DOE uses firmware machine learning to bolster electric grid cybersecurity

The Department of Energy is integrating machine learning (ML) with a threat information-sharing tool it developed to find cybersecurity adversaries embedded in electric grid control systems.

DOE‘s Grid Modernization Laboratory Consortium (GMLC) consists of the Idaho, Argonne and Sandia national labs and the National Renewable Energy Laboratory — all working together on the Firmware Command and Control (FC2) project.

Firmware is often vulnerable, permanent software present in industrial control systems and operational technology (OT), and INL partnered with software company Forescout to ensure FC2’s cyber data analytics could detect firmware-centric vulnerabilities with ML.

“Embedded systems are black boxes with little insight on what subcomponents make up the code underneath, preventing protection and potentially rendering the system vulnerable,” said Rita Foster, infrastructure advisor at INL, in commentary. “Emerging machine-learning techniques enable the identification of ubiquitous libraries, which may contain known potential vulnerabilities.”

INL further developed the Structured Threat Intelligence Graph (STIG) for sharing of actionable threat information among grid utilities and OT vendors, who are notoriously stingy with such information. Rather than having threat analysts read thousands of lines of code, STIG visualizes relationships between attack patterns, compromise indicators and exploits and presents mitigations.

FC2, and GMLC more broadly, are helping utilities like Southern California Edison and Detroit Energies — which serve as large, expensive testbeds — augment their grid architectures. Meanwhile OT manufacturer partners like Siemens, Rockwell Automation, Eaton, GE, and Hitachi can develop better cyber protections.

“The need for an analysis tool to share security threat information and intelligence has escalated, and existing tools have proven to be inadequate,” Foster said.

A number of big-name OT manufacturers the government employs — Emerson, Honeywell, Mitsubishi Electric, Rockwell Automation, and Schneider Electric — do business with InterNiche, whose stack was revealed to have 14 newly discovered vulnerabilities Wednesday.

Forescout Research Labs and JFrog Security Research disclosed set, dubbed INFRA:HALT, as part of the former’s Project Memoria. The vulnerabilities allow for remote code execution, denial of service, information leaking, transmission control protocol spoofing, and Domain Name System cache poisoning, which could compromise OT and critical infrastructure like the electric grid.

Forescout’s report recommends utilities limit the network exposure of critical vulnerable devices through network segmentation, apply patches once vendors release them, and block or disable support for unused protocols like HTTP.

The 14 vulnerabilities were discovered using cutting-edge automate binary analysis for large-scale vulnerability finding.

“We believe that the cybersecurity community is at a turning point, and soon automated vulnerability discovery techniques will become more common, which should make finding very large-scale vulnerabilities, such as those affecting TCP/IP stacks, faster and more frequent,” reads the report. “All these vulnerabilities, however, will have to be disclosed, mapped to affected devices and mitigated.”

How precise email analysis reduces healthcare ransomware threats

Ryan Witt is an industries solutions and strategy leader at Proofpoint, specializing in healthcare and cybersecurity. He has over 15 years of experience advising healthcare institutions on the value of robust data protection.

The healthcare industry has come under intensified attacks by malicious actors over the last year amid new opportunities to target institutions during the COVID-19 pandemic.

health care

Ryan Witt, Industry Solutions and Strategy Leader, Proofpoint

Among various cyberthreats the healthcare industry faces, ransomware poses particular risks to the patients these institutions are serving. While the goal of ransomware attacks is to extract a payment, the consequences of holding health organizations’ IT systems hostage puts patient safety and critical care at risk.

Earlier this year, for example, one university medical system which offered important oncology services in their region was victim to a ransomware attack that blocked access to its electronic medical record systems (EMRs). That institution was forced to turn away some oncology patients as a result of not being able to reliably access patients’ records; or in other circumstances, they could offer only skeletal services with staff reduced to recreating patient records on pen and paper.

It took the institution roughly a month to essentially reconstitute their medical records and fully eradicate the ransomware from their system at an untold cost in patient safety and lost productivity. This kind of ransomware attack illustrates a large and growing problem occurring throughout the country, where unseen criminals are holding public and private healthcare organizations hostage.

While many organizations have built up an ecosystem of security tools to monitor network activity and firewalls to block malicious traffic, often their greatest security and compliance risk comes from their employees and business associates who inadvertently fall victim to phishing emails or stolen credential dumps.

