The GIST of Govt IT
The weekly show that breaks down ideas, innovations and decisions that cut through complexity and offer real insights from the intersection of technology and the mission.
The GIST of Govt IT
Cupcakes & OODA Loops: Inside(r) Insights Into the New Federal AI Cyber Playbook
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Last episode, we left you hanging with a question: when it comes to cybersecurity, what is the federal government doing to both leverage AI and defend against AI threats and most importantly, are we moving fast enough? In the conclusion of this two-part series, Sean takes us inside a White House industry day convened at the request of the Federal CISO Council. He breaks down the two themes of the day that framed very different problems: using AI to optimize cybersecurity (running a SOC, governance, and compliance faster) and securing AI itself. Brian and Sean dig into the agentic SOC, the build-vs-buy question for federal agencies, why data fragmentation is the recurring obstacle in every AI conversation, the role of MCP and RAG in getting agents to the data, and live demos. Cupcakes and OODA loops make an appearance and Sean provides his verdict on whether the government is moving fast enough and his hacker name is finally revealed.
RESOURCES MENTIONED IN THIS EPISODE
The White House Industry Day
- About the Indian Treaty Room, Eisenhower Executive Office Building
Vendors & Demos Featured in the Episode
- Lasso Security (AI red teaming and purple teaming)
- SimSpace (full-stack cyber range simulation)
- Elastic AI workflows (bring-your-own-LLM, air-gap deployable)
AI Security Frameworks & Standards
- OWASP Top 10 for LLM Applications
- OWASP AIVSS — AI Vulnerability Scoring System (agentic AI)
- MITRE ATLAS (Adversarial Threat Landscape for AI Systems)
Key Technical Concepts
- Model Context Protocol (MCP) — bringing the agent to the data
- Retrieval-Augmented Generation (RAG) explained
- CDM Program (Continuous Diagnostics and Mitigation)
Industry & Government Collaboration Communities
- ATARC — Advanced Technology Academic Research Center
- ATARC Working Groups (Zero Trust, Agentic AI, Cyber AI Convergence)
- Northern Virginia Technology Council (NVTC)
- OWASP (Open Worldwide Application Security Project)
Other References
- Geoffrey Moore, Crossing the Chasm (technology adoption lifecycle)
Related Episodes
- Episode 5: "Vibe Hacking" and Nation State Cyber Threats
- Episode 2: Fighting Fire with Fire: Federal AI Security - Securing Agentic AI with Elad Schulman, CEO of Lasso Security
The Hosts & Show
- Swish
- GIST360
CONNECT WITH US
Got an idea for a future episode? Want to be a guest? Let us know.
Brian Lake - blake@swishdata.com
Sean Applegate - sapplegate@swishdata.com
Subscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.
The Federal AI Cyber Question
Brian LakeLast episode, we left you hanging with a question. When it comes to cybersecurity, what is the federal government doing to both leverage AI and defend against AI threats? And perhaps most importantly, are we moving fast enough? We left it hanging on purpose because the answer isn't so simple. It's truly varied and nuanced. Some corners of the government are moving with both speed and urgency that would genuinely surprise you, while others are still waiting for someone to show up with a plan. Recently, Sean was invited to the White House, where he spent the day along with over 80 industry leaders and federal CISOs trying to answer exactly those questions. What he found was complicated, encouraging in places, and more than a little sobering. To break it all down and get the answers we left you hanging with, you know what we have to do. Let's get down to the gist of it. Outstanding, Brian.
Sean ApplegateLet's get to it.
Hacker Names And Fresh Press Suits
Brian LakeYeah, you know, listen, before we get to it, I know I put you on the spot last week about what your hacker name would be. It wasn't fair of me. So we we obviously did chat about it afterwards. So why don't you let the folks know that if Sean Applegate wasn't an upstanding X-Marine, CTO, firm supporter of the U.S. government, but it was stuck in like a window that's room in St. Petersburg, what would the hacker name be?
Sean ApplegateYeah, so so it was a good DOD guy. I have an acronym for you. JOTHAWA. So this is my gamer tag, JOTAWA. It, you know, I was inspired probably by some uh Star Wars uh characters or uh I'm kind of a sci-fi guy, love, love the sci-fi stuff, but uh, but in actuality, it's an acronym of of all of my family members, first the the the their first letter and their first name. So I have uh five kids, so so plenty of letters plus plus my wife to pick from.
