<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet media="screen" type="text/xsl" href="https://one.sightlinemg.com/federaltimes/wp-content/themes/smg/assets/xslt/rss-xslt.xml"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
xmlns:news="http://www.pugpig.com/news"
>

<channel>
	<title>Federal Times - Federal Times</title>
	<atom:link href="https://one.sightlinemg.com/federaltimes/author/justin-lynch/feed/" rel="self" type="application/rss+xml" />
	<link>https://one.sightlinemg.com/federaltimes</link>
	<description>Federal Times</description>
	<lastBuildDate>Sat, 08 Aug 2026 18:43:07 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://one.sightlinemg.com/wp-content/uploads/2026/06/favicon-fed.png?w=32</url>
	<title>Federal Times - Federal Times</title>
	<link>https://one.sightlinemg.com/federaltimes</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">255331619</site><atom:link rel="next" type="application/rss+xml" href="https://one.sightlinemg.com/federaltimes/feed/?paged=2" />
	<item>
		<title>How the security clearance backlog hurts cybersecurity</title>
		<link>https://one.sightlinemg.com/federaltimes/home/2019/02/15/how-the-security-clearance-backlog-hurts-cybersecurity/</link>
					<comments>https://one.sightlinemg.com/federaltimes/home/2019/02/15/how-the-security-clearance-backlog-hurts-cybersecurity/#respond</comments>
		
		<dc:creator><![CDATA[Justin Lynch]]></dc:creator>
		<pubDate>Fri, 15 Feb 2019 00:04:30 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Newsletters]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2019/02/15/how-the-security-clearance-backlog-hurts-cybersecurity/</guid>

					<description><![CDATA[Tempers flared during a Feb. 14 Senate hearing about cybersecurity in the energy sector.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/home/2019/02/15/how-the-security-clearance-backlog-hurts-cybersecurity/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">28556</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/Security-Badge.jpg.jpg" width="1199" height="708" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Tempers flared over a backlog of security clearances during a Feb. 14 Senate hearing about vulnerabilities in the energy sector, with lawmakers raising concern that the issue was leading to poor cybersecurity.</p>



<p class="wp-block-paragraph">The exchange began when Sen. Martha McSally, R- Ariz., questioned if there was enough informatjon sharing. </p>



<p class="wp-block-paragraph">“Vertical information sharing amongst the government and with the private sector is something that is lacking,” McSally said. “The clearance issues, the opportunity to do tare lines so that the information can be shared out there is really important.”</p>



<p class="wp-block-paragraph">In response, Karen Evans, the assistant secretary for cybersecurity at the Department of Energy, agreed that “the clearance process is an amorphous process.”</p>



<p class="wp-block-paragraph">Energy committee chairwoman Sen. Lisa Murkowski, R-Alaska, continued: “We have heard that time and time and time again. I understand that it is still an issue even though we had addressed it through the fast tracks, that we continue to have holdups through the FBI.”</p>



<p class="wp-block-paragraph">Sen. Angus King, I-Maine, expanded on the frustration with the background investigations bottleneck.</p>



<p class="wp-block-paragraph">“The last time we checked in the intelligence committee there was a backlog of something like 750,000 security clearances. It’s a huge problem,” King said.</p>



<p class="wp-block-paragraph">In fiscal 2016, only 10 percent of executive agencies <a href="https://www.gao.gov/assets/690/688918.pdf">reviewed</a> in a Government Accountability Office report met timeliness standards for Top Secret clearances. But the American government has made some efforts to fix issues with security clearances in the cybersecurity sector.</p>



<p class="wp-block-paragraph">During the 2018 midterm election season, the Department of Homeland Security pushed for more state and local officials to receive security clearances so they could receive classified threat briefings. Programs were also created to read-in executives of critical infrastructure sectors about cybersecurity threats the intelligence community was monitoring.</p>



<p class="wp-block-paragraph">However, there have also been some setbacks.</p>



<p class="wp-block-paragraph">Efforts from Sen. Mark Warner, D-Va. to reform the security clearance process in the 2019 Intelligence Authorization Act were stifled at the last moment and not included in the final bill. However, Warner has continued to push for the measure in new legislation <a href="https://www.warner.senate.gov/public/index.cfm/2019/2/vice-chairman-warner-reintroduces-legislation-to-revamp-security-clearance-process">proposed</a> Feb. 1.</p>



<p class="wp-block-paragraph">“The current vetting process for security clearances and positions of trust is too complicated, takes too long, costs too much, and fails to capitalize on modern technology and processes,” Warner said. “We must act now, especially amidst allegations of inappropriate granting and revoking of clearances and anxieties caused by the government shutdown.”</p>
]]></content:encoded>
	</item>
		<item>
		<title>Department of Homeland Security warns of cyberattacks on third-party companies by China</title>
		<link>https://one.sightlinemg.com/federaltimes/home/2019/02/07/department-of-homeland-security-warns-of-cyberattacks-on-third-party-companies-by-china/</link>
					<comments>https://one.sightlinemg.com/federaltimes/home/2019/02/07/department-of-homeland-security-warns-of-cyberattacks-on-third-party-companies-by-china/#respond</comments>
		
		<dc:creator><![CDATA[Justin Lynch]]></dc:creator>
		<pubDate>Thu, 07 Feb 2019 21:15:22 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Newsletters]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2019/02/07/department-of-homeland-security-warns-of-cyberattacks-on-third-party-companies-by-china/</guid>

					<description><![CDATA[Infiltrating third-party companies that store confidential details about swathes of other businesses is more efficient than targeting those firms individually, according to the Department of Homeland Security and information security analysts.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/home/2019/02/07/department-of-homeland-security-warns-of-cyberattacks-on-third-party-companies-by-china/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">9306</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/DHS.jpg.jpg" width="900" height="608" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph"><a href="https://www.fifthdomain.com/dod/2018/10/08/theres-a-serious-threat-to-the-supply-chain-says-pentagon/" target=_blank>Chinese</a> hackers have done the math and have figured out that infiltrating the third-party <a href="https://www.fifthdomain.com/critical-infrastructure/2018/06/12/chinese-attacks-on-contractors-a-phenomenon-on-the-rise/" target=_blank>companies</a> that store confidential details about big businesses is more efficient than attacking each of those firms individually, Department of Homeland Security and information security analysts said.</p>



