology Officer, Axonius Federal, offers practical insights on how tool updates can disrupt compliance processes if not carefully managed.

Tune in on your favorite podcast today to gain valuable insights into how agencies can apply the DMD practically, align data strategy with Zero Trust goals, and navigate the complexities of federal environments.

View Details

Artificial intelligence depends on its ability to draw insights from massive datasets, but size alone isn’t the goal.

This week on Feds At the Edge, our panel of experts explore how smarter data management can make AI faster, more efficient, and more reliable by focusing on clean, well-labeled, and right-sized information.

Years ago, scientists dreamed of capturing data from sources as vast as satellites and as precise as atomic sensors. That dream is now reality, and today’s challenge is ensuring that this flood of data is organized and manageable.

Thane Price of Idaho National Laboratory shares how reducing duplicative data and streamlining metadata helps AI learn more effectively. Gulan Shakir from the National Archives and Records Administration discusses how modern cloud infrastructure accelerates data transfer compared to legacy systems. And Cloudera’s Kevin Talbert explains how proper data cataloging, synthetic datasets, and metadata management enhance testing and training for AI models.

View Details

Recent studies have shown how AI agents have expanded the attack surface for Federal agencies.

This week at Feds At the Edge, we’ll explore why fundamentals such as visibility, inventory, runtime, and least-permissive access control, are more critical than ever.

Phishing and security training are good starting points, but developers must learn what tools to use to be able to use AI an appropriate manner.

Rob Roser, Ph.D., CISO at Idaho National Laboratory, highlights the surge in APIs—essential for communication but prime targets for attackers. Stephen Ringo, Senior Solutions Engineer at Akamai, outlines four key defenses for AI-driven data: discovery, posture, runtime protection, and continuous testing.

Tune in on your favorite podcast today as our panel underscores the urgency of integrating API security into comprehensive cybersecurity strategies and recommends programs to test and validate APIs before production deployment.

.

View Details

AIOps, where artificial intelligence meets IT operations.

This week on Feds At the Edge, we explore how AIOps is reshaping how agencies approach software development and system management.

Experts will explore best practices for boosting productivity, from managing legacy systems efficiently to leveraging AI Task Forces to identify high-value use cases.

We will also examine the minimal risk-high impact activities such as utilizing a help desk, which help service the needs of large organizations like the USMC.

We will even touch on managing the changes in code sets, which could be thousands per day, and well beyond human capabilities.

Tune in on your favorite podcast today as our panel underscores the importance of oversight, governance, and transparency when deploying AI-driven systems, ensuring innovation delivers measurable value safely.

View Details

AI is no longer a mystery – it's a powerful tool in your day-to-day toolbox.

This week on Feds At the Edge, we explore how government leaders are putting AI to work to unlock collaboration, streamline reporting, and turn mountains of unstructured data into smarter decisions.

Christie Burris, CDO and Director of GDAC for the North Carolina Department of Information Technology, shares how her team developed North Carolina eLink, their AI-powered platform to help them tackle the challenges of sharing data and analyzing large amounts of data- saving an estimated 415 hours annually. Arti Tangri, Equity Data Lead for the City of San Jose, CA, explains how AI helped make sense of massive amounts of Wi-Fi access point data to show measurable improvements in public wireless service. And Bob Deppisch, VP & General Manager at HEAVY.AI, highlights how advances in analytics, data management, and security are shaping the next wave of AI in government.

Tune in on your favorite podcast today to hear how AI is enabling smarter decisions, better collaboration, and measurable results in government.

View Details

The father of modern management, Peter Drucker, said “If you can measure it, you can manage it.” Nowhere is this more true than in the DOS’s Continuous Monitoring and Risk Scoring program.

This week on Feds At the Edge, CMRS experts explore how advanced technology has enhanced the capabilities of CMRS in defense across the DOD.

Robert Kimball if C5ISR highlights today’s networks are so large, innovations in working at scale have to be employed. Communities must understand the principles of cyber defense to achieve effective defense.

Tune in on your favorite podcast today to hear more on the evolving world of CMRS, the role of AI, and the next steps for strengthening defense through continuous monitoring.

View Details

Can artificial intelligence make federal decisions smarter?

Artificial intelligence is transforming how government agencies train, manage infrastructure, and make critical choices, but with that power comes high-stakes challenges.

This week on Feds At The Edge, experts cut through the hype to explore AI’s real challenges and opportunities for federal leaders. Joe Cheng, CTO for Posit, highlights the core problem: while getting answers from AI is easy, verifying those answers is much harder. Jaime Fitzgibbon, AI/ML Portfolio at DIU, underscores that when it comes to combat decisions, human judgment must remain at the center. And Chris Ritter, Division Director of Scientific Computing & AI and Director of the Digital Innovation Center of Excellence, Idaho National Laboratory, likens searching for reliable federal data to finding a needle in a haystack, and shares how open-source verification can help.

AI’s potential is undeniable, but its success in government depends on trust, transparency, and human judgment.

Listen now on your favorite podcast platform to learn how federal leaders can harness this powerful tool, without losing sight of its limits.

View Details

AI in software development sounds like a dream, faster coding, cleaner refactoring, and technical reports that actually make sense to stakeholders. But, what's the bad news in the classic good news/bad news scenario? Poisoned training data, compliance risks, and systems that are brittle and will not scale.

This week on Feds At The Edge, Alex Gromadzki, Assistant Director of Data Science at US GAO, and Steven Toy, Senior Director, Cloud Infrastructure for ICF, unpack the opportunities and pitfalls of generative AI in federal software development. From source-citing AI to data security in the software lifecycle, they reveal why small, testable use cases may be the smartest way forward.

Listen now on your favorite podcast platform to hear how federal leaders can balance innovation with responsibility as AI reshapes the software development life cycle.

View Details

A looming deadline always gets attention, and for DoD suppliers, the clock is ticking. On October 1, 2025, the Department of Defense will begin including Cybersecurity Maturity Model (CMMC) certification requirements in new contracts.

This week on Feds At The Edge, four leading experts cut through the complexity and share practical guidance to help you start, or finish, your CMMC journey.

Sean Frazier, Federal Chief Security Officer for Okta, explains why “Know Thy Data” is the key to applying the right level of security where it matters most. Alan Dinerman, PhD, Senior Manager, Cyber Strategy, Policy, and Privacy at Mitre, puts CMMC in context with other cybersecurity standards, noting its focus on Controlled Unclassified Information. And Jeff Adorno, Field Chief Compliance Officer at ZScaler, warns of risks in the AI era, where sensitive data can unintentionally “leak” into Large Language Models. The panel as a whole highlights how aligning with existing frameworks and using current technologies can demonstrate progress to auditors and ease compliance.

Listen now on your favorite podcast platform because whether you’re deep into compliance or just getting started, this conversation will help you navigate the evolving landscape of CMMC and beyond.

View Details

Migrating federal systems to the cloud is never simple - but Michael Howard has lived it. This week on Feds At The Edge, we get the unvarnished truth about making the difficult transition from federal on-prem networks to the cloud.

Michael Howard, Engineering and Digital Transformation Chief at TRANSCOM, compares available tools, highlights the shift from waterfall to agile development, and explains why quarterly updates no longer cut it.

Howard explores the benefits of containerized workloads for portability, the importance of CSP-specific training, and how his team built a zero-trust-ready cloud environment.

Listen now on your favorite podcast platform to learn how Kubernetes, DevSecOps, and cloud-native tools can boost efficiency, security, and adaptability.

View Details

Here is the link to the free webinar on August 27, 2025 2pm EDT

Empowering Agencies with Optimized IT Operations preview

Cybersecurity teams are facing a “perfect storm” - more attacks, fewer defenders, and outdated infrastructure.

This week on Feds At The Edge, we offer a sneak peek into an upcoming webinar that will teach you how to truly see what’s happening on your network- moving beyond basic monitoring to actionable observation.

Brian Chamberlain, Account Executive, USMC/USN, SolarWinds, Chamberlain breaks down why simple monitoring isn’t enough. Without pinpointing blind spots or knowing where to start, agencies waste time, increase risk, and rack up costs. He explores: Automation: Threats move too fast for humans to manage alone. Hierarchy: How to prioritize what matters most. Compliance: Practical takes on NIST 800-207, FIPS 140-2, and Common Criteria. AI in Action: How artificial intelligence can reveal inefficiencies and free humans to focus on decisions.

View Details

Everyone knows it’s not just about having data, it’s about having the right data.

This week on Feds At The Edge, we’re diving into how federal and state agencies are transforming raw data into trusted, actionable insights that drive better outcomes.

Our expert panel breaks down how data modeling is bridging the gap between collection and impact:

  • Natalie Evans Harris, CDO for the State of Maryland, reveals how trust begins with engaging staff, educating users, and gathering feedback.

  • Marcus Thornton, Deputy CDO for the Commonwealth of Virginia, shares how a straightforward MOU can streamline data sharing and clarify roles.

  • Andrew McGovern, Sr. Principal Consultant at Quest Public Sector, explores how adaptable data models support compliance and set the stage for automation.

Whether you're a policymaker, data professional, or IT leader, this episode is packed with real-world strategies to unlock the full value of your data.

Listen now on your favorite podcast platform and learn how public sector leaders are using data modeling to boost efficiency, build trust, and maximize ROI.

View Details

When new technology is introduced, people may not take advantage of the advanced capabilities. The transition to a Zero Trust methodology is causing federal leaders to abandon traditional methods of compliance.

Keith Busby from CMS sums up the problem nicely. Some of the systems he supports serves the needs of 150 million Americans. If they don’t leverage the capabilities of the cloud, then they will never be able to move to a much more secure Zero Trust Architecture.

Shane Barney from USCIS provides even more shocking numbers. He casually mentions on his log information today is as high as 20TB!

In order to finance this transformation, Sanjay Koyani from the Department of Labor suggests that agencies take advantage of the Technology Modernization Fund. In fact, they got 15 million from the TMF to enable their digital transformation.

Today’s discussion provides ways to overcome the challenges of massive data sets by leveraging innovation in cloud management tools.

View Details

Any individual would know keeping operating systems up to date is a no-brainer when it comes to cybersecurity. But what happens when you’re managing an estimated seven million devices? This is the challenge for the Department of Defense.

This week on Feds At The Edge, we unpack the concept of applying Security Technical Implementation Guides, otherwise known as STIG, crucial tools for configuration management.

Dr. Kurt Jarvis, Technical Director for Cyber for the Air Force Sustainment Center, explains why each environment's unique risk profile makes STIG essential for balancing security and usability. While Brian Hajost, COO at SteelCloud, highlights the challenge of automating manual controls.

Tune in on your favorite podcast platform today for expert insights on balancing security with usability, maintaining continuous compliance, and how AI and large language models could reshape the future of STIG implementation.

ss.

View Details

Fifteen years ago, “continuous monitoring” was as simple as watching a single server down the hall. Today, it’s a high-stakes mission across sprawling hybrid networks being bombarded with data and under constant security threats.

This week on Feds At The Edge, we explore how federal agencies are modernizing the once-simple concept of Continuous Diagnostics and Mitigation (CDM) to protect complex, data-heavy systems.

Jason Ralph, Director of Security Operations for the Department of Labor, shares candid insights on deploying new CDM tools, highlighting both their potential and the unintended side effects on legacy systems.

Our panel tackles real-world challenges like monitoring encrypted traffic in a Zero Trust environment, the need for stable network foundations, and how peer community groups can accelerate success.

Tune in on your favorite podcast platform today to hear practical lessons, hard-won strategies, and fresh perspectives on staying ahead in the federal cyber landscape.

View Details

As cyber threats grow more sophisticated, federal agencies need security that can think on its feet.

This week on Feds At The Edge, we explore how agencies are evolving toward Zero Trust by implementing dynamic security—a flexible approach that adjusts access and authentication in real time based on context and behavior.

Justin Chin, Director of the Government Solutions Segment at Ping Identity, opens with a relatable example: when your bank flags suspicious login activity and adds a second layer of authentication. That adaptive friction is dynamic security in action.

Federal agencies face unique challenges based on their IT architectures. Paul Blahusch, CISO at Dept of Labor, explains how a centralized system allows broad, consistent policy enforcement. In contrast, Elizabeth Schweinsberg, Sr. Technical Advisor for CMS, shares how her agency’s federated model requires a more tailored approach to dynamic security.

Tune in on your favorite podcast platform today for insights into the different paths agencies are taking, why enterprise structure matters, and how collaboration is key to building secure, adaptive systems that support the Zero Trust journey.

=

View Details

Everyone wants a secure network, but how do you prove it?

This week on Feds At The Edge, we speak with cybersecurity experts to discuss how to establish meaningful cybersecurity metrics to document that security.

LtCol Natalie Lamb, Cybersecurity Division OIC, Cyberspace Operations Group in the USMC, and Brian "Stretch" Meyer, Sr. Director of Engineering at Axonius Federal, breaks down three essential areas for leaders to focus on:

  1. Aligning Investments - With limited time and funding, agencies must prioritize cybersecurity efforts that support their mission.

  2. Knowing Your Network - From cloud sprawl to remote devices, your attack surface is growing. Understanding what you own and protect is the foundation of effective security.

  3. Setting Priorities - “Ya can’t measure what you can’t see.” Prioritize detection to make your metrics meaningful. We dive into two key performance indicators:

· MTTD (Mean Time to Detect) – How quickly do you identify a threat?

· MTTR (Mean Time to Remediate) – Once you detect it, how fast can you fix it?

Tune in on your favorite podcast platform today to learn why aligning your security metrics with mission outcomes isn’t just good practice, it’s essential for long-term resilience.

View Details

Everyone knows automation is powerful, but it’s also a double-edged sword.

This week on Feds At The Edge, we speak with cybersecurity experts who share how to securely align automation with Zero Trust principles. We spend the hour diving to importance of shared responsibility models, protecting critical surfaces, and using automation to enhance observability and control, especially in cloud environments.

Michael Hardee, Chief Architect for Red Hat, shares insights on how automation can reduce social engineering risks by eliminating human override. While Don Yeske, Director, National Security Cyber Division at DHS, highlights how AI can uncover vulnerabilities in outdated enterprise architectures, including a recent zero-day attack.

Both experts emphasize the “human-in-the-loop" approach, agreeing that automation should augment, not replace, human insight. As Michael Hardee reminds us, “automation is not a license for us to check out.”

Tune in on your favorite podcast platform today!

View Details

The theme of the current administration is to do more with less. Today, we hear from experts on how they have assisted in implementing Zero Trust by leveraging all resources possible.

We know implementing Zero Trust is a continuous process; David Bottom from the SEC provides guidelines on what to review constantly. He suggests focusing on decreasing privileges, patching systems, and learning how to extract meaningful signals from the flood of data entering the federal government.

None of this can be done without cooperation across the agency. As an example of working with others, David Bottom references the SEC's EDGAR (Electronic Data Gathering, Analysis, and Retrieval).

Jennifer Franks, GAO, recommends that listeners take advantage of federal guidelines to spend as little as possible while meeting compliance goals. For example, CISA, OMB, and NIST all offer guidance in implementation. She has an excellent eight-word summary of Zero Trust: right users, proper access, at the right time.

Many agencies are understaffed. As a result, one way to meet goals is to leverage the right tools. Brian "Stretch" Meyers believes the most "bang for the buck" will be achieved by using tools to establish visibility. From there, one can identify key items to reach compliance.

Zero Trust is an initiative that is here to stay. Listen to the podcast to get ideas on how to optimize the staff and resources at hand.

View Details

One of the greatest promises of modern technology is its ability to streamline complex, paper-based systems - cutting costs, improving access, and eliminating waste, fraud, and abuse.

These complicated systems are often the biproduct of a complicated network, like the ones you find in the Department of Labor which are handling unemployment insurance claims fifty different ways in fifty different states. Or how military members and their families often have to handle an issue when they are thousands of miles from home and might not easily have access.

This week on Feds At The Edge, we explore how innovative leaders are leveraging technology to streamline these critical processes to meet their unique and specific needs.

Akanksha Sharma, Director of Digital Transformation for Dept of Labor, shares how her team built a unified identity verification system that cuts through the complexity of each state’s unemployment claim systems—reducing fraud and improving access. Meanwhile, Kevin Adler, Digital Transformation Advisor at ServiceNow, discusses how digital tools are empowering military families to easily submit claims and work orders, replacing slow, manual methods with mobile-first efficiency.

Tune in on your favorite podcasting platform today to hear how smart technology can create seamless systems, empower users, and transform public services for the better.

View Details

Automation is everywhere—but is it helping us, or quietly introducing new risks?

This week on Feds At The Edge we share a special three-part series that explores the evolving role of automation in cybersecurity- from its promise to its pitfalls. In session one, we lay the groundwork with a high-level view of automation’s true purpose and challenges. We follow up with session two- digging into application security and the critical role of cloud telemetry. And we wrap up this hour with insights into threat intelligence, risk visability ahd how to stay ahead of evolving threats.

Featuring experts from the Department of Labor, DOD, Peraton, Checkmarx and Team Cymru, tune in on your favorite podcasting platform to hear our grounded, real-world look at what automation means today- and where its headed.

View Details

In recent years, the Department of Defense has been rethinking how it approaches communications technology—shifting from traditional, insular solutions to embracing innovation from the commercial sector. While off-the-shelf cellular devices aren’t suitable for the battlefield, the underlying technologies powering 5G and emerging 6G networks are becoming too valuable to ignore.

This week on Feds At The Edge, we explore how the military can harness advanced commercial technologies like 5G, 6G, and AI to enhance battlefield operations. The discussion centers on three critical considerations:

  • Edge Computing for Resilience: In combat zones where communication links are vulnerable to disruption, processing data at the edge is essential.

  • Agile Networks for Rapid Response: Battlefield conditions evolve quickly. Flexible standards in 5G/6G—especially through tools like 3GPP’s Network Data Analytics Function—enable self-optimizing, reconfigurable networks.

  • Upgrades Without the Overhead: Upgrading physical hardware in remote or high-risk environments (like submarines) can be difficult, but software-based systems offer promising alternatives.

View Details

The 2023 FBI Internet Crime Report reveals that nearly 21% of ransomware attacks targeted the healthcare and public health sectors—making them the top victims.

This week on Feds At The Edge, we explore how agencies can defend against these growing threats.

Benjamin Koshy, Chief Information Security Officer and Director, Division of Information Security of Indian Health Service, explains the unique identity management challenge in healthcare: balancing open patient access with strict data protection.

Keith Busby, Acting CISO at CMS, outlines how to go beyond Zero Trust with real-world risk assessments and robust incident response plans - not just a three-ring binder gathering dust on a shelf. And Alec Lizanetz, Identity Protection Specialist from CrowdStrike, emphasizes the importance of prioritizing threats and using frameworks like CISA’s to respond efficiently.

Tune in on your favorite podcasting platform today to hear practical, high-impact strategies to secure critical systems and protect patient care, perfect for healthcare leaders who must protect both data and lives.

View Details

Today’s modern network has placed identity management in the forefront to manage a plethora of landscapes – on and off prem, public and private, hybrid, and the new kid on the block, alt-clouds.

This week on Feds At The Edge, we explore how the Defense Information Systems Agency (DISA) is leading the charge in modern identity management, once a backwater concept, to center stage, with its ambitious program, Thunderdome.

Chris Pymm, Portfolio Manager, Zero Trust & Division Chief for ID7 at DISA, shares how Thunderdome spans 50 sites and 12,000 users, automating identity controls to outpace threats like lateral movement. We also hear from Quest Software Public Sector cybersecurity expert Chris Roberts, who breaks identity management down to its core: know the user, know the device, know the behavior.

Tune in on your favorite podcasting platform today to hear how DISA is redefining identity for today’s distributed networks—and what your agency can take from their playbook.

View Details

“Shift Left” is a popular phrase in software development used to represent the idea of prioritizing certain tasks earlier in the life cycle process to avoid or easily identify potential problems before it moves on.

This week on Feds At The Edge, we ask the question – What does it take and what does it really mean to “shift left.” Our expert guests share practical insights on tackling the complex realities of modern software design and deployment.

Amit Madan, Chief Architect, Center for Enterprise Modernization at Mitre, recommends preparing for potential gaps when integrating legacy systems with modern, cloud-based solutions—and ensuring clear delineation of security responsibilities between agencies and cloud providers.

Eoghan Casey, Field CTO for Own, offers a compelling take on risk: sometimes, staying put poses more danger than moving forward. He highlights the need for early collaboration with security professionals and stresses the value of cross-agency knowledge sharing to foster a culture of security grounded in risk management and compliance.

Tune in on your favorite podcasting platform today to learn how federal teams are embedding security into every step of the software lifecycle—right from the start.

View Details

As federal agencies move toward greater efficiency, cloud adoption is making the transition from optional to essential. But Federal leaders know not every system is a good candidate.

This week on Feds At The Edge, our expert guests share what agencies will need to know in order to identify which of their systems can move to the cloud and which systems are best suited to remain on-prem.

David Updike, CTO and Director for the Office of Digital Services & Technology Architecture at EPA, explains how cost frameworks reveal trade-offs between flexibility and savings, and the importance of AI in forecasting scalability.

India Baboola, Chief, Systems Engineering Division, Office of the Chief Information Officer (OCIO) for ICE, emphasizes that even the smoothest cloud transitions face a major hurdle: keeping databases synchronized and data validated throughout migration.

Tune in on your favorite podcasting platform today to hear practical insights on how AI, machine learning, and cloud-native apps are shaping the next wave of federal cloud strategy.

View Details

Zero Trust is more than a technology shift, it’s a cultural one.

This week on Feds At The Edge, our expert guests explore how agencies can successfully implement Zero Trust by focusing on people, leveraging AI, and understanding risk at every level.

With over 600,000 employees and 1,000 applications, the USPS faced a massive challenge. Heather Dyer, VP & Chief Information Security Officer for the USPS, shares how clear communication, continuous monitoring, and behavioral insights were key to driving adoption. Joined by Prem Jadhwani, CTO at Government Acquisitions Inc, the discussion dives into understanding risk, managing access to critical assets, and integrating Zero Trust with cloud environments and external partners.

Tune in on your favorite podcasting platform today to hear practical insights and proven strategies to tackle Zero Trust in a complex environment.

View Details

The cloud offers incredible potential, are you making the most of it?

This week on Feds At The Edge, our expert guests explore three key strategies for utilizing AI to optimize potential, lighten workloads and ensure security in the hybrid and cloud work landscape.

AI for Smarter Cloud Management: Kevin Walsh, Director, Information Technology and Cybersecurity Team at GAO, suggests turning your focus on what we’ve learned from past use cases, especially for those who are overwhelmed with the idea of where to even begin their integration journey.

AI-Powered Training for Cloud Optimization: Sam O'Daniel, President & CEO for TVAR Solutions, proposes if AI can generate summaries, why not use it to create dynamic, continuously updated training materials for cloud optimization?

Balancing Cost and Performance: Noell Rebelez, Cloud Services Program Manager at the Department of Labor, highlights the importance of cost analysis - especially around GPU expenses - to ensure cloud investments align with your agency’s mission.

Tune in on your favorite podcasting platform today as we take a step back in this rapidly changing federal tech landscape and explore actionable insights to help you maximize AI and cloud potential.

d.

View Details

Digital transformation has been a federal buzzword for years, but what’s the first step in making it a reality? It all starts with knowing what’s on your network and being able to monitor it before and during a transition.

This week on Feds At the Edge, our expert guests take a deep dive into the future of network monitoring and digital transformation.

Tom Gilmore, Enterprise Data Architect in the USMC, drops a staggering statistic: in just 2.5 years, over 15,000 applications were built and deployed across the Marine Corps—many of which are likely duplicates. This explosion of tools raises the question: how do we manage this sprawl effectively?

Joshua Stageberg, Vice President of Product at SolarWind, dives into the exponential growth of network monitoring tools, cautioning against "tool sprawl" and the siloed observability it creates. Instead, he advocates for a unified, single-pane view as the key to true modernization, offering not just insights into apps and data, but a roadmap for optimizing computing and operational efficiency.

Tune in on your favorite podcasting platform today for valuable lessons on collaborating with operations teams, addressing their pain points, and using observability to drive more effective and efficient digital transformation.

View Details

Everyone is trying to unlock Artificial Intelligence's promise. We have seen generative AI tricks that can summarize long documents in a flash, which is substantially different from the requirements of serious federal research.

Today, we examined some challenges scientific communities experience in applying AI. Quentin Kerilman from the PNN labs throws some icy water on AI enthusiasts when he cautions that using AI for many sensitive applications has no framework. Leaders must use their best judgment when including data sets in projects.