Brian LakeWell, you know what? That's uh it's a great one. I love it, man. I think if you were a hacker, you would be instilling fear across the world for sure. So, all right, well, listen, uh, let's get into today's episode. Excited
The White House Calls
Brian Laketo like, you know, bring the conclusion of our two-part series, this kind of new cyber AI, cyber threat landscape that we're dealing with. Just but just to recap and level set from the last episode, we really tried to map the landscape for the listeners. You know, we talked about the GRU router hacking, the Iranian ICS attacks, we talked about mythos and the autonomous uh zero day discoveries, CISA running a significant um reduction of staff and employees. So we closed the show last time. You know, we talked, oh, Project Um Open Wing. Glass Wing. Open Wing, Brian. Project Glass Wing. Project Glass Wing. I keep screwing up. It's like an Andy, it's like an Andy Weir novel that hasn't been written yet. So um so we closed last episode with a big question. Today we're gonna answer it or we're gonna try to so you know, talk to us. Like, tell us a little bit about this recent trip that you had uh where you went over to the White House. Um you there was an event where they were bringing together industry um leaders, uh cybersecurity leaders, industry thought leaders, uh, uh along with government CISOs to really start to examine this and how can the government rewrite the playbook? What are the tools and solutions and the applications they need to be looking at? So ultimately, tell us how you got to the White House. Uh what happened? How did we get here?
Sean ApplegateSure. Yeah, so we're very involved in the community. One of those groups is a group called ATARC. They have uh a number of working groups and uh Lindsay over there basically came up with a last-minute kind of request out to the industry partners and the government and said, Hey, we've got a request out of the executive office of the president. In this case, it's um the Federal Citizen Council managed out of OMB. And they'd like to bring in a bunch of companies to talk about AI-powered security technologies across two main themes, right? And these there were there are eight categories in detail, but the two big themes were using AI to optimize cybersecurity, to run a SOC or run governance or compliance faster and more efficiently. The second was securing AI itself. And those are two very different topics when you think of the technologies and the techniques, but those were the two things to do. And a lot of this really got back to can we move faster as a government? Because the uh hackers out there that are using AI are certainly moving quicker, and we we can't keep doing things the way we've always done them. And so in this case, what was shocking was we we had like 12 hours to put the requests in, or it was short, like you know, four maybe 18 hours, but it wasn't very long. We had to have it in by like the next morning by 9 a.m. So I hit up our Center of Excellence team, so a bunch of really smart solution architects. A lot of these guys worked in industry for big tech companies. Now they're at Swish, they do a lot of thought leadership work, they're in the weeds. They threw together some of their favorite cutting-edge cyber companies that are using AI to deliver capabilities. And um, I put my quick review on it, added one or two others, punched in a bunch of contact info, which they wanted so that they could EOP could do the outreach to the industry members. We kicked it over to Lindsay. She got it in just in time. And believe it or not, that weekend on a Saturday, one of our industry partners gets a gets an outreach from the White House saying, hey, we'd like to have you come in for this industry day. Um they reach out to us, hey man, like, do you know anything about this? Or yeah, we recommend you recommended you for this event. And um, anyways, we recommended a few other partners too. But um, I got I got the plus one invite from last social security. So a lad Shulman who had on a, who's a friend of the pod, has been on here before, invited me. Very gracious of that. So, of course, like a good marine, I have to uh you know go spit shine my shoes, get the plants uh kept nice and creased and make sure I bought a new tie and it my wife approved of it. So it it fit the theme.
Brian LakeWendy when you gave the thumbs up on the tie, or did you present her options?
Sean ApplegateI I I presented a couple new options, and and she shot down the maybe the more bold option I had and uh guided me to a more conservative uh you know red tie, some nice blue and white stripes, and a couple other things. So it was it was a little more laid back. Anyways, probably the safer choice.
Brian LakeNo uh funky Jerry Garcia colors or looks, right? Don't wear the tie-dyed tie.
Sean ApplegateYeah, I'd have to keep I'd have to. Wait, Brian, is there a is there a is there a Phish tie? Does that exist?
