While artificial intelligence continues to dominate cybersecurity conversations, several federal policy developments are quietly reshaping the security landscape for enterprises — particularly organizations that work with the U.S. government or operate critical infrastructure.
Speaking at the CyberRisk Leadership Exchange in Boston last month, ICIT founder and chairman Parham Eftekhari urged security leaders to look beyond political headlines and pay attention to the policy work taking place across federal agencies.
"There's politics, and then there are the folks doing the work," he said. "The folks doing the work are genuinely there because they want to make America safer."
The developments he flagged continue to unfold. Here's what he covered — and where each stands today.
"CISA is in good hands with Nick [Anderson]," Eftekhari said. "The people doing the work care about the mission, and they care about helping make organizations more secure."
For CISOs, that means AI governance programs should be designed with flexibility in mind rather than assuming a single federal standard will emerge in the near term.
Eftekhari said that some recent procurement and contracting changes received relatively little attention despite their potential impact on organizations selling into the federal market. Even amid the Pentagon's recent pause and review of CMMC's third-party assessment phase, underlying NIST SP 800-171 and DFARS obligations remain in force — and contractors should expect cybersecurity to remain a condition of doing business with the government.
"It seems like everybody has forgotten about quantum because of AI," Eftekhari said.
Federal investment in quantum technologies continues to accelerate through executive action and bipartisan legislation, while existing federal law already requires agencies to inventory cryptographic systems and prepare for migration to post-quantum cryptography. Recent executive actions have expanded that focus with additional workforce and technology initiatives.
"If you're not doing your cryptography inventories now, you really need to start," he said.
Security leaders should treat Washington the same way they treat threat intelligence: as another source of strategic risk information. Understanding how legislation, executive orders and geopolitical developments affect supply chains, cloud providers, technology investments and regulatory expectations allows CISOs to provide better guidance to executive leadership and boards.
"The people who can connect policy, business risk and cybersecurity are going to become more valuable to their organizations," Eftekhari said.
Rather than relying solely on news headlines, he encouraged security leaders to follow updates from agencies such as CISA, NIST, ONCD and other federal organizations directly to better understand how policy changes translate into operational priorities. He also pointed audience members to ICIT which provides a weekly policy update to its members.
Speaking at the CyberRisk Leadership Exchange in Boston last month, ICIT founder and chairman Parham Eftekhari urged security leaders to look beyond political headlines and pay attention to the policy work taking place across federal agencies.
"There's politics, and then there are the folks doing the work," he said. "The folks doing the work are genuinely there because they want to make America safer."
The developments he flagged continue to unfold. Here's what he covered — and where each stands today.
1. CISA is rebuilding while continuing operational priorities
Although the Cybersecurity and Infrastructure Security Agency (CISA) continues to operate under acting leadership, the agency has begun rebuilding portions of its workforce after earlier staffing reductions while maintaining priorities such as vulnerability management and public-private collaboration. Eftekhari encouraged organizations not to mistake political uncertainty for operational paralysis."CISA is in good hands with Nick [Anderson]," Eftekhari said. "The people doing the work care about the mission, and they care about helping make organizations more secure."
2. AI regulation is becoming increasingly fragmented
The White House has established a national AI policy framework through Executive Order 14365, but state governments continue to move forward with their own AI legislation, creating a patchwork of requirements similar to what organizations experienced with state privacy laws.For CISOs, that means AI governance programs should be designed with flexibility in mind rather than assuming a single federal standard will emerge in the near term.
3. Federal contractor cybersecurity requirements continue to expand
Organizations doing business with the federal government should closely monitor evolving cybersecurity requirements surrounding Controlled Unclassified Information (CUI) and NIST SP 800-171 compliance.Eftekhari said that some recent procurement and contracting changes received relatively little attention despite their potential impact on organizations selling into the federal market. Even amid the Pentagon's recent pause and review of CMMC's third-party assessment phase, underlying NIST SP 800-171 and DFARS obligations remain in force — and contractors should expect cybersecurity to remain a condition of doing business with the government.
4. Quantum deserves as much attention as AI
The strongest warning from the discussion centered on quantum computing."It seems like everybody has forgotten about quantum because of AI," Eftekhari said.
Federal investment in quantum technologies continues to accelerate through executive action and bipartisan legislation, while existing federal law already requires agencies to inventory cryptographic systems and prepare for migration to post-quantum cryptography. Recent executive actions have expanded that focus with additional workforce and technology initiatives.
"If you're not doing your cryptography inventories now, you really need to start," he said.
5. Policy awareness is becoming a leadership skill
Perhaps the most important takeaway had little to do with specific legislation.Security leaders should treat Washington the same way they treat threat intelligence: as another source of strategic risk information. Understanding how legislation, executive orders and geopolitical developments affect supply chains, cloud providers, technology investments and regulatory expectations allows CISOs to provide better guidance to executive leadership and boards.
"The people who can connect policy, business risk and cybersecurity are going to become more valuable to their organizations," Eftekhari said.
Rather than relying solely on news headlines, he encouraged security leaders to follow updates from agencies such as CISA, NIST, ONCD and other federal organizations directly to better understand how policy changes translate into operational priorities. He also pointed audience members to ICIT which provides a weekly policy update to its members.
