Dana Deasy0:00
Good morning, good morning all. Right, so I understand we've got sponsors here today. You can go out and visit them during the breaks. If you're really exciting, you can go down the first floor. I think there's a fashion show or some sort of clothing lined up down there. So I was gonna try to tell you the name of the place but I can't pronounce it. So, all right, well listen, thank you Tom for the very kind introduction. It's an absolute pleasure to be part of the ninth annual Billington Cybersecurity Summit. I'd like to thank Tom for giving me this opportunity to come and speak with you today, and for Margaret McDonald for organizing what everybody knows to be a first-class event. The agenda simply looks outstanding. I may be a bit biased in that Thomas Shelley, who works on my staff, is here participating in two panels, one on automation and one on innovation. I think we'll all agree these panels are very, very timely right now, and the panel lineups on who's participating looks phenomenal. I really wish I could stay all day and listen, as I'm sure there's a lot that I'll learn as well as all you will today. As you know, this is my first role in government as the DoD CIO. I find it incredibly unique and challenging. Now, if you'd asked me a year ago what I'd be doing, I would have never imagined it was working at the Pentagon. Earlier this year, I was enjoying retirement with my wife when I received a call from Deputy Secretary of Defense Shanahan asking me to come on board and be the department's next CIO. I was a bit surprised to say the least, but knew it was an opportunity I simply could not turn down, and my wife definitely agreed with me. Working alongside our service members and dedicated civilians at the department is truly an amazing honor. The opportunity to serve my country and help solve some of the greatest problems facing our country is something I take very, very seriously. Well, enough about me. Let's get down to talking about why I'm here. I'm sure you all want to hear about the future cyber direction for the department. First, a little level setting that I think might be helpful this morning. As you know, Secretary Mattis has three lines of effort in the National Defense Strategy that are paramount to everything that we do across the DoD. You can see these on the screen. They are: delivering lethality to the warfighters, continuing to foster and grow partnerships that cut across mission success, and enacting reforms that will maximize resources and minimize unnecessary risk. Now, as the CIO, I've identified four priorities to support Secretary Mattis's vision. These, shown behind me, are cloud, artificial intelligence, communications, command and control, or known as C3, and cybersecurity. The order of the topics is by no means the order of importance, but rather think of them as the order of integration. As you may have heard, we are developing a cloud enterprise capability at the department. The cloud will truly revolutionize the technology advances for our warfighter. Next, artificial intelligence is the agent of transformational change across the DoD. We must continue to research and develop new AI capabilities. Therefore, the department plans to stand up the Joint Artificial Intelligence Center, known as JAIC. The center will develop new AI capabilities and concepts that will support DoD's military missions and business functions. Now, next is C3 modernization, which is absolutely the key to successful mission assurance. Since we are now living in the digital age, we must have C3 systems that match the times. At the end of the day, we need the right communication at the right time to protect and enable the warfighter. Given that I am here today at a cyber conference, I suspect you'd like to hear more about our fourth area: cybersecurity. Cyber touches everything we do across the department. My mantra as I talk to people across the department is that we must have a cyber-first, cyber-always mindset in everything we do. Cybersecurity must be baked into every network, every system we develop, every piece of equipment that we acquire. As a matter of fact, when it comes to managing acquisition programs, I have been advocating changes inside the department from the phrase 'cost, schedule, and performance' to 'security, cost, schedule, and performance.' Whether a soldier downrange, a sailor at sea, a civilian in their offices around the world, we must all recognize that cybersecurity is not merely an IT problem. It is the responsibility of everyone to work together and practice good cyber hygiene to protect DoD systems and networks. Now, recently I was in traffic. Now that I moved to DC, I spend a heck of a lot more time in traffic, it seems, and thought to myself that cybersecurity is a lot like driving your car. When behind the wheel, you must be aware of all potential threats on the road ahead. You put your seatbelt on because it could save your life if you were to get into an accident. You must make sure your wipers work so you can see the road in a storm. You keep your eyes on the driving behaviors of the other drivers on the road. You must make sure to use Bluetooth so you can stay focused on driving, not finding your phone when it rings. As with driving, cyber threats are often unforeseen and unknown. Just like in a car, we want to avoid a crash, and cyber crashes can be devastating. Today, I would like to talk to you about a few of the key preventive measures that the department is leveraging. These measures are holistic, interwoven, and most importantly, focus on the entire ecosystem for the department, from endpoint security to comply-to-connect, to identity, credential, access management, and to our defense base, and finally, our people. First, starting with comply-to-connect. If you look at the graphic, you will see the first component is what we are calling comply-to-connect. We all know that networks are vulnerable to cyber threats. Operator defenders face a number of problems: they cannot defend what they can't see, cannot harden what they cannot find, may be late to remediate, and sometimes mitigations simply do not work. The operators and