HSDF THE PODCAST
The Homeland Security and Defense Forum proudly presents HSDF THE PODCAST, an engaging series of policy discussions with senior government and industry experts on technology and innovation in government. HSDF THE PODCAST looks at how emerging technology - such Artificial Intelligence, cloud computing, 5G, and cybersecurity - is being used to support government missions and secure U.S. national interests.
HSDF THE PODCAST
Full Spectrum Cybersecurity at DHS Part 2
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Episode xxx: Full Spectrum Cybersecurity at DHS Part 2
Welcome to our “TUESDAY EDITION of HSDF THE PODCAST,” a collection of policy discussions on government technology and homeland security brought to you by the Homeland Security and Defense Forum
AI is already changing federal cybersecurity, but the most urgent question is not which model is smartest. It’s whether defenders can adopt AI fast enough to protect missions while adversaries use the same tech to evade detection, exploit vulnerabilities, and manipulate people at scale. In this two part episode, we unpack what’s holding government back, what “good” looks like in a modern SOC, and where industry partnerships can actually deliver measurable impact.
Featuring:
- Christopher Cleary, Vice President, Global Cyber Practice, MANTECH
- Thomas Dempsey, Deputy Executive Director, Cybersecurity Directorate, U.S. Customs and Border Protection
- Dustin Goetz, Chief Information Officer, U.S. Immigration and Customs Enforcement
- Rob Thorne, Deputy Chief Information Officer (Acting), U.S. Immigration and Customs Enforcement
- Luke McCormack, Former Chief Information Officer, U.S. Department of Homeland Security (moderator)
This discussion took place June 10th, 2026, at HSDF’s Cyber Symposium
Follow HSDF THE PODCAST and never miss latest insider talk on government technology, innovation, and security. Visit the HSDF YouTube channel to view hours of insightful policy discussion. For more information about the Homeland Security & Defense Forum (HSDF), visit hsdf.org.
Time Box And Big Question
SPEAKER_06We got 10, 15? Okay, good. Just trying to time box us. All right, Chris, for you. We used to talk about the metaphor of I've got refrigerators, got internet access now. Now I got a toaster, it's got AI capability in it. Right. And but we think about some of the basics that the federal government is doing in regards to ADI. There's some level of sophistication. I was super impressed by the green room conversation we had earlier. But there's still a lot of potential to unlock in regards to the federal government and the use of AI. What's the barrier there? What's your sense about what's it going to take to get to where, from where we are today to just fully realizing the power and capability of this technology? So
Why AI Progress Feels Stuck
SPEAKER_06you ended with power and capability.
SPEAKER_04I am not an AI expert. I was a history major in college. I failed calculus my freshman year. So I wanted to graduate. But I think that the realization of the AI discussion, I think we probably talked about a little bit in the last panel, is taking it from a history major's perspective. We as a race of humanoids have always gotten really good at taking a technology and weaponizing it. There's been no technology we've ever touched that we haven't figured out how to do something less than desirable with it. I think this technology is represent is no different. We're in the process of debating that now, but it's going to happen. And if it's not done by us, it's going to be done by somebody else. So the question is, how do we begin to recognize that? Now, something else we were talking about
Training Gaps And Hiring Tradeoffs
SPEAKER_04is the training that goes around this. Well, AI is changing everything, right? It really is. And it's to the point where, you know, even the requirements discussion, some of these things we don't know their requirements until after the fact. They just this, so it's just the it's just the nature of the environment that we live in right now. From a training perspective, how to use these sort of things, one of the things that I think industry has been trying to work with government a little bit more on is there's so many, there's that the saying of what there's 600,000 open cybersecurity jobs, something like that. The number changes every day, give or take. But then there's a lot of students coming around out of college that can't find jobs.
SPEAKER_06Thing go.
