Chief Information Officers (CIOs) from across the Intelligence Community (IC) and the Department of War (DoW) gathered at the Department of Defense Intelligence Information System (DoDIIS) Worldwide Conference for three days of impactful speeches and dynamic panels. The message was clear: the technology landscape has shifted more in the past six months than in years prior, and the systems, people and partnerships that protect the nation’s secrets must adapt just as quickly.
Five insights define the path forward for securing and modernizing the nation’s intelligence enterprise.
1. Autonomous AI Agents Are Creating a New Category of Cybersecurity Risk
Across the IC CIO panel, no concern loomed larger than AI agents capable of independent action. E.P. Mathew, CIO of the Defense Intelligence Agency (DIA), described recent forensic research in which an AI agent, given a simple task and cut off from the internet, began communicating with other AI agents to work around its constraints. They left one another notes on escaping their sandboxed environment and debated attacking an external platform to obtain what they needed to complete their assignment.
Mathew also cited a case in which AI agents achieved complete root access to an organization’s infrastructure in just 13 hours, a feat that previously required a team of highly skilled human attackers. The familiar “shadow IT” now has a more dangerous successor in “shadow AI agents,” where one misconfigured or under-instructed agent could trigger cascading consequences across hundreds of organizations through IC information-sharing environments.
James Grimsley, Executive Director for Command, Control, Communications and Cyber Systems (C4S) and Deputy CIO at the U.S. Transportation Command (TRANSCOM), said securing agentic AI feels manageable today largely because most organizations do not yet have it running on their networks. Once those nonentities exist, the response must be Zero Trust done right: continuous logging, constant re-validation and enough automation and orchestration to confirm an agent is behaving exactly as expected. The harder problem is building the department’s own agentic AI defense, trained by the intelligence and cybersecurity analysts who know the network inside and out.
2. Patch Velocity and Security-as-Mission-Readiness Have Become Front-Line Priorities
As adversaries increasingly use AI to discover software vulnerabilities, IC and DoW CIOs described unprecedented patching demands and security alerts. Roger Greenwell, CIO for the Defense Information Systems Agency (DISA), stated, “We can’t afford the downtime…it’s about the availability of our systems and our networks to get data to our senior leaders in order for them to make decisions faster than anyone else.” Organizations are accepting risk they would not have tolerated a few years ago because there is not time to fully assess every implication before acting.
Products cannot be secure at a single point in time; resiliency and dynamic patching must be built in so fixes can be applied at a moment’s notice without disrupting mission operations. The AI and Zero Trust strategy panel reinforced this shift, describing a tendency to keep systems operational over patching them. Organizations must instead treat cost, performance and security as a single equation. Greater automation in patching and monitoring reduces downtime while giving leaders clearer visibility into system dependencies and who is accessing sensitive capabilities.
3. Security Must be Designed in from the First Day
Several panelists traced many of the IC technology challenges to security arriving too late in development. Colin Hankey, CIO and Director of the Technology and Innovation Office (TIO) for the Department of State (DOS), argued the traditional pattern of building a tool, implementing it and then bringing it to security must be reversed. Hankey noted that identifying a problem during needs analysis costs roughly a hundred times less to fix than catching it after a system is operational and an organization has too much invested.

Douglas Cossa, IC CIO, illustrated this shift in mindset with an example from the National Geospatial-Intelligence Agency (NGA): a routine cybersecurity tool run under his authority identified a zero-day vulnerability in a widely used commercial product, prompting a vendor patch that protected organizations beyond the DoW and IC. E.P. Mathew went further, arguing that the traditional Risk Management Framework (RMF) process has become a compliance exercise built to check a thousand boxes instead of a genuine risk management tool. DIA is piloting an agentic AI platform that continuously scans systems, patches flaws as they are found and automatically documents inherited controls, aiming to replace paperwork-heavy authorizations with real-time monitored views of risk.
Shayne Grubbs, Chief of the Office of Mission Integration with the DIA’s Directorate for Operations, distilled the same philosophy into a four-part DevSecOps framework:
- Build a secure-by-design architecture from the beginning
- Automate network orchestration from the start
- Apply Zero Trust protocols throughout
- Employ reusable, pre-approved patterns
Security adds the most value when it is integrated in the early stages of system design. The fastest mission systems are those that operationalize trust from day one.