<p class="wp-block-paragraph">&#8220;You can outsource your operations but you cannot outsource your risk,” Bradford Wilkie, head of stakeholder engagement at the Department of Homeland Security’s cyber division said during a Feb. 6 briefing.</p>



<p class="wp-block-paragraph">The Department of Homeland Security and the information security firms, Recorded Future and Rapid 7, said that the Chinese government sponsored <a href="https://www.fifthdomain.com/international/2018/12/14/the-nsa-and-china-feuded-in-cyberspace-in-2014-will-they-again/" target=_blank>group APT10</a> is responsible for attacking third-party companies that could leave the door open to a broad swath of potential victims. Examples of third-party companies include cloud service providers, data storage companies, internet providers and credit card companies.</p>



<p class="wp-block-paragraph">“Malicious cyber actors working on behalf of the Chinese government have been targeting managed cloud service providers,” Wilkie said.</p>



<p class="wp-block-paragraph">The Chinese embassy in Washington D.C. did not respond to a request for comment.</p>



<p class="wp-block-paragraph">DHS officials specifically warned about the Cloud Hopper campaign, one that targets managed service providers who store sensitive details from the finance, telecommunications, biotechnology, consulting, and automotive industries. The Chinese hacking campaign is not limited to one location and has been spotted on every continent, according to a Homeland Security slide.</p>



<p class="wp-block-paragraph">“This actor sweeps up collateral targets of opportunity, in addition to their primary targets of interest,” another slide said.</p>



<p class="wp-block-paragraph">“In general, they are using widely available tools or living-off-the-land,” said Casey Kahsen, an incident response engagement lead at the Department of Homeland Security. “That’s part of what makes attribution so difficult.”</p>



<p class="wp-block-paragraph">The hacking effort is tied to China’s five-year plan that promotes economic growth in the fields of robotics, next-generation information technology and biotechnology, according to the Department of Homeland Security.</p>



<p class="wp-block-paragraph">Recorded Future and Rapid 7 also released a joint report Feb. 6 that warned of hackers targeting third-party service providers. The report cited the infiltration of Visma, a Norway-based cloud services provider worth more than $1 billion as an example.</p>



<p class="wp-block-paragraph">“We assess that APT10 likely compromised Visma with the primary goal of enabling secondary intrusions onto their client networks, and not of stealing Visma intellectual property,” the joint report said.</p>



<p class="wp-block-paragraph">An international apparel company and a U.S. law firm with experience in intellectual property law were also targeted by similar campaigns, the report said.</p>



<p class="wp-block-paragraph">“It’s a lot more efficient to victimize a managed service provider if you know that 10 of your potential targets use that managed service provider for say, internet access,” said Priscilla Moriuchi, director of strategic threat development at Recorded Future told Fifth Domain.</p>



<p class="wp-block-paragraph">“The global business community doesn’t have a handle on” supply chain management,&#8221; Moriuchi said. “Attackers know that. In this case we’ve seen the [Chinese] Ministry of State Security. The [Russian] GRU and likely a lot of others in the future are going to be employing a technique to attack third-party supply chains.”</p>
]]></content:encoded>
	</item>
		<item>
		<title>Surprising ways the government shutdown actually boosted federal cybersecurity</title>
		<link>https://one.sightlinemg.com/federaltimes/uncategorized/2019/01/30/surprising-ways-the-government-shutdown-actually-boosted-cybersecurity/</link>
					<comments>https://one.sightlinemg.com/federaltimes/uncategorized/2019/01/30/surprising-ways-the-government-shutdown-actually-boosted-cybersecurity/#respond</comments>
		
		<dc:creator><![CDATA[Justin Lynch]]></dc:creator>
		<pubDate>Wed, 30 Jan 2019 19:27:29 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2019/01/30/surprising-ways-the-government-shutdown-actually-boosted-cybersecurity/</guid>

					<description><![CDATA[New research shows how the shutdown did and didn't impact the government’s digital defenses.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/uncategorized/2019/01/30/surprising-ways-the-government-shutdown-actually-boosted-cybersecurity/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">11265</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/AP18261677876721.jpg.jpg" width="1200" height="774" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Lawmakers and IT security analysts have warned that the 35-day partial government shutdown crippled cybersecurity of federal networks. However, new <a href="https://na01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsecurityscorecard.com%2Fresources%2Fcybersecurity-impact-analysis-of-us-government-shutdown-report&#038;data=02%7C01%7Cjlynch%40fifthdomain.com%7Ccc866d8e98cb4f98312108d6862afdb8%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C0%7C636843917118435588&#038;sdata=154%2F8RHUZHUgpT%2BN8v28yMe7RQU0Bix6w%2BM7MIpsNbg%3D&#038;reserved=0" target=_blank>research</a> shows that the shutdown actually boosted the federal government’s digital defenses in some areas.</p>



<p class="wp-block-paragraph">Security Scorecard, an organization that tests cybersecurity, found that both endpoint security and patching actually increased inside the federal government during the five-week partial shutdown.</p>



<p class="wp-block-paragraph">The study illustrates the complicated nature of improving cybersecurity inside the federal government and the overwhelming workloads IT officials face.</p>



<p class="wp-block-paragraph">“The most secure computer is one that is turned off, and there were a lot of turned off computers during the shutdown,” Alex Heid, chief research officer at Security Scorecard, told Fifth Domain. “We saw a drop in internet traffic coming from .gov during the shutdown,” which made the federal government “less of an exploitable attack vector.”</p>



<p class="wp-block-paragraph">And for the computers that were on, the Security Scorecard research found that patching, or applying critical updates, experienced a 1.38 percent gain during the <a href="https://www.fifthdomain.com/congress/2019/01/09/why-the-shutdown-could-aggravate-the-cyber-workforce-gap/" target=_blank>shutdown</a>.</p>



<p class="wp-block-paragraph">Two potential reasons were cited. First, many essential security employees of the U.S. government were still working — with pay or without — during the federal shutdown. And because traffic was significantly reduced it was easier to patch devices during the <a href="https://www.defensenews.com/video/2019/01/14/how-the-shutdown-is-affecting-federal-cybersecurity/" target="_blank">shutdown</a>.</p>



<p class="wp-block-paragraph">“A lot of the more critical functions of the federal government continued to operate and it seems that patching exploitable conditions was one of them,” Heid said.</p>



<p class="wp-block-paragraph">Federal employee workstations and mobile devices are considered to be the most vulnerable attack vectors, according to Security Scorecard.</p>