Cybercriminals have shifted their focus from targeting technical deficiencies to human vulnerabilities: the busy clinician who clicks on an email attachment; the eager patient who fills in credentials to claim a fake offer; an employee who interacts with emails from their suppliers, not realizing it is an imposter account.

Growing threats against the healthcare sector

The Healthcare Information and Management Systems Society (HIMSS) released a 2020 Cybersecurity Survey in which they concluded that 89% of all cyberattacks, including ransomware attacks, start on email. Cybercriminals today are adapting their techniques to strategically target people within the organization, using social engineering techniques that are designed to trick users into making security mistakes.

Threat actors approach these email-based attacks with same effort, time and resources they used to put in to understanding network vulnerabilities. And there is enough actionable research from Proofpoint that clearly states who is being targeted within the healthcare sector.

For example, if an institution has a clinical research component, it is being attacked to gain access to intellectual property. Employees that deal with supply chain — those who are downloading invoices, paying invoices or approving quotes — are being targeted because they are more prone to click on a malicious link. If the organization deals with controlled substances that have monetizable value on the black market, those employees are at high risk as well.

Proofpoint conservatively analyzes 5 billion-plus emails per day with a significant portion of those being sent to health institutions. Our data shows that up to 90% of emails that are sent to healthcare institutions are being blocked by email filters. The rest is composed of targeted emails which appear to come from a known person or entity. Attackers do their homework, targeting people based on data readily available to them. Caught off guard, an employee may click on something without thinking, leaving the network open to risk.

The resulting ransomware attack may not happen immediately after a compromised credential. Once a cybercriminal gets access to the system, they can take their time gathering information about the organization to navigate their way to a part of the architecture where they can launch their exploits.

Though many security leaders today talk about upcoming security threats, such as medical device vulnerability, the data shows ransomware, phishing and imposter emails still work, and these are low investment and high-return attacks for cybercriminals. Certainly, medical devices have very valid weaknesses, but we do not anticipate a significant shift in how criminals invest in attacks until the email-based attacks become less profitable.

The good news is that healthcare organizations don’t have to wait for tools to be developed to address this problem. Modern security platforms, like Proofpoint’s, give security leaders the insights they need to make strategic investments that protect the organization’s people.

Building a security strategy informed by data

At Proofpoint, we believe that if organizations can see the data behind who is being attacked, they can better anticipate and mitigate the risks on their threat landscape. A people-centric security approach provides institutions with the ability to apply risk-based controls based who is being targeted and why they are being targeted.

We understand the value of protecting people. With Proofpoint’s research, tools, capabilities and technology, we give organizations the means to keep the bare minimum of exploits away from their targets.

If an organization has 50,000 email addresses, for example, and only 10% or those are being significantly targeted, it wouldn’t be appropriate or cost effective to set up the gold standard of security tools against all 50,000 email addresses. Instead of treating everyone the same, the institution can apply adaptive controls on those people who are most at risk.

Our Targeted Attack Protection solution provides visibility to an organization’s “Very Attacked People” (VAP), which allows the institution to identify which job functions are under attack and why. Once that is known, the organization can decide which adaptive controls should be used to offer enhanced protection such as fine tuning their sandboxing so that any emails that come to those individuals can be directed into a sandbox for further analysis.

They can also place certain exchanges in an isolated environment, so that whole email interchange exists within a container to prevent seepage onto the enterprise network. All of the activity exists in a containerized environment which can significantly improve the ability to prevent data losses.

Finally, we always recommend that organizations continuously update their security training. Understanding which departments are at greatest risk will help leaders make strategic decisions on who has greater exposure to security awareness training. Ultimately, minimizing risk will come down to making sure that these people are best equipped to understand what a suspicious email would look like.

Learn more about how Proofpoint can help protect your organization, and your people, against malicious attackers.

CMMC Accreditation Body hires CFO from insurance group IFG

The Cybersecurity Maturity Model Certification Accreditation Body, the non-governmental body responsible for operating the Department of Defense’s new contractor cybersecurity compliance regulations has hired Raymond Karrenbauer as CFO.

Karrenbauer will be dual-hatted in the new role and also hold the post of executive vice president overseeing IT and tech portfolios. He is the AB’s first official CFO, taking over from Yong-Gon Chon who served as acting CFO while being on the board of directors. Over the past year, the AB has been transitioning from a volunteer organization run by its board to one with professional staff.

