"The Coast Guard has about 1,500 different locations globally in which we provide services," Captain Patrick Thompson told attendees at the Ivanti Public Sector Summit.
Captain Patrick Thompson on the Coast Guard's dispersed footprint and environmental constraints
That 1,500-location figure framed one of the Summit's central problems: scale plus environment. Captain Patrick Thompson described a network that includes manned stations, planes, helicopters, ships and remote communications sites that often host sensors and radios. Many of those sites sit in places that are hard to reach — "at the top of a mountain," "atop skyscrapers," or in places in Alaska and Maine that "you need a snowmobile or something to get to," he said — making routine maintenance and patching difficult.
Mark Treleven on submarines, underwater drones, and the next frontier of connectivity
Extending networks beyond the shore and into the depths of the sea emerged as a provocative operational question. Mark Treleven, Lead Field Chief Technology Officer at Ivanti, said he had been "reading an article the other day about submarines and underwater drones in the ocean, and the need to create connectivity for those devices so that you could change the logic of the drone in the field." He posed the practical problem plainly: "How do you do that? But more importantly, how do you protect those endpoints and make sure they stay on mission? You’ve got subs that are essentially floating, underwater SCIFs."

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadKevin Walsh on inventories, identity, CDM, and the limits agencies face under Zero Trust
For federal systems, knowing what is on the network has become foundational. Kevin Walsh, Director of the Information Technology and Cybersecurity Team at the U.S. Government Accountability Office, argued that asset inventories are essential "so that we can know what to protect. You can’t protect it if you don’t know about it, and that’s a problem in the government."
Walsh laid out four interdependent aspects of modern defense under Zero Trust: "what do you have on your network," "who is on your network," "what is happening on your network," and "how to protect what’s on your network." He reported that agencies are generally doing okay at the first two — inventories and identity — but that "the latter two things, not so much." He also highlighted how the Internet of Things has blurred traditional boundaries: "Your refrigerator may now be a target for Chinese espionage. Who knew?"
What this means for technologists and security teams, for military and maritime operators, and for vendors and patch providers
- Technologists and security teams: The Summit stressed that continuous diagnosis and mitigation (CDM) tools must be deployed broadly and that visibility alone is not enough — agencies must close gaps in traffic monitoring and active protection. The GAO assessment quoted by Kevin Walsh implies teams must accelerate work on the "what is happening" and "how to protect" elements of Zero Trust.
- Military and maritime operators: For maritime services like the Coast Guard, environmental access constraints require patching and maintenance solutions that are automated, resilient, and tolerant of long periods without human intervention. Captain Thompson tied such reliability directly to mission outcomes, including the ability to "communicate to mariners in distress."
- Vendors and patch providers: Rapid vendor patch delivery needs corresponding speed and governance in distribution. Summit speakers highlighted the vendor-to-device pipeline as a chokepoint: vendors are "coming out with patches quickly," and organizations must be prepared to get those fixes to remote endpoints as fast as possible.
Patching, automation, and the AI dilemma: voices from the Summit
Speakers tied urgency for faster, more automated patch management directly to AI-driven threats. Captain Thompson warned that "AI has a lot of potential. It also has a lot of peril. There’s good. There’s bad. It introduces new risks. It introduces new opportunities," and concluded bluntly: "Is it going to help the attackers more or the defenders more? Right now, I’d say it’s helping the attackers more."
That asymmetry in speed — attackers using AI to find and weaponize vulnerabilities faster than defenders can respond — pushed multiple Summit participants to argue for automation with controls. According to Illum, "We need to be using AI where we can with governance, with guardrails, to be able to deliver the patches faster from the vendors to the individual systems." Captain Thompson echoed the operational requirement for automation plus redundancy: "Making sure that we have solutions in place where patching can happen quickly, can be fully automated, and can have resiliency and redundancy is incredibly important," because the failure of those systems would have real-world safety impacts.
The Ivanti Public Sector Summit brought federal, state, local, and military voices together around a sharply narrowing window: networks are expanding to hard-to-reach places and to new classes of devices, AI is accelerating attackers' capabilities, and patch pipelines and defensive tooling must get faster, more automated, and more resilient. The tradeoffs are concrete — from snowbound mountain-top radios to underwater drones — and the prescriptions offered by Summit speakers were correspondingly pragmatic: inventory relentlessly, close gaps in monitoring and protection, and automate patch delivery with governance so mission-critical systems remain available when they are needed most.