Brian LakeUm they're not that I'm aware of. I don't think they're they they're not into the lice the branding licensing game that the Grateful Dead are into these days. So I'm sure at some point in the future, or uh I know a couple I know a couple like clothing designers that could really kind of probably take some inspiration and go that direction, but I'll let you know. I'll I'll be the first to wear it for sure. I would show up to the White House with it. Now I'm I don't know if they let me in the door, but who would have to see how that goes? So besides that, so you're looking look you're looking sharp. You got, you
Speed, Culture, And OODA Loops
Brian Lakeknow, you got your the starch in the shirt, extra starch. What's the honest answer that you saw? Is is the government move I mean, they they sound like they moved pretty fast to put this event together, but are they moving fast enough to to manage the tsunami of AI threats that are coming from these from these nefarious actors that can use AI in a manner that we're I don't think we're ready for.
Sean ApplegateYeah. Are we moving quick enough? I mean, I think we can always move faster. As a guy that worked in the special operations community as a Marine, what's called a Marine Expedition Unit, I've seen some very large organizations execute missions in in hours, not days, with thousands of people. So I'm a big fan of move move fast, um, innovate quickly and figure things out because it's all about you know adapting to the needs of the mission. In this case, we need to adapt to the pace of our adversaries. In this case, a lot of it is AI generated. And the problem is a lot of the younger gut, you know, younger or less capable people can grab these tools or the fishing as a service platforms and provide a fairly big impact without a lot of lift, so a lot less effort these days. When you get back to the agencies, right, the bottom line is it's nuanced because some agencies are moving very quickly and they're well funded. And there are other agencies that maybe are less funded or maybe just you know culturally more bureaucratic and rules-based and which tend to be anti-change. And so it's just harder to get things done in some organizations based on the culture. So I think you're gonna find that it's gonna vary a lot like Jeffrey Moore's crossing the chasm. You've we have very early adopters that are open to accepting more risk, and we have laggards that are you know gonna let everybody else to take take the chance, try things out, they'll figure out, and then they'll they'll finally adopt it, you know, three, five, six years later, ten years later, whatever works out. But a lot of it is is definitely gonna be, I think, collaborative in nature. So that was the promising thing out of the event was bringing everybody together and hearing from them was critical. So maybe we'll we'll set save that for a minute to go deeper into it. But again, it really gets back to the Oodaloop. We talk a lot about the Oodaloop, but basically, how do we make decisions faster? That everybody realizes we have to do that. Now we actually have to do that.
Brian LakeSo you can see your reflection, your shoes. You've got your nice Wendy approved conservative tie on. Walk us through like who who who organized the event, where was it at inside the EEOB? Talk to us a little bit about like just overall the event itself and like how the day kind of progressed.
Sean ApplegateYeah. So
Inside The Indian Treaty Room
Sean Applegateit's a beautiful day in March. The weather, the sun was out, the clouds were away. It could not have been a better day to have good weather in, I guess it'd be late winter, early spring, right? Not official spring yet, probably. But it was at the Indian Treaty Room, which is interestingly the place where Eisenhower held the very first live televised presidential press conference in 1955. It's also where the nuclear test ban treaty was signed in 1963. So this is a very important room in the Eisenhower building. It's beautiful. There are sculptures and marble everywhere, and it's it takes up like two floors. So there's like a like a little walkway area above you where people can stand and look down into the room, but it was beautiful. Anyways, it feels very uh, you know, I would say professional when you walk in, right? It's it's formal. Um, we had about 80 industry members along with federal, the federal SOSO council in this case. So uh there were some folks from Department of War there as well. So it wasn't just civilian agencies. And so we had, I think, good broad coverage. It was Chatham House rules, so we can't really reference names in the pod, right? It's non-attributable content and activity. Um, and this was not a procurement event, right? It really was for the federal SOSOs to kind of present to industry their vision, right? How do we, how do we, we need to move quicker, we have these things going on, we can operate more efficiently. Would they want to operate more efficiently when you think of looking at the KPIs and the value and how they move quick? How do they really go back to first principles and think around KPIs and getting things done more productively with less cost and more technology and uh and really good people to execute that? And then um how do we leverage and change first principles to really leverage AI to do their job? So it's kind of the North Star moment, right? When you think about this, it was their opportunity to say, hey, look, we need to blow things up. The second thing was they were there to listen to industry. So the good thing was that we had a lot of really smart technology companies and operators in the room. Um, and it was really a great time to spend an hour and a half, two hours where we could pose questions, go back and forth and have conversations, and we could really dig in. And then they asked some really hard questions around how do we do in things in industry? What can we do different in government? And so it was interesting to see how everyone responded and where there were some really great ideas, and maybe some ideas that weren't maybe always ready for government, but they're working out in commercial industry today in small, I'll say test cases. Um and a lot of the organizations that were there were younger startups. So think of round