Booz Allen expects number of staff working in office to decline

Booz Allen Hamilton is expecting the number of its staff working full time in its offices and on government premises to fall from previous levels, according to the federal contractor’s CEO.

Speaking on a second-quarter earnings call, Horacio Rozanski praised the creativity of the company’s clients during the COVID-19 pandemic and said many continue to embrace new ways of working.

“[W]e have a group of people who work full time at government and our facilities. And that too will continue, although we expect it to proportionately decline from historical levels,” Rozanski said. “Our clients have shown a great deal of creativity over the course of the pandemic. And based on this experience, many are interested in flexible models that better serve their missions while reducing the number of people who are 100% onsite.”

The comments come as agency staff return to the office and follow an earlier policy advising federal departments to consider embracing a more geographically distributed workforce. The Office of Personnel Management also issued further guidance on that policy July 23 “to assist agencies … as they plan for the safe, increased return of Federal employees to physical workplaces (“reentry”) and the post-reentry work environment.”

Agencies have each set their own strategy for bringing their workforce back to the office with input from the Safer Federal Workforce Task Force.

According to the prior guidance, federal departments were advised to embrace more telework “where possible and appropriate,” and where it could help to benefit equity, inclusion and the delivery of missions.

The geographic location of the federal government jobs was highlighted last month with the Biden administration’s Executive Order on Diversity, Equity, Inclusion and Accessibility, which was intended to examine new ways of getting underserved and minority communities into the workforce.

Responding to questions from analysts on the company’s earnings call, Booz Allen’s executive team said also that the company’s projection for achieving about $200 million in cost savings from its acquisition of Liberty IT, remains unchanged.

In an interview earlier this year with FedScoop, Booz Allen’s head of civil business Kristine Martin Anderson said the consulting company’s “number one” job following the $725 million deal would be to deliver on existing contracts with the Department of Veterans Affairs, but that the transaction will allow the company to deploy Liberty’s resources across other areas of its balance sheet.

Accelerating forensics investigations by leveraging AWS GovCloud

Christine Halvorsen has spent more than 20 years working in various law enforcement, intelligence and IT roles for the Department of Justice and the FBI before joining AWS in 2019. She currently serves as senior technical business development manager on AWS’s Mission Acceleration Team.

The explosive growth of digital forensics information over the past two decades has transformed the way federal law enforcement and regulatory agencies deliver their missions. But it has also put new pressures on many federal agencies to develop more scalable and advanced solutions.

Christine Halvorsen, Sr. Technical Business Development Manager, AWS’s Mission Acceleration Team

When I started out as an FBI agent in 1996, we were still getting used to the forensic tools and principles for collecting, extracting, storing and safeguarding digital evidence. By 2010, the FBI’s Regional Computer Forensic Laboratory reported the average case by sifting through and managing four terabytes of data.

That was modest compared to the FBI’s 2013 Boston Marathon bombing investigation, which collected more than 50 terabytes of information. By the time I was called in as senior investigator in the 2017 Las Vegas Mandalay Bay shooting, the FBI was faced with collecting and analyzing a petabyte of data for that single case.

Were it not for the built-in capabilities of the cloud — to upload and analyze all of that unstructured, circumstantial evidence quickly, and in ways that were both secure and auditable — it would have been impossible to manage a case of that size, involving 13 responding agencies and so many tragic deaths and injuries.

Meeting mission needs at scale

Finding proverbial needles of evidence in today’s massive digital haystacks has never been more challenging. The volume of data from personal computers, smartphones, social media, emails, and e-commerce, as well as surveillance cameras, sensors and countless other devices continues to grow exponentially. By 2025, the amount of data generated each day is expected to reach 463 exabytes globally.

And it’s not just a challenge for law enforcement. There’s a wide range of government agencies, overseeing financial, health, consumer protection and many other sectors, that are similarly responsible for properly handling, analyzing, preserving and storing evidential information from the point of ingest and throughout its lifecycle.

Leveraging the cloud can help agencies scale IT resources up and down, as well as save IT costs. But perhaps more importantly in government, the cloud offers agencies on-demand compute power and modern applications to process workloads at a pace that agencies require to meet their missions.

