エピソード

  • A Pause, Not a Pass on CMMC
    2026/07/21
    On July 13, the Department of War hit pause on one of the most consequential compliance regimes in the defense industrial base. In Episode 14 of The GIST of Govt IT, Brian and Sean break down the suspension of CMMC Phase II — the third-party assessment requirement that was set to take effect November 10 — and what it actually means for the thousands of contractors caught in the middle. Sean's message is blunt: this is a pause, not a repeal. The requirement to protect controlled unclassified information isn't going anywhere, and the smart move is to keep marching toward NIST SP 800-171 compliance regardless of what the 60-day CMMC Reform Task Force recommends. The conversation digs into the real economics that triggered the review, the False Claims Act lawsuits already settling in the six-to-eight-figure range for contractors who attested to compliance they didn't have, why ISO 27001 is the closest on-ramp for commercial companies new to the space, and a clear Monday-morning playbook. Plus, CISA Director Nick Andersen's hacker name (hint: he's a Matrix fan).Resources Mentioned in This EpisodeThe Core StoryDepartment of War release: "Forging the Arsenal of Freedom: DoW Suspends CMMC Phase II Requirements" (July 13)Office of Industrial Base Growth version of the announcementFederal News Network coverageThe CMMC Reform Task Force RFI (responses due 12:00 PM ET, Friday, August 14) — posted on SAM.gov Legal & Advisory AnalysisMorgan Lewis — "Cybersecurity Obligations Remain"Crowell & Moring — DFARS obligations & contractor action stepsGreenberg Traurig — the July 13 memoranda explained Standards & Frameworks ReferencedNIST SP 800-171 Rev. 2 (protecting Controlled Unclassified Information) NIST SP 800-171 Rev. 3CMMC Program overview (DoD CIO)ISO/IEC 27001 (the commercial on-ramp Sean recommends)DFARS 252.204-7012 (safeguarding covered defense information)FIPS 140 validated encryptionCompliance & Assessment ConceptsSPRS (Supplier Performance Risk System) — where self-assessments are postedDIBCAC (Defense Industrial Base Cybersecurity Assessment Center)C3PAO (CMMC Third-Party Assessment Organizations) via the Cyber ABThe False Claims Act AngleDOJ Civil Cyber-Fraud InitiativeThe False Claims Act (DOJ overview)The Hosts & ShowSwishGIST 360CONNECT WITH USGot an idea for a future episode? Want to be a guest? Let us know.Brian Lake - blake@swishdata.comSean Applegate - sapplegate@swishdata.comSubscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.
    続きを読む 一部表示
    24 分
  • Fed Christmas in July? The OMB M-26-14 Holiday Rush Begins!
    2026/07/13
    Level One by Christmas. Level Two by Valentine's Day. Level Three by Independence Day. That's the OMB M-26-14 logging mandate clock federal agencies are now racing against — and if you don't want to spend your holidays at the office, it's time to start planning now! In Episode 13 of The GIST of Govt IT, Brian and Sean dig into OMB M-26-14 on the eve of Sean's fireside chat with CISA Director Nick Andersen. Sean breaks down what actually changed: the shift from long-term log hoarding (30 months of cold retention) to an outcomes-driven model focused on defending the cyberspace effectively, and the dramatic expansion of scope to include IoT and operational technology — the unmanaged, line-of-business-owned, often third-party-managed devices that CISOs have never had eyes on. The conversation walks through the mechanics: the Logging Reference Architecture (LRA) dropping mid-August, the 90-day plan requirement, and the three maturity levels with their rising inventory-and-logging thresholds (70/50, 80/80, 90/90). Brian and Sean unpack why asset inventory is the real "creeper" that will blindside teams, why OT discovery requires drop-in kits and passive network detection rather than active scanning that can break physical systems, why centralized logging matters for coordinated FSEB-wide defense, and how to think about "three-for-one" investments that solve this mandate and other capability gaps at once. ----------RESOURCES MENTIONED IN THIS EPISODEThe Core Policy- OMB M-26-14 (new logging mandate, issued May 22)- OMB M-21-31 (the rescinded SolarWinds-era predecessor)- OMB M-26-14 Signals a New Era for Cyber Visibility (BLOG)Background: The SolarWinds / Sunburst Hack- CISA on the SolarWinds supply chain compromise- GAO review of federal M-21-31 log management adoptionThe Maturity Milestones (per the memo)- Level 1 (Basic) — ~120 days after LRA: 70% of assets inventoried, 50% logged centrally- Level 2 (Intermediate) — ~Valentine's Day 2027: 80% inventoried, 80% logged- Level 3 (Advanced) — ~320 days / Independence Day 2027: 90% inventoried, 90% loggedOT/IoT Discovery & Network Detection Solutions Referenced- Zeek- Corelight (commercial Zeek / "Sericana" reference- Armis- Dragos- Nozomi Networks SIEM, SOAR & SOC Modernization- Continuous Threat Exposure Management (CTEM)- CISA SIEM-as-a-service with ElasticRelated Episodes- Episode 12: The Founding Father's Guide to Federal IT- Episode 7: Iran Came for the US Dams and We Got Lucky: Frontline Insight from the OT Fight- Episode 6: Cupcakes and OODA Loops: Inside(r)'s Insights Into the New Federal Cyber PlaybookUpcoming Events- July 14 Breakfast Briefing at the National Press Club — "When the Perimeter Disappears: Securing the Converged Federal Enterprise Across IT, IoT, and OT": - July 14 Mid-Year Federal IT Priority Setting Session with a fireside chat featuring CISA Director Nick AndersenThe Hosts & Show- Swish Data - GIST 360 ----------CONNECT WITH USGot an idea for a future episode? Want to be a guest? Let us know.Brian Lake - blake@swishdata.comSean Applegate - sapplegate@swishdata.comSubscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.
    続きを読む 一部表示
    36 分
  • The Founding Fathers' Guide to Federal IT
    2026/07/06

