Skip to main content
Home
Main navigation
  • CAPABILITIES
  • SOLUTIONS
    • ArgusGA
    • AthenaGA
    • ComplySyncATO
    • ComplySyncATO (ServiceNow)
    • HephaestusGA
    • PhoenixGA
  • CUSTOMERS
  • CONTRACT VEHICLES
  • ONPOINT
Responsive Hamburger Menu
  • CAPABILITIES
  • SOLUTIONS
    • ArgusGA
    • AthenaGA
    • ComplySyncATO
    • ComplySyncATO (ServiceNow)
    • HephaestusGA
    • PhoenixGA
  • CUSTOMERS
  • CONTRACT VEHICLES
  • ONPOINT
  • GREEN ACCELERATOR
  • PARTNERS
  • CAREERS
  • ABOUT US
primary menu
GREEN ACCELERATOR
PARTNERS
CAREERS
ABOUT US
alt

FILTER BY

Type
Tags
Sectors
Capabilities
Sort by
APPLY
RESET
Our takeaways from the Appian Government 2024 event

EUGENE GOLDLUST

EUGENE GOLDLUST
Sr.Account Executive
2024-11-11

Recently, ASSYST’s Sr. Account Executive, Eugene Goldlust, and Business Analyst, John Kimberl, attended the 2024 Appian Government event, where they explored the latest in low-code, RPA, intelligent automation, and AI. Eugene and John closely collaborate with our delivery teams to bring innovative, best-in-class solutions to our clients, and this event provided valuable insights to enhance their work. They share key takeaways and perspectives on how emerging technology trends in low-code platforms can empower government agencies to streamline processes, boost efficiency, and enhance citizen services.

Eugene: John, I’m glad we both had the chance to attend Appian Government 2024 this year. There was so much insight into how Appian is reshaping the public sector. Where do you think we should start?

John: Absolutely, Eugene! I’d say we start with the opening keynote. Matt Calkins really set the tone, didn’t he? His emphasis on process innovation as a driver for operational efficiency was inspiring.

Eugene: I completely agree. Hearing Matt lay out how Appian’s platform is actively enabling agencies to align technology with mission objectives was powerful. It’s clear that Appian is committed to making a meaningful impact in the public sector. His point about Appian’s role across all Cabinet-level agencies really showed the trust and demand they’ve built up.

John: Yes! It really reinforced how Appian goes beyond being a product-driven company; they’re truly focused on process-based services that adapt to an agency’s needs. I think it’s this flexibility that makes Appian so valuable to public sector clients.

Eugene: Exactly, and the new tools they unveiled fit right into that mission. Ben Allen’s demo of ProcureSight was a game-changer. The way this AI-enabled procurement research tool simplifies acquisition workflows while maintaining compliance—it's going to save agencies both time and resources. Imagine the efficiencies we could apply here at ASSYST.

John: Absolutely! And did you notice how seamless Appian Case Management Studio was? That centralized tool for managing cases, integrating documents, and tracking workflows—it's a dream for anyone managing complex cases across multiple departments.

Eugene: Yes, that and Process HQ were highlights for me. Process HQ brings visibility into workflows' bottlenecks and helps make real-time adjustments. It’s exciting to think about how tools like these could elevate our work and improve stakeholder engagement.

John: Agreed, and I also noticed a big theme on process automation and AI integration. Ben McGrane from the USDA shared some valuable insights on transforming incident procurement operations. He talked about centralizing data from numerous systems, ensuring faster access to key information.

 

Eugene: Exactly! That project McGrane mentioned—using a process automation strategy to enhance USDA’s Forest Service procurement data management—was impressive. It’s similar to how we’re utilizing Data Lakes and Data Fabrics for our clients, but this showed a clear path for enhancing that through Appian’s ecosystem.

John: It definitely sparked ideas for our team. I liked hearing how they use AI to refine data sharing and provide teams with a holistic view. These insights fit perfectly with our work in creating interconnected, interoperable data platforms.

Eugene: Then there was the talk on low-code development. What did you think of that panel with Brigadier General Kevin Woodard and Rear Admiral William Dwyer? Their insights into Appian’s low-code capabilities for the Navy and Marine Corps’ case management systems were compelling.