Ramesh Menon from the DIA warns that careful data collection must still be used. For example, one must use fair, unbiased data. Is the AI appropriately documented? Further, a scientist will always need multiple data modalities. When used in AI, it needs to be appropriately tagged.

Medical data has much theoretical value from AI. But this is the exact data that has double and triple protection. What about leaks and backdoors?

Despite all the challenges presented, transparency, human oversight, and collaboration were emphasized to ensure AI's practical and responsible use.

View Details

When the Federal Chief Data Officer (CDO) role was first introduced, simply knowing where data was stored and how to secure it was a major accomplishment. Today, CDOs are expected to be strategic leaders, driving data-driven decision-making across federal agencies. But how can they successfully make this transition?

This week on Feds At the Edge, our expert guests provide a roadmap for CDOs looking to expand their influence. Arjuna Rivera, Senior Solutions Engineer at Atlassian, kicks off the discussion by outlining seven key considerations for obtaining actionable, high-quality data—emphasizing the importance of clean, unbiased data, capacity management, and data mining. He also highlights the power of visualization and predictive modeling in uncovering critical insights.

Jiashen You, CDO for U.S. Equal Employment Opportunity Commission, then takes the conversation further, exploring how CDOs can collaborate across agencies to foster a data-driven culture. He shares insights on working closely with Chief AI Officers and introduces the Business of Data Working Group—a vital initiative helping federal data leaders tackle shared challenges and implement effective solutions.

Join us for an insightful conversation on the evolving role of CDOs and the strategies they need to lead with impact.

View Details

Despite the official launch of 5G networks in 2018, their full potential for federal applications has yet to be realized.

This week on Feds At the Edge, we explore the value of a mature 5G network and the groundbreaking possibilities of its next evolution.

Sal D'Itri, Chairman of National Spectrum Consortium, introduces the concept of a “network in a box,” an on-demand, scalable solution that enables rapid adaptation to changing workloads.

Steve Vogelsang, CTO Federal at Nokia Federal Solutions, discusses the need for better device ecosystems, the potential for 5G in emergency services, and the importance of interoperability and resilience in large, geographically dispersed networks.

One of the most exciting discussions revolves around Non-Terrestrial Networks (NTN)—a game-changing application that leverages satellite connectivity to provide emergency communications in remote areas.

Andy Greig, President, North America for Druid Software, sheds light on why, despite seven years of development, the device ecosystem still struggles to fully capitalize on 5G’s potential. Finally, our panelists offer insights into the future of 6G, the next step in high-speed, flexible communications.

Tune in now on your favorite podcasting platform as we uncover the challenges, innovations, and future possibilities of 5G and beyond!

of 5G.

View Details

With cyberthreats on constant rise, Federal Leaders consider what role automation can play in managing cloud involvement and best practices to ensure their commitment to securing the nation’s data.

This week on Feds At the Edge, we explore the role of AI, governance, and collaboration in strengthening security and improving capabilities and data security.

Joseph Ronzio, Deputy Chief Health Technology Officer, Veterans Health Administration, talks about the risks of blind patching and the benefits of a hybrid approach—combining automation with manual oversight.

Brian "Stretch" Meyer, Sr. Director of Engineering, Axonius Federal, sheds light on compliance challenges, the importance of visibility and control in cloud security, and the disconnect between regulations and engineering teams.

Tune in now on your favorite podcasting platform for actionable insights on modernizing federal cloud security.

View Details

Despite federal mandates requiring every agency to have a disaster recovery plan, 6% of the federal government still lacks one entirely.

This week on Feds At the Edge, we explore proven strategies for building effective backup plans and provide timely advice for organizations with basic or intermediary recovery plans looking to enhance their preparedness. We’ll focus on the key pillars of disaster recovery- planning, communication, and continuous updates.

Tommy Baril, Assistant Director, Defense Capabilities and Management Team, for GAO, highlights the need for synchronized disaster recovery plans across federal agencies, stressing strategic communication and role clarity.

Kashif Ansari, Senior Director of Sales Engineering, Commvault, discusses the role of AI in accelerating system recovery, helping identify compromised segments faster than human intervention.

Tune in now on your favorite podcasting platform to uncover the critical distinction between IT disaster recovery and cyber resilience, and gain actionable insights to strengthen your organization’s readiness.

View Details

While the ability to transfer records between hospitals and other medical systems offers significant benefits, it also introduces unique challenges and risk for safeguarding Healthcare IT.

This week on Feds At the Edge, federal leaders examine three areas of concern:

interoperability

unique aspects of the attack surface

the impact of IoT devices.

Jennifer Franks, Director, Center for Enhanced Cybersecurity for GAO, highlights reports of rising cyber threats due to medical data interconnectivity and the need to secure legacy systems, especially since medical data remains unchanged over time.

Joe Ronzio, Deputy Chief Health Technology Officer, Veterans Health Administration, shares the difficulties of managing medical device inventories across 170+ hospitals and highlights how upgrading encryption systems, like FIPS 140, can introduce vulnerabilities.

Tune in on your favorite podcasting platform now to learn about how healthcare organizations can navigate these challenges and strengthen their cybersecurity posture.

\

View Details

When the cloud was first introduced to the Federal Government, their implementation had a “lift and shift” approach, essentially moving servers from one location to another. But cloud technology has matured into a complex ecosystem spanning public, private, and hybrid environments – creating distinct management challenges.

This week on Feds At the Edge, federal leaders offer their suggestions on managing this ever-evolving and complex landscape, with a focus on training, understanding data and leveraging cloud functions.

Dr. Gregg Bailey, Deputy Chief Information Officer in the Office of the CIO for the US Census Bureau underscores the importance of recognizing data management in a hybrid cloud is different, and suggests training on native cloud functions to leverage the new technologies may be a path of success.

Kristin Ruiz, Deputy Assistant Administrator, Deputy CIO for TSA, keeps us focused on security implementation with zero trust principles and strong data governance.

Tune in on your favorite podcasting platform now to hear what they have to say, and how with the proper security controls, AI has the potential to enable improved management of these complex cloud environments.

View Details

Protecting operational technology (OT) environments is more complex than ever, requiring precise inventory, continuous monitoring, and strong IT-OT collaboration.

This week on Feds At the Edge, our expert panel unpacks the key cybersecurity challenges operators face in securing their OT systems.

Anthony J. DiPietro, Technical Director, Defense Critical Infrastructure Division for NSA, underscores the importance of maintaining an accurate inventory, especially in remote environments where “ghost” assets can appear unnoticed.

We’ll discuss how continuous monitoring helps mitigate these risks and why traditional IT security methods, like sandboxes and automatic updates, don’t always work for OT systems.

We also explore the evolving role of AI and Machine learning in OT security, workforce development, and the ever-growing threats posed by interconnected IoT and OT networks.

Tune in on your favorite podcast platform for expert insights on fortifying OT environments against emerging cyber threats.

View Details

Here is our final. Playing on the drama a bit.

In healthcare, every second counts, and Artificial Intelligence is transforming how data is analyzed to save lives. But when critical decisions hinge on AI, ethics, accountability, and trust become non-negotiable.

This week on Feds At the Edge, dive into the complexities for applying AI in healthcare.

Joe Ronzio, Deputy Chief Health Technology Officer for Veterans Health Administration, shares insights on the importance of rigorous human oversight, traceable training data, and recognizing bias in AI systems.

We also tackle the tough questions:

How do we secure medical data?

What role does encryption and governance play?

Don’t miss this compelling conversation.

View Details

In an era marked by economic uncertainty, political shifts, and the rise of remote work, federal agencies face new challenges in maintaining a thriving workforce. Balancing productivity with employee well-being is no longer optional—it’s essential.

This week on Feds At the Edge, we dive into how federal leaders can create scalable, personalized, and sustainable strategies to support their teams’ growth and mental health.

Our guest, Matisha Montgomery, Chief Learning Officer at HUD, shares groundbreaking insights on career development. She challenges the traditional “climbing the ladder” mindset, encouraging professionals to leverage transferable skills for lateral moves that lead to long-term success.

We also explore the importance of durable skills—adaptability, empathy, and leadership—that are critical in today’s workforce. Hear why it’s time to rethink conventional leadership methods and embrace new approaches to foster a resilient, connected, and effective team.

Tune in on your favorite podcast platform for actionable insights from our experts, and discover how federal leaders can navigate the complexities of the modern workplace.

View Details

This week on Feds At the Edge, we dive into the evolution of the Cybersecurity and Infrastructure Agency's Continuous Diagnostics and Mitigation (CDM) program in addressing the growing cyber-attack surface.

Hemant Baidwan, CISO for DHS, OCIO, noted that Continuous Diagnostics and Mitigation is a comprehensive suite of tools and policies, with a key focus on understanding the attack surface and ensuring high data quality during deployment.

John Schneider, Senior Systems Engineer, Axonius Federal, discussed the challenges inherent in managing IoT and OT devices for federal agencies, stressing interoperability and automation as best practices.

Tune in on your favorite podcasting platform as we discuss the critical role of partnerships and inter-agency collaboration to enhance cybersecurity postures.

= = =

View Details

The U.S. healthcare system, which includes roughly 200 federal hospitals, are constantly at risk for or under cyber-attack.

This week on Feds-At-The Edge we explore ways to improve security through basic controls like software updates and patching, with the conversation quickly turning to the importance of practical strategy.

Developing a good data inventory: Full of IoT devices? Learn what to include for your expanded attack surface

Human Interaction: Learn the critical role humans play amid the new promises of AI

Contingency Plans: If your agency was attacked today with ransomware, would you be able to identify your critical data?

View Details

Managing vast amounts of data, reducing alert fatigue, and improving threat detection can all be accomplished with automation.

This week on Feds At the Edge, we have three experts in automating cybersecurity response to provide guidance on best practices to deploy automation. They highlighted the need to establish a valid baseline for expected network behavior to identify deviations effectively, reducing false positives.

Bob Costello, CIO at CISA, stressed keeping humans involved in the process, citing a recent incident where AI breached an organization, bypassed security features by defeating automation.

Richard LaTulip, Field Chief Information Security Officer, Recorded Future, addressed resistance to AI in cybersecurity, warning that the overwhelming volume of attacks makes proper automation essential for staying competitive.

Tune in on your favorite podcasting platform as we discuss how automation is essential but must be applied with caution and human oversight to ensure robust defense mechanisms.

View Details

SaaS (Software as a Service) applications, due to their ease of launch and proliferation, have created a “perfect storm” for attackers, and a significant challenge for cybersecurity professionals. Organizations with over 1,000 employees typically use 150+ SaaS applications, often unmanaged, which expands the attack surface and poses a unique threat to entities like the federal government.

This week on Feds At the Edge, we discuss where the threats may lie and give practical information on attempting to control this new threat vector.

Mark Canter, CISO at US GAO, highlights the widespread lack of understanding about where data is used, emphasizing the importance of good data management practices. AI can play a pivotal role in systematically addressing this issue.

Tune in on your favorite podcasting platform as we explore why organizations should maintain accurate inventories of SaaS applications, identifying and managing shadow SaaS apps, and implementing robust governance practices to secure and optimize their SaaS ecosystems.

View Details

Malicious actors are always looking for the “Easy Button” when it comes to breaching your system.

This week on Feds At the Edge, we are revisiting our conversation on looking at the protection of Operational Technology (OT), critical hardware on premises. Traditionally separated from IT systems by air gaps, OT is now increasingly managed by IT departments due to the convergence of IT and OT.

Few realize that OT has federal compliance regulations, just like IT. The real issue, should an OT systems administrator have to do repetitive work to comply with IT mandates? Marty Edwards, Deputy CTO, OT/IoT from

Tenable, noted that he has seen up to 80% similarity between IT and OT compliance standards, prompting efforts to reduce redundancy.

View Details

This week on Feds-At-The Edge we explore AI used as a strategic tool, focused on risk mitigation, applications, and continuous user feedback.

Risk Mitigation: Risks vary by application. Luke Keller, Chief Innovation Officer at US Census bureau, highlighted using NIST guidelines, including bias reduction frameworks, to ensure ethical and accurate AI deployment. High-quality, diverse datasets are essential.

Use Cases: Start small with proofs of concept to test limitations and risks. Ryan Simpson, Engineering Chief Technologist for the Public Sector for NVIDIA, recommended tools like Retrieval-Augmented Generation to develop use cases which work with limited data and are easy to evaluate. Early wins can allay some fears and can build confidence.

User Feedback: Gathering user input during small test cases is crucial for refining and finding practical applications of AI in federal settings.

Tune in on your favorite podcasting platform as we explore strategic, iterative approaches that foster safe and effective AI implementation.

ns.

View Details

AI is just another tool in the technology market, only becoming a powerful resource when agencies learn how to best utilize it to reach mission goals.

This week on Feds-At-The Edge we explore several insights on deploying AI effectively for the federal government landscape.

Caroline Carusone, Deputy CIO for NRC, discusses AI’s potential in identifying security risks and solving complex engineering challenges, like improving atomic reactor designs.

Luke Keller, Chief Innovation Officer at the US Census Bureau, explains AI's role in handling massive datasets, enhancing earth observation for accurate population counting, automating data ingestion, and metadata classification.

And Kurt Steege, CTO for ThunderCat Technology, introduces the concept of "multimodal AI," which processes data in multiple formats, broadening its utility.

Tune in on your favorite podcasting platform as the panelists stress the importance of reliable data, experimentation to explore AI's capabilities and limits, and defining specific use cases to use AI responsibly. They emphasized a strategic, ethical, and well-managed approach to AI deployment in federal agencies.

View Details

When you enter the world of software as a service (SaaS), you can get lulled into a false sense of security. After all, pioneers in SaaS had logos that explicitly stated, “No more software.” You could almost think your responsibility for data and security was over.

Unfortunately, it is not that easy. Agencies must manage user access and data protection.

Today’s discussion details that process from Eoghan Casey, from Own Company.

Eoghan Casey starts with data visibility—knowing what data is sensitive and what is not. This directly feeds into the concept of Zero Trust.

While making a backup of data seems unambiguous, it is not. User error can cause an administration to have to restore from backup. Has all the data been compromised? Which data should be recovered?

If your agency gets hit with ransomware, this ability to restore can allow leaders to bring systems up in a timely manner without having to pay a ransom.

Taking recovery further, systems should be tested annually to see what time it takes to recover.

Eoghan Casey also stressed the importance of continuous monitoring, backup strategies, and zero-trust principles. He predicted increased use of AI and machine learning in SaaS environments to enhance efficiency and security while warning of growing threats from cloud-conscious cyberattacks

View Details

If you’ve tuned before then you’ve heard the three magic words; People, process, technology. While technology often takes the spotlight, there’s a reason why “people” come first.

This week on Feds-At-The Edge we explore the cultural shifts agencies are prioritizing to achieve zero trust.

Jothi Dugar, CISO at NIH’s Center for Information Technology emphasizes the age-old advice, communication is key. Federal leaders should speak a language all stakeholders understand, and responsibility should be placed in the hands of the many and not the hands of the select few.

We’ll also explore the benefits of collaborative group environments where everyone contributes to change.

Matthew Posid, a Principal & CSO with KPMG shares how real-world zero trust examples can help technical leaders buy-in.

Tune in on your favorite podcasting platform to hear more about the importance of continuous learning, experimentation, and collaboration to navigate these complexities.

View Details

In today’s data-driven world, network systems are under immense pressure to handle increasing loads of data while staying compliant in a rapidly evolving landscape. How can agencies effectively secure their systems when every little nook and cranny requires oversight?

This week on Feds-At-The Edge we explore how microsegmentation is emerging as a vital strategy for agencies working toward a robust zero-trust architecture.

Rob Thorne, CISO of U.S. Immigration and Customs Enforcement, highlights how complex systems often have hidden connections unknown to administrators, which micro-segmentation can reveal.

We will also dive into how machine learning and AI can be utilized to identify exactly what is on your network so you can ensure end-to-end security.

View Details

The concept of "continuous" protection, inspired by continuous software development, is gaining traction among federal tech leaders in response to rising cyber-attacks.

This week on Feds At the Edge, we sit down with subject matter experts who provide guidance for transitioning from the basic “Authority to Operate” snapshot in time to a “Continuous Authority to Operate.”

Col Bryan A Eovito, Commanding Officer, for the Marine Corps Cyber Operations Group, emphasized the value of establishing a baseline for comparison to detect discrepancies, warning that low-code/no-code solutions have vulnerabilities too.

Major Ben Hunter, Deputy Chief Information Security Officer for US Army Software Factory, explained that reaching ATO first allows for transitioning to Continuous ATO, with success measured by how quickly security patches can be applied and systems recovered.

Tune in on your favorite podcasting platform as our experts talk about the importance of good partnership between public & private sectors to take advantage of a wide range of solutions.

= =

View Details

Your agency will be attacked. Even if we look at the most conservative estimates, a company like Statista shows 32,211 attacks on federal agencies in 2023. The conclusion is obvious: you will be attacked and must have a way to remediate the problem.

Today, we sat down with three experienced cyber professionals to hear suggestions on improving federal cyber security resilience.

Russel Marsh from the National Nuclear Security Administration observes that federal employees may work 9 am to 5 pm every day, but malicious actors do not. The best practice here is to have a checklist of what to do in an “off-hour” emergency.

As part of a resilience strategy, focus on device and asset attribution, as well as the ability to discard certain devices. Conduct tabletop exercises and simulations to assess incident response and communication processes.

Flexera’s Dylan Hudak has seen federal systems with unsupported applications still on them. Visibility and proper software lifecycle policy can remedy easy problems like this.

View Details

This week on Feds At the Edge, sit down with an industry expert and state election officials from Pennsylvania, Florida, and Georgia to focus on election security challenges and solutions.

Challenges:

Traditional threats like disinformation and denial-of-service (DoS) attacks continue to be significant. There is also a growing concern about the physical threats faced by election officials, leading to high turnover rates. In Pennsylvania, 2/3 of officials have left their positions, resulting in an influx of new, less experienced staff.

Solutions:

Tabletop exercises are an easy and cost-effective method to prepare for potential issues. They are able to clarify procedures for responding to unexpected attacks and who to contact. The Help America Vote Act offers funding to improve election security, and testing systems while maintaining cybersecurity is essential. Resources from NIST and CIST provide valuable, targeted guidance to support election officials.

Tune in on your favorite podcasting platform as our experts discuss the importance of practical training, funding, and cybersecurity in securing elections.

= =

View Details

In a world of rapid change and threat, organizations need to be ready and waiting with a plan. One good approach some are taking to navigate an ever-evolving landscape is to lean on a “digital playbook.” Customized to each situation and the unique and individual needs agencies big and small have, these playbooks could make the difference between a scramble and a smooth transition.

This week on Feds At the Edge, leaders from the Federal and commercial sectors discuss the integration of digital playbooks in federal modernization, emphasizing the blend of people, processes, and technology.

AI is an essential part of a digital playbook, with guidelines for ethical use, bias training, and data security. Rear Adm. Christopher Bartz, Deputy CIO of DHS, talks about the AI Corps exploring ways AI can increase security and reduce system costs.

View Details

The 2021 Colonial Pipeline incident has stood in history as a prime example of the importance of cyber resilience for critical infrastructure. This week on Feds At the Edge, we delve into the call-to-action events like this have created for agencies everywhere and the resources available for even the smallest entities.

Cheri Caddy, Senior Technical Advisor for Cybersecurity at the US Department of Energy, talks about resources like CISA & NIST, but suggests that private companies should also build ties with local FBI offices.

Brendan Peter, VP, Global Government Affairs of SecurityScorecard, notes the importance of continuous risk assessment and evaluating the impact of policies to ensure they actually reduce cyber threats.

View Details

When a network is attacked, analysts return to the logs to gain an understanding of where the point of vulnerability was, which makes keeping these records a crucial tool in cyber resilience.

However, a lack of staff, poor existing systems, and limitations on information sharing in our increasingly complex and hybrid landscape could prevent agencies from keeping their records reliable and up-to-date.

This week on Feds At the Edge, leaders from the Federal and commercial sectors share they ways they’ve been able to overcome the hurdles they face when logging events.

Tate Jerussi, Director of Civilian, August Schell, and Former Deputy CIO at DOE HQ highlights prioritizing critical logs and utilizing existing tools to address these issues. And Derrick Lawson, Staff Solutions Architect at Splunk, recommended following established guidelines, such as the MITRE ATT&CK framework.

Tune in on your favorite podcasting platform as our experts reinforce the idea of embracing OMB 2131 as a logging standard and leveraging frameworks from organizations like MITRE to improve event logging practices and enhance security.

View Details

With an accelerated leap in our post-COVID world, mobile devices such as cell phones have become a crucial part of the landscape for remote workers and in turn have also become a key component of today’s attack surface.

This week on Feds At the Edge, leaders from the Federal and commercial sectors share vulnerabilities in the devices we bring from home, and the popular apps that put our sensitive data into the wrong hands. We explore websites that are designed to fool the end users into believing they are on a secure platform.

Tune in on your favorite podcasting platform as agency and industry experts share methods to protect mobile devices, secure applications, keep operating systems updated and train users not to fall prey to web-based attacks.

View Details

The transition to cloud computing by federal agencies has highlighted the importance of security, especially as sensitive federal assets are now in hybrid environments.

This week on Feds At the Edge, leaders from federal and commercial sectors focus on improving security within the complex cloud environment. When code is written with the cloud in mind, applications can be moved easily, updates can be mastered, and systems architects can leverage many aspects of the cloud that are missed with an old “lift and shift” approach.

Dave Hinchman, Director, Information Technology and Cybersecurity for US GAO, coined an aphorism, “Documentation is easy, implementation is hard.”

Tune in on your favorite podcasting platform as participants discuss how to leverage cloud-native code and avoid the mishaps that plagued others.

View Details

In this week’s episode of Fed’s At the Edge, we are talking about US Elections. From observations about challenges seen in previous elections to best practices to ensure a safe and fair election process.

We’ll explore sources of help for election officials like utilizing CISA, local associations, and the US Election Assistance Commission. We also touch on critical areas like cybersecurity, communications, and physical security.

Mark Earley, Supervisor of Elections for Leon County, FL, shares how election professionals should be aware of phishing vulnerabilities as they honor the responsibility of answering citizens emails

Tune in on your favorite podcasting platform today to hear this and more, and learn how you can get involved.

View Details

rev 1 When people think of Zero Trust, they imagine large organizations like the Department of Transportation. We sat down with Nick Graham from Raventech to look at smaller entities and their efforts at cybersecurity. The obvious reason is that these attacks can be very profitable, even if the target is a school or hospital.

He begins the interview by mentioning that, many times, smaller institutions can serve as the gateway to larger targets. Nick suggests three ways to prioritize the transition to a safer cybersecurity posture:

ONE: The easiest starting point is Multifactor Authentication. Most of the frameworks for larger organizations begin with identity. If for example, a school is too small for a full-blown Identity, Credential, and Access Management system, MFA alone is a major move to eliminate many security problems.

TWO: Staff limitations may limit the ability to implement a strategy. However limited budgets can be served cost-effectively with managed services. This means having a third-party company provide services you may not be able to afford. This can be anything from network segmentation to delivering cloud security services.

THREE: Finally, cybersecurity training for onboarding and continuous training. Ransomware typically starts with phishing emails. Nick recommends that staff be regularly trained in how to recognize an attack when it arrives in your inbox.

Nick Graham provides refreshing relief for smaller organizations to be able to provide adequate security for organizations with limited budgets.

View Details

draft When the federal government makes a strategic decision to implement Zero Trust principles, they must consider both user identity and the data users are trying to access.

Today, we have leaders in the federal and commercial sectors look at both data and identity and emphasize the need for centralized coordination, automated labeling, and real-time access control through Identity Management.

Brian Rosensteel from Ping Identity argues that some kind of “federated” identity management system is the most effective for federal identification. Each agency really cannot be responsible for responding in a timely manner given the details that Zero Trust demands.

Access controls have been around since the start of networks. During the discussion, participants gave opinions on the value of both access based and role-based access controls. They also suggested that “context” based access controls may provide additional abilities for systems administrators to improve real-time access controls.

View Details

Today’s experts agree on the potential of Large Language Models (LLMs) in government agencies. Some benefits include improved knowledge management and a reduced burden on tedious tasks.

Andres Perez from the CMMC hits the nail when he states that an organization may have data that can answer questions they did not know existed. The CMMC has put together a large Knowledge Management Platform that assists federal professionals in accessing information.

