A program by the Cybersecurity and Infrastructure Security Agency (CISA) is set to enhance its speed and efficiency in providing cybersecurity tools to federal agencies. Richard Grabowski, acting branch chief of service delivery and deputy program manager for the Continuous Diagnostics and Mitigation (CDM) program, emphasized the need for faster collaboration to address evolving cyber threats. “We have to get faster,” he stated, noting that current methods are insufficient for both past and future threats.
To achieve this, the CDM program aims to implement responsible automation of tasks, allowing cybersecurity experts to concentrate on more complex threats rather than routine alerts. Velocity, unification, and data-driven risk management are identified as the three core goals of the program. Unification involves breaking down data silos to facilitate meaningful connections and actionable insights, while data-driven risk management ensures agencies have timely and accurate information during crises.
One of the key offerings of the CDM program is Security Information and Event Management (SIEM) as a Service, a cloud-based platform designed for threat analytics and incident response. Grabowski mentioned a three-year roadmap for its expansion, which includes increasing staff and providing training.
Mike Duffy, the acting federal chief information security officer, outlined three guiding principles for the future of CDM: aggregating demand across agencies, focusing on outcomes rather than products, and designing acquisition processes for continuous improvement. He stressed the importance of maintaining an agile mindset to adapt to emerging threats and reduce risks across the federal government.
The evolution of the CDM program has been significantly influenced by the SolarWinds breach, which affected at least nine federal agencies. Matt House, CISA’s acting associate director and program manager for CDM, highlighted the need for a common operating picture to enhance operational visibility and coordination in response efforts.
For more details, refer to the full article on CyberScoop.
Follow Cyber Warriors Middle East for further global cybersecurity developments.



