Inside the Federal Cybersecurity Playbook: Bob Costello on AI, Identity, and FedRAMP at Black Hat 2026
Bringing new technology into government takes more than innovation, it takes navigating security requirements, procurement rules, and operational demands unique to the federal market. At Black Hat 2026, theCUBE's Krista Case sat down with Bob Costello, Chief Digital and Information Officer at The Merlin Group and former CIO of CISA, to unpack how agencies are approaching AI governance, identity for AI agents, hardware supply chain security, and the realities of the FedRAMP certification process. Bob also shares what CISOs and practitioners should look for when evaluating the wave of AI-native startups in the crowded security market.
TRANSCRIPT
Krista Case: Welcome back to theCUBE. We are continuing to roll through the afternoon of day two here at Black Hat 2026. I'm Krista Case. And over the next few minutes, we're going to be talking about how the federal government has really become an important proving ground for cybersecurity innovation. What we're seeing is that bringing new technology into the government requires more than just innovation. Companies have to navigate security requirements, procurement processes, and operational expectations that are very unique to the federal market. I'm joined this afternoon by Bob Costello, Chief Digital and Information Officer with the Merlin Group, and the former CIO of CISA. Bob, thanks for joining theCUBE.
Bob Costello: Happy to be here.
Krista Case: Yeah, how's the afternoon treating you today?
Bob Costello: It's been amazing. For some reason, it was my busiest day out here.
Krista Case: Yeah?
Bob Costello: But I'm happy to wrap it up with theCUBE today.
Krista Case: Yeah, we love it. Thanks for joining us. So Bob, you have a really interesting vantage point. You've seen some of these challenges around bringing security innovation from both sides. Again, you're relatively new in this role, my understanding is, as the CIO.
Bob Costello: Yeah, about six months.
Krista Case: Okay, yeah, at Merlin Group, but previously, again, you had that experience at CISA. So could you talk to maybe the biggest vantage point that you've gleaned from observing this development from both sides?
Bob Costello: Yeah, no, that's a great question. So I was actually a long-term federal employee in the military about 22 years. I spent the last four and a half years as the chief information officer over at CISA. So I think on that side of the fence, it's finding ways to do kind of innovative contracting so I could bring in solutions very fast, work with some of the smaller, more innovative companies, while also working with some of the largest players out there to secure our systems, make sure we were delivering for the American people. We want to spend their tax dollars effectively. And we always want to be constantly innovating. So we don't want to be behind the public sector. And often we were, excuse me, the private sector. We were running systems that are absolutely critical to national security. So you have to be careful, but you also have to protect them. On this side, what I really enjoy is, it's, The Merlin Group is an interesting company. We have essentially three portions. One is a separate company where we do something called Merlin Ventures, where we work with new cyber companies, seed stage, A-series funding, and I get to work with those founders, and it's absolutely amazing. We run something called the FedRAMP Accelerator, Constellation GovCloud, and that's my kind of unit that I run, and what we do there is we help companies be able to sell to the federal government, states, local governments, or critical infrastructure with FedRAMP certified solutions. And then we also have an entire, essentially, go-to-market engine called Merlin Cyber, where we can sell to the federal government and others.
Krista Case: So Bob, before the camera went live, we were talking about some of the key areas, I guess, of the cybersecurity stack that we really need to see some innovation in, right? Especially to be able to do things like keep pace with adversaries that are using AI.
Bob Costello: Absolutely.
Krista Case: So, I know you had talked about, data security was one area, certainly I'm seeing that as well. And then, shocker, artificial intelligence, right? I heard it a few times this week.
Bob Costello: Maybe once or twice, right?
Krista Case: So, from your vantage point as kind of looking to sell into the federal government, can you talk more specifically about what these customers are struggling with, especially when we think about maybe data security and maybe moving AI into production.
Bob Costello: Yeah, I think those are two great subjects. And I think as we're kind of looking at it through the lens right now, bringing AI into production is fascinating. We're all using it in some format. I think we're finding in many ways maybe it's unmanaged to a degree. We often, one of the, when we talk about data security and AI, one of the most interesting things, we've heard the term agents a lot throughout the entire conference and we hear it in the news and the world and every company is talking about AI agents. Often those agents operate under my own identity on my machine. Do we really know, should it operate that way? What does that agent have access to? Just like a human, does it have elevated privileges? And that's something that I think we really need to concentrate on. And in that space too on AI, are we training people how to use it effectively or are people turning out AI slop? Which is a very interesting avenue. And I think that's something we need to be very conscious of too.
Krista Case: I agree Bob, and underscoring the point regarding identity, we've had a number of those companies on theCUBE and conversations with them. And I think solving, as you mentioned, the visibility and governance piece of AI agents from an identity perspective, I think is going to be one of the key control points for operationalizing AI moving forward.