Many federal agencies have sensitive data that they would like to generate insights from, but not have it exposed in an insecure manner. One method to do this ethically is to create “synthetic” data sets where conclusions can be drawn while never compromising personally identifiable information.

Rather than thinking LLMs are the end answer, many subject matter experts comment that AI and LLMs should be viewed as extensions of human abilities. Chris Roberts from Quest states that this technology should be viewed as an augmentation to strategy, not a replacement.

Developments in using AI to derive information from LLMs are changing rapidly. In addition to policy on data security, Don Wildner from BAE suggests that federal agencies may have to organize new policies on how to ethically create a prompt. Some may be allowed, some not.

View Details

Disputes over the 2020 presidential election have persisted for four years.

This week on Feds At the Edge, we discuss best practices to ensure the 2024 election's safety and accuracy with a focus on the need for robust cybersecurity measures, having a strategy to respond to cyber threats and the need to have strong partnerships with the private sector.

Lester Godsey, CISO, Enterprise Technology for Maricopa County, Pheonix AZ, highlights the influence of social media on election integrity, suggesting that false information can impact the voter’s predisposition to vote.

Jim Richberg, Head of Cyber Policy and Global Field CISO for Fortinet, discusses the effects of misinformation, disinformation, and malinformation which could cause people’s perception of the election to be altered.

View Details

Ep. 159 Overcoming Legacy Infrastructure Through Digital Transformation

If you are trying to achieve a digital transformation in your organization, this is the discussion for you to listen to

We have a group of state leaders and commercial subject matter experts who share their success in making a meaningful change in their respective organizations.

Renoir Pope from California recommends that one should focus on the user experience. When this happens, they feel included and are more willing to transition. Even with a user-focused approach, you still need a systems administrator to get feedback from users to iron out wrinkles in the system.

Further, he also developed a “California Design System.” This overview focuses on user experience and provides a consistent and sustainable transition method to a newer digital experience.

One of the most obvious suggestions was to keep in communication with the staff who will be impacted by the change. Jesse Ravera from Roseville, California suggests to communicate to the staff with the vision of the project and the responsibilities of everyone.

Users will embrace change when they are part of the process, and the new implementation has tangible benefits for them. Success means enterprise architects put a laser focus on the people engaging with the digital change.

View Details

rev one

Today’s interview has a focus on data integrity, evolution of AI, and training.

Ram Iyer from the FDA made a sage observation: you should look at a use case before spending time and effort on cleaning the data. For example, if you are looking at a life-and-death cancer study, you should spend time on that data.

However, not all tasks have serious outcomes. You may look at user interface for a web site that will be a rough basis for an upgrade. Ram suggests you take precious time and assign it to more serious tasks.

Chat GPT has made AI a household term. If you are trying to get ideas on where to travel in Italy, this might be considered “Everyday AI.” In other words, low risk decisions.

However, looking at nuclear weapons distribution is a much more serious topic and can be fatal. Everyone has time limits, use them wisely.

Kyle Tuberson from ICF suggested that a person with domain knowledge should be combined with a technology expert in order to squeeze out as much value from AI is possible. The domain expert could help with prioritizing data and the technical person may assist in structuring prompts correctly.

Also, during the discussion, the participants differentiated between training and reskilling. Today’ professionals have plenty of technical training, however they may not realize that sensors all provide data in a different format. Further, a complete “lift and shift” is not needed in all modernization programs, we now have ways to manage data from legacy systems to incorporate into a modern offering.

View Details

Rev one

= = = =

All baseball fans know Willie Mayes just died; everybody in the world of cybersecurity knows John Kindervag produced the concept of Zero Trust. Today’s discussion has the person most knowledgeable about Zero Trust discuss deployment in the federal government.

This learned group provides listeners with several guideposts for Zero Trust.

The discussion starts with the importance of identity management. If Zero Trust allows access to a person, you should have strong assurance of identity.

“Without identity, nothing else matters” Robert Ross, Idaho National Labs

One may think of the big three cloud service providers. However, Sean Connely from CISA reveals that we have over three hundred cloud service providers for federal information technology. Just understanding the “main and the plain” can get you in trouble.

It is one thing to say “complexity.” However, Lamonte Yarborough indicates that HHS must worry about 1200+ networks. This statement alone shows the raw volume of attacks to manage.

The father of Zero Trust, John Kindervag, provides much clarification on his specialty. One meaningful statement from John is that compliance does not mean security. Zero Trust must be part of the “DNA” of every systems administration. That way, tools can be combined with practical human knowledge to secure federal data.

View Details

(rev one)

According to TechCrunch, 2024 has already seen one billion stolen records and is still rising. In today’s discussion, we learn ways state and local organizations can secure unstructured data.

KINDS OF DATA

Enterprise architects like to sit in front of a whiteboard and design a network with data all nicely arranged in columns. This is great for optimizing for retrieval from large databases.

According to Jimmy Rogers, up to 90% of the data he sees is unstructured. This “unstructured” data comes from sensors, CAD design, satellites, and body cameras. One way to view this data is it is not in a column but in a workflow.

Beginning with knowing how to manage unstructured data is key to keeping it secure.

STRATEGY

Terry Berttinger from Ohio has a simple, but effective strategy to protect data. Make sure a person owns that information. When that happens, people develop pride in working on efforts to make sure that data is not arbitrarily assigned and is stored in the appropriate place to secure it.

SMALL BUDGET

All participants understand the limitations of a state budget. However, Todd Holler suggests that a systems administrator can make simple changes like hardening Active Directory which can have a major impact. Further, CISA is gaining a well-won reputation for assisting state and local organizations by providing free information, checklists, and advice to secure unstructured data.

Finally, one of the participants was willing to share that his system was compromised. Transparency is the only way to help other organizations see what they can do to secure systems.

View Details

For the video of this podcast: Bringing Agility to the Modern Security Operations Center

Follow FedInsider on LinkedIn

Today, we look at protecting critical infrastructure called Operational Technology (OT). One might think, what does a sensor in a water filtration plant have to do with my servers?

OT can be considered as hardware on premises. Some are old and it is quite expensive to update.

For years, IT leaders did not have to worry about security because IT and OT were separated by air gaps. However, today we see a convergence where the IT department is being placed in charge of protecting both IT and OT.

The first challenge to overcome is discovering what is on your network. We are looking at physical devices, virtual devices, and virtual devices in the cloud. Inventories need to be tracked, and some will argue the cloud will permit IT/OT systems to be easier to be configured in an automated fashion.

During this interview, compliance is a topic that is discussed in depth. We all know about IT compliance like NIST 800-53; few realize that OT has federal compliance regulations as well. The real issue, should an OT systems administrator have to do repetitive work to comply with IT mandates?

Marty Edwards from Tenable remarked that he has seen up to 80% similarity in compliance standards. As a result, today, committees are meeting to make sure they can eliminate redundance in compliance for OT vs. IT.

Malicious actors are always looking for the “Easy Button” when it comes to system penetration. If federal leaders aren’t careful, remote sensors can provide a launch pad for the next cyber event.

View Details

In professional baseball, the team with the biggest budget does not win all the championships. Today, we look at ways to boost your cyber defensive skills with a limited budget.

We must start with a state government that seems to “get it” when it comes to cybersecurity. James Weaver documents the thoroughness of their prevention system which includes a Joint Cyber Task Force. This may be a model for other states with funding, but he admits much can be accomplished by leveraging federal initiatives and taking advantage of training programs.

THE FEDS

Eudora Fleishman from Fairfield City California refers to programs provided by the Cybersecurity & Infrastructure Security Agency (CISA) for local communities. The link will give your local government and education institution guidelines, working groups, and more. Eudora documents that CISA will help your organization make a presentation for funding.

https://www.cisa.gov/resources-tools/groups/state-local-tribal-and-territorial-government-coordinating-council

TRAINING

James Weaver from North Carolina had a poignant quote about cybersecurity training, “it is more vocational than high education.” He casually mentions that, just in the state of North Carolina they have 21,000 job openings in cyber.

The fact of the matter is that we have a serious gap in people who can administer and defend systems. Many Human Resources Department demand a four-year degree and eight years of experience. That kind of inflexible thinking will delay any proper way to address the cyber crisis we are facing.

HELP

The subject matter experts all agree that one key part of preparation is partnering with commercial organizations that have the experience to prevent a cyber-attack.

The episode has an obvious conclusion: local governments and educational institutions can take advantage of offerings to make up for lack of cyber security funding.

View Details

Mike Tyson famously said everyone has a plan until they get punched in the face; what is your plan if you are hit with a cyber-attack? What does recovery look like?

Today, we have a brutally honest conversation about a topic nobody wants to address: the step-by-step process of recovery from a cyber-attack.

Solomon Adote frames the discussion by saying that attacks can compromise the management of hypervisors. As a result, the best practice here is to isolate the hypervisor to establish virtual domains and firewalls that you know are safe.

James Thurmond has an insightful suggestion to set up an isolated account. He takes the common phrase “Break in Case of Emergency” and applies it to setting up accounts only used in an emergency. He calls this a “break glass” account that will give a systems administrator a starting point for recovery.

All the subject matter experts suggest tabletop exercises. These allow individuals to set up playbooks that include telephone numbers and action steps in case of an event.

One key component of one of these playbooks is an accurate assessment of your assets. You must know where all your assets are located. All these must be documented,

Danny Page from Rubirk takes it to the next level. An attack may exfiltrate data of which you are not aware. Because of this, a systems administrator must have an accurate scope of the reach of the attack.

A balance is needed between prevention and recovery skills for all systems with sensitive data.

View Details

The federal government is playing a game of cyber-ack-a-mole. When networks are hardened, malicious actors go after endpoints; then Endpoint Detection & Response systems evolve. When endpoints are secure, the apps get attacked.

Today, we have a group of experts looking at sophisticated attacks on federal apps and APIs. The first line of attack is to make sure the database of code libraries is authenticated to be safe. Around 2018 the concept of a Software Bill of Materials became popular. This would ensure safe code at one point in time.

However, as Jerry Cochran points out, the SBOM concept is weak because of the constant change of code that is taking place. The static concept of “safe code” is altering with updates and new compliance changes. Peter Chestna from CheckMarx points out that even if an issue is detected, the remediation process can be cumbersome and time-consuming.

Artificial Intelligence has been shown to detect vulnerabilities in this dynamic code. Unfortunately, the attackers also have access to AI and have used it to search for weaknesses.

When a cyber professional examines code, they frequently use a signature-based approach. During the interview, Nate Fountain suggests that a better approach is to use behavior analytics. That way, a federal leader can have compromised code, but it cannot exfiltrate data because it does not have permission.

The battle is still continuing; recent reports indicate that 41% of attacks are on the next level: the API itself.

View Details

Years ago, anti-virus software updates were sent on floppy disks in the U.S. Mail. Today, the attack surface is so large, we need continuous diagnosis and mitigation (CDM).

Legacy solutions like Security Information and Event Management (SEIM) would isolate data to point solutions. Andrew Manos suggests that if you consider today’s volume, the only way to handle is centralizing data.

Today, we have experts sit down and discuss how to take this CDM concept and deploy a solution for federal agencies. The discussion opens with best practices for a transition to CDM and follows with some guidance for the transition.

After gaining an understanding of what is on a network, it is recommended to start to experiment to evaluate rapidly innovative technologies. This process will need to have a workforce – more flexible than in the past.

Data surges have caused agencies to seek solutions to this vexing problem. One way to break this bottleneck is with the cloud. James Scobey observes the cloud allows data to be managed through an API that can go across environments.

Once a mature approach to CDM is viable, then advanced considerations like sharing data with other agencies can be considered.

View Details

Every reader has heard the phrase, “Lulled into complacency.” One may have completed a checklist and can sit back and feel secure. It can be a false security.

Today’s explosion of data and reliance on compliance has led to a situation where federal agencies can be subject to attack from a vector that was not anticipated.

The Zero Labs report from Rubrik shows how much data has grown:

Data: 25% growth in data year-over-year for most organizations

Cloud: 61% growth in cloud

SaaS: 200% increase

This growth is detailed in statistics from data.gov. They state that 250,000,000 data sets being used by the public sector. The bad news: generative AI will create more data.

Best practices to steal yourself against attack include identifying where the data is stored, prioritizing what to protect, and collaborating with humans to determine who has access and when.

Travis Rosiek from Rubrik explains how he was working with an agency in a backup capacity. When they tried to determine what to back up, they discovered sensitive data where it should not be.

All agencies have a limited budget for data protection. Travis Rosiek recommends finding the most sensitive data and prioritizing protection there.

Malicious actors know the vulnerable moments in a large organization. When someone leaves, weekends, and holidays. Managers should consider covering aspects of security when these events present themselves.

One entertaining “human” problem Travis Rosiek reveals is hoarding data. Simply keeping data for eternity can open a federal agency to malicious actors who have hidden attack codes in the data.

The lesson: move beyond compliance and think strategically about how your agency will get attacked.

View Details

By now, we have seen demonstrations of Artificial Intelligence summarizing content and even producing images. These are all great YouTube videos for a rainy Saturday afternoon, but what about the work of the government?

With AI, one must begin with the data. When it comes to explaining how to leverage the petabytes of information, Karen Hall has a memorable quote.

“Generative AI can unlock the knowledge trapped in data.”

Her four guidelines for releasing this information are

· Make sure the data is authoritative

· Enable connectivity to other systems

· Be aware of data standards

· Use AI in a responsible manner.

AI requires mountains of data to see patterns and help humans make conclusions. Government agencies may have sensitive information in their data stores, making it difficult to assemble meaningful data stores.

Dr. Travis Hall from NTIA suggests that you can use AI to protect personal information. AI can be used as a privacy enhancing technology by being able to obfuscate data so trends can be seen to save money and speed up operations.

Our expert from California, Hong Sae, provides many ways AI can assist government functions. He lists predicting traffic patterns, locating potholes, voice analytics customer service, gunshot detection, and predicting crime patterns.

It is the early days of applying AI in a fast and secure manner. This discussion gives listeners the basic building blocks for success,

View Details

Everyone wants to pick up the phone and quickly get a human who has an immediate, correct, response. On the other hand, government institutions are characteristically understaffed and underfunded. The challenge is to apply modern technology to improve customer service within the allotted budgetary constraints.

Amanda Nabours suggests that an answer that is one hundred percent correct must begin with the data used to provide answers. Data stores must prevent bias and privacy must be protected.

Right now, her agency is in an exploratory phase, but she notes that one key aspect of a successful deployment must be training employees before a role out of what to expect when AI is relied upon to provide answers to citizen questions.

Google’s Tony Orlando expands on the robust nature of adding AI to citizen experience. He details how AI can improve the speed of response, automate reporting tasks, provide a more personalized experience, and even reduce fraud.

During the interview Tony Orlando expands on six models to improve citizen experience, everything from improved reporting to optimizing traffic.

This may be a great practical application of AI for government.

View Details

Everyone wants to pick up the phone and quickly get a human who has an immediate, correct, response. On the other hand, government institutions are characteristically understaffed and underfunded. The challenge is to apply modern technology to improve customer service within the allotted budgetary constraints.

Amanda Nabours suggests that an answer that is one hundred percent correct must begin with the data used to provide answers. Data stores must prevent bias and privacy must be protected.

Right now, her agency is in an exploratory phase, but she notes that one key aspect of a successful deployment must be training employees before a role out of what to expect when AI is relied upon to provide answers to citizen questions.

Google’s Tony Orlando expands on the robust nature of adding AI to citizen experience. He details how AI can improve the speed of response, automate reporting tasks, provide a more personalized experience, and even reduce fraud.

During the interview Tony Orlando expands on six models to improve citizen experience, everything from improved reporting to optimizing traffic.

This may be a great practical application of AI for government.

View Details

Compliance is difficult enough in an air-conditioned data center; taking this essential concept to an austere geography that has spotty communications with the potential of bullets flying makes it almost impossible.

This disruption of communication has a new term, Denied Disconnected Latent, or DLL. When communications are restored, they still must maintain compliance standards.

Today we get some perspectives on how to manage this arduous task.

From a design perspective, an agency may have a process where the developers who deploy the application may not be the ones who make end points secure. As a result, a process must be worked out where the apps are updated and the security process for the end points are systematized as well.

Jay Bonci from the U.S. Air Force describes how compliance can be checked during a regular maintenance process where central compliance information can be transferred to the field.

Nigel Hughes from Steel Cloud shares that today, many systems administrators are executing this update through a set of tools. This manual process may have been tolerated with a few end points, today there is such a profusion that automation is needed.

In a perfect world, one can scan assets, determine policy posture, examine apps, browsers, databases, baseline. If there is a drift – they can be snapped back into compliance.

For more details, listen to the discussion because it delves into federated vs. centralized compliance and the theoretical debate over defining an end point in a world of platform-as-a-service.

View Details

When the United States expanded westward, there was a surprise around every corner; in a similar vein, we see unlimited storage, fast speeds, and artificial intelligence creating a technical “wild west” environment for the federal government.

Instead of a posse of Texas Rangers, we have a group of federal experts who have demonstrated their ability to corral malicious code and prevent robbers from stealing you blind.

Marisol Cruz Cain from the GAO highlights some of the unpublicized aspects of AI. She mentions that its ability to rewrite code can make attribution difficult. In other words, AI can allow malicious code to mutate frequently, preventing any signature identification.

Although the federal government has many cyber compliance requirements, the idea of using an independent group to attack a system was discussed. In the parlance of the cyber community, this is called a “red” team. They attack systems to see what weaknesses they can find. This effort can help address unanticipated weaknesses.

One anticipated weakness that is sitting in the front of many is legacy systems. Paul Blahusch Dept of Labor recommends taking a prudent view of your system to see which ones are legacy and which have unique vulnerabilities. He suggests funds can be appropriated based on vulnerabilities.

We are at a level where leaders may be confronted with cyber tools heaped upon cyber tools. JD Jack from Google suggests a practical approach called “security validation.”

This gives leaders a report on what could happen in an attack. With this method, you look at the tools you have and find a way to evaluate them.

View Details

Tools | What to segment | floating data centers

Four years ago, we needed to have panels define Zero Trust Architecture (ZTA). Today, the federal community recognizes the benefits of ZTA. That was the first hurdle; today, we have a panel that gives the “hows” of implementation, with a focus on micro-segmentation.

When Angela Phaneuf worked at the US Army Factory called Kessel Run, they made themselves famous with innovation. Angela gives some practical tips on how to deploy ZTA.

She explains that tools can assist in the move to micro-segmentation, however there are many. One approach that has worked for her is to assemble a catalog of tools that can help in a variety of environments.

Dr. Cyril “Mark” Taylor shares with the audience his view of the priorities to accomplish change. He mentions policy first, culture, and finally, the technology itself. His experience with the military indicates that once a team has a well-defined goal, the transition can be made.

For most of its recent history, the US Coast Guard has had to rely on slow satellite service. Captain Patrick Thompson informs the audience that today’s Coast Guard is looking at satellite service that can run as high as one hundred megabits per second (Mbps).

Increased speed gives crews the ability to use more compute and storage at the edge – he calls today’s ships floating data centers.

Sometimes, more data can lead to trouble. A system architect should know where micro-segmentation is a benefit. Dave Zukowski from Akamai suggests one looks at the risk profile of a system – just because they can does not mean they should be integrated.

View Details

Today we hear perspectives on how AI can assist federal agencies. Kevin Walsh from the GSA provides observations at several federal agencies; Pritha Mehra from the U.S. Post Office gives practical examples of deployment.

The overriding consensus is that AI is not the panacea to solve all federal technology problems. However, it has promise but must be approached cautiously to use its power to meet your agency’s mission.

Kevin Walsh from the GAO has seen his share of federal agency AI implementation. He has concluded that effectiveness varies from agency to agency. He cautions that one cannot paint with a broad stroke and update every legacy system using AI. There may be some systems that are not a suitable candidate for any kind of upgrade. Further, some systems need to be turned off.

He suggests you consider evaluating the risks associated with AI, which include oversight, false information, and acknowledging how AI makes decisions.

Pritha Mehra from the Post Office gives outstanding examples of how the Post Office is already using AI to improve service. They are looking at processing, the network, and supply chain issues.

They are at a maturity level where they are looking at optimizing delivery time for packages through AI analyzing data.

It sure looks like other agencies can look at guidelines from the GSA as well as success stories from the Post Office to glean ways to apply AI to improve their respective agency.

View Details

Every headline one reads sings the praises of Generative Artificial Intelligence; today’s interview showcases some successes and also, some aspects that federal users should be aware of. The discussion includes concepts like hallucinations, test beds, and establishing trust.

When Chat GPT was released, there was an explosion of people lauding its benefits. Finally, one can vacuum up previous knowledge and present it in many formats. What has not been highlighted is that there can be serious glitches in this approach and produce narratives where Napoleon was part of the American Civil War.

Sukhvinder Singh uses a common term in the field to define this. He calls it a “hallucination.” To prevent psychedelic experiences, Sukhvinder goes on to suggest one way to prevent these entertaining, but frustrating, results is to set up a test bed. That will allow federal leaders to experiment with data, try out governance processes, and gain a better understanding of cost.

By now, it is well known in Generative AI that if you vary the prompt, you can vary the results of a query. These variations do nothing to assist a public-facing website like the TSA has. They seek Generative AI to provide repeatable operational responses.

Generative AI is maturing fast. Listen to this discussion to see which use cases can make this innovative technology sustainable and trustworthy.

View Details

ChatGPT certainly has a great public relations department. It is portrayed as the answer to every conceivable problem for the beleaguered federal technology professional.

Today, we sit down with a group of experts in what may be termed “Applied Artificial Intelligence.” We look at several aspects, including preparing your data for AI, the best applications for AI, and putting up guardrails to use AI safely.

Mangala Kuppa from the Department of Labor indicates that every use case is unique. If one data set can yield valid results does not mean the results will be the same with another data set. In her experience, every use case will require you to do a bit more to ensure satisfactory results.

Kurt Steege from Thundercat Technology catches the attention of the listener when he lists malicious code that has been enabled by AI. He refers to Dark Bard, Poison GPT, and Deep Fakes as examples of how malicious actors are using AI to attack.

It is no wonder that the best tool to counter AI attacks is . . . AI itself. For example, an AI attack enables such speed that a human may not be able to stop it. Julian Zottl indicates that we may not have a choice to whether or not to use AI in defense.

When the interview winds up, the participants agree that AI should be framed within a broader context of the technology system itself. Reliable & trusted results from AI are not just technical solutions. They include governance, alignment with agency goals, and accountability.

View Details

Years ago, federal leaders would dream of getting the terabytes of data. The mechanics of collecting and processing have been solved; few thought that we would have more computing power than trusted information.

Today’s discussion focuses on some of the risks in storing, sharing, and analyzing data.

One of the reasons for this concern is the data generated by machines. Questions are being asked about how that data is collected and the method of collection.

Let us assume the data is clean, the next step is to protect and share it. Some will suggest there has been too much focus on protecting the network, the applications, and even the API instead of the data itself. Collaboration may not mean sharing everything in a data set. It is possible that in a record with one hundred fields, an analyst may only need two fields to accomplish the task.

When it comes to analysis, Casey Johnson observes that it is difficult to detach from bias and let the data tell us what to do. Jeff Shilling from the National Cancer Institute suggests that we need people with an excellent statistical background combined with human deliberation to get valid results.

Technology may have gotten ahead of our ability to use data strategically.

View Details

Multifactor Authentication | Active Directory | Access Brokers

If one takes a cursory look at cybersecurity, one may conclude that Multifactor Authentication (MFA) may be the answer to cyber woes. That might have been true a couple of years ago, but malicious actors are adapting to every blockade put in their path.

Today, we sat down with several identity management experts to get updated on current threats and best practices for reducing the attack surface for federal technology.

MFA has a proven weak point. Researchers have discovered that when an individual leaves an MFA session the session can remain open, leaving opportunities for attackers.

Even if MFA is performing flawlessly, we live in a dynamic world. People are changing constantly; systems must be designed to adapt to today’s rapid changes. MFA just isn’t robust enough to counter today’s threats. Deeper authentication must be considered.

Active Directory is all pervasive in the commercial world as well as in government. Some estimates give it a 90% market share. Jay Bonci from the Air Force observes that systems architects must design systems to eliminate weaknesses of Active Directory.

Andre Murphy from CrowdStrike describes a new concept called, “access brokers.” One can purchase identities much like shoes. This leads to attackers walking in the front door with no need to break any locks. In other words, there is no need for malicious code when you have the keys to the front door.