defenders will be more able to do their job if we know who and what is on our network at any time. While straightforward, we all know this is hard to do. Comply-to-connect will help the department identify and protect devices that are connected to the department's defense networking, and they will assure that they are automatically patched to ensure secure configurations. The changing nature of cyber threats requires we remain agile and ready. Next, I'd like to talk about ICAM. I have directed, and we are working on, an identity, credential, and access management strategy for the DoD that will replace a 2014 DoD identity and access management strategy. ICAM strategy will revolutionize how we create digital identities and the maintenance of associated attributes, including both people and non-person entities. ICAM creates a secure, trusted environment where any of our users can access all of the authorized resources, including applications and, of course, our valuable data to have a successful mission. It also will let us know who is on the network at any time. Now, I know what you're thinking. Most of you hear about identity credential management at DoD and what you think about is the Common Access Card, CAC. They have been a key component in DoD security. Some of you may have heard that the CAC is going away. Well, from my standpoint, the CAC will remain the department's principal authenticator for the foreseeable future. However, the department must be ready to adapt as we accommodate an environment where more than 4.5 million users, that is rapidly evolving due to current and emerging threats from our adversaries. Now, DoD has always been a pioneer when it comes to driving innovation. We must continue to do so and incorporate key storage and biometrics and prepare for a future where we need quantum-resistant cryptography. These innovations will become critical to ensure our warfighters continue to operate in a secure environment. Now, let's talk more about our defense industrial base. I know a large part of the audience today here is comprised of our industry partners. So first of all, a huge thank you for your attendance today. Many of you are likely familiar with the Defense Industrial Base, known as the DIB, cybersecurity program. Our DIB CS program is currently voluntary, yet critical, public-private information sharing program between the government and private industry. Voluntary organizations must follow the NIST standards for maintaining security. This program enables DoD to respond and mitigate threats from adversaries and ensure DoD information is protected. We must protect our information so our capabilities remain intact. Doing so will simply save the lives of men and women in uniform. Within the DIB is the DoD Cyber Crime Center, known as DC3, the operational focal point that allows DoD to share classified and unclassified cyber threats with the DIB. As of today, there are more than 300 cleared defense companies that participate in the DIB. Now, earlier this year, Deputy Secretary of Defense Shanahan highlighted the importance for the department to ensure that commercially provided products and services from industry are secure. The Deputy Shanahan said, and I quote, 'We want the bar to be set so high it will become the condition of doing business.' I cannot echo enough how much I agree with the Deputy's comments, because the security of systems and products we acquire are critical to our national defense. We have all read the headlines about exfiltration. We need to collectively up our game. Our standards to maintain and accountability needs to be held. We must do this as partners, and we all need the headlines to stop. Finally, I'd like to talk about people. I've talked about the importance of comply-to-connect and ICAM and partnerships, but the heart of everything and fundamental to all is the people. In 2016, Congress gave DoD the authority to create the Cyber Excepted Service, known as CES, that enables the department to manage our civilian cyber professionals, focusing on mission positions. CES allows for more agile recruitment of candidates and streamlined HR procedures and delivers market-competitive pay. Fortunately, we have been able to hire many very qualified people to fill our cyber positions. However, the department needs ways to continue to bring in the brightest minds. I'd like to think that all of you today are simply a recruiting arm extension for the department. Please help us to encourage young and smart digital natives to seek a job in government service. A couple of months ago, I had an absolute pleasure to spend some time with some college students who won a National Cyber Award. They were completely engaged, incredibly well-rounded, and very eager to hear what a cybersecurity job at the DoD looks like, feels like. Taking full advantage of the opportunity to do some real-time recruiting, we had a great conversation that day, and I remember it so well. They wanted to know about what the jobs looked like at the DoD, and I simply said, 'Working at the DoD is a calling. You are on a mission, and it is simply captivating.' It is clear that we must continue to recruit and retain an eager, motivated workforce that are not only driven to serve their country but also understand that the DoD mission is unlike any other. Maintaining a strong cyber workforce is paramount to the long-term success of protecting our country. In closing, I'd like to state we cannot do this alone. The integration of cloud, artificial intelligence, and C3 will only be fully successful with a robust cybersecurity environment. The long-term success of our warfighting capabilities depends not only on the diligence of our service members and our civilians but our allies and industry partners as well. Once again, Tom, thank you for inviting me to be part of the ninth annual Billington Cybersecurity Summit. It is a rare opportunity to bring together so many people that are as passionate as I am focused on the topic of cybersecurity. We are all here to secure the future of tomorrow, today. Thank you, and I believe we have some time here to take some questions from the audience this morning.