Presented by EY
Cybersecurity is becoming inseparable from the way federal agencies modernize technology, processes and mission delivery. In the latest episode of “Modernizing Government: The EY Insight,” Dr. Justin Ubert, Division Chief for Cybersecurity & Operations at the Federal Transit Administration, Department of Transportation, and Rob Brougham, Principal of Cybersecurity at EY, joined Fed Gov Today host Francis Rose at the EY Center for Government Modernization to discuss why agencies must move beyond treating cybersecurity as a compliance exercise and instead design security into modernization from the beginning.
For years, federal cybersecurity programs have often been driven by compliance requirements, documentation and checklists. Ubert said that approach contributed to cybersecurity becoming siloed from the broader technology mission. Today, with agencies pursuing artificial intelligence, data modernization and other emerging capabilities, that separation is becoming increasingly difficult to sustain.
Brougham agreed that cybersecurity expertise needs to be present at the beginning of development cycles. Technology teams may understand how to build and deploy new capabilities quickly, but without cybersecurity professionals contributing context about organizational risk, mission requirements, security tools and processes, important protections can be missed. Bringing that expertise into the development process can produce a more secure product while also improving the user experience.
That enterprise perspective becomes especially important as data moves across systems and organizations. Ubert explained that agencies need to understand data lineage, provenance and how information is being used across different environments. Artificial intelligence is increasing that urgency because effective AI depends on reliable, well-managed data.
Brougham said AI is also forcing agencies to examine modernization more holistically. Agencies must consider mission value, users, security, technology, underlying data and cost together rather than treating each as a separate problem. That may require redesigning longstanding government processes to take advantage of technologies that did not exist when those processes were created.
Ubert emphasized that modernization should therefore not be defined simply by acquiring new technology. Agencies should first break processes into their individual components, determine what outcomes they are trying to achieve, and then identify where technology can improve those processes.
The second half of the conversation focused on how artificial intelligence and an accelerating cyber threat landscape are changing the way agencies manage risk.
Ubert said government cybersecurity is also becoming more contextual. Rather than automatically prioritizing vulnerabilities solely because they receive a high technical score, agencies can evaluate which systems are exposed, which vulnerabilities are actively being exploited, and how an attacker could move through an environment toward mission-critical assets. That allows limited resources to be directed toward the risks that matter most.
The conversation then shifted from cybersecurity protection to broader operational resilience. Brougham introduced the concept of a “minimum viable enterprise” — the systems, people, suppliers and capabilities an organization absolutely needs to continue performing its most important missions if a disruption occurs. Because every agency has a different mission, that minimum operating environment will also be different.
For transportation organizations, Ubert said the technology organization’s responsibility is to provide a secure and resilient environment that can support those different mission priorities. Business owners identify the workloads and functions they need most, while the technology and cybersecurity teams provide standardized platforms, controls and infrastructure capable of keeping those critical functions operating.
Ultimately, both guests argued that the fundamentals of cybersecurity remain relevant even as technology changes rapidly. The difference is how agencies apply them. Risk management must become more agile, responsive and connected to mission needs, with cybersecurity leaders operating as partners in modernization rather than as a back-office compliance function.
That shift may be the defining feature of cyber modernization: security is no longer something agencies add to technology. It is part of how resilient government systems, processes and missions are designed from the start.