Ideas
Compliance theater is over: What FedRAMP 20x means for every vendor selling to government
COMMENTARY | Attacks now move faster than human-paced patch cycles can keep up with and a compliance program built around periodic reviews will not catch them.
Ideas
Closing federal security gaps in an era of AI-enabled attacks
COMMENTARY | Agencies that align IT, security, data and AI leadership can be prepared for the speed and scale of tomorrow’s AI threats.
Ideas
CMMC Works. Now let’s sharpen it.
COMMENTARY | This is not the moment to loosen the standard. The Defense Federal Acquisition Regulation Supplement requirements behind CMMC should not change.
Ideas
Gartner has confirmed the battle for authority is happening right now. Is your agency ready for the aftermath?
COMMENTARY | If agencies don't act, the consequences won't be abstract.
Ideas
CISA just changed the rules. Is your vulnerability program ready?
COMMENTARY | BOD 26-04 is a mandate about process. What it implies is a mandate about intelligence.
Ideas
3 security questions agencies should answer before Gold Eagle lands
COMMENTARY | The agencies that build that capability will define what good looks like for the next decade.
Ideas
The agentic SOC for today’s air-gapped environments: rethinking cyber defense in the age of AI
COMMENTARY | If you're not using AI to defend against AI, then the adversary has already closed the gap.
Ideas
The perimeter is gone. Security has to follow the data.
COMMENTARY | Many zero trust plans are still anchored to the old idea of the border. That protects a version of government IT that no longer exists.
Ideas
Modernization redefined: Why public sector IT leaders must put data at the center of AI architecture
COMMENTARY | Public sector organizations must put data first when making infrastructure choices.
Ideas
Don’t just pick the low-hanging fruit — harvest the whole orchard
The instinct is to point AI at low-stakes busywork. The bigger payoff is the high-stakes work everyone’s avoiding. Why don’t we have both?
Ideas
What the Telecommunications Act of 1996 teaches the federal government about governing AI
COMMENTARY | The federal government's responsibility is to establish clear rules before markets become entrenched.
Ideas
Federal zero trust faces challenges with AI agents
COMMENTARY | There is no realistic path where federal agencies opt out of agentic AI.
Ideas
How federal cybersecurity teams can adapt to a post-DOGE environment
COMMENTARY | The long-lasting impact of DOGE has been to accelerate a broader shift toward more disciplined, efficient and operationally resilient security strategies.
Ideas
Stop automating inefficiency and scale AI the right way
COMMENTARY | Four operational realities that agencies must address before AI can deliver mission impact at scale.
Ideas
More data, less clarity: Why federal research oversight needs to change
COMMENTARY | Most federal research oversight still follows a familiar model.
Ideas
NSPM-12: The NSS cyber memo agencies cannot ignore
COMMENTARY | NSPM-12 dropped last week. Anyone who has spent serious time in federal cybersecurity should read it carefully.
Ideas
A practical blueprint for AI transformation in the public sector
COMMENTARY | Stop viewing AI as a standalone miracle and start viewing it as the engine within a larger machine.
Ideas
The path to better program management: a road still less traveled
COMMENTARY | In spite of important reform efforts and legislation, our government still faces problems in managing and implementing major programs and systems modernizations.
Ideas
What DOGE taught us about AI and federal workers
COMMENTARY | Mass layoffs have left thousands of federal workers unemployed and struggling to find their footing as AI accelerates disruption across the public sector.
Ideas