What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Industries
- Government
- Reported by
- 1 outlet
Get our latest cybersecurity news first on Google.
A Cybersecurity and Infrastructure Security Agency program that provides tools and capabilities to other agencies has to get speedier so it can push them toward being able to move more quickly themselves, an agency official said Tuesday.
“We have to get faster,” said Richard Grabowski, acting branch chief of service delivery and deputy program manager for the Continuous Diagnostics and Mitigation program at CISA. “The way that we collaborated today wasn’t fast enough for the threats of yesterday, and they certainly aren’t going to be fast enough for the threats of tomorrow.”
That means pushing responsible automation of tasks that also can do so at scale, he said, so that experts “can focus more [on] dealing with the novel threats and adoption and tuning of advanced technology, and not hitting alerts every other day.”
Velocity is one of the three core goals for the CDM program, along with unification and data-driven risk management, Grabowski said at the Elastic Federal Cyber Defense Breakfast, produced by FedScoop.
Unification means keeping data out of silos so “we are connecting those deployments in a meaningful way to really stimulate reusable, actionable lessons learned,” Grabowski said. And data-driven risk management means that in the event of a crisis-level event, agencies are able to “see what is happening with timely, accurate, and trustworthy data, so that we are the tool of first response when the things hit the fan.”
One of CDM’s offerings is Security Information and Event Management (SIEM) as a Service, a cloud-based platform for threat analytics, incident response and more. Grabowski said there’s a three-year roadmap for expanding and enhancing it, including by ramping up staff and conducting training.
Mike Duffy, the acting federal chief information security officer, said at the same event that three principles should guide what comes next for CDM. One is aggregating demand across agencies that share common problems: “When agencies need the same capabilities, we should use federal scale to improve security, interoperability and value.”
Second, he said, “is buying outcomes, not product” by making it clear what outcomes the federal government is seeking and then allowing commercial markets room to innovate.
Duffy said the third was to “design acquisition for continuous improvement,” meaning making sure that acquisition models promote competition and opportunities for new capabilities to enter.
“Now is not the time to set capabilities and move on for the next 10 years,” he said. “Mow that agile mindset of how we can continue to deliver and deploy capabilities based on the threats we’re seeing to reduce risk at scale across the federal government — that is absolutely key.”
CDM has been evolving since the SolarWinds breach that compromised at least nine federal agencies, said Matt House, CISA’s acting associate director and program manager for CDM.
“Post-SolarWinds, one of the things that that the government took away was, we lack what I would say is a common operating picture with respect to the operational visibility we need to be able to assess and coordinate response government wide,” House said at the event.
Latest Podcasts
Government
Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal
Hawley probes OpenAI over Hugging Face breach
Governments ‘buying time’ in race between innovation, security, national cyber director says
FTC rescinds policy statement requiring health apps to notify customers after a breach
Technology
The G7 tells industry to hurry up and prep for post-quantum encryption
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Pegasus, NoviSpy variant spyware found on devices of Serbian activists
Wyden seeks upgraded NSA security guidance on commercial VPN use
Threats
GitLab's critical flaw is already drawing internet-wide probes
Conti ransomware crew member sentenced to four years in prison
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Lawmakers call on Commerce to sanction hackers-for-hire
Policy
FBI cyber chief worries private sector not sharing enough cyber threat information
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Reproduced in full under licence from CyberScoop. © CyberScoop. Written by Tim Starks.
Coverage
One outlet has carried this so far.
2026-09-15 19:45 UTC
Related stories
- [Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
Dark Reading · 2026-11-12
- [Virtual Event] Building a Secure AI Strategy for the Enterprise
Dark Reading · 2026-10-08
- CISA and NIST Issue Guidance to Protect Cloud Identity Tokens
Infosecurity Magazine · 2026-09-16
- Ministry of Justice apologizes after court staff accessed Southport victims' files
The Register · 2026-09-16
- Windows Server 2022 reaches end of mainstream support next month
BleepingComputer · 2026-09-16