“Raymond is a bona fide IT and business trailblazer who understands both financial management and how to build a world-class online user experience. As such, his joining the Accreditation Body gives us a transformational boost and will change the way our CMMC stakeholders interact with us,” CMMC AB CEO Matt Travis said in a statement.

CMMC is the new compliance program DOD created to verify its contractors have the cybersecurity to handle sensitive information. The model established five tiers of security, with one being the lowest and five requiring expensive cyber systems. Third-party assessors will test all 300,000 defense contractors against the model, with their certification determining a contractor’s ability to continue work with the DOD. The AB oversees the ecosystem of trainers, assessors and certifications of CMMC assessments.

Karrenbauer comes from the insurance industry, most recently working as senior vice president and chief information officer for IFG Companies, a privately held insurance group. There he was responsible for the company’s IT portfolio. He also has experience in other IT roles and at online startups.

“I look forward to creating a world-class cyber accreditation organization and an online marketplace that accelerates the adoption of the CMMC framework,” Karrenbauer said in a statement.

Coast Guard launches new cyber strategy

The Coast Guard will build more cyber teams to focus on the cybersecurity of maritime critical infrastructure from attacks after a rash of hacks and ransomware incidents that shut down key services, the service’s top cyber officer announced Tuesday.

Its new Cyber Strategic Outlook was developed over the past 18 months and is the first update to the Coast Guard’s cyber strategy since it was signed in 2015. The changes come amid concerns over the increased vulnerability of critical infrastructure and an increase in attacks like the Colonial Pipeline ransomware incident, Rear Adm. Michael Ryan, commander of the Coast Guard’s Cyber Command said at the Sea-Air-Space conference.

“It really is about revitalizing the focus of our organization,” he said.

The new outlook focuses on protecting the tech that enables maritime commerce, like software that tracks shipments and operational technology in ports. There has been an increase in automation and tech used to enable the global shipping network, a growth in attack surface for hackers Ryan said needed to be recognized in the strategy.

“As your strategy gets older and latent it becomes less relevant,” Ryan added.

One of the deliverables in the new strategy is creating new cyber teams focused on defending networks and conducting cyber operations to thwart malicious attack on critical infrastructure. The first two cyber mission teams have already been stood up, with funding for a third team requested in the fiscal 2022 budget request. Other units, like a cyber support team will also be established, according to the new strategy.

Another part of the strategy focuses on protecting the guard’s own IT platform, the Enterprise Mission Platform (EMP), which is part of the Department of Defense’ Information Network (DODIN). The goal is to ensure the Guard has secure connectivity to carry out its broader homeland defense mission, according to the strategy.

The Coast Guard, a military service, is uniquely housed under the Department of Homeland Security, giving it law enforcement authority and relationships with other DHS agencies like the Cybersecurity and Infrastructure Security Agency (CISA).

The service has sought to modernize its legacy IT since 2020. The latest outlook is separate the Coast Guard’s previously-established IT modernization strategy, but speaking at the Sea-Air-Space conference, Rear Adm. Ryan said the two would work in tandem to improve its network. security.

FedRAMP just automated checking security authorization packages for completeness

The General Services Administration plans to release XML-automated validations next week allowing vendors to check their security authorization packages for completeness before submitting them to the Federal Risk and Authorization Management Program.

FedRAMP used Schematron’s rule-based validation for making assertions against XML to automate the process and wants vendors to self-test their packages to ensure all the required data is there, before the program reviews them and decides whether to issue a cloud product an authority to operate (ATO).

More easily hackable legacy systems stay in operation longer when agencies can’t quickly purchase cloud products they need for lack of an ATO, and vendors have long wanted FedRAMP to automate parts of its authorization process.

“I think it’s a great step in automated validation,” said Zach Baldwin, automation lead within the FedRAMP program management office (PMO), during an ACT-IAC event Tuesday. “I want cleaner documentation before I have my review team lay eyes on it.”

The PMO wants vendors to implement the validations that allows them to reinsert new files with more complex checks as FedRAMP improves them, Baldwin said.

FedRAMP is also considering an agile ATO, a critical set of controls vendors can implement quickly while saving lesser ones for later.

The PMO recently partnered with the Department of Homeland Security’s .govCAR to score vendors’ security architectures against cyberthreat heat maps. Updated scores will be released in the near future, but they can be used to create a risk profile as agencies make cloud service purchasing decisions, Baldwin said.

