惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

L
LangChain Blog
The GitHub Blog
The GitHub Blog
Recent Announcements
Recent Announcements
MyScale Blog
MyScale Blog
P
Proofpoint News Feed
S
Security @ Cisco Blogs
N
News and Events Feed by Topic
H
Hacker News: Front Page
Attack and Defense Labs
Attack and Defense Labs
S
Secure Thoughts
Microsoft Security Blog
Microsoft Security Blog
N
Netflix TechBlog - Medium
U
Unit 42
Stack Overflow Blog
Stack Overflow Blog
T
Threat Research - Cisco Blogs
Google Online Security Blog
Google Online Security Blog
Spread Privacy
Spread Privacy
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
L
LINUX DO - 热门话题
T
Tenable Blog
博客园 - 叶小钗
D
DataBreaches.Net
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园_首页
人人都是产品经理
人人都是产品经理
aimingoo的专栏
aimingoo的专栏
C
Check Point Blog
博客园 - 三生石上(FineUI控件)
量子位
P
Proofpoint News Feed
H
Help Net Security
Blog — PlanetScale
Blog — PlanetScale
宝玉的分享
宝玉的分享
Recorded Future
Recorded Future
The Register - Security
The Register - Security
F
Fortinet All Blogs
Engineering at Meta
Engineering at Meta
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Last Week in AI
Last Week in AI
S
Schneier on Security
V
Vulnerabilities – Threatpost
雷峰网
雷峰网
Microsoft Azure Blog
Microsoft Azure Blog
G
GRAHAM CLULEY
G
Google Developers Blog
月光博客
月光博客
V
V2EX
T
Troy Hunt's Blog
A
Arctic Wolf

