AI, Zero Trust Could Be Key to Securing Federal Telework
For many agencies, extended telework policies may require reevaluation of cyber risk posture.

Federal agencies say teleworking is here to stay, and theyโre adjusting their cybersecurity strategies accordingly.
For many federal agencies, teleworking presents a unique cybersecurity challenge: suddenly thousands of employees are using home Wi-Fi networks and personal devices to work, and sometimes view classified information, potentially opening up their departmentโs network up to cyber criminals and nation-state actors.
Zero trust architecture and constant monitoring of all network nodes are important, but a mindset shift is key, said senior officials from NIST, the Air Force and the Department of State at a FedInsider webinar last week.
Frank Konieczny, chief technology officer for the Air Force, said the service was not prepared for mass telework at the beginning of the coronavirus pandemic, but prioritizing security issues while shifting to remote work ensured it didnโt encounter any major cybersecurity hiccups.
โThe first thing we did was ask, โhow are we going to maintain security, and how many VPNs do we have to establish?โโ Konieczny said at the webinar. โThe second piece was how can we give security to everybody out there, and how do I communicate with people who do not have a government laptop?โ
As a result, the Defense Department set up a Microsoft Teams site that allowed everyone to connect with each other at a lower security level, he added.
Pete Gouldmann from the Enterprise Risk Office at the Department of State said another key issue was educating employees on cybersecurity best practices while teleworking and implementing a zero trust policy for all connected devices.
โI think we need to all accept the fact that a defense model is not going to be enough all on its own, it limits your reach for your ability to work,โ he said. โOne of the things I would suggest is a very strong focus on data and identity management.โ
Gouldmann detailed the practice where personnel were cleared for software and services with an all-or-nothing approach is now gone.
โNowadays weโre able to do business with people with a different level of trust. I would encourage the audience to look at a multi-assurance model to reach people wherever they are and based on who they are, where they are, and what they have access to,โ he said.
Jeff Greene, director for the National Cybersecurity Center of Excellence at NIST, said even a simple phone call while working from home should be thought of as a โdata transferโ requiring zero trust authentication.
โYou may need to apply more security to have that kind of chat when youโre not within the confines of a secure government building,โ he said. โStopping and thinking and getting people to build that pause in is going to be hard. There is a mindset shift when you canโt just walk down the hall and talk with someone.โ
Knoieczny said telework is โhere to stayโ for many Air Force employees, which is why the branch is doing a zero trust demo to enhance its cybersecurity posture.
โWe realized people were sitting at home on their own devices and they wanted to get into a high-level-five email that they could not get into,โ he said. โWeโre looking at that risk posture [and] maybe [employing] a graduated risk profile where I may need more authentication information before I go forward. Authentication could be biometric โฆ. I think weโre always evolving to looking at risk, and the resiliency of the mission is what we want to maintain.โ
During a second FedInsider webinar about AI powering zero trust, Education Department CISO Steven Hernandez said the agency has been using AI for intrusion detection and network security.
โReally where we want to be with AI is headed toward this idea of zero trust,โ he said. โWeโre building out that architecture.โ
Hernandez said he hopes AI could help sift data to predict cyber threats before they happen and help the Education Department make more accurate, thorough decisions about how to handle cyber threats and take action more effectively.
โNo human in our organization could possibly get their arms around the volume of data we have and make sense of it in real time so we can take action,โ he said. โIn our [cyber] strategy, AI is one of the core components of our defenses.โ
This is a carousel with manually rotating slides. Use Next and Previous buttons to navigate or jump to a slide with the slide dots
-
New Federal UX Head Joe Gebbia to Tackle Government Websites
The Airbnb co-founder wants to align federal digital service experiences with those expected in the commercial and private sector.
2m read -
Defense IT Summit
The 2026 Defense IT Summit will bring together senior IT leaders to examine how emerging technologies and strategies are advancing mission readiness.
Ritz Carlton Pentagon City | 1250 S Hayes St, Arlington, VA 22202 -
Inside FedRAMP 20x: GSAโs Pete Waterman Talks Speed, Security
FedRAMP 20x is transforming federal cloud authorizations. GSAโs Pete Waterman shares how automation and continuous monitoring are speeding approvals and strengthening security.
24m watch -
Nominations Open for the 2025 AI Summit Flywheel Awards
GovCIO Media & Research, a leading federal technology media company, opened the Flywheel Award nominations for the 2025 AI Summit.โฏ
7m read