How AI Is Reshaping Cyber Defense Across Government
Innovation in Government from the Billington Cybersecurity Summit 2026 is presented by Carahsoft.
Artificial intelligence is changing both sides of cybersecurity. Government agencies can use it to identify threats, automate routine work and respond faster, but adversaries are drawing on the same capabilities to conduct attacks with greater speed and sophistication. Recorded at the Billington Cybersecurity Summit 2026, this episode of Innovation in Government explores how military, civilian and industry leaders are preparing for AI-enabled threats, identity attacks, ransomware, quantum computing and an increasingly complex technology environment.
Preparing the Navy to Fight Through a Cyberattack
Cyber has traditionally served as an enabler for military functions including intelligence, command and control, and fires. Chris Page, Acting Assistant Deputy Chief of Naval Operations N6N9C for the U.S. Navy, says defense leaders must now consider the possibility that cyber could become the main effort during a battle, a phase of conflict or even an entire military campaign.
That shift has significant implications for how the Navy designs its architecture, organizes its workforce and prepares for operations. Cyber capabilities can persist inside a target environment, steal intellectual property, undermine confidence and put forces at risk. Page also warns that the line between cyber espionage and an attack can be thin, creating difficult questions around escalation, de-escalation and crisis management.
He argues that the Navy should apply its traditional damage-control philosophy to the cyber domain. Sailors are trained to keep a ship afloat and in the fight even after it has been damaged. Cyber resilience requires the same confidence, supported by established procedures, realistic exercises and responses that have been planned before a crisis occurs.
Ships must also be capable of operating when communications or network access are disrupted. Page notes that the Navy’s ships, submarines and aircraft already carry significant amounts of sensor data and preloaded information. That local capacity, combined with resilient systems and the expertise of sailors, can allow crews to continue navigating, maintaining equipment and understanding the operational environment even when they are disconnected.
Key Takeaways
- Cyber could become the primary focus of a future battle or military campaign rather than simply supporting other warfighting functions.
- The Navy can apply its damage-control principles to cyber by preparing crews and systems to continue operating after an attack.
- Onboard data, resilient technology and experienced sailors are essential to sustaining operations in disconnected environments.
📺 Watch Full Interview
Winning the AI Cyber Arms Race
Artificial intelligence is accelerating the competition between cyber defenders and adversaries. Egon Rinderer, Senior Vice President of Federal and Enterprise Growth at NinjaOne, describes that competition as an arms race in which the stakes are growing as the technology advances.
Government faces a particular challenge because its adversaries may not apply the same safeguards or restrictions to AI systems. Agencies, meanwhile, must balance speed and innovation with security, oversight and responsible use. Rinderer says there is no simple answer to that imbalance, but government and industry must treat it as a serious strategic risk.
AI can also strengthen the fundamentals of cybersecurity. One area with immediate potential is patch management. When a critical vulnerability becomes known, agencies may have only a narrow window to apply the necessary patch across an enterprise. Manual steps and human handoffs can consume much of that time.
Rinderer says AI and automation can reduce those delays by accelerating the work between the release of a patch and its deployment across every affected device. That allows cyber professionals to focus on decisions that require human expertise while machines handle repetitive processes at scale.
Looking ahead, Rinderer believes the more consequential milestone may come when AI can approximately simulate reasoning. That capability could become a powerful force multiplier for defenders, but it would also introduce new risks when placed in the hands of adversaries.
Key Takeaways
- Government is competing against adversaries that may deploy AI without equivalent safeguards or operational restrictions.
- AI can improve foundational cybersecurity practices by reducing the time required to deploy critical patches.
- The ability of AI to approximate reasoning could become a major turning point for both cyber defense and cyber threats.
📺 Watch Full Interview
When Cyberattackers Stop Breaking In and Start Logging In
Many cyber adversaries no longer need to force their way into a system. With stolen credentials and hijacked sessions, they can simply log in.
Matt Topper, President of UberEther, says this development is transforming identity and access management from a traditional IT function into a real-time cybersecurity capability. Even strong credentials such as PIV and CAC cards do not eliminate the risk. An attacker can wait until a legitimate user authenticates and then steal the resulting session.