Bob Costello: I totally agree because we've already seen agents do things that were unexpected. Some of them, there was a story of the airline where an AI agent essentially lowered ticket prices and they had to honor them. And I'm all for that. It was good for the consumer.
Krista Case: Good for the consumer.
Bob Costello: But you don't want a person to be overprivileged in your environment. We cannot have someone with 12 agents working for them also overprivileged. And when you come back to identity, identity is the first pillar in every zero trust model. So it's just now bringing AI into that identity pillar. And also one area that I think is really becoming more critical is hardware intelligence. Are the things connecting to my environment what they say they are? So, supply chain security is huge.
Krista Case: And, the fact that we've seen all these supply chain attacks over the last several years before the industry was even upended by AI, I think really validates that point, Bob.
Bob Costello: Absolutely. Yeah.
Krista Case: So, Bob, you referenced that you run this FedRAMP accelerator program. Are you seeing that federal agencies are starting to think about their preparedness for FedRAMP earlier?
Bob Costello: So I see companies preparing.
Krista Case: Yes, yes.
Bob Costello: Excuse me.
Krista Case: Oh, no, no.
Bob Costello: And I think what is becoming fascinating is we are seeing a demand signal from not just the federal government, but from others for FedRAMP solutions. So states and local governments are now starting to enact procurement regulations or laws saying, you should be GovRAMPed or FedRAMPed. And that's, I think, a wonderful change in direction. So I think a lot of companies are seeing their addressable market for FedRAMP solutions really increase. And I think that that's really good because, when we FedRAMP something, we're really checking hundreds of controls and ensuring that this application or this service is ready to rock and roll for the type of data that will enter into it.
Krista Case: So, Bob, you bring up a great point that, again, there's these multiple points that have to, that these companies have to go through to be FedRAMP certified. Do a lot of companies maybe underestimate that process and what's required? Maybe we'll start there.
Bob Costello: Yeah, I think that is sometimes a possible outcome or possible misconception. I do think the FedRAMP PMO has done a good job on adjusting FedRAMP and maybe making it easier in the explainability of it. I think if a company has a good idea of other compliance frameworks, they'll be able to kind of work through that. However, unlike others, you might have to find an agency sponsor. You might have to do all these other things. And then what is often underestimated for early companies is the sales cycle in federal can be quite long. It's not like let's have one meeting. By the time you hit the bottom floor of the elevator, you have a purchase order. It can be six months, 12 months, 18 months before that first sale. And that can be a tremendous amount of capital that a company is putting into that FedRAMP solution.
Krista Case: That makes sense, Bob. And are there any changes to FedRAMP requirements or to the process of getting FedRAMP certified as a result of this adversarial use of AI and as we're sort of adapting to how that's changing the threat landscape?
Bob Costello: That's a great question. And they have been modernizing FedRAMP for a while now. There's a program called FedRAMP 20x that's going to make things faster. They're making adjustments so that, CISA also had something called Binding Operational Directive 26-04 that came out. And what it really talks about is, and what it was leaning into with AI and the adversarial use of AI, and the rapid discovery now of vulnerabilities, is you can't patch everything. So you've got to prioritize based on risk. So we're moving into a world now where we want to understand the data in our systems, the risk, should that data be exposed or compromised. So what BOD 26-04 talked about is you need to prioritize, goes into everything from, hey, this vulnerability came out, can the adversary automate that vulnerability? Do you have other things in your environment that chain together, that create a —
Krista Case: Absolutely.
Bob Costello: Yeah, so you're spot on with that. So we're seeing the government make these changes, not just through FedRAMP, but through the work CISA's doing, the work NIST is doing, the work that NSA does for the defense industrial base, moving to a model to adjust for adversarial use of AI, or even just AIs discovering vulnerabilities at a pace that humans could not.
Krista Case: It's been something we've been hearing about, Bob, all week, right?
Bob Costello: Oh, excellent.
Krista Case: It's the speed and scale, and it's also chaining together these potential vulnerabilities and how that—
Bob Costello: Yes.
Krista Case: Excuse me, how that really changes how security operations need to move, the pace that they need to move at.
Bob Costello: Absolutely.
Krista Case: So are you seeing that in federal sector as well?
Bob Costello: We are. And we're seeing, I think one of the interesting things that happens when there's an executive order or a CISA directive, it may only apply to the federal sector, but others adopt it because they're like, this makes sense. So you start seeing changes throughout the entire ecosystem. And it can take time, but I do see that it's not just changing in federal. The actions by the federal government are then allowing others to adopt that or reference it to change things in the commercial or the larger public sector ecosystem.
Krista Case: Absolutely, that makes sense, Bob. And we were talking a little bit about the role of identity in these AI stacks and we've been having a number of conversations around governing AI in production. And I know that it sounds like you actually helped to establish AI governance when you were at CISA. Is that correct?
