Industry matters when assessing cyber risk to the defense industrial base
Manufacturing and research and development companies — not simply small and medium-sized businesses (SMBs) — bear the highest risk of cyberattacks within the defense industrial base, according to a BlueVoyant report released Tuesday.
The New York City-based cybersecurity company independently analyzed available third-party data from a sample of 300 small and medium-sized defense contractors and found industry mattered more than size in determining cyberattack risk. Smaller businesses remained more susceptible within their industries.
BlueVoyant’s report comes after a string of successful cyberattacks that targeted SMBs and raised the question of whether they, with their limited defenses, offer easiest access to the supply chain. The answer is more nuanced.
“Not only are R&D firms vulnerable, they are particularly attractive to attackers,” reads the report. “R&D firms work on cutting-edge products, develop valuable IP, and often create and sell software and tech that become components in larger and more important systems — making them attractive as points of entry for malicious insertion or IP theft.”
More than half of the SMBs assessed had unsecured ports critically vulnerable to potential ransomware attacks, while 48% had those and other severe vulnerabilities, like outdated software or operating systems, rendering them “high risk.”
Nearly 20% of the SMBs had multiple vulnerabilities and showed evidence of threat targeting, while 7% deemed “critical risk” had been compromised in some way.
BlueVoyant found 28% of the firms would likely fail to meet the most basic, level 1 Cybersecurity Maturity Model Certification requirements. That statistic is more troubling with nation-state adversaries and cybercriminals proving increasingly adept at finding the weakest link within supply chains and when exploitable weaknesses abound among SMBs.
Roughly 300,000 companies directly contract with the Department of Defense, and its CMMC requires “significant investment” in new controls from SMBs with limited budgets and technical expertise, according to the report.
Meanwhile, contract primes and other large companies are under “enormous pressure” to reduce the attack surface of their supply chains, without full visibility into the network security of the subcontractors they’re responsible for, according to the report. The financial and logistical costs of designating subcontractors to CMMC tiers and ensuring their compliance isn’t cheap, especially when one business’ tier may vary contract to contract — causing some primes to force their subcontractors to level up.
While BlueVoyant had no way of determining firms’ cybersecurity maturity in line with CMMC compliance, it did recommend companies use continuous cyber monitoring to secure their supply chains. More than six months after the announcements of the F5 and Microsoft Exchange vulnerabilities, nine companies that were either small manufacturers or large R&D companies still hadn’t addressed them due, in part, to reliance on point-in-time compliance assessments.
Most vulnerabilities SMBs had were tied to email security protocols or else unsupported software, suggesting a lack of patching policies and continuous monitoring, according to the report.
Primes should further focus on addressing issues with high-risk subcontractors based on industry and then size, BlueVoyant recommended.
The company believes predictive risk analysis of SMBs is ultimately possible but said a sample size larger than 300 businesses is needed.
DOD looks to boost cloud capabilities on foreign soil
The Department of Defense is looking for the support of foreign countries to build data centers and cloud computing capabilities outside of the U.S. to boost its global connectivity, according to a new cloud strategy document released in late May.
The challenge is that the DOD needs to have total control of and access to both its data and the computing resources it will use to analyze it, but many foreign countries have laws that allow them as host nations to access any data stored on their soil. According to the department’s new Outside the Continental United States (OCONUS) Cloud Strategy, that would be a problem that requires DOD to negotiate directly with host nations and lean on commercial cloud service providers to keep its data and cloud capabilities private.
“Given the challenges with meeting host nation data control requirements, cloud service providers must make a significant investment to support OCONUS locations,” says the strategy, which was signed by acting CIO John Sherman.
The DOD wants to bring full cloud capabilities to OCONUS locations to enable its modern strategic concept of operations called Joint All Domain Command and Control (JADC2), which relies on having the tech at hand to connect data from across all domains of the battlefield. Without the ability to store, transmit and analyze data, the military is without the core tech needed to support the new capabilities leaders have set as a priority.
“Cloud computing can help solve today’s national defense challenges, but its true potential is to solve tomorrow’s challenges,” the strategy states. “Collaboration across these domains, increasingly enabled by high-tech, software-driven solutions, must occur at the global point of need, at the tactical edge, and at the fight.”