John: It’s impressive to see the military adopting low-code platforms. The fact that Appian’s low-code process automation solution allowed them to deploy a secure, compliant, and user-friendly legal case management system—that’s huge! It highlighted just how agile low-code can make government services.

Eugene: The configurability is unmatched. Low-code allows agencies to customize applications without heavy coding, which means they can deploy faster and adjust as needs evolve. That approach empowers teams to solve issues directly rather than relying on developers for every small change.

John: Exactly, and this “citizen developer” concept is growing. Seeing how low-code was used to build an intuitive case management app for a city’s waste hazard management really illustrated the possibilities. The way they involved stakeholders in the design—from city officials to citizens—was a masterclass in Human-Centered Design.

Eugene: You’re right, John. This emphasis on stakeholder-driven design will be critical as we push for more user-centric applications. It was a great example of how low-code platforms like Appian’s empower end-users to customize and refine applications to their needs.

John: And then there were all the discussions on intelligent automation. Hearing the U.S. Army’s Assistant Secretary, Young Bang, discuss the Army’s 500-Day Plan for AI was impressive. They’re envisioning an AI-enabled, intelligent automation environment that could reshape decision-making processes.

 

 

Eugene: The scope of their vision was inspiring. With AI-enabled, intelligent automation, they’re aiming for more responsive and adaptive systems. It’s clear that their open-architecture approach will make it easier to adopt these innovations seamlessly across different programs.

John: Exactly. It’s a forward-thinking strategy that mirrors our approach at ASSYST, particularly as we expand our AI and automation capabilities. The idea of operationalizing AI in real-world environments was motivating.

Eugene: Lastly, I have to say, the networking opportunities were invaluable. I had some great discussions with peers and industry experts who share our commitment to improving government services.

John: Same here. I left with so many new ideas and potential partnerships that could lead to exciting collaborations for ASSYST.

Eugene: That’s the best part—Appian Government 2024 wasn’t just a showcase of tools and solutions; it was a community of like-minded professionals, all pushing for progress in government technology. Here’s to taking these insights and using them to drive meaningful changes for our clients.

John: Absolutely, Eugene. This event reinforced that we’re on the right path with our approach at ASSYST and opened our eyes to some new possibilities. Looking forward to seeing how we can apply these insights together.

 

 

ASSYST Low-Code Capabilities

What distinguishes ASSYST is our precision-engineered approach to leveraging low-code solutions tailored to complex, sector-specific needs. ASSYST’s approach ensures that each client’s unique operational and regulatory requirements are met. By fully exploiting the capabilities of low-code platforms and Cloud services, we deliver customized solutions that drive strategic objectives, optimize resource utilization, and enable rapid adaptation to evolving business landscapes.

Product names mentioned are for informational purposes only

Security Data Fabric - Innovating a Modern Data Landscape for Future-Ready Cybersecurity

EUGENE GOLDLUST

EUGENE GOLDLUST
Sr.Account Executive
2024-10-29

I enjoyed speaking with Vinay Shirke about ASSYST's innovative approach to a modern data landscape, Security Data Fabric. We explored how this data management framework enhances risk management, resilience, and intelligence within security data analytics. Vinay shared valuable perspectives on how ASSYST's Security Data Fabric is designed to unify and optimize security data, empowering organizations to make faster, more informed decisions to stay ahead of evolving cyber threats. This conversation sheds light on the future of cybersecurity and ASSYST's commitment to pioneering solutions for a safer, data-driven world.

Read more on LinkedIn | ASSYST' Security Data Fabric

ASSYST Joins USDA STRATUS Launch: Driving Cloud Innovation Forward | Nov 15, 2024

RAM PRASAD

RAM PRASAD
EVP – Business Solutions
2024-10-29

ASSYST, as the prime contract holder for the USDA STRATUS Blanket Purchase Agreement (BOA), is excited to sponsor and exhibit at the launch event. The event, organized by the Advanced Technology Academic Research Center (ATARC), serves as a collaborative forum for the USDA, federal partners, and industry leaders to shape the future of cloud technology.

Date and Time

November 15, 2024, 7:30 AM - 3:00 PM ET 

Location

USDA Headquarters Complex - Washington, DC

About USDA STRATUS

USDA designed the STRATUS Program for USDA (https://www.usda.gov/disc/stratus) to address the complexities of expiring and fragmented cloud contracts. It enables cost optimization, fosters robust competition, and leverages the government's collective buying power.

