Federal Cybersecurity Has Changed, CDM Must Change with It.
- ICIT Research
- 54 minutes ago
- 5 min read
August 2026
Authors: Brett Freedman - Senior Director of Emerging Technology, Hugo Holopainen - Research Lead
The federal government's Continuous Diagnostics and Mitigation (CDM) program helped transform civilian cybersecurity over the past decade, but the environment it was built to protect no longer exists.
In 2013, the majority of CFO Act agencies operated a local federal data center. Today, those very same agencies run workloads in at least two or three clouds and hold mission data in several hundred SaaS subscriptions that no single office has fully inventoried. Meanwhile, advances in artificial intelligence, automation, and adversary tooling are accelerating the speed at which vulnerabilities can be discovered and exploited; the window between a vulnerability's disclosure to confirmed exploitation of a high-severity vulnerability has been reduced to 5 days from an average of 8.5 days in 2025.
If CDM is to remain one of the federal government's most important cybersecurity investments, it must evolve. Instead of compliance-oriented monitoring, it must become a practical enterprise cyber defense program through an acquisition model. This model would consolidate common capabilities into enterprise purchases, design a technical core to support incident response, and provide visibility that follows agency data into the cloud and AI systems where that data now resides. To add insult to injury, these changes will need to be implemented amidst a Cybersecurity and Infrastructure Security Agency (CISA) at the Department of Homeland Security (DHS) that has lost roughly a third of its staff in just the last year and a budget the administration has now proposed cutting again.
This is the context for a renewed look at CDM, one of the federal government’s most important cybersecurity programs. Launched in 2012, it was created to help civilian agencies identify, monitor, and manage cyber risk through tools, sensors, dashboards, and shared services. In the years following, it helped agencies build capabilities around asset management, identity and access management, network security, and data protection. CDM has also given both CISA and federal leaders a mechanism for understanding cybersecurity posture across the Federal Civilian Executive Branch (FCEB). In practice, however, large parts of the program have functioned primarily as a compliance and scorecard reporting mechanism.
While CDM retains its value, it was largely designed for a federal environment that predates Zero Trust architectures, large-scale cloud adoption, and generative AI.
A new white paper issued jointly by the Institute for Critical Infrastructure Technology (ICIT) and the Center for Cybersecurity Policy and Law (CCPL) entitled CDM 2.0: Advancing Federal Cybersecurity, asserts that CDM should evolve beyond compliance-focused acquisition and reporting into a dynamic operational platform designed for the realities of the next decade. The white paper recommends a set of reforms described further below.
REFORM THE ACQUISITION AND FUNDING MODEL
Devise a clearer acquisition and funding model. Fragmentation can increase administrative burden, limit visibility into duplicative purchases, slow deployment, and make it harder for the government to understand where capability gaps remain. CDM is well positioned to help address this by aggregating buying power for common cybersecurity capabilities and creating more consistent pathways for agencies to access vetted tools and services.
OMB and CISA should identify a limited set of core enterprise cybersecurity categories suitable for CDM coordination, while preserving agency flexibility where mission needs differ. Core capabilities such as endpoint detection, asset discovery, vulnerability management, identity security, cloud security, data protection, logging, and Zero Trust access are needed across the FCEB. A transparent exception process can help balance consistency with operational reality, while a Centralized Chief Information Officer (CIO) pilot program with small agencies could produce a more secure, efficient, and cost-effective IT management model.
A more coordinated CDM model. This would help reduce duplication, improve licensing, standardize terms, and give smaller agencies access to capabilities they may not be able to acquire efficiently on their own.
MODERNIZE CDM’S TECHNICAL CORE
CDM's technical architecture also needs to keep pace. The federal dashboard was built to support periodic reporting and oversight, while CISA and agencies increasingly need it to support decisions made on the timeline of an active intrusion.