A, Round B, AI generated native companies that are, you know, a couple, a couple rounds of funding in, you know, they're 30, 50, 200 people. They're not, you know, 50,000 people. Now, some of the big folks were there certainly there as well. So, you know, if you're um familiar with some of the some of the folks that are out there there that uh that are larger cyber companies, a few of them were invited as well. Um we probably had four partners with Swish in the room, and so it was interesting to see and interact with some folks that we've known a long time, and and their input was certainly very valuable. And a lot of them are building AI into these large platforms. The question is how do you maybe it's a typical innovator's dilemma, Brian, right? You have a development team, you've got a revenue stream, you've got a lot of customers that use it and they know how to use it. And then you go, well, how do we blow this thing up and change it? And and you almost have to build a separate product team, some little part of the company, or you have to buy and acquire a new company and fold them in and then help them go build that next gen thing, or snap that AI capability into your existing product. So that's that's from an industry perspective, that's always hard. Um, and it gets back to kind of the behavior of the organization and just the kind of the gravity of core products and core product lines or business units, and be a being willing to maybe build something that's unprofitable and game-changing for two, three, four or five years sometimes until the industry is caught up. And then you eventually make a money with it. So that's that's the hard part.
Brian LakeTalk to me a little bit about like the themes that you were hearing from these presentations, both from the government side as well from the industry. And and before before we even dig into that, I'm glad to hear you know that there were some of these early stage startups. I know we talked uh recently on a previous podcast about the challenges of some of these startups to enter into the government ecosystem, but it's really great to hear that you know they were some of the you know the organizations represented in the room because they're bringing a lot of new ideas and they can move at a different speed uh than a lot of these other organizations. So, but that that's wonderful, fantastic. Glad to hear that. Uh, you know, bully on the Federal Assiso Council for making sure that they were included. But what were the big major themes you heard uh in in the room?
Sean ApplegateYeah, and maybe one thing to tie off on the last question. The day wrapped up with demos and lunch. So we'll get into that later, probably. Okay. Key themes for the day.
Data Silos And SOC Automation
Sean ApplegateData, data was a core topic. It's crazy. Every time we talk about AI or agents or solving problems, data is somewhere in the conversation. And a lot of this gets back to having the right data, the right fidelity of data, bringing it together as much as possible is super important. So if we have an agent, if we have a SOC agent, for example, we'd have to be able to go find the data, access the data. Some of that will get easier over time. We'll talk a bit about that in a minute, probably, and maybe maybe new technical ways to make it easier. So you don't have to bring it all together. But data is very still very much fragmented in large agencies. And so think of data and agencies. You've got the parent organization, the most senior department, and then you've got components underneath them that also have their own cyber tool, their own data sets, their own desktops they manage. And so think of potentially having to manage layers of the department and then the agencies or the components underneath them. These are problems that most commercial systems don't have because they're not a million employees or 300,000 employees, and they don't have the bureaucracy and the legal limitations around them in some cases, um on what they can do or can or can't collect. And so data is very fragmented, it's siloed, it's unstructured in many cases. And then the question becomes, well, how do we bring AI into that environment and make it function at scale if it doesn't have all the data? So those are one of the that's a common theme. And the second was a lot of folks really wanted to get to federated data and federated search. And that that may be the perfect panacea, but it may not be realistic when you think of all cyber capabilities and different types of things. When you think of governance, operational data, patching and vulnerabilities, and exploit management, and then all your cyberlogging for the SOC. That's tricky. And so one of the topics that came up was you know, can we use model context protocol for the agent to be able to go to the data instead of bringing the data to the agent? And can we use uh retriever augmented generation to drive better context? And I think more recently, and this didn't really come up a lot in the session, but skills have become a very important thing. We've talked about this before, Brian. I think having really good SOC skills are important. We did talk a little bit about SOC skills in the event and about, hey, could we build SOC skills and markdown files maybe for people to share? But that was kind of discussed in small pockets of the thing, not in the big over-ring, big overarching conversation. It wouldn't be it wouldn't be a podcast episode without markdown files or OODA loops, right? Yeah. And at the end of the day, right, it uh this really gets back to operational efficiency and process improvements. So things like, hey, how many, how many, how can we patch faster? Can we address exploits quicker? Can we do ATOs quicker? Can we do governance more effectively at scale across thousands of IT employees in their systems? Um, and ideally, can we hunt and find incidents or find bad guys faster? And can we then respond to those incidents quicker and in a more automated fashion? I mean, at the end of the day, um the SISOs need to be able to operate in the SOC needs to be operated very quickly. So they have to be able to pick up the pace of the mission and um and do that in ways that are maybe a little different than they've they've done them for the last five or 10 or 15 years.
