Award-winning broadcaster Francis Rose joins Scoop News Group as VP of Multimedia Solutions
Washington, D.C., August 11, 2021 — Scoop News Group, the leading tech media company serving C-Suite decision-makers in the Government IT community, announced today that it has hired award-winning news broadcaster Francis Rose as Vice President of Multimedia Solutions.
Joining SNG, Rose brings 20 years of experience covering the top storylines in all three branches of the U.S. government as well as the military. He will play a key role in supporting the company’s multimedia offerings and building upon Scoop News Group’s robust network of digital content across all of its brands.
“I am thrilled to welcome Francis to our team during this tremendous time of growth,” said Goldy Kamali, CEO of Scoop News Group. “As we continue to expand our multimedia offerings and unveil exciting new developments, Francis is the obvious choice. His passion for community, which is at the heart of everything we do as a company, as well as his leadership amongst federal decision-makers for over 15 years on television and radio, made this a perfect fit.”
Rose brings an extensive background covering the management and business of the federal government, most recently as the host of ABC 7’s Government Matters daily television program. With Scoop News Group, he will continue his work chronicling the federal community on-camera and behind the mic, producing an online video series and daily podcast, among other things.
“I’m excited to join the team of experienced, respected pros at Scoop News Group,” said Francis Rose. “I share the company’s commitment to building community among the people who drive the business of the federal government. I hope my experience and background in creating compelling audio and video content for those people complements and enhances Scoop News Group’s world-class reporting and events.”
About Scoop News Group
Scoop News Group is the leading gov tech media company in the country and is comprised of five digital news brands — CyberScoop, FedScoop, StateScoop, EdScoop and WorkScoop — that reach the top mission and IT decision-makers in government.
Built on a foundation of award-winning journalism and the most prestigious executive events in the government IT community, we engage top C-level decision-makers and influencers in government every single day through our widely-read digital publications, newsletters, podcasts, videos and world-class events.
Hyten calls on defense industry to deliver more timely solutions
The military’s No. 2 officer, Gen. John Hyten, wants more from the defense industrial base, saying contractors need to deliver more timely capabilities that offer “integrated deterrence.”
In remarks made Wednesday, the vice chairman of the Joint Chiefs of Staff said industry can support new concepts like Joint Warfighting more effectively. The comments come as Hyten prepares to retire from the military in November after four decades in uniform.
“We are not delivering an end game,” he told an audience at the Space and Missile Defense Symposium Wednesday. “We have to do that.”
Hyten called out one specific need to have more sensors and better data analysis on missile defense. It has been an area where the military has experimented with new types of data integration and collection, but Hyten doesn’t appear satisfied.
“I would like to have overhead sensors that a see everything,” he said.
Hyten is not the only high-ranking officer to ask industry to focus on new tech. Adm. Michael Gilday, chief of naval operations, recently told industry to stop lobbying Congress to require the military to buy old platforms he says it doesn’t need.
“Although it’s in industry’s best interest … building the ships that you want to build, lagging on repairs to ships and submarines, lobbying Congress to buy aircraft that we don’t need … it’s not helpful,” Gilday said at the Navy League’s Sea-Air-Space conference. “It really isn’t in a budget-constrained environment.”
Gilday later added what he does want to see form industry, not just what they should not do: “Industry can help pivot to new technologies and new platforms.”
Hyten said in order to get industry up to speed on the new direction the military wants to experiment in, the Joint Requirements Oversight Council (JROC) will be hosting an industry day where leaders will brief contractors on the Joint Warfighting Concept (JWC). The JROC sets requirements for the military’s platforms and weapon systems and has been working on requirements for more data sharing that services will need to implement in their acquisitions.
The JWC has four pillars that all revolve around having weapon systems that can connect and share data with one another in order to converge their capabilities. They include long rang precision fires, Joint All Domain Command and Control (JADC2), contested logistics and information advantage. All four are predicated on the ability to share data and integrate capabilities, like with JADC2 where all sensors would be able to connect and use artificial intelligence to analyze data coming from a battlefield like a military internet-of-things.
Senate passes $1T infrastructure bill
Senate lawmakers have passed a $1 trillion bipartisan infrastructure spending bill, which if enacted, would provide funding a range of new federal cybersecurity funding measures.
Among the proposals included in the draft legislation is a $100 million fund for responding to and recovering from cyberattacks, and $21 million in funding for recruitment at the recently formed Office of the National Cyber Director (NCD).
The legislation now progresses to the House of Representatives, where it will be debated – and potentially amended by – lawmakers.
