
Sign up to save your podcasts
Or


5G will be a massively transformative technology. This is an interview that shows you how the “mostly” 4G technology will be put on steroids with the transition to 5G. It is not just a numeral change; this new technology will impact enterprise systems all over the world.
Can 5G allow military applications to share spectrum?
Physically, we know that “dual use” means highly secure organizations, like the military using technology that is proven in the commercial world. The best example is military satellites “hitching” a ride on rockets with commercial satellites.
However, 5G has so much flexibility that allows the Department of Defense to apply the “dual use” concept to the communications spectrum.
Can federal applications take advantage of inexpensive hardware?
One of the main advantages of today’s data centers is using inexpensive generic hardware and varying the software. This concept of “disaggregation” can be applied through the flexibility that 5G offers.
Does 5G have an application in cybersecurity?
When it comes to patching software, the federal government needs speed. When gaps are found in systems, the speed of the patch is critical. The speed advantage of 5G allows the federal government to apply patches and update faster.
Where to invest 5 billion dollars
5G is forcing states like Louisiana to carefully consider how they should invest the estimated five billion dollars in infrastructure money they will be getting in the next five years. If a traditional fiber network can be destroyed by a weather event, what role should wireless play in bringing resilient high-speed access to rural areas?
According to Dr. Chase Cunningham, there are over 1.7 million ransomware attacks a day.1 This isn’t isolated to commercial organizations, these attacks include schools, hospitals, and state organizations.
Who pays? According to an article dated April 12, 2023, in VentureBeat Magazine, 83% of organizations paid up in ransomware attacks.2 What is the FBI policy on paying ransom? What happens when a state agency gets attacked?
Today we have two battle hardened cyber warriors who focus on state and local issues sharing details on how to prevent and recover from a ransomware attack.
organizations
“According to a recent survey conducted by Rubrik, 50% of respondents had dealt with ransomware attempts in the past year!” Steve Stone, Rubrik
Rubrik runs a lab that seeks out information on attackers. It is summed up nicely in four words.
“We operationalize evil finding,” Steven Stone, Rubrik
Some states have unique challenges in providing assistance or ransomware prevention. For example
“California has 58 counties, some are larger than the states that compromise the United States” Lloyd Indig, California
Twitter: @FedInsider
LinkedIn: https://www.linkedin.com/company/fedinsider/
Facebook: https://www.facebook.com/FedInsiderNews
In grade school, we all learned about states capitals and the geographic shape of each state. When you compare the way they manage technology, they vary drastically as well. When it comes to the way states structure their technology, some states are hierarchical, some are centrally controlled. Each state presents a unique way to solve the same problem: cybersecurity.
Today’s discussion combines federal leaders with technology experts from three states. Each person brings a different aspect to the discussion. One overriding theme that Solomon Adote reinforces is the importance of identity management. It seems to be the first pillar in the transition to a zero-trust architecture for federal as well as local governments.
= = = = = = = = = =
“Cybersecurity at the state level is a very interesting topic to me because every state is structured differently, every state IT organizational structure is different, and some have a very hierarchical structure and others are very centrally controlled and managed.” Michael Mestrovich, Rubrik
“Many of these federal programs we have in the states that do the work and all the data and interact with the citizens.” Suzette Kent
“People of Colorado and the people of Colorado are at different levels and stages of IT proficiency” Craig Hurter, Colorado
“Russian affiliated, organizations, they all have the ability with significant resources at their disposal, I think some have close to 740,000 bots at their disposal to generate a significant amount of traffic against any entity.” Solomon Adote Delaware
“But there has been workforce development change has come as a result of that as well” Jason Cavendish Michigan
“More significant in the public sector but is shared by the private sector is the talent challenge” Suzette Kent
Twitter: @FedInsider
LinkedIn: https://www.linkedin.com/company/fedinsider/
Facebook: https://www.facebook.com/FedInsiderNews
= = =
Most readers have seen the headlines about cyberattacks; a small percentage may even have been the target. The news media doesn’t seem to cover the many ways federal agencies are providing help to state and local territorial organizations. Federal agencies offer many ways to help understaffed local government. This includes providing resources, training, or directly helping. This is an interview with three federal experts who provide a tremendous amount of help for beleaguered state and local technology managers.
We all know the Secret Service was created by President Lincoln in 1865 to protect the currency. It is also obvious they provide physical protection for the President. What kind of information can they provide to state and local systems managers to prevent cyber-attacks?
