Agencies & industry partners discuss how to modernize outdated infrastructure & secure networks with the rise of advanced technologies & a changing threat landscape.
As technology evolves at exponential rates, so do the associated challenges and security threats. To keep up with the cybersecurity changes that arise with advanced technologies (like artificial intelligence), the White House released Executive Order 14110 in October 2023 on the “safe, secure, and trustworthy development and use” of AI. In March, the Office of Management and Budget released guidance on improving governance and managing the risks of AI.
At a recent FedInsider webinar, thought leaders from government and industry discussed the impact and risks associated with implementing AI, mitigating the threat of AI on identity management controls, and the role zero trust plays as technologies and threat tactics advance.
Featured Experts:
Weighing the Impact & Risks of Implementing AI
“Complexity is the enemy of security,” said Larry Moore, chief information security officer for the Texas Division of Emergency Management (TDEM). “AI introduces an entirely new level of complexity to our environment.”
Considering the criticality of TDEM’s work, trust and resilience are key in emergency response and management, so the positive impact of implementing AI-based tools must be worth the trade-off of increased risk and cost.
Chris Bunton, chief information officer for the Texas Department of Agriculture, sees the potential of advanced technologies, but noted that leaders must first consider the return on their investment. “From a security perspective, I am always very cautious with new technology,” he said. “What are we trying to achieve? What is the bottom line? Are we trying to be more efficient or effective? Or do we want to address capacity?”
Threat actors are using advanced tools that can effectively permeate newer systems to be more successful and extensive in their breaches, potentially causing more expensive damage to recover from.
Gabe Perez, vice president of systems engineering for US Public Sector West at Fortinet, said when considering AI, it’s important to realize that “while you can buy it off the shelf, it isn’t consumed that way and you have to build it… there must be developers in your organization who actually program the intelligence.” He recommends that organizations ensure they have structured data to feed the machine, developers to program the machine and decision-makers to analyze everything.
Mitigating the Threat of AI on Identity Management Controls
The advent of AI means it will become easier for bad actors to steal or spoof someone’s identity — making identity credentialing and access management more important than ever. And with the dramatic increase of cloud in government, agencies should build the right foundation for identity credentialing and monitoring.
“If you are not building in the controls from day one, you will be challenged as soon as you get deployed and as the employment matures,” said Dave Hinchman, director of the information technology and cybersecurity team at the U.S. Government Accountability Office. “We have threats out there because bad actors are using AI. From the federal perspective, we are still trying to figure out how to best bring AI to bear to address that.”
Santina Saxby, information systems security manager for the Texas Army National Guard, said Texas is eyeing the government’s use of the Travel Document Issuance System and Identity, Credential and Access Management tools. “These are the federated, single sign-on endeavors,” Saxby said. “We’re moving in the same direction, but at different speeds.”
At the local level, Christine Conklin, cloud computing engineer for the IT Services Department for the City of San Antonio, Texas, said her office identifies users in person first during onboarding before giving them access to any resources — but implementing AI starts with policy.
“You can turn on all the widgets and configure things but… if you do not have a policy to enforce the standards, then you don’t really have a leg to stand on,” Conklin said.
From the industry perspective, Katie McCroskey, senior director of enablement at Delinea, said once agencies find the balance between security and risk, they must ensure they have the right resources, budget, skills, tools and automation to secure identities and welcome scalability.
“With cloud, we see more and more traditional security going away,” McCroskey said. “We see privilege access done in the cloud now, and privilege data in the cloud too. So, organizations need to adapt their security controls.”
Considering that the use of AI in identity management can pose ethical concerns, it’s important for agencies to know what data is being used to train any AI models that control ICAM solutions. “It’s about knowing the data, trusting the data, and ultimately growing that out to what will become the signals for identity,” said Jeff Scott, solutions architect at Intercede. “Also, you need to ask where you are collecting those data signals from, and ultimately, how are those decisions being made.”
Zero Trust as the Cornerstone for AI & Identity Management
“Zero trust is seen as the new mechanism to combat the threat landscape,” said Bart Lauwers, cybersecurity officer, Security Operations for the City of Austin, Texas. “The threats are changing, and you can no longer rely on the fact that somebody who signed in doesn’t get their token hijacked. Single sign-on is a necessity for the idea of infrastructure, but this comes with the need for a trust relationship between applications.” Austin has been on a zero trust journey for a few years, removing the old principles of implicit trust.
Nick Russo, vice president of sales of the Americas at Skyhigh Security, said zero trust is essential in preventing unauthorized access, and is also critical for stopping AI-generated attacks.
“When you are using AI, all you have to do is think of something and then you can ask the AI for whatever you want in different formats and contexts… and if you have that type of AI in your environment, I could get a piece of information that I definitely shouldn’t have,” he said. “So you still want to monitor and be able to control that data.”
Agencies are still in the process of replacing legacy equipment with the infrastructure needed to support zero trust, but adopting zero trust in government starts with culture, said Chris Jensen, public sector business development at Tenable.
“A big part of changing the culture depends on education and training,” he said. “That is something that can take a while, but that is okay because the implementation of zero trust is very incremental… I think the people side of the equation needs to be given as much attention as the technology side of the equation.”
Ernesto Ballesteros, cybersecurity state coordinator for Texas at Cybersecurity and Infrastructure Security Agency Region 6, agreed, especially considering CISA publishes cybersecurity guidance for state and local agencies. Ballesteros also said he understands that agencies are challenged with resources, manpower and budget when trying to move away from perimeter-based defenses.
“We are going to look at every resource in the organization and continuously monitor and assess the risk posture of every single access attempt, which is difficult to do. It requires a cultural shift, but also a fundamental understanding of the technology,” Ballesteros said.
That’s why all of the panelists agreed that getting to zero trust can be a long and challenging journey, but the shift in the cybersecurity threat landscape due to advanced technologies like AI requires getting started down that road as soon as possible. And so, the focus right now needs to be on figuring out how to make that journey as secure and efficient as possible.












