Ideas

Compliance theater is over: What FedRAMP 20x means for every vendor selling to government

COMMENTARY | Attacks now move faster than human-paced patch cycles can keep up with and a compliance program built around periodic reviews will not catch them.

Ideas

Closing federal security gaps in an era of AI-enabled attacks

COMMENTARY | Agencies that align IT, security, data and AI leadership can be prepared for the speed and scale of tomorrow’s AI threats.

Ideas

CMMC Works. Now let’s sharpen it.

COMMENTARY | This is not the moment to loosen the standard. The Defense Federal Acquisition Regulation Supplement requirements behind CMMC should not change.

Ideas

CISA just changed the rules. Is your vulnerability program ready?

COMMENTARY | BOD 26-04 is a mandate about process. What it implies is a mandate about intelligence.

Ideas

3 security questions agencies should answer before Gold Eagle lands

COMMENTARY | The agencies that build that capability will define what good looks like for the next decade.

Ideas

The agentic SOC for today’s air-gapped environments: rethinking cyber defense in the age of AI

COMMENTARY | If you're not using AI to defend against AI, then the adversary has already closed the gap.

Ideas

The perimeter is gone. Security has to follow the data.

COMMENTARY | Many zero trust plans are still anchored to the old idea of the border. That protects a version of government IT that no longer exists.

Ideas

Modernization redefined: Why public sector IT leaders must put data at the center of AI architecture

COMMENTARY | Public sector organizations must put data first when making infrastructure choices.

Ideas

Don’t just pick the low-hanging fruit — harvest the whole orchard

The instinct is to point AI at low-stakes busywork. The bigger payoff is the high-stakes work everyone’s avoiding. Why don’t we have both?

Ideas

What the Telecommunications Act of 1996 teaches the federal government about governing AI

COMMENTARY | The federal government's responsibility is to establish clear rules before markets become entrenched.

Ideas

Federal zero trust faces challenges with AI agents

COMMENTARY | There is no realistic path where federal agencies opt out of agentic AI.

Ideas

How federal cybersecurity teams can adapt to a post-DOGE environment

COMMENTARY | The long-lasting impact of DOGE has been to accelerate a broader shift toward more disciplined, efficient and operationally resilient security strategies. 

Ideas

Stop automating inefficiency and scale AI the right way

COMMENTARY | Four operational realities that agencies must address before AI can deliver mission impact at scale.

Ideas

More data, less clarity: Why federal research oversight needs to change

COMMENTARY | Most federal research oversight still follows a familiar model.

Ideas

NSPM-12: The NSS cyber memo agencies cannot ignore

COMMENTARY | NSPM-12 dropped last week. Anyone who has spent serious time in federal cybersecurity should read it carefully.

Ideas

A practical blueprint for AI transformation in the public sector

COMMENTARY | Stop viewing AI as a standalone miracle and start viewing it as the engine within a larger machine.

Ideas

The path to better program management: a road still less traveled

COMMENTARY | In spite of important reform efforts and legislation, our government still faces problems in managing and implementing major programs and systems modernizations.

Ideas

What DOGE taught us about AI and federal workers

COMMENTARY | Mass layoffs have left thousands of federal workers unemployed and struggling to find their footing as AI accelerates disruption across the public sector.