Skip to main content
CybersecurityIncident Response

Agencies Shift from Volume to Decision-Quality Security Outcomes

Federal agency meeting room with diverse group seated around table under soft daylight.

“Agencies breaking through the data problem all share one defining characteristic,” Bart Larango, Strategic Industry Advisor, Federal at Splunk, explained — and that simple observation framed much of the Federal Cybersecurity Executive Summit hosted by Optiv + ClearShark.

Bart Larango on intentional, decision-oriented data architectures

Larango told Government Technology Insider that agencies succeeding at federal cybersecurity have made a deliberate choice: they decide explicitly which data is needed to support operational decisions, and then design architectures around that intent. That choice, he said, produces clarity about what data exists, where it lives, and how it is protected — answers many agencies still lack. The distinction is practical: data curated around decisions produces useful detection, investigation, and response outcomes, whereas undifferentiated bulk logging consumes resources without delivering those outcomes.

OMB mandate M-26-14: correcting a volume-over-utility approach

The summit discussion situated M-26-14 as a policy correction to a prior logging regime. Agencies that adopted the earlier federal logging mandate, M-21-31, found themselves rewarded for volume rather than utility, Larango said. The new OMB mandate, M-26-14, shifts the metric from how much data is retained toward decision-quality outcomes — examples explicitly named include continuous event monitoring, threat hunting, investigation, response, and forensics. Larango described a crucial tension reinforced across communities: compliance-oriented, normalized, schema-aligned data is necessary for meeting mandates, but operators conducting threat hunts require original, high-fidelity telemetry to be effective.

AI's role: managing velocity so humans manage judgment

At the summit, federal leaders used phrases such as “real-time visibility” and “machine-speed operations” to describe what they want AI to enable. Larango framed AI’s value narrowly and operationally: triage and initial investigation. In practice, that means using AI to sort thousands of alerts and lift repetitive workload from scarce human analysts so those analysts can focus on judgments that truly require human oversight. He outlined community-specific constraints that shape how AI is applied: the intelligence community cannot afford bandwidth-heavy triage, civilian agencies face workforce scarcity, and the military needs defenders operating inside an adversary’s decision cycle. Despite different missions, Larango said the technical answer is the same — AI to manage data volume and velocity while preserving human judgment for critical decisions.

Data-first, architecture-parallel modernization to protect legacy systems

Modernization, the summit emphasized, cannot break what already works. Larango recounted how acquisition frameworks and Authorization to Operate (ATO) processes limit agility; Department of War program managers, for example, cannot simply provision tools in weeks. The approach that works, he said, is “data first, architecture parallel”: deploy telemetry collection against legacy systems without changing those systems or introducing new attack surfaces. That telemetry layer becomes the connective tissue between current and future state architectures, allowing modernization to proceed as evolution rather than disruption and decreasing operational risk.

How the Department of War, civilian agencies, and the intelligence community will respond

  • Department of War (DoW) program managers — Constrained by acquisition and ATO timelines, they will rely on telemetry layers and parallel architectures that do not require rapid re-provisioning of tools.
  • Civilian agencies — Facing workforce scarcity and the requirements of M-26-14, they will focus on building architectures that supply decision-quality data and deploy AI for triage with human oversight to close capability gaps.
  • The intelligence community — With bandwidth and operational-security constraints, it will prioritize architectures that preserve high-fidelity telemetry for operators while minimizing extraneous triage traffic.

Larango also flagged an implementation window opened by a cluster of mandates — M-26-14 plus Zero Trust, post-quantum cryptography, and AI directives — that he said “has started implementation mandates that require architecture decisions now.” Meeting those windows, he argued, requires a specific combination: platform capacity that carries an authorization posture and classified coverage to operate where the mission lives, paired with advisory and implementation depth that understands how federal programs actually move and the human relationships between program offices and authorization officials.

“The Federal Cybersecurity Executive Summit mattered because the federal cybersecurity environment right now is uniquely demanding,” Larango reflected. The summit’s practical takeaway was concrete rather than rhetorical: agencies must back architecture decisions with platforms that span old and new environments, deploy AI with human oversight built in, and secure implementation partners able to bridge strategy and execution — or risk leaving mandates on the whiteboard.

Source: Government Technology Insider