Federal Tech Podcast: for innovators, entrepreneurs, and CEOs who want to increase reach and improve brand awareness

John Gilroy
undefined
Sep 29, 2026 • 31min

Ep. 351 Why Federal AI Needs Trust, Governance, and Human Oversight!

SAS has led data management for the federal government for over fifty years. We face a new technology that tightly integrates data and AI. Today, we sit down with Reggie Townsend to get his ideas on human involvement in AI and review a new report, the 2026 Data and AI Impact Report. AS's 2026 Data and AI Impact Report, based on IDC research, finds that trustworthy AI is strongly associated with better business results. Organizations with strong governance, data quality, auditability, and explainability practices were 15 times more likely to report strong AI ROI. Nearly all users—97.2%—override AI recommendations at least occasionally, with lack of explanation the leading reason. Trust also declines as AI becomes more autonomous. Only 17.5% of enterprises have data infrastructure mature enough for agentic AI. The study, covering 2,699 decision-makers across 28 countries, concludes that strong data foundations and trustworthy AI practices are essential for successfully scaling AI. During the interview, Townsend tempers this information with comments about a human component, typically called getting the human in the loop. He begins by noting that humans are part of the solution, then comments on federal involvement. Townsend thinks government involvement in evaluating AI capabilities may be warranted to protect citizens.
undefined
Sep 23, 2026 • 19min

Ep. 349 AI Is Changing the Speed of Federal Cyber Attacks Today

Malicious cyber-attacks are increasingly driven by AI and identity vulnerabilities. Today, we sat down with Adam Meyers from CrowdStrike to detail this acceleration and offer some solutions. Attack Acceleration Meyers highlights a significant decrease in breakout time, which is the duration between initial access and lateral movement. In 2024, the average breakout time was 48 minutes. By 2025, this decreased to an average of 29 minutes, with the fastest recorded at 27 seconds. One reason for these attacks is strategic. Current defenses often focus heavily on endpoints while neglecting identity and cloud control planes. Specifically, organizations must monitor many issues. For example, unauthorized users provisioning new multi-factor authentication (MFA) devices. Also, impossible travel scenarios where logins occur from disparate geographic locations in impossible timeframes. During the interview, Meyers expands on the concept of "cross-domain hunting." They must constantly switch between roles—such as threat hunting and incident response—across various tools and screens, contributing to burnout rates comparable to air traffic controllers or EMTs. Emerging Trends AI is driving a massive increase in vulnerability discovery; CVE publications in June 2026 were up 96% compared to June 2025. Additionally, machines now generate two and a half times as many detections as humans. The conclusion is that AI will be able to fight AI in cybersecurity. It may be a rocky road, but it will balance the threat in the end.
undefined
Sep 23, 2026 • 18min

Ep. 348 Protecting Federal Data in the Age of AI and Zero Trust

Years ago, the phrase "big data" entered the vocabulary of federal technology leaders. Please note, it was not "accurate" data; it was not "significant" data, just big. Today, we sat down with Monty Montgomery from Island to get some insight into best practices for protecting data in modern federal systems. He expands on concepts like data valuation, zero trust implementation, and AI integration. Data. Monty begins by stating the obvious: not all data is equal; protecting low-value information like hobbies is inefficient compared to protecting high-value assets like Social Security numbers or banking details. Further, agencies often struggle with "data buckets" that treat all information as having uniform value, which leads to misallocated labor hours. Zero Trust Implementation The conversation highlights a shift from traditional perimeter security to a more granular, user-centric Zero Trust Architecture. Monty notes that monolithic, multi-billion-dollar network stacks often fail because they are too rigid; instead, agencies should adopt tools that move closer to the user and allow for rapid iteration. AI Integration The emergence of generative AI introduces new paradigms for both data protection and potential vulnerabilities. Best practice is for agencies to run experiments to "fail fast," allowing them to learn from unsuccessful attempts rather than committing to inflexible, large-scale failures. Listen to the interview to gain insight into protecting data at rest, data in transit, and data in use.
undefined
Sep 16, 2026 • 22min

