At this year’s Billington Cybersecurity Summit, Michael Duffy, the Acting Federal Chief Information Security Officer at the Office of Management and Budget, used his fireside chat to lay out three priorities for the Chief Information Security Officer Council: enterprise cyber defense, operational resilience, and securing a modern government. Zero Trust runs through all three. On enterprise cyber defense, Duffy pointed to raising the baseline on vulnerability management, supply chain risk, and incident response, and doing so across the federal enterprise instead of agency by agency.
Agencies working toward that maturity bar are managing three things at once: the technical work of Zero Trust itself, pressure to bring down the cost of running the network and security stack, and the obligation to keep delivering their core mission without interruption while they do both.
Where the security case and the cost case meet
Two separate pressures are pushing agencies toward the same decision. On the security side, AI-enabled attacks now run at machine speed, autonomous and high-volume in a way that outpaces human defenders and detection models built for a slower threat environment. Zero Trust maturity is no longer only a compliance target. It is a test of whether an agency’s architecture can keep pace with how attacks are actually being carried out.
On the cost side, years of layering point solutions on top of legacy infrastructure have left many agencies running fragmented environments that are expensive to operate and hard to secure consistently. Budget pressure is pushing consolidation regardless of any security deadline. When these two pressures land on the same modernization decision, agencies that address them together, instead of negotiating security and cost separately across different contract actions, get more value out of the money already being spent.
Device consolidation. Agencies running separate appliances for routing, firewall, and secure access are managing separate consoles, separate patch cycles, and separate licensing agreements for functions that can increasingly run on a single platform. Consolidating those functions cuts the number of systems that have to be configured, monitored, and kept current, which is where a meaningful share of operational cost and risk originates.
Wide area network cost. Legacy MPLS circuits are among the more fixed and difficult to reduce line items in federal network budgets. Many agencies are already revisiting this transport question as they complete the transition off Networx and Washington Interagency Telecommunications System contracts onto the General Services Administration’s Enterprise Infrastructure Solutions vehicle. A software-defined approach to the wide area network lets agencies shift traffic onto lower-cost broadband where it makes sense, while keeping policy enforcement consistent no matter which transport is carrying the traffic. That does not mean replacing every circuit at once. It means having the option to make the switch as contracts come up for renewal, instead of staying locked into legacy pricing.
Consistent visibility. Fragmented tooling raises cost, and it also makes it harder for security and network teams to see the same picture at the same time. A common platform gives agencies one consistent view across distributed environments, shortens the time it takes to spot and respond to an issue, and cuts down on the number of overlapping tools an agency has to fund in parallel.
Modernization cannot come at the expense of the mission
Federal civilian agencies are carrying two obligations at once: reaching Zero Trust maturity, and continuing to deliver the citizen-facing services that are their core mission without interruption. A modernization effort that strengthens security posture but disrupts service delivery, even briefly, has not solved the problem the agency was actually asked to solve.
Sequencing matters here as much as the technical approach. Agencies that build Zero Trust implementation into their existing operational and budget calendar, instead of forcing a single cutover, reach the maturity bar without putting service continuity at risk along the way.
The path forward
One thing would make it easier to judge how close government actually is to that bar: public visibility into agency-level progress. There is currently no regular, public reporting on how individual federal civilian agencies are progressing toward target-level Zero Trust maturity. With the fiscal year 2027 deadline ahead, a public, agency-by-agency accounting of where things actually stand would give Congress and industry a clearer picture of the work still ahead.
Agencies furthest along have not treated security modernization, cost reduction, and mission continuity as separate initiatives. They have used the modernization work already underway to reduce complexity, not add to it, and built the sequencing so the mission never has to stop for it. That is the bar the rest of government now has to clear.