In its current form, the bill would give the Cybersecurity and Infrastructure Security Agency a new authority to declare a significant cybersecurity incident in coordination with the Department of Homeland Security. Such a declaration would give the DHS secretary access to the $100 million recovery fund. CISA would then have responsibility for managing the federal and non-federal response to such an attack — a measure that is intended to assist in the future response to digital security breaches such as the Colonial Pipeline hack in May.
The proposed $21 million included in the bill text gives NCD the budget to hire new cybersecurity staff, an issue that remains a major concern for federal officials in a tight labor market.
Progress of the infrastructure bill through the Senate was obstructed by disagreement over amendments, including the proposed introduction of new cryptocurrency reporting requirements. Lawmakers Tuesday morning voted 69-30 to approve the bill.
Other amendments that fell away before the bill progressed included a proposal by Senate Appropriations Committee ranking member Richard Shelby, R-Ala., which could have provided $2.5 billion for the rollout of 5G wireless technology at Department of Defense facilities.
Commenting on the passage of the bill, Sen. Gary Peters, D-Mich., said: “These provisions will help strengthen cybersecurity at every level of government, protect sensitive personal information, and strengthen our response to online assaults by providing the federal government and other public and private entities, such as critical infrastructure companies, with the resources to prevent and recover from attacks.”
How the pandemic served as catalyst for advancing zero trust
Zero-trust principles have encompassed cybersecurity discussions in one form or another for much of the past two decades. However, the widening adoption of the cloud, ever more sophisticated cyberattacks, and the rapid shift to employees working from anywhere, have pushed the need for zero trust architecture to top of agency IT priority lists.
At the same time, the pandemic served as a catalyst for accelerating security measures in government, say government sector cybersecurity experts during a recent IT security panel discussion.
“There are three subsets of culture that I’ve seen, thankfully, be changed positively through the pandemic that relate to cybersecurity and zero trust,” says Juliana Vida, chief strategy advisor at Splunk, and a former deputy CIO at the Pentagon.
“One of them is risk acceptance,” she says. She pointed to how the Department of Defense “put almost a million people into a remote work environment… leveraging cloud technology because they had to. They just didn’t have a choice anymore. It was [like] a burning platform — and a motivating factor…to accept certain levels of risk that maybe they wouldn’t have a year and a half ago,” she says. “And I think that’s a positive thing, because there are many other barriers in place that probably are worth reviewing.”
A second change was reflected in ways in which position — and who has priority in government organizations — are often tied to physical buildings, she says. “I think we’ve seen a leveling of the playing field, where all voices [and ideas] are equally important” with virtual meeting platforms. The pandemic helped “bust” certain social paradigms around work, she maintains.
The third change revolves around what Vida referred to as the “Big R” — requirement documentation in the government. “Yes, it’s still important. But I think what we saw in the last year was that the definition of what a requirement is, has changed. You could say that the pandemic is the requirement for having modern technology — for having agile and scalable cloud platforms — because you must modernize,” she argues. “Because if you don’t, you can’t work. To me, that’s the ultimate requirement.”
Many of those same themes hold true for Renata Spinks, acting senior information security officer and chief technology officer for the U.S. Marine Corps, who also shared her perspectives on security, zero trust and the impact of the pandemic during the panel discussion.
“I think the largest takeaway for me has been taking a look at what your risk acceptance model is. And the only way that you can truly make an assessment of where you will accept risk is knowing your landscape, understanding that terrain, and knowing where my enterprise begins and ends,” she says.
Spinks concurred with Vida about shifting social paradigms at work and the expanded notion of requirements in light of the changes agencies went through over the past year. “I’m going to add one more word, which is resilience,” she says. Agencies need to focus not only on evolving risks and requirements, but also on operational resilience to better manage the unexpected.
“I think the thought process of remote work and distributed workforce — meaning you’re working from multiple locations… because you need to — that’s why zero trust is so important in understanding those behaviors and making sure that you… have just what you need from a technology perspective,” she says.
“Now, with the emphasis on remote work and remote learning and telehealth, there’s just more of a general understanding across all sectors of American society that we need to pay attention to this. So that’s a good thing. I just hope that the momentum carries forward. It’s time to modernize and really lean into this zero-trust architecture,” she says.
“One of the biggest lessons that we’ve seen,” adds Vida, “and that I hear customers constantly talk about, is the power of cloud technology. Agencies that had already moved into the cloud — or had elements of any kind of hybrid cloud architecture — were able to pivot faster than those who didn’t. That’s because cloud provides the agility, the scale and the flexibility that is absolutely necessary to drive into a digital environment. And the cloud has the ability to manage, share, and manipulate huge volumes of data.”
