As Washington races ahead, are existing national security technology systems at risk? | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Terry Gerton Brad, let me go to you with the first question. Every administration publishes strategy documents, and when you compare this national security science and technology strategy to what we’ve been hearing about for the last several years, what genuinely looks different in this document?

Brad LaPorte Yeah, first thing, I mean, for those that aren’t aware, this is basically the White House’s homework assignment, you know, specifically within the realm of science and technology, and it answers, given everything that we could invest in, you know, where do we hedge our bets? And really, like what we’re looking at it is, and what’s different is really having a heavy focus on what cybersecurity means, and across this entire element and all the different categories that are in here. That encompasses the whole, you know, 140 programs and all of that and basically the 19 different components of the Department of War. And really what it comes down to is we’re trying to figure out, you know, what do we fund versus protect, and where is this new money going to go and, and, in trying to allocate it? And the attack surface has never been larger than it is right now. I mean, our defense posture is the highest it has been in decades. And really it’s going across each of the four major pillars of the document and really seeking the sense of urgency. And one of the things that I really wanna talk about today is the Golden Dome.

Terry Gerton Rob, when you think about this, you know, Brad has just talked about urgency, he’s talked about Golden Dome and kinetic impacts, but when you read it through the lens of implementation, where do you think agencies will have the hardest time turning the priorities into actual capabilities?

Rob Smith Basically, the hardcore problem is the technology that we use. We use systems that we call embedded systems where they’re self-contained devices, and the problem with these self- contained devices is patching. And, you know, the patches don’t exist. And then when you create a patch, the device has to be recertified. And so the delay here is, it’s just unrealistic. We can’t keep up with the amount of hacking that’s going on, thanks to AI and the reality that AI can do in 24 hours, what would take us months or even years to find the vulnerability. We can’t fix the technology fast enough because we have these embedded systems that control things like satellites or even telephone systems or power, electric, water, you name it. All these hardcore operational technology devices, they just can’t be updated easily. This is the core problem.

Terry Gerton Rob, if you were a federal CIO or a program executive officer today and you were reading this strategy, what would you be scratching your head over? What is the biggest mismatch, I guess, between the cyber resilience that the government says it wants and the way it currently manages those operational systems that you’re talking about?

Rob Smith I mean, in the end of the day, it’s wrong how it’s being done. And we’ve done this for 40 years. So it’s for 40 years, it was right. And it’s not like we’ve been doing it wrong for 40 years. It’s just because of how AI is and with all the recent news of AI being used to penetrate businesses and governments, times have changed and the financial model has changed. So you don’t have the, the bodies, the physical amount of people to track this stuff and to have somebody to be able to actually implement fixes, to make fixes and implement them. So if I was the CIO, honestly, I’d be panicking right now and they have good reason to panic, you know, the famous Douglas Adams line, don’t panic. This is a case where panic, but smart panic is warranted. And what we’re talking about is looking at the problem differently and to try and take the device as we know it in a patch out of the solution and find a way to mitigate that the exploit may be there, but it can’t actually be used. And so this is the challenge CIOs need and CISOs as well need to face themselves. How can we prevent these devices from actually being compromised, even though the vulnerability is there?

Terry Gerton Rob Smith is the founder and CEO of LionFish Tech Advisors. Brad LaPorte is an advisor at LionFish. Brad, let me come to you. LionFish has just released a report, you call it the Cyber Golden Dome, I think. Trying to get at the issues that Rob has raised here around operational vulnerabilities, where did you see a blind spot in this report that maybe you expected to see a solution?

