IC Insiders Archives - Intelligence Community News https://intelligencecommunitynews.com/category/ic-insiders/ Breaking news about the market for products, systems and services for the U.S. intelligence community Mon, 18 May 2026 12:53:32 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg IC Insiders Archives - Intelligence Community News https://intelligencecommunitynews.com/category/ic-insiders/ 32 32 59882712 Transitioning to Post-Quantum Cryptography: What Federal Agencies Must Do Now https://intelligencecommunitynews.com/ic-insiders-44593-2/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-44593-2 Mon, 18 May 2026 12:53:32 +0000 https://intelligencecommunitynews.com/?p=44593 From IC Insider Thales Trusted Cyber Technologies By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies Has your agency begun...

The post Transitioning to Post-Quantum Cryptography: What Federal Agencies Must Do Now appeared first on Intelligence Community News.

]]>
From IC Insider Thales Trusted Cyber Technologies

By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies

Has your agency begun its strategy for transitioning to post-quantum cryptography (PQC)? If you’re not fairly far along now, you’re actually a bit behind. New guidance from the administration this past March, along with a memo from the Department of War last year, is ramping up the urgency. In fact, some of the stalwart cryptographic solutions used in the federal sector will be given the axe in the next five years.

Fortunately, there are some simple steps you can follow to start gearing up for your PQC transition. We’ll address those steps in a moment, but let’s first understand the context of this increasingly pressing need for dealing with security in a post quantum world.

Cyber Strategy and the Push for Infrastructure Security

March 2026 saw the release of this administration’s Cyber Strategy for America. The strategy organizes priorities around six “pillars of action,” each of which has direct implications for both federal contractors and agency cybersecurity teams. Two of those pillars are particularly relevant to this discussion: securing critical infrastructure and modernizing and securing federal government networks.

The modernization pillar in particular calls for accelerating the adoption of cybersecurity best practices, PQC, zero-trust architecture, and the transition to the cloud. This is part of the administration’s desire to have decisions made and implemented at the agency level more quickly.

PQC is becoming essential in securing federal networks. And, the Cyber Strategy comes as the Department of War has announced prioritization of solutions using NIST- approved, CNSA 2.0-listed PQC algorithms in lieu of previously-accepted quantum resistant solutions that make use of symmetric key management protocols. The Department will cease to test, pilot, use, or procure commercial solutions using these symmetric key technologies for quantum resistance. So, for agencies and contractors still relying on any of those solutions, the clock is running.

Why the urgency? Experts project the first cryptographically relevant quantum computers could emerge as early as the next decade.

Protecting systems from the quantum computing threat can’t wait until 2030. Harvest now, decrypt later schemes involve collecting data encrypted with classical algorithms today and decrypting it once a sufficiently powerful quantum computer exists. Intelligence, personnel records, and operational communications being transmitted right now are being targeted with this in mind. This is not a future problem.

Meanwhile, past cryptographic migrations across federal landscape have taken over a decade. From a purely historical perspective, things are already behind schedule.

On top of all this guidance, it’s important to remember that NIST released its first finalized PQC standards in August 2024, and is now in the process of deprecating specific cryptographic primitive algorithms and schemes on a set schedule. Agencies that have not migrated before those cutoff dates will be running deprecated cryptography in critical systems.

A Migration Memo to the Department of War

Back in November 2025, the Department of War released a memo titled, “Preparing for Migration to Post Quantum Cryptography.” The memo was directed to senior Pentagon leadership, combat commands and field activity directors, and laid the groundwork for migrating to PQC. (This guideline memo builds on the Quantum Computing Cybersecurity Preparedness Act of 2022, which requires agencies develop a PQC transition timeline based on their assessment of how they use potentially vulnerable cryptography.)

“Advancements of Quantum Information Science (QIS) and cryptanalytically relevant quantum computers requires expedited migration to quantum-resistant cryptography to safeguard the Department’s information systems, communications, and personnel,” the November 2025 memo reads.

It goes on to say, “The migration to post quantum cryptography (PQC) must not only be planned and executed with deliberate urgency to maintain warfighter lethality and information dominance in the DoW global ecosystem, but also strategically coordinated…To achieve this level of coordination, we must identify PQC migration points of contact for information sharing and create processes for streamlining intake and prioritization of PQC solutions to support certification activities and timelines.”

The Department’s memo stresses that agencies must receive cryptographic intake and deployment approval before testing, evaluating, piloting, investing in, using, or deploying any quantum-resistant or quantum-resilient technologies. It also bans outright a set of technologies for use in providing confidentiality, authenticity, or integrity on DoD networks:

  • Quantum Key Distribution (QKD)
  • Solutions combining QKD with other cryptographic keys
  • Quantum communications or networking
  • Non-local quantum randomness generation
  • Non-FIPS random number generation

 

Providing quantum resistance in solutions using cryptographic pre-shared keys (PSK) not provisioned through NSA Key Management Infrastructure for Type 1 devices will be sundowned on December 31, 2030. Symmetric Key Establishment, Agreement, and Distribution Protocols will be eliminated a year later, on December 31, 2031.

For future solutions, underlying technology must include crypto agility.

Crypto Agility: The Requirement Behind the Requirement

As organizations prepare for the post‑quantum era, crypto agility becomes essential—enabling systems to adopt PQC algorithms rapidly, minimize operational disruption, and remain resilient as cryptographic standards evolve. Many long‑established cryptographic programs have already internalized these principles, giving them the architectural headroom to absorb PQC’s larger key sizes and increased computational demands with minimal friction. NIST’s Cybersecurity White Paper CSWP 39 reinforces this need by detailing the tradeoffs, operational challenges, and interoperability considerations inherent in achieving true cryptographic agility.

For agencies, the actionable takeaway is clear: every modernization or procurement decision should explicitly require demonstrable crypto‑agility, ensuring that systems acquired today can adapt to tomorrow’s PQC mandates instead of becoming tomorrow’s technical debt. This shifts crypto agility from an abstract aspiration to a concrete acquisition criterion that safeguards mission longevity.

As organizations transition into the post‑quantum era, crypto agility becomes essential—enabling systems to rapidly adopt PQC algorithms, minimize operational disruption, and stay resilient against evolving cryptographic threats.

Seven Steps to a PQC Transition Strategy

So what are the steps agencies must take in developing their PQC transition strategy? There are seven:

  • Awareness
  • Inventory technology/prioritize systems
  • Automate crypto discovery
  • Automate inventory
  • Set up a PQC test environment
  • Practice crypto agility
  • Apply quantum key generation and implement quantum-resistant algorithms

 

Let’s take a quick look at each step.

Awareness. Your transition strategy is a top-down initiative. Leadership must be fully aware of the challenge: not only the risks, but the specific actions required to meet them. The harvest now, decrypt later threat means that PQC migration isn’t a future budget line, it’s an active operational risk.

Inventory cryptographic technologies and prioritize high-risk systems. The Office of the National Cyber Director (ONCD) provided specific instructions to federal agencies on inventorying their cryptographic systems. ONCD directed agencies to submit prioritized cryptographic inventories by May 2023. For many, unfortunately, that was a paper exercise. A manual process is less precise than one using available electronic tools, and your cryptographic footprint has grown since that submission.

Automate crypto discovery. Crypto inventory is not a one-time task. Organizations continuously create new cryptographic instances across their environments. Automated discovery is the only practical way to maintain an accurate picture. You cannot migrate what you have not mapped.

Automate discovery and inventory. Multiple vendors offer automated cryptographic discovery tools. Assess what is available and match tools to your environment. Automated tooling surfaces cryptographic dependencies that manual processes miss entirely.

Set up a PQC test environment. Now that the NIST standards are finalized, it is time to upgrade your environment for testing. As previously noted, PQC algorithms generate larger keys, and the performance impact of those larger keys could affect your systems in ways you had not anticipated. Test before you deploy at scale.

Practice crypto agility. Supporting both classical and PQC algorithms simultaneously is what makes an organization crypto agile. Devices and platforms being procured today must be capable of this. If they are not, you have to begin modernizing those systems now.

Apply quantum key generation and implement quantum-resistant algorithms. The foundation of encryption is the quality of the cryptographic keys. Organizations should leverage a quantum random number generator (QRNG) to produce high-quality entropy as the basis for all keys and cryptographic operations. Encryption solutions must use the standardized NIST PQC algorithms, or be crypto-agile with a clear and near-term upgrade path to them.

The administration’s Cyber Strategy, the Department of War phase-out deadlines, and the NIST deprecation schedule all point in the same direction: Cryptographically dangerous quantum computers are coming, and the threat is real.

Agencies should plan their transition strategies now work. Automate your crypto discovery, stand up a PQC test environment, require crypto agility in new procurements, and prioritize migration on your highest-risk systems first.

Industry has been working on this for years. Agencies need to close the gap.

About Thales TCT

Thales Trusted Cyber Technologies, a business area of Thales Defense & Security, Inc., protects the most vital data from the core to the cloud to the field. We serve as a trusted, U.S. based source for cyber security solutions for the U.S. Federal Government. Our solutions enable agencies to deploy a holistic data protection ecosystem where data and cryptographic keys are secured and managed, and access and distribution are controlled.

For more information, visit www.thalestct.com

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

The post Transitioning to Post-Quantum Cryptography: What Federal Agencies Must Do Now appeared first on Intelligence Community News.

]]>
44593
Governing What You Cannot See: How the IC Should Think About Security and Oversight for AI Augmented Development https://intelligencecommunitynews.com/ic-insiders-governing-what-you-cannot-see-how-the-ic-should-think-about-security-and-oversight-for-ai-augmented-development/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-governing-what-you-cannot-see-how-the-ic-should-think-about-security-and-oversight-for-ai-augmented-development Mon, 11 May 2026 13:00:58 +0000 https://intelligencecommunitynews.com/?p=44537 From IC Insider Coder By Ross Weatherford, Senior Director of National Security Programs at Coder   Over the last several...

