VYPR
advisoryPublished Sep 15, 2026· 1 source

CISA's CDM Program Accelerates Cybersecurity Tool Delivery to Federal Agencies

CISA's Continuous Diagnostics and Mitigation (CDM) program is undergoing a significant overhaul to enhance its speed and efficiency in providing essential cybersecurity tools and capabilities to federal agencies.

The Cybersecurity and Infrastructure Security Agency (CISA) is prioritizing a dramatic increase in the speed and efficiency of its Continuous Diagnostics and Mitigation (CDM) program. This initiative aims to equip federal agencies with cybersecurity tools more rapidly, enabling them to respond more effectively to the evolving threat landscape. Richard Grabowski, acting branch chief of service delivery and deputy program manager for CDM, emphasized the urgency, stating, "The way that we collaborated today wasn’t fast enough for the threats of yesterday, and they certainly aren’t going to be fast enough for the threats of tomorrow."

The program's strategic evolution is centered around three core goals: velocity, unification of data, and data-driven risk management. Velocity is paramount, pushing for the responsible automation of tasks to allow cybersecurity professionals to focus on novel threats and advanced technology adoption rather than being overwhelmed by routine alerts. Unification seeks to break down data silos, ensuring that deployed security capabilities are interconnected and generate actionable insights for continuous improvement.

Data-driven risk management is crucial for crisis response. In the event of a significant incident, agencies must have access to timely, accurate, and trustworthy data to enable swift and informed decision-making. This capability is intended to position CDM as a primary tool for federal agencies when critical events occur. One key offering within the CDM program is Security Information and Event Management (SIEM) as a Service, a cloud-based platform designed for threat analytics and incident response, which is slated for significant enhancements over the next three years.

Mike Duffy, acting federal chief information security officer, outlined additional principles to guide the program's future. These include aggregating demand across agencies with common needs to leverage federal scale for improved security and interoperability, and focusing on procuring desired security outcomes rather than specific products, thereby fostering market innovation. The emphasis is on acquiring capabilities that deliver results, allowing commercial vendors flexibility in how they achieve those outcomes.

Duffy also stressed the importance of designing acquisitions for continuous improvement, moving away from long-term, static deployments. An agile mindset is essential to continually deliver and deploy capabilities that adapt to emerging threats and reduce risk across the federal government at scale. This approach ensures that the cybersecurity posture of federal agencies remains dynamic and responsive.

The CDM program's evolution is particularly significant in the wake of the SolarWinds breach, which impacted at least nine federal agencies. Matt House, CISA’s acting associate director and program manager for CDM, noted that the incident highlighted a critical deficiency in a "common operating picture" for operational visibility across the government. This lack of unified visibility hampered the ability to assess and coordinate response efforts effectively.

Moving forward, CDM aims to provide this much-needed common operating picture, enhancing government-wide situational awareness. By focusing on speed, data integration, and outcome-based acquisition, CISA intends to bolster the overall cybersecurity resilience of federal networks against increasingly sophisticated threats. The program's post-SolarWinds recalibration underscores a commitment to proactive and adaptive cybersecurity defenses for the federal enterprise.

Synthesized by Vypr AI