To drive modernization and the mission forward today’s federal IT leaders need four essential elements: technology, innovation, cybersecurity, and knowledge management. At this year’s AFCEA Bethesda Emerging Leaders Winter IT Luncheon, leaders from the federal government and industry discussed the how to navigate their path forward embracing transformation while continuing to deliver on the mission and managing their chosen paths forward within budget constraints and in the face of unrelenting cyber attacks.
As federal leaders look to strengthen their IT infrastructure to build resilient organizations, candid conversations, like those at this year’s luncheon, will be vital to driving tech adoption and the mission forward. “This year’s theme captured exactly what federal IT leaders are grappling with at the moment,” shared Eric Skiff, Vice President of Technology at SecuriGence. “At the table I was sitting at the conversation focused on supply chain integrity and risk management, CMMC implementation, and GenAI data loss prevention,” he continued. “Leaders today can’t evaluate new technologies without simultaneously assessing security implications, supply chain exposure, and knowledge protection. Today, integrated decision making is the reality facing government leaders.”
As the pace of technological innovation only continues to quicken, agencies must embrace decision making with imperfect information to make forward-looking infrastructure choices and investments. For Skiff, a prime example of this is the accelerating pace of Post-Quantum Cryptography (PQC) migration. “We’re not waiting for quantum threats to materialize but building crypto-agility into systems now,” he explained. “We’re supporting agencies as they implement strict key management with automated rotation, deploy TLS 1.3 with perfect forward secrecy as default and architect for cryptographic flexibility so they can swap algorithms without rebuilding infrastructure.” This shift is driven by the ‘harvest now decrypt later’ threat, where adversaries capture encrypted data today and store it until quantum computing breakthroughs make it feasible to decrypt it at a later date. Agencies that refresh infrastructure with PQC readiness in-mind today, are future-proofing their infrastructure and avoiding costly retrofits later.
While federal agencies need to be building for the era of PQC, today they need to be focused on maintaining a robust and resilient cybersecurity posture with Zero Trust. “Zero Trust mandates have advanced the cybersecurity posture of federal agencies by forcing systematic implementation and measurement of principles including least privilege, segmentation, multifactor authentication, and role separation,” Skiff shared. “The mandate has created visibility and accountability across agencies and resulted in consistent adoption of best practices and best-in-class technologies to comply with Executive Order 14028.”
While many agencies are now in compliance with the implementation of Zero Trust, there’s always more to be done. “The next step for agencies is pivoting from prevention to resilience,” Skiff explained. “Zero Trust assumes a breach is inevitable, and agencies need to architect for that reality. This means focusing on detection speed, containment automation, and recovery capabilities.” To turn this advice into action, to accomplish this new architecture, agencies need to implement behavioral analytics to identify anomalous access patterns, automating micro-segmentation responses to isolate compromised segments, and building immutable audit trails that survive adversary tampering. “Robust and resilient environments don’t just prevent breaches—they detect them faster, contain them more effectively, and recover without mission disruption.”
Underpinning all the discussions at the table during the AFCEA Winter luncheon, however, was the need to manage not just data, but all the knowledge created by and for the agency. “Knowledge management should be a frequent topic of discussion in every agency, because it’s foundational to every IT priority today,” Skiff explained. “A clear focus on knowledge management delivers compound returns.” For example, effective knowledge management enables AI implementation, strengthens cybersecurity, and improves mission outcomes. Without knowing what to protect, an agency remains vulnerable to exploitation; without knowing whether its data is accurate, training an AI system effectively is impossible; and without knowing where data is stored, agency personnel waste time searching for information instead of applying it to mission critical problems.
As agency IT leaders look to the next stages of their technology modernization and innovation programs, it’s clear that their unique mission has only become more complex and more vital. With the introduction of new threats to information and systems security and integrity as agencies enter the Post Quantum-AI era, ensuring that the four essentials – technology, innovation, cybersecurity, and knowledge management – are all accounted in planning and invested in for execution is imperative.
Learn more about the discussions at the AFCEA Winter Luncheon, here.