Brian LakeDo you think that uh is there a level of comfort when it comes to using AI to secure to secure these environments when it comes to these federal CISOs? You know, where what does that look like in their mindset um right now? Yeah.
Sean ApplegateWell, you if you break federal into a few areas, it's certainly more comfortable. It's some more open organizations that are cloud native and maybe less risk adverse. And there's somewhere where they're not as comfortable with it. And some of this may be because they're just air-gapped, more sensitive environments, harder to just use commercially available frameworks that are FedRamped, for example. So you're gonna deploy them on-prem. So I think the answer is they're very comfortable using AI for cybersecurity. They are not as familiar with securing AI. And so you'll find, I think long term, the need for a CISO and their security architects to work very closely with the chief artificial intelligence officer will become increasingly important, and especially their developers that are building those agents or building the AI capabilities to help the SOC potentially. And a lot of this it gets back to do they build their own custom agents on a on a general platform or do they adopt specialized security agents from industry? Or do they have bicommercial off-the-shelf tools that happen to have an agent or generative AI built built into those as well? So the answer might be all three for large organizations, but for small organizations, they're they're probably gonna be budget constrained and need to make some tough choices on where do they spend that dollar for the biggest return on investment. And so, you know, and that naturally gets you back to hey, you know, how proactively can we be? If you're a bad guy, you know, you're running the offensive side of things, and you're gonna, you know, think like the hacker, get out in front of those things, and then shore up your kind of uh weak underbelly areas. And again, most federal agencies have done a really good job there, um, but it isn't gonna stop the hackers from using more advanced attack techniques that are better crafted. Um, we'll see that with like um the Venom attack sector here recently, where they're using some really well-crafted attacks in the middle of techniques with Office 365 SharePoint, share document looking things that look very real um and are easy to miss as a average employee that just wants to be able to work with a with a partner that looks like they shared a doc with you, but they really, really didn't, right? Um, and then on the defensive side, it's really about securing you know, that end-to-end environment. So again, doing things like probably low-hanging fruit, doing red teaming with AI makes a lot of sense typically, because it's expensive, it's human capital intensive, and you don't do it very often. But when you do do do it, you typically get a lot of value. So that's an area, you know, we think in using AI, there's a ton of value in using AI-powered red teaming or using AI-powered red teaming to target your AI systems, which are typically the least secure right now.
Brian LakeYou mentioned agents a qu a couple of different times. Was agentic AI like a key theme in the room? Was it we're struggling to, I mean, it sounds like we're struggling to understand how to use AI just in general, but now like that next step of an agentic AI future? I mean, are was there a clear understanding about what agentic AI means and the implications for these government agencies? I think they have a a clear vision of what they would love to have.
Sean ApplegateNow the question's gonna be hey, from from building specialized agents that can do those different jobs across the security team or the CISO staff, which ones are the ones you need to lean into first, experiment with first, and and figure things out with? And I think the SOC, you know, agentec platform is probably the one that's of most interest because it's it's where they have a lot of staff. That's where the most critical problems happen. That's also where there's probably a ton of value in defending the environment, right? When you think of cyber network defenses or defending your applications or AI. So I think that's an area that's going to be very promising for a lot of CISOs. And there are four or five startups in the space that are net new, brand new, laser focused on that area of challenges. And um, you know, a few of maybe one or two or three have gotten a few federal buys. So they're early days.
Brian LakeWe'll see how they shake out. Okay. Well, so I'm hearing three themes coming out of that. Data is the real foundation, a real need to focus on governance and process improvements, and really starting to really wrap their brains around the different players and participants to create a truly offensive, defensive AI capability without. federal government. So that that with those themes in mind, you know, you mentioned there were demos. Like so talk to us a little bit about like the demos, what what is good looking like? You mentioned that there was uh you know an agentic sock you know uh organization in the room. So uh what what what did you see and what was what was some of the most interesting things that came out of it from your perspective.