<p class="wp-block-paragraph">The research also found that there was a 9.16 percent increase in endpoint security during the partial shutdown, which is correlated to the total number of internet traffic.</p>



<p class="wp-block-paragraph">“Since the U.S. federal government was shut down, so were many of the workstations and endpoints. There was a noticeable drop in internet browsing traffic coming from the U.S. federal government,” the report said.</p>



<p class="wp-block-paragraph">However, the report from Security Scorecard was not all positive.</p>



<p class="wp-block-paragraph">The research found that network security decreased by 1.58 percent during the shutdown, which was caused by a rise in expiration of SSL certificates, which ensure encryption between a computer and a website. Still, this change was within the normal patterns of the U.S. government, according to Security Scorecard.</p>



<p class="wp-block-paragraph">Heid admitted that he was “surprised by what we found,” but that it “makes a lot of sense.”</p>



<p class="wp-block-paragraph">The federal government typically has some of the worst cybersecurity standards, according to the Security Scorecard report, although it has marginally increased over the past few years.</p>



<p class="wp-block-paragraph">Overall, Heid said the positive and negative findings of the shutdown balanced out.</p>



<p class="wp-block-paragraph">“There was very little impact from the standpoint of an external attack perspective,” Heid said. “The federal government’s network have always been a punching bag and incredibly vulnerable.”</p>
]]></content:encoded>
	</item>
		<item>
		<title>DHS orders ‘emergency directive’ to guard against hacks</title>
		<link>https://one.sightlinemg.com/federaltimes/cyber/2019/01/23/dhs-orders-emergency-directive-to-guard-against-hacks/</link>
					<comments>https://one.sightlinemg.com/federaltimes/cyber/2019/01/23/dhs-orders-emergency-directive-to-guard-against-hacks/#respond</comments>
		
		<dc:creator><![CDATA[Justin Lynch]]></dc:creator>
		<pubDate>Wed, 23 Jan 2019 22:25:37 +0000</pubDate>
				<category><![CDATA[Cyber]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2019/01/23/dhs-orders-emergency-directive-to-guard-against-hacks/</guid>

					<description><![CDATA[The Department of Homeland Security said in Jan. 22 emergency directive that multiple executive agency websites have been impacted by a hacking campaign that has been linked to Iran.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/cyber/2019/01/23/dhs-orders-emergency-directive-to-guard-against-hacks/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">32088</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/DHS.jpg.jpg" width="900" height="608" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">The Department of Homeland Security <a href="https://cyber.dhs.gov/ed/19-01/#fn:1" target=_blank>said</a> in Jan. 22 emergency directive that multiple executive agency websites have been harmed by a hacking campaign, although it is not clear what exactly has been affected or which agencies are involved.</p>



<p class="wp-block-paragraph">The attack involves targeting the Domain Name System, the department said, which is the backbone of the internet’s address system.</p>



<p class="wp-block-paragraph">“Using compromised credentials, an attacker can modify the location to which an organization’s domain name resources resolve,” the department’s Computer Emergency Readiness Team <a href="https://www.us-cert.gov/ncas/current-activity/2019/01/10/DNS-Infrastructure-Hijacking-Campaign" target="_blank">said</a> Jan. 10 in a post on DNS hijacking. “This enables the attacker to redirect user traffic to attacker-controlled infrastructure and obtain valid encryption certificates for an organization’s domain names, enabling man-in-the-middle attacks.”</p>



<p class="wp-block-paragraph">Homeland Security ordered federal agencies to take four steps within 10 business days. That process included auditing DNS records, changing DNS account passwords, adding multi-factor authentication and monitoring certificate logs. It’s not clear how many employees will be effected by the change or if the changes can take place during a partial government shutdown.</p>



<p class="wp-block-paragraph"><a href="https://www.washingtonpost.com/world/national-security/dhs-issues-emergency-order-to-civilian-agencies-to-squelch-cyber-hijacking-campaign-that-private-analysts-say-could-be-linked-to-iran/2019/01/22/40a3fce2-1eab-11e9-8e21-59a09ff1e2a1_story.html?utm_campaign=EBB%201.23.19&amp;utm_medium=email&amp;utm_source=Sailthru&amp;utm_term=.89d54b9cfdcd" target="_blank">The Washington Post reported </a>that no intelligence or Defense Department networks have been affected, citing U.S. officials.</p>



<p class="wp-block-paragraph">The emergency directive is one of the most significant public operations undertaken by the Cybersecurity and Infrastructure Security Agency since it was created in November, 2018.</p>



<p class="wp-block-paragraph">In a previous update that detailed the DNS attack, Homeland Security referred to an <a href="https://www.fireeye.com/blog/threat-research/2019/01/global-dns-hijacking-campaign-dns-record-manipulation-at-scale.html" target="_blank">analysis</a> from the threat intelligence firm FireEye.</p>



<p class="wp-block-paragraph">Then, FireEye said the DNS hacking campaign has “affected dozens of domains belonging to government, telecommunications and internet infrastructure entities across the Middle East and North Africa, Europe and North America.”</p>



<p class="wp-block-paragraph">FireEye said there was evidence Iran was behind the campaign, citing IP addresses.</p>



<p class="wp-block-paragraph">The threat intelligence firm said it found no clear pattern in how the attackers gained access to the DNS files, but added that in some instances used “sophisticated phishing attacks.”</p>



<p class="wp-block-paragraph">“This type of attack is difficult to defend against, because valuable information can be stolen, even if an attacker is never able to get direct access to your organization’s network,” FireEye said. “This DNS hijacking, and the scale at which it has been exploited, showcases the continuing evolution in tactics from Iran-based actors.”</p>
]]></content:encoded>
	</item>
		<item>
		<title>With China looming, intelligence community backs AI research</title>
		<link>https://one.sightlinemg.com/federaltimes/home/2019/01/12/with-china-looming-intelligence-community-backs-ai-research/</link>
					<comments>https://one.sightlinemg.com/federaltimes/home/2019/01/12/with-china-looming-intelligence-community-backs-ai-research/#respond</comments>
		
		<dc:creator><![CDATA[Justin Lynch]]></dc:creator>
		<pubDate>Sat, 12 Jan 2019 01:51:34 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[IT & Cloud Report]]></category>
		<category><![CDATA[Newsletters]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2019/01/12/with-china-looming-intelligence-community-backs-ai-research/</guid>