SPEAKER_04And why is that with the US cyber challenge? And the US, and I think one of the things that that the government needs to sort of concede a little bit for industry is say maybe every new contract we're going to put people, 10% allowed of them, 10% of the workforce is allowed to come in with zero experience. Because we have to do somewhere. And what's funny, again, using from the military's perspective, and I think the military specializes in taking people with no experience and turning them into something that is proficient at something, right? Pilots, submariners, whatever. And then what happens is five years later, we want we wonder why we can't keep our workforce inside the Navy because you are now five to 10 years experience, you are absolutely at the sweet spot for industry to come grab you and triple your salary. So how do we change that? And why is it impossible for the new kid coming out of college that can't find a job because they don't have where do you get that five years of experience? There's got to be some kind of give and take on that. I'm combining a lot of things together, but the AI thing with that, with the fact that maybe AI enables people to come in with very little experience, is going to help them do their job or their work or a little more proficiently because there's training wheels that they have that can enable them
Three AI Threats That Matter
SPEAKER_04to go do it. But I think the thing that scares me the most about the technology is you look at AI from three fundamentals. There's the whole killer robots that we're all worried about. There's the how it finds vulnerabilities and weaponizes those faster. And then I think there's this whole other that AI, just from a, I guess we'll call it the deep fake world, right? The way that it can, the cognitive side of what AI is going to be able to do to shape behavior. And do we begin to wield that as a lever of national power? Do our average you could argue that China's doing it right now with things like TikTok, right? They understand how to get into play the long game to go and manipulate a whole generation of folks through this new tool that is very addictive, that just leads to more scrolling. And there's so many of those conversations you can bring together. I'm sorry, I'm going down a rabbit hole. What was the question again?
SPEAKER_06Because I can talk about AI all day long. No, I think you got it. And speaking of staying on the AI trains.
ICE SOC Shifts Beyond Signatures
SPEAKER_06Rob, I'm going to come over to you. ICE SOC, widely recognized as one of the more sophisticated SOCs in the department, I'd say, right? Certainly up there in the top tier. And you guys are doing quite a bit of work in regards to, again, trying to stay away from the offensive word, if you will, or offense, I'll say, versus being very forward-thinking in regards to how you operate and trying to protect from the adversaries, recognizing the fact that they now have fully realized AI weapons in the chamber, et cetera, and perhaps your use of AI to counter that, et cetera. Tell us about how all that's going and what's the thought process today, what's the vision tomorrow? Yeah.
SPEAKER_08We're not using AI right yet to counter it. But what we are doing, for example, we're removing our reliance just on signature-based detection. So one thing we're doing, and there's still huge value to that, but when you look at AI, AI can evade a lot of those signatures. They're away with it, or they can that they're aware of it. So what we're moving towards is more of a behavior-based threat model where we're looking, and I said the word earlier, but we're focused more on identity. So what we're looking at is anything, authentication patterns. So anything that may stand out. We're looking at privileged access and user access and anything that might look like an anomaly there. So again, and I'll be brief here, Luke, because I know we don't have as much time and I know you got another questions that you want to get through, but we're very focused on that identity
From Reactive Response To Hunting
SPEAKER_08piece. And one more piece to it, Thomas earlier said to kind of move away from a proactive to a reactive model. And so we've kind of got to get away from that thought of we detect something, then we respond, and then we fix it. We've got to get to that model where we're predicting, we're hunting, and then we're detecting. So we've got to be more proactive than reactive because when we're reacting, it's already there. We got to get it before it's there.
SPEAKER_06You feel like you have the right tools and are the tools available in the community and industry to perform at that level that you're describing?
SPEAKER_08So I think it's maturing in this area. It's really about getting those threat hunting teams together. But there are a number of tools that we've we've invested in. But like Dustin said, we're always open to, and our path is to do POVs and look at those products that can provide us the best capability.