Must complement agency security operations centers and existing security platforms. Its value should come from helping CISA and agencies better understand where risk is concentrated, where tools are deployed, where coverage is incomplete, and where coordinated action is needed.
EXPAND VISIBILITY TO NON-TRADITIONAL AND EMERGING ASSETS
Extend visibility into assets. Federal networks no longer consist primarily of traditional on-premises IT assets, and agencies now depend on cloud workloads, SaaS applications, and AI-enabled systems, to name a few. These assets are extremely valuable, but they also expand the attack surface.
CDM 2.0 should provide a phased, risk-prioritized approach for extending visibility into these environments. Cloud security is especially urgent: federal systems are increasingly hybrid and multi-cloud, and traditional monitoring approaches may miss threats it faces. As such, CDM should support cloud-native security capabilities that reflect how modern federal systems are built and attacked.
CDM must adapt to AI as well. Agencies need visibility into how AI systems access data, interact with identities, and create new attack paths across federal environments. AI is being adopted for agency cyber (as we learned at ICIT's Congressional Summit, CISA already has access to Mythos), and its adoption introduces new questions around sensitive data exposure, third-party AI services, shadow AI tools, model and data supply chains, etc. CDM should help agencies manage these risks through common visibility standards and shared guidelines.
The federal government has already invested billions of dollars and more than a decade of effort in CDM. The question is now whether that investment will remain anchored to yesterday's cybersecurity challenges or instead adapted for the challenges yet to come.
Zero Trust, cloud computing, machine identities, and AI are reshaping the federal attack surface, and adversaries are already adjusting to that reality. CDM should too.
For more detail, read the ICIT & CCPL CDM 2.0 White Paper and Recommendations here.
Brett Freedman has nearly two decades of experience at the highest levels of government. A
Partner and Head of Government Affairs at Gray Space Strategies, a strategic advisory firm,
Brett’s public service career includes serving as a Legislative Assistant for a Congressman and as
a Presidential Management Fellow in the Department of Homeland Security. Brett was an
Attorney at the National Security Agency and in the National Counterterrorism Center in the
Office of the Director of National Intelligence.
In 2013, Brett served as the Counsel to the President’s Review Group on Intelligence and
Communications Technologies which examined the disclosures of classified information by
Edward Snowden. He then served as Counsel to the Senate Select Committee on Intelligence,
including as General Counsel for then-Chairman Mark R. Warner (D-VA). Most recently, Brett was
Chief of Staff for Assistant Attorney General Matthew G. Olsen of the National Security Division at
the Department of Justice, helping oversee the daily operations of several hundred attorneys in
foreign investment, counterterrorism, counterespionage, and cybersecurity.
Brett holds a Juris Doctorate, a Master of Law and Diplomacy, and a Bachelor of Arts in
International Affairs. He is also an Adjunct Professor at Georgetown University in cybersecurity
Hugo Holopainen leads research and content development at ICIT and Gray Space Strategies, bringing technical depth and disciplined analysis to the organization’s engagements. Hugo researches the intersections of cybersecurity, aerospace, critical infrastructure, emerging technology, and defense.
He brings experience across security and international environments, with a background spanning military service, diplomatic work, and emerging technology. His work focuses on understanding complex systems, analyzing technical developments, and translating that understanding into immediate decisions and longer-term positioning and program direction. His work bridges defense, cyber, and emerging technology to inform strategy at the nexus of security and innovation.
About ICIT
The Institute for Critical Infrastructure Technology (ICIT) is a nonprofit, nonpartisan, 501(c)3think tank with the mission of modernizing, securing, and making resilient critical infrastructure that provides for people’s foundational needs. ICIT takes no institutional positions on policy matters. Rather than advocate, ICIT is dedicated to being a resource for the organizations and communities that share our mission. By applying a people-centric lens to critical infrastructure research and decision making, our work ensures that modernization and security investments have a lasting, positive impact on society. Learn more at www.icitech.org.
-500x198.png)
