Ideas

CISA just changed the rules. Is your vulnerability program ready?

COMMENTARY | BOD 26-04 is a mandate about process. What it implies is a mandate about intelligence.

3 security questions agencies should answer before Gold Eagle lands

COMMENTARY | The agencies that build that capability will define what good looks like for the next decade.

The agentic SOC for today’s air-gapped environments: rethinking cyber defense in the age of AI

COMMENTARY | If you're not using AI to defend against AI, then the adversary has already closed the gap.

The perimeter is gone. Security has to follow the data.

COMMENTARY | Many zero trust plans are still anchored to the old idea of the border. That protects a version of government IT that no longer exists.

Modernization redefined: Why public sector IT leaders must put data at the center of AI architecture

COMMENTARY | Public sector organizations must put data first when making infrastructure choices.

Don’t just pick the low-hanging fruit — harvest the whole orchard

The instinct is to point AI at low-stakes busywork. The bigger payoff is the high-stakes work everyone’s avoiding. Why don’t we have both?

What the Telecommunications Act of 1996 teaches the federal government about governing AI

COMMENTARY | The federal government's responsibility is to establish clear rules before markets become entrenched.

Federal zero trust faces challenges with AI agents

COMMENTARY | There is no realistic path where federal agencies opt out of agentic AI.

How federal cybersecurity teams can adapt to a post-DOGE environment

COMMENTARY | The long-lasting impact of DOGE has been to accelerate a broader shift toward more disciplined, efficient and operationally resilient security strategies. 

Stop automating inefficiency and scale AI the right way

COMMENTARY | Four operational realities that agencies must address before AI can deliver mission impact at scale.

More data, less clarity: Why federal research oversight needs to change

COMMENTARY | Most federal research oversight still follows a familiar model.

NSPM-12: The NSS cyber memo agencies cannot ignore

COMMENTARY | NSPM-12 dropped last week. Anyone who has spent serious time in federal cybersecurity should read it carefully.

A practical blueprint for AI transformation in the public sector

COMMENTARY | Stop viewing AI as a standalone miracle and start viewing it as the engine within a larger machine.

The path to better program management: a road still less traveled

COMMENTARY | In spite of important reform efforts and legislation, our government still faces problems in managing and implementing major programs and systems modernizations.

What DOGE taught us about AI and federal workers

COMMENTARY | Mass layoffs have left thousands of federal workers unemployed and struggling to find their footing as AI accelerates disruption across the public sector.