By bringing together key stakeholders, the program aims to modernize enterprise data management and streamline the procurement of leading commercial IT services and solutions for government agencies. The STRATUS initiative sets the stage for smarter, more agile cloud strategies, paving the way for a unified approach to federal cloud adoption and innovation.

Event Website

https://atarc.org/event/usda-stratus-event/

ASSYST's USDA STRATUS BOA

https://www.assyst.net/contracts/usda-stratus-boa

Scope of USDA STRATUS BOA

USDA agencies can conveniently procure a wide range of cloud integration and development services, including managed services, to meet their evolving IT needs through the STRATUS BOA. The agreement's scope covers essential areas such as governance, cloud strategy, and cloud and platform architecture, providing a solid foundation for digital transformation efforts. Agencies can also access support for cloud migration, cloud security, platform operations, and engineering, as well as CI/CD pipeline engineering, identity and access management (IAM), user management, and change management to ensure seamless cloud operations.

Additionally, STRATUS enables procurement of application development and integration, discovery, framing, and design services, fostering innovation and modernization. The BOA extends to training, operations and maintenance, sustainment, and digital product management, ensuring agencies can effectively maintain and evolve their cloud solutions. For compliance and security, USDA agencies can also leverage FedRAMP authorization, 3PAO assessor services, and security assessment and authorization (A&A), all within a streamlined procurement process. This comprehensive offering makes STRATUS a key resource for USDA's cloud modernization and strategic IT initiatives.

Meet our Team at the Launch 

 

 

https://www.linkedin.com/in/prasadram/

ASSYST Cloud Services

ASSYST’s Cloud services allow customers to build, deploy, and manage applications, services, and infrastructure in the Cloud. We utilize and administer Cloud platforms, such as Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP), to rapidly and continuously develop and deploy applications and services for our customers’ systems and applications. 

Connect with us: TeamUp@assyst.net | https://www.assyst.net/connect

ASSYST Named a 2025 OrangeSlices Elev8 GovCon Honoree

RAM PRASAD

RAM PRASAD
EVP – Business Solutions
2024-10-22

 

ASSYST is proud to announce its recognition as a 2025 OrangeSlices Elev8 GovCon honoree. This prestigious award highlights our excellence in the competitive Federal GovCon marketplace, where delivering innovative solutions is paramount. This recognition reflects our commitment to fostering a culture that attracts top talent, partners, and clients.

The Federal GovCon sector continues to be one of the most complex and competitive marketplaces in the world. The consistent and long-term winners of today and tomorrow are those companies that understand they must not only bring to the table efficient and effective solutions but also a corporate culture that demonstrates their own excellence, making them a beacon for talent, partners, and clients. 

ASSYST is honored to be included in a select list of federal government contractors who have been identified as #doingittherightway based on outstanding results in several key areas: 

  • Good Partner - in ways that go above and beyond to provide support, mentorship, engagement, collaboration, and bridge the divide, building one successful team to deliver for their client.   
  • Growing Your Talent - with a focus is on what is best for the individual. 
  • Philanthropy – that is driven by its team, by its focus, and by what is happening in the world and communities it works in.   
  • Exemplify Innovation – and are guided by principles that understand the status quo is not enough and they must demonstrate they are doing more and doing better.   
  • Industry Engagement – that includes multiple aspects including mentorship, giving of time or services, sharing of intel, will involve people from across the company and will be driven by a desire to give back.   
  • Inclusive and Diverse - finding ways to have those voices heard, for combining those personalities on shared efforts for the betterment of all involved.   
  • Sustainability Practices – demonstrating that everyone must do their part and they have identified and defined ways they can #dobetter for themselves and their government clients.   
  • Investment for the Sake of Betterment - putting money behind their commitment to improving the work environment and experience for both internal teams and as it relates to customer delivery. 

These characteristics were defined as drivers to Elev8 GovCon and provide a major competitive edge, including higher levels of employee and customer engagement and loyalty, which translate into higher growth and profits. The companies recognized above, and the leaders guiding these teams forward understand what it takes and are models of #doingittherightway. 

