What the New Administration Means for Cyber with Gary Barlet
In this segment, Gary Barlet will speak to how long-standing government workers can be roadblockers to deploying new technology, how the new administration could push for a more aggressive approach against nation-states, and how AI is going to potentially close the federal skills gap and the large role it will play in 2025.
Transcript
This is Textron tv. Good morning everyone. Welcome back here to techron tv.
My next guest is Gary Bartlett. Gary is the public sector CTO for Illumio. Illumio.
If you don't know, well, Gary's gonna tell you about Illumio if you don't know. But first, let's say hello and hear about Gary. Hey, Gary, welcome to Textron tv.
How are you? I'm doing great, Alan. Thank you for having me today.
I appreciate it. It's our pleasure to have you on. Gary, before we jump into Illumio and, and we're going to talk about cyber and the next administration, let's hear a little bit about your journey.
Sure. Um, so, uh, I've been in the cyber realm for basically my entire adult life. Um, started off, I spent 20 years as a cyberspace operations officer in the United States Air Force.
Uh, retired as lieutenant Colonel, um, and then became a federal CIO for 10 years at the office of the Inspector General for the United States Postal Service. Wow. Uh, I've been around, uh, DOD for, you know, you know, 20 years and then federal go for another 10 years.
And after doing that for 30 plus years, uh, finally decided it was time, maybe for a slight change. And, uh, so I came over to the private sector and, uh, where I joined Illumio as the public sector C two O about just, just shy of three years ago. Good for you.
You know, so I wasn't always on this side of the camera. I, I actually did a number of public, no, not a number of ve uh, venture backed startups. Someone went public.
Um, but one of them was in cyber still secure. And we, about 60% of our business was fed federal space. And for those of you out there who have never had the pleasure of dealing in the federal space, it's, it's really a world unto itself.
It's a market unto itself. It's a huge market. I, I forget, I used to know what the IT spend on the, in the federal budget space were, but it's literally hundreds of billions, right?
Yes. Uh, when you go through it and, and DOD within the Fed, right. Fed space, you have civilian and DOD within the DOD and the three letter agencies.
It's yet another sort of labyrinth of, of procurement and contracts and certifications and and so forth. So, God bless you for doing what you do. And, you know, and this, and this, by the way, is apparent and we see people who, who've lived that Fed World for a number of years, and then companies like Illumio who want to be in the Fed space, they need people like Gary to, to navigate this.
And that's exactly why they brought me over. Right. Is, you know, I'm familiar with the policies, I'm familiar with the language, I'm familiar with all the contracting, the, the rules surrounding money, uh, you know, how is, uh, secured and spent.
And, uh, and, and as you said, it's, it's a very different world unto itself. Uh, and it's very hard to understand if you haven't actually lived it. Yes, sir.
Our mistake was, we, so we were selling something called NAC back then, network Access Control. And we had, we had big contracts with the Army and the NMCI, Navy Marine Corps Internet, uh, department of Interior, a whole bunch, and other agencies and stuff. But what happened was we made our products so specific to what the feds wanted, that it really was not as good as a commercial product because it was, you know, military great.
Right? It was, you know, it was built for them. But anyway, you live and learn.
Uh, Gary Illumio, some folks out here have heard of Illumio. I'm sure some folks out here are probably Illumio customers even, but there's a lot of folks who have and it aren't. So why don't you, if you don't mind, give us a little bit of the Illumio story.
Absolutely. Uh, so Illumio is coming up when 11 years old. Uh, we got started in the financial sector, uh, working with banks.
So we are a microsegmentation company. Yep. Which means, uh, that we focus on internal to the enterprise.
Uh, and trying to answer the question, what happens after the inevitable breach happens, right? So, when you look at a lot of enterprises today, they spend a lot of time, energy, resources into preventing a breach, but really don't pay any attention to what happens after a breach occurs. Right?
So how do you prevent the initial breach from spreading laterally, uh, inside your enterprise, right? Uh, in the zero trust realm that's off, often referred to as at East West Movement. Um, so what do you do once an adversary, once a piece of malware, once a piece of ransomware has gotten inside your enterprise?