Bob Costello: We tried.
Krista Case: Fair enough.
Bob Costello: We did the best we could at the time we could. And I had great people helping me. Lisa Einstein, who's leading a lot of AI efforts at CISA. We had to always meet the mission. I can't tell a threat hunter no because then they'll go do it themselves and then I'm in a worse place. I think governance is extremely hard because a lot of when we're working on governance are people that I was always a little hard to govern in my time as an engineer or CIO. But when you're trying to write that or put guardrails around it, when things are changing so fast and the mission is changing so fast. So governance has to kind of move at the speed of business or mission and also not be so restrictive or onerous that it's impossible for people to do their jobs.
Krista Case: We've been hearing a lot about that, certainly. So there is the fact that organizations overall are trying to leverage AI as quickly as they can. Their risk appetite is changing, right? So they're understanding that they're going to have to make some trade-offs. Are you seeing that in the federal government side as well?
Bob Costello: We are. And we've been doing that for years. Because whenever there's a new technology, what are my trade-offs? What is my exposure through this? And then also, too, one of the things we're noticing, too, is both, worldwide, how do I train the workforce now? How are things changing? And I'll be careful with what jobs go away. But there are some things that are highly automatable that maybe machines do better. And now how do we train people to either interact with those machines or retrain people to do other things?
Krista Case: And where do you think humans are going to kind of bring maybe the expertise and kind of, because we're hearing a lot about this, that it's kind of the human augmented, human in the loop, right? So where is a human going to bring expertise that AI just can't bring to bear?
Bob Costello: I think one example, and going back to the Hugging Face, what we saw them do, that humans at Hugging Face, they had to run incident response. You're like, I've been there. It's not fun. Actually, it can be fun. But it's scary. They came up with this amazing idea to run an LLM internally. So human ingenuity and that ability to work together and talk and come up with these innovative ideas, I think we are very much still in the game there. So I don't worry about AI replacing that. I do think when you start talking about autonomous decisions, I think if an AI is getting a high fidelity signal that your machine is infected or has an issue, the AI should be able to isolate that machine. Now, do I think an AI should be able to, say, shut down the IRS's system? Well, let's not pick on the IRS. Because maybe they should. But healthcare. Should it shut down a hospital system? Absolutely not.
Krista Case: Absolutely.
Bob Costello: So I think you have to develop that risk appetite.
Krista Case: Yes.
Bob Costello: And then also how the AI informs us of the actions that happened.
Krista Case: And it's a process in terms of learning to trust, right? The AI's decision-making to then allow it to take some of these actions. I'm sure that federal government entities are probably even a little bit more skeptical than we might see in a security department from a public sector, excuse me, a private sector organization. Would that be a fair assessment?
Bob Costello: I think it would be. And then also, we all look at risk differently. One of the examples I sometimes use is lawyers in government, and sure, while it's always advice from a lawyer, it's, you know, we have to be compliant. We have to follow this. Sometimes in the private sector, you may work with your governance teams and risk teams and lawyers, and they may come back and say, well, you know, it's going to cost us $10 million to fix this. The fine's only $10,000. We could take lots of fines and still make more money. So that is a difference in how we look at risk within the government. And also, much like missions that happen in healthcare, the water sector and others, all those public servants, and I'm so proud of the public servants that I served with for 18 years at DHS, they're the best in the world. We are incredibly worried about all of it. And those systems keep terrorists out of the country. They're how we fly safely. They're how customs and immigration happen. The Secret Service does much more, you know, the presidential protection is a huge mission, but they do amazing work with the Treasury Department and others on that side of their mission. So FEMA is responding to disasters all the time across the country. So those systems that support those things, we took very seriously, and the people still there do as well. So we had to be really careful how we would introduce technology into it or changes into the environment.
Krista Case: Absolutely. And how do you think these organizations will think about maybe accelerating the pace that they can introduce new pieces of technology? And I ask that, Bob, because I think as security organizations, whether you're public or private sector, are trying to keep pace with attackers, we're going to potentially have to make some decisions more quickly in addition to kind of changing our risk appetite there. So do you think that it will start to maybe kind of change that mindset a little bit?
Bob Costello: I think so. And the people I work with, the defenders and others, they are, you know, we have to move at the speed of the adversary and be faster and adjust to that. So it will happen. And we also see in the commercial sector too, every release is coming out with AI built in. So sometimes you kind of end up in this adoption cycle and you cannot avoid it. So I think that that is driving change too. And I think it is very important though to measure the effectiveness of AI and what it's doing. But I think those two areas, we must do it because we see the direction that is happening in the world and we need to maintain America's technical superiority. And companies are just building it in. I don't think I can go to, obviously, Black Hat, you're going to see a lot of that, but I could go to any trade show right now for information and all that.
Krista Case: The AI conference down the street, right?
