Technology
When Speed Becomes a Liability: Reevaluating Third-Party Risks in Federal Decision-Making
Navigating Third-Party Risk in Government Programs
The Growing Challenge of Third-Party Exposure
Third-party exposure continues to be one of the most significant vulnerabilities in government operations today. According to SecurityScorecard, a concerning 58% of breaches involving the top 100 U.S. federal contractors originated from third-party attack vectors. This statistic underscores a critical reality: the most pressing risks often lie beyond organizational borders.
Federal agencies and their contractors have poured resources into strengthening their internal systems. Cyber defenses are more robust, access controls have tightened, and monitoring capabilities have matured significantly. Yet, attackers have adapted; they no longer focus solely on the toughest targets. Instead, they exploit trusted relationships that remain outside direct oversight, leading to vulnerabilities that are often overlooked.
Understanding Where Risk Enters
Vulnerabilities often seep in through suppliers, partners, subcontractors, and affiliates, many of whom operate outside the formal security networks. These entities often maintain access to sensitive systems and data, which creates a complex risk landscape. As agencies are pressured to expedite acquisitions and partnerships, they face a growing challenge: making rapid decisions in organizations where technology and threats evolve at breakneck speed. In such a scenario, the urgency to act can transform into a vulnerability.
Consequently, the risk landscape has shifted from areas with established defenses to the partners that support operational work. Suppliers often don’t view themselves as part of government operations, even when their access points to sensitive information position them squarely in that domain.
The Pitfalls of Traditional Vetting Processes
Traditional vetting practices were designed for a slower-paced environment, wherein risk assessments occurred infrequently—often only during onboarding. However, this model has become outdated. Company dynamics change; leadership turns over, financial pressures mount, and cyber postures evolve. A supplier previously deemed low-risk can quickly become a significant threat.
Moreover, information about suppliers is often dispersed across multiple platforms—contracts, compliance records, cyber assessments, and legal reviews exist in separate systems governed by different teams. Consequently, organizations typically face delays in gathering the necessary data, and by the time a decision is made, the risk may be far more pronounced than anticipated.
Evolution of Threats
The nature of threats is also undergoing transformation. Artificial intelligence has emerged as a powerful tool for malicious actors, facilitating the bypassing of traditional trust-based checks. There have been notably alarming cases where AI-generated job seekers have infiltrated workplaces, presenting polished resumes and fabricated employment histories. These synthetic characters often slip past robust vetting processes and gain access to internal systems without raising any red flags.
The implications are serious; if a supplier unwittingly hires an individual with a false identity, that person not only gains entry to a private enterprise but also potentially accesses sensitive governmental data, networks, or operations through established connections. As such, the risk often materializes through standard operational processes, coming to light only after significant damage has been done.
The Role of Analytics and AI
To navigate this complex environment effectively, organizations can harness analytics and artificial intelligence. These tools provide the means to monitor extensive supplier ecosystems and identify shifts that might go unnoticed through conventional methods.
When utilized correctly, analytics can integrate various signals—an unexpected change in ownership, unusual credential activities, or variations in access patterns. Alone, these elements may seem innocuous; however, when examined together, they can reveal emerging risks that require immediate attention.
Analytics and AI enable leaders to focus their efforts on significant changes rather than attempting to review every detail continuously. By doing so, organizations can prioritize high-risk areas, ensuring that risk considerations align seamlessly with acquisition and partnership decisions.
Characteristics of Effective Third-Party Risk Management
Successful organizations typically embody a series of practical habits in managing third-party risks:
-
Clear Awareness of Relationships and Changes: Maintaining a comprehensive understanding of partnerships and any changes since the last review is crucial.
-
Ongoing Risk Assessment: Recognizing that risk is not a one-time evaluation; it continues to evolve throughout the relationship’s life is essential.
-
Separation of Information from Decisions: While analytics can surfacing relevant signals, human judgment remains vital in interpreting these findings and making informed decisions.
-
Integration of Risk Considerations in Decision-Making: Aligning risk assessments with acquisition and partnership actions ensures that decisions are made with a full understanding of potential vulnerabilities.
