Federal Tech Podcast: Recent Episodes

John Gilroy

The federal government employs 1.8 million people and spends $90 billion on information technology products and services. This is the only podcast that gives you ideas on reducing cost and improving quality for that massive expenditure.

View Details

Everyone has read about how much productivity AI can have for federal applications. That allure can lead you into a situation where you may not be as prudent as you should be.

Today, we sat down with Jamie Holcomb, COO of Electrosoft, and Steve Riley, VP and Field CTO of Netskope, to better understand how to balance the promise of AIAI with practical application in the federal government.

Steve Riley has looked at federal technology projects, and he thinks that the government must get out of their pilots and into operations, measuring results and impact that is meaningful to the taxpayer.

They highlight the rapid advancements in AI, noting that government agencies struggle to keep pace with commercial innovation.

Riley thinks agents are great for gathering, assimilating, and assessing information. It is probably not time for them to have independent agency.

A survey reveals that 78% of federal leaders believe AI tools should be managed like users or devices within zero trust frameworks. Only 31% of federal IT leaders have high visibility into public AI tools.

Because of Jamie Holcomb's experience at the United States Patent and Trademark Office, he thinks success comes down to action, not architecture. From his view, agencies need timely intelligence connected directly to operational decisions.

The conversation emphasizes the need for federal agencies to balance innovation with security, particularly in predictive AI and zero trust strategies, and to prioritize AI discovery and integration.

View Details

For decades, software was "bespoke." Each application was carefully crafted to solve a specific problem. When this was applied to the federal government, they discovered that this process was slow and unpredictable.

The solution: a software factory. From custom-built software to software that could be created in an organization that had a "bubble" that could standardize on federal security guidelines. From there, they could deliver safer, higher-quality software much faster.

Today, we sit down with Jorge Lopez, Vice President of Security Operations and Trust and Safety at GitLab, to discuss the concept of software factories in the federal government.

Lopez admits the importance of visibility, collaboration, and compliance in these factories. However, during the interview, he notes that gaps in DevSecOps often stem from organizational issues, such as miscommunication between security and development teams. He emphasizes the need for proper monitoring, incident response, and managing secrets to mitigate risks.

Digging deeper, he states that if a federal organization does not have monitoring in place, they will only discover a problem after it happens.

One approach is to go to the people responsible for defending the software. Lopez has seen success when security operations teams and software factory teams talk to each other.

Lopes also discusses the impact of AI on code production and the importance of proactive measures to ensure software factory security.

View Details

Today, we sat down with Rajan Venkatachalam from Icertis to discuss the evolution of federal contract lifecycle management. The main takeaway is that contract management is becoming harder to ignore, even though many organizations still overlook it. Perhaps it is too difficult; perhaps changing management with compliance is too complex.

Rajan begins the interview by putting AI into perspective. He coins a great phrase when he states that AI has gone from "Buzzword to Backbone." In other words, the value of AI is so clear that it should be applied across all aspects of running a federal agency.

If you are asking for specifics, he gives them. Rajan states that agencies, contractors, and Icertis have seen up to 40% faster proposal-to-award cycles. Icertis has been in the contract management world since 2009.

Building on that experience, they have honed their commercial skills to the point where they can examine every sentence in a contract to assess its limitations and strengths. If you sell to the federal government, Icertis can monitor rapid changes in compliance requirements and ensure your offering stays current. They highlight the shift from paper-based to automated and digital processes, driven by AI and compliance frameworks like FAR, DFAR, and CMMC.

Finally, Rajan sees the future as autonomous contracting. He can see a future where a solicitation is reviewed and a proposal is generated. This increase in speed allows humans to review the process before submittal.

This points to faster, more predictable, and compliant-friendly contracting, which is crucial for agencies under pressure to deliver quickly.

View Details

IT modernization carries unanticipated risks. Take operational technology, or OT, as an example. As modernization has increased the number of OT and IoT assets across many federal locations, it has also introduced new vulnerabilities.

Federal leaders are warning that the situation has reached a tipping point. CISA maintains a growing list of vulnerabilities, and the NSA has issued warnings about OT and IoT risks. A recent SANS report indicated a 20% increase in confirmed OT attacks.

To explore these challenges, we sit down with Chris Grove, Director of Cybersecurity Strategy at Nozomi Networks, to discuss the cyber-physical security challenges facing the federal government, particularly the modernization of older OT systems.

He highlighted the difficulties in maintaining asset inventories, the impact of AI in both attacks and defenses, and the complexities of implementing zero trust in OT environments.

During the interview, Grove addresses topics such as remote access, older technology not designed for updates, and OT devices that move around on ships and planes.

Thirty years ago, "unified communication" was introduced by technology like VoIP. With the proliferation of OT devices, Grove recommends a unified security architecture.

Grove emphasized the importance of resilience and the need for AI-enhanced tools to manage alerts and anomalies effectively. He also noted growing concerns about drone security and the significant workload expected to result from AI-discovered vulnerabilities.

View Details

Taylor Johnston, President of the Institute of Applied Engineering at the University of South Florida, discussed a secure research environment developed with AWS and the federal government.

This initiative allows researchers to work with classified information, progressing from unclassified to top-secret levels.

The partnership uses AWS GovCloud for multi-domain, multi-accessible research. Many organizations train models on unclassified data, but classified data has different nuances. Analysts need to build that model in IL6 using those data sets.

Johnston highlighted the university's proximity to key military commands and its results-based research, emphasizing the importance of human performance and AI in military applications.

During the interview, Johnston observed that AI is an enabler for productivity, not a job stealer.

The university aims to bridge gaps among academia, the defense industrial base, and venture capital, helping enhance operational capabilities.

View Details

At one time, reacting to a cyber threat was enough; signatures and blocklists could cope. But AI is now amplifying every aspect of cyberwarfare, including speed and scope, leaving these traditional defenses in the dust. Today's threats can be numerous and personalized, making old approaches worthless.

Patricia Titus, Chief Information Security Officer at Abnormal AI, discussed the challenges of transitioning from legacy to modern AI-driven security architectures at the AWS Public Sector Show.

During the interview, she advised focusing on asset visibility, decision-making platforms, and non-human identities to enhance cybersecurity.

So many federal organizations are deploying tools that it is difficult to get a baseline or inventory of what is on a system. Titus recommends starting with an accurate inventory to establish a "normal" baseline and detect abnormalities.

She also stressed the necessity of modernizing security architecture in parallel with cloud migration and the dangers of relying on outdated tools.

View Details

The Department of War realized it was dealing with a supply chain risk of vulnerable vendors; back in 2019 they launched the Cybersecurity Maturity Model Certification. The goal was to ensure defense contractors protected sensitive unclassified information.

Over the years it has transitioned from being a "checkbox" compliance to moving way beyond the minimum to pass.

During today's interview with Travis Goldbach from Coalfire Federal, he gives us overview of how CMMC has made the transition to building a security program that protects the mission, supports growth, and earns trust.

Goldbach continue by stating the cybersecurity is going to impact just about everybody – from sales, to legal, to operations, to finance and even executive leadership.

Travis highlights the importance of CMMC for acquisition, noting that many defense contractors are unprepared. CMMC 2.0, implemented in November 2025, simplified the framework from five levels to three, focusing on basic cyber hygiene, CUI protection, and advanced protection.

He also discusses the impact of remote work and AI on CMMC readiness and the importance of a robust ecosystem of trusted partners for sustained compliance.

Rather than detailing the number of controls in the varying levels of CMMC, the discussion moved on to the concept of documentation. The challenge Goldbach sees is the conflation of documentation with readiness.

More must be added to documentation to make it viable. For example, companies need ownership, governance, and accountability in a repeatable process.

View Details

In this episode of the Federal Tech Podcast, Robert Salvia of Fortress Information Security explains why agencies must move beyond a compliance mindset and adopt continuous risk management. One key insight stands out: "It's not what you find, it's what you fix," showing that mission impact should guide vulnerability priorities rather than compliance boxes.

One insightful observation Salvia makes concerns observability. Many companies pride themselves on being able to see network details, including potentially unknown vulnerabilities. Salvia says the ability to find is important, but the ability to fix that problem is more valuable.

He suggests that AI can assist in that endeavor, but it is a force multiplier, not an answer to everything. His main theme is to move from compliance to continuous risk management.

Salvia explores the complexities of supply chain risk management (SCRM), emphasizing the need for comprehensive, enterprise-level solutions that address both hardware and software vulnerabilities. Salvia highlights the importance of collaboration, continuous monitoring, and adapting to new threats and regulations.

He also discusses the role of AI, such as Mythos, in increasing the scale of vulnerability detection and the necessity of integrating AI with human expertise for effective risk management and remediation.

View Details

In this episode of the Federal Tech Podcast, John Gilroy interviews Justin Fessler, Vice President of Public Sector at LogicMonitor, about the growing role of autonomous AI and observability in federal government IT operations.

Fessler explains that autonomous AI is not about replacing people but about automating repetitive operational tasks, correlating complex system events, and helping IT teams make faster, better-informed decisions. Rather than allowing AI to operate without oversight, LogicMonitor focuses on keeping humans "in the loop" while AI handles time-consuming analysis and routine remediation.

A central theme is the importance of complete visibility across increasingly complex federal environments. LogicMonitor's agentless monitoring technology discovers devices, cloud resources, applications, and shadow IT without requiring software agents on every endpoint. This broad visibility enables agencies to identify unmanaged assets, reduce blind spots, optimize cloud costs, and strengthen security.

The discussion also highlights observability's critical role in Zero Trust. Fessler notes that agencies cannot secure or verify assets they cannot see. By discovering everything connected to the network—including servers, cloud services, IoT devices, cameras, badge readers, and physical infrastructure—LogicMonitor helps agencies build a stronger Zero Trust foundation.

Gilroy and Fessler examine the challenges of managing hybrid and multi-cloud environments, emphasizing that agencies require a single operational view regardless of where workloads reside. LogicMonitor integrates information across cloud providers and third-party platforms, including ServiceNow, Splunk, Dynatrace, Datadog, and IBM Watsonx, enabling AI-driven event correlation and faster incident response.

The conversation concludes with the future of autonomous IT. Fessler predicts increased automation, AI-assisted self-healing infrastructure, and significantly reduced mean time to identify and resolve incidents. Rather than replacing IT professionals, autonomous AI will eliminate repetitive work, allowing skilled personnel to focus on higher-value mission objectives while improving operational resilience, reducing alert fatigue, and delivering better digital services to citizens.

For more information, visit www.logicmonitor.com/solutions/federal-government.

View Details

Craig Bowman, Senior Vice President at Trellix, discussed Trellix's project to secure Ukraine's cyber environment against nation-state attacks, highlighting the rapid evolution of attack vectors from Ukraine to the U.S. He emphasized the importance of AI in cybersecurity, noting Trellix's use of AI to autonomously mitigate attacks, as seen during the 2025 cyber espionage campaign.

Bowman also explained Trellix's detonation chamber technology, which isolates and analyzes threats without affecting live data, and its Agentic AI, which operates on-premises without data movement to provide real-time cybersecurity insights.

Ukraine has become the world's most concentrated cyber battlefield, giving security teams unprecedented visibility into emerging attack techniques. In this interview, Trellix's Craig Bowman revealed that attack patterns once took six months to reach the U.S. after appearing in Ukraine—today, that gap can be as short as six seconds —highlighting why AI-powered cyber defense is becoming essential for federal agencies.

It is essential because a human simply cannot fight an autonomous machine by clicking through alerts. It is time to use AI to fight AI.

View Details

Today, we examine the strategy for filling technology roles in the federal government.

Everyone reading this sentence knows that the federal government is competing with commercial organizations for tech talent. Combining that with an arduous federal hiring process, a reduced budget, and a drastic increase in cyberattacks heightens this concern.

We sat down with Nav Singh, the Chief Marketing Officer at Eightfold.ai, to discuss the company's mission to match job candidates with roles based on skills.

For example, Eightfold has analyzed 1.6 million skills and 1.6 billion career trajectories, enabling it to identify and upskill employees for roles like cybersecurity. Singh emphasizes the importance of reducing bias in hiring and leveraging AI to discover hidden talents within organizations.

During the interview, he reviews the idea of training people who you already have on staff for cybersecurity positions. It is possible to assess talent and identify which candidates can make this transition.

This "hidden talent" theme makes even more sense for the federal government. One may need a specific kind of security clearance. It may be easier to assign an existing employee with that clearance and train them rather than go through the whole vetting process again.

Singh also mentions introducing an AI interviewer to enhance hiring consistency and efficiency. He states that the future workforce will be a combination of humans and agents. This is a scenario in which agents perform repeatable tasks, while humans set the strategy and exercise judgment.

View Details

John Gilroy and Josh Wilson, CEO of LMI, discussed the shift from traditional defense technology development cycles to rapid deployment, emphasizing the need for integrated hardware-software systems.

For decades, the military would assemble detailed requirements, solicit bids, select a winner, and wait years for the contract to be completed. This approach can work with some hardware systems, but today's combat requires maximum flexibility and adaptability.

This approach prompts the question of whether a company is judged by how perfect its product is on day one. What about day two? What about the pace? Can they figure it out based on what they learn?

Wilson suggests a more flexible approach in which a combat system is proposed, evaluated quickly, defects are identified and replaced, and the system is then reassessed. He highlights LMI's approach, which combines software, hardware, services, data, and AI to deliver outcomes, citing examples like asset management in shipyards and the

He stresses the importance of trust, earned through demonstrable solutions, and the cultural shift towards outcomes over ownership and the SHPRD program.

Wilson also notes the success of the Ivy Sting exercises, which prioritize user feedback, and the potential for scaling rapid development models across the Army and other federal agencies.

You can read the press release here: https://www.lmisolutions.com/press-release/anduril-partners-with-lmi-to-generate-battlefield-technology-for-the-u-s-army

View Details

Finding a needle in a haystack would seem like a minor endeavor compared to what today's federal systems managers must face. Let's take a stab at a correct farmyard analogy – the haystacks double in size every day and are moving.

That sounds like an exaggeration, but recent reports show that nine million zero-day exploits are released every day. AI is putting malicious actors on steroids.

Chris Townsend, Global Vice President of Public Sector at Elastic, discussed the company's role in federal cybersecurity and data management. His argument is, essentially, that cybersecurity is a data problem. If threats are viewed from that perspective, the more data you can bring into your security environment, the more effective you are at defending it.

Elastic enables security operations analysts who are responsible for detecting threats to keep up with today's tlandscape and cyber-attack velocity. Elastic's platform and tools can reduce false positives and help federal security operations centers (SOCs) prioritize valid threats.

Townsend highlighted Elastic's agentic AI tools, which help SOC operators prioritize and remediate threats, reducing mean time to detect and respond.

Elastic's partnership with CISA for a managed Security Information and Event Management (SIEM) as-a- service was also mentioned, emphasizing the importance of standardizing data for effective AI-driven cybersecurity.

Townsend goes on to articulate Elastic's launch of a SIEM-as-a-Service offering for federal civilian agencies, featuring Elastic Security on Elastic Cloud. SIEMaaS delivers a cloud-based platform for next-generation, AI-powered threat analytics, incident response, and open-standards-based cybersecurity data ingestion.

Here is a link to Chris' blog describing CISA's SIEMaaS offering and how it supports federal agencies' cybersecurity posture while reducing costs

View Details

John Gilroy hosts Dennis Woo, Director of Federal Sales at Kong, to discuss the rise of API management in federal security.

API management has been a slowly growing concern for the past decade. Cloud adoption has driven API adoption; now we see cheap storage and AI systems making many API connections.

Voilà, API security is now a topic for federal security leaders.

During the interview, Dennis Woo discusses the origin of Kong and brings up topics of major concern for cybersecurity:

The perimeter is disappearing. Before the cloud, a perimeter might have been the walls of a data center. APIs caused that to increase dramatically. Today, we see agents talking to APIs, APIs talking to models, and models consuming MCP tools.

Woo remarks that the last thing a federal agency wants is token consumption at enterprise scale. Kong offers an API and AI management tool to ensure compliance, avoid vendor lock-in, and reduce cost.

If we fast-forward five years, Woo predicts systems that are semantically aware, systems that can understand intent and detail, and systems that can manage risk. This can extend to semantic guardrails, semantic compression, and even token management.

Listen to the podcast to understand how to manage an AI environment that can get out of control

View Details

Today, we sat down with Snehal Attani from Horizon3.ai to discuss the impact of large language models (LLMs) like Mythos on federal cybersecurity.

He makes a range of startling statements.

First, he admits that AI tools like Mythos can find bugs in code. In fact, he claims that the effort to find it may drop to zero.

He also warns of the potential for AI-generated exploits to overwhelm security operations centers. Attani predicts a surge in vulnerabilities, what some call a Vulnpocalypse, and stresses the importance of prioritizing remediation and building muscle memory for incident response.

However, that does not mean the effort to exploit the vulnerability is also zero. Knowing vulnerability does not guarantee a successful attack.

Second, this new information can overwhelm a system administrator. His call to prioritization can yield effectiveness. He makes statements like, "The hardest part of the job is deciding what not to fix."

Finally, in a twist on the cybersecurity business, Attani admits that the attacker will get in. The best perspective is to see yourself as in the business of blast radius management.

Attani advocates focusing on core cybersecurity fundamentals and cautions against chasing headlines to avoid organizational distraction.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Everyone seems to have an opinion on AI. Today, we interviewed Levi Gundert, the Chief Security and Intelligence Officer for Recorded Future.

He thinks that AI gives federal leaders an opportunity to fight back.

For example, one aspect of cybersecurity is velocity; the number of attacks has expanded exponentially. Gundert thinks this is an opportunity to match this attack's velocity.

Many will balk at this opinion. They will describe federal data as challenged in cross-domain sharing, data labeling, and data trapped in PDFs or legacy systems.

During the interview, in a refreshing observation, Gundert observes that defenders have always been on the back foot. Always in defense. Finally, AI can give tools that level the playing field.

One application of AI is the ingestion of the data provided to federal systems. AI can be used to provide actionable intelligence. In some systems, this deluge can result in false alerts. When used properly, AI can filter through the signal and identify what is critical.

Gundert emphasizes the need for automation and decision advantages in threat intelligence, the challenges of data fragmentation and legacy systems, and the urgency of upgrading systems to address vulnerabilities.

They also touch on the role of AI in insider threats, the potential of Mythos to increase vulnerabilities, and the importance of sharing threat information to enhance cybersecurity.

View Details

Ep. 322 Mattermost Secures Mission Critical Federal Collaboration

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

The federal government has an unbelievably wide network. We all know about the IRS citizen-facing websites. We log in from our homes, the server is in the cloud somewhere, and we file our taxes.

At the other end of the spectrum is the military and intelligence community. The military talks about a "contested" environment. This can be in Low Earth Orbit or can be underwater in a submarine. There are no simple connections in that world.

Yet users demand security in a world constantly under attack and disconnected. Resilience means they must not lose packets of information. Also, just to make it interesting, this can be a life-or-death situation.

Into this demanding world steps Corey Hulen, founder and CTO of Mattermost. Their mission is to provide collaboration software designed for high-trust, high-risk environments, including even air-gapped network components.

The software emphasizes resilience in contested environments, ensuring collaboration continues even when network connections are lost.

Hulin highlights the importance of both security and compliance, noting the challenges of meeting multiple regulatory standards.

He also addresses the need for AI to support human decision-making in mission-critical scenarios, ensuring quick, informed responses.

View Details

https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Today we sit down with an HR company, Workday, to see if it can transfer the success it has had in the commercial world into helping federal agencies reach ambitious goals.

Matthew Cornelius works for Workday, but he has spent mor than a decade working in a wider variety of federal agencies. The interview covers topics like the shift towards skills-based hiring, the challenges of outdated HR systems, and the need for comprehensive workforce data.

One concern is that the applicant can report skills. One candidate's Python experience may differ greatly from another's.

Presidential administrations have encouraged the concept of skills-based hiring. However, this is a subject that is difficult to implement. For example, it can clash with the standard GSA classification system. Today's AI skills are changing so rapidly, it would be almost impossible for an HR person to understand what skill sets are important.

Cornelius has firsthand experience in federal HR systems that are dated. He references using Excel spreadsheets that can have issues with version control and backup.

One great place to start is to use a system than can give an HR manager a "birds eye" view of the skills of their current employees. He emphasizes the importance of communication, empathy, and leveraging modern HR technology to improve federal HR processes and outcomes.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Two of the least well-known, but most important acronyms in federal technology are ITSM and ITOM. IT Service Management focuses on services and user experience, while IT Operations Management focuses on technical performance and monitoring.

These two concepts are the backbone for maintaining the massive federal IT systems we see everywhere.

Today, we sat down with Seth Gardner from BMC Helix, who details how BMC Helix can provide insights for service management.

He starts with the importance of visibility and generating clean, reusable data for AI.

Gardner maintains AI is only as good as the data behind it—and most federal agencies are still "re-wrangling" fragmented systems.

In this episode, BMC Helix explains how correlating incidents across 12+ tools can pinpoint root cause and dramatically reduce mean time to resolution.

He also touches on the importance of data sovereignty and security in multi-tenant environments.

The conversation concludes with Seth outlining BMC Helix's differentiator in adapting to rapid technological changes.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Angel Smith, President of Global Public Sector at Virtru, discussed the challenges of data interoperability in federal agencies, emphasizing that trust and policy issues often hinder data sharing more than technology.

It took several years, but the federal government has realized that its defenses are not perfect and has had to adopt a zero-trust approach to limit access to important information.

Zero Trust is Missing the Point

During the interview, Angel Smith argues that Zero Trust seems to focus on the network and identity, rather than on data. While intended to secure infrastructure, these changes can create new attack vectors.

Data Sovereignty is broken.

Traditionally, a data set would reside in a hard drive in a server room down the hall. Because of this, thinking about security can be focused on the physical location of the data or its sovereignty.

Sometimes, a strategic approach is necessary to protect data.

This is an outdated approach because data can be protected by the data object itself, which can carry control.

Security vs. Speed is a False Tradeoff.

This legacy thinking also applies to security. Some will exist to control data because it has been viewed as too time-consuming.

Smith also stressed the need for modern data governance to enable AI and other advanced technologies, advocating for a rethinking of legacy practices to enhance data security and usability without compromising mission speed.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

There is a popular podcast in the Washington, D.C. area called "Feds at the Edge." The title alone acknowledges the importance of edge devices for the sprawling federal government.

Today, we sat down with Tommy Gardner from HP to discuss the challenges of securing millions of endpoints in the federal government, including legacy systems and operational technology (OT).

When it comes to OT, Gardner makes a shocking observation: if you take an endpoint, like a sensor in a boiler, and it gets compromised, it could shut down the refinery, and people could get hurt. That is why HP has developed a system called the Workforce Experience Platform (WXP), which manages diverse devices and applies updates remotely.

One little-known fact Gardner brings up is that, when malicious actors assess vulnerabilities, the easiest way to get into a network is through the printer. In fact, HP now offers printers with defenses against post-quantum encryption.

Given that a company like HP has thousands of products, the supply chain is a major consideration. During the interview, Gardner mentions that HP has over 10,000 vendors in its supply chain. He addresses the complexities of supply chain security, emphasizing the need for rigorous vendor verification and compliance with the Trade Act.

He concludes by advocating for AI at the edge for real-time decision-making and cost efficiency.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

The Veterans Administration is a system with nine million enrolled veterans across 1,300 facilities. In a system like that, downtime is not an option.

Today, we look at how a company successfully reduced documentation time, increasing adoption in one part of this massive system.

We sat down with Nilanjan Sengupta from Thoughtworks to learn which methods proved successful.

He began by stating the focus must not be on bits and bytes, but on mission outcomes. For example, for years, clinicians spent 10–20 minutes per patient on documentation, often taking 2 or more hours to leave their shift.

Sengupta highlights a successful pilot of AI ambient scribe technology at the VA to address this issue. It was so successful that it achieved an 86% adoption rate among primary care providers.

During the interview, Sengupta outlined topics such as the importance of data governance, trust infrastructure, and a responsible AI strategy.

He emphasized the need for a well-governed data discovery process and a cultural shift towards treating data as a mission-critical product.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Interest in technology comes in waves. Back in 2022, managing the supply chain became number one on the list of priorities for federal technology leaders. Since then, we have seen a huge cycle of AI dominating the federal government's attention span.

This shift in focus may be causing you to overlook other critical supply chain concerns.

Today, we sat down with Bob Kolasky from Exiger. His company got its start by helping the Department of Justice monitor HSBC, a large financial management company. That led to a successful reputation, prompting other federal agencies to ask for their help.

During today's interview, Kolasky gives an overview of due diligence, continuous monitoring, and risk management. He argues that AI-driven supply chain insights reveal hidden risks, fraud, and vulnerabilities that impact federal agencies and contractors.

With attacks occurring so rapidly, Kolaksy expands on the application of continuous monitoring across the entire supply chain. He uses the term "illuminate" to describe the technology Exiger offers that can carefully examine all aspects of the supply chain.

Exiger's technology is so advanced that it can look at unstructured data, sanctions lists, adverse media, ownership records, and trade data.

With that amount of information, systems must be put in place to ferret out abnormalities and prepare for the next wave of supply chain attacks.

= = =

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Sending deceptive email has been around for decades. It has gone from a Nigerian prince asking for financial assistance to 10,000 people. Today, phishing isn't 'spray and pray' anymore—AI is creating hyper-personalized emails that look exactly like someone you trust.

Today, we sat down with Patricia Titus from Abnormal AI to learn how the correct response to an enhanced AI phishing attack. Some may shock you. Voices are being emulated, hyper personalized threats are being developed, and threat actors are using AI faster than humans can respond.

This deception is getting increasingly difficult to defend. One approach that Patricia Titus recommends is to start off being AI-native and using behavioral techniques to defeat the massed attacks.

During the interview, Patricia Titus explains that the Abnormal AI system will look at normal behavior over 15-30 days and flags anomalies. Abnormal AI partners with major SaaS providers and offers a free 30-day proof of value.

The technology aims to reduce alert fatigue and operational drag, enhancing cybersecurity efficiency.

View Details

If you go to Google Trends and type in API threats, you get a classic hockey stick. This is probably caused by the proliferation of connectors to cloud solutions paired with the popularity of AI.

Today, we sat down with Brian Dennis from Akamai to talk about the problem this can present to federal systems. He begins by telling the audience that API attacks have increased by over 1,200 percent, reflecting the Google data.

The shock is that many organizations, federal included, do not even know how many API's they actually have. There may be APIs that were designed in earlier systems; there could have been APIs designed, used, and now dormant. Worse, it is possible that individuals have launched independent systems, called Shadow APIs, which can present unimagined vulnerabilities.

The fact is malicious actors know this is a current vulnerability. It is a matter of knowing what to do when you get attacked.

During the interview, Brian Dennis makes some suggestions that can help overcome some of these challenges.

Microsegemetation will allow any breach to be blocked off. Traditionally, microsegmentation has been a time-consuming task but today's AI can make it a trivial concern.

Akamai has recently merged with a company called Guardicore that can provide enhanced network visibility.

Today, developers are grabbing code off the shelf and plugging it in. There may be insecurities in this approach. Dennis explains how Akamai's No Name can help identify and secure APIs at the code level, enabling operational security from development to runtime.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

This is an interview at the Salesforce Agentforce World Tour in Washington, D.C., held on March 29, 2026, at the Washington Convention Center.

Mia Jordan was the federal CIO twice and brings a unique view to the discussion of challenges and solutions around federal technology. She sat down with Federal Tech Podcast at the Salesforce Agentforce World Tour to give her thoughts on AI and innovation in the federal government.

Jordan notes the federal government has used AI for a decade, but now faces pressure to move rapidly from concept to production.

Although there is a sense of urgency from federal leaders, Jordan cautions that a human being should be in the loop when deploying AI. One way to accomplish this goal is to use tools that assist with it.

One example she uses is the Salesforce tool Einstein Next Best Action. It can look at a workflow and make suggestions for a human to select.

Jordan also addressed how the Informatica acquisition lets agencies track data lineage—who created it, when, and how it is used—so they can defend decisions during audits. touches on the role of low-code tools in automation and the need for reimagining workflows.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

Today, we sat down with Paul Tatum, Executive Vice President, Global Public Sector at Salesforce, to hear how Salesforce can help federal agencies reach ambitious goals with Agentic AI.

By now, everyone has played around with AI, and possibly some agents. Viewed independently, they can dazzle. Unfortunately, the federal government expects action based on data.

If you isolate Agentic AI, you can fall into the trap of lacking the ability to scale, ensure security, and maintain control.

In those several weeks, notable technology leaders have jumped headfirst into some agentic offerings from new vendors. What is not reported is that many have jumped back out because of privacy concerns.

Salesforce can serve as the "adult in the room," enabling federal leaders to leverage agentic technology in a secure and compliant manner.

The good news: agents can connect just about everything. The bad news: agents can connect with everything. In the federal government, one needs trusted, mission-specific data through controlled interfaces.

During the interview, Paul provides insight into innovation and security while using Agentic AI in a federal environment. He envisioned future AI evolving from reactive to initiative-taking and personalized, potentially becoming a concierge for citizens.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

Today, we sat down with Charles Fiery from Excella to discuss the complexities of improving federal agency processes. He shared insights on the challenges of process discovery, change management, and data transformation.

It is always difficult to assess a large enterprise, whether public or private, to determine how to improve complex processes. One approach is to look at duplicative systems; the federal government provides a notable example.

The federal government has evolved into new agencies over the years. Because of technical and legal challenges, they have mostly remained siloed. As a result, we have human resource systems that do remarkably similar tasks.

A consolidation effort would reduce costs, improve speed, and assist in interagency collaboration. The OMB mandate requires agencies to integrate core HR functions while maintaining ancillary services like payroll and benefits.

The transition involves mapping current systems, identifying essential functions, and ensuring data compliance.

Current systems need to ensure the data they provide is accurate and error-free. Each agency has unique data, and structuring that data is important.

Visibility into system components is much more difficult. Connectors and integration are complicated by shadow IT and AI.

Charles Fiery concludes that although the transition is challenging, completing the necessary groundwork will lead to stable and compliant improvements in federal HR systems.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

In the 1990's, the World Wide Web was so popular that it was facetiously called the Worldwide Wait. Centralized servers handled a small workload but bogged down as volumes increased.

As a result, Content Delivery Services sprang up to distribute the workload worldwide. By 2001, large news organizations could manage unpredictable increases in traffic. The past decade saw a drastic increase in traffic and threats to it.

During the interview, Omeed Nosarti describes how companies like Fastly began offering proprietary methods to deliver content faster.

Nasrati highlights Fastly's proprietary technologies, such as Smart Parse, which reduces false positives in web application firewalls (WAFs), and its network architecture optimized for low latency and high cache hit ratios.

Included in this conversation is the appearance of many remote points on many federal networks. These can function by increasing the attack surface and including the possibility of attacking the Application Programming Interface (API).

Nasrati also mentions Fastly's API security features, including schema enforcement and discovery, and its significant ROI in terms of infrastructure and human capital costs.

Nasrati emphasizes the importance of real-time traffic analysis and the evolving nature of DDoS attacks.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

In 2026, we are seeing an increase in cyberattacks targeting defense contractors and defense production.

Today, we met with Tim Miller, Field CTO at Dataminr, who explained how the company is helping the federal government address this growing threat.

Traditionally, cyber threats could be classified as "Zero Day." Essentially, this meant an attack targeting a software or hardware vulnerability that was unknown to the public. They were effective because no security patch existed, and they could bypass defenses.

AI has compressed this 24-hour window to minutes. If your opponent is speeding up attacks, then the defender must use similar tools to prevent a breach. Dataminr has developed something called "real-time intelligence."

This concept can provide early warnings, help separate nuisance attacks from serious malware, and address today's workforce gap in cyber defense knowledge.

During the interview, Miller noted that the company also launched a new product for cyber defense that integrates threat intelligence with internal data.

It is called Dataminr for Cyber Defense and leverages AI and Agentic AI to neutralize threats.

= =

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

Today, we sat down with Trey Ford from Bugcrowd to talk about ethical hacking.

One of the most memorable phrases from ancient Rome is Quis custodiet custodes? (Who Watches the Watchman?).

This ancient admonition has direct application to federal cybersecurity. We know federal agencies spend millions of dollars to protect data. How does one ensure the contracted companies are doing their jobs?

Traditionally, an organization would use penetration testers, contractors, or basic scanning methods. However, today's attack surfaces are expanding, and malicious actors are innovating so rapidly that we are being forced to consider more creative options.

In other words, an annual penetration test against an AI-inspired attack is too focused to be effective.

The innovation Bugcrowd brings to the table is a community of researchers who can attack a system from many perspectives.

During the discussion, you will learn about federal vulnerability disclosure programs, how to overcome talent shortages, and how Bugcrown vets its research community.

Trey Ford also touches on the FedRAMP journey, AI integration, and the evolving cybersecurity landscape, stressing the need for human creativity and dynamic responses to threats.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

The word "deplorable" signals something shockingly bad. Often used for the truly awful or dreadful, Todd Harbour, with decades of federal data experience, applies it specifically to data quality.

That may be an overstatement, but the description certainly makes the point that today AI is based on fragmented, incomplete data sets. The bright, shiny thing called AI is so much in focus that federal leaders may not pause to ask what data is being used to train today's models.

During the interview, Harbour acknowledges that nobody is seeking perfection here. He has coined the term "mission-ready" to describe the kind of data that should be used for decision-making in the federal government. This would indicate a serious attempt to include siloed and poorly structured data.

In a fascinating digression, he refers to MIT's Project Iceberg. This initiative suggests that AI is only the "tip of the iceberg" of its economic impact. The majority are in the future and beneath the surface.

If that is the case, the case for mission-ready data is even stronger.

Harbour urges immediate initiative-taking measures to confront these challenges and proactively prepare for rapid AI-driven changes to cybersecurity and national defense.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

When people look back on 2025 they will see many changes in the FedRAMP process. It looks like a new administration examined the process, got feedback from companies, and launched new initiatives to speed up the process.

During today's interview, Irina Denisenko (Knox CEO) details FedRAMP's challenges and something called "FedRAMP 20x." Knox runs the largest FedRAMP-managed cloud, enabling 90-day authorizations by hosting customers' production environments.

Denisenko explains the story of the origin of Knox Systems: she was running a training company and the Air Force wanted to use her product. It would have taken so long to complete the FedRAMP requirements that she just bought a company that was FedRAMP compliant.

It is hard to believe that the process is so frustrating that fewer than 500 apps are authorized at moderate/high FedRAMP

The initiative from the GSA is called FedRAMP 20x It shifts to continuous monitoring and continuous authorization, moving from annual audits (sampled every 3 years) and monthly CVE spreadsheets to real-time, machine-readable data.

What Knox offers is a tried-and-true platform that has reduced time for compliance in order to better serve federal needs.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Way back in 2011, one of the goals of FedRAMP was to eliminate software redundancy. The federal government had evolved to the point where one agency would spend millions of dollars on the same application program that the agency in the same zip code had just invested heavily in.

The theory proposed by luminaries like Vivek Kundra was to move to the cloud to share services. Reducing cost and improving resilience. FedRAMP was the initiative that established a safe environment for federal cloud use. Companies can comply with regulations outlined in an Authorization to Operate (ATO).

Well, fifteen years later, and we are seeing the same duplication not in the application programs, but in the process to get the ATO itself.

For example, FedRAMP, RMF, and agency internal policies may require specific artifacts to satisfy one or the other.

During the interview, Travis Howerton paints the legacy model—static documentation, annual/3-year audits, spreadsheets. His solution is to have AI assist with documentation, which will drastically reduce compliance time; he cites an example of reducing a process from 52 weeks to 356 weeks.

RegScale uses OSCAL (XML/YAML/JSON) to auto-generate RMF artifacts and integrate with SIEMs (Splunk, Elastic), Axonius, ServiceNow, and APIs.

Howerton understands the limitations of many automated systems and suggests that a human is a key component after the machine language has assembled the data to make the decision.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Cybersecurity is a rapidly evolving field, where every effective defense technique is quickly noticed and adapted to by malicious actors. The real question is how fast each side of this ongoing cat-and-mouse game can respond.

Let us take an example of web applications. In the decade-long slog of the cloud, federal users migrated to web-based applications protected by Web Application Firewalls (WAFs). firewalls. As that method matured, malicious observers noted that the Application Programming Interface (API) allowed these software programs to communicate and exchange data.

Voila, another attack vector was born. During today's interview, Joe Henry from Akamai Technologies notes that 80% of their customers report API attacks.

Henry details a curious term called "Broken-Object Level Authorization." In this attack, an application fails to check if a user is authorized to access specific data objects. The ID is manipulated, and the malicious actor gets access.

Akamai's API Security performs behavioral analysis beyond WAFs, flags PII exposure, and supports a zero-trust posture.

Software developers talk about a "shift left"; we apply that to the Akamai approach. They have a worldwide network of Points of Presence (POPs) and data centers where they can observe attacks as they develop. It is so strong that it provides fail-open resilience with a 100% SLA.

Akamai provides a State of the Internet Report (quarterly). If you would like to stay connected with the next manifestation of attack, consider subscribing or visiting their website to stay informed about the latest trend

View Details

Twenty years ago, the concept of Bring Your Own Device (BYOD) entered the federal IT landscape with the advent of network-connected devices like Blackberries—sometimes even within secure federal networks.

This slow start has exploded into a federal information technology system with sensors on satellites, submarines, and everywhere in between. That "in between" can include on-prem networks, multiple clouds, and hybrid clouds.

Today, we sit down with Ryan Leiws, the CEO of Rancher Government Solutions, to look at some of the challenges in managing this dispersed environment and how to manage it.

Lewis describes how Rancher connects hybrid environments using containers and Kubernetes for secure orchestration.

Lewis emphasizes continuous compliance and DevSecOps via Rancher's Carbide stack, SBOM-level visibility, and rapid recovery in contested, denied/disconnected/intermittent/limited (DDIL) environments.

Lewis notes that Rancher's declarative stack reduces maintenance and allows simple app redeployment.

They also emphasize portability, cost efficiency, and alignment with zero-trust principles, with upcoming hardened features.

=

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

We began the interview with a startling fact. Maximus' federal systems interface with one in three Americans each year—about 110 million people.

Building on Maximus's broad reach, Pledger says the company's core is designing world‑class digital experiences by starting with the end goal (e.g., veterans' benefits) and using automation, AI, analytics, and omni‑channel outreach.

We have all heard about improvements in systems; today, Pledger offers specifics on how health care can improve. He cites his own 2008 Iraq injury and notes veteran case durations historically ran three hundred to four hundred days; Maximus has reduced that to two hundred to 270 days, but still deems it too long.

Maximus' success is due to its unique ability to leverage AI to drive this transformation. One approach is to partner with companies with vertical-market expertise.

For instance, Maximus partners with Salesforce (CRM) and Genesis (telephony) to respond to complex medical cases. Example: outbound campaigns (text, email, AI‑generated calls) cut lapses; proactive engagement improves experience and reduces call‑center burden.

Maximus is a story about a complex environment being tamed through understanding processes, applying technology, and making the right partnerships.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

Everyone reading this has had minor delays at the airport. It is remarkable that more problems have not developed. Look at Chicago O'Hare International Airport—it has 857,392 takeoffs and landings in a year. Each one has passengers, and most have luggage.

The opportunities for problems are overwhelming. Now add an increasing number of sensors and interlaced networks, and you have an attack surface of biblical proportions.

All an adversary needs is one single point of vulnerability to attack a system. Think what could happen if an airport network were disabled by a ransomware attack.

During today's interview, Lou Karu makes suggestions for defense that include a multi-layered strategy emphasizing zero trust and network segmentation.

However, Karu reminds us that a cybersecurity strategy is not complete without a robust recovery plan. For example, if a basic recovery plan was deployed, it is possible that a system can have compromised code locked into a backup. An airport suffers an attack, pays the ransom, and the recovered data has more attacks built in.

Best practice here is to have a backup system that is rapid and accurate, and that restores the code without it being hot-infected with additional malicious code. Systems like this from Rubrik call these backups "immutable."

The next time you go to the airport, try to imagine the numerous attack points that an airport must contend with. Even the most robust cyber defense must include plans for safe, secure recovery.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

Technology is changing so fast that it is impossible to predict the next twelve days. Despite that, we have asked Travis Rosiek, Public Sector CTO at Rubrik, to gaze into his crystal ball and make some predictions for the next twelve months.

The good news is that Rosiek sees a shift from intellectual property theft to disruptive attacks on critical infrastructure.

The bad news is that Rosiek thinks attacks are increasing to the point that an event will light a fire under the current cybersecurity plans.

During the interview, the concept of Zero Trust was unpacked. The idea is that federal systems have already been breached. As a result, the focus must be on microsegmentation, with permission as the limiting factor. Roseik's opinion is that malicious actors have planted code into systems that are acting as "sleepers."

At one time in the indeterminate future, this code can be invoked, and severe damage can take place.

If this nightmare situation occurs, the best defense is to have recovery built in. Today, leaders must have a system in place to restore data from backups.

Unfortunately, malicious actors know this plan as well and have been known to insert code into backups that renders them useless.

In a complex game of attack and counterattack, Roseik believes that a recovery strategy that includes immutable backups and an audit mechanism is the best approach in the 21st-century world of threats and countermeasures.

He also stressed the necessity of reducing complexity to enhance cybersecurity and the need for initiative-taking measures, including regular stress testing and resilience training.

= =

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

It is always tricky to compare commercial networking challenges with those faced by federal leaders. For example, the military and intelligence agencies require traffic encryption. How can an organization detect threats while observing this traffic?

Today, we discuss Vectra AI's network threat detection capabilities with Wes Nagel, DoD sales manager, and Gage Cowger, a security engineer.

With technology from Vectra AI, network traffic can be analyzed for timing, size, direction, and protocol use. These can give behavioral patterns for network visibility without worrying about encryption.

Cowger will argue that behavioral patterns are more effective than signatures, especially in mitigating alert fatigue. Signatures can overwhelm monitors with false positives; Vectra's AI and ML capabilities provide trustworthy alerts.

This ability positions Vectra AI to adapt to new networking initiatives, such as software-defined and OT/IoT networks, which will be prevalent in the future.

The discussion also touches on the future of network detection, emphasizing the need for real-time, behavior-based detection to counteract advanced threats and adapt to evolving networks.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

One of the biggest trends in software development over the past 10 years is the shift from writing code to "assembling" code from off-the-shelf components.

During today's interview with Javed Hasan from Lineaje, we learned that 70% of that pre-assembled code is open source. In other words, an anonymous person in some countries modified software instructions.

This casual approach may be fine for small businesses, but an organization like the federal government must be highly cautious.

Hasan describes how his company was one of the first to work with the federal government to set standards for this existing code. These initial efforts began ten years ago and resulted in Executive Order #14028, which requires a Software Bill of Materials for any organization selling to the federal government. This initiative expanded in 2021-2022 when NIST published related guidelines.

These efforts are a good start. However, federal leaders must evaluate SBOM technology from many perspectives. For example, how to incorporate this mandate into air-gapped networks, legacy COTS, or even in a classified environment.

System administrators also need to know if they are exposed. Further, every organization has a varying definition of what "deep software transparency" is.

Hassan also discusses Lineage's innovative approach to creating "Gold open source" software, ensuring it is free of malware and vulnerabilities.

If you are interested in seeing a demonstration of how Lineaje can help with software forensics, there is an event at the Carahsoft office in Reston, Virginia, on January 30

= =

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

In the past 10 years, Amazon Web Services has gone from a niche player in the federal government to being responsible for billions in sales.

One key aspect of this is how Amazon integrates leadership with innovation to address complex federal requirements.

Today, we sit down with Andrew Christian to get an overview of concepts like customer obsession, working backwards, and the sixteen leadership principles that AWS implements to accomplish that drastic growth.

ONE Customer-focus

In the commercial marketplace, the concept of being "customer-focused" is certainly not breaking news. However, as Christian explains, AWS tries to understand (almost obsessively) what the requirements are for federal systems.

No, technically, they are not "customers," but they are the end users for any technology project. This focus has given AWS remarkable success in the commercial world, and when they apply it to federal technology, they can succeed where others have failed.

TWO Working Backwards

Christian explains that "working backwards" is a concept where a team is forced to write a mock press release and FAQ for a future project. This is before they build anything. This helps to clarify the customers' needs by identifying gaps early.

THREE encouraging innovations

Many describe innovation as failing fast, then recovering. That may hold up in a commercial application where lives are not at stake.

During the interview, Andrew Christian differentiates between the importance of making quick, reversible decisions (two-way doors) versus long-term, impactful ones (one-way doors).

He encourages federal agencies to adopt these principles to enhance their innovation and adapt to a world co constantly changing technology.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

One famous cartoon featured two vultures sitting on a fence; one turned to the other and said, "I am sick of waiting, let's kill something."

When it comes to preventing cyberattacks, the federal government is well known for a defensive approach. They have security systems, air gap systems, and even a zero-trust approach. This defensive approach is essential but may not give the federal government a complete view of how to protect data.

Today, we sat down with Chris Jones, Nightwing's Chief Technical Officer. He outlines some of the characteristics of a concept called "offense informs defense." This is a method that Nightwing has developed through over 40 years of working with federal technology leaders.

For example, they developed their Counter Trace service, which uses offensive cyber strategies to defend critical infrastructure. The service involves proactively hunting for vulnerabilities, identifying access points, and analyzing digital evidence to expose cyberattacks.

During the interview, Jones mentions that the GSA has received this approach well. In fact, Nightwing recently won all six GSA Highly Adaptive Security Services categories. These handle security aspects like Penetration Testing, Incident Response, Risk Assessments, Cyber Hunt, and High Value Asses Assessments.

Jones emphasizes the importance of initiative-taking, cybersecurity, AI integration, and collaboration across agencies to adapt to protect federal data.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Today, we have an experienced tech veteran, Bob Stevens from GitLab, offering insights on how he sees the federal government overcoming three main technology challenges in 2026.

Challenge ONE: Software improvement on scale.

Stevens observed that everyone has seen AI's ability to review code. It has passed the basic phase, and now, in 2026, it cannot only review code but also identify security vulnerabilities, ensure compliance, and even generate documentation.

This means that older, expensive-to-maintain systems can be transitioned to more flexible, economical cloud models.

Challenge TWO: Going away from reacting.

The word "continuous" has been the goal for cyber defenders for the past several years. Fortunately, AI is allowing that noble goal to be put into practice. When applied appropriately, newer technology can achieve lower breach rates and faster threat response times.

Challenge THREE: emergence of a "universal" developer.

Traditionally, requirements would be gathered by an intermediary and then translated into instructions for software developers. Stevens shows how newer AI-based approaches can eliminate that intermediary step.

In other words, a pilot can precisely describe what they want in an avionics system, and the developers can work from that description. That means solving domain-specific problems with traditional development skills.

Ideally, subject matter experts directly translate their knowledge into functional software systems. Some call this the "universal" developer approach.

Stevens emphasized the importance of AI, security, and flexibility for future developers. GitLab's DevSecOps platform integrates AI across the entire software development process.

View Details

(We recorded this interview at Monk's BBQ in lovely downtown Purcellville, VA)

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Defrauding the federal government is like the weather; everyone wants to complain, but nobody can do anything about it. For example, a joint DOL-SBA report from December 2024 revealed $2.3 billion in potentially fraudulent payments.

