Reflections from TechNet Cyber 2026: The Future of Cybersecurity Is Becoming Operational
After spending three days at AFCEA TechNet Cyber 2026 in Baltimore, I left with a strong sense that the cybersecurity conversation across the Department of Defense, Intelligence Community, and industry is entering a new phase.
For years, discussions centered on modernization strategies, compliance frameworks, and technology adoption. Those topics remain important, but this year’s event felt noticeably more operational. Leaders were less focused on policy for policy’s sake and more focused on outcomes, execution, and mission effectiveness.
Several keynote presentations reinforced this shift, particularly remarks from Department of War CIO Kirsten Davies and Army Cyber Command Commander LTG Paul Stanton. Together, their messages painted a picture of where defense cyber priorities are heading over the next several years.
Observation #1: The Department Wants to Move from Cyber Compliance to Cyber Effectiveness
One of the most important themes from CIO Kirsten Davies’ remarks was the desire to bring a more operational and practical approach to cybersecurity.
Davies repeatedly emphasized that her background as a cybersecurity operator influences how she views the CIO role. Rather than adding layers of policy, she discussed creating a more holistic approach to cyber defense, workforce readiness, and operational effectiveness across the Department.
What stood out to me was the underlying message that cybersecurity must become an engineering and operational discipline rather than a documentation exercise.
This was particularly evident in discussions surrounding the Department’s ongoing efforts to improve and modernize the Risk Management Framework (RMF). Across the conference, there was broad acknowledgment that the historical RMF process often became overly focused on compliance artifacts, checklists, and paperwork rather than measurable risk reduction. The emerging Cyber Security Risk Management Construct (CSRMC) appears intended to shift the focus toward engineering rigor, operational outcomes, and continuous risk management.
My takeaway is that the Department is signaling a desire to make cybersecurity accreditation processes faster, more repeatable, and more closely tied to actual mission risk.
For industry, this could represent a meaningful opportunity to help agencies move from “authorization as an event” toward “risk management as a continuous operational process.”
Observation #2: AI Discussions Have Matured Beyond Pilots
Another major theme throughout TechNet Cyber was the maturation of artificial intelligence discussions. The conversation has clearly moved beyond experimentation. Rather than asking whether AI can help, government leaders are now asking how to operationalize AI securely and responsibly at scale.
Interestingly, very few conversations focused on AI models themselves. Instead, discussions centered on data quality, governance, trust, security, infrastructure readiness, and access to mission-relevant information.
The common thread was clear: AI effectiveness is ultimately a data challenge. Organizations are increasingly recognizing that trusted, accessible, and secure data will determine whether AI initiatives deliver operational value.
The AI conversation is becoming less about technology adoption and more about decision advantage.
Observation #3: LTG Stanton Reinforced the Need for Operational Readiness in Cyberspace
LTG Paul Stanton’s remarks reflected a similar operational mindset. Throughout his presentation, the emphasis was not simply on defending networks, but on preparing forces to operate effectively in contested digital environments. His comments reinforced a reality that cyber readiness is now inseparable from mission readiness.
One observation that resonated with me was the continued focus on readiness, resilience, and the ability to operate despite disruption.
For many years, cybersecurity conversations focused heavily on preventing breaches. Today’s military leaders appear increasingly focused on ensuring mission continuity when adversaries inevitably attempt to disrupt operations.
That distinction is important.
The question is no longer:
“Can we prevent every intrusion?”
The question is becoming:
“Can we continue executing the mission under attack?”
This represents a more mature and operationally relevant way of thinking about cybersecurity.
Observation #4: The Defense Industrial Base Is Now Part of the Battlefield
Another notable point raised by CIO Davies was the importance of cybersecurity across the Defense Industrial Base. She highlighted the reality that vulnerabilities within suppliers and partners can directly impact operational outcomes for warfighters. The Department’s cyber posture increasingly extends beyond government-owned networks into the broader ecosystem that supports national defense missions.
This reflects a growing understanding that mission assurance depends upon the security and resilience of an interconnected network of government agencies, contractors, technology providers, and mission partners. The boundaries between government cyber risk and industry cyber risk continue to blur.
Observation #5: Trust Is Emerging as a Strategic Requirement
Perhaps the most consistent theme I observed throughout the conference was the importance of trust.
- Trust in data.
- Trust in digital infrastructure.
- Trust in AI recommendations.
- Trust in supply chains.
- Trust in mission systems.
Many of the discussions surrounding Zero Trust, AI, cyber resilience, and RMF modernization ultimately pointed back to the same fundamental challenge: creating confidence that systems, information, and decisions can be relied upon in increasingly contested environments.
As technology becomes more integrated into every aspect of military and intelligence operations, trust is becoming a strategic requirement rather than simply a technical objective.
Looking Ahead
Leaving Baltimore, I came away with the impression that the Department is moving toward a more operational model for cybersecurity.
The signals from senior leaders were consistent:
- Simplify and improve cyber risk management.
- Focus on outcomes instead of compliance.
- Operationalize AI responsibly.
- Improve resilience and mission readiness.
- Strengthen trust across the defense ecosystem.
The technologies will continue to evolve, but the underlying objective appears increasingly clear: enable mission success in a world where cyber, data, and operational effectiveness are inseparable.
TechNet Cyber 2026 reinforced that cybersecurity is no longer just about protecting networks. It is becoming a foundational element of mission execution, operational readiness, and decision advantage across the modern digital battlespace.