Bob Costello: Yes, absolutely, yeah. So we're seeing companies just build all of this in.
Krista Case: Yeah, and so Bob, I know we were talking a few minutes ago about AI governance and some of the initiatives that you had underway. I'm interested in looking at the control points in AI governance. Again, I know we were talking about identity, but what do you think are going to be some of the key control points in that AI governance stack moving forward?
Bob Costello: Yeah, and it's such a fascinating question because I think sometimes what I really like to do that AIs can't do that we can, this is a whiteboard session. Because it touches the whole aspect of the organization. It touches your human capital, it touches your finance, it touches acquisition, it touches the systems you're on, customer service, so I think that's part of it. How do I box it in? Excuse me, how do I fill those boxes? And then also, I don't think you can have governance without strategic intent. This is what we actually want AI to be doing in our organization and the outcomes that we expect. Here's how we shall govern and drive direction through that. So I know it's kind of a long answer to I hate governance in a silo vacuum. It's got to be part of the full circle of the organization.
Krista Case: Absolutely, Bob. And we're seeing the role of the CISO in particular is evolving. On one hand, they're having to make these decisions about risk tolerance, but they're also having to work with the board to understand what are some of these trade-offs that we have to make. So what do you see the role of the CISO being in this conversation? Are they kind of at the center of it and they're connecting the dots.
Bob Costello: You know, and you hit on one thing. CISOs need board visibility.
Krista Case: Yes.
Bob Costello: And they need to be able to address the board, brief the board, and have that support to execute in the way to secure the environment. So I think that's wonderful to keep hammering home. And we see every organization attack that problem in unique ways. In the federal government, the CISO would report to me, they report to the CIO, so we work as a team together through many processes. In industry, it typically is someone else. They report in different areas, but I do think they are often adopting AI effectively, but it also can't be that should something go wrong, the CISO worries that their job is gone. You've got to be doing the parts of your job.
Krista Case: Yes.
Bob Costello: But we should also always assume, and this is part of Zero Trust, we wake up every morning and assume a breach, assume compromise. And I really think CISOs need to be given that authority to secure the environment while ensuring that business outcomes are not affected by it.
Krista Case: I'm hearing it's becoming a more durable role.
Bob Costello: Yes, exactly.
Krista Case: It's less a breach happened, slap on the wrist. It's more, let's talk through, could we have prevented this? What happened? And what actions do we need to be taking moving forward and almost a consultant in some ways to the business.
Bob Costello: I absolutely agree and there's actually a great example of that right now in the federal government. So CISA had a security incident and they disclosed it, they wrote about it, they put it on their webpage and they said here's what happened, why we believe it happened, and the actions we're taking for it. And I believe that when we hide security breaches, and obviously not everyone can publicize it, there's issues sometimes with that. But the more that you talk about it and then say what went right, what went wrong, what was just okay, because there's a spectrum of all of this. And then how do you learn from it? And any ability to communicate what happened to the community helps us all get better. So that is something that I could not agree more with the direction that we're seeing.
Krista Case: Absolutely. And Bob, one closing question. So you referenced earlier in the conversation, you kind of oversee some venture capital, you know.
Bob Costello: I work with that group.
Krista Case: Yeah, you work with that group, thank you. So if I'm a CISO or a practitioner walking the show floor here at Black Hat, I'm getting inundated with especially a lot of these startups that are claiming these AI native capabilities. What do you think we should be looking for in terms of evaluating the merit of the technology and really the viability of this slew of startups trying to solve some of these problems.
Bob Costello: Well, I think too, I always look for energy in people that have done something before. Oh, I was an operator, I saw this problem, I'm creating a solution for this problem. Or maybe they have a background in founding successful companies. I think the other thing too is, I think it's okay to ask companies, show me your test results. I know you're saying you're 20% better than X. Can you show me how it was done? And was it only done in this very controlled environment?
Krista Case: Yes.
Bob Costello: Or was it actually done in an operational area? So I would encourage anyone, my best days are talking to founders and startups. The energy is there. They're passionate. They're seeing things in a new light. Spend time with these small companies and you will learn something through the whole process. But I would always say too, ask the tough questions. Especially if you're being asked, hey, buy this. We do that all the time. We ask tough questions about car buying or house buying, all those things. Just bring those skills to bear when you're buying software.
Krista Case: Make sure you look under the hood and really understand.
Bob Costello: Love that analogy.
Krista Case: Absolutely. Well Bob, this has really been a pleasure. I appreciate it. Thank you for taking the time today.
Bob Costello: It's been wonderful. Thank you so much, today. I always love being on theCUBE.
Krista Case: We appreciate you coming, enjoy the rest of the show.
Bob Costello: Thank you.
Krista Case: Thank you. And thanks so much for listening and tuning in. Stay tuned, we'll be right back in just a few minutes with more from Black Hat 2026.

