CMS moving beyond compliance-based cybersecurity | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Watch the entire discussion here.

The Centers for Medicare and Medicaid Services is moving beyond mere compliance to risk-based cybersecurity, with a focus on continuous monitoring and attack surface management.

CMS Chief Information Security Officer Keith Busby said that transition is aimed at linking compliance with “threat-informed, risk-based defense.”

“So that we don’t have to send system teams through all these other check-the-box activities,” Busby said in an interview with Federal News Network. “More so going, hey, because we’re making these decisions based off of this information, and we’re staying within these guardrails, we are inherently compliant. It’s more of a continuous monitoring, continuous reactive state.”

The federal government has been investing in “visibility” for more than a decade through programs like the Cybersecurity and Infrastructure Security Agency’s Continuous Diagnostic and Mitigation (CDM) program.

But Busby said CMS is now leaning into a “protect first, visibility second” mindset.

“We’re starting to make that transition from just having visibility, but using automated continuous reaction based off of that visibility,” he said.

With the healthcare sector being a top target for ransomware actors and other cyber attacks, CMS’s ultimate goal in cybersecurity is avoiding any disruption to patient care.

To identify and disrupt threats, Busby said the agency has moved away from merely relying on system authorization documents toward “continuous attack surface management.”

“So what are we scanning? What do we see showing up that’s associated with CMS?” Busby said. “And I think we’ve done a really good job of not just doing that continuous monitoring from the edge, but also layering in external researchers.”

Busby said CMS uses CISA’s bug bounty program to “have public researchers across the globe come after us and tell us where they see issues from our public-facing attack surface.”

In addition to 6,000 federal employees, CMS relies on thousands of contractors and other third parties that have to use sensitive data and systems.

Busby said CMS’s endpoint management approach is centered on protecting the data.

“Our data should not leave our environments, and so when you talk about third parties, we need to really minimize the amount of times we are sharing or sending our data, our functions off networks that we have visibility into, off assets that we have visibility into, off of our ability to be able to implement controls around protecting those assets,” Busby said. “So that is the direction that we are heading. We are trying to pull all of those things back internal to CMS to ensure to still have everyone be able to do their mission, but come to us to do it.”

AI as a force multiplier

Busby said he also views artificial intelligence as a “force multiplier” for CMS’s cybersecurity efforts. The agency is now recruiting recent graduates with skills in areas like AI, as the agency shifts to in-house hiring to reduce costs and improve flexibility.

“We need to be very intentional in the use cases for AI,” Busby said. “AI gets thrown around there for everything … but I like to take very specific slivers and go, okay, let’s use AI for this, let’s make sure it’s working well for this. That way we can still hold ourselves and that model accountable.”

Busby said his team is looking at how to use AI for a range of use cases, including alert triage, behavior analytics, anomaly detection and vulnerable prioritization.

“We want to use it to help generate detections and validate patches, and test controls for it,” he added.

Last year, CMS started testing how to use AI to take findings from manual penetration tests and share those results across the agency’s IT environment.

“We take those findings, we can use a model to help us create detections, and we can then share across the enterprise to go, ‘We found this flaw in system over here, we should be alerting if we see this type of exploit across our entire enterprise,’” Busby said. “Before we would have to have detection engineers writing these and tailoring it to meet each system. We’re now able to use these AI models to help us speed that process up.”

As the technologies and approaches behind cybersecurity quickly evolve, CMS earlier this year announced plans to hire roughly 100 people into its Office of Information Technology.

Busby said recent college graduates are leaving school with skills in areas like agentic AI that would be useful for CMS.

“I think we really need to lean into the knowledge that people are picking up before they even get to us, and to help push us to grow and accept and adapt, not have them conform to our ways, but let’s really learn from them,” Busby said.

The CISO also said CMS is shifting away from relying solely on contractor support for technical roles to “doing more of that hands-on stuff ourselves.” For instance, CMS is now hiring junior ethical hackers.

“Traditionally, we’ve always relied on contractor support for that function, but we’re bringing in some federal folks now to be able to do that early in their career, learn, help us try different things, and then ideally they’ll move on to bigger and better roles within the government as they grow their career,” Busby said.

The shift to relying more on in-house technical talent could give the agency more flexibility to shift roles and responsibilities.

“Don’t get me wrong, I love our contractor community. They are a tremendous asset to us, but at times there are very specific roles or rules that we have to go through, and with federal employees, it’s a little bit easier for us to change priorities at a quicker pace without having to ensure that contract execution occurred,” Busby said. “I think that’s really important for our organization.”

Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.



——————————————————-


Click Here For The Original Source.

National Cyber Security

FREE
VIEW