One reason that I value participating in industry events is that I always come away smarter, learning from industry and government experts who generously share their time and knowledge.
I had that experience recently at the AGA Professional Development Training event in Washington, D.C. I moderated a panel discussion titled “Fortified Future: Cybersecurity Through Consolidation,” where four panelists covering acquisition, operations and policy in federal and state and local government painted a vivid picture of the risks and opportunities for cybersecurity in shared services.
Consolidating risk
The discussion centered on using shared services to protect organizations at scale, an ongoing federal initiative. Shared services enable agencies to operate more efficiently, focusing the expertise and effort of maintaining an IT environment into a single instance that serves many organizations. Centralizing platforms makes it far easier to see what is happening across systems and data. That visibility delivers meaningful speed at scale, enabling agencies to expand capabilities without multiplying infrastructure.
While centralization and standardization provide clear operational and economic value, it is also clear that not all aspects of cybersecurity lend themselves to consolidation. Organizations should look to common cybersecurity activities like vulnerability management, patching, endpoint detection and response and the Security Operations Center as candidates for shared services. This allows them to maintain more direct control over unique mission environments that may include specialized information or operational technology.
Consolidation has a dual impact on cybersecurity. On the one hand, standardizing controls, reducing fragmented systems and embedding security architecture early in modernization planning strengthen protection against adversaries.
However, consolidating operations also consolidates risk. When multiple organizations run critical functions through a single hub, that hub becomes a high-value target. Moreover, the build-once-share-widely model means any disruption or breach has the potential to ripple throughout the network of connected organizations if the solution is not designed appropriately.
Filling the cyber skills gap
Another persistent challenge for federal cybersecurity is the continuing shortage of skilled experts to fill vacant jobs. As Rosa Underwood, Senior Cybersecurity Advisor at the General Services Administration, noted during our discussion, this isn’t just a staffing consideration; it actually increases the insider threat risk. As cybersecurity leaders and their teams take on work that should be spread among more people, the resulting stress can lead to errors, such as misconfiguring devices and thereby leaving them vulnerable.
There are some steps that could help fill the employment gap. Justin Ubert, Division Chief for Cybersecurity & Operations at the Federal Transit Administration (FTA), part of the Department of Transportation, noted that agencies don’t need to seek out people who hold degrees in cybersecurity or closely related fields. There are training programs that can provide people with the skills they need to fill the roles without years of academic work.
Consolidation is another measure to mitigate the impact of the skills gap. By serving more organizations from a single shared services hub, fewer employees are needed to maintain cyber defenses.
Pursuing consolidation with intent
After an enlightening discussion, I walked away with a few key points that agencies may find helpful to consider as they confront their own cybersecurity challenges:
Strengthen enterprise risk visibility. Centralization makes it possible to track threats, workloads and performance holistically, but agencies must maintain robust monitoring and analytics. A holistic approach to centralization while maintaining accountability and flexibility is key.
Elevate supply chain security. Conduct continuous supplier assessments. Understanding their security patching practices, vulnerabilities and risk management processes helps protect the broader ecosystem. Take advantage of acquisition best practices published by GSA to avoid duplicating work already done.
Align modernization with regulatory momentum. Post-quantum cryptography, updated logging requirements and AI directives present strategic opportunities to modernize with future threats in mind.
Prioritize scalable defenses. As agencies rely more heavily on shared platforms, defenses must be able to scale and adapt quickly, especially for AI-driven threats and Internet-of-Things environments.
Preserve mission uniqueness. Consolidation should not come at the expense of context. Agencies can maintain distinctive requirements through configurable shared platforms rather than uniform ones.
Stepping into a more resilient future
Consolidation may seem like a simple efficiency initiative, but it can provide a strategic lever for building more resilient, transparent and adaptable government operations while evolving cybersecurity at the pace of adversarial change. Success depends on maintaining thoughtful balances between scale and specialization, between visibility and risk, and between innovation and regulation.
If you’d like to explore practical ways to turn this evolving landscape into meaningful business outcomes, fill out the form below.