The Top 5 Insights from the SANS 2026 Government Security Forum 

By Steve Jacyna |

September 22, 2026

Government cybersecurity leaders and industry experts gathered for the SANS 2026 Government Security Forum with a shared recognition that artificial intelligence (AI) has fundamentally changed the pace at which cyber threats move. Sessions throughout the day returned repeatedly to a single theme: incident response plans, governance frameworks and compliance timelines built for a slower era now have an opportunity to evolve alongside the technology shaping today’s threat landscape. 

From a keynote on AI-accelerated attacks to panels on critical infrastructure defense, nation-state threats, identity and exposure management, the forum painted a picture of a Federal cybersecurity community proactively modernizing its playbook to keep pace with machine-speed threats. Here are the five insights that define the path forward for defending Government missions in an age of machine-speed threats. 

AI Is Reshaping Threat Activity, Driving the Need for Faster Incident Response 

Rob T. Lee, Chief AI Officer and Chief of Research at the SANS Institute, opened the forum with a stark recalibration of how fast a modern intrusion can move. Whereas breakout from initial access to lateral movement inside a network once took weeks, Lee described current attacker timelines measured in minutes, driven by AI systems that can chain vulnerabilities, write exploit code and pivot through an environment without a human in the loop. Previous containment processes, built around meetings to weigh business impact before taking systems offline, present and opportunity for organizations to streamline decision-making to match that speed. 

Lee pointed to a recent incident in which an AI model operating without guardrails broke out of an isolated test environment, discovered a previously unknown vulnerability and used it to reach an external platform before returning to complete its original task, all without direct human instruction. He also described responders being blocked from using leading AI models to analyze their own incident data because the material was flagged as attack-related content under the models’ usage policies, forcing some organizations to turn to alternative models mid-incident. His recommendation to Government and industry alike: secure approval now, before an incident occurs, to stand up a vetted AI model on internal infrastructure that can be used to accelerate forensics when it matters most. 

AI Governance Starts with Visibility 

A panel featuring Andy Hanks, Executive Strategist at Tanium, and Chris Saunders, Public Sector Solutions Engineering Leader at Wiz, tackled the blurred line between personal and professional AI use inside Government and industry organizations alike. Both panelists agreed that effective governance is impossible without a clear inventory of what AI capabilities already exist across an enterprise. Employees across an organization can now stand up applications using cloud infrastructure and AI models on their own, creating an evolving AI footprint that security teams benefit from tracking closely. 

The panel also observed that AI governance often begins with initial guardrails that expand into a more enabling framework as trust and understanding grow. As adoption accelerates, governance policy continues to evolve alongside emerging tools and use cases. The panelists agreed that building an accurate, continuously updated inventory of AI usage, tied to clear data-handling rules, is the necessary foundation for governance policy to be enforced effectively.  

Securing Critical Infrastructure Demands New Skill Sets 

A panel on AI adversaries and critical infrastructure, led by Dean Parsons, Principal Instructor at SANS, with Sarah Cleveland, Senior Director of Federal Strategy at ExtraHop and Jen Sovada, General Manager for Public Sector at Claroty, identified remote access and vendor connections as the leading attack vector into industrial control systems. Panelists noted that AI is accelerating how quickly adversaries can identify and exploit these openings, and that the share of control system compromises originating from a connected IT network has climbed sharply over the past several years, largely through shared credentials between IT and Operational Technology (OT) environments. 

The panel agreed that network visibility delivers the highest return on investment (ROI) among the five critical Integrated Control Systems (ICS), since visibility is the foundation for protecting and prioritizing what matters most. A separate session from a Department of the Air Force (DAF) technical director on OT cyber workforce development reinforced the same conclusion from a staffing perspective: the large majority of devices inside a typical control system do not run standard operating systems and responding to an OT incident increasingly requires a blended team, similar to a special forces unit, that brings together engineering, safety and cybersecurity expertise rather than applying IT playbooks unchanged. 

Threat-Informed Defense Means Knowing Your Adversary and Speaking the Board’s Language 

A SANS senior advisor and former FBI cyber division leader delivered a session on threat management that moved from the geopolitical to the practical. He outlined four major cyber threat categories targeting Government and critical infrastructure:  

  • espionage-focused actors seeking long-term access to sensitive networks 
  • disruptive groups targeting critical systems and operations 
  • attackers exploiting basic security gaps in operational technology environments  
  • sophisticated criminal enterprises leveraging data extortion and AI-driven social engineering tactics 

The session’s central insight was that most breaches stem not from unforeseeable attacks, but from well-known, highly visible risks, underscoring the value of consistently prioritizing foundational security practices. He urged security leaders to translate technical risk into financial terms that boards can act on, showing not just how many vulnerabilities exist but what they represent in expected financial loss, since regulatory disclosure timelines now require boards to demonstrate active oversight of cyber risk.  

Identity and Exposure Management Must Be Rebuilt for Machine-Speed Operations 

A panel on identity, featuring Jon Clay, VP of Threat Intelligence at Trend Micro and Brian Meyer, Federal Field Chief Technology Officer (CTO) at Axonius, examined how Zero Trust and identity frameworks hold up against autonomous AI agents. The panelists agreed that Zero Trust principles remain sound, but that most frameworks assume identities are human controlled, an assumption agentic AI breaks entirely. Service accounts and Application Programming Interface (API) tokens used by AI agents are frequently left out of existing identity inventories, creating visibility gaps similar to those organizations worked through in the early days of cloud adoption. 

A separate panel on exposure management, featuring Scott Cooper, Co-founder and Chief Product Officer at Nucleus Security and Tim Jones, Technical Director at Horizon3.ai, connected this shift to a new Government mandate compressing remediation timelines for the highest-risk vulnerabilities from weeks to days. Both panelists agreed that meeting that timeline requires moving away from static annual assessments toward continuously reprioritized, business-aligned exposure management, validating what is actually exploitable in a live environment rather than simply cataloging every known vulnerability. 

Across every session, the SANS 2026 Government Security Forum returned to the same underlying theme: AI is compressing attacker timelines, creating a clear opportunity for organizations to modernize their defenses, governance structures and workforce models to match. Seizing that opportunity will require Government agencies and their industry partners to pair AI-accelerated defense with disciplined visibility, cross-disciplinary skills and clear, board-ready risk communication. 

As Carahsoft, The Trusted Government IT Solutions Provider™, continues supporting Federal cybersecurity modernization, the insights from the SANS 2026 Government Security Forum inform how industry can help Government agencies defend their missions against increasingly fast and capable adversaries. 

Explore Carahsoft’s Cybersecurity portfolio of leading solutions that support Federal cybersecurity priorities, including AI governance, identity management, exposure management and critical infrastructure protection. 

Contact the Cybersecurity Team at Cybersecurity@Carahsoft.com or (888) 662-2724 to discuss how Carahsoft’s technology partners can support your mission requirements. 


Related Articles