					<description><![CDATA[The United States government is trying to boost its artificial intelligence capabilities with new research, according to public documents and experts.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/home/2019/01/12/with-china-looming-intelligence-community-backs-ai-research/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">28376</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/GettyImages-858052994.jpg.jpg" width="4200" height="2800" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">The U.S. government wants to boost its artificial intelligence capabilities or risks being left behind by the private sector and China.</p>



<p class="wp-block-paragraph">In the last two years, that’s meant new AI initiatives from the Pentagon, the Defense Advanced Research Projects Agency and the intelligence community. Now, the Intelligence Advanced Research Projects Activity is <a href="https://www.iarpa.gov/index.php/working-with-iarpa/requests-for-information/deep-learning">requesting</a> information about research efforts on “cutting-edge machine learning techniques.” IARPA posted the formal request for information Dec. 4. The deadline for industry to submit information is Jan. 17.</p>



<p class="wp-block-paragraph">“Of specific interest is the respondent’s knowledge of, and experience implementing, current, cutting-edge machine learning techniques,” the intelligence community’s research arm said. Respondents are required to have top secret clearances to work on the project, according to the IARPA listing.</p>



<p class="wp-block-paragraph">In addition to its deep learning program, IARPA leaders want information about research into “future computing systems” that can self-learn. Such a move could have implications for improving government cybersecurity.</p>



<p class="wp-block-paragraph">“The need for real-time (or near-real-time) analysis of massive amounts of heterogeneous data in this new era of explosive data growth has dramatically broadened the application space for advanced computers,” IARPA said. “The current volume and variety of data are already beginning to exceed the ability of today’s most advanced classical systems to deliver optimal solutions.”</p>



<p class="wp-block-paragraph">Most cyber threat detection platforms use some form of artificial intelligence to create warning indicators, according to public and private sector officials. However, the U.S. government is behind the private sector when it comes to use of AI, said James Yeager, the public sector vice president at cybersecurity firm Crowdstrike.</p>



<p class="wp-block-paragraph">“There is, by design, a more staggered type of approach to some of these advances in technology in the public sector, and as a result, the government is going to be behind the private sector,” Yeager said.</p>



<p class="wp-block-paragraph">IARPA has a “very high-risk-but-high-reward approach to solving complex problems. They take a lot of time and take a lot of resources,” said Yeager. “But If they can come out of that research project with a silver bullet, it is going to benefit everyone.”</p>



<p class="wp-block-paragraph">Andrew Laskow, a senior manager at Blue Prism, which provides AI products to federal government and defense agencies, said that in the U.S. government many people are “looking to AI for problems that they cannot solve.”</p>



<p class="wp-block-paragraph">“There is still a misunderstanding at the highest levels of what AI can and cannot do,” Laskow said.</p>



<p class="wp-block-paragraph">Public and private sector officials <a href="https://www.fifthdomain.com/thought-leadership/2018/11/28/how-artificial-intelligence-can-improve-cyber-systems/" target=_blank>warn</a> that AI-backed threat network indicators can overload users and create too many warnings.</p>



<p class="wp-block-paragraph">Michael McGeehan, head of business development at Blue Prism, described intelligent automation being broken down into the “thinking side” and the “execution side.”</p>



<p class="wp-block-paragraph">The artificial intelligence platform is the “thinking side” that makes decisions and is analogous to the human brain. On the other hand, robotic processing automation is the “execution side” that carries out tasks, like an arm or a leg.</p>
]]></content:encoded>
	</item>
		<item>
		<title>Why the shutdown could aggravate the cyber workforce gap</title>
		<link>https://one.sightlinemg.com/federaltimes/home/2019/01/09/why-the-shutdown-could-aggravate-the-cyber-workforce-gap/</link>
					<comments>https://one.sightlinemg.com/federaltimes/home/2019/01/09/why-the-shutdown-could-aggravate-the-cyber-workforce-gap/#respond</comments>
		
		<dc:creator><![CDATA[Justin Lynch]]></dc:creator>
		<pubDate>Wed, 09 Jan 2019 21:43:02 +0000</pubDate>
				<category><![CDATA[Acquisition and Management Update]]></category>
		<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[IT & Cloud Report]]></category>
		<category><![CDATA[Newsletters]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2019/01/09/why-the-shutdown-could-aggravate-the-cyber-workforce-gap/</guid>

					<description><![CDATA[The prolonged shutdown could devastate an already hollowed out workforce.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/home/2019/01/09/why-the-shutdown-could-aggravate-the-cyber-workforce-gap/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">21342</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/AP17249708619733.jpg.jpg" width="4382" height="2921" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">As the federal government’s partial shutdown <a href="https://www.defensenews.com/industry/2019/01/08/us-government-shutdown-creating-angst-for-defense-contractors/" target="_blank">threatens</a> to spill over into its fourth week, House leaders and industry representatives are worried the work-stoppage will have long-running implications and could cripple the government’s ability to hire qualified IT workers in the future.</p>



<p class="wp-block-paragraph">“How can we ever hope to recruit or maintain IT talent when hardworking government workers are told: ‘Sorry, you aren’t getting paid, but you still need to come to work’ or ‘Sorry, but no paycheck this week because of politics?’” Rep. Robin Kelly, D-Ill., said in a statement. “Large private sector companies never say this to their employees and these are our competitors when it comes to IT talent recruitment.”</p>



<p class="wp-block-paragraph">In the previous Congress, Kelly was ranking member of the IT subcommittee and is expected to chair the body in the new session.</p>



<p class="wp-block-paragraph">Concerns about the shutdown only complicate an already difficult job market for federal government agencies. Between April 2017 and March 2018 there were more than 300,000 open cybersecurity jobs, according to research by CompTIA, with more than 13,000 alone in the public sector.</p>



<p class="wp-block-paragraph">However, the talent gap in Washington, D.C., is already expected to worsen with the introduction of Amazon’s second headquarters in the Crystal City area of Arlington, Virginia, just blocks from the Pentagon.</p>



<p class="wp-block-paragraph">“With the addition of an Amazon HQ2, federal agencies are no longer going to be able to recruit top-tier talent to the government directly. Not many are going to want to work for a federal agency when they can work for Amazon,” said Steve Witt, a director at Nintex, a software company specializing in automation. “With government shutdowns occurring on a somewhat regular basis, and the current shutdown being longer than past ones, it’s making private employment far more appealing.”</p>