The post Governing What You Cannot See: How the IC Should Think About Security and Oversight for AI Augmented Development appeared first on Intelligence Community News.

]]>
From IC Insider Coder

By Ross Weatherford, Senior Director of National Security Programs at Coder

 

Over the last several months, the conversation inside the IC about AI-augmented development has moved fast. Platform engineering is replacing the monolithic software factory. The builder population is expanding beyond credentialed engineers to analysts, operators, and specialists who carry the community’s most irreplaceable asset: domain expertise. Both of those shifts are real, and together they create a problem the IC has not yet solved.

More builders mean more environments. More environments mean more surface area. And when autonomous AI coding agents are introduced into that expanded landscape, agents that can access repositories, generate code, and execute tasks without continuous human direction, the blast radius of a misconfiguration, a compromised dependency, or an insider threat expands in ways that traditional security models were not designed to handle.

This is not a theoretical concern: Georgia Tech’s Systems Software & Security Lab tracked 35 new CVE entries in March 2026 alone that resulted directly from AI-generated code, up from six in January and fifteen in February. Veracode’s 2025 GenAI Code Security Report found that AI-generated code contains 2.74 times more vulnerabilities than code written by humans. Apiiro found AI-generated code creates 322 percent more privilege escalation paths. The democratization of development is genuinely transformative, yet it comes with a governance challenge that the IC needs to get ahead of before the scale arrives, not after.

The agentic AI risk layer

The security risks of AI-assisted coding are real enough on their own. But AI coding agents, autonomous systems that do not merely suggest code but take actions, access file systems, call APIs, and modify repositories, introduce a qualitatively different class of risk.

These agents can access repositories outside their intended scope, generate verbose outputs that inadvertently leak sensitive context, and escalate privileges in ways that no human developer would, simply because the agent’s optimization function does not include the same threat model a trained engineer carries. Check Point Research disclosed critical vulnerabilities in a major AI coding tool in February 2026, including configuration injection flaws that allowed remote code execution the moment a developer opened a compromised project, and the OpenClaw supply chain attack confirmed over 1,100 malicious packages in an AI agent ecosystem, roughly one in five packages in the affected repository.

This is already informing how the Intelligence Community approaches AI deployment. The question is no longer whether AI agents will operate in IC development environments, because they will. The question is whether the governance infrastructure will exist when they do.

Human on the loop as operational reality

The IC cannot have a human reviewing every line of AI -generated code. With developers estimating that 42 percent of committed code is already AI-assisted, and increasing, that model is not merely impractical, it is impossible. Yet the alternative is not abandoning oversight, but moving oversight to where it can actually operate: the policy and boundary level rather than the task level.

In practice, this means immutable audit logs that capture what every agent did, when it did it, and in what context; toolchain limits that constrain what an agent can access so a coding assistant working on a frontend component cannot reach into a classified data pipeline; sandboxed execution environments where agent generated code runs in isolation before it touches anything in production; and SIEM integration that treats agent activity as a first class telemetry source rather than an afterthought bolted onto existing monitoring.

The shift from human in the loop to human on the loop is not about reducing accountability. It is about making accountability scalable. A senior engineer reviewing a pull request is valuable, but a platform that prevents the pull request from ever containing unauthorized access patterns is more valuable, because it operates continuously and does not depend on one person’s attention on a random Tuesday.

What coherent governance looks like across agencies

Each IC agency has distinct missions, infrastructure, and risk tolerances. No one is arguing for a single centralized governance platform because that would repeat the exact mistake the monolithic software factories made. What the community needs is shared baselines.

ODNI is already moving in this direction. In March 2026, ODNI announced it is building the policy framework, governance, and standards to accelerate AI adoption across the IC, and DNI Gabbard has since announced the largest ever IC cybersecurity investment and modernization effort, which includes policy standards for AI in cyber defense, a shared repository for security reviewed applications, and expanded threat hunting capabilities.

The architecture this points toward is one in which ODNI sets minimum standards for red teaming, auditability, and incident reporting. Meanwhile agencies deploy on their own infrastructure and use their own toolchains, yet produce logs and controls compatible with a common framework. It is better understood as the difference between requiring everyone to use the same car and requiring everyone to drive on the same side of the road, because the goal is interoperability rather than uniformity.

Intelligence Community Directive 505 on Artificial Intelligence, combined with NIST’s Secure Software Development Framework and SP 800-218, provides the policy scaffolding, but what has been missing is the operational infrastructure that makes those directives enforceable at the speed development actually moves.

Compliance that travels with the workspace

The most durable governance model is one in which policy is embedded in the environment itself, not layered on top of it after the fact.

The principle is consistent across all of this: when compliance is embedded in the environment rather than layered on top, it scales. Small platform teams define it once in code. Every builder, human or agent, inherits it automatically. The governance model for AI agents is not a new problem — it is the same infrastructure problem, applied to a faster and less predictable actor.

When a workspace template defines what an AI agent can and cannot do, what repositories it can access, what actions it can take, and what boundaries it must respect, that governance is structural, and it does not depend on the individual developer configuring it correctly, and it does not depend on a security team reviewing every session, because a workspace that meets governance requirements on an unclassified network works identically on a classified one, since the controls are defined in the template rather than in a separate policy document that someone has to remember to apply.

Coder’s approach to agent boundaries, task definitions, and centralized environment management give security teams visibility and control over what AI agents do inside builder workspaces without requiring those teams to be present for every session, so the platform becomes the enforcement mechanism and governance becomes infrastructure.

The cost of waiting

Provisioning speed, prototype speed, the speed to turn domain expertise into mission capability — those are the stakes this argument has been building toward. But the most consequential speed question is not about development environments. It is about how fast adversaries are moving while the IC deliberates.

China is now estimated to spend roughly $2 billion annually on AI enabled military systems, comparable to United States levels, and has deployed autonomous ground robots, AI driven drone swarms, and machine learning systems for target recognition and operational planning at scale and the PLA is actively restructuring its joint operational frameworks around AI driven combat platforms. Russia, meanwhile, is taking a different but equally consequential approach, rapid, iterative deployment of autonomous systems in actual combat in Ukraine, refining capabilities through operational feedback loops that compress the development cycle in ways traditional procurement cannot match; Russian and Chinese officials held formal consultations on military AI cooperation in Moscow in November 2025, and they are not waiting to resolve governance before deploying, because they are deploying and adapting in parallel.

The IC’s advantage, and it is a genuine advantage, is that it can move fast and build trust simultaneously. Democratic accountability, rigorous oversight, and transparent governance are not obstacles to speed. When done correctly, they are accelerants, since they build the institutional confidence required to deploy AI capabilities broadly rather than keeping them confined to pilot programs and proofs of concept that never scale.

But that advantage has a shelf life. The Pentagon’s fiscal year 2026 budget requests $13.4 billion for AI, so the investment is there, the policy direction from ODNI is there, and the commercial technology to enforce governance at the platform level exists today. What remains is the execution, standing up the infrastructure that makes governance operational before the scale of AI augmented development outpaces the community’s ability to oversee it.

The organizations that get this right will not be the ones that moved cautiously. They will be the ones that built governance into their development infrastructure from the start, so that when the scale arrived, the trust was already in place.

The governance infrastructure the IC needs is not a future requirement. It is a current one. The factory has already given way to the framework. The builder population is already expanding. The agents are already operating. The window to get ahead of it is not as wide as it might appear.

About the author

Ross Weatherford is a Director of National Security Programs at Coder, where he partners with DoW, Intelligence Community, and defense contractor customers on secure, compliant development environments and agent ready workspaces. With over two decades in cybersecurity and federal technology, Ross has led cyber architecture and engineering teams at Northrop Grumman across classified space and ground systems and served as lead solutions architect for the largest account in national security programs at Red Hat. He holds CISSP, CCSP, RHCSA, and AWS certifications.

About Coder

Coder is the only AI development Infrastructure that unifies development environments, AI governance, and autonomous agents into a single, self-hosted system. It enables enterprises to move development off unmanaged endpoints and into standardized, policy-controlled environments where both builders and AI agents operate in parallel safely. With centralized governance, AI model-agnostic flexibility, and full observability, Coder allows organizations to scale AI adoption without compromising security, compliance, or cost control. Learn more at coder.com.

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

 

The post Governing What You Cannot See: How the IC Should Think About Security and Oversight for AI Augmented Development appeared first on Intelligence Community News.

]]>
44537
Who Builds the Mission Now? How the IC Is Expanding the Definition of a Developer https://intelligencecommunitynews.com/ic-insiders-who-builds-the-mission-now-how-the-ic-is-expanding-the-definition-of-a-developer/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-who-builds-the-mission-now-how-the-ic-is-expanding-the-definition-of-a-developer Sun, 12 Apr 2026 20:48:58 +0000 https://intelligencecommunitynews.com/?p=44313 From IC Insider Coder By Austen Bruhn, Staff Solutions Engineer — US Public Sector at Coder The hardest problems in...

The post Who Builds the Mission Now? How the IC Is Expanding the Definition of a Developer appeared first on Intelligence Community News.

]]>
From IC Insider Coder

By Austen Bruhn, Staff Solutions Engineer — US Public Sector at Coder

The hardest problems in IC software development in 2026 are not technical. They are organizational – it’s the challenge of overcoming mission knowledge gaps between the people who understand the problem and the people who can actually solve it.

The person who best understands a mission gap — the all-source analyst who has spent five years tracking a specific threat actor, the SIGINT specialist who recognizes patterns invisible to anyone outside their collection account — is rarely the person positioned to act on it. That knowledge gets translated into a requirement. That knowledge gets written down as a requirement, then turned into a statement of work and, ultimately, that becomes a contract. Somewhere in that chain, irreplaceable operational insight loses most of its fidelity.

This bottleneck rarely makes it into conversations about IC modernization. Infrastructure debt does. Talent retention does. Procurement timelines do. But the gap between the people who understand the mission and the people authorized to build tools for it is at least as consequential as any of those. And it’s been widening while the rest of the conversation moved on.

A new kind of builder is emerging

The conversation is starting to shift. CDAOs at major defense primes are investing in citizen developer programs — training analysts, logisticians, and specialists to build workflows, notebooks, and data transformations without traditional coding backgrounds. The Marine Corps Chief AI Officer has pushed for models where operators contribute directly to the tools they use in the field, rather than filing requirements and waiting. Gartner estimates that citizen developers now significantly outnumber professional developers in large enterprises, and the ratio is still moving even in the Defense Industrial Base (DIB).

What’s making this realistic rather than aspirational is the state of AI-assisted development. The DoD’s own Chief Digital and AI Office acknowledged in a February 2026 solicitation that its software development workforce “currently lacks standardized, enterprise-wide access to AI-enabled coding tools that are commonplace in the commercial sector,” and that the gap “limits developer productivity [and] slows the delivery of mission-critical software.” That gap is exactly the opportunity. An analyst who can describe a problem clearly, evaluate whether a proposed solution makes sense, and iterate is someone who can build useful things today in a way they couldn’t before. The underlying technical knowledge required has dropped significantly. The domain expertise those analysts already carry has not.

What this looks like on the mission

Take an OSINT analyst who has identified a gap in how the community is processing a new collection source.

Under the model most programs still operate on, that insight gets written down as a requirement. It gets reviewed, prioritized, and eventually turned into a statement of work or added to an existing program. Months later—sometimes longer—there’s a tool. Whether it still fits the original need is a separate question.

The alternative looks different.

That same analyst opens a compliant development environment, selects a template aligned to their data stack, and starts prototyping. An AI coding assistant helps fill in the gaps where they don’t have deep engineering experience. Within a few days, something is testable. Within a week, it’s shareable.
The key difference isn’t just speed. It’s fidelity. The person who understood the problem is still the one shaping the solution.

DoD’s Advana platform—a centralized, CAC-enabled data and analytics environment—has already shown what happens when that barrier is removed. Analysts can access data, build workflows, and share useful outputs without standing up a program first.

The opportunity for the IC is extending that model beyond analytics into broader development, so domain experts can do more than analyze data. They can build the tools they need, when they need them.

The infrastructure problem underneath all of this

None of it happens if standing up a compliant workspace takes two weeks or longer.

That’s the constraint that kills citizen developer initiatives before they start. When provisioning access to a development workspace still means navigating approvals, provisioning steps, and configuration work that only a handful of people understand, the friction is high enough that only few engineers bother. Domain experts who might prototype something valuable just don’t. The opportunity cost is invisible, so it doesn’t show up in any program’s risk register.

There are also constraints that don’t go away: accreditation boundaries, ATOs, and networks that weren’t designed for rapid iteration. Those are real, and they shape what’s possible.

Platform engineering addresses this at the source. Small, focused platform teams define what compliant development looks like, build it into self-service templates, and let anyone with access spin up a workspace in minutes — pre-configured, policy-compliant, ready to go. Workspace infrastructure is defined as code. Security controls are built in rather than added after the fact. The same template that works on an unclassified network works identically on a classified one, in an air-gapped facility, without asking the builder to re-platform when they change networks.

That last point matters more than it might sound. A senior analyst willing to try building something shouldn’t have to become a system administrator first. The infrastructure either gets out of the way or it doesn’t.

Security as the floor, not the door

The compliance model most programs inherited treats security as a gate: something you pass through at the beginning or prove at the end. That made sense when developers were a small, specialized population that could be managed through access controls and vetting processes.

It breaks down when the goal is to expand who builds. You can’t selectively enforce compliance based on whether someone has a traditional development background. What you can do is move the enforcement into the platform itself. Toolchain access is defined before anyone writes a line of code, audit logs are generated automatically, and policy is traveling with the workspace rather than depending on individuals to follow procedures correctly every time.

In a platform model, the controls are defined once and enforced everywhere. NIST’s Secure Software Development Framework (SSDF) has been making this argument at the policy level for years: security should be continuous and integrated, not a final checkpoint. Platform engineering is how that principle becomes operational reality. When compliance is built into the platform, it stops being the mechanism that determines who gets to start building.

What the IC actually stands to gain

The agencies that figure out how to turn domain expertise into repeatable, shareable capability will have something that can’t be easily replicated by competitors or contractors. The analyst who developed a novel approach to a collection problem retires, and under the current model, that approach retires with them — maybe preserved in a report, maybe not. A Science study published in early 2026 found that productivity gains from AI-assisted coding were sharpest among experienced practitioners — not junior developers. The IC’s senior analysts, operators, and specialists are exactly that population.

When those people can build tools that encode what they know, expertise becomes institutional rather than individual. An analyst’s data transformation becomes a template. A targeting workflow becomes a starting point for the next team. The distance between having an idea and building something useful around it starts to compress.

The competitive pressure here is real. Near-peer adversaries are moving aggressively to apply AI to their own software development and autonomous operations. The IC’s response can’t just be better infrastructure for the engineers it already has. It needs infrastructure that expands who gets to build, and that starts with ensuring the people who understand the mission are the ones shaping the tools.

The IC’s advantage will belong to the organizations that stop separating those two groups at all.

Austen Bruhn is a Staff Solutions Engineer for the US Public Sector at Coder, where he works with government and defense programs on secure, compliant development infrastructure across classification levels.

Coder is the AI software development company leading the future of autonomous coding. Coder helps teams build fast, stay secure, and scale with control by combining AI coding agents and human developers in one trusted workspace. Learn more at coder.com.

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

The post Who Builds the Mission Now? How the IC Is Expanding the Definition of a Developer appeared first on Intelligence Community News.

]]>
44313
The Software Factory Is Dead, Long Live the Software Factory https://intelligencecommunitynews.com/ic-insiders-the-software-factory-is-dead-long-live-the-software-factory/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-the-software-factory-is-dead-long-live-the-software-factory Mon, 09 Mar 2026 12:52:55 +0000 https://intelligencecommunitynews.com/?p=44022 From IC Insider Coder By Amanda Phelps, Head of Global Public Sector Partnerships and Alliances at Coder I have watched...

The post The Software Factory Is Dead, Long Live the Software Factory appeared first on Intelligence Community News.

]]>
From IC Insider Coder

By Amanda Phelps, Head of Global Public Sector Partnerships and Alliances at Coder

I have watched talented government and defense teams pour years of effort into software factories, and watched those same factories quietly become the thing slowing development down. That is not a failure of the people who built them. It is a signal that the model has run its course.

For the past decade, “software factory” has been the defining concept of digital transformation across the Department of Defense and the Intelligence Community. Initiatives like Platform One, Kessel Run, Black Pearl, and Kobayashi Maru proved that modern DevSecOps could work in sensitive environments, that containers could survive an ATO, and that developers did not need to wait months for infrastructure. Those teams deserve every bit of credit they receive.

But the model they pioneered is now collapsing under its own weight. The factories we built were cathedrals. What the mission needs now is something more flexible, like a framework.

The untenable cost of the monolith

The original software factories had to be centralized and monolithic. Kubernetes was not yet authorized. CI/CD pipelines could not yet satisfy NIST 800-53 controls. GitOps was unproven at the classification boundary. Early adopters bore enormous compliance burdens just to establish that modern development was possible in secure environments at all.

The fundamental problem is that monolithic factories try to be everything to everyone. A single factory is expected to serve programs building web applications and programs training machine learning models, teams operating in the cloud and teams in air-gapped facilities, experienced engineers and teams encountering modern development for the first time. That breadth creates impossible tradeoffs. Make the factory standardized and you alienate programs with specialized requirements. Make it flexible and you drown in configuration complexity until the factory itself becomes the bottleneck.

These factories also became single points of failure. When key personnel leave, institutional knowledge walks out with them. Platform teams get consumed by access requests, exception handling, and organizational overhead. The infrastructure meant to accelerate delivery starts slowing it down.

A maturing commercial ecosystem changes the calculus

What changed is that commercial technology matured in ways government-built factories cannot match.

Purpose-built infrastructure automation tools now treat cluster provisioning, configuration management, and infrastructure-as-code as solved problems. Declarative approaches — defining the desired state and letting automation handle the realization — enable agencies to enforce discrete access controls, reduce insider risk, and remove human error from provisioning. These capabilities are core to the tools, not incidental to them.

For the developer experience specifically, the shift has been equally significant. Secure, cloud-based development environments address one of the most persistent pain points in classified software development: standing up a compliant workstation and becoming productive. Developers in air-gapped facilities typically wait days, and weeks or months are not uncommon, for properly configured systems. Modern development environments can be provisioned in minutes from an approved template, with security controls built in rather than bolted on. Coder provides this capability for IC and DoD programs — teams define workspace infrastructure as code, enforce policy at the platform level, and support everything from unclassified development through classified and disconnected environments without changing the developer workflow.

This approach also shifts the maintenance burden from overworked government platform teams to vendors with engineering resources, SLAs, and dedicated security response. When something breaks, you open a ticket rather than lose months of capability development while someone reconstructs a Kubernetes cluster from memory.

Platform engineering: Smaller teams, greater scale

The successor to the software factory is not another factory. It is a platform engineering model where small, focused teams curate technology choices and define integration patterns rather than building and operating infrastructure from scratch.