Today, we sat down with Jeff Gallimore from Excella, where he will diagnose the problem of federal waste, fraud, and abuse. From there, he presents a solution that has already saved millions of dollars.

The problem: too many silos

From a data management perspective, most enterprise computational capabilities evolved through a federated approach. From a historical perspective, it makes sense that each agency would have its own computers and storage.

It makes sense that individual data stores in this environment would be separated, or perhaps the word "siloed", into distinct areas. Now, if you have one silo, you can protect it; if you have a thousand, then there is a problem.

During the interview, Gallimore mentioned an agency that manages 9,000 grants. That is a lot of data to coordinate when it is stored in its "silos."

The solution: gap analysis

Silos can be secure, but the architecture can allow for gaps in security coverage. These gaps, or seams, can allow fraudsters to exploit this structure. For example, an agency may have a division that has identified a person as a fraudster.

If that information is not shared, this person can use the same exploit on another area of the agency. Further, interlinks between federated systems can allow adversaries to gain access.

Excella has a profile of how they have managed to fill in the gaps in siloed data architecture.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

When cloud computing was introduced, it was quite a simple concept: leverage other people's hardware to scale easily. Not too much to manage.

However, today's cloud world has metastasized. Today, federal leaders live in a world of on-prem, multiple clouds, private clouds, hybrid clouds, and even sovereign clouds. Complications arise when they are burdened with compliance requirements and staff reductions.

Today, we sat down with Ryan McArthur from Zscaler to discuss how to effectively manage a cloud environment when challenged with deploying Zero Trust. He begins by sharing his experience helping federal leaders understand the inherent risks of the VPN system.

Few realize that VPN technology was first introduced by Microsoft back in 1996, and then popularized with Windows 4.0, which included built-in support. Thirty-year-old technology can present severe limitations.

Unfortunately, the popularity of VPN technology increased with the demands of remote computing during COVID. We are now in a situation where many enterprises have built their architecture on this dated technology.

Ryan mentions that one key to juggling clouds is to focus on the applications themselves. He emphasized Zscaler's ability to securely connect users.

If you want more information about Zscaler, you should attend the Zscaler Public Sector Summit in March, where you can discuss and collaborate further.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

We are at the point where AI is almost expected in any technology offering.

Today, we sat down with John Kindervag from Illumio to learn how AI can be applied to the world of federal Zero Trust.

Some have characterized today's current cybersecurity situation as an arms race; some call it a whack-a-mole game. An innovative technology, such as AI, becomes popularized, and adversaries use it to improve attacks. As a result, the defenders of data must bolster their response, and they, in turn, use AI to defend.

He highlights the importance of visibility, using AI to quickly parse logs, and the concept of dwell time, in which attackers can remain undetected for extended periods.

To protect valuable data, Kindervag distinguishes between the attack surface and the defense surface. Although a malicious actor can instigate AI-driven attacks across any surface, sensitive information can be protected by thorough segmentation of the protected surface.

During the interview, Kindervag provides tactics to manage legacy technology, fragmented data, and the critical topic of risk-averse culture.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

It is rare to see AI applied to federal cybersecurity mandates.

However, today, we will sit down with Louis Echenbaum from Color Tokens. He will unpack the concept of using AI to help federal leaders improve their ability to implement microsegmentation.

We all know about Executive Order 14028 and the OMNB Memo M-22-09, which are forcing federal agencies to deploy a robust Zero Trust framework. The key components include identity and access management, asset management, continuous monitoring, and micro segmentation.

During the interview, Louis Echenbaum expands on current challenges like legacy systems and visibility. For example, what happens once a malicious actor breaches a federal system? Some call this east-west traffic.

The general response is to prioritize and segment data so the intruder is denied access.

This concept looks good on paper, but in the real world, leaders encounter some issues. First, how can they know exactly what is on their network? This is perplexing in environments where endpoints are in areas that cannot be upgraded.

Further, the move to a hybrid cloud offers varying levels of data segmentation. One system administrator may be competent with a specific cloud service provider but does not know all the details of another company. This skills gap can lead to coverage gaps and opportunities for attack.

The solution Echenbaum suggests is to leverage AI to improve visibility and give leaders ways to prioritize datasets into appropriate microsegments.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

In the world of federal technology we are being deluged with so much information about Artificial Intelligence that we may not see what some of other technologies that may have as great an impact as AI.

The White House, the OMB (M-23-02), the Office of the National Cyber Director have made it clear that the time to prepare for post-quantum cryptography is now. Agencies are required to inventory cryptographic systems, prioritize high-value assets, and build migration plans in line with NIST standards.

Today, we sit down with Eric Hay from Quantum Xchange to look at making this transition. During the interview, Hay handles issues like technology, operations and appropriate strategy.

He highlights the role of NIST in developing and approving new algorithms like NIST PQC Post Quantum Encryption, ML, and CHEM.

Eric explains the five-step process for transitioning to these new standards: discovery, prioritization, deployment, monitoring, and management.

Rather than spending time evaluating algorithms, Eric Hay stresses the importance of a network-centric approach, suggesting that agencies focus on securing data transport first.

Eric predicts Q day, when current encryption methods could be compromised, within 3-5 years, with some European partners aiming for 2029.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

John Kindervag began the concept of Zero Trust; he probably did not realize the impact it would have on the technological community.

Today, we look at the federal government and Zero Trust implementation from 40,000 feet. Kindervag will opine on topics such as browser security, the importance of data, and operational technology.

Instead of using his technical knowledge as a cudgel, Kindervag reinforces the importance of a balanced approach in which federal leaders consider both technological and behavioral aspects of implementing Zero Trust.

People with a basic understanding of Zero Trust can disregard the importance of data; he calls it the 'protect surface'. This involves identifying and securing the smallest space within the network, as well as the entire network itself.

One missing link in the move to Zero Trust is Operational Technology. When looking at the Department of War, it has assets deployed all over the world. They have thousands of sensors that may or may not be part of a network.

Kindervag suggests that when you have a protected surface that is a critical asset, which means it can be included in data sets.

The interview ended with comments regarding the challenges of implementing zero trust, particularly the need for strong leadership and the potential of AI to enhance cybersecurity measures, while acknowledging the complexities of data classification and the evolving threat landscape.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

A quick review of malicious activity shows large-scale cyberattacks being run without any human intervention. That means traditional penetration testing, which occurs once a year, can be easily defeated by massive, systematic attacks. During the interview with Snehal Antani, CEO of Horizon Three, he highlights the importance of continuous autonomous penetration. He suggests that it may be the only response to a non-human automated attack. Horizon3 has recently collaborated with the NSA's Cybersecurity Collaboration Center to develop the Continuous Autonomous Penetration program. He details identifying critical vulnerabilities not only in federal systems, but also in the Defense Industrial Base.]

Today's cyber threat landscape is rapidly evolving, with artificial intelligence fueling a new wave of increasingly sophisticated attacks. Malicious actors now leverage AI to automate and scale their operations, resulting in large-scale, highly coordinated cyberattacks requiring little to no human oversight. This surge in automation on the offensive side has exposed a significant gap in the traditional cybersecurity strategies of federal agencies, which still largely rely on manual or scheduled defense mechanisms such as annual penetration testing. These legacy approaches are woefully inadequate against relentless, continuously evolving threats executed by automated tools that probe for weaknesses around the clock.

Federal leaders, traditionally cautious about deploying automated systems for cybersecurity, now face a crucial crossroads. The old paradigm—where automation in cyber defense was seen as risky—must be reconsidered in light of real-world evidence that manual processes cannot keep pace with automated adversaries. In a recent interview, Snehal Antani, CEO of Horizon3, emphasized the critical need for continuous, autonomous penetration testing. He argued that just as attackers use automation to identify and exploit vulnerabilities at scale, defenders must employ similar automation to uncover and remediate those weaknesses swiftly and continuously.

To advance this approach, Horizon3 has partnered with the NSA's Cybersecurity Collaboration Center, launching the Continuous Autonomous Penetration program. This initiative aims to proactively identify critical vulnerabilities not just in federal government networks, but also across the Defense Industrial Base. By integrating automated, persistent penetration testing into daily operations, federal agencies can better defend against the nonstop, AI-driven threats now targeting every aspect of their infrastructure.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

The good news is that federal security measures are preventing successful attacks; the bad news is that adversaries are examining every nook and cranny of a federal system and increasingly targeting the browser itself as an attack vector.

During the interview, Scott "Monty" Montgomery gives a quick overview of Enterprise Browsers and Secure Enterprise Browsers. After all, browsers have been around since 1994. It may be the only application ubiquitous on home-based machines and in enterprise systems.

They were not designed for security; they were intended to open the internet to the World Wide Web, full of images, links, and audio. Malicious actors did not have to focus on an app with limited use; by targeting a browser, they have almost unlimited targets to attack.

Montgomery mentions the increase in browser-based attacks. In fact, they increased by 198% in the second half of 2023. Scott explains that phishing persists because people are curious or fearful, leading them to click on malicious links.

A Secure Enterprise Browser can help prevent many common phishing exploits. Additionally, an SEB can support policies and controls.

This means that an SEB fits completely with any current Zero Trust initiatives across all agencies. Beyond that, SEBs can be configured to manage legacy systems and even operate in low-bandwidth environments.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Every federal agency prepares a backup strategy to protect data. This is a rigorous endeavor in which teams practice what to do in the event of a breach or system failure.

However, nobody really has a plan for a temporary federal shutdown.

Any political pundit worth his salt knows there will be another federal shutdown sometime in the future. It is reasonable to consider automation to see how it can be used to bridge services during a temporary shutdown.

David Grundy is the Public Sector CTO for Tines. He has decades of experience in and outside the federal government. He highlights the challenges of human-centered workflows. For example, just because the staff is reduced does not mean attackers will take the day off. Adversaries work 365 days a year and are immune to political infighting.

Based on David Grundy's experience, an agency should start with visibility to know which workflows exist. From there, document processing can be detailed, enabling scaling.

During the interview, Grundy shares his experience in a federal agency that had to make digital transitions while complying with federal regulations. He is optimistic that operational resilience can be achieved through initiative-taking by all federal agencies.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

In a recent report from Microsoft, they share that foreign adversaries are increasing attacks on American infrastructure. One variation is that they will not penetrate systems and attack, but they will steal credentials and install code to act in stealth mode. This code can hide for years and be deployed when the antagonist wants.

Today, we sat down with Travis Roseik from Rubrik to try to find some options for defending against this hidden attack.

Let us say an agency has improved its resistance to foreign attacks. This is satisfactory progress, but what happens in a situation where the malicious code was planted prior to the increased defense.

Further, during the interview, Roseik states that companies may be able to leverage AI to improve defense, nation states will be using that same AI to improve attack methods.

If malicious code is within the walls of an organization, whether by AI or user error, Roseik makes the point that a defensive posture may not be enough in today's sophisticated world of attack. He recommends moving from a defensive approach to an initiative-taking threat hunting strategy.

Even if Zero Trust and threat hunting fail, the best response is to have immutable backups. For example, if a breach occurs and the system recovers quickly, then the attackers will go after more vulnerable targets.

The conversation underscores the urgency for organizations to adapt and innovate to counteract these threats.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

The federal government recognizes that threats are multiplying at an exponential level. In fact, in October 2025, CISA released a free vulnerability scanner, and 10,000 organizations have signed up. Today, CISA is at its current capacity.

Today, we examine solutions from a successful startup called CrunchAtlas. One of the co-founders, Ben Fabrelle, will share with the audience his experience in threat hunting in the federal government and why he combined with another veteran to form a company that can assist in threat intelligence, data analysis, and automation.

During the interview, Fabrelle says that CrunchAtlas likes to attack "wicked" complex problems. One of the most complicated problems the federal government has is identifying threats in a world where the DoD is being attacked by malicious actors every day.

Fabrelle suggests that the solution is a persistent cyber-hunt platform. It can search for threats in a wide range of environments. This means it can be deployed on-prem, in the cloud, or in an air-gapped environment. The founders view that a platform approach is the best way to scale against these adversaries.

One of the key differentiators for CrunchAtlas is its ability to operate in the cloud, on-prem, and even in an air-gapped environment. In fact, their offering's code stack, from design, operates in an air-gapped environment.

Automation in this kind of environment will allow for a reduction in false positives, which will, in turn, reduce fatigue and decrease the need for human threat hunters.

View Details

Ep. 281 How Zero Trust Automation Helps Federal Agencies do More with Less

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

As this interview was recorded, the federal government was in the middle of a shutdown. Hundreds of pundits have given interviews about the politics of the situation; very few have looked at the impact on cybersecurity during a phase of workforce reduction.

Today, we sat down with Gary Barlet, the Public Sector CTO at Illumio, to see whether Zero Trust can help the federal government bridge this short personnel gap.

Barlet begins by giving an overview of Zero Trust and automation. Rather than having human beings vet entry into federal systems, the concept is to use an automated process that reviews credentials and decides on permission.

Barlet emphasizes the importance of Zero Trust in automating security tasks and maintaining operational resilience, especially with reduced staff.

He continues to mention several other benefits of Zero Trust in a federal environment.

Compliance: A well-thought-out Zero Trust architecture will enable managers to collect data to demonstrate policy enforcement.

Legacy: One can effectively take existing systems and "ring fence" them off. This approach creates hundreds and hundreds of rings of defense.

Design: During the interview, Gary recommends that you have a handle on the real traffic to reduce complexity. That way, when policies change, the rules can adapt to the environment.

Maturity Level: Although CISA has a maturity level for Zero Trust. Barlet distills down some of the requirements for which efforts can be applied to sensitive systems. He suggests focusing on security, not necessarily on a grade.

Additionally, he addresses the challenges of managing complex, hybrid environments and the emergence of shadow AI models, stressing the need for robust policies and controls.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Today, we sat down with Chris Wysopal from Veracode to talk about how to leverage the power of AI to increase productivity in federal systems. It seems like every headline you read talks about AI speeding up the process of writing code.

However, there may be mixed messages here.

Wysopan read some academic reports that talked about vulnerabilities being introduced in human code as well as AI code.

Because this has been a concern for a while, He initiated the Gen AI Code Security report. They examined a wide range of LLMs to get a fair overview. They discovered 45% introduced vulnerabilities. What is even more shocking is this is similar to the rate from regular, old, garden variety software developers.

You can get more details from the Veracode's 2025 Gen AI Code Security Report. It details methodology and notes despite improvements in syntax; security remains a concern.

When he presented at a recent Billington Cyber Summit, he was deluged with people interested in problems with AI generated code.

The overview is Implement a centralized risk management approach to prioritize and address the most critical vulnerabilities.

View Details

A recent study from Carnegie Mellon University is titled "AI Agents Fail at Office Tasks Nearly 70% of the Time."

Federal agencies are adopting Agentic AI for the efficiency it can deliver. Unfortunately, many do not realize that Agentic AI is prone to operational risks, ranging from technical glitches to legal complications to accidental database deletion.

When Agentic AI causes problems at a federal agency, there can be lives at stake.

Today, we sat down with Travis Rosiek, Rubrik's Public Sector Chief Technology Officer. During the interview, he explores the federal challenges of implementing Agentic AI, building an Agentic AI inventory, and making Agentic AI visible, auditable, and reversible.

CHALLENGES

Everyone —from a systems administrator to an agency administrator —knows that data must be backed up. However, very few understand that Agentic AI is a collection of agents that can be attacked, just like a database.

Rubrik offers the capability to reassure users that Agentic AI can be reversed if malicious actors enter the picture.

STARTING POINT

Most cybersecurity professionals agree that one starts by understanding a system's apps, data, and connections. Five years ago, it was easy; getting a grasp on what Agentic AI connects to is a much more intangible concept.

During the interview, Travis Rosiek unpacks Rubrik's history and its unique ability to understand complex systems.

CAREFUL

In a rather shocking statement, Rosiek says one should approach introducing technology with the assumption that it will fail. This is not a pessimistic approach, but a nuanced understanding of how complexities in current systems can lead to unintended consequences.

Rosiek advises starting with the end goal in mind, planning for worst-case scenarios, and building trustworthy AI architectures to mitigate risks and ensure reliable operations.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Elastic has been around since 2012 and has been gradually gaining traction in the commercial world. In fact, Elastic has recently signed agreements with Nvidia and Google to improve integration with its distributed search analysis. All this assists with AI search and observability.

Today, we sat down with Chris Thompson from Elastic to highlight how commercial success can be applied to the federal world.

Looking back at his decades of work with federal agencies, he sees one of the problems in acquisition. In a world of rapid change, it is challenging to acquire technology that can keep pace with the fast pace of change.

During the interview, Thompson discusses a recent strategic agreement developed by Elastic working with the GSA and other companies. This streamlines the process of providing technology to federal professionals.

This agreement accomplished several tasks at once:

It leverages the GSA's collective buying power. Rather than negotiating separate prices for dozens of agencies, it has substantial discounts with all the major cloud providers.

It reduces duplication. We know several federal agencies are facing similar tech challenges. Rather than duplicating requirements gathering and testing before making a purchase, the GSA approach eliminates this duplicative process.

With numerous AI tools flooding the market, this agreement enables the accelerated use of these tools.

When you have standardized contracts, enhanced security is typically the result.

No contract is perfect, and people who have developed this agreement know it is a living document that can flex and adapt to technical situations as they arise. GSA officials have stated this is an evolving approach, giving it the ability to adapt to innovative technology, new companies, and a rapidly changing cyber threat.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

MongoDB has spent years earning a formidable reputation in the developer world; today, we will unpack some of its capabilities for project managers and federal leaders so they can understand where MongoDB may fit in their stack.

Conventional wisdom is that MongoDB is a flexible open-source database. Although that is true, this does not do justice to some characteristics that will appeal to the federal audience.

ONE: An agency may have restrictions on where the cloud is not suitable for storage. Because of its ability to use flexible, JSON-like documents, MongoDB has listened to those needs and can have storage in many varying regions.

In fact, we have seen a movement to move cloud applications back on premises. MongoDB provides flexibility for working in both hybrid and on-premises environments.

TWO: Most readers have studied encryption and think of it primarily as data at rest. Cloud storage transitions have forced a method where data is encrypted during transit.

MongoDB can take encrypted data and search while it remains encrypted. Some will describe encryption at rest, in transit, and now, data in use.

THREE MongoDB has listened to the federal community and is offering something called MongoDB Atlas for Government. It is a secure, fully managed cloud database service for U.S. Government agencies to modernize applications and oversee sensitive data.

During the interview, Ben Cephalo revealed the effort MongoDB is making to serve federal agencies that require FedRAMP high capabilities.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Many listeners have become so familiar with AI that they may have assumed it has been around for decades. Today, we sat down with Will Angel from Excella to explore the application of AI to federal technology from a more nuanced perspective.

We dive into three main aspects of AI: challenges of integrating AI services, Model Context Protocol, and security considerations with agentic systems.

Challenges:

No company has grown as fast as ChatGPT; in fact, it is the fastest-adopted consumer application in history. Today, it has an estimated eight hundred million weekly users. This has attracted developers who work on federal projects.

Wil Angel recommends careful consideration of people arbitrarily porting data to or from products like ChatGPT because it can compromise data security.

MCP

In certain circles, the term "Model Context Protocol" is used constantly. It has become so popular that people do not realize it was just coined by Anthropic in November of 2024. During the interview, Angel presents variations on MCP for software development and warns about the hype surrounding the relatively new standard for AI systems.

Agentic AI

Autonomous systems have been the holy grail for every software developer. The promise of Agentic AI is so powerful that some have jumped into applications without a more prudent approach.

When a series of tasks is assembled, unintended consequences can come into play. It is one thing in the commercial world to reveal essential data; it is a completely different situation when the DoD is dealing with life and death situations.

Angel predicts significant changes in AI over the next few years, with large language models revolutionizing software systems.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Sometimes, the plow must go deeper. Current approaches to Zeer Trust implementation can leave gaps in security. Today, we sat down with Akamai's Mike Colson to discuss the concept of combining Identity Credential Access Management with Least Permissive Trust.

Setting the stage, Mike Colson details some of the challenges in the varying kinds of Zero Trust that are being applied in the Federal Government.

The standard way of implementing ICM can result in assigning more resources than necessary, leading to permission creep and inflexible permission.

Over provisioning: The amount of data being created is almost impossible to manage. A person may be given access to a data set they are not permitted to see. A "just in time" permission structure would help avoid that situation.

Stale: Just because a person has access to a data set on a Tuesday does not mean he has access on a Wednesday. People can leave the workforce, be reassigned, or change roles. Access must be constantly updated.

Static: Ron Popiel made the phrase, "Set it and forget it," memorable. Unfortunately, this approach can lead to a permission structure that may limit access to key data. This may be considered under-provisioning, potentially leading to time delays in obtaining key information.

Colson took the listeners through several iterations of access control, including Role-Based Access Control and Attribute-Based Access Control. On top of these old favorites, Colson discussed what may be called Context-Based Access Control, or what he calls Least Permissive Trust.

Least permissive trust is a concept Colson outlined, which uses user behavior, device health, and contextual factors to grant permission dynamically.

The conclusion is simple: not all Zero Trust is created equal.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

The impact of AI in software development in the federal government is so pervasive that, in July of 2025, the President of the United States released a White House AI Action Plan.

Today, we sat down with Bob Stevens from GitLab to put this development into perspective, examine some use cases, and suggest methods that federal agencies can use to prepare for this technological shift.

What precipitated the initiative is the recognition that change is occurring so rapidly in the world of software development that the federal government must adapt more quickly than in the past, or it will be vulnerable to cyberattacks.

Stevens notes that the federal government has been targeting modernization, producing software faster, and being more efficient, for a decade. AI will help them get there, with some possible cost reduction.

For example, in the past, a vulnerability may have taken weeks to discover. Utilizing AI allows federal software developers to reduce that discovery to minutes. That ties in with one essential element in the White House initiative: security. In fact, one of the pillars of the Action Plan is titled "Promoting Secure-by-Design AI Technologies and Applications."

Stevens has been involved in federal software development for decades and thinks that a platform approach best serves the essential objectives of this Action Plan. The conversation concludes with the potential for AI to streamline government processes and improve operational efficiency.

If you are interested in learning more about the economics of this approach, you can download The Economics of Software Innovations: $750 billion Opportunity at a Crossroads.

View Details

Fraud rates in the public sector are estimated at 20%, compared to 3% in the private sector. Some estimate the loss to the federal government at over $500 billion.

Today, we sat down with Haywood Talcove, the CEO of LexisNexis Special Services. He presents listeners with shocking statistics on fraud, shares personal stories, and offers suggestions to help taxpayers overcome this loss of money.

FRAUD

Talcove begins by noting the fraud rate in the federal government before COVID was a paltry 0.1%. No news there. However, during the COVID-19 pandemic, federal employees were legally obligated to disperse funds promptly. They became more concerned about sending out money than maintaining precise accounting.

PERSONAL STORY

During the interview, Talcove recounts the story of how a bank teller defrauded his mother. He details the frustration in just trying to uncover the fraud. After many attempts, he collaborated with local police to discover the method of the attack.

SOLUTIONS

The fact of the matter is that an employee of AMEX has a strong interest in preventing fraud. In contrast, many in the federal government are more concerned about compliance with directives than avoiding loss.

NIST has a recent update standard, NIST SP 800-64 Digital Identity Guidelines, but criminals move faster than federal regulations can keep up.

The solution is obvious: to improve data sharing between government agencies. Next, learn from the private sector how to identify and stop fraud more effectively.

What can a consumer do?

· One credit bureau freeze closed.

· Two informed delivery post offices

· Three county alerts on title

· Four text messages alert any transaction -- know quickly.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

We are recording this at the Air Force Air, Space, & Cyber Conference. During the second day of the conference, General B. Chance Saltman, Chief of Space Operations at the Space Force, talked about a “focus on readiness.”

Our guest, Rob Bocek from Virtualitics begins the interview by talking about the concept of readiness being applied to AI.

In fact, Bocek recently did an in-depth discussion of this topic at a conference he led titled The Frontiers of AI for Readiness.

Today, we combine some of the lessons learned from that gathering with some of the goals and aspirations that were given at presentations at this year’s Air Force Air, Space, & Cyber Conference. In a wide-ranging interview, Bocek comments on topics like guardrails, leadership, procurement, and collaboration.

GUARDRAILS

Even the casual observer will notice that AI will have an impact on the DoD. However, the DoD deals with life and death decisions daily and cannot be subject to data poisoning and LLM attacks. During the interview, Bocek commented on implementing guardrails when experimenting with AI.

LEADERSHIP

In the corporate world, leaders will justify a blind jump into AI with assertions like, “if they don’t jump in, their competitors will.” The DoD deals with much more than a profit and loss statement. Military leaders must step up with understanding the positives and negatives of AI, and lead technology experts into correct implementations.

PROCUREMENT

When General B. Chance Saltman was presenting nobody in the audience thought he would include acquisition reform as one of his three main points. He reinforced the concept of living in a contested world where adversaries can adapt quickly, and the American military cannot be held back by antiquated procurement processes.

Listen to the podcast to get an idea of some of the solutions available for federal leaders trying to use AI in a responsible manner.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Ten years ago, Nutanix exploded on the federal scene. By now, just about every listener has heard of Nutanix partnering with the federal government in a wide range of projects.

Today, an update with Greg O'Connell from Nutanix. He demonstrates how federal agencies can leverage Nutanix's experience to achieve mission success across various cloud environments.

During the interview, O'Connell gives a basic comparison of multi-cloud vs. hybrid cloud. From his perspective, a multi-cloud environment includes one or more public cloud providers. A hybrid cloud enables a system that combines on-premises infrastructure with public cloud services. This allows a single, integrated environment, providing more control over access, compliance, and ability to connect with legacy systems.

Existing applications and data always present a challenge in moving to the scalability and flexibility of the cloud. Nutanix brings to federal technology its ability to work with legacy systems in a system that has been evaluated over time.

Most federal leaders may wonder what is taking place in other agencies. To that end, Nutanix provides an annual report on cloud activities.

The 7th Annual Nutanix Enterprise Cloud Index Report highlights that 94% of US government entities utilize AI, but 76% require infrastructure improvements.

Liten to this podcast to get an update on innovation from Nutanix and download the report to gain a better understanding of activities in the federal tech community.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Most listeners are familiar with LMI as a sixty-year-old nonprofit, providing logistics management services and related research to the federal government.

Today, LMI is a for-profit organization that leverages its decades of experience to gain a competitive advantage in understanding use cases where AI can reduce costs, enhance security, and facilitate the analysis of unstructured data.

An engagement with LMI does not begin with clients explaining federal regulations; it starts with mission-ready products and platforms that are built on a deep understanding of the need for trust, transparency, and compliance.

During the interview, Bettina Koleda explains that the federal government is getting pressured to do more with less. Additionally, because of the importance of the data inherent in many federal applications, users must trust that the data is not being compromised in any manner.

LMI has developed a platform called LIGER that combines the need for reduced costs while maintaining compliance. Bettina Koleda explains how it can help translate mission goals into software requirements and continuously refine solutions through feedback from federal agencies.

Kaleida is optimistic about the future of AI, believing it can help solve significant global issues if managed effectively.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

It is difficult to pinpoint an exact number, but some statistics show an executive is five times more likely to be attacked than a regular employee. It makes sense. If you receive a suspicious email from a fellow employee, do not respond. However, if you receive an email from the CEO, you are more likely to react more aggressively.

In today's interview, Richard Fleeman and Ricky Freeman from Fortreum Labs discussed the increased risk executives face, citing a 74% human error rate in breaches.

How do malicious actors get personal information on an executive? Sometimes, leaders are too active on social media and, for example, post when they are on vacation. If an employee gets fooled, he may transfer assets online.

Okay, we know ransomware is on the rise drastically, and companies are vulnerable – what can an executive do to prevent this activity?

Richard Fleeman observes that once the money is transferred, it is exceedingly difficult to find a resolution. He suggests that prevention is the best approach.

Start with social media and see if you are revealing your email or confidential information. Some call this oversharing. Multi Factor Authentication is a terrific way to limit access to your accounts.

People often use the same password. Humans tend to repeat passwords. "Password spraying" can be used to break into accounts.

Fortreum offers a service to help executives avoid these common pitfalls. They can start with publicly available data and then move onto the dark web.

Ricky Freeman notes that attacks like the OMB breach often result in data for sale on the dark web. He has developed tools that enable the scraping of the dark web to determine if an executive can compromise sensitive information.

Hard to expunge – easier to opt out Dark web. Even if your compromised information is extant on the dark web, you may not be able to do anything about it.

Fortreum's services include manual testing, attack surface analysis, and dark web scraping to identify vulnerabilities and provide recommendations.

You can get an idea of your vulnerability by taking advantage of guides to see if you are exposed.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

The federal government manages a great deal of sensitive information that it is reluctant to share with other agencies or organizations. However, isolation means important decision-making data can be inadvertently withheld from leaders.

The simple term "collaborate" can be easily applied in a classroom. Still, it becomes almost impossible with petabytes of data that have varying levels of security, such as classified, secret, and top secret.

Even if the puzzle of sharing data is solved, the issue of data classification changes and data being attacked with malicious code remains.

Sean Berg is the CEO of Everfox, a company that has spent the last twenty-five years solving this data problem by using cross-domain technologies.

During the interview, Sean Berg discusses the role of AI in ensuring data integrity, the challenges posed by legacy systems, and the critical nature of data management in national security and digital transformation.

Sean Berg moves beyond Cross Domain Solutions to Everfox's Content Disarm and Reconstruct (CDR) technology. With this approach, the document is opened and examined for malicious code, then copied. CDR is a tool for ensuring data integrity and preventing malware infiltration, allowing for safe and secure collaboration between federal entities.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Sometimes, a company becomes so large that it is difficult to be specific about how it can help any organization, especially one as vast as the federal government.

Today, we sit down with Ron Bushar, Chief Information Security Officer & Managing Director – Google Public Sector. We address many of the significant concerns federal technology leaders have regarding topics such as cloud-native, edge computing, and Zero Trust.

This is a rudimentary overview of working with Google Public Sector. If you would like to connect in more detail, you can attend the free Google Public Sector event in late October. The focus will be on the investments Google Public Sector has made in AI and security.

Ron Bushar begins the discussion by highlighting the benefits of transitioning to cloud-native applications. Modern applications demand availability anytime and anywhere.

Emphasizing applications that can leverage the cloud provides scalability and security that are often lacking in older systems. Furthermore, when one combines cloud-native with AI, the result is a lighter-weight platform that can be used worldwide to support missions.

This “anywhere” concept encompasses areas of the world that require remote access, which is increasingly referred to as edge computing. Google has provided international access since its early years, and it has the capability that can allow federal technology to be connected at the edge.

Most federal security conversations today involve the concept of Zero Trust. Ron Bushar makes the point that Google was a pioneer in Zero Trust.

Listen to the interview to hear about

· 70% discount

· Agentic AI

· Hardening of Google

· Gemini and federal applications

Even better, attend the Google Public Sector event on October 29, 2025.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Virtualitics, a company spun out of Caltech and NASA JPL in 2016, focuses on applying advanced AI to mission-critical challenges, including asset availability, personnel readiness, and supply chain optimization.

During the interview, Rob Bocek, Chief Revenue Officer at Virtualitics, provides listeners with insight into how his company can enhance Air Force readiness while ensuring explainability and democratizing AI.

Sometimes, AI is described as a “black box” where one pours in data and out pops an answer. In a life-or-death scenario that many military organizations face, this arbitrary approach will not suffice. As a result, solutions provided by Virtualitics, document the process carefully.

Listening to the customer is key to understanding supply chain problems. Rob Bocek details how his team will get close to the end user. This can be a “democratic” approach where a wide variety of input is absorbed. Virtualitics aims to identify the root causes of pain and determine what specifically needs to be solved.

He highlights their ability to detect anomalies, optimize training pipelines, and anticipate equipment failures. Once these preliminaries are brought together, the most tremendous success will be accomplished when leadership takes risks.

Looking ahead, Virtualitics is hosting the Frontiers of AI for Readiness Summit at Caltech to convene DoD leaders, academics, industry, and investors. Bocek emphasizes partnerships across technology providers, cloud platforms, and startups as essential to scaling AI solutions and accelerating the DoD’s adoption.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

In 1987 Microsoft introduced PowerPoint, it is one of the few applications that has endured almost four decades! Today, we look at some options that incorporate more flexible ways to innovate.

Charles Firey from Excella provides listeners three ways to make a transition from PowerPoint to modern applications. He discusses setting temporary instances of a modification, making sure this approach is consistent, and where to look for opportunities to apply this dynamic method.

Sandbox. Instead of worrying about managing sensitive data, create a sandbox or synthetic data environment to enable quick concept demonstrations without compromising security or compliance. Once a federal leader can see the proposed solution, iterations can take place in a more effective manner.

Consistent. Once the concept of a “sandbox” has been established, think about federal security considerations. Develop a consistent approach for creating prototypes that align with production-ready compliance requirements that include protecting data at rest and data in transit.

Opportunities - Identify opportunities to incorporate rapid prototyping as part of the method. Not every technical problem can be solved with improving interactions with websites; however, many areas can be helped if you know how to apply an iterative approach to software development.

Charles notes that Excella uses synthetic data and consistent workflows to ensure prototypes align with production standards. The conversation also touches on the cost-effectiveness and future potential of AI-driven prototyping in federal projects.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

In boardrooms across America, members are slowly starting to notice the proliferation of cyber-attacks. It is one thing to recognize the danger, quite another to do something about it.

Board members may ask, how does a company’s risk profile compare to others? What is a reasonable amount of money to budget for cybersecurity? What about company growth & change? Are there tools to use to approximate risk level?

Today, Ben Scudera from Fortreum jumps feet first and answers the tough questions Ben admits that financial estimates are always difficult, he suggests a typical spend of ½ % - 2% of a company’s annual budget for a typical company. If you are in a regulated environment, perhaps one like a hospital or bank, you may need to revise that estimate.

Risk prioritization will have to vary based on the circumstances of each organization. Some start at a weak baseline, others can be quite safe.

Even if you are secure, what happens in the future is your company acquires another? What about drastic growth in sales and plant expansion? How to keep up with new attack vectors?

Ben’s goal is to provide an understanding of the threat without any scare tactics. One approach is to use a guideline from Fortreum’s Cyberfoundation that includes eighteen metrics. This view allows leaders to prioritize remediation efforts.

He highlights the importance of continuous risk management and education to combat evolving threats like ransomware and phishing attacks.

Here is a link to the guidelines from Fortreum:

View Details

Ep. 264 How Automation Is Accelerating Digital Transformation Across Federal Agencies

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

In this episode of the Federal Tech Podcast, host John Gilroy interviews Nabil Amiri, Vice President of Business Development for the federal practice at NWN. The discussion introduces NWN’s expanding role in helping federal agencies adopt advanced technologies, particularly artificial intelligence (AI), as part of broader digital transformation efforts.

Amiri explains NWN’s recent acquisition of Leverage Information, a move that brought deep federal experience—especially with defense, intelligence, and civilian agencies—into NWN’s already strong commercial portfolio. This merger allows NWN to deliver robust, secure IT solutions tailored to the complexities of federal requirements such as FedRAMP, STIGs, and Zero Trust. He emphasizes that innovation and compliance can—and must—coexist in the federal space.

The conversation touches on the real-world challenges federal agencies face, like outdated systems, budget cuts, workforce reductions, and tool sprawl. Amiri critiques the proliferation of “single panes of glass” in IT environments, which often complicate rather than simplify operations. NWN’s strength lies in delivering visibility across systems, reducing complexity, and enabling security and automation through integrated, scalable platforms.

Key themes include Zero Trust architecture, infrastructure modernization, automation, and streamlining tech procurement. NWN’s flexible acquisition pathways (e.g., via GSA and SEWP contracts) make it easier for agencies to respond quickly to crises like COVID or cyberattacks.

On AI, Amiri emphasizes its role in real-time data analysis to improve visibility and prevent outages, critical for mission continuity. NWN remains vendor-neutral, working with a broad ecosystem of partners to deliver best-in-class, mission-focused outcomes.

Looking ahead, Amiri confidently predicts that AI will become foundational to all federal IT strategies, driving operational resilience and transformation in the next five years. The interview sets the stage for deeper dives into emerging topics like agentic AI and cloud-native strategies in future discussions.

View Details

Ep. 263 How Microsoft Drives Cloud-Powered Transformation in Federal Agencies

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Microsoft has been a behemoth in the world of information technology since its founding in 1985. The only way to understand how Microsoft can impact the federal government is to take a topic like AI and conduct a thorough analysis.

Today, we sat down with Wole Moses, the Chief AI Officer for Microsoft Federal. He shares his perspective on how Microsoft's innovation can help federal agencies achieve their ambitious goals. Essentially, we discuss AI's role in cyber threats, legacy infrastructure, and compliance.

Moses explains that Microsoft's AI assistant, Copilot, is integrated into various products to enhance productivity. He emphasizes the importance of a strategic approach to AI, aligning projects with agency missions and goals.

Moses discusses the potential of AI to modernize legacy systems and processes, improve cybersecurity, and support software developers.

In AI, multimodal refers to a system that utilizes text, images, audio, and even video. He also highlights the need for multimodal AI to expand communication capabilities and the importance of compliance with frameworks like FedRAMP and NIST RMF.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Today, we discuss the importance of user experience for federal websites with guests Amanda Chavez and Rishi Vajpayee from Qualtrics.

The expansion covers topics such as cost savings, automation, and the impact of unstructured data on how websites provide information.

COST SAVINGS

Older systems in the federal government may have been designed to optimize for one function. When new administrations are elected, it is possible that alterations can be made, and the existing system can lead to inefficiency and slow data utilization.

During the interview, Amanda Chavez details how a company like Qualtrics can help federal leaders understand friction points. This is especially effective when making a transition to the cloud.

Bottlenecks are identified, and the remedy is provided, enabling the complete flexibility of the cloud to be leveraged.

AUTOMATION

Federal agencies are encouraged to do more with less. Automation can provide the solution to this challenge. Frequently, self-service channels can provide information to citizens faster and more reliably than a traditional human in a call center can.

UNSTRUCTURED DATA

Rishi Vajpayee discusses some of the weaknesses in how surveys about web experience have been conducted. He notes that unstructured data, such as text, email, and feedback, provides a much richer and deeper understanding of how to enhance a website's effectiveness.

Qualtrics' upcoming federal summit in August aims to address these issues and improve service delivery. The Qualtrics Federal Summit event in August 2025 will discuss improving the federal website.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

The current administration has a focus on reducing costs while also improving the delivery of goods and services. When it comes to handling data, innovations in code generated by artificial intelligence have enabled this remarkable goal.

The challenge arises when transitioning from the data center to the hospital. " Fail early" may be a mantra for a software developer, but in a healthcare situation, it is unacceptable.

Today, we sat down with two executives from Phillips and explored the value of applying mobile technology to reduce cost and enhance patient outcomes in hospitals.

Both gentlemen are military veterans, and the focus of the discussion is the Department of Veterans Affairs, which operates 170 medical centers and employs over 470,000 staff members.

When examining the population of veterans, we can see that it has a wide distribution in rural areas. This can mean long trips for patients to get care.

During the interview, we look at wearable devices that can provide information to physicians to help make treatment decisions. These can provide real-time health monitoring to act as an "early warning" system for patients. For example, it can detect signs of infectious diseases before symptoms appear.

Advances in machine learning and artificial intelligence enable Phillips to develop a risk score calculation that reduces exposure to vulnerable populations.

Explore opportunities to further deploy Philips' remote monitoring and telehealth technologies within the VA healthcare system.

View Details

Want to listen to other episodes? www.Federaltechpodcast.com

In 2018, ransomware was a quaint little cyberattack. Suddenly, the first half of 2024 saw $459 million paid in ransomware. Everyone is being targeted: retailers in the UK, resellers in LA, and even the federal government can be included in the target for ransomware attackers.

Today, we sit down with Douglas Holland to see what role Akamai plays in preventing these rapidly proliferating attacks.

One of the strengths of Akamai is its ability to handle a wide range of internet activity, as Akamai processes 11 trillion DNS queries daily. This gives them a perfect perspective to identify troublesome sites and apply Domain Name Systems (DNS) to provide robust cybersecurity.

Douglas Holland puts this situation into perspective by noting that during the COVID-19 pandemic, more and more people started using VPN technology, making systems vulnerable to phishing attacks.

He notes the rise of ransomware-as-a-service and phishing-as-a-service, emphasizing the importance of employee training and education.

Holland also addresses the challenges of VPNs and remote desktop security, advocating for zero-trust architectures and multi-factor authentication.

The interview ends with discussing the role of AI and machine learning in Akamai's threat protection.

View Details

Everybody knows the world of technology is changing on a massive scale; in the federal community, there is a similar seismic change, but it has to do with policy, not graphics chips.

In 2020, the Department of Defense aimed to ensure its suppliers had a reasonable level of cyber protection and released the first version of the Cybersecurity Maturity Model Certification (CMMC).

In subsequent years, CMMC became a “nice to have” rather than a mandate. COVID-19 drastically increased the number of remote users, federal technology was moving to the edge, and malicious actors continued to expand their attacks unremittingly. As a result of this “Perfect Storm,” regulators at the DoD have gotten serious about CMMC compliance.

In today’s interview, we sat down with two CMMC experts and discussed some of the challenges associated with completing the CMMC requirements.

Fortreum’s Ben Scudera mentions that as many as 300,000 companies may be looking at CMMC compliance. While individual companies can read the requirements, there can be misunderstandings.

For example, if a company tries to define Controlled Unclassified Information, it may cast too wide a net or too narrow a net. If they are audited, the entire concept of scoping CUI can become a holdup for certification.

Early versions of CMMC allowed companies to review their capabilities and report themselves. Today’s CMMC transition is from self-attestation to external audits. These audits are challenging, with only 70 C3PAOs available to support 80,000 companies that require level 2 compliance.

The process is complex, requiring detailed data scoping and significant preparation time.

Companies must strike a balance between the costs and benefits of compliance, particularly for small businesses. The conversation also touches on the broader implications of CMMC for supply chain security and the potential for CMMC to evolve beyond federal contractin

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

According to Forrester, 48% of organizations have more than one hundred tools in a typical toolchain.

How many are not being used? How many duplicates are there? How many can remove abilities in other tools?

When you deal with a company, they are getting paid to focus on their solution and ignore others. When you deal with a reseller, they have biases, respond to changes quickly, and understand the complexities of vendors in “swim lanes,” which can include competitors.

Today, we sit down with Sam O’Daniel, the President and CEO of TVAR. The conversation ranged from selection of the correct tool to procurement and licensing models.

For example, in a recent interview, Scott Rose from NIST talked about modern technology that may include IPv6. The sad news is that it prevents scanning address blocks because it cannot scan all the addresses that IPv6 covers.

TVAR collaborates with numerous vendors and is familiar with the strengths and weaknesses of each. Additionally, he understands which vendors work well together and respects the concept of their “swim lanes” in the context of federal technology.

A typical federal leader cannot spend five hours a day keeping up with modern technology; resellers must maintain updated knowledge, which they can provide federal agencies with a perspective that few have.

The conversation also addresses the challenges of procurement and the need for tool consolidation to minimize government waste.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Artificial Intelligence can dazzle people to the point where they lose focus on the objectives of the federal agency.

In today’s interview, Adam Lurie from Knexus begins by discussing a corporate strategy that combines research and innovation with engineering. This approach has been consistent over decades of serving the federal government.

One stellar example of this fusion was their success in the $919 million 10-year Supply Chain Risk Illumination Professional Tools and Services (SCRIPTS) Blanket Purchase Agreement from the GSA.

One of the challenges in “applied” AI is the data itself. Often, particularly in the federal government, there are strict rules governing the handling of data. We have all heard about the encryption of data at rest and data in transit. Given this limitation, it may be challenging to establish an iterative process that optimizes security and reliability.

The answer from Knexus is to use synthetic data to emulate an actual sensitive federal data set. That way, several methods can be used to rapidly identify foreign influence, monitor vendor integrity, and visualize complex risk management scenarios.

This innovation enables developers to optimize the security of a supply chain, taking into account variations that incorporate modern technologies and adapt to emerging threats.

A key partner in this creative approach is Google. Knexus was recently named 2025’s Google Cloud Business Application Partner of the Year for Government.

Retaining security while innovating will be the key to applying AI to solve federal business needs now and in the future.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Fifteen years ago, Vivek Kundra began the “Cloud First” policy in the federal government. It took five years for people beginning to talk about “cloud native” applications. In other words, instead of a lift and shift to the cloud, developers could take advantage of the cloud’s capabilities resulting in increased agility, scalability, and resilience.

Well, here we are in 2025, and it sure looks like the early days of cloud computing. Lots of dazzling, but few people know how to leverage efficiency, speed, and personalization of AI.

Today, we sat down with Sri Iyer, CTO and Co-founder of a company called KOVR.AI. Finally, he presents to listeners how AI can be applied to the tedious process of federal certification.

We look at the complex process of CMMC. One aspect of CMMC is CUI. It does sound simple, but if a company over scopes or under scoped CUI it can make for difficulty in completing the certification.

Further, assets are changing all the time. How can a company provide a detailed report of its assets at a specific moment in time?

Next, the employees in a typical federal contractor are billing 40 hours a week. Is a business owner supposed to pull people off a revenue-generating position to complete CMMC tasks?

Finally, what about the companies who supply the DIB? In a normal supply chain, more than just the company seeking CMMC is part of the puzzle.

Listen to the interview to see how the innovation Sri Iyer can be applied to making the CMMC process faster and easier to document.

Iyer emphasizes the importance of proper documentation and training for CUI (Controlled Unclassified Information) and offers practical advice for companies to prepare for CMMC, including creating an inventory of IT systems and vendors, and seeking expert help.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Zebra Technologies is the best-kept secret in town.

The reason is simple: Zebra Technology has been in business for 55 years and has achieved an impressive amount of success in the commercial world. Jan states that 80% of Fortune 500 companies rely on Zebra for asset tracking.

Yet, if one were to walk through a federal technology trade show, one would never identify Zebra. In today’s interview, we focused on how Zebra Technologies has had a relentless focus on replacing pen-and-paper systems with modern technology.

One unexpected benefit of streamlining asset tracking is the reduction in time to prepare reports. Jan Ruderman states that audit preparation can be reduced from eight hours to twenty minutes.

Federal technology leaders are drowning in data, much of which is generated by devices such as Operational Technology under the control of Information Technology. Logistics management is the only way to get control of a rapidly changing system.

The real lesson is an application of commercial success to the needs of a federal government that is increasingly operating at the edge.

View Details

Seventy percent of the world's internet traffic goes through Ashburn, Virginia. That fact has led to the growth of over five hundred data centers in Northern Virginia. Today, we sat down with one of those companies to examine its data centers and its relationship with the federal government.

John Reynolds is the Director of QTS Federal. He has decades of experience in federal technology and provides the listener with an overview of QTS's origins, its values, and recent growth.

He views the data center business as a real estate endeavor. Land is acquired, a facility is constructed, and it has occupants. A company like Amazon Web Services have their dedicated data centers; QTS can house several different customers. We do not know the specific names; we can assume they are as large as Facebook and encompass federal agencies of all types.