Automation wouldn’t be possible without FedRAMP’s work with the National Institute of Standards and Technology to create the standardized Open Security Controls Assessment Language (OSCAL) for authorization packages. NIST released OSCAL 1.0.0 in early June.

“I’m going after the time it takes to get an authorization and the number of passbacks between my review teams and the [cloud service providers] and [third-party assessors],” Baldwin said.

Pentagon names Gregory Kausner acting head of acquisition

The Department of Defense has appointed Gregory Kausner to assume the duties of undersecretary of defense for acquisition and sustainment.

He takes up the role in an unofficial capacity after a career in military leadership at the Pentagon, most recently as executive director for international cooperation.

There is some nuance to Kausner’s appointment — he has been asked to do the job of undersecretary of defense for acquisition and sustainment but does not officially hold the position, as undersecretary of defense for acquisition and sustainment requires a presidential nomination and Senate confirmation.

News of the Kausner’s assumption of the duties comes after Defense Innovation Unit Director Mike Brown earlier this month requested that his name be withdrawn from Senate consideration for the position as President Biden’s nominee. His decision came amid an ongoing investigation from the DOD’s Inspector General into his conduct.

DOD today also announced the appointment of Paul Cramer to perform the duties as deputy undersecretary of defense for acquisition and sustainment.

In the undersecretary role, Kausner is responsible for all matters relating to defense acquisition, contract administration, logistics and materiel readiness. The scope of his brief also encompasses work relating to installations and environment, operational energy, as well as the acquisition workforce and the defense industrial base.

Kausner had performed the duties of deputy undersecretary of defense for acquisition and sustainment since January this year and previously served in a multitude of other senior military roles.

How automated analytics can improve digital services, security and workflows

As leaders at federal civilian, health and defense agencies continue to grapple with the explosion of data coming at them from all directions, the need for more robust platforms, capable of managing and making sense of all that data, has taken on new urgency.

The good news is, a new generation of AI-assisted IT operations (AIOps) platforms and intelligent analytics platforms — as well more advanced security orchestration, automation and response (SOAR) solutions — are giving agencies powerful new capabilities to keep up with that data, according to a new report from FedScoop.

Read the full report.

The availability of AIOps, data analytics and SOAR solutions are expected to play an important role in helping agencies achieve the White House’s May 12 “Executive Order on Improving the Nation’s Cybersecurity.” The order, among other directives, requires agencies to begin implementing new steps to modernize their cybersecurity practices and improve how they respond to cybersecurity vulnerabilities and threats. Those requirements come on top of the Federal Data Strategy 2020 Action Plan, which calls for agencies to take concrete steps to govern, manage, protect and leverage the value of federal data.

The challenge agencies face, according to the report, isn’t just the volume of data getting generated and processed every day. It’s how to effectively assemble so many types of structured and unstructured data emanating from so many disparate systems — and then, how to make sense of it in order to make timely business decisions or mitigate cybersecurity threats.

The report, which was underwritten by Splunk, outlines five critical functions that modern AIOps platforms can now perform, from ingesting dating to analyzing it in real time and initiating remedial actions when necessary.

It also touches on the benefits of platforms like Splunk SOAR and Splunk IT Service Intelligence (ITSI) platforms, that can help agencies reduce the time it takes to investigate and resolve IT issues.

Ann Mehra, strategic healthcare programs leader at Splunk, recalls in the report how “close to 50 individuals were trying to get to the root cause of what was happening, utilizing a number of different tools. We stepped in and in 48 hours, we were able to look across the organization’s networks, across its applications, and across its data sources and were able to identify the root cause.”

ITSI also gives agencies a platform for managing large-scale IT development projects. That was the case when the U.S. Census Bureau decided to conduct the 2020 decennial census online, requiring a massive effort to modernize their IT, security and data operations, according to Wylie Vasquez, leadership advisor for observability and AIOps markets at Splunk.

One of the key advantages Census found in Splunk’s Data-to-Everything platform, according to the report, is the ability to ingest and unify nearly any kind of data — structured or unstructured, including logs, metrics, text, wire, API or social-media — from nearly any tool and any system, on-premises or in the cloud.

Another benefit of automation, the report says, is the ability to reduce the potential for human errors or delays that can occur in highly repetitive tasks. Automation also can help agencies maintain greater system continuity in circumstances where personnel rotate in and out of positions, as is routinely the case in the military.