Red Teaming Demos And Cyber Ranges
Sean ApplegateSo when you think of the demo format they basically had themed rooms where they bucketed different vendors let's say between two to three vendors per room and uh it's like speed dating, right? So everybody gets 20 minutes to present their demo. There's some government guys in a room they ask you some questions you're not really sure where they're from you try to tease it out you do the dance and uh and then then you you kind of break away from there after doing your little demo. Now the nice thing is every one of those demos was recorded and is is now available to the federal CISO Council through their kind of intranet means so if you're a federal employee feel free to head over to the Federal CISO Council resources at OMB you can look at all of these demos go see them yourself. The the thing was you couldn't make them all right you can make a handful. Now most of the the the industry members were encouraged to just do their demo but not sit in on everybody else's demos. So um I didn't see a bunch of the demos but um we had uh you know lasso did it was who I was with so LASO security did a red teaming demo with uh purple what we call purple teaming so they basically had automated guardrails and those guardrails tied into things like the OWASP top 10, the AI vulnerability scoring system and AI UC1 which is a brand new um framework that's commercially available it's built by like 500 SISOs and a lot of Fortune 100 SISOs around building secure AI agentic applications. So it was really cool to see how they can kind of reduce the ODA loop from finding vulnerabilities where they can do 3000 different attack vectors and it it can do adaptive attacking. So it learns your app and then creates its own custom attacks a lot like Anthropic Mythos does. But it's truly AI powered and can get really creative with the agents and then fix things quick. And so we showed that it was really impressive. We had another company in our room called SimSpace and they do simulated cyber environments a lot of think of like training environments and places where you can go beat things up and they were able to do full stack simulations which was pretty interesting because a lot of the simulations I've been in the past were like network simulations but you couldn't yet attack like real applications separately or real hardware separately. These guys could bring in containers and hypervisors and applications and they had a bunch of threat attacks already in and so it was a really powerful cyber range so it was cool to think about hey could we take things like lasso security within with an external red teaming and then build up the customer's application environment into sim space and then go attack that with a red team and then could we put guardrails in it and almost run like a real time you know bleak blue blue team red team type of scenario. Really cool for training. Anyways that was an example that the more importantly they had desserts Brian so that was that was probably the more important part was we we break after the demos you head back to the uh the Indian treaty room and the White House has amazing cupcakes these little Hershey Kisses boxes and the box that was uh signed by Donald Trump himself, right? The uh the stamped on signature so beautiful presentation everybody loved the cupcakes it was yeah this administration is real good at the at branding yeah yeah so we uh you know we all got got enough of our uh you know testing and tolling and um again a lot of a lot of this stuff was tied into to optimizing a SOC, doing governance automated, doing continuous ATOs, using agents to write the ATO or get the ATO answers out of out of unstructured data. So there were there were lots of breadth in the demos. And then when you think of the bigger vendors most of them are adding some type of either agentic or have already added some large language model capability. So I think from the the large traditional partners there's a lot of promising things coming. You know one of one of my favorites is um Elastic has this AI workflow capability and you can plug in your own LLM on the back end. So for a lot of our Department of work customers or IC customers or more sensitive workloads, you can deploy that air gap to plug it into whatever LLM you want or it could be a cloud LLM like bedrock and um you know build your own workflows custom really fast. And so there's a lot of interesting things you can do with that without without a lot of lift to be honest and it's very adaptable. So those are some of the things we saw.
Build Vs Buy Agentic SOC
Brian LakeIs it is it uh I mean for government agencies is it better to at this stage I mean historically the government has built and been very custom architectures very custom you know use cases uh which has caused a ton of legacy debt within the federal government when it comes to this agentic sock kind of mentality is it better to build or buy at this stage for for these government agencies um you know what what's the what's the mindset there?
