HSDF THE PODCAST
The Homeland Security and Defense Forum proudly presents HSDF THE PODCAST, an engaging series of policy discussions with senior government and industry experts on technology and innovation in government. HSDF THE PODCAST looks at how emerging technology - such Artificial Intelligence, cloud computing, 5G, and cybersecurity - is being used to support government missions and secure U.S. national interests.
HSDF THE PODCAST
Full Spectrum Cybersecurity at DHS Part 1
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Welcome to our “TUESDAY EDITION of HSDF THE PODCAST,” a collection of policy discussions on government technology and homeland security brought to you by the Homeland Security and Defense Forum
In this two part episode, we examine what it really takes to modernize government IT without sacrificing security, from legacy app risk to identity-first protection for a mobile workforce. We also challenge the way we buy technology, arguing for earlier cyber requirements, faster acquisition paths, and tighter collaboration with industry.
Featuring:
- Christopher Cleary, Vice President, Global Cyber Practice, MANTECH
- Thomas Dempsey, Deputy Executive Director, Cybersecurity Directorate, U.S. Customs and Border Protection
- Dustin Goetz, Chief Information Officer, U.S. Immigration and Customs Enforcement
- Rob Thorne, Deputy Chief Information Officer (Acting), U.S. Immigration and Customs Enforcement
- Luke McCormack, Former Chief Information Officer, U.S. Department of Homeland Security (moderator)
This discussion took place June 10th, 2026, at HSDF’s Cyber Symposium
Follow HSDF THE PODCAST and never miss latest insider talk on government technology, innovation, and security. Visit the HSDF YouTube channel to view hours of insightful policy discussion. For more information about the Homeland Security & Defense Forum (HSDF), visit hsdf.org.
Welcome And Audience Q&A Plan
SPEAKER_04A couple things. One, I wanted to say thanks for hanging in there. It's been an action-packed day, that's for sure. Two, I will make sure that we budget a little bit of time at the end because we want to make sure that you all have an opportunity to ask some questions. And then we'll wrap it up with some final thoughts from the panel members.
Technical Debt And Legacy Risk
SPEAKER_04Dustin, I'm going to start with you. And this is an age-old issue. It's a challenge that I know you've been facing and trying to get your arms around it, both you and Rob. And that's this age-old issue about technical debt, right? You've every CIO incorporates and adopts some technical debt that you're trying to work through. And there's this delicate balance of trying to move forward and deliver capability and then have to make sure you're managing your current environment, your legacy environment, let's call it, and making sure all that stays secure, right? From the top to the bottom. Can you walk us through the thought process and how that's going?
SPEAKER_01It's not fast enough. By the way, good afternoon, everyone. I usually will say something along those lines early on, and I apologize. Yes, like legacy applications, modern applications, from OCIO's perspective, we're trying to treat them all the same and give them the care, love, and feeding that they need to ensure that our officers and agents have a secure and reliable platform, regardless of the device or where they're at. There are inherent risks with a lot of the legacy applications that we're trying to address, but step one in doing that is really understanding and identifying what technologies and applications we have out in our ecosystems. So recently we came out with Shadow IT memo, where we're trying to catalog, identify and catalog all of our IT. And then from there, we'll work in with the program offices to understand what's the what's the future for the application? Will it be sunseted with new capabilities that we have coming online through our other platforms, or do we really have to sustain this? And if in which case we'll work with them to really modernize the application to ensure that it meets cybersecurity compliance. We are trying to limit the number of custom applications that we have coming into our infrastructure. So where possible, we're going to try to point them to existing platforms and infrastructures. But our requirements all start with programs. And if you're out there talking to the programs, which I encourage you to do, but do it with partnership of OCIO. Understand that we're trying to consolidate our applications. We're in platforms, we're trying to continue to deliver reliable applications. And there's or trying to standardize across the board. So just work with us as you bring ideas to bear. We're open to hearing them and we want to hear them. But sometimes we have limiting factors that we're thinking about not only today, but in the future.
SPEAKER_04Thank you very much for the way in here, please. We know he's going to have to do that.