The FBI, GAO, and CISA offer many suggestions and recommendations in the form of case studies and recommended practices. Did you know the Secret Service offers training opportunities at the National Computer Forensics Institute for state and local governments? Further, it has ways the federal government can pay for this training.
When most people think of the FBI they think of the iconic blue windbreaker, they are much more than that. Scott Nickerson reminds listeners of the 56 local FBI offices in the country. He thinks local organizations should reach out to these offices before a cyber-attack. They even have ways technology administrators can join the FBI cyber task force.
Twitter: @FEdInsider
LinkedIn: https://www.linkedin.com/company/fedinsider/
Facebook: https://www.facebook.com/FedInsiderNews
Ep. 95 Making Progress on the Zero Trust Journey
Leaders in the Federal Information Technology field plan to complete the Zero Trust transition over the next few years, but each will have their own unique path to follow.
In this week’s episode we’ve gathered thought leaders from HHS, the U.S. Census Bureau, the CIA and Rubrik to discuss this ever-important topic and what it means for each agency.
We’ll explore the idea that the approach to data itself has changed, and it has evolved from being a simple endpoint.
In his work as Tri-chair of a group being developed by HHS to work with multiple agencies in the Zero-Trust journey, Gerald Caron shares, “identity is very important if you talk about the pillars of zero trust.
Twitter: @FEdInsider
LinkedIn: https://www.linkedin.com/company/fedinsider/
Facebook: https://www.facebook.com/FedInsiderNews
By now you have heard of the millions of dollars the federal government is making available for 56 states and territories as well as 3,033 counties.
If you are interested in taking advantage of one of these grants, then you should listen to this interview with technology leaders who are intimately familiar with how grants are assigned to improve cybersecurity for states and territories.
Some basic rules: the funding will be distributed over four years. However, the awards are designed to be stretched out, so year #1 goes for four years, year #2 goes for four years, and so on.
Second, the states are expected to contribute an increasing portion of the investment. 10% of year one; 20% of year two; 30% of year four; 40% of year four.
The concept is to make sure the applicant has a good plan on how to effectively use the funds over a long period. According to CISA’s Trent Frazier, it is a formula-based grant program. The idea is for the states to use investments to close gaps or sustain abilities in cybersecurity. He suggests the best practice here is to identify vulnerabilities – how to use investment to mitigate risk
The experts address practical aspects. For example, counties vary in size and a smaller county may not have the resources to complete an application. Rita Reynolds from the National Association of Counties suggests that help is available with the application process.
Zhen Zhen Sun from Texas observes that this effort shouldn’t not just be a replacement of technology The idea is to replace technologies.
During today’s discussion, you will hear from subject matter experts who talk about what state and local organizations can do to prevent ransomware as well as how to prepare for the new funding opportunities that are targeted at improving defense against cyberattacks.
One of the biggest lessons of this discussion is the existential nature of a ransomware attack. According to Doug Levin from K-12 Security Exchange, in 2021 alone there were 166 cyberattacks in 66 schools. Six of those schools had to temporarily shut down.
The experts indicated three best practices: have a good understanding of your current situation, know what organizations offer free help, and get a grasp on how insurance works.
When you have a complete survey of your system, you will understand where you have gaps and that understanding will give you the ability to evaluate systems that can help. One unexpected consequence of this effort is this survey can help you complete an application for cyber insurance. Jennifer Lotze remarked that a few years ago her insurance policy application had a few questions; today’s is fourteen pages of requirements. Also, do not be surprised if rates have gone up 30% since your last inquiry.
Historically, state governments and schools have been underfunded when it comes to cybersecurity prevention. In an attempt to address this concern, the Infrastructure Investment and Jobs Act was passed in 2021. It allocated over one billion dollars to improve state, local, and tribal security between 2022 and 2025.
When it comes to free services, the discussion uncovered many resources. For starters, CISA offers Cyber Resilience Review and Ransomware Readiness Assessment; they are free assessments to know what is going on in your network.
The Department of Education offers a website called “Protecting Student Privacy” as a service from the Privacy Technical Assistance Center that provides up-to-date information on safe practices.
Listen to the discussion to get fantastic tips on prevention, free resources, and suggestions on how to navigate the turbulent waters of cyber insurance.
When it comes to modernization for federal IT most people focus on data centers, clouds, and agile software development. One key part of this effort must be acquisition. This is a discussion where subject matter experts from several agencies look at some new mandates from the executive office and detail how they are implementing them.