This distinction matters enormously for the IC because the scalability problem that killed monolithic factories came down to headcount. When every program office queues behind a central platform team, scaling means hiring more government employees — slow, expensive, and constrained by hiring authorities that often have little relationship with the pace of mission need. When programs consume infrastructure through self-service catalogs built on proven commercial technology, scaling becomes a software problem. That is solvable.

In this model, platform teams do three things well:

  1. Define what compliant deployment looks like
  2. Curate the approved components that programs draw from, and
  3. Provide self-service interfaces that let development teams operate within security guardrails without creating a ticket for every resource request

 

The result is portable compliance. A workspace template that meets security requirements in an unclassified environment should work the same way on a classified network and function without modification in an air-gapped facility. Policy travels with the infrastructure.

The cross-domain problem

For the IC specifically, the platform engineering transition carries an additional imperative that defense-focused discussions tend to overlook: cross-domain development.

A developer supporting a program that spans multiple classification levels does not simply move between environments. They context-switch between different physical machines, credential sets, toolchains, and organizational processes. Work products moving between domains pass through transfer processes measured in hours or days. Managing cross-domain workflows has historically required dedicated personnel whose primary function is shepherding data across boundaries rather than building capability.

Platform engineering changes this. When development environments are defined as code and centrally managed, it becomes possible to maintain consistent toolchains and security baselines across classification levels while preserving the hard separations that protect sources, methods, and program equities. A developer’s workspace on the low side and their workspace on the high side can be structurally identical. Cross-domain transfer processes can integrate into the development workflow rather than function as afterthoughts. The compliance burden shifts from individuals performing manual procedures to the platform enforcing those procedures automatically.

IC programs are already deploying remote development infrastructure that spans classification boundaries with consistent policy enforcement and without asking developers to re-platform every time they change networks.

The democratization of building

Here is where this transition becomes genuinely transformative — and where the IC has a specific advantage to capture.

The IC has always had a large population of domain experts who are not software developers but who possess operational knowledge no development team can fully replicate. All-source analysts who understand threat actor behavior in ways that cannot be captured in a requirements ticket. SIGINT specialists who recognize patterns in data only visible through years of operational exposure. Collection managers who understand source constraints in ways that lose critical nuance when translated to pure technicians.

Platform engineering, combined with the right development infrastructure, is beginning to make these people builders. Not in the traditional software development sense, but in the sense of constructing tools, notebooks, workflows, and analytical environments that extend individual expertise into repeatable, shareable capability. An analyst who can prototype a data transformation that makes a new collection source exploitable is not writing production software. But they are producing real mission value — in ways that centralized software factories were never designed to support.

The enabling condition is a development environment that removes the infrastructure tax on exploration. When standing up a secure, compliant workspace requires a ticket and a two-week wait, only credentialed engineers do it. When it requires a template selection and a few minutes, the population of people who can meaningfully participate in building expands dramatically. Compliance becomes the baseline from which everyone works, not a gate that filters who can start.

What is actually dying (and what is not)

What is dying is the centralized, monolithic software factory that inserts itself as the critical path for every development team it serves. The model where a single isolated organization controls the infrastructure, tools, processes, and standards for all programs is giving way to something more sustainable.

The mission need those factories served is not dying. It is growing. Agencies still need to compress delivery timelines, elevate security postures without stifling innovation, retain technical talent, and deliver capability at the speed modern threats demand. The difference is that the IC no longer needs to build its own factory to achieve those outcomes. The Air Force’s Platform One has evolved toward a platform-of-platforms model. The Navy has moved to multi-vendor strategies that reduce lock-in and increase operational resilience. Across the IC, organizations are realizing they can adopt proven frameworks and adapt them to their compliance requirements rather than rebuilding from scratch.

The path forward

The question is no longer whether modern DevSecOps practices can work in classified environments. That is proven. The questions now are much harder to solve.

Can we build development infrastructure that genuinely serves the cross-domain operating reality of the intelligence enterprise, rather than forcing developers to absorb that complexity as manual overhead? Can we extend the population of people who build to include analysts, specialists, and operators whose domain expertise is the IC’s most irreplaceable asset? Can we shift enough of the compliance burden into the platform itself that security becomes an accelerant rather than a constraint?

Platform engineering makes all of this achievable. Small teams can support large organizations. Compliance becomes portable and workspaces repeatable across classification levels. The maintenance burden that currently consumes government talent shifts to software. The distance between having an idea and building something useful around it can be measured in minutes.

The factory that tried to control everything is giving way to a platform that enables everyone. That is not a loss. It is the next evolution the mission has been waiting for.

About the Author

Amanda Phelps leads Global Public Sector Partnerships and Alliances at Coder, where she works with government and defense organizations to enable secure, compliant development environments across classification levels. She specializes in creating partnership strategies that accelerate software delivery for programs in the public interest.

About Coder

Coder is the AI software development company leading the future of autonomous coding. Coder helps teams build fast, stay secure, and scale with control by combining AI coding agents and human developers in one trusted workspace. Coder’s award-winning self-hosted Cloud Development Environment (CDE) gives teams the power to govern, audit, and accelerate software development without trade-offs. Learn more at coder.com.

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

The post The Software Factory Is Dead, Long Live the Software Factory appeared first on Intelligence Community News.

]]>
44022
Security at the Enterprise Edge: Top Five Concerns https://intelligencecommunitynews.com/ic-insiders-security-at-the-enterprise-edge-top-five-concerns/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-security-at-the-enterprise-edge-top-five-concerns Sun, 01 Feb 2026 22:23:27 +0000 https://intelligencecommunitynews.com/?p=43755 From IC Insider Thales Trusted Cyber Technologies By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies As digital transformation continues...

The post Security at the Enterprise Edge: Top Five Concerns appeared first on Intelligence Community News.

]]>
From IC Insider Thales Trusted Cyber Technologies

By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies

As digital transformation continues driving change in federal agencies’ operating environments, the need for edge-level data protection has never been greater. Cloud and edge environments are essentially becoming micro data centers, taking on many of the IT core infrastructure characteristics formerly reserved for large HQ facilities. Bolstered by renewed interest in the  Modernizing Government Technology Reform Act, there has been a rise in core-level IT capabilities at the network edge government-wide.

This interest, however, introduces some challenges for extending core-level security to edge environments. For example, solutions for these edge environments may be constrained by specific, size, weight and power demands, and may require more elaborate data protection technology.

When developing an ecosystem to protect data at the edge, it’s important to consider several key principles, namely size constraints, the threat of hostile access, managing cryptographic keys, controlling access, protecting mission-critical data in transit, and complying with regulatory requirements.

Right-sizing edge solutions to defend data access

The government’s size, weight and power (SWaP) requirements for equipment in tactical areas are very specific. That, along with the extreme conditions in the physical environment at the network edge, creates demands on both durability and compactness in edge security solutions.

Add to these demands the need for data security in the event of equipment being taken by  other parties during conflict and you begin to understand the scope and complexity of edge network technological capabilities.

Edge equipment must come with a cryptographic erase solution that protects encrypted data. In fact, the military generally follows NIST policies for the destruction of physical media after a sanitation process. This process typically requires overwriting drives multiple times to ensure data is properly erased.

To simplify this process somewhat, data encryption keys can be erased or destroyed, obviating the need to sanitize the storage drive itself. The data itself remains encrypted and inaccessible, no matter who might control the physical equipment.

These simpler types of protective measures are essential for edge products because users at the edge may not have as much experience with data security measures as their counterparts in headquarters data centers. Default configurations must be secure and easy to understand.

Also, keep in mind that edge systems are also susceptible to connectivity issues. Consequently, such systems must be able to store and secure data locally, sending new or updated data  back to the core or the cloud after the connection is restored. As an added concern, multiple connected units must be configurable at the enterprise level.

The importance of centralized key management

We wrote earlier about the usefulness of data encryption keys in limiting data access. Such keys are particularly important at the edge, where an organization’s IT security teams may need to manage multiple cryptographic keys and a variety of encryption solutions.

Unfortunately, native key management solutions are not typically interoperable. As a result,  system administrators often store cryptographic keys in the same location as encrypted data – which does not follow best practices for key management and  practically invites exploitation.

The answer here is to ensure centralized key management. By doing so, an organization has secure storage and backup of encryption keys. Access control policies are defined. Encryption tasks can be separated from key management tasks. The entire key lifecycle is more properly addressed – from key creation, rotation, backup and destruction. In edge environments, where keys can be susceptible to compromise, this approach is indispensable.

When deciding on appropriate cryptographic products, it’s important to look for solutions with hardware security modules (HSMs) as removable tokens. HSMs act as the root of trust for encryption solutions. These removeable tokens can be ideal in edge environments, because detachable tokens keep essential data safe, even in the most remote or hazardous locations. Without the root of trust, encryption keys remain secure on the edge device and are not accessible without the HSM token.

Control access with multi-factor authentication

With apps, services, and data in the cloud, accessed through devices at the edge, everyone becomes an outsider. That creates a genuine need to establish and enforce identity and access security policy safeguards for assets in the cloud, on-premises, and at the edge.

New threats and risks are heightened as operational requirements change, demanding a simple but scalable solution for authentication. Multi-factor authentication, therefore, is the most secure way to limit access to data and applications, particularly at the edge.

With multi-factor authentication at the edge, organizations can be assured of better access control across multiple environments. This is true no matter which devices are used, and whether data is maintained locally, on-premises, or in the cloud.

Protecting data in transit

The demand on high-speed wide-area networks has been pushed with cloud migration of data, global collaboration, and bandwidth requirements at the edge.

Huge amounts of data are traversing the network and consequently under constant threat. It is essential to encrypt everywhere – both data in motion and at rest.