Currently, the DOD manages more than 200 data centers on military bases outside of the U.S. on “status of forces agreements” that allow the military jurisdiction over the tech resources, a DOD spokesperson told FedScoop. DOD policy precludes any sensitive data from being hosted outside of places that the U.S. doesn’t have legal jurisdiction.
“Currently, the Department has limited data center capacity in its OCONUS locations when considering existing workloads, increasing data production, and growing use of commercial cloud services,” the spokesperson said.
The main goals of the new strategy are to provide resilient connectivity for military operations outside of the U.S., increase computing power and get more tech talent out into the field. The three goals all face challenges from the hostile environments for computing to the military’s tech skills gaps.
One workaround the strategy calls for is finding computing tech that has less size, weight and power (SWaP). More nimble compute power would relieve several of the constraints the strategy is contending with, including when the military needs cloud capabilities in areas with weak infrastructure.
“Data needs to be processed close to its source and staged as close to the warfighter as possible to enable data-driven decisions,” the document states.
Other objectives within the strategy include instituting more training for service members and civilians based outside of the U.S. and building out a “Mission Partner Environment” for partnered militaries to link safely into U.S. systems with the right level of access.
Cybersecurity asset management trends point to increasing complexity
Nathan Burke, chief marketing officer at Axonius, has over 15 years of technology and leadership experience. He is passionate about bringing new technologies to solve real cybersecurity problems.

Nathan Burke, Chief Marketing Officer, Axonius
Increasing visibility into government infrastructure remains a key challenge to combat security threats. And though agencies most likely have all the security tools they need, IT leaders still struggle to see how those tools are properly deployed across their networks and devices.
The pandemic and remote work environment certainly accentuated these challenges, but these aren’t the only factors driving visibility and security risks, according to a recent study Axonius commissioned with Enterprise Strategy Group (ESG).
The second annual Cybersecurity Asset Management Trends report surveyed IT and cybersecurity professionals across organizations in North America to understand current asset visibility challenges and trends. According to the findings, 72% of respondents reported that modern IT infrastructure complexity has continued to grow over the past two years.
If you think back 10 to 15 years, most organizations had a pretty standardized set of devices or applications on the network. However, the state of IT environments today raises a lot of questions about what an IT asset is. Is an Amazon storage instance an asset? Or an IoT device? What about ephemeral devices that may live for only an hour?
Organizations have not only increased the types of devices that need to be managed, but the pace of change, which requires almost a more robust and up-to-date asset inventory.
Additionally, with different device types, organizations have also acquired different solutions to manage or secure them. The report findings indicate that on average, organizations depend on eight different tools to pull together asset inventories. And the average asset inventory will take 86 person-hours to generate.
Post-pandemic response presents new opportunities
Though the shift to remote work accentuated complexity and visibility challenges within government IT infrastructure, the preparation for employees to return to the office presents IT leaders with a notable opportunity to get back to the basics of asset management and cyber hygiene.
When federal employees return to the office, they will bring with them devices that either were not managed by agency IT or which have not been updated over the last year. The security risks of these visibility gaps may be striking for agency leaders.
And though it remains to be seen how government agencies will navigate hybrid-work structures, industry trends suggest the demand for remote work capabilities are on the rise. On average, respondents in the survey expect 40% of their organization’s workforce will work remotely after the COVID-19 outbreak is controlled — an increase from 23% prior to the pandemic.
In addition to remote work needs, the rapid development of digital services is making it more difficult for IT to answer simple questions about their assets.
Eight in 10 people in the survey acknowledged facing visibility in gaps in the cloud, up by 10% from last year. Respondents also reported widening visibility gaps with end-user devices (75%) and IoT devices (75%).
The study suggests that IT and business teams are getting applications, cloud services, and devices out to their workforce faster than what security teams can keep up with.
Moving from a reactive to proactive security position
While there is no shortage of security challenges that agencies are facing, the goal for now involves focusing the resources they have where they can deliver the most impact.
The recently issued cybersecurity executive order from the Biden administration promises to give cybersecurity modernization efforts greater attention. Though most agencies already have enough security and device management tools, many teams lack the visibility they need to be confident in complying with new security efforts.
