Last week, retired Air Force Gen. Gregory Touhill was appointed as the first federal chief information security officer. The appointment was well received throughout industry and the public sector as he brings technical expertise, leadership, accessibility and inclusion to the cybersecurity mission. He is viewed as a consummate cybersecurity professional who is well liked on both sides of the political aisle and by our global allies.
In accordance with the Cybersecurity Workforce Strategy announced in July by the White House, Touhill will be responsible for the development and implementation of cybersecurity policies and practices across the federal government. Cybersecurity has become a top priority of federal spending strategy with around $19 billion being allocated for that mission across agencies in 2017. Recent breaches in both government and industry have demonstrated the vulnerability of and threats to our networks.
Touhill has been an outspoken advocate of the implementation of private-public partnerships to mitigate cybersecurity threats. This includes promoting information sharing and building standards and best practices as a cybersecurity community. His new role will provide a bigger pulpit to evangelize these key elements required for enacting a successful, collaborative cybersecurity strategy among stakeholders.
The retired general had previously served as the deputy assistant secretary for cybersecurity and communications at the Department of Homeland Security, where he was responsible for implementing programs and technologies to safeguard government networks and critical infrastructures from cyberthreats. These include the industrial control systems and interfaces of our energy grid and financial networks, of which more than 90 percent are owned by the private sector. In his DHS role, his work also involved coordinating communications across 125 different federal departments and agencies and with state, local and territorial governments.
Having served in cybersecurity roles in both military and civilian capacities, Touhill brings a unique perspective of the requirement for risk management and best practices. At a 2015 George C. Marshall European Center’s program for cybersecurity studies, he said: “At the end of the day, cybersecurity is not about technology, it’s about managing risk. One of the things I’ve learned in my professional career and my academic career is that you have to look at a strategy. You can buy down your risk by 80 percent by implementing best practices.”
Touhill appointment coincides with DHS’ intentions to reorganize the National Protection and Programs Directorate (NPPD) and the continued development of a national cyber incident response plan, which was called for in the National Cybersecurity Protection Act of 2014 and in Presidential Directive 41. Congress has elevated DHS’ role in cybersecurity, and the federal CISO will work closely with both the reorganized NPPD and the response plan.
Touhill’s appointment signifies the seriousness of information security as we move further into the digital era and the need to prioritize cybersecurity as a top national priority. The selection of Gen. Touhill is a consensus pick to set the stage for the new CISO role to bring strategy and leadership for the challenges that lie ahead.
Charles “Chuck” Brooks serves as the vice president for government relations and marketing for Sutherland Government Solutions. He served at the Department of Homeland Security as the first director of legislative affairs for the Science and Technology Directorate. Find him on Twitter at @ChuckDBrooks.