MeriTalk

The FedRAMP High Supply Crisis Is a Federal Security Problem – Not a Procurement Footnote How More Tightly Focused Software Development Initiatives Will Unlock Innovation Across Government Transforming Federal Cybersecurity Through Private Sector Innovation Evolving Zero Trust and Embedded AI – Federal Government Cybersecurity Predictions for 2026 Unlocking AI’s Potential in High-Assurance Environments Accelerate Agentic AI in the Federal Government: Top Takeaways Why Congress Must Reauthorize the Technology Modernization Fund Make Cybersecurity a Key Ingredient of Modernization How Spectro Cloud’s PaletteAI Secure helps agencies scale AI securely, compliantly, and confidently Fix the Foundation: How Hybrid Cloud and Trusted Data Enable Government AI New Google Workspace Cost-Saving Offer Available for U.S. Federal Government Reinventing FedRAMP in the Age of AI Balancing Security and Efficiency: The Federal IT Dilemma in the AI Era Meeting Evolving State and Local Cyber Threats AI Is the Solution to Stop AI Data Theft Enhancing U.S. Government Operations with AI and Human-Centered Design How FinOps Can Help Agencies Slash Cloud Costs in 5 Steps Will Quantum Computing Weaken or Strengthen Cybersecurity of Federal Systems? Improving Citizen and Federal Employee Experience with Virtual AI Assistants Strategies for Securing the Federal Supply Chain Reframing the U.S. Government’s Approach to Cybersecurity Oversight Three Steps Agencies Can Take to Meet Government’s AI Requirements The Impact of NIST’s PQC Standardization on the Federal Cybersecurity Ecosystem Generative AI is Revolutionizing Federal Government Operations NIST’s new PQC Algorithms and What They Mean for Federal Agencies Addressing the U.S. Quantum Labor Shortage Before It’s Too Late How a Community Vigil Approach and Secure by Design are Critical to Software Cybersecurity Addressing the Talent Shortage: How Digital Government Improves Satisfaction, Retention Here’s What We Can Learn (and Do) About Cybercrime from FBI’s Latest Internet Crime Report Implementing AI Assurance Safeguards Before OMB’s December Deadline The Next AI Wave: Quantum AI CDM’s Evolution to Non-Traditional Technology: Why Now and How Will it Succeed? Customer Expectations Require Agencies to Raise the Bar on Customer Experience, Report Shows Applying for Government Benefits Shouldn’t Be Difficult When It Comes to Identity Verification Four Federal Software Supply Chain Security Trends to Watch FedRAMP Baseline Transition Points to OSCAL-Native Tools What Zero Trust Means for Modern Government: Best Practices for Key Tenets Four Ways to Handle the IT Funding Crunch Agencies Need to Get Creative to Fill the Cyber Workforce Gap Customer Identity trends report shows control trumps convenience Federal Agencies Making Strides Toward Sustainability and Climate Action Executive Order 14028 | Improving the Nation’s Cybersecurity Depends on Data | All Data is Security Data Applying Geospatial Intelligence, AI/ML to Climate Change Challenge My Cup of IT: Angry at Arthritis, Hunting for Cures How the Federal Government Can Help Combat a Fragmented Internet Accelerating Cybersecurity for US Critical Infrastructure Getting in on the Ground Floor of the ‘New Observability’ Comply-to-Connect is Key to Zero Trust for DoD How Will Upcoming Cryptocurrency Regulations Affect Industry? My Cup of IT: Cup Cake for Kushner? Launching a New Era of Government Cloud Security Managing IT Complexity in Federal Agencies Agencies Must Modernize Zero Trust Approaches to Achieve Optimal Protection Five Essential Metrics for Measuring Federal Government CX Unlocking the Benefits of 5G and Beyond The Federal Factory of the Future: How AI is Transforming Manufacturing The Quantum Impact on Cyber How Next-Gen Computers Will Transform What’s Possible for Federal Government Agencies Must Take an Authentic Approach to Synthetic Data Biometrics and Privacy: Finding the Perfect Middle Ground Two-Way Street: Why Officials and Constituents Are Equally Responsible for Securing the Midterms The “Programmable World” Will Bring the Best of the Virtual World Into the Physical One Cyberattacks are a Common Occurrence and the Costs are Higher Than Ever Increasing Equity Through Data and Customer Experience The AI Edge: Why Edge Computing and AI Strategies Must Be Complementary How Metaverses and Web3 can Reshape Government Four Emerging Technology Trends set to Impact Government Most 5G Enables AI at the Edge Plugging Cyber Holes in Federal Acquisition Resilient Critical Infrastructure Starts with Zero Trust The Evolution of Government Tech Procurement Under CMMC 2.0 Zero Trust Requires Continuous, Tested Security for Federal Agencies How Multi-INT Fusion Accelerates Mission Intelligence for Real-Time Decision Advantage Three Things to Consider for Responsible AI in Government Legislation, White House Orders Show Agencies Opportunity for Hybrid Cloud Creating an Effective Framework for DoD’s Software Factories Realizing Upsides for Digital Security in the Hybrid Workplace A Future With AI and ML: The Power of Workforce Education Five Tips to Begin MFA Integration and Embrace Zero Trust The Vital Intersection Between Equity and Digital Transformation Equity as a Platform: Applying a New Mindset to Scale Innovation Harnessing the Right Data for Evidence-Based Equity From EO to Action: Human Factors of Enabling a Cyber Safety Review Board For Equity in Government Services, It’s Time to Change the Paradigm Critical Questions to Ask When Considering Explainable AI (XAI) for Your Federal Agency The Telework Model for Government: COVID Lessons for Building an Effective Workforce DevSecOps: 4 Steps for Mitigating the Next Cyber Attack in Your Federal IT Environment Better Cyber Hygiene Helps, but Federal Security Needs SASE Lift DoD, Feds Plot Top Cyber, Cloud Priorities for 2022 Cloud-Native Government: How to Transform With Intention DoD and VA Health Networks Face Growing Threat From Medical-Device Vulnerabilities New Federal Cybersecurity Requirements: How Agencies Should Implement a Zero Trust Architecture Protecting Our Nation Through Big Data Analytics Three Ways COVID-19 Altered Federal, State IT Budget Allocations Ransomware is More Than a Cybersecurity Issue From Me to We: Take the Mission Further With Multiparty Systems Anywhere, Everywhere: Integrating Your Virtual Workplace ‘I, Technologist’: Empowering Innovators in the Federal Workforce Mirrored World: Digital Twins Report for Duty Across Government Stack Strategically: Rearchitecting Government for What’s Next
Eliminating Silos in IT/OT Cybersecurity Is a Funding Challenge, Not a Technical One
MeriTalk Sta · 2026-04-15 · via MeriTalk

By: Tom Guarente, vice president of external and government affairs, Armis

In light of ever-increasing cyber threats from nation-state adversaries, including major spying campaigns like Salt Typhoon, the need for strong cybersecurity protection has never been more urgent. Given the reported deployment of offensive cyber measures in U.S. military operations, we should expect adversaries to counter with their own deployments.

Noting that the recently released White House “Cyber Strategy for America” appropriately focuses on securing critical infrastructure, our current reality of converged technologies necessitates a more holistic and proactive security model. While this has been an elusive goal because the federal government often lacks the mechanisms needed to fund and deploy effective security tools across both IT and operational technology (OT), the strategy appears to take a much-needed approach. While the government has traditionally focused most of its cyber operations on IT, it has begun to recognize the need to address OT, which has not been nearly as well protected.

Agencies are often stymied in their attempts to broadly apply cybersecurity across both IT and OT due to funding silos and other bureaucratic hurdles. Organizational silos often prevent government security leaders from acquiring the same cybersecurity tools as Fortune 500 enterprises. Not only are agencies siloed from one another, but organizations that manage their own cyber initiatives often find it difficult to share lessons with peers in other branches of the same department.

For example, we have seen one organization with a very mature Facilities Related Control System (an OT system used for building management, controlling electricity operations, etc.) that had been broken in half and organized by geography, each part with its own funding lines, initiatives, contract vehicles and products. This somewhat random division has made it difficult for leadership to apply the necessary tools and controls across the organization to protect systems and users from cyber threats.

Within organizations, divisions also exist between components responsible for IT (often the CIO’s team) and those responsible for OT (often the CSO’s team). These silos prevent organizations from procuring common tools for cybersecurity protection across the entire enterprise. Even when the need for such tools has been identified, organizations often cannot identify the funding mechanisms to justify a procurement. OT is segregated from the IT side with different funding lines, preventing buyers with access to IT-related funding from using it to buy an OT security tool – at least not without navigating a drastic amount of red tape to get that procurement across the finish line. And if they do, purchasing multiple point solutions introduces more complexity into an environment.

Policy decrees and executive orders mandating OT security improvements are essential catalysts, yet they frequently falter at the implementation level due to an “unfunded mandate” gap. While higher-level directives establish necessary requirements, they rarely provide the financial or structural frameworks required by lower-level offices to execute them. To be effective, these orders must evolve beyond compliance checklists to include comprehensive frameworks for longevity and continuity. This requires a dual-track funding model that covers initial capital for acquisition as well as dedicated, multi-year budgetary support for operational and expert staffing.

To bolster at-scale deployment, the plan should also include support structures, such as mobile “tiger teams” or shared-service models that provide specialized technical expertise to under-resourced offices, ensuring that OT security solutions are not only deployed but sustained throughout their lifecycle.

Bridging the gap between policy and protection means that agencies need to establish a standardized baseline for assessing converged technologies well before deployment. However, these baseline requirements will remain toothless without a radical overhaul of the procurement and authorization pipeline. Currently, processes like FedRAMP and DoD-specific cybersecurity authorizations are often opaque and sluggish, offering little transparency into optimization or timelines.

This state of gridlock suggests that these authorization bodies are understaffed and under-resourced – themselves victims of the broader funding crisis, rendering high-level security talking points irrelevant if the administrative machinery cannot process the solutions at the speed of the threat. If these authorizations are to remain a mandatory prerequisite, the FedRAMP process should adopt a model defined by clear milestones and predictable iterative outputs.

To secure critical infrastructure at scale, agency leaders must transition from ad-hoc procurement to programmatic, congressionally-funded initiatives. An effective catalyst for modernization could be the establishment of new enterprise-wide contract vehicles similar to the Global Enterprise Modernization Software and Support (GEMSS) contract, awarded in 2022. That contract gave a broad range of military organizations unlimited access to software licenses, technical support and network modernization services. By pre-negotiating pricing and centralizing funding at the department level, these types of agreements can lower the barrier to entry for individual agencies and offices.

When solution sets are structured, priced and funded for “too good to miss” enterprise adoption, they give mission owners the leverage they need to bypass traditional silos. Ultimately, these large-scale programs do more than cut costs. They promote a standardized security posture that becomes an indispensable utility, ensuring that OT defense is treated as a permanent capability.

Talking points are not enough. Agency leaders have to put money behind what they say their priorities are and increase efficiencies in delivering on those priorities when it comes to securing both IT and OT environments. We should all work together to operationalize the Cyber Strategy for America and create a new approach to protecting our nation.