Organizations that successfully implement these practices often witness tangible benefits:
- Accelerated decision-making with increased confidence
- Earlier and more proactive risk discussions
- A readiness to disengage from problematic partnerships
- A reduction in unforeseen issues arising in the future
Conversely, organizations struggling with third-party risk management exhibit slower review processes and often make rushed decisions under pressure.
Implications of Overlooking Third-Party Risks
The stakes are extraordinarily high when third-party risks go unnoticed. Adversaries can glean valuable insights into how government operations are supported, identifying where access points exist. This intelligence can be exploited, leading to unauthorized access or leverage that threatens critical systems.
The repercussions are typically not dramatic failures but rather a series of decisions that initially seemed reasonable. By the time the cumulative risk is apparent, the impact can be profound and exceedingly difficult to rectify.
This challenge is not about knowing everything; it’s about understanding where vulnerabilities lie. Missions often falter in the gaps between organizations, systems, and trust. Leaders must confront the decision of whether to look into these seams and act proactively.
Todd Harbour is a managing member of Grist Mill Exchange and managing partner at Core4ce.
Technology
Citrix Enhances DaaS Offerings Through Numecent Acquisition
Citrix Acquires Numecent: A Game-Changer in Application Delivery
Citrix has recently announced the completion of its acquisition of Numecent, a notable player in enterprise application delivery and container management. This strategic move is poised to significantly enhance Citrix’s offerings in the cloud software arena, particularly in the realm of Desktop as a Service (DaaS). By incorporating Numecent’s innovative solutions, Citrix aims to simplify cloud-based application delivery across Windows environments, alleviating common pain points associated with traditional app management.
Enhanced DaaS Capabilities
With the acquisition of Numecent, Citrix boosts its DaaS capabilities, which are integral to modern enterprise operations. The goal is to streamline application management while cutting costs related to complex traditional app packaging and image management. As organizations increasingly migrate to cloud solutions, having robust DaaS capabilities is becoming essential to ensure seamless application delivery.
Numecent’s Innovative Solutions
Numecent brings to the table its cloud-based technologies, notably Cloudpaging and Cloudpager. These tools revolutionize how applications are delivered and managed across both physical and virtual Windows environments.
Cloudpaging
At the heart of Numecent’s offering is Cloudpaging, a patented technology that packages Windows applications into isolated containers. This allows applications to be streamed on-demand to Windows endpoints, eliminating the need for traditional installation processes or modifications to the base image. This on-demand approach significantly reduces the administrative burden on IT teams, allowing them to focus on more critical tasks.
Cloudpager
Complementing Cloudpaging, Cloudpager serves as a cloud management console enabling IT administrators to manage app assignments, push updates, roll back releases, and track usage metrics across various Windows endpoints. This streamlining of application management tasks can ultimately free up valuable time for IT professionals, enabling them to focus more on strategic initiatives.
Addressing Enterprise Challenges
Citrix recognizes that managing a Windows environment can be fraught with challenges, including bloated desktop images and application conflicts. Shawn Bass, Senior Vice President at Citrix, emphasized that application management has long been a headache for enterprise customers. Numecent’s solutions provide an elegant resolution to these issues, making it easier for IT teams to maintain and manage their software environments.
Benefits for Citrix Customers
The acquisition promises numerous enhancements for Citrix’s existing user base. By integrating Cloudpaging and Cloudpager, Citrix aims to deliver more efficient and effective application management solutions. Notable benefits include:
-
Reduced Desktop Management Costs: By isolating applications from the desktop image, organizations can minimize the number and size of images they need to maintain, driving down management costs.
-
Faster Update Cycles: The technology allows organizations to shorten application update cycles, facilitating rapid deployment of new features and security patches.
-
Application Compatibility: Legacy and modern applications can coexist without conflict, reducing the troubleshooting burden on IT teams.
-
Resilience and Recovery: In cases of ransomware attacks or site failures, Citrix users can quickly restore applications from the cloud, ensuring minimal downtime.
-
Unified Management Console: IT administrators can manage applications across physical and virtual environments from a single console, improving visibility into software usage and licensing.