Facebook may require one set of standards when it comes to security, and the NIST provides guidelines for federal data protection, which QTS includes as part of its compliance. The company participates in the community and understands the impact of energy requirements and cooling for local communities.

John Reynolds highlights the importance of resilience with multi-layered power redundancy and advanced energy contracts. QTS is also expanding into Europe and exploring alternative power sources due to grid limitations.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

There is a whirlwind of change in federal technology. For example, Federal News Network has reported that 25% of the IRS technology staff have left. Additionally, funding has been reduced, data stores are increasing, and we are all trying to understand the impact of Artificial Intelligence.

Today, we sat down with Phoebe Nerdahl and Sayed Said from SNYK. They offer solutions to address the challenges of changing technology in this environment.

The approach from SNYK is to start at the beginning of the code development process, what is called a shift left.

They discussed the need for a secure framework for AI adoption, leveraging Snyk's proprietary database and security research team to enhance code security.

The conversation also touches on the evolving definition of AI and its integration into various applications.

Snyk's AI Trust Platform aims to protect against insecure AI-generated code, emphasizing continuous security monitoring and automation. They have a vulnerability database, which enables them to review code for potential issues. Further, their platform can automate this needed remediation.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Gregory Garrett, Chief Operating Officer at REI Systems, discussed digital transformation and innovation at the AWS summit in Washington, DC. He has a fascinating background that includes a career as a fighter pilot, the publication of twenty-four books, and guest lecturing at Georgetown University.

The stated goal of today's administration is to reduce costs and eliminate waste. Today's aging systems are prime candidates for innovation. Unfortunately, there is no "innovation" button that a federal leader can press to have a variety of suggestions at their fingertips, allowing them to choose the best alternatives for improvement.

He has applied all this experience in dealing with talented software developers by organizing a competition for new ideas. It is REI's "REI Innovation Competition," which generated over 100 white papers and led to a proof of concept for government agencies.

From REI's perspective, digital modernization must address issues such as legacy systems, code revision, and improved code documentation. As a case in point, Gregory Garrett reviews the success REI has had in the federal grants management program.

During the interview, he delves into topics such as quantum computing and interoperability. Listen to the perspective of a digital leader who can extract innovation and leadership out of highly skilled software professionals.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Many of today’s archaic federal systems have been built over decades. As a result, they are perfected but also fragile. One obvious source of vulnerability is the workforce that created it.

It is hard to believe that COBOL was released in 1960 and is still active in some federal systems. The individuals who developed the code for these systems are now long past retirement age. Some code was accurately documented, and some were not. As a result, the process of transferring to a newer environment is fraught with concern.

Until AI, the only way to understand the underlying code was for a human being to review it line by line. Everyone realized that this process was so tedious and time-consuming that an informal policy emerged, essentially patching the system. They kicked the can down the road for the next generation.

Well, AI is her. It has the unique ability to review code, identify problems, and provide solutions quickly. This will drastically reduce the risk of moving antiquated systems from aging code systems.

Today, we sat down with Kartik Mecheri from Karsun Solutions and Alan Thomas, former Commissioner of GSA FAS. During the interview, they offered suggestions on how best to accomplish the challenging task of digital modernization.

Kartik emphasizes the value of a platform like ReDuX. Utilizing Amazon’s Bedrock, ReDuX allows system developers to create a blueprint for the existing system. When combined with humans, this platform will save money on maintaining older systems and bring much-needed flexibility to new applications.

Listen to learn how Karsun Solutions can reduce costs, increase flexibility, and improve efficiency in the process of digital modernization.

The conversation also touched on the challenges of mission-critical systems, the role of AI in reducing risk, and the evolving job market, suggesting a shift towards strategic and innovative roles.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

How do you defend your website against an attack that can reach one hundred million requests a second?

The federal government is in an unusual position: in addition to the "garden variety" attacks, such as phishing and ransomware, it is also subject to political attacks with a specific agenda. Ostensibly, they do not have financial motivation; their motivation is a political statement.

Welcome to hacktivism.

The tool they use is a tried-and-true, good, old-fashioned Distributed Denial of Service (DDoS) attack. If you consult your history books and shake off the dust, you will find that the first DDoS attack was recognized in 1996.

Advances in cloud computing and AI have been a force multiplier for malicious actors to shut down websites. In the past, the attacker would remain anonymous; not today. Today's hacktivist often claims responsibility for the attack and publicize their demands.

It has gotten to the point where DDoS attacks are available to consumers as DDoS-as-a-service.

Pascal Geenes has authored an article about a particularly nasty DDoS attack, appropriately called "DieNet." It attempts to instill doubt and chaos in a federal site.

What is the defense? Pascal Geenes has identified vulnerabilities in APIs as a key attack vector. Many federal agencies are not aware of their API inventory. It is possible to scan a federal site, identify a flaw in an unused API, and leverage that knowledge to launch a DDoS attack.

Radware's solutions, including AI-driven security, help mitigate these attacks quickly, reducing the mean time to resolution (MTTR). Heenan emphasizes the importance of being initiative-taking in cybersecurity.

= = =

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Sometimes, one plus one is three.

Back in 2021, McAfee’s Enterprise business merged with FireEye to form Trellix. Today, the net result is a company that generates $1.2 billion globally and $400 million in the public sector.

In today’s interview, Ken Karsten details how federal leaders can use Trellix to improve cybersecurity in a federal world with rapidly increasing end points.

Setting the stage, Ken Karsten reviews an Executive Order 14028 from 2021 that encouraged federal agencies to aggressively protect endpoints, sometimes called Endpoint Detection and Response.

In four short years, AI has transformed the way malicious actors attack end points and the defense had to be improved. Enter, Extended Detection and response.

During the interview, Ken Karsten gives listeners an overview of XDR’s continuous monitoring, advanced analytics, and rapid threat assessment and response capabilities. Advances in AI have allowed Trellix to deliver EDR and XDR capabilities at a drastically reduced cost.

Topics in the discussion include Operational Technology, 5G, and Trellix’s recent DoD IL5 authorization.

Provide a link to download the Trellix Cyber Threat Report.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

If you are a regular listener, you know that I interview tech companies to have them elucidate the ways they can help federal agencies reach goals.

Today, I will pull back the curtain and sit down with an HR professional from a successful company to understand his business and how he is hiring technical staff.

First, Kentro has been in business for over twenty years and has a formidable reputation for ethical and responsible assistance in federal projects.

Jun Choi is the Senior Vice President of Human Capital Services at Kentro. His company focuses on digital modernization, cybersecurity, and data and AI services.

During the interview, Jun Choi highlights the importance of a growth mindset, adaptability, and practical experience over formal education. The focus is on growth because nobody has a crystal ball to divine what will happen in the next five years. If the past is prologue, Kentro will expand, but where?

Procurement methods are rapidly changing along with technology itself. Many of the skills needed today were not taught in universities in the past. As a result, Jun Choi likes to discover whether a candidate has been in situations where a flexible mindset has been the key to success.

He has seen college graduates with simply basic skills. Unfortunately, today’s AI can do all the basics easily. Humans need critical thinking when they understand the implications of a large language model.

Choi remains optimistic about the future, predicting stabilization and innovation driven by AI.

View Details

In this episode of the Federal Tech Podcast, host John Gilroy sits down with Vishwas Lele, CEO and co-founder of pWin.ai, and Larry Katzman, President and CEO of Applied Information Sciences (AIS), to explore how technology leaders can write smarter proposals in an increasingly complex federal landscape. The conversation dives into the current state of the government contracting industry, including how shifting policy initiatives are shaping new opportunities—and new challenges—for contractors.

Larry shares firsthand insights on how AIS is adapting to these changes, the role of pWin.ai RFP tool in improving proposal efficiency and win rates, and what lessons they've learned along the way.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Years ago, the headline “Data Breach” was shocking; today, it is common. That may not be a problem for some, but the federal government maintains data stores that contain information about finances, health, and military matters.

A recent report has shown that 50% of federal agencies have reported data breaches. It appears that it's time to find a solution.

Today, we sat down with Blain Canavan from Thales Group to examine the usual suspects and the potential threats ahead.

THE USUAL SUSPECTS:

MFA: Protecting data can be accomplished with something as basic as phishing-resistant Multi-Factor Authentication. The first step in identity management can significantly reduce threats.

Encryption: Deploying encryption can protect data at rest, in transit, and memory.

Keys to the Kingdom: Little-known methods of managing the PKI system can help reduce risk in protecting data.

THEAT DOWN THE ROAD: QUANTUM

Now that you have checked the boxes for basic data protection, it is time to get a grasp on what lies ahead. We have read about quantum cryptography for twenty years. Today, we have pre-standardized quantum-resistant cryptographic algorithms available.

One needs to take action a little sooner. During the interview, Blair Canavan highlights the proactive measures taken by the US federal government, including the implementation of PQC-safe digital signatures by 2025.

The “down the road” also has a delimitation -- Blair emphasizes the urgency of replacing outdated cryptographic methods, such as RSA and ECC, by 2030 and 2035, respectively.

Include the 2024 data threat report.

= ==

View Details

Today, we have a pattern interrupt. Instead of a standard 25 minute interview, we will sit down with five nominees for a leadership award from Women in Technology.

Each candidate sits for a "lightning" round of eight minutes where they answer three questions about leadership and give their reason for participating in Women In Technology.

In order to see who won, you will have to visit Women In Technology.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Everyone is trying to figure out how to apply AI to federal problems—essentially, building large language models and trying to wring value from them. Inevitably, many are jumping into creating LLMs from various data stores.

We are right at the point where consideration is given to managing enormous data sets in the federal government, emphasizing the need for operational efficiency and security.

The hard lesson learned is data in transit, which means expense.

Today, we will sit down with Dr. Ellison Anne Willimas to explore the potential of privacy-enhancing technologies to enable secure and efficient data use across classification boundaries and data silos.

Dr. Ellison Anne Williams suggests a solution called Privacy Enhancing Technology (PET). It is applied to data as it sits in a silo, a data lake, or whatever nomenclature is used to describe large data sets these days.

PETs allow the secure and private use of data across boundaries and classifications. She explains how PETs enable AI and machine learning models to be trained and used without compromising sensitive data.

The conversation also touches on the cost savings from avoiding data replication and the potential for significant operational efficiencies.

Explore the potential of privacy-enhancing technologies to enable secure and efficient data use across classification boundaries and data silos.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Automation is a two-edged sword. On the one hand, it promises greater efficiency; on the other hand, it can pose inherent risks, such as maliciously modified data, bias, and even data poisoning.

During today’s interview, Mia Jordan from Salesforce offers a solution. She is an experienced federal executive with a long-standing involvement in the federal technology community.

She has identified bottlenecks that can be solved with a structured approach that offers flexibility. Rather than grabbing any data set off the shelf, when the data has been curated, it can avoid many of the issues with creating specialized data sets.

Secondly, a company like Salesforce may have seen similar processes and have a store of code that can solve an agency’s problem. Re-purposing code that has worked before in a secure environment is a way to accelerate solving vexing federal issues.

The conversation also highlights the importance of collaboration and community within the federal government in enhancing efficiency and service delivery.

During the interview, Mia Jordan reviewed Agentforce and gave guidance on deploying a process called Role, Knowledge, Action, and Guardrails.

View Details

Here we are in the spring of 2025, and the headline news is that the federal government is removing tech staff; at the same time, reports are coming in of thousands of unfilled cybersecurity positions across the government.

Today, we sit down with a self-proclaimed “Cybersecurity Lifer” who will give the perspective of the SANS Institute on this dilemma.

John Pescatore has been involved in federal cybersecurity since 1978. When he examines our current situation, he gives his opinion on training, skill level, and legislation that is being considered to address many of these issues.

He mentions recent SANS studies that have suggested the issue is less about the number of openings than about finding individuals with a specific skill set required for a federal role.

He discusses the evolution of cybersecurity training from hands-on courses to community college programs and the importance of practical experience.

Pescatore also discusses AI's role in cybersecurity, noting its limitations and the need for domain expertise. He emphasizes the importance of rotating staff roles and providing continuous training to retain talent in federal agencies.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

GitLab has been around for ten years and has garnered a reputation for helping federal agencies ensure compliance with stringent government standards.

Today, we sat down with Joel Krooswick from GitLab to discuss some top-of-mind topics for the software development community: Agentic AI and the implications of applying AI to software development.

Joel Krooswick explains that Agentic AI acts as unit taskers, managing specific tasks exceptionally well, such as code creation and refactoring. He emphasizes the importance of contextual awareness and security protocols to prevent malicious attacks.

In a play of words, it was suggested that "artificial" Intelligence may be replaced by "augmented" Intelligence—GitLab's role in augmenting, not replacing, developers, and the need for real-time compliance checks.

They also touch on the cultural shift required to adapt to AI's advancements, ensuring human value remains central in the workforce.

Joel will speak at the Gartner Security & Risk Management and AWS Public Sector Summit in the Washington, DC, area on June 10-11.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Everyone who has listened to a podcast about technology has heard the phrase, “People, Process, Technology.” This is a model derived from a management consultant in the 1960’s. We have seen a lot of focus on technology, a smattering of attention given to people, almost no concern with the process itself.

Today’s interview with Aubrey Vaughn, Vice President of Strategy and Business Development at Celonis, to discuss process intelligence over artificial intelligence.

Instead of a technical description, Aubrey shares a story about saving $10 billion in improper payments and emphasizes the importance of understanding why processes fail. Aubrey explains that process intelligence is the backbone of business operations, simplifying and improving efficiency.

One approach to evaluating a process is to make a duplicate of it and analyze the processes apart from the operation. Some call this making “digital twins.” He highlights the role of digital twins in creating a complete blueprint of organizational processes.

During the interview, Aubery Vaughn provides information about the "Process Intelligence Day" event in September 2025 to the audience, including details on the location, agenda, and how to register. events in September will offer educational sessions and CPE credits on process intelligence.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

AFCEA’S TechNet Cyber conference held in Baltimore, Maryland was the perfect opportunity to sit down with Bryan Rosensteel, Head of Public Sector Marketing at Wiz.

Wiz is the “new kid on the block,” and it has had tremendous growth. During the interview, Bryan Rosensteel shows how agentless approaches can improve visibility and assist with compliance.

We all know how complexity has infiltrated federal technology. We have the usual suspect of Cloud Service Providers, hybrid clouds, private clouds, and, if that was not complicated enough, alt-clouds. As a result, it is almost impossible to get a “bird’s eye” visibility to provide cyber security.

Two main ways have been proposed to secure this much-desired system’s view.

Agent. One approach is to put a bit of code on each device, called an “agent” method. It is good for granular control, but can slow down a scan and must be maintained

Agentless. Bryan Rosensteel from Wiz describes something called a “agentless” method to gain visibility into complex systems. This method leverages infrastructure and protocols to accomplish the scanning objective much faster.

Bryan Rosensteel states that in a world of constant attacks, this faster method allows for rapid updates to threats.

Beyond better observation, an agentless method, like the one provided by Wiz, allows for compliance automation, continuous monitoring, and sets the groundwork for effective Zero Trust implementation.

View Details

AFCEA’S TechNet Cyber conference held in Baltimore, Maryland was the perfect opportunity to sit down with Greg Carl, Principal Technologist from Pure Storage.

Pure Storage is used by 175 federal agencies. Time to sit down from a subject matter expert and explain their value proposition.

Today’s federal government is attempting to accomplish digital modernization through a move to the cloud and, at the same time, reduce staff. To multiply the risk associated with this endeavor, we see an increase in cyber attacks on data at rest, in transit, and while in use.

Greg Carl drills down on how Pure Storage can help federal leaders in several areas, he begins with Retrieval Augmented Generation, RAG.

People have jumped into AI without knowing how to structure a large language model, the popular LLM. RAG focuses on text generation and tries to make sure the data collected is accurate, relevant, and contextually aware.

Pure Storage asks, if RAG protects the results of a query, what protects the “Retrieval” part of RAG. We know LLMs are being attacked every day. Malicious code could be placed in a LLM, and the RAG system might not know.

A decade ago, backups were child’s play. A server down the hall, a backup appliance. Today, one needs an agile cloud solution to perform continuous backups in a hybrid world. One way to gain resilience is to use immutable backups where the attacked system can be restored and not lose valuable time.

Speed and security handling important data activities can reduce costs for federal leaders by improving accuracy of LLMs and speed the time to recover after an attack.

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

When most of us hear the word “lifecycle,” we normally assume they are talking about the Software Development Lifecycle. Today, we are going to vary that concept and discuss the Contract Lifecycle and its management. It has been recognized as a part of systems management, so it has developed its own abbreviation: Contract Lifecycle Management, or CLM.

Our guest is Ryan Donley from Icertis. He highlights the shift from traditional methods like Excel spreadsheets to modern digital platforms.

Much like software, the CLM can be divided into pre-award, post-award, compliance, and closeout areas. Every agency oversees this sequence in a unique manner.

Ryan Donley points out that some organizations still use Excel spreadsheets for this task. He recommends that people realize that antiquated processes can limit your ability to have accurate information and can cause reporting to be delayed.

Further, when a system is automated, coordination between departments is accelerated, and issues like compliance can be acted upon quickly.

Icertis operates on a single-tenant GCC high cloud with Microsoft, ensuring security and compliance.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Brian Funk from Metaphase summarizes his company in one sentence, “It’s all about meeting – meeting the mission with the technology.” What makes his company unique is the focus on drawing down costs in an efficient way.

That is a great concept and has worked for Metaphase since its founding in 2013, but today we are uncertainly living in a world of policy. The question to ask, how does Metaphase operate in a world where the next six months are almost impossible to predict.

Brian Funk’s response is that they support over twenty agencies, it has given them a range of experience so they can select from a wide range of solutions. One example he gives includes a rapid response to a DHS RFI.

Instead of sketching a possible solution, Metaphase delivered a fully functional application. That in and of itself, is a demonstration of being able to rapidly adapt to unpredictable situations.

Funk also discusses the need for guardrails in AI usage and the potential for AI to enhance both efficiency and security in federal IT.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

The federal government is releasing so many RFIs and RFQs that it is increasingly challenging to select which ones to respond to.

For example, let us say you get 60 requests. You do not have an equal chance to win any of the sixty messages. Do you assign the same amount of time to each one? Do you review each and rank the chances of success? What about the time you used in the ranking process?

Remember, you could jeopardize your chances of winning if you do not respond promptly.

Deep Water Point & Associates offers one solution to this dilemma. During the interview, Brian Seagraves describes a system called “North Star” that leverages AI to look at an opportunity and give it a grade for your specific company. A ranking of 0—100 means you will not waste time or effort on a proposal that will go nowhere.

As a “proof of concept,” John Milward from Axxa painted a picture of a solution. In 2023, he was drowning in responding to opportunities. He started using the North Star system and has experienced drastic improvement.

Brian Seagraves reminds the audience that the federal government still awards contracts and sends out RFPs. During stressful times, it is always best to keep a cheerful outlook and increase the number of opportunities for your company.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Artificial Intelligence can be applied to code generation, predictive analytics, and what is called “generative” AI. " Generative means the AI can look at a library of information (Large Language Model) and create text or images that provide some value.

Because the results can be so dazzling, many forget to be concerned about some of the ways the starting point, the LLM, can be compromised.

Just because LLMs are relatively new does not mean they are not being attacked. Generative AI expands the federal government's attack surface. Malicious actors are trying to poison data, leak data, and even exfiltrate secure information.

Today, we sit down with Elad Schulman from Lasso Security to examine ways to ensure the origin of your AI is secure. He begins the interview by outlining the challenges federal agencies face in locking down LLMs.

For example, a Generative AI system can produce results, but you may not know their origin. It's like a black box that produces a list, but you have no idea where the list came from.

Elad Shulman suggests that observability should be a key element when using Generative AI. In more detail, Elad Shulman details observability from a week ago vs. observability in real-time.

What good is a security alert if a federal leader cannot react promptly?

Understanding the provenance of data and how Generative AI will be infused into future federal systems means you should realize LLM security practices.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

The federal government needs to share information on a wide variety of platforms and must provide methods to ensure this transmission is secure. Of course, the hard part is the “how” part of this data transfer.

Tim Fuhl from Owl Cyber Defense gives the listener an overview of how Owl Cyber Defense can help federal agencies share information securely.

To accomplish this task, he discusses two fundamental concepts: diodes and Cross Domain Solutions.

Diodes. This is a mysterious word that was liberated from electrical engineers. When designing a semiconductor, one may need to create a one-way path to prevent a signal from returning. The solution in electronic design is a “diode.”

Owl Cyber Defense took an electrical concept called a diode, which provided “one-way” data transfer. When they combined this one-way street with a data path, they developed a “data diode,” a device that limits data transfer to one direction, protecting the system from a reverse movement.

When it comes to securing federal systems, a “data” diode is a device that restricts data transfer one way, essentially creating a one-way street.

Cross Domain Solutions. One of the newest abbreviations in the world of security is Cross Domain Solution (CDS). The federal technical world is comprised of levels of protection. As a result, what is needed is a way for communication between varying security levels.

During the interview, Tim Fuhl defines both terms and gives examples of where this innovation can be applied to federal systems.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

In traditional commercial selling, a company seeks to understand its business problems and then presents a solution that would save time and money. Understanding federal requirements has a few more barriers than scheduling a meeting with the CIO.

The federal government has security requirements and considerations few commercial companies can even consider. There are no effortless ways to understand system requirements for a company trying to break into the federal marketplace.

This has been understood for decades. In fact, Ron Reagan decided to help small businesses understand their needs and provide some assistance.

The Small Business Innovation Research (SBIR) program was established in 1982. The concept was simple: an agency would post requirements and look for a small company to get a response. If the proposal was favorable, some steps allowed further development and funding.

During today’s interview, Tom Ruff updated us on the three phases of SBIR and provided specific examples of companies that have successfully navigated the process.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Most people are so overwhelmed with the dazzle of Artificial Intelligence that they dismiss the power of quantum computing.

Reality is the optimized solution for solving some federal problems involving artificial intelligence; other issues need to consider quantum.

Today, Murray Thom puts the ability of quantum computing in a better perspective. For example, when it comes to aerospace maintenance, there are so many variables that classical computing is challenged to provide an answer. We all know that a traditional computer would use bits (0s and 1s). Quantum allows an approach that is not as linear and can provide faster answers to many questions.

The crus of the interview was not a debate on the origins of quantum and Einstein’s remark about God not throwing dice. The debate is over—quantum work. Quantum computing can help the federal government find solutions to public sector challenges like optimizing public services, transportation networks, and defense.

The core of this interview is whether your federal agency is looking for a problem that is too expensive or too time-consuming to solve using classical computing. It is possible to use quantum innovation to solve the problem more economically.

Look at some success stories from D-Wave; they may provide an economic option for you.

Download the D-Wave e-book “Transforming the Public Sector: Quantum-Powered Optimization” on the Carahsoft website.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

It is a challenge for most technology companies to give a three-word summary of what they do, especially with the complexity implied with the phrase “entity resolution.” The CEO of Senzing, Jeff Jonas, gives a three-word summary of the complex issues they manage -- “bad guy hunting.”

OK, what does this mean to federal tech leaders?

Today, we sit down with Will Layton to learn how a topic like “entity resolution” can improve federal cybersecurity.

During the interview, he gives an overview of how federal systems have evolved over the years and the need to understand the implications of automation.

We know federal systems are, in general, moving to the cloud. This may be a private cloud, a public cloud, or even a hybrid cloud. Second, data ingestion has overwhelmed most agencies.

As a result, many large-scale organizations are implementing automated tools, some call “agents” to become more efficient.

Will Layton describes how humans need to be identified an automated tool, or entities, need to establish credentials as well.

When a malicious actor tries to present like an entity in a complex automated system, Senzing can identify it and save federal leaders from unwanted actio

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

For many, IDEMIA is a relatively unknown company that was recently awarded a 10-year Blanket Purchase Agreement from GSA. The focus is on next-generation identity proofing for login.gov.

At first glance, you might say “IDEMIA” is an overnight success. Upon further examination, you will discover that IDEMIA has served federal agencies for over 60 years.

During the interview, Donnie Scott gives listeners a complete rundown on the variations on identity, identity proofing, identity management, and identity access management.

He reinforces that rigorous identity-proofing can reduce waste, fraud, and abuse of federal systems.

This is becoming a more complex problem. For example, technology enthusiasts are experimenting with so-called “agents” to access data, assemble it, and then attempt to draw conclusions.

At each step along the way, there are gateways to verify the validity of the person (or non-human entity) requesting data.

This interview offers a great perspective from a well-respected company that provides identity proofing to the federal government.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Walking around the Salesforce World Tour DC can make you dizzy with use cases. Let’s step back and look at underlying principles.

To boil down the massive information overflow, we sat down with Nasi Jazayeri from Salesforce to focus on improving efficiency by taking advantage of Salesforce agents.

Automation. Federal employees will obviously be asked to do more with less. One way to accomplish this task is to structure a system where tedious decisions do not have to be made by humans. Tasks can be designed without human oversight to a specific level.

Workflows. Salesforce is increasingly becoming a hub for data amalgamation. Integrating API into workflow can improve how systems can manage various dependencies.

Compliance. This is one of Salesforce's superpowers. Everyone is trying to figure out where the best application of agents would be. Inevitably, mistakes will be made. Compliance is built into a system like Salesforce. You can evaluate several options without reinventing the wheel for each instance.

Salesforce has many use cases for agentic applications, such as citizen service automation, healthcare administration, and interagency collaboration. Sometimes, general value principles can reinforce decisions made regarding agents and Salesforce.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Federal leaders are walking a tightrope. They want to leverage the promise of AI; however, they are responsible for making federal data secure. Beyond that, these AI “experiments” should not negatively impact the larger systems and must have a detached view of practical applications.

During today’s conversation, Paul Tatum gives his view on accomplishing this balance.

He illustrates the idea of experimenting with AI through, of all things, avocados. For example, he acts as if he must document the process behind importing avocados. He shows how an AI agent can be used safely and provides practical information.

The key here is “safely.” People working on federal systems are jumping into AI agents without concern for compliance or security. They run into the phrase “unintended consequences” when they access data sloppily, which can lead to sensitive information leaks.

Rather than detailing potential abuse, Paul Tatum outlines the Salesforce approach. This allows experimentation with specific guidelines as well as for compliance and controls for autonomous agents.

This way, the data to be accessed will be cleaned and not subject to misinformation and duplication problems. Further, because you are acting in the functional equivalent of a “sandbox,” you can be assured that information assembled from AI experiments will be placed in areas where they are safe and secure.

Learn how to leverage AI, but learn in an environment where mistakes will not come back to haunt you.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Most people know Cloudflare from federal or commercial experience. They have been around since 2009, and some will estimate that around 20% of all websites use Cloudflare for web security services.

The listener's question is simple: can one apply this commercial success to improving federal network security?

During today’s interview, Anish Patel from Cloudflare answered that question by directing his comments to Zero Trust, User experience, and automation.

Zero Trust is a federal initiative that cuts across civilian and military agencies. Cloudflare can assist by providing access to applications and data by verifying every user and device before granting access.

Because of their commercial success, Cloudflare realizes that an end-user experience can impact security at many levels. Simplifying the remote user experience will bolster security for everyone.

With today’s massive data increase and constant attacks, users can get alert fatigue and not be as responsive to threats as in an earlier age. During the interview, Anish Patel details how automation from Cloudflare can reduce the amount of vigilance needed by end users to accomplish network security goals.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Once the transition to the cloud became dominant, the importance of identity was placed ahead of permission to access apps and data.

When data centers were down the hall, one could have physical access to a room and sign-on permission. The hybrid cloud, private clouds, and an interest in “alternative clouds” make identity the keystone of modern computing.

Companies like Okta, Ping, and SailPoint work with identity and access management but rely on services that can provide a federated identity service.

Today, we sit down with Dr. John Pritchard, the CEO of Radiant Logic, and learn that Radiant does not compete with these well-known vendors but provides the backbone for their service.

Dr. Pritchard uses an interesting phrase: “continuous identity hygiene.” This means that although a person’s biology will not change, he can compromise essential elements of his identity. This must be a continuous process.

This fact has been recognized by CISA and DoD’s 2027 Zero Trust Goals and can be identified as Identity Security Posture Management.

In this thorough discussion, Dr. Pritchard presents a 30-year framework for network identity and includes comments on a unified data layer, data staging, and how to select a reference architecture for using a federated identity service.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Many people deceive themselves when moving systems to the cloud, thinking the same precautions used for an on-premises system can be used in the cloud.

Neil Carpenter from Orca Security dispels that notion right out of the box. He details that when a system is moved to the cloud, it operates under a shared responsibility model. While the Cloud Service Provider may be able to serve a solid infrastructure, that does not mean the applications and data are protected as well.

Further, the popularity of virtual systems means that workloads can spin up and down rapidly. This means a one-time scan is just that: a photograph of a moment; only continuous monitoring can provide the reassurance that federal systems managers demand.

While we know that cloud systems can scale rapidly, many do not understand that scaling also widens the attack surface. Michael Hylton from Orca Security recommends investing in a system that can provide continuous scanning in a dynamic environment.

How is this accomplished? During the interview, Neil Carpenter defines agent vs. agent-less systems. When Orca Security established an agent-less system, it allows them to scan, speeding deployment and reducing the risk of coverage gaps.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Today, we sit down with Karthik Natarajan, Solutions Engineering Manager, U.S. Public Sector, for SNYK.

SNYK has garnered a formidable reputation in the commercial sector by helping to identify and fix vulnerabilities in code, open-source dependencies, and container images.

Karthik Natarajan acknowledges that no code can be 100% secure; however, one way to improve by a magnitude is to incorporate the “Shift Left” approach. This phrase has been around for twenty years but has recently gained momentum.

The concept of shift left moves testing and performance evaluation to an earlier part of the software development lifecycle. But SNYK goes further by applying AI to look at open-source dependencies.

When infrastructure transitions to “infrastructure as code,” vulnerabilities may be included. SNYK also looks for vulnerabilities in infrastructure code.

The interview ends with Karthik explaining that SNYK’s success is due to it being written for cloud applications- it is cloud native. Also, they judiciously use AI and rigorously check corrections to code that may introduce trouble.

View Details

The federal government is transforming from on-premises and private cloud systems to a hybrid cloud.

What most listeners do not realize is that the linchpin to this transition is the Application Program Interface (API). It has been hiding under the radar for so many years that malicious actors use this perspective to attack the API.

Info Security Magazine reports that 99% of organizations struggle with API security. Where to start? First, get an inventory of how many APIs you are dealing with.

Stephen Ringo emphasizes the need for discovery tools to identify rogue and shadow APIs, noting that passive discovery methods are preferred to avoid network disruptions.

He also points out that API security is often overlooked, even in cloud-native solutions, and that misuse, rather than malformation, is the primary threat. Ringo advocates initiative-taking measures to secure APIs and prevent data breaches.

  • Three main ways to protect APIs:
  • Educate and raise awareness about API security risks among federal CIOs and IT leaders.
  • Discover and inventory all APIs, including rogue or shadow APIs, within the organization.
  • Evaluate API security capabilities of cloud providers and ensure proper security controls are in place.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

We all know the quote from Peter Drucker, "If you can measure it, you can manage it." It's pretty easy to apply when throwing a javelin but difficult when measuring success in complex software development projects.

Today, we sat down with Jeff Gallimore, Chief Technology and Innovation Officer and founder of Excella. He brings with him decades of experience collaborating with teams on successful federal projects.

We start by noting the fallacy of using one metric to measure success. While completing the initiative on time might make an agency administrator happy, that will change rapidly if compliance is not achieved, and scaling will break the system into pieces.

Jeff has seen breakthroughs using a framework called DORA, DevOps Research and Assessment). The key metrics are deployment frequency, lead time for changes, change failure rate, and failed deployment recovery time.

These metrics, now part of Google, are research-based and predictive of IT and organizational outcomes.

They emphasize the importance of a holistic approach, avoiding single-metric focus, and the role of leadership and culture in fostering high-performing teams

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

The Partnership for Public Service recently conducted a poll, and just 23% of Americans believe federal services are easy to navigate.

Today, we will examine the importance of User Experience and how to overcome some of the challenges federal agencies face when attempting to improve.

Lisa Hoover is the Head of Experience and Design at Karsun Solutions. In that role, she has experienced all aspects of federal design. She begins by observing that customer challenges may be recognized but not remediated.

She argues that there are several reasons for this standstill. Many federal agencies are dealing with legacy systems, and attempts to improve the CX can have unintended consequences.

Further, qualitative improvement is difficult to determine in a world of bits and bytes. Sometimes, the ease of scaling data can make a system so complex that one does not know where to begin.

Lisa Hoover recommends looking at Karsun Solutions' ReDuxAI offer. It leverages AI to establish a “blueprint” to see how everything connects, making digital transformation possible.

Hoover also addresses the need for efficiency in federal IT, aiming to streamline processes and improve customer satisfaction. The conversation underscores the potential of AI to enhance federal service delivery.

https://karsun-llc.com/innovation-center/innovation-center-projects/go-redux-ai/

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Here we are at the beginning of 2025, and Bill Church, F5's CTO, discusses the company's role in helping federal agencies navigate the complexities of multi-cloud environments and cybersecurity threats.

F5's strength spans the application portfolio of enterprise organizations. This includes application security, enhancement, quick access, improved availability, and even making them secure. It doesn't end there; they also help with encryption and authentication.

Church emphasizes the importance of flexibility and consistency in managing diverse cloud environments.

He highlights the challenges of API discovery, noting that many organizations are unaware of the number of APIs in their systems. F5's tools, like the App Study Tool, help identify and manage these APIs.

Church also discusses using AI and machine learning in F5's solutions for enhanced security and data protection, including an AI gateway for large language models.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Matt Lembright, Global Lead of Censys Search, discusses the company's role in scanning the entire internet for threats, focusing on frequency, accuracy, and data richness.

Censys helps government agencies and private organizations manage their attack surfaces by identifying exposed devices and vulnerabilities.

The conversation highlights the challenges of securing operational technology (OT) and Internet of Things (IoT) devices, emphasizing the importance of understanding device protocols and maintaining up-to-date software.

Lembright stresses the need for community engagement, local government involvement, and effective communication to protect critical infrastructure.

He also mentions Censys' cybersecurity glossary as a resource for understanding key terms and concepts.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

There is an idiomatic expression, “You can’t see the forest for the trees.” Essentially, it means that some people are so focused on the details that they cannot see the bigger picture.

Today, Bob Ritchie, SAIC's Chief Technology Officer, takes a step back and examines the evolution of federal technology from a strategic perspective.

He argues that because digital transformation is so convoluted, leaders tend to focus on the details of a transition rather than the ultimate objective. He frames this analysis in terms of systems integration vs. mission integration.

He explains that while systems integration focuses on integrating technology for better outcomes, mission integration emphasizes achieving specific mission outcomes by iterative learning and adapting to technological changes.

Ritchie highlights the importance of aligning systems with mission goals and maintaining vigilance to ensure technology choices support these objectives.

He also discusses the need for a mature approach to technology adoption, including the strategic use of legacy systems like mainframes and the importance of a standard data layer to reduce complexity.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

In spy movies, the federal government has unlimited funds for intelligence. In fact, it is always at its fingertips, no matter where it is located. Would it be so?

In the real world, agencies have budgets that limit their ability to do everything from reducing fraud to ensuring the safety of a supply chain.

One way to leverage the funds allocated for this task is to use Open-Source Intelligence or OSINT.

During today’s interview, Jason English from Babel Street shares his thoughts on how OSINT should be a part of the matrix where federal agencies can get practical intelligence.

He starts by defining OSINT, which includes search engines, social media, public relations, news sources, web scraping, data analysis, and, yes, the dark web.

This information is freely available to everyone, which gives it distinctive advantages. First, classified information can be costly to obtain. Rather than limiting your information sources to one area, OSINT will provide a much wider range of sources quickly.

Further, transparency is becoming a more prominent theme in technology—by definition, one can review the origin of any piece of information to assure its veracity.

When it comes to collecting, analyzing, and disseminating information, OSINT provides benefits that answer many of today’s federal agency requirements.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Technology comes and goes; you can call it the cloud, zero trust, or even Artificial intelligence. In early 2025, we see stress that we have not seen before.

The GAO has issued a report examining the federal IT Acquisition process and concluding that it needs to strengthen oversight, implement a mature acquisition strategy, and have a capacity-capable system.

Today, we sat down with Reid Jackson from Unison to discuss how to make these key acquisitions. During the interview, he discussed Acquisition Management, Cost Engineering, Virtual Acquisition, and Project Management.

Unison has been involved in federal acquisition since 1984 and has a deep and thorough understanding of the procurement process. Reid Jackson relates that some newer organizations may have a superficial knowledge of regulations and may deploy software solutions that do not enable astute and effective decisions for federal agencies.

During the interview, Reid Jackson from Unison overviews many aspects of these challenges.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Bill Sullivan, an independent consultant with experience in federal technology, discusses the impact of the new administration's policies on federal projects. He advises federal employees to maintain professionalism despite the hiring freeze and emphasizes the importance of security standards, particularly in AI and data management.

Sullivan highlights the need for government to adapt its acquisition process to keep up with technological advancements. He also compares the current AI initiative to the Kennedy space mission, suggesting it could improve energy production. Sullivan emphasizes the importance of security, especially considering global competition, and praises Elon Musk's systematic approach to change.

Key takeaways:

Maintain a professional demeanor and continue working diligently despite the changes.

Monitor the developments around the $500 billion investment and its potential impact on energy and data center co-location.

Advocate for reforms to the federal acquisition process to enable faster adoption of modern technologies.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

A recent SAS report shows that 84% of government decision-makers plan to invest in Generative AI in the next fiscal year. During today’s interview, Reggie Townsend details some of the precautions federal leaders must take to leverage this innovative technology.

We begin the interview by mentioning that, in a governmental setting, technology cannot go beyond what is necessary to achieve a legitimate aim. Although that is a noble concept, it can be futile because we are in the incipient stage of this technology.

We do not have any laws about using AI; we have a patchwork of national and international regulations on the ethical application of AI.

We can start with the Executive Office of the President. In addition to other Executive Orders, President Biden released further guidelines his last week in office. While well-meaning, these guidelines are not practical when put into perspective of what is going on in other countries.

Reggie Townsend indicates that AI Safety Institutes can promote consistency and a proper ethical response to using data from citizens to feed AI.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Anyone with a pulse knows the new Trump administration has rescinded dozens of Executive Orders written by the previous president, Joe Biden. Executive orders #14110 and #14141, which dealt with artificial Intelligence, were part of this package.

This has put the federal technical community in a state of expectation. On the one hand, they are charged with reducing costs by leveraging technology; on the other hand, they have a hiring freeze, and nobody knows what the new AI mandates will consist of.

Today, we sat down with Jennifer Sample from EmpowerAI, a veteran of the tech wars, and asked her what direction developments in AI will take.

Jennifer Sample reminds listeners that the federal government must consider privacy restrictions when applying AI to solving federal problems. Unfortunately, our near-peer adversaries have no such constraints.

When the federal government attempts to apply AI, it does so inconsistently. The CIO Council may be able to list 1,700 federal use cases for AI, but the hard part is vetting the data sources and matching impact with agency goals.

During the interview, Jennifer Sample discusses concepts like being AI ready, continuous qualification, and contextual governance.

2025 will force the federal government to do more with less; AI is a tool that can help accomplish that noble goal.

If you want to hear a more in-depth discussion, she will speak at the Potomac Officers’ Club on March 12, 2025, in Tyson’s Corner, Virginia.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

A recent study showed that the federal government has identified 1700 use cases for Artificial Intelligence. Today, we examine some challenges and solutions for unlocking the power of AI represented in these examples.

Our guest, Joel Krooswyk from GitLab, examines Software Bills of Material, repatriation, and what efficiency might look like in the future.

SBOM. For years, software developers have recommended using a Software Bill of Material. Today, its value has become so apparent that it is becoming mandatory.

During the interview, Joel Krooswyk discusses the security benefits of mandating an SBOM policy for all federal software development.

Fifteen years ago, Vivek Kundra coined the phrase “Cloud First.” It took a while, but cloud adoption is pervasive by the federal government. However, with this adoption, we have seen examples where cloud service providers may over-promise and under delivery.

The interview provides guidelines for transitioning from the cloud back to the premises, which is increasingly called “repatriation.”

Software development in the future will make compliance partner with DevSecOps in an automated process. This will reduce maintenance costs and provide real-time reporting. Intelligent automation will be able to validate each step of the process.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

“Efficiency” seems like the new buzzword for federal technology in the next few years. When writing software sense, efficiency can mean writing code once and moving on to regular maintenance.

However, we see security initiatives being mandated that cause developers to go back to previous stable systems and add code alterations to comply with new cyber threats. Even beginner efficiency experts will tell you the time and cost of operating in this manner can be expensive.

Further, recording can add new bugs and risks, making the system more complex.

Federal technology leaders from CISA have not lost sight of this. They have a “Secure by Design” initiative that addresses this issue. As in many tech concerns, the concern is how to accomplish this noble task.

Today, we sit down with Nathan Jones from Sonar. He offers a solution that seeks to “shift left” the whole concept of security by design. His company provides systems that can review code to ensure its compliance. Further, he expands on an approach that can collaborate with developers while they write code.

Nathan Jones gives listeners details about how Sonar’s Qube can be deployed on a server, in the cloud, or with IDE.

The benefits are ample: lower maintenance, minimizing risk, and allowing a focus on innovation rather than rewriting code.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

People are getting comfortable with Generative AI and applying it to many business areas. This widespread adoption shows many of the weaknesses of individuals misusing technology.

It is one thing to settle a baseball statistics argument with GenAI; another complete application when competing for a million-dollar federal contract that includes management of sensitive information.

These include biased outputs, lack of creativity, and misinformation, to name a few.

Today, we offer a solution. Vishwas Lele is the co-founder and CEO of pWin.ai. He has decades of experience in federal contracts and a sophisticated understanding of applied Artificial Intelligence.

He has seen the reliance on cliches and superficial language that can result in the inappropriate application of AI for proposal writing.

His solution is to partner with Shipley Associates, a proposal writing company that has been in business for fifty years and has technology that can safely use AI.

The result: pWin.ai. If you would like a more detailed explanation, consider attending a webinar on January 22, 2025

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Everyone reading this knows that April 15 is the dreaded day that one must pay federal income taxes. Big business has hordes of tax accountants and lawyers who do tax planning to accommodate federal deadlines.

Sometimes, the deadline could be better known. Are you familiar with the OMB’s M-24-15? This will require companies to submit compliance information in a machine-readable format.

Today, we sat down with Valinder Mangat from DRTConfidence. Valinder describes technology, deadlines, and approaches your company can use to comply.

This interview will serve as a warning about an immense deadline that is crucial if you work with the federal government and cloud service providers.

Essentially, NIST recognized that compliance done manually was time-consuming and subject to error. Back in 2016, they suggested OSCAL to streamline compliance. In addition to speeding things up, OSCAL allows for reuse without repetitive assessments.

Whether you realize it or not, by the end of 2025, each federal contractor will be expected to provide compliance information in the OSCAL format, which stands for Open Security Controls Assessment Language.

The other side of the coin is important to discuss as well. If you are an agency dealing with cloud compliance, you will be expected to be able to ingest compliance data in the OSCAL format.

View Details

Ep 206 Federal Data, Fast Access, Security

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

When it comes to technology, the founders of VAST Data can be described as “prescient.” In 2015, they looked at the problem of data management from a unique perspective.

They did not want to call their company VAST “storage” but VAST “Data” because the problem they tried to solve was not the amount of storage but how to get instant and fast access to that data.

The wave they rode was a combination of nVidia investing in graphic processing units and flash storage becoming more affordable. The result: VAST Data has grown to be valued at over nine billion dollars.

During the interview, Randy Hayes details the value proposition of this innovation for federal projects. Their first customer was NIH, and they have built on that reputation ever since.

Randy Hayes mentions that the current Zero Trust initiative begins with identification. Rapid, accurate authentication rests on fast access to data.

Further, we have seen a resurgence in many organizations' migration from the cloud to on-prem solutions, mostly due to rising cloud costs and data sovereignty issues. VAST Data can provide efficient and quick ways to manage this data transfer.

Innovation, dropping chip set prices, and understanding federal problems all allow VAST Data to assist federal agencies in accomplishing ambitious goals.

If you want to learn more, VAST Data will attend the Nvidia GTC conference on March 17th in San Jose, California.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Complex environments exist in commercial organizations and the federal government. In a typical fashion, humans resist change until an incident force restructuring. In this case, the change of design will be costly.

During today’s interview, Nick Pesce says that today’s systems are burdened to such an extent that structural change should start now, when it is easy and less expensive, and then wait for an incident that will cause change.

Both guests, Nick Pesce and Don Lamb, have experience in federal government change management. They work for the well-respected MITRE, home of the ATT&CK framework.

As a result, they can look at a systemic problem and see the solution.

Their report, Recommendations for Creating Cross-Agency Enterprise Design Specifications, details ways to make this change. They also detail user stories and use cases and how to manage requirements and proofs of concept.

Their argument goes that when combined with understanding mission objectives, the existing information silos in the federal government can be overcome.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Cybersecurity professionals like to talk about data “at rest” and data “in transit.” They never mention how exactly this concept of “in transit” takes place.

Once upon a time, in a data center far, far away, one could take a database and move it easily. Kind of like taking a suitcase in your car and driving across town.

Today, federal agencies are deluged with so much data, is it more like dragging your entire house across town?

Moving data today involves concepts like data tiring. This is an approach where data is taken to a third place and transferred from there. Due to limitations of latency, network bandwidth, and compliance concerns, this is a process that can take way more time than can be imagined. You may have some highly compensated data scientists waiting days for a complete transfer.

Let us take another scenario. What if your agency has some data stored in a specific cloud provider? It may be discovered that charges were higher than expected and the data need to be returned to the on prem environment. If not done properly, this transition can be fraught with issues.

Further, many federal agencies are sitting a veritable treasure trove of data, both structured and unstructured. These could be images, text, email, or video. Pure Storage offers ways to derive value from a wide variety of unstructured data. structured and unstructured data. These could be images, text, email, or video. Pure Storage offers ways to derive value from various unstructured data.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

We all know that in 1492, Columbus sailed the ocean blue. A couple of years later, a map maker named Americo Vespucci made quite a splash with a new map. This has a direct parallel with today’s information technology.

Columbus really did not “discover” anything—it was there all along. When you look at an enterprise system, be it a bank in Houston or a federal agency, you may have only a hint of what is on your network.

Who knows what kind of “ghost IT” has been added to your system? It could be a deliberate attempt by an employee to circumvent the compliance process; it could be a malicious actor who has entered your system.

Today, we sit down with Tom Guarente from Armis, the “Asset Intelligence Company.” Armis can take a detailed look at your network and provide you with actionable information. On-premises networks, endpoints, data centers, cloud, and hybrid cloud = a wide range of potential presences on your network.

During the interview, Tom Guarente emphasized the importance of putting this information in proper perspective. When an asset is identified, its relationship to other assets and its context is just about as important as the ability to detect it at all.

Armis can assist federal agencies with understanding relationships and vulnerabilities they did not even know they had.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

We have all heard that the phones we carry around have more computing power than was used in the Apollo moon mission. Breaking news: these powerful devices in our pockets are vulnerable to attacks of which we cannot dream.