The cloud can help address four recurring challenges we hear from our customers, particular those whose missions depend on managing digital evidence:

  • Reducing the processing backlog — When it comes to managing digital evidence, there are five critical stages that must be handled properly: collection, extraction, storage and chain of custody, analysis, and dissemination. As digital case workloads grow larger and more complex, fixed IT resources make it harder to complete the front-end tasks. That cascades into costly delays in completing analytic work. At AWS, we’ve been helping customers use the scale of the cloud to provide a dynamic and cost-effective way to accelerate workloads in those first three stages — helping in turn to analyze and disseminate evidence faster.
  • Optimizing familiar forensics tools to work in the cloud – Customers tell us they want the ability to use the secured forensic tools they are familiar with on-premises turbo-charge them using the cloud’s high-performance compute environment. Together with our partners, we’re helping them make that transition while reducing their software licensing costs. Instead of agencies, for instance, having 10 licenses sitting on one workstation, which limits how many people can process evidence, AWS and its partners are developing new licensing models in the cloud to support the customer’s needs and application of the tools, allowing more examiners and analysts to work simultaneously with agility and speed, given the cloud’s processing power.
  • Automating digital extraction and analytics processes – Our customers also tell us that many of their processes are still manual, cumbersome and repetitive. We’ve been able to automate significant portions of that work. For instance, examiners using AWS’s GovCloud can extract digital evidence from bundles of data and then immediately apply analytics. That helps narrow their searches for needles in the digital haystacks and quickly gain insights from what’s in the data.
  • Managing evidence storage more effectively – The unique statutory requirements for storing evidence — in some cases for 25 years — presents a special challenge for agencies. It’s no longer practical or economical to keep buying more and more storage infrastructure. With AWS infrastructure, agencies can choose a range of storage models, including our deep archive option, which allows agencies to store data for pennies on the dollar compared to on-prem storage. AWS also makes it easier to automate the movement of evidential data from one stage to the next and into final storage after cases are closed, freeing up forensic examiners and analysts to concentrate on delivering their missions.

AWS has been working with multiple federal agencies from federal law enforcement to federal financial institutions to establish working models that address all four of these challenges. These models have reduced the time to process digital evidence from weeks to minutes. The cloud’s elasticity has spurred innovative approaches to analyzing forensic data and given investigators greater analytical, entity extraction, and translation capabilities. But most of all, the cloud is giving agencies the ability to manage their digital evidence workloads at a pace that’s more commensurate with their needs of their missions.

Learn more how AWS is helping federal agencies manage their escalating digital workloads.

Anduril appoints Goldfein, MacFarland to advisory board

Defense technology firm Anduril has appointed a handful of top former defense officials to its advisory board.

The company named five new advisors including Katharina McFarland, former assistant secretary of defense for acquisition, retired U.S. Air Force Chief of Staff Gen. David Goldfein and former U.S. Navy officer Adm. Scott Swift, who was commander of the U.S. Pacific Fleet.

Goldfein was the 21st Chief of staff of the U.S. Air Force, in which role he was responsible for organizing, training and equipping the service.

Pangiam CEO Kevin McAleenan, who served as acting secretary of the Department of Homeland Security during the Trump administration, and Constantine Saab, the chief technology officer at Valor Equity Partners and a longtime CIA executive, also join its advisory committee.

Commenting on the five new appointments, Anduril CEO Brian Schimpf, said: “We are honored to be joined by an esteemed group of experts who will provide strategic counsel as we grow the company and scale Anduril’s software and hardware products across the DOD.”

“The board brings a wealth of knowledge and perspective on the inner workings of the government agencies responsible for our nation’s safety and security. They will help guide our work to rapidly modernize U.S. defense capabilities,” he added.

Earlier this month, Anduril won a $99 million contract to provide the Department of Defense with a new automated counter-unmanned aerial system (C-UAS) capability. The Production Other Transaction (P-OT) Agreement was struck between the company and the Defense Innovation Unit,

DOJ reveals 27 U.S. Attorneys offices had emails compromised in SolarWinds hack

A total of 27 U.S. Attorneys offices had one or more employees’ Microsoft 365 email accounts compromised, when Russian hackers used the SolarWinds Orion updating system to push malware to agencies, the Department of Justice revealed Friday.

DOJ believes the advanced persistent threat group, APT29 or Cozy Bear, had access to the accounts from May 7 to Dec. 27, 2020 and all sent, received and stored emails and attachments within.

