Federal agencies are strengthening industry ties to secure critical infrastructure, build the cyber workforce and address vulnerabilities.
Federal agencies are looking to deepen their partnership with the private sector to protect critical infrastructure, with joint efforts to identify vulnerabilities, deploy technology and scale solutions.
National Cyber Director Sean Cairncross said Thursday at the Billington Cybersecurity Summit in Washington that government and industry need to work “hand in glove” rather than rely on compliance checklists as technology increasingly shapes both critical infrastructure and the threats against it.
“We’re in a moment technologically where security and innovation have melded, and in order to move forward, protect critical infrastructure, make sure the systems that our citizens rely on for daily life are protected and secure, we need a relationship that is hand in glove, and that means we cannot be dictating a compliance checklist to industry,” said Cairncross.
CISA Acting Director Nick Andersen told reporters in a sidebar at the summit Wednesday that the agency is looking to increase its relationships with and support of infrastructure operators following high-profile attacks in the water sector.
“We want to be able to provide them with tools to appropriately manage [vulnerabilities], to properly prioritize and contextualize for them. Where is it that we think they need to be spending their time? But it’s also a tremendous opportunity for us to use AI for positive things to be able to assess our own risk and be able to assess our own threats and be able to look at our own vulnerability landscape as we sort of assess our wider attack surface,” he said.
Texas Pilot for the Water Sector
Water infrastructure has often fallen toward the bottom of the priority list in critical infrastructure protections, Cairncross said. To address that challenge, the federal government partnered with Texas to launch Project Watershed 250.
Launched Aug. 31, the initiative connects Texas water utilities with cybersecurity resources at no cost to participating providers. It brings together federal and private-sector capabilities with state and local expertise to strengthen the security of water systems and related critical infrastructure.
The effort begins with a six-month pilot to develop best practices and scalable cybersecurity solutions. The pilot will also assess participating Texas water utilities for vulnerabilities and help address identified risks using private-sector cybersecurity and AI tools.
“What we are trying to do is go find a specific, concrete solution, and then scale off of that. We’re excited about it. We’ve got other sectors that we’re going to move this sort of program into. We’ll be announcing soon, but water is a good start,” Cairncross said.
Keeping the Talent Pipeline Open
One major challenge federal agencies face is attracting and retaining highly skilled technical talent.
CISA is working to fill many vacancies in roles across its cybersecurity, infrastructure security and emergency communications divisions.
“We look forward to welcoming hundreds of new CISA employees in the very near future,” Andersen said, adding that he is focused more on prioritizing which positions need to be filled than on reaching a specific workforce number. “With the emerging threat space that we see, do I have the right people in the right roles right now to get the job done?”
It’s a focus as well for the Office of Personnel Management, which faces a shortage of skilled cybersecurity professionals, said OPM Director Scott Kupor.
OPM launched its U.S. Tech Force initiative to attract technical talent in areas including software engineering, data science and cybersecurity to the federal government. The agency has since expanded the initiative with a dedicated cybersecurity specialist role.
The agency is also coordinating with existing programs, including the National Science Foundation’s CyberCorps Scholarship for Service, to strengthen the workforce.
“What we’re trying to do is make sure that as the White House and others figure out the appropriate relationships with the private sector and adopt technologies, do we have the appropriate resources, the appropriate know-how within the government agencies to be able to actually deploy and further those technologies?” Kupor said.
