Available on Demand | May 28, 2025 | 2 Hours | 2 CPE
The federal government has invested almost four years to move all its systems and networks to a least permissive access architecture, based on the concept of “never trust, always verify.” This has significantly improved cybersecurity, but it’s a moving target – bad actors, whether cyber criminals or hostile nation-states, keep evolving their tools and tactics, seeking new vectors they can penetrate.
To constantly improve an agency’s risk profile, security professionals must pay attention to trends both in cyber attacks and in new defensive measures. For instance, hackers are using AI to help their social engineering efforts, ferreting out and stealing legitimate login credentials.
Join us as thought leaders from government and industry discuss their progress in implementing least-permission and how they are thinking about next steps.
We’ll Discuss:
Accreditation:
Participants can earn 2 CPE credits in Business Management & Organization.*
* To receive CPE credit you must arrive on time and participate in the surveys throughout the webinar. Certificates will be e-mailed to registrants. In accordance with the standards of the National Registry of CPE Sponsors, 50 minutes equals 1 CPE. By providing your contact information to us, you agree: (i) to receive promotional and/or news alerts via email from Federal News Network and our third party partners, (ii) that we may share your information with our third party partners who provide products and services that may be of interest to you and (iii) that you are not located within the European Economic Area.
What is CART?
CART (communication access realtime translation) provides instant accessibility for all participants by delivering the spoken word as a realtime stream of text.
CART Captioner Professional Certifications
Our CART services are provided by Home Team Captions. All of our CART captioners hold, at minimum, the CCP (Certified CART Provider) certification, or higher, from NCRA (National Court Reporters Association.)
To view the CART feed for this webinar: Register for this webinar, login from the link provided, and click on the CART Tab and click the link to begin using CART.
Hosted By:
Opening Remarks:
Fireside Chat:
Session One: Rethinking Least Permissive Architectures
The federal push to implement zero trust architectures across all agencies is built on five pillars – identity, devices, networks, applications and workloads, and data. These work well, but do not address one of the government’s ongoing issues: the existence of technology silos, where – whether because of outdated, legacy systems or capture by proprietary tech – that make achieving least permissive much more difficult. This is where the concept of “least privilege” comes in.

Sr. Scientific Technical Manager, Cybersecurity,
Naval Information Warfare Center (NIWC)
Session Two: Identity, Access & Micro-segmentation
Identity is central to zero trust, but it also can be a fluid concept; users can be identified by their job titles, the tasks they’re assigned, the work groups – both within and across disciplines – they contribute to, to name a few examples. A user might require access to a particular application in one role, for instance, but have no need for access when working in another of their roles. Utilizing micro-segmentation – dividing networks into smaller segments that can be isolated, often at the individual workload level – can mitigate threats from users that legitimately have access to one part of a system but should not be able to move laterally to other parts of that system.
Session Three: Building Cross-Pillar Capabilities
Integrating security across the five pillars means ensuring visibility across all of them, and analytical tools that can take the information to present a unified picture. To accomplish that requires both automation – to ensure that cybersecurity is consistent and up-to-date – and orchestration that ensures all the pillars are attended to in a timely manner. These measures also apply to governance, such as the application of required regulations and reporting.
Closing Remarks:












