Key Takeaways
- CMS is moving beyond simple compliance checklists to a threat‑informed, risk‑based cybersecurity model that ties continuous monitoring directly to inherent compliance.
- The agency adopts a “protect first, visibility second” mindset, leveraging tools like CISA’s Continuous Diagnostic and Mitigation (CDM) program and external bug‑bounty research to gain real‑time insight into its attack surface.
- Protecting patient‑care continuity drives CMS’s focus on minimizing data exposure, especially with thousands of contractors and third parties that handle sensitive information.
- Artificial intelligence is viewed as a force multiplier; CMS is piloting AI for alert triage, behavior analytics, anomaly detection, vulnerability prioritization, and automating detection creation from manual penetration‑test findings.
- To increase agility and reduce reliance on contractors, CMS plans to hire roughly 100 IT professionals, recent graduates skilled in agentic AI and junior ethical hackers, fostering an in‑house technical workforce that can adapt quickly to evolving threats.
CMS Shifts from Compliance‑Focused to Risk‑Based Cybersecurity
Keith Busby, the Chief Information Security Officer for the Centers for Medicare and Medicaid Services (CMS), described a strategic pivot from “check‑the‑box” compliance activities to a threat‑informed, risk‑based defense. By aligning security decisions with real‑time threat intelligence, CMS aims to make compliance a natural byproduct of continuous monitoring rather than a separate, burdensome process. This shift reflects a broader federal trend of moving beyond static authorizations toward dynamic, adaptive security postures that can respond swiftly to emerging threats.
From Check‑the‑Box Compliance to Threat‑Informed Risk Management
Busby emphasized that the new approach links compliance directly to defensive actions: “Because we’re making these decisions based off of this information, and we’re staying within these guardrails, we are inherently compliant.” The goal is to eliminate repetitive audit‑style tasks for system teams and instead focus resources on proactive threat hunting, mitigation, and remediation. By treating compliance as an outcome of continuous risk assessment, CMS hopes to free personnel for higher‑value security work.
Continuous Monitoring and Attack Surface Management as Core Pillars
A cornerstone of the revised strategy is continuous attack surface management. CMS now scans not only its internal networks but also monitors external assets associated with the agency. Busby explained, “What are we scanning? What do we see showing up that’s associated with CMS?” This ongoing visibility is supplemented by engaging external researchers through CISA’s bug‑bounty program, which invites global talent to probe CMS’s public‑facing surfaces and report vulnerabilities. The combined internal‑external view helps the agency spot misconfigurations, exposed services, or emerging threats before they can be exploited.
“Protect First, Visibility Second” Strategy
While visibility remains important, CMS is adopting a “protect first, visibility second” philosophy. Rather than waiting for alerts to trigger action, the agency prioritizes preventive controls—such as hardening endpoints, enforcing least‑privilege access, and encrypting data at rest and in transit. By strengthening defenses upfront, CMS reduces the likelihood that a breach will occur, making the subsequent monitoring effort more about confirming that protections remain effective rather than reacting to incidents after the fact.
Leveraging Federal Programs and External Research for Visibility
CMS continues to build on the foundation laid by the Cybersecurity and Infrastructure Security Agency’s Continuous Diagnostic and Mitigation (CDM) program, which has provided the federal government with a decade‑long investment in asset visibility and vulnerability management. Busby noted that CMS is now layering CDM data with findings from external bug‑bounty hunters and red‑team exercises. This hybrid approach ensures that the agency sees both internal weaknesses and external attack vectors, enabling a more comprehensive risk picture.
Securing Data Across Contractors and Third Parties
With over 6,000 federal employees and thousands of contractors handling CMS data, protecting information shared beyond the agency’s direct control is a top priority. Busby stressed that CMS’s endpoint management philosophy centers on keeping data within its own environments: “Our data should not leave our environments… we need to really minimize the amount of times we are sharing or sending our data… off assets that we have visibility into.” To achieve this, CMS is working to pull data processing back inside its networks whenever possible, while still allowing mission‑critical functions to be performed by trusted partners under strict oversight and technical controls.
Artificial Intelligence as a Force Multiplier in Cyber Defense
Busby described artificial intelligence (AI) as a “force multiplier” that can amplify the effectiveness of limited cybersecurity staff. CMS is being deliberate about AI use cases, focusing on specific slivers such as alert triage, behavior analytics, anomaly detection, and vulnerability prioritization rather than applying AI broadly without clear objectives. This targeted approach allows the agency to validate AI models, maintain accountability, and measure tangible improvements in detection speed and accuracy.
Automating Detection Creation via AI‑Enhanced Pen‑Test Insights
One concrete AI initiative involves taking findings from manual penetration tests and using machine‑learning models to generate detection rules that can be deployed across the entire enterprise. Busby explained, “We take those findings, we can use a model to help us create detections, and we can then share across the enterprise… ‘We found this flaw in system over here, we should be alerting if we see this type of exploit across our entire enterprise.’” Previously, detection engineers had to craft custom rules for each system; AI now streamlines this process, reducing time‑to‑defense and ensuring consistent coverage.
Growing an In‑House Cyber Workforce to Boost Flexibility
Recognizing that cyber threats evolve faster than contract cycles can accommodate, CMS announced plans to hire roughly 100 professionals into its Office of Information Technology this year. Busby highlighted the value of recruiting recent graduates who already possess skills in emerging areas like agentic AI. By hiring talent early in their careers, CMS hopes to benefit from fresh perspectives and avoid the inertia that can come with long‑standing contractor relationships. The agency aims to create a workforce that can adapt quickly to new tools, techniques, and threats without waiting for contract renegotiations.
Bringing Junior Ethical Hackers In‑House
As part of the in‑house talent push, CMS is also bringing on junior ethical hackers—individuals who can perform penetration testing, red‑team exercises, and vulnerability assessments directly for the agency. Busby noted that while CMS values its contractor community, having federal employees perform these functions enables quicker priority shifts and greater agility: “With federal employees, it’s a little bit easier for us to change priorities at a quicker pace without having to ensure that contract execution occurred.” This internal capability not only reduces reliance on external vendors but also cultivates a pipeline of cybersecurity professionals who can grow into senior roles within CMS or elsewhere in government.
Future Outlook: Sustaining Patient Care Through Adaptive Cybersecurity
Ultimately, CMS’s cybersecurity evolution is driven by a singular imperative: ensuring uninterrupted patient care. By embedding continuous monitoring, attack surface management, AI‑augmented detection, and a flexible, skilled workforce into its defense strategy, the agency seeks to transform security from a periodic compliance exercise into an ongoing, resilient operation. As ransomware and other cyber threats increasingly target healthcare, CMS’s proactive, risk‑based posture—anchored in protection, informed by visibility, and powered by emerging technologies—offers a model for how federal health agencies can safeguard critical services while adapting to an ever‑changing threat landscape.