Traditional security systems may miss that activity because the initial login appears valid. To address the gap, organizations are moving toward identity threat detection and response. Instead of granting broad access for an entire session, agencies can continuously evaluate what a user is attempting to access and require additional authentication for sensitive or administrative functions.
That decision can incorporate more than a credential. The system can consider whether the user is connecting from an authorized device, whether that device is properly managed and patched, and whether other elements of the session match the user’s normal profile.
AI agents introduce another identity challenge. Agencies must understand what each automated service is, where it originated and whether it should receive access to a particular credential or application. Topper says identity controls should prevent an AI agent from obtaining sensitive keys or permissions it never needed in the first place.
At the same time, AI can help agencies modernize identity management by automating the connection of legacy applications to current identity and access-management systems.
Key Takeaways
- Stolen credentials and authenticated sessions allow adversaries to enter systems without triggering traditional security warnings.
- Agencies need continuous identity evaluation that considers devices, security posture, behavior and requested privileges.
- AI agents must be treated as identities with carefully controlled access to credentials, applications and sensitive data.
📺 Watch Full Interview
Building Agentic Cyber Defense at Mission Speed
The U.S. Army is exploring how AI agents can help its cyber workforce defend against thousands of autonomous attacks occurring simultaneously.
Brandon Pugh, Principal Cyber Advisor for the U.S. Army, describes an initiative that brought senior leaders from government and industry together for an exercise examining the potential of agentic cyber defense. The group identified approximately 17 to 20 capabilities that could strengthen Army defenses but concluded that attempting to pursue all of them at once would dilute the effort.
The Army narrowed its initial focus to three areas that could be piloted and deployed quickly. Those priorities include responding agentically to detected incidents, using autonomous deception capabilities against adversaries and strengthening purple-team assessments that examine an organization’s security from both offensive and defensive perspectives.
Pugh says success requires more than promising technology. Funding must be aligned with the effort, operational units must be ready to test the capabilities and acquisition teams must have a path to bring them into the Army within months rather than years. The Army must also resolve policy questions surrounding the use of autonomous agents on its networks and determine when human approval is required.
Industry interest has been significant. A recent solicitation seeking an agentic response capability generated 108 submissions in seven days from companies of many different sizes.
Pugh also emphasizes that the Army cannot protect its installations and defense critical infrastructure alone. Sustaining the movement of troops and equipment requires collaboration with the Department of Homeland Security, FBI, Department of Energy and other partners that bring different authorities and resources to the mission.
Key Takeaways
- The Army is concentrating its initial agentic cyber-defense effort on three capabilities that can be piloted quickly.
- Funding, acquisition support, operational testing and clear policies are all necessary to deploy autonomous cyber tools at mission speed.
- Protecting Army installations and critical infrastructure requires coordination across the federal government and private sector.
📺 Watch Full Interview
Automating Cyber Defense Without Losing Human Judgment
As cyberattacks move at machine speed, agencies need automation that can accelerate their response without removing people from decisions where human judgment is essential.
Navid Wlotzka, Principal Solutions Engineer for Public Sector at Tines, says strong cyber hygiene remains the foundation. Organizations must understand their assets, manage vulnerabilities, test incident-response capabilities and verify that their security tools are operating as expected. Automation can make those practices more consistent and allow agencies to execute them at greater speed.
Wlotzka distinguishes between deterministic automation and AI-assisted work. Traditional, code-based workflows can perform predictable tasks without sending every step through an AI model. AI can then be introduced selectively where it provides meaningful analytical value, such as summarizing an investigation, organizing information or offering additional context to an analyst.
This approach can improve efficiency while helping organizations control the cost and complexity of their AI use. It also allows teams to retain human oversight at critical decision points.
Wlotzka recommends a crawl-walk-run approach. Agencies can begin by automating repetitive, low-level tasks that consume analysts’ time but do not depend on complex judgment. Removing that noise gives cyber professionals more time to investigate sophisticated threats, conduct higher-level analysis and concentrate on work that directly advances the mission.