SPEAKER_06And you're always looking for more talent, right? Uh I know that's a big one as well. Uh I got two loaded questions, fully loaded for the audience, and not excuse me, for the uh the panel members here, and then we'll jump to the audience. And
Major Incidents And Communication Breakdowns
SPEAKER_06one is just I'm gonna pick on Dustin here, but anyone can chime in. Let's just talk about major incident, right? We we the alarm has shot up. It's a multi-interagency type of whopper thing. And you've got to start communicating across the various components, across other parts of the interagency with the private sector. In the perfect world, what does that look like? And where do we need to improve there so that we're not just doing the good old phone tag and 50 people on a conference call, that kind of thing.
SPEAKER_03The smart side of me says step back and let Rob handle it. And that's fine too, right? Yeah. Yeah. My experience, a good CIO has a better DCIO. That used to be the CISO knows where all the bones are buried. But I ideally, in my experience in dealing with cyber threats in the past, the really relies on the communication piece predominantly. If you don't have good communication with your operators who are doing conducting the threat hunt and the analysis, or you don't have good communications with your lateral partners, that being the other components in DHS, you're doing nothing but wasting time and spinning your wheels. As a community, I think we can do a better job in collaborating the information that we have on incidents, what our responses are, how we're managing them. IOC's the all the tradecraft buzzwords. We just got to we have to do a better job. We are getting there and we are getting better.
SPEAKER_06Is that dashboard flow is that working better than it did in the past? You know,
Dashboards And Shared Situational Awareness
SPEAKER_06starting your CDM information and we're standardizing tool sets that one.
SPEAKER_03Okay. And then we're going to start sharing the a lot of the data sets in the dashboards so that we can have that larger enterprise picture. So, yes, that's where I was going with it. Thanks, Luke, for stealing my thunder dashboards.
SPEAKER_06Okay. I'm even thinking about the Mr. Duffy dashboard, right? Maybe we could find him in the green room and say, how's that dashboard going? Because I'm thinking even as at an interagency level, right? Where it's hitting the fan, it's a solar winds kind of play. And the look there. It sounds like that's moving in the right direction. Let me break here for a minute. We got 10 minutes left. I got a couple more juicy questions that I may ask, but I want you all to be able to have an opportunity to ask some questions.
Tool Gaps And Where AI Helps
SPEAKER_06Fire away here. Whoa, don't rush the stage here. Wait for the microphone right here behind you.
SPEAKER_02Thank you so much for your time today, panel. I'm also I'm Chris with Lidos. This is for Dustin and Rob here. You guys talked a little bit about to the SOC. Are there specific tools that you're really happy with? And if not, are there certain gaps that you you're looking to fill this next go round?
SPEAKER_08Yeah, so uh I'll I'll jump in really quick and I'll say, yeah, there are tools that we're happy with. I'll keep it broad, but we do have gaps. We do have things that that we want to grow.
SPEAKER_06We talked a little bit about yeah, maybe what your functional gaps are without getting into tools, right? Yeah, obviously it's got some active activities going on there, right?
SPEAKER_08Yeah, and exactly. I think if you look at it from a functional perspective, the detection piece, we want to grow a little bit more. We think AI can help us there. And so I think that's where industry can come and provide some value and how we could can do that. AI is great at providing you numbers, but we've got to make it work a little bit harder for us and provide it some more value. So we're looking at some creativity in those areas.
SPEAKER_06But the technical any other functional areas that need a little bit more capability in them going forward? If you have any thoughts on that, detection is CBP as well.
SPEAKER_05I would say AI is one of the largest areas, and though it's one of the largest areas that we're concerned about, and just that general and with leveraging it in both an offensive and defensive capability, because that's where we see a lot of the gap is how do we make sure, and they I heard them touch on it with the last panel, is how do you make sure that the systems that are coming in are going to meet the needs because everything is so new and so evolving that as we evaluate these tools, one of the things that Robin and Dustin both said is that we need to do POCs, we need to do POVs to make sure that these are doing what we expect them to do and that they're performing at a level that we need them to for organizations. And I think that's one of the key things that we're looking at as we look at those different types of things to fill those gaps is what can we implement quickly and leverage in order to prove value for the organization so that we can look to move forward with them if it does.
