Deloitte acquires military cybersecurity firm Sentek

Deloitte has bought San Diego-based cybersecurity and systems engineering firm Sentek for an undisclosed sum.

The acquired company provides services to the defense, security and justice sector, and the Navy is one of its largest clients.

Mike Canning, head of Deloitte’s public services division, said the deal would expand the consultancy’s presence in San Diego and boost its cybersecurity work with branches of the military and other federal agencies.

Eric Basu, CEO and founder of Sentek Global, said: “Sentek Global and Deloitte share many common values, not the least of which is providing high-quality services and solutions for the agencies that serve our country. He added: “We are joining Deloitte to help our government clients solve complex systems engineering and cybersecurity challenges, while also accelerating the scaling of our services for defense, security and justice sector organizations.”

National labs modernization bill introduced in Congress

A bill that would compel the Department of Energy to use appropriated funds to upgrade its national laboratories has been introduced in Congress.

Rep. Bill Foster, D-Ill., earlier this month introduced the draft legislation, which has been referred to the House Committee on Science, Space and Technology. Foster worked as a high-energy physicist and particle designer at Fermi National Accelerator Laboratory prior to becoming a member of Congress.

If it passes, the new legislation will require the secretary of Energy to fund deferred maintenance projects at the national labs, as well as modernization projects and critical infrastructure updates.

The Department of Energy operates 17 strategically significant research facilities across the U.S., focused on scientific research across a range of areas, including management of the country’s nuclear weapons stockpile.

In late June, an analogous bill was also introduced in the Senate by two Democrat lawmakers, requiring the DOE to upgrade infrastructure at the national labs.

As part of the annual funding appropriations process, Energy is required to submit to House and Senate committees a list of projects that will receive funding. For fiscal 2022 through 2026, the department is authorized to receive $6.1 billion for maintenance and modernization through the appropriations process.

At least one-sixth of the funding for maintenance made available during each fiscal year must be managed by the Office of Science at the Department of Energy.

Senate NDAA draft includes study of budgeting process, other tech provisions

The Senate draft version of the fiscal 2022 National Defense Authorization Act could be the start of the Department of Defense and Congress rethinking the defense budgeting process, a system that advocates for tech modernization have long said inhibits the DOD’s ability to be agile.

A summary published by the Senate Armed Services Committee includes a provision that would establish a commission to study the planning, programming, budget and execution process that forces acquisition programs to wait years before getting full funding from Congress. The budgeting process was created in the 1950s to ensure proper accounting for major industrial projects like buying tanks, but inhibits the kind of rapid iteration needed when buying software, experts have said.

“The FY22 National Defense Authorization Act will help safeguard the nation, counter a range of evolving threats, and support our troops both on and off the battlefield.”

“[I]t prioritizes programs and policies to strengthen our cyber defenses, improve readiness, and accelerate research and development of advanced technologies that will give our forces strategic advantages,” committee chairman Sen. Jack Reed, D-R.I., said in a statement.

The bill still has a long way to go before becoming law, including passing both the full Senate and House, but the powerful defense committee often gets many provisions enacted into law.

Other new provisions in the summary include several reports the secretary of defense would be required to submit to Congress, including one on DOD’s contractor compliance regime the Cybersecurity Maturity Model Certification (CMMC), new augmented reality headset technology and DOD’s use of commercial autonomous capabilities.

The bill would also match several requests the DOD has for Congress, including increased funding for research and development and “full funding” for U.S. Cyber Command. On top of more money for research and development, it would give new hiring authorities to the DOD to retain technical talent in labs. The bill would also create a “civilian cybersecurity reserve” within Cyber Command.

Ex-HHS modernization adviser JD Walter joins Golden Key Group

Professional services consultancy firm Golden Key Group has appointed JD Walter as Executive Vice President of Solution Optimization and Execution.

Previously he was a modernization advisor at the Department of Health and Human Services, and also has several decades of experience as a federal contractor working with various federal departments.