    Happy 250th birthday, America. In this special shortened Fourth of July episode of The GIST of Govt IT, Brian and Sean keep it snackable for the beach-and-boat crowd — kicking off with a debate over favorite founding fathers before turning to a rundown of the GIST 360 summer event lineup. Sean previews what's coming: a July 14 breakfast briefing at the National Press Club on securing the converged IT/OT/IoT enterprise; a mid-year federal IT priority-setting session featuring a fireside chat with CISA Director Nick Andersen, an ATARC roundtable on operationalizing continuous threat exposure management, as well as several webinars on deck. If you want to know where federal IT leaders are placing their bets for the last stretch of the fiscal year, this is your map to the conversations that matter. Plus a kite-surfing Ben Franklin!

    ----------

    RESOURCES MENTIONED IN THIS EPISODE

    Upcoming GIST 360 Events

    - July 14 — Breakfast Briefing, National Press Club - "When the Perimeter Disappears: Securing the Converged Federal Enterprise Across IT, IoT, and OT"

    - July 14 — Mid-Year Federal IT Priority Setting & Listening Session, The Riggs Rooftop (9th & E, Washington DC, 5:30–7:30 PM)

    - August 13 — Webinar: "From the Edge to the Enterprise: The Future of Mission-Critical Infrastructure"

    - August 25 — Webinar: "Rethinking Command and Control Resiliency at the Tactical Edge"

    The Hosts & Show
    - Swish
    - GIST 360
    ----------

    CONNECT WITH US

    Got an idea for a future episode? Want to be a guest? Let us know.

    Brian Lake - blake@swishdata.com

    Sean Applegate - sapplegate@swishdata.com

    Subscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.


