Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

CMS Pivots to Risk-Based Cybersecurity Model, CISO Says

by Jamie Bennet
August 4, 2026
in Cybersecurity, Federal Civilian, News
Keith Busby. The CMS CISO discussed the agency's shift from compliance- to risk-based cybersecurity model.

CMS Chief Information Security Officer Keith Busby discussed the agency's shift from compliance- to risk-based cybersecurity model.

  • CMS Chief Information Security Officer Keith Busby said that the agency is transitioning from a compliance- to risk-based cybersecurity model
  • One of the agency’s strategies is to utilize its Cybersecurity and Infrastructure Security Agency’s bug bounty program
  • Busby explained that they will abide by a “protect first, visibility second” philosophy

The Centers for Medicare and Medicaid Services is reworking its cybersecurity approach, moving away from a checklist-driven compliance model toward one built on continuous monitoring, attack surface management and real-time threat response, Keith Busby, CMS chief information security officer, said in an interview with Federal News Network.

Table of Contents

    • You might also like
    • FEMA Appoints Steven McAndrews as CIO
    • Raytheon Lands $23B Navy Tomahawk Missile Contract
    • DHA Seeks Industry Input on Modernizing Joint Medical Planning Tools
  • What Is CMS’ Attack Surface Management Approach?
  • How Is CMS Using AI in Its Risk-Based Cybersecurity Model?
  • How Will CMS’ New Strategy Impact Its Cyber Workforce?

You might also like

FEMA Appoints Steven McAndrews as CIO

Raytheon Lands $23B Navy Tomahawk Missile Contract

DHA Seeks Industry Input on Modernizing Joint Medical Planning Tools

Busby said the shift is designed to tie regulatory compliance directly to active defense rather than treating the two as separate obligations. “We’re starting to make that transition from just having visibility, but using automated continuous reaction based off of that visibility,” he explained.

The federal government has spent more than 10 years building out visibility into agency networks through initiatives such as the Cybersecurity and Infrastructure Security Agency’s Continuous Diagnostics and Mitigation program. Busby said CMS is now building on that foundation with a “protect first, visibility second” philosophy, using the data gathered through monitoring to trigger automated protective action rather than simply cataloguing risk.

Because CMS operates in the healthcare sector, a frequent target for ransomware groups and other malicious actors, the agency’s overriding cybersecurity priority is preventing any disruption to patient care.

CMS Pivots to Risk-Based Cybersecurity Model, CISO Says

Federal health leaders from HHS, DHA, and more are converging on December 3 to share how they are spending billions on artificial intelligence, modernization and expanded care access. Reserve your seat at the 2026 Healthcare Summit on December 3 and get the inside track on FY27 contracting priorities straight from the decision-makers.

What Is CMS’ Attack Surface Management Approach?

To get ahead of emerging threats, CMS has shifted from relying primarily on system authorization documentation, according to Busby. The agency tracks what is being scanned and what shows up in connection with CMS systems, layering internal monitoring with input from independent researchers. CMS taps into the Cybersecurity and Infrastructure Security Agency’s bug bounty program to invite outside researchers worldwide to probe its public-facing systems and flag weaknesses.

Busby added that the agency’s guiding principle is to keep CMS data inside environments it can directly monitor and control, limiting how often information or system functions move outside networks and assets where CMS can enforce its own security controls. The broader goal, he said, is to pull those functions back in-house so that partners can still carry out their work, but do so within CMS-controlled environments.

How Is CMS Using AI in Its Risk-Based Cybersecurity Model?

Busby also described artificial intelligence as a force multiplier for the agency’s cybersecurity mission. CMS is recruiting recent graduates with AI-related skills as part of a broader push toward in-house hiring intended to cut costs and increase flexibility.

Rather than deploying AI broadly, Busby said his team is targeting specific, well-defined use cases — including alert triage, behavioral analytics, anomaly detection and vulnerability prioritization — so that performance can be closely tracked and the tools can be held accountable.

How Will CMS’ New Strategy Impact Its Cyber Workforce?

To keep up with evolving cybersecurity technologies and approaches, CMS already announced earlier this year that it intends to add about 100 positions to its Office of Information Technology. Busby noted that many recent graduates already arrive with hands-on experience in areas such as agentic AI, and said the agency wants to learn from that incoming talent rather than force new hires to simply adopt legacy practices.

The agency is also bringing more technical functions in-house, including hiring junior ethical hackers — a role CMS has traditionally filled through contractors. Busby said the goal is to give early-career federal employees a chance to learn and experiment on the job, with many expected to advance to larger roles elsewhere in government as their careers progress.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

AFRL, Texas Space Commission Ink Deal to Fast-Track Commercial Space Tech for Defense

Next Post

GSA Is Reworking How New Tech Reaches Federal Agencies

Recommended For You

Space Force Transfers Control of AEHF-5 Satellite to Space Ops Command

by Matthew Nelson
December 6, 2022
Space Force Transfers Control of AEHF-5 Satellite to Space Ops Command

The U.S. Space Force has handed over to the Space Operations Command the authority to control a communications satellite built by Lockheed Martin.

Read moreDetails

A Steve Jobs Opera—Why Tech Innovators Are Today’s Shakespearean Heroes

by Charles Lyons-Burt
May 7, 2025
Daniel Glaser, K2 Integrity head of of global jurisdictional services

Traditionally, operas tend to take grand, historical characters as their subject matter. “Shakespearean figures, mythical characters from Wagner, Puccini’s tragic heroines, Verdi’s conflicted kings,” opera enthusiast and Washington...

Read moreDetails

Jen Easterly Says Federal Computer Software Manufacturing Should Improve

by Branson Brooks
August 24, 2024
2024 Wash100 272x270 Jen Easterly

Due to a recent surge of cybersecurity infiltrations, Jen Easterly, director of the Cybersecurity and Infrastructure Security Agency, believes the technology industry must advance computer software manufacturing processes to...

Read moreDetails

AECOM Exec Shailen Bhatt Nominated to Lead DOT’s Federal Highway Administration

by Naomi Cooper
July 22, 2022
AECOM Exec Shailen Bhatt Nominated to Lead DOT's Federal Highway Administration

Shailen Bhatt, senior vice president of global transportation innovation and alternative delivery at AECOM, has received a nomination from President Joe Biden to serve as administrator of the...

Read moreDetails

Cybersecurity Exec Sean Plankey Nominated to Lead CISA

by Jane Edwards
March 12, 2025
Cybersecurity Exec Sean Plankey Nominated to Lead CISA

President Donald Trump has nominated Sean Plankey, former director for cyber policy at the National Security Council, to serve as director of the Cybersecurity and Infrastructure Security Agency.The...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • C5ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • Department of War
  • DHS
  • Digital Assets
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Intelligence Community
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Technology
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!