“Being named a 2025 OrangeSlices Elev8 GovCon honoree highlights our commitment to excellence and innovation. At ASSYST, we strive to deliver outstanding solutions while fostering an inclusive environment that empowers our associates and partners. This recognition inspires us to keep pushing the boundaries in the Federal GovCon sector.” — Joe Anderson, COO, ASSYST.

The official announcement is available here - https://orangeslices.ai/its-time-to-elev8-govcon-2025-edition-recognizing-those-government-contracting-companies-who-are-doing-it-the-right-way/

About OrangeSlices AI

OrangeSlices AI. Playful Name. Serious about Democratizing Data and Disrupting the GovCon Competitive Intelligence Market. The core mission for OS AI is to identify, share and create timely, actionable and responsible information and data products, tools, and resources that 1) are accessible to all organizations and their teams, small to large; 2) will assist Federal government and Industry IT and consulting leaders to more effectively identify and engage with each other; and 3) shine a spotlight on those leaders and companies that are #doingitright.

SOARing Into the Future: Enhancing Cybersecurity with Orchestration and Automation

VIJAY NARASIMHAN

Vijay Narasimhan
Chief Technology Officer
2024-10-22

In today's rapidly evolving cybersecurity landscape, organizations face increasingly complex threats that require innovative solutions. One such solution is Security Orchestration, Automation, and Response (SOAR), which has emerged as a game-changer for cybersecurity operations.

SOAR integrates various security tools and automates repetitive tasks, enabling faster and more accurate incident responses. Its true strength lies in its ability to streamline workflows, allowing cybersecurity teams to focus on high-priority threats and strategic initiatives. By harnessing the power of SOAR, organizations can enhance their overall security posture and operational efficiency.

Enhancing Efficiency with Security Orchestration, Automation, and Response (SOAR)

Organizations that have embraced SOAR are experiencing notable benefits:

  • Increased Efficiency: Automation of routine tasks allows security teams to respond to incidents more swiftly, concentrating on more complex threats that require human intervention.
  • Enhanced Collaboration: SOAR fosters better communication among different security tools and teams, breaking down silos that often hinder effective threat response.
  • Improved Data-Driven Decisions: SOAR enables organizations to make informed decisions based on real-time information by centralizing threat intelligence and automating data collection.

Key Strategies for Effective SOAR Implementation

  1. Integrate Diverse Security Tools: SOAR acts as the central nervous system for Security Operations Centers (SOCs), bringing together various security technologies, including Security Information and Event Management (SIEM) systems, Intrusion Detection Systems (IDS), and Threat Intelligence Platforms (TIP). This integration is crucial for maintaining a holistic view of the security landscape.
  2. Automate Incident Response: Implementing automated workflows, known as playbooks, can significantly enhance incident response times. For instance, automating phishing detection and response workflows can drastically reduce the time it takes to contain threats.
  3. Leverage Threat Intelligence: Centralizing and analyzing threat intelligence data allows organizations to stay ahead of potential risks. Effective use of threat intelligence helps agencies proactively identify vulnerabilities before they can be exploited.
  4. Continuous Monitoring and Evaluation: Organizations should track key performance metrics to assess the effectiveness of their SOAR implementations before and after. Metrics such as Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), and user satisfaction scores provide valuable insights into operational performance. Once SOAR implementation is in place, periodic monitoring is necessary to ensure false negatives are in check.

Threat Intelligence Reporting for Incident Response and Service Recovery Preparation

Proactive threat intelligence reporting is essential for ensuring that organizations are prepared for incidents and can recover services swiftly. By integrating threat intelligence with incident response strategies, organizations can:

  • Anticipate Threats: Regular reporting on emerging threats and vulnerabilities enables organizations to prepare their defenses.
  • Streamline Incident Response: With timely and relevant threat intelligence, incident response teams can act more effectively, ensuring that incidents are managed efficiently.
  • Enhance Service Recovery: A well-prepared organization can recover from incidents more quickly, minimizing downtime and maintaining service quality.