Walter is the latest former government technology leader to join the HR consultancy, after Jessica Salmoiraghi earlier this year moved to the company as a vice president. Salmoiraghi was previously chief acquisition officer at the General Services Administration, a role that she vacated in January.

Commenting on the appointment, GKG CEO and founder Gretchen McCracken said: “Throughout his career, JD has established himself as a government shared services expert with a focus on modernization activities that optimize government efficiency. Those skills are invaluable in our line of work.”

State Department’s security procurement division lacks integrated IT for ‘efficient’ contracting

The division that arranges security for the State Department’s domestic and foreign posts lacks integrated financial management and procurement IT systems for efficient contracting, according to its Office of Inspector General.

The IG found State’s Diplomatic Security Contracts Division staff manually enters data on critical security services and supplies, despite it slowing their work and making it difficult to follow internal controls.

Supplies and services DSCD contracts for include protection for State Department employees and facilities, new local guard posts oversees and armored vehicles for embassies.

“The continued lack of a centralized and integrated procurement and acquisitions system designed for acquisitions program management reduces the effectiveness of acquisition planning and management and increases the opportunities for errors,” reads the OIG’s unclassified report released Thursday.

Part of the problem is the Office of Acquisitions Management, of which DSCD is a part, hasn’t completed its analysis of State Department IT architecture to determine where procurement systems can be integrated. Secondly, the Bureau of Administration, of which AQM is a part, hasn’t implemented a knowledge management strategy for managing files on standard operating procedures, contracting templates and policy documents. OIG recommended the bureau do so, to which it agreed.

Lastly, the State Department’s Global Financial Management System (GFMS) and eFiling module of the Integrated Logistics Management System (ILMS) are managed by different bureaus. The Bureau of the Comptroller and Global Financial Services manages GFMS, while the Bureau of Administration’s Office of Logistics Management manages ILMS.

Because integrating the two systems is the bureaus’ responsibility and not DSCD’s, OIG recommended the two bureaus create a schedule of potential systems improvements based on the results of AQM’s completed IT architecture analysis. The Bureau of Administration agreed, and State Department employees told OIG several initiatives were already underway to strengthen systems integration.

DSCD’s IT issues are exacerbated by the fact it’s understaffed. OIG found 11 of 43 positions vacant at the time of its inspection, which created high workloads for employees across the division’s three branches: security, worldwide protective services, and local guard force and anti-terrorism assistance and training (LGF/ATA).

LGF averaged eight contracts per contracting officer (CO) across 105 contracts worth $2 billion, and together one security and one AGA CO handled a combined 91 contracts worth $6.8 billion.

COs struggled to complete contractor performance assessments and contract file management as a result, and the Office of the Procurement Executive hasn’t done a comprehensive staffing analysis for DSCD — though one is planned for fiscal 2021. OIG recommended the Bureau of Administration have OPE conduct the analysis, to which it agreed.

“Without such an analysis, the division’s current staffing and workload situation increases opportunities for mistakes, reduces effectiveness, limits DSCD’s capacity to implement innovative practices, and ultimately reduces the level and quality of AQM’s support to [the Bureau of Diplomatic Security].”

DOD tests new machine learning capabilities for JADC2

The Department of Defense recently concluded a round of tests of new machine learning technology that aims to increase data sharing between combatant commands.

The North American Aerospace Defense Command and Northern Command’s Global Information Dominance Experiment 3 (GIDE 3) brought 11 combatant commands, the Joint Artificial Intelligence Center (JAIC) and other tech leaders together July 8-15 at Peterson Air Force Base in Colorado to test the use AI in warfare.

The GIDE experiments aim to advance tech that will enable the DOD’s new concept of how it will fight in the future, where data from across military domains will be shared between machines and AI will assist commanders in their decision-making. The idea is captured in the department’s larger strategy of Joint All Domain Command and Control (JADC2), which is a guiding framework for many experiments like GIDE 3 and others across the services.

The GIDE 3 experiment showcased how the software tools designed for cross-combatant command collaboration, assessment, and decision-making can be used to enable more effective global logistics coordination, intelligence sharing and operations planning,” said Gen. Glen VanHerck, NORAD and NORTHCOM commander.

The third phase of the GIDE experiments focused on testing the JAIC’s new Matchmaker tool, designed to create defensive options by reading real-time data from the field and analysis assessments from analysts, according to a release from the Air Force. The tool is meant to provide a core capability within JADC2 of linking and analyzing data from across domains, replacing the current process of human analysts talking over radios with data often siloed between domains.

“By integrating more information from a global network of sensors and sources, using the power of AI and machine-learning techniques to identify the important trends within the data, and making both current and predictive information available to commanders, NORAD and USNORTHCOM are giving leaders around the globe more time to make decisions and choose the best options available, whether in competition, crisis or conflict,” VanHerck said. 

The first two GIDE experiments focused on how to coordinate early warning alerts between a handful of commands using AI and how to collaborate on logistics during war. The third test in mid-July was the final GIDE experiments hosted by Northern Command and NORAD, which has been an early adopter of AI and JADC2-related tech.

The two homeland defense commands also run the Pathfinder program, which uses AI to detect air threats like incoming missiles or even small drones.

TTS awards 4 contracts for governmentwide agile services

The General Services Administration’s Technology Transformation Services awarded blanket purchase agreements (BPAs) to four tech companies to streamline governmentwide procurement of agile development and IT support services.

Together the BPAs comprise the TTS Organization’s Transformation Agile Lifecycle (TOTAL) and allow TTS to issue task orders on behalf of other agencies.

TOTAL is part of a federal push to accelerate digital transformation through shared services at the same time the Technology Modernization Fund prioritizes investments in cybersecurity and IT modernization.

“Outside GSA, TTS will be able to rapidly implement contracts for Agile Delivery at the speed of need,” said Greg Godbout, director of digital services and business development at Fearless, which won one of the BPAs on July 15. “Inside GSA, TTS will use the same advantages to support and scale internal shared services like Login.gov.”

Fearless’ BPA alone is worth up to $120 million over the next five years and covers TOTAL’s Functional Area 3: lifecycle agile development focused on applications, data science, product delivery and quality assurance.

The other BPAs went to minority- and women-owned firms SemanticBits, Bixal and Amivero across three other functional areas:

  • Lifecycle agile development for infrastructure, security, system architecture, DevSecOps, and security assessments;
  • Lifecycle agile development for design, user research, user interface/user experience, information architecture, content strategy, accessibility, and prototyping and modeling; and
  • IT program support for customer account management, outreach, acquisitions, finance, operations, and project and program management.

Congressional report calls for DOD tech to be built at home

A congressional task force is urging the Department of Defense to better work with its partners to bring tech supply chains back within the U.S. and its allied nations.

The report from the Defense Critical Supply Chain Task Force points to protecting DOD’s supply chains as a critical but overlooked defense objective. The task force’s leaders Reps. Elissa Slotkin, D-Mich., and Mike Gallagher, R-Wisc., said the supply chain disruption caused by the coronavirus pandemic was a motivator behind the investigation into how DOD buys its critical supplies, including tech, during war.

“Last year, we all saw how the shortages of PPE cost American lives. We struggled to get things like masks and gloves for our healthcare workers, and it was obvious that our supply chains had failed,” Slotkin said.

For tech, like the microchips that power everything from computers to weapon systems, many of the base materials come from abroad. Some, like rare earth elements, come mostly from China — a situation that could snarl supply chains for DOD if it ends up in a war with the country.

“Throughout the pandemic, U.S. adversaries like China weaponized supply chain vulnerabilities in a way that threatened Americans’ health and security,” Gallagher said. “Our Defense Critical Supply Chain faces similar weaknesses that, if exploited, would impair our ability to compete with our adversaries and respond to crises. This problem will not age well.”