SPEAKER_07Had another question here.
Consolidation With Mission Autonomy
SPEAKER_07Hey, my name's Rohan Oswald from Trellics. This is a question for you, Rob. You mentioned that ICE is moving closer to data identity and device posture. So my question was really around as DHS is really consolidating around IT, how much authority do the components still have to shape those capabilities as it relates to mission-specific requirements?
SPEAKER_06You know, you stole one of my juicy questions because I'm dying to hear the answer to this. What? Of course, we still have councils.
SPEAKER_08So we have the CISO Council and the CIO council, and we come together there and we talk quite a bit about some of our challenges and some of the things that we need to work on, some of the gaps and some of the capabilities we have. So, for example, if we need an API gateway tool, we might say, hey, we're testing this out, we're looking at these two products, and hey, we're using these products. So we do have a huge say in some of the direction that we're going with as far as some of the tool sets and other things that we're using. And it starts at the CISO and the CIO council, and then we work our way through there. So we're doing communication was a big thing we talked about earlier, and that's what's going on.
SPEAKER_06So there is the ability, I know there's a lot of work going on with this tool rationalization, which makes perfect sense. But there is a level of autonomy that is allowed and useful for when it's time to have a little bit of autonomy as needed, right? You're gonna work with the mothership, try to make it all work, but it's not gonna be just an absolute peanut butter spread one size fits all.
SPEAKER_08We like to be on board with the headquarters, but there are certain opportunities to go in different directions for different needs. We have different mission sets, and so as a result of that, we do have different needs. So there is some autonomy to go in different directions.
SPEAKER_03Yeah, I just want to say that there's a lot of opportunity for the components to stay independent of the headquarters. Yeah. However, there are very clear and strategic goals that Antoine McCord has put out for us to align to. And I think it's important for the components and for the taxpayers for us to go in this direction. Identity platform, some level of cybersecurity services, and there are other platforms licensing that we're going after. Those things are obvious wins, and we want to stay in alignment with headquarters. So CIO CISOs talk on a recurring basis through forums, making sure that the decisions that we're making not only align to headquarters, but to the components as well, because they may have a better idea of doing it. We don't want to repeat someone's.
SPEAKER_06And I think Antoine's done a nice job of really pulling you together as you described, right? So that you're very much involved in tool rationalization. It's not being delivered to you. You're as a community coming together to look at what makes sense for the greater good as opposed to eat your peas and get over it kind of thing, which I think is the smart play there, right? Other questions? Here's
The Single Pane Of Glass Reality
SPEAKER_06one.
SPEAKER_01Tony Serrano from Mantec. I had a question for Mr. Thornton, Mr. Goetz. This industry term single pane and glass, right? With all the uh constraints with acquisitions and licensing, but at the same time a lot of the platform modernization and combining all these different platforms together, do you think that's still a realistic goal or even possible to have a true single pane of glass for operating for operations and for monitoring?
SPEAKER_08No. Yeah, that was my first thought.
SPEAKER_03No, but you have to strive towards something, all right. You can't we if we start to collectively say we need a single pane of glass, we may get 50% there and still have a better position than when we started. So it may that's euphoria, and we all tried to go towards euphoria. But the reality is if you again just get 50% there, I think that's close enough for a victory.
SPEAKER_06Unless you had something more one last question, I think that's and then I'm gonna let these guys give their final thoughts over here.
SPEAKER_00All right, thank you guys so much for your time today. My name is David Gentilli with Ever Pure, formerly Pure Storage.
Data Inventory Data Governance At Scale
SPEAKER_00And my my question is directed towards Dustin and Rob. And wanted to just kind of identify a couple initiatives that you might have, but specifically around the topics that we explored today. We talked a lot about critical infrastructure, identifying attacks before they happen, and utilizing AI. And ICE and CBP are not only law enforcement agencies, but they're massive data enterprises, probably combined, one of the largest in the world. So, what are you doing today to identify that data? Because part of cybersecurity is understanding your data, what's in that data, who's accessing that data, where that data lives, because there are a lot of data silos in the two agencies with disparate, maybe not talking to each other. How are you doing that data inventory on a mass scale, whether it's in the cloud, on-prem, at the edge? When how are we putting governance around that to ensure that data is safe and that you're increasing your cyber resiliency?