View Details

Mountains of data and Artificial intelligence are impacting every aspect of all federal agencies. Today, we examine the impact of technology innovation on modernization of human resources.

Jason Nelson opens the discussion with some sobering facts. Who knew the TSA gets 200,000 job applications a year? If we assume two hundred workdays in a year, this means they manage 1,000 a day! Whoa.

During the discussion, we saw three methods to use data & AI to help all federal agencies: improved evaluation, automation, and bots.

Evaluation. Some agencies are taking the data they have been collecting to get away from the typical “check box” method of potential employee evaluation. They are using previous success rates of team members and deriving methods to apply that to new applications.

Automation Shweta Agnihotri from ICF suggests that agencies can apply artificial intelligence to existing professionals to evaluate their skill sets to help underrepresented groups. This means that analysis can be done on core related functions, rather than traditional test-based evaluations.

Bots It is unfortunate the releasing bots too early has made most people not see their value. Donald Bauer from the State Department gives examples where a bot can automate pre stage data for applicants. For example, artificial intelligence can review forms and see areas that are missing better than a human can.

The conclusion is simple, when deployed within guidelines, artificial intelligence can offer improved accuracy in forms, better analysis of skills, and can free up time for higher level activities.

View Details

Ep. 138 Barbarians at the Gate: Zero Trust, Active Directory, and what you need to know

Our panel today will focus on Microsoft’s Active Directory and identity management. Here is an executive summary of this week’s interview: barbarians at the gates and zombies in the basement.

BARBARIANS. Everyone knows about the barbarians. Chris Roberts from Quest Public Sector indicates that there are ninety-four million attacks on Microsoft’s Active Directory every day. Active Directory is popular in both the commercial and the federal market as well.

Members of the panel state that a strong identity management program will stop attackers in their tracks. When it comes to implementing Zero Trust, multi-factor authentication may not be sufficient.

Some of today’s weaknesses include weak passwords, inactive accounts, overuse of admin accounts, and not de-provision of what you do not need.

ZOMBIES One approach to making your agency resilient is to do backups, we know all that. What you do not know is that some backup systems omit Active Directory. This means that a malicious actor Can plant code in the Active Directory.

Studies show that 92% of those backups are attacked.

After an attack, the data is recovered—but the code can still be lurking in the Active Directory. According to Shawn Kingsbury from SAIC, third-party AD recovery apps are better than Microsoft’s. Further, please review those apps to make sure they have backups for AD included.

View Details

The federal government poses unique challenges in identity management. They are constrained by heavy security, a surfeit of data, and, most importantly, a limited budget.

Today’s interview takes all three aspects into account and offers listeners creative solutions to solve the vexing crisis in federal identity management.

One of the first concerns is mobility. This does not just apply to military operations which, by definition, will be all over the world. Today’s civilian agencies like FEMA have emergency remote users as well as many employees and contractors working remotely.

The initial secure environment includes PKI processes that work well on a desktop system; now so much on a mobile. During the interview, it was suggested that a centralized model of identity verification may be the solution that can manage circumstances that do not include desktop computers.

In a nod to the human condition, it was observed that if the identity solution is not convenient or will be subverted.

SailPoint’s Frank Brugulio points out that once a stable initial process is designed, then one must worry about continuous monitoring. The federal government includes legacy systems that may not work with new identity management systems, and a person’s attributes may change,

What the first federal systems designers never imagined is a fact brought out by James Imanian from CyberArk. He states that today, we must deal with forty-five machine identities for each human.

When you throw all these factors together, you must understand that we are dealing with a limited budget and staff. Well deployed artificial intelligence can do menial tasks like recognizing unauthorized devices, advanced logging analytics, some sticky compliance issues.

View Details

Eliminate silos, simplify maintenance, and add agility.

“Rube Goldberg” is a term that is used to describe a ridiculously complicated mechanism. One may apply that phraseology after a quick look at some federal systems. It only makes sense.

Over the years systems have been customized to respond to a specific kind of workflow inherent in an individual case. Humans being humans, all think they are unique and radically different from any other system.

After a couple of decades of this, you get case management systems that are siloed with unique methods of doing the same activity.

In today’s interview, we will look at a new way to streamline the entire case management process to reduce cost, simplify maintenance, and be more responsive to changing needs.

Jason Adolf from Appian unpacks the concept of modularity in case management systems. That way, users do not get bombarded with change and can adapt incrementally. A system that is low code no code makes it easier to adopt leading edge methods into the application when you are ready.

Prem Abuvasamy has had to manage patches with disparate systems. His experience shows that a multi-vendor approach can result in multiple timetables for system patches. It is possible that the system administrator wants to patch but is limited by the vendor.

Tedious reports can take advantage of a system that allows for code to be reused and applied to a variety of case management systems. This means that reports can be generated automatically, allowing federal technology leaders to concentrate on larger agency objectives.

This is a valuable discussion on change management, even if you are not responsible for case management.

View Details

Transitioning to Zero Trust for any large enterprise, be it a federal agency or a car manufacturer, can be a herculean effort.

Today’s interview is with three thought leaders who specialize in the critical component of Zero Trust: Identity. Each person has been involved in many large digital transformations and offers suggestions to help the journey be less painful.

The focus is on automation, risk management, and changing while still accomplishing the agency's mission. Here is a quote from Josh Brodbent that sums up his position:

“The ultimate goal here is to have security while enabling the mission “

Frank Briguglio from SailPoint asserts that to reach a mature level of Zero Trust, one must automate. It seems obvious, that automation can control visibility and tie all things together. However, his caveat is one needs to not go too far. If the automation is just machine-readable, the human element is out of the loop.

Starting any project, if you are rebuilding a car engine or moving to Zero trust, you need to know where to start. Bill Proffer from Leidos suggests that a federal technology leader should start by understanding the risk appetite they have. When you know where sensitive data resides, you can start with easy controls, and then move on to the grey areas.

Continuous maintenance is associated with software development these days. However, a prudent approach would be to include a lifecycle aspect to access controls as well. This would include individuals and physical or logical objects.

When you keep these fundamentals in place, you can make a smooth adaptation to controlling access through identification.

View Details

Understanding APIs: thousands of them | hard to discover | Vampire APIs

The discussion starts with Patrick Sullivan from Akamai stating that 80% of the attacks they are seeing involve the API.

What is an API?

Originally, it was a quick way to integrate systems. When servers were down the hall, they had minimal use. The popularity of the cloud has drastically increased the number of APIs on a system. Some federal networks can have thousands of APIs.

Why worry?

An API is small but powerful. It can be a single line of code. Not only that, APIs are an embedded part of so many systems that it is hard to even discover where the APIs reside.

How to protect federal data?

Shane Barney from USCIS suggests that API protection should be “baked in” when software developers write code. If you combine that with a continuous runtime model, you will at least know where they are located.

During the interview, Patrick Sullivan coins the phrase, “Vampire API.” This can be an API that was written and then replaced. However, malicious actors can access the code and modify it to serve their purposes.

Another unforeseen circumstance is the logic within the API. It can be sloppily written to allow the validated code itself to be taken advantage of.

Listen to the episode to learn about federal leadership in protecting APIs. These include NIST checklists and understanding the origin of code.

View Details

Large organizations, whether public or private, all have challenges in making a digital transformation. Today, we sit down with public sector leaders who have had success in managing to make large, state-based systems adapt to today’s world of rapid change.

When we say some state systems are large, that is no exaggeration. Ajay Gupta tells listeners that in California they manage three million calls a day and seventy million website visits a year. Whew. How to manage this volume in a world where software development talent is almost impossible to find?

Ajay talks about looking at offerings that can be customized by users, this is commonly called “low code, no code.” He explains the key to making this change is to be sensitive to legacy systems to achieve optimized performance.

Nobody has all the answers, some state leaders are offering vendor days. This is where public sector leaders engage with vendors with problems they want to solve. When this leads to innovation, Ajay suggests you start in a small area, iterate, and then expand.

Nadia Hansen from Salesforce looks at some financial issues. Re-inventing the wheel for every business process in a state would be ridiculous. She suggests developing a framework that can accommodate 70% of the needs of a specific task. From there, a low code no code approach can be taken to customize the process.

That way, overall cost is reduced, feedback is generated from users, and funds can be managed efficiently.

The bottom line: automate what you can. With that approach, you will be able to use expensive talent to solve more complex issues and the tedious processes can be accomplished through automation.

View Details

Secure Operations Centers (SOC’s) were designed in the early 1970 with an attempt to thwart minor malicious codes. Well, things have changed slightly in the past 50 years! Today’s SOC provides 24 hour a day, year-round protection for key government organizations.

Somehow, this initial design has not kept up with the profusion of threat vectors and many need to be upgraded to manage today’s threats.

This is an interview with several leaders who have decades of experience in optimizing the performance of a SOC. We have experts from the Cybersecurity and Infrastructure Agency (CISA), a couple of major research laboratories, and a subject matter expert from Palo Alto Networks.

During the interview they discussed topics like tool management, the importance of standards in automation, and some help that is offered by CISA.

Humans tend to be attracted to bright, shiny things. Companies like to dangle innovation in front of commercial and federal leaders, and they tend to jump on them. Some studies show that many only use 20% of a tool’s capability. Robert Roser suggests reviewing the capabilities of existing tools before adding tolls to mange threats.

Several participants indicated that every incident may not be a threat; one should prioritize where to go next. That concept is nice in theory, but in practicality, it needs standards that lead to automation to allow the threats to be prioritized.

A SOC can get hit with thousands of alerts a day, causing operators to misidentify threats due to alert fatigue. Michael Duffy from CISA understands and lists ways that CISA can assist. He refers to the Binding Operational Directive CISA 22-01 that is designed to cut down on alert fatigue.

The threat to federal SOCs is real and the response can help everyone involved make federal systems more secure.

View Details

Ep. 131 Identity – One Critical Element of CISA’s Zero Trust Maturity Model

When you walk down the grocery store aisle you are bombarded with “New and Improved.”

The Cybersecurity and Infrastructure Security Agency sure is not selling soap, but they are in the business of improving their original model as much as Proctor and Gamble.

Today, we hear comments on the new CISA Zero ‘trust Maturity Model Version 2.0. The observations will help federal leaders learn lessons from the initial recommendations.

The latest version boils down to more prominence on identity, new maturity levels, and increased emphasis on visibility.

Each subject matter expert agreed that funding must be applied carefully. For example, Bill Proffer from Leidos notes that added visibility allows people to prioritize data and develop a more effective risk profile.

When Frank Briguglio cited the statistic that 84% of recent cybersecurity events were identity-related, each of the participants agreed. CISA recommends more robust identity management as the initial step in the Zero Trust journey.

In CISA's first guidelines on Zero Trust, they had three levels of maturity: Traditional, Advanced, and Optimal. Feedback from users showed that most assessments fell between traditional and advanced. To assist in planning, a new category, called “Initial” was included. D

This is the stage where automation was brought into Zero Trust, a good reflection of the sophistication of Zero Trust's progress.

When you listen, you will learn of all the ways the federal government is providing learning tools for this important transition. Frank Briguglio recommends the NCOEE implementation project which looks at horizons for deploying Zero Trust.

View Details

Identification, Micro-segmentation, and Continuous Monitoring.

Zero Trust is maturing. We have gone from “What is Zero Trust” to “Now that I understand it, how can I afford Zero Trust for my agency?

Today’s interview is with Brian Dennis from Akamai, a well-known expert on the deployment of Zero Trust. He will give the listener an overview of the most economical way to deploy Zero Trust.

Conceptually, Zero Trust is not a sole product; it is a group of products that work together. This is the main reason careful budgeting must be applied to several specific expenditures in this area.

Brian’s advice to get the most “bang for your buck” you need to get Identity Access Management under control, apply micro-segmentation, and include continuous monitoring in your grouping of products.

All federal initiatives directed at Zero Trust begin with identity management. This is the linchpin, and the solution must provide correct identification before anything else happens.

Divide and conquer is a military concept that can be applied to computer networks. The concept of micro-segmentation was known years ago, but systems have gotten too large to segment manually. Today, we have automated systems that allow permissions to be assigned to each limited area.

Ransomware is up; we see new variations of attacks every day. This means that any reasonable budget must include continuous inspection.

Focusing on these three areas will enable your systems to use a Zero Trust approach. Of course, there are exceptions, like MRI machines. However, these examples of systems that cannot be upgraded can be isolated with proper security system techniques.

View Details

The past five years have shown us an incredible increase in the amount of data being generated. We have seen the Internet of Things combine with fast communications and cheap storage. The result is a deluge of data that has to be protected; with new challenges come new solutions.

Today we sat down with a veteran in data protection, Aaron Lewis. He shares with listeners lessons learned from decades of his involvement in data protection. He focuses on three ideas that involve data: classification, mapping, and recovery.

He starts with you understanding the data itself. The adage, “If you protect everything you protect nothing” applies here. A system administrator must be able to separate sensitive, classified, and top-secret information. Effort should be placed on the most valuable data.

Data mapping sounds like a simple task. Well, at one time it was. Today a system may be attacked when data is residing in many locations. Aaron reminds us that in a modern enterprise, you may see data on the wrong network. It could be in a chat tool, like Slack. If you just protect data that sits in your network, you will be vulnerable.

Mike Tyson famously said that everyone has a plan until they are hit in the face. However, Aaron points out that many federal leaders may not even have a plan. If they do, it is sitting on a shelf. Some have called this “shelfware.”

To be able to effectively defend data, one should have a current plan that is living. Aarons says that a plan is not a plan unless it has been tested. He recommends a disaster recovery plan that responsible parties rehearse.

View Details

The federal government employs millions of people doing, it seems, millions of activities. With such a wide range of activities taking place, it is difficult to take a technology like AI and see how it can live up to its billing by making the federal workforce more efficient.

Each federal agency will, undoubtedly, apply AI in a differing manner. One way to see how AI may fit your organization is to listen to this interview. We have a wide range of individuals representing a wide range of agencies and commercial agencies who know about federal operations.

During the interview, they share ways they are using AI, including:

· Department of State: Using AI to classify diplomatic cables.

· Government Accounting Office: acquisition

· Defense Innovation Unit: Aerospace maintenance

Taka Ariga takes a view of “applied” AI from a large-scale. What he sees is AI applied to specific segments, with limited knowledge. For example, in aerospace maintenance, a system can be devised to know when aircraft wires may need to be replaced. Similar silos are represented in identity proofing, and data analytics.

Taka’s observation is that AI is a team sport. Each federal project must include compliance issues, ethical issues, and transparency. He feels that projects must include team members who can understand subtle concepts like biased databases.

With all the ink that has been given to AI, Jamie Fitzgibbon from the Defense Innovation Unit makes a startling statement when she says the “only 1% of DoD appropriation is dedicated to AI.” She articulated many of the use cases when AI makes the DoD more efficient but notes that military leaders have more caution than others.

All participants note that one weakness in AI is in the selection of data sets. The selection process of that data can bias results. What about data sets that are sitting in storage? Can they bring valuable findings for a valid conclusion?

View Details

Prioritization Patching Pre-Authentication

Logging has always been a thankless and tedious task for systems administrators. Over twenty years ago, this problem was solved with a free logging program called Log4j. It was effective, free, and easy to use. The logging framework became so popular that it was truly pervasive, being part of nearly all systems.

As William Shakespeare would say, “Aye, that’s the rub.” Because it was everywhere, it made a tantalizing target for malicious actors. They knew that if they could compromise its code, it would open doors to areas that were extremely hard to find.

Two years ago, Log4j was compromised by a malicious actor enabling them to get control of systems.

During the interview, you will hear how leaders structured a response through prioritizing, patching, and preauthorization efforts.

Prioritizing: Every federal agency has sensitive data assets. With system visibility, one could discover which assets were vulnerable as well as the location of outward-facing applications. This way, assets could be prioritized. This tiering system was important because some libraries were not being used and shouldn’t be worried about.

Patching: Large systems take time to patch. The risk, of course, is that the malicious code would propagate during this time. Solomon Adote discussed his targeted response. He recommends leaders limit access to systems to buy time for the rest of the patching activities.

Pre-Authentication efforts: Members of the leadership group agreed that one of the best preventative practices occurs before anyone enters the system. West Colie recommends a way to make sure software libraries are examined before they are loaded onto sensitive federal applications. He mentions a Software Bill of Materials that can assure developers that threats like Log4j are not included.

In the area of prevention, it was recommended that the person asking for access to a system be authenticated “upstream.” Before even submitting a username and password, a potential visitor should be vetted at a completely different site.

The world of cybersecurity is a never-ending battle. Learn lessons from the remediation efforts for Log4j so you can apply them to the next cyber threat to your federal agency.

View Details

“Word clouds” were popular a few years ago. If we attempted to re-popularize the visual representation of an image with terms associated with federal technology, you would see phrases like “hybrid cloud,” “Zero Trust,” and “unfunded mandate.”

We may have to adjust the “word cloud” because of the Infrastructure Act of 2022, we are looking at $1.9 billion in funds appropriated for cybersecurity.

Today’s discussion provides guidance on optimizing the use of these funds, so state and local governments can solve today’s threat and prepare their staff for years down the road.

Tim Roemer from Thrive DX suggests that some local organizations may not have a mature position when it comes to cybersecurity posture. Because of this, a typical local area may consider spending money on advanced technology, what he calls the “Ferrari.” He suggests they should optimize funds for basics like cybersecurity awareness training.

One way to optimize the funding is to take advantage of the free services that CISA provides. They offer free assessments as well as penetration tests. These activities can bring local areas up to a more mature model of cybersecurity where they can make informed decisions about funding measures.

During the interview, it became obvious that, even with the increased funding nobody has 100% certainty, and nobody has 100% of all the answers. Continuous training must be part of any plan to optimize these funds.

View Details

More end points staffing challenges automation

Today, we sat down with three state experts and three subject matter experts and heard them give ideas on the most effective way to combat cyber threats. The discussion can be boiled down into three main areas: risk in increased workload, staff challenges, and automation.

Covid increased the number of people logging in remotely and, at the same time, there was an increase in data collected by sensors. That increased workload presented opportunities for malicious actors. Tony Lauro mentions that this data collection can involve Application Program Interfaces (APIs). They must be protected because they act as a gateway and an attack point for outsiders.

This increase in data collection also includes the obligation to act in a way that protects personal information. If not done correctly, sensitive data can be collected and stored in an unsafe manner, leaving it exposed to attack.

Everyone knows about the lack of staff for cybersecurity professionals. Jeremy Wilson from Texas details how Texas has an “Infosec Academy” that trains staff in principles of combatting cyber-attacks. His experience shows that a person doesn’t necessarily need a degree in computer science to be effective at preventing and remediating attacks.

Automation is a double edges sword. On one hand, it can assist in updating systems and validating identity; on the other hand, attackers can use automation to accelerate attacks as well. David Morgan from Texas suggests that in a post pandemic world Identity, Credential, and Access Management must be a priority. Automation can allow platforms to talk to each other, but a systems administrator must know where the gaps are and provide end point protection.

View Details

Complexity Identity Credentials and Access Management (ICAM) Toxic Combinations

Napoleon Hill once said that a goal is a dream with a deadline. When it comes to the federal transition to Zero Trust Architecture, the Office of Management and Budget outlines a path for implementing zero-trust architecture by 2024. Today’s discussion gives federal practitioners terrific guidelines on how to accomplish that noble goal.

The group is a wonderful mix of federal experience, innovative leaders, and experts who were part of many initial network specifications. During the discussion three topics were obvious: how to manage complexity, identity, and unexpected combinations.

Complexity

During an exchange about “shiny new things” that seem to trap system managers, Josh Brodbent made a fantastic observation when he stated that complexity doesn’t always mean effectiveness.

Drilling deeper into the concept of new technology, Frank Bruglio suggests some people will purchase a “shiny new toy” for the sole reason to check a box on a compliance requirement.

ICAM

Bryan Rosensteel has spent his career in the world of federal identity management. His experience leads him to believe that to fulfill the desired transition to zero-trust architecture, application developers must be taken into consideration.

His point is simple, if ICAM isn’t a part of application development, how can they assure that it will be compliant? Bolting on compliance brings about delays and unneeded code revisions. Bryan expands on this concept with his thoughts on abstract authentication and centralized structures.

Toxic Combinations

Frank Briguglio reminds us that managing Identity Credentials and Access Management must be understood at a much deeper level. In the discussion, he revives the phrase “toxic combinations.” This is a reference to granting privileges to users that can create risks in unexpected ways.

Automation has its limits, and humans must be part of the package when a federal agency commits to zero-trust-architecture.

View Details

Sprawl > Visibility > Segmentation & micro segmentation

When technology people hear the term “segmentation” they normally apply that term to network topology. After all, networks have been segmented since the early days when subnets were devised (RFC 791 in 1984).

During today’s discussion, we will learn that although network segmentation is important, we must also consider the value of applying segmentation to applications as well. Rob Thorn from ICE explains that we need both approaches to have a secure federal system.

Instead of a server down the hall, a typical federal agency is encountering “sprawl.” Public clouds, private clouds, multiple data centers, and the day of saying an application is sitting on a server in the building is long forgotten.

Gary Barlet from Illumnio points out that many systems administrators really don’t know what calls are being made by applications. When it comes to network visibility, applications must be included. Hence the importance of application segmentation. An argument can be made that this approach can be termed micro segmentation.

The next logical step is gaining visibility into the network to have a deeper understanding of who is accessing what. Gary Barlet makes some shocking observations about visibility. Some organizations do a thorough analysis of their system and see servers they thought were taken offline; these “ghost” servers may not be patched properly and result as being a significant vulnerability.

View Details

Everyone who has driven through Missouri knows that the state motto is “Show Me.” That is the theme for today’s interview.

We all have seen the hype about artificial intelligence. Well, time to give some specific examples so federal and state leaders can see how to apply AI to reduce costs and improve service for citizens.

Today’s podcast is a fantastic panel of experts who reflect views from academia, states and localities, as well as corporate expertise. They manage topics ranging from AI bias to floodplain insurance.

Amanda Randles opens with practical advice. She says we should not fear AI, we should focus on ways to train users on how to use these tools in the best way.

Moving from academia, David Edinger gives specific examples from Denver on how he has deployed AI to improve citizen experience. For example, if AI can detect anomalies on an X-ray better than a human, why not use AI to free up time for a radiologist to face-to-face with patients?

A more mundane example is Denver’s non-critical support line, what he calls “311.” David details how AI has been deployed in chatbots to help people with typical tasks like getting a license. It can also anticipate questions and provide appropriate answers. Finally, AI-enhanced response systems can work 24 hours a day 7 days a week, which improves citizen service as well as reduces the burden on staff to work weekends.

Moving to the West Coast, Hong Sae describes how AI can be used to predict major events on a flood plain. This predictive ability has helped citizens with reducing the cost of flood plain insurance.

This far-ranging discussion includes each person contributing to the concern of AI being used in an ethical manner as well as how to trust the data that is provided.

View Details

In 2021, the federal government provided initiatives for a move to zero trust; after two years it is time to look at the progress agencies have made.

Today’s discussion includes federal experts who have made remarkable progress in the implementation of Zero Trust. The group also includes an experienced subject matter expert from a large commercial organization, IBM.

The conclusion from the short discussion is the value of taking into consideration many of the human aspects of implementing zero trust. This human aspect can be divided into three areas: strategy, design, and leveraging guidance from the federal government.

Strategic concerns begin with understanding the nature of a zero-trust implementation. As Wayne Rogers points out, one can’t throw a switch and have zero trust just emerge from those bits and bytes. He suggests a test pilot program, getting feedback, and then continuing until it is complete.

When it comes to multiple cloud vendors, Wayne brings brilliant insight. He looks back at traditional federal tech implementations, he observes that they were using a variety of vendors. His suggestion is to apply the same strategy to cloud based zero trust. Using multiple clouds yields benefits like resiliency and reducing cyber-attack vulnerability. If one vendor gets attacked, your secondary provider will be available.

As far as reducing risk goes, he details an approach where you distribute the technology for Zero Trust among several Cloud Service Providers. For example, one can place SASE on one, ICAM on another, and storage on a third. Although it can be complicated, he shows that it can increase speed drastically.

IBM’s Akiba Saeedi recommends that a federal manager should look at a transition to zero trust by focusing on use cases. Take one implementation and examine it regarding disruption, privacy, and remote work. She has seen success when working with several vendors on specific use cases.

All guests agreed a great place for guidance on a zero-trust transition is NIST’s Center of Excellence on Zero Trust called the National Cybersecurity Center of Excellence, or NCCOE project.

