Earlier this month, leading cybersecurity and technology experts from across federal, state, and local government, as well as the United States Department of War, came together with trusted industry partners at the Ivanti Public Sector Summit. The event, which was themed, “Modernizing Endpoint Security & Services Delivery,” focused on the challenges that modern organizations face when working to deliver services to end users while keeping sprawling networks and massive ecosystems of endpoints secure in the face of increasingly sophisticated cyber threats.
The cybersecurity puzzle facing modern government agencies and military organizations is getting harder by the minute. That’s because networks are extending further than ever, the need to gather and access data is driving a proliferation of sensors and other digital devices to the network edge that need connectivity, and demand for digital services is increasing across all facets of the organization.
Extending Out to the Tactical Edge and Beyond
Just how massive are the networks and endpoint ecosystems of modern government agencies and military organizations? Comments Captain Patrick Thompson of the United States Coast Guard made at the Summit paint a picture.
“The Coast Guard has about 1,500 different locations globally in which we provide services,” he said. “Many of those are manned Coast Guard stations, but we also have planes. We have helicopters. We have ships. And we also have a lot of remote sites. We have sites that are purely for communications [but also have] sensors on them.”
While patching and securing endpoints across 1,500 locations worldwide may already seem difficult and overwhelming, the sheer number of sites is only part of the problem. Environmental challenges also make it difficult to reach and interact with the equipment at many of these locations.
“Oftentimes [these locations] sit at the top of a mountain. Or they sit atop skyscrapers or large buildings. This high altitude enables the sensors and radios and antennas to communicate out to shore and find boaters in distress,” explained CAPT Thompson. “As you can imagine, in places like Alaska and up in Maine, there are sites that you need a snowmobile or something to get to.”
The need for connectivity is even forcing some government agencies and military organizations to ponder extending networks to previously unimaginable places – like the depths of the sea. But with every challenge that comes with extending the network even further to the tactical edge, more questions about endpoint security follow.
“I was reading an article the other day about submarines and underwater drones in the ocean, and the need to create connectivity for those devices so that you could change the logic of the drone in the field,” Mark Treleven, Lead Field Chief Technology Officer at Ivanti, told Summitt attendees. “It was thought-provoking from a networking perspective. How do you do that? But more importantly, how do you protect those endpoints and make sure they stay on mission? You’ve got subs that are essentially floating, underwater SCIFs.”
But it’s not just unmanned aircraft and underwater vehicles driving the extension of the network to the tactical edge. Numerous panelists at the Summit talked about an expectation younger generations have, demanding access to data, digital services, and connectivity wherever they’re operating.
“The generation behind us has an expectation that we’ve never seen; that there will be connectivity and the ubiquity of data throughout their roles, and they’re going to push us really hard for that,” said Mark Krzysko, the former Principal Deputy Director of Acquisition Policy and Analytics for Enterprise Data at the United States Department of War. “Putting my iPhone next to my iPad and having it sync up and ready to go in a matter of seconds is going to be an expectation.”
As Farhan Saifudin, Director of Federal Systems Engineering at Ivanti, explained, this expectation will soon extend into even the classified and air-gapped spaces.
“Over the last decade, we’ve been focused on enterprise use cases and enabling what I call the ‘knowledge worker’ or the ‘desk worker.’ Bringing enterprise email and collaboration apps on modern mobile operating systems,” he said. “What we’re now starting to see is the frontline worker use case being expanded upon. I think we will absolutely start to see mobile devices at the tactical edge and in classified spaces.”
Unfortunately, this expansion of the network and the distribution of mobile endpoints beyond the office to the very tactical edge is coming at a time when cybersecurity professionals are already at a disadvantage – scrambling to mitigate network vulnerabilities before AI-enabled malicious actors can exploit them.
“AI has a lot of potential. It also has a lot of peril. There’s good. There’s bad. It introduces new risks. It introduces new opportunities,” said CAPT Thompson. “Is it going to help the attackers more or the defenders more? Right now, I’d say it’s helping the attackers more.”
If the Summit made anything clear, it’s that government agencies and military organizations face a difficult task: expanding networks and delivering essential services while still protecting those networks and sensitive data from more capable adversaries. So, what is needed to protect these mission-critical networks?
Inventories, CDM, and New Approaches to Patching
With so many new endpoints and devices getting connected, it’s increasingly essential that government agencies and military organizations know everything on the network.
“Why are asset inventories so important in these circumstances? The quick and pithy response is so that we can know what to protect. You can’t protect it if you don’t know about it, and that’s a problem in the government,” said Kevin Walsh, the Director of the Information Technology and Cybersecurity Team at the U.S. Government Accountability Office. “There’s shadow IT. We’re also seeing IT come online that wasn’t traditionally considered IT because of the Internet of Things – [things like] industrial control systems and other systems at the edge that traditionally weren’t really considered hackable that are now hackable. Your refrigerator may now be a target for Chinese espionage. Who knew?”
However, it’s no longer enough to simply know what is connected to the network – especially in the era of Zero Trust cybersecurity.
“The first aspect is, what do you have on your network? If you want to protect it, you have to know about it. The second aspect is who is on your network? Managing identity is a big deal. The third aspect is what is happening on your network. Looking at the traffic, seeing what’s going on. And the fourth aspect is how to protect what’s on your network,” said Walsh. “We found that agencies are generally doing okay at those first two things: what’s on your network and who’s on your network. The latter two things, not so much.”
This gap in government cyber defenses makes continuous diagnosis and mitigation (CDM) tools essential. But it’s equally important to identify and eliminate vulnerabilities before malicious actors can exploit them to keep them off the network. However, as CAPT Thompson explained, traditional patching approaches can be difficult as mission-critical networks and connected devices extend into locations people can’t easily reach.
“Making sure that we have solutions in place where patching can happen quickly, can be fully automated, and can have resiliency and redundancy is incredibly important,” CAPT Thompson explained. “Because, if these systems went down, we’d no longer be able to communicate to mariners in distress.”
With AI helping malicious actors identify and attack vulnerabilities faster than cybersecurity and network teams can patch them, agencies also need faster patching to keep pace with the speed of the threat. That could involve leveraging AI to automate patch management.
“We need to be using AI where we can with governance, with guardrails, to be able to deliver the patches faster from the vendors to the individual systems,” explained Illum. “Vendors are coming out with patches quickly. We need to be able to get that to the devices and be able to install them as quickly as possible.”