<p class="wp-block-paragraph">Roughly 800,000 federal workers are affected by the shutdown, which has taken a <a href="https://www.fifthdomain.com/congress/2018/12/21/how-a-government-shutdown-affects-americas-cybersecurity-workforce/">particular toll</a> on the cybersecurity community.</p>



<p class="wp-block-paragraph">The National Institute of Standards and Technology is experiencing an 85 percent cut in its workforce. The Director of National Intelligence’s analysis and operations staff has been slashed 60 percent. And the newly created Cybersecurity and Infrastructure Security Agency has 45 percent of its staff furloughed.</p>



<p class="wp-block-paragraph">In addition to federal employees who are either furloughed or working without pay, the shutdown affects private contractors as well. Experts have <a href="https://www.federaltimes.com/federal-oversight/congress/2019/01/03/federal-contractors-quietly-working-as-the-partial-shutdown-continues/" target="_blank">previously</a> told Fifth Domain that federal services companies may experience cash-flow shortages.</p>



<p class="wp-block-paragraph">“Unlike federal civilian employees, no one provides these contractor employees with back pay to cover their lost work,” <a href="https://www.pscouncil.org/Downloads/documents/Hill%20Letters/PSC%20Shutdown%20Letter%20to%20President%20Trump%201.8.19.pdf">wrote</a> David Berteau, president of the Professional Services Council, a membership organization of government contractors, in a Jan. 8 letter to President Donald Trump. “These contractors work side-by-side with their government counterparts, motivated by the same goals of public service and safety. They deserve to be treated the same as their federal civilian counterparts.”</p>



<p class="wp-block-paragraph"><i>Jessie Bur contributed to this report.</i></p>
]]></content:encoded>
	</item>
		<item>
		<title>How the government shutdown slows down cybersecurity</title>
		<link>https://one.sightlinemg.com/federaltimes/home/2019/01/09/how-the-government-shutdown-slows-down-cybersecurity/</link>
					<comments>https://one.sightlinemg.com/federaltimes/home/2019/01/09/how-the-government-shutdown-slows-down-cybersecurity/#respond</comments>
		
		<dc:creator><![CDATA[Justin Lynch]]></dc:creator>
		<pubDate>Wed, 09 Jan 2019 00:54:52 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[IT & Cloud Report]]></category>
		<category><![CDATA[Newsletters]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2019/01/09/how-the-government-shutdown-slows-down-cybersecurity/</guid>

					<description><![CDATA[As President Donald Trump and congressional Democrats continue to feud over spending for a border wall and parts of the federal government remain shutdown, some of the federal government’s cybersecurity community remains out of commission.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/home/2019/01/09/how-the-government-shutdown-slows-down-cybersecurity/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">28472</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/AP18345609032772.jpg.jpg" width="1200" height="800" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">The list includes some of the United States&#8217; primary cyber defenders: The Department of Homeland Security’s counterterrorism center. Federal guidelines for cybersecurity. Even private cybersecurity courses.</p>



<p class="wp-block-paragraph">As President Donald Trump and congressional Democrats continue to feud over spending for a border wall and parts of the federal government remain shutdown, some of the federal government’s cybersecurity community remains out of commission.</p>



<p class="wp-block-paragraph">Among the heaviest hit areas of the government are the National Institute of Standards and Technology, which has 85 percent of its staff <a href="https://www.commerce.gov/sites/default/files/2018-12/DOC%20Lapse%20Plan%20-%20OMB%20Approved%20-%20Dec%2017,%202018.pdf">furloughed</a>. Because of the shutdown its public standards, which are also relied on by private companies and<a href="https://twitter.com/LisaJohnson/status/1080911044141182977"> for cybersecurity courses</a>, have been removed from the internet. <a href="https://www.dhs.gov/sites/default/files/publications/DHS%20Procedure%20Related%20to%20a%20Lapse%20in%20Appropriations%20(12-20-2018)%20-%20FINAL%20..._0.pdf">Nearly half</a> of the staff from the Department of Homeland Security’s new Cybersecurity and Infrastructure Security Agency are furloughed.</p>



<p class="wp-block-paragraph">“A lot of real heavy lifting to secure the critical infrastructure is done by my DHS colleagues,” wrote Allan Friedman, a director of cybersecurity at the Department of Commerce’s National Telecommunications and Information Administration. “None are being paid — including those running the 24-hour watch at the [National Cybersecurity and Communications Integration Center]. Only half of them are able to do their job.&#8221;</p>



<p class="wp-block-paragraph">Other parts of the federal government’s cybersecurity remain fully operational. The Pentagon, U.S. Cyber Command and most areas of the intelligence community are not affected by the shutdown. The Treasury Department’s IT and computer security incident response are deemed essential as well.</p>



<p class="wp-block-paragraph">However, the biggest impact of the shutdown will not necessarily be felt in the short term.</p>



<p class="wp-block-paragraph">“Operational, mission-critical employees are mostly designated as essential, and so we can expect that network monitoring will continue and cyber security incidents will get an appropriate response,” wrote Phil Reitinger in a post for the Global Cyber Alliance, a membership organization that promotes strong cybersecurity behavior. “What worries me most is the long-term effect of further limiting the pool of cybersecurity people who are willing to work for government.”</p>



<p class="wp-block-paragraph">As the standoff continues, available financial reserves that agencies have saved are set to dwindle, Alan Chvotkin, executive vice president for the Professional Services Council, <a href="https://www.federaltimes.com/federal-oversight/congress/2019/01/03/federal-contractors-quietly-working-as-the-partial-shutdown-continues/" target="_blank">previously</a> told Fifth Domain. Some contractors are also facing cash-flow difficulties, Chvotkin said. Some government officials contacted by Fifth Domain needed special permission to even answer emails and make phone calls. Those who had previously scheduled travel plans were unsure if their trips would go through.</p>



<p class="wp-block-paragraph">Roughly 800,000 federal workers have been <a href="https://www.militarytimes.com/news/pentagon-congress/2018/12/21/coast-guard-would-bear-the-brunt-of-latest-government-shutdown/">affected</a> by the shutdown, according to the White House.</p>
]]></content:encoded>
	</item>
		<item>
		<title>Federal contractors quietly working as the partial shutdown continues</title>
		<link>https://one.sightlinemg.com/federaltimes/congress/2019/01/03/federal-contractors-quietly-working-as-the-partial-shutdown-continues/</link>
					<comments>https://one.sightlinemg.com/federaltimes/congress/2019/01/03/federal-contractors-quietly-working-as-the-partial-shutdown-continues/#respond</comments>
		