“Removing the error factor” is one of the key benefits of automation, says Eric Hennessey, staff consulting solutions engineer for national defense accounts at Splunk. “Whenever you can take humans out of the loop on some of these tasks — especially a task that you do over and over again — and institutionalize these repetitive processes, using an automated playbook like we do with Splunk SOAR, you greatly reduce that opportunity for error.”

Read the full report on how automated analytics can improve digital services, security and workflows.

This article was produced by FedScoop and sponsored by Splunk.

Booz Allen expects number of staff working in office to decline

Booz Allen Hamilton is expecting the number of its staff working full time in its offices and on government premises to fall from previous levels, according to the federal contractor’s CEO.

Speaking on a second-quarter earnings call, Horacio Rozanski praised the creativity of the company’s clients during the COVID-19 pandemic and said many continue to embrace new ways of working.

“[W]e have a group of people who work full time at government and our facilities. And that too will continue, although we expect it to proportionately decline from historical levels,” Rozanski said. “Our clients have shown a great deal of creativity over the course of the pandemic. And based on this experience, many are interested in flexible models that better serve their missions while reducing the number of people who are 100% onsite.”

The comments come as agency staff return to the office and follow an earlier policy advising federal departments to consider embracing a more geographically distributed workforce. The Office of Personnel Management also issued further guidance on that policy July 23 “to assist agencies … as they plan for the safe, increased return of Federal employees to physical workplaces (“reentry”) and the post-reentry work environment.”

Agencies have each set their own strategy for bringing their workforce back to the office with input from the Safer Federal Workforce Task Force.

According to the prior guidance, federal departments were advised to embrace more telework “where possible and appropriate,” and where it could help to benefit equity, inclusion and the delivery of missions.

The geographic location of the federal government jobs was highlighted last month with the Biden administration’s Executive Order on Diversity, Equity, Inclusion and Accessibility, which was intended to examine new ways of getting underserved and minority communities into the workforce.

Responding to questions from analysts on the company’s earnings call, Booz Allen’s executive team said also that the company’s projection for achieving about $200 million in cost savings from its acquisition of Liberty IT, remains unchanged.

In an interview earlier this year with FedScoop, Booz Allen’s head of civil business Kristine Martin Anderson said the consulting company’s “number one” job following the $725 million deal would be to deliver on existing contracts with the Department of Veterans Affairs, but that the transaction will allow the company to deploy Liberty’s resources across other areas of its balance sheet.

Accelerating forensics investigations by leveraging AWS GovCloud

Christine Halvorsen has spent more than 20 years working in various law enforcement, intelligence and IT roles for the Department of Justice and the FBI before joining AWS in 2019. She currently serves as senior technical business development manager on AWS’s Mission Acceleration Team.

The explosive growth of digital forensics information over the past two decades has transformed the way federal law enforcement and regulatory agencies deliver their missions. But it has also put new pressures on many federal agencies to develop more scalable and advanced solutions.

Christine Halvorsen, Sr. Technical Business Development Manager, AWS’s Mission Acceleration Team

When I started out as an FBI agent in 1996, we were still getting used to the forensic tools and principles for collecting, extracting, storing and safeguarding digital evidence. By 2010, the FBI’s Regional Computer Forensic Laboratory reported the average case by sifting through and managing four terabytes of data.

That was modest compared to the FBI’s 2013 Boston Marathon bombing investigation, which collected more than 50 terabytes of information. By the time I was called in as senior investigator in the 2017 Las Vegas Mandalay Bay shooting, the FBI was faced with collecting and analyzing a petabyte of data for that single case.

Were it not for the built-in capabilities of the cloud — to upload and analyze all of that unstructured, circumstantial evidence quickly, and in ways that were both secure and auditable — it would have been impossible to manage a case of that size, involving 13 responding agencies and so many tragic deaths and injuries.

Meeting mission needs at scale

Finding proverbial needles of evidence in today’s massive digital haystacks has never been more challenging. The volume of data from personal computers, smartphones, social media, emails, and e-commerce, as well as surveillance cameras, sensors and countless other devices continues to grow exponentially. By 2025, the amount of data generated each day is expected to reach 463 exabytes globally.

