Blog

When the Perimeter Disappears, Everything Drives and Simultaneously Jeopardizes the Mission

July 22, 2026 By Brian Lake

There is a line inside the Department of War that the only thing left that is not digital is the bayonet. Everything else, from the water and power feeding a base to the weapons projecting force from it, now carries a digital footprint. The perimeter federal security teams spent a generation hardening has dissolved into millions of connected things, and most were never designed to be defended. 

That was the backdrop for the latest GIST 360 breakfast briefing, When the Perimeter Disappears: Securing the Converged Federal Enterprise Across IT, IoT, and OT, hosted by Swish and sponsored by Armis Federal. Sean Applegate, CTO of Swish moderated a candid conversation with Aaron Bishop, CISO and acting Principal Deputy CIO at the Department of War, Dr. Justin Hubert, a component CISO at the Department of Transportation, and Matthew Shalbetter, a Federal Civilian Strategist at Armis Federal. What emerged was less a technology briefing than a field report on how the IT, OT, and IoT worlds are colliding. 

Culture Is the Hard Part, Not the Technology 

The panel kept returning to a truth no product roadmap solves. Cyber teams and OT teams do not speak the same language. Security practitioners live by the confidentiality, integrity, and availability triad, but in an operational environment availability is close to the only thing that matters, because a control system that goes dark can stop a mission cold. The Department of War’s fix is deceptively low tech. Put the mission owner, the OT engineer, and the cyber practitioner in one room, add pizza, and do not let anyone leave until they agree on what has to stay running and why. Bishop calls the output Mission Relevant Terrain for Cybersecurity (MRTC), a way of tracing the thread from a mission down through the systems and infrastructure it silently depends on. Miss that thread and you never see how one compromised building takes down the ability to project force. 

Air Gapped Is a Comforting Myth 

Ask a federal engineer whether a critical system is air gapped and the honest answer is increasingly no. There are too many creative ways to bridge a gap, intended or not, to treat isolation as a control. Much of the federal estate was architected for the 1980s and carries fifty years of technical debt, predating internet protocol, multi factor authentication, and modern encryption. The workable path is to wrap rather than replace. Federal teams put authentication and monitoring around legacy assets, pull telemetry out through one way connections so nothing gets pushed into fragile OT networks, and use microsegmentation so an intruder who lands cannot pivot into the systems that must never go down. A vessel that is at once IT, OT, and IoT, or an elevator bank still running on an unsupported operating system, is not an edge case. It is Tuesday. 

The Old Way of Ranking Vulnerabilities Now Gets You Popped 

For years, security teams triaged the flood of vulnerabilities the same way. Sort by critical, high, and moderate, then work down the list until the next Patch Tuesday. That cadence is gone. Frontier AI models can now chain a low severity flaw to a medium one and produce an attack pattern nobody prioritized, precisely because everyone was heads down on the criticals. The kill chain no longer runs in a neat line. It fans out, fast, and automatically. 

Federal agencies are adjusting. Newer CISA direction pushes teams to contextualize vulnerabilities for their own environment rather than react to raw severity scores, the conversation that lets an OT engineer explain why a paper critical is well compensated while an exposed safety system rated moderate is the real emergency. The harder problem is remediation speed. Automated patching is coming, but trust and breakage remain real, and someone still has to deploy the fix onto the box. Campaigns like Volt Typhoon, which positioned quietly inside US critical infrastructure ahead of a potential conflict, are counting on that last mile being slow. Visibility is the precondition for all of it, because an asset an agency cannot see is one it cannot patch or defend. 

Modernization Is the Business Case, and the Clock Is Not Waiting 

The panel agreed on how to fund this work. Do not walk in with a no. Walk in with modernization, because the AI and automation that leadership wants depend on the modern identity and architecture that legacy environments cannot provide. Bishop spent eighteen months educating a service secretary on a risk most leaders assume is already handled, the way everyone assumes the lights come on when they flip the switch. The payoff was more than a billion dollars to replace OT at the most critical bases, won by starting small and showing progress rather than asking for everything at once. Defense does not stop at the fence line either, and every federal leader should be able to answer one forcing question. If this all goes down, how long can the mission keep running? 

Watch It. Share It. Then Act on It. 

The perimeter is not coming back, and the agencies that thrive will treat IT, OT, and IoT as one connected mission rather than three separate problems. For more information and for future conversations like this one, join the GIST 360 community and listen to GIST of Govt IT podcast. When you are ready to baseline where your environment stands, reach out to the team at Swish. Thanks to Armis Federal for sponsoring the discussion.