Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Why DHS no longer has a compliance mindset for cybersecurity

Дата публикации: 13-04-2026 19:12:13

Hemant Baidwan, the former CISO at DHS and now executive CISO at Knox Systems, said his former agency is doing better to stay ahead of cyber threats.

Основное содержимое страницы с новостью.

During his two years as the chief information security officer for the Department of Homeland Security, Hemant Baidwan said he has a lot to be proud of.

He led the development of a DHS cybersecurity strategy. He helped move the agency further along in its zero trust journey.

But Baidwan, who left his role in March to join the private sector, said that his most significant accomplishment as the DHS CISO was all about changing the agency’s cyber mindset.

Hemant Baidwan DHSHemant Baidwan is the former chief information security officer at the Department of Homeland Security and now executive CISO at Knox Systems.

“The biggest one that I’m really proud is helping shift our focus from purely compliance-driven approaches from a cybersecurity standpoint toward really operational risk management,” Baidwan said during an “exit” interview on Ask the CIO. “The AI threats from the adversary using AI is a real thing, and we just don’t have the luxury to rely on some of the legacy processes right now to be able to secure our systems and our data. Shifting to this approach is something I’m really proud of because it’s also just something that is extremely critical and is needed. We are in a critical time right now in the federal space and actually cyber space.”

Cyber experts have been warning public and private sector organizations about the increased threats posed by AI. In fact, in its 2026 Global Threat Report, CrowdStrike found an 89% increase in attacks by AI-enabled adversaries. Additionally, the company found AI is accelerating attacks, dropping the average eCrime breakout time to 29 minutes, a 65% increase in speed since 2024.

“In one intrusion, data exfiltration began within four minutes of initial access,” the company said.

For too long, agencies were too focused on meeting the compliance requirements of laws, policies and regulations from the Federal Information Security Management Act to zero trust. Baidwan said while compliance remains important, DHS had to accelerate its process to identify and mitigate cyber risks.

“We had to start looking at, what are the attack paths that I’m seeing today for my systems that someone can take advantage of to compromise our systems and data? How do we shift right so we identify them earlier?” said Baidwan, who now is the executive CISO at Knox Systems. “When I speak about cybersecurity through compliance versus really operationalizing the risk operations, that’s really the shift that now compliance becomes basically an outcome. You do things to bring down the risk. You’re securing your systems. It starts with good implementation, good configurations and good standards. All of that needs to be followed from the start. But this continuous monitoring piece and operationalizing that piece basically means that now the risk operations center is focused on looking at real-time threats that are impacting us.”

A better ATO process

Baidwan said DHS was trying to get ahead of the threat so they would know about a real or potential vulnerability before it became a known exploited vulnerability (KEV). He said by the time something is a KEV, it may be too late.

“Getting in front of that, trying to look at risk and issues that are coming up, and securing your systems is part of how you operationalize cybersecurity. It’s through that lens where you are monitoring real time, you have the right visibility and you have the right visibility in your identity, your architecture and what are the other things this system is touching so you can map those attack paths, and then start bringing down the risk again to make your systems secure,” he said. “We talk a lot about the flywheel approach, where once we have that visibility and we understand what our most riskiest things are, then you look at that at a large scale for the department. For example, you will know that we have this one challenge that most of the systems face, and then you can determine if is it a funding issue or a technology issue or a people issue or a process issue, or some combination of reasons. Then that leads to the right strategic discussions at the CIO Council or at the CISO Council. It helps to set your priorities for the fiscal year and the OMB budget request process. All of those things tie in very well together, but it’s hard to do that from a compliance mindset.”

Baidwan said one example of how DHS has shifted its mindset is around the authority to operate (ATO) process and applying the risk management framework.

He said DHS has moved away from doing point-in-time assessments of systems and is applying a continuous monitoring approach to more and more systems under the ATO process.

“We have the right architecture. We have the right tools. We have the right telemetry flowing in, which is the challenge within itself many times, but we have that. So if we are doing that, then how do we leverage that data to be able to test some controls and see whether they are applying multi-factor authentication effectively?” Baidwan said. “That data is continuously being obtained and evaluated so you can use that to be able to then translate that data into security decisions. How do I translate that to make sure that I have successfully tested this one control, for example, and it’s implemented effectively or not? That was a huge win.”

Copyright © 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Minnesota bringing more government organizations under its cyber umbrella011.0703-09-2026
2The 2 tech offices helping to change CMS’ approach to mission success010.9311-09-2026
3Report: Chinese 'cyber spies' hacked top US agencies014.1726-08-2026
4IDD GmbH erklärt ganzheitliche Compliance: Warum Datenschutz, IT-Sicherheit und KI zusammen gedacht werden müssen08.3621-05-2026
5Navigating Cyber Disclosures in 2026: A Limited Renewal of CISA 2015, and “Take Two” on Finalizing CIRCIA’s Reporting Regulations011.7426-02-2026
6Медведев призвал цифровизировать КПП для мигрантов на границе как можно скорее08.4629-09-2026
7COINTELPRO Is Back016.4708-09-2026
8OpenAI hack sparks further concern over AI models going rogue07.0128-09-2026
9Nvidia announces security system to stop AI agents from going rogue010.9928-09-2026

Классификация: . Схожих патентов: 0. Схожих новостей: 9. Тональность: 0. Информативность: 7.95. Источник: federalnewsnetwork.com.