Cybersecurity

How IT vendors should approach the federal post-quantum cryptography market

From inventory support to DARPA's $282M benchmarking initiative, here's where the opportunities are — and what to avoid, write immixGroup’s Joshua Iseler and Grier Egan.

Stop trying to prevent every cyberattack. Start planning to survive one.

Iran-linked intrusions targeting defense software suppliers are a wake-up call for agencies and contractors, writes Gary Barlet, public sector CTO at Illumio.

Find opportunities — and win them.

Google launches threat disruption unit, stops short of calling it ‘offensive’

The unit will use legal authorizations and technical capabilities to impede cyber threat groups, though company execs say it will not go so far as to hack into adversaries' systems.

How Knox Systems helps others crack the FedRAMP bottleneck

The startup secures $25M in Series A capital for its strategy to get companies authorized within 90 days.

Trump’s new cyber strategy details more offensive response to cyber threats

“Unlike other Administrations, the Trump Administration will not tinker at the edges and apply partial measures and ambiguous strategies that neglect the growing number and severity of cyber threats,” the strategy said.

CISA orders agencies to patch and replace end-of-life devices, citing active exploitation

The directive gives agencies three months to identify unsupported edge devices, a year to begin removing them and 18 months to eliminate them entirely.

White House cyber shop is crafting AI security policy framework, top official says

ONCD chief Sean Cairncross also said a bedrock National Cyber Strategy, initially expected last month, is coming “sooner rather than later” without specifying a date.

The CMMC compliance gap is now a competitive risk

As enforcement ramps up and primes tighten supplier requirements, contractors face a choice: prepare now or lose access to DOD work.

GSA quietly rolls out CMMC-like cybersecurity framework for contractors

The General Services Administration's new requirements for protecting controlled unclassified information apply immediately to new contracts, at the contracting officer's discretion.

OMB reverses Biden-era software attestation order

A new executive branch memorandum instead allows agencies to lean on software bills of materials, or SBOMs, in lieu of a universal attestation framework.

US charges former Accenture employee with misleading feds on cloud platform’s security

Danielle Hillmer, most recently employed with SentinelOne, allegedly concealed a cloud product’s noncompliance with federal security regulations.

SEC to drop high-profile SolarWinds hack lawsuit

The landmark lawsuit garnered pushback from dozens of cybersecurity leaders last year.

Transportation Command seeks zero-trust contract management system

TRANSCOM seeks a mature, cloud-enabled solution to replace legacy tools and support the military's all-domain command strategy known as CJADC2.

Upcoming White House cyber strategy to seek more involvement with private sector

The Trump 2.0 cyber strategy is in development, National Cyber Director Sean Cairncross said, though he did not elaborate on when it would be released.

CISA orders government to patch F5 products after ‘nation-state’ cyber intrusion

“This cyber threat actor presents an imminent threat to federal networks using F5 devices and software,” CISA’s directive says. China-linked hackers previously exploited F5 vulnerabilities.

Crunch time for CMMC as November deadline looms

Full implementation of the standard takes effect in a month. In the meantime, a new study shows a compliance gap that could lock unprepared contractors out of defense contracts while cyber vulnerabilities persist.

Pentagon unveils new cybersecurity framework to counter real-time threats

The five-phase construct emphasizes automation and continuous monitoring over checklists to protect defense systems.