Skip to main content
Cybersecurity

Pentagon Shifts Cybersecurity Focus to Leverage Emerging Tech

Modern lab with sleek workstations and futuristic devices surrounding a prototype device.

"We can't continue to throw people at the cyber problem; we have to throw technology at the cyber problem," Department of Defense Chief Information Officer Kirsten Davies told the Billington Cybersecurity Summit in Washington, D.C., laying out a pivot in how the Pentagon plans to defend its sprawling digital estate.

Pentagon CIO frames a technology-first posture

Davies described the Department of Defense’s cybersecurity challenge as a "complex Rubik's cube of problems" driven by a mix of new and legacy systems across thousands of networks that include both civilian and military components. That technical heterogeneity, she said, requires tools that span "everything from automation to machine learning to actually AI" and—crucially—capabilities that "must operate even when it's disconnected."

Her remarks emphasized two linked objectives: reduce reliance on sheer headcount for routine defense tasks, and deploy machines to handle scale, speed and continuity. At the same time, Davies argued that human talent must be used "in a much more effective way" so the department can pair its personnel with automated systems rather than replace the workforce outright.

Hiring shift: skills-based recruiting and apprenticeships

To match the new approach, Davies said the department is prioritizing applicants' demonstrable abilities over traditional educational credentials. That includes a specific emphasis on skills relevant to working with AI systems—she named "prompt engineering" as an example of a capability the department is now looking for in candidates.

Practical steps have followed rhetoric. DOD began accepting applications in July for a new Cyber Registered Apprenticeship Program intended to expand the cyber talent pipeline through skills-based hiring. The department closed its first job listing four days early after receiving more than 15,000 applications, and plans additional rounds of opportunities.

From policy shop to active mission role: acquisition reform under way

Davies said her office is shifting away from operating merely "as a backend policy shop" and taking a more active role in the department’s mission. "Reform is a big thing for us," she said, and the first phase of that reform involved identifying policies and mandates that could be reduced or eliminated—work that she said affected more than 60% of relevant DOD guidance.

Part two, Davies explained, is attacking the acquisition process itself. Where approvals and onboarding of new capabilities typically can take "anywhere from six to 18 months," she described a test of a platform that reduced that timeline to 17 seconds. Davies tempered the demonstration with questions about substantive risk: "Are we asking the right questions? Are we demanding the right documentation from software companies? Is the output of a 17-second process actually reducing risk?"

CMMC pause and a formal review by the CMMC Reform Task Force

The CIO’s office has also taken a tangible regulatory step: it suspended the second-phase requirements for third-party assessments under the Cybersecurity Maturity Model Certification program. The mandatory security framework for defense contractors was stopped in July for a 60-day review by a CMMC Reform Task Force; that assessment period is set to end on Friday. The task force has received more than 1,100 responses to its request for information on CMMC’s next steps.

On the same day Davies spoke, Washington Technology reported that DOD is moving beyond a simple suspension and is effectively implementing a binding regulation that would codify the pause—an operational change that would formalize the temporary halt to second-phase assessments while the task force completes its review.

What this means for technologists, procurement teams, and DOD cyber staff

  • Technologists and security teams: Expect increased emphasis on automation, machine learning and AI-capable tools that must function in disconnected environments; teams will need to develop skills to integrate and validate outputs from fast, automated acquisition channels.
  • Procurement leaders and defense industrial base companies: The department’s push to shorten approval cycles and cut more than 60% of guidance suggests vendors will face new, accelerated review paths—but they will also need to provide clearer documentation and answers to the questions Davies highlighted about risk and required deliverables.
  • DOD cyber staff and recruits: The department is signaling a hiring standard that favors demonstrable skills—such as prompt engineering for AI—over formal degrees. The Cyber Registered Apprenticeship Program, which drew more than 15,000 applicants to its first posting, is the immediate mechanism for bringing that talent into the department.

Davies’ comments sketch a department trying to square speed and scale with security and governance. The test that delivered a 17‑second approval raises a sharper question than the demonstration may intend: can a dramatically faster process be paired with the documentation and oversight the department itself says it needs? While the CMMC Reform Task Force collects input and the apprenticeship program continues to attract candidates, the department's next moves—how it defines required vendor outputs, how it validates accelerated procurements and how it integrates agentic AI into everyday operations—will determine whether "throwing technology" supplements human expertise safely, or simply shifts the burden to a new set of unanswered questions.

Original story