SPEAKER_00Well, you know, I always do. When my boss is here, I've got to jump in
Fix It Or Compensate For It
SPEAKER_00as well. And from a security perspective, one of the things when we look at our legacy applications, sometimes we say, hey, we got to fix them, but we don't always have to fix them. So what a lot of these have vulnerabilities to them. So one of the things that we weigh often is, hey, what's the cost to get these legacy apps fix fixed versus what are some of the compensated controls that we can put in place? So sometimes if it's working and it's getting the job done, you just leave it as is and you invest in other areas until you can swing back around and maybe solve some of those vulnerabilities in the end.
SPEAKER_04Yeah, invest your way out of that. So I appreciate that. And a good old wrapper seems to work sometimes, right?
SPEAKER_00Yeah.
SPEAKER_04I appreciate that. Thomas, I appreciate you coming out here. And
From Reactive Security To Threat Hunting
SPEAKER_04we know that the uh the deputy scissors are the ones doing the heavy lifting. And I think about CBP, it's this freaking aircraft carrier out there. A lot of moving parts around a lot of IoT, et cetera. And you've got this sort of position of originally of this passive, right? We're gonna we're gonna try to keep this environment stabilized. And now you're really into more sophisticated instrumentation, really active metering. And just how does one go from that sort of stable environment to really getting aggressive and getting in front of these adversaries and putting yourself in a position where you can do that properly and keep the mission running?
SPEAKER_03Thank you for the question and thank you all for being here. So I think the biggest thing is changing the mindset from that reactive approach. We're gonna have our security operations, we're gonna set triggers, we're gonna set tripwires, we're gonna set alerting, and we're just gonna wait for something to happen into a more proactive mindset. So it's working with our forward-thinking cyber threat intelligence teams, finding what the adversaries are doing, and then positioning ourselves as an organization in order to be prepared when they use those tactics, techniques, and procedures to attack against us. One of the things we did early on with our cyber threat intelligence program was identify goals and priorities that were very specific to the organization. So we're looking at actors that are interested in our actual mission and we're looking at how they can actually impact our mission. And then we're communicating that from the cyber threat intelligence team, from our SOC, through our SOC, up to leadership to make sure that they are aware of these actors and the capabilities. But then as we're doing that, we're taking a proactive approach to go out and look for these actors within our environment. Because the way that we've seen things happen over the past couple of years, it's not if you're breached, it's when you're breached and how can you find them. We have a cyber threat hunt team that actively goes out and searches for campaigns. We find the different techniques that these specific actors are doing. We find the different indicators of compromise, and then we span across the network. We look at the different high-value assets that we have to identify if we see any of those techniques being executed within those areas. And then we validate. The thing that comes from threat hunting that is kind of challenging is it's a negative. You can't really prove a negative. Oh, we didn't see anybody in the environment. We're taking this proactive approach, but we didn't find anything. So, what do you do? What we've done to caveat that is we find configuration flaws. We find things that are going on in the actual environment that adversaries would be able to take advantage of. And then we report on those. We work with the system teams, we work with the different individuals within the organization to make sure that they can fix the actual vulnerabilities within the systems prior to an adversary being able to attack them and being able to exploit them. So it's really shifting that culture from, hey, we're going to sit back and wait to we're going to actively go out, find the adversary, we're going to actively go out, find what they're doing, and then we're going to take action against that. And then enabling the organization to follow along with us as we do that to take preventative actions prior to being exploited.
SPEAKER_04And no doubt with some sophisticated instrumentation that you're doing there. So we really appreciate you laying the framework out as to describing that. I don't want to say offensive posture because that doesn't sound right, but being in a situation where you're getting out in front of it. Chris,
What Government Misses About Industry
SPEAKER_04and this is not to meant to be pull a pin out and roll a grenade across, but I think these type of questions are important here. And this is about the biggest thing the federal government fundamentally misunderstands, right? Misunderstands in your eyes, and you can speak on behalf of the industry about commercial providers and how they manage cyber risk and the new national strategy. What's your perspective of that?