View Details

Most people today think the sum of Artificial Intelligence is ChatGPT; this is a discussion of a wide range of use cases where the federal government can apply AI. After listening, you will realize that ChatGPT is just one element of the advances in technology to allow federal leaders to make data-driven decisions leveraging artificial intelligence.

The use cases discussed range from compliance at the Department of Education to applying Natural Language Processing to satellite images. In this range, there are five concepts about AI you may never have thought of.

What about clean data? One challenge the CDC has is it may get secondhand or even thirdhand data that they are challenged with cleaning up. That experience is reflected in other agencies as well.

Federal leaders are concerned about privacy and security. Federal leaders are skilled in understanding the use of this data and whether it complies to make sure it is safe.

No federal agency can apply artificial intelligence in a vacuum. It must be an enterprise-wide endeavor. To that end, we see Executive Order 13960 to provide overall guidance on how to handle data for larger organizations.

Analytics matter. Ten years ago, everyone talked about big data; then they realized that actionable information wouldn’t just drop out of a large data set. Leaders must have a laser focus on deriving lessons from the massive data sets they encounter.

English isn’t the only language on the planet. You can’t just translate the language into English, you must seek out annotators who can provide nuance in a foreign language. This is especially true for intelligence agencies who monitor foreign threats. Just because today’s Large Language Models are based on English, doesn’t make it apply to other countries.

Vijay Sharma summed up the discussion brilliantly – he said having Artificial Intelligence is like having the best bike in town and not knowing how to ride it.

View Details

One of the challenges of raising a child is teaching them how to share; one of the challenges of federal information technology professionals is teaching them to share.

Today we take a look at organizations that encounter cyber threats and their efforts at sharing threat information.

Sharing cyber threat information isn’t a recent idea -- Executive Orders have encouraged sharing for years.

February 13, 2015, talks about the goal of creating robust information sharing related to cybersecurity risks and incidents.

May 12, 2021 “Removing barriers to threat sharing” that encourages the sharing of information across federal agencies.

In the commercial world, people are afraid to share cyber threat information because it may make them look weak to customers. If they share that data with competition, then their commercial opponents may have a leg up on them.

The federal world is just resistant but for different reasons. If a vulnerability is announced, there is a threat that federal systems that aren’t patched will be vulnerable to attack.

This is the challenge addressed in today’s interview with federal CISOs and a commercial expert.

Jonathan Feibus from the NRC looks at budget -- smaller agencies may not be able to afford to get commercial data on threats.

Companies like Mitre make available public Common Vulnerabilities and Exposure (CVE) lists for free. The most recent list includes 210,558 vulnerabilities.

It is indeed possible for a commercial company to have systems where vulnerabilities can be identified and remediated before they makes the CVE list.

View Details

Executing the mission, abstracting complexity, driving for speed

The Biden administration didn’t just release Executive Order 14-058 to make federal websites look good, the practical aspect of user experience is making sure citizens can access information in a speedy, and safe manner.

Conrad Bovell from HHS makes a strong statement when he states the reason for cybersecurity is to secure the mission of the agency. For his agency, it is quite a large mission.

During the interview, he casually mentions that HHS has a #1.68 trillion annual budget.

The obvious method is to lock everything down, however, the functioning of the agency means that he and his team must assess risk to when funding research. The challenge is to get both: good experience and speed.

The HHS complex in suburban Maryland is quite extensive and complex, but nothing compared to the geographically remote and secure networks the military must operate in. Randy Young gives the perspective of a trusted partner who assists in making the network easy to use and secure. He maintains the way to support the warfighter drives better technology outcomes on the user’s terms, not the terms of whatever new technology is available.

Putting yourself in the end user’s boots can make security experts understand how to manage risk and deliver the speed needed all the way to the feds at the edge.

Twitter: @FedInsider

LinkedIn: https://www.linkedin.com/company/fedinsider/

Facebook: https://www.facebook.com/FedInsiderNews

View Details

Compliance, maturity levels, edge computing

Some people think the television phrase, “Set it and forget it” applies to Zero Trust. Today’s discussion throws that notion out the window.

The interview takes a deep dive into how an agency can move to a Zero Trust Architecture. Three experts discuss compliance, maturity levels, and the role of edge computing. The conclusion is obvious: Zero Trust is a serious, constantly evolving methodology and federal leaders must take advantage of every resource possible to gain a thorough understanding of the process.

Jennifer Franks from the GAO points out that Zero Trust is not a new concept and the federal government has all kinds of reference materials to support leaders. She lists information from DISA, NIST, the DoD as well as the OMB. She reminds listeners that there is a maturity model associated with Zero Trust change -- and leaders must be aware of revisions to these documents. Jennifer reminds the audience of the recent upgrade to the DISA model that adds more maturity levels.

Guidance is nice, but where to start? During the interview, Wayne Rogers talks about looking at your respective agency’s situation and doing a gap analysis. Once that is complete, then one can set priorities. For example, when he used this process, his agency identified a weakness in their VPN system. He prototyped a transition to Secure Access Service Edge and then deployed it across the agency.

Probably the best quote from this interview was provided by Akamai’s Tony Lauro. He said, “Security has to work despite users.” He is referring to the base concept behind Zero Trust – an automated system that can identify threats and provision resources with appropriate access levels that can have nothing to do with end users acting themselves.

Ron Popeil’s catchphrase may work on television, but not in today’s federal government.

Twitter: @FedInsider

LinkedIn: https://www.linkedin.com/company/fedinsider/

Facebook: https://www.facebook.com/FedInsiderNews

View Details

Technology maturing, constant attacks, automated responses

For the last ten years, everybody in federal software has been discussing the maturity model. We all know that a system must start, be managed, and be optimized. Unfortunately, only recently have advances in hardware and software allowed this process to take place.

Today, we listen to a conversation between a federal technology expert and a commercial subject matter expert with a focus on cybersecurity in a post-pandemic era. Covid kickstarted the ability for federal leaders to be able to be transparent and to collaborate securely. Perhaps this is a story about the technology maturing to give the ability to have an observability in a system with high compliance.

For example, Brian Dennis, Principal Technologist Public Sector, Akamai points out that micro-segmentation has always been known to prevent malicious actors from moving into the network. For years, this process has been clunky and woefully inadequate. Brian suggests that modern systems can make micro segmentation, and its impact on zero trust, easy and flexible.

Today’s federal agencies are under constant attack and must be adaptable enough to accomplish configuration and change management. Automation may hold the method to accomplish this complicated goal.

Many agencies have billions of actions a day and no human can keep up with responding to attacks. Today, systems are available where threats can be responded to in a rapid, automated, manner.

View Details

Network visibility, remote access, leveraging artificial intelligence.

Predictions are almost impossible in the rapidly changing world of military communications. Despite that, our tech leaders will offer ideas on visibility, a uniform defense network, and eliminating lateral movement in these networks. If you look at the past twenty years, an argument can be made that the DoD has responded quickly to attacks; however, the solution really hasn’t had resilience or redundancy in mind.

Today’s interview gives three ways the DoD is accomplishing the task of remediating some of these issues. The experts discuss software defined networks, network visibility, and applying artificial intelligence to these concerns.

Bill Urig observes that we have reached the human limit to understanding a complex network. One can’t apply any sophisticated preventative measures, like software defined networks, unless they have a deep and through knowledge of the network.

To this end, he has used tools from Red River and Akamai that can provide exact information to system administrators to identify the digital terrain. That information will tell systems analysts the difference between a failed server or nefarious activity.

During the interview, Col. Joseph Pishock addressed the issue of the future of Identity Credentialing, and Access Management. From his point of view, ICAM has always been a siloed approach. They may be able to take advantage of specific tools, but Secure Access Service Edge is best deployed when using a consolidated platform.

All are optimistic that the general trend of understanding the network can give a better response to an attack.

View Details

Trusting your network, sharing information, leveraging new tools.

The DoD has targeted 2027 as the date to make the transition to Zero Trust. The initiative includes 91 activities and 7 pillars; additionally, it wants the result to be flexible beyond 2027. This is an interview that includes a Major from the Army and a commercial subject matter expert who look at challenges and solutions to achieving that goal.

The discussion focuses on three areas: role of constant communications, inter service communication, and the concept of fabric at the edge for improved communications.

During the discussion, Major Cory Dombrowski mentioned the challenge of identifying people at the edge. In a world of constant communications, identification is the first step. If it takes a week to complete authentication, it may comply with the zero trust principles, but have no value.

If the Army gets attacked, they should be able to share that information with other branches of the military. In the interview, the participants talk about needing open lines of communications to be able to use data across departments.

However, parts of the DoD have made remote zero trust a reality. New systems have allowed segments to take in data, apply rules, and apply remediation. Edge based fabric allows them to authenticate remotely and optimize speed.

View Details

Maintaing operations while under attack

Today we have the first part of a three-part series with a focus on Cyber Threats 2023 in the DoD. This initial interview looks at high level considerations: cloud, identity management, and maintaining a secure network while undergoing improvement.

An argument can be made that in the past 20 years the DoD has responded to attacks in a siloed manner. In other words, they may have gotten a solution that worked, but it may not have interoperated with other aspects of the DoD.

Today’s threats are so overwhelming that focusing on a silo will make you vulnerable. Enterprise organizations are always difficult to change; the DoD is no different. Attacks have become so rampant that the DoD has had to review where they are, how they go there, and produce a plan to remediate concerns.

Cloud-based systems begin with identity management and can achieve the goals of quick response, reaching endpoints securely, and adapting to a rapidly changing attack environment. Proof of concept is an idea called Secure Access Service Edge. It allows the military to score access to any point in the globe. The success of this program showed that the military can leverage the cloud to secure the edge.

This is not being done in a theoretical environment, there is an initiative that a zero-trust architecture must be implemented by 2027.

Twitter: @FedInsider

LinkedIn: https://www.linkedin.com/company/fedinsider/

Facebook: https://www.facebook.com/FedInsiderNews

View Details

When you hear of scouts giving scholarships, you think of the University of Alabama discovering a defensive lineman in rural Georgia.

This is a story of the long-term result of the federal government discovering and developing talent. This effort had a tremendous long-term impact on improving cybersecurity in the government and commercial sector as well.

Today we have Travis Ross, the new CTO Federal for Rubrik. During the interview, you will learn about his fascinating career. Somewhat of a “Doogie Howser,” Travis was spotted early in his schooling to be a whiz at solving puzzles.

DISA saw his potential and helped him with a scholarship and training to leverage these unique skills to solve some perplexing problems. The amazing part is that his scholarship letter arrived on September 10, 2001. The incident the next day set the stage for his career.

He engaged in the early days of DoD PKI and the Public Key Encryption Program. After a distinguished federal career, he moved on to commercial organizations. He has chosen to work for Rubrik because he can apply the full spectrum of his varied skill set to apply commercial innovation to federal concerns.

If you are not hooked by now, you may want to know what his thoughts are on topics like compliance, software development, and continuous improvement. The overview is that compliance must be a continuous process and security must be “baked in” the code before it ever gets released.

Great perspective from a person who has sat in the federal and commercial seat helping federal leaders overcome major challenges.

Twitter: @FedInsider

LinkedIn: https://www.linkedin.com/company/fedinsider/

Facebook: https://www.facebook.com/FedInsiderNews

View Details

= = = =

What happens if a patch means replacing a $500,000 piece of equipment?

Malicious actors are equal-opportunity attackers. Of course, they will go after federal agencies in the cloud; they will also attempt to penetrate systems through good old-fashioned industrial equipment, assets, and processes – what has gotten the label “Operational Technology.”

We take it for granted that when an exploit is discovered we can patch our systems, whether in the cloud or on-premises. There is a much different story when we switch from patching Information Technology to Operational Technology.

Today’s interview brings together observations on reducing risk in operational technology from experts as varied as the NSA, CISA, and industry experts.

Tony DiPietro from NSA highlights facts like OT can be widely dispersed geographically. Further, many of these systems are not as flexible as an app in the cloud. In other words, you cannot rule out a patch and correct the patch the next day. Some OT systems take a long time to propagate. Further, because of the high degree of variability, one patch will not work for all OT systems.

The good news is that organizations like CISA have teams looking for vulnerabilities in OT. For example, Brandon Tarr discusses the fact that CISA has a five-phase method to seek out OT vulnerabilities. They work with over 3,000 independent researchers and that occurs across six hundred different vendors.

Marty Edwards suggests that many software applications are designed to look for vulnerabilities in standard IT systems, but few for OT. He reiterates the assertion that you cannot protect what you cannot see. The idea is one must have a thorough understanding of all aspects of OT in the system you manage.

One takeaway from the discussion is the dilemma that some organizations are facing. For example, what if you are in a hospital and have an MRI machine running Windows 95? The system cannot be patched and must be replaced. Can you justify a $500,000 expense for a new MRI?

View Details

“We already have Zero Trust,” what to do when broke, and Beyond Thunderdome

Today, we look at how the DoD is implementing Zero Trust Architecture. We will see some areas that deployed ZTA before it was mandated; some teams that couldn’t afford ZTA, and finally, a look at something called Thunderdome that may allow the department to reduce the adoption time from five years to one year.

Rick Simon is the cyber portfolio manager at the Defense Innovation Unit in Mountain View, California. Their mission is to reach out to commercial organizations and seek innovative ways to solve problems in the DoD. Because of the risk of connecting to outside environments, since its inception, the DIU has always implemented Zero Trust principles before they were released into an initiative.

When you listen to the interview, Robert Kimball describes a group in the Army that wanted to move to Zero Trust because they were constantly failing penetration tests. They had no money, so they did a “field expedient” and assembled the tools they had and, with this new configuration, managed to resist a red team penetration test.

The military never fails to impress with names for projects, DISA’s project Thunderdome fits the bill.

Rick Simon explains how it is a prototype that combines secure access with a wide range of technologies using Zero Trust as the approach to security. This project can allow the military to drastically reduce the time to implement Zero Trust.

Captain Patrick Thompson from the Coast Guard reinforces the concept that the cloud will give leaders the tools to move to zero trust, allowing people to get their jobs done at the speed of need even in areas of denied movement.

The concept of Zero Trust is confusing, listen to the interview to get several approaches; one may work for your agency.

Twitter: @FedInsider

LinkedIn: https://www.linkedin.com/company/fedinsider/

Facebook: https://www.facebook.com/FedInsiderNews

View Details

In January of 2021, Executive Order 13985 titled Advancing Racial Equity and Support for Underserved Communities Through the Federal Government was released. Today’s discussion shows how agencies are responding to that mandate around identity management.

It would seem there should not be a problem. The goal here is to make sure everyone has access to benefits, loans, and even FEMA support. In an ideal world, a citizen accesses a federal website, gets identified, and continues through the process. However, we have people get frustrated with the digital process of identification to the point where they abandon their requests.

Today’s discussion looks at the NIST's special Publication 800-63 and its fourth draft revision, which mentions advancing the equity of identity management.

David Temoshok is one of the experts at NIST who drafted the document. He explains some of his thoughts about how to manage large numbers of people trying to get identified. He explains some of the challenges in digital credentials and some advances made, referencing login.gov. From a broader perspective, he thinks that a federated approach to identity management may be the solution.

The 2017 NIST 800-63 included multi-factor identification, the current draft tries to take this concept to the next level. It suggests ways to make MFA phishing resistant. One of the weaknesses of making identification “frictionless” is the risk of overprovisioning.

Bryan Rosensteel from Ping brings a good perspective to the challenges of digital identification, he thinks that it is an exciting time to be involved in the world of identification, especially in one new aspect like automation and identity lifecycle management. He mentions topics like military systems that are disconnected, yet still must maintain credentials.

Twitter: @FedInsider

LinkedIn: https://www.linkedin.com/company/fedinsider/

Facebook: https://www.facebook.com/FedInsiderNews

View Details

What do you do when your daily log entries increase by a factor of fifty?

Shane Barney, USCIS describes that prior to the cloud he had about 200GB of log data a day; after the move to the cloud, this was multiplied by 50, they are at 10TB a day. Obviously, it is not possible to use old tools for a workload this large.

Everyone reading this knows that when the federal government made the move to the hybrid cloud, they became deluged with data. The solution discussed today is something called Cloud Security Posture Management. This is an approach that automates identification and remediation of risks across cloud infrastructures.

During the interview, the federal leaders gave examples of how they have gone through a digital transition and assumed everything was configured properly. After the transition, the error became obvious. One takeaway is that pilots have checklists, and systems administrators need an automated checklist to look for compliance issues and misconfigurations.

Jeffrey Lush, U.S. Air Force, summarizes the need clearly: there is a gap between what you know and what you don’t know.

Each expert observed that managing a cloud network gives better visibility, for instance, being alerted to when there are open ports, open potentially exposed to the Internet. Further, an approach that includes CSPM can give administrators monitoring, validation, and compliance specifically tied to many areas of the Zero Trust. The net result is early threat detection.

In a rare instance of validation of a digital transformation, Shane Barney estimates that his agency saved $25 million in savings through deploying a Cloud Security Posture Management system.

Twitter: @FedInsider

LinkedIn: https://www.linkedin.com/company/fedinsider/

Facebook: https://www.facebook.com/FedInsiderNews

View Details

Getting exhausted after 4, 294,967,296 addresses.

If you have been around federal technology for the last fifteen years, you have heard people warning ad infinitum about what happens when we run out of IPv4 IP addresses. Somehow, we humans have managed to take the existing IPv4 system and apply duct tape and wire to make it endure.

Listen to today’s interview to hear the clarion call about IPv6. The federal government is finally getting serious about systems being compliant with IPv6. There is a wake-up call to have 50% compliance by 2025.

In November of 2020 the OMB issues memorandum M-21-07 which details the strategic intent to operate its networks and access the services of others using only IPv6.

Today’s interview focuses on many of the observations to this transition made by Robert Sears. He is the chair of the federal IPv6 Task Force. He leads the efforts to get agencies together and try to bring folks to discuss various topics on technology, transition, planning, and we also work with the private sector to help them understand how they can help the government meet its requirements to move to IPv6.

Robert Sears provides guidance with the technical as well as the regulatory impact of this transition. He makes the sage observation that the noble goals from fifteen years ago can finally be accomplished with the powerful new tolls available.

Cricket Liu expands the discussion to include consideration of applications. Federal leaders must realize some legacy applications may not be prepared to run over IPv6.

Listen to the discussion to see the weakness of the current dual mode of operating and learn best practices to make the transition.

Twitter: @FedInsider

LinkedIn: https://www.linkedin.com/company/fedinsider/

Facebook: https://www.facebook.com/FedInsiderNews

View Details

This episode will remind you of the old McDonald’s slogan, “millions and millions” served.

Did you know . . .

5.0 million open jobs in cybersecurity?

$1.0 billion was allocated by the federal government for grants to improve cybersecurity standards for state, local, tribal, and territorial agencies?

$1.6 trillion in Accounts Receivable at the Department of Education?

$10.5 trillion is the estimate for ransomware attacks by 2025.

When listening to this episode, you will learn approaches to these questions from all over the map and everyone from a federal official to a subject matter expert from Rubrik. By now, most government leaders know of the upcoming funding under the infrastructure funding. The overriding theme is how to be good stewards of this new funding.

Further, this distinguished group delves into topics like security awareness, Multi-Factor Authentication, and encryption.

One observation from Steve Hernandez, Department of Education is that today, we finally have the technology to deliver on the promise of zero trust.

Samy Bouhaouala, Accenture Federal Services observes that threat actors have the same machine language and artificial tools we have. This means we must be careful how we set up new systems.

You will be shocked when you learn of the increases in cyber insurance States have seen. There are reports of increases of as much as 500 million dollars for an annual policy. Ray Yepes, of the State of Colorado, conducted a survey and discovered that most States were self-insured.

Adding to this increase is the fact that some insurance companies are not including ransomware in their coverage.

This interview will give you specific figures to understand the cost and challenges in the future of government cybersecurity.

Twitter: @FedInsider

LinkedIn: https://www.linkedin.com/company/fedinsider/

Facebook: https://www.facebook.com/FedInsiderNews

View Details

Right now, we are in the hype cycle for AI, Gartner calls it the “peak of inflated expectations.” Representations are made and many surprises are unearthed. This is an interview that focuses on definitions, reliability, and automation about applying AI to problems warfighters face.

What is AI?

Years ago, Alan Turing came up with the baseline definition of artificial intelligence – being able to mimic human responses under specific conditions. Some individuals in the episode argue we haven’t even approached artificial intelligence. A statement is made that just because you call it AI doesn’t make it AI.

Is the data reliable?

Years ago, the colloquial phrase was, “garbage in; garbage out.” Today’s massive data stores reinforce this concept. However, the phrase becoming more and more popular is, “authoritative data source.” Each thought leader in the discussion has ideas on cleaning data.

What is the role of automation?

During the interview, Michael Pomatto NAVAIR suggests that today’s interpretation of artificial intelligence has ramifications in the systematic processing of information. Robotic Process Automation is the first step. When machine learning is added, he calls it hyper-automation. What does it mean to do mundane office tasks?

What does the future hold?

Jaime Fitzgibbon, Defense Innovation Unit makes a provocative statement when she asks how technology leaders can plan ten years out when game-changing technology hasn’t been invented yet.

Future interviews will expand into topics like scaling, the amount of data needed, and bias built into the algorithm. These experts set the baseline for a fascinating future.

Twitter: @FedInsider

LinkedIn: https://www.linkedin.com/company/fedinsider/

Facebook: https://www.facebook.com/FedInsiderNews

Reference: https://www.ynetnews.com/article/sjg0qah83

View Details

What if you were responsible for a network of 80,000 users in 24 time zones? Just for fun, let’s make you responsible 24 hours a day and mistakes can be fatal. Your challenge: react in 90 minutes or less to an intruder.

Is it an incident or a cable cut? This can sound trivial until you realize that you are dealing with a life and-death situation.

This is the incredible challenge that faces the United States Special Operations Command.

Today, we hear the tactics and strategies from two colonels in the unenviable position of having responsibility. Listen to the interview to get a new perspective on handling an overwhelming number of signals in a lethal environment.

Col. Joseph Pishock talks about the “grey space.” We know the military has its proprietary secure networks – what happens when one needs to optimize by using commercial services?

Col. William Uhrig suggests that commercial companies may have a lead in understanding the cyber threat in this “grey” space. If that is the case, then the military will have to figure out a way to safely and securely take advantage of commercial capabilities.

Twitter: @FedInsider

LinkedIn: https://www.linkedin.com/company/fedinsider/

Facebook: https://www.facebook.com/FedInsiderNews

View Details

Here is the dilemma. On one hand, there is a constitutional mandate that American citizens have the right to petition the government; on the other hand, today’s leading attack tool, phishing, uses email as its primary attack vehicle. Traditional filters and gateway security have proven weak against this threat.

Today’s discussion gives you the best practices for managing this quandary and leaving your federal agency open to communication from citizens as well as keeping it safe.

Keep listening and you will find more challenges to deploying mandated solutions. Randall Vickers from the U.S. House of Representatives notes that they do not play by the same rules as the rest of the government. They are not mandated to comply with standard cyber regulations, and members of the House own their data. This combination makes it important to have a deep and thorough understanding of security practices, and the flexibility to apply them in this unique environment.

When listening you will find out that cyber security is not as simple as locking down a system. Let us take the many recommendations about cybersecurity collaboration. We know that federal agencies should share information about threats. When this encrypted information is sent from one agency to another, it is normally decrypted, inspected, and then encrypted and sent on its way. However, there may be compliance issues that prevent this inspection.

Zero trust and information sharing sure look good when they are proposed on a whiteboard. This is an interview that opens up some of the practical aspects of lofty federal mandates.

Twitter: @FedInsider

LinkedIn: https://www.linkedin.com/company/fedinsider/

Facebook: https://www.facebook.com/FedInsiderNews

View Details

Can segmentation limit the impact from a blast zone?

Early cyber attackers would enter a system and then roam about, a virtual “land and expand.” Once it was detected, it could be isolated; the area impacted was termed the “blast zone.”

One approach to containing damage is to limit the “blast zone” by structuring your network into modules, or segment that would restrict movement. Some draw the analogy to a submarine that has compartments that would prevent sinking.

In the inevitable game of cat and mouse, malicious actors countered by commandeering the apps that run on the network, this would effectively override any network segmentation.

Illumnio suggests that if you segment the apps themselves, you draw boundaries around components, regardless of whether the network infrastructure is segmented or not. You will be able to minimize the impact.

Listen to the interview to see how to stop attacks that go beyond network segmentation.