Ep. 347 How Fake Job Applicants Threaten Federal Cybersecurity Today

When most federal technology leaders look at preventing cybersecurity attacks, they rarely go beyond the network. Today we are looking at a new breach vector: the resume. Patricia Titus from Abnormal AI begins the interview with a shocking story about a recently discovered exploit. In the summer of 2026, the FBI confirmed that a North Korean operative spent months working inside a federal agency as an authorized employee. Because of this incident, Titus makes the case for why the security perimeter must extend upstream to the resume. During the interview, she details how VOIP numbers are used to mask origins. Beyond that, advances in voice duplication (vishing) allow HR personnel to be duped. Not only that, but today's AI technology allows a single actor to manage several accounts. In other words, today we have a scenario playing out where a naïve hiring manager can have several fake resumes from the same individual competing for the same position. Once a system is compromised, lateral movements are enabled to gain access to sensitive areas of the network. There are attempts to block this system, commonly called Application Tracking Systems (ATS). Gaps in the ability of this system can be addressed by establishing a formal partnership between the cybersecurity team and the HR department. From there, behavioral patterns can be used to detect abnormal patterns. The conclusion is obvious; can public sector leaders effectively validate identity without relying solely on automated systems that may be deceived by high-quality synthetic data?
undefined
Sep 14, 2026 • 26min

Ep. 350 Elastic and Google Distributed Cloud: AI-Powered Cyber Defense in Air-Gapped Environments

Today, we sat down with leaders from Elastic and Google Distributed Cloud to discuss how their unique combination of skills can address cybersecurity, AI operations, and resilience in sovereign air-gapped environments. Most listeners hear the phrase "air-gapped" and think absolute safety. Sean MacKirdy from Elastic offers insight into air-gapped environments. He reminds the audience that, by definition, an air-gapped system cannot get updates from the Internet. That means they are vulnerable to attacks. Further, data transfers, cross-domain guards, patching cycles, supply chains, USB devices, and insiders remain potential entry points. Google's TJ Banasik's solution is to consolidate tools. For example, common tools include capabilities like endpoint detection, user behavior analytics, and vulnerability management. Elastic Security can be combined with Google Distributed Cloud. For example, Elastic uses specialized, self-managed platforms to provide unified security for air-gapped environments. This automation reduces fatigue, staffing requirements, response time, and integration complexity in a SOC. This interview provides a brief overview of the concepts discussed. For more details, please attend the Google Public Sector Summit on October 20, 2026, at the Reagan Center in Washington, DC. You'll see how Elastic and Google Distributed Cloud work together, with subject matter experts in the room with you. Federal agencies must consider how to protect air-gapped networks amid regulatory authorization, data sovereignty, and operational risk. That is why it is important to meet face-to-face with developers from Elastic and Google to determine the optimized solution for your agency. The Google Public Sector Summit presents the perfect opportunity to accomplish that task.
undefined
Sep 10, 2026 • 23min

Ep. 346 Security Telemetry: Detecting Insider Risk in Federal IT

Michael Crossland, Solutions Engineer for National Security Programs at DTEX Systems, discussed the evolution and importance of insider threat protection in the federal government. DTEX, with over 20 years of experience, focuses on data capture and telemetry to enhance risk and behavioral awareness. Crossland makes the argument that behavior is key to reducing the cybersecurity risk. Crossland emphasized the challenges of managing remote workforces post-2020 and the role of AI in both productivity and security risks. Because of the DTEX experience, they can draw from a wide background to be able to move from reacting to an attack to being able to have proactive insider-risk detection. He highlighted the significance of metadata in understanding user behavior and the need for privacy-first approaches. Crossland also touched on the future of cybersecurity, predicting a continued focus on AI and behavioral analytics to stay ahead of threats.
undefined
Sep 3, 2026 • 23min

Ep. 345 How AI Is Transforming Federal Cognitive Operations

Here is the free media kit from Federal Tech Podcast The explosion in sensors and remote devices has led to many discussions in the federal tech community. In fact, there is a podcast called Feds at the Edge. Today, we look at how an AI native startup can help the military make accurate and speedy decisions at the tactical edge. Our guest is Carrick Longley, the CEO of ZenithFlow. He came to understand the problem of operating in a contested environment while serving in the U.S. Marine Corps. He begins the discussion by examining decision-making in a remote environment. Traditionally, one may use the well-known OODA loop. That is to say: Observe, Orient, Decide, Act. This concept may have had application in earlier environments. However, today, a warfighter may lose communication in the first few minutes in a contested environment. They could be in a world where disinformation is present, and decisions are extremely difficult. During the interview, Longley discusses circumstances in which a warfighter may be deluged with information yet lack a way to filter the most important data. Longley expands upon a concept called "cognitive domain." From his perspective, data is not the problem. He states that the way we process the information makes sense. That way, we can make better decisions off that data. For Longley, speed in decision-making is accomplished by moving the human's decision earlier. He emphasizes the importance of early detection and pre-bunking of adversarial narratives, as well as the need for synthetic audiences to test messaging effectiveness. Listen to the interview to learn how a network must be able to operate in isolation and still inform military leaders to make decisions that are rapid, accurate, and effective.
undefined
Sep 1, 2026 • 27min