We can just pick up our phones and read the headlines. Brian Krebs reports federal charges against SMS attacks, Salt Typhoon getting into our phone systems, even the FBI telling us to use encryption on our phones.

Today, we sat down with Jim Coyle from Lookout to unpack the concept of mobile threats. He begins with some startling facts. For example, Jim Coyle states that over half the movable devices in a recent study did not have an up-to-date operating system.

One simple proof-of-concept is with a malicious URL. On a desktop, one can hoover over a URL to see where it is taking you; a credible URL will be clicked on a phone device with no questions asked.

There are other entries as well. For example, what happens when a company with a legitimate app gets bought out by a malicious actor? It is possible for them to have an open door to your phone.

The good news – a lot of mobile malwares will not survive a reboot. The lesson: every night plug in your phone, turn it off and on.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Malicious actors are taking advantage of AI and the federal government. As a result, we are in a strange Wack-a-Mole game in which applying AI for defense has become so complex that each application seems to require specific skill sets.

Today, we sit down with two leaders of NRLabs to discuss their unique approach to applied AI.

NRLabs leverages the founders' diverse aerospace engineering and cybersecurity backgrounds to provide innovative solutions, including penetration testing and red team activities.

Individuals can become limited in understanding these nuances. As a result, NRLabs has formed a method called the Cyber Collab, where they meet regularly to offer individual perspectives and applications.

Because of this, they continue research and testing on using localized adversarial AI models to identify vulnerabilities in cloud-based AI platforms.

During the interview, Jon David details exploring opportunities to partner with organizations like CISA's Joint Cyber Defense Collaborative (JCDC) to enhance collaboration and information sharing on critical infrastructure security.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

In Frank Herbert’s classic Dune, Paul Atreides's martial arts instructor discusses knife fighting and a “feint within a feint.” Today, we apply for this martial art tactic in federal information technology.

Malicious actors are flooding networks with false attacks, which are, in essence, feints with knives. Digital technology can multiply this activity, or noise, to such an extent that the real attack may be missed.

The question is: How can we differentiate between the noise and the actual attack?

Today, we have Chris Howard and Zach Vaugh, two experts from Vectra AI. They explain Vectra AI's approach to understanding threat attack intelligence.

For the past fourteen years, Vectra AI has focused on this noise-to-signal ratio, garnering some thirty-five patents in this endeavor.

They understand the nuances of code morphing, lateral movement, and something curiously called “living off the land.” As a result, they alert a manager to suspicious activity; leaders can be assured they are not dealing with a false alarm.

This innovation is important today because Zero Trust is being implemented today. The concept is to allow the right person to have the right data at the right time. How do you know the data has not been injected with malicious code?

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

In 1967 the movie Cool Hand Luke gave us this famous quote, “what we have here is a failure to communicate.” Surprisingly, this adage may apply to federal technology as well.

If a federal leader allows secure information to be communicated, they can get fired. If they do not allow enough access to appropriate information, decisions can go sideways.

The federal government is being bombarded with data, some important, some trivial. The challenge is to get life-and-death information into the hands of decision makers. So, we have massive data stores and some of them reside in the intelligence community.

During the interview, Dr. Williams offers an innovation that allows users to access multiple sources as if it were a single database. Further, the data can be protected to allow the correct users the specific amount of data permitted.

The beneficiary of this method of protecting data at rest is Artificial Intelligence. The data that if fed into AI model can be leveraged and protected at the same time.

View Details

While everybody is focusing on Artificial Intelligence, malicious actors are going after the soft underbelly of modern technology: operational technology, or OT. Today, we take a look at the increasing threat of cyber-attacks on operational technology (OT) systems, which are often not built with security in mind.

Operational Technology is represented by control systems, logic controllers, and other end points found in critical infrastructure like water and systems that generate energy, like oil, natural gas and even nuclear. Today’s experts share ideas on how to mitigate risk through.

Collaboration: Throughout the federal government communities are being formed that seek to share information on OT threats. For example, CISA has a Joint Cyber Defense Collaborative that serves as a clearing house for communication between industry and the federal government.

Continuous monitoring: Marty Edwards works on several federal committees to try to establish data formats that would allow for interoperability to monitor attacks and update existing operational technology.

Proactive measures: Jonathan Feibus from the NRC shares that 90% of the systems he monitors are focused on Information Technology. Vendors seeking solutions to this problem should look at extending methodologies built for IT into the realm of OT.

The discussion ended with a discussion of the integration of IT and OT security, the role of AI in enhancing security, and the need for comprehensive asset inventories and risk assessments.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Using a phone to read or communicate has become so standard that church people are expected to read scripture with their phones. Using mobile devices to transmit secure information.

Traditionally, secure communication was based on desktop systems; today, we need to pivot and learn how to apply mobile device management to leverage the cloud to provide safe and secure communications through mobile devices.

Our guest today, Harold Smith, has spent the last twenty years gaining a deep understanding of secure communications and applying that understanding to developing a trusted mobile development platform.

During the interview, you will be bombarded with acronyms like NIAC (National Information Assurance Partnership), MATTER (Mobile Apps to the Tactical Edge Ready), and many more.

As a bonus, Harold provides a brilliant sidebar on another acronym: SBIR (Small Business Innovation Research). If you are trying to break into the federal market, this precis is just what you need.

The takeaway is that Monkton provides a platform for developers to deliver safe and secure code to people in our mobile world. This can mean a warfighter, a clinician, or even an emergency responder from FEMA.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

When Qlik was founded in 1993, hard drives were measured in megabytes, and the Internet was primarily text-based. If lucky, you could get information in structured columns and formats.

Fast forward thirty years, and some estimate YouTube alone has 4.3 petabytes of data loaded every day.

The federal government certainly has its share of formatted data. A recent survey showed that 80% of data collected by the federal government is unstructured. This is information like text files, videos, or emails that are stored in many formats. As a result, it isn't easy to store and manage.

This has a real impact when an organization tries to take advantage of Artificial Intelligence.

Today, we sit down with Andrew Churchill to discuss creating a solid data foundation for AI. We detail topics like data movement, data streaming, and data quality during the discussion.

He differentiates between data lakes and data warehouses as strategies for handling all the unstructured data used for training AI models.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

With public speaking, everyone has butterflies before they begin; instructors tell speakers to get them to fly in formation.

When it comes to tools for cybersecurity, we have a similar situation – you may have End point Detection and Response, Extended Detection and Response, Managed Detection and Response, DR, XDR, MDR, Security Information and Event Management, and many others.

ThreatQuotient was founded with the intention of making sure these disparate tools provide actionable information for federal agencies.

During today’s interview with Craig Mueller, he takes us through context, customization, and collaboration that is needed in all federal agencies. The net result is the reduction in false positives and automation of the intelligence lifecycle.

Criag Mueller brings up a topic that is rarely covered—air gapped systems. Because of their deep understanding of the intelligence community, ThreatQuotient can provide services to agencies that use air-gapped networks.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Ep 196 How to take a Federal Network Above and Beyond

Today, we see our network being pushed and pulled in every direction: remote users demand access, millions of endpoints must be managed, and wireless networks abound. The Internet we use every day was designed for a much more humble requirement: essentially, bursts of communication between small entities.

Our interview with Dan DeBacker from Extreme Networks will define these new requirements and how innovation can keep you up to speed.

One of the best podcasts in Washington, DC, is “Feds at the Edge.” It recognizes the rapid decentralization of systems, which has reached the point where some organizations are considering doing the “compute” aspect of the network at the edge.

Let me state the obvious: a network that is not optimized will not allow speed to be efficiently achieved.

Hybrid networks can increase complexity to the point where speed degenerates and opportunities for malicious actors can appear.

During the interview, Dan DeBacker details how methods and techniques can be applied to carefully examine a network and ferret out stealth networks and areas that can “leak” access.

When a system is visible, it is easier to incorporate legacy networks and enhance connectivity between sites.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Federal technology leaders operate in a confusing world. On the one hand, they must grant access to data that is needed by users; on the other hand, they must comply with security requirements that severely restrict that access.

Craig Mueller from Varonis offers a solution: efficient data management will ensure that all information will be carefully categorized to allow this razor’s edge of operation. The approach will allow for a concept called “complete coverage.”

“Complete coverage extends to everything in the hybrid cloud as well as legacy systems.

During the interview, Craig Mueller describes a concept called Data Security Posture Management. Essentially, this process allows for complete coverage, governance, and user analytics.

Many do not realize that AI tools crawl a network and assemble as much as they can. In a federal application, there may be information that is not categorized correctly and should not be allowed to be scanned.

This is a classic example of data that gives the ability to share too easily.

Proper organization of data, both structured and unstructured, will all the balancing game of access and security to be deployed and scaled.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Our guest today is Jonathan Alboum, the Federal CTO for ServiceNow Federal. This interview should begin like Mission Impossible movies.

“Jonathan, your mission, should you accept it, is to describe all the variations ServiceNow serves federal technology leaders. You have 25 minutes. This message will self-destruct in ten seconds.”

This is an “impossible mission” because Service Now has customers in over one hundred agencies. It sure appears each instance is unique. One way to understand this “variation on a theme” is to look at the agenda for their annual conference.

In March 2024, ServiceNow covered topics ranging from agile software development to forms to new vs. legacy applications. It is kind of hard to find a Gartner quadrant for ServiceNow.

During the interview, Jonathan delves into one aspect of artificial intelligence and details the application of large language models and smaller large language models.

Listen to the interview and consider it a “tasting menu” for efficiency, productivity, and integration concepts. Oh yes, it also dives into applied Artificial Intelligence.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Everyone awake in biology class remembers the difference between a somatic and an autonomic nervous system. (Cheat sheet: You can control somatic, but the other kicks in without knowing.)

What does this have to do with federal information technology?

Today, we sat down with Dave Link, the founder of Science Logic, and he talked about how to manage complex federal systems. We all know in the early days, one could use a spreadsheet to update and patch most networks.

However, today’s hybrid networks and supercharged cyber-attacks are throwing manual methods out the window. Dave Link suggests an automated approach that parallels human biology can be the answer.

For example, he calls his system an “autonomic IT.” A quick translation means that an agent can run in the background and examine the health of a network. It can evaluate and patch automatically, like the system that controls your heartbeat and respiration.

When there is an issue, a sentient human can jump in. This may be like a human being moving out of the way of an oncoming bus. This person has an operating cardiovascular system; however, a human must alter survival.

Listen to the interview to see how this human/technology parallel holds up.

View Details

Ep 192 Forensic Analysis and Digital Footprint

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Cellebrite is a company that earned its stripes in the commercial world with its ability to find a needle in a haystack.

In other words, they have developed an ability to sift through mountains of data, find the essential parts of an investigation, and leverage that information to close a case.

In other words, anyone can find the proverbial needle; who can find the right needle that will solve the puzzle and bring the case to closure? The federal government is plagued with fraud and abuse from very sophisticated malicious actors. These actors are adept at creating false identities and covering their tracks.

The GAO estimates that in 2023, Fraudnet reported 4,400 allegations in fiscal year 2023. Further, the Department of Justice reports $2 billion in illicit activity. It takes talent mastered in the commercial world to close federal cases.

During the interview, Maurice Cook provides examples of the restricted federal environment in which Cellebrite must operate. They must be transparent and ethical on all levels.

Fortunately, Cellebrite has managed to transfer that commercial skill set to the federal government under the guise of a digital investigative platform.

Listen to gain a better understanding of forensic analysis and digital footprints.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Google's public sector has exploded into the federal technology marketplace. Today, we recapitulated the recent Google Public Sector event and tried to understand the reasons for the success.

Our guest is Troy Bertram, Executive Managing Director of Google's public Sector Partner Ecosystem. Together, we review the keynote presentations, essential concepts, and the value Google can bring to rapid innovation in the federal government.

The event kicked off with Karen Dahut, CEO of Google Public Sector, emphasizing the value of making systems foundationally secure. Apparently, this message resonates with the tech audience.

Although Google Public Sector has only been around for two years, it saw 1,000+ people attend, including 24 federal leaders and attendees from over ten countries. Apparently, operational resilience is an international concept.

We also heard some entertaining concepts. Leigh Palmer talked about AI as “always confident, not always correct.” She and her panel focused on the importance of having valid data before the discussion of artificial intelligence begins.

Forrester has some predictions about the public sector that apply to federal cloud usage. They say that “public sectors should become more adaptive to build resilience and fuel innovation.

Troy Bertram focuses on the DoD's efforts to leverage many of the concepts detailed at this conference.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Humans can be easily deceived. You look at an iceberg and think that is all you have; the same approach can be applied to federal websites. At first glance, you notice the visual and do not understand how the website may be providing valid information or if this can be done in a timely manner.

Those aspects of web design are essential and can be measured easily with well-known tools like heat maps, Google Analytics, and user surveys.

Today, we go below the surface of the iceberg. Lee Becker from Medallia helps listeners expand the user interface concept to include the outside and the inside.

For example, a superficial understanding of the user interface would serve a citizen in a form. This is one way to interpret Executive Order 14058, “Transforming Federal Customer Experience and Service Delivery to Rebuild Trust in Government. “

However, when you dig deeper, you will understand that in 2022, 190 million hours were spent on forms at the Department of Homeland Security.

Lee Becker shares his experience and shows listeners how to go beyond the screen, dig deeper with the user interface, and improve larger goals like collaboration, security, and transparency. Ep. 190 User Experience: the plow must go deeper.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Robb Wong helps clients at Deep Water Point & Associates better understand the U.S. Small Business Administration. They recently announced that Fiscal Year 2023 had a record-high 28.4 % of federal contracts to small businesses.

Robb is in the perfect position to help. He has started several small businesses and was appointed associate administrator at the Office of Government Contracting & Business Development in the U.S. Small Business Administration.

This experience makes him the perfect person to help listeners understand existing rules and proposed rules to help them develop the federal technology business.

Here are four highlights of the conversation:

He emphasized the importance of adapting to proposed SBA rule changes, which could alter small business strategies for 2025. Wong advocated for increasing the 8(a) sole source limit to $8-10 million and suggested gradual transitions for mentor-protege joint ventures to maintain small business participation.

He also called for government support to cover the prohibitive costs of CMMC certification.

Encourage clients and the industry to participate in the rulemaking process and provide comments on the proposed changes.

Prepare small businesses for the changes to the mentor-protege program, which are expected to be implemented in early 2023.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

The federal government is the largest employer in the United States, employing approximately three million people. It buys everything from rubber bands to rockets. In the area of technology, it buys everything from toner for a copier to communications to a satellite.

How can a small company sell to this monolith? Some will argue that the best approach is to develop a relationship with a successful company to understand the dynamics of federal technology acquisition.

Connect with Slalom at the ACT-IAC conference in Hershey, PA on October 27, 2024

Today, we sit down with Jim Igoe, Slalom's Director of Public Sector Partnerships. He describes why Slalom has successfully partnered with over seven hundred companies.

He mentions several concepts.

focus on change that matters. In other words, federal employees can notice a discernable change when an engagement is complete.

Develop a thorough and complete understanding of the project before commencing.

Listen to the interview to better understand how to enter a complicated market and identify, foster, and build relationships with strategic partners.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Joel Krooswik from Gitlab has seen more code reviews than he can count. He has seen duplicate code, insufficient data, and insecure code. "Work harder" may be the maxim in the NFL, but this is a fool's errand regarding software development.

Traditionally, a code review would yield remediation that would take hours and detailed work. During the interview today, Joel looks at how Artificial Intelligence can be applied to four areas:

  • Clean code. A system may work now despite problems. However, it can fail once it is stress-assessed with mountains of data. Clean code means it is easier to scale.
  • Speed. Humans may not be able to see system inadequacies that slow it down. AI can see log jams that a human cannot.
  • Duplicate code. Various individuals have maintained older systems so that code may have been duplicated. Duplicate code is complex for humans to find but easy for AI.
  • New features. Application "A" may run on a system with no problems; when updated, it may highlight issues you do not know exist. AI can look at code and allow for more accessible features.

During the interview, Joel focuses on how these abilities can be applied to the federal environment.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Last year, we were all dazzled by Artificial Intelligence vacuuming up words to spit out text, collecting code, and generating code.

Well, it's time to see if those parlor tricks can be applied to federal work.

Bob Ritchie is a self-proclaimed "code warrior" with years of experience evaluating federal software projects. He mentions three areas where AI can help federal projects.

It's tedious work to review code and try to make improvements. Software developers' analytical abilities can be better utilized by having the code highlighted and remediating the problem.

Security. A famous phrase in software development is "shift left." Problems arise when security mandates are applied to existing codes. If you assume a timeline in software creation, a shift to the left means putting the correct code before release.

AI can help developers look at previous code iterations and quickly make security changes before release.

Humans. Bob Ritchie has seen the power of AI and has also seen analysts not using correct prompts to take advantage of that power. His solution is to create a variation on the popular Hack-a-thon: a "prompt-a-thon."

In other words, you need to get a group of people together and help them understand the proper way to word a prompt to get the results you need.

This is a fascinating interview with a well-known expert who provides an excellent summary of current policy trends and the impact of AI on government modernization efforts.

View Details

John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

When it comes to preparing for a hurricane, the federal government has FEMA, NOAA, and a wide range of recovery options. However, we all know quantum is coming down the road, and many are not prepared for what will come. And it will come. We do not know when.

Serious scholars have posited that future quantum computers will be able to break our current encryption.

What is quantum encryption? You can go to YouTube and be impressed with the advanced mathematics involved in quantum. The basic idea is that someday in the future, specialized computers will be able to crack today’s encryption.

During the interview, experts from Tyto Athene discuss prevention and elaborate on a concept called Post Quantum Encryption.

Some parts of the federal government take this concept seriously. NIST has considered some options and is offering some tests. Richard Wheeler gives a detailed description of the NIST initiatives.

One may ask, why worry now? This is because nation-states are vacuuming up and storing data. As for now, they cannot decrypt it. However, they may be able to in the future. Personal information and federal secrets will have value somewhere down the road.

View Details

John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

If you read federal mandates, “continuous monitoring” is becoming popular. If you type the phrase into Google Trends, you will see a drastic rise in the past five years.

However, very few people can detail ways to implement this noble policy.

Today, we sit down with Branden Wood from Tetrate to explore an option that can assist federal leaders in taking a strong step toward the elusive goal of Zero Trust and continuous monitoring.

The answer involves understanding something called the service mesh. This is a concept of a service layer whose entire purpose is to monitor communication between services in an application. Many benefits accrue from using this sophisticated form of communication.

For example, one can execute load balancing, encrypt data, and discover other running services. The discovery process may have the most impact on cybersecurity.

In today’s complicated software development world, automated processes may generate unexpected activity. Even an experienced software developer may not be able to recognize the impact of the code he has released.

Service mesh architecture begins with providing observability, reliability, and security in today’s large-scale microservices architecture.

During the interview, Branden Wood references Air Force’s Platform One as a federal organization that has embraced Tetrate to provide secure code in this increasingly dangerous world.

View Details

John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

History books will document the origin of the relational database at around 1970. About a decade later graph technology was introduced but it has taken decades for the cost of storage to go down and the ability to compute to go up. Finally, we can take advantage of a new way to unlock answers from a database.

A typical relational database looks at information in tables. This can be fantastic for many actions, which is why it became popular. However, drilling down into information can involve re-indexing and hopping around tables.

Graphing technology looks at the data and tries to find relationships. As consumers, we know if we purchase an expensive couch with a credit card, the credit card company may email and question if that is a valid purchase.

Well, multiply that by hundreds of thousands of users and millions of data points. It is not just a couch; it may be automated financial transactions that involve fraud.

Attend the Neo4j Graph Summit Government event on October 9th at the Spy Museum in Washington, D.C.

For a human to sit down with some tables of data would make the process so time-consuming, that millions could be stolen before the culprit was discovered.

During the interview, John Bender from Neo4J explains how they respect the existing data structures but can layer on a deeper understanding of the relationship between a specific transaction and an outcome. In other words, you will not have to say goodbye to your data silos.

Another application is understanding the supply chain. Because so much hardware and software are outsourced, it is hard to connect the dots. John Bender refers to an Army project where they have eight million nodes and twenty-one million relationships.

Listen to put into perspective new ways to improve analytical speed and reduce risk from fraud to the supply chain.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Today, we talk about a 47-year-old company whose income was up 21% last year. Yes, the company is Oracle.

Kim Lynch is a well-known technology executive, and she highlights how Oracle can solve complex federal tech concerns. She begins by giving a brief overview of the recent Oracle Cloud World announcements.

Kim Lynch takes all these announcements from Oracle Cloud World and applies them to specific federal problems.

If you are interested in leveraging the hybrid cloud and improving security, this is the interview for you.

Larry Ellison’s comments will surprise (shock) people who work with the federal government. First, was the embrace of other cloud service providers like Amazon Web Services and Google Cloud Platform. Who can believe that Larry Ellison is inviting leaders from AWS and GCP to the stage at an Oracle event?

The concept is we live in a hybrid world; Oracle is embracing this “multiverse” to help federal leaders leverage the cloud platform in its entirety.

Secondly, Kim Lynch reflects on the idea that Oracle employees will not have passports next year. After years of cybersecurity lifting signs of “Kill the password,” Oracle may be the leader.

If you have been in the world of technology, you know that we are all flooded with data. During the interview, Kim Lynch uses the term “petabyte” comfortably. Scaling to Zettabytes will make all data experts cringe, but it is a term used casually.

Wow. This is not your father’s Oracle, even if it is 47 years old.

View Details

John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Once upon a time, requirements would be collected and a software team would write custom code and after a year or two, a solution would be released.

This seems like the Land of Oz.

Today’s software developers grab code off the shelf, assemble it, and then deploy it. Then iteration after iteration must be evaluated and deployed in a world of constantly changing system requirements and cyber attacks.

Let us not forget testing must be included in each phase. There is functional testing, performance testing, checking for data integrity, mobile testing, and let us not forget user interface testing. In the federal world, consideration must be given to compliance. In the intelligence sphere, this is all taken up a notch.

Modern software development is a marathon with a constantly changing course and a never-ending finish line.

Today, we sat down with Adam Rosenbaum from Tricentis to examine the role of testing in this arduous process. He suggests that the custom part of coding prevalent years ago should be applied to automating testing.

This way, application testing can be automated using custom built-for-purpose solutions to verify functionality and performance. Adam Rosenbaum looks at a no code, low code approach to relieve some of the burden of excessive testing demands.

Two main benefits of automated testing are to be able to do several tests at once and that time can be used to free up developers for other human-based analytical work.

View Details

https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

FedRAMP was launched fourteen years ago; today we get an update on metrics and use cases to help companies considering certification.

James Leach has been immersed in the world of FedRAMP since the beginning. Today, he gives listeners insight on navigating the FedRAMP compliance process.

Commercial companies understand, in detail, the business problem they can solve. For some reason, when it comes to the federal government, they think they can “copy and paste” a business case and have it resonate.

When they apply, they may reference a single-threaded business case without federal business. Or they may promote an on-premises model and not include a cloud reference. Finally, organizations may dive into a hybrid cloud environment where it is a challenge to get sponsors.

First, one must do business with an agency and understand their requirements in detail; they will have different priorities from a regular “for profit” company. You will also need an agency to sponsor your application.

Once these basic hurdles are achieved, then one can begin to study cloud reference architecture. During the interview, James Leach gave several guidelines.

You need to understand FedRAMP more as a maturity model than a checklist for compliance.

You need to understand the controls but, more importantly, how the mandates are implemented.

Commercial companies can expend considerable resources to achieve FedRAMP certification, only to get frustrated in the end. FedRAMP is not a walk in the park and must be taken seriously.

View Details

Fun fact #1: 90% of software developed today comprises third-party apps.

Fun fact #2: 48% of organizations have over one hundred tools in the toolchain.

What could go wrong?

Today, we sat down with Ben Chicoski from CloudBees. He discusses the evolution of software development, emphasizing the importance of testing in the software delivery lifecycle.

CloudBees acquired Launchable to use AI to analyze test patterns and results to surface only important tests. He highlights that up to 80% of tests are unnecessary, consuming significant developer time.

CloudBees leverages AI and machine learning to optimize testing, reduce waste, and improve efficiency. The conversation also touches on the importance of continuous improvement, trustworthy pipelines, and the future challenges and opportunities in federal software development.

This discussion includes release orchestration and how it addresses the unintended consequences of increased development speed.

https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

Growth always brings challenges. In today’s episode, we talk about how the DoD can manage the challenge of development in several aspects of identity management.

Like most federal agencies, the DoD has made a move to the hybrid cloud; this alone adds to the complexity of the identification process. However, in addition to the 1.3 million active-duty service members, they must contend with reserves, DoD civilians, veterans, and many more. Oh, did we mention mobile?

The official designation of the process of validating identity is called Identity Credentialing and Access Management, or ICAM.

During this interview, experts from Akamai suggest:

Consider applying AI/ML to help analyze identity data.

Fast Identity Online (FIDO) FIDO standards exist, and one can consider applying FIDO to simplify identity.

Akamai has worked with both Defense and Civilian agencies to enable technologies like CAC/PIV and YUBIkey. Further, their well-known enterprise access management gives them the ability to protect web applications as well as mobile devices.

Many organizations are tasked with managing millions of individuals. Very few are associated with capabilities that can have as serious consequences as the DoD.

View Details

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

When you watch a spy movie you get the impression that the federal government’s intelligence agencies have unlimited funds for intelligence, satellites, and anything else that sounds mysterious.

Well, today’s interview will reinforce the concept that every federal agency has a limited budget. Money is allocated to buy test tubes at NIH or purchase intelligence data.

There may be situations where federal agencies may not be able to access information from the dark web, or they may get overwhelmed with the volume of data produced on any given day.

Today, we sat down with McDaniel Wicker to talk about how Babel Street is positioned to provide reliable data to federal agencies.

Babel Street began with a focus on foreign language knowledge acquisition. During the interview, McDaniel shared how Babel Street has grown into a service that can provide a wide range of information for various clients.

McDaniel’s company has the technology to sift through information in a wide variety of languages to understand sentiment. As a result, they are positioned to do expensive, original research or even just confirm suspicious activity for an agency.

Listen to the interview to get a better perspective on how the federal government can leverage artificial intelligence and multiple sources to provide timely information that can result in responsible decisions.

View Details

Want to make the most out of your next podcast appearance? https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

According to the MIT Technology Review, the federal government has over 26,000 websites. What good is it if citizens cannot access the information they require?

Today, we have Angela Mercado from RELI Group discuss User Experience (UX) and User Interface (UI) for federal websites.

One of the many impacts of COVID was American citizens were trying to get information from federal websites and were frustrated. As a result, in December of 2021 the White House issued Executive Order 14058, which had an emphasis on improving user experience for federal web sites.

Angela Mercado likes to focus on the phrase “Human Centered Design.” This means to gather as much data from users as one and to seek to optimize their experience.

During the interview she reviews heat maps, surveys, Net Promoter Score, and a myriad of tools to diagnose a faltering website. The goal is to reduce user frustration, have their commercial website experience like a federal website, give the user a seamless experience and to take advantage of automation and Artificial Intelligence to accomplish these tasks.

For example, AI tools can be used to scan federal websites to determine if they follow accessibility standards.

She gives listeners a great overview of the UI/UX work done by the GSA as a proponent of improved user experience for federal websites.

Want to make the most out of your next podcast appearance?

View Details

Want to make the most out of your next podcast appearance? https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Every software developer knows about the meeting in February 2011 at a skiing lodge in Utah. Seventeen people met to produce the “Agile Software Manifesto.”

Large software projects were falling left and right. This was a group of experienced developers who thought interaction and flexibility were keys to producing complex code effectively.

They introduce concepts like iteration and technical debt to the general audience.

Twenty- three years later we see a distortion of these concepts in the federal government’s approach to software development. They may launch an application quickly and suboptimal, and then expect to iterate.

However, this process has been distorted to a point where 70% of the federal IT budget is spent on this “iteration” under the guise of Operations and Maintenance.

Today, we sat down with Sonny Hashimi, the Head of Global Sector for Unquirky. He has experience in the commercial world as well as the federal government. His last federal title was Commissioner, Federal Acquisition Service for the GSA.

He has seen this flawed software development strategy from many angles. He suggests that proprietary software should be replaced by open-source methods that will allow for rapid change in code.

That way, patches, and changes in direction of application development can be accomplished in a timely manner. This change would free up millions of dollars to accomplish improvements in federal systems.

Listen to hear his diagnosis of the problem and the options he provides.

View Details

https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Forrester is well-known for conducting surveys with technology leaders and releasing conclusions. Today, we sat down with Sam Higgins, a Principal Analyst for Forrester, and looked at several studies he has participated in regarding the public sector and Artificial Intelligence.

We begin with some findings showing that 35% of global public sector organizations indicate an interest in implementing AI. Reduced cost, improved security, and automation are general benefits that have been reported.

This global view has been reinforced in the federal government with several programs including the AI test beds at the Department of Energy, Project Linchpin from the Army, and even the Air Force designating a Chief Data and AI Office.

During the interview, you will hear some surprising findings. One study shows that the responsibility for AI Strategy most often resides in the technology department, not official leadership.

Forrester is well-known for conducting surveys with technology leaders and releasing conclusions. Today, we sat down with Sam Higgins, a Principal Analyst for Forrester, and looked at several studies he has participated in regarding the public sector and Artificial Intelligence.

We begin with some findings showing that 35% of global public sector organizations indicate an interest in implementing AI. Reduced cost, improved security, and automation are general benefits that have been reported.

This global view has been reinforced in the federal government with several programs including the AI test beds at the Department of Energy, Project Linchpin from the Army, and even the Air Force designating a Chief Data and AI Office.

During the interview, you will hear some surprising findings. One study shows that the responsibility for AI Strategy most often resides in the technology department, not official leadership.

View Details

Want to make the most out of your next podcast appearance? https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Our guest today is a grizzled veteran of the cyber wars. Chuck Herrin from F5 Networks has considerable experience in commercial and federal networks to see trends.

For example, years ago one could diagram a network easily. Today, we have complex systems that are bombarded with data. Virtual systems are allowing for databases to be created on the fly. Combine that with storage being split between in-house systems and many clouds, you get a situation difficult to understand.

Some hark back to 1970 when the Temptations released a song called “Ball of Confusion.” Chuck has seen systems that can be appropriately titled a ball of confusion.

The solution? Understand your architecture. This way, you know all your endpoints and realize that the architecture is, in effect, your attack surface. From there, take a close look at your Application Program Interfaces.

Traditionally, one attack vector was the application itself. However, new cloud-based systems mean a process of distributed applications. As a result, the new attack point may be the API. We have a new term called a “leaky” API.

Chuck Herrin will share with listeners his experience and give you a deeper understanding of the role of protection of the API as part of a full orb strategy to protect vital federal data.

View Details

Want to make the most out of your next podcast appearance? https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

It seems like everyone is testing AI options; however, when it comes to technology like Quantum, people seem to shy away.

Today, we will attempt to clear up some of the questions listeners have about how to apply Quantum to federal problems.

Our guest Murray Thom has been working with Quantum for years. Further, his company, D-Wave, has been in business for 25 years, has two hundred patents, and employs over two hundred subject matter experts. So, D-Wave is not a startup without any proven record.

Murray sets the stage by setting up a contrast: classical computing compared to quantum computing. Traditional computers allow for a limited number of answers, while a quantum computer is not limited to the binary nature of the way we have been using computers.

Rather than diving into the philosophy and mathematics behind quantum, Murray looks at applications that can be boiled down to use cases.

If you look at the millions of containers that enter the United States each year, you can understand the complex nature of logistics. Effective use of quantum can allow for reduced fuel consumption, faster delivery times, and happier customers.

The federal government can apply this technology to areas like weather forecasting and even managing the 30,000 satellites that are projected to be circling the earth by 2030.

View Details

Want to make the most out of your next podcast appearance? https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

= = =

Fortinet’s Jim Richberg is a battle-tested veteran. His opinions are sought out in Congress and all over the world. Today, we sat down with Jim to assess the implications of the federal government using AI when it comes to cybersecurity.

Jim likes to distinguish between two broad categories of AI: discriminative AI and Generative AI.

Discriminative: AI that can classify data but cannot generate it. From a cyber perspective, it can assess sentiment and image classification. It can alert when there is a potential threat.

Generative AI: produces results based on amalgamation of existing data. This can be text, music, and even designing images. There is a possibility that a Generative AI application can look at a network and generate a report finding vulnerabilities.

So far, these have been defined, but the results have been few.

Jim Richberg thinks federal organizations are being limited to not having standards in contract terms as they procure AI.

One topic that many seem to overlook is the power requirement for AI. Some solutions include modifying chip design. But Jim cautions that it can take as long as five years to get a data center up and running while energy concerns are building daily.

This is a fascinating discussion that includes Jim’s delineation of MDM of Misinformation, Disinformation, and Malinformation.

View Details

Want to make the most out of your next podcast appearance? https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

= =

Some estimates are that the federal government will have spent one trillion dollars before the end of September 2024.

Federal contractors will be bombarded with opportunities; your bidding selection can make or break your company.

The issue is balance. If you respond to every solicitation, you won’t get to them all and the ones you complete may not be thorough enough to be the winner.

One can always throw humans at the problem, but nobody has the staff to even read the solicitations.

Today, Brooke Smith from Deep Water Point & Associates presents an option. He talks about the right way to bid and the wrong way to do it. Of course, a year you should have been ahead of the RFP process.

However, some funding hasn’t been approved until late in the process. As a result, you will see new opportunities popping up. In order to eliminate contested awards, we may see task orders, GWACs, IDIQ, and even OTAs just to get work under contract before the end of the year.

During this discussion, Brooke Smith details the role of automation that can help federal contractors use their limited time properly. They combine human experience with analysis of a company’s capabilities to help them select the projects that can yield the best results.

This is a “must listen” to learn how to optimize how your company can respond to year end offerings.

View Details

Want to make the most out of your next podcast appearance? https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

= =

Congressman Gerry Connely maintains that that the platform is the solution; today, we discuss the topic of data strategy with Rob Carey of Cloudera.

Rob begins by stating that when it comes to managing data, you need to consider what the outcome may be.

For example, if you are assembling data on nuclear weapons, you need much more care than putting together traffic information.

Some would say that this is the difference between serious data and a newly coined phrase “Everyday AI.” In other words, negligible risk decisions. This differentiation can assist in making budget decisions.

Rob goes on to discuss the expanded attack surface. With all of today’s sensors and data centers, many agencies are starting to use “petabytes” to describe the amount of information they are ingesting.

Companies like Cloudera can assist federal tech leaders by giving them a system where they can provide governance. For example, he describes an offering called Cloudera Security Governance Lineage. This provides a view of data from “soup to nuts.” Allowing managers to profile data, clean the data, and provide lineage tracking.

Federal agencies must not treat all data as being equal. Limited resources force systems administrators to view data from legacy systems, the hybrid cloud, and new sensors as part of a priority.

View Details

Want to make the most out of your next podcast appearance? https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

John Kindervag is the father of Zero Trust; Greg Touhill is the general of Zero Trust; today, we sit down with Dr. Zero Trust, Chase Cunningham.

Dr. Chase Cunningham has a solid background for his opinions. He served in the military, has a PhD., five patents, and has written five books.

We begin the discussion with praise from Randy Resnick, the Director of the DoD Zero Tryst Portfolio Management Office. The DoD is not the only federal area with large systems to concern themselves with.

The challenge in making a transition to Zero Trust is extant in the civilian agencies. For example, LaMonte Yarborough from the HHS indicated he must manage systems to try to make a transition to Zero Trust.

His Cunninham experience includes running a red team, so we pivoted the conversation about AI. Malicious actors or red teams can use AI-based tools like Dork GPT to create new ways to attack systems.

Today’s far-ranging discussion oversees many topics that federal leaders would be interested in., including cybersecurity skills, compliance, and managing legacy systems.

Technology periodicals all have headline articles on the lack of talent in the world of cyber security. Chase mentioned a school in Virginia called CyberNow Labs. It is a “trade” school that can prepare individuals quickly for a job stopping malicious actors. He mentioned several students are getting job offers before they leave.

When the topic of quantum was introduced, comments were made that, from a cybersecurity perspective, it is wiser to concern yourself with basics like identity and patching rather than worrying about a future quantum event

View Details

Data Destruction?

Find out more about data destruction best practices for federal agencies here.

https://securis.com/government-agencies/

Want to make the most out of your next podcast appearance? https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

What happens to sensitive information on electronics when they are replaced?

Most tech conversations today focus on the feats of Artificial Intelligence. Reports are generated, software is written, and predictions are made. However, few understand the e-waste implications of this tidal wave.

To start with, AI requires an incredible amount of computational power. If you combine that fact with the typical computer refresh cycles then we have a growing situation where federal agencies hard drives and SSDs with sensitive information that must be disposed of properly.

Sensitive information is not just stored on computers and networking equipment in data centers, we have it dispersed on tablets, mobile phones, laptops and even Navy ships.

You may ask – how often does sensitive information get out? A recent study has shown that 40% of used computers purchased on popular ecommerce sites had personally identifiable information on them. Governments and financial institutions have been embarrassed or fined for data breaches.

Our conversation today is with “Sal” Salvetti from Securis. His company provides a service that can take end of life computers, phones and tablets and dispose of them in a secure and sustainable manner.

Federal agencies have to comply with directives from GSA, DLA, NSA and NIST (800-88) around the proper disposal of end of life electronic devices.

In the interview, we learn how Certified Secure Data Destruction Specialists (CSDS) from Securis can help your agencies comply with federal guidelines and protect national security.

Many federal managers don't understand the full asset management lifecycle of hardware and the cyber security risks. Don’t treat old computers like trash.

The conversation provides best practices concerning when software can be used to wipe data and when devices or drives should be shredded. You will also learn why certifications from the National Association of Information Destruction (NAID AAA) R2 are critical for ITAD (IT Asset Disposal) providers.

View Details

Want to make the most out of your next podcast appearance? https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn

\https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes?

www.Federaltechpodcast.com

Donald Rumsfeld is famous for talking about the “unknown unknowns.” Well, today we will be a little more specific and focus on some “knowns.”

Most listeners know that cyber threat companies regularly list vulnerabilities. Jay Wallace estimates VulnCheck alone has a list of 300,000 known threats.

The Cybersecurity & Infrastructure Security Agency (CISA) decided to help federal agencies narrow down this list. They put together a list of vulnerabilities that were specific to federal networks. For example, if no federal agency ever uses “XYZ” software, why should a federal information professional care about it? It is not and will never be on their systems.

The key to understanding the KVE is that CISA will not just put a vulnerability on a list and say, “Good luck.” They will post a patch to remediate the problem.

VulnCheck helps federal agencies with prioritization, proof of concept, and a community.

Prioritization

For example, VulnCheck can assist in setting up priorities or these varying threats.

Proof of Concept

For example, during the interview, Jay Wallace mentions something called a Proof of Concept (PoC). VulnCheck can look like software combinations and determine if they can be a threat.

Community

Also, VulnCheck has an active community where these threats are discussed. Just this year, the VulnCheck community has been active in many areas, including making information about vulnerabilities consumed in a more palatable manner.

Malicious actors know about vulnerabilities, and a responsible federal manager should become familiar with how to manage this vulnerability list.

View Details

Want to leverage you next podcast appearance? https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn

https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes?

www.Federaltechpodcast.com

In baseball, one way to rattle an opponent hitter is to say, “Ya can’t hit what ya can’t see.” Today, we see cyber-attacks at a pace beyond a human’s ability to detect; we must consider applying artificial intelligence and automation to meet the current threat.

During the interview today, Palo Alto’s Erix Trexler outlines the correct approach for cyber defense. First, it is not enough to identify a threat. One needs to get the data, normalize it, and sort it quickly to have actionable intelligence. From there, actions can be taken to stop the attack.

Brigadier General Greg Touhill (retired) was the first Federal Chief Information Security Officer. He once said if you prioritize everything, you prioritize nothing.

Eric Trexler expands on this concept by emphasizing that each agency must have an effective strategy of prioritizing data, automating response, and then having a formal incident response in place.

Erick suggests that artificial intelligence can provide abilities like anomaly detection, capacity prediction, threat intelligence and even data classification to be able to execute an effective strategy.

Each agency has a varying level of cyber defense maturity. Eric emphasizes that a company with the resources of Palo Alto they can meet you where you are in your journey.

View Details

The volume of cyber attacks on federal organizations has gotten to the level that traditional methods have lost their efficacy. If you merely react to an intrusion, the malicious actor has gotten what he wants and has left.

Today, we sat down with Vinay Anand, the Chief Product Officer for a company called NetSPI. Back in 2001, they were founded to improve server, network, and application penetration services. Their initial offering of penetration testing has become so successful that it is being used by nine out of the top ten banks in the United States.

Over the decades, they have learned that true security went beyond penetration testing. They had to take a more initiative-taking approach.

For example, the attack surface back in 2001 was minuscule compared to what is happening today. Covid has encouraged remote access, sensors are everywhere, and cheap storage has allowed malicious actors the opportunity to place code in unimaginable places.

A tech leader must be able to identify and protect the unknown. The first step is to protect the external-facing network and the internal network.

The internal aspects can be controlled by tools classified as Cyber Asset Attack Surface Management analysis. The external system can be examined by an External Attack Surface Management system as well.

That may be a terrific beginning, but this knowledge must be augmented while simulating an attack. NetSPI can assist an agency in developing an attack plan and narrative. That way, they can understand their risk profile and optimize methods to recover from an attack.

During the interview, Vinay Anand gives a terrific overview of the development of different methodologies behind system protection.

Want to leverage you next podcast appearance? https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

Ep. 162 Managing Kubernetes can Increase Security and Reduce Cost

The military likes to use the phrase “situational awareness.” Of course, it is important in an anticipated conflict; it can also apply when managing complex federal IT systems.

For example, we have seen federal systems move to the cloud. This transition allows for more flexible ways to manage applications, especially with units that can include code, commonly called containers. However, the ease of scale with this cloud environment means that we are presented with challenges in managing these containers.

Kubernetes was developed to offer a limited solution for managing replication, load balancing, and scheduling. However, Kubernetes has limitations.

Today, we sit down with Dan McGuan from Rancher Government Solutions. During the interview, he describes how they has worked with many agencies over the years to help them with the complex management of virtual systems.

For example, we see malicious actors targeting containers. Basic Kubernetes was not designed for cyber protection. Dan McGuan describes how they have worked with Mitre to design a hardening guide for Kubernetes.

Another example is controlling energy consumption. Some have described ships in the U.S. Navy as “floating data centers.” Every data center has a challenge with energy consumption. Rancher Government Solutions is collaborating with companies like nVidia to present solutions that drastically reduce energy consumption in limited environments like warships.

Managing a complex abstract environment can yield more security, more control over data, and reduce infrastructure costs.

Want to leverage you next podcast appearance? https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

Want to leverage you next podcast appearance? https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

Everyone likes to hit the “Easy” button, especially software developers. Rather than laboriously generate code line-by-line, today’s software professionals may just grab code from a repository and re-purpose it. Why reinvent the wheel?

Malicious actors have noticed this process and have inserted code into many libraries, acting like a like Trojan Horse. As a result, some organizations are offering codes that have been inspected. They look at known vulnerability lists and see if the code includes any of them. If not, it is given a seal of approval.

Frequently, this is called a “Software Bill of Materials.” A convenient solution: however, upon inspection, SBOMs can be problematic.

The weakness of SBOM

During today’s interview, Joel Krooswik, Federal CTO for Gitlab, described in detail some of the ways software must be continuously protected.

According to the SBOM folks, the code is clean when leaves the “shelf.” However, due to continuous improvement code changes hourly. All an SBOM provides is a certification at a specific point in time for known vulnerabilities.

Joel Krooswik gives listeners an enterprise architect’s perspective. He indicates that digital transition introduces new code, new architectures, and innovative approaches. At any step along the way, security can be compromised.

The unknown unknown

Donald Rumsfeld famously said, “There are unknown unknowns.” This can be directly applied to what GitLab calls “fuzz” testing. This allows professionals to throw random inputs into a system to see what happens. Finally, you get a view of a potential possibilities that are not obvious.

Joel Krooswik presents many insights when it comes to protecting software. He states that just because a system is identified as needing a patch, it does not mean it will be done in a flash.

Understanding all the risk factors will allow a federal leader to make a prudent choice when it comes to protecting software systems.

.

View Details

All the headlines would make you think the federal government is spending millions of dollars on bleeding-edge innovative technologies.

However, a detached perspective shows when looking at funding one can conclude that 80% of technology spent is on operations and maintenance. If we continue this, then will have unreliable systems that are not effective at managing the current volume of data.

Today, we sit down with Badri Sriraman, the Senior Vice President of Karsun Solutions. He has years of experience helping federal agencies make this important strategic transition. He has a deep and thorough understanding of many federal systems including records, engagement, and intelligence.

Badri suggests that one potential use of artificial intelligence is to apply it to gain a better understanding of existing legacy systems. You may realize what data is duplicative or useless and what serious dependencies the existing system has built in.

From there, a plan can be devised where a segment of the legacy system is transitioned and evaluated. One tool that has been successfully used by Karsun Solutions is called “goredux.ai” This was designed to provide an enterprise architect with an idea of how to make a strategic transition.

The interview ends on a serious note. Legacy systems are more likely to have known vulnerabilities. There are increased costs inherent in older systems. Older systems may not allow federal leaders to reach agency goals. Finally, if all the budget is assigned to operations and maintenance you can paint yourself in a corner without a budget for modernization.

Want to leverage you next podcast appearance? https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

The federal government purchases over $90 billion a year in information technology porductds and services. The purpose of the Federal Tech Podcast is to listen to strategies and tactics for untapping that market for your company. Each week we sit down with technology leaders to hear how their solution fits in the complex federal technology world.

For more information on Federal Tech Podcast Follow John Gilroy on LinkedIn

View Details

Every technology has a maturation cycle; today we see Artificial Intelligence transitioning from being a parlor trick to being considered for serious applications. The federal government wants secure and reliable solutions to solve problems in the military and healthcare.

Our guest today is Dr. Ellison Anne Williams, she has a PhD in mathematics and is the founder of Enveil. She provides an overview of AI security by suggesting it is only as good as the data over which you train and use it.

AI is exposed to large data sets and models are encoded with the data with which they were trained. This process can leave the model vulnerable and open to attack, she describes one attack called a “model inversion.”

This is a machine learning technique that examines a model’s output and infers personal information about its data subject.

Dr. Ellison suggests a group of technologies called “Privacy Enhancing Technology.” During the interview, she gives an overview of how it can securely and privately train a model to produce richer insights.

PET allows leaders to secure the use of a wider range of data sources. You can use homomorphic encryption to safely train your model over sensitive data.

This interview is an overview of a technology that can allow federal agencies that must deal with sensitive information to be able to leverage the speed and insights that AI can provide.

Want to leverage you next podcast appearance? Take the quiz. https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

Years ago, people would laboriously code character by character. This tedious process would take hours and would include errors. Over the years, libraries of prewritten code have evolved that allow software developers to “grab” some code, modify it, and finish a project earlier.

Malicious actors have taken advantage of this short cut and have injected code into these software libraries that get taken along for the ride.

