エピソード

  • Security Compliance Checklists vs. Commander's Intent
    2026/09/14

    The government is great at security governance — but that isn't the same as being secure. In Episode 18 of The GIST of Govt IT, Brian and Sean sit down with Ian Kelly of Cloudflare, a self-described liberal arts major turned 15-year Google veteran turned public-sector technologist, to talk about closing the gap between the checkbox and the outcome. The conversation digs into why the exploit window has collapsed from weeks to roughly five minutes, the pivot from point-in-time compliance to continuous, risk-based security, and AI governance before the horse leaves the barn. Sean and Ian also get into edge compute, the CBP conversational video bot built for the FIFA games, infrastructure as code for repeatable accreditation, and the emerging discipline of AEO — optimizing content so agents, not just humans, can use it. Plus, Cloudflare's FedRAMP High authorization and IL4 intentions, a wall of lava lamps as a cryptographic entropy source, and three Monday-morning takeaways, not to mention KatEye makes an appearance.


    Resources Mentioned in This Episode

    Featured Guest

    • Ian Kelly, Senior Director of Solutions Engineering, Cloudflare Public Sector

    • Cloudflare Public Sector

    • Cloudflare FedRAMP High authorization announcement

    Cloudflare Capabilities Discussed

    • Cloudflare Edge Compute

    • Cloudflare AI Gateway (visibility, governance, cost control)

    • Cloudflare SASE / Zero Trust

    • Cloudflare's LavaRand entropy wall (true randomness)

    Compliance, Standards & Frameworks

    • FIPS 140-3 validated cryptography

    • FIPS 203 and NIST post-quantum cryptography

    Also Mentioned

    • KATSEYE

    • Military Grade Metal Podcast

    Related Content

    • GIST360 Webinar: Rethinking Command and Control Resiliency at the Edge

    The Hosts & Show

    • Swish

    • GIST 360

    CONNECT WITH US

    Got an idea for a future episode? Want to be a guest? Let us know.

    Brian Lake - blake@swishdata.com

    Sean Applegate - sapplegate@swishdata.com

    Subscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.


    続きを読む 一部表示
    46 分
  • The LRA is Here and the Clock is Ticking!
    2026/08/31

    It's here. On August 20, CISA dropped the Logging Reference Architecture (LRA) a practitioner's guide that operationalizes OMB M-26-14 and the countdown just got real. In this episode of The GIST of Govt IT, Brian and Sean break down the aggressive timeline it sets: agencies have 90 days to inventory their environment and submit a plan in Cyberscope (the week before Thanksgiving), then about 30 more to hit Baseline 1 maturity (the week before Christmas). Surprisingly, or not, Sean's read is refreshingly positive, this guide was written by practitioners for practitioners, with concrete advice, outcome-focused questions to ask your teams, and clear thresholds: 70% of assets inventoried, 50% logging coverage, 50% actionable alerts, six-month retention.

    The conversation digs into why IoT and OT are the hard part (segmented networks, third-party-managed devices, systems you can't actively scan), why the LRA deliberately doesn't mandate AI, and a practical path forward: assign a single LRA owner, reconcile your CMDB against your property book, deploy passive OT listening kits rather than scanning fragile systems, and use end-of-fiscal-year funds now to close gaps you can't fill over the holidays. The clock is ticking and agencies are going to have to build the airplane while they fly.


    Resources Mentioned in This Episode

    The Core Documents

    • CISA Logging Reference Architecture (LRA), released August 20

    • OMB M-26-14 (the logging mandate the LRA operationalizes)

    • CyberScope (where agencies submit their plans)

    The Baseline 1 Thresholds

    • Inventory visibility: 70% of assets captured in a centralized inventory

    • Collection coverage: 50% of inventoried assets logging

    • Collection operations: 50% of logs producing actionable alerts

    • Data retention: minimum six months (per M-26-14; the LRA guide notes a slightly different figure)

    • Timeline: plan ~Nov 18, Baseline 1 ~mid-December

    Frameworks & Technical References

    • MITRE ATT&CK (adversary behavior models)

    • CISA Zero Trust Maturity Model

    • NIST SP 800-92 (log management guidance)

    The Threat Backdrop

    • DOJ/FBI seizure of Chinese state-sponsored hacking infrastructure (August 26)

    • CISA advisory on edge-device compromise and lateral movement

    • Anthropic and OpenAI on the narrowing window to defend against AI cyber threats

    From Swish / GIST 360

    • Swish LRA planning assessmen

    • “When the Perimeter Disappears” breakfast briefing recap

    Related Episodes

    • Episode 13: Fed Christmas in July? The OMB M-26-14 Holiday Rush Begins!