The department first acknowledged the intrusion on January 6 but made its latest announcement to promote cybersecurity information sharing among agencies.

“The Department of Justice understands that when victims make information public about the nature and scope of computer intrusions they suffered, others can use that information to prepare themselves for the next threat,” the update read. “To encourage transparency and strengthen homeland resilience, today we are providing additional details about the SolarWinds intrusion in December 2020.”

At least 80% of employees in New York’s Eastern, Northern, Southern and Western district offices had their accounts compromised, and all have been notified and instructed on how to identify cyberthreats, the department said.

Among the other districts compromised were two in California, the District of Columbia’s, three in Florida, one in Georgia, one in Kansas, one in Maryland, one in Montana, one in Nevada, one in New Jersey, one in North Carolina, three in Pennsylvania, three in Texas, one in Vermont, two in Virginia, and one in Washington.

Upon discovery, DOJ’s Office of the Chief Information Officer eliminated the hackers’ backdoor into its email environment and notified the Cybersecurity and Infrastructure Security Agency and Congress, but the damage persists.

“The department’s objective continues to be mitigating the operational, security and privacy risks caused by the incident,” reads the update.

Senate committee calls for FISMA to be revamped

The Senate Committee on Homeland Security and Governmental Affairs has identified continued major cybersecurity failings across agencies and is calling for the Federal Information Security Modernization Act (FISMA) to be reformed.

A new report published Tuesday identifies IT security flaws across almost every major U.S. government department, including the failure to secure citizens’ personal and financial data and the inability to keep track of thousands of items of IT equipment.

According to the committee, lawmakers should update FISMA to require federal agencies and contractors to notify the Cybersecurity and Infrastructure Security Agency (CISA) of certain cyber incidents and to amend the definition of “major event” to ensure Congress is notified of breaches quickly.

FISMA was enacted in 2014 to create a requirement that each federal agency develop, document and implement a complete information security plan. It has come under scrutiny following recent hacks, including the SolarWinds attack in late 2020, during which multiple government departments were compromised.

The report recommends also that CISA expand shared offerings to all federal agencies, including enhanced endpoint detection.

Core government departments, including the Social Security Administration, are failing to handle data securely, according to the report.

An audit by the Department of Transportation’s Inspector General found 14,935 IT assets belonging to the department of which it had no record. This included 7,231 mobile devices, 4,824 servers, and 2,880 workstations that were unaccounted for.

The Senate committee’s review highlighted also that many agencies continue to run copies of software on their computer systems that are no longer supported by technology vendors and also flagged the failure of agencies to obtain the required authorities to operate for all of their technology business systems.

The committee’s findings are based on its own analysis, as well as work carried out by the inspectors general of federal agencies during fiscal 2020.

It followed up on an earlier report, issued in 2019, that identified the failure of eight key government agencies to comply with federal cybersecurity standards. According to the latest iteration of the study, seven agencies have made only minimal progress in improving their compliance with the regime, and only one – the Department of Homeland Security – was judged to have employed satisfactory cybersecurity standards during 2020.

Top Navy officer says Project Overmatch work ‘headed in the right direction’

The Navy’s work to execute its portion of the Joint All Domain Command and Control (JADC2) strategy has a way to go, but the service is “headed in the right direction,” according to Adm. Mike Gilday.

Speaking Monday at the Sea-Air-Space conference, the Navy’s most senior officer said the service is in the third cycle of testing new technology this year as part of the program, but that challenges remain.

“We’re very excited about where it’s headed. We’re not satisfied with where we are. We have a way to go before we get to the point where we roll out strike group-wide in 2023,” Gilday said.

The Navy’s section of the JADC2 strategy is known as Project Overmatch, and its goal is to connect data multiple domains of warfare.  The senior officer added that he hopes that within a decade ships will have the connectivity to send all of their data over any network in a secure manner.

By having the ability to constantly share data, the hope is military command and control can be assisted by artificial intelligence that can generate more options for commanders orchestrating a multi-domain battle. It’s a tall order for a service beset with cybersecurity challenges and legacy systems the service recently started to modernize.

Rear Adm. Douglas Small, who is leading Project Overmatch, also said his office is still working on the foundational architecture and testing new tech. He said he has enough money and enough cloud computing to work through the technical challenges, but finding ways to actually share data have yet to be discovered.

