Presented by FedHIVE & Carahsoft
Government agencies cannot eliminate every cybersecurity risk or protect every piece of information with the same level of effort. Michael Cardaci, CEO of FedHIVE, says leaders must identify the data and systems most important to their missions and apply security based on the potential consequences of a compromise.
Speaking at the Billington Cybersecurity Summit 2026, Cardaci describes risk as a spectrum rather than an absolute. Any information connected to an external environment carries some level of exposure.
The practical question is which data could create the greatest impact if it were stolen, changed or made unavailable. Other information may still deserve protection, but it may not justify the same investment or controls.
This risk-based approach becomes more important as government technology environments grow increasingly complicated.
Agencies frequently debate whether to operate systems on premises, in a commercial cloud or through a hybrid model. Cardaci believes most large organizations will continue using a combination.
Each major cloud provider offers different services that may appeal to a particular program or mission. A large agency will often need to interact with several of those platforms rather than standardize everything on a single provider.
At the same time, agencies may retain private infrastructure to preserve data sovereignty or support specialized requirements. Government-specific cloud environments add another layer.
Legacy systems cannot be modernized all at once, and new technologies continue entering the enterprise. Containerization, artificial intelligence and modern applications must operate alongside older platforms that still support active missions.
The resulting environment can resemble a complex collection of interacting services rather than a clean migration from one architecture to another.
Security strategies must account for information moving across all those layers. Agencies need visibility into where their data is located, which systems can access it and how controls remain consistent as it travels.
Cybersecurity teams can use AI to identify anomalies across multiple systems faster than analysts could through manual review.
Adversaries have access to the same advantages. They can use AI to find weaknesses, automate reconnaissance and adjust attacks. Cardaci expects that competition to become an arms race between offensive and defensive systems.
Agencies cannot simply adopt AI and assume it will improve their security. They need to understand which data the system can access, whether its conclusions are reliable and how an adversary might manipulate it.
Human oversight remains important, but people alone cannot review the volume of activity generated by large hybrid environments. AI can help narrow the field and direct analysts toward the most important behavior.
Many cybersecurity tools focus on activity that is clearly unusual. A login from an unexpected country or a major transfer of data may generate an immediate alert.
Cardaci says AI may help agencies examine more subtle changes within otherwise normal behavior.
An attacker using a legitimate account may avoid obvious anomalies. The activity could appear routine at first glance, but small changes in how the user accesses information or moves through systems may reveal the compromise.
AI can establish a more detailed picture of normal behavior for individual users and systems. It can then identify variations that do not cross a traditional alert threshold but still deserve review.
The same analysis can help agencies manage permissions. A user may have legitimate access to data but no longer need it for a current role. Continuous review can identify those unnecessary privileges before an attacker exploits them.
Traditional access strategies often begin by denying broad access and creating exceptions for approved users. The size and complexity of modern agencies make it difficult to verify that every exception remains appropriate.
AI can support a more dynamic process, but agencies must connect the technology to clear mission priorities. The objective is not to generate more alerts. It is to understand how data is being used and focus defensive resources on the systems that matter most.
Key Takeaways