Managed SOC Services Enhancing Technology Investments

Managed Security Operations Center (SOC) services provide organizations with expert monitoring and management of their security technologies. By leveraging these services, organizations can:

  • Maximize Technology Investments: Outsourcing SOC capabilities allows organizations to focus on core competencies while benefiting from advanced security technologies and expertise.
  • Achieve 24/7 Coverage: Managed SOC services ensure continuous security monitoring, reducing the risk of overlooked incidents.
  • Utilize Advanced Analytics: With access to specialized analytics tools, managed SOC teams can provide deeper insights into security events, enhancing overall situational awareness.

SOAR Stack Components

Understanding the foundational components of a SOAR solution can further aid agencies in optimizing their cybersecurity operations:

SOAR Stack ComponentsDescriptionApplicable Standards
SIEM (Security Information and Event Management)Centralized logging and event correlation platform.

- NIST SP 800-92: Guide to Computer Security Log Management

- FISMA: Federal Information Security Management Act

- CISA: Cybersecurity and Infrastructure Security Agency logging mandates

Incident Response AutomationAutomates incident response processes such as threat containment and mitigation.

- NIST SP 800-61: Computer Security Incident Handling Guide

- FIPS 199: Standards for Security Categorization of Federal Information and Information Systems

- FedRAMP: Federal Risk and Authorization Management Program

Threat Intelligence Platform (TIP)Centralizes and analyzes threat intelligence data from multiple sources.

- NIST SP 800-53: Security and Privacy Controls for Information Systems and Organizations (RA-5: Vulnerability Scanning)

- EO 13636: Improving Critical Infrastructure Cybersecurity

Vulnerability ManagementIdentifies, evaluates, and mitigates security vulnerabilities.

- NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management Technologies

- CMMC: Cybersecurity Maturity Model Certification Level 2 (RA.L2-3.11.1)

Endpoint Detection and Response (EDR)Provides real-time endpoint monitoring and incident response capabilities.

- NIST SP 800-137: Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations

- FISMA: Federal Information Security Modernization Act

Playbook AutomationEnables the automation of routine security workflows.

- NIST SP 800-61 Rev. 2: Computer Security Incident Handling Guide (Section 3: Incident Response Life Cycle)

- FIPS 200: Minimum Security Requirements for Federal Information and Information Systems

User Behavior Analytics (UBA)Detects anomalous user behavior based on established baselines.

- NIST SP 800-94: Guide to Intrusion Detection and Prevention Systems (IDPS)

- NIST SP 800-53: AU-6 Audit Review, Analysis, and Reporting

Security OrchestrationIntegrates multiple security tools to streamline processes.

- NIST Cybersecurity Framework (CSF): Secure software development practices are integrated (PR.PS-06)

- NIST SP 800-53: SI-4: System Monitoring

Case Management SystemOrganizes and tracks security incidents for review and compliance.

- NIST SP 800-53 Rev. 5: IR-5 Incident Monitoring

- ISO/IEC 27001: Information Security Management System (ISMS)

 

ASSYST Capabilities: Enabling Effective Cybersecurity Solutions

At ASSYST, we enhance cybersecurity operations through innovative capabilities that complement SOAR implementations:

  • Integrated Cybersecurity Solutions: Our comprehensive capabilities include SOAR, SIEM, Endpoint Detection and Response (EDR), and Threat Intelligence Platforms, ensuring seamless integration among organizations’ security tools.
  • Cyber Risk Advisor as a Service (CRAaaS): Our proactive risk management service professionals offer continuous policy directives, assessment requirements, and strategic insights, empowering agencies to stay ahead of evolving threats.
  • Security Data Lake and Security Data Fabric: These capabilities allow for the aggregation and analysis of vast amounts of security data, leading to informed decision-making and a proactive security posture.
  • AI-Enabled Metadata and Conversational AI: Leveraging AI technologies enhances the relevance of threat intelligence and improves user engagement with our security solutions.
  • Compliance Expertise: We help organizations navigate complex regulatory landscapes, ensuring that our solutions align with NIST, FISMA, FedRAMP, and RMF requirements.