    • Episode 15: Billion Dollar Pilots and Boil Water Notices: Securing OT Environments

    • Episode 7: Iran Came for the Dams and We Got Lucky: Frontline Insights into the OT Fight

    The Hosts & Show

    • Swish

    • GIST 360

    CONNECT WITH US

    Got an idea for a future episode? Want to be a guest? Let us know.

    Brian Lake - blake@swishdata.com

    Sean Applegate - sapplegate@swishdata.com

    Subscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.


    続きを読む 一部表示
    33 分
  • Federal AI Wants to Fly but Data Weighs it Down
    2026/08/24

    Somewhere between 60% and 80% of federal AI projects have stalled out and the common denominator almost always traces back to the data. In Episode 16 of The GIST of Govt IT, Brian and Sean sit down with Matt Lawson, Director of Solution Engineering for NetApp Federal, to unpack what it actually takes to build a data foundation that lets AI succeed. Matt's thesis is that projects keep stalling because teams can't get the right data, in the right place, at the right cost.

    The conversation digs into data gravity (you can't move petabytes overnight, and you can't beat the speed of light), the take-the-data-to-the-model vs. bring-the-model-to-the-data debate (answer: you need both), and the copy-of-a-copy sprawl that quietly wrecks both budgets and data authority. Matt walks through ideas that change the math, and the guys close out on post-quantum cryptography and why “harvest now, decrypt later” makes it a today problem, not a tomorrow problem. Plus Matt on why he always chooses the blue pill.

    Featured Guest

    • Matt Lawson, Director of Solution Engineering, NetApp Federal

    • NetApp Public Sector

    The “Why AI Projects Fail” Data

    • The concept of data gravity

    AI, RAG & Partners

    • Retrieval-Augmented Generation (RAG) explained

    • Apache Kafka (real-time event streaming)

    Post-Quantum Cryptography

    • NIST Post-Quantum Cryptography Standards (FIPS 203/204/205)

    • OMB M-23-02 (migrating to post-quantum cryptography)

    The Monday-Morning Playbook (Matt Lawson)

    • 1. Catalog your data — know what data sets you actually have

    • 2. Plan for a federated environment — data will live in many places, some not even yours

    • 3. Design for security from day one — immutability, ransomware recovery, and PQC can't be bolted on later

    Related Episodes

    • Episode 9: Quad Charts Be Damned: Data Meets the Mission

    Upcoming Event

    • GIST 360 Breakfast Briefing with NetApp — Washington, DC, November 10

    The Hosts & Show

    • Swish

    • GIST 360 Program

    CONNECT WITH US

    Got an idea for a future episode? Want to be a guest? Let us know.

    Brian Lake - blake@swishdata.com

    Sean Applegate - sapplegate@swishdata.com

    Subscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.