Sean ApplegateThis is Sean's opinion and I've been around the government for for just a just a minute. I think most of the agencies are going to get more value by by buying a purpose built agitic sock platform. And and again there's a there's probably four or five companies laser focused on that and then there are our broader platform plays where that stuff starting to be developed by larger companies pretty quick. So I think you're gonna have to assess what your environment looks like kick the tires on a few few environments a few things and give it a shot. But my my concern is the the typical federal system integrated being paid to run a SOC is really incentivized to put butts in seats and protect their people. And while they certainly want to optimize how they work their their contract does not incur typically incentivize them to make technology investments, to do process uh you know optimization um on the government's behalf at least. And so there's a bit of, I think where we've always tried to drive big strategic change in a program, it's sometimes tricky to do that with the way the contract is structured and for the services piece of it at least. So I think there's going to be a need for a lot of strong government leadership to kind of grab the torch, set clear direction and lead both our government workers and their contractors to where they want to go. And that's a challenge for the CISOs probably and it may require some contracts to get them sunset and put some new new structures in place with different incentives potentially. But we need to be laser focused on how do we do that and and work on that from an engineering and design perspective. So I think the organizations have really strong enterprise architects really strong creators and the government will typically do much better here. And when you think of breaking breaking that SOC function up and it's really the functions they broke up and themed into like three big areas, right? We broke them into governance and ATO compliance. And some of this could layer a bit into like security posture management. So it was like hey how are things running? Are they configured properly? What are our vulnerabilities and exploits and how do we configure things to address all those things to mitigate risk. We have the typical kind of hunt, detect and respond with just really kind of core SOC functions, right? So hey I have alerts coming in I need to go research those things and I need to either figure out if it's a false positive or positive and I need to go address something right. In some cases that's can be a small quick in and out it could be something much more robust. But that's where using agents to do the uh find the data patterns, find the indicators of compromise, connect the dots from a knowledge graph or a graph query language really quickly, find those patterns, document it all, and then make recommendations to a human in a loop so they can you know approve it or deny it or maybe tweak it is important. And that that's probably the most important thing the CISOs can do. And that's where a lot of like the startups are focused. And then operations and process redesign is huge. And this is where it really is going to fall on the humans to help figure that out draft it and then get have to be really comfortable with rapid change and retraining and reskilling their employees. We were in a ATARC working group or I guess roundtable right earlier this week Brian and uh one of our customers was really focused on hey as we do AI and AI security, we have to reskill all of our employees and we've seen this in uh a lot of other customers that are doing reskilling right now and I I'm talking reskilling at the like secretary of the agency level not just at the the middle management level. So it's been impressive to see the reskilling happen. But I think the more we more we all buy in on get comfortable with AI, get comfortable with new technology and and feel it, the quicker we'll be able to change and move and collaborate.
Shared Services And Workforce Reskilling
Brian LakeI mean this is no longer just the CISO's problem or just the CDO's C DAO's problem it's not just the network team's problem or the app team's problem it's everyone's problem right we all gotta we all gotta figure this out and upskill our skills to ensure that we're all rowing in the right direction I think that's a really interesting point. So let me ask you this though it sounds like it could be expensive like how do small agencies or mid-sized civilian agencies you know really think about building relationships with vendors or if they've historically been using shared services through high impact service providers, how do they really think about this or think about trying to like bring these capabilities into their environments?
Sean ApplegateWhat's that look like yeah I think I think again back when you look at a small agency often understaffed so more work than there are people a little bit like the local some of the local government and state government things we've talked about in the past and again there's there are probably a hundred small independents in the federal government so not every agency is huge. I think they're gonna be best served by looking at shared service opportunities where they don't have to build and maintain things they they feed it their data and they get the dashboard and they get the workflows and they get the you know agentic benefit out of it. But they don't have to design it create it and host it and patch it, right? So I think that's a really good model. There certainly we're we're one or two SIS in room that are doing that today for other platforms and other I take traditional security services for their their organizations and lots of components and I think they'll be doing that for for some of the agentic workflows coming down the road. The other one is if you're if you're in the federal civilian executive branch, there's SIS SIM as a service model that's using Elastic framework and some really experienced integrators have been running the CDM program for a long time but extending that to collecting your your cyberlog data flowing that into an elastic powered engine and certainly they'll probably be building I would imagine a bunch of AI workflows on top of that and that's a pretty open platform so they'll be able to get really creative. Obviously you know Sys is a little understaffed right now and there's not a secretary running it. So hopefully we button button up the uh secretary thing here shortly and uh we get we get somebody in running the agency and uh but they've got really strong technical leadership on the government side there. Funding funding helps.