Adopting innovative tools like SOAR is essential for organizations looking to strengthen their cybersecurity posture. By leveraging the capabilities offered by ASSYST, agencies can enhance their security operations, drive efficiencies, and ultimately protect against the ever-evolving threat landscape.

www.assyst.net/cyber

ASSYST awarded contracts for Army Digital Communications Support

EUGENE GOLDLUST

EUGENE GOLDLUST
Sr.Account Executive
2024-10-09

ASSYST is pleased to announce that we have won two new task orders under the Army ITES-3S IDIQ from Army Contracting Command, Aberdeen Proving Ground (ACC-APG), and the Redstone Arsenal, Alabama - Aviation and Missile Command (AvMC)

Under these contracts, ASSYST and its partners will provide robust systems and infrastructure support, enabling seamless video conferencing, teleconferencing, printing, real-time digital communication, and innovative collaboration solutions.

"As the prime contractor for ITES-3S, our focus is on delivering innovative technology and exceptional value to ensure the success of our service members," said Loren Gray, the Army Program Manager, ASSYST.

About Army CHESS ITES-3S IDIQ

ITES-3S offers decentralized ordering with no contract access fee charged to agencies awarding against it. The base ordering period of performance is from September 25, 2018, to September 24, 2023, with five option years. This contract is managed by the US Army’s Computer Hardware, Enterprise Software and Solutions (CHESS) program and Army Contracting Command, Rock Island (ACC-RI). Service Areas include Cybersecurity Services, Information Technology Services, Enterprise Design, Integration, Consolidation, Network/Systems Operation and Maintenance, Telecommunications/Systems Operation and Maintenance, Business Process Reengineering (BPR), IT Supply Chain Management, IT Education and Training.

ASSYST ITES-3S IDIQ Program Contacts:

Eugene Goldlust  | LinkedIn

Loren Gray | LinkedIn

Tel: 703-230-3100 

Email: ites3s@assyst.net

Web: https://assyst.net/contracts/Army-ITES3S-IDIQ 

Cybersecurity Awareness Month 2024 : Message from Vinay Shirke, CIO and Vijay Narasimhan, CTO

RAM PRASAD

RAM PRASAD
EVP – Business Solutions
2024-10-02
Cybersecurity Awareness Month - 2024

Cybersecurity Awareness Month 2024: ASSYST's Vision for a Resilient Digital Future

Vinay Shirke, CIO and Vijay Narasimhan, CTO

In recognition of Cybersecurity Awareness Month, ASSYST reaffirms its unwavering commitment to building and securing a resilient digital future for our customers, partners, and the broader community. As leaders in cybersecurity, we—Vinay Shirke, CIO, and Vijay Narasimhan, CTO at ASSYST—recognize the urgency and shared responsibility of safeguarding data, systems, and critical infrastructure in an increasingly interconnected and complex digital landscape. This commitment aligns with the Cybersecurity and Infrastructure Security Agency's (CISA) “Secure Our World” initiative."

Follow ASSYST OnPoint on LinkedIn to Read More

www.assyst.net/cyber
ASSYST to exhibit at CMS Works 2024 - The Annual CMS Cybersecurity Conference

KHALIL ZEBDI

KHALIL ZEBDI
EVP – Business Development
2024-10-01

ASSYST is delighted to participate in and sponsor the CMS CyberWorks 2024 event. 

Meet our Team
Khalil ZebdiJohn Kimberl

In recognition of Cybersecurity Awareness Month, ASSYST reaffirms its unwavering commitment to building and securing a resilient digital future for our customers, partners, and the broader community. 

ASSYST brings over 30 years of experience delivering enterprise, innovative, and professional solutions to federal clients. As a CMMI Level 3 (DEV/SVC), ISO 9001, and ISO 27001 certified company, we continually refine our capabilities to support mission-critical systems that deliver secure and impactful citizen services. Our offerings include program and project management, human-centered design, system modernization, DevSecOps, cloud management, cybersecurity, data analytics, AI-driven solutions, and digital services.

ASSYST supports healthcare clients, including HHS, CMS, FDA, HRSA, PSC, ASTP/ONC, NIH, CDC, VA, and various state and local government agencies. Leveraging our Green Accelerator Platform, we provide specialized solutions like the Security Data Lake, Test Automation Framework Portal, ComplySyncAI for Cybersecurity ATO Compliance, Hephaestus for HL7® FHIR® Health Data Interoperability, and Collab AI for LLM and RAG-based document search and collaboration.