One key motivator is the FAR change that includes recommendations to open conversations with contractors and be more transparent. The goal is to open federal procurement to make it more equitable.
Craig Morgan from the DCMA details how they have a website that shows their strategic plan for modernizing tools and integrating the enterprise environment. They want to unify data so customers can make well-informed acquisition decisions. All participants point out how they are making their acquisition process more transparent.
One of the most remarkable approaches was from Monica Taylor from DHA. She discusses her success using the Procurement Innovation Lab. They have coached 148 procurement teams to lower the barrier for innovative contractors. The net result has been to encourage nontraditional contractors. The GSA takes the lead in this category with a website that includes The Nine Innovative Acquisition Practices as well as articles dedicated to keeping federal acquisition experts informed in areas of acquisition innovation.
Technology can assist in making the federal acquisition question system more equitable. Brian McCormick from ICF points out that some agencies suffer from siloed systems, separate data sets, and isolated workflows that prevent teams in agencies from communicating accurately.
Brian suggests that platforms exist that can implement Robotic Process Automation and protective analytics, better-leveraging data to make better-informed decisions. Procurement professionals can look at their experience with procurement and see trends. Perhaps they can see preferences for a certain kind of vendor. From there, they can address ways to make their acquisition more balanced.
This is such a detailed and nuanced conversation. Dive in to hear comments on The Price Act, The Chip Act, and much more.
When it comes to a top ten list of trending phrases in the category of technology, “backup” never cracks the top ten. After all, you merely make a copy of the existing data --- right?
Well, the millions of dollars have been lost to ransomware attacks have caused a sea change in approach to backups. In fact, after listening to this interview, you will see backup as an inflection point for recovery
The consensus of the subject matter experts in this discussion is to establish a strategy to prevent an attack and well as have policies in place after an attack.
One issue is the deployment of resources. Some governmental organizations are “siloed” to an extent that works to the benefit of attackers. One scenario is the security teams think the backup is managed by the backup team; the backup thinks security is someone else’s job. This causes delays in response time. The best practice here is to have tabletop exercises where stakeholders know exactly what to do in case of an attack.
Traditional ideas of backing up once a day are finished. One must consider backing up every four hours. On top of that, one must know where an accurate backup point exists.
During the discussion, Joseph King from CAS Severn indicated that phishing attacks resulted in a $20 billion loss in 2021 and government teams must not underestimate their opponent.
Comments from all participants indicate that cybersecurity is a cat-and-mouse game. Government agencies have backups, the attackers put malicious code in the backup. If one uses immutable technology for the backups, then the attackers move to the next level.
Joshua Stenhouse from Rubrik talks about current attacks where the policy for retention is changed. That way, they fool the organization into not retaining data at all. If you are considering a backup option, then immutability and policy structure must be included in the requirements.
The interview gives great advice for systems managers: do not assume backups will be there, you should evaluate your backups in a virtual environment, and don’t expect you can recover up to the last serviceable date.
Decades ago, system administrators would dream about having the storage we have today. Very few considered the ramifications of controlling and allowing access to petabytes of data that were increasing every day.
This is an interview with several experts from federal and state organizations who share challenges in handling large amounts of data whose access must be carefully managed. Considerations include compliance, retention, and making sure the data is accurate.
One concept discussed is data sharing. Jennifer Coester from the State of Delaware talks about groups who all agree that data must be shared between departments. The caveat is that they want access to other information but want to restrict access to theirs. Perhaps this is not a technical issue, but a concept that should be handled in management.
Administrative aspects of managing data were reflected in comments from David Sanchez from the Air Force. He handles completely different kinds of information and data. He observes that military organizations are so structured that initiatives from a high level may take time to trickle down to lower-level areas.
As an example, he cites policies for giving access to data. One size does not fit all. Policies for accessing nuclear data certainly vary from policies that involve medical information. Each functional area must have its own policies.
Medicare, Medicaid, and healthcare.gov each have tremendous amounts of information, with each category subject to specific legal limits to access. George Linares from the CMS shares with listeners how they have successfully been able to tag data by domains.
He does warn that just because you have figured out how to manage the existing system does not mean that you will not have challenges. There is a new federal initiative to examine health care from an equity perspective. Data scientists must be able to go back to existing systems and pull up pertinent information that will assist in evaluating new topics like this.
From the publisher's feed