		<dc:creator><![CDATA[Justin Lynch]]></dc:creator>
		<pubDate>Thu, 03 Jan 2019 16:14:42 +0000</pubDate>
				<category><![CDATA[Congress]]></category>
		<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Newsletters]]></category>
		<category><![CDATA[Oversight]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2019/01/03/federal-contractors-quietly-working-as-the-partial-shutdown-continues/</guid>

					<description><![CDATA[For government contractors the partial shutdown is bringing uncomfortable dilemmas.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/congress/2019/01/03/federal-contractors-quietly-working-as-the-partial-shutdown-continues/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">12702</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/AP18204506940981.jpg.jpg" width="1200" height="775" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">As the <a href="https://www.federaltimes.com/congress/2019/01/02/no-end-for-government-shutdown-after-white-house-meeting/" target=_blank>standoff</a> between President Donald Trump and Democratic lawmakers <a href="https://www.federaltimes.com/management/budget/2018/12/21/shutdown-watch-house-passes-cr-with-border-wall-funding/" target=_blank>continues</a>, the federal government’s partial shutdown is presenting unenviable dilemmas for the government services industry. Business owners are considering emergency financing options and some employees are working at their own direction but may not be paid back, experts told the Federal Times.</p>



<p class="wp-block-paragraph">Political disagreements over $5 billion in funding for a southern border wall showed no signs of abating Jan. 2, after Trump met with incoming House Majority leader Rep. Nancy Pelosi, D-Calif., and Sen. Chuck Schumer, D-N.Y.</p>



<p class="wp-block-paragraph">Some 800,000 government workers are affected by the shutdown, which is set to enter its third week.</p>



<p class="wp-block-paragraph">For government contractors, the impasse may bring uncomfortable dilemmas.</p>



<p class="wp-block-paragraph">Some government contractors may face cash-flow shortages if the shutdown continues, Alan Chvotkin, executive vice president for the Professional Services Council, told Federal Times. Because some contract-workers are still required to perform their contracts but their employers are not being paid, the government service providers face an unexpected cash-flow deficit, Chvotkin said.</p>



<p class="wp-block-paragraph">The financial impact of this budget shortfall will vary based on the size and cash reserves of each contractor, he said.</p>



<p class="wp-block-paragraph">“Smaller companies that do not have a large number of contracts may not have the cash reserves, and the risk for them is greater,” Chvotkin said.</p>



<p class="wp-block-paragraph">These companies may ask their employees to take time off, ask them to take training days or will ask banks for lines of credit to cover the timing of any cash-flow shortage, he said.</p>



<p class="wp-block-paragraph">The practice of “working at risk,” when government contractors perform services without funding or a contract, is common during shutdowns, Guy Timberlake, chief visionary officer of the American Small Business Coalition, told Federal Times.</p>



<p class="wp-block-paragraph">“Some companies will take a loss since they may not be able to invoice some or all of the time worked by employees during the shutdown,” Timberlake said. The practice “is not specific to one industry, but spread across healthcare, intelligence, cybersecurity and other sectors.”</p>



<p class="wp-block-paragraph">Some government employees are also working without pay.</p>



<p class="wp-block-paragraph">According to Senate Democrats, 6,503 staff from the State Department, 35,000 Internal Revenue Service and more than 50,000 staff from them U.S. Department of Agriculture are currently working without pay. </p>



<p class="wp-block-paragraph">The last time government contractors faced such a dilemma was in 2013 during a 16-day shutdown. That may be a case study for government contractors and their employees.</p>



<p class="wp-block-paragraph">“Some contractor employees were reportedly laid off during the shutdown and furloughed contractor employees were not necessarily paid by their employer during or after the shutdown,” <a href="https://www.gao.gov/assets/670/666526.pdf" target=_blank>according to </a>a Government Accountability Report that analyzed the impact of the 2013 spending shortage.</p>



<p class="wp-block-paragraph">The effects of today’s shutdown are being felt in other ways as well.</p>



<p class="wp-block-paragraph">In most circumstances, the Pentagon cannot enter into new contracts with defense firms, <a href="https://www.ndia.org/-/media/sites/policy-issues/government-shutdown-general-guidelines-final.ashx?la=en">according </a>to the National Defense Industrial Association. Nineteen Smithsonian museums and the National Zoo closed to the public on Jan. 2 because of their funding shortfall. <a href="https://www.nist.gov/" target=_blank>The National Institute of Standards and Technology website</a>, which offers guidance on federal cybersecurity standards that are often used by businesses, has a temporary homepage.</p>
]]></content:encoded>
	</item>
		<item>
		<title>What the future of artificial intelligence means for cybersecurity</title>
		<link>https://one.sightlinemg.com/federaltimes/newsletters/it-cloud-report/2018/12/27/what-the-future-of-artificial-intelligence-means-for-cybersecurity/</link>
					<comments>https://one.sightlinemg.com/federaltimes/newsletters/it-cloud-report/2018/12/27/what-the-future-of-artificial-intelligence-means-for-cybersecurity/#respond</comments>
		
		<dc:creator><![CDATA[Justin Lynch]]></dc:creator>
		<pubDate>Thu, 27 Dec 2018 21:48:53 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[IT & Cloud Report]]></category>
		<category><![CDATA[IT & Networks]]></category>
		<category><![CDATA[Newsletters]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2018/12/27/what-the-future-of-artificial-intelligence-means-for-cybersecurity/</guid>

					<description><![CDATA[Two new papers give an insight into how artificial technology will be used for cybersecurity in the future.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/newsletters/it-cloud-report/2018/12/27/what-the-future-of-artificial-intelligence-means-for-cybersecurity/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">32134</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/GettyImages-86871522.jpg.jpg" width="1200" height="800" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Future wars may be decided by computers fighting each other in cyberspace, <a href="https://cyberdefensereview.army.mil/Portals/6/Documents/CDR%20Journal%20Articles/CDR_V3N3_FULL_SINGLE%20PAGES_WEB-READY.pdf?ver=2018-12-18-093122-497">some</a> national security experts argue. But <a href="https://www.fifthdomain.com/show-reporters/black-hat/2018/08/07/why-algorithms-can-harm-cybersecurity/">others</a> predict artificial intelligence brings false security to cyber defenses because the technology’s behavior can be hard to perfect.</p>



