Billington CyberSecurity Summit

Cyber Defense Enters the Age of Autonomous Operations

Written by Fed Gov Today | Sep 18, 2026, 4:32:29 PM

 

Industry Takeaways from the Billington CyberSecurity Summit

Artificial intelligence is rapidly changing the balance between cyber attackers and defenders. Adversaries can use it to discover vulnerabilities, generate convincing attacks and operate at a scale that would previously have required teams of skilled professionals. Government agencies and their industry partners can use the same technology to accelerate investigations, automate routine security work and respond before an attack spreads.

Industry conversations at the Billington CyberSecurity Summit 2026 revealed a consistent message: government cannot answer AI-enabled threats simply by adding another tool to an already complicated technology environment. Agencies need to reconsider where their defenses are placed, how much access they give autonomous systems and how intelligence is converted into action across organizational boundaries.

Five central themes emerged from the discussions: the speed of the AI competition, the continued importance of cyber hygiene, the disappearance of the traditional perimeter, the need to control autonomous agents and the value of collective defense.

An Arms Race Moving at Machine Speed

AI gives adversaries the ability to automate work that once required significant time and expertise. Reconnaissance, vulnerability discovery and attack development can increasingly occur at machine speed.

“This is an arms race. We need to treat it like one,” said Egon Rinderer, Senior Vice President of Federal and Enterprise Growth at NinjaOne.

Government faces an imbalance in that competition. Federal agencies must consider security, privacy, responsible use and appropriate oversight before deploying AI. Nation-state adversaries may operate without the same restrictions. They can place advanced capabilities directly into the hands of cyber operators while government organizations navigate acquisition processes and approval requirements.

That does not mean agencies should eliminate safeguards in pursuit of speed. It means they need acquisition and operational models that allow responsible technology to reach defenders quickly enough to remain useful.

AI is also making offensive capabilities accessible to people who may lack traditional cybersecurity training. Autonomous platforms can identify vulnerabilities and conduct attacks with limited input from the user.

“The offensive capability that we used to face as a human adversary is now being democratized with AI,” said Alissa Knight, CEO and Founder of Assail.

That democratization changes the potential scale of cyber activity. A person no longer needs years of technical experience to direct an AI-enabled system toward a target. The technology can translate a relatively simple instruction into a sequence of reconnaissance and exploitation activities.

The implications extend beyond enterprise networks. The application programming interfaces connecting cars, trains, aircraft, ships and satellite systems can create paths for remote attacks. Vulnerabilities in those interfaces could produce consequences involving public safety and military operations, not merely the loss of information.

Government’s response must include AI-powered defense, but the objective should not be to insert AI into every process. Agencies need to identify the tasks where speed and scale provide a measurable advantage.

Cyber Hygiene Still Determines the Outcome

The arrival of autonomous attacks does not make basic security practices obsolete. It makes failures in those practices easier for an adversary to find and exploit.

“Cyber hygiene still reigns true today,” said Navid Wlotzka, Principal Solutions Engineer for Public Sector at Tines.

Agencies still need effective vulnerability management, incident-response testing, asset awareness and confidence that their security tools are operating correctly. AI and automation can help organizations perform those activities consistently across large and complicated environments.

Patch management illustrates the importance of combining sound practices with greater speed. Once a critical vulnerability becomes known, defenders may have only a short period before attackers begin exploiting it widely. Agencies must identify affected systems, test the update and deploy it across the enterprise.

Manual handoffs can consume much of that window. AI and automation can reduce the time between a patch’s release and its deployment by finding affected devices, organizing information and executing approved actions. Cybersecurity personnel can then focus on exceptions and risk decisions that require a deeper understanding of the mission.

This approach treats AI as a force multiplier for existing teams. It does not assume that technology can compensate for an agency that lacks an accurate asset inventory or a repeatable response process.

Agencies can begin with repetitive work that consumes analysts’ time but does not depend on complex judgment. Automating alert enrichment, information gathering and routine investigative steps gives people more time to evaluate sophisticated threats.

“You definitely don’t want to automate the human out of processes where their human judgment is essential,” Wlotzka said.

That principle provides a useful dividing line. Machines can handle speed, scale and repetition. People should remain responsible for decisions that require mission context, accountability and an understanding of potential consequences.

The Perimeter Is No Longer a Useful Boundary

Government technology now extends across internal networks, commercial clouds, government cloud environments, operational systems and disconnected locations. Employees can also introduce unauthorized applications, APIs and AI models.