SPEAKER_06And I'd like CBP to take a crack at this as well. So maybe even start with CBP. We could start over here.
SPEAKER_05So we work very closely with our chief data officer from the cybersecurity side. We tied directly in with her as she's working with uh different components within CBP to identify where that data lives. And then we leverage that and work with her in order to make sure we have the correct security in place through those processes to make sure that the data is being tagged, that we're able to categorize it, that we're able to put protection in place where it exists and where it's coming from, and then where it's going to. And that's the larger picture. What we're trying to do is where does all it come from, but then where is it all going to? And is it going to be protected at that same level there? So it's really a collaboration between different groups, specifically with our chief data officers.
SPEAKER_03Yeah. And
Data Fabric Data Mesh Direction
SPEAKER_03for ICE, we are I can't remember what we're now calling it. You'd probably heard me reference it as data like in the house at least or something. Yeah. So we're moving towards the data fabric data mesh where we're trying to leave data at point of origin, but registering it with within the larger data fabric for consumption. There are some benefits to doing that. First and foremost is going to be cost, right? And if we try to push out some cumbersome data architecture, put the costs on the application owners to re-engineer and to uh enforce cybersecurity, it's just going to break. It won't happen. They won't do it. It's too costly. So the idea of a vendor specific across the department that provides that data mesh data fabric layer, and then consuming products within that architecture is the best way that I think we're going to go. To your earlier question, though, data discovery is going to be a pain. It's going to be hard for us to wrap our arms around the data because they haven't traditionally registered all of the data products. So we brought on a new CDO. Our old one was phenomenal. We've got another one that's going to come in and also help in identifying it, coming up with a strategy on data identification. And it's partnership. And again, I have to say that five more times, partnership.
SPEAKER_04Quick
Closing Thoughts On Partnership
SPEAKER_04quick closing thoughts. Chris, we're going to start with you. Yeah. Partnership is important. I the questions of the audience were the ones that we would anticipate, right? They're the good ones. Help me figure out how to help you and then the money and the resources behind it to close those deals. But not an easy game that we play. So good luck to everybody.
SPEAKER_05Thomas. I'll say it's an evolving landscape. We've seen a lot of new technologies with AI coming into the picture. Things are moving faster than ever. So traditionally, government does not move as fast as industry, which is why we are dependent on industry to come in and help us, to support us to get to where we need to be. So we really are looking forward to further collaboration and making sure that we can achieve our mission with your support.
SPEAKER_03Dustin, Chris had mentioned earlier about bringing in lower-level folks with no experience to try to groom them. I think that is a golden opportunity for industry and government to partner on to figure that out. If we can start homegrown, growing experience from the very basic elements and growing them into what the government needs and corporate needs, I think that's a win-win situation. The reason the government doesn't do that is because you guys charge us for it.
SPEAKER_04So firm fixed price, it is we would be lower, we would lower the prices of those. Yeah, trust me.
SPEAKER_03But I heartily agree with that. And that's investing in our future, and we need to take steps in doing that now.
SPEAKER_06Give me some ideas with the cyber challenge. Rob, take us home.
SPEAKER_08Yeah. So that scares me a little bit because I love that idea too. And I was going to say something about it, but Dustin just stole my sounder there a little bit. But 10%, I think that was a good start to get folks in there. You heard me talk about identity and you heard me talk about needing to secure the data, push security down there. We're looking for industry to come in, tell us how we can do that better, what tools or what capabilities we can put in place, looking for creativity. AI is going to be key for us. We're very focused on operationalizing AI. So love ideas.
SPEAKER_06And for this panel that wrap it up. Really good for you here to folks.