We also offer Information System Security Officer as a Service (ISSOaaS) and Cyber Risk Advisor as a Service (CRAaaS) to enhance security programs and operations. ASSYST drives innovation in healthcare, security, and digital transformation, empowering clients to excel in today’s complex digital landscape.

www.assyst.net/cyber

ASSYST Joins U.S. Department of Labor for Cybersecurity Awareness Day: Strengthening Cyber Defense Together

EUGENE GOLDLUST

EUGENE GOLDLUST
Sr.Account Executive
2024-10-01

ASSYST is proud to announce its sponsorship of the upcoming Department of Labor (DOL) Cybersecurity Awareness Day on October 10, 2024, organized by the Federal Business Council (FBC). 

Meet Our Team 
Joe AndersonEugene Goldlust

In recognition of Cybersecurity Awareness Month, ASSYST reaffirms its unwavering commitment to building and securing a resilient digital future for our customers, partners, and the broader community. 

ASSYST brings over 30 years of experience delivering enterprise, innovative, and professional solutions to federal clients. As a CMMI Level 3 (DEV/SVC), ISO 9001, and ISO 27001 certified company, we continually refine our capabilities to support mission-critical systems that deliver secure and impactful citizen services. Our offerings include program and project management, human-centered design, system modernization, DevSecOps, cloud management, cybersecurity, data analytics, AI-driven solutions, and digital services.

ASSYST supports healthcare clients, including HHS, CMS, FDA, HRSA, PSC, ASTP/ONC, NIH, CDC, VA, and various state and local government agencies. Leveraging our Green Accelerator Platform, we provide specialized solutions like the Security Data Lake, Test Automation Framework Portal, ComplySyncAI for Cybersecurity ATO Compliance, Hephaestus for HL7® FHIR® Health Data Interoperability, and Collab AI for LLM and RAG-based document search and collaboration.

We also offer Information System Security Officer as a Service (ISSOaaS) and Cyber Risk Advisor as a Service (CRAaaS) to enhance security programs and operations. ASSYST drives innovation in healthcare, security, and digital transformation, empowering clients to excel in today’s complex digital landscape.

www.assyst.net/cyber

CRAaaS - Cyber Risk Advisory, Monitoring, and Expert Guidance to Strengthen Security Posture

JOHN KIMBERL

E10
Business Development Specialist
2024-09-26

In today’s rapidly shifting cybersecurity landscape, agencies face increasing pressure to protect their systems, maintain compliance, and manage risks while adapting to emerging threats. But how can organizations ensure they're equipped to meet these challenges without overwhelming their internal teams? This is where ASSYST Cyber Risk Advisor-as-a-Service (CRAaaS) steps in, offering expert guidance and strategic oversight to bolster an agency’s security posture.

I am John Kimberl, a business analyst at ASSYST. I am joined by Khalil Zebdi, EVP of business development at ASSYST. Khalil has nearly three decades of Industry experience, including 15 years focused on large-scale cybersecurity programs for U.S. Federal Government Agencies. He’ll help us answer some of the most common questions about CRA-as-a-Service and how it can benefit organizations.

John Kimberl: Khalil, you’ve got nearly three decades of experience in IT, with the last 15 years laser-focused on large-scale cybersecurity programs for federal agencies. That’s pretty impressive. Can you tell us how ASSYST’s CRA-as-a-Service fits into that landscape and why it’s relevant now?

Khalil Zebdi: Thanks, John. You’re right—the cybersecurity landscape is evolving faster than ever, and agencies are feeling the pressure to keep up. That's where ASSYST’s Cyber Risk Advisor (CRA)-as-a-Service comes into play. We designed this service to help organizations navigate policy, compliance, privacy, and risk management challenges. It’s not just about putting out fires; it's about empowering agencies strategically to enhance their security posture. Our CRA service ensures they’re keeping up and staying ahead.

John: So what exactly does a Cyber Risk Advisor do? I mean, how do they differ from other security roles?

Khalil: Great question. Think of the CRA as a key part of the CISO’s team but with a broader view. They handle the RMF (Risk Management Framework) for multiple systems simultaneously, which is no small feat. They’re focused on the big security issues—policy, privacy, compliance, and operational integrity for FISMA systems. What’s unique about the CRA is its direct engagement with agency stakeholders and leadership, guiding them through security challenges and offering risk recommendations that align with NIST best practices. