惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Troy Hunt's Blog
Blog — PlanetScale
Blog — PlanetScale
Engineering at Meta
Engineering at Meta
F
Full Disclosure
Recorded Future
Recorded Future
The GitHub Blog
The GitHub Blog
Microsoft Security Blog
Microsoft Security Blog
GbyAI
GbyAI
博客园_首页
博客园 - 叶小钗
MongoDB | Blog
MongoDB | Blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Recent Commits to openclaw:main
Recent Commits to openclaw:main
H
Hacker News: Front Page
人人都是产品经理
人人都是产品经理
The Cloudflare Blog
博客园 - 司徒正美
Webroot Blog
Webroot Blog
Google DeepMind News
Google DeepMind News
Help Net Security
Help Net Security
Cloudbric
Cloudbric
PCI Perspectives
PCI Perspectives
有赞技术团队
有赞技术团队
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
TaoSecurity Blog
TaoSecurity Blog
L
Lohrmann on Cybersecurity
量子位
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
T
Tailwind CSS Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
B
Blog RSS Feed
Apple Machine Learning Research
Apple Machine Learning Research
大猫的无限游戏
大猫的无限游戏
P
Proofpoint News Feed
N
News and Events Feed by Topic
罗磊的独立博客
T
Threat Research - Cisco Blogs
Schneier on Security
Schneier on Security
T
Tor Project blog
IT之家
IT之家
M
MIT News - Artificial intelligence
S
Security @ Cisco Blogs
O
OpenAI News
AI
AI
S
Securelist
Simon Willison's Weblog
Simon Willison's Weblog
The Last Watchdog
The Last Watchdog
月光博客
月光博客
Security Archives - TechRepublic
Security Archives - TechRepublic
L
LINUX DO - 热门话题

MeriTalk

Eliminating Silos in IT/OT Cybersecurity Is a Funding Challenge, Not a Technical One The FedRAMP High Supply Crisis Is a Federal Security Problem – Not a Procurement Footnote How More Tightly Focused Software Development Initiatives Will Unlock Innovation Across Government Transforming Federal Cybersecurity Through Private Sector Innovation Evolving Zero Trust and Embedded AI – Federal Government Cybersecurity Predictions for 2026 Unlocking AI’s Potential in High-Assurance Environments Accelerate Agentic AI in the Federal Government: Top Takeaways Why Congress Must Reauthorize the Technology Modernization Fund Make Cybersecurity a Key Ingredient of Modernization How Spectro Cloud’s PaletteAI Secure helps agencies scale AI securely, compliantly, and confidently Fix the Foundation: How Hybrid Cloud and Trusted Data Enable Government AI New Google Workspace Cost-Saving Offer Available for U.S. Federal Government Reinventing FedRAMP in the Age of AI Meeting Evolving State and Local Cyber Threats AI Is the Solution to Stop AI Data Theft Enhancing U.S. Government Operations with AI and Human-Centered Design How FinOps Can Help Agencies Slash Cloud Costs in 5 Steps Will Quantum Computing Weaken or Strengthen Cybersecurity of Federal Systems? Improving Citizen and Federal Employee Experience with Virtual AI Assistants Strategies for Securing the Federal Supply Chain Reframing the U.S. Government’s Approach to Cybersecurity Oversight Three Steps Agencies Can Take to Meet Government’s AI Requirements The Impact of NIST’s PQC Standardization on the Federal Cybersecurity Ecosystem Generative AI is Revolutionizing Federal Government Operations NIST’s new PQC Algorithms and What They Mean for Federal Agencies Addressing the U.S. Quantum Labor Shortage Before It’s Too Late How a Community Vigil Approach and Secure by Design are Critical to Software Cybersecurity Addressing the Talent Shortage: How Digital Government Improves Satisfaction, Retention Here’s What We Can Learn (and Do) About Cybercrime from FBI’s Latest Internet Crime Report Implementing AI Assurance Safeguards Before OMB’s December Deadline The Next AI Wave: Quantum AI CDM’s Evolution to Non-Traditional Technology: Why Now and How Will it Succeed? Customer Expectations Require Agencies to Raise the Bar on Customer Experience, Report Shows Applying for Government Benefits Shouldn’t Be Difficult When It Comes to Identity Verification Four Federal Software Supply Chain Security Trends to Watch FedRAMP Baseline Transition Points to OSCAL-Native Tools What Zero Trust Means for Modern Government: Best Practices for Key Tenets Four Ways to Handle the IT Funding Crunch Agencies Need to Get Creative to Fill the Cyber Workforce Gap Customer Identity trends report shows control trumps convenience Federal Agencies Making Strides Toward Sustainability and Climate Action Executive Order 14028 | Improving the Nation’s Cybersecurity Depends on Data | All Data is Security Data Applying Geospatial Intelligence, AI/ML to Climate Change Challenge My Cup of IT: Angry at Arthritis, Hunting for Cures How the Federal Government Can Help Combat a Fragmented Internet Accelerating Cybersecurity for US Critical Infrastructure Getting in on the Ground Floor of the ‘New Observability’ Comply-to-Connect is Key to Zero Trust for DoD How Will Upcoming Cryptocurrency Regulations Affect Industry? My Cup of IT: Cup Cake for Kushner? Launching a New Era of Government Cloud Security Managing IT Complexity in Federal Agencies Agencies Must Modernize Zero Trust Approaches to Achieve Optimal Protection Five Essential Metrics for Measuring Federal Government CX Unlocking the Benefits of 5G and Beyond The Federal Factory of the Future: How AI is Transforming Manufacturing The Quantum Impact on Cyber How Next-Gen Computers Will Transform What’s Possible for Federal Government Agencies Must Take an Authentic Approach to Synthetic Data Biometrics and Privacy: Finding the Perfect Middle Ground Two-Way Street: Why Officials and Constituents Are Equally Responsible for Securing the Midterms The “Programmable World” Will Bring the Best of the Virtual World Into the Physical One Cyberattacks are a Common Occurrence and the Costs are Higher Than Ever Increasing Equity Through Data and Customer Experience The AI Edge: Why Edge Computing and AI Strategies Must Be Complementary How Metaverses and Web3 can Reshape Government Four Emerging Technology Trends set to Impact Government Most 5G Enables AI at the Edge Plugging Cyber Holes in Federal Acquisition Resilient Critical Infrastructure Starts with Zero Trust The Evolution of Government Tech Procurement Under CMMC 2.0 Zero Trust Requires Continuous, Tested Security for Federal Agencies How Multi-INT Fusion Accelerates Mission Intelligence for Real-Time Decision Advantage Three Things to Consider for Responsible AI in Government Legislation, White House Orders Show Agencies Opportunity for Hybrid Cloud Creating an Effective Framework for DoD’s Software Factories Realizing Upsides for Digital Security in the Hybrid Workplace A Future With AI and ML: The Power of Workforce Education Five Tips to Begin MFA Integration and Embrace Zero Trust The Vital Intersection Between Equity and Digital Transformation Equity as a Platform: Applying a New Mindset to Scale Innovation Harnessing the Right Data for Evidence-Based Equity From EO to Action: Human Factors of Enabling a Cyber Safety Review Board For Equity in Government Services, It’s Time to Change the Paradigm Critical Questions to Ask When Considering Explainable AI (XAI) for Your Federal Agency The Telework Model for Government: COVID Lessons for Building an Effective Workforce DevSecOps: 4 Steps for Mitigating the Next Cyber Attack in Your Federal IT Environment Better Cyber Hygiene Helps, but Federal Security Needs SASE Lift DoD, Feds Plot Top Cyber, Cloud Priorities for 2022 Cloud-Native Government: How to Transform With Intention DoD and VA Health Networks Face Growing Threat From Medical-Device Vulnerabilities New Federal Cybersecurity Requirements: How Agencies Should Implement a Zero Trust Architecture Protecting Our Nation Through Big Data Analytics Three Ways COVID-19 Altered Federal, State IT Budget Allocations Ransomware is More Than a Cybersecurity Issue From Me to We: Take the Mission Further With Multiparty Systems Anywhere, Everywhere: Integrating Your Virtual Workplace ‘I, Technologist’: Empowering Innovators in the Federal Workforce Mirrored World: Digital Twins Report for Duty Across Government Stack Strategically: Rearchitecting Government for What’s Next
Balancing Security and Efficiency: The Federal IT Dilemma in the AI Era
MeriTalk Sta · 2025-06-03 · via MeriTalk

By Erich Kron, security awareness advocate at KnowBe4

The federal IT landscape is undergoing a significant transformation. Budget constraints and staffing reductions are pushing agencies to do more with less. For chief information officers (CIOs) and senior policymakers, the challenge is clear: maintain operational excellence and strong cybersecurity defenses while embracing tools that boost efficiency and watching the budget. Enter artificial intelligence. It is both a powerful ally and a new threat vector.

The Fiscal Reality: Less Money, Fewer People

Across federal agencies, tightening budgets are becoming the norm. Mandates to streamline operations are happening while dealing with workforce attrition due to retirements and hiring freezes. This leaner operational model places enormous pressure on IT leadership. Maintaining the same, or even increasing, levels of security and performance with fewer resources requires a new way of thinking.

Agencies are beginning to adjust by automating routine tasks, optimizing service delivery, and consolidating infrastructure. But efficiency gains alone don’t eliminate risk. In fact, if not carefully implemented, they can introduce new vulnerabilities. This is not a new battle, funding is almost always tight in governmental agencies at all levels, however the focus on cost cutting and reducing the size of government has introduced some significant new hurdles.

Threat Landscape: Shifting Risks, New Motivations

Cyberthreats have evolved beyond opportunistic ransomware and other malware. Nation-state actors, cybercriminal syndicates, and hacktivist groups now pursue broader goals: data theft, surveillance, disruption, and even political leverage. Federal systems – which are repositories of sensitive personal, operational, and national security data – remain high-value targets.

AI adds a new twist to this already complex threat matrix. It’s not just a tool for defenders; it’s becoming a weapon for attackers:

  • Data Exploitation at Scale: With AI, adversaries can quickly analyze massive datasets from public breaches to craft highly targeted phishing or social engineering campaigns.
  • Deepfake Deception: Fake audio and video are being used to impersonate trusted voices in virtual meetings or approval workflows, enabling financial fraud or data exfiltration.
  • Automation of Malice: AI-driven malware can adjust its behavior in real time, evading traditional signature-based defenses.

AI on the Defense: Smarter Shields

Despite the risks, the same technology also provides federal IT leaders with unmatched advantages:

  • Threat Detection and Response: AI enhances anomaly detection, enabling agencies to identify suspicious activity sooner and react much faster.
  • Automated Triage: Routine alerts can be analyzed, filtered and escalated more accurately, allowing overburdened security teams to focus on the highest-priority incidents.
  • Predictive Insights: Machine learning models can forecast potential vulnerabilities based on system behaviors and historical data.

Navigating the AI Paradox

CIOs must strike a delicate balance. Embracing AI is not optional. It is essential that AI be employed in order to survive in today’s cyber and budgetary climate. But as adoption grows, so does the attack surface. That’s why a layered security approach is more critical than ever:

  • Human + Machine: Security awareness must evolve. AI-powered threats demand an educated workforce capable of spotting deception, especially in high-stakes environments. A robust human risk management program is needed to address the threats from social engineering and human error.
  • Policy and Governance: Clear guidelines on AI use, ethical boundaries, and incident response protocols are essential to avoid misuse and ensure accountability.
  • Cross-Sector Collaboration: Federal agencies cannot do it alone. Sharing threat intelligence and aligning strategies with private sector counterparts can help mitigate systemic risk.

The Road Ahead

There is no silver bullet, but there is a path forward. By investing in both technology and people, and adopting a realistic mindset about efficiency and security trade-offs, federal CIOs can lead the way through this transition. Considerations must be made about the most efficient use of AI in their environments and where human oversight should be in place. AI is not the enemy, but ungoverned, it could become one.

Erich Kron is a security awareness advocate at KnowBe4. He is a veteran information security professional with over 25 years of experience in the medical, aerospace manufacturing, and defense fields, an author, and a regular contributor to cybersecurity industry publications. He is the former security manager for the US Army’s 2nd Regional Cyber Center-Western Hemisphere and holds CISSP, CISSP-ISSAP, SACP, and many other certifications.