    続きを読む 一部表示
    19 分
  • The Five-Dollar Agentic AI Hacker
    2026/06/29
    Four days. A spare $500 mini PC from Microcenter. An open-source quantized model running on 512 MB of VRAM. And by Thursday morning, an autonomous AI agent named Jenkins was finding vulnerabilities, chaining exploits, gaining root, and maintaining persistence — entirely on its own, with no human in the loop. In Episode 11 of The GIST of Govt IT, Brian and Sean are joined by Marlin McFate, Federal CTO and CISO at Cohesity to dig into the experiment Marlin documented on his new Substack, Peripheral Tech. Marlin walks through the architectural choices that made Jenkins possible — the "discussion skill" approach to working with agents like colleagues, the orchestrator-subagent model, the safety capability files that proved more effective than external guardrails — and why the implications go far beyond "Mythos changed everything." The conversation digs into the real thesis: the barrier to nation-state-grade offensive cyber didn't just fall — it fell years ago, and most organizations are still spending 80% of their cybersecurity budget trying to prevent attacks rather than recover from them. Brian, Sean, and Marlin unpack the digital jump bag, the minimum viable agency concept, why finding the last clean backup is "a bad lie" the industry has been telling for years, and what Cohesity's RAG-enabled secondary data approach means for agencies trying to feed AI without standing up a fifth copy of their data. Plus, AI agents throw fits and take on personalities for their own. ----------RESOURCES MENTIONED IN THIS EPISODEFeatured Guest- Marlin McFate, Federal CTO & CISO, Cohesity- Peripheral Tech (Marlin's Substack)- Jenkins- Cohesity Federal- Cohesity Gaia (conversational AI search for backup data)The Experiment & The Stack- Kali Linux (penetration testing OS)- Ollama (local LLM runtime)- Qwen open-source models (Alibaba)- The Mythos vulnerability discovery report (Cloud Security Alliance)- Anthropic Project GlasswingAgentic AI & Security- Gambit Security research on multi-AI hacker (Anthropic + OpenAI split-context attack on Mexican government)Federal Cyber Policy & Frameworks- OMB M-26-14 (cybersecurity logging and monitoring for IT/IoT/OT)- CISA Industrial Control Systems resources- NIST AI Risk Management FrameworkConcepts Discussed- Westrum Organizational Culture Typology- Project Bravo (Stuart Wagner, formerly Air Force, now Navy)- Platform One (DoD DevSecOps platform)Open Source AI Frameworks- vLLM (high-throughput LLM inference)- Red Hat OpenShift AILearning Resources- O'Reilly Learning Platform- O'Reilly AI Sandboxes & Guided LabsRelated Episodes- Episode 7: Iran Came for the Dams and We Lucky- Episode 2: Fighting Fire with Fire to Secure Federal AgentsUpcoming Event- Marlin speaking at AWS Public Sector Summit DC — Tuesday, June 30, 2:00 PM, Convention Center side theaterThe Hosts & Show- Swish- GIST 360 program----------CONNECT WITH USGot an idea for a future episode? Want to be a guest? Let us know.Brian Lake - blake@swishdata.comSean Applegate - sapplegate@swishdata.comSubscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.
    続きを読む 一部表示
    1 時間 14 分
  • An Apache Down. An ASV Up: Crossing the Rubicon for Autonomous Warfare
    2026/06/22
    In Episode 10 of The GIST of Govt IT, Brian and Sean are joined by David Hutchins, Director of Naval Systems and Defense Technology at Forecast International, fresh off SOF Week in Tampa to discuss the pervasiveness of autonomous systems and platforms that is changing calculus of warfare. David, a Marine Corps veteran who enlisted at 17, walks through the moment autonomous warfare crossed the Rubicon. The conversation digs into the cat-and-mouse evolution of counter-drone tech in Ukraine, why the LCS may finally have found its purpose in de-mining the Strait of Hormuz, the supply chain reality of mass-producing autonomous systems, the role of contested logistics and modular open architectures, and the upcoming World Cup. Plus the ever creative tactics of Marines in the field and how Sean once used pantyhose to keep sand out of IT systems when he was down range. ----------RESOURCES MENTIONED IN THIS EPISODEFeatured Guest- David Hutchins, Director of Defense Technology and Naval Systems, Forecast International- Forecast International- Defense & Security Monitor (Forecast's research blog) Forecast International Related Resources - Strait of Hormuz Under Threat of Mines, Are Literal Combat Ships the Solution- A New DAWG in the Fight: The Pentagon's $54B Bet on Autonomous Warfare- Safeguarding the World Cup: The Critical Role of Counter Drone SystemsDefense Autonomous Warfare Group (DAWG) Coverage- DefenseScoop on the FY27 DAWG budget- Task & Purpose on the $54B DAWG ask - The Hill analysis on the autonomous warfare pivot- SOUTHCOM Autonomous Warfare Command (SAWC)Key Events Referenced- SOF Week 2026- Maneuver Warfighter Conference (Fort Benning, GA)The Strait of Hormuz Helicopter Rescue- AH-64 Pilots Rescued by Uncrewed Surface Drone (BBC)- Saronic Corsair USV platform overviewUnmanned Naval Systems Discused- SailDrone (Coast Guard partner, Great Lakes & North Atlantic)- US Coast Guard Coastal Sentinel programDrone & Counter-Drone Programs Referenced- Project Maven (DoD AI-enabled targeting)- DoD Drone Dominance program World Cup 2026 Counter-UAS Funding- DHS Counter-UAS resources: https://www.cisa.gov/topics/physical-security/unmanned-aircraft-systems-uas- Counter-UAS for World CupCounter-Drone Technology & Standards- FAA Drone Regulations & Pilot Licensing- FAA Beyond Visual Line of Sight (BVLOS) rulesThe Hosts & Show- Swish- GIST 360----------CONNECT WITH USGot an idea for a future episode? Want to be a guest? Let us know.Brian Lake - blake@swishdata.comSean Applegate - sapplegate@swishdata.comSubscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.
    続きを読む 一部表示
    57 分
  • Quad Charts be Damned: Data Meets the Mission
    2026/06/15
    For years now, the question for federal agencies has been the same: is your data ready for AI? In Episode 9 of The GIST of Govt IT, Brian and Sean sit down with Andrew Churchill, who leads Qlik's Public Sector Business across the US and Canada, to dig into whether the answer is finally shifting from "not yet" to "we're getting there" — and what's actually driving it. Andrew shares how policy moves are pushing the idea that data belongs to the mission, not the system owner; how AI is automating the mundane data prep work; and why the trust score on the data behind an AI recommendation is becoming the single most important factor for senior leaders making decisions. Brian, Sean, and Andrew unpack the agentic identity challenge nobody's talking about, the IBM Think team that burned 20% of its annual Mythos token budget in a single weekend, why a federal employee who knows the mission plus AI beats a forward-deployed engineer every time. Why federal data progress is a war of inches and why leaders need to turn the people delivering small wins into heroes — quad charts be damned. Plus, live music recommendations for the DC region. ----------RESOURCES MENTIONED IN THIS EPISODEFeatured Guest- Andrew Churchill, VP Public Sector, Qlik- Qlik Public Sector- Qlik Data Literacy Program (free resources)- Qlik FedRAMP authorization statusHegseth's Advana Memorandum- Advana restructuring memo and program overhaul (Jan 2026) - Hegseth's "Transforming the Warfighting Acquisition System" memo (Nov 7, 2025)DoD AI/Data Programs Referenced- Advana (DoD enterprise data and analytics platform)- Project Maven (DoD computer vision/AI)- Project Bravo (Air Force innovation initiative)Federal Data Policy- DoD Data Strategy- Federal Data Strategy (strategy.data.gov)- Data.govLive Music Featured- Tedeschi Trucks Band - Bound for Glory - Tedeschi Trucks Band Live from Red Rocks - Full Concert- Point Break Music Festival- Warped Tour DCReferences & Concepts- Gartner BI/Analytics Magic Quadrant- Stuart Wagner (Navy, former Air Force CTO)- Lori Mangold (Booz Allen, former Army Chief G3/5/7) Previous Events- Transforming Data Into a Strategic National Asset w/ NASA CDO- Qlik Public Sector SummitLife's a Game of Inches- "Al Pacino" Epic Monologue from Any Given Sunday The Hosts & Show- Swish - GIST 360Come find Brian, Andrew, and Sean at a show this summer. Quad charts not required!CONNECT WITH USGot an idea for a future episode? Want to be a guest? Let us know.Brian Lake - blake@swishdata.comSean Applegate - sapplegate@swishdata.comSubscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.
    続きを読む 一部表示
    52 分
  • Minutes, Not Months: Inside the New Cyber Velocity Facing Federal Agencies
    2026/06/08