One proposed solution is something borrowed from the shipping industry. A commercial invoice may be packaged with a bill of lading to indicate the contents of the package. This “assurance” has been transferred to the world of pre-written code and is now called a “Software Bill of Materials,” or SBOM.

In a world where you are shipping a ton of Portland Type II cement overseas, this bill of lading works finds; it has some challenges being transferred to the dynamic world of software.

In a typical federal environment, there is continuous change in the code itself. It would be difficult to change on ton of a manufactured product like Portland Type II Cement. However, the once approved software package may have so many changes that the Software Bill of Materials may not have any validity.

During the interview today, David Jurkiewicz unpacks the concept of an initial SBOM and then how software packages can evolve over time and still retain compliance. His company can take this basic guarantee and examine the software for many concerns, including.

· Vulnerabilities

· Dependencies

· Integrity

· Malware

· Foreign presence

· License

David Jurkiewicz provides details on how companies can resolve vulnerabilities and ensure safe operations in a world where code is grabbed off the shelf and slipped into a package.

Want to leverage you next podcast appearance? https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

One of the most practical applications of Artificial Intelligence (AI) is to assist in network observability. The big move to Zero Trust is predicated on the ability to have a thorough understanding of network assets.

This is a significant issue for federal information technology. We have legacy systems, shadow IT, and a deluge of data in addition to the confusion that a hybrid network can bring.

Riverbed takes a phrase from science, telemetry. Initially, it was used to troubleshoot the original network: the power grid. Since then, the term has been modified to apply to a standard data collection system for analyzing information on a digital network.

The fact that 98% of the Fortune 100 uses Riverbed for determining network status means that they are the de facto leaders in the market.

Today, we sat down with Jeff Waters to help us understand how Riverbed can be applied to federal systems. You would expect Jeff to emphasize network management, however, he shows how the basic “telemetry” approach can be used for improving user experience.

The approach is simple: if a technology can look at movement on a network, it can be applied to understanding how federal sites are used by citizens.

We move from DevOps to Artificial Intelligence Ops, or AI Ops at the end of the interview. This concept allows Riverbed to be able to understand a situation and offer remediation. Because the network is so well understood, the solution is effectuated quickly.

Telemetry – from old-school electrical troubleshooting to helping with user experience on a federal website.

= = =

Want to leverage you next podcast appearance? https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

In 1848 they found gold at Sutter’s Mill in California. According to the CEO of Cohesity, data is the new gold. Today, we sit down with David Kushner from Cohesity to unpack what this “gold” reference means for federal technology leaders.

This has always been the case. Today, we see cheap storage, fast Internet, and Generative AI producing an overwhelming amount of data sets. The challenge is how to protect them.

This “perfect storm” has not gone unnoticed by federal leaders. If you casually look at a few recent federal mandates, you constantly see a reference to “security” and Artificial Intelligence.

· White House: President Biden issues Executive Order on Safe, Secure, and Trustworthy Artificial Intelligence

· Homeland Security: Promoting AI Safety and Security

· OMB: Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence

Cohesity has been in business for over a decade and has garnered a reputation for efficient management of critical assets. We sit down with David Kushner to unpack what these innovations mean for the federal government.

For example, we all know that the federal government gets attacked thousands of times a day. We all know the “usual suspects,” but what is starting to happen is malicious code is being injected into backups. It is conceivable that a systems manager could reach for the backups and introduce compromised data into a sensitive data set.

During the discussion, David mentions that Cohesity has worked with over three hundred federal agencies in a wide variety of services. In February of 2024, Cohesity launched a search assistant called Gaia. This allows enterprise-level organizations to use Large Language Models and Retrieval Augmented Generation in a manner that complies with compliance mandates.

Listen to learn about Gais, backups, and a new world where the data is the gold that is being exfiltrated.

= = =

Want to leverage you next podcast appearance? https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

We are at the point where Artificial Intelligence is splitting into several capabilities. These include Generative, Natural Language Processing, Computer Vision, Predictive, and Deep Learning to name a few.

Today, we sit down with Melisa Bardhi from Excella and look at one aspect of AI, Generative AI, and examine how it can be used responsibly for federal applications.

In a short 25 minutes, she covers

· Definitions

· Beginnings

· Security

· Existing models

· AI training

Melisa begins by admitting that one must be cautious about data that is used to feed AI. All humans have biases, whether intentional or not. One document she would like to share with the audience is Excella’s Generative AI Use Policy.

Rather than starting with a major tech overhaul, it is suggested that an agency looks at a pilot with well-defined outcomes. Generally, Generative AI should be deployed in a controlled environment.

Security is foremost in the minds of all federal employees. The challenge is that many of the recommendations from laudable organizations like NIST can be hard to understand. As a result, Excella has unpacked many security concepts in several blogs. A reference is Decoding Artificial Intelligence: A Simplified Guide to Key Terminology.

https://www.excella.com/insights/decoding-artificial-intelligence-a-simplified-guide-to-key-terminology

When you read about ChatGPT producing summaries, this is an example of a model that is used in a wide-open environment. Melisa suggests agencies test out pre-trained models through cloud platforms like Azure ML, AWS Sagemaker, and GCP AI Platform.

Fortunately, we are bombarded with places to learn more about Generative AI. During the interview, Melisa mentioned agencies should consider partnering with research institutions and groups like ACT-IAC. For example, you can start your Generative AI journey with an article titled “AI Understanding in the Federal Government.”

https://www.actiac.org/documents/ai-understanding-us-federal-government

= = =

Want to leverage you next podcast appearance? https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

Sometimes, we must look at literature to get an understanding of the current situation for federal GWAC contractors. Let us look back to Charles Dickens with, “It was the best of times, it was the worst of times.”

Here is the scenario: your company spends a ton of time and money to get a spot on a GWAC contract. never to win any work. All your hopes and dreams of increasing business have been crushed.

Today, we sit down with Brian Seagraves from Deep Point Water & Associates to take a detached view of this GWAC process and provide some suggestions.

We begin with some shocking numbers. We all know that federal organizations working under GWAC send out notifications regularly. In a perfect world, a resolute employee shows up for work at 9 AM, sees a notification, and then begins the filtering process.

In the real world, companies are overwhelmed by notifications and end up working to dead ends.

For example, one organization gave 27,450 announcements annually. Simple math indicates, that with 250 workdays, this is 100+ notifications a day. Mere humans cannot keep up. Inevitably, their companies may pursue bad fits or even miss excellent opportunities.

During the interview, Brian suggested a solution from Deep Water Point & Associates that can assist in this complex filtering work. His company has managed to combine a strong knowledge of keywords and human understanding of culture to assist in the selection of which announcements to pursue.

He details how they developed GWAC NorthStar. This is a “as-a-service” offering and a company can be set up with a free 30-day trial.

GWAC NorthStar is a good example of how Artificial Intelligence can be combined with human “know-how” to speed up the proposal process.

= = =

Want to leverage you next podcast appearance? https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

We are in a whirlwind of change. Data is pouring into federal agencies.

A recent report indicated that data was growing at 25% a year; cloud usage at a rate of 61%; and Software as A Service an astounding 200%. Oh, did I forget to mention that Generative AI is also increasing data exploding?

It is one thing to worry about data from John’s Doughnuts, and quite another to worry about sensitive military, financial, and health information that the federal government is charged to protect.

Data. gov estimates that 250 million data sets are being used by the public sector.

This increase in data has not been missed by the White House. On February 28, 2024, an Executive Order called “Protecting America’s Sensitive Data” was issued.

Today, we sat down with Adam Costello to have him share some of his practical knowledge of securing data. Adam begins by suggesting federal agencies start by figuring out where these data sets are stored. Humans make mistakes, humans jump into shadow IT and create ghost data, and people do not understand retention protocols.

Adam suggests that an Asset Management Database can establish a baseline for documenting data. From there, we can get a better perspective on concerns like encryption, micro-segmentation, time-based retention methods like records management, and establishing a Recovery Point Objective.

If you look at your network configuration and blink an eye, it has changed. Listen to the interview to gather best practices from a data management specialist with decades of experience.

= = =

Want to leverage you next podcast appearance? https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

Sometimes, the most important impact of technology can be behind the curtains.

Today, we will not focus on AI Deep Fakes and AI language translation, but on the impact AI on software development.

Terry Miller from Karsun begins the interview with the basics of software development: collecting user stories. Traditionally, a systems analyst would interview several users to see how a software system should behave.

This time-consuming process can be assisted with AI helping in assembling the details. Please note, Terry Miller will argue that AI is used as an auxiliary to humans putting together the stories. It can reduce time by eliminating tedious tasks and allowing well-paid professionals to focus on the key concepts.

Every large organization, including the federal government, has legacy systems that need to be replaced. This is always challenging because older systems have been put together with the proverbial duct tape. It can challenge a human to review code that has so many twists and turns to understand what to send to the new system and what is unnecessary.

AI can be used to review existing code to see where it can be leveraged to make an easy transition. Enterprise architects can then design a systematic approach to enable this transfer.

If you would like to see an example of this transition technology, you can visit Karsun Technologies and evaluate their tool called ReDuX-AI.

= = =

Want to leverage you next podcast appearance? https://content.leadquizzes.com/lp/fk1JL_FgeQ

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

Ep. 150 Can a platform provide a path to safe AI for federal technology?

About every reader knows that ServiceNow is a large company that helps the federal government with managing large systems.

Today, Dr. Raj Iyer answers the question – is ServiceNow keeping up with AI to help reduce cost and improve delivery for massive federal systems?

Dr. Iyer is in a unique position because of his years of experience in commercial systems and a recent stint as the CIO of the United States Army. An argument can be made that he is up to date with managing large systems and has a thorough understanding of challenges in data security and cyber vulnerabilities.

During the interview, he provided a wide range of examples of how ServiceNow is leveraging its platform-as-a-service offering. A big splash was made when ChatGPT was able to generate content from large language models.

When it comes to the federal. government, they cannot use the stand large language model because of security concerns.

One approach that ServiceNow has taken is a partnership with NVidia that will all federal agencies to create domain-specific data sets. They can be compliant, secure, and allow innovation to be applied to a myriad of federal-specific problems.

= = =

Want to leverage you next podcast appearance? .

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

Everyone has seen AI with articles and even deep fake videos. No doubt it is dazzling, great for a conversation at a picnic with friends.

The question is . . . can you put AI in work boots?

Vishwas Lele has a novel idea: combine the best of AI with the best of proposal writing. Further, his innovation can be applied to an environment where data must be held securely. Yes, we are talking about proposals for the federal intelligence community.

Vishwas describes the Microsoft approach to AI – differentiates between free and paid Chat GPT as well as the free and paid versions of CoPilot. He describes how Microsoft CoPilot can provide FedRAMP high protection for data.

When it comes to writing proposals for the federal government, we have several factors to consider:

1 AI depends on data libraries. If the proposal must include reviewing classified data, then precautions must be taken with forming data libraries.

2 Proposal writing is an art, not a science. By now, we have all heard of “hallucinations” provided by AI – my personal favorite is Napoleon being part of the American Civil War.

Vishwas suggests AI but must be amended with human knowledge. Shipley & Associates have garnered a stellar reputation in the proposal community.

pWin.ai is partnering with Shipley and Associates to bring a human understanding of requirements to the proposal process.

Look for yourself. Go to pWin.ai and request a demo.

= = =

Want to leverage you next podcast appearance? .

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

Federal technology has paralleled the commercial world in its expansion to millions of endpoints. On one hand, this means better information from something like an intrusion sensor. On the other hand, it means the attack surface has just expanded exponentially.

It has come to a point where there has been a normalization of breaches. Unfortunately, this does not mean one can neglect protecting your agency from external threats.

ZeroFox specializes in understanding external threat security. They have been around since 2013 and “Zero” in on protecting apps, data, people, domains, and API’s.

During the interview, AJ Nash goes into considerable detail when he differentiates between the surface web, the deep web, and the dark web.

He does not realize it, but he is a differentiator as well. ZeroFox relies on leaders like AJ Nash who have considerable experience in the intelligence community and understand the levels of security that are necessary to protect sensitive federal systems.

But they do not just stop at identification. AJ Nash continues his comments on something called “automated remediation. “ZeroFox can help your agency move to the next level and integrate with systems that can snap into action when a threat is detected.

COVID, fast Internet connections, and small sensors have made the Internet infinitely more dangerous than it was even a few years ago. Understanding external threats can prevent takeovers and attacks.

= = =

Want to leverage you next podcast appearance? www.podscorecard.com

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

After hundreds of interviews with tech innovators I have concluded they are all trying to accomplish the same thing: tell how they can help get the word out that they may have a slice of the solution for federal information technology. One of the best ways to “get the word out” is through a community of interest.

During the interview today, Derek Weeks details his success in forming a community around Development Operations, or DevOps. In fact, he has published a book detailing that wildly successful endeavor: Unfair Mindshare LINK

One of the keys is to listen to problems and gaining a deeper understanding of the challenges in remedying complex tech concerns in the federal government. The community is called DevOpsDay https://devopsdays.org/

Derek and a colleague started with an idea to have a couple of hundred developers have access to each other in an informal meeting. It became so popular that it has blossomed into a group of 30,000.

Some key takeaways

·Start with a user-lead experience. There is no use in guessing what topics will be of interest to the community. Reach out personally to dig deep into current issues and concerns.

·Give without expectation. User generated content is closest to the problems than anything from the marketing department. Content from sponsors as well as from members should be shared willingly.

·1,000-hour rule. There is a commitment of at least 1,000 hours a year to accomplish a successful community. This is not a “set it and forget it” initiative. Careful nurturing and growth of the community needs a real effort.

·Localize community relationships. We have seen meetups all over the world. One way to get the word out is to contact like-minded professionals. A problem in Sao Paulo, Brazil could be the exact concern in Kigali, Rwanda.

·Sustaining the relationship is as crucial as beginning it. Derek gives specific tips on maintaining the relationship over the long haul.

The success of community building tells us more about software developers than anything else. Aggressive pitches will be discounted. Generic email blasts are outdated.

Digital natives appreciate authentic experiences. This means that a community leader does not look at a member of a community as a “prospect” but as a “person.”

= = =

Want to leverage you next podcast appearance? www.podscorecard.com

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

The federal government has a myriad of technological challenges: legacy systems, Zero Trust, and even maintaining existing equipment! Most companies who work in that environment solve problems from a traditional office, or, even more comfortably, a home office.

Unfortunately, life at the tactical edge is not that easy.

Today, we dive into the tactical edge network with Sumner Lee, the CEO of a company called Fuse Integration. He started his career at the U.S. Naval Academy and has served in a variety of different geographical environments.

As a result, he has an appreciation for warfighters being in remote and contested environments where communications are critical.

Because today we rely heavily on digital systems for targeting and coordination in the field, any loss of communication can result in grave consequences.

One of the keywords in the interview is the term “resilience.” In common tech talk, this means having a backup server in another state. When it comes to the tactical edge, it means establishing a system that has backups. For example, if a cable connection goes down, a satellite can provide backup. If someone loses all communications, they still have basic functioning capabilities.

During the interview, Sumner provides examples of how difficult resilience can be in contested environments that are geographically disparate. When a warfighter is under pressure, it is even more important to provide seamless information that is user focused.

When friction is reduced, difficult tasks can be completed in a more efficient manner.

= = =

Want to leverage you next podcast appearance? www.podscorecard.com

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

Cybersecurity threats are like fashion; wait a few years and they come back in style.

The Internet was designed to take a series of digits and resolve them to a website address. This was deemed the Domain Name Service, or DNS. In 1996, we saw the first malicious actor flooding a system with an attack. This was called a Distributed Denial of Service Attack, or DDOS.

Over the years new methods of attack have proliferated and DDOS has taken a back seat. However, the number of endpoints has risen exponentially. It certainly looks like we are in a perfect storm to revive good old-fashioned DDOS.

During today’s interview, Rob San Martin tells the audience that Akamai processes over 11 trillion DNS requests a day and can see trends. According to Akamai’s internal threat intelligence, in 2023, 60% of DDOS attacks had a DNS component.

Looks like we are Back to the Future!

Sean Lyons from Akamai shared an amazing story from last year. A local government was attacked more than 6,000 times. This attack was sustained for over three- and one-half hours.

If you work for a federal agency and are looking for an on-premises solution for this problem, you may want to consider Akamai’s new offering in hybrid DNS infrastructure security called Shield NS53.

Listen to the interview to gain a better understanding of options for controlling DNS issues in your system.

= = =

Want to leverage you next podcast appearance? www.podscorecard.com

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

Appian Corporation is a 25-year-old technology company that focuses on improving process automation for large organizations. Once a year they have an annual conference for developers and partners. They rotate this meeting all over the world, we are lucky enough to have them meet in Washington DC where we have the chance to sit down with one of Appian’s co-founders, Michael Beckley.

During the interview Michael Beckley covered topics like the impact of artificial intelligence on process automation; process automation and acquisition professionals; and how to improve process automation.

Appian Corporation was one of the first companies to embrace a platform that was described as no-code, low-code. The interview will give you a detailed understanding of the benefits of that approach.

After these questions, we pivoted to looking at how Appian Corporation can help the federal audience reach agency goals. Michael detailed concepts like re-using code, compliance, and how Appian uses objects.

During the event, I decided to meet some developers and ask them what questions they would ask if they had the opportunity to sit down with one of the founders of Appian. Let us begin with the questions from the “floor.”

Minor Mata from Costa Rica. “No questions, we just appreciate all the free training.” He expanded on the concept of not just technology training, but instruction in solving business problems as well. Appian understands that software needs to enable execute in practice.

Noe Miniel from Miami. “Can you improve the speed of the interface?” Appian gives you the tools to speed up the system. That is the purpose of the Appian data fabric.

Jason R. from the federal government. “Can you make the code easier to review?” Appian incorporates the ability to configure Appian. This can allow senior architects to review the code and not create redundancy. They have template libraries as well as visual tools to allow comparison of code in development.

Listen to the interview to get a bird’s eye view of the progress Appian has made over the years to help federal agencies develop flexible code as well as maintain high compliance standards.

= = =

Want to leverage you next podcast appearance? www.podscorecard.com

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

In connecting with some new listeners, I learned that some have never sold to the federal government and listened to the podcast to see how other companies manage to work with federal agencies in reaching agency goals.

Well, it seems time to pull back with a bonus episode on how to sell technology to the federal government. To accomplish this task, I looked for a person with twenty years of experience in public sector marketing. The logical choice was Brian Chidester. He has worked for many companies in the past two decades and, as a bonus, has a podcast as well. His podcast is called The Government Huddle https://podcasts.apple.com/us/podcast/the-government-huddle-with-brian-chidester/id1506796636

In a far-ranging discussion, Brian overviews topics like regulations, contract vehicles, and partnerships.

COMMERCIAL VS. FEDERAL

The interview begins by listing how selling to a commercial organization differs from a federal agency. For example, you may not realize that a contracting officer for an agency may be prohibited from discussing the purchase with the end users.

For-profit companies may have some compliance requirements, but none come close to the layer and layer of regulations on a federal site. The federal site cannot just respond to the needs of one segment, like shoe buyers. They serve the public and, as such, must provide access for all citizens equally.

CONTRACT VEHICLES

The federal government is allocated funds in a completely different manner than a commercial organization. For example, an agency like NASA may have Solutions for Enterprise-Wide Procurement (SEWP). It provides information on products available to contractors.

PARTNERSHIPS

During the discussion, Brian details what can happen. The federal government may have allocated money for a project and mandated a certain amount for small businesses. Your company may be a perfect fit, but you do not qualify to bid on the contract.

It is perfectly feasible to partner with companies like Carahsoft or The Immix Group on a proposed solution. You may have the technical talent, and a company like Carahsoft understands the complex compliance process. It is a win-win proposition.

Brian Chidester ends the interview on a high note. He reinforces the idea that the federal government is actively seeking talent that will solve their problems.

= = =

Want to leverage you next podcast appearance? www.podscorecard.com

Want to connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

Not all threats to the United States are discussed in English. That simple concept is well known in the intelligence community; however, making an obvious statement and being able to understand the nuances of a foreign language is a different matter.

Today’s interview is with John Weaver, the Chief Strategy Officer for a company called Babel Street. The company began in 2009 with its name recognizing its ability to understand languages. From this humble beginning, it has grown into a powerhouse for looking at open-sourced information and doing advanced analytics.

During the interview, John Weaver talks about the dilemma many federal agencies are encountering. On the one hand, they have an increased number of sensors and storage where they can amass tremendous amounts of raw data.

The dilemma federal leaders face is how to unlock the insight that matters.

Babel Street focuses on open-sourced information for situational awareness on topics that go beyond linguistics. Of course, they can do a multilingual search, but they have enhanced that basic skill to include social media monitoring, entity resolution, and situational awareness.

Listen to the interview to gain insight on how Babel Street can help you ingest insights promptly.

John Weaver refers to an article called “What is the Risk-Confidence Gap” that can help you understand how to leverage your budget and resources to reduce threats to your agency.

= = =

Want to leverage you next podcast appearance? www.podscorecard.com

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

Artificial Intelligence is at the phase where federal and commercial technology leaders are amazed by novel model architectures. Each one can perform a function like data preprocessing, feature extraction, or prediction. The demonstrations are impressive; today we look at the data behind the dazzle.

Adam Kowalski from proximal has spent years helping organizations follow a data-centric AI approach. During the interview, he expands on having high-quality, relevant data has precedence over any model architecture.

One weakness of generative AI systems is they can be subject to bias. You may have insufficient data. Taking a data-centric approach can eliminate many of the errors we are seeing in AI results.

The results of varying from this precept can be disastrous as well as entertaining. In the commercial world, this can result in millions of dollars of loss. In the federal government, there can be much more grave consequences of ignoring the data.

It is not all serious. Adam Kowalski mentions an entertaining term from the AI community. If you ask a public language model a question about ancient Rome, you may discover a key player was Abraham Lincoln. This is called a “hallucination.”

= = =

Want to leverage you next podcast appearance? www.podscorecard.com

Connect to John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Want to listen to other episodes? www.Federaltechpodcast.com

View Details

Cheap storage and fast Internet have made data collection cheap and fast. It is no wonder that we have federal agencies that are drowning in data.

Some will argue that the federal government is the largest collector of data in the world.

That may be a fantastic fun fact that will dazzle your neighbors, but how is that data being used to move forward the goals of the agency?

Today, we sat down with Jason Green from Virtru. He brings his considerable experience to bear when he describes how agencies can optimize that data. He provides his thoughts on digital strategy, collaboration, and safeguarding that data.

STRATEGY During the interview, Jason makes a sage observation. He remarks that when looking at the overview of digital transformation strategy, the focus has been on applications and not the data itself. AI will be making increasing inroads around decision-making and serious decisions cannot be derived from dirty data.

COLLOBORAGE – When a data analyst is limited to one data set their conclusions can be biased. The need for collaboration is obvious. The “how” is the tricky part. Jason suggests that more careful attention be paid to tagging data so that some fields can be shared and some not.

SAFEGUARDING – Years ago, data was guarded with hashing techniques. In today’s fast-changing world, mere hashing is not sufficient. Data stores can be injected with poison data; this means continuous monitoring must be stretched into the data stores themselves.

If you would like to learn more about managing data, you may want to attend “DMV Rising” a networking event at Virtru headquarters in Washington DC on September 5, 2024. You will be able to sit in on sessions as well as ask face-to-face questions for subject matter experts.

= = =

www.podscorecard.com

Connect to John Gilroy on LinkedIn

https://www.linkedin.com/in/john-gilroy/

Got goin’ to Mars on your bucket list? Listen to Constellations Podcast

https://www.kratosdefense.com/constellations/podcasts

Want to listen to other episodes?

www.Federaltechpodcast.com

View Details

In 2021 the federal leaders recognized a problem with citizen experience on federal websites. As a result, Executive Order 14058 was released dedicated to improving citizen services for federal technology.

However, a 2023 McKinsey & Company report states the average score for federal services is only 31%.

Justin Fessler from Yext appears on the Federal Tech Podcast to offer some insights on how to improve the citizen experience, especially as it pertains to search. Everyone has laughed at the misleading results that a search engine gives. Everyone has opinions.

It is one thing when you search for some obscure historical fact, and another when you are looking for a tax ruling.

During the interview, Justin Fessler observes that much of the information citizens require may be sitting in a data store somewhere in the agency. He suggests that generative AI can be applied to these data sets to provide answers more easily and in the context of the user.

One concern that is expressed by everyone is the “black box” nature of generative AI. How can you trust the answer from a faceless system? Justin Fessler provides the answer: citations. In the Yext search platform, stacks of data are searched quickly, and citations are offered for the answer.

Improving citizen experience means documents can be retrieved for important ranging from legal to emergency services.

= = =

www.podscorecard.com

Connect to John Gilroy on LinkedIn

https://www.linkedin.com/in/john-gilroy/

Got goin’ to Mars on your bucket list? Listen to Constellations Podcast

https://www.kratosdefense.com/constellations/podcasts

Want to listen to other episodes?

www.Federaltechpodcast.com

View Details

The Federal Trade Commission recently estimated that nationwide fraud tops ten billion dollars. Most of the efforts to stop this abuse start with identification.

However, the federal response has been weak.

Today, we have a former federal leader and current Vice President and Head of Public Sector Strategy for Society on the podcast, Jordan Burris. He opens with the obvious – if malicious actors are leveraging artificial intelligence to attack identities, then the only logical response is to use AI against AI.

AI allows malicious actors to assemble identity information for fast access. Recent reports highlight a concept called an “identity access broker.” This is a company that stores compromised credentials and sells them like one would buy shoes.

From his perspective, the federal government has not moved away from legacy systems fast enough and is leaving itself vulnerable. For example, a traditional system may approve an identity, but not be able to continuously maintain that identification. It has been shown that Multi-factor Authentication can leave sessions open where an initial valid identity can be compromised.

Identity is not stagnant and innovative approaches can look at many aspects of identity, including liveness detection.

CrowdStrike’s Global Threat Report shows a 147% increase in identity attacks. Federal agencies are not immune to these attacks.

= =

www.podscorecard.com

Connect to John Gilroy on LinkedIn

https://www.linkedin.com/in/john-gilroy/

Got goin’ to Mars on your bucket list? Listen to Constellations Podcast

https://www.kratosdefense.com/constellations/podcasts

Want to listen to other episodes?

www.Federaltechpodcast.com

View Details

ChatGPT has overwhelmed the headlines in the past few months. It has brought the concept of artificial intelligence to the forefront of many discussions. Like everybody talking about swimming in the Olympics and then forgetting about it for four years.

Well, Primer.ai has been deeply involved in artificial intelligence since its inception seven years ago. It did not start with creating a bot for a site selling shoes, it got its start from I-Q-Tel and has a laser focus on helping the defense community apply technology to real-world problems.

The company has deep relationships in the defense community and understands the need of applying natural language processing to the warfighter’s needs.

During today’s interview, Mark Bruner from Primer set up the discussion by talking about innovation from Silicon Valley and the requirements of the hardnosed military community. Rather than walking away from the potential benefits of technical innovation, Primer sees itself as an intermediary with the skill set to be able to bridge the gap between real-world requirements and the software community.

One of the key elements that is glossed over is the need for ethical application of artificial intelligence. This means understanding how large libraries are assembled and then, at the output end, knowing when to assist the data analysis with human values.

The military knows it must adapt to a rapidly changing world, Primer can broker relationships and see value where others cannot.

Here is an article from Primer that may help To go faster on AI, Start with Existing Gaps

https://primer.ai/featured/to-go-faster-on-ai-think-small-and-build-trust/

= = =

www.podscorecard.com

Connect to John Gilroy on LinkedIn

https://www.linkedin.com/in/john-gilroy/

Got goin’ to Mars on your bucket list? Listen to Constellations Podcast

https://www.kratosdefense.com/constellations/podcasts

Want to listen to other episodes?

www.Federaltechpodcast.com

View Details

In most of my interviews, I sit down with a company and talk about innovation in solving federal technology goals. Today, a twist.

Sonny Hashmi was at the center of the battle for improving federal technology. For the past three years, he was the Commissioner of the Federal Acquisition Service at the GSA. This has given him a unique perspective on what the bottlenecks are in streamlining federal technology.

He dealt face-to-face with issues like Zero Trust, remote work, and digital innovation. After looking at a myriad of issues, he decided that the way to apply Occam’s law to federal technology was to reduce the complexity of software development.

Sonny Hashmi explains that 80% of the technology budget is spent on maintaining systems. This means continuous monitoring, patching, and applying new compliance regulations. His approach to solving the problem is to start at the beginning, software development itself.

The solution is quite simple: adopt a codeless method that allows a wider range of people to work with legacy systems, rapid application, and compliance.

During the interview, Sonny Hashmi details some problems he has seen. He talks about everything from struggles with ATO to end-of-life application management.

Listen to the interview to learn how the Unqork approach can assist in many aspects of the major digital transformation the federal government is undergoing.

www.podscorecard.com

Connect to John Gilroy on LinkedIn

https://www.linkedin.com/in/john-gilroy/

Got goin’ to Mars on your bucket list? Listen to Constellations Podcast

https://www.kratosdefense.com/constellations/podcasts

Want to listen to other episodes?

www.Federaltechpodcast.com

View Details

Everyone reading this has seen the movie Top Gun with Tom Cruise and heard the classic phrase, “The Need for Speed.” Well, a desire for speed is not limited to Naval Aviators. People in federal technology may not have call signs but need to optimize communication speed between data centers.

If you were to stand in front of a whiteboard with a bunch of enterprise architects, they would dazzle you with CPU and GPU speeds. Memory tricks with virtualization give you tons of memory. However, at the end of the day, the real choking point is the connections between those stacks of silicon.

During today’s interview, Rob Shore from Infinera unpacked how optical speeds have drastically changed over the years. Today’s speeds allow for transmittal of 1.2 Terabits per second. That makes the speed of your home wi-fi look like a bicycle racing a Maserati.

The conversation took a fascinating twist. While everybody is debating the methods of data collection for artificial intelligence, systems engineers are worrying about the hardware being able to “catch up” to the speed demands that, for example, driverless cars demand.

At the end of the conversation, Rob talks about applying the concepts for fast optical cable to inside the data center. Same principles, a need for speed between servers and routers inside a data center as well as between data centers.

You can watch the short video starring Rob Shore that explains one technical aspect of technology, coherent optics.

= = = = = =

Got a podcast interview coming up? What's your score?

www.podscorecard.com

Connect to John Gilroy on LinkedIn

https://www.linkedin.com/in/john-gilroy/

Got goin’ to Mars on your bucket list? Listen to Constellations Podcast

https://www.kratosdefense.com/constellations/podcasts

Want to listen to other episodes?

www.Federaltechpodcast.com

View Details

An American poet once wrote about reaching a fork in the road and he considered which path to take. When one attempts to consider branching logic and automation in complex technical systems, there is a lot of consideration given to which path to take.

There may be lessons to be learned from Robert Frost’s 25-line masterpiece.

Today’s discussion is with Thomas Kinsella, Chief Customer Officer and Co-founder of a company that focuses on improving automation. It is appropriately called Tines.

Thomas Kinsella was asked to discuss a typical day in the life of a person working in a Security Operations Center, or SOC. He describes it as a plethora of alerts, new data, and disjointed tools.

His description of the SOC was kind of like One Day in the Life of Ivan Denisovich by Aleksandr Solzhenitsyn. The story is almost as monotonous as a Soviet era gulag, although the remuneration may be slightly higher.

Thomas Kinsella describes issues with alert fatigue, difficulty of finding good staff, and incompatible systems that make duplicative works. He and his co-founder decided to come up with a better solution, they founded Tines.

During the interview Thomas Kinsella describes how they have been able to use technology to assemble data from a variety of sources. This was to address the idea of alert fatigue, if an incident was possibly confirmed, then it should be pursued.

Secondly, the way to address staff shortage was to design a visually based system so that an untrained individual could drag and drop actions into a sequence. In fact, Tines provides playbooks for many scenarios in a secure environment, he calls them playbooks.

The result is a system that can produce a Secure Orchestration Automation and Response system that is easy to use, scalable, and doesn’t need the expertise of a PhD. in computer science.

For more on Tines, please read the blog “Cybersecurity in 2024: Five Predictions from our co-founders”

= = =

What’s your score? Take the Podcast Appearance Scorecard

www.podscorecard.com

Connect to John Gilroy on LinkedIn

https://www.linkedin.com/in/john-gilroy/

Got goin’ to Mars on your bucket list? Listen to Constellations Podcast

https://www.kratosdefense.com/constellations/podcasts

Want to listen to other technology podcasts?

www.Federaltechpodcast.com

View Details

Today we sit down with Susan Kidd and Valinder Mangat and discuss FedRAMP.

Some will argue that FedRAMP is an unruly thirteen-year-old. Although FedRAMP has authorized over three hundred public service cloud providers, there is much work to be done.

For example Valinder Mangat opens the discussion by noting that we have approximately five hundred applications in the pipeline. We have a situation where manually reviewing compliance is going to be too difficult. As a result, FedRAMP is making changes. They are starting to automate the process, causing companies to become familiar with a new acronym, Open Security Controls Assessment Language, or OSCAL.

During the interview, Susan Kidd reviews her philosophy that ties into understanding OSCAL. It has been her experience that there is a limit to working hard; the best results are accomplished when one takes advantage of automation and can work smart. To that end, Susan Kidd launched something called Idea Labs, an initiative that can assist federal agencies in modernizing their automation processes using OSCAL.

Today’s compliance is not just a check box item. In the interview, Valinder Mangat details aspects of software development. There was a time when code was released and approved, like a snapshot. Today, there is a continuous improvement model in effect along with continuous testing.

The only way to accomplish that is to leverage technologies like OSCAL to keep up with changes in threat actors and best practices for handling mountains of data.

Valinder Mangat has a nice summary of this consideration: champions of innovation instead of captives of compliance. In other words, technology can be leveraged so a company does not take six months to get approved. OSCAL puts tools into the hands of federal leaders faster.

More details about the IdeaLab at DRTConfidence.

= = =

What’s your score? Take the Podcast Appearance Scorecard

www.podscorecard.com

Connect to John Gilroy on LinkedIn

https://www.linkedin.com/in/john-gilroy/

Got goin’ to Mars on your bucket list? Listen to Constellations Podcast

https://www.kratosdefense.com/constellations/podcasts

Want to listen to other technology podcasts?

www.Federaltechpodcast.com

View Details

If you were to take a class in Data Management 101, you would walk into the classroom on the first day and be bombarded with terms like data lake, data warehouse, and data mart. Phew. Where to begin?

Let us jump to a federal agency. They are being deluged with data from low code no code, big application platforms, and let us not forget legacy applications that are not in the cloud. How to manage this ball of data confusion. Once it is overseen, how can an agency share information with outsiders to allow for data collaboration?

We begin today with a solution offered by a company called Snowflake. Winston Chang suggests that if can take advantage of a single platform, you can abstract the data layer which allows you to manage the data more effectively.

OK. Now that we can look across data sets, we encounter the problem of what eyes get to see. Who gets to see what columns and rows and who does not? Winston Chang suggests that a data platform will enhance collaboration by allowing leaders to be able to decide which information, or parts of information, will be available to which parties.

During the interview, Winston makes some provocative statements. He argues that if we want to focus on infrastructure, then the data itself must be considered as the infrastructure.

If this discussion provokes more detailed information, you may want to consider attending the “Data for Breakfast” conference on March 7, 2024, at Tyson’s Corner Ritz Carlton. You can question experts from Snowflake on topics as varied as artificial intelligence and managing data as a platform.

What’s your score? Take the Podcast Appearance Scorecard

www.podscorecard.com

Want to listen to other technology podcasts?

www.Federaltechpodcast.com

Connect to John Gilroy on LinkedIn

https://www.linkedin.com/in/john-gilroy/

Got goin’ to Mars on your bucket list? Listen to Constellations Podcast

https://www.kratosdefense.com/constellations/podcasts

View Details

A recent study by Deloitte indicates that 67% of executives struggle with data analytics. The knight in shining armor that offers a rescue is artificial intelligence.

Today’s interview pours the promise of artificial intelligence into both ends of the spectrum: qualifying data sets that are being used and, subsequently, producing explainable results.

The headline overview of artificial intelligence involves writing a report by ChatGPT. Although that may be true, the article will be derivative and will not move the ball intellectually.

You will hear Kyle Rice discuss how Virtualitics can use artificial intelligence methods to look at data sets that are being investigated. Once those libraries are produced, then they can take artificial intelligence to look at making conclusions.

When analysis is approached from that point, you eliminate the guess-and-test method. That is to say, there is a good chance that the hypotheses that are created by humans. In other words, you will not spend precious time trying to answer the wrong questions.

Virtualitics poses that a rational way to generate data sets can give users the ability to form elusive data-derived decisions.

During the interview, Kyle describes the approach as “intelligent data exploration.” The added value of this approach is defensibility. For example, if a data scientist produces a conclusion, their sources can be questioned. Instead of pointing to a black box in the corner, a team can produce explainable artificial intelligence.

Interested in reading more from Virtualitics? Why AI’s Success Depends on Making it More Explainable and Conversational

What’s your score? Take the Podcast Appearance Scorecard

www.podscorecard.com

Want to listen to other technology podcasts?

www.Federaltechpodcast.com

Connect to John Gilroy on LinkedIn

https://www.linkedin.com/in/john-gilroy/

Got goin’ to Mars on your bucket list? Listen to Constellations Podcast

https://www.kratosdefense.com/constellations/podcasts

View Details

We begin this episode with a shocking statistic: 80% of hybrid cloud breaches involve credential abuse. During the interview, Jimmy McNary from Semperis unpacks the whole concept of protecting identities in the hybrid cloud.

The interview covers a wide range of topics.

First, we start by taking a view of how large systems have evolved. Larger systems tend to have two or more identity processes, and Active Directory from Microsoft has a 90% share of that overall market.

Secondly, some identity systems can use outdated Identification Access Management systems.

Thirdly, we have employees and contractors who enter and leave systems. This can produce confusion in de-provisioning access.

Putting all three together produces a perfect storm for malicious actors. They can use tools to scan systems for vulnerabilities in, for example, identification processes, and set up an attack.

Semperis uses Active Directory as the starting point to orchestrate identification. They can stop malicious actors before they attack, during the attack, and help post-attack.

In a poignant example, Jimmy McNary relates the story that some organizations spend significant amounts of money on backups, including immutable backups. Unfortunately, they forget about backing up Active Directory. We know that it is likely the attack vector included Active Directory, but it is not protected.

This is a scenario where the system is restored, and the malicious actor has retained credentials to allow him back into the system.

Jimmy McNary provides practical tips to avoid these frustrating situations.

= =

What’s your score? Take the Podcast Appearance Scorecard

www.podscorecard.com

Want to listen to other technology podcasts?

www.Federaltechpodcast.com

Connect to John Gilroy on LinkedIn

https://www.linkedin.com/in/john-gilroy/

Got goin’ to Mars on your bucket list? Listen to Constellations Podcast

https://www.kratosdefense.com/constellations/podcasts

View Details

The title of this podcast is “Federal Tech Podcast.” For many people, this evokes an image of stacks and stacks of servers in a windowless data center.

Today’s interview shows listeners how that data can be unlocked and put in the hands of front-line officers, whether they are federal or civilian.

Bob Griffin from Siren has been involved in bringing data to online operators for decades. During the interview, he presents a challenge that many encounter. In one example he gives, a person drives up to a warehouse in the middle of the night and sees an unexpected car.

The idea I to get as much information as you can in front of the officer. In years gone by, this has been done with desktop computers. An officer may have to communicate with an office where someone may run a search.

There is no doubt that this is an effective method. Siren has been the leader in the unique ability to look at various data silos and search them for salient information.

In this interview, Siren announced a breakthrough that takes the traditional ability of a desktop and puts it in the hand of a mobile device the officer.

Finally, time is not wasted. An officer can approach a situation and be prepared with actionable insight into perpetrators and take appropriate action.

Finally, data that fulfills the role it was designed for, making burdensome tasks faster and easier for users.

Get any mileage out of your last podcast appeareance? Take two minutes to complete the Podcast Appearance Scorecard

View Details

Today, we look at the proper way to manage the hybrid cloud for federal projects.

Our guest is the Chief Technology Officer for Thundercat Technology, Kurt Steege. Kurt has an extensive background that includes a stint as the Chief Enterprise Architect at the FBI.

An argument can be made that the move to the hybrid cloud can increase flexibility and reduce cost; an equally valid argument can be made that the increasing complexity of the hybrid cloud can cause poor visibility, insecure data transmission, and compliance issues.

We see federal agencies not getting boxed into a corner by using more than one cloud service provider. This may be great for financial reasons, but the hybrid cloud, by definition, is going to be much more difficult to observe. The risks are always changing, some cybersecurity experts say that Application Program Interfaces are the new attack vector; a multi-cloud system makes accounting for all of them hard.

Another obvious fact, if your agency moves to the “XYZ” cloud, there is a transmission of data. If they go ahead and send another application to the “ABC” cloud, there is another communications port. Each one adds to the attack surface for an agency.

Finally, each cloud service provider has diverse ways of offering compliance. At the end of the day, a federal official must sign off on the compliance. Understanding the subtilities of these differences may cause excessive delays.

Thundercat Technology has a white paper that could help. It is titled “Cloud Transformation Leads to Better Outcomes for Government Agencies.”

View Details

If you do a Google search on “Leadership” you get five billion results. Seems like a topic that has been given tons and tons of attention.

A better way to gain an understanding of leadership is to seek out examples of poor leadership and try to avoid them. Enter, How NOT to Lead: Lessons Every Manager Can Learn from Dumpster Chickens, Mushroom Farmers, and Other Office Offenders. The latest book from Dr. Chase Cunningham

This is an interview with Dr. Chase Cunningham where he gives his reasons for authoring the book and the origin of many of his stories. He has a fascinating background that includes being raised on a farm in Texas, working in sensitive military areas, and completing a Ph.D.

Some of the chapter titles look like a setup from a professional comedian. He has chapter titles like

Do not be a Dumpster Chicken

Go Slow to Be Fast

Beware the Brilliant Jerk

Do not be a mushroom farmer.

Do not chase unicorns.

Yes, the chapter titles are brash and so are Chase’s recommendations.

Let us one tiny aspect of the book: the idea of starting a company, getting investors, and becoming a millionaire. That certainly is the goal of millions and millions of entrepreneurs.

Chase has seen investors and innovators in action. He has seen naïve startups get dazzled with investment dollars give up control of companies, and become employees to a demanding task master. Wait a minute, one of the reasons for starting a company was to become independent.

Chase tells the untold part of the “rags to riches” story of technology startups. An innovator may produce an idea and surround themselves with a core group that develops and makes the company grow. Many are hired with the promise of riches when the company goes public.

What can happen is the founder falls for the trap where the company’s value gets diluted, and the promises made to the initial group have been cast aside.

When you buy and read this book you will be drawn into memorable stories about roping cattle, small boar maintenance, and keyboard warriors.

Buy this book today to help you become a successful entrepreneur, a better leader, and a decent human being.

View Details

Over the years some technical terms are easy to understand for mere mortals – data centers, high-speed internet, and even identity management. However, when you mention the term “Kubernetes,” a normal professional eye would glaze over. Some technical professionals may have to revert to making up some applications.

Well, the wait is over. Today, world-famous Paul Smith from Rancher Government Services will give a working definition of Kubernetes and show how efficiently using this technology can reduce costs and improve security for federal systems.

We begin the interview from 40,000 feet with a general guide to open-source software and Paul Smith gives an overview of Linux and Red Hat. That parallel seems to ring some chords.

Next, the concept of “container” was expounded upon. A container is merely a bundle of software, this is portable. It can be used as plastic blocks children use. You can pick up the container and run it anywhere. When it comes to three-year-olds, the blocks end up all over the house!

Now that the foundation is set, Paul Smith indicates that in and of itself, the open-source Kubernetes provides high availability and scaling; on the other hand, it can be difficult to install, complicated, and needs to be monitored.

Today’s federal hybrid clouds need a way to manage these containers. Enter, Rancher Government Solutions.

During the interview, Paul Smith presents some of the challenges in a multi-cloud world. He includes comments on legacy systems, edge computing, and orchestration.

If you would like more information on Rancher Government Solutions, please download the free whitepaper titled Pioneering Secure by Default Open-Source Kubernetes Solutions

If you would like to attract customers to your company on your next podcast appearance, then should fill out the Podcast Appearance Scoreard. See where you stand and get some pracical tips and suggestions so you can leverage that next podcast appearance.

View Details

When people think of Amazon Web Services, they normally think of a data center. This was certainly top of mind when AWS hosted 10,000 at its Public Sector Summit in 2023.

Today, we go in a different direction. Dave Rubal is a well-known innovator in the Washington DC technical community. He has decided to throw his hat into the ring with something called the Secure Tactical Edge.

It makes sense. If you look at how storage and computing are changing. In a recent study, IDC predicts that in the future 75% of data will be collected at the “edge.”

The federal government has a myriad of ways to manage this “edge” concept. Civilian agencies may have one approach, and the DoD has another. In addition to being on the edge, they need to be able to deploy this concept in a tactical as well as secure method.

During today’s interview, Dave Rubal sketches out one aspect of that movement to the edge. He talks about how the DoD can securely use edge cases. In other words, the Secure Tactical Edge.

Let us take a small task as an example, storage of video feeds. The DoD has facilities all over the world and needs physical security. It would be ridiculous to store these feeds in a data center across the globe. Further, there are retention policies that are in place to reduce the burden of storage.

Another example may be unstructured data being collected all over the earth, and even above. Agencies must be able to architect a solution that takes advantage of innovation on the edge to reduce cost, improve flexibility, and provide data rapidly so warfighters can make decisions quickly.

Here is a hashtag summary:

#TacticalEdge #OperationalEdge #HybridCloud #EdgeComputing

This is the episode that introduces the tried and true, “Up close and personal” Dave’s avocation is to volunteer at his local fire station. He is a licensed EMT and has saved lives with his skills.

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

James Eselgroth will lead a discussion about innovation and change in federal technology.

Normally, one would think about solutions to problems. Traditionally, develop a list of changes, check each off the list, list, and move on. That may be a fantastic way to build a house, not that it simply does not work in today’s dynamic software environment.

In today’s fast-moving technical climate, one approach is to use something called an MVP. No, not the National Football League kind of MVP, not Most Valuable Player, but a “Minimal Viable Product.”

A “Minimal Viable Product” is a concept that originated in agile software development. The idea was not to submit a complete, finished product but to present the essence, framework, or basics of a product and get feedback.

This initial offering had to include working elements but omitted many of the details like user interface concerns and complex integration projects.

During the interview, Jim explains how this concept applies to the federal audience. He references a quote from Federal CTO Clare Martorana who said “Demos, no memos.” This temporary solution would be presented to stakeholders and see if it was a good fit. Alterations are made and the next iteration is presented.

Listen to the interview to hear how Jim provides an overview of his innovation lab. This results in the MVP approach allowing for solutions to be built in two to four weeks.

Highlight has a new offering called EdgeWerx. Look for announcements at

https://highlighttech.com/

View Details

AI? Process mining? We owe it to the listeners to put the strange title into perspective.

