cisatrade-pressNewsThe Broadside2 min read

CISA CDM program chases speed with automation, agile buying

The roadmap is sound, but the program couldn't locate all F5 instances during last October's emergency directive, the gap between "tool of first response" and current reality remains wide.


TL;DR

CISA deputy program manager Richard Grabowski laid out a three-pillar CDM roadmap Tuesday: velocity through automation, data unification, and data-driven risk management, positioning the program as "the tool of first response when the things hit the fan." Acting federal CISO Mike Duffy called for acquisition reform: agencies should aggregate demand and buy outcomes rather than products, with contracts designed for continuous improvement rather than decade-long lock-in. SIEM-as-a-Service gets its own three-year expansion plan. The roadmap is coherent. But the program's October 2025 inability to locate all F5 instances during an emergency directive (and a GAO finding that CDM only partially meets its goals) shows how far it still has to travel.

The CDM program's leadership used a FedScoop industry event Tuesday to lay out an ambitious modernization roadmap, and to concede, unusually candidly, that the program currently isn't fast enough.

"We have to get faster," said Richard Grabowski, CISA's acting branch chief of service delivery and deputy CDM program manager. "The way that we collaborated today wasn't fast enough for the threats of yesterday, and they certainly aren't going to be fast enough for the threats of tomorrow." The remedy is threefold: velocity through responsible automation at scale, so analysts focus on novel threats rather than triaging alerts; data unification across agency silos to generate reusable intelligence; and data-driven risk management that positions CDM as "the tool of first response" during crisis-level events.

Acting federal CISO Mike Duffy framed the acquisition side, urging agencies to aggregate demand for common capabilities and buy outcomes rather than products so vendors can innovate on delivery. Contracts, he said, must be designed for continuous improvement. "Now is not the time to set capabilities and move on for the next 10 years." The SIEM-as-a-Service offering will follow a three-year expansion roadmap with staffing increases and training.

That agile mindset marks a departure from CDM's 2012 origins as a $6 billion contract vehicle, and it reflects hard lessons from the SolarWinds breach, which CISA's Matt House said exposed the government's lack of "a common operating picture with respect to the operational visibility we need." But the program still has ground to cover. Last October, during an emergency directive for F5 vulnerabilities, CISA couldn't automatically determine where all F5 instances were deployed across federal networks. GAO reported in June 2025 that CDM was only partially meeting its goals. The roadmap is coherent, and the candor about speed is welcome. The test is whether acquisition reform and automation can close the gap before the next crisis does.


Published ·Deep Fathom