One of the key recommendations for how to work with allies to reshore critical tech capability supply chains is to use the National Technology and Industrial Base (NTIB) Council and create an international council. The councils should be used as forum to coordinate industrial policy among allies, the report recommends.

“The NTIB is an underutilized forum and should be leveraged to shape policy and partnerships with allies,” the report states. “To reduce reliance on adversaries and expand partnerships, the NTIB will need to help shape global policy.”

Shield AI buys company whose AI beat a fighter pilot in a dogfight

The company that built an artificial intelligence system advanced enough to beat a fighter pilot in a simulated dogfight has been acquired by defense tech startup Shield AI.

Heron Systems is a small team of researchers based around the Beltway that develops multi-agent deep reinforcement learning AI for defense applications. Shield focuses on “AI for maneuver,” selling AI-enabled drones and robots aimed at helping to keep troops out of harm’s way.

Purchasing Heron Systems will expand Shield’s business portfolio into the cockpits of the military’s airplanes.

“Truly special AI companies are incredibly rare assets in the defense market,” Shield AI co-founder and CEO Ryan Tseng said in a statement. “Heron has developed the most advanced AI-pilot for fighter aircraft in the United States.”

Shield did not disclose how much it paid for Heron, but the company will continue to operate as a wholly owned subsidiary of Shield.

“Shield AI enables us the opportunity and scale to accelerate the integration of our AI-pilot on a next generation fighter and UAS,” Brett Darcey, Heron Systems general manager, said in a statement. “What stood out about Shield AI for us – is that they’re really the only ones who have an operational AI pilot that can operate on the edge without GPS or comms, and this has been proven on combat operations.”

Heron put its AI to the test in the Defense Advanced Research Project Agency’s  AlphaDogfight, which pitted a trained F-16 pilot against several companies’ AI systems in a simulated dogfight. The event was set up as a contest, with Heron coming out on top beating the human pilot 5-0. While some were impressed by the results, others saw the tests as “AI theater,” showing off interesting technical achievements that won’t necessarily translate to real world applications.

NIST selects 18 tech companies for zero-trust demos

The National Institute of Standards and Technology selected 18 tech companies to demonstrate zero-trust security architectures as it drafts guidance for agencies and industry.

Companies will work with NIST‘s National Cybersecurity Center of Excellence to design and deploy architectures in accordance with Special Publication (SP) 800-207, as part of the Zero-Trust Architecture Project.

The project comes after the Biden administration issued a cybersecurity executive order in May requiring agencies to create plans to implement zero-trust security within 60 days.

“Implementing a zero-trust architecture has become a federal cybersecurity mandate and a business imperative,” said Natalia Martin, acting director of the NCCoE, in an announcement. “We are excited to work with industry demonstrating various approaches to implementing a zero-trust architecture using a diverse mix of vendor products and capabilities and share ‘how to’ guidance and lessons learned from the experience.”

The NCCoE plans to publish a NIST Cybersecurity Practice Guide in the SP 1800 series detailing the steps needed to implement reference designs at the end of the project.

Participating companies include: Amazon Web Services, Appgate, Cisco Systems, F5 Networks, FireEye, Forescout Technologies, IBM, McAfee, Microsoft, MobileIron, Okta, Palo Alto Networks, PC Matic, Radiant Logic, SailPoint Technologies, Symantec, Tenable, and Zscaler.

The selected vendors responded to a Federal Register notice to submit capabilities that aligned with the project’s desired solution characteristics. Each one was extended a cooperative research and development agreement, enabling them to participate in the consortium.

“We are all committed to collaborating and demonstrating different, practical approaches to implement a zero-trust architecture,” said Stephen Kovac, vice president of global government at Zscaler, in a statement. “As we know, no one solution fits every situation.”