Ep. 344 Why Cybersecurity Must Shift from Compliance to Resilience

Here is the free media kit from Federal Tech Podcast John Gilroy and Snehal Antani, CEO of Horizon Three AI, discuss the evolving landscape of cybersecurity, emphasizing the need for a shift from compliance to resilience and defense. The discussion began with taking a look a common list of vulnerabilities. Back in 2021, CISA could develop a list of common vulnerabilities, and they called it the Known Exploited Vulnerability Catalog. It was an authoritative list of specific software flaws and security bugs that had been verified in the wild. Today, malicious actors have overwhelmed us with vulnerabilities. We have reported 1600 software and hardware vulnerability entries, making it almost impossible to address each issue. Antani argues that what is important it to patch the critical vulnerabilities, not the complete list. He states, "I'd rather patch the right few things quickly than everything slowly." During the interview, Antani refers to a couple of federal initiatives that reinforce his approach. For example, BOD 26-04 is an initiative from CISA that signals a move from vulnerability identification to real world exposure. This concern is beyond the federal government. The European Central Bank has looked at threats and is telling bank CEOs that AI is shortening the time from discovery to exploitation Antani also predicts that small and medium-sized companies will be prime targets for cyber-attacks in the coming months. From small businesses to federal governments to banks, it looks like we are in the middle of a drastic change in the way organizations handle vulnerabilities
undefined
Aug 25, 2026 • 22min

Ep.343 Building Trustworthy Agentic AI for Federal Mission Success

Today we hear what James Rebsco from Striveworks has to say about solving this problem for the federal government. Rebesco suggests beginning with a deep understanding of the problem. Once you make sure the solution makes sense, then look at AI opportunities that can help solve the problem. Applying the solution to real-world situations can be difficult. One may produce a model that behaves flawlessly in a clean, air-conditioned environment. In the real world, the situation is changing daily, commonly called a contested environment. The defense community must deliver and manage production-grade machines that operate in austere, disconnected, and high-stakes environments. Some in the academic community would like to put a stop to AI progress. The idea is to produce ethical and moral guidelines before proceeding. That certainly sounds nice when debating on a campus. Rebesco points out that we do not have the luxury of this approach. In today's geopolitical environment, we have adversaries who are very smart, capable, and well-resourced. History has shown us the results of appeasement and delay. He emphasizes the importance of embedding AI in real-world scenarios and ensuring models can adapt and learn. Robesco also discusses the concept of "situational awareness" in AI and the need for continuous testing and evaluation. During the interview, he mentions StriveWorks' platform, Chariots, which aims to provide dependable, mission-critical AI solutions.
undefined
Aug 18, 2026 • 19min

Ep. 342 Making Zero Trust Practical With Modern Identity Security

John Gilroy and Danelle Osworth discuss Delinea's privileged access management (PAM) solutions on the Federal Tech Podcast. Delinea's unique selling points include delivering just-in-time access, a hybrid platform for on-premises and cloud environments, and continuous verification of identities. During the interview, Ginelle has an insightful comment about Zero Trust and the federal government. She looks at Zero Trust as an opportunity for the government to take cybersecurity steps in the right direction. The key concept is to begin the Zero Trust journey, not necessarily where they begin. Oswroth goes on to say that identity security is the foundation for everything in cyber. In the future, standing privilege will feel as outdated as passwords on a sticky note. But today's threat is unyielding. This means that an identity solution must be able to continuously monitor access as well as credentials. Osworth emphasizes the importance of zero trust principles and the practical application of identity management. Delinea's platform supports 99.995% uptime and encrypted vaulting for machine and AI identities. They highlight the need for continuous authentication and authorization to manage the influx of non-human identities. The conversation also touches on the challenges of balancing security with innovation in the federal government.

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app