Data in transit is best protected by network encryptors which allow people, organizations and locations to securely share information. Network encryptors protect data, video, voice, and metadata from eavesdropping, surveillance, and overt and covert interception which is critical at the edge.

Vendor agnostic interoperability is critically important for these solutions, to make it easier on network architecture and IT professionals. Also important is the flexibility to adapt to changing security and network requirements.

Security compliance policies and regulations

Compliance with security requirements is a critical part of minimizing vulnerability at the edge, where susceptibility to attack is considerably greater. To ensure compliance, enterprise-level security policies must be applied across all architecture, including the edge.

Organizations need to look for solutions that carry certifications from multiple organizations, including FIPS 140; the Commercial Solutions for Classified program, and the Committee on National Security Systems Memo #063-2017. The Department of Defense’s Information Network Approved Product List, which had been a repository for such solutions, was sunset in December 2025. Cybersecurity requirements are in the process of transitioning to the DISA RME Vendor Security Technical Implementation Guides (STIG) program.

The challenge of building an IT infrastructure with hardened security that extends to the very edge can seem daunting. By considering these five aspects, it will become significantly easier to develop a system that appropriately controls access and protects data at rest and in transit – from the core to the cloud to the edge.

About Thales TCT

Thales Trusted Cyber Technologies, a business area of Thales Defense & Security, Inc., protects the most vital data from the core to the cloud to the field. We serve as a trusted, U.S. based source for cyber security solutions for the U.S. Federal Government. Our solutions enable agencies to deploy a holistic data protection ecosystem where data and cryptographic keys are secured and managed, and access and distribution are controlled.

For more information, visit www.thalestct.com

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

 

 

The post Security at the Enterprise Edge: Top Five Concerns appeared first on Intelligence Community News.

]]>
43755
From Visibility to Advantage – Building a Quantum-Safe Intelligence Enterprise https://intelligencecommunitynews.com/ic-insiders-from-visibility-to-advantage-building-a-quantum-safe-intelligence-enterprise/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-from-visibility-to-advantage-building-a-quantum-safe-intelligence-enterprise Mon, 05 Jan 2026 12:43:54 +0000 https://intelligencecommunitynews.com/?p=43518 From IC Insider Tychon Quantum Readiness as a Strategic Advantage For the Intelligence Community (IC), cybersecurity has never been purely about...

The post From Visibility to Advantage – Building a Quantum-Safe Intelligence Enterprise appeared first on Intelligence Community News.

]]>
From IC Insider Tychon

Quantum Readiness as a Strategic Advantage

For the Intelligence Community (IC), cybersecurity has never been purely about compliance. It’s about mission assurance and ensuring that national security operations remain confidential, authentic, and resilient in the face of evolving threats.

As quantum computing accelerates, the next frontier of cyber risk will not be patch management or endpoint defense. It will be cryptographic control. The ability to see, understand, and govern the encryption that underpins every mission system.

Organizations that treat quantum readiness as a strategic advantage, rather than a regulatory requirement, will lead the transition to the post-quantum era.

Why Visibility Is the Foundation of Readiness

You can’t secure what you can’t see. Yet across the federal enterprise, most agencies still lack full visibility into the cryptographic landscape that protects their networks.

Hundreds of algorithms, certificates, and key stores exist across legacy systems, mission applications, and third-party integrations. Many were deployed years ago and never revisited.

This fragmented visibility creates risk in two critical ways:

  • Unknown exposures – such as cryptography in use but not cataloged or scored.
  • Budget uncertainty – no accurate data to estimate PQC migration or hardware refresh costs.

 

Without automated discovery, modernization becomes guesswork.

Data-Driven Decisions Start with Tychon

Tychon Quantum Readiness gives IC leaders a complete, continuously updated view of the organization’s cryptographic posture.

It inventories every algorithm, certificate, and implementation across endpoints, servers, containers, and cloud infrastructure. Then it produces NIST-aligned risk scores, hardware readiness data, and normalized “gold-standard” cryptography inventories, the foundation for informed executive decisions.

The result is not just compliance, it’s clarity to action the following:

  • Inventory and risk triage
  • Classify and protect high-value data
  • Plan to adopt hybrid cryptography (e.g. move to hybrid schemes)
  • Vendor and supply chain engagement
  • Operational policy changes
  • Test, pilot, and interop
  • Workforce tooling

From Inventory to Investment Intelligence

The result is not just compliance, it’s clarity. CIOs, CISOs, mission leaders, program managers and budget officers gain real-time insight into what needs upgrading, how much it will cost, and where modernization can deliver the greatest security impact.

Modernization planning without cryptography data is like budgeting without an asset list. Tychon’s continuous telemetry enables agencies to:

  • Forecast PQC migration costs with precision by correlating algorithm risk to specific systems and hardware.
  • Quantify hardware readiness by evaluating whether current compute capacity supports PQC algorithms.
  • Model out-year budgets for system upgrades or replacements aligned with OMB and NIST timelines.

 

In a constrained fiscal environment, these insights transform quantum readiness from an unfunded mandate into a measurable investment strategy.

Aligning with Federal Frameworks

Tychon doesn’t just produce data, it aligns that data with federal frameworks that matter most to the IC:

  • OMB M-23-02: Automated cryptography inventory and reporting for agency compliance.
  • NSM-10: National Security Systems protection requirements and modernization goals.
  • CISA CDM: Continuous Diagnostics and Mitigation integration for real-time risk visibility.

 

Through its SIEM-first design, Tychon streams cryptographic data directly into existing dashboards such as Elastic, Splunk, Axonius, and others, providing mission-level visibility without new infrastructure.

Bridging PQC and Zero Trust

Zero Trust architectures rely on continuous verification and cryptographic assurance. Without visibility into algorithms and keys, Zero Trust becomes partially blind.

Tychon bridges this gap by delivering cryptography telemetry as a continuous diagnostic signal, enriching the same data streams that feed Zero Trust, insider-threat, and compliance platforms.

In doing so, it aligns PQC migration with the IC’s broader modernization strategies including Zero Trust, AI-assisted SOCs, and digital transformation.

From Reactive Compliance to Proactive Governance

Quantum readiness offers the IC an opportunity to evolve beyond reactive reporting cycles. By automating discovery and assessment, agencies can maintain a living cryptography inventory, one that updates continuously and underpins proactive decision-making.

This shift turns compliance into governance, enabling leadership to:

  • Establish measurable risk reduction goals.
  • Correlate cryptography health to mission availability.
  • Demonstrate audit readiness at any moment.

 

It’s the difference between meeting a mandate and commanding the modernization agenda.

Mission Resilience Starts with Cryptography Integrity

For decades, encryption has silently protected the IC’s most valuable assets from human intelligence and operational data to analytic models. As the quantum era approaches, that protection must evolve.

Agencies that act now will not only safeguard their missions but also gain operational agility, cost certainty, and data confidence long before Q-Day arrives.

Your Next Step

Begin your agency’s transition to a quantum-safe future. Start a 90-day pilot of Tychon Quantum Readiness today at tychon.io/pilot or contact info@tychon.io to learn more.

About Tychon

TYCHON is a NIST NCCoE consortium collaborator and proven cybersecurity innovator delivering automated cryptography discovery and quantum-readiness solutions across U.S. Federal, DoW, and commercial enterprises. Tychon provides instant cryptographic visibility, risk assessment, and compliance reporting for the post-quantum era.

Sponsored content provided by Tychon LLC, a NIST NCCoE consortium collaborator for PQC.

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

 

The post From Visibility to Advantage – Building a Quantum-Safe Intelligence Enterprise appeared first on Intelligence Community News.

]]>
43518
Inside the Mission – Automating Cryptographic Discovery and Risk for the Quantum Era https://intelligencecommunitynews.com/ic-insiders-inside-the-mission-automating-cryptographic-discovery-and-risk-for-the-quantum-era/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-inside-the-mission-automating-cryptographic-discovery-and-risk-for-the-quantum-era Wed, 10 Dec 2025 13:01:13 +0000 https://intelligencecommunitynews.com/?p=43372 From IC Insider Tychon Manual Cryptography Inventory: A Hidden Operational Burden Across the Intelligence Community (IC), cybersecurity teams have faced...

The post Inside the Mission – Automating Cryptographic Discovery and Risk for the Quantum Era appeared first on Intelligence Community News.

]]>
From IC Insider Tychon

Manual Cryptography Inventory: A Hidden Operational Burden

Across the Intelligence Community (IC), cybersecurity teams have faced an unexpected challenge: finding and cataloging every instance of encryption in use. Whether it’s a TLS certificate, a VPN configuration, or an embedded algorithm in a mission system, each represents a potential vulnerability in a quantum future.

Most agencies today rely on spreadsheets, manual scripts, and ad hoc tools to attempt discovery, an approach that consumes thousands of analyst hours, delays compliance with OMB M-23-02 and NSM-10, and leaves decision-makers blind to emerging risks.

The problem isn’t effort. It’s visibility.

The Need for Continuous, Automated Discovery

Every encryption key, certificate, and cipher suite deployed across an enterprise is a potential weak point once quantum computers arrive. Agencies need more than one-time inventories; they need continuous visibility and risk scoring.

Automation is the only viable path forward. Without it, cryptographic inventories grow stale within weeks, and remediation plans are based on outdated assumptions.

Tychon Quantum Readiness delivers exactly that. Continuous, automated cryptography discovery, inventory, and risk assessment that’s built for scale and designed for the complexity of IC networks.

Engineered for Mission Simplicity

Unlike legacy cryptography management tools that require heavy infrastructure, agents, or separate consoles, Tychon deploys as a stateless binary. It runs with no persistent services or external dependencies, and it integrates directly with existing endpoint and systems management tools including BigFix, Intune, SCCM, and Ansible.