SPEAKER_02Getting to speak for the entire industry, apparently, and representing the entire federal government's position. I guess I'll be a little broad with this answer. I feel first of all, thanks for having me here as well. A little bit of fish out of water. I'm a Department of Defense, Department of War guy. So the DHS stuff is not my forte. But you did use the word aircraft carrier at one point, naval officer. So I'll use some of these moving forwards. Having been just in the Department of War as the CISO for the Department of the Navy and then the principal cyber advisor, looking at these levels, things were a much higher level. And one of the things I've always felt bad for all the CIOs and all the CISOs is at the end of the day, it's an enablement function to whatever your core business is, right? At the end of the day, it's not the core function of any of our organizations to provide an information system. It's something that we all depend on. So in the Navy, all our big dollars go to aircraft carriers and munition consumptions and the Columbia class submarine or the things the Marine Corps are trying to do. Cybersecurity, all of those things are things that sort of get what's left over, right? And a lot of times those become billpayers for things that we've got to go do in the Navy. And I'm sure that exists, that same problem exists in each of your organizations. So what is industry's perspective on this? Now, I say this next piece to be somewhat controversial. The reporters in the room, don't get me in trouble. When I would talk about the Department of War, I'd say, what's our core mission? And fundamentally, the Department of War exists for two reasons. It's to deliver lethality or prevent lethality being delivered on us. That's fundamentally is what the Department of War does. So what's industry's core mission? And I would say industry's core mission is to find people with money and make that money your money, right? And I would imagine most people in this room represent industry. And I would say the most of the people, and some of you have come from governments, right? And now have done the job. And now you're on the industry side, which we will all end there one day. Eventually you'll transition from that side to this side. And the question is so it's this interesting perpetual cycle that we play of trying to come up with a product or a service that is something that you can get the attention of. But what I think the government has realized is in very few instances, everything the government uses comes from industry. Again, I'll use the Navy as an example. The Navy does not make anything. They buy everything shoelaces, munitions, ships, fuel, all of that comes from industry. And a lot of the workforce that enables that, particularly in the DC, comes from the contractor side. So when you say is what is industry's biggest thing that government doesn't understand, is industry's in this to ultimately make money. It sounds cold, but you could say it's a cold mission of why does ICE exist? Why does customer board protection exist? Why does the Navy exist? And those are the games that we play. But acknowledging that, I think, is important because when it comes to some of the capabilities that the government's looking for, we're going to get into answer the question you want to answer, right? Is the thing. As more requirements come into industry to build things that are more secure, particularly the last panel talking about mythos, there's a cost associated with that. And I would always make the example. The reason an Arleigh Burke destroyer costs $3 billion is not to make it float, right? That it's to keep it floating when somebody's trying to put a weapon in it. That's why it costs $3 billion. Because I can go buy a merchant ship and put a whistle launcher on it at a much reduced cost. But to make something that, and really the conversation we get in all of these systems is when you want to move something from being secure to resilient, and the new word is survivable. If I have a dedicated, sophisticated, well-resourced adversary trying to apply their table against my problem set, how do I go to build something that is now survivable? And then have government recognize the cost associated with that. Because the government doesn't balk because a destroyer costs three and a half. Actually, it's like it's three and a half billion dollars now. That's why it costs that. And I think you could take that and apply it against a lot of different mission sets in the government. And it's that acknowledgement back and forth, I think, is where the conversation gets a little more interesting.
SPEAKER_04Appreciate that perspective, Rob, I'm gonna toss it over to you.
Zero Trust For Data And Identity
SPEAKER_04Think about the level of activity in regards to data being collected at these various remote locations, right? Very sensitive data, biometrics data, et cetera. Very sophisticated equipment. And I'm curious to know as you're securing that environment to make sure that it's protected, what's the balance about I'll say oversecuring it to the point where the officer can't do their damn job, right? So tell me about how that works and how that is working and what you might be thinking about to make that even better, particularly as you start talking about this mobile environment, et cetera, et cetera. Yeah.