What do you have in place to prevent that from spreading? Uh, so that's where Illumio comes in. We provide a very easy way to do a couple of things.
One is we allow you to visualize, uh, in a, in a nice map, in a nice graphical way, what things are touching, what, uh, you know, from a, which applications are talking, which other applications, which servers are talking to, which other servers. Uh, and we do that in a very user-friendly manner that is network agnostic. Um, and the reason why network agnostic is important is adversaries or malware.
They don't care about the underlying routers and switches that are connecting things. They care. Can one server talk to another server?
'cause that's how they jump. That's how they move. Yep.
That's right. They compromise one server, then they look and say, what other servers can we, can we get to, to compromise? So what I Illumina does is we come in and we create individual little compartments inside your enterprise.
Uh, so we ask ourselves, which servers should be talking to which servers, and let's turn everything else off. If, if servers don't have any reason to talk to each other, then they should not be talking to each other. A classic bureau trust, right?
Absolutely. So fits, fits very well that zero your Blacklist. Absolutely.
So we get into, uh, really, if you're really doing this right, you, it's an allow only model, right? You only allow the traffic that is absolutely necessary for applications to function and you turn everything else off. Uh, we love using the, the, uh, visualization of a submarine, right?
Everybody kind of has seen movies with submarines or they, you know, maybe they've been on a real submarine. Um, so it's really, uh, when you look at a submarine, they have all these little individual compartments, right? And why do they do that, right?
Why do they have all these individual doors that they can shut? Well, if, if the submarine springs a leak, a leak without all those individual compartments, the submarine's gonna flood and sink, right? So with those individual compartments, you can shut off all those individual compartments.
And one individual leak doesn't cause a submarine to sync. So in the cyber realm, that means that a individual breach, right? A a cyber breach doesn't turn into a cyber disaster, right?
You don't have, it Gets Contained. It, it gets contained, and you don't have the entire enterprise end up getting owned. So that's really where Lumio comes in.
And we do this with cloud Native, we do this with on-prem, uh, and we do it with endpoints. So we're, we're a platform, uh, that allows you to very easily visualize all those connections I talked about, and then easily put in place rules, um, that allow you to say, these are the things I want to allow, and then everything else I'm gonna turn off, I'm gonna shut shut the doors that need to be, that, that don't need to be open. Breach containment, breach containment.
I wonder why Garner hasn't coined that term yet. Usually they're good at that stuff, right? Yeah.
It's, yeah, Gar Garner's starting to come around to all of this. Uh, the, they've issued some, some recent, uh, publications regarding this. Uh, Forster actually has a Forster wave, uh, that discusses, um, well, They're subtype, well, I'm not here to compare Gartner to Forrester, but sometimes a little, you know, Forrester can be a little more on the edge, no pun intended.
Um, you know, in, in recognizing some of these new trends, Gartner will wait until a percentage of their base, you know, customer base is, is talking about it. But certainly breach containment I think is a great way of thinking about it. com.
com. Yes, sir. Absolutely.
So, yeah, I would encourage anyone, we've got some great material out there that'll, that'll help you, uh, uh, really understand, uh, what we do and how we do it. Um, and I encourage everyone out there listening to, to go take a quick look. Fantastic.
I wanna turn, if it's okay with you, to our topic of discussion today. You know, it's a bit of a ritual in Washington with every new administration got with the old in with the new who made promises on the campaign trail. Who's gonna live up to their promises?
Uh, are we changing for change sake? And, and it's, you know, it's kind of the democracy chacha. Sometimes we take one step forward and two steps backwards, sometimes two step forwards and one step backwards.
But it's very rarely linear. There's always a zig and a zag and a, you know, bits and starts. We're at that juncture again, come January, January 20th, whatever it is, we'll have a new administration who promised to really shake things up in some radical things.
And, you know, at this point we're kind of reading goat innards and tea leaves and crystal balls. But that being said, wanted to ask your opinion on what this new incoming administration may mean for cyber specifically, uh, in the four years ahead. Sure.
Uh, so as you said, right, it's, it's, you know, your guess is as good as mine right now. Uh, we'll, we'll see once, uh, once, uh, as they say, butts get into seats and you see what they're actually gonna do. Uh, but, you know, a couple of things that I think give me some, um, high confidence that in the world of cyber, um, I think that we're gonna see continued progress.