Integration and Support Moving Forward
Looking ahead, Citrix plans to further integrate Numecent’s technologies into its platform while ensuring support for existing physical Windows desktops and laptops that operate outside Citrix DaaS environments. This commitment to supporting current Numecent customers will be crucial as Citrix continues to enhance its service offerings.
Arthur Hitomi, CEO of Numecent, remarked that joining forces with Citrix would accelerate their mission to strengthen application resilience across enterprises. By combining their expertise, the goal is to deliver app-centric solutions capable of thriving in complex, high-scale environments.
The financial terms of this acquisition haven’t been disclosed, but the implications are clear: Citrix is preparing to redefine application management in the enterprise landscape, fostering a more agile and responsive IT environment.
Technology
NYC Schools Implement New Policy Banning AI Use for Students Through 8th Grade
New York City Schools Enact Strict Technology Policy
In an unprecedented move, nearly 600,000 public school students in New York City will soon face stringent restrictions on the use of artificial intelligence (AI) in the classroom. This policy, set to be unveiled by Mayor Zohran Mamdani and Schools Chancellor Kamar Samuels, aims to address growing concerns about the implications of technology in education as the new school year approaches.
Restrictions on AI for Younger Students
Under the new policy, generative AI tools—including chatbots, AI tutors, and instructional programs—will be completely prohibited for all students up to and including eighth grade. High school students will also face limitations, with access granted only under “restricted” conditions. This initiative marks a significant departure from policies in other school systems, positioning New York City as a leader in limiting AI’s role in early education.
Screen Time Limits for Young Learners
In addition to banning AI tools, officials are implementing strict limits on screen time for younger students. Children in preschool through second grade will not be allowed individual learning devices during class, while students in third to fifth grades will face a daily maximum of 30 minutes. Middle schoolers won’t be able to use devices for more than 45 minutes each day. This decision reflects a broader concern about the potential negative impacts of excessive screen exposure on children’s development.
Context and Rationale Behind the Policy
As the largest school system in the nation approaches the start of the school year on September 10, the announcement signifies a dramatic shift in educational technology policy. City leaders have been under pressure from parents, educators, and lawmakers who have voiced apprehensions about the integration of AI in learning environments.
Teacher Use of AI: A Different Story
While the restrictions are severe for students, the policy allows teachers to utilize approved AI tools for specific administrative and instructional purposes. These include lesson planning and transforming materials for diverse learning needs. However, the use of AI in grading, monitoring student behavior, counseling during crises, and developing individualized education plans remains strictly off-limits.
Voices of Concern: Parents and Educators
The push for this restrictive policy has been fueled by escalating anxieties among parents. Advocacy groups have called for a moratorium on AI use in schools, citing the need for safeguards to protect students from potentially harmful consequences. UFT President Michael Mulgrew has noted that many parents fear the unknowns associated with AI, emphasizing their protective instincts toward their children.
Mulgrew described AI as “a very dangerous thing,” urging schools to avoid implementing new technologies that haven’t been thoroughly vetted. This apprehension highlights the ongoing conversation about ensuring educational tools genuinely enhance learning rather than hinder it.
Critiques of AI in Education
Supporters of the restrictions argue that many AI-driven educational programs fail to provide substantial academic value. Critics contend that these resources often resemble video games, inadvertently encouraging students to avoid traditional, critical thinking methods. This viewpoint echoes prior concerns that led to New York City’s cellphone ban, which aimed to diminish distractions and enhance student engagement.
The Mayor’s Perspective
Mayor Mamdani asserted that the tech industry may promote AI in early education as both inevitable and essential. However, he and other officials are taking a more cautious approach, pushing back against the narrative that integrating AI into early education is a must-have.
Unveiling of the Policy
The formal announcement of these significant changes is scheduled for 10:30 a.m. at the Brooklyn STEAM Center in the Brooklyn Navy Yard. This event promises to set the stage for New York City’s educational landscape as it grapples with the balance of technological advancements and children’s developmental needs.
Technology
CR Extends Cybersecurity Information Sharing Law Until December
Cybersecurity Information Sharing Act: A Continuing Debate
In the complex landscape of cybersecurity, legislative measures like the Cybersecurity Information Sharing Act (CISA) of 2015 hold significant weight. Currently, Congress faces heightened urgency regarding the reauthorization of CISA, as concerns grow over cyber threats to critical infrastructure.
