“Protect identity like it is Tier-0 because it now is, and practice getting it back before the day you have to.” — Jimmy McNary
Why identity has been recast as Tier‑0
For years, agencies focused on hardening the network perimeter: stronger defenses, faster patching and improved threat detection. That posture, once the gold standard, is now being re-evaluated because attackers increasingly rely on compromised credentials and identity systems to bypass those defenses. Federal agencies are recognizing a structural shift: identity is no longer an ancillary control, it is the foundation that underpins every mission. Jimmy McNary, Deputy Federal CTO at Semperis, expressed this change in framing during a discussion on the Government Technology Insider podcast with host Lucas Hunsicker.
Active Directory and identity infrastructure as primary targets
McNary and Hunsicker focused on how identity infrastructure — with Active Directory explicitly named in their conversation — is being targeted by today’s threat actors. The implication is straightforward: when an adversary gains control of credentials or compromises identity services, traditional perimeter defenses can be rendered ineffective because identity is the gatekeeper for access and authority across systems. That centrality elevates identity to the highest tier of critical assets.

Built by Nubivance.
OSINTSights' secure edge-first architecture, AI content pipeline, and serverless ops are designed by Nubivance. We do this for clients too.
Talk to us →Recovery planning must sit alongside prevention
The podcast emphasized that building cyber resilience is more than preventing intrusions; it also requires the ability to protect and rapidly recover the identity infrastructure that supports mission activity. McNary’s admonition to “practice getting it back before the day you have to” reframes recovery planning from a secondary exercise to an operational imperative. Agencies that focus solely on prevention risk prolonged outages or degradation when identity systems are breached — an outcome the conversation treats as avoidable through deliberate recovery rehearsals and resilient identity design.
How AI factors into identity defense and attack
McNary and Hunsicker also discussed how artificial intelligence is reshaping both cyber defense and identity‑focused attacks. Although the podcast did not enumerate specific AI tools or techniques, it made clear that AI is altering the calculus on both sides: defenders must account for new patterns and speeds of attack, while attackers can leverage AI-enhanced methods against identity systems. The short exchange signals a need to adapt identity protection and recovery practices for an environment in which AI changes threat dynamics.
What this means for federal agencies, security teams, and procurement leaders
- Federal agencies: Must treat identity infrastructure as mission‑critical and integrate identity recovery objectives into continuity planning rather than assuming prevention alone will suffice.
- Security teams and technologists: Need to prioritize defenses that directly protect identity systems (for example, identity configuration, monitoring and rapid restoration capabilities) and to run recovery exercises so restoration can occur under operational pressure.
- Procurement leaders: Should factor identity resilience into sourcing decisions, seeking solutions and services that explicitly support identity protection and rapid recovery rather than relying solely on perimeter controls.
The conversation on Government Technology Insider, featuring Jimmy McNary of Semperis and host Lucas Hunsicker, narrows a broad strategic choice into a concrete instruction: protect and rehearse identity like it is the highest-value target. That statement reframes investment priorities and operational routines in agencies that depend on identity systems to execute their missions.