Uh, I think the Biden administration, uh, has made great progress, uh, with regards to federal cyber initiatives. Um, and I honestly expect the Trump administration to continue that. Um, you know, a lot of people forget that CSA was founded under the Trump administration, uh, right.
A lot of people forget that, right? So, CS a, you know, the, the institution that it is today, you know, owes its existence and its origination back under the, the, the first Trump administration, uh, you know, and, and President Trump issued an executive order that, that, you know, directed federal agencies to focus more on cyber. Uh, so I don't think that, that there's this lack of understanding from this incoming administration on the importance of, of cyber, um, and, and how critical it is for, uh, you know, for government entities, the public sector, uh, to really, you know, take it seriously and understand the, the threats that are out there in the world today.
Um, I would argue having been, you know, again, you know, 20 years in the military and dealing with nation state threats and watching, you know, worrying about, you know, tanks rolling through Europe or, you know, uh, flare ups in the Middle East and things, cyber is the, is the domain we're fighting in today, right? It's, it is, it is the largest domain that we are fighting in. And I don't think that's lost on anybody, you know, and I don't think it's lost on this incoming administration.
Uh, so I don't think that there's going to be some sort of, um, bury your head in the sand and pretend like there's no threats in, in the cyber Rome. I honestly don't see that at all. So, who thought we'd have tanks rolling through Europe again?
Right? Right. It, Right.
You know, All against, all gotta do, assuming you're around my age. We grew up in a Cold War era where that was, you know, are, are they gonna come from East Germany and the West Germany? Absolutely.
But we never really, you know, at the end of the Cold War, we thought tank warfare in Europe is probably in the history books, but it's real. Um, yes, the Trump administration did start this. They also fired the administrator 'cause he said the election wasn't rigged.
Um, so with one hand, they give, and with the other hand they take away, but this is the way of it. But here, here's what, here's what bother or not bothers me, but concerns me. I agree.
The Biden administration, the executive orders, much like the Trump administration executive orders, have given us some, some backbone in what we want to do from a cyber perspective. This has grown since it was originally founded. And, and I think they've done yeoman's work over the last, or over the last administration.
However, both the Biden administration and the Trump administration, 95% of what they've done around cyber has been by fiat, by executive order, not with the consent and approval of the United States Congress. And if we look at recent Supreme Court rulings, they're getting kinda squirrely about agencies and commissions and, and so forth, acting without congressional authority and mandate. And quite frankly, our Congress has not had a great history over the last 12 years, maybe more of, of having the political will to get things done.
Even things that seem likes nonpartisan, like Skype cyber's a nonpartisan issue. No one raises their hand and says, yeah, I want us to be attacked by a foreign state, you know, a nation state player, or to have ransomware. Everyone wants good cyber hygiene and regulations, but we don't have other than by, as I say, fiat, by by executive order, we haven't been able to get bills passed.
That seems Right. So it's Gonna be laws made. Yeah, it's gonna be very interesting.
Right? So what, what that Supreme Court decision that you referenced, uh, does, if it changes the, the outlook of Congress a little bit. Uh, you know, I'm all about, uh, one of my big things that I like to preach is accountability, right?
It's hard to, uh, it's hard to get things done if you're not gonna hold people accountable for getting those things done. Right? If, if, if someone can dodge accountability, uh, then, you know, and, and there, there's no repercussions, right?
Then, then what's the incentive to sometimes to, to get things done? I think in some ways, maybe Congress has been able to dodge some accountability because of the fact that executive orders, uh, were able to do things right? And the agencies could do things without them having to take a stance on things, right?
So it'll be very interesting from my perspective to see what happens now that, you know, as you said, there's been some rulings that say, no, no, you can't do these things by fiat Congress. If you want these things done, then do it right, then get together, uh, figure out the compromises you need to figure out and put these things into law, right? And also, the nice thing about things getting put into law, they have a little more tangibility of, of holding others accountable, right?
Sure. You know, and, and you can say, it's one thing to say, oh, is an executive order, and everybody kind of shrugs and goes, okay, that sounds great. Uh, but when you say, oh, it's a, it's a federal law, right?
That's a completely different conversation, right? You can be, you can be held accountable, you can be sued, right? You can potentially get fined or go to prison, Right?
Yeah. I mean, you have the full weight and authority. Absolutely.
So, so I am optimistic, right? I I I like to be a glass half fool kind of guy. Uh, I am very optimistic that maybe even with those changes, as you mentioned, that maybe it's gonna force congress, you know, especially something that, that, as you said, that that is, that is not political, right?
Everybody agrees that cyber's important, right? Uh, I am hoping that now, you know, as the new Congress comes in, they're all gonna get together and realize that, hey, if we say cyber's important, if we know that we're under attack, if we know that we've got a, this, this obligation, right? And I've considered a moral obligation, right?
When you look to federal government, um, it's got a lot of information about its citizens, about, you know, the citizens in the United States, uh, a lot of, uh, you know, very, uh, sensitive information, uh, you know, when it comes to intelligence and the DOD, right? We had a moral obligation to protect that, that that information that, that we have, that, that the government collects. Um, It's a strategic obligation.
Absolutely. We can't, you know, that's one of the big things with TikTok, for instance, right? They think that, well, you know, it's owned by a Chinese company and that the Chinese government is collecting information on American citizens.
Yeah. And at some, at some point, we up, right? We have to, and, and that's why I'm hoping, right?
I, I, again, I'm a very optimistic kind of guy. Uh, I am hoping that Congress is going to realize that, hey, the only way that these things are gonna be done is if they act right, that they're gonna have to get together, and they're gonna have to figure out how to cooperate in such a strategic realm of strategic importance that they're gonna have to get together and pass some legislation. And I, and I argue, uh, it's not just the passing the legislation, but the funding to go with it.
Well, that, and that's the other part of it, right? 'cause Congress holds the purse strengths. And, and I think, you know, we, we spoke about PII and stuff like that, but look to me, in an age of terrorists, in an age of nation state espionage, nation state warfare, where, where cyber is the new battlefield critical infrastructure, both private and public, has to be an imperative of, of our government to protect.
And, you know, I, I think it all depends on does Congress want to, you know, throw spitballs on both sides of the aisle, or they want to get together on something that we could get together on and do something right? That that's going to, you know, for lack of a better word, it's not gonna upset anyone if we actually did something around cybersecurity and, and protecting our critical infrastructure and our nation secrets and the personal information of our citizens. The, the other thing I, I kind of not worry about, but I'd like to see us make sense of, is in the app, you know, nature, nature of poors a vacuum.
And in the, in the absence of our Congress passing laws, we've had many states pass laws, which is good for them. Uh, you know, I applaud them for having the political will to do it, but it creates a quilt, a patchwork where all of these laws don't necessarily, you know, lock up. So you got, how are you supposed to have one law for here, one law, you know?
And the internet had knows no borders. It's the same thing with the eu, frankly, right? The eu, they pass stuff all the time.
And, And you think about the impact it has on, on, you know, companies like, like Illuma, right? Yeah. Which, right.
We're trying to, to provide capabilities. And if all of a sudden we're dealing with a patchwork of laws, right? That, like you said, very, very often or could be in conflict with each other, right?
How are, how are companies supposed to innovate while trying to navigate that weird maze of, of this patchwork of of laws, right? So, you know, I'm, I'm hoping things like that, uh, are going to spur Congress into understanding that, um, they have to work together. If you think about the, the recent, you know, the, the big news story about the hack of the telecommunications companies, right?
Um, it wasn't, it wasn't targeted at one party or another, right? It wasn't targeted at, uh, any particular group that was targeted against the United States of America. Right?
Uh, I think we can all get on board to go, we gotta do something, right? Um, and that's where I, that's Critical infrastructure to me. Absolutely.
And that's where I'm hoping that Congress right? With, with some of these recent changing, uh, you know, you know, you know, referencing back to that Supreme Court decision, that Congress is gonna start to be held accountable, right? And at the end of the day, right, voters can speak with their votes if they need to, right?