Key Takeaways
- Automation can help agencies perform foundational cybersecurity practices consistently and at machine speed.
- Deterministic workflows can handle predictable tasks while AI is introduced selectively where it adds analytical value.
- Agencies should automate repetitive work while preserving human judgment at critical decision points.
📺 Watch Full Interview
The Road to Post Quantum Cybersecurity
Government agencies are preparing for a future in which sufficiently powerful quantum computers could break many of today’s encryption methods. Nick Nilan, General Manager for the U.S. at Arqit, says agencies should begin the transition to post-quantum cryptography before that capability arrives.
The first step is discovery. Cryptography exists throughout an organization’s applications, networks, operational technology and supply chain. Agencies need a comprehensive inventory that identifies where cryptography is being used, whether it is secure against current attacks and which systems will become vulnerable to quantum-enabled attacks.
They can then map those findings against their broader IT and operational-technology environments, prioritize high-value assets and engage vendors about their post-quantum roadmaps.
Nilan warns that delaying the transition extends the exposure created by “harvest now, decrypt later.” Adversaries can collect encrypted information today and retain it until they possess the computing power to decrypt it. Data created during every additional year before migration may therefore remain vulnerable in the future.
The risk extends beyond stolen information. Nilan also highlights “trust now, forge later,” in which future adversaries could break the cryptography that supports authentication, forge certificates and impersonate trusted people or systems.
Agencies should ultimately pursue crypto agility—the ability to replace or modify cryptographic methods without disrupting the mission. Building software-defined encryption and establishing primary, alternate, contingency and emergency options can make the current migration more manageable while simplifying the migrations that will inevitably follow.
Key Takeaways
- Agencies should begin by discovering and inventorying cryptography across their IT, operational technology and supply chains.
- Delaying migration increases exposure to both “harvest now, decrypt later” and “trust now, forge later” threats.
- Crypto agility will help agencies adopt post-quantum protections and respond more effectively to future cryptographic changes.
📺 Watch Full Interview
Why Identity Is the New Cybersecurity Perimeter
Post-quantum computing could become both a powerful government capability and a new source of cybersecurity risk. Troy Grubs, Vice President of U.S. Public Sector at Ping Identity, says agencies have an opportunity to prepare early and help establish standards for its practical and secure use.
Government is sometimes viewed as following the commercial sector in technology adoption. Post-quantum cryptography offers a chance to lead by shaping the policies, architectures and implementation practices that will be required around the world.
Quantum capabilities could improve computing speed, mission execution and the rollout of new technologies. Those same capabilities could also strengthen adversaries and weaken existing defenses. Agencies should use the time available now to improve their architectures and develop a deeper understanding of how post-quantum computing will affect their operations.
Grubs identifies identity as the new security perimeter. In a distributed environment, agencies must continuously evaluate whether they can trust each person, device and nonhuman identity attempting to access data or applications.
That principle also applies to agentic AI. Autonomous systems may be able to complete increasingly complex tasks, but agencies must retain visibility into what those systems are doing and maintain appropriate human oversight. Zero trust, continuous evaluation and strong identity security will be central to managing both the opportunities and the risks.
Key Takeaways
- Post-quantum cryptography gives government an opportunity to help establish global security and implementation standards.
- Identity is becoming the primary security perimeter as users, devices and autonomous agents access distributed resources.
- Agentic AI requires continuous evaluation, clear controls and appropriate human oversight.
📺 Watch Full Interview
Protecting Healthcare From a Growing Ransomware Threat
Healthcare cybersecurity protects more than information. A successful cyberattack can disrupt hospital operations, delay treatment and threaten patient care.
Charlee Hess, Director of the Healthcare and Public Health Cybersecurity Division at the Department of Health and Human Services, explains that HHS serves as the sector risk management agency for healthcare and public health. Its responsibilities extend across hospitals, public-health offices, pharmaceutical laboratories, healthcare manufacturing, blood banks and other organizations that support the nation’s healthcare system.