SPEAKER_00Yeah. No, that's just that's a great question. And something that we're challenged with every day. I used to say, how do I protect my network? But actually now I'm saying how do I continuously assess device trust? How do I trust an identity or validate an identity? And then how do I protect data that's everywhere? And so what we've done is, like most people with our zero trust journey, of course, most are aware, we've moved away from that primary security model. But really, what we're focused on now is more of that data and identity security model and focused on on both the data and identity. So what we've done is we started to push down a couple of things we've done. So we started to push down security to the data level. So what we're looking at here is data classification labels, DLP, attribute-based security control. On the mobile devices. Not there yet on the mobile device, but yeah, on the on the mobile devices. Maybe there's an opportunity out there. We have there. Okay. Sorry about that. Go ahead. So on the endpoint devices, on our mobile devices, we do have MDM device management. We have our EDR capabilities. Something that we're really pushing now is to continuously assess our device posture. So looking at patch levels and seeing, hey, should we allow this device on the network or should they have these capabilities? And then the other thing that we're doing, I know that AI has been a big topic here, specifically Methos and some of the concerns there. We're pushing patches, more automating patching at this point, not testing as much, or at least we're headed in that direction to say how can we get out patching quicker. And then finally, when we look across the board, we see moving forward, identity is really going to be our core, the cornerstone of our security program. So this is focusing on things like multi-factor authentication, risk-based authentication, policies specific to devices that we need to set. Really, what we're trying to do, Luke, is we're trying to move away from saying, hey, the reliance on the network, the trust on the network, and move away from having to trust that location of the network and pushing it down to the data and it's so the network is uh you're everywhere now, so to speak, from a mobile perspective.
SPEAKER_04So you really got to get away from that guard gates unlocks type of phenomenon. So we really appreciate that. Dustin,
Faster Buying With Proof Of Value
SPEAKER_04we've talked about some levels of sophistication around some of this technology that you're trying to insert and do it very quickly, as you I think started out there trying to get it done as fast as you can. And I know that you're interested in some of these non-traditional, we'll call them, methods of acquiring goods and services. And I know there's been a lot of conversation, at least I think there has been, with your your acquisition shop. You want to talk about that, maybe tease the audience on some of these things that you're thinking about in regards to some of these non-traditional ways of acquiring goods and services. Don't want to put words in your mouth. Maybe it's just doing what you do today, but do it a lot faster. But yeah.
SPEAKER_01Yeah, absolutely. So that is one of our big challenges right now is trying to figure work with industry and figure out the complex engine of acquisition for government. We I'm preaching to the choir. I used to sit on your side, so I suffered your pain in going through the government acquisition process. I'm doubling down now because I'm sitting on this side and I want to see things done faster. The 18 months, 24 months acquisition cycle, it's just entirely too long. The technology changes before we even get it out into the operations. What we're trying to do is work with industry to come up with different acquisition models, more IDIQs, smaller task orders that are delivery-based on a specific function or capability set, proof of value, proof of concept are going to be, I think, game changer source as we start to look more towards proving capabilities before we even start that acquisition capability. That way we know where we're going to get at the end of that, and also just do more of agile type development on services and capabilities. We're not looking at developing that larger application and keeping everyone on board, staffing up on for 18 months. It's just that's not there. We'd rather bring small work groups in, get a completed task, uh, get a task issued, get them on, get it done, and then start managing the application from that point forward. Of course, all the while talking about DevSecOps. So hopefully that goes without saying Rob is, I don't want him to kill me later for not mentioning security operations. But yeah, just to put a cap on that, it takes a lot of partnership. For those of you that have heard me in panels talk before, the one things I one of the things I always harp on is how much of a reliance I put on the partnership with industry. And that takes open and honest communication. We don't want to say no to ideas, so we want to hear them and just talk through some of the concepts of that and ideas that you have. So please let's just sit down, have a cup of coffee and talk about it, and let's see where it goes from there. I'm always open for those types of communication, those conversations.
SPEAKER_04OTAs and SIBRs is that uh kind of conversation going on in the building? Is there a desire to do that? An appetite, or is it OTAs not so much right now?
SPEAKER_01We lost our SIBR authority for a few months. We've recently got it back, and so we're trying to figure out, we're working with OAQ to see how we can best leverage that. That's definitely back on the table.
SPEAKER_04Looking forward to hearing more about that for sure. Tom,
Cyber Acquisition Risk Management Early
SPEAKER_04you're a big proponent of software by design. So was the prior director of SISA, right? And I always felt when I was in service, we would have some really sophisticated vendors in there doing sophisticated work for us. Something wouldn't go right. I just didn't feel real good about answering. We got them in there, we paid them a lot of money to do this, and that seems like now we're paying them in here to fix it. What's going on here? And I know you've done a lot of work with C CARM. So give us some lessons learned, what you found out about, what's the drive behind that? What is it? And how can we keep making that better so that we get way to the left of this issue?
SPEAKER_03Yeah, absolutely. So you mentioned the term C CARM. So what that is, it's cyber acquisition risk management. What we've done is we've tried to integrate the cybersecurity component that we have with the acquisition side of the house so that we're starting to talk about cyber during the mission needs phase. When they're starting to define what we need for the mission, we're there with them talking about cybersecurity. And what we intend to do, and what we have done with that, is start to get the program managers to think about that, starting to get our industry partners to understand, hey, these are the requirements that we have from a cyber perspective. So they're already baked into the products. Because what we've seen a lot of is again, we get so far down the road, and then the requirements just aren't there. And from the cybersecurity side, we're the no guys. Oh, you can't do that because it doesn't have cyber baked in it. So just take a step back. If we're there from the beginning, we define the requirements. We say, this is what you need to do in order to be successful in this environment, to be able to deploy whatever it is that you're building, to be able to acquire whatever it is you're acquiring. This is how you do it. This is what we can do with you in order to get you there. That's what we've started doing. And then holding their hands and walking with them through that process. So understanding not just from the cyber side, but also building out the threats, right? What are the threats to this specific mission set? What are the threats that we need to be aware of? So as they're building this, it's not just being built to be cyber secure, it's being built to be cyber resilient so that we know when we get it there, we've considered what these different actors can do. We've considered the vulnerabilities that we need to account for. And we are trying to get one step ahead so that when we actually deploy into production, we're not deploying something that's full of holes and having to fall back and start patching and start nailing things on after the fact because we were there and considering it with them from the beginning. And that's something that has been very successful with the different programs. And honestly, it's also helped us to identify Shadow IT within the organization because we're tapped in to the actual acquisition lifestyle from the lifecycle from the cyber side, but also being able to work with our invent teams and other teams that are trying to deploy things quickly, being able to understand or have them understand what those requirements are early on in the acquisition lifecycle. So you don't go out and purchase something, get the ability to start moving forward with something that just won't work in the end. So I think that's been really successful for us. And again, the biggest thing is just being able to integrate with the programs as they start looking at the mission needs, what they're actually going to procure, what is going to go through the acquisition lifecycle, and what they're going to end up with in the end state.
Collaboration Expectations For Vendors
SPEAKER_04And do you feel like you're getting the right cooperation? You've got a bunch of industry folks here. Have they gotten the message? Obviously, you're delivering it today. But do you feel like you're getting the right cooperation from them? Is there anything that is there an ask out there for them to make sure you fulfill the things that you're trying to do here in this effort?
SPEAKER_03The biggest thing is just the collaboration and having them understand and working with us to make sure that we can get you to where you need to be successful with us because ultimately you're the ones that are going to make us successful in the end. And we want to be able to provide the requirements. We want you to be able to use those requirements to further what you're doing so that when you bring it to us, it's something that we can use, we can provide out, we can give it out to our mission stakeholders, and they can take it and field it. Because if you don't do that, we're going to end up saying no when you try to field it with our program managers, and that's going to wind up not being good for anybody. So just really that collaboration and working with us to ensure that you're integrating what you need to, that you're securing the way you need to, and then we can move forward. Excellent.