This design makes Tychon ideal for secure and air-gapped environments:

  • No new agents or network appliances required
  • No proprietary dashboards to train on
  • Deployment measured in hours, not months
  • Zero operational friction across classified and unclassified domains
  • No additional servers, databases, or external calls
  • Extensive reporting options to include CBOM, CSV, JSON and more

A SIEM-First Design for Real-Time Insight

Tychon’s architecture reflects a SIEM-first philosophy that is designed to feed cryptographic visibility directly into mission systems that already exist.

It integrates natively with BigFix, Elasticsearch, Splunk, Axonius, and Armis, streaming continuous diagnostics and cryptography risk telemetry into the same dashboards security teams already use.

Pre-built dashboards instantly surface:

  • Protocols and ciphers in use
  • Certificates nearing expiration or using deprecated algorithms
  • Key lengths and curve types
  • Cryptographic libraries and binaries detected in applications

 

No retraining. No console switching. No data silos.

From Static Spreadsheets to Continuous Compliance

Federal policy has accelerated the demand for live cryptographic visibility. Under OMB M-23-02, agencies must not only complete a one-time cryptography inventory but also report ongoing progress and risk posture.

Tychon automates this requirement, generating NIST-aligned reports and dashboards for OMB, NSM-10, and CISA CDM compliance frameworks.

By automating data collection, normalization, and scoring, Tychon reduces cryptographic inventory costs by up to 90 percent, eliminating more than 1,200 staff hours per reporting cycle.

Risk Scoring that Speaks the Language of Mission Owners

Not all cryptography carries equal risk. Tychon’s integrated scoring engine quantifies exposure based on algorithm age and strength, key length, implementation type, system criticality, and quantum vulnerability.

This NIST-aligned scoring model helps agency leaders to mission program managers prioritize mitigation efforts and budget allocations.

It also supports hardware readiness analysis by identifying systems unable to support PQC algorithms. This is a crucial insight for hardware budget lifecycle and modernization planning.

Security Without Trade-Offs

Security and simplicity rarely coexist, but Tychon achieves both. The self-contained binary includes all required libraries internally, eliminating dependency risks. It’s easy to hash, verify, and attest for supply-chain integrity.

Data never leaves the customer’s environment. Role-based access, audit logging, and FIPS-validated components ensure that the system meets the security bar expected by DoW, IC, and FCEB environments.

Proven at Mission Scale

Tychon’s technology is battle-tested at scale. The same engine that underpins Tychon Quantum Readiness has been operational across the U.S. Army’s global enterprise, more than 800,000 endpoints, for over eight years.

In classified and disconnected environments, Tychon continues to deliver real-time cryptographic telemetry with unmatched performance and reliability.

For the IC, this means confidence that the same solution proven in the world’s largest defense networks can extend securely into sensitive mission systems.

Why It Matters to the Intelligence Community

Quantum readiness is not a compliance checkbox, it is an operational continuity issue. Encryption is the foundation of every IC mission: protecting data at rest, authenticating users, securing communications, and maintaining trust in classified networks.

Losing confidence in that foundation could have cascading effects on national security operations.

By automating the discovery and management of cryptography, Tychon helps IC organizations transition from fragmented, manual visibility to continuous, data-driven assurance.

A New Seamless Path to PQC Readiness for BigFix Customers

BigFix customers now have the option to activate Tychon’s Quantum Readiness capabilities as a native BigFix offering, eliminating the need for additional tools or integrations. This direct integration allows agencies to perform automated cryptographic discovery and risk assessment using the same BigFix workflows they already trust for endpoint management. By leveraging BigFix’s deployment scale, agencies gain immediate visibility into quantum-vulnerable algorithms, certificates, and keys across every managed system. This new offering, known as BigFix Quantum Risk Analyzer, dramatically accelerates compliance efforts and enables a seamless path to PQC transition planning. This combined new solution will be generally available to BigFix customers for trial or purchase in January 2026.

The Future: Continuous Cryptography Intelligence

The next era of cybersecurity will not simply monitor threats, it will monitor the integrity of cryptography itself. With Tychon, agencies stream cryptographic telemetry into their preferred SIEM, business intelligence, and big data platforms for continuous diagnostics and mitigation, aligning perfectly with Zero Trust and PQC transition initiatives.

Request a live demonstration to see Tychon Quantum Readiness in action. Automate your cryptography visibility within hours, not months. Contact info@tychon.io or visit tychon.io.

About Tychon

TYCHON is a NIST NCCoE consortium collaborator and proven cybersecurity innovator delivering automated cryptography discovery and quantum-readiness solutions across U.S. Federal, DoW, and commercial enterprises. Tychon provides instant cryptographic visibility, risk assessment, and compliance reporting for the post-quantum era.

Sponsored content provided by Tychon LLC, a NIST NCCoE consortium collaborator for PQC.

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

The post Inside the Mission – Automating Cryptographic Discovery and Risk for the Quantum Era appeared first on Intelligence Community News.

]]>
43372
The Urgency of Quantum Readiness – What the Intelligence Community Needs to Know Now https://intelligencecommunitynews.com/ic-insiders-the-urgency-of-quantum-readiness-what-the-intelligence-community-needs-to-know-now/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-the-urgency-of-quantum-readiness-what-the-intelligence-community-needs-to-know-now Thu, 20 Nov 2025 02:52:13 +0000 https://intelligencecommunitynews.com/?p=43223 From IC Insider Tychon The Quantum Countdown Quantum computing has moved from theoretical curiosity to technological inevitability and with it...

The post The Urgency of Quantum Readiness – What the Intelligence Community Needs to Know Now appeared first on Intelligence Community News.

]]>
From IC Insider Tychon

The Quantum Countdown

Quantum computing has moved from theoretical curiosity to technological inevitability and with it comes one of the largest security transitions in modern history. When Dr. Peter Shor unveiled his algorithm in 1994, the world learned that quantum computers could one day break the public-key encryption that protects everything from battlefield communications to classified research and national intelligence data.

That day, commonly known as “Q-Day,” may be closer than many think. Dr. Michele Mosca, one of the world’s foremost experts in quantum computing timelines, gives Q-Day a 1-in-7 chance by 2026 and a 50 percent chance by 2031. For the Intelligence Community (IC), where adversaries continuously collect encrypted traffic to decrypt later (“Harvest Now, Decrypt Later”), this risk is immediate.

There will be an immediate impact if large scale quantum computers emerge

  • Breaking RSA, Diffie–Hellman, and ECC – the algorithms that protect most classified and unclassified government communications.
  • Compromising diplomatic, military, and IC networks that still rely on classical public-key cryptography.
  • Identity theft of government credentials, including digital signatures.

Harvest Now, Decrypt Later Is Already Here

Adversaries do not need to wait for Q-Day. Many already intercept and store encrypted communications today with the expectation that they can decrypt them once quantum computing power matures. Data collected now such as diplomatic cables, SIGINT and HUMINT communications, Intelligence sharing arrangements or even sensitive personnel records may be exposed years later. What is at risk, historical operational TTPs, sources, networks, covert methods, OPSEC, and more to provide our adversaries with a greater understanding of U.S. Intelligence.

The only defense is proactive migration to quantum-safe algorithms, known collectively as Post-Quantum Cryptography (PQC).

PQC Mandates Are in Motion

Federal and IC organizations are not starting from scratch. A series of policies and directives are already shaping the national PQC roadmap:

  • OMB M-23-02 – Requires agencies to inventory and assess cryptography, report on quantum-susceptible algorithms, and establish PQC transition plans.
  • NSM-10 – Directs agencies to protect National Security Systems (NSS) from quantum threats.
  • NIST PQC Standards – Algorithms like CRYSTALS-Kyber and CRYSTALS-Dilithium are being standardized into Federal Information Processing Standards (FIPS) for broad adoption.

 

Together, these mandates demand one critical capability: knowing what cryptography you have, where it resides, and whether it’s quantum-vulnerable.

The Four Phases of Quantum Readiness

Every organization, from mission system owners to intelligence analysts, will need to navigate four core phases of quantum readiness:

  1. Information Discovery: Identify systems, data flows, and communication channels using encryption.
  2. Cryptography Inventory: Locate every algorithm, key, and certificate in use.
  3. Risk Assessment & Analysis: Determine which assets are quantum-susceptible and prioritize remediation.
  4. Remediation & Migration: Replace vulnerable cryptography and modernize systems for PQC.

 

Manually completing these steps across hundreds of thousands of endpoints and applications could take years, time the IC cannot afford.

Automating Readiness with Tychon

Tychon Quantum Readiness automates cryptography discovery, inventory, and risk assessment across endpoints, networks, containers, and cloud environments. The lightweight, stateless utility deploys seamlessly through tools IC agencies already use such as BigFix, Intune, SCCM, or Ansible, with no new agents or consoles to manage.

Within hours, mission owners can see where vulnerable cryptography lives, score their risk using NIST-aligned metrics, and generate dashboards suitable for compliance reporting to OMB M-23-02 and NSM-10.

Field-proven on more than one million U.S. Government systems, Tychon demonstrates scalability that matches IC mission environments.

Risk Management, Not Reinvention

Cybersecurity has always been about risk management. Tychon brings that same maturity to quantum readiness. Helping agencies measure, analyze, mitigate, and manage cryptographic risk without disrupting existing operations or retraining staff.

Because data never leaves the customer environment and Tychon runs within existing security stacks, it aligns naturally with classified, air-gapped, and compartmented networks.