Small said one of the most challenging aspects of the programs is transferring data across domains, from the air to sea to other parts of warfare. That challenge is augmented by the Navy’s geographic posture, having its ships being disconnected through miles of oceans. 

The CNO said Overmatch and the JADC2 framework it follows is a priority for the service. It’s also a priority for other services and the department as a whole, that recently signed a JADC2 strategy. But so far, few enterprise capabilities have materialized beyond some battle management applications on ships.

VA awards Peraton $497M IT infrastructure contract

The Department of Veterans Affairs has awarded Peraton an IT infrastructure contract that could be worth up to $497 million over seven years.

The Virginia-headquartered company will provide infrastructure-as-a-managed service for storage and computing infrastructure facilities across the U.S. and globally.

According to the company, it will deliver an enterprise-scale solution that integrates on-premise infrastructure with the VA’s enterprise cloud architecture.

Under terms of the contract, Peraton will be tasked with supporting up to 220+ petabytes of data, ranging from business operations data to the medical images used in veteran care. It will undertake the contract work at up to 300 VA sites across the continental U.S. and abroad.

Commenting on the award, George Rollins, vice president of VA and defense health at Peraton, said: “This is an incredible win for the team. We look forward to our continued partnership with the VA, and to helping the Department realize the expected benefits from its major modernization initiatives.”

ThunderCat Technology had protested the award of the contract to Perspecta — which was recently acquired by Peraton — earlier this summer but then withdrew its complaint.

Senate infrastructure bill includes $20M for cyber response and recovery

The $1 trillion infrastructure bill would put $20 million in the Cyber Response and Recovery Fund in fiscal 2022 and every year thereafter through fiscal 2027, a bipartisan group of senators revealed Sunday.

The fund supports the Cybersecurity and Infrastructure Security Agency‘s response efforts after the Homeland Security secretary, in consultation with the national cyber director, declares a significant cyber incident at the federal, state, local or tribal level.

Senators want to bolster the fund after significant cyber incidents like the compromise of the SolarWinds Orion software supply chain, which saw multiple federal agencies breached.

CISA can spend the funds on vulnerability assessments, technical incident mitigation, malware analysis, analytic support, threat detection and hunting, and network protections. Funds may also be used for grants or cooperative agreements that update or replace hardware and software or else to contract IT or cyber personnel.

Agencies may be required to reimburse the funds and must report on their use. Meanwhile, CISA must notify the national cyber director of the duration of the significant cyber incident and the reason for and coordination of any allotted funds. The Homeland Security secretary then has 180 to report how the funds were used and their effectiveness mitigating the incident.

The Senate bill would provide CISA an additional $35 million for risk management and stakeholder engagement operations and support, and the new national cyber director office would receive its first $21 million for salaries and expenses until fiscal 2022 appropriations are made.

The Department of Homeland Security Science and Technology Directorate would receive $157.5 million for non-cyber and cyber-related research and develop into critical infrastructure security and resilience, security testing of telecommunications equipment, industrial control systems and open-source software.

Job-coding issues may hinder DOD’s cyber workforce recruitment, IG says

Department of Defense components have not accurately coded jobs for their civilian cybersecurity personnel, limiting the ability to recruit and retain the targeted cybersecurity positions they most need, according to an inspector general report.

While the DOD has followed mandates to issue guidance on coding civilian cybersecurity jobs per the 2015 Federal Cybersecurity Workforce Assessment Act, the application of those codes at the component level has been inconsistent or inaccurate, the IG found in a recent audit.

“As a result, the DoD may be unable to accurately determine the skill set and size of its civilian cyber workforce,” the watchdog said in a report made public Monday. “Without coding all positions (filled and unfilled), the DoD may develop incorrect workforce planning activities, such as recruitment and retention strategies, and incorrectly report on work roles of critical need.”

The report redacted exactly how many of the DOD’s core and non-core cybersecurity positions had coding issues across the three military departments and gave no specifics on how widespread the issues are with other components in the Fourth Estate.

The IG said quality assurance measures would ensure components comply with the DOD’s cyber workforce coding guidance. Though the Army has an automated quality assurance system in place for coding civilian cybersecurity roles, the Navy and Air Force lack full systems to ensure they are meeting the goals of the Pentagon.

The IG concluded the report by recommending the DOD Office of the CIO require components to code filled and unfilled cybersecurity roles in accordance with federal requirements and conduct a feasibility study on issuing a more thorough quality assurance system for proper coding.