Vida, like many IT advisors, cautioned against a “lift and shift” approach and instead, focusing on moving workloads in ways that capitalize on cloud-based applications and services. She also recommended that agencies continue to look at cloud platforms to break down silos, share information. “Because that’s where the power of data is — in leveraging everything that exists in an enterprise. I think we’re going to see a continuation of that because it drives efficiencies, drives economies of scale, and it just builds better partnerships,” she says.
Spinks reinforced that point by stressing the importance of establishing “the conditions for not only adopting cloud but employing cloud in your environment.”
“The Marine Corps migrated to an Office 365 environment what looked like very quickly,” she says, “but what we don’t talk a lot about is our infrastructure challenges that we had to overcome. And we spent countless hours with sometimes-planned outages and sometimes not. I would submit, even outside of the DoD — having come from Treasury and Department of Homeland Security — infrastructure across the world is just a place we’re going to have to really invest in.”
View the full on-demand discussion with Renata Spinks and Juliana Vida. And learn more about how Splunk is helping government secure their IT environments and strengthen their zero-trust architecture.
GAO denies Salient’s protest of US Patent Office’s $2B IT contracts
The Government Accountability Office denied Salient CRGT’s protest of five contracts worth $2 billion awarded by the U.S. Patent and Trademark Office for IT modernization, in a legal decision released Monday.
Salient contended USPTO‘s analysis of proposals didn’t align with the Business-Oriented Software Solutions (BOSS) solicitation’s evaluation scheme, which based awards on the highest technically rated proposals with “fair and reasonable” prices.
GAO found USPTO’s comparative analysis and awards to Booz Allen Hamilton, Halvik Corporation, RIVA Solutions, Science Applications International Corporation (SAIC), and Steampunk Inc. were “reasonable, adequately documented and consistent” with the solicitation.
“Salient does not identify, and our review of the record does not find, any distinguishing aspect of either Salient’s or Booz Allen’s proposal that the agency failed to consider,” reads GAO’s decision made July 21. “We deny this ground of protest.”
BOSS primarily sought agile development teams for modernization and maintenance of USPTO IT, and five 10-year, indefinite-delivery, indefinite quantity contracts were awarded — three to small businesses. After technical rating and pricing, criteria were ranked as follows: small business participation, technical approach, past performance, and program management and staffing approach.
After selecting three small business proposals, USPTO found SAIC’s higher technically rated than Salient’s and selected them along with Booz Allen as the highest technically rated non-small business proposals.
Salient protested USPTO’s analysis on the grounds the agency weighted past performance and program management and staffing approach — areas where the large businesses received “superior” ratings to Salient’s “satisfactory” ones — more heavily. SAIC’s overall rating was inflated as a result, Salient argued.
“The agency contends that it properly found SAIC’s proposal to be higher technically rated than Salient’s because the relative benefits identified in SAIC’s proposal under the most important factor, small business participation, as well as under the past performance factor, and the program management and staffing approach factor, outweighed the relative benefits identified in Salient’s technical approach,” reads the decision.
USPTO evaluated the small business participation and subcontracting plans of large business offerers Booz Allen and SAIC. SAIC proposed 36% of contract work would be done by small businesses, compared to Salient’s 27%, leading GAO to side with USPTO’s decision.
Salient also protested the award to Booz Allen on the grounds the company’s proposal was unreasonably found higher technically rated that SAIC’s, during a comparative analysis of just those two proposals.
Booz Allen proposed the worst small business participation of the three companies, which Salient felt meant they’d win out in a comparative analysis between the two. But GAO agreed the advantages of Booz Allen’s technical approach outweighed participation shortcomings.
Booz Allen, SAIC and Salient did not respond to a request for comment.
DOD considering marketplace for smaller cloud vendors as follow-on to JEDI replacement
The Department of Defense will look at setting up a marketplace for smaller cloud vendors as a “follow-on” contract to the eventual Joint Warfighter Cloud Capability (JWCC) acquisition.
Research about the potential launch of such a marketplace will take place after JWCC has been awarded, and is not expected to begin until April 2023.
Details of the JWCC were made public last month, after the DOD announced it was canceling the JEDI contract, following a nearly-two year acrimonious bid dispute of the contract’s initial award to Microsoft.
Danielle Metz, deputy CIO for information enterprise at the DOD, revealed details of the future program earlier this week to a virtual audience at a Potomac Officers Club conference.
“It will not be exclusive to the five U.S.-based hyperscale cloud service providers, but it will be available to anyone, any integrator or cloud service provider, that can meet the department’s requirements,” Metz said.