A Temporary Solution
Recently, Congress opted for a temporary solution by passing a continuing resolution that extends CISA 2015 through the upcoming stopgap funding period into early December. The Senate has already approved this measure, which now awaits President Donald Trump’s signature. However, the frequent short-term extensions have only intensified calls from industry leaders for a more permanent resolution.
Growing Concerns Amid Cyber Attacks
The climate of cybersecurity is shifting rapidly, fueled by advancements in artificial intelligence and a surge in cyber incidents targeting essential services such as water and wastewater systems. The urgency for a long-term reauthorization is palpable, as recent attacks have highlighted vulnerabilities that were previously underestimated.
The Role of CISA 2015
CISA is designed to provide essential privacy and liability protections, encouraging companies to share critical data about cyber threats and vulnerabilities with government agencies and each other. This collaborative framework is vital for identifying and mitigating widespread cyber threats effectively. Despite its importance, CISA has experienced lapses; it briefly expired during last fall’s government shutdown and faced uncertainties earlier this year.
Calls for a Robust Solution
Industry groups are increasingly vocal about the need for comprehensive reauthorization. Leaders from the Operational Technology Cybersecurity Coalition (OTCC) have pressured lawmakers, emphasizing that CISA’s reauthorization is crucial for preventing large-scale cyber campaigns. Tatyana Bolton, OTCC Executive Director, pointed out that the data shared under CISA allows for timely warnings to potential victims before attacks occur.
Bolton further stressed the importance of moving beyond temporary fixes, saying, “We can no longer keep doing minor extensions of CISA 2015. We must have long-term authority to operationalize actionable, timely, and relevant information.”
Legislators’ Concerns
Despite industry pressures, not all lawmakers are on board with a straightforward reauthorization. Senate Homeland Security and Governmental Affairs Committee Chairman Rand Paul (R-Ky.) has emerged as a significant roadblock. He has indicated that any reauthorization must address free speech concerns, introducing an additional layer of complexity to the negotiations.
Industry Perspectives
Industry associations have echoed the OTCC’s sentiments. In a letter advocating for a continued extension, they highlighted the necessity of government-industry collaboration to tackle evolving cybersecurity risks, particularly those associated with AI systems. The recent launch of the Treasury Department’s AI cybersecurity clearinghouse, “Gold Eagle,” depends heavily on the protections offered by CISA 2015.
The associations warned that a lapse in CISA would undermine not just ongoing information-sharing practices but also the foundational efforts of the Gold Eagle Initiative, which aims to expedite the detection and remediation of vulnerabilities in collaboration with key stakeholders.
Extending Cybersecurity Frameworks
In addition to CISA 2015, the recent stopgap funding bill also extends other critical cybersecurity measures, including the Federal Cybersecurity Enhancement Act and the Technology Modernization Fund, providing a temporary safety net as discussions continue.
The challenges surrounding CISA 2015 underscore the delicate balance lawmakers must strike between cybersecurity interests and broader legislative concerns. As debates continue, the focus remains on finding a sustainable path forward that will adequately address the growing array of cyber threats facing the nation.
-
Comedy2 weeks agoThe funniest and most hilarious ANIMAL videos #1 – Funny animal compilation – Watch & laugh!
-
Comedy6 days agoEmmanuel Don’t Do It – Emu Goes TikTok Viral for Messing With Caretaker’s Phone
-
Celebrity clips2 weeks agoDogs Set House on FIRE while Filming an OLYMPIC Tiktok!
-
Celebrity clips2 weeks agoBest Talking Dog Videos (January 2023)
-
Comedy1 week ago? Funny and Cute Cockapoo ? Dogs and Puppies Tiktok Compilation
-
Comedy2 weeks agoFunny Hamster Compilation
-
Comedy6 days agoGoldendoodle — Adorable And Hilarious Videos And Tik Toks Compilation
-
Comedy2 weeks agoBest and funniest squirrel & chipmunk videos – Funny and cute animal compilation