View Details

High-speed Internet has been so much a part of the typical listener’s life that few remember the construction crew in your neighborhood when you got high speed Internet. Contrasted to that, we all know about the massive infrastructure bill that is attempting to level the high-speed Internet playing field for everyone in the United States.

Lisa Von Bargen from the Alaska broadband office presents a nightmare scenario for trying to give Internet to rural areas. When describing the geography of the last frontier, she states much of Alaska is roadless. What will come as a shock is, in some parts of rural Alaska, it can cost as much as a million dollars a mile to cover that final distance!

Geographic considerations are forcing Lisa and her staff and technology partners to be more creative about offering high-speed connections. Listen to experts from states like Michigan and companies like Federated Wireless show how they are being forced to be flexible and creative in their approach.

One topic brought up was a solution called a 5G Private Network. If you have a rural area and can get fiber to one part of it, there are systems today that can set up wireless services to that geographic area. This “5G Private Network” provides options for redundancy and security that others don’t provide.

Speaking of flexibility, when it comes to Citizen Band Radio, we normally think of truck drivers. Innovation has come to the Citizen Band Radio Service. Listen to how Federal Wireless and AWS are using new parts of the spectrum to provide Internet to remote tribes.

Twitter: @FedInsider

LinkedIn: https://www.linkedin.com/company/fedinsider/

Facebook: https://www.facebook.com/FedInsiderNews

View Details

Lessons from episode number one of Feds at the Edge can be applied to the ninety-nine that follow

At first glance, it is an interview about a tragic fire that befell the world-famous Notre Dame Cathedral in 2019; however, looking deeper you will see that the description risk management can be applied to the life of every federal information professional.

The federal government sits on a legacy system that has proven to be successful for decades. The Notre Dame Cathedral was built in 1163. Our federal system is encased in impregnable data centers, much like the limestone of the cathedral.

As evidenced by a plethora of Executive Orders, acknowledgment is given to make changes, like Zero Trust, to reduce risk. During the interview, you will find that the cathedral had a fire protection plan put together by experts. Unfortunately, it was not deployed for fear of the transition to a safer environment was too risky in itself.

From the perspective of a federal project manager, it is a case study of concepts like risk management, probability, and monitoring. What assumptions are you making about a black swan event and your security system?

“During our case study, today, we are going to look at some of the assumptions, factors, and components that shaped the fire protection plan. And that may have ultimately led to its failure.” Dr. Natalie K. Houghtby-Haddon, Associate Director GW CEPL & Assistant Professor, GW College of Professional Studies

“That public tweet occurred before the fire department arrived at Notre Dame” Dr. Natalie K. Houghtby-Haddon, Associate Director GW CEPL & Assistant Professor, GW College of Professional Studies

Petabytes of data and forests of trees: “And it was called that because the wooden beams that made up that attic dated back to the 12th and 13th century, and wood for more than 1300 trees were cut down and used in building that attic.” Dr. Natalie K. Houghtby-Haddon, Associate Director GW CEPL & Assistant Professor, GW College of Professional Studies

Firewalls are standard practice for all computer systems today. “Officials chose not to alter the attic with any modern fire safety measures measures such as sprinklers, or firewalls” Tom Brandt, Chief Risk Officer, U.S. Internal Revenue Service

“What is risk appetite, it's the type and amount of risk that an organization is willing to accept in pursuit of values.” Tom Brandt, Chief Risk Officer, U.S. Internal Revenue Service

Risk Management does not just apply to moving to the hybrid cloud. “So, as you're accepting risk, are you accepting something that's high likelihood? And if it were to occur? Are you accepting something that's high impact?” Alice Miller, Chief Risk Officer, Millennium Challenge Corporation

Twitter: @FedInsider

LinkedIn: https://www.linkedin.com/company/fedinsider/

Facebook: https://www.facebook.com/FedInsiderNews

View Details

5G will be a massively transformative technology. This is an interview that shows you how the “mostly” 4G technology will be put on steroids with the transition to 5G. It is not just a numeral change; this new technology will impact enterprise systems all over the world.

Can 5G allow military applications to share spectrum?

Physically, we know that “dual use” means highly secure organizations, like the military using technology that is proven in the commercial world. The best example is military satellites “hitching” a ride on rockets with commercial satellites.

However, 5G has so much flexibility that allows the Department of Defense to apply the “dual use” concept to the communications spectrum.

Can federal applications take advantage of inexpensive hardware?

One of the main advantages of today’s data centers is using inexpensive generic hardware and varying the software. This concept of “disaggregation” can be applied through the flexibility that 5G offers.

Does 5G have an application in cybersecurity?

When it comes to patching software, the federal government needs speed. When gaps are found in systems, the speed of the patch is critical. The speed advantage of 5G allows the federal government to apply patches and update faster.

Where to invest 5 billion dollars

5G is forcing states like Louisiana to carefully consider how they should invest the estimated five billion dollars in infrastructure money they will be getting in the next five years. If a traditional fiber network can be destroyed by a weather event, what role should wireless play in bringing resilient high-speed access to rural areas?

View Details

According to Dr. Chase Cunningham, there are over 1.7 million ransomware attacks a day.1 This isn’t isolated to commercial organizations, these attacks include schools, hospitals, and state organizations.

Who pays? According to an article dated April 12, 2023, in VentureBeat Magazine, 83% of organizations paid up in ransomware attacks.2 What is the FBI policy on paying ransom? What happens when a state agency gets attacked?

Today we have two battle hardened cyber warriors who focus on state and local issues sharing details on how to prevent and recover from a ransomware attack.

organizations

“According to a recent survey conducted by Rubrik, 50% of respondents had dealt with ransomware attempts in the past year!” Steve Stone, Rubrik

Rubrik runs a lab that seeks out information on attackers. It is summed up nicely in four words.

“We operationalize evil finding,” Steven Stone, Rubrik

Some states have unique challenges in providing assistance or ransomware prevention. For example

“California has 58 counties, some are larger than the states that compromise the United States” Lloyd Indig, California

Twitter: @FedInsider

LinkedIn: https://www.linkedin.com/company/fedinsider/

Facebook: https://www.facebook.com/FedInsiderNews

View Details

In grade school, we all learned about states capitals and the geographic shape of each state. When you compare the way they manage technology, they vary drastically as well. When it comes to the way states structure their technology, some states are hierarchical, some are centrally controlled. Each state presents a unique way to solve the same problem: cybersecurity.

Today’s discussion combines federal leaders with technology experts from three states. Each person brings a different aspect to the discussion. One overriding theme that Solomon Adote reinforces is the importance of identity management. It seems to be the first pillar in the transition to a zero-trust architecture for federal as well as local governments.

= = = = = = = = = =

“Cybersecurity at the state level is a very interesting topic to me because every state is structured differently, every state IT organizational structure is different, and some have a very hierarchical structure and others are very centrally controlled and managed.” Michael Mestrovich, Rubrik

“Many of these federal programs we have in the states that do the work and all the data and interact with the citizens.” Suzette Kent

“People of Colorado and the people of Colorado are at different levels and stages of IT proficiency” Craig Hurter, Colorado

“Russian affiliated, organizations, they all have the ability with significant resources at their disposal, I think some have close to 740,000 bots at their disposal to generate a significant amount of traffic against any entity.” Solomon Adote Delaware

“But there has been workforce development change has come as a result of that as well” Jason Cavendish Michigan

“More significant in the public sector but is shared by the private sector is the talent challenge” Suzette Kent

Twitter: @FedInsider

LinkedIn: https://www.linkedin.com/company/fedinsider/

Facebook: https://www.facebook.com/FedInsiderNews

View Details

= = =

Most readers have seen the headlines about cyberattacks; a small percentage may even have been the target. The news media doesn’t seem to cover the many ways federal agencies are providing help to state and local territorial organizations. Federal agencies offer many ways to help understaffed local government. This includes providing resources, training, or directly helping. This is an interview with three federal experts who provide a tremendous amount of help for beleaguered state and local technology managers.

We all know the Secret Service was created by President Lincoln in 1865 to protect the currency. It is also obvious they provide physical protection for the President. What kind of information can they provide to state and local systems managers to prevent cyber-attacks?

The FBI, GAO, and CISA offer many suggestions and recommendations in the form of case studies and recommended practices. Did you know the Secret Service offers training opportunities at the National Computer Forensics Institute for state and local governments? Further, it has ways the federal government can pay for this training.

When most people think of the FBI they think of the iconic blue windbreaker, they are much more than that. Scott Nickerson reminds listeners of the 56 local FBI offices in the country. He thinks local organizations should reach out to these offices before a cyber-attack. They even have ways technology administrators can join the FBI cyber task force.

Twitter: @FEdInsider

LinkedIn: https://www.linkedin.com/company/fedinsider/

Facebook: https://www.facebook.com/FedInsiderNews

View Details

Ep. 95 Making Progress on the Zero Trust Journey

Leaders in the Federal Information Technology field plan to complete the Zero Trust transition over the next few years, but each will have their own unique path to follow.

In this week’s episode we’ve gathered thought leaders from HHS, the U.S. Census Bureau, the CIA and Rubrik to discuss this ever-important topic and what it means for each agency.

  • In agencies like the Census bureau that is known for collecting data every ten years, what role do identity devices play in the data they collect every day?
  • In agencies like the CIA with complex expertise architecture, what’s gotten easier to manage?

We’ll explore the idea that the approach to data itself has changed, and it has evolved from being a simple endpoint.

In his work as Tri-chair of a group being developed by HHS to work with multiple agencies in the Zero-Trust journey, Gerald Caron shares, “identity is very important if you talk about the pillars of zero trust.

Twitter: @FEdInsider

LinkedIn: https://www.linkedin.com/company/fedinsider/

Facebook: https://www.facebook.com/FedInsiderNews

View Details

By now you have heard of the millions of dollars the federal government is making available for 56 states and territories as well as 3,033 counties.

If you are interested in taking advantage of one of these grants, then you should listen to this interview with technology leaders who are intimately familiar with how grants are assigned to improve cybersecurity for states and territories.

Some basic rules: the funding will be distributed over four years. However, the awards are designed to be stretched out, so year #1 goes for four years, year #2 goes for four years, and so on.

Second, the states are expected to contribute an increasing portion of the investment. 10% of year one; 20% of year two; 30% of year four; 40% of year four.

The concept is to make sure the applicant has a good plan on how to effectively use the funds over a long period. According to CISA’s Trent Frazier, it is a formula-based grant program. The idea is for the states to use investments to close gaps or sustain abilities in cybersecurity. He suggests the best practice here is to identify vulnerabilities – how to use investment to mitigate risk

The experts address practical aspects. For example, counties vary in size and a smaller county may not have the resources to complete an application. Rita Reynolds from the National Association of Counties suggests that help is available with the application process.

Zhen Zhen Sun from Texas observes that this effort shouldn’t not just be a replacement of technology The idea is to replace technologies.

View Details

During today’s discussion, you will hear from subject matter experts who talk about what state and local organizations can do to prevent ransomware as well as how to prepare for the new funding opportunities that are targeted at improving defense against cyberattacks.

One of the biggest lessons of this discussion is the existential nature of a ransomware attack. According to Doug Levin from K-12 Security Exchange, in 2021 alone there were 166 cyberattacks in 66 schools. Six of those schools had to temporarily shut down.

The experts indicated three best practices: have a good understanding of your current situation, know what organizations offer free help, and get a grasp on how insurance works.

When you have a complete survey of your system, you will understand where you have gaps and that understanding will give you the ability to evaluate systems that can help. One unexpected consequence of this effort is this survey can help you complete an application for cyber insurance. Jennifer Lotze remarked that a few years ago her insurance policy application had a few questions; today’s is fourteen pages of requirements. Also, do not be surprised if rates have gone up 30% since your last inquiry.

Historically, state governments and schools have been underfunded when it comes to cybersecurity prevention. In an attempt to address this concern, the Infrastructure Investment and Jobs Act was passed in 2021. It allocated over one billion dollars to improve state, local, and tribal security between 2022 and 2025.

When it comes to free services, the discussion uncovered many resources. For starters, CISA offers Cyber Resilience Review and Ransomware Readiness Assessment; they are free assessments to know what is going on in your network.

The Department of Education offers a website called “Protecting Student Privacy” as a service from the Privacy Technical Assistance Center that provides up-to-date information on safe practices.

Listen to the discussion to get fantastic tips on prevention, free resources, and suggestions on how to navigate the turbulent waters of cyber insurance.

View Details

When it comes to modernization for federal IT most people focus on data centers, clouds, and agile software development. One key part of this effort must be acquisition. This is a discussion where subject matter experts from several agencies look at some new mandates from the executive office and detail how they are implementing them.

One key motivator is the FAR change that includes recommendations to open conversations with contractors and be more transparent. The goal is to open federal procurement to make it more equitable.

Craig Morgan from the DCMA details how they have a website that shows their strategic plan for modernizing tools and integrating the enterprise environment. They want to unify data so customers can make well-informed acquisition decisions. All participants point out how they are making their acquisition process more transparent.

One of the most remarkable approaches was from Monica Taylor from DHA. She discusses her success using the Procurement Innovation Lab. They have coached 148 procurement teams to lower the barrier for innovative contractors. The net result has been to encourage nontraditional contractors. The GSA takes the lead in this category with a website that includes The Nine Innovative Acquisition Practices as well as articles dedicated to keeping federal acquisition experts informed in areas of acquisition innovation.

Technology can assist in making the federal acquisition question system more equitable. Brian McCormick from ICF points out that some agencies suffer from siloed systems, separate data sets, and isolated workflows that prevent teams in agencies from communicating accurately.

Brian suggests that platforms exist that can implement Robotic Process Automation and protective analytics, better-leveraging data to make better-informed decisions. Procurement professionals can look at their experience with procurement and see trends. Perhaps they can see preferences for a certain kind of vendor. From there, they can address ways to make their acquisition more balanced.

This is such a detailed and nuanced conversation. Dive in to hear comments on The Price Act, The Chip Act, and much more.

View Details

When it comes to a top ten list of trending phrases in the category of technology, “backup” never cracks the top ten. After all, you merely make a copy of the existing data --- right?

Well, the millions of dollars have been lost to ransomware attacks have caused a sea change in approach to backups. In fact, after listening to this interview, you will see backup as an inflection point for recovery

The consensus of the subject matter experts in this discussion is to establish a strategy to prevent an attack and well as have policies in place after an attack.

One issue is the deployment of resources. Some governmental organizations are “siloed” to an extent that works to the benefit of attackers. One scenario is the security teams think the backup is managed by the backup team; the backup thinks security is someone else’s job. This causes delays in response time. The best practice here is to have tabletop exercises where stakeholders know exactly what to do in case of an attack.

Traditional ideas of backing up once a day are finished. One must consider backing up every four hours. On top of that, one must know where an accurate backup point exists.

During the discussion, Joseph King from CAS Severn indicated that phishing attacks resulted in a $20 billion loss in 2021 and government teams must not underestimate their opponent.

Comments from all participants indicate that cybersecurity is a cat-and-mouse game. Government agencies have backups, the attackers put malicious code in the backup. If one uses immutable technology for the backups, then the attackers move to the next level.

Joshua Stenhouse from Rubrik talks about current attacks where the policy for retention is changed. That way, they fool the organization into not retaining data at all. If you are considering a backup option, then immutability and policy structure must be included in the requirements.

The interview gives great advice for systems managers: do not assume backups will be there, you should evaluate your backups in a virtual environment, and don’t expect you can recover up to the last serviceable date.

View Details

Decades ago, system administrators would dream about having the storage we have today. Very few considered the ramifications of controlling and allowing access to petabytes of data that were increasing every day.

This is an interview with several experts from federal and state organizations who share challenges in handling large amounts of data whose access must be carefully managed. Considerations include compliance, retention, and making sure the data is accurate.

One concept discussed is data sharing. Jennifer Coester from the State of Delaware talks about groups who all agree that data must be shared between departments. The caveat is that they want access to other information but want to restrict access to theirs. Perhaps this is not a technical issue, but a concept that should be handled in management.

Administrative aspects of managing data were reflected in comments from David Sanchez from the Air Force. He handles completely different kinds of information and data. He observes that military organizations are so structured that initiatives from a high level may take time to trickle down to lower-level areas.

As an example, he cites policies for giving access to data. One size does not fit all. Policies for accessing nuclear data certainly vary from policies that involve medical information. Each functional area must have its own policies.

Medicare, Medicaid, and healthcare.gov each have tremendous amounts of information, with each category subject to specific legal limits to access. George Linares from the CMS shares with listeners how they have successfully been able to tag data by domains.

He does warn that just because you have figured out how to manage the existing system does not mean that you will not have challenges. There is a new federal initiative to examine health care from an equity perspective. Data scientists must be able to go back to existing systems and pull up pertinent information that will assist in evaluating new topics like this.

View Details

Digital transformation is a phrase bandied about everywhere these days. Its application is everywhere from ordering coffee online to the Pentagon. Just as a point of comparison, the DoD has 27 million people with over $3 trillion in assets and over 17 business systems. The amount of complexity is overwhelming for any project involving change.

Today’s interview brings together four experts in improving the existing Enterprise Resource Management (ERP) system in the federal government. The discussion gives the listener insights into the areas of strategy, automation, and process improvement.

The DoD is comprised of individuals with strong leadership characteristics. It is possible that each leader promotes their agenda at the cost of the others, and, at the expense of the overall agency objective. During the interview today, Greg Little, DoD, reinforces the new concept of starting with outcomes.

Once this is done, duplicative systems can be eliminated, and systems can be designed to reduce costs for the entire portfolio. The phrase that sums it up is, “have the business strategy drive the technology strategy.”

One aspect of accomplishing the digital transformation of an immense organization like the DoD is automation.

Greg Little provides more details on the complexity of IT at the DoD. There are over 25 accounting systems with more than 250 feeder systems. Conducting an audit with this level of complexity would never be possible with a few accountants and some spreadsheets. Automation is the only way to handle this number of systems, without it, the audit would not be sustainable.

The DoD is currently using Robotic Process Automation, and have 50 digital assistants. Of course, the goal is compliance with financial regulations, but automation allows leaders to use data to drive decisions, tie resources to performance, and financial stewardship.

Part and parcel of these large systems are legacy ERP. Jonathan Moak, Salesforce suggests that older systems must be incorporated into the move to the cloud. However, if can’t merely be a “lift and shift,” it must make finance part of the complete business management system.

Enhanced flexibility and interoperability will allow leaders to gain a better understanding of the impact of financial management on the entire agency.

View Details

IBM and the Ponemon Institute have reported that the average breach cost in 2022 was $4.24 million. If that is used as a rough estimate, data breaches in state and local governments can be very expensive. There is a lot at risk and budgets are tight. State and local governments really have to look at leveraging what funds they have.

Today’s discussion provides recommendations for sources of information on hardening systems, coming up with action plans, and the role of insurance.

There is no lack of help if you are seeking guidance when it comes to making your system secure. Guides from CISA and NIST give specific information.  Most suggest starting with an accurate evaluation of what is on your system.  There may be situations where people sign up for services with a credit card without informing system managers. System surveys are difficult when one has to look for shadow IT.  

Action plans normally start with ways to respond to an incident.  One weakness in a backup playbook is the time it takes to restore one system vs. ten systems. System managers may have to get ideas on unexpected circumstances.

Best practice is to harden your system and have an action play. The unintended benefit of documenting your security is qualifying for cyber insurance.  Risk assessment can vary in size of organization.  Insurers try to limit exposure – excluding certain events. One certain bet is that it will become more and more expensive to get cyber insurance.

You may not realize that a cyber insurance package can be an 11 page application   combination of entire system – every environment will have a different footprint. Tony Lauro Akamai mentions that an insurance plan must never be considered to be a substitute for a hardened system. 

View Details

Interest in machine language and artificial intelligence has been growing and growing since around 2015. It was a perfect storm where storage prices decreased, and virtualization became standard. Like most maturing industries, challenges appeared. It was found that the conclusions provided by artificial intelligence were dependent on the quality of the data it collected. This finding became so common that in 2020 the federal government responded with Executive Order 13960 promoting the use of trustworthy intelligence in the federal government.

This is an interview with a focus on applying that guidance across many federal areas, including cybersecurity.

Technology leaders from the National Science Foundation have formulated the National Artificial Intelligence Research Resource Task Force (NAIRR) https://www.nsf.gov/cise/national-ai.jsp to give guidance on using data more effectively. Recommendations include the categories of security privacy, civil rights, and sustaining the resource. The goal was to help get control of the unwieldy and expanding IT environments.

Wayne LeRiche, Palo Alto Networks, gives an example of applied AI with some of the security concerns relating to Domain Name Servers (DNS). Attacking a DNS server is a classic approach malicious actors have used for years. The traditional method of defense is rule-based. If “x” occurred, then react with “Y.”

Attackers can ratchet up the attack with something unknown that the rules-based system can’t handle it. AI can handle drastic increases in speed that a rules-based system can’t. Further, artificial intelligence can understand unknown methods of denying service to the DNS.

Rather than focusing on one aspect of prevention, experts on the panel suggest that Rule-Based and Machine-Learning DNS security services be used in parallel.

Finally, Tony Walker, NetScout, presents a scenario where one part of the team is proficient in network management while another part of the team has a sophisticated knowledge of data management. The solution that is provided by AI must be tempered with careful consideration of data sources and the ability to use that knowledge in an environment full of people with different skill sets.

View Details

Both federal and civil organizations are challenged with coming up with creative ways to keep and attract a modern workforce. During this discussion, federal leaders share innovations on retaining their workforce and replacing retiring employees.   

Paul Pietsch, Partnership for Public Service brings up some shocking statistics.  In one agency, the Gen-Z makes up only 1.6% of the workforce and, in the next two years, 33% of the federal workforce in that agency will hit retirement age. This second figure is sometimes referred to as the retirement tsunami.

The experts on the panel all admit that they are presented with a challenge of retaining the younger workforce, and, at the same time, reaching out to new candidates.  The only way to reach this goal is with forward thinking approaches. 

When it comes to keeping Gen X and Gen Z on board, the federal leaders discussed topics like rotating assignments, appealing to public service, assisting with student loans, including retention bonuses, flexible scheduling, and mentoring.

Post COVID, all agencies understand the attraction of remote working and having a flexible schedule.  One creative idea that is used at the Department of Education is rotating assignments.  A manager can offer an inducement for a person to stay with the agency by offering them the ability to learn new skill sets in other areas.

Another innovation suggested by Jacqueline Clay, Department of Education, is to form cohorts of people when they get hired. You can select them for specialized training.  Because they will get to know one another, they can share knowledge in an informal manner.

Mentorship programs have been started in some agencies, normally they last one year.  In a twist, some are experimenting with reverse mentorship: where a younger person can share knowledge of topics like Slack with professionals who may have expertise in other areas.

Some agencies offer financial incentives to keep team members and will compensate for a referral that results in a hire.

Today’s young people can have college debt, some studies show the average student debt is $18K.  Some agencies are offering up to $60K in student loan forgiveness.

If your target employees are participating in social media, then a wise leader should know how to communicate in that media.  Joseph Abbott, from the USDA, remarked they created a new vocabulary where agency concepts could be understood in a world of emojis and memes.

View Details

Federal mandates include Environment, Social, and Governance (ESG) policies. Like many federal initiatives they provide broad guidance and enacting these lofty goals can be difficult.

Today’s interview looks at leaders from the federal government, state, and local who share ways they have been able to include ESG goals in their organizations

Two of the people in the podcast are from California. Traditionally, California has been a leader in these efforts for decades. Andrew Collins, from the San Francisco Employee’s Retirement System, really sums up the challenge. Because he has a fiduciary responsibility to the people who retire, he tries to meet ESG goals, but must include risk management along with seeking opportunities for ESG characteristics.

The world of finance and investment is full of metrics. One challenge the discussion participants discussed is how to measure whether investments include climate change or even social equity goals. Brian Rice from the California State Teachers’ Retirement Funds lets listeners know about the 25 risk factors included in the evaluation his group uses.

Most people know that the National Science Foundation provides grants for a wide variety of needs. In response to a recent Executive Order indicating that ESG goals must be included in grant approval, the NSF has taken a slightly different tack than the state and local groups.

The NSF is looking at geographic targets for development well. For example, they are trying to create geographically diverse communities for investment in the NSF project. The idea is that no equity is accomplished if only one area has all the innovation. They layer ESG goals on top of this regional approach.

One innovation from the NSF is to create a repository of information about technology projects. For example, if a person is seeking funding for a specific biotechnology project, they can easily see where similar innovators are considering launching companies. This eliminated duplicative efforts and allowed for collaboration beyond one’s locale.

