The 17th annual Billington CyberSecurity Summit tackled the theme of “Reducing Risk in An Age of AI-Enabled Threats” when it met Sept. 8-10 at the Walter E. Washington Convention Center in Washington, D.C. More than 3,000 attendees, including senior public- and private-sector leaders in defense, intelligence, and civilian communities, turned out to talk all things cyber. Plus, more than 150 GovCon vendors filled an exhibit hall to show off the latest protection innovations.

The Importance of Partnership

Together, GovCon and government can be a formidable force against cyber threats, experts at the conference said.

David Imbordino, director of the National Security Agency’s Cybersecurity Directorate, called collaboration “absolutely essential” as adversaries target both the public and private sectors.

“We’re here to try to solve this together, and we want to be providing the insights that we have into adversary intent, capabilities, etc., to help feed what the solutions will be moving forward,” Imbordino said.

Brett Leatherman, the assistant director of the FBI’s Cyber Division, also encouraged industry to become a better government partner in thwarting cyber threats. That’s because the environment “is becoming untenable for any one organization to defend alone,” he said.

Yet, the FBI is seeing fewer companies share information about hacks and breaches, he added. “Victims reporting early and providing information early allows us to move upstream against actors that are quickly moving across infrastructure in the U.S., Europe and beyond,” Leatherman said.

GovCon Feedback on CMMC

Pentagon officials are reviewing GovCon feedback about the Cybersecurity Maturity Model Certification program as they weigh overhauling it. Historically, small and midsize businesses have said the process, which is currently on hold during the review, is prohibitively difficult for them.

After issuing a request for information over the summer, the department received more than 1,100 responses and is studying more than 10,000 pages of documentation, said Defense Department CIO Kirsten Davies.

“More than 50% of the respondents were in favor of us putting this on hold and seeking some level of reform. A lot of this has been very, very positive,” Davies said. “The negative feedback we received was: ‘Why did this even start, why were we required to do this?’ … CMMC was hitting small to medium-sized businesses really, really hard and inappropriately hard. So, we have some work to do.”

The Pentagon is also assessing other GovCon-related cyber issues. One is potential vulnerabilities in industry’s operational technology—something the CMMC didn’t address, according to Davies. Another relates to controlled unclassified information, which industry stakeholders suggest making a mandatory marking.

AI: Friend and Foe

Lt. Gen. Paul Stanton, head of the Defense Department Cyber Defense Command and director of the Defense Information Systems Agency, didn’t mince words when he said that long-delayed maintenance of DoD networks has left them vulnerable to attacks that are “mind-boggling in terms of the complexity.”

“For some reason, over the past three decades, we have not treated our network and our data in the context of a weapon system, and we have postponed and deferred the sustainment and maintenance of our systems to our potential peril,” Stanton said.

He vowed that would change, especially as AI—agentic AI, in particular—changes the cybersecurity game. “Static defenses will not work in an era of AI-enabled cyberspace warfare,” Stanton said.

For instance, AI uncovers vulnerabilities so quickly that agencies and GovCon must issue patches more often, added Colleen Ferranti, the FBI’s assistant section chief, cyber engagement and intelligence section. “We have to do more risk-based…patching, and we have to be doing that continuously,” she said.

But AI isn’t all bad. At NSA, Imbordino said it helps analysts tackle tasks and find anomalies quickly. “Right now, we’re looking at how to use AI where we could triage so much more,” he said. “Volume has always been a problem.”

At the same time, cybersecurity basics are still critical, added Jason Bilnoski, a deputy assistant director of the FBI’s Cyber Division.

“What will prevent the attacks in the next 18 months are the same things that would have prevented the attacks of yesterday,” he said. “Speed and capability [are] certainly increasing with the use of AI, but the end state is still the same. How actors are compromising, whether it’s criminal or nation-state, still stays the same.”

Cybersecurity is a perennial challenge, so we’ll for sure watch to see what develops to inform the 18th annual Billington CyberSecurity Summit next year!