Acting CIO John Sherman agreed with those recommendations, clarifying that DOD has required such coding since May 2020 and that as of June 2021, all components have at least primary work roles coded into their manpower and personnel systems.

On the matter of quality assurance, Sherman said the DOD has already conducted a feasibility study on the issue, leading to the department creating a “cyber workforce common data model” on DOD’s Advana data platform to make sure coding is accurate and complete. Using Advana, Sherman said, it will give the DOD “a dashboard view of appropriately configured systems and the corresponding coded populations of filled and unfilled positions and identify systems that are not yet compliant.”

Within the report, the IG acknowledged the DOD’s greater progress taking action “to meet strategic goals for the recruitment and retention programs of its civilian cyber workforce.” Specifically, the department has ramped up use of its Cybersecurity Scholarship Program and its Cyber Information Technology Exchange Program. It has also started work developing a Cyber Aptitude Test and implementing the Cyber Excepted Service framework and enhancements.

Despite such progress, in April, Lt. Gen. Dennis Crall, CIO of the Joint Staff, told the Senate Armed Services Subcommittee on Personnel that he was “concerned about the pace” at which DOD is hiring and training cyber personnel. “I think the divide between the need is growing compared to what we’re able to fulfill. I’m not sure we’re closing the gap, and time is ticking for us to do so.”

Department of Energy expands CyberForce program

The Department of Energy is expanding its CyberForce program by offering year-round competitions, webinars and career resources designed to prepare collegiate students to fill workforce gaps — especially around industrial control systems (ICS) and operational technology (OT).

Argonne National Laboratory leads the program and added two virtual, solo competitions, comprising a Conquer the Hill series, that allows students to hone cyber skills mapped to the National Institute of Standards and Technology‘s National Initiative for Cybersecurity Education (NICE) Workforce Framework.

Argonne launched a Cyber Defense Competition in 2016 to help address the national cyber talent shortage, predicted to reach 1.8 million workers by 2022, which has evolved into a program benefitting not only companies but government as well.

“The National Labs, Department of Energy and all the other federal agencies are obviously equally looking for talent that is interested,” Amanda Joyce, CyberForce program director, told FedScoop. “Bringing students on-site, or even bringing them in virtually, brings awareness to the national lab system.”

Tech giants like Amazon, Microsoft and Google attract the top cyber talent, but students forget DOE keeps the lights on for those companies — literally — and can give them the hands-on  training in real-world scenarios involving ICS and OT they lack, Joyce said.

Argonne won’t hold the next in-person, team CyberForce Competition until 2022 because of the Covid-19 pandemic, which is why it started the Conquer the Hill series.

The Reign Edition set for September will be a timed, capture-the-flag event with non-traditional  escape room elements that force competitors to think logically.

While the Adventurer Edition, which ran from July 16-18, gave participants 48 hours to complete 160-plus cyber tasks of varying difficulties in a question-and-answer format. University of Central Florida student Cameron Whitehead won.

While Conquer the Hill events try to admit all who register, the CyberForce Competition only allows one team per university to enter. The red-blue, attack-defend competition requires teams to perform daily tasks like examining log files while keeping everything from email to ICS operational, in what is a multi-lab event.

This year the CyberForce program also added a once-a-month webinar series highlighting key cyber topics; a virtual career fair for more than 1,000 students to meet with cyber companies; and is creating a workforce development portal that will report on students’ progress and let them engage with each other and government and industry experts year-round.

The need to have students fill cyber roles defending ICS and OT became more critical after a hacker breached a Florida water treatment plant in February and a ransomware attack on Colonial Pipeline in May, which led the company to shut the pipeline down temporarily and saw people panic-buying gas into scarcity across the Southeast.

“Why we push operational technologies so much is because the technology we’re using is very old,” Joyce said. “”The problem is none of these systems were ever really meant to be on the internet.”

The CyberForce program encourages students to think through the added cyber risks ICS and OT present and consider what constitutes the proper amount of security, how the networks communicate internally and with other networks, and how a hacker might turn them off.

Security isn’t just updates, patches and firewalls when it comes to such systems, Joyce added.

“The problem is that doesn’t work for everything and specifically for our operational technology networks,” she said. “And it takes a unique skillset to really understand that and to figure out that these systems are very sensitive in nature.”