According to a recent survey from KMPG, ESG considerations about ESG are reflected in these recent Executive Orders. Results indicate 70% government should take a role in solving environment and social issues

ESG is an issue that is challenged with the balance of social goals while maximizing financial value creation. This podcast is a great introduction to practical ways to comply with ESG demands.

View Details

In the commercial world companies estimate annual sales and make a budget. Hard to apply basic management 101 to the Continuous Resolution situation that many federal agencies have found themselves in the past few years.

Today’s interview brings together several experienced federal professionals who give guidance on the new world of budgeting. Issues brought up include critical timing concerns, technical definitions, and the impact of shortened periods to accomplish annual goals.

Timing. An agency can set a budget, then not know when, or how much, they will get funded. Somehow, agencies manage to get by, but most of the lessons learned are part of institutional knowledge of each respective agency and are not shared.

For example, what if an agency plans an expenditure, then only gets 75% of what was planned? If a chunk of a budget is eliminated, how does an administrator prioritize what projects to continue and which ones to cut?

Definition. Under a CR, an agency cannot begin any projects. This leads to the legal parsing of the meaning of “new.” If a system replaces an existing system, is it new? When a system is maintained, is this a new project? If a vulnerability is found, can it be remedied with a new patch?

Compressed year. How long will the CR last? 30, 60, 90 days? Does this mean that each agency must produce an administrative plan for each shortened year?

The interview ends on a bright note. Elizabeth Field shows the GAO understands the challenges this presents. They have issued a report called Selected Agencies and Programs Used Strategies to Manage Constrains of Continuing Resolutions.

View Details

The three subject matter experts in this discussion give the listener a wonderful perspective on challenges and solutions to moving to Zero Trust.

The interview revolves around tools needed to audit a network, risks inherent in a hybrid cloud, a why a Zero trust platform gives an agency the flexibility it needs to deploy zero trust effectively.

Every discussion about zero trust for government agencies starts with trying to determine what is on your network. Smurti Shah from Michigan notes that tools that commercial organizations can use to accomplish that task may not work in a government environment. Therefore, State and local organizations must select Governance, Risk, and Compliance (GRC) solutions that are permitted.

Ian Farquhar from Gigamon brings up a fascinating issue with the “discovery” aspect of network analysis: cognitive bias. For example, a systems administrator may swear on a stack of bibles that they have documented every single item on the network. Ian mentions simple questions like: What about that copier? Does it ever have sensitive documents on it? What about the printer? If your organization allows employees to bring in devices, what kind of security implications does that bring?

During the discussion, the concept of “trust” was unpacked. We know that trust applies to “who” and “what,” but what about the system itself? Ian Farquhar applies trust to logging and Cloud Service Providers (CSPs).

The Solar Winds event looks like it started with the modification of the logs themselves. If you trust the logs, then you can be vulnerable to attack, one should apply zero trust to log controls.

One approach to minimizing vendor lock-in is to use a hybrid cloud. This adds complexity to an already complicated situation. The CSPs certainly do a wonderful job at telling people about the security of their cloud. Be careful to apply controls to that cloud environment, offloading trust to them can put you at risk.

All participants agreed that zero trust gives the flexibility to handle attacks today and in the future.

View Details

An argument can be made that the Solar Winds breach precipitated the interest in Zero Trust in the federal government. Thousands of words have been written, justly, about the incident. However, much less attention has been given to how SolarWinds has handled the situation.

SolarWinds has provided us with a classic case study on how to handle a crisis. They have been transparent, changed leadership, and have made strategic acquisitions that help them serve customers better.

An example of that strategy is today’s interview with Gregory Fetterhoff, the CEO of Monalytic. It was acquired by SolarWinds and operates as a separate company. An argument can be made that new leadership at SolarWinds has objectively looked at how to improve service to federal customers and made the acquisition of Monalytic to remedy the situation.

During this interview, Gregory Fetterolf gives three reasons why this partnership is effective: the skill set Monalytic brings, accommodations made for corporate culture, and the synergy gives Solar winds the ability to serve the federal government in other areas.

Monalytic is comprised primarily of people who have served in the military or federal government. SolarWinds had extensive experience in commercial environments. The credentials that Monalytic brings to the table allow them to have a deep understanding of federal needs.

Consultants like to say culture eats strategy for breakfast. What happens when two completely different cultures get thrown into the same room? Leadership at SolarWinds has the confidence to allow the successful culture at Monalytic to continue, garnering respect from all employees.

The strength of this new partnership is revealed in the interest of both federal as well as commercial organizations. From the government side, they appreciate the ability of Monalytic to understand their needs. Commercial entities know that federal compliance is difficult; if they start with federal compliance, the commercial concerns go away.

Sometimes, it takes an event to show the true strength of a company.

View Details

When the World Wide Web was developed in the late 1980s the idea was you could get information from the platform easily. Well, that certainly worked. In the past thirty years, this “interconnectedness” has brought benefits and unexpected risks.

One of the dangers is the ease of one system connecting to another. Great if you want to validate a person’s identity; also beneficial for a malicious actor to place code in a system that automatically updates.

The most egregious example of the danger of automatic interconnectedness is the Solar Winds event. Systems were set where network “A” trusted code from network “B.” The cyber attackers took advantage of this trust and inserted code into the target system.

The application for systems managers is obvious – if your architecture is designed to connect to trusted third-party solutions providers, how can know the code is clean? If you combine that with the lack of staff that most state and local governments have, then you have a serious problem. Just to amplify the situation, remote connections blossomed in COVID and the number of logs to manage is out of control.

This is a discussion where subject matter experts from software companies, federal leaders, and county practitioners sit down to provide some suggestions to solve the vexing problem. One possibility is to treat code in a “suspected” manner. Take each system update and consider it as malicious and run it in a sandbox before deploying. Unfortunately, this is a labor-intensive process, and we are assuming a situation with a lack of professionals.

Bill Harrod from Ivanti suggests that systems administrators can take advantage of artificial intelligence and automation to vet patches and updates quickly. If there is an issue, remediation can take place rapidly.

Another remedy discussed was including text in future contracts where software vendors must assure end users that the code they provide has been thoroughly evaluated. This does nothing for a system in place today, but it is a good long-term preventative measure.

View Details

This interview is a terrific primer for preparing your agency to prevent ransomware.  We have four experienced thought leaders who discuss issues like knowing what is on your system, where to find free prevention resources for a limited staff, and best practices for maintaining a safe network. 

Knowing what is on your system is the basic starting point for security, however, this simple concept can be difficult to accomplish.  Auditing your system can be compromised through users avoiding consolidation through shadow IT.

The term “shadow IT” has had Its peaks and valleys of interest in the past decades – some refer to it as “unauthorized modifications.” The origins are obvious.  If a system administrator makes it onerous to comply with security directives, users will come up with a workaround and use a credit card for an application, unknown to management.

The federal government understands the staffing challenges of state and local governments. As a result, the Cybersecurity & Infrastructure Security Agency (CISA) provides guides and training for these groups. During the interview, we learn that CISA is developing guidelines for an attestation letter.  This would act as a trust mechanism for smaller agencies concerned about malicious code coming from vendors.

Even if your system is thoroughly reviewed and current with updates and patches, you can still be vulnerable.  One simple instance of best practices is offered by Bill Harrod from Ivanti.  He suggests that each update must be tested and validated before being installed.  This is because of the complicated nature of hybrid systems today.  One update can have an impact on another system that is dependent on it.

Much to unpack in the group discussion – they talk about automation, machine learning, and the software lifecycle as it is applied to the software supply chain.

View Details

Today’s interview looks at ways state and local government entities can prevent ransomware. Traditionally, these organizations are understaffed and underfunded when it comes to cybersecurity professionals.

The unintended consequence of this budget constraint is making them vulnerable to ransomware attacks, with its thousand-fold cost. The interview will give you a plethora of free resources to help your organization prevent a ransomware attack if you have a limited budget.

A part of the Department of Homeland Security, Cybersecurity and Infrastructure Security Agency (CISA) has assembled a Joint Ransomware Task Force. It had its first meeting in September of 2022. One of the ambitious goals was to provide free information to help organizations, like State and Local Governments, with ransomware prevention.

Well, they delivered. StopRansomware.gov https://www.cisa.gov/stopransomware is authentic. It provides information on DNS blocking and even offers a free phishing assessment. Additionally, they offer best practices for backups, multi-factor authentication, and user training.

During the interview, you will learn there are over 90,000 State, Local, Tribal, and Territorial (SLTT) groups who lack the resources to establish a reasonable defense against attack. Many do not realize that just because you pay the ransom does not mean they will not attack again. Even worse, you may pay the ransom and then the data can be released anyway. There is no honor among thieves.

Doug Levin, K12 Security Information Exchange, gave an intriguing four-part summary of risks SLTT organizations face:

1 Primary attack vector will be email phishing – CISA can help in training

2 Legacy systems may not be patched, making them exposed

3 Due to a lack of budget, organizations may have vulnerable legacy applications

4 Passwords can be compromised (The result of a phishing attack)

SLTT groups are not alone in ransomware prevention. Federal organizations are stepping into the gap by helping in many ways.

View Details

When one reads the current literature on federal systems and zero-trust architecture, one gets overwhelmed by diagrams, charts, and prescriptive messages.

Lots of “should” and not many “we did.”

Well, this podcast will fill in the gaps. This is a discussion between a subject matter expert from Palo Alto Networks and a federal zero-trust practitioner. They dissect the best approaches to Zero Trust and give practical guidelines for migrating to a zero-trust architecture for a federal environment.

The discussion starts with how to select priorities. Everyone knows that Zero Trust is not a minor change that is merely adopted overnight. If zero trust is a journey, where does one start, and what priorities should be set?

Drew Epperson Palo Alto Networks provides the most practical advice on this concern. He suggests that you should identify the public attack surface and gain an understanding of where your valuable assets are located. The fantastic point he makes is that if you have a zero-trust system that does not allow the protection of assets dynamically, then you should start from scratch.

Beau Houser, US Census Bureau, makes a valid point when he suggests that a move “left” in the software development process will make Zero Trust much easier to deploy. In the parlance of software developers, a security move “left” means, on a timeline for a project, security considerations are given during the actual process of putting together the code.

One risk that is pointed out is that a systems administrator may be relieved that the code is being developed with security considerations, some may say “baked in.”  The concern is that that person may get lulled into not worrying about continuous monitoring of the code. There very well could be a zero-day attack built into the code that will only be released later.

The interview concludes on a positive note. Beau House relates how his agency is having remarkable success in training technical staff. The dual benefit is it aids in staff retention and makes the transition to zero trust much smoother.

View Details

Ransomware is targeting vulnerable populations at hospitals. A hospital presents a “perfect storm” for attackers: thousands of apps, a multiplicity of medical equipment connected to the Internet, and sensitive information being stored.

In today’s podcast, Scott Pross applies his healthcare background and technical savvy to offer suggestions to prevent these attacks.

From his background in healthcare, Scott Pross knows that healthcare professionals have a wide variety of applications that they can use. He suggests that a good approach is to interview users to see exactly what applications they constantly use and what ones are relegated to the back shelf. Armed with this knowledge, a systems administrator can prioritize which applications to lock down.

Also, there are several areas to monitor and the approach he suggests is to develop a dashboard system that has areas for topics like the network, Email server, Accounting, and Marketing. This way, managers can get an idea of which systems can be used and which ones should be avoided.

Scott Pross suggests a dashboard system provides three main benefits, especially in a healthcare environment. First, the simplicity of a dashboard could translate IT issues into business issues. Rather than being informed of a specific event in a log, a graphical description could be given to show how that incident would impact the functions of, for example, the Email server. That way, managers could inform staff about issues and resolutions.

Second, because leaders have a visual element in front of them, it stops them from physically going down to the server area to interrupt network administrators doing their work.

Third, information from the dashboard could empower managers to make business decisions. For example, if there were storage issues, a business decision could be made to add storage arrays to eliminate concerns in the future.

View Details

When you read the current literature on cloud systems management, one key factor is what is called “observability.” With so many moving parts, one tends to focus on a specific group of indicators and miss the overall activity.

When Vivek Kundra started to talk about “Cloud First” back in 2009. He had no idea the size and complexity of clouds that would evolve in his desire to reduce cost and increase flexibility for federal projects.

SolarWinds has been a leader in system observability for decades. Today, we have a person who has successfully used Solar Winds on a variety of systems and relates some of the best practices for gaining this elusive observability.

Scott Pross has seen systems managers look at specific aspects of federal systems in silos. For example, a manager may have data coming in on servers, or even the network itself. Another set of metrics may give information on applications. Managing virtual environments has evolved into a category in and of itself.

When a problem arises, a troubleshooter may microfocus on an area, but not realize how it impacts the entire ecosystem. Scott suggests that using solutions from SolarWinds can give a systems analyst a view from 40,000 feet instead of ten feet off the ground.

Another consideration is how to monitor activity in a cloud when its architecture is changing. The change may be for compliance reasons, expanding applications, or something as basic as running out of room and having to adapt to an influx of data.

Leaders of federal agencies are not interested in extremely detailed observations about logs. They want to know when their application will be available for citizens or employees. Addressing this issue, Scott details how, using SolarWinds, he can assemble dashboards to give leaders a better understanding of what has gone wrong to enable them to make data-based decisions.

View Details

We all read the Executive Order on Improving the Nation’s Cybersecurity when it came out. It was great at telling federal technology leaders “what.” Unfortunately, it was not too detailed on “how.” Today’s discussion gives the listener a fantastic dose of practical applications.

We have tech visionaries from the DoD, CISA, GSA, and CrowdStrike. They offer suggestions based on years of federal experience. The discussion ranges from gap analysis to prioritize needs to the evolution of the Trusted Internet Connection (TIC) from 1.0 to 3.0. Further, an analysis is given of the progress of agencies on incorporating point of a reference architecture to specific recommendations for the DoD to comply with zero trust.

Kevin Gallo gives an overview of TIC. Initially, its goal was to limit the number of connections a federal agency had to outside sources. Since its inception in 2007, the federal government has seen an explosion in endpoints and cloud services. As a result, some view TIC 3.0 has a distributed cybersecurity policy enforcement tool.

Speaking of the multiplicity of clouds, there are so many moving parts that any solution must include the ability to interconnect with many systems. Ned Miller from CrowdStrike talks about the millions of endpoints CrowdStrike has already secured in an incredibly complex system.

For civilian agencies, the GSA is offering a Buyer’s Guide that can assist leaders in assessing offerings that can lead to a stable zero-trust architecture. Additionally, they offer free workshops on implementing Zero Trust where hundreds of federal technical people have participated.

From the DoD Randy Resnik gives the listener a detailed description of the 45 capabilities and the 151 activities that must be accomplished before an effective deployment of Zero Trust can be accomplished.

If that is not a full plate, the interview ends with a serious overview of threat hunting. Perhaps this august group and meet again and provide more details on this important topic.

View Details

Veeam has a focus on making sure its solution is powerful but user-friendly.

Well-regarded technology guru Bruce Schneider once said, “Complexity is the enemy of security.” This maxim is an effective way to describe how Veeam helps its customers all over the world. Veeam protects over eleven million accounts with systems that are easy to use and able to be integrated into other parts of the environment.

Today’s focus is on assisting schools to improve their defense against ransomware. We have a technology specialist from Northeast Technical College in Wisconsin sit down with Aaron Murphy from Veeam. They discuss topics like the ease of use, the hybrid cloud, and platform and tools.

Karl Reishi makes a profound observation when he says that the use of the cloud has matured. Rather than the old phrase, “Cloud First,” he suggests that the best practice is to have a reasonable plan of what you want your system to look like after the transition. Flexibility is key in the world of multiple clouds, especially when it comes to disaster recovery.

Another aspect of “cloud maturity” is realizing the two environments you plan to have this year may transition to four or five in the future. Aaron Murphy adds to the discussion when he observes that a recovery process must be in place, and assessed, for each of these environments.

From Karl Reishi’s experience, the cost of moving to the cloud is a wash. The main benefit he sees is it releases technical talent from the drudgery of security checklists and maintenance so they can concentrate on understanding the needs of students and teachers.

Few technology discussions include the concept of protecting the application in the whole lifecycle. That means protection must start during development, continue through testing, and then until the application is ended.

View Details

Today’s discussion could not be timelier. COVID has brought an increase in ransomware attacks on schools. Here, experts sit down and describe the kinds of attacks schools are encountering and offer practical remedies.

It is front-page news that COVID has impacted learners from kindergarten to high school (K-12). Assessments are being challenged, teachers are quitting, and students are frustrated. If that were not enough, we have seen that this shocking transition has left school systems open for attack.

From a strategic perspective, it makes sense. It has been drilled into adults not to click on a strange-looking email. However, COVID has forced all communications between teachers and parents to be via email. Harried and under pressure, it is not surprising that someone clicks on a phishing email.

Further, at least adults can check their credit scores and may get emails from a credit card or bank of suspicious activity. No true with a ten-year-old. An identity can be compromised online, and a malicious actor can run up thousands of dollars of purchases in a mere 30 days.

It has been reported that a school district in Iowa recently paid the ransom to get school data back.

The story must start at the school itself. Elvis Teah from the Baltimore Public School System states that the main problem is with phishing emails; he also reinforces the concept that you need an infrastructure to listen to traffic entering and exiting.

Small school districts all over the country have limited staff. When COVID hit, the limited staff had to spend most of the time making sure students and teachers had access to online resources. As a result, we have seen a spike in school attacks.

Doug Levin from K12 Security Information eXchange has a deep understanding of the situation. He thinks that smaller schools must take advantage of the information on cybersecurity available from CISA and organizations that provide K12-specific information.

View Details

Federal agencies are pushed and pulled in different directions. A notable example is the entire process of adding staff. It takes an estimated one hundred days to make a hire. Human resource professionals are pushed to speed that up. On the other hand, agencies must also comply with mandates to increase diversity. How many hours are in the day to review resumes?

The answer may be by applying artificial intelligence. Today’s discussion focuses on the ability of artificial intelligence to help speed through applications and, at the same time, be able to increase diversity in the workforce.

Joe Biden’s sweeping Executive Order improves the federal workforce by improving diversity, equity, inclusion, and accessibility (DEIA) in the federal workforce. It was announced on June 25, 2021. It is getting some momentum because in September of 2022 the Chief Diversity Officers Executive Council will look at making suggestions to help agencies achieve compliance.

It is a challenge to apply these mandates to the volume of applications received. Greg Singleton from HHS estimates they have 90,000 direct employees.  A big number for a stressed human resource group to review diversity.

Dan Hopkins from Eightfold AI states that applying artificial intelligence to this problem will start by creating overall efficiency. It can also provide deeper insights into what is required for the role. Finally, it can help oversee the hundreds and thousands of applications the federal government gets a year.

Carol J. Smith from the DoD has had an experience where she has seen bias in the methods to produce artificial intelligence. If the data is going to be collected and curated by humans, then it could have a bias. She recommends a human be integral to the process of any applied intelligence.

View Details

The federal government is trying to update much of its neglected infrastructure. They have grants available to replace bridges and roads, and even improve broadband access for everyone.

Unfortunately, many of the systems the federal government uses to manage these grants are as outdated as some of the bridges that are targeted with the funds.

Now, this would not be a cause for concern if the grants were small and manageable. However, there has been an explosion in the amount and number of grants federal agencies must manage.

In today’s discussion, the traditional way grants have been managed could be viewed as a system that needs to be updated as well. The number of grants and the amount of money is going from the millions to the billions.

Brette Fisham, Department of Treasury begins the podcast with a fantastic overview of where federal grants management was, where it is now, and where it is headed. She describes a decentralized system where each of the fifty awarding agencies had its grants management system, at one time. The systems did not talk to one another.

She mentions that it was only in 2013 that the federal government enacted grant regulations, until that time, each agency was operating under its own rules.

To add to the structural inadequacies of grants management, the application process itself has become burdensome. For example, some organizations may submit a 200-page application for a grant. Paper-based systems are inherently slow and can have constant bottlenecks.

During the discussion, the concept of centralizing and digitizing the process of application, management of the grant, and then, closing it out was described in detail.

The example of expanding broadband was brought up as a case in point. The old paper-based system was designed for a set of applicants who knew the inner workings of the government, limiting the equity of the application process.

Another benefit of a centralized grants management system was physically determining where new broadband service should be installed. A digital system would allow for a graphical depiction of geography, allowing agencies to accomplish their goal of equally distributing access to high-speed Internet.

View Details

The federal government is trying to update much of its neglected infrastructure. They have grants available to replace bridges and roads, and even improve broadband access for everyone.

Unfortunately, many of the systems the federal government uses to manage these grants are as outdated as some of the bridges that are targeted with the funds.

Now, this would not be a cause for concern if the grants were small and manageable. However, there has been an explosion in the amount and number of grants federal agencies must manage.

In today’s discussion, the traditional way grants have been managed could be viewed as a system that needs to be updated as well. The number of grants and the amount of money is going from the millions to the billions.

Brette Fisham, Department of Treasury begins the podcast with a fantastic overview of where federal grants management was, where it is now, and where it is headed. She describes a decentralized system where each of the fifty awarding agencies had its grants management system, at one time. The systems did not talk to one another.

She mentions that it was only in 2013 that the federal government enacted grant regulations, until that time, each agency was operating under its own rules.

To add to the structural inadequacies of grants management, the application process itself has become burdensome. For example, some organizations may submit a 200-page application for a grant. Paper-based systems are inherently slow and can have constant bottlenecks.

During the discussion, the concept of centralizing and digitizing the process of application, management of the grant, and then, closing it out was described in detail.

The example of expanding broadband was brought up as a case in point. The old paper-based system was designed for a set of applicants who knew the inner workings of the government, limiting the equity of the application process.

Another benefit of a centralized grants management system was physically determining where new broadband service should be installed. A digital system would allow for a graphical depiction of geography, allowing agencies to accomplish their goal of equally distributing access to high-speed Internet.

View Details

If you want to cover the breadth and scope of protecting assets in today’s rapidly changing world, it is best to get a wide range of opinions. The diverse group who sat for this discussion come from local, state, and federal backgrounds and, because of that background, give the listener a tremendous perspective on this important topic.

The interview examines priorities, sharing threat information, and the responsibility of management to provide the time and tools for security professionals to do their job.

It is headline news when an oil line gets attacked, but our experts agree that a topic that is not newsworthy is key to keeping data safe: the basics. All three technology leaders said that one must get methodical with basics, like patching, eliminating weak credentials, and instructing staff about social engineering.

Sharing information is a much-debated topic in the cybersecurity community these days. During the discussion, Terry McGraw talked about some of the legal liabilities of disclosure in the commercial world. He suggests that systems administrators who want to share information on attacks are hamstrung by legal considerations.

This is contrasted with some of the new ways threat information is shared in state and local organizations. Jeremy Wilson from Texas lauds the ability of the Multi-State Information Sharing and Analysis Center (MS-ISAC) to help with distributing threat knowledge.

He also mentions the value of training. One department in the wide-ranging realm of the state of Texas information technology was looking at a 30% click-through rate with phishing attacks. He says that a training program dropped that click-through rate to 4%.

Terry McGraw’s final comments were very transparent. He stated that proper protection of assets may not always involve the latest and greatest offering. He suggests that leaders can get the most value from establishing best practices for patching and protecting authorized access to information.

View Details

If you want to cover the breadth and scope of protecting assets in today’s rapidly changing world, it is best to get a wide range of opinions. The diverse group who sat for this discussion come from local, state, and federal backgrounds and, because of that background, give the listener a tremendous perspective on this important topic.

The interview examines priorities, sharing threat information, and the responsibility of management to provide the time and tools for security professionals to do their job.

It is headline news when an oil line gets attacked, but our experts agree that a topic that is not newsworthy is key to keeping data safe: the basics. All three technology leaders said that one must get methodical with basics, like patching, eliminating weak credentials, and instructing staff about social engineering.

Sharing information is a much-debated topic in the cybersecurity community these days. During the discussion, Terry McGraw talked about some of the legal liabilities of disclosure in the commercial world. He suggests that systems administrators who want to share information on attacks are hamstrung by legal considerations.

This is contrasted with some of the new ways threat information is shared in state and local organizations. Jeremy Wilson from Texas lauds the ability of the Multi-State Information Sharing and Analysis Center (MS-ISAC) to help with distributing threat knowledge.

He also mentions the value of training. One department in the wide-ranging realm of the state of Texas information technology was looking at a 30% click-through rate with phishing attacks. He says that a training program dropped that click-through rate to 4%.