Some will argue that a federal agency is a collection of business processes. For example, a company turns in its taxes; a laboratory applies for a grant; and even federal agencies must comply with cybersecurity requirements. Some will label this process management.

Because the federal government deals in billions of dollars these processes can be quite complex. Experts have evolved who can examine these processes and determine ways to improve the process. Because there are stacks and stacks of petabytes of data to be concerned with, the term “mining” has become popular to describe this kind of examination.

OK. Step Two. We all know that artificial intelligence is trying to be applied to as many aspects of federal technology as possible. Many are talking about potential savings. However, this may be true with simple tasks like creating reports; however, complicated processes may present a challenge to artificial intelligence.

If someone arbitrarily slaps an AI Process into a system, it could wreak havoc. Please remember that AI is derivative, and can absorb previous systems but not necessarily offer anything new.

During this interview, Christopher Radich breaks down some concepts that Celonis uses to gain a deep understanding of complicated processes before AI gets a chance to work.

For example, they have pioneered applying the concept of digital twins to processes. This is a way that a process can be evaluated to discover the implications of process change.

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

Process Mining for Dummies https://www.celonis.com/ebook/process-mining-for-dummies/

View Details

In today’s interview, Guarv “GP” Pal from stackArmor presents a warning call to let people know that a sudden jump into any technology can present unintended consequences. He offers suggestions to make AI meaningful, safe, and dependable.

Everyone remembers Bill Murray on Groundhog Day having the same experience over and over. After a few years of experience in federal technology, we are looking at something similar.

First, the commercial sector I dazzled. Next, federal technology leaders feel like they must get in the same boat. A few years ago, many agencies jumped headfirst into the cloud, and then FedRAMP had to come along to put some guides on the cloud experience.

Fast forward to 2024, today’s Artificial Intelligence is falling into the standard pattern. Federal technology leaders can feel left out and make a quick adaptation, then later guidance emerges to rectify some of the unintended consequences of artificial intelligence.

Researchers are seeing security vectors that are unique to AI. What security principles should be considered when putting together a Large Language Model? Can a bias be introduced?

What controls do you have in place today that you can apply to your agency’s AI journey?

To bring in a diverse set of opinions to offer guidance, GP discusses his company’s development of an AI Risk Intelligence Center of Excellence. They have assembled a high-power group of leaders with federal experience to provide training models and actionable steps for making a safe and secure transition to AI.

View Details

The first part of this interview is a fascinating description of how John Kindervag produced the concept of Zero Trust. In the early days of networking, many users were described as “trusted users.” John questioned as to why they did not take the next step and verify then. The response was classic – because it would be rude.

Fast forward a few decades and we see countless breaches and billions of dollars of intellectual property lost because of fear of offending the sensitivities of users.

Back to 2011. Interfaces on firewalls could have varying levels of trust associated with them; the question from John Kindervag was, “why any levels at all?” His idea of zero trust resonated in the commercial and federal marketplace. For example, an Executive Order was issued in May of 2021 mandating the adoption of zero trust for the federal government.

During the interview John Kindervag presents a fascinating contrast between the attack surface and the protect surface. This is a framework to allow federal leaders to prioritize what data to protect.

To gain a better understanding of how to deploy Zero Trust, The National Security Telecommunications Advisory Committee was established. It presents a five-step model and shows how to build Zero Trust one protects surface at a time.

Listen and learn about the Cloud Security Alliance and myriad ways to develop expertise in the nuances around incorporating Zero Trust into your federal network.

Mentioned in the interview: What is Zero Trust Architeture?

https://www.illumio.com/blog/what-is-a-zero-trust-architecture

View Details

On December 13, 2021, an Executive Order titled “Executive Order on Transforming Federal Customer Experience and Service Delivery to Rebuild Trust in Government.” This initiative reflects the greater commercial experience. Because people are now so comfortable with transactions on a phone that customers are using sites that present as “user friendly.”

When combined with the Covid information that the federal government was presenting, the idea of improving the user experience only makes sense.

Thelma Van is an articulate and experienced professional with user experience. During this interview, she takes the topic from a high level the level of the click. The interview covers topics like infrastructure, common communication, and a focus on user needs.

When it comes to defining user experience or UX, it is a formal method to evaluate functionality. In other words, how a typical user attempts to complete a task on a website.

Thelma Van suggests that if agencies are interested in improving user experience, then they should start with getting as many stakeholders as possible in a room and listening to the challenges they express. Although there are tools like heat maps and speed evaluations, her experience makes her put the focus on human beings first.

The federal government is going through a “digital transformation.” Many focus on important topics like identity management, software bills of materials, and even graphics processors. This is the interview that shows listeners that software development should put primary emphasis on the people the systems are designed to serve.

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

DoD tossed the revisions to the OMB; the 300,000 people in the DIB are waiting with ‘bated breath to see what it looks like in the Federal Register. Will it be a “final” rule? Will it be an “interim” rule?

The first paragraph sounds like an academic dispute in an ivory tower; that “tower talk” is particularly important for the 300,000 companies that comprise the defense industrial base. Today, sit down with Kevin Hancock from Exostar. He will give you his thoughts on this important piece of federal regulation.

If you wanted to classify this transition as revolution or evolution, you would have to side with the Darwin followers. The CMMC is not anything new, this is just the next logical step.

Smaller companies may earn a living as subcontractors to a large prime contractor. The large organizations are making inquiries to all their partners to see where they stand with CMMC. May are looking in the mirror and asking, where do I start?

During the interview, Kevin Hancock from Exostar breaks the process down into segments that any company can understand. He explains that ten companies may have ten different sets of requirements to comply with CMMC.

For example, do you have the expertise to run the requirement in-house? Even if you did, is this the optime way to use their time? Will an application from a company like Exostar be able to leverage the skill set you have in-house?

Your company may just need a few templates to complete. However, you may be in a situation where you are looking at six months to complete an 18-month project. Had you started earlier, you would not have been in the situation.

We all understand that CMMC was put in place to safeguard controlled unclassified information and controlled unclassified information. These are reasonable requirements, yet each person listening to this podcast may have a different journey. Exostar can help.

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

There was a time when a “snapshot” of a federal system was taken, and its security posture was evaluated based on the moment in time. That may have been a tolerable solution when a network consisted of two dozen personal computers and a server down the hall. However, this superficial approach will not work with today’s networks in constant change.

For example, data is exploding and entering systems from a wide variety of portals. Add to that the devices that deliver that tsunami of data are doubling and tripling themselves.

During this interview, Jonathan Trull from Qualys gives his opinion on the state of today’s federal technology when it comes to vulnerability assessment, configuration settings management, asset management, and dynamic application security testing.

He also addresses qualitative aspects of managing assets. Jonathan Trull refers to the weakness of a “checkbox” approach to managing assets. In mature systems like the federal government has today, you may discover managed and unmanaged assets. Just because you check the box on “managed” assets, this does not mean it is professionally managed; it may be poorly managed leaving a system vulnerable.

Software development is all about Minimum Viable Products and frequent changes. Terrific for agile software development, however, each update means a new weakness could be introduced. Federal leaders must embrace agile methodologies and keep systems safe at the same time.

This means everyone should consider dynamic security application testing as part of a prudent network safety analysis.

This interview will give you a good introduction to how to keep enterprise systems safe in a world of constant change.

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Thousands of books have been written about agile software development since the release of The Agile Manifesto back in 2001.

It was a noble, but frustrating concept two decades ago. They really did not have the tools to have informal teams combine to complete complicated software development projects. For example, if your team were in one building, you could meet daily and provide updates on agile topics like product backlog and continuous integration.

This face-to-face approach hit a wall when team members were remote.

Back in 2006, the founders of Bluescape saw the problem and started to develop technology that allowed professionals to accomplish the task of process management and workflow automation.

In 2011, the Scaled Agile Framework (SAFe)started releasing frameworks for assisting larger organizations deploy agile methodologies. Bluescape works well with the principles of SAFe.

During the interview, Norm Literini describes how Bluescape provides a platform to allow software to be developed in a flexible manner. It provides common operating tools to unite sectors, this can be in software, crisis response, of cross-functional planning.

Further, Bluescape is FedRAMP and IL4 / IL5 compliant so federal systems managers can rely on a system to produce software safely as well as effectively.

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

The world is exploding with data and the need for systems to manage it. Unfortunately, we are not seeing a commensurate growth in people who are getting trained in software development. Let’s state the obvious: the need for coding is driving companies to look at ways to reach project milestones creatively.

Companies like Nintex offer what they classify as no code, low code solutions. Essentially, they look at ways to systemize code creation.

Let’s put this concept into perspective. In 1999 Salesforce popularized the concept of software-as-a-service. It became the world’s largest software firm in 2022.

One could consider low code, no code as a compromise between prepackaged systems like Salesforce and companies who laboriously wrote each line of custom code. This approach provided a reduction in development time, along with an added benefit of scalability.

One weakness of custom coding is the time-consuming process it takes. Today, we see individuals in companies jumping on “shadow IT” where they use systems that may be included in the purview of systems administrators.

Speeding up projects with no code, low code acts as a deterrent to the dangerous jump to unauthorized code on networks.

During the interview, Steve Witt talks about the popularity of low code, no code in the commercial world. Many estimate that 84% of today’s enterprises turn to low code, no code.

The interview includes Steve’s differentiation between Business Process Automation and Robotic Process Automation. Furthermore, listen to the comparison Steve provides between low-code and no code systems to see what approach may benefit your agency.

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

One of my goals in “Federal Tech Podcast” is to let federal leaders get an idea of what new companies and ideas are available to help them reach their goals.

Well, everybody knows Google. This is an interview with Leigh Palmer from Google to bring to light some unknown areas of Google.

Leigh provides Google's perspective on major cloud issues, like defining “cloud native” and giving her opinion on the hybrid cloud. She thinks that federal leaders should look at the success Google has had with commercial organizations.

To accommodate that knowledge transfer, Google Public Sector was launched in 2022. It has gotten so popular that they now have an annual conference dedicated to the federal government called the Google Public Sector Conference.

At the last conference, a couple of innovations were expanded upon. During the interview, Leigh Palmer details some of the advantages of what is called Codey. Finally, you can evaluate code with the assurance of a company the size of Google standing behind it.

https://blog.google/technology/developers/google-colab-ai-coding-features/

Recently, we have seen the OMB provide a FedRAMP draft memo seeking comments on changes to the venerable FedRAMP. We all know that FedRAMP was released ten years ago; many do not realize that this is the first change. Some of the recommendations include guidance on cloud deployments as well as a suggestion to move away from dedicated clouds.

Leigh has been involved in helping federal agencies reach goals for decades. Listen to learn how agile and innovative a big company like Google can be.

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Ep. 114 Improving Digital Adoption for Secure Federal Technology

Commercial enterprises and the federal government have a challenge in managing the tremendous tsunami of data that has been released in the past few years. On top of that, federal agencies are under an unfunded mandate to adopt Zero Trust for all its systems. During this interview, Billy Biggs from WalkMe suggests that Artificial Intelligence may provide solutions to this complex problem.

He begins by addressing the concept of digital automation. For example, when a person requests time off, they may have to engage five separate systems. With automation, you can reduce that complexity.

Billy Biggs looks at artificial intelligence from a longer perspective. He observes that today’s Artificial Intelligence may be the worst one will see in their life. One approach he likes to see is a focus on increasing productivity with AI on a small scale first, then raising the level of adoption.

His overall message is that AI will make substantial changes and humans will have to be trained in the new applications. This process cannot be done in a traditional classroom, it must be done in a process where training is done in an environment where training is built right into the application.

A true digital transformation cannot waste time, it must look at how an AI system works identify the top ten issues, and create user efficiency with that approach. That way, time is not wasted teaching people about aspects of any new application that are not pertinent.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Josh Brodbent has an amazing technical background. When he was still in his teens, he started a company that managed services. For the past twenty years, he has immersed himself in the world of technology with a particular focus on ICAM and cyber security.

During today’s interview, we tapped his technical expertise to comment on some trends in cybersecurity that can impact the federal government: the MGM hack and CISA updates.

The MGM attack was a curious combination of old-school methods and artificial intelligence. According to reports, a malicious actor used a telephone call to gain access to a system. The telephone number was easy to find; the rest of the pieces of the puzzle were available through social media. This new vector launches a new portmanteau. It combines voice with phishing to yield “Vishing.”

The real talent in this attack was the convincing phone manner, with doses of urgency, which allowed the hackers to get into the MGM system. They set up some ransomware and walked away with an estimated 100 million dollars.

Josh Brodbent looks at the recent announcement from CISA. To use securely developed software, they a. mandating that a higher level of officers at software companies attest to the security of the code. This may grab the attention of leaders in the “C” suite to actively comply with federal regulations.

The interview ends with an examination of the complex issues federal leaders face. Josh observes that many in the commercial and federal world chase after “bright shiny objects” a can take they are off the goal. He observes that complexity does not always mean effectiveness.

Listen for the MGM details and lessons to streamline your federal agency.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Some will argue that providing cybersecurity to a federal agency is a balancing game. On the one hand, you must encrypt network traffic; on the other hand, you provide a mechanism where this encrypted traffic is inspected. This must be done in compliance with many regulations and not have any impact on the speed of the network.

Sounds easy when a group of software developers are arguing around a white board. However, in the real world this task must be accomplished in a rapidly changing environment in the hybrid cloud. Systems are under attack daily; mountains of unstructured data bombard federal systems on an hourly basis. These factors moves up the level of complexity.

Your system must be flexible enough to give you a thorough understanding of network traffic. Some analysts call this “Cryptographic Agility.”

Chaim Mazal from Gigamon provides the listeners with an overview of the company, Gigamon. In business since 2014, they currently work with 87% of all Fortune 100 companies. They have recently announced an offering called “Precryption.” It gives federal leaders deeper control of the TLS layer.

During the interview, Chaim outlines how Preryption can reduce cost, overhead, and overall resources in an effort at deep inspection of network data.

Ian Farquar is a colleague of Chaim’s at Gigamon. He has a magnificent phrase that talks about data. He once said, “look at traffic because that is where the truth is.” Deep observability can give federal leasers and foot up on controlling massive amounts of data.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

In Calvinball, the rules were always changing. When it comes to the DoD’s Cybersecurity Maturity Model Certification, it seems to look increasingly like Bill Watterson’s masterpiece, Calvin and Hobbs.

Today’s interview is with Dr. Amy Williams from Coalfired Federal. She has years of experience in the nuances of CMMC and has a strong academic background to be able to understand complex topics and present them in an understandable manner.

Amy begins the interview with the range of activities that companies have regarding CMMC compliance. Some companies have invested thousands of hours in preparing for this rigorous compliance;. On the other hand, some organizations do not realize it could be a twenty-four-month process and if they delay starting, they could compromise future business.

One of the main takeaways from the interview is the timeline on CMMC that Coalfire Federal provides. It has been a circuitous route where the DoD was vociferous about the program and then had a mysterious quiet period. Then, like Venus sprouting from Zeus’s brow, the DoD releases more details on CMMC.

Dr. Amy Williams observes that companies should know what is essential and what is superfluous at the varying levels of CMMC. Many defense contractors are already working 10-hour days without the burden of CMMC compliance. In order not to waste time, a framework is given as to when a company should consider using a consultant and when to bring the compliance work in-house.

The episode ends on an optimistic note – it was observed that the baseline of compliance, a mere seventeen controls, is basic cybersecurity for any modern company. These include basics like multifactor authentication and understanding where important documents are located on your network.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

In the early days of computer networking, one was taught to make the network hard on the outside and soft in the inside. A more popular variation on this concept was your network should be like a castle with a moat around it to prevent entry. Well, both metaphors have been destroyed.

Today, you would be naïve if you did not assume the bad guys are inside your network. The proposed solution is, of course, zero trust. However, you do not flip a switch and have a zero-trust network assembled.

Before the world ushers in the panacea of Zero Trust, federal technology leaders must have tools to protect what is going on inside the castle walls. Early attempts Intruder Detection Systems. This approach could generate false positives, needed full-time monitoring, and was expensive.

During today’s interview, Mark Bowling from shares with the audience a concept called Network Detect and Response. They begin with complete network transparency. Through proprietary means, they could gain complete visibility on a network.

Years ago, a federal agency could walk down the hall to see the network; today’s networks are flooded with remote sensors, contractors, new employees, and remote workers. This dynamic nature makes it difficult to draw up a rough diagram, not have a thorough understanding. Even if you did, this network would be changing with virtual systems spinning up and containers adding to the confusion.

Mark Bowling has decades of experience with highly classified documents on highly secure systems. He suggests thorough visibility allows leaders to set up a tiered structure to locate high value assets and protect them first.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Traditionally, a threat was detected, and a remediation plan was deployed. This is classic Endpoint Detect and Response (EDR). Would that life be that easy.

Today, we have malicious actors using generative Artificial Intelligence to slightly alter code, so it doesn’t resemble previous attacks. This kind of eliminates the “detection” part of EDR.

This isn’t rare anymore. In fact, in August of 2023 Deep Instinct did a study where it concluded that there was a significant increase in cybersecurity attacks fueled by generative Artificial Intelligence. Some findings

· 75% increase in attacks last year

· 85% if these attacks are attributed to generative Artificial Intelligence

During today’s interview, Carl Froggett from Deep Instinct gives an option to run-of-the-mill EDR. He gives the listeners an overview of how Deep Instinct started. He explains that, originally, they relied on open source for data on attack activity. However, researchers discovered that open source was not powerful enough.

Deep Instinct decided to develop proprietary ways to look at massive data streams to determine if there were threats. They started with Artificial Intelligence, moved to Machine Learning, and focused on the algorithm associated with a concept called Deep Learning. They have had tremendous success.

One determinate of effective threat screening is reducing false positives. This is a significant problem. In the interview, Carl Froggett suggests that if an organization has 30,000 events a day and just 1% are false positives, this can be a massive drain on work for cyber professionals.

When your opponent uses Artificial Intelligence then you must respond in kind; learn how Deep Instinct can assist your agency in today’s brave new world.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Everyone who has watched everything from Star Wars to Star Trek has never encountered some of the problems we see in space today: collisions and space junk. It just doesn’t make for a good story on the big screen.

However, the reality is that there will be 30,000 satellites launched before 2030 and we are encountering challenges in what is called situational awareness. In this application, situational awareness is the concept that a satellite must know where it is heading, and whether other objects in space may be on a collision course.

This is such a complex problem that companies like Kahan Space have had to take advantage of technology like cloud computing and artificial intelligence to make space exploration safe.

Today, we sat down with Araz Feyzi, one of the co-founders of a company called Kahan Space. The problem that is solved is simple to describe, but incredibly complex to solve space situational awareness.

During the interview, Araz gave a great explanation of the problem. For example, on the high seas, there is international law that has been established if there is an incident.

However, in outer space, there are no rules of engagement. If a satellite is heading towards an American satellite, there is no law or regulation to tell the satellite operators what to do.

This is such a complicated problem that Kahan Space was launched to enable satellite operators to be able to predict trajectories. The cloud’s ability to store and compute must be utilized to have a better outcome when there is an incident.

The term Araz uses is the popular “orchestrate.” Normally used for terrestrial data processing, it is increasingly being used for analysis of complicated satellite patterns.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Today, we have Will Laforest from Confluent explain how federal leaders can harness the power of data streaming.

We all know that data has exploded since the advent of cheap storage, remote computing, and the proliferation of the Internet of Things. Several lessons have been learned. First, just because you have petabytes of data doesn’t mean it can help in making decisions; second, if you delay acting on that data you can leave your agency vulnerable.

The Federal Data Strategy recognizes these concepts.

In this interview, Will LaForest unpacks the idea of getting insights on perishable data. His company, Confluent, was founded in 2014 by engineers who leveraged an open-source project called Kafka to enable systems to absorb data in real-time.

During the interview, Will provides guidelines on understanding concepts like low coupling, microservices, and data meshes.

The foundational concept is to allow federal agencies to ingest data rapidly and be able to take advantage of the plethora of information to assist in making decisions that need to be made rapidly.

The best example that Will LaForest gives is threat intelligence. When a malicious event occurs, time is of the essence. Rapid response can mitigate any damage that is done by many cybersecurity events.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Kenny Rogers once had a popular song where he sand, “There’s time enough for countin’ when the dealin’ is done.”

Well, there was a lot of spending during Covid and now is the time to reflect on how we could have optimized that spend.

In the studio today is Tom Voshell from Coupa. He will bring a new perspective on how to efficiently allocate resources. The focus is not on shopping for the best price; the emphasis is to admin that acquisition is a complex process and systems should be administered to make sure the spend is optimized.

The initial example he gave was the four billion dollars that is spend annually by the GSA on P cards. When used properly, this spend can result in a 25% savings. Combine that with properly administered points, this can allow an agency to have funds for much needed equipment or services. Tom Voshell details the difference between a proactive and a reactive spend.

In another example, if a person in Utah wanted to get landscaping, they may select a company. Perhaps they did not know there was already in place a negotiated agreement between the federal government and a local landscaping company.

There was no malice intended, but it is possible that the person making the decision had no idea about systems and procedures for getting a job done.

Tom Voshell recommends an approach that is systematic and user friendly. This is the way to optimize existing funds as well as leverage any benefits from using cards to purchase goods and services.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Donald Rumsfeld is famous for saying there are “unknown unknowns.” Today’s interview with OnSolve takes this concept down a practical road: once something Is known, how can you quickly inform people of the issue?

When it comes to the federal government, notifications can range an incredible gamut. A systems administrator needs to know if a server is malfunctioning in a data center; a FEMA administrator needs up-to-date information on weather conditions; satellite operators need to know if a collision is imminent.

OnSolve has been helping commercial organizations as well as the federal government since 1998.

Our guest today is Chris Hurst. He is no stranger to emergencies – he has served in war zones and has been responsible for life-and-death situations.

During the interview, he articulates a brilliant concept. Today, the concept of situational awareness seems to be general. Kind of like, having a balanced diet.

Chris Hurst takes the next step. He indicates that there is no monolith situational awareness. It should be thought of as a situational awareness that is applied to a specific use case.

Local police feeds must be structured differently from natural disasters.

Furthermore, Chris gives the listeners a great perspective on how each one of those organizations needs a varying level of depth in notification.

But is it not just making people aware, OnSolve is attempting to gather sources from hundreds of places to be able to have better learning on the risk side.

Listen for information on how your agency can benefit from understanding the range of options available when you consider risk notification.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Artificial intelligence in software development has been top-of-mind for federal technology leaders once ChatGPT was popularized. This concern is documented in the recent “Request for Information on Open-Source Software Security: Areas of Long-term Focus and Prioritization” which was issued in August of 2023.

Their concerns include the Secure Open-Source Software Foundation, incentives to secure open-source software, as well as research and development. If you are interested in commenting on this RFI, you may want to review a recent survey by GitLab.

They recently published its 2023 Global DevSecOps Report: The State of AI in Software Development. They surveyed 1,000 software professionals and asked about concerns ranging from data security to training.

Today, we will sit for an interview with Bob Stevens, the Vice President of Public Sector from GitLab to focus on this study and where results may be able to be applied to federal agencies.

One curious finding of the study was the fact that software developers spend 75% of their time on concerns that do not include writing code.

Because software development is changing so fast, 81% of respondents indicated that they needed more training.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

If you have ever raised teenagers, you know the phrase, “unintended consequences.”

In today’s world of federal technology, this concept can be applied to data storage. What are the consequences if you do not thoroughly erase data? It could be an open door for data leakage.

For example, what happens when your agency moves data from one cloud to another? Is it erased? How do you know?

Let’s talk about the 500-pound elephant in the room – a cybersecurity event. Today’s malicious actors have been known to place trojan horses in other areas of a system. The concept of data sanitization is a concern for many federal leaders.

Ok. We know we have standards for data erasure. Civilian agencies have heard of NIST 800-88 and the folks at the Pentagon know DoD 5220-22 M/M ECE. That is all well and good if applied properly.

Many breaches occur because of human error; the same humans are tasked with applying these procedures for data sanitization.

Maurice Uenuma from Blancco gives a great overview of some of the problems with effectively administering data erasure. He brings up some issues that you may not have considered:

In a world of feds at the edge, what happens to data stored on remote devices?

How to automate erasure to make it compliant and secure

End-of-life cycle issues apply to software development and hardware as well.

Scalable storage is great – what happens to the dynamic elements of data storage?

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

It is always nice to occasionally get out of the trenches to look at the larger issues. Today, we sat down with Michael Mestrovich from Rubrik. He has decades of experience in three letter agencies and has a perspective that is hard to match when it comes to getting a handle on current trends in cybersecurity.

Michael gives a quick review of current trends in cybersecurity legislation. He notes that many have overlooked something as simple as the Internet of Things. IoT is projected to have as many as 30.9 billion endpoints by 2025.

Much of this technology is quickly placed without proper understanding of vulnerabilities. He suggests that much of it is in a deploy-and-forget type of implementation. This casual approach can drastically increase the attack surface for a federal agency.

Michael moves on to some of the current threats that are facing federal technology leaders. In order to get a grasp on what is prevalent, it is possible that people in the intelligence community may struggle with sharing information on threats.

When it comes to Artificial Intelligence, Michael thinks that it can have a positive impact on security when used in areas like automation.

Resilience is a term that is popular among leaders at the DoD; but it has application on civilian agencies as well. Rubrik has proved itself over the years in knowing how to gain visibility into a network and then having the ability to create immutable backups that are a good strategy at preventing malicious actors from planting code in backup copies.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

This is John Gilroy

It is hard to believe that I have done over 1,000 podcast interviews.

Some guests get four hundred impressions on LinkedIn, and some get 4,000.

How do you explain the difference? -- keep listening . . .. Hit the music, Manny . . .

= = =

Ever since Covid, I have been doing lots of in-person interviews – at BBQ places, Fish Shacks, breweries; we have had fantastic success; most guests ask how they can leverage their appearance to increase reach and improve brand awareness for their company.

Let me share with you four ways to take advantage of your podcast appearance.

· Tell the story visually.

· Be specific.

· Make it easy to reach you.

· Ask

= = = =

Number ONE Tell the story visually – I realize this is counter-intuitive, but our small human brains react to images much better than audio or text. Studies have shown that your optic nerve is 40x faster than your audio nerve. So . . .

Make sure you have a great publicity photo. I have changed the publicity photo on LinkedIn for clients and have seen their followers double.

Even better, get a photo doing the podcast face-to-face; it’s not that difficult. You can ask the podcast producer if they can record at a conference. The “where” is not important.

LOGO When you do your promotion, people will see the image first. An image of a guest in a Zoom and an image of a guest in front of a microphone with a logo is like night and day.

You need three elements for a successful on-site interview: a microphone with a logo, a professional photographer, and an audio engineer.

MICROPHONE – A “flag” is the logo that appears on a microphone – make sure you have one.

PHOTOGRAPHER: The professional photographer will get you fantastic images for promotion, but also for your LinkedIn profile, and your website. You can use it when you ask to get on other podcasts.

AUDIO An audio engineer using a directional microphone can bring life to the interview. The listener hears noises in the background, it makes the interview authentic.

= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

Number TWO In order to be terrific, you gotta be specific. Before the interview, rehearse a short “origin” story and a “customer benefit” story, include details and colorful language.

Example: Yeah, we have been in business for a while now.

Example: We were founded in 2016 by two Google engineers who had a better idea of how to manage networks.

= = =

From there, develop statistics about the problem you solve. Listeners will remember the story, but the numbers will make it emotionally comfortable to justify listening to the podcast.

= = =

Covid has really had an impact on system administrators managing cloud applications; how has Covid impacted your log volumes?

Example: Many companies have increased the numbers they manage

Example:

· Before Covid we were managing 200GB per day in log data

· After Covid, we now manage 100TB a day in log data.

= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

Number THREE Make it easy to reach you.

This is equally true if you have a big company or a small company.

Example: just look me up on Google, my name is Dennis Szymanski. That’s hard. I have interviewed companies like Kenetica, Savyint, Ardalyst

How to make it easy: register an easy to remember website and redirect it to your company.

Example: I got a tough last name, Szymanski. The best way to contact me is with my website, federal tech podcast dot com.

My name is hard to spell, but the fundraiser is easy: bike for your beer dot com.

You can expand this to your call to action at the end of the interview. Once you have an

easy to remember website, then have a call to action that will benefit the listener.

Example: Go to FederalTechPodcast.com and download the scorecard on How to Leverage your Podcast Appearance.

= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

Number FOUR Ask.

Ryan Leveque once wrote a book with a one-word title -- “Ask,” let us apply “ask” to your podcast appearance.

Ask the host to mention the call to action verbally and on the show notes page with a link.

Ask the listeners to download the valuable PDF from the URL you mentioned.

Ask your company to include your appearance on the company website – you can slip it into a blog, a press release, or an event.

Ask your social media team to prepare for the release of the interview and then hit hard, especially during the first 72 hours. Personally, for each guest I do 25 Tweets, audiogram, LinkedIn, transcript, show notes with image logo, and link to company: email, paid advertising, and much more. If that is what I do, your team should double my efforts.

Ask your followers on LinkedIn to comment, not like. A twelve-word comment is worth a hundred “likes.” You can prime the pump by asking questions – “What do you think of a software bill of materials?”

Ask to get on other podcasts based on your appearance – now you have a website with a show notes page to reference when you approach other podcasters.

= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

Conclusion: how to leverage your podcast appearance.

ONE Tell the story visually, not verbally.

TWO Be specific.

THREE Make it easy to reach you.

FOUR Ask

I’d like to thank our guest, John Gilroy, moderator of the Federal Tech Podcast. . ..

View Details

Traditionally, a cyberattack would be identified, and the remediation process would begin. The effectiveness of this is questionable because not all attacks are discovered. Secondly, even if they were discovered, the malicious actor may have left files in areas for future exploits. Because of this logic, we see a new emphasis on threat detection.

In fact, in July of 2023, the Department of Homeland Security issued a report to Congress with a report called “Threat Hunting.” This nineteen-page report covers areas that include the number of services to review, the time required, and the number of personnel to deliver this service.

This initiative is one reason to listen to today’s interview with David Monnier, the CIO from Team Cymru. David is a seasoned threat hunter as well with decades of experience including a stint in the U.S. Marine Corps.

During the interview, David talks about challenges in threat hunting federal leaders contend with that range from lack of tools to undocumented baseline activity to the lack of executive-level support.

He begins with the simple identification of an IP address that a federal leader may have uncovered in a threat analysis. Many questions must be asked: Is it just you or is someone spraying the entire Internet? When was this discovered? What do other organizations have to say about this IP address?

David expands on what is called “pure signal.” This is a concept that gives you an understanding of the source of these events and what infrastructure this malicious code can be found in. Real threat intelligence gives you the tools to put attacks into perspective.

One final concept is although federal-based threat hunters have a great capability, not even sophisticated federal threat-hunting systems have the kind of experience in the commercial world to be able to understand the nuances of today’s sophisticated attacks.

View Details

Arthur C. Clark once wrote, “Any sufficiently advanced technology is indistinguishable from magic.” This observation certainly applies to Artificial Intelligence.

Unfortunately, there are federal agencies that aren’t quite enthralled with “magic”, and they do require some information on how AI derives its conclusions. Kind of like your high school math teacher asking you to show your work on that last answer.

Today, we have an accomplished practitioner of AI giving listeners an idea of what understanding AI is. The interview is based on a recent article Patrick Elder wrote called, “Explainable AI.”

The challenge is obvious – AI is based on bringing in massive amounts of data, it could be in the form of words, code, or images. This is all well and good if you are a high school student and want some help with writing a paper on, for example, Arthur C. Clarke.

The federal government is challenged with storing sensitive information and not all of it is permitted for collection to render AI effective.

Patrick Elder details three approaches: white, black, and glass box. The black box approach gives results and humans don’t know how they derive conclusions. The white box is transparent about how it gets conclusions. These are both contrasted with a model called the glass box.

During the interview, Patrick provided examples of explainable AI. If you would like to dig deeper, you can read his article, “Explainable AI: How XAI Puts the End User Back in the Driver’s Seat."

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Sometimes, you need to pull back and try to separate reality from the shenanigans.

During today’s interview, world-famous David Linthicum pulls back the curtain on many of the misconceptions of federal cloud technology and puts a focus on reality.

In some academic circles, David would be classified as an “iconoclast.” This is quite an impressive word that means a person who attacks or criticizes beliefs. The perfect summary for David’s latest book, An Insider’s Guide to Cloud Computing.

Let us just take a few of the opinions that go against common beliefs.

Page 33 “What if the best cloud storage is not always in the cloud?” Well, finally. It takes someone with David’s decades of experience to stand up to the “common wisdom” that the cloud is the magical elixir for all problems.

Page 87 “Edge computing will increase development and cloud computing cost threefold” David is stating the obvious. We know that sensors are everywhere from mountains to oceans, to satellites. In a never-ending attempt to compute at the “edge,” we can sometimes neglect to closely examine cost.

Page 106 “Cost is overlooked when considering best development and architectural approaches” Covid has caused many organizations to spend like a drunken sailor. Covid is over. Just because it is possible does not mean it is the correct approach for a federal agency with a budget.

Page 69 “When is Artificial Intelligence overkill?” Whether we like it or not, humans do tend to get obsessed with the most current shiny object. Unfortunately, they also apply it to every situation imaginable. In the early days of Excel, I once met a person who loved the flexibility of the spreadsheet so much that she used it for a newsletter. Right tool; wrong application.

During the interview, David expands upon where marketing people may have over-emphasized the strength of many cloud technologies.

Read the book to gain a better grasp on terms like “cloud native” and “cloud washing.” Sometimes, the best advice is a splash of chilly water in the face.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

When the history of Covid and federal information technology is written, historians will talk about the amazing ability to transition to remote workers. As in all history, when time separates incidents, one gets a more nuanced perspective.

It is true that massive amounts of effort were expended. That kind of pressure resulted in over provisioning of systems. From today’s perspective, it is obvious that this transition was not as optimized for cost as it could have been.

It makes sense, the major cloud service providers vary in ways they handle data and invoice for usage. It is difficult enough to understand the subtleties of one cloud service provider, nonetheless three. The good news, years ago (prior to the cloud), federal leaders dealt with multiple vendors. In this cloud era, handling several vendors can act as a check on over provisioning, and distribute services so there is no need to worry about down time.

During the interview, Melissa Palmer reviews the sudden change that took place three years ago. She suggests that technology like Hashicorp’s Terraform can provide users visibility into the system and the ability to provision, secure, and connect in an effective manner.

In fact, Terraform is used widely in federal systems, but is pretty much unheralded. In an effort to remedy this situation, Melisssa outlines the formation of a federal Terraform User’s group that would provide support and inspiration for federal users.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

When you use the term “data scientist” you normally think of an inarticulate introvert who is dazzled by numbers and has week social skills. Well, this interview with Aaron Pujanandez from Excella may change the preconception.

We start off with referencing an article from the Harvard Business Journal from 2012.

This was probably a conceit eleven years ago, but in the last decade we have seen cheap storage, available compute, and ubiquitous fast Internet. Perhaps the title is getting closer to the truth.

We begin the interview with having Aaron differentiate “data analyst” from “data scientist.” Many common themes including Python and being part of a team. From Aaron’s view, a data analyst may be charged with providing a visual depiction of data elements where a data scientist may delve into mor advanced topics like subtleties of Extract, Transform, Load, Machine Language, and code review.

One of the challenges faced by federal information professionals is the volume of data to ingest. During the interview, Aaron talked about many of the aspects of selecting data and making sure it is safe in transit.

Aaron provides the listener with his thoughts on selecting the right data, data quality, handling large volumes of data, data access and, finally, the all-important concept of being able to communicate findings to non-technical stakeholders.

There are no silver bullets here – just an opportunity to approach large data sets and artificial intelligence from a perspective that will give actionable results.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Akamai has been a well know partner in many federal technology projects for many years. Some of their activities are obvious – some not as easy to see as it may appear.

Rob San Martin is a twenty-year veteran of Akamai and sits down to give a broad overview of some of the ways Akamai is improving federal cybersecurity that may not be obvious to the common observer.

One: Akamai sees one-third of the world’s Internet traffic every day. Being in the “catbird” seat allows it to see threats that are not apparent to smaller organizations. Of course, Akamai provides this information as a paid service to commercial companies, but they also share this with federal organizations in a timely fashion.

Further, Akamai is developed a method to “anonymize” threat activity to share it with the larger cybersecurity community.

Two: “Privilege creep,” is an attempt to describe what happens over a period in many large organizations. A person may start off with one set of permissions and they grow and grow. After a few years, the person may have changed jobs and retained rights to see documents that no longer apply. Akamai can and assist with micro segmentation that can limit the extent of overprivileged.

Three: Many in the industry say cybersecurity must work despite users. This means that there is automation in place that can manage threats without humans.

For example, a federal agency had a serious misconfiguration. Normally, the process was to go to a generic database of common vulnerabilities, discover what it can do. Then, set up some kind or test bed for remediation. Finally, the solution is distributed over the system.

It is possible for Akamai to determine a weakness and assign a patch before the standard vulnerability lists even include it.

Akamai works in the background of many federal agencies to agencies to accomplish tasks like adding automation, setting up networks, and improving user experience.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

In the early days of the networking one could put together a simple diagram of computers, routers, and switches. The more complex it became, the more detailed was the diagram.

When you combine containers, services and virtualization, today’s networks make early systems look like child’s play. Containers have proliferated because they can house all the necessary elements to run in any environment. When you combine them into pods and clusters you can increase effectiveness; however, this next generation relies on services to communicate.

During this interview Branden Wood details how Tetrate offers a solution to this situation. They offer something called the “service mesh.” Essentially, it is a dedicated infrastructure layer that facilitates this service-to-service systems architecture.

Branden delved into the details during the interview, but the real value is, when constructed in a manner that can manage these services, it offers high availability. It can allow for encryption across systems. It can offer concepts like discovering what services are available, internal load balancing and compliance improvement.

One challenge for the Air Forces is to be able to deploy code rapidly from many locations. The Air Force has several “factories” scattered across the United States. Using Tetrate as their provider to allow encryption in transit for highly sensitive information. This means systems can be changed, altered, and improved in days, not months.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

We begin the interview with statistics on fraud from several organizations, including PBS, AP, and others. Covid fraud estimates range from $80 to $200 billion. One way to prevent future abuse is with a robust identity proofing platform.

The miliary likes to talk about “force multipliers.” This can also apply to technology companies who serve the federal government.

Let’s take Socure – a well known company that provides identity proofing for many federal agencies. While Socure was developing its expertise another company, Berbix was laser-focused on helping federal identity checks.

In June of this year Socure acquired Berbix – a force multiplier. This has given the federal government all kinds of benefits. This combination gives federal leaders best in class accuracy paired with unparalleled speed, and much more.

During the interview Eric Levine gives a detailed explanation of “DocV,” which is an abbreviation for Predictive Identity Document Verification. He gives a thorough explanation of passive and active identification methods.

The interview concludes with a review of how federal agencies can assist people in Hawaii with providing a frictionless way to access federal information and assistance.

Here is link to the white paper from Socure titled, “Predictive Identity Document Verification.”

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Covid forced federal organizations to move to the cloud. Federal leaders discovered a confusing world of multi-clouds, public cloud, private cloud, and even hybrid cloud. We have even seen federal systems using cloud tools to manage premises applications and data.

There is one constant variable: an organization must be able to identify users. Years before Covid, this was a small, isolated field of knowledge. However, the complex nature of the cloud has forced system administrators to gain an understanding of the identity ecosystem.

One crucial aspect of that ecosystem is identity management. Companies have had to adapt to the demands that include scalability, user experience improvement, and rapidly changing security compliance requirements.

This is an interview with Tommy Cathey from ForgeRock. He has deep knowledge of the whole identity management lifecycle and carefully explains to listeners the many aspects of identity. He gives a clear and cogent explanation of governance, access management, identity proofing, and even point access management.

One way to gain a better grasp of this field is to read the recent called ForgeRock Identity Breach Report. Combine this with the detailed federal section of the ForgeRock website, you will get a handle on complex terms like decentralized identity and federated identity.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

The Great Lakes used to have iron ore boats running from Minnesota to Ohio. The ship was not very agile but was unstoppable at 12 knots. There is a close parallel with the federal government.

It is such a massive entity that it is unstoppable when it sets its sights on a goal. However, when challenged with new threats, it has a difficult job altering course.

Right now, the federal government understands it is being attacked every second. Sometimes, the traditional methods can leave it vulnerable to attack.

In 2023 the Executive Office of the President released its strategy for cyber security. The 57-page document includes sixty-five specific actions to change the massive ecosystem of federal technology.

Today, we have Jim Richberg from Fortinet in the studio to break it down for listeners. His opinions are based on a twenty-year career in the intelligence community as well as decades of service in many organizations like AFCEA, the World Economic Cybersecurity Leadership Forum, and the Forbes Technology Council.

During the interview, Jim gives you the salient points. He suggests that the shift of liability from the government to commercial organizations is a major point. From a software development perspective, Jim Richberg argues that the shift to the left into incorporating security into software design is significant as well.

This episode will help you put the new strategy in perspective, and you can see how it impacts your agency.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

During the interview, Bryan Rosensteel applies his considerable federal experience in identification to help you understand where basic MFA can be applied and when to move on to more appropriate methods of identification.

Instead of just a mere six-digit code, you may want to use a physical device like a CAC card to prove your identity. In cases like phone access where cards are not practical, you can take it to the next level. A person seeking identity verification can be identified by technology to know where you are, what kind of connection they are using if you are deploying a usual device, and even the time of day.

Federal systems are being attacked every day; it is best to understand some of the options; you must understand some of the variations on “strong” verification.

View Details

Once upon a time, surveys had meaning. However, today, if you buy a toothbrush, you are sent a five-page survey on customer satisfaction.

Let us say you are trying to comply with the December 2021 Executive order to improve citizen experience with your federal website. What kind of feedback do you expect from a typical citizen who cannot take another survey?

Today, we sat down with Matt Chong from Federal Qualtrics. They take a different approach to improving a citizen’s website experience. Qualtrics has been in business for fifteen years and is used in eighty-five of the Fortune 100. Qualtrics has a unique way of listening to users: by leveraging unstructured data.

During the interview, Matt Chong admits that one can listen to a phone call and get a good guess at citizen sentiment. However, given limited resources, this approach does not scale. Qualtrics has the technology to look at conversational analytics. They can have a conversation and can generate an enormous amount of insightful information quickly.

Even if you had a staff of dozens, you would not be able to accomplish the speed this innovation takes from unstructured data.

Matt Chong shows you how to go from “listening” to “understanding” to being able to act on the information provided. You can automate the tedious job of call volume, website visits, and citizen profiles into one system that puts you in the driver’s seat when it comes to analysis.

Federal websites have gone beyond HTML and heat maps. The maturity of understanding citizens is at the next level – the level needed to be able to improve the customer experience at many distinct levels.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Advances in artificial intelligence are being released every day and being proposed as solutions for federal problems. Anyone who has raised children through their teen aged years is aware of the phrase, “unintended consequences.”

We must be careful not to be dazzled by modern technology and not realize what unintended consequences are in store before we understand the ethics of modern technology.

Today, we have Reggie Townsend, the Vice President, of Data Ethics at SAS in the studio. He provides listeners with some commonsense guidelines to use artificial intelligence ethically.

In addition to his technical expertise, he is a member of the National Artificial Intelligence Advisory Committee.

During the interview, Reggie talks about the problem in data collection. How do you know the data set the AI model was trained on? Is it a biased data set? How can you identify bias? SAS has worked at many levels of the federal government to solve some of these perplexing dilemmas.

It seems to come down to trust. A recent survey by Pew Research shows that 20% of Americans trust the government. Reggie suggests that one way to eliminate bias is to work with more diverse teams.

The government is responding to some of these issues of trust. The Executive Office of the President has seen this situation and has offered a “Blueprint for an AI Bill of Rights: Making Automated Systems Work for the American People” back in October of 2022.

SAS has a website dedicated to helping people gain a better understanding of accessing quality data in an ethical and human-centered world.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

The federal government has been told to move to the cloud since Vivek Kundra famously coined the phrase “cloud first” fifteen years ago. Unfortunately, somehow the “how” was not included in the prescription.

In an attempt to achieve assigned goals, we have seen agencies “lift and shift” on premises applications to the cloud. There is the checkbox complete. A simile here is you have a broken-down Fiat in your garage, you move to California and put the broken-down Fiat Spyder in your new west coast garage. Different garage, same malfunctioning automobile.

Why not take advantage of some the unique capabilities the cloud provides in order to leverage this cloud transition?

Today, we sat down with Brandon Hertel, Software Developer for Vidoori. We begin the interview by expanding on some of the flexibility the cloud provides and how a federal agency can use this. The focus of the discussion is coming to terms with the expression “cloud native.”

Brandon argues that “cloud-native” is an approach to software development, we take as an example a federal agency that wants to take an application to the cloud.

We begin the interview by talking about concepts that are part of being cloud native. Brandon Herte. Defines ideas like DevSeOps, Cloud Native Open Standards, micro services, and containers. From his perspective, a federal agency can take an application, move to the cloud, and then include these concepts in order to achieve the goals of scalability, flexibility, and being agile.

This is an interview that gives you a better understanding of some of the concepts of “cloud native.”

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Painting with a wide brushstroke, there are three kinds of data: data at rest; data in transit; and data in use. Today, we speak to the person who pioneered the concept of protecting data in use. Her name is Dr. Ellison Ann Williams and has an impressive background, having an MS in Mathematics, an MS in Computer Science, and a Ph.D. In Mathematics. Additionally, she served at the NSA for ten years and has a thorough knowledge of federal security requirements.

Let us state the challenge:

tech companies are scraping the Internet for as much information about users as they can. Storage is cheap, and they are running amuck. The regulation came in a delayed, haphazard, and geographically disparate manner.

On the other hand, this kind of information can assist communities to help solve common problems. Allowing cross-border and cross-sector collaboration can result in impressive results. It is possible that longitudinal studies derived from this “scraped” information can help in medical analysis.

Dr. Williams suggests that innovation in Privacy Enhancing Technologies (PET) can balance both requirements. Further, the technology that allows for advances in-store & compute can also help to provide PET innovation.

During the interview, Dr. Williams introduces homomorphic encryption. This is certainly not the place to dive into what it means for the federal audience. You may want to go to enveil.com/FAQ to start your understanding.

Collecting data is easy, figuring out how to use it to benefit humankind and, at the same time, protecting privacy is the new world we live in. Dr. Ellison Anne Williams has some solutions.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Most listeners have heard of Palo Alto Networks. Today, we bring in Eric Trexler to give us an overview of what the venerable Palo Alto Networks has developed to help federal agencies reach their goals.

Eric started his career as a U.S. Ranger and has held leadership positions in many companies. He has chosen to work for Palo Alto Networks because he views it as the largest cybersecurity company in the world. From Eric’s perspective, he views it as the one company that can make a significant difference in protecting federal assets.

He reflects on the thousands of point solution vendors he saw at the last RSA conference. Each one may have a valid solution to a specific challenge. The problem is that most large organizations may have between 40 and 120 products, all trying to work together. If you must add constant updates to these point solutions, it makes integration almost impossible.

The same problem was faced by the information technology community with platforms; Eric suggests that there is a strategic advantage to having integration baked in before ever seeing a system.

Automation is key in managing the challenges of running a safe Security Operations Center (SOC). Eric gives an example of the efficiency that can be accomplished with SOC management by referencing Palo Alto Networks. By using a platform approach, Palo Alto Networks SOC can be managed by ten people. This is amazing when you realize that Palo Alto Networks has acquired seventeen companies in the last four years – remarkable consolidation.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Definitions are always tough in the world of networking. The initial concept was all hardware: a group of computers connected through cards, routers, and cables. Oh, how things have changed in a mere fifty years!

Software virtualization allowed systems administrators to spin up “hard drives” in no time. This was so practical that it was applied to the network itself in something called a Software Defined Network. Unfortunately, it took several decades for hardware to catch up to this kind of virtualization.

The hybrid cloud has accelerated the adoption of virtual networks in today’s federal tech landscape. Combining networks means leveraging an old concept called Application Programming Interfaces, or “APIs.” They allowed two or more programs to communicate.

Unfortunately, this innocuous part of networking has become a target for malicious actors. During the interview, Patrick Sullivan from Akamai gives a broad background on the importance of understanding where APIs fit in federal network visibility.

Attacking systems via the API has become so popular that scraping content has gone from websites to the API itself; Patrick mentions a new phrase called, “API Scraping.”

Network managers demand visibility and awareness, it seems like they should start to consider one of the newest attack vectors, the API. There is some validity to starting to look at the API as the network.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Last year Americans lost $10.3 billion to online crime; contrast that with the estimated $1.3 billion lost to home robberies. Today’s interview with Dr. Zulfikar Ramzan from Aura gives our federal listeners ideas on how to protect your identity.

We have learned that when a person’s identity gets compromised, it can lead directly to their employer, an especially sensitive problem when considering people who work for the federal government.

In the cybersecurity community the gold standard for a detached perspective on understanding cyber threats is the annual Verizon Data Breach Investigations Report, commonly referred to as the DBIR.

This report reinforces many of the threats presented by Dr. Zulfikar. The DBIR shows that 74% of breaches involved the human element. This can be anything from compromised passwords to identity theft. In the corporate world, this can lead to financial compromise. In the federal world, it can lead to an international incident.

Let’s state the obvious: since Covid, remote workers have taxed the ability for systems managers to protect assets with simple username and password logins. Other ways to verify identity must be considered.

Dr. Ramzan has a PhD. From MIT and 60 patents. He was involved in a leading cybersecurity organization when he heard of the innovations coming out of Aura. As a result, he decided to take his impressive background and hone in on helping individuals protect their identity.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

A wise man once said two things can be true at once. On the one hand, federal law enforcement agencies are being bombarded with data. Petabytes seem to be leaking in from the roofs and seeping in from the basement. On the other hand, they are being pushed to give analysis quickly while being understaffed.

Not a problem to solve for the sight of heart. Into the fray steps Siren.

During today’s interview, Brian Gilkey explains that Siren was founded with the idea of using concepts from the semantic web to be able to absorb mountains of data, digest it, and then present the findings in an easy-to-use graphical manner.

Siren’s technology enables agencies to gather the most common data sources and most desired data sets. They could reach into the mysterious dark web as well as social media.

Brian expands on the dilemma facing federal agencies. Even if they have the funding to add analysts, it may take up to eighteen months to get them productive. The graphical capabilities of Siren allow the Matrix-like stream of ones and zeros to make sense.

If you are interested in learning more about Siren they have a free PDF titled “Investigating Data Driven Law Enforcement.”

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

It seems like everybody in federal information technology was at the AWS Washington, DC event a couple of weeks ago. We didn’t manage to interview Tyler Johnson from the floor, so we got him on a Zoom call to explain how his company can help federal leaders achieve the goals for their agency.

Tyler Johnson says that CloudBees can take all the point providers at the AWS event and wrangle them into one continuous build. This allows a kind of unified test and deployment for software pipelines.

Ok, let’s make this simple. A bee goes from flower to flower and gathers pollen. CloudBees gives federal agencies the ability to gather data from a wide variety of sources.

During the interview Tyler Johnson presented a scenario many federal techs leaders face. They must submit projects to a release board. If one uses traditional methods, it would be difficult to adjust artifacts or move them to different parts of the development cycle.

Because today’s systems are so complex, it is a major task to coordinate this test and deploy pipeline. The trending phrase used today to manage this is called “release orchestration.” This is important in the agile software development approach where you may have different work streams and many microservices to coordinate.

Listen to the interview to understand how CloudBees can give you a bird’s eye view of managing releases of software to be able to accomplish the noble goal of continuous improvement.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

The good news is that today’s digital technology allows for seemingly infinite variations on a code; the bad news is malicious actors know this and change their code constantly.

One of today’s responses to this constant attack is called “continuous” improvement. Quite a simple phrase to type, but difficult to accomplish. How do you continuously improve a complex software application that is used by a federal agency? How can anyone know what impact revised code will have on dependencies?

We all know that large teams produce the application programs used by the federal government. That code may go through an iterative process and can be improved through testing. Although agile practices may be used in development, the release can be compared to the waterfall process, when the code is released – it is released in full.

That means when a security patch is included, it is released in full – with only a partial knowledge of what implications it will have on today’s hybrid cloud systems.

Today’s interview with Sara Mazer from LaunchDarkly suggests that a better approach is to release revisions in a “modular” manner. A federal agency can take 10% of the code, release it and see what kind of problems develop. Once developers and program managers are happy with the functionality, they can release it to an increasingly larger percentage.

Sara goes into the way this works – with a “feature flag.” She describes this idea as a “wrapper” around the code that allows partial release. It also allows an easy rollback. The net effect is faster iteration by being able to test one version, correct it rapidly, and then move on to the next iteration.

During the interview, Sara talks about LaunchDarkly being able to improve citizen experience with websites. She indicates that this test and rollback can allow federal leaders to try out different citizen-facing websites to determine which ones work best.

Listen to learn ways to continuously update your federal systems.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

There are certainly many ways to approach security in today’s complex hybrid federal cloud. raditionally, a manager would look at a system and have an agent assigned to each machine. This could be a virtual machine or a real instance.

This structure goes back to the days of servers in the back room and megabytes of storage. Once you put a few “zeros” behind some data stores, then you have a problem with scaling. The business problem is simple: the old “tried-and-true” may have worked for years, but it doesn’t work in the cloud.

When Avi Shua launched Orca Security, he solved the scaling problem with a technique called “side scanning.” It is kind of like a football team taking a photo of another team’s formation. The game is not impacted at all, but a person can see what is going on.

This is what Orca Security does for the federal government. Doug Hudson explains that their patented technology enables a systems manager to take a “snapshot” of system information and not impact the environment. From there, Orca Security can look at system health.

Orca can go beyond blocking and tackling. Today’s emphasis on continuous integration means that there may be dependencies introduced that have unintended consequences. Just because a system is acceptable at noon does not mean it is safe after an update has been made. Technology from Orca Security allows to identify mis configurations that modifications may introduce.

During the interview, Doug Hudson indicated they did not need agents because their innovation allowed them to use native cloud technology to get information out of the cloud ecosystem.

Listen to the interview to get a better understanding of data leakage and the relationship Orca Security has with AWS as well as Snowflake.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

When 10,000 people show up to talk about cloud computing, what topics do they cover? Today, we sit down with Jeffery Kratz, Vice President, of Worldwide Public Sector Channels & Alliances to find out.

With a conference this large, there are hundreds of stories to tell. To focus on the needs of the federal government, we will look at how improvement with Amazon partners can help federal agencies reach their goals.

First, Amazon is targeting partners with Transformation Modules. This means that a partner can do the face-to-face work of understanding the needs of a specific federal program. From there, they can take advantage of one of these modules to deepen their understanding of how innovations from Amazon can help federal agencies reduce costs and improve security for that specific initiative.

Second, sometimes, great ideas come out of startups. Approaching solving federal concerns from a different perspective, Amazon is launching an AWS GovTech Accelerator for Startups. They take the modules to the next level.

The program includes a one-month virtual and combines it with in-person opportunities for technical and business mentorship for GovTech startups. It is one thing to have a great solution, quite another to be able to package it in a format that will adhere to stringent federal requirements.

It looks like this program will bring innovation faster to the federal government.

Third, we learn something new. According to the well-respected consulting firm Euroconsult, we will see 17,000 new satellites by 2030. Today’s ground station technology is based on outdated proprietary hardware and software.

Amazon is leading the charge when it comes to making today’s ground stations simple and scalable. Jeffery Kratz mentions the success of a company out of Japan called Infostellar with a new array of 26 ground stations serving the satellite and space community.

This is especially important for the newly created Space Force as well as existing programs at the Department of Defense.

Listen to the interview to catch up with how Amazon is responding to the dynamic needs of federal agencies.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Forty years ago, the boxer Roberto Duran famously said, “No mas.” Translated from Spanish, it means, “no more.” Sugar Ray Leonard was bombarding him with too many punches to handle.

The flood of data and the incredible size of data stores in the federal government is causing the federal government to examine how to store and categorize data more efficiently. We could be reaching the point where federal agencies say, “No mas.”

Today’s interview with Chris Brown from Immuta offers a solution: federated governance. This is a decentralized approach to ingesting data where tags can be automatically added, and data is classified by attribute-based access control.

During the interview, Chris talks about policy management through what is called mesh architecture.

Essentially, it is a method that is cloud agnostic and allows for scalability and reliability that today’s data stores can’t provide.

Most readers know about the federal data strategy as recommended by the Data Act and the Evidence-based Policy Act. They encourage something called “self-service analytics.” This means that a domain expert can retrieve data and derive insight from it without having to engage with information technology experts.

Immuta’s proprietary method originated with the company founders working with people in the Intelligence Community. Their challenge was sharing information about threats without compromising sensitive data. Their approach allowed for the automation of tags that could provide for the much-desired collaboration without revealing details that weren’t appropriate for consumption outside a specific realm.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

If you go to Google Trends and compare “Artificial Intelligence” to “Chief Data Officer” you will find a hockey stick for AI and a pancake for Chief Data Officer. It seems that many are ignoring the importance of the Chief Data Officer in assuring that the data used for AI is accurate.

The importance of managing data in the federal government has been reflected in the formation of the Federal Government’s Chief Data Council. In a remarkably mature analysis, they decided that they needed to ask fellow members what their priorities were to serve them better.

Mitre was commissioned to execute the survey and they chose Andrea Heithoff and Nick Pesce to write the report. There are two reports, both free. One is at a high level for the benefit of the entire federal community. One is much more detailed and available for the Chief Data Officers themselves.

They have taken a provocative approach to summarizing their findings. Rather than a mechanical representation, they decided to structure the answers into three categories: Model, Improving, and Challenged.

Listen to the interview to learn so much about success in today’s madcap world of exploding data streams, ransomware attacks, and federal mandates. Conclusions include the importance of foundational work that is needed to make AI successful.

Federal mandates are filled with suggestions about collaboration and sharing data, you can read what the CDO members think are the best approaches to this initiative.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Our interview is with Steve Forster, a data scientist from the DLA.

Steve started in the warehouse and through years of struggle and hard work managed to rise to the position of Senior Data Strategist. This parallels the transformation that the DLA is undergoing.

The DLA was formed in 1961 and has over 25,000 people supporting the Department of Defense worldwide.

To reduce costs and improve service to the military, the DLA is undergoing a transition from an outdated COBOL warehouse system to a modern system.

Much of the warehouse has sensitive military equipment and as a result, the data that controls them must be secure. When it comes to keeping data safe, Steve draws an analogy to owning a firearm. During the interview, he said, “And just like any gun, you keep in a locked cabinet inside your house, data has to be treated the same way.”

Effectively handling data in a large organization allows everyone to be on the same page. You need to have a common construct so everyone can have the same level of understanding of that information.

Steve had attended several sessions at the Qlik Public Sector World conference – a few highlighted the ability of Chat GPT to assist in data management. From a high-level perspective, Steve thinks AI will cut down his learning time for new technologies. From a practical, down-to-earth view, Steve has seen demonstrations where technologies like Chat GPT can help in classifying unstructured data to make it usable for leaders in much less time.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Consider this: a few years ago, a Navy officer would have a financial question about how a program was executed, and its t took 45 days to get an answer. Certainly, a contrast for a Naval Aviator’s need for speed.

Today, we interview two leaders in the Navy’s Financial Management Data and Digital Transformation program. They provide insight on a wide range of topics with a focus on giving leaders near real-time information on key decisions.

One fascinating phrase that both use is the term, “decision advantage.”

From their perspective, the next major conflict will be going to be done within an information space. Being able to make rapid decisions will be a key to winning.

It is kind of entertaining to consider the 45-figure mentioned about.

In 45 days, a company may have an update to a system. In 45 days, the amount of information received by an agency could overwhelm expectations and cripple the decision-making matrix.

The complexity of the problem is hard to imagine. “Jay” Smith, Analytics as Service Portfolio Owner, Financial Management Data & Digital Transformation Program - Department of Navy states that the Navy is responsible for 20,000 organizations all over the world. Each one needs accurate and reliable information to make decisions effectively.

David Magjuka, Director of Digital and Data Transformation - Department of Navy, Financial Management System expands on the importance of financial information. He views it as the connective tissue across domains like the business side and the operational side.

There’s hope – they had success with small gradual steps. Many times, they failed, but got up and tried again. When this incremental improvement takes place over time, you can make a transition in a large financial organization.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

When Covid hit, thousands of federal employees bumped up the number of visits to federal agency websites.

But let’s not forget the number of citizens visiting federal agency websites has skyrocketed as well. It is possible that these websites were designed before the epidemic with expectations of a certain volume of visits and transactions that were much lower.

The obvious logjam is data access, but an equally valuable concern was the experience the person had when engaging with the website. They could get frustrated with the interface and abandon the site. This can range from a farmer asking for a loan to a scientist applying for a grant for research on transmissible diseases.

The federal government has gotten enough feedback on these concerns to issue Executive Order 14058 which is titled, “Transforming Federal Customer Experience and Service Delivery to Rebuild Trust in Government.”

During the interview with Terry Miller from Karsun Solutions, he gives an overview of user experience on federal agency websites. He starts with the baseline, US Web Standard Design, and how it impacted the design of websites.

He applies concepts taken from agile software development to improve ways to scale and add resilience. One phrase he expands on is the concept of “product mindset.” He unpacks this idea to show how it focuses on values and empathy for the citizen. In the end, this process will increase engagement, save money, and improve speed.

Listen for tips on improving your agency’s website to make it scalable and resilient.

View Details

With all this hype about artificial intelligence, one key component that is getting left behind is the quality of the data that is used. To use a biblical reference, if you build your house on sand, chances are it will not survive the next storm.

Talend is a company that has a focus on data integration and management. In today’s interview with Tom Scurlock gives listeners an overview of how this can be applied to large federal systems.

We know that federal agencies are taking advantage of the cost savings of the hybrid cloud. The new challenges start with making sure you know where all the data is located. A new term is starting to be bandied about called “dark data.”

For example, an agency may collect, process, and store data. This information may have to be stored for compliance purposes, it could be duplicated, or it may possess key findings that are needed when a data set is constructed to assist in an AI project. Tom suggests that a flexible platform may help large organizations produce actionable findings.

During the interview, Tom Scurlock mentions the AI Bill of Rights. This is a starting point for the building of a policy on the safe and ethical rules for using artificial intelligence. Despite all the dazzling capability of Chat GPT, it is apparent that there can be algorithmic discrimination patterns in developing large learning models.

People don’t know what happens to the business information that is the basis for Chat GPT. The role of data privacy, especially when it comes to medical records, is included in this proposed document.

This preliminary AI Bill of Rights can’t be implemented unless organizations know where their data resides, who has access to it, and where federal compliance mandates must be applied.

View Details

Covid prioritized identity verification. It went from the bottom of the tech stack to the top. Many federal agencies have zero trust initiatives divided into segments; each group starts with identification as the first pillar.

Our guest Jordan Burris has years of experience in managing identities for large organizations. He has worked in commercial enterprise technology as well as the Office of Management and Budget. During the interview, he makes the claim that digital identity is a critical infrastructure. Listen to the interview to see how he defends that statement.

Jordan begins the discussion with delineating verification, authentication, and access management. From there, we learn about the priority the White House has put on identity and he reviews some of the major initiatives the federal government has – from the Pandemic Anti-Fraud Act to the National Cybersecurity Strategy.

The headline in identity verification focuses on waste, fraud, and abuse. Of course, that makes sense. However, Jordan Burris brings out another aspect of identity management: American citizens who encounter friction when trying to get services from the federal government.

These could be people without credit history, homeless veterans, or even people without identification.

One of the value statements from Socure is to make sure equity is central to their mission. When a company can help make a federal agency more accessible because of efficient identification, the goal of equity is pushed forward.

Quick and accurate identity verification is the key to unlocking the power of today’s world that has less and less paper and more and more digital identities.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

If you can distill today’s cybersecurity recommendations down to one word, that word me be “trust.” We have Executive Orders that talk about “trust” in digital architecture. Look at the motto for today’s enterprise architecture, “Zero Trust Architecture.”

The way most of us apply this trust is to garden a variety of humans. This may involve using some kind of a.”

system to assure that a person is a human they represent themselves to be. Kevin Bocek from Venafi states machines interact on networks more than humans.

It seems warmer to call them “nonperson entities,” but no matter what nomenclature you use these machines are subject to the same foibles as humans, even something as mundane as not working.

During the interview today, Kevin Bocek answers questions federal technology professionals may have when it comes to why they should be concerned. This is especially true when it comes to working in a cloud-native world.

Kevin points out that many may be familiar with a concept like Software Development Lifecycle but may not realize that we also have a Certificate Lifecycle that needs to be managed. He mentions the popular idea of including cybersecurity concepts early in the development process, what is known as “shift left.”

Traditionally, developers are under the gun to produce code in a typical production process. As a result, it is possible that they may not want to waste time with the laborious manual process of requesting and deploying machine identities. One approach might be to use systems that automate that process before the code is deployed.

Looking at your federal network and considering machine identity can be the first step in a zero-trust journey.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

When industries mature, users learn how to optimize them. For example, early televisions were huge, expensive, and black and white. Technology has made them small, cheap, and stunning. When the cloud was introduced 15 years ago, there was a rough transition with rough starts, failures, and much money wasted.

Recent figures from Gartner indicate that, in 2023, the global public services cloud market will increase by 20% to an amazing total of $591 billion. It is one thing to move to the cloud, and another effort completely to take advantage of all the savings and efficiency it can provide.

Frequently, cloud service providers are obsessed with storage and computing; app providers want to work with data efficiently. What falls between the cracks is the human who must interact with the system, and make it perform tasks that will help a federal agency reach its assigned goals.

During today’s interview, Billy Biggs from WalkMe shows the audience what kind of remarkable savings can accrue when a federal agency uses a digital adoption platform (DAP). Billy suggests that a DAP can provide an overlay that looks at the sequence of tasks that a user performs. In a simple example, some studies show a professional spends 45 minutes a day toggling back and forth between applications. Simple multiplication will show a waste of an expensive analyst’s time.

Why should a federal agency spend billions of dollars on software and not have staff use it? Just because an enterprise architect can design a sophisticated flow chart doesn’t mean mere mortals will implement its power. Billy Biggs references organizations that have had a drastic reduction in redundant and confusing workflow after implementing DAP solutions.

The whole idea of efficiently using the funding for technology has been noticed at high levels of the federal government. All we must do is look at Executive Order 14059 which talks about user experience to make digital systems more effective.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

For some reason, the topic of Artificial Intelligence has embedded itself into the common mind. It is so pervasive that one might walk into a local Seven-Eleven and hear a conversation about ChatGPT.

It may be fine for an undergraduate student to use generative AI to help write a term paper, but those who manage federal agencies must get serious about how Generative AI can help, or hurt, their agency.

Today, we sat down with Dr. Jennifer Summer from Accenture Federal Services. In addition to her academic achievements, she also has decades of experience in advanced technology as well as ten patents. She brings a great perspective to this discussion.

During the interview, she suggests that one should be open-minded to the capabilities of artificial intelligence but remember that federal data sets should be combined with generative artificial intelligence with an abundance of caution.

Stories about ChatGPT producing ridiculous messages are replete in the current literature. That is a situation that is not tolerable in organizations like the Federal Reserve or the Department of Defense.

She suggests that listeners look at what Accenture Federal Services is doing with its Generative Artificial Intelligence Center of Excellence. The Center is gathering top data scientists and software developers to see how algorithms can be applied to federal systems. The idea is to first simulate prototypes in systems with synthetic data to see how they would work before even considering any federal application.

Dr. Summer suggests that, when used properly, artificial intelligence can help with intelligence synthesis, help in coding, improve knowledge management, and even generate content. The Center even has the capability to evaluate environments where solutions need to be scaled.

Listen as Dr. Sample gives you example after example of how you can safely take advantage of the breakthroughs being made in generative artificial intelligence.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

When you look at the Executive Orders that have been issued you can see many references to user experience. The initial order, #14058, included thirty-six customer experience improvements across seventeen different federal agencies. This was followed up in March of 2023 with further fact sheets that detail improving the typical citizen experience with federal websites.

It is one thing to issue an Executive Order and quite another to implement it in the complicated world of federal technology.

We interviewed Frank Antezana, the CEO of a company called iTechAG. They have a good history of assisting federal agencies overcome some of the major challenges in improving the website experience that citizens have.

One may think that the experience is limited to the speed of the website or the look of the site. Although this may be part of the package, the real meat-and-potatoes of improving the citizen experience has more to do with accessing data quickly, reducing the administrative burden of these programs, and making sure the information provided is accurate.

In the 1970s, some federal websites were giving lip service to this idea, it was called Human Centric Design. During Covid, we had increased citizens accessing data and services from the federal government. Frequently, they had to get information from more than one place. If a farmer is applying for a loan, they may have to connect to the Department of Agriculture as well as the IRS.

Frank Antezana explains that reducing the administrative burden can be an overly complex project. Considerations must be given to navigation and having a thorough understanding of enterprise architecture.

Listen to the podcast to hear how iTechAG is setting up a lab to look at new tools and methods to help improve the citizen experience.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

In every spy movie, you see there is a scene where someone is in line at an airport and there is emotional music where the government agent looks at the passport, looks at the actor, and makes a decision. Well, the world of digital identities is much more complicated that any scene in a Bourne movie.

In our digital world, identification is such a hot topic we have conferences that have an extensive list of speakers who discuss aspects of ways a network can identify the person trying to log in.

Today’s interview introduces the listener to several aspects of what is called identity verification, especially how it is applied to federal systems. We have Matt Thompson and Jordan Burris from a company called Socure on the podcast. Both have serious credentials and each one brings a perspective to the discussion.

Matt opens the interview by boldly stating that Americans have the fundamental right to control our identity. During the interview, he reviews several ways systems like Socure can make sure each person attempting to verify their identity can have control.

Jordan mentions a little-recognized point of view. He argues that when you can accurately confirm your identity you can access a digital ecosystem regardless of your race, age, or socioeconomic background. Most do not realize that many federal programs are dependent on accurately making applications for grants or assistance. Each process begins with an accurate identification process.

Many aspects of identity management are discussed in the interview. Matt Thompson talks about levels of identification. If you want access to statistics on a federal system may be one level; however, legal documents may need advanced identity verification.

This interview just touches the surface of this topic – the subject matter experts even dive into topics like the dark web providing personally identifiable information for people to create “synthetic identities.”

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Our post-Covid world is full of clouds merging, remote data being collected, and a rash of new federal security initiatives. This is causing federal technology professionals to look for better ways to see what is on their network and then make decisions on how to use that data.

In the last six months, there has been a surge of interest in a company called Elastic.

During today’s interview with George Teas from Elastic, he shares with listeners the importance of accurately knowing what is on your system and how to manage data from multiple sources.

Many users need information quickly because they need actionable information. Elastic has evolved into an offering that can index petabytes of information in milliseconds.

In addition to speed, today’s hybrid network generates data from sensors from railroads, planes, and even geospatial information from satellite constellations. The range in type of information varies from structured to unstructured.

George Teas shares that two major concerns for the federal audience are data visibility and analytics. He uses the Department of Homeland Security as an example.

Some estimate that DHS may have thirty to forty different data sources to pull from. If there is an imminent threat, managers must be able to draw information from on premises servers, proprietary information, the public cloud, as well as the hybrid cloud. A flexible system must be used to derive information from this complex system.

Once you have visibility into your system, Elastic can assist you in using tiered storage. Essentially, you can segment data into cheaper storage, and frozen storage to reduce cost or even analyze the data quicker.

Listen to the interview to gain a better perspective on breakthroughs in data analysis and visibility in the challenging world of cheap storage, multiple systems, and high-security requirements.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

When the history of software development is written, they will look back at the decade that preceded 2023 as the era where developers started to pull pre-written code off repositories and assemble code in this “modular” manner.

Many federal systems are constructed in this “cut and paste” method. This is all well and good if the code can be trusted. But can it?

Today, Emile Monette from Synopsys shares with listeners some fascinating statistics that document this historical transition and he offers solutions as well.

During the interview, Emile Monette references a recent study by his company, Synopsys, called the Open-Source Security and Risk Analysis Report. They examined 1,700 codebases across seventeen industries and their findings correlate to what technology leaders think is happening.

Ninety-six percent of scanned codebases contained open-source code. Perhaps the federal government should consider ways to make sure this code is safe to use. However, there is even more surprising data that was released. Emile notes that, in addition to examining codebases more carefully, systems administrators should consider the basic “blocking and tackling” of software. He cites the figure that 89% of codebases were out of date and 91% contained components that were not the current version.

Synopsys has been in business since 1986 and has decades of experience in developing code for highly complex silicon design. This is a rigorous development that must have high assurance of security and quality. They are applying this in-depth knowledge to help the proliferation of federal organizations that are in a situation where they require to know that the code they are using is safe.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

When it comes to the federal government, the old news is “move to the cloud.” Today, the question is, how can your agency optimize its presence in the hybrid cloud?

Today, we sit down with a tech veteran, Michelle Rudnicki, the Vice President of the U.S. Public Sector for NetApp to answer that question. Her company has been involved in data management for decades and it is difficult to shoehorn her observations into a 25-minute interview. We have decided to look at some of the newer offerings from NetApp and see where they can be applied in federal information technology.

Michelle gave a great explanation of what “tiering” means for government IT. “Tiering” involves looking at the types of data one is storing and analyzing the most cost-effective way to store that data in the cloud. NetApp has a tool called “Cloud Checker” that provides visibility and transparency to accomplish that end. NetApp is collaborating with Amazon Web Services with an offering called “ONTAP.” Michelle explains ONTAP allows the least amount of friction when a federal system is seeking to make a change to the AWS cloud system.

“BlueXP” certainly sounds like a new rocket from SpaceX, but it is not. During the interview, Michelle explains that BlueXP gives you a view of your data landscape through one point of control. Sounds like visibility on steroids.

It looks like the hybrid cloud is reaching a point where many of the basics have been developed and now, we are at a maturity level where there is so much data to manage that fine-tuning can allow for significant savings.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Out of all the phrases that technology has generated in the past ten years, I think I like the phrase, “cloud washing” the most. The concept is that a traditional company would promote itself as always being cloud native. Kind of like being a Monday morning quarterback.

In 2023, the variation on that theme is “Artificial Intelligence washing.” Now that AI is a trending phrase you can see technology websites suddenly claiming the long history they have with artificial intelligence, or, what may be called, “artificial intelligence washing.”

This brings us to today’s interview with Chris Howard from Vectra. The company has been knee-deep in Artificial Intelligence since 2010. As Chris explains, they have honed that knowledge to be able to apply it to the world of cybersecurity.

During the interview, Chris explains how Vectra deals with an insider threat. They have focused on techniques to understand how an insider moves within a network. The overall approach to this is what Vectra calls “Attack Signal Intelligence.”

Without divulging proprietary information, Vectra has proven itself to be able to isolate and respond to a variety of malicious actors. Essentially, they have trained AI to think like an attacker and give the appropriate defensive response.

Chris describes a case study where a person was let into the network with appropriate credentials as a test to see Vectra’s capabilities. Merely by watching behavior, the algorithms from Vectra were able to isolate the malicious actor.

Realistically, attacks are so prevalent that defense is almost impossible for a human without an automated tool. The safety provided by Vectra doesn’t stop with the installation of the Vectra platform. It has been designed to continuously learn new threats and respond accordingly.

Listen to the interview to gain a better understanding of an advanced way to handle cyber threats.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Out of all the phrases that technology has generated in the past ten years, I think I like the phrase, “cloud washing” the most. The concept is that a traditional company would promote itself as always being cloud native. Kind of like being a Monday morning quarterback.

In 2023, the variation on that theme is “Artificial Intelligence washing.” Now that AI is a trending phrase you can see technology websites suddenly claiming the long history they have with artificial intelligence, or, what may be called, “artificial intelligence washing.”

This brings us to today’s interview with Chris Howard from Vectra. The company has been knee-deep in Artificial Intelligence since 2010. As Chris explains, they have honed that knowledge to be able to apply it to the world of cybersecurity.

During the interview, Chris explains how Vectra deals with an insider threat. They have focused on techniques to understand how an insider moves within a network. The overall approach to this is what Vectra calls “Attack Signal Intelligence.”

Without divulging proprietary information, Vectra has proven itself to be able to isolate and respond to a variety of malicious actors. Essentially, they have trained AI to think like an attacker and give the appropriate defensive response.

Chris describes a case study where a person was let into the network with appropriate credentials as a test to see Vectra’s capabilities. Merely by watching behavior, the algorithms from Vectra were able to isolate the malicious actor.

Realistically, attacks are so prevalent that defense is almost impossible for a human without an automated tool. The safety provided by Vectra doesn’t stop with the installation of the Vectra platform. It has been designed to continuously learn new threats and respond accordingly.

Listen to the interview to gain a better understanding of an advanced way to handle cyber threats.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

In March of 2023, the National Cybersecurity Strategy was released. Lots of pundits opined a day or two after the release; rather than an immediate reaction, it seems best to wait for a news cycle or two to look at the strategy from a better perspective. Well, what better perspective than a person who has worked inside the government, is an attorney, and has some serious credentials in the tech world?

Today, we sat down with Bill Wright, Global Head of Government Affairs at Elastic. The strategy document talks about the importance of infrastructure. Bill Wright comments that 80% of the critical infrastructure in the United States is privately held. One overarching purpose of the document is to try to fill in the security gaps in the private sector.

Bill remarks that the third “pillar” of the document may present the biggest challenge. This is the call for federal privacy legislation. Americans are sensitive to any kind of federal control over-identification. This alone may take three to five years to pass legislation.

What is new is a shift of security liability to the software makers. The Executive Order is trying to incentivize solutions providers to have basic security built into the offering, instead of the constant bolting on of software packaged to comply with a new initiative. Years of failure have shown how limited this after-the-fact approach is.

Because Bill has decades of experience in technology policy, he can see how some industry groups may balk. The example he gives is members of industrial water systems were not consulted before this mandate.

He ends the interview by stating the obvious: computer networks are now part of the critical infrastructure of the United States. Many of the security recommendations are made with an understanding of the role of CISA in the entire endeavor.

Listen to the interview to get a fresh, new perspective on the new federal mandate.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

When the history of technology of the twentieth century is written, one of the giants will probably be Ray Kurzweil. As most listeners know, he designed the first Optical Character Recognition (OCR) machine. The drudgery and error-inducing process of keying in forms was reduced.

Today’s interview is with Chirs Harr from Hyperscience. During the interview, he gives listeners an understanding of how OCR has become Intelligent Document Processing. He argues that the founders of Hyperscience produced innovation that combines expanding OCR’s ability and have it reducing clerical errors, improving performance, and deliver better customer experience. Not only that but the solution can also be scaled to handle the enormous number of documents.

The ability to scale saves taxpayers money. In a recent study conducted last year, there is a report that four agencies process over 800 million documents a year. This number seems high until you think about the size of your tax return last year.

Handling a massive number of documents applies to artificial intelligence. It may not have occurred to you that a large part of the information that is poured into machine learning is generated with a paper document.

Any effort at increasing the accuracy of that data means the results will improve.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

If you toss a baseball anywhere inside the Washington, D.C. beltway, you will probably hit a company that develops software. Well, what differentiates them? Size? Degrees the staff hold. The number of contracts?

Today, we sit down with a couple of software development experts from Excella to talk about completing more that the bare minimum for a project. They argue, quite cogently, that quality is the characteristic that is the hardest to achieve and has the most lasting impact on federal projects.

Two representatives from Excella are in the studio to argue their case. Doguhan Uluca and Keith Mealo from Excella sat down to discuss everything from shift left to legacy to elite performance.

The interview begins with a discussion about FISMA High Impact and FedRAMP. From there, they provide opinions on memory safe-languages and cloud-native development. They both have extensive experience with highly sensitive software development projects.

Some companies look at a project and set up a checklist and methodically go down the list. When the minimum is completed, the project is complete. Keith Mealo suggests that one must have full-orb comprehension of the system. When a person examines the consequence of deciding can you get an idea of solving the problem, not just checking a box.

During the discussion, the moderator tried to draw a parallel between an automobile getting a State inspection. A mechanic may see “examine the seat belt” and hit the check box. A better inspector may ride with the driver to make sure the safety device is in use. However, the master mechanic will notice a problem with the brakes while looking at the seat belt and not release the vehicle until the entire vehicle is safe.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Artificial Intelligence certainly has piqued the interest of the defense community here in Washington, DC. The Brookings Institution has a recent study that shows 307 vendors working with the federal government on many aspects of artificial intelligence.

Today, we look at a company that has been involved with helping humans leverage information from data for over 25 years. His emphasis is to be a champion of human and AI teams.

During this interview with Danial Serfaty the founder and CEO of Aptima. He suggests that artificial intelligence may not be the panacea everyone seems to be looking for. He talks about some of the skills needed to develop effective AI. For example, one must be careful during the machine learning aspect of development.

However, one can see some applications for AI in the federal government. One obvious example is diagnosis x-rays. Today, machines can see issues that may elude diagnosticians.

Daniel Serfaty is not saying that AI should take over the diagnosis, however, AI can be a tool that can assist in understanding medical issues.

Also, COVID has put an enormous amount of stress on hospitals. Let’s say we have a surgeon who is going into multiple procedures late in the week. Wouldn’t it be effective to be able to ask a medical system that has AI built int to it for an opinion?

A second example may be the proliferation of space debris. There is an estimated xxxx in space right now. We know 30,000 satellites will be launched by 2030 – how can anyone keep track of a myriad of satellites and thousands of pieces of debris? This is a problem that collecting information and making course projections could help ensure safe satellite transmissions.

View Details

Today’s interview with Mike Wiegland from Shift5 highlights how commercial technology can assist warfighters on the battlefield. Mike provides insight into how the commercial industry can help innovate with defense technology.

He has a military and technical background and has real-world examples of how operational technology can enable military systems to deter adversaries.

The federal government is being attacked relentlessly. Malicious actors are constantly looking in every nook and cranny to get an edge. Even if you dedicated all the estimated 1.3 million DoD employees full-time, it wouldn’t be enough to overcome the attacks.

As a result, federal agencies are looking to partner with private companies to solve some persistent problems. One can define “public-private” partnership in many ways, the most common are efforts at defining standards.

However, what happens when a commercial organization has a technology that can assist a federal agency? The most recent example was when Starlink assisted Ukraine with geo-intelligence. Ostensibly, the satellite system was a commercial endeavor, but it was used at the tip of the spear. The referenced mass of electronics circling the earth at 23,000 is a simple, visual example.

When one uses commercial products for a federal, or even a military application, it can be called “Dual Use.”

A more mundane example may be operational technology or OT. Frequently, these are sensors that monitor industrial or transportation equipment. An example may be monitoring sensors on aircraft.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

In the early days of the Internet, companies would design databases that could handle what they perceived as tremendous amounts of information. Memory was expensive, so those databases were optimized to handle related pieces of information, or relational databases. They relied on a system that used structured data language to pull up information.

It got to the point where two or three companies dominated all large systems. They became so ubiquitous that companies like Microsoft would acknowledge the dominance of Oracle by using it for Microsoft customer names.

The past fifteen years have seen memory get cheap, and virtualization has made storage a minor concern. Combining this with mountains of unstructured data being generated with sensors, phones, and occupational technology, new databases had to evolve.

One way to break through the constraint of a relational database is with a way to approach that that goes beyond Structured Query Language, or “Not only Structured Query Language.” MongoDB is an example of a database classified as NoSQL. Some have classified this as an object-oriented database.

When comparing them, some will argue that a SQL database is better when one has many writes; and a No SQL is faster when it comes to reads. Like anything, it is best to carefully evaluate your needs and select a system that fits your set of requirements.

MongoDB is an example of this No SQL approach. During the interview, Brent Leech provides an overview of why MongoDB has the performance characteristics that will serve as the answer to many federal data management goals.

The federal government is presented with many data handling challenges – they have vast repositories of structured data as well as daily accumulating unstructured amounts of information. The more you know about databases the better you will be at evaluating appropriate systems.

Follow John Gilroy on Twitter @RayGilray

Follow John Gilroy on LinkedIn https://www.linkedin.com/in/john-gilroy/

Listen to past episodes of Federal Tech Podcast www.federaltechpodcast.com

View Details

Leaders at NASA know the value of simulation. Before the Rover was sent to Mars, designers ran it though many scenarios on earth. Of course, they couldn’t reproduce the climactic conditions on the Red Planet, but they knew they had to try to simulate the environment before it left for a 103.3-million-mile journey.

Their pioneer work probably was developed out of training simulations for pilots. Why crash a $200 million plane if you can rehearse a “life-like” cockpit from a training facility?

Software developers are presented with a similar problem, but the variables are different. Instead of a pilot not being able to land a plane, they may design a system that exposes private information or a system that does not have the interoperability that the designers planned for.

The solution is to artificially generate data that is very similar to “live” information. That way, they can run simulations to learn about unexpected events when systems collide.

Thomas George from Vidoori is a data scientist from Vidoori who explains many of the concepts behind synthetic data and its application. For example, a simulation can be run with synthetic data that shows what the expected value of a financial transaction should be. If a set of data is very close to real data, one can tell if there have been any waste, fraud, or abuse possibilities.

From a data management perspective, one can take a large data set and “pressure test” the workflow to see if there is latency in the architecture.

Thomas George observes applying artificial data should be an essential part of large organizations that have sensitive data that needs to be protected.

View Details

Many phrases are bandied about that give the impression that they will solve the world’s problems. You know them as well as I do: artificial intelligence, machine learning, and even Robotic Process Automation.

This is an interview with Brian Baney from Aeyon. He has worked with many varying applications of RPA to solve federal problems and can give an objective perspective. During the interview, Brian gives a full orb analysis of the strengths and weaknesses of applying RPA to federal systems.

The discussion begins with defining terms. Rather than a panacea for all ills, Brian reminds the listeners that an RPA system merely responds to programming languages, not human languages. As a result, much consideration must be given to the design of the RPA system. This includes identifying data sources, organizing data, and knowing where a human must step into the process.

Brian’s company, Aeyon, has a fantastic track record with organizations ranging from the Air Force to the Marines to NASA. He gives unfiltered answers to questions presented in the interview.

For example, he willingly admits bots can add complexity to a system. One bot may be difficult to manage; what kind of unintended consequences will accrue when a group is interacting with each other?

The answer is to have experience with process mining and business process management to take advantage of the benefits RPA brings to the table. This includes reducing errors, eliminating mundane tasks, and freeing up time for federal technology professionals to use for value-added tasks like determining the impacts of multiple bots on a federal system

View Details

Big problems need big solutions. Let us take a look at the Veteran’s Benefits Administration as an example.

It has been reported that the VBA completed a record 1.7 million total claims in fiscal 2022. It disburses about $100 billion in benefits. That would certainly qualify as a major problem for any workflow scenario.

No management course in the world would teach that anyone can manually handle that level of complexity.

The role of process automation is to take a look at an overwhelming situation, like the one presented above, determine what the repetitive tasks are, and design an automation to speed up the delivery process.

That sentence is quite an easy one to write, however, there are many permutations to automation. Let’s start with how the data is stored before the automation is even considered. If a large organization chooses an architecture that involves data lakes or data warehouses, they limit itself to a central storage facility.

During the interview with Mike Beckley from Appian, he recommends begins with streamlining the intake process. From there, the manual processes can be automated and then you can make the workflow more efficient.

Design process automation can be established, but one has to remember that workflows can change and compliance requirements may update as well. A systems analyst must have a way to easily visualize the automation process so it can adapt to a changing world.

Appian has been a leader in helping federal systems automate, they are reported to be used in over 200 government agencies. Results have included a drastic time reduction in processing claims, increased accuracy, and elimination of redundant systems.

Listen to the interview to hear how Mike responds to questions about artificial intelligence, continuous improvement, and the Software Bill of Materials.

View Details

Today’s interview focuses on how the commercial success of Zscaler and its hundreds of patents can help large military organizations reduce costs and increase security of a cloud transition.

A good way to understand the challenges that the U.S. Army facing was by some of the comments that Ray Iyer, the Army’s Chief Information Officer, made during his recent exit interview.

When he started his position, he characterized the information technology the Army used as being decentralized. This resulted in duplicate systems and no standard way to prevent attacks. By making the transition to the cloud, he had to look above the stovepipes to see duplicate systems and optimize any investment they made.

Steve Kovac from Zscaler outlines how their technology can help leaders like Ray Iyer be able to reduce costs for a cloud transition from massive systems.

Steve starts by discussing Zscaler’s achievement of FedRAMP High level across the board. This is unique because it allows them to reach all levels of secure data in a military application. When that is combined with Zscaler’s Security Cloud, the DoD can provide communications that are not only secure but fast.

Essentially, Zscaler provides a secure “first hop” during an interaction with a federal system. It is secure because it can completely obfuscate the ability of a malicious actor to intercept the communication. In a humorous and entertaining phrase, Hansan Bae from Zscalar sums up the threat by saying, “If it’s reachable, it’s breachable.” Zscaler provides a solution that eliminates the ability for a malicious actor to “reach” a system.

The message is clear: use a trusted intermediary technology to provide you with secure, flexible, and scalable access.

If you would like to hear more about federal applications, Zscaler has an inaugural Public Sector Summit on March 8, 2023. It has federal leaders talk about overcoming the challenges of large systems that can enable them to implement Zero Trust.

View Details

Reliaquest is a very successful commercial company, and it has a set of skills that can be directly applied to the federal government.

Today’s interview is with Michael McPherson. He worked for the FBI for over 25 years, and he chose to work for Reliaquest because he believes its technology matrix offers the best hope for securing all networks, that included federal.

During the interview, he explains why he believes this combination works. First, his background can assist federal agencies to prioritize extant risks. Second, Reliaquest’s track record in the commercial world gives it skills in scaling and security optimization that are in defense inside the beltway.

Finally, Reliaquest has recently acquired a company called Digital Shadows This gives Reliaquest an unusual viewpoint on activities going on the Dark Web. Malicious actors, origins of attacks, and methods can be conveyed to the Reliaquest platform to give federal leaders a wider range of threat information.

Continuous improvement is a phrase that is popular in the agile and DevOps world. This idea applies to your agency’s cyber posture. Once a system is placed that can manage, detect, and respond to threats – it must be updated regularly.

Reliaquest has proven in the highly competitive commercial world that its system can act as a force multiplier to respond to cyber-attacks.

View Details

Federal technology leaders are pushed and pulled from many directions. On the one hand, they are expected to produce solutions that respond instantly; on the other hand, they have restricted budgets, unlimited amounts of unstructured data being transferred all the time, and concern about efficiency.

This is an interview with Zach Duncan from Pure Storage, he provides some solutions to these vexing problems.

Innovations from companies like Pure Storage can help you reduce costs for your data center. For example, they can provide 96% less rack space and reduce energy costs by 85%. That means you can use the resources you have more efficiently.

The proliferation of IoT, sensors and cameras can make ingesting unstructured data a nightmare. One way to manage that dilemma is with technology that is purpose-built for that endeavor. During the interview, Zach Duncan from Pure Storage outlines how technology like Flash Blade helps with unstructured data.

First, it says goodbye to traditional disk-based architecture. Flash memory is applied in a proprietary manner that allows for more speed and capacity. It is one thing to have improved speed, but that speed must be paired with systems that can manage unstructured data. Furthermore, when new features come available, you can take advantage of software updates.

What’s the bottom line? Every agency needs to abstract data before it is outdated. Examples are everywhere. For example, in February of 2023, there was a weather balloon floating across America. Tremendous amounts of structured and unstructured data were required to make projections about its activities and the results of it hitting the ground. A decision had to be made promptly.

That event was unpredicted, but that is the definition of preparedness. Your agency is challenged with being able to react to an unprecedented situation with a data strategy that will provide leaders with accurate, data-based decisions. A correct data management strategy will help agencies reach that goal.

View Details

When you hire a moving company, they send out a representative and they do a survey of what is in your house and give you an estimate. A much more difficult scenario is when a federal technology leader tries to get a handle on what they have in their domain and how to maintain it.

To continue the house analogy, if you have a piano it just sits there. In the tech world, virtual assets are constantly being fired up and shut down. Half of the house is in storage (the cloud) and your kids are building rooms off the garage (shadow IT). On top of it all, your cousin with ten kids is moving in (a new federal initiative), and, on top of all that, a thief is trying to get into the kitchen (malicious actor).

No wonder federal asset management is tough.

Fortunately, systems have been developed to assist in this frustrating endeavor. To get a handle on incident, problem, and change management, the Information Technology Library (ITIL) has developed 26 processes that provide guidance. A subset of those processes is called Information Technology Service Management (ITSM).

It is estimated that there is 20,000 Software as Service options for federal systems. All one needs is a credit card to start up systems that make life easier for the user and drive security people crazy. Once an effective view of what is running is established, one can eliminate duplicative services and remove dangerous code.

During today’s interview, Malcolm Davis from WWT expands on some basic concepts.

For example, one cannot generate any kind of visibility without automation. Additionally, a federal technology manager must be concerned with topics like maintenance expenses, license consumption, and managing outdated assets.

For example, there are dozens of tools that can be used for system management tasks. An organization may have five tools doing the same task. It is also possible that an agency is paying a license fee and maintenance on four tools they don’t use.

Once visibility is achieved then tool consolidation can take place.

Just because you have code that is not active doesn’t mean it is not a threat. Malicious actors have been known to bury code into innocuous data that will sit for months. Then, once triggered, it can start its inevitable lateral move.

View Details

When the concept of Cybersecurity Maturity Model Certification (CMMC) was first developed, nobody envisioned the roller coaster ride it would take since its inception with Executive Order 13556 in 2010 with its emphasis on Controlled Unclassified Information.

The goal was to assess and enhance the cybersecurity posture of contractors who serve the DoD. The target framework was a document from NIST called 800-171. Over the years the CMMC guidelines have evolved and so have recommendations from NIST.

Over this period of time communication from the DoD about CMMC has ranged from constant briefings to a period where the DoD was incommunicado. The result of that unusual series of events is a deadline in November of 2023, or possibly earlier, when companies will be expected to comply with the revised regulations.

Today, we sat down with Igor Volovich from Qmulos to put a framework around CMMC to give the 300,000 members of the Defense Industrial Base a handle on today’s status. During the interview Igor repeats his core message: don’t wait until the last minute to begin the process. You could end up looking at your competition in full compliance and your company running out of time.