    続きを読む 一部表示
    43 分
  • Billion Dollar Pilots and Boil Water Notices: Securing OT Environments
    2026/08/11
    “The only thing that isn't digital in the Department of War is the bayonet.” That line from DoW CISO Aaron Bishop set the tone for a standing-room panel Brian moderated in Washington, DC, with partners at Armis. In Episode 15 of The GIST of Govt IT, Brian and Sean bring listeners the lessons learned from that breakfast briefing on securing the converged IT, IoT, and OT enterprise — featuring Bishop, Department of Transportation CISO Dr. Justin Ubert, and Armis’ Director of Civilian Strategy Matthew Shelbetter.The conversation digs into the central insight all three panelists shared: the hardest part of convergence isn't the technology, it's the culture. IT security teams and OT operators speak different languages, hold different priorities (availability and safety first), and have to learn to meet in the middle — often starting with nothing more sophisticated than a room, a tabletop exercise, and a lot of pizza and Mountain Dew.Brian and Sean also unpack Bishop's concept of mission-relevant terrain for cybersecurity, why attack path mapping and asset discovery are the foundation, how to pay for OT security when the funding is scattered (identity-for-agents riding on AI budgets, consensus-building at HHS, and Bishop's $1B OT security pilot anchored to a zero trust framework), and why the community — local utilities, mayors, volunteer responders, partners like Dominion Energy — has to be in the room before the house is on fire. Plus, three Monday-morning takeaways straight from the panelists.The Panel & Blog• When the Perimeter Disappears Breakfast Briefing Recap Blog • Aaron Bishop, CISO, Department of War• Dr. Justin Ubert, CISO, Department of Transportation• Matthew Shelbetter, Director of Civilian Strategy, Armis • Armis FederalPolicy & Frameworks Referenced• OMB M-26-14 and the CISA Logging Reference Architecture : https://www.whitehouse.gov/omb/memoranda/• DoD OT Zero Trust Reference Architecture• CISA Zero Trust Maturity Model• GSA “Eliminate, Automate, and Optimize” playbook for AI/agents• NIST SP 800-82 — Guide to Operational Technology SecurityThe Threat Backdrop• CISA advisory on Iranian-affiliated actors targeting water and critical infrastructure• CISA Industrial Control Systems resources• EPA Water and Wastewater cybersecurity resourcesThe Three Monday-Morning Takeaways• Dr. Justin Ubert: Get the disparate teams — red, blue, OT, leadership — in the same room• Matthew Shelbetter: Talk to the operators; educate leadership and frontline managers, then get the right platforms and partners• Aaron Bishop: Start with asset discovery — know what you have, where it is, and who owns itRelated Episodes• Episode 14: A Pause, Not a Pass on CMMC• Episode 13: Fed Christmas in July? The OMB M-26-14 Holiday Rush Begins!• Episode 7: Iran Came for the Dams and We Got Lucky: Frontline Insights into the OT FightUpcoming Events• Upcoming GIST 360 webinars and fall breakfast briefingsThe Hosts & Show• Swish• GIST 360CONNECT WITH USGot an idea for a future episode? Want to be a guest? Let us know.Brian Lake - blake@swishdata.comSean Applegate - sapplegate@swishdata.comSubscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.
    続きを読む 一部表示
    32 分
  • A Pause, Not a Pass on CMMC
    2026/07/21
    On July 13, the Department of War hit pause on one of the most consequential compliance regimes in the defense industrial base. In Episode 14 of The GIST of Govt IT, Brian and Sean break down the suspension of CMMC Phase II — the third-party assessment requirement that was set to take effect November 10 — and what it actually means for the thousands of contractors caught in the middle. Sean's message is blunt: this is a pause, not a repeal. The requirement to protect controlled unclassified information isn't going anywhere, and the smart move is to keep marching toward NIST SP 800-171 compliance regardless of what the 60-day CMMC Reform Task Force recommends. The conversation digs into the real economics that triggered the review, the False Claims Act lawsuits already settling in the six-to-eight-figure range for contractors who attested to compliance they didn't have, why ISO 27001 is the closest on-ramp for commercial companies new to the space, and a clear Monday-morning playbook. Plus, CISA Director Nick Andersen's hacker name (hint: he's a Matrix fan).Resources Mentioned in This EpisodeThe Core StoryDepartment of War release: "Forging the Arsenal of Freedom: DoW Suspends CMMC Phase II Requirements" (July 13)Office of Industrial Base Growth version of the announcementFederal News Network coverageThe CMMC Reform Task Force RFI (responses due 12:00 PM ET, Friday, August 14) — posted on SAM.gov Legal & Advisory AnalysisMorgan Lewis — "Cybersecurity Obligations Remain"Crowell & Moring — DFARS obligations & contractor action stepsGreenberg Traurig — the July 13 memoranda explained Standards & Frameworks ReferencedNIST SP 800-171 Rev. 2 (protecting Controlled Unclassified Information) NIST SP 800-171 Rev. 3CMMC Program overview (DoD CIO)ISO/IEC 27001 (the commercial on-ramp Sean recommends)DFARS 252.204-7012 (safeguarding covered defense information)FIPS 140 validated encryptionCompliance & Assessment ConceptsSPRS (Supplier Performance Risk System) — where self-assessments are postedDIBCAC (Defense Industrial Base Cybersecurity Assessment Center)C3PAO (CMMC Third-Party Assessment Organizations) via the Cyber ABThe False Claims Act AngleDOJ Civil Cyber-Fraud InitiativeThe False Claims Act (DOJ overview)The Hosts & ShowSwishGIST 360CONNECT WITH USGot an idea for a future episode? Want to be a guest? Let us know.Brian Lake - blake@swishdata.comSean Applegate - sapplegate@swishdata.comSubscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.
    続きを読む 一部表示
    24 分
  • Fed Christmas in July? The OMB M-26-14 Holiday Rush Begins!
    2026/07/13
    Level One by Christmas. Level Two by Valentine's Day. Level Three by Independence Day. That's the OMB M-26-14 logging mandate clock federal agencies are now racing against — and if you don't want to spend your holidays at the office, it's time to start planning now! In Episode 13 of The GIST of Govt IT, Brian and Sean dig into OMB M-26-14 on the eve of Sean's fireside chat with CISA Director Nick Andersen. Sean breaks down what actually changed: the shift from long-term log hoarding (30 months of cold retention) to an outcomes-driven model focused on defending the cyberspace effectively, and the dramatic expansion of scope to include IoT and operational technology — the unmanaged, line-of-business-owned, often third-party-managed devices that CISOs have never had eyes on. The conversation walks through the mechanics: the Logging Reference Architecture (LRA) dropping mid-August, the 90-day plan requirement, and the three maturity levels with their rising inventory-and-logging thresholds (70/50, 80/80, 90/90). Brian and Sean unpack why asset inventory is the real "creeper" that will blindside teams, why OT discovery requires drop-in kits and passive network detection rather than active scanning that can break physical systems, why centralized logging matters for coordinated FSEB-wide defense, and how to think about "three-for-one" investments that solve this mandate and other capability gaps at once. ----------RESOURCES MENTIONED IN THIS EPISODEThe Core Policy- OMB M-26-14 (new logging mandate, issued May 22)- OMB M-21-31 (the rescinded SolarWinds-era predecessor)- OMB M-26-14 Signals a New Era for Cyber Visibility (BLOG)Background: The SolarWinds / Sunburst Hack- CISA on the SolarWinds supply chain compromise- GAO review of federal M-21-31 log management adoptionThe Maturity Milestones (per the memo)- Level 1 (Basic) — ~120 days after LRA: 70% of assets inventoried, 50% logged centrally- Level 2 (Intermediate) — ~Valentine's Day 2027: 80% inventoried, 80% logged- Level 3 (Advanced) — ~320 days / Independence Day 2027: 90% inventoried, 90% loggedOT/IoT Discovery & Network Detection Solutions Referenced- Zeek- Corelight (commercial Zeek / "Sericana" reference- Armis- Dragos- Nozomi Networks SIEM, SOAR & SOC Modernization- Continuous Threat Exposure Management (CTEM)- CISA SIEM-as-a-service with ElasticRelated Episodes- Episode 12: The Founding Father's Guide to Federal IT- Episode 7: Iran Came for the US Dams and We Got Lucky: Frontline Insight from the OT Fight- Episode 6: Cupcakes and OODA Loops: Inside(r)'s Insights Into the New Federal Cyber PlaybookUpcoming Events- July 14 Breakfast Briefing at the National Press Club — "When the Perimeter Disappears: Securing the Converged Federal Enterprise Across IT, IoT, and OT": - July 14 Mid-Year Federal IT Priority Setting Session with a fireside chat featuring CISA Director Nick AndersenThe Hosts & Show- Swish Data - GIST 360 ----------CONNECT WITH USGot an idea for a future episode? Want to be a guest? Let us know.Brian Lake - blake@swishdata.comSean Applegate - sapplegate@swishdata.comSubscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.
    続きを読む 一部表示
    36 分
  • The Founding Fathers' Guide to Federal IT
    2026/07/06

    Happy 250th birthday, America. In this special shortened Fourth of July episode of The GIST of Govt IT, Brian and Sean keep it snackable for the beach-and-boat crowd — kicking off with a debate over favorite founding fathers before turning to a rundown of the GIST 360 summer event lineup. Sean previews what's coming: a July 14 breakfast briefing at the National Press Club on securing the converged IT/OT/IoT enterprise; a mid-year federal IT priority-setting session featuring a fireside chat with CISA Director Nick Andersen, an ATARC roundtable on operationalizing continuous threat exposure management, as well as several webinars on deck. If you want to know where federal IT leaders are placing their bets for the last stretch of the fiscal year, this is your map to the conversations that matter. Plus a kite-surfing Ben Franklin!

    ----------

    RESOURCES MENTIONED IN THIS EPISODE

    Upcoming GIST 360 Events

    - July 14 — Breakfast Briefing, National Press Club - "When the Perimeter Disappears: Securing the Converged Federal Enterprise Across IT, IoT, and OT"

    - July 14 — Mid-Year Federal IT Priority Setting & Listening Session, The Riggs Rooftop (9th & E, Washington DC, 5:30–7:30 PM)

    - August 13 — Webinar: "From the Edge to the Enterprise: The Future of Mission-Critical Infrastructure"

    - August 25 — Webinar: "Rethinking Command and Control Resiliency at the Tactical Edge"

    The Hosts & Show
    - Swish
    - GIST 360
    ----------

    CONNECT WITH US

    Got an idea for a future episode? Want to be a guest? Let us know.

    Brian Lake - blake@swishdata.com

    Sean Applegate - sapplegate@swishdata.com

    Subscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.


    続きを読む 一部表示
    19 分
  • The Five-Dollar Agentic AI Hacker
    2026/06/29
    Four days. A spare $500 mini PC from Microcenter. An open-source quantized model running on 512 MB of VRAM. And by Thursday morning, an autonomous AI agent named Jenkins was finding vulnerabilities, chaining exploits, gaining root, and maintaining persistence — entirely on its own, with no human in the loop. In Episode 11 of The GIST of Govt IT, Brian and Sean are joined by Marlin McFate, Federal CTO and CISO at Cohesity to dig into the experiment Marlin documented on his new Substack, Peripheral Tech. Marlin walks through the architectural choices that made Jenkins possible — the "discussion skill" approach to working with agents like colleagues, the orchestrator-subagent model, the safety capability files that proved more effective than external guardrails — and why the implications go far beyond "Mythos changed everything." The conversation digs into the real thesis: the barrier to nation-state-grade offensive cyber didn't just fall — it fell years ago, and most organizations are still spending 80% of their cybersecurity budget trying to prevent attacks rather than recover from them. Brian, Sean, and Marlin unpack the digital jump bag, the minimum viable agency concept, why finding the last clean backup is "a bad lie" the industry has been telling for years, and what Cohesity's RAG-enabled secondary data approach means for agencies trying to feed AI without standing up a fifth copy of their data. Plus, AI agents throw fits and take on personalities for their own. ----------RESOURCES MENTIONED IN THIS EPISODEFeatured Guest- Marlin McFate, Federal CTO & CISO, Cohesity- Peripheral Tech (Marlin's Substack)- Jenkins- Cohesity Federal- Cohesity Gaia (conversational AI search for backup data)The Experiment & The Stack- Kali Linux (penetration testing OS)- Ollama (local LLM runtime)- Qwen open-source models (Alibaba)- The Mythos vulnerability discovery report (Cloud Security Alliance)- Anthropic Project GlasswingAgentic AI & Security- Gambit Security research on multi-AI hacker (Anthropic + OpenAI split-context attack on Mexican government)Federal Cyber Policy & Frameworks- OMB M-26-14 (cybersecurity logging and monitoring for IT/IoT/OT)- CISA Industrial Control Systems resources- NIST AI Risk Management FrameworkConcepts Discussed- Westrum Organizational Culture Typology- Project Bravo (Stuart Wagner, formerly Air Force, now Navy)- Platform One (DoD DevSecOps platform)Open Source AI Frameworks- vLLM (high-throughput LLM inference)- Red Hat OpenShift AILearning Resources- O'Reilly Learning Platform- O'Reilly AI Sandboxes & Guided LabsRelated Episodes- Episode 7: Iran Came for the Dams and We Lucky- Episode 2: Fighting Fire with Fire to Secure Federal AgentsUpcoming Event- Marlin speaking at AWS Public Sector Summit DC — Tuesday, June 30, 2:00 PM, Convention Center side theaterThe Hosts & Show- Swish- GIST 360 program----------CONNECT WITH USGot an idea for a future episode? Want to be a guest? Let us know.Brian Lake - blake@swishdata.comSean Applegate - sapplegate@swishdata.comSubscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.
    続きを読む 一部表示
    1 時間 14 分