And it’s not just a challenge for law enforcement. There’s a wide range of government agencies, overseeing financial, health, consumer protection and many other sectors, that are similarly responsible for properly handling, analyzing, preserving and storing evidential information from the point of ingest and throughout its lifecycle.

Leveraging the cloud can help agencies scale IT resources up and down, as well as save IT costs. But perhaps more importantly in government, the cloud offers agencies on-demand compute power and modern applications to process workloads at a pace that agencies require to meet their missions.

The cloud can help address four recurring challenges we hear from our customers, particular those whose missions depend on managing digital evidence:

  • Reducing the processing backlog — When it comes to managing digital evidence, there are five critical stages that must be handled properly: collection, extraction, storage and chain of custody, analysis, and dissemination. As digital case workloads grow larger and more complex, fixed IT resources make it harder to complete the front-end tasks. That cascades into costly delays in completing analytic work. At AWS, we’ve been helping customers use the scale of the cloud to provide a dynamic and cost-effective way to accelerate workloads in those first three stages — helping in turn to analyze and disseminate evidence faster.
  • Optimizing familiar forensics tools to work in the cloud – Customers tell us they want the ability to use the secured forensic tools they are familiar with on-premises turbo-charge them using the cloud’s high-performance compute environment. Together with our partners, we’re helping them make that transition while reducing their software licensing costs. Instead of agencies, for instance, having 10 licenses sitting on one workstation, which limits how many people can process evidence, AWS and its partners are developing new licensing models in the cloud to support the customer’s needs and application of the tools, allowing more examiners and analysts to work simultaneously with agility and speed, given the cloud’s processing power.
  • Automating digital extraction and analytics processes – Our customers also tell us that many of their processes are still manual, cumbersome and repetitive. We’ve been able to automate significant portions of that work. For instance, examiners using AWS’s GovCloud can extract digital evidence from bundles of data and then immediately apply analytics. That helps narrow their searches for needles in the digital haystacks and quickly gain insights from what’s in the data.
  • Managing evidence storage more effectively – The unique statutory requirements for storing evidence — in some cases for 25 years — presents a special challenge for agencies. It’s no longer practical or economical to keep buying more and more storage infrastructure. With AWS infrastructure, agencies can choose a range of storage models, including our deep archive option, which allows agencies to store data for pennies on the dollar compared to on-prem storage. AWS also makes it easier to automate the movement of evidential data from one stage to the next and into final storage after cases are closed, freeing up forensic examiners and analysts to concentrate on delivering their missions.

AWS has been working with multiple federal agencies from federal law enforcement to federal financial institutions to establish working models that address all four of these challenges. These models have reduced the time to process digital evidence from weeks to minutes. The cloud’s elasticity has spurred innovative approaches to analyzing forensic data and given investigators greater analytical, entity extraction, and translation capabilities. But most of all, the cloud is giving agencies the ability to manage their digital evidence workloads at a pace that’s more commensurate with their needs of their missions.

Learn more how AWS is helping federal agencies manage their escalating digital workloads.

Anduril appoints Goldfein, MacFarland to advisory board

Defense technology firm Anduril has appointed a handful of top former defense officials to its advisory board.

The company named five new advisors including Katharina McFarland, former assistant secretary of defense for acquisition, retired U.S. Air Force Chief of Staff Gen. David Goldfein and former U.S. Navy officer Adm. Scott Swift, who was commander of the U.S. Pacific Fleet.

Goldfein was the 21st Chief of staff of the U.S. Air Force, in which role he was responsible for organizing, training and equipping the service.

Pangiam CEO Kevin McAleenan, who served as acting secretary of the Department of Homeland Security during the Trump administration, and Constantine Saab, the chief technology officer at Valor Equity Partners and a longtime CIA executive, also join its advisory committee.

Commenting on the five new appointments, Anduril CEO Brian Schimpf, said: “We are honored to be joined by an esteemed group of experts who will provide strategic counsel as we grow the company and scale Anduril’s software and hardware products across the DOD.”

“The board brings a wealth of knowledge and perspective on the inner workings of the government agencies responsible for our nation’s safety and security. They will help guide our work to rapidly modernize U.S. defense capabilities,” he added.

Earlier this month, Anduril won a $99 million contract to provide the Department of Defense with a new automated counter-unmanned aerial system (C-UAS) capability. The Production Other Transaction (P-OT) Agreement was struck between the company and the Defense Innovation Unit,