Atlassian, Stop Securing Whats Broken Blog, Preview Image, 2026

Stop Securing What’s Broken: Why DevSecOps Transformation Starts with the Mission

By Matthew Graviss |

July 21, 2026

At the U.S. Department of State, I led a technology team focused on modernizing how the agency delivered services to its workforce. One of our early priorities was improving how payroll issues were tracked and resolved. More than 10,000 requests had accumulated in an email-based system where every new message required manual backtracking just to find the history of an issue, with no shared visibility into status or progress. 

Our team built a frontend solution to report and track issues through defined stages, giving the agency a clearer picture of where things stood and reducing the burden on already-stretched inboxes. That was one piece of a larger effort. Through initiatives led across the State Department, the backlog dropped by 90% and resolution times improved significantly for employees serving missions around the world. The fix was not a new tool. It was starting with the mission and redesigning the workflow around it.

Later, when we needed a secure generative AI capability, we didn’t have the luxury of a multi-year development cycle. So, we partnered across teams to bring StateChat to life, one of the first compliant generative AI applications to go agency-wide in the Federal Government, delivered in a fraction of the time a traditional development cycle would have taken. 

Both these experiences point to the same lesson I carried across nearly two decades of public service, from Customs and Border Protection (CBP) to U.S. Citizenship and Immigration Services (USCIS) to leading enterprise AI strategy for global diplomatic operations: transformation fails when you try to secure or automate what’s already broken.

That conviction is what brought me to Atlassian. And it’s what I want to challenge this community to think about differently.

The $80 Billion Question

The question is not how to spend less. It is how to make what we build actually move the mission forward. The Federal Government spends roughly $100 billion annually on IT. By most estimates, $80 billion of that goes to simply keeping existing systems running: patching, maintaining and nursing along infrastructure that was never designed for today’s threat landscape or mission tempo.

That’s not a technology problem. It’s the cost of maintaining mission-critical systems that were built to last, even when the mission has evolved.

DevSecOps was supposed to help fix this. Integrate security into the development pipeline. Ship faster. Catch vulnerabilities earlier. But too often, we adopt the toolchain without fully adopting the mindset. We attempt to bolt security scanning onto existing waterfall processes and teams that were never set up to work that way, only to be frustrated when velocity doesn’t improve.

Start with the End, Not the Tool

The agencies I’ve seen succeed, whether from inside Government or in my work with Federal agencies since joining Atlassian, share one trait: they start with the mission outcome, not the technology decision.

What does that look like in practice?

Atlassian, Stop Securing Whats Broken Blog, Embedded Image, 2026
  • They define what “done” means before selecting tools. Not “we implemented a CI/CD pipeline,” but “we reduced time-to-ATO from 18 months to 90 days” or “we can deploy a critical patch within 24 hours of identification.”
  • They treat change management as the project, not a side effect. Government is often described as risk-averse. I’d argue it’s change-averse, and those are different problems. Procurement hurdles, compliance requirements and deeply embedded processes become reasons not to act rather than constraints to plan around. The agencies that break through have change agents who treat those hurdles as part of the project scope, not blockers outside it.
  • They demand transparency and measure what matters. If you can’t see where work is happening, how it’s flowing and whether you’re meeting the goals you set, it’s difficult to distinguish between meaningful progress and mere process maintenance.

Security Is a Workflow, Not a Gate

Here’s what I wish more Federal leaders understood: DevSecOps isn’t about adding security to your development process. It’s about designing a process where security is inseparable from delivery.

The industry is validating this shift. Gartner recently renamed its Magic Quadrant from “DevOps Platforms” to “DevSecOps Platforms,” recognizing that security is no longer a bolt-on but a mandatory, integrated capability across the entire software lifecycle. Atlassian was recognized as a leader in that evaluation for the fourth consecutive year, placing highest in Ability to Execute. That recognition matters not because of the label, but because of what it signals: the market expects security and delivery to move as one.

What does that look like when it’s working?

  • Automated risk classification. Not every change needs a CAB review. Low-risk changes should flow. High-risk changes should trigger the right approvals automatically. The decision logic should be codified, consistent and automatic, not dependent on a manual review cycle.
  • Vulnerabilities surfaced where developers work. Not in a separate report delivered after the fact, but surfaced in real time, where developers are already working. At Atlassian, we used our own AI agents to auto-resolve 51% of security vulnerabilities across 6,000 engineers in six months. That’s what’s possible when security findings live in the same workflow as the development work itself.
  • End-to-end traceability. From code commit to production deployment, every change is tracked, every decision is auditable and every stakeholder has visibility appropriate to their role.

The Cultural Shift No One Wants to Talk About

At State, I learned that inefficiency itself is a security risk. When systems or approvals move too slowly, people adapt: they find workarounds, reach for unsanctioned tools or build shadow processes just to get the mission done. Mission needs don’t wait. The agencies that succeed don’t just tolerate change; they design for it.

This doesn’t require heroics. It requires:

  1. Shared definitions. If your security team, your developers, and your operations team can’t agree on what “production-ready” means, no toolchain will save you.
  2. Shared ownership across functions. DevSecOps at scale isn’t just CI/CD. It’s unified metrics, shared visibility and collaboration across mission and technology functions.
  3. Continuous iteration. Transformation isn’t something you turn on and complete. It’s continuous, iterative and ongoing. The agencies that sustain momentum are the ones that build iteration into the culture, not just the calendar.

What I’ll Be Talking About on July 28

I’ll be on the AI Tools for Security panel at the Carahsoft DevSecOps Conference on July 28 at 10:50 AM near Washington, D.C., sharing more on this topic, including how agencies can embed security into their delivery workflows without slowing down the mission.

If you’re a Federal leader navigating the pressure to modernize faster and more securely, whether you’re setting strategy or managing the day-to-day of delivery, I’d welcome the conversation.

Because the future of Government DevSecOps isn’t about better tools. It’s about better outcomes.

Join Matthew at the Carahsoft DevSecOps Conference on July 28, 2026, in Reston, VA. Register here.

Carahsoft Technology Corp. is The Trusted Government IT Solutions Provider, supporting Public Sector organizations across Federal, State and Local Government agencies and Education and Healthcare markets. As the Master Government Aggregator for our vendor partners, including Atlassian, we deliver solutions for Geospatial, Cybersecurity, MultiCloud, DevSecOps, Artificial Intelligence, Customer Experience and Engagement, Open Source and more. Working with resellers, systems integrators and consultants, our sales and marketing teams provide industry leading IT products, services and training through hundreds of contract vehicles. Explore the Carahsoft Blog to learn more about the latest trends in Government technology markets and solutions, as well as Carahsoft’s ecosystem of partner thought-leaders.


Related Articles