JWCC, on the other hand, will only be open to the largest “hyperscale” cloud providers, like Amazon Web Services and Microsoft, whose cloud systems are capable of offering secret and top-secret cloud environments
The goal of opening up to more service providers is to be able to provide services that fit across the department’s many mission areas. The idea of a marketplace was teased by acting CIO John Sherman when the JWCC was first announced.
Metz added that she expects by the time market research begins, the DOD will be much more “cloud fluent” and industry will have new technical innovations to offer.
Correction: Aug 11, 2021. This article was updated to clarify that the proposed marketplace will be a separate follow-on contract, rather than a part of the JWCC procurement itself.
Senators propose AI training for federal acquisition workforce
A bipartisan duo of senators introduced a bill that would increase the federal acquisition workforce’s understanding of artificial intelligence by creating a training program for them on the risks and benefits of the technology.
The AI Training for the Acquisition Workforce Act would give the Office of Management and Budget and General Services Administration a year to stand up the program if passed.
Sens. Gary Peters, D-Mich., and Rob Portman, R-Ohio, proposed the legislation, part of a broader push by lawmakers to ensure the U.S. leads foreign competitors like China in the emerging sector while doing so ethically.
“We need a federal acquisition workforce that understands AI, how it works, how it can help the government run better, and the ways we can fix the problems with AI systems so those procurement professionals can know they are buying the right AI systems for the government,” Portman said in the announcement.
The training program would cover AI science, system features, risks like discrimination and privacy violations, and risk mitigations. Contracting officers would be taught how to procure trustworthy AI and the latest national security trends pertaining to the technology.
OMB would be expected to update the program once every two years with new information.
The bill lays out an interactive program taught by technologists and other public- and private-sector experts and would require OMB to track workforce participation.
Code for America management say they are open to union recognition talks
Senior leaders at civic technology nonprofit Code for America have indicated they are open to talks over potential union recognition.
Sources speaking to FedScoop said management responded to a request for dialogue sent by organizers late Friday, which could pave the way for voluntary recognition of the representative group.
In a statement to this publication, a spokesperson said that Code for America is working with staff and organizers from the Office and Professional Employees International Union to understand the process.
“We are continuing to learn more about their efforts and look forward to building upon continued inclusive efforts to ensure that Code for America is a great place to work,” said the statement. “We are also committed to ensuring that our actions are consistent with our legal obligations under the National Labor Relations Act, and that we also respect the rights of all of our employees under the law.”
The California nonprofit was founded in 2009 and works with the federal government and state agencies to improve the design of civic technology. It is currently working on federal government tech projects relating to safety net benefits and earned income tax credits.
Under U.S. labor law, an employer can choose to recognize a union voluntarily, or can insist on a secret-ballot election held by the National Labor Relations Board.
Code for America employees last week revealed plans to unionize with the Office and Professional Employees International Union (OPEIU) Local 1010. So far, 62 people at the organization have signed union authorization cards, which is understood to represent about 77% of its workforce.
One source speaking to this publication described the reception of demands from management as “prompt and optimistic.”
Among the concerns of Code for America staff seeking to unionize are recent plans to adjust the salary of new employees who work remotely away from the organization’s California headquarters. Other concerns include the availability of mental health support and diversity, equity and inclusion measures.
Employees inside the federal government and the wider technology sector have received a boost from the prioritization of rights to collective action under the Biden administration.
As part of its budget proposals, the administration in January proposed a pay raise for employees and said it would encourage union activity and collective bargaining.
A spokesperson for Code for America added that prior to the request for union recognition, the organization had raised salaries across the board by about 10% to 20% and that it continually benchmarks benefits it offers against those of other companies and nonprofit organizations.
DIU seeks tech to help fight GPS spoofing
The Defense Innovation Unit is searching for commercial tech that could help the military locate disruptions in satellite-based systems like the Global Positioning System (GPS).
Global navigation satellite system (GNSS) manipulation or “spoofing” has become increasingly low-cost with high-stakes impacts on both defense and commercial interests. DIU wants a solution that uses analytics to search through commercially available data to find spoofed and disrupted signals, it wrote in a recent solicitation.
“The entire world is dependent on GNSS or GNSS-based systems, yet the GPS architecture and its users are vulnerable to denial and manipulation by adversarial actors,” DIU wrote.
Spoofing is an interference to the signal or data transmission in GPS. Devices used to disrupt that signal can be as cheap as $250 and as small as a cellphone.
Threats to satellite-based communications systems like GPS include operations that have enabled narcotics trafficking, unapproved operation of autonomous vehicles, illegal fishing and piracy, according to DIU. Signal jamming by nation-states also poses a threat to military communications in battle. This is of great importance as the Department of Defense has been creating new concepts of operations that more heavily rely on communications and data links.
