The Federal Government’s Data Protection Relies on Resilience Beyond Just Cybersecurity

Share

In an age where cyber threats are evolving at an astonishing pace, federal networks find themselves squarely in the crosshairs. With attackers harnessing more sophisticated tools — especially those powered by artificial intelligence (AI) — the risks to government systems have intensified. A report from the Department of Homeland Security, titled “Mitigating Artificial Intelligence (AI) Risk,” shines a light on the broad spectrum of potential attacks. These threats range from disruptions in AI-enabled supply chains to direct assaults on critical infrastructure and theft of intellectual property.

As the adoption of cloud technologies skyrockets and Internet of Things (IoT) devices proliferate, the vulnerabilities within federal networks continue to multiply. In this rapidly changing landscape, relying solely on cybersecurity measures is not enough. Rather, federal agencies must embrace a resilience-first strategy. This involves integrating zero-trust principles, real-time monitoring, and robust data recovery plans into their defense frameworks.

One major challenge that federal infrastructure faces is the widespread myths surrounding resilience. While there may be an illusion of progress, the capabilities of adversaries continue to accelerate, outpacing the defenses put in place by federal agencies. Traditional tactics, techniques, and procedures (TTPs) have remained stagnant, often leaving systems exposed to emerging threats. Cyber resilience is therefore posited as the next frontier in cybersecurity — a mindset that federal cybersecurity leaders are increasingly advocating for.

However, despite this push for a resilience-focused approach, there remains a glaring gap in prioritization and investment. Rob Joyce, former director of cybersecurity at the National Security Agency, noted before the House Select Committee on the Chinese Communist Party that agencies must prepare for cyberattacks with a mindset of resilience. This means ensuring that when attacks occur, they have a limited impact, allowing for quick recovery and minimal disruption. The stark reality is that as threats become more complex, organizations cannot afford to rely merely on backups — such an approach breeds complacency and fails to account for the sophisticated tactics employed by modern adversaries.

To bolster cyber resilience, federal agencies should consider implementing three core strategies: adopting trusted security frameworks, prioritizing data safeguards, and fostering a culture of continuous improvement. The National Institute of Standards and Technology (NIST) has published essential guidelines in “Building Cyber Resilient Systems,” which outlines principles that help organizations anticipate and withstand cyberattacks, enabling swift recovery and adaptation in response to threats. The recent update to the NIST Cybersecurity Framework (CSF) 2.0 underscores the critical importance of data backups and recovery mechanisms as foundational elements of a resilience strategy.

In conjunction with these established standards, employing threat-based models such as the MITRE ATT&CK® framework can provide invaluable insights. This model offers a comprehensive overview of real-world adversary tactics and techniques, empowering organizations to adopt proactive security measures tailored to identified threats. According to Ron Ross, a former fellow at NIST, the consistent implementation of vital controls like data encryption, multifactor authentication, and access management can significantly mitigate the risk of cyberattacks.

Another cornerstone of cyber resilience lies in prioritizing training, conducting regular tabletop exercises, and fostering inter-agency collaborations. These initiatives ensure that teams are equipped to respond effectively and decisively in the event of a cyber incident. Tabletop exercises not only help to uncover gaps in existing response protocols but also build muscle memory and clarity around roles and responsibilities during high-pressure situations. Continuous training is imperative for keeping personnel informed about emerging threats and best practices. By coordinating planning efforts across departments, overall situational awareness and response agility can be significantly boosted.

Moreover, establishing strong communication channels between federal agencies and private sector partners is essential, especially in light of the organizational shifts seen in recent years. Cyber incidents rarely occur in a vacuum; often, one agency’s experience can provide valuable lessons for another. By tapping into shared experiences, adopting proven best practices, and maintaining transparent information exchanges, agencies can collectively fortify their defenses against potential threats. This collaborative approach serves as a cornerstone for building a unified government cyber defense.

To enhance resilience further, the adoption of Zero Trust principles is increasingly gaining momentum. No longer viewed as merely an optional security add-on, Zero Trust has evolved into a foundational blueprint for cybersecurity across government agencies. Research indicates that organizations with advanced Zero Trust frameworks can significantly cut breach costs, by more than $1 million, through measures such as continuous monitoring, automated data recovery, and response protocols. Ensuring that data is protected during an attack, coupled with a commitment to eliminating implicit trust in traditional backup methods, becomes essential for meeting federal Zero Trust objectives and cultivating cyber resilience.

It is crucial for agencies to extend beyond a mindset that merely relies on data backups. While backups are undeniably an essential component of any security strategy, an overreliance on legacy backup solutions can create a deceptive sense of security. Often treated as a checkbox exercise, backups may not be integrated into an organization’s broader security measures, leading to them being overlooked until a crisis strikes. Alarmingly, a significant 71% of chief risk officers predict organizational disruptions stemming from cyber risks and criminal activities.

Agencies must mobilize to enhance their cyber resilience, proactively securing government operations against a backdrop of escalating threats. By embedding zero trust principles, prioritizing training, accelerating cross-agency collaboration, and adapting to AI-driven risks, federal entities can ensure mission continuity in the wake of cyberattacks.

Travis currently serves as the Public Sector CTO at Rubrik, dedicated to helping organizations achieve greater cyber and data resilience. His expert background includes leadership roles such as Chief Technology and Strategy Officer at BluVector, CTO at Tychon, Federal CTO at FireEye, and Principal at Intel Security/McAfee, along with crucial leadership experience at the Defense Information Systems Agency (DISA).

The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of Rubrik.

Read more

Local News