4. Identity, Data and Zero Trust Form the Foundation of AI-Ready Cyber Defense
As IC agencies integrate AI more deeply into their cyber defense, E.P. Mathew outlined three layers where automation must deliver measurable advantage: threat detection built on network telemetry, proactive vulnerability discovery and AI-assisted incident response capable of acting within microseconds of an event rather than waiting for human triage. Elizabeth Durham-Ruiz, Director of Command, Control, Communications and Computer Systems (C4) and CIO at the U.S. Strategic Command (STRATCOM), reinforced this from the Zero Trust side. STRATCOM is building a registry of every AI model in its environment, tracking when each was last touched or retained and pairing that inventory with real credential and access management.
Rob Shaffer, Deputy Director of Intelligence at U.S. Space Command (SPACECOM), made a parallel, data-driven case. As new high-capacity collection constellations come online, he said, “I don’t need to disseminate everything that’s been collected. What I want to look for are the patterns, the anomalies and the changes.” Agentic AI’s value lies in surfacing those insights while keeping a human in the loop for the decisions that matter most.
A high percentage of successful compromises begin with compromised identity, making legacy identity systems one of the IC’s most consequential vulnerabilities. E.P. Mathew described a framework in which data pedigree, where a piece of data originated, determines who and what may access it. That determination then drives policy, tagging and entitlements for humans and machines. When data access is denied by default, the likelihood of compromise drops sharply, along with the burden on human security teams.
5. Modernizing at Mission Speed Includes Faster Acquisition and True Partnership
Patrick Grimsley voiced one of the conference’s sharpest frustrations with a lived example: a requirements gap was identified, a year was spent waiting for proposals and another year was spent testing them. Five years later, industry had already built and fielded the exact capability he originally requested. Grimsley argued for shifting weight away from prolonged research and development to faster testing and evaluation, handing requirements to industry and compressing implementation timelines. He credited TRANSCOM’s working capital fund and his delegated authorizing-official authority with helping his team move faster by owning the risk decision instead of waiting on a lengthy approval chain.
Panelists also urged organizations to distinguish genuine legal restrictions from policies that can be changed. Several panelists agreed the same principle applies to technology: programs that build bespoke identity solutions, cross-domain solutions or other pieces of the IT stack spend more time and money yet often produce systems that fail to integrate with the broader environment. Geographic separation, organizational silos and differences between intelligence, IT, cyber and operational communities were repeatedly cited as friction points that stronger communication, transparency and partnership can help resolve.
That spirit of partnership extends to industry. Grimsley challenged vendors with a memorable analogy. “If I ask for pancakes and I go to 15 different engineers,” he said, “I’m going to get 15 different ways to make a pancake… What I really asked for was the pancakes.” His advice was to spend time with mission owners, understand what they are asking for and build that instead of adding unrequested features. Technology and policy can only carry modernization so far; people and culture will determine success.
The Intelligence Community’s Digital Future
DoDIIS Worldwide 2026 reinforced that the IC’s next era of modernization will be defined as much by trust and discipline as by any single technology. Agencies are not adopting AI, Zero Trust and enterprise services for their own sake. They are rethinking how identity, data, security and acquisition decisions are made from a system’s first day so analysts, warfighters and decision makers that depend on IC technology can trust it under pressure. Success requires sustained collaboration between Government leaders and industry partners who understand security and innovation must advance together.
As Carahsoft, The Trusted Government IT Solutions Provider®, continues supporting IC and defense modernization, the insights from DoDIIS Worldwide 2026 inform how industry can best partner with IC and DoW leaders to deliver the secure, resilient technologies required to protect the nation’s most critical missions.
Explore Carahsoft’s defense portfolio of leading solutions that support IC modernization priorities including cybersecurity, Zero Trust, AI and cloud infrastructure.
Contact the Carahsoft team at sales@carahsoft.com or (888) 662-2724 to discuss how Carahsoft’s technology partners can support your mission requirements.