DIU, the DOD’s Silicon Valley outpost, was established to find commercial solutions to thorny defense challenges such as GPS spoofing. In this specific case, it seeks solutions that can ingest a mix of data, including terrestrial, space-based and others, that could help ferret out false signals. DIU wrote it has no preference on what data the system uses, just that it be able to use multiple types.
Cybersecurity in a shrinking world
On the very first day that former FBI agent Eric O’Neill was assigned to go undercover to investigate the most notorious cyber spy in U.S. history, the target of that investigation looked at O’Neill and said something remarkable.
“So, O’Neill, have you ever heard of something called Hanssen’s law?” the man asked. O’Neill responded that he did not recall studying such a law at the FBI Academy in Quantico.
The man sitting across the table looked back at O’Neill and began to explain Hanssen’s law. “The spy,” he said, “is always in the worst possible place.”
O’Neill could neither believe what he was hearing nor where the conversation was taking place. He was sitting across from Robert Philip Hanssen, one of the most damaging FBI cyber insiders in history, and they were talking as colleagues in the information assurance division within FBI headquarters. O’Neill maintained his poker face and asked Hanssen what he meant.
“That spy is that person with the access to information and the wherewithal to use that information to sell it to those who will do the most damage with it. And that Eric,” Hanssen said to O’Neill, “is what we in the FBI as counterintelligence agents, are tasked to do. Find that spy. Hunt them wherever they are.”
Speaking at the 2021 Public Sector Innovation Summit sponsored by VMware, O’Neill — now National Security Strategist at VMware and author of Gray Day: My Undercover Mission to Expose America’s First Cyber Spy — acknowledged that Hanssen’s words were very prescient.
(Watch O’Neill’s full presentation here.)
The FBI’s most sobering discovery had to do with Hanssen’s use of the Bureau’s own IT infrastructure. To their dismay, the FBI found that Hanssen had used his authorized access to the Bureau’s Automated Case Support system and his knowledge of computers to monitor the FBI investigation that was trying to find him.
At the heart of the ACS system, which first came online in 1995, is the Electronic Case File (ECF). The ECF contains all of the Bureau’s internal communications relating to ongoing investigations and programs. Subsequent investigation of Hanssen’s use of the ECF system showed that he routinely searched the system using search terms directly related to the investigation that was aimed at uncovering his identity.
Hanssen compromised thousands of pages of classified documents detailing the most sensitive intelligence collection programs in the U.S. intelligence community. Among the most damaging disclosures concerned the details of a tunnel that had been dug beneath the Soviet embassy in Washington and outfitted with high-tech listening devices that were monitored by the FBI and the National Security Agency.
It was the exchange with Hanssen and the lessons learned from the investigation that would begin the evolution of O’Neill’s own thinking about cybersecurity and insider threats, which he now shares with government agencies and companies on behalf of VMware.
“As I thought about whether the spy is always in the worst possible place, I realized that the spy is always in the worst possible place for anyone who is breached,” O’Neill said.
Cyberspies are changing the world, according to O’Neill. “There are no hackers, there are only spies,” he said. “The true cyberattackers, cyberspies, and cybercriminals are well-resourced, are very knowledgeable and they’re using sophisticated computer equipment…to get at the data that is the currency of our lives. And as the world gets smaller, cyberattacks are simply growing.”
Pandemic 3.0 – Reopening Our World
O’Neill refers to the massive shift in how people work — from pre-pandemic to pandemic-era remote work and now the post-pandemic reopening — as Pandemic 3.0. Cyberspace has become more hostile, said O’Neill. Destructive attacks have increased 118%, he said.
“Cyberattacks have quadrupled during the pandemic and foreign spies have been targeting everything, in particular COVID-19 research in the healthcare sector,” O’Neill said.
These trends pose a significant challenge for the Pandemic 3.0 world, in which we must find a way for employees to work from any place, on any device, and through any cloud. “Zero trust and endpoint [detection] is critical for remote work,” O’Neill said. “Zero trust is the only way to ensure that everyone accessing your data is authorized.”
The pandemic also forced a massive expansion in cloud investments but when you move to a public cloud “you’re moving to a tough neighborhood,” according to O’Neill. “You may be able to secure your own resources, but you have no control over who’s sharing that environment with you. So you have to prioritize security cloud workloads at every point in the security lifecycle,” he said. “That means security that extends across workloads, containers, and Kubernetes.”
Learn more about “Zero Trust” strategies and how VMware is helping to accelerate public sector innovation.