If Congress is, if, if, if voters feel like Congress, you know, is not working to protect them, right? They may try to find others who, who may have a better ability to work together to try to protect our, So that's an interesting point. You know, I've been in cyber 25 plus years, and forgive me if I've grown cynical, but I've been waiting a long time for the people to rise up and say, God damn it, we're, we're fed up and we're not gonna take it anymore.
Right? We want strong cybersecurity regs in place. Now, for a long time, the cybersecurity industry went the other way.
We said, look, we'll take care of ourselves. 'cause we don't want the government to police us. We'll, we'll, you know, industry groups, PCI and stuff like this in lieu of government regulation.
But, you know, people vote for their pocketbooks, as we've seen in this election more than anything else, right? People vote for their pocketbooks books. I unfortunately, until we have a, I don't want to use the term cyber pro harbor, but a, a serious cyber event that's gonna affect people's lives and rally the public to do something here.
I, I don't know if, if our elected officials kind of feel the heat, right? I, I think it, you know, it's, it comes more from the insiders. The experts saying, Hey man, this is a huge risk.
We gotta do something. Right? And, and I agree, right?
I think that that something like that certainly could be the, the catalyst, uh, that will drive change. I Mean, I'd hate to see it come to that though. Me too.
And that's why I'm optimistic, right? I, I like to be the hopeful kind of guy, uh, having been doing this for a long time. It's sometime hard, uh, to, to be the, the optimist in the room.
But, uh, I really, really strongly believe that, that over the next couple years, uh, Congress is, is going to agree that they've got to come together on, on the topic of cyber, right? That they've got to, uh, you know, we're, you know, quite frankly, right? We're, we've got some serious problems that need to be addressed in the, in the, in the world of cyber.
Um, and at some point, right, those problems are gonna rise up. And I am hoping, uh, and very hopeful that that Congress is going to come together and realize that, hey, we better do something before that, that cyber Pearl Harbor happens, right? Uh, because if we don't, and when you look at, you know, recent, you know, uh, you know, recent issues around the world, you know, the way that like Russia used cyber, uh, you know, and its attacks against Ukraine, right?
Those things are getting that attention, right? People are realizing that, you know, the, the nets, the, the next event could be us, right? And we could be dealing with the Chinese or the Russians, or, you know, in search your favorite, Or Iran or North Korea.
I mean, North Korea is a country that supports itself by hacking. Absolutely. Absolutely.
So it's at, you know, so I'm, I am hoping that, that, uh, and the other thing that comes into play, right, is as you know, over time, as new members get elected, right? You're, you're, you're starting to see the, the members who are getting elected to Congress have grown up in the digital age, right? Yeah.
More, more internet. Yeah. They're a little more intimately familiar with the digital age, uh, not just the benefits of it, but also the threats of it, right?
And, and how, how delicate that cyber can be at times. Right? So I'm hoping that that kind of thing also is, is, is starting to, to turn the tide a little bit with Congress, uh, that they're gonna realize that there are actions that they are gonna have to take.
And again, I go back to the fact that they're not gonna be able to rely as much on executive orders, uh, you know, uh, you know, fiat by agency heads to, to declare things that they're gonna realize that that responsibility as theirs, and they're gonna have to, to, to, I think step up and, and live up to that responsibility. I agree with you. I wish we had more time, guy.
'cause you know, another, uh, topic is this, the incoming administration has a lot of tech people, you know, who put big money. Yep. People don't put money in without a payback.
Right? And what's it gonna mean for tech and, and vis-a-vis cyber? But unfortunately, we'll have to save that for another time.
'cause we, this 15 minutes turned into 25. Uh, but hey, it's been great having yarn here. This is a really interesting topic, obviously for people like you and I, I think it's a great topic for, for our audience as well.
Keep up the great work at Illumio, Gary, keep doing Fighting the good fight. You know, as they say in the DOD, it's all about the mission. Absolutely.
Right. Thank you. Thank you for having me.
And I, I'm happy to come back anytime and, and chat with you some more about this stuff. Absolutely. It'll be interesting as it unfolds.
We'll do that. Gary Bartlett, public sector, CTO Illumio here on the Tech Trunk tv. We're gonna take a break.
We'll be back with more.