Terry McGraw’s final comments were very transparent. He stated that proper protection of assets may not always involve the latest and greatest offering. He suggests that leaders can get the most value from establishing best practices for patching and protecting authorized access to information.

View Details

This is a discussion that provides the listener with ideas of how agencies are adopting identification to enable to zero trust and gain some insight into the evolution of access control in the federal government.

The federal government certainly is not a monolithic enterprise; it must manage mundane requests like access to National Parks as well as negotiate atomic energy agreements.

NIST has reinforced the fact that identification is the first component of deploying Zero Trust. When a mandate comes from the White House to target Zero Trust, it makes sense that each agency will have a history of identification systems and have a different level of sophistication when it comes to identity management.

Bryan Rosensteel from Ping gives a remarkable analysis of the evolution of Attribute Based Access Controls. His purview is immense. He begins by examining the historical application of Attribute Based Access Controls. He comments they were effective but tedious to deploy.

To streamline this system, Role Based Access Controls were implemented. Unfortunately, today’s technical climate allows malicious actors to steal identities and defeat the RBAC method. Bryan Rosensteel argues that today’s dynamic system will have to revert to the precise controls that ABAC provides.

The weakness of Multiple Factor Authentication is reviewed by David Temoshok, NIST. He suggests that when a person gets a code via SMS text message, it is transmitted via the public telephone system. He calls this weak MFA. This is another reason today’s Role Based Access Control, can provide the kind of security that some agencies require.

FEMA’s needs for identification are broader than most. Dr. Gregory Edwards from FEMA understands the complexity of cryptographic identification models, but he also recognizes that he cannot give every flood victim a federally issued PIV card. Solutions must be provided where FEMA optimizes quick access to federal assistance while maintaining security controls so vital for federal information technology.

Listening to this podcast will give the listener a terrific overview of innovations in access control and the variety of ways federal agencies are coping with identification with the new focus on Zero Trust Architecture.

View Details

This is a discussion that provides the listener with ideas of how agencies are adopting identification to enable to zero trust and gain some insight into the evolution of access control in the federal government.

The federal government certainly is not a monolithic enterprise; it must manage mundane requests like access to National Parks as well as negotiate atomic energy agreements.

NIST has reinforced the fact that identification is the first component of deploying Zero Trust. When a mandate comes from the White House to target Zero Trust, it makes sense that each agency will have a history of identification systems and have a different level of sophistication when it comes to identity management.

Bryan Rosensteel from Ping gives a remarkable analysis of the evolution of Attribute Based Access Controls. His purview is immense. He begins by examining the historical application of Attribute Based Access Controls. He comments they were effective but tedious to deploy.

To streamline this system, Role Based Access Controls were implemented. Unfortunately, today’s technical climate allows malicious actors to steal identities and defeat the RBAC method. Bryan Rosensteel argues that today’s dynamic system will have to revert to the precise controls that ABAC provides.

The weakness of Multiple Factor Authentication is reviewed by David Temoshok, NIST. He suggests that when a person gets a code via SMS text message, it is transmitted via the public telephone system. He calls this weak MFA. This is another reason today’s Role Based Access Control, can provide the kind of security that some agencies require.

FEMA’s needs for identification are broader than most. Dr. Gregory Edwards from FEMA understands the complexity of cryptographic identification models, but he also recognizes that he cannot give every flood victim a federally issued PIV card. Solutions must be provided where FEMA optimizes quick access to federal assistance while maintaining security controls so vital for federal information technology.

Listening to this podcast will give the listener a terrific overview of innovations in access control and the variety of ways federal agencies are coping with identification with the new focus on Zero Trust Architecture.

View Details

Some will argue that COVID has forced federal agencies to move to the cloud and drastically increased remote access. One of the unintended consequences of this transition is a realization that the data that is created in these environments must be managed much better than in traditional, on-premises circumstances.

If agencies are all on the same page with classifying and managing data, that will reduce friction and allow agencies to get the maximum benefit of all this data and understand patterns and trends.

Hannah Hunt is the Chief Product and Innovation Officer for the Army Software Factory. They are the leading edge at agile software development in a highly secure environment. To rapidly develop solutions, they may spin up environments where data exists for an hour. Given those constraints, it only makes sense to have continuous security and continuous compliance with the data.

One obstacle to being able to work with data sets in an extremely flexible environment is starting with effective data management.

Unfortunately, in the commercial world and the federal government, a lot of data management is still manual. No systems administrator would pause to automate the production of a new virtual environment, but eyebrows are raised when data is managed in an automated manner.

During the discussion, the topic of Shadow IT was brought up. For example, if a system is set up for compliance and it takes days to get answers.

Human beings, as they will, will find ways to circumvent these compliance models and subvert the system.

That is why Dan Graves from Delphix suggests that if you produce a data management system that is compliant and fast, that will reduce the temptation for end users to set up apps that are independent of the compliance requirements.

View Details

Some will argue that COVID has forced federal agencies to move to the cloud and drastically increased remote access. One of the unintended consequences of this transition is a realization that the data that is created in these environments must be managed much better than in traditional, on-premises circumstances.

If agencies are all on the same page with classifying and managing data, that will reduce friction and allow agencies to get the maximum benefit of all this data and understand patterns and trends.

Hannah Hunt is the Chief Product and Innovation Officer for the Army Software Factory. They are the leading edge at agile software development in a highly secure environment. To rapidly develop solutions, they may spin up environments where data exists for an hour. Given those constraints, it only makes sense to have continuous security and continuous compliance with the data.

One obstacle to being able to work with data sets in an extremely flexible environment is starting with effective data management.

Unfortunately, in the commercial world and the federal government, a lot of data management is still manual. No systems administrator would pause to automate the production of a new virtual environment, but eyebrows are raised when data is managed in an automated manner.

During the discussion, the topic of Shadow IT was brought up. For example, if a system is set up for compliance and it takes days to get answers.

Human beings, as they will, will find ways to circumvent these compliance models and subvert the system.

That is why Dan Graves from Delphix suggests that if you produce a data management system that is compliant and fast, that will reduce the temptation for end users to set up apps that are independent of the compliance requirements.

View Details

The COVID pandemic has impacted society in many ways, this discussion looks at aspects of change in higher education in learning environments, IT transformation, and protecting the infrastructure. Companies like Nutanix offer tools and systems to reduce cost and improve cybersecurity in this transition.

Before the COVID crisis, considerations were given to online learning, but the focus was on traditional, classroom teaching. Higher education led the way in adapting to the new environment. Paul Padley from Rice University shows how his university had to drastically increase video capabilities for teaching.

Logically, the university had to buy more storage for these videos.

College systems had to learn how to manage this increase in storage. The result was the hybrid cloud world we live in today. Systems had to be improved to focus on speed and had to enhance governance to prevent cyber-attacks.

While the systems administrators had to worry about the structure of the data storage systems, the academics had to concern themselves about the structure of the classes offered. Students started to trend older with an interest in seeking new short-term credentials.

An increase in online offerings challenged leaders to improve identity access and management.  Traditional systems expected full-time students to be on campus with network access; now, we see remote students with few classes expecting the same access to college learning systems.

The federal government has responded to these needs by offering grants that can assist universities in this transition.  Many of these grants include requirements to increase cybersecurity before the aid is transferred. 

Some universities are applying virtualization to accomplish this task. Systems can be configured to allow for a “virtual” desktop.  This means that a student will be allowed access to a limited environment where strict controls are placed in a designated area. This allows Role

View Details

Cloud Service Providers have no problem sharing with you the number of data centers they own, the flexibility of options, and the ease to start in the cloud. However, what is never overtly stated is that the federal technology manager is responsible for the security of their data if it is on the server down the hall or in the cloud.

The conversational phrase is, “they are not on the hook for the security of your data.” 

Today, we have several perspectives on understanding how to protect federal data in the cloud. Experts from three areas provide their views on data protection, standards, and working in a cloud environment.

When it comes to protecting data in the cloud, Skip Bailey from the U.S. Census Bureau thinks that one needs to approach it strategically first. Each of the three main Cloud Service Providers has proprietary ways of handling aspects of data control. If you think you are going into a multiple cloud environment and plan or relying on one set of rules, you are mistaken. You will need staffing to support these multiple clouds.

As in other endeavors, standards bodies can provide guidance that can assist in coming to terms with handling heterogeneous environments, in this case, varying cloud providers. Craig Hurter from the State of Colorado suggests that one should get comfortable with ISO specifications like the ISO 17789 as well as some of the general guidelines from the Cloud Security Alliance. That way, you can compare the terms of service for each Cloud Service Provider with whatever standards you choose.

It seems likely that a multi-cloud world is where federal data lives. If that is the case, then it would behoove managers to be able to evaluate each Cloud Service Provider’s capabilities. Each cloud may have options to allow control, the key is to understand how those cloud provider’s proprietary offerings compare to commercial ones.

Sterling Wilson suggests that you start with three questions. What happens if you delete data. How easy is it to deploy Multi-Factor Authentication? What about the security of data in transit?

One concept that Craig Hurter brings up is the idea of architecting data storage in depth. The idea is that the initial system is solid, but, over time, something called “drift” takes place. Updates may not all be installed promptly; other maintenance can be delayed. What may happen is you can lose security over time, while still holding to the initial design specifications.  You may have “drifted” without knowing it.

View Details

Cloud Service Providers have no problem sharing with you the number of data centers they own, the flexibility of options, and the ease to start in the cloud. However, what is never overtly stated is that the federal technology manager is responsible for the security of their data if it is on the server down the hall or in the cloud.

The conversational phrase is, “they are not on the hook for the security of your data.” 

Today, we have several perspectives on understanding how to protect federal data in the cloud. Experts from three areas provide their views on data protection, standards, and working in a cloud environment.

When it comes to protecting data in the cloud, Skip Bailey from the U.S. Census Bureau thinks that one needs to approach it strategically first. Each of the three main Cloud Service Providers has proprietary ways of handling aspects of data control. If you think you are going into a multiple cloud environment and plan or relying on one set of rules, you are mistaken. You will need staffing to support these multiple clouds.

As in other endeavors, standards bodies can provide guidance that can assist in coming to terms with handling heterogeneous environments, in this case, varying cloud providers. Craig Hurter from the State of Colorado suggests that one should get comfortable with ISO specifications like the ISO 17789 as well as some of the general guidelines from the Cloud Security Alliance. That way, you can compare the terms of service for each Cloud Service Provider with whatever standards you choose.

It seems likely that a multi-cloud world is where federal data lives. If that is the case, then it would behoove managers to be able to evaluate each Cloud Service Provider’s capabilities. Each cloud may have options to allow control, the key is to understand how those cloud provider’s proprietary offerings compare to commercial ones.

Sterling Wilson suggests that you start with three questions. What happens if you delete data. How easy is it to deploy Multi-Factor Authentication? What about the security of data in transit?

One concept that Craig Hurter brings up is the idea of architecting data storage in depth. The idea is that the initial system is solid, but, over time, something called “drift” takes place. Updates may not all be installed promptly; other maintenance can be delayed. What may happen is you can lose security over time, while still holding to the initial design specifications.  You may have “drifted” without knowing it.

View Details

An argument can be made that the Infrastructure Investment and Jobs Act of 2021 is a once-in-a-lifetime opportunity to ensure the viability of the American dream for the next several generations. This is an interview with a group of federal and state leaders who are serious about using the money effectively to optimize this long-term investment.

The discussion begins with an observation that COVID forced rural communities to realize that their children couldn’t attend school without broadband access. Broadband access also could improve telemedicine and business.

The IIJA addresses this disparity by improving broadband to rural areas.

Lee Jones from the USDA identifies the Rural Partners Network as a pioneer in connecting rural communities to foster economic growth. They help with navigating federal programs and listening to the community for guidance on projects. The IIJA will, by necessity, include information technology to manage the funding effectively. 

There will be rural participants who fear this concept and may not have the trust in the federal government that others have.  Shannon McCarthy from the State of Alaska understands these concerns and has incorporated ways to deal with this reluctance, including ways for citizens to be anonymous.

Everything involves risk, especially multi-million-dollar federal projects. One unfortunate circumstance is when COVID increased everyone’s online presence, there was a corresponding increase in cyber-attacks.  If the Rural Partners Network can help rural communities with understanding federal programs, then CISA also helps with understanding cyber risk.

Free information about preventing a cyber-attack is provided by CISA. Dr. David Mussington from CISA details the free tools that are available to understand these new attacks and ways to prevent organizations from digital-born disasters.

View Details

Federal mandates are strongly encouraging agencies to apply Zero Trust. You do not just put on a pair of shoes and run the Boston Marathon; in a similar vein, you do not flip a switch, and the next day your agency has applied Zero Trust Principles. You should understand how your system needs to be prepared, then design a plan that will make the transition timely and effective.

Today’s guests give guidelines on this “hygiene” and what transition concepts to keep in mind.

Alvin "Tony" Plater, U.S. Department of the Navy, suggested that just because you are compliant, does not mean that your system is acceptable. Of course, he recognizes the value of regulations, but he thinks a well-structured system should go beyond compliance. For example, he views the importance of data integrity as a key component of maintaining existing systems.

Zero Trust requires you to assign access to people based on many characteristics, one being their role. Nothing new here, Role Based Access Control has been around for decades, but its implementation has been cumbersome at best. Consider role-based controls that give ease of use for system administrators.

Another aspect of hygiene is to make sure your existing systems all have user-supported versions. Using an older system that is about to go out of service has been called a “secretive vulnerability.” Unfortunately, one unexpected consequence of this maintenance could be more vulnerabilities. The basic hygiene concept is you cannot go to Zero Trust without a clean start.

From an architectural standpoint, you should know all your endpoints as well as have an enterprise architecture that can lock a malicious actor’s exploits into a limited area, what some call a “limited blast radius.”

The U.S. Patent and Trademark Office (USPTO) was a pioneer in remote work, even before COVID. Leadership at the agency recognizes the fast change in technology, even in the past three years. For this reason, the USPTO is changing to a Secure Access Service Edge initiative that will increase the ability to dynamically filter endpoint activity.

Humans have a dominant role in this transition. Each of the participants agrees that getting the right people behind the tools is the fastest way to increase security through Zero Trust.

View Details

Professional sports broadcasters frequently use the phrase, “taking it to the next level.” Well, when it comes to improving application development in the federal world, taking it to the next level can involve some new concepts presented in this discussion.

This is an interview with three professionals who have worked on many federal projects. They provide the listener with guidelines for making the transition with minimal expense and maintaining federal security standards.

The discussion opens with a contrast between the traditional method of developing software and the way it is done today. Chris Moran from GDIT estimates 90% of systems generated today are comprised of third-party applications. In other words, it is assembled rather than coded line for line. This new method allows for flexibility and rapid development.

Two other methods for deploying software were introduced in this discussion. When multiple applications are deployed over multiple clouds, a person dedicated to reliability must be included in the team, usually referred to as a “Site Reliability Engineer.”  This person is tasked with maintenance, patching, and increasing automation for those responsibilities.

View Details

The last few years have presented a “perfect” storm for malicious actors to tap into sensitive data.  It’s one thing to opt into something like Facebook and have them lose your data.  It is quite another when a state or federal organization has your data, and it is compromised.  No blame on the citizen in this case.

That is why people who are employed by the state, local, and federal agencies take the concept of securing citizen data seriously. This sense of responsibility is evidenced in the interview between a technology leader from the State of Colorado and a technical expert from Rubrik.

Today’s discussion ranges from best practices for securing data, zero trust in the cloud, realistic concerns, and the realities of a post-COVID world. One of the dominant parts of the conversation is the move to the cloud.

Sterling Wilson from Rubrik details three aspects of a cloud transition that must be considered.

First, which data will be moved to the cloud?  If the data is compromised and transferred to the cloud, you are merely moving a problem from one area to another.  It could be a ticking clock with malware waiting to launch.

Secondly, many don’t realize that when an agency chooses a cloud service provider, there is no implied responsibility to back up that data.  To secure citizen data, technical leaders must realize that this concept must be addressed.

Finally, will the cloud solution provide the same security that you have in your on-premises application?

Access to this data was also presented in the discussion.  Yvette Florez mentions the Fast Identity Online Standard as a common approach that many governmental organizations can take advantage of when seeking to bolster their authentication process.

View Details

So many federal information technology professionals have been hit by cyberattacks that they know it is a never-ending battle.  The real question is – what is the most effective way to implement a digital transformation to react to this constant attack? Today’s discussion brings together two people who have been responsible for managing highly visible networks, a cybersecurity expert from the FBI, and an expert from a technical partner that can bring an overview to the discussion.

Clarice Kent from the U.S. Marine Forces Cyberspace Command begins the discussion with a valid point – you can’t take advantage of leading-edge technology with legacy infrastructure.  Rather than a full swoop approach, the Marines are approaching the network upgrade systematically.

After she observes existing technology, she extends her remarks to the security stack.

View Details

Last year the monumental Infrastructure Investment and Jobs Act was passed by Congress. It has $450 billion earmarked to renew existing programs and $550 billion designated for new federal spending. As the name implies, most money will go to roads & bridges, railways, and other public projects.

The question is – how can this enormous amount of money be efficiently distributed, managed, and audited? Today’s discussion gives the listener seven perspectives on answering these important questions. The topics reviewed include expanding access to this appropriation, digital transformation, and risk management.

Study after study has shown the number one priority for rural citizens is access to broadband connections. The question is – where to start? Xochitl Torres Small from the USDA opens the discussion by claiming that, up until now, many of the maps that show coverage are not accurate.

View Details

Events in Europe have caused the Department of Defense to go on a high alert for cyberattacks. This wary posture has been emulated by civilian agencies as well. The question many federal information technology professionals are asking is: how can I keep my agency safe from cyberattacks in this increased threat environment? Today’s panel answers this basic question from several perspectives. First, the subject matter experts look at the National Security Strategy and some of its top concerns. Then, they look at existential threats and solutions Finally, they deepen the discussion with specific recommendations to avoid trouble.

In case you think these attacks on federal systems are blown out of proportion, then visit the Cyberstructure & Infrastructure Security Agency (CISA) site and see the “Shields Up” for guidance. Because of malicious cyberactivity, you can see the latest updates as well as specific actions for all organizations.

View Details

For the last decade, commercial and federal technical specialists have been talking about the power and flexibility of virtualization in servers. Today’s discussion brings us up to date with the impact of similar changes in the world of federal networks.

Today’s federal networks must manage a drastic increase in volume, inconsistent data flows, maintenance changes, as well as managing costs.

Jim Westrop from Ciena Government Services puts the increase in volume in simple terms. During the discussion, he mentions that the edge of the network is now one hundred times the size it used to be. We all know that a data center has seen similar increases, but in a data center, the volume can be managed easily because it is consistent. The drastic increase in data-generating at the edge does not come in easy-to-digest packages. There may be peaks and valleys that challenge any system.

View Details

If your favorite baseball site is attacked you have a mild inconvenience; if your healthcare provider gets locked out of data, then you have a serious problem. Today’s discussion includes experts from the Department of Health and Human Services (HHS), the Center for Medicare & Medicaid Services (CMS), and a subject matter expert from Rubrik. They discuss the concept of improving the delivery of customer services in a world full of cyberattacks. The focus is on quick recovery if a system is compromised.  Dr. John B. Murphy from Rubrik sets the stage when he says that if you look at the average time an attacker is in a network, which is subsequently compromised, it is around 70 days. What about a hospital that has surgeries scheduled and emergency room patients arriving hourly? Dr. Murphy suggests that it is a best practice to have backups that are immutable and readily accessible to maintain continuity of service for extremely sensitive networks.

View Details

The concept of an electric car is nothing new; images abound of electric vehicles from a hundred years ago. Decades of inexpensive oil prices have forced electric vehicles into small niches like convenience transportation on golf courses. Reports of human-caused climate change have caused interest in electric vehicles to rise. Combine that with action from aggressive entrepreneurs like Elon Musk is setting the stage for a major transition to electric vehicles.

However, it is not as easy as changing a manufacturing plant from gasoline engines to electric engines, infrastructure must be implemented to accommodate the charging and maintenance of new modes of transport.

Today’s discussion looks at electric vehicles from the perspective of infrastructure, data, and federal leadership in using fleets of electric vehicles.

View Details

At one time the “tactical edge” was a man on horseback. Today’s tactical edge encompasses sensors, satellites, flexible communication, and much more. To orchestrate this new capacity, military leaders are adopting capabilities to make that valuable data resilient, secure, and timely.

During the interview Colonel Khatod, United States Army Cyber Command, gave some details, "I look at the entire Army, we have 1.4 million end points on five continents."  Those end points can produce a staggering amount of data that needs to be analyzed and acted upon.

View Details

Today’s current events sharpen everyone’s focus on how the United States military can cooperate with other allies. Jeffrey Phelan from Rubrik leads a discussion among two American leaders and Brigadier General Crossfield from the United Kingdom.

Each one of them comments about four key elements: security, interoperability, data sharing, and data as a structural asset. Each person presents concerns about each issue.

View Details

In 2021 the White House issued its Executive Order on Diversity, Equity, Inclusion, and Accessibility in the Federal Workforce. This is a conversation that addresses the goals of that initiative. The discussion includes a healthcare informatics professional and two medical doctors who look at the Veterans Administration patient experience. Topics include equity, diversity, and telehealth.

View Details

Google has been using Zero Trust for six years, the Executive Order from the White House has finally gotten behind this cybersecurity best practice. The question is, how can federal information leaders apply those concepts to an estimated 1.8 million federal employees?

This is a discussion that includes experiences from three federal leaders and a battle-hardened commercial subject matter expert

View Details

This discussion is a great perspective on transitioning to Zero Trust Architecture from the perspective of federal and state information technology leaders. They cover topics from connections to regulations to the long-term perspective of this major transformation

View Details

Today’s interview will give you perspectives from five states on how they manage the ransomware threat, and that sage advice will be combined with a subject matter expert from Tenable. Tenable’s Chris Jensen has seen it all when defending against ransomware. He observes that ransomware does not typically come from a brand-new zero-day threat. From his experience, ransomware will attack “known vulnerabilities” in systems. This is especially true with techniques that have not been patched.

View Details

Today’s federal leaders pull back the curtains of deploying zero trust in a federal environment. Their advice is tempered by a well-known cybersecurity professional, Patrick Sullivan from Akamai.

Steven Hernandez begins the discussion by offering some advice rarely given. He explains that the old paper-based system was painful. Documents would not be returned to the appropriate place; records got lost; documents could be copied. So, when today’s federal technology managers complain about the difficulty in implementing Zero Trust Architecture, please remember where this discussion began.

View Details

When we look back on 2020, federal information technology professionals will note the drastic increase in remote users, the move to the cloud to allow collaboration, and the serious threats that arose because of these unfortunate series of events. 

Data security is becoming important because we have seen a drastic increase in ransomware attacks. In fact, in March 2020 alone there was a reported 148% increase in ransomware attacks.  With all this transition, one can get distracted from some of the core principles of data management: specifically, data backups as a first line of defense against ransomware.

Today’s interview has two subject matter experts who put the concept of data protection into the new order of federal information technology.  The transition to remote work was relatively painless, the concern now is how to make people more productive.

View Details

When a federal information professional hears the phrase “ransomware” they think of some small attack on a consumer.

They may have a mitigation plan, but nothing serious. Well, it is time to get serious.

During this discussion, you will hear of two separate, but similar, attacks on hospitals. One attack was so severe they had to burn the servers down to the ground. They had to use paper forms for twenty-three days. The other hospital was attacked similarly but managed to mediate the problem. Neither one paid the ransom.

One of the directors of information from Sky Lakes Medical center gives a provocative blow-by-blow review on the mitigation efforts. He suggests developing relationships with vendors who can provide service 24 hours a day 7 days a week.

In this discussion are subject matter experts from the Department of Homeland Security and Infoblox, a leading cybersecurity vendor.

Ransomware was the #1 crime of 2020 and is getting more sophisticated. During the interview, you will hear about what the recommendations are from DHS’s Homeland Security Investigation. Jason Canboy, Special Agent Program Manager, Dept of Homeland Security, will send a shudder down your spine when talks about malicious actors moving from custom attacks to something called “Ransomware as a Service.) Ransomware attacks are getting so well known, that attackers do not need to understand the meticulous detail of a cyber-attack, they can merely pay a fee and have the attack code at their disposal.

Chris Usserman, Principal Security Architect at Infoblox Federal suggests that handling a ransomware attack is similar to contract tracing for COVID – you must have a detailed record of the attack and inform the cybercommunity to help prevent others from this attack.