Brad LaPorte Yeah, absolutely. So it’s an amazing report. And the country has decided to build a shield around its skies. But the real decision is with the real money behind it and every piece of that shield. So the radars, the interceptors, the command and control, the satellites, it all runs on software and the underlying elements on the ground level under that dome. And most of that software is written in C and C++ and older legacy software code, decades ago in a different world before all of us, for most of us. For a world that nobody imagined that a machine could read a million lines of code overnight and find a flaw in it. And it’s not necessarily a physical Golden Dome problem, that’s the whole department. We’ve mapped here at LionFish against the FY27 budget line items in more than 140 funded programs across 19 components. And about $87 billion in this year’s procurement. And that’s basically $160 billion in next year’s request. And it’s all running on that code that can’t quickly be attached. That’s a real root problem, and really pointing that out. And I was shocked when this report came out that, hey, we’re not addressing the core problem here. What happens with these systems that are going to protect our skies if they can’t actually fire. And this is an ongoing threat and concern that we have, you know, in the cybersecurity community and in the larger Department of War.

Terry Gerton The approach to cyber security right now seems to be patch and hope or take things offline. What is a better approach, especially when all of these systems have to work together but they may not all be connected so you can’t put push a patch that gets to everything all together? What are you all suggesting?

Brad LaPorte Yeah, that is a core problem, right? So kind of what Rob alluded to in the beginning, you know, really we have to implement something that’s called operational software assurance, which is what we’re identifying and designating, which is keeping deployed software secure by default, protecting it and provable across the whole entire operational life. So we identified three major pillars, identify, protect, and comply. And it’s distinct from traditional software assurance, which is asked whether a software was built, brought securely before it’s fielded. And that dives into more of the runtime security, so the actual embedded runtime security which is a discipline under that protects killer, where you’re actually have an active in place protections that make an exploit attempt to fail at the moment it runs. So you’re actually, you don’t have to patch it, you’re actually immunizing it up front. In a lot of these systems, you either can’t reach it physically or even digitally, or you can’t outrun it. And that’s the underlying problem. So we have to come up with a different solution because there’s no way that we can patch these systems. And even if we could, the amount of time and cost and efforts to do that would be impossible. So we’d have to look at this more programmatically in the way that do it.

Terry Gerton Can you say a little bit more about how immunizing these embedded software, this embedded software code would work?

Brad LaPorte Yeah, so to keep it simple, really what we’re talking about is providing a protective layer or to even simplify it further, effectively a vaccine for the software code itself. So a lot of code itself, you have to put it together. You have to assemble it. You’re compiling that together and you have rewrite that code manually. And there’s new technologies that have come out in the past couple of years that allow you to actually be able to protect that code at the earlier stages, where you’re actually doing that and actually almost putting a hardened shell around that code so it’s actually protected and can’t be penetrated by an attacker. That’s a very simple, straight way of understanding it.

Rob Smith And Rob? I have an even simpler analogy. Imagine a police officer watching your shop. That’s all they do. They stand at the door and they watch to make sure nothing leaves and everything acts accordingly. That’s what we’re talking about. Somebody whose sole job it is, and in this case it’s software, to watch to make sure it’s behaving properly.

Terry Gerton So Rob, let me ask you to take that kind of to the next step then. This strategy talks repeatedly about accelerating acquisition, adopting technology faster, partnering with industry. Again, how should leaders today think about this balance between building the next thing that this strategy suggests and securing the things they already have with your policeman analogy?

Rob Smith Well, let’s take the latter first because that’s the more important issue really. And it’s going to require a substantial amount of funding, full stop. This is not something that magically happens and can just appear. Luckily, it’s, you know, it’s part of the plan and we are really suggesting the technology, not how to fund it or pay for it. What we’re suggesting is that it needs to be done. And with proper funding and support by getting agencies behind it, this is something that can actually easily be built and at a substantial savings versus patch, repair, patch, repair and give you a much better, safer solution. To come back to the first part of your question, if you have full agency support, you’re going to have the vendor community all behind you and jumping on board. And so ultimately it comes down to getting the money and the agencies to back it, and if they do, then we have a game changer here because you’re never going to be able to stop all vulnerabilities. It’s what we always tell clients about ransomware. You will get ransomware, it’s just you have to be prepared how to deal with it, and this is how you deal with these devices being attacked.

Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.



——————————————————-


Click Here For The Original Source.