<p class="wp-block-paragraph">Two new papers attempt to narrow that expansive philosophical divide and give an insight into how AI will be used for cybersecurity in the future.</p>



<p class="wp-block-paragraph">Artificial intelligence-powered machines are &#8220;likely to become primary cyber fighters on the future battlefield,” Alexander Kott, chief scientist at the Army Research Lab, wrote in a Dec. 18 <a href="https://cyberdefensereview.army.mil/Portals/6/Documents/CDR%20Journal%20Articles/CDR_V3N3_FULL_SINGLE%20PAGES_WEB-READY.pdf?ver=2018-12-18-093122-497">edition</a> of the Army’s Cyber Defense Review.</p>



<p class="wp-block-paragraph">“Today’s reliance on human cyber defenders will be untenable in the future,” Knott wrote, citing the growing complexity of future fighting. Those conflicts are made more difficult by exponentially more connected devices, robotic battles and other coming technological innovations.</p>



<p class="wp-block-paragraph">Knott, whose research is specific to cybersecurity in future battlefields, suggested that current AI technology is not adequate. He argued that because of the fluid nature of fighting, the number of connected devices and deficiencies in mobile computing power, machine learning “must experience major advances to become relevant to the real battlefield.”</p>



<p class="wp-block-paragraph">But Knott’s criticisms of current artificial intelligence capabilities on the battlefield mirror other complaints about the technology from the broader cybersecurity industry.</p>



<p class="wp-block-paragraph">Most advanced threat-detection technologies use some form of AI to flag a potential incident, but experts have <a href="https://www.fifthdomain.com/industry/2018/08/23/why-too-much-attention-on-foreign-actors-and-voting-machines-can-hurt-cybersecurity/">told</a> Fifth Domain that an influx of false positives from this technique can create “threat fatigue” if not properly calibrated. For example, IT and security organizations receive roughly 17,000 malware alerts per week, according to a study by research firm Ponemon. Only 19 percent of those alerts are considered reliable, and only 4 percent are investigated, <a href="https://www.ponemon.org/local/upload/file/Damballa%20Malware%20Containment%20FINAL%203.pdf">according</a> to the research.</p>



<p class="wp-block-paragraph">Another <a href="https://cyberdefensereview.army.mil/Portals/6/Documents/CDR%20Journal%20Articles/CDR_V3N3_FULL_SINGLE%20PAGES_WEB-READY.pdf?ver=2018-12-18-093122-497">paper</a> in the same Dec. 18 edition of the Army Cyber Review argues that using blended approaches to AI might enhance cybersecurity defense.</p>



<p class="wp-block-paragraph">Most artificial intelligence can be categorized as either “symbolic” or “non-symbolic.”</p>



<p class="wp-block-paragraph">Symbolic AI means the use of automated logic that has been pre-programmed, like decision trees.</p>



<p class="wp-block-paragraph">Non-symbolic AI means the use of a program that is able to self-learn threats and identify anomalies.</p>



<p class="wp-block-paragraph">Researchers at AI research firm Soar Technology have used both machine-learning concepts in a Navy project to boost cybersecurity defense.</p>



<p class="wp-block-paragraph">“To realize the full potential of AI, we must integrate its various forms in order to offset the limitations of each,” wrote the paper’s authors, Scott Lathrop and Fernando Maymí, who both work for Soar technology. “No one approach will be sufficient because each approach is optimized for one specific set of problems at the expense of others.”</p>



<p class="wp-block-paragraph">Researchers are already addressing these and other current limits of AI.</p>



<p class="wp-block-paragraph">Examples include <a href="http://ceur-ws.org/Vol-2057/Paper15.pdf">autonomous</a> deception tactics, <a href="http://ceur-ws.org/Vol-2057/Paper7.pdf">deep learning research</a> that uses high-powered computers and <a href="http://ceur-ws.org/Vol-2057/Paper3.pdf">autonomously</a> distributing networks to prevent DDoS attacks.</p>



<p class="wp-block-paragraph">In July, the Pentagon <a href="https://www.boozallen.com/e/media/press-release/booz-allen-selected-to-help-apply-artificial-intelligence.html">signed</a> a five-year, $885 million contract with Booz Allen Hamilton, a defense contractor, for an AI project. Specific details of the project are not clear.</p>



<p class="wp-block-paragraph">In addition, the Pentagon <a href="http://cdn.defensedaily.com/wp-content/uploads/post_attachment/206477.pdf">released</a> its AI strategy in August. That document suggested that in the short term the Department of Defense should develop &#8220;a database that captures potential or known cybersecurity vulnerabilities of the various sensors” that are essential to machine learning.</p>
]]></content:encoded>
	</item>
		<item>
		<title>How the new acting Pentagon chief views cybersecurity</title>
		<link>https://one.sightlinemg.com/federaltimes/home/2018/12/24/how-the-new-acting-pentagon-chief-views-cybersecurity/</link>
					<comments>https://one.sightlinemg.com/federaltimes/home/2018/12/24/how-the-new-acting-pentagon-chief-views-cybersecurity/#respond</comments>
		
		<dc:creator><![CDATA[Justin Lynch]]></dc:creator>
		<pubDate>Mon, 24 Dec 2018 20:31:57 +0000</pubDate>
				<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[IT & Cloud Report]]></category>
		<category><![CDATA[Newsletters]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2018/12/24/how-the-new-acting-pentagon-chief-views-cybersecurity/</guid>

					<description><![CDATA[Comments from Patrick Shanahan, who will take over as acting secretary of defense Jan. 1, give insight into his cybersecurity priorities amid growing national security challenges.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/home/2018/12/24/how-the-new-acting-pentagon-chief-views-cybersecurity/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">32008</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/GettyImages-876762790.jpg_5099c5.jpg" width="2000" height="1125" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">President Donald Trump announced in a Dec. 23 <a href="https://twitter.com/realDonaldTrump/status/1076881816462737408" target=_blank>tweet</a> that Patrick Shanahan will become acting secretary of defense Jan. 1, replacing outgoing Pentagon chief Jim Mattis two months early. While it is not clear how long Shanahan will remain in the job, he is on the short list of officials who could become the full-time Pentagon chief.</p>



