I’ve spent a good part of my career on the federal side of cybersecurity as a dedicated mission partner, and if there’s one lesson that never stops repeating itself, it’s this: knowing you should be secure and knowing you are secure are two very different things. Most organizations, including some of the most sophisticated in the world, still operate on the first kind of knowledge — a patchwork of vulnerability scans, compliance checklists, and point-in-time assessments that tell you what could go wrong, not what will happen when a real adversary shows up.
That gap is exactly why today’s announcement matters. The Defense Information Systems Agency (DISA) has selected AttackIQ as the enterprise platform for Adversarial Exposure Validation (AEV) across the Department of War (DoW) and it comes at a moment when the policy pressure to close that gap has never been higher.
In June, Executive Order 14409, “Promoting Advanced Artificial Intelligence Innovation and Security,” gave the DoW 30 days to prioritize the cyber defense of information systems and directed CISA to expand federal programs that enhance AI-enabled defensive tools.
An executive order sets direction; it doesn’t stand up a capability by itself. This deployment is what that direction looks like when it becomes an operational program spanning the Military Services, Defense Agencies, and Combatant Commands; the entire Department of War. It’s worth stepping back from the press release for a moment to talk about why a decision like this is so consequential, and why it’s critical to get right at this scale.
A Common Picture of Readiness
The Department of War divides its DoD Information Network (DoDIN) into unique DoDIN Area of Operations (DAOs), each assigned to protect their assigned cyber terrain. Each of these DAOs must continuously understand their cybersecurity posture and be able to answer the question, ‘Are we ready to withstand an attack by a nation-state adversary?’
Threat-informed Continuous Threat Exposure Management (CTEM) gives them a way to answer that question with evidence rather than estimation — validating, day after day, whether detections actually fire when a specific adversary technique hits their environment. It’s an operational approach built to deliver continuous, evidence-based proof that security controls perform against real-world adversary behavior, not just on assessment day.
The Shift From Point-in-Time to Continuous
A once-a-year penetration test tells you about the network you had a year ago. Adversary tactics, techniques, and procedures are changing in real time, and defensive environments continuously evolve. New tools get deployed, configurations drift, and detections get tuned (or untuned) without anyone noticing until it’s too late.
Continuous validation flips the model. Instead of asking “did we pass the last assessment?“, it asks “would we catch this specific technique right now, in this environment, with today’s configuration?” Then it keeps asking that question automatically against the techniques adversaries are using against the defense industrial base and government networks. That continuous evidence is what enables a move from anecdotal confidence to measured readiness.
Putting AI to Work on the Analyst’s Hardest Problems
Technology validation is only half of the equation, and it’s the half that is easiest to automate. As part of this rollout, the Department is also deploying AttackIQ’s AVA Agentic OS and Watchtower, our hyper-localized AI threat intelligence analyzer. Together, they’re built to tackle the parts of cyber operations that don’t scale well with headcount alone: identifying which adversary techniques are most relevant to a given mission, prioritizing what to validate first, and continuously tuning defensive operations based on validation results.
It’s also a direct response to the executive order’s call to expand federal programs and services that enhance AI-enabled defensive tools, rather than treating that mandate as a box to check.
That distinction matters — not AI as a buzzword bolted onto an existing tool, but AI applied directly to operational bottlenecks that have always limited how fast cyber teams can move.
Training: The Other Half of Readiness
The part of this announcement I’d encourage people not to skim past is AttackIQ Academy. It’s tempting to treat platform deployments as purely technical rollouts, but a validation platform is only as effective as the operators who know how to use its output — how to scope an assessment against a real technique, interpret prevention and detection results correctly, and communicate those findings to both technical teams and leadership who need the “so what.”
That’s why the custom AttackIQ Academy learning path built for this deployment doesn’t rely on traditional video modules. It puts operators inside interactive, AI-driven decision simulations that respond to the choices they make and give them individualized feedback on their reasoning, not just a completion certificate. Across all DAOs, that creates a shared baseline of judgment, not just a shared piece of software.
“As a leader of many DoW Network and Security Operations Centers, standing up many of them for DISA and USCYBERCOM, my biggest challenge wasn’t the amazing tech being integrated — it was training. The best way to get maximum value out of the new tech is to ensure your people are trained — not just with a quick overview PowerPoint, but by taking the security system through its paces and properly integrating it into your daily workflow. In this fast-paced cyber world, you still need to take the time to fully understand the valuable solution that you now have to ensure you maximize its capabilities.”
Paul Craft,
Brigadier General, US Army (Retired), former Deputy Commanding General of ARCYBER and founder of DISA’s Global Operations Command
The Bigger Shift This Represents
Strip away the product names, and what’s happening here is a shift in how a large, mission-diverse organization answers the question, “are we ready?” Not with a snapshot. Not with a checklist. With continuous, evidence-based proof — of technology and people — measured consistently across every part of the enterprise.
That’s the standard threat-informed CTEM was built to meet, and it’s the standard we believe defense and federal organizations of every size should hold their security programs to, whether they’re operating at DoW scale or a fraction of it.