He suggests that you start with a thorough understanding of the basis for CMMC, the NIST 800-171 document. Next, don’t forget your company is part of a matrix of vendors; you should contact your partners or affiliates to see where the shared responsibility lies. Finally, Igor suggests you speak to vendors who may be able to help.

Chances are, if you wait, you will be overwhelmed with work. The normal reaction is to seek out help at that point. However, you may encounter CMMC compliance experts with a serious backlog,

The lesson: understand the requirements, seek help from affiliates, contact people with expertise to help with the rough spots, and most of all . . . DO NOT DELAY.

View Details

Akamai has been around the security community for so long that they almost deserve the term, “venerable.” They first made a big splash on September 11, 2001. That was the day The Washington Post was overwhelmed by traffic. Some quick work from Akamai helped newspapers and organizations keep up to speed.

In its early years, Akamai was known as a Content Delivery Network that helped websites adjust to wide fluctuations in traffic and increase speed for website loading. After demonstrating that prowess, federal technology professionals understood Akamai to have a very geographically diverse content delivery network that had a deep understanding of network traffic and was agile enough to adapt to a wide range of conditions.

Building on this unparalleled knowledge, Akamai is able to assist in preventing cyberattacks on commercial and federal systems. This interview has two subject matter experts describe how this ubiquitous network puts Akamai in a unique position to serve federal cybersecurity needs.

Rob San Martin presents some innovations that Akamai has for technology partners. Traditionally, Akamai has been viewed as a unified product. A customer would be able to use the entire platform or not at all. Today, Akamai can split off aspects of its offering to fill in the gaps of some point-based solutions.

Patrick Sullivan details how Akamai’s entrance into FedRAMP High allows it to protect data for critical applications like law enforcement, emergency services, and healthcare.

Many listeners are familiar with the grueling process that gives solution providers the ability to offer cloud-based solutions to the federal government. FedRAMP was initially introduced back in 2011. It has evolved a rigorous set of rules that are accredited by the American Association for Laboratory Accreditation (A2LA). Based on a long list of controls provided by NIST SP 800-52, the base certification process can take years and hundreds of thousands of dollars to achieve.

Each agency must deal with data that has varying levels of security. As a result, the FedRAMP certification has evolved into three levels: low, moderate, and high. Each level ramps up the level of sensitive information it can handle, up to High – where a breach of this level of data could lead to a disaster.

Akamai has built on its platform to be able to serve federal clients in many levels.

View Details

Federal leaders will attest to the statement, “Security must be top of mind throughout an application’s development.” Today, we sat down with Jeff Gallimore, Chief Technology, and Innovation Officer at Excella to try to see how this noble concept can be applied to the amazingly complex and ever-changing world of federal technology.

During the interview, Jeff highlights the areas of continuous improvement, naming conventions, and the shift left.

If you were to watch a movie that entails police, you would undoubtedly encounter the abbreviation, CI, which stands for Confidential Informant. However, in today’s discussion of cybersecurity and software, CI brings a new meaning – Continuous Improvement. Jeff Gallimore describes CI as integral to keeping a software project safe.

The concept was broached in 2001 with the Manifesto for Agile Software Development. A group of developers met on a mountaintop and gave principles for improving software development. Near the top of the list was their concept of “responding to change,” what we call continuous improvement. Chances are, those experienced developers could not have anticipated the drastic increase in Internet usage and attacks. All this highlights the need to adapt code.

Moving on to other terms, when asked to differentiate between DevOps and DevSecOps, Jeff did not want to engage in the latest nomenclature debate. He thinks that federal leaders should focus on outputs, not on defining processes. In the time that a team debates DevOps, they can be moving on to another issue.

Another phrase was defined – Shift Left. No, nothing to do with politics, this refers to the traditional way software developers would write code. They would have a large whiteboard and diagram the process of moving from left to right.

In this context, a “shift left” indicates an interest in including cybersecurity at earlier stages of the software development life cycle.

Jeff also commented on the role of automation in managing large hybrid cloud projects. Automation can be offered as the remedy to this complicated circumstance. However, the range of point solutions and platforms merely reinforces the importance of humans understanding the flow of a project.

View Details

Technology changes so rapidly that, sometimes, people who are involved in federal technology may not realize how well-known companies are innovating to respond to the new threat landscape.

F5 is well known to the federal community; they started in the mid-1990s beginning with application delivery controllers. Even at its inception, the founders of F5 demonstrated an advanced understanding of traffic patterns and security with its load balancers.

In 2017, Francois Locoh-Donou started to steer the company into new waters. Because of their knowledge of networking, they had a good basis for understanding cybersecurity threats. They aggressively moved into the area of threat intelligence and web application firewalls. Their products were so well received in the commercial world that today, almost all of the Fortune 50 use F5.

During today’s interview, Peter Kersten, Regional Vice President of F5, shows how F5 innovation can assist federal agencies to hit their goals. One key is to focus on the API and not the data. After all, the federal government has petabytes of critical data.

Peter Kersten explains that the gateway to secure data is to protect access through the network. That is why F5 has tools like BIG-IP and NGINX. As a general rule, the BIG-IP offering looks at traditional network security and NGINX has a focus on microservices. He explains how they apply to federal data challenges in the discussion.

If you are considering F5 are using F5 and not taking advantage of all its horsepower, you may want to consider attending the Public Sector Symposium taking place at the Ritz-Carlton at Tyson’s Corner. The two-day conference includes sessions that give you continuing education credits as well as unpacking the power of the F5 approach to security.

View Details

When Vivek Kundra called for a cloud-first emphasis back in 2011, he never thought that it would be so popular that a situation would arise where data centers may be in short supply.

Everybody knows 70% of the world’s Internet traffic goes through Ashburn Virginia. In spite of massive numbers of data centers and constant construction or more, most do not know there is a 1% vacancy rate. Every data center under construction in Northern Virginia for the next 18 months is under contract.

We have documented the challenge of moving to the cloud in many other podcasts. We have discussed everything from funding, and security, to managing the transition. Who would have thought that the data explosion had caused a shortage of data centers?

As a result, when an agency starts to look for a data center, they may not have the range of selection they had as little as three years ago.

Today, we sat down with Stuart Dyer from CBRE, he is an expert in helping organizations select the correct data center for their needs. Because of the explosion in demand, getting a data center is not as easy as asking for five bids and selecting the best value.

During the interview, Stuart explains how an agency must have a thorough understanding of every aspect of the requirements for a data center. Size, redundancy, and security are among many factors. The reason is they may have to prioritize what they can live with and what they cannot. It is a seller’s market for data centers.

View Details

Years ago, one would enter a federal agency with a badge and go to work.  The server was down the hall and much of the security was based on the classic Personal Identity Verification (PIV) card.

The past five years has seen that model turned upside down.  During COVID, 80% of federal employees started to work remotely.  The move to the cloud has accelerated the need for a more flexible, yet authoritative, personal identification.

The hybrid cloud is starting to look like a maze of interlocking dependencies that make identification difficult.  For example, if a malicious actor manages to steal credentials, are there ways to develop an authentication that goes deeper than basic information? What are the limitations to Multi Factor Authentication?   

Remote authentication goes beyond workers doing a daily job.  Federal organizations like FEMA must be able to respond to remote needs.  If a citizen is in a flood, they need to prove their identification quickly and completely to get assistance.  Fraud and abuse are replete in the COVID financial assistance.  Many times, this theft is a result of identity that is poorly managed.

This is an interview with a company called ABBYY; a company that has a strong reputation in the commercial community for innovation with identity verification. 

During the podcast Brian Hettinger discusses how ABBYY applies a concept called “identity proofing” to identity verification.  This process aims to assemble information from a person that can be correlated with other data to establish identity.  

The White House is mandating federal agencies to improve customer service. Rather than delays through a standard identification process, agencies should consider new ways to make a transition from defense in dept to identification in depth.   That alone would be an increase in customer service by eliminating deceit and reducing cost to remediate stolen credentials.

View Details

All systems, including federal systems, are full of vulnerabilities. The question is, given a limited number of hours in the day and a limited staff, how can you optimize your resources to remedy this issue?

Well, the Cybersecurity & Cyberinfrastructure Security Agency has released a Binding Operative Directive that targets that concern. It was released on November 10, 2023, and is titled, “Transforming the Vulnerability Landscape.”

During today’s interview, Willie Hicks from Dynatrace will look at the whole issue of discoverability and what impact this new BOD will have on the federal community.

If you examine the BOD from 40,000 feet, it transfers the focus from the federal technology leaders to the vendors. Instead of having a security announcement buried on a vendor’s website, CISA suggests it be posted in a machine-readable format. This way, updates can be automatically sent out so they can be ingested.

The Vulnerability Exploitability eXchange helps users know if a given product is impacted. The military knows that if you defend everything you defend nothing. It allows links to the Software Bill of Materials so users can know about which vulnerabilities they should worry.

Finally, they look at something called the Stakeholder Specific Vulnerability Exchange. This reinforces the fact that not all vulnerabilities impact all federal agencies. CISA suggests that agencies consider vulnerability frameworks that can assist in reducing risk.

Will Hicks applies his years of experience in federal technology to unpack many of these concepts during the interview. He reinforces the concept of visibility. One cannont set appropriate priorities if one doesn’t know what is on the network.  Once that essential step is accomplished, then an administrator can use guidelines to set priorities.

View Details

It is all about alignment.

When you hit a pothole, you need to get your car aligned; if you do not your tires will wear out and can cause an expensive repair to the bushings and ball joints of your car.

Anybody who has worked on a federal technology project knows the world of digital potholes. Only in this case, the project halts because your agency’s data is not aligned with the agency’s goals.

During this interview, Tom Scurlock from Talend explains how to make sure your data is clean and dependable. If you decide to jump into machine learning, you will discover the importance of data scientists give to having reliable data.

The Talend website takes a quote from ancient Rome and applies it to today’s digital transformation. The phrase is “Fortune Favors the Prepared.”  You can take this to mean that if you are seriously looking at machine learning and artificial intelligence, it would benefit you to have a complete assessment of the quality of your data.

The federal government is taking this ancient maxim to mind as well. The Evidence-Based Policymaking Act of 2018 established the Chief Data Officer’s Council. Currently, there are ninety members. This is a strong vote for the federal government to realize the importance of data.

One of the results of being careful with data is it will allow agencies, and researchers analysts to produce reliable repeatable decisions and results. That sidesteps the inevitable arguments about the starting point of the analysis and gives most of the time to federal leasers for actual analysis and getting value for the data.

View Details

Once upon a time scientists would dream of the day when they could have enough information to make decisions based on data. Young readers may have to go to history books to see computer science majors take stacks of punch cards to a computer room so they can get an answer in the morning.

Fast forward to 2022, we have so much data we don’t know how to handle it. The overview is simple – gather up a reasonable number of data sets and pour it through an algorithm and then out pops the answer.

For example, back in 2017, it was reported that the DoD collected 22 terabytes of data a day. You would have to add many zeros to that number to see what they are collecting today.

As a result, people with a doctorate in mathematics, like Dr. Elsa Schaefer from LinQuest, must wrestle with questions about what data to gather to make valid decisions.

During the interview, she used terms like Data Wrangling, Machine Language Operations (MLOps), and data brittleness. It appears that there is as much an art as it is a science to competently gather data for decisions to be made. The term “brittle” is intriguing.

Let’s say you have an application with a large data set that is working well. It is quite possible that a systems architect can pour that data into a data set, and it may cause problems. Because it may cause a system to break, it is called “brittle.”

LinQuest is developing a platform to help federal leaders gain a better understanding of using machine data.

Data scientists try different scenarios and algorithms to see how they hold up. If you would like to pursue this topic further, you may want to download a fact sheet that details their Harness for Adaptive Learning.

View Details

When it comes to a federal agency making the transition to Zero Trust, sometimes, ya gotta bring in the big dog.

Greg Garret has written 24 business books and has decades of experience helping federal agencies solve complex problems. Seems to me he might be able to give a good perspective on understanding the federal government’s transition to zero trust better than most.

During the interview, Greg covered a wide range of topics on making this transition. He was asked to put on his CISSP hat, then his Vice President hat, then his CISO hat. The overall conclusion is no one company has the magic sauce. Each agency will have to review what options are available and put together a “stack” that fits their unique requirements.

The problem is, of course, it is not a trivial matter to understand all the permutations of offerings available to the federal government. In a timely manner, a survey must be done to know your current situation and then be able to know what combination will optimize the spending to accomplish your goals.

Greg Garrett offers a couple of solutions. First, Peraton has put together a “Test Kitchen” for federal technology called the “Ecosystems Lab Environment.” They have spent millions of dollars assembling proposed products and considering options that may have an impact on an agency.

Second, Peraton has put together a case study called, ”Guiding Federal Agencies on their Zero Trust Journeys” that includes case studies that put various combinations of technology into play.

View Details

If you were to do a “thought cloud” of technology, you would see the usual suspects, companies like Microsoft, AWS, and Google.

Nobody would include Elastic Search in this discussion, yet it is seen all over the place, perhaps the best kept secret in federal technology. Because it is capable of being modified in so many ways, it is difficult to categorize it. Elastic is a flexible tool that allows a federal agency to gain visibility on a wide range of fronts.

As a result, we see many federal projects where Elastic is in the background acting as the “glue” to get information from disparate sources.

Elastic is based on open-source code. During the interview, Christopher Towsend from Elastic defines the difference between Open Source and Open Security, referencing Elastic Search Technology.

Let’s toss around some cybersecurity concepts that may produce data for a federal agency. You may have systems that handle Security Information Event Management (SIEM), Security Orchestration Automation Response (SOAR), Extended Security Response (XDR), and even the lowly Endpoint Security (still seeking a snappy acronym).

Because this is such a complex topic, Elastic has put together a free report titled, “Elastic 2022 Global Threat Report: A Roadmap for Navigating Today’s Growing Threatscape”

View Details

There was a time in American culture when “living on the edge” was a social construct. Perhaps a person was a test pilot or motorcycle racer. In terms of federal information technology, we all live on the edge.

The edge referred to is, of course, the digital edge. The wall protecting federal data has long been breached and technologies like Zero Trust are being implemented to protect vital assets.

The term Secure Access Service Edge was coined by Gartner in 2019. It was a stodgy concept at the time and then COVID hit. The millions of remote sessions were causing technology leaders to evaluate the way they handled security. Suddenly, the acronym SASE was born, along with its unique pronunciation: “Sassy.”

During the interview, Dr. Tim Robinson from WWT gives a detailed description of SASE. He is uniquely qualified to speak to the federal audience because he was a Marine and has worked his way up to a Ph.D. in Computer Science.

A rough description may be cloud technology is being leveraged to optimize network connectivity to allow for consistent policy enforcement, centralized visibility, and scalability.

It is always good to look at an emergency and, later, do a course correction. An argument can be made that COVID forced technology leaders to use Virtual Private Networks (VPNs). After all, they were available and easy to deploy.

In hindsight, most can conclude that the VPN has strategic weaknesses. It is simply not optimized for the cloud.

Listen to the interview to get an expert’s view on ways to increase security and reduce costs to protect federal data.

View Details

It is not just lemmings that follow a herd off the cliff; technology professionals are garden-variety humans and subject to herd thinking as well.

If you try to keep up with trade publications you are subject to the editorial selection process of the folks who run the periodicals, newspapers, blog sites, newsletters, and podcasts. Catchy phrases pop up and it puts some joy into the drudgery of a daily tech column. You can take that from experience, I wrote over 500 weekly technology columns for The Washington Post.

Occasionally, you need to get your head out of the sand to get a wider perspective. For each of the past fifteen years, Verizon has provided the community with the Data Breach Investigative Report, or the DBIR.

During the interview, Melissa Gilbert tells listeners of the 23,816 incidents and 5,212 confirmed breaches included in the report. They gather information from over eighty organizations all over the world. She elucidates upon the difference between an event, an incident, and a breach. She details the data schema used for the report and explains the 4 A’s: Actor, Action, Asset, and Attribute.

You can get your own copy of the free report here: The Verizon Data Breach Investigative Report

One of the key findings was the 13% increase in ransomware reported in the 2021 survey. If your agency has an initiative to prevent ransomware, you can be assured that you are not diving into an arcane topic.

The conclusion is to focus on securing credentials. Most of these attacks start with credential theft and then move deeper into the system.

View Details

In today’s interview, Darin Curtis from Menlo Security gives an overview of how to protect against these kinds of threats. To describe this new category, he uses a curious acronym HEAT, Highly Evasive Adaptive Threats.

Malicious actors leave no stone unturned in creative ways to attack federal technology. We all know that the perimeter has been breached and we must rely on Zero Trust Architecture.

The next level of attack is to attack the word “trust” itself.

Traditionally, file formats like PDFs have been viewed as unbreakable. When most people get an email from a colleague with a PDF file, they would normally trust it. This is also true with Excel or Word documents that are transferred on a normal business day.

Today, these files can have malicious code injected into them.

Another approach is to take advantage of that “trust” in HTML code. Some malicious actors will disguise malware into HTML code, called HTML Smuggling. This time, instead of a PDF in an email, it may be an innocent link. This is made possible by HTML5’s ability for download capability.

During the interview, Darrin reinforces the concept that compliance does not ensure an agency is secure. Some studies show ransomware is one of the biggest single threats to government networks; the delivery mechanism can include these HEAT files.

If this interview piques your interest in Menlo Security, then you can download the free report titled “Modernizing Secure Access Through Zero Trust”

View Details

Ten years ago, it was a major accomplishment to move an application from a federal on-premises server to the cloud. Fast forward to 2022.

There is so much data flooding into a wide variety of clouds used by the federal government that the term “terabyte” is tossed around like a stickie note. Updated terms are being generated to make sense of the large data stores: phrases like “data lakes” and “data warehouses” are being coined to give some structure to the fire hose of zeros and ones.

During this increase, large secure systems are being tasked with a transition to the cloud – while preventing attacks and absorbing data twenty-four hours a day.

Federal leaders have seen the problem and have attempted to generate ways to understand data being presented from networks, storage arrays, servers, and much more. At this level, automation is the only way to be able to present information in a manner where someone can make a decision.

At one level, there is a challenge to get observability of federal systems. Taken to the next level, can we harness data to be able to make predictive decisions?

Today’s interview with Andrew Churchill gives a view of how technology companies can combine to help understand how the complex federal cloud can be managed. Rather than one ring to rule them all, he suggests assembling a team of disparate skills to be able to take advantage of unique skill sets.

Andrew gives an overview of this approach in the interview. He touches on automation and real-time operational intelligence. If you want a deeper dive, he suggests you attend an event called “Cloud Modernization with AWS and Qlik.” It will take place near the Metro in Rosslyn, Virginia on November 14, 2022. It will have subject matter experts with serious federal experience teamed with data scientists and analysts.

View Details

Attacks on the software supply chain have grown by an average of 742% a year since 2019. It makes complete sense if you look at several factors.

Years ago, a software developer would write code as part of a large project. It is quite possible they had the opportunity to examine all aspects of their code for vulnerabilities. That transitioned to developers grabbing blocks of code from libraries. Even then, they had at least a chance to review code grabbed from software repositories.

Federal mandates regarding cybersecurity are forcing systems administrators to speed along work by using code from software libraries. Unfortunately, remote work and cloud transition has made projects so complex that, if they tried to examine each line of code in the project, it would never get done.

One solution is to look at options for examining open-source code before being incorporated into a project. Today’s interview is with Dr. Stephen Magill from Sonatype. He gives a detailed description of how software developers can be assured code they develop is safe. He reminds the audience that, even with bespoke code, newer versions must be added along with improved code over the long haul.

Dr. Magill brings up an interesting aspect of software risk – artifacts. In this sense of the word, an “artifact” is a bit of code that can make binaries work in a system. As a result, they must be managed as carefully as traditional binaries.

If you would like to have more details about security and open-source software, consider downloading the annal report from Sonatype called the “2021 Start of the Software Supply Chain” from Sonatype.

View Details

Sometimes, success means being at the right place at the right time.

BeyondTrust has been active in the world of access control for decades. They have seventy patents and have a well-earned reputation for deep knowledge of secure remote access.

Before COVID hit, BeyondTrust was strong in a niche product category; when COVID forced commercial and federal systems to drastically increase remote access, BeyondTrust was ready. When cybersecurity experts started to recommend a concept called “Zero Trust,” BeyondTrust had “trust” right in their name!

BeyondTrust’s Josh Brodbent works with non-profit organizations like ATARC to be able to sit on committees to listen to the needs of the federal workforce. As a result, he has seen the reasons people succeed at access control and, unfortunately, how they fail.

One of his observations is that Multi-Factor Authentication may not be enough for a robust deployment of Zero Trust. Most experts would criticize MFA because it frequently relies on the public phone system to transfer code.

Josh points out that, in his experience, larger organizations have so many security controls that humans can get sick of all this MFA. If you get hundreds a day you may end up with “MFA” fatigue.

One innovation for BeyondTrust is a concept called “Just in time” access. When installed correctly, users can get access verification promptly because the system is structured with keeping the user happy.

Another term that Josh brought up was the phrase “dynamic access.” In the past, dynamic access was designed for on-premises applications. A few rules to consider, but not many. Today, we see private clouds, public clouds, hybrid clouds – a wide range of systems that can cause a complex process like dynamic access delay response.

View Details

Guidehouse is a well-known consulting company with a two-word motto, “outwit complexity.”  They have a track record of working with complex federal projects in areas ranging from health sciences to artificial intelligence.

Today we sit down with Christine Owen, whose two-word motto is “Identity Evangelist.”

The federal government has been encouraging agencies to get serious about identification.  We can list announcements from the Executive Office of the President, to NIST, Homeland Security, and even the Office of Management and Budget.

The motivation has been the COVID-inspired move to the cloud.  If it were just one cloud, there would be a few issues.  The complexity begins when clouds become dependent on other systems, whether it is an on-premises system or a hybrid cloud.  Identity seems to be the best way to assure security.

Christine has a legal background and, as a result, has a keen eye on the implications of the plethora of standards and regulations that are promulgated about identity. That is not to say she isn’t technically competent.

For example, she can articulate the three ways to become phishing resistant. Additionally, she can articulate very clearly the implications of Role Based Access Control and Attribute Based Access Control. 

There are organizations like the National Security Telecommunications Advisory Council that have run articles implying that the transition to Zero Trust may end up being an incomplete experiment. 

Listen to the interview to get a balanced and detailed observation on identity management in complicated federal systems.

View Details

Everyone working for the federal government knows that basic security training is mandated. Still, there are event that are reported in many agencies. That would beg the question – is basic training enough? If it isn’t what options are available.

As a rule, much of the training available is highly technical and best suited for systems administrators. However, we see malicious actors targeting everyone with phishing attacks. It would seem reasonable to consider a human-focused training regime. A good example is the excellent technical training offered by the SANS Institute.

We may have a situation where the top of the pyramid understands sophisticated attacks, yet the vast majority are vulnerable. In a recent article in Axios, they concluded that cyber attacks are easy to underestimate and under train employees in cybersecurity.

Erich Kron is a Security Awareness Advocate for a company called KnowBe4. They provide a long list of free tools to help you, and your team, understand some of the basic concepts to prevent social engineering, ransomware, and phishing.

During the interview, Erich details the impact of training on a group’s susceptibility to common phishing scams. KnowBe4 takes an actual attack, makes a reasonable copy, and incorporates that into the training they offer. Not textbook, but it very practical.

Listen to the interview to gain a better understanding of Return on Investment for security training and to see what Erich has to say about vulnerabilities is using phones for remote work.

View Details

In the commercial world, companies do competitive evaluations.  In fact, after hundreds of appearances on live television, I can confirm that each station has the other stations on screens around the office.

Well, why not look at the dark web and learn what the malicious actors are discussing? After all, “Know thy enemy and know yourself; in a hundred battles, you will never be defeated” is a well-known quote from Sun Tzu

Jole Bagnal from SpyCloud has credentials that are above reproach, graduating from West Point and having served at the highest levels in the federal government.  During the interview, he talks about fraud prevention, account takeovers, and much more. 

The Credential Exposure Report from SpyCloud provides some stunning numbers. It talks about a 64% password reuse rate, and 687 million records with Personal Identifiable Information being available in dark areas of the Internet. 

One of the trending phrases in software development is “shift left.”  This is a general term that suggests software development processes should include security measures from the jump, not after a system undergoes testing procedures.

In a similar vein, Joe Bagnal says that if a system administrator has advanced knowledge of a system attack, then appropriate precautions can be taken.

The discussion includes insight into threats from operational technology and brings to light some thoughts on advances in identity access management.

View Details

We are living in challenging times; citizen trust is waning.

Pew Research has a great quote about citizen trust “Only two-in-ten say they trust the government in Washington to do what is right “just about always.”

COVID has forced citizens to try to get information from the federal government about health issues, financial support, and taxes. Just recently, there was a drastic increase in citizens seeking information about federally backed loans. However, when it comes to citizens looking for information we can list FEMA, air travel, Social Security, and even small business loans as candidates for improved service.

The Biden Administration realized that many were getting frustrated with federal online services and issued an Executive Order (EO) in December of 2021 that gave a thorough list of ways to improve online services. These were thirty-six customer experience commitments spread among seventeen agencies.

The EO hits on subjects like consistency, self-service, secure identification, navigation, and even responsive assistance.

During this interview, Brian Chidester from Genesys provides ideas on how to improve customer service. He devolves into un-government-like topics like Return on Investment and having empathy with the needs of citizens. He suggests that there are systems that can leverage artificial intelligence to take predictive analytics to a new level.

For example, if you are contacting a call center, some systems can route your call to the best person who can manage your issue based on many factors.

Brian Chidester gives an overview of automation that can improve case status tracking and provide citizens information in the context of a secure federal system.

View Details

World famous Brian Papp from CISA has the best line when it comes to justifying the use of Artificial Intelligence in federal projects. “There is too much data and not enough people to understand it.” Bingo.

We are living in a world where the term “petabyte” is tossed about like a can of beans. Sensors are in the ocean, on moving vehicles, and in outer space. The federal government needs to collect data from fields as far ranging from financial derivatives to miles per gallon of a post office truck.

Unfortunately, universities and colleges do not offer degrees in artificial intelligence. As a result, much learning consists of anecdotes and case studies that may have applications in the federal world.

There is no doubt that artificial intelligence can provide benefits to the federal government. Studies have shown that, when deployed properly, artificial intelligence can streamline a user’s online experience, automate processes, and provide better use of data.

Paul Dillahay is the CEO of a company boldly called Empower.ai. His company bet on artificial intelligence before it became a buzzword at places like Gartner and Forrester Research. During the interview, he reviews the benefits of artificial intelligence at agencies like the GSA and the Commodity Futures Trading Commission.

Paul suggests that one should start with quality data to get the best results. From this basic goal, he recommends that any initiative must align properly with agency goals; clean data that is tagged and sorted may not have any value if it is producing the result the agency is charged with. The infrastructure must be optimized, and you should start with small steps to prove the application.

The conversation began and ended with trust. The Executive Order from 2020 talks about “trustworthy” artificial intelligence. It is one thing

View Details

It sure looks like the federal government is starting to recognize data is a strategic asset; managing that asset given today’s pace of volume and complexity forces leaders to examine a more systematic approach to handling data. 

Let’s review in 2021 there was an Executive Order called the Federal Data Strategy.  That same year, the State Department deployed its data strategy.  The DoD developed the Joint All-Domain Command and Control (JDAC2) to utilize data in today’s contested environments.  The Chief Data Officers Council now lists 90 members.  

Today’s interview is with Rob Carey, the well-known expert who boasts twenty-five years of increasing management authority in the United States Navy.  He begins with an observation that focusing on the platform or the infrastructure will miss direct systems administrators.  Effectively securing the data over a hybrid cloud will allow one to optimize this data stream in a fast and secure manner.

During the interview, Rob defines concepts like data lakes, data warehouses, and data lake houses. The focus is not to produce a tech glossary, the reason for the differentiation is to give federal leaders data-driven insights. 

He argues that today’s hybrid world must be bridged by a system that can leverage machine learning and artificial intelligence to classify and tag data in a fast-moving world. 

View Details

Software vendors will talk about an increase in productivity once the system is in place; one aspect that doesn’t get mentioned is the whole process of learning the system.  Right now, the federal government is in the middle of a drastic increase in activity.  Billion-dollar programs are being deployed and federal technology professionals will, most certainly, launch new systems to manage these initiatives.

One aspect of digital transformation is the basic one – learning the new system.  These new systems can be specialized scientific applications of more general tools, like project management. 

Billy Biggs from WalkMe suggests we look at a solution that has helped over 2,000 corporate customers. It is an overlay on a browser that can anticipate questions that come up when a person needs to be onboarded or learn a new system. 

Before COVID, there may have been some informal knowledge-sharing “around the water cooler.” Today, there is a high likelihood that a person may be hired and be expected to learn a new project management system while working at home, alone. 

In the new variation of “Home Alone,” this person may get stuck- and drive-up support tickets, losing valuable time.  Further, there is a much more diverse workforce, where assumptions about systems knowledge may not be even balanced throughout the team.

WalkMe uses artificial intelligence to see how most people would use a digital system and provides prompts to help in that change. Listen to the interview as Billy details how his solution increases productivity, and visibility, and allows users to scale.

View Details

Magicians work by misdirection.  The same is true in managing federal in federal information technology.

Let’s say you have done your work with compliance on your Infrastructure as a Service Platform and your Platform as a Service. Malicious actors know this all too well.  As a result, they look at the weak spot – the apps themselves.  It is possible that your eyes were on the wrong part of the system.

Some pay lip service to app security.  For example, when an Authority to Operate is granted, security of your apps may be given an overview, then ignored.  Sometimes, a review of app security does not take place until the three-year expiration.

If not continuously monitored, mismanag3ed apps can put your agency’s system out of control.  Line of business users may decide to sign up for a SaaS product without the security people being informed.  Systems can be misconfigured. Data can be misclassified. You may have people who have left your agency and there are unnecessary user accounts extant.

Securing apps on a hybrid cloud needs regular posture assessment.  In the commercial world there are products classified as SaaS Security Resource Management systems.  During the interview, Brandon Conley, details how a platform that examines apps can eliminate configuration issues, structure user permissions, and assist with changed in compliance requirements.

View Details

They stopped building castles with moats and walls when technology made them useless.  Today, our notions of perimeter defense are being negated by technology as well. This time, the network has expanded the number of threat vectors to the point where it is almost impossible to even catalog the endpoints.

Because federal networks are being accessed from mobile devices, there is an increased federal focus on enhancing cyber defense.  We don’t have to look further than the Office of Management and Budget to see them requiring Zero Trust Architecture.  ZTA’s first pillar is identity; identity is increasingly dependent on edge devices like laptops and phones.

Facts about cybersecurity are fascinating. Recently, Verizon released its Data Breach Investigations Report, a well-respected study of cyber security concerns.  They state that 62% of breaches were caused by partners to organizations, not from internal threats.  This fact alone is an interesting twist on the concept of the supply chain. Federal information professionals now must worry about external threats on mobile devices of contractors. 

During the interview, Tony D’Angelo provides suggestions for increasing Mobile Endpoint Security.  He suggests that humans may be more vulnerable with a phone because we typically drop our guard with something like a text message with a link.

Tony D’Angelo turns the table in the middle of the interview – he mentions a tool that is used to attack phones called “Pegasus.”  It can embed on a phone without any user action.  Lookout has become adept at identifying malicious code on phones. So good, they claim they can recognize a zero-day attack before it occurs.

View Details

The federal government is subjected to thousands of cyberattacks a day. When you combine that statistic with the tremendous gap in people that need to be hired for cyber defense, you can see the problem that is developing.

One way is to gain a better understanding of malicious actors move from network to cloud and then expand into a system. The log information is all there, the problem is that there is so much of it, a human doesn’t have a chance of trying to get a handle on the attack vectors taking place.

When it comes to processing enormous amounts of information, the classic Central Processing Unit has limitations. One way around this limiting factor is to use a Graphical Processing Unit, or a GPU. Today, systems architects are designing systems that can cluster thousands of GPUs to accomplish this tremendous task. There are some systems with 10,000 GPUs processing large amounts of data.

During the interview, Bartley Richarson talks about the role nVidia has in understanding the people attacking the federal government. He outlines basic concepts like data preparation, model training, and visualization. When presented with mountains of data and an incredible demand on compute, systems can be structured to help federal managers accelerate time to insight.

The basic example used is determining a best path for a firefighter to follow. There is a better example in outer space. For example, a traditional satellite will gather data and relay that data to a ground station. From there, it will be relayed to a place where the analysis is done. Each step along the way takes time.

One approach is to have a satellite that can do autonomous board data fusion in space. From there, it can use artificial intelligence to relay information to the federal government. This can be as pedestrian as a traffic report to a wide range of military intelligence.

View Details

Everyone reading this knows that the typical federal agency runs thousands of apps. We have seen reports that range from 600 apps to 2,400 apps. The number of apps is debatable, and the managing of these apps is the real concern.

According to Beau Hutto from Netskope, only 3% of these apps are managed. You can attribute that to a lack of funding, trained system managers, or a constant state of transition, but the fact remains that each one of these apps can develop into an attack point for the system.

During the interview, Beau Hutto talks about an innovative way to manage a network – through something called a Secure Access Edge Service. This is an approach where an intermediary platform can provide a manager with knowledge about the user, the device, and the app. This allows for the automation of task management in disparate systems. Beau Hutto argues that a system like this will reduce complexity, provide universal access, and be cost-effective.

In a related development, Netskope is organizing a group of network experts into the Netksope Network Visionaries. They will take years of combined experience to give observations about recent attacks and potential remediation efforts.

Netskope recently partnered with the U.S. Patent and Trade Office to upgrade its network management system. The USPTO understood that, even with a system that performing at an optimal capacity, technical changes were happening so rapidly they needed to move the idea of zero trust to the edge of their cloud-spanning system.

View Details

A simple Google search will tell you that we now have seven billion people and over twelve million active endpoints. These are devices that are moving on the ground and even in outer space.

It is unfortunate that the basis for managing endpoints on a network began as controlling individual desktop computers in a single building. Oh, for the simplicity of those days.

Today’s federal network has hundreds of endpoints to manage. Employees, contractors, phones, remote workers, identity management challenges – they all add to the complexity of understanding who is on your network. Many federal systems rely on “inherited” credentials for a person using the system, a sure recipe for failure in security.

“Non-Person Entities” sure sounds like it comes out of a science fiction movie. Managing devices on a system will have to incorporate understanding robotic process automation and its implications.

Malicious actors will treat each point as an opportunity to evaluate and attack. One of the most popular ways to attack today is with ransomware. Ivanti regularly releases its Ransomware Index. The report from 2022 indicated a rise I of 7.6% in ransomware. The war in Ukraine has increased wariness for all federal systems.

During the interview, Bill Harrod from Ivanti suggests that mobile end points could have high potential for allowing malicious code into a system. Systems called Unified Endpoint Management are becoming increasingly relevant for federal protection.

Bill Harrod explains that there is no perfect tool, best practices for containing this threat is to microsegment a system to control the “blast radius” of an attack. This resiliency should be based on a deep knowledge of what is on your network.

View Details

Ep. 18 Splunk’s SURGe: How to get immense value from a small group

A convincing argument can be made that Splunk is a leader in analyzing machine data for enterprise systems; ninety-two of the Fortune 100 use Splunk. They apply this skill set to the federal world and help enhance security and drive resilience. Because of this wide experience, they have seen many kinds of attacks like the infamous Solar Winds incident.

There are many ways to respond to this amalgamation of knowledge. One can hold that knowledge behind a paywall and charge people. What is interesting is Spunk’s Ryan Kovar decided to get a group of veteran vulnerability specialists and share that information with the Spunk community. They call it SURge.

Their goal is to be a timely advisor and provide research into cybersecurity challenges for large federal systems. Their first free white paper was, “Detecting Supply Chain Attacks.” They also have a podcast and a video series on YouTube.

For the federal IT community, the most important member of SURge is Mick Baccio, Global Security Strategist. He began his career in the federal government and has shown his expertise over two decades, culminating in being the Branch Chief, Threat Intelligence at the Executive Office of the President.

During this interview, Mick reviews the main challenges of securing federal technology: unifying logs standards, multifactor authentication, ubiquitous encryption, and reliable asset inventory. He suggests that a platform can assist federal agencies in reaching the much-vaunted goals.

One of the best quotes from the interview is, “Security is a data problem.”

View Details

Digital transformation in federal information technology includes improving the citizen experience. It seems like everything you need from the federal government needs a form. This is most obvious in areas related to health and taxes but has application across most federal sectors.

Improved citizen experience means forms completion reduces friction and gives federal agencies benefits like faster rendition, ease of scale, 24/7 service, and increased security.

This was obvious four years ago. In 2018, the U.S. Congress recognized that transitioning away from paper into a digitized form would reduce cost and increase citizen experience. That was the year they passed the Integrated Digital Experience Act that required agencies to make a transition from paper to digitized forms that were accessible on desktop computers and phones.

View Details

It is unusual to find someone with twenty years of experience in the U.S. Army culminating in a position as the Chief Data Officer of the United States Army Futures Command. However, even rarer to find a person with a PhD. in systems engineering and multiple awards for systems engineering achievement. Yet, we did.

Today, we are joined by Dr. Portia Crowe, Chief Data Strategist, Defense, and Applied Intelligence Accenture Federal Services. We are going to try to take that mountain of experience and distill it into a thirty-minute interview. The discussion focused on federal data strategy and best practices to achieve digital transformation in the federal government.

Dr. Crowe’s challenges have not been insignificant – she had to work in environments where bandwidth is severely limited, even without communications. As a result, her lessons are even more applicable in a federal environment where cloud capabilities and high-speed Internet abound.

View Details

Riverbed Technology has been helping federal information technology professionals get a grip on their networks for years. They are well known for Wide Area Network monitoring systems. They have a new offering to assist in today’s multi cloud environment.

As everyone reading this knows, COVID has drastically increased remote work, so it has gotten difficult to understand exactly who is on your federal network. Combine that with cheap storage and proliferation of edge devices, and you have masses and masses of data to worry about. We get to use the term “zettabyte” to describe the amazing amount.

So, you may be in a situation where you have many access points on your network and are making a transition to the hybrid cloud. You may have gone from five hundred cloud services to 5,000 cloud services. However, your opps budget and your opps tools have not changed. Your staff has remained the same as well.

One way to get a handle on managing the “mess” is to look at offerings that give you visibility on your network. Chances are you have Riverbed Technologies products on your network already. Why not learn about Riverbed’s new offering, Alluvio, to see if you can leverage existing equipment to help automate monitoring the complex new systems you are facing.

During the interview, Craig McCullough talks about how Alluvio developed and how federal leaders can take advantage of its power to help reach the goals of digital transformation and zero trust.

View Details

The Cybersecurity and Infrastructure Security Agency recently highlighted the five pillars of a maturity model when it comes to Zero Trust:  Identity, Device, Network, Workload, and Data. There is no accident that the first pilar is identity. Sean Frazier is a well-known expert in identity management. During this interview, he provides a perspective about this topic that ranges from compliance to assistance in proposal writing.

One can argue that this is an isolated emphasis until you realize that the OMB Memo 22-09 talks about centralized identification, multifactor identification, and device signaling,

It would seem reasonable to conclude that an effective identity management system is a key component in making sure today’s dynamic federal hybrid cloud is safe.

View Details

When the automobile was invented, nobody ever thought of a superhighway. After millions of cars had come off the assembly line, government leaders had to adjust and design highways that could accommodate six lanes and high-speed travel for everything from a motorcycle to an eighteen-wheeler. The same is true with cloud computing. Years ago, Vivek Kundra started to talk about taking baby steps to the cloud. Well, today we have multi-million-dollar data centers and huge cloud providers that are handing increasingly federal large amounts of data. Federal leaders have reached a point where “going to the cloud” is like driving a Model T. We have much more serious matters to consider.

DataDog is a company that can help federal leaders manage the cloud as part of a digital transformation. They help improve application performance, ensure reliability, and streamline multi-account account management. The net result is a transition to a hybrid cloud that is flexible, fast, and safe.

View Details

Veeam has been serving large organizations for so long that many have categorized it as a company that only does backups. Well, times have changed, and so has the approach to making data safe.  Jeff Reinhard begins the discussion by defining the terms:  backup, replication, and snapshots. From there, he dives into more serious strategic concepts. A decade ago, a systems administrator could rely on a backup solution and feel comfortable. Today’s hybrid systems combined with malicious attacks and petabytes of data make those days look like a walk in the park.

Federal systems are increasingly hybrid, meaning that protecting data must have the ability to integrate into several applications as well as legacy systems. Multiple clouds are one concept, but when you have dozens of systems with patches, upgrades, and critical data, it requires sophisticated methods to have valid backup copies.

View Details

Matt Thompson from Socure brings a wealth of experience to the topic of federal identity management. After a successful career in the military, he noticed that there was a lot of friction for veterans to get benefits from the federal government. He has been working with that issue of identification for his entire career. The company, Socure, has a similar origin story. The founder had a tough time establishing credit as a young man and noticed that there must be a better way to validate one’s credentials. Johnny Ayers launched Socure in 2012 intending to make it easier to establish identity. His goal was to verify 100% good IDs and eliminate fraud across the Internet. Socure has been a ridiculously successful company. This was a challenge that banks faced, too fast and they may not have valid identification, too slow and they may lose a customer. If an identification system holds up the process, it can be described as “friction.”

View Details

Today we sit down with John Cofrancesco from Fortress Information Security to get insights on the issues with the supply chain and the federal government. When it comes to federal technology, it is well known that bringing in chunks of software can introduce vulnerabilities. The real issue is not recognizing the code flaws, the issue is finding time in a hectic schedule to be able to remediate these problems. For example, CISA has something called the Vulnerability Exploitability Exchange that lists known software vulnerabilities. Companies like Sonatype offer surveys where they identify thousands of lines of code with structural flaws.

One of the vulnerabilities (the Log4J) is well known. Rezilion announced it had scanned 90,000 servers that still had this problem.

So, having a list of vulnerabilities is not the issue. The concern is cleaning up the federal code in an effective manner.

View Details

Years ago, McDonald’s had a sign in front of each restaurant that said, “Millions and millions sold.” It would be fair to appropriate this tagline to the world of your digital identity. That is because in 2017 147 million Americans in Equifax has personal data stolen. Oh, let us not forget the twenty-two million for the Office of Program Management and the fifty million from recent T-Mobile breaches. Because of this, it is important to understand some of the identification options for federal technology leaders. That is why we have Wes Turbeville from ID.me in the studio today.

Traditionally, identification started with a username and password. It has gotten to the point that so much personally identifiable information is floating on the Internet that major companies have initiated programs to eliminate this old-school way of authentication.

View Details

For years people in federal information technology have been talking about “silos” of information. One of the benefits of moving to the cloud was the possibility of removing some of this isolation. There may be other silos that may not be comprised of hard drives.  For example, when you limit your technical staff to a specific profile. That just encourages sameness of thought. The Proceedings of the National Academy of Science reported that a more diverse group is more likely to outperform a more homogenous team.   https://www.packard.org/insights/perspectives/why-diversity-in-stem-matters/

We are in a world of attacks coming from every quarter. Limiting yourself to one predetermined category of technical expert will set you up for failure. Think of it this way . . . if a football team has forty quarterbacks, they will lose every game; the same is true if they have all kickers.

View Details

Today we sit down with Jason Goetz, Senior Director, Public Sector, Snyk to talk about securing software for the federal government. When most people think of a supply chain, they think of a physical item. For example, a manufacturer in China makes a router and ships it to the United States. The impact of the supply chain has been thoroughly apparent due to COVID disruptions. However, most software developers today do not start from a blank slate, they start by grabbing code from a code repository and assembling it like Legos. In many situations, they follow agile development precepts and iterate and get feedback, but what happens is that the code is completed without any consideration for a security scan. Inevitably, issues will be found, and the development team must go back to work.

During the interview, Jason Goetz suggests there is a better approach, he calls it, “Shift Left.” 

View Details

Jay MacMillian, Executive Vice President at Booz Allen shares his ideas on digital transformation for the federal government. The interview covers the role of the cloud, citizen experience, and the steps to take for the federal government to move forward.

When it comes to moving to the cloud, Jay Macmillan observes that many agencies get transfixed by point solutions. He suggests that a better approach is to take a comprehensive view to the issue of cloud architecture. When that is done, the concerns of ending up in a point solution silo can be avoided.

Further, when an agency adopts the wider view, it gives them the ability to structure systematically. The idea here is to expect a change in future enterprise architecture renditions. That way, costs will be reduced when applications move in or out of a hybrid cloud.

View Details

The word that is normally used to describe “quantum computing” is game changer.  During this interview, Duncan Jones, the Head of Cybersecurity at Quantinuum gives you a better understanding of what quantum computing is and how it can help a federal agency reach its goals.

The discussion began with an attempt to define quantum computing.  Rather than a binary output, a quantum method gives a variety of solutions.  Many now talk about today’s CPU-based computing as “classical” computing.

View Details

In the studio today, we welcome Julie Smith, the Executive Director of the Identity Defined Security Alliance and Yash Prakash, Chief Strategy Officer from Saviynt.

One of the key challenges for the federal government to move to the hybrid cloud is establishing valid identity. The cloud can reduce cost and improve flexibility for federal information systems. However, it may come with security concerns.

On March 21, 2022, the White House released a statement warning of the threat of cyberattacks. Industry and federal leaders have responded to other warnings in a variety of ways. One of the overarching concepts that has been well received is Zero Trust. The lynchpin for Zero Trust is establishing the identity of the person being trusted with data.

View Details

Blue Ridge Networks has been in business for over twenty years. CEO John Higginbotham shares how network security began with untrusted networks and has become focused on Zero Trust Architecture. Today’s federal systems reflect commercial systems – there is a mess with data, there are application issues, and some systems have poor security. COVID has caused federal information technology professionals to reassess this status and revise many aspects of security.

COVID has certainly caused a drastic increase in connections taking place Along with that, there is also a need for more protection. During the interview, John Higginbotham suggests that a great starting point is multi-factor authentication. He agrees that frameworks from groups like DoD, NIST, and CISA can help in structuring a plan.

View Details

In the studio is Mark Forman, Executive Vice President at Dynamic Integrated Services. He has a distinguished career in and out of the federal government. His ability was recognized when he was named the first Federal Chief Information Officer for the Federal Government. Mark is on the podcast to provide observations about accomplishing digital transformation in today’s fast-changing climate. For example, here we are in March of 2020 and the federal technology is starting to recover from COVID and, now, cyber-attacks are occurring at a feverish pitch all over the world. How can the federal government hold its own in the superheated environment?

View Details

AvePoint is a well-respected Microsoft partner. In the studio, John Peluso, their Chief Product Officer, provides his thoughts on how a Microsoft platform can be a viable option for accomplishing a federal agency journey to Zero Trust. The transition to Zero Trust is increasingly becoming a federal mandate In January of 2022, The Office of Management and Budget set out nineteen requirements that agencies must follow by 2024.

In March of 2022, funding was approved for the DHS Cybersecurity & Infrastructure Agency to make it mandatory that federal agencies notify CISA of a breach within 72 hours.