‘We have to throw technology at the cyber problem,’ Pentagon CIO says

Pentagon Chief Information Officer Kirsten Davies appears at a Senate Committee on Armed Services subcommittee hearing on cybersecurity on Capitol Hill on March 24, 2026 in Washington, DC.

Pentagon Chief Information Officer Kirsten Davies appears at a Senate Committee on Armed Services subcommittee hearing on cybersecurity on Capitol Hill on March 24, 2026 in Washington, DC. Andrew Harnik/Getty Images

Defense Department Chief Information Officer Kirsten Davies said the Pentagon has to focus on “leveraging the fantastically skilled people that we have in a much more effective way.”

The Pentagon is shifting its cybersecurity posture to rely more on new capabilities to maintain its digital defenses rather than just bolstering its operational manpower, the department’s IT head said on Wednesday. 

Speaking at the Billington Cybersecurity Summit in Washington, D.C., Department of Defense Chief Information Officer Kirsten Davies said “we can't continue to throw people at the cyber problem; we have to throw technology at the cyber problem.”

Given DOD’s vast size, she said managing cybersecurity at scale means the department has to look at using “everything from automation to machine learning to actually AI,” since the threat environment and range of new and outdated IT systems across its operations presents “a complex Rubik's cube of problems.”

Davies noted that DOD maintains thousands of different networks and includes both civilian and military components, meaning that “this technology must be ready and available, and it must operate even when it's disconnected.” 

When one small IT problem can have a ripple effect across the entire Pentagon, Davies said it’s also important to “think about leveraging the fantastically skilled people that we have in a much more effective way.”

“As we embrace AI and leverage massive, massive quantities of agentic AI, how do we do that in a way that's supportive of our workforce and provides innovation across that?” she said.

Davies noted that the department is working to onboard employees that know how to actually use new and emerging tech capabilities, with DOD prioritizing relevant job candidates’ abilities over their educational backgrounds. When it comes to using AI, she said, this means focusing more on applicants who are skilled at prompt engineering — developing instructions for the models to output accurate information.  

“Why are we leveraging people for things that technology can do now? Like, let's really build skills and talent that know how to leverage technology very effectively,” Davies said. This mindset has already led to the department working to attract a new crop of cyber professionals.  

DOD began accepting applications in July for a new Cyber Registered Apprenticeship Program to bring more cybersecurity talent into the agency, with a particular focus on prioritizing skills-based hiring. The department ultimately closed its first listing four days early after receiving more than 15,000 applications, although DOD has said it plans to open additional rounds of opportunities.  

In a previous interview with Nextgov/FCW, Davies said her office was working to transition away from operating as a backend policy shop to taking more of an active role in DOD’s overall mission. She reiterated that mindset on Wednesday, saying that “reform is a big thing for us.”

Davies said this includes reforming the way DOD acquires new products, systems and weaponry. The first step in this process, she noted, was identifying policies and mandates that the department could whittle down or cut entirely — something that equated to more than 60% of relevant DOD guidance. 

Now, the department is in the process of carrying out part two of the initiative, which entails looking at the actual process that companies have to go through when it comes to approving new capabilities.

Davies said this process could take anywhere from six to 18 months, but noted that the department just tested out a platform that took that standard timeline “and shortened it to 17 seconds.” She said, however, that the speed of the tested platform is just one component of what the Pentagon must evaluate when it comes to transforming its acquisition strategy.

“That doesn't address what some of the root things are that I still want to address, which is, ‘Are we asking the right questions? Are we demanding the right documentation from software companies?’ Is the output of a 17-second process actually reducing risk?’” she said.

One major step that Davies’ office has taken is its decision to suspend the second-phase requirements for third-party assessments under the Cybersecurity Maturity Model Certification program. The mandatory security framework for defense contractors was stopped in July for a 60-day review by a CMMC Reform Task Force. That assessment period is set to end on Friday. 

Davies said the task force has received more than 1,100 responses to a request for information about CMMC’s next steps.

“We wanted to hear more from the defense industrial base on what was important for meaningful, dynamic cybersecurity," she added.

Davies’ remarks came the same day that Washington Technology reported that DOD is moving beyond a suspension of CMMC’s phase two requirements and is effectively implementing a binding regulation that would codify the pause.