Using a cybersecurity asset management platform offers a greater opportunity to close those visibility gaps.
The Axonius cybersecurity asset management platform, for instance, gives agencies the ability to gather asset and vulnerability data across an organization’s entire network into a centralized view. The platform connects to all of an agency’s different asset management and security tools to collect and analyze their respective data — regardless of the asset type.
The totality of that data, when combined and correlated, provides a powerful overall picture. But it also allows an organization’s IT team to query how any and every asset either adheres to, or deviates from, their security policies. The results often prove eye-opening. For example, one Axonius customers recently ran a query to test the deployment of an endpoint protection tool and discovered that it was only installed on 40% of those devices that required endpoint protection.
Once vulnerabilities are exposed, an agency can decide what action to perform. So, if the query finds an endpoint that is missing an agent, an automated action can be programmed to install it, update a database or submit a ticket.
Taking steps towards achieving full visibility across federal agencies’ network environments will always come down to knowing what is on the network.
What we recommend above all: Use the momentum created by the pandemic and recent security incidents to encourage strategic conversations among agency leadership on implementing an operational plan for full network visibility today.
Learn more about how Axonius can help your organization address security risks with modern asset management solutions.
Industry group warns onerous criteria for GWACs may benefit large contractors
The Alliance for Digital Innovation (ADI) has urged caution over the introduction of further evaluation schemes for contractors bidding on governmentwide acquisition contracts, or GWACs.
In a report issued Tuesday, the industry group said that while it supports action by the federal government to tackle rising cybersecurity threats, the use of overly complex evaluation criteria benefits large incumbent companies working in the federal technology space, and may be stifling innovation.
“An example of this concern is presented by the recent heavy reliance on using scoring worksheets for evaluations of GWAC proposals (where companies must score high in order to receive an award),” says the report. “While this objective method of evaluating high numbers of offers can save time and protect the government from frivolous protests, the criteria used in these worksheets is based on traditional large, long-term government contracts.”
The report argues that such criteria “heavily favor the traditional large government contractors and create a huge barrier to entry for smaller, more specialized firms that provide deep expertise in specific technology solutions.”
In addition to raising concerns about one-size-fits-all evaluation criteria, ADI has called on GWAC administrators to engage more effectively with commercial industry. It noted that some agencies had made recent progress by appointing liaison staff to maintain relationships with the private sector.
“[M]any agencies still have a limited interest in meeting with potential vendors that are not familiar with the unique government culture and acquisition processes. This unintended bias particularly impacts nontraditional vendors whose commercial solutions were not built primarily to deal with government-specific requirements,” the report says. “Moving these activities further up in the procurement cycle gives GWAC administrators greater access to information, market intelligence, and customer feedback that can help them even before the first word of an RFP is published.”
ADI also called on GWAC administrators to show a more open approach to prior commercial use cases presented by new vendors. In some cases, according to the trade body, these may provide as accurate a guide as a company’s previous track record in government procurement.
“Just because a certain vendor (or vendors) have followed the letter of previous procurements and built the government whatever unique, bespoke solution they requested, that does not necessarily mean that they have the kinds of ideas, products, and services that will meet the evolving customer demands required in new GWACs,” ADI said in the report.
DOD to embed data experts within military units
The Department of Defense is launching a new Artificial Intelligence and Data Accelerator initiative (AIDA) that will embed teams of data experts within combatant commands, Deputy Secretary Kathleen Hicks said Tuesday.
Under the scheme, two types of teams will be embedded: operational data teams, which are focused on creating new tools and policies, and “flyaway teams” that are parachuted in to assist on specific problem sets.
The initiative is part of the DOD’s work to implement its Joint All Domain Command and Control (JADC2) strategy, which outlines a vision in which a military internet of things and data become central to the theater of war.
Hicks said the new data teams will bring “top tier talent and technology” to modernize the data and IT infrastructure combatant commands rely on and the policies that dictate data usage. They will start with a 90-day window to make improvements.
Artificial intelligence is to be used to sift through the large amounts of data being generated as part of the JADC2 strategy. AI systems in command centers will have the power to communicate directly with each other.