The sector remains an attractive target because it holds highly personal and valuable data while operating services that cannot tolerate prolonged disruption. Hess says her team triaged more than 2,200 ransomware attacks during the previous year.
Smaller and rural healthcare providers often face those threats without the cybersecurity staff or funding available to larger hospital systems. HHS created healthcare cybersecurity performance goals that allow organizations to improve their defenses in manageable stages. Providers with fewer resources can begin with essential goals before advancing to more sophisticated protections.
They can also strengthen resilience through regional resource sharing, federal vulnerability-scanning services and participation in cybersecurity working groups.
When an incident occurs, healthcare organizations should contact the FBI or the Cybersecurity and Infrastructure Security Agency for law-enforcement and technical support. HHS focuses on the potential impact to patients, including ambulance diversions and interruptions to care. It can also connect affected organizations with experienced partners that have navigated similar attacks.
Key Takeaways
- Healthcare cyberattacks can disrupt essential services and directly affect patient safety.
- HHS cybersecurity performance goals give smaller and rural providers a practical roadmap for strengthening their defenses.
- Effective incident response combines law enforcement, technical assistance and support for maintaining patient care.
📺 Watch Full Interview
Securing Data Across a Complex Hybrid Cloud
Cyber risk is not absolute. Agencies cannot protect every system and piece of information in exactly the same way, making it essential to identify the assets that would have the greatest impact on the mission if compromised.
Michael Cardaci, CEO of FedHIVE, says agencies must evaluate the importance of their data and apply security measures based on mission risk. That work is becoming more difficult as government technology environments grow increasingly complex.
Many agencies operate across several commercial cloud platforms while retaining on-premises systems, private clouds and government-specific environments. They must modernize legacy applications while adopting containerization, artificial intelligence and other new capabilities. The result is likely to be a layered hybrid environment rather than a complete transition to any one platform.
AI adds another layer to that complexity. It can automate repetitive work, reduce labor demands and analyze information across multiple systems. It can also provide adversaries with faster and more effective tools, creating an arms race between offensive and defensive AI.
For cyber defenders, AI’s value may extend beyond finding obvious anomalies. It can help examine normal patterns of behavior and detect small changes in how people or systems access and move data. An activity may initially appear legitimate but still indicate that an account has been compromised or that a user retains access that is no longer required.
Key Takeaways
- Agencies should prioritize cybersecurity resources according to the mission importance and potential impact of their data.
- Government environments will continue to combine multiple clouds, private infrastructure and legacy systems.
- AI can help defenders identify subtle changes within otherwise normal user and system behavior.
📺 Watch Full Interview
Closing the Security Gaps in Government Communications
A government agency may possess strong cybersecurity tools and still lack resilience if those tools do not reflect how its employees actually work.
Andrew Schmitt, Sales Director for Public Sector at LeapXpert, says agencies must balance protection with usability. Employees increasingly communicate through consumer messaging applications, including Signal and iMessage. These platforms are fast and familiar, but they may operate outside an agency’s normal systems for security, compliance, governance and records retention.
The challenge becomes especially important during a crisis. Employees naturally turn to the fastest and most reliable communication channels available. If agencies block those channels without providing a practical alternative, users may create workarounds that expand the security gap.
Schmitt argues that agencies should find ways to give employees access to effective communication tools while ensuring those conversations remain secured and governed. Cybersecurity policies must account for human behavior rather than assuming that every employee will abandon familiar tools simply because they are prohibited.
Agencies should also continually revisit their policies as technology changes. “This is how we have always done it” is not a sufficient reason to maintain an approach that no longer supports the workforce or the mission.
Artificial intelligence will become part of that evolving environment, but Schmitt says human checks and balances will remain necessary. Technology can support the mission, but people must continue to oversee how it is used and whether it remains consistent with an agency’s security responsibilities.
Key Takeaways
- Cyber resilience depends on understanding how employees actually communicate and complete their work.
- Blocking familiar messaging platforms without a usable alternative can encourage insecure workarounds.
- Agencies must balance usability, security, governance and human oversight as communication technology evolves.
📺 Watch Full Interview
