Security1 publisher2 min readPublished
CISA's CDM deputy program manager says the program collaborated too slowly for yesterday's threats
Richard Grabowski told a FedScoop-produced breakfast that CDM has to get faster and that responsible automation at scale is the route to it. The one interval he attached is a three-year roadmap for the program's SIEM service.
The Watch · Security desk

What happened
- CISA's Continuous Diagnostics and Mitigation program, which supplies tools and capabilities to other federal agencies, has to speed up before it can push those agencies to move faster, Richard Grabowski said Tuesday.
- Grabowski said CDM's cloud-based SIEM as a Service, used for threat analytics and incident response, has a three-year roadmap for expansion that includes ramping up staff and conducting training.
- He named three core goals for the program: velocity, unification of data across agency deployments, and data-driven risk management during crisis-level events.
- Matt House, CISA's acting associate director and CDM program manager, said the program has been evolving since the SolarWinds breach compromised at least nine federal agencies.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- contradiction The automation pitch and a staffing ramp came from the same official in the same talk: on this record, CDM automation and federal headcount travel together.
- constraint An agency waiting on faster CDM delivery has one horizon to plan against, the three-year SIEM roadmap.
- exposure The missing government-wide operating picture House describes is the condition incident responders still coordinate in, and the breakfast leaves this quarter's detection where it was.
- decision Duffy's demand-aggregation principle would move capability selection up to federal scale, turning an individual agency's tool preference into an input to a joint buy.
The automation Grabowski described targets alert handling. Getting faster means pushing responsible automation of tasks that can also run at scale, he said. That way, he said, experts can focus more on dealing with novel threats and on the adoption and tuning of advanced technology, and not on hitting alerts every other day. [3][4]
On velocity, Grabowski said, "The way that we collaborated today wasn't fast enough for the threats of yesterday, and they certainly aren't going to be fast enough for the threats of tomorrow." [2] He did not attach a date or a measurable target to that goal. [10] Unification means keeping data out of silos, he said, so "we are connecting those deployments in a meaningful way to really stimulate reusable, actionable lessons learned." [8] The third goal is crisis performance. Agencies should "see what is happening with timely, accurate, and trustworthy data, so that we are the tool of first response when the things hit the fan." [9]
The procurement side came from Mike Duffy, the acting federal chief information security officer, who gave three principles for what comes next. [11] The first is aggregating demand across agencies with common problems. "When agencies need the same capabilities, we should use federal scale to improve security, interoperability and value," Duffy said. [12] The second is "buying outcomes, not product," by stating the outcomes government wants and leaving commercial markets room to innovate. [13] The third is to "design acquisition for continuous improvement," meaning acquisition models that promote competition and let new capabilities enter. [14] "Now is not the time to set capabilities and move on for the next 10 years," he said. [15]
All three federal officials quoted at the event hold acting titles: Grabowski as acting branch chief of service delivery, Duffy as acting federal CISO, and Matt House as CISA's acting associate director and CDM program manager. [19] The venue was the Elastic Federal Cyber Defense Breakfast, produced by FedScoop. [18]
House described the gap CDM has been working on. "Post-SolarWinds, one of the things that that the government took away was," he said, "we lack what I would say is a common operating picture with respect to the operational visibility we need to be able to assess and coordinate response government wide." [17] The breakfast produced goals for closing it, and no schedule. [10][17]
What to watch
- Whether CISA publishes a schedule or a measurable target for CDM's velocity goal.
- Whether the staffing ramp inside the three-year SIEM as a Service roadmap survives the budget cycle.
- Whether the three officials setting CDM's direction keep the roles once permanent appointments are made.