The Time to Act Is Now

Quantum readiness is no longer a research initiative. It’s a national security imperative. Agencies that begin automated cryptographic discovery today gain the time and clarity needed to meet federal timelines and stay ahead of adversaries already collecting data for future decryption. Taking action now is necessary and beneficial to agencies as it:

  • Gives leaders the facts needed to plan as early inventory provides the scope, scale, and complexity necessary to build accurate PQC budgets, staffing models, and modernization timelines.
  • Enables smart prioritization by knowing which systems use quantum-vulnerable algorithms lets agencies focus first on the highest-risk, highest-impact assets.
  • Creates leverage with vendors and integrators exposing dependencies on third-party products, giving agencies time to secure roadmaps, upgrades, and contract modifications.

 

Learn where your cryptography stands. Visit tychon.io to schedule a Quantum Readiness Assessment and receive your no-cost 90-day pilot.

About Tychon

TYCHON is a NIST NCCoE consortium collaborator and proven cybersecurity innovator delivering automated cryptography discovery and quantum-readiness solutions across U.S. Federal, DoW, and commercial enterprises. Tychon provides instant cryptographic visibility, risk assessment, and compliance reporting for the post-quantum era.

Sponsored content provided by Tychon LLC, a NIST NCCoE consortium collaborator for PQC.

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

The post The Urgency of Quantum Readiness – What the Intelligence Community Needs to Know Now appeared first on Intelligence Community News.

]]>
43223
Speed. Security. Simplicity. Rancher Government Transforms Kubernetes Operations in Classified Environments https://intelligencecommunitynews.com/ic-insiders-speed-security-simplicity-rancher-government-transforms-kubernetes-operations-in-classified-environments/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-speed-security-simplicity-rancher-government-transforms-kubernetes-operations-in-classified-environments Wed, 12 Nov 2025 14:03:30 +0000 https://intelligencecommunitynews.com/?p=43158 From IC Insider Rancher Government Solutions With IC Cloud Support, Intelligence Community teams can now provision and manage clusters faster...

The post Speed. Security. Simplicity. Rancher Government Transforms Kubernetes Operations in Classified Environments appeared first on Intelligence Community News.

]]>
From IC Insider Rancher Government Solutions

With IC Cloud Support, Intelligence Community teams can now provision and manage clusters faster and more securely, simplifying operations across the most restricted networks.

For mission owners across the Intelligence Community, secure modernization has long meant trade-offs: classified environments often lag behind commercial clouds in automation, speed, and usability. Rancher Government Solutions (RGS) helps close that gap.

RGS, a leader in secure, enterprise-grade Kubernetes management for the U.S. Government, has announced the General Availability (GA) of IC Cloud Support. This breakthrough capability brings full provisioning and lifecycle management to classified cloud environments without requiring access keys, custom software development kits (SDKs), or manual workarounds.

“Our customers in classified environments deserve the same operational simplicity and resiliency they get in commercial cloud,” said Adam Toy, Chief Technology Officer at RGS. “With IC Cloud Support, RGS brings that consistency to the most secure environments in government.”

The Challenge: Managing Kubernetes Behind the Airgap

Organizations operating in airgapped or restricted AWS and Azure regions face a radically different landscape from commercial cloud users. These classified environments are completely isolated by design, with no internet connectivity, external endpoints, or public resource exchange.

As a result, provisioning or managing Kubernetes infrastructure required manual, highly constrained processes:

  • Physically moving software via burned discs or removable media into SCIFs
  • Operating without identity access management (IAM) keys or secrets, since credential creation is prohibited
  • Rewriting code to communicate with .gov API endpoints and custom certificate authorities
  • Relying on imported clusters that limited access to Day-2 operations like scaling, shell access, or certificate rotation

 

This fragmentation left DevSecOps teams balancing compliance with complexity—manually managing infrastructure that, in commercial settings, takes minutes.

From Technical Preview to Full Operational Capability

When RGS first announced IC Cloud Support as a technical preview in March 2025, it was clear the capability filled a critical operational gap. The preview demonstrated that by leveraging a differentiated Rancher Government build, users could provision clusters in classified AWS regions by simply toggling the new “Carbide Instance Credential” option—removing the need for manually managed keys and secrets.

Since then, RGS engineers have expanded the feature set and hardened the integration for General Availability. The result: full RKE2 and EKS provisioning, native classified API endpoint compatibility, and seamless Day-2 lifecycle management—all inside the familiar Rancher Manager interface.

How It Works: Secure Automation Without Keys or Custom Code

At the core of IC Cloud Support is a Kubernetes-native approach that replaces manual access management with secure automation.

When IC Cloud Support is enabled, Rancher Manager uses the EC2 instance’s own IAM role (rather than user-managed credentials) to authorize access. This is powered by the Carbide Instance Credential, a hardened mechanism unique to RGS that uses instance metadata services to assume cloud permissions automatically.

This eliminates the need for:

  • Handwritten SDKs or API scripts
  • Local key storage or secrets rotation
  • Custom certificate handling for classified domains

 

The outcome: a keyless, zero-trust-aligned provisioning workflow that meets the stringent security expectations of intelligence and defense networks.

Full Parity for Classified Cloud Operations

The General Availability release introduces a complete suite of enhancements designed for mission-critical continuity:

  • Native provisioning for RKE2 and EKS clusters in classified AWS regions
  • Instance-level authorization via Carbide Instance Credential
  • Compatibility with classified API endpoints and certificates
  • Expanded Day-2 operations including node scaling, certificate rotation, snapshot/restore, and encryption key rotation
  • UI and UX parity across AWS Commercial, GovCloud, and classified regions

 

Together, these improvements eliminate operational gaps between environments, giving intelligence agencies feature parity and user experience consistency across classification levels.

Why It Matters for the Intelligence Community

For operators inside the Intelligence Community, the implications are significant.
Classified cloud environments support some of the nation’s most sensitive workloads—mission systems that demand both speed and assurance. IC Cloud Support means these systems can now be provisioned, scaled, and secured with the same simplicity and confidence found in commercial deployments.

Benefits include:

  • Faster mission delivery: Full provisioning in minutes, not days
  • Reduced human error: Eliminates manual configuration and scripting
  • Operational continuity: Consistent Rancher UI across all classification levels
  • Accelerated ATO cycles: Built-in compliance and evidence generation
  • Improved security posture: No external keys or unmanaged secrets

 

This advancement directly supports the Intelligence Community’s goals of agile modernization, zero trust implementation, and mission-ready cloud operations.

Availability and Next Steps

IC Cloud Support is now available to all RGS customers through the Carbide Portal and Registry. After downloading the latest Rancher Government build for Rancher Manager, users can deploy directly in classified regions by toggling the Carbide Instance Credential option during cluster provisioning.

For more information or to schedule a technical consultation, contact info@ranchergovernment.com or visit us at ranchergovernment.com.

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

The post Speed. Security. Simplicity. Rancher Government Transforms Kubernetes Operations in Classified Environments appeared first on Intelligence Community News.

]]>
43158
Understanding Data Security Posture Management: Five Questions to Get You on Your Way https://intelligencecommunitynews.com/ic-insiders-understanding-data-security-posture-management/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-understanding-data-security-posture-management Mon, 03 Nov 2025 15:08:16 +0000 https://intelligencecommunitynews.com/?p=43089 From IC Insider Thales Trusted Cyber Technologies By: Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies Data Security Posture Management...

The post Understanding Data Security Posture Management: Five Questions to Get You on Your Way appeared first on Intelligence Community News.

]]>
From IC Insider Thales Trusted Cyber Technologies

By: Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies

Data Security Posture Management (DSPM) is emerging as a better way to get visibility into where your sensitive data is located, who has access to it, how it has been used and how stored data and applications are secured. It’s a shift from perimeter-based defenses to data-centric approaches, and it’s important to understand because, in today’s hybrid multi-cloud environments, and with quantum computing just around the corner, dynamically managing data security postures is essential.

In the article that follows, we’ll take a deeper dive into what DSPM is, and what you need to know to implement this strategy effectively.

DPSM and today’s security challenges

In general, DPSM refers to tools and practices organizations can use to protect sensitive data across their infrastructure. These tools identify vulnerabilities, generate alerts, and provide remediation guidance to address data security risks. When integrated into other security systems, DSPM helps organizations maintain a strong data security posture and meet regulatory requirements.

There are several challenges and risks that have emerged in recent years that make DPSM strategies essential for any organization:

Poor visibility into data security across the information lifecycle. Accurately identifying and classifying data is harder than ever as data now spreads across clouds, data lakes, and on-premises systems. Understanding the location and interaction of structured and unstructured data is, of course, essential. But today, data can be easily moved and shared. When users share data without proper security measures in place, that sensitive information may end up in unknown or external locations, which makes it more vulnerable to data exfiltration attacks.

Credential sprawl. Cloud computing has led to organizations storing sensitive data online. Because of the adoption of cloud services, containers, and DevOps; keys and secrets are now scattered across platforms, repositories, and codebases. This in turn increases the attack surface, and exposes your data to problems arising from mismanaged credentials. In fact, according to the 2024 Verizon Data Breach Investigation Report, 80% of data breaches involved stolen credentials. Securing sensitive credentials and preventing unauthorized access are one direct benefit of implementing a DSPM strategy.

The AI threat to credential security. In a report from Sapios research and Deep Instinct, a significant uptick in attacks over the past year was traced back by survey respondents to bad actors using generative AI. With AI, attacks like phishing are more convincing, scalable, and harder to detect, which increases the risk of credentials being compromised. Multi-factor authentication is not enough to counter this threat; it must be supplemented with behavioral monitoring, such as tracking unusual access times, login locations, and unexpected data downloads. An effective DSPM strategy can help safeguard organizational data across all environments.

