September 16, 17, 18, 2025 | 2:00PM EDT | 1 Hour Each | 3 CPE

Cybersecurity professionals know that the only constant in their field is change – new threats, new bad actors, and new tools and technologies to respond to them. Keeping up with such a volatile landscape requires both alertness and agility. The federal government, responsible for defending the United States against all manner of hostile actions, takes cybersecurity seriously.

This three-part webinar series will examine some of the most urgent issues facing government agencies today. During part one, experts will share insights into how agencies can prepare for and respond to ransomware attacks, a persistent and costly threat to public organizations of every size. Part two will focus on securing the supply chain—highlighting the risks posed by compromised software and third-party vendors, and the importance of tools like the Software Bill of Materials (SBOM) in safeguarding systems. Part three will turn to Zero Trust Architecture, a comprehensive approach to cybersecurity that is rapidly being adopted across federal agencies and increasingly by state and local governments as well.

Moderator:

Bill Pratt, Moderator & Contributing Editor, FedInsider (AI Roundtable: Unlocking Efficiency & Integrity in Government Operations)

Bill Pratt
Moderator & Contributing Editor,
FedInsider

September 16 – Day One: Responding to Ransomware

Ransomware is one of the biggest cyberthreats facing government at all levels in the U.S.. According to the Federal Reserve Bank of St. Louis, there were 90,837 local government entities in 2022. A 2024 study found that ransomware attacks against state or local agencies declined in last year – only about a third of study participants said their agency had been hit by such an attack. While this is far better than 2023, when 69% of participants said their agency had been targeted, it still means almost 31,000 agencies had to defend themselves. And almost all the attacks attempted to compromise the agencies’ backups.

The federal government has been aggressive in responding to ransomware across all sectors, both public and private. The FBI has a web page dedicated to the topic and a guide to existing best practices and mitigation strategies; the Federal Trade Commission offers guidance to small businesses. The Cybersecurity and Infrastructure Security Agency (CISA) offers a one-stop portal for information and assistance in dealing with ransomware, and set up a Joint Ransomware Task Force for coordinating, deconflicting, and synchronizing efforts to combat ransomware across federal, state, local, tribal, territorial, private sector, and even international partners.

Our panel of government and industry experts will discuss the trends they see in ransomware attacks, what has proven effective at thwarting them, and how to be prepared to mitigate their impact

Learning Objectives:

  • Review the role of encryption in protecting against ransomware, including understanding end-to-end communications channels to identify which devices are not encrypted

  • Delineate your agency’s policies and practices regarding data backups (how frequently they should happen, criteria for prioritizing the systems and devices, etc.)

  • Outline how your agency can get assistance from law enforcement to remediate a ransomware attack

Cesar Gamez, Information Security Administrator, City of Roseville CA

Cesar Gamez
Information Security Administrator,
City of Roseville CA
James K. Jennings-Roche, CISO, DC3

Travis Rosiek
Chief Technology Officer,
Public Sector,
Rubrik

September 17 – Day Two: Maintaining Supply Chain Security

After seeing first-hand the massive effects of supply chain disruption during the pandemic and the impact of accidentally using infected open-source software by software providers, state and local governments are aware of the risks of supply chain disruptions due to a cyber attack.

Agencies have to broaden their thinking about where risks may be encountered. For instance, cybersecurity experts see the Salt Typhoon incursion into several U.S. telecommunications companies’ networks as a supply chain attack, where the companies’ customers – especially all levels of government – actually are the intended victims.

The Executive Order issued in May 2021 setting forth requirements to improve national cybersecurity, included the requirement that any organization providing software to the federal government must also include a Software Bill of Materials (SBOM), but there is no nationwide policy that all state and local agencies require SBOMs from their software vendors.

Our panel of government and industry thought leaders will discuss why SBOMs are useful in defending agency supply chains, what red flags you should look for in an SBOM, and the steps you can take to protect your systems while the information is being gathered.

Learning Objectives:

  • Identify what policies, if any, your agency has in place to protect its supply chain

  • Outline the most likely sources of corrupted software, such as freeware and open source code, currently used by your agency

  • Review steps you can take to evaluate your vendors’ risk of being compromised

Ryan Lewis, Deputy CISO Security Operations & Technology, Illinois Department of Innovation & Technology

Ryan Lewis
Deputy CISO Security Operations & Technology,
Illinois Department of Innovation & Technology

September 18 – Day Three: The Importance of Zero Trust Architecture

The federal mandate that agencies utilize a Zero Trust architecture to strengthen cybersecurity has been in place for four years, and most federal agencies have made excellent progress toward meeting the deadlines spelled out in the Executive Order.

State and local governments are not covered by the federal EO, but many of them are pursuing their own zero trust policies or evaluating how to implement them. After all, having a zero trust architecture in place provides a comprehensive strategic approach for protecting against a wide range of cyberattacks.

Join thought leaders from government and industry as they discuss how they have been building a zero trust architecture for their organizations, what they found most challenging, and the benefits they have seen from implementing it.

Learning Objectives:

  • List the elements of a zero trust architecture implementation plan, including risk assessments, budget and resource requirements, and multi-factor authentication techniques/tools

  • Review your own government’s commitment to and plan for establishing a zero trust architecture, government-wide and within your agency

Mark Brennan, Cloud Security Officer, New Jersey Department of Health

Mark Brennan
Cloud Security Officer,
New Jersey Department of Health
Jeff Frederick, Director, Solutions Engineering, Public Sector, Yubico

Jeff Frederick
Director, Solutions Engineering,
Public Sector, Yubico