Is the Government Moving Fast Enough
Brian LakeLet's fund this agency gang. Let's let's go. So let me ask you we've we've spent the past two episodes kind of mapping the threads talking about how the government's responding the need to blow up and create a new playbook. What's the verdict in your mind? What what should practitioners on both sides of the aisle be really thinking about are we ready to do it? Are we doing it? Where's your head at here? Are we prepared?
Sean ApplegateEvery journey starts with the first step, Ryan from a the federal government saying hey AI powered security things are important for us. We we can't just talk about them we have to do them. This was an important first step. I mean other an individual certainly have taken first steps to do these things but it does signal the agency's urgency to accelerate and put more focus on it which I think is extremely promising. They claim they're going to do follow-on meetings and so if you're in the federal government and uh and you're in the CISO teams or you're a senior architect working for a CISO, I think being involved in these future activities around sprinting around using AI for cyber or securing AI is it's a great opportunity. It's probably a once in a lifetime moment as we think see this thing kind of take on a life of its own to really be a change agent in the organization. So look the energy the energy in the room was great. It was it was amazing a lot of great people want to achieve big things and and think out of the box. And so you know I think that the gap is typically what's technically feasible right now and who's comfortable trying some new things but maybe not succeeding, being comfortable with a risk and unknown and what can we actually deploy and get done and think about that probably over quarters not years in my opinion. We've seen a lot of change in the last 12 months there's only more change coming so don't don't sit back and be comfortable with where you're at I guess is the bottom line. You know rethink how you do that and that that may create some painful situations for either federal teams or integrators that need to learn new tools or new techniques. So just be comfortable not being comfortable.
Brian LakeWell I'm glad to hear that they're planning to do more events but I mean I think it's not the only opportunity in the space with with government industry collaboration. I know we're part of several organizations in the space that are laser focused on on building you know the bridge between industry and government ATARC, ACIAC, NVTC, OWASP I mean so where if you're in the industry or in the government, talk a little bit about some of these organizations that are out there and how they should be plugging in to try to continue this conversation even before the next uh event down in the White House.
Sean ApplegateYeah certainly yeah well so our favorite guy Tom Sutter was in the room who runs ATARC and uh yeah I mentioned to Tom at lunch that most of what was talked about at the CISO level early in the morning with industry, we were already talking about in the ATARC working groups whether it was the AgenTic AI working group, their Zero Trust working group their DevSecOps working group or even the continuous ATO worker. And so I they're so industry, you know government and industry driven and their ability to collect feedback and then adapt to what they the members want is amazing. So I was really excited about that. So my first recommendation is if you're not involved with ATARC, go get involved with the working group. You'll probably find one or two that really align with your day-to-day job that meet bi-weekly go join a working the other place Act IX Cyber community of interest is a great place they've also have an AI community of interest a number of the topics covered there were uh really on target and they had like for example they had an AI red teaming presentation maybe six months ago there with some open source libraries that you can use outside of that I yeah I would say the Federal CISO Council is great. And then on the community open source side the open web application security project is one of my favorites so if you want practical advice hands-on tangible controls and operational advice to do those things that's probably the in my case the most technical resource if you're an engineer applying things not just a leader running things to go go really leverage from that perspective so you know that's that's the bottom line right go learn engage other people in the community you'll be impressed with with who's who's around the working groups and the community interests that can share great thoughts and you don't have to do it on your own. Get out with people collaborate build good partnerships um roll your sleeves up and go go do it don't just talk about it yeah execution is the variable that's left right you have to actually do it.
Brian LakeI mean because honestly this is it's one of the most exciting times and to be in the government IT space the stakes have never been higher so I'm glad to hear that uh you were able to interact and engage down in the White House. I'm glad to hear that the administration is taking this seriously and trying to move at the speed of relevancy right now. So I think we all need to do our part. We all need to road together. Obviously listen man uh another great show really happy to hear about all your experiences uh I know you're getting ready to head on vacation and so I hope you have a wonderful time and we'll we'll be back uh when you're back and with more episodes with more interesting conversations with more guests so while you're out there everything's in the show notes let us know what we missed uh let us know what you want to talk about in the future want us to talk about come on be a guest subscribe wherever you listen go to gist360.com for any upcoming events around a lot of these different topics but as always my friend it's been a pleasure thanks for everything Sean thank you for listening everybody see you later