Post-Quantum Cryptography risk. As many news reports indicate, it’s only a matter of a decade or less before quantum computing breaks asymmetric algorithms like RSA and ECC, exposing sensitive data. The damage this could cause may not be apparent for years. The 2025 Thales Data Threat Report shows “Harvest now, decrypt later” attacks are the leading interest in post-quantum computing. Cybercriminals are collecting encrypted data today to decrypt when a Cryptographically Relevant Quantum Computer (CRQC) exists. Organizations’ need to prepare now by adopting the National Institute of Standards and Technology (NIST) FIPS post-quantum cryptography standard  algorithms (ML-KEM, ML-DSA and SLH-DSA) and embracing crypto agility.

Difficulty detecting insider threats. Insider threats, including leaks and sabotage, are becoming increasingly sophisticated and challenging to detect. Traditional perimeter security is insufficient to prevent breaches. What’s really required is effective risk management through robust monitoring.

The growing importance of data governance. Global data protection regulations impose severe penalties for non-compliance. US Federal Government guidelines for achieving Zero Trust maturity models by 2026 contain requirements for data governance. This makes it more important than ever to recognize behavioral changes and identify threats before they compromise sensitive data. DSPM as a security strategy can help address emerging vulnerabilities and attack vectors.

To implement a comprehensive and successful DSPM strategy, you will need to have answers to these five questions. Let’s look at each one.

DPSM Question One: Where is my sensitive data?

Many organizations don’t fully understand where their sensitive data is. In the 2025 Thales Data Threat Report, 24% of respondents indicated that they had little or no confidence in identifying where their data is stored. This creates security risks that can create opportunities for attackers – often through hidden vulnerabilities or misconfigured databases you may not even know exist.

To secure sensitive data, you have to know its specific location. That applies to both structured data (from databases and spreadsheets, for example) and unstructured data (like emails, documents, and multimedia files).

Unfortunately, data types are often spread across various storage environments, including on-premises servers and multiple cloud platforms (like AWS, Azure, or Google Cloud). What’s more, data within an organization is often moved, processed, and accessed by various applications and users. This dispersal of sensitive data across locations complicates comprehensive tracking and management without advanced monitoring tools.

Data protection regulations (GDPR,  HIPAA, Zero Trust etc.) require detailed knowledge of where specific types of data are stored. Consequently, it is critical to leverage data discovery and classification to automatically discover all data stores in your data estate – from structured to unstructured – across on-premises, cloud, multi-cloud, and hybrid environments.

Automated discovery and classification is the only way to routinely and consistently discover and classify new or modified data stores.

DPSM Question Two: Who has access to my sensitive data?

Controlling and monitoring who has access to sensitive data is essential for preventing unauthorized use and potential data breaches. Many organizations, however, lack the comprehensive tools required for full visibility and oversight of data access. Without a way to aggregate and analyze access to data across various systems and platforms, it’s hard to know who has access to sensitive information.

Many modern enterprises employ complex and layered access structures, including role-based access control (RBAC), attribute-based access control (ABAC), and other models. These intricate systems make it difficult to understand exactly who has access to what data and under which conditions.

Additionally, in large organizations, different departments or divisions often manage their own IT resources independently. This can lead to inconsistent access controls and policies. Decentralization makes it harder to track data access throughout the organization.

Scanning your data store locations for granted user rights and displaying various details regarding user rights is critical to understanding your data posture by mapping users and privileges to database objects across all databases.

DPSM Question Three: How well are credentials protected?

It’s important to have safeguards over metadata and credentials – such as encryption keys and secrets – that can unlock encrypted data to make it readable and usable. This includes using cryptography that supports protecting data today and tomorrow, because cryptographically relevant quantum computers will only accelerate malicious decryption techniques.

The problem in protecting credentials is that many organizations rely on multiple cloud providers to house data, so that key creation, management, and rotation processes may vary across CSPs. With an ever-increasing number of encryption solutions, it’s difficult to manage policies protection levels – to say nothing of escalating costs.

The best way through this maze is to transition into a centralized encryption key management system. Centralizing keys and secrets management for key life-cycle  generation, storage, rotation, backup, recovery, revocation, and termination effectively delivers separation of duties. This ensures that the same person creating and managing the keys cannot access protected data.

Limiting access to sensitive data to only those who need it for their work can reduce the risk of insider threats and external attacks. And monitoring who has access to data can help in auditing and tracking usage patterns, which can be vital for security and operational efficiency.

DSPM Question Four: How has my sensitive data been used?

Tracking how data is accessed and used over time is vital for security and compliance. This includes understanding the context of data access and modifications, and detecting unusual patterns that could indicate a security threat.

Effective data usage tracking requires advanced monitoring and logging tools that provide detailed and accurate records of all data interactions. Many enterprises lack these tools or do not have them fully integrated across all systems. This can lead to gaps in data usage visibility.

Complicating matters is that enterprises employ on-premises systems, multiple cloud platforms, and a variety of end-user devices. Each of these environments can process and store data differently, which makes it challenging to track exactly how data is accessed and used across the entire organization.

Understanding specifically how data is used makes it easier to detect anomalies, because unusual access patterns or unexpected data modifications can be early indicators of a data breach. Then, by optimizing data access controls, organizations can better match actual business needs and security requirements.

With the digital economy driving exponential data growth, organizations must have data-centric compliance and security solutions to reduce risks of non-compliance and breaches. That includes comprehensive logs of data usage, which are not only crucial for audits, but can be invaluable during forensic investigations after a security incident.

DSPM Question Five: What is the security posture of our data stores?

Assessing the security posture of data stores involves evaluating the effectiveness of implemented security measures, identifying vulnerabilities, and understanding the impact of potential threats. This knowledge can help strengthen defenses, enabling proactive improvements to data security and aiding in the prevention of breaches.

Therefore, it’s important to manage security resources effectively. By knowing where security is weakest, organizations can allocate resources more effectively to where they are most needed.

Regular assessments of your security posture ensure that defenses keep up with evolving threats and changing business practices.

Effective posture management requires the latest regularly updated vulnerability definitions, leveraged through scans to assess resources, search for vulnerabilities and determine risk. By scanning databases with predefined vulnerability tests, organizations can be aware of databases susceptible to the latest threats.

These scans, using CVSS, assign a risk score to the vulnerabilities discovered in your network and data. CVSS is “an open framework for communicating the characteristics and impact of IT vulnerabilities.” It is maintained by NIST as part of the Security Content Automation Protocol (SCAP) framework. Scoring vulnerabilities using CVSS provides an accurate model for measuring the risk inherent in discovered vulnerabilities and prioritizing them for mitigation.

Beyond scanning, it’s also important to employ monitoring across the data management lifecycle. Monitoring delivers real-time information, such as system events, alerts, violations, blocked sources and more. Monitoring events, alerts, and violations is a multi-faceted pursuit. Depending on your specific implementation, there may be several types of users with varying roles and associated security policies. You will need to fine-tune for yourselves how events are interpreted to determine if an alert is a false positive, an attack, or something else.

These are the important things to know about DSPM, and the state of your data, to establish a strategy that will gain you greater visibility into where your sensitive data is located, who has access to it, how it has been used and how stored data and applications are secured.

Quantum computing is becoming more of a reality every day, and multi-cloud environments are only complicating matters further still, so perimeter-based defenses are no longer enough. Dynamically managing your data security postures – ideally from a single platform – is essential to keeping data secure today and into the foreseeable future.

Keeping Your Data Safe with a Single Platform for DPSM

Across all businesses, public sector and private industry, data is an organization’s most valuable resource, driving economies of scale. As more businesses and even federal agencies are adopting AI, more data than ever before will be generated, leading to more data depositories, more data blind spots and more potential to leave data exposed and vulnerable to bad actors.

To protect this data, every security professional knows that they need an effective way to identify sensitive data and to keep it secure for their organization’s own sake and for compliance with local and international cybersecurity guidelines.

This can lead to a complicated and scattershot collection of solutions and tools. There are, however, some vendors that can support your Data Security Posture Management (DPSM) efforts with a single platform to help you understand the state of your data.

To take one example, CipherTrust DSPM automates the discovery and classification of both structured and unstructured data. This platform is applicable across a wide range of data stores, including on-premises, cloud, multicloud, and hybrid-cloud environments.

If you are ready to look for an all-in-one data platform for DPSM, here are the feature and benefits you need to look for from a solution vendor:

Scanning and Identifying Data: Make sure your DSPM platform can systematically scan data environments—whether on-premises or in the cloud—to discover data repositories. This must include databases, big data platforms, cloud storage, and file systems.

Classifying Data: After data repositories are discovered, a DSPM platform must be able to classify data based on its type and sensitivity. This automated classification helps organizations to understand the data they hold, and to prioritize their security accordingly.

Understand User Access: To identify excessive, inappropriate, or unused privileges, an effective DSPM platform must provide user rights management, monitoring data access, and activities of privileged users. It must also give security and IT teams full visibility into how data is accessed, used, and moved around the organization.

A comprehensive data protection strategy is crucial for DSPM. That means establishing a solid foundation for data protection through encryption and effective credential management.

Platforms like CipherTrust DSPM identify sensitive data and protect it with industry-leading technologies. The right platform ensures the security of your credentials and metadata, preventing unauthorized access by users and applications, and reinforcing your overall data security and compliance framework.

About Thales TCT

Thales Trusted Cyber Technologies, a business area of Thales Defense & Security, Inc., protects the most vital data from the core to the cloud to the field. We serve as a trusted, U.S. based source for cyber security solutions for the U.S. Federal Government. Our solutions enable agencies to deploy a holistic data protection ecosystem where data and cryptographic keys are secured and managed, and access and distribution are controlled.

For more information, visit www.thalestct.com

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

The post Understanding Data Security Posture Management: Five Questions to Get You on Your Way appeared first on Intelligence Community News.

]]>
43089