The strategy for how JADC2 could modernize military operations was signed by Defense Secretary Lloyd Austin in May, giving the department the approval to move ahead on new initiatives like AIDA.
The technology that is intended to drive JADC2 has largely yet to materialize. That’s one of the problems the new operational and flyaway teams will work on, building out the data platforms and AI infrastructure that will form the basis of the strategy.
Connolly floats legislative fix for IT working capital funds
Congress probably needs to revisit the Modernizing Government Technology Act because some agencies still haven’t created IT working capital funds, based on legal advice from their general counsels, said Rep. Gerry Connolly, D-Va., Monday.
The Subcommittee on Government Operations he chairs may open up a policy dialogue with those agencies and their counsels, but more likely a legislative fix is needed, Connolly said.
Only three out of 24 agencies graded received “As” in implementing the MGT Act on the last FITARA scorecard in December, in part, because their lawyers continue to tell leaders they lack transfer authority to put appropriated money in IT working capital funds.
“[I]n some cases they’ve formed the funds,” Connolly said, during a MITRE event. “In some other cases they have not because they’ve been advised legally they don’t have the authority, even though the law we passed says you do.”
A jurisdictional “turf battle” between the House Oversight and Appropriations committees could ensue over the working capital funds — designed to bank unused IT dollars until agencies are ready to invest them in long-term modernization projects — unless they work together, Connolly said.
Agencies must also be required to produce plans for the use of their IT working capital funds, he said.
“From my point of view, it’s just critical every agency has a working capital fund so that they can stay abreast of changes in technology, implement the latest encryption programs and measures to protect the assets in the databases and proprietary information, and retire those legacy systems,” Connolly said.
Former CISA innovation chief joins Silicon Valley defense tech incubator
Defense technology incubator and consultancy BMNT has hired the former chief of the Cybersecurity and Infrastructure Security Agency’s innovation hub.
Sabra Horne joins the Palo Alto-based company as an entrepreneur in residence, where she will help to lead its InsightAI program.
Horne has held senior roles at CISA since 2017, and prior to that at the National Security Agency. Earlier in her federal career, Horne was a director in the Office of Communications at the Department of Justice and has also served as a senior adviser at the Office of the Director of National Intelligence.
BMNT is an innovation consultancy and early-stage tech incubator that was established in 2013 by former U.S. Army Colonel Peter Newell. It applies the Silicon Valley startup mentality to national security issues and works with large organizations including federal agencies. Its clients include the Australian and British governments, and earlier this year set up a U.K. entity.
InsightAI uses natural language processing and artificial intelligence to sift information from employee surveys and other internal information. The program is intended to reduce the number of human hours required to do such work and to carry it out in a more reliable and objective manner.
Horne joins other leaders within BMNT with federal government experience including Jackie Space, who was a visiting senior research fellow at the National Defense University. Before joining the private sector she was a program manager in the U.S. Air Force.
Commenting on the appointment of Horne, Newell said: “All of the staff who arrive at BMNT join the company because they have a unique drive for mission-driven work.”
“Sabra brings an incredible skillset and understands the context of how natural language processing and artificial intelligence will change the nature of defense and intelligence work.”
Horne said: “I am thrilled to be part of the remarkable group at BMNT and to join their work in supporting national security. With the success of the company’s hacking programs, their mission-focused and innovative services, and the development of InsightAI, under the inspiring leadership of Pete Newell, this is a group I had to join.”
DOD to elevate cyber, network testing in new exercises
The Department of Defense will hold large-scale exercises this calendar year to test the resiliency of battlefield networks and project how the U.S. military would cope if it comes under sustained cyber attack while fighting future wars.
The latest exercises will differ from current war games that focus on guns and tanks or experimenting with emerging tech, Lt. Gen. Dennis Crall, chief information officer for the Joint Staff said Monday. They will be focused on testing the Joint All Domain Command and Control (JADC2) strategy, where networks connect all military operations in air, land, sea, space and cyberspace.
The event will take place”not just in a special IT forum, not just with CIOs, but with the warfighter,” Crall said .
Crall was critical of the department’s prior lack of attention to cyber and network connectivity. He described the place of IT in briefings as “one-slide deep,” with that slide containing some graphics with lightning bolts and little information.