    48 hours. That's the time it took for a federal employee credentials to be stolen as a result of a phishing attack, to being listed on a dark web marketplace. In Episode 8 of The GIST of Govt IT, Brian and Sean sit down at Check Point's Engage Summit in DC with Yochai Corem, General Manager of Check Point's Exposure Management division, to unpack what happens when both sides of cyber warfare have agentic AI — and why the next three years will not be kind to defenders. Yochai shares why pen testing once a quarter is no longer relevant, how a single Chinese developer built an entire attack program in a week using an army of agents, and what Iranian threat actors targeting Israeli hospitals look like in real-time during active kinetic conflict. The conversation digs into agentic red teaming vs. automated red teaming (and why the difference matters), why "safe remediation" still keeps a human in the loop, how to use the firewalls, WAFs, and IPS you already own as compensating controls when patching takes weeks, and the under-discussed reality that government leaders must put their hands on the keyboard with AI. Plus: Yochai's family cookbook and other vibe-coding stories.


    RESOURCES MENTIONED IN THIS EPISODE


    Featured Guest

    - Yochai Corem, GM, Exposure Management, Check Point
    - Corem Travel — Yochai's travel planning app

    Check Point
    - Check Point

    - Check Point Exposure Management
    - Check Point Engage Summit - Washington, DC


    Check Point's Exposure Management Acquisitions
    - Cyberint (now part of Check Point's external risk management)
    - Veriti (automated security control management)
    - Cyclops (now Check Point's CAASM offering)


    Exposure Management & CTEM Framework
    - Gartner Continuous Threat Exposure Management (CTEM) overview
    - CISA Known Exploited Vulnerabilities (KEV) Catalog


    Agentic AI & Red Teaming
    - OWASP Top 10 for LLM Applications
    - OWASP AIVSS — AI Vulnerability Scoring System for Agentic AI
    - MITRE ATLAS (Adversarial Threat Landscape for AI Systems)


    Threat Actor Tracking

    - Check Point Research (threat intelligence blog)

    - Check Point ThreatCloud AI


    Concepts & References

    - Air-gapped network security guidance (NIST SP 800-82)

    - IRGC (Iranian threat actor background — CISA advisory on CyberAv3ngers)


    Related Episodes

    - Episode 7: Iran Came for the Dams and We Got Lucky: Frontline Insights into the OT Fight
    - Episode 6: Cupcakes & OODA Loops: Inside(r) Insights Into the New Federal AI Cyber Playbook
    - Episode 5: Vibe Hacking and Nation State Cyber Threats

    Upcoming Events

    - GIST 360 Breakfast Briefing at the National Press Club, July 14, 2026 - When the Perimeter Disappears


    The Hosts & Show
    - Swish
    - GIST 360

    CONNECT WITH US

    Got an idea for a future episode? Want to be a guest? Let us know.

    Brian Lake - blake@swishdata.com

    Sean Applegate - sapplegate@swishdata.com

    Subscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.


    続きを読む 一部表示
    41 分
  • Iran Came for US Dams and We Got Lucky: Frontline Insights from the OT Fight
    2026/06/01
    When Iranian-linked cyber actors hit U.S. water, energy, and government facilities through internet-exposed Rockwell Allen-Bradley PLCs during the sixth week of the U.S.–Iran military campaign, they did it with attacks that were eightfold above baseline and got within 30 to 40 minutes of opening dam gates. In Episode 7 of The GIST of Govt IT, Brian and Sean sit down with Matthew Shalbetter, Director of Strategy for Civilian Agencies at Armis Federal and a 16-year HHS veteran, to unpack what's really happening at the convergence of IT and OT. Matthew breaks down why cyber has become the great equalizer for nation-state actors, the difference between Iranian "disrupt and distract" tactics, and Chinese prepositioning ahead of a potential Taiwan invasion. The conversation digs into the cultural chasm between IT and OT teams, what the Ukrainians taught a roomful of Western OT practitioners at RSA about why red teaming beats paperwork, and the basics that still aren't done. Trump's seven-page cyber strategy and what ServiceNow's $7.75B acquisition of Armis — closed April 20 — means for federal customers. Plus: Matthew's Hacker Name...DirtTrackRESOURCES MENTIONED IN THIS EPISODEFeatured Guest- Matthew Shallbetter, Director of Strategy for Civilian Agencies, Armis Federal- Armis FederalThe Iranian PLC Attacks- CISA Joint Advisory AA26-097A — Iranian-Affiliated Cyber Actors Exploit PLCs Across US Critical Infrastructure- Rockwell Automation security advisories- CyberAv3ngers / IRGC threat actor backgroundOT Discovery & Exposure Research- Shodan — internet-exposed device search engine- Censys — internet asset discovery- Armis State of Cyberwarfare ReportOT/ICS Frameworks & Government Guidance- NIST SP 800-82 — Guide to Operational Technology Security- CISA Cross-Sector Cybersecurity Performance Goals (CPGs)- DoD Zero Trust Overlays (including OT guidance)- NERC CIP Standards (electric sector OT)Federal Cyber Policy- White House National Cyber Strategy (the seven-page version)- CDM Program (Continuous Diagnostics and Mitigation)- CISA Industrial Control Systems resourcesThe ServiceNow + Armis Deal- ServiceNow completes Armis acquisition (April 20, 2026)Threat Actor Tracking Partners Referenced- Armis Centrix Threat Intelligence- DragosRelated Episodes- Episode 5: Vibe Hacking” and Nation State Cyber Threats - Episode 6: Cupcakes & OODA Loops: Inside(r) Insights Into The New Federal AI Cyber PlaybookUpcoming Event- GIST 360 Breakfast Briefing at the National Press Club, July 14 - When the Perimeter Disappears Securing the Converged Federal Enterprise Across IT, OT and IoT Environments The Hosts & Show- Swish- GIST 360CONNECT WITH USGot an idea for a future episode? Want to be a guest? Let us know.Brian Lake - blake@swishdata.comSean Applegate - sapplegate@swishdata.comSubscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.
    続きを読む 一部表示
    57 分