“We can no longer say that the perimeter is dissolving. It is gone,” Knight said.

Security capabilities must therefore operate wherever the mission and its assets are located. That is particularly important for military organizations that may need to conduct cyber operations in contested or austere environments without a reliable connection to a cloud-based service.

AI and data sovereignty will receive greater attention as agencies consider what information they are sending to externally hosted models. Offensive cyber operations can produce sensitive details about targets, vulnerabilities and operational methods. Government leaders must decide whether that information should leave their controlled environments.

Cloud economics present another consideration. Continuous, high-volume AI operations can generate substantial costs. Smaller models and locally deployed systems may give agencies greater control over both sensitive information and spending.

Local deployment, however, can expand the shadow AI problem. Employees may download and operate models without the knowledge or approval of security teams. As AI models become smaller and easier to deploy, that challenge will grow.

Comprehensive discovery must now encompass traditional devices, cloud assets, APIs and AI models. The first task is understanding what is present, what information it can reach and whether it creates a new route into the environment.

The disappearance of the perimeter does not eliminate boundaries. It requires agencies to create smaller, more precise boundaries around individual identities, workloads, data and mission assets.

AI Agents Need Enforceable Boundaries

As agencies adopt agentic AI, they are placing autonomous systems inside networks that were not designed to control them. Traditional routers, switches and firewalls may divide an enterprise into broad segments, but those controls often lack the granularity needed for an agent moving dynamically among several systems.

“We’re over-permissioning our AI agents,” said Louis Eichenbaum, Federal Chief Technology Officer at ColorTokens.

An agent assigned to complete a task involving a human-resources system may still be able to reach a financial server. Even if it is not instructed to access that server, excessive permissions make the action possible.

Organizations sometimes assume they can train an AI model to avoid inappropriate behavior. Training is useful, but it is not an enforceable security boundary. Agencies need technical controls that prevent an agent from leaving its approved environment regardless of what the model decides to do.

Zero-trust principles offer a practical foundation. Strong identity, asset discovery, least-privilege access and microsegmentation can restrict each agent to the specific resources required for its task.

The focus should move from broad network segments to individual assets and workloads. Software-based controls can follow an identity or application and adapt as it moves through an environment.

The distinction between governance and enforcement is critical. A policy may state that an AI agent should not access financial data. An effective architecture makes that access technically impossible.

Agencies must also treat AI agents as nonhuman identities. Each one needs an owner, a defined purpose, limited permissions and continuous monitoring. Because agents can complete actions at machine speed, excessive access can create significant damage before a person has time to intervene.

Collective Defense Must Lead to Action

No agency or company can see the entire threat environment. One organization may detect an unfamiliar tactic weeks before it becomes visible to the broader government.

Collective defense allows participants to combine those individual observations, investigate emerging activity and warn others before they are attacked.

“The world is awash in threat intelligence,” said Tom Stockmeyer, Managing Director for Government and Critical Infrastructure at Cyware.

The problem is not necessarily a lack of information. It is identifying the intelligence that is unique, relevant and actionable.

Information-sharing communities succeed when members actively contribute rather than simply receive automated feeds. A participant may surface activity that does not match a known threat actor. Analysts across the community can form a focused team, compare evidence and determine whether the activity represents a false positive or a new campaign.

The findings can then be shared with CISA, the FBI, the National Security Agency or the appropriate sector risk management agency. This provides government with evidence drawn directly from environments where attacks are occurring.

Member engagement is one of the clearest measures of whether a collective-defense community is healthy. Technology can move indicators between systems, but people build the trust required to share sensitive observations and collaborate on complicated investigations.

The final challenge is turning intelligence into defensive action. Large agencies and sophisticated companies may have the tools and personnel needed to apply a new indicator immediately. Smaller organizations often do not.

Collective defense must solve that “last mile” by helping less-resourced members take action through the tools they already possess. Shared intelligence has limited value if only the most capable participants can use it.

Keeping People at the Center of Autonomous Defense

The central lesson from the summit is that AI will not reduce the importance of cybersecurity fundamentals or human expertise. It will expose weaknesses in both more quickly.

Agencies need accurate asset inventories before they can govern AI, strong identity controls before they can trust autonomous agents and repeatable cyber practices before automation can improve them. They also need communities that turn isolated observations into shared defensive action.

AI can process information, execute routine steps and operate at a scale people cannot match. Human professionals still provide mission context, ethical judgment and accountability.

The most resilient agencies will not choose between automation and people. They will establish clear boundaries between the work machines can accelerate and the decisions people must continue to own.