“No one was really looking at this,” he said, adding that while some people in DOD have focused on network resilience, it was “not holistically.”
That will change with combatant command-level exercises planned for this year, he said. He didn’t give any more details or a name of the exercise, but said they would represent a new way of testing the strategy.
So far, services have hosted test events for the tech they are building as a part of JADC2. The Air Force’s contribution, Advanced Battle Management System (ABMS) has had several joint “on-ramps,” where new tech was tested, but Crall said these were carried largely as a means of experimenting with new technology instead of simulating entire battles.
DOD weighing options on JEDI with possible changes coming soon, says No.2 Hicks
The Department of Defense could take a new direction by next month on its Joint Enterprise Defense Infrastructure (JEDI) cloud contract, Deputy Secretary Kathleen Hicks said Monday.
Hicks said that while the department is keeping its options open, she expects movement on the stagnant contract soon.
“We are very actively looking at our options,” Hicks said at the DefenseOne Tech Summit Monday. “We will be moving forward in a…direction in the next month or so, but I am not going to get into where we might end up,” she said, citing the ongoing litigation around the contract.
The contract remains stuck in legal limbo as Amazon Web Services continues to protest the 2019 award of the contract, worth up to $10 billion over 10 years, to Microsoft.
Hicks reiterated the importance of getting enterprise cloud into the department, both for emerging warfighting capabilities like Joint All Domain Command and Control (JADC2) and back-office business operations. Secretary of Defense Lloyd Austin recently signed a new strategy for JADC2 — a new digitally-driven concept of operations that relies on an enterprise cloud to store data and connect weapons in a battlefield.
“The department must have an enterprise cloud solution approach in order to make the most of JADC2,” Hicks said.
One option before the DOD is canceling the JEDI contract and starting fresh; while DOD officials have contemplated the possibility in the past, Hicks did not mention it Monday.
AWS recently scored a victory in court with a federal claims judge agreeing to the company’s requested timeline on hearings in the case and receiving additional documents.
HHS launches $80M public health IT workforce program promoting equity
The Department of Health and Human Services launched a program for IT workforce development with American Rescue Plan Act funds Thursday.
Dubbed the Public Health Informatics & Technology Workforce Development Program, the $80 million consortium will create a curriculum; recruit and train participants; secure paid internships; and place people at public health agencies, nonprofits, clinics and companies.
The program will encourage minority-serving colleges, universities and other institutions to apply for funding, in keeping with the American Rescue Plan’s goal of addressing health and socioeconomic inequalities highlighted during the COVID-19 pandemic.
“With this funding, we will be able to train and create new opportunities for thousands of minorities long underrepresented in our public health informatics and technology fields,” said HHS Secretary Xavier Becerra in the announcement. “Investing in efforts that create a pipeline of diverse professionals, particularly in high-skilled public health technology fields, will help us better prepare for future public health emergencies.”
The pandemic showed race and ethnicity-specific data was lacking during public health reporting and data analysis due, in part, to limited IT infrastructure and underfunding of staff needed at the state and local levels. Data on infections, hospitalizations, mortality rates, and health and social vulnerabilities must be disaggregated by variables like race, ethnicity, age and gender to paint a complete picture of a disease’s spread.
About 4,000 participants will be trained by the PHIT Workforce Program over four years, with the Office of the National Coordinator for Health IT awarding up to $75 million for cooperative agreements and spending the remaining $5 million on administration. Awardees must show their training, certificate, degree and placement programs sustain a continuous pipeline of diverse public health IT professionals.
Participants will not only be part of the consortium but a community of practice for sharing resources and lessons learned with each other.
ONC’s notice of funding opportunity supports President Biden‘s executive order on ensuring a sustainable public health workforce. The office will hold an information session on the opportunity on June 23.
“The limited number of public health professionals trained in informatics and technology was one of the key challenges the nation experienced during the COVID-19 pandemic,” Micky Tripathi, national coordinator for health IT, said in a statement. “This new funding will help to address that need by supporting the efforts of minority serving institutions and other colleges and universities across the nation to educate and launch individuals into public health careers.”