<p class="wp-block-paragraph">Regardless of the length of his tenure, Shanahan,<a href="https://www.defensenews.com/outlook/2018/12/10/us-deputy-defense-secretary-a-look-at-missiles-space-and-cyber-in-next-years-national-strategy/" target=_blank> the Pentagon deputy</a> since 2017, has been one of the Pentagon’s top advocates for stronger contractor cybersecurity and IT acquisition and will lead the department months after it was given expansive and loosely defined authorities to conduct offensive cyber operations.</p>



<p class="wp-block-paragraph">How Shanahan will handle these greater cyber authorities, even on a temporary basis, remains an open question that will be tested immediately amid evolving challenges, such as an alleged hacking campaign from China.</p>



<p class="wp-block-paragraph"><b>Unclear views on cyber operations</b></p>



<p class="wp-block-paragraph">In August, the secretary of defense was given the ability to conduct offensive cyber operations without informing the president as long as it does not interfere with the “national interest” of the United States, four current and former White House and intelligence officials have told Fifth Domain.</p>



<p class="wp-block-paragraph">A Pentagon official told Fifth Domain that while there is a general outline of what specific operations may affect the American “national interest,” some details are not explicitly defined.</p>



<p class="wp-block-paragraph">And a <a href="https://dod.defense.gov/News/Transcripts/Customwho/31001/" target=_blank>review</a> of his public remarks show that Shanahan has not made significant comments about how America should conduct offensive cyber operations. He has <a href="https://dod.defense.gov/News/Transcripts/Transcript-View/Article/1402941/off-camera-on-the-record-media-availability-with-deputy-secretary-shanahan/" target=_blank>shied</a> away from giving detailed responses about U.S. Cyber Command.</p>



<p class="wp-block-paragraph">“There are two new war-fighting domains, cyber and space, for which we are developing doctrine and capabilities,” Shanahan <a href="https://dod.defense.gov/News/Transcripts/Transcript-View/Article/1639948/remarks-by-deputy-secretary-shanahan-at-the-air-force-associations-air-space-an/" target=_blank>said</a> Sept. 19.</p>



<p class="wp-block-paragraph">A spokesperson for Shanahan did not respond to questions from Fifth Domain.</p>



<p class="wp-block-paragraph"><b>Focus on defense contractors</b></p>



<p class="wp-block-paragraph">As deputy, Shanahan has focused on “<a href="https://www.google.com/url?sa=t&amp;rct=j&amp;q=&amp;esrc=s&amp;source=web&amp;cd=26&amp;ved=2ahUKEwj37eC2j7nfAhXCMd8KHTbfDB4QFjAZegQICRAB&amp;url=https%3A%2F%2Fwww.defensenews.com%2Fpentagon%2F2018%2F12%2F21%2Fwith-mattis-out-is-shanahan-poised-to-rewire-the-pentagon%2F&amp;usg=AOvVaw0W2m3_tk6Adqgq2RphrDmH" target="_blank">re-wiring</a>” the Pentagon. He has called good cybersecurity “<a href="https://www.c4isrnet.com/show-reporter/afcea-west/2018/02/06/pentagons-no-2-dismissing-cyber-risks-is-like-ignoring-smoking-dangers/">foundational</a>” to working with the department.</p>



<p class="wp-block-paragraph">“Cybersecurity is, you know, probably going to be what we call the ‘fourth critical measurement.’ We’ve got quality, cost, schedule, but security is one of those measures that we need to hold people accountable for,” Shanahan <a href="https://www.fifthdomain.com/digital-show-dailies/air-force-association/2018/09/19/shanahan-cyber-security-will-become-fourth-critical-measurement-for-industry/" target=_blank>said</a> Sept. 19 during an Air Force Association conference.</p>



<p class="wp-block-paragraph">Shanahan’s focus on contractor cybersecurity comes as China is believed to be targeting defense contractors, particularly those on the lower end of the supply chain, in an attempt to steal sensitive American secrets, <a href="https://www.fifthdomain.com/dod/2018/10/21/pentagon-moves-to-secure-supply-chain-from-foreign-hackers/" target=_blank>according</a> to intelligence officials and industry executives.</p>



<p class="wp-block-paragraph">Shanahan, however, has placed responsibility among the top defense firms.</p>



<p class="wp-block-paragraph">“I’m a real strong believer that the Tier 1 and Tier 2 leadership has a responsibility to manage the supply chain,” Shanahan <a href="https://dod.defense.gov/News/Transcripts/Transcript-View/Article/1639948/remarks-by-deputy-secretary-shanahan-at-the-air-force-associations-air-space-an/" target=_blank>said</a> in the Sept. 19 speech.</p>



<p class="wp-block-paragraph">In October, Shanahan was put in <a href="https://www.fifthdomain.com/dod/2018/11/02/a-new-dod-task-force-addresses-the-growing-threats-to-critical-technology/" target="_blank">charge</a> of a new Pentagon task force to combat data exfiltration that focuses in part on these defense firms.</p>



<p class="wp-block-paragraph">“Together with our partners in industry, we will use every tool at our disposal to end the loss of intellectual property, technology and data critical to our national security,” Shanahan <a href="https://www.fifthdomain.com/dod/2018/11/02/a-new-dod-task-force-addresses-the-growing-threats-to-critical-technology/">told</a> Fifth Domain in October.</p>



<p class="wp-block-paragraph">A specific area of focus inside the department is finding out which companies are in the Pentagon’s supply chain, according to officials involved in the process, but it is not clear if it is specifically part of Shanahan’s task force.</p>



<p class="wp-block-paragraph">Inside the Pentagon, Shanahan has also emphasized the need for smarter IT acquisition.</p>



<p class="wp-block-paragraph">In an October. interview with Fifth Domain, Shanahan expressed frustration with the Pentagon’s procurement process, but said to expect “a number of things that are foundational to being able to achieve enterprise solutions.”</p>



<p class="wp-block-paragraph">He hinted that those changes are focused on the “right platforms and the right level of integration” that can support high-end computing and artificial intelligence.</p>



<p class="wp-block-paragraph">“I’m super frustrated that we can’t go faster on like basic things like the cloud,” Shanahan said. “Most of everything we do is software-driven.”</p>



<p class="wp-block-paragraph"><i>Aaron Mehta contributed to this report. </i></p>
]]></content:encoded>
	</item>
	</channel>
</rss>
