CISO Reveals CMS Shift to Risk‑Based Cybersecurity Strategy

0
7

Key Takeaways

  • CMS is shifting from a checklist‑driven compliance model to a risk‑based, continuous‑monitoring cybersecurity approach.
  • The agency adopts a “protect first, visibility second” philosophy, using monitored data to trigger automated defensive actions.
  • Attack surface management now blends internal monitoring, external scanning, and CISA’s bug‑bounty program to identify and remediate weaknesses proactively.
  • Protecting patient‑care continuity remains the top priority, given the healthcare sector’s high ransomware risk.
  • Artificial intelligence is deployed selectively—for alert triage, behavioral analytics, anomaly detection, and vulnerability prioritization—while CMS recruits AI‑skilled graduates to build in‑house expertise.
  • The cyber workforce is expanding by roughly 100 positions, with a focus on junior ethical hackers and recent graduates who bring hands‑on experience in agentic AI and modern tools.
  • By pulling more technical functions back into CMS‑controlled environments, the agency aims to maintain security oversight while still enabling partners to perform their work.

Transition to a Risk‑Based Cybersecurity Model
Centers for Medicare and Medicaid Services (CMS) Chief Information Security Officer Keith Busby announced that the agency is moving away from a compliance‑centric, checklist‑driven approach toward a risk‑based model. In an interview with Federal News Network, Busby explained that the new strategy ties regulatory requirements directly to active defense mechanisms rather than treating compliance and protection as separate silos. The shift emphasizes continuous monitoring, attack surface management, and real‑time threat response, enabling CMS to react dynamically to emerging threats instead of merely documenting them after the fact.


“Protect First, Visibility Second” Philosophy
Building on more than a decade of federal investments in network visibility—such as the Cybersecurity and Infrastructure Security Agency’s (CISA) Continuous Diagnostics and Mitigation program—CMS now prioritizes protection over mere observation. Busby described the guiding principle as “protect first, visibility second,” meaning that data gathered through monitoring is used to trigger automated protective actions instantly. This approach transforms passive situational awareness into an active defense loop, reducing the window between detection and mitigation.


Leveraging CISA’s Bug Bounty Program for Attack Surface Management
To stay ahead of threats, CMS has expanded its attack surface management beyond reliance on system authorization documentation. The agency now tracks what is being scanned and what appears in connection with its systems, combining internal telemetry with input from independent researchers. A cornerstone of this effort is CMS’s participation in CISA’s bug‑bounty program, which invites ethical hackers worldwide to probe public‑facing assets and report vulnerabilities. By crowdsourcing testing, CMS gains diverse perspectives and uncovers flaws that might evade traditional internal assessments.


Safeguarding Patient Care Amid Rising Ransomware Threats
Because CMS operates within the healthcare sector—a frequent target for ransomware groups and other malicious actors—the agency’s overriding cybersecurity objective is to prevent any disruption to patient care. Busby stressed that maintaining the availability and integrity of health‑information systems is non‑negotiable, as downtime could directly affect treatment outcomes. Consequently, CMS’s risk‑based model is engineered to detect and neutralize threats before they can impair clinical operations or compromise sensitive health data.


Refined Attack Surface Management Approach
CMS’s updated attack surface management moves away from static authorization paperwork toward a dynamic, continuous process. The agency monitors network traffic, asset inventories, and vulnerability feeds in real time, layering this internal data with external findings from bug‑bounty hunters and third‑party scanners. This hybrid visibility enables CMS to prioritize remediation based on actual exploitability rather than theoretical risk scores, ensuring resources are focused on the most critical weaknesses.


Keeping Data and Functions In‑House
A key tenet of CMS’s strategy is to retain data and critical functions within environments it can directly monitor and control. Busby noted that the agency seeks to limit how often information or system capabilities leave CMS‑controlled networks, where external parties might apply differing security standards. By pulling more technical functions back in‑house—while still allowing partners to perform their work within CMS‑managed settings—the agency gains tighter oversight, reduces supply‑chain risk, and ensures consistent enforcement of its security controls.


Targeted Use of Artificial Intelligence
Artificial intelligence is positioned as a force multiplier in CMS’s cybersecurity arsenal, but its application is deliberate and narrowly scoped. Busby said the team is focusing on well‑defined use cases such as alert triage, behavioral analytics, anomaly detection, and vulnerability prioritization. By concentrating AI on these specific tasks, CMS can closely monitor performance, validate effectiveness, and hold tools accountable. To support this effort, the agency is recruiting recent graduates with AI‑related expertise, aiming to build in‑house capability that reduces reliance on costly external contractors and increases operational flexibility.


Impact on the Cyber Workforce
Anticipating the need for skilled personnel to sustain the new model, CMS announced plans to add approximately 100 positions to its Office of Information Technology. Busby highlighted that many incoming recruits already possess hands‑on experience with emerging technologies like agentic AI, and the agency intends to learn from this fresh talent rather than forcing them to conform to legacy practices. Additionally, CMS is hiring junior ethical hackers—a role traditionally filled by contractors—to cultivate a pipeline of federal cybersecurity professionals. These early‑career employees are expected to gain practical experience on the job, with many poised to advance into larger roles across government as their careers develop.


Looking Ahead
CMS’s transition reflects a broader federal movement toward proactive, risk‑informed cybersecurity that aligns compliance with real‑time defense capabilities. By integrating continuous monitoring, attack surface management, AI‑driven analytics, and a revitalized workforce, the agency aims to fortify its networks against evolving threats while safeguarding the uninterrupted delivery of healthcare services. Stakeholders interested in the agency’s FY27 contracting priorities and upcoming initiatives can attend the 2026 Healthcare Summit on December 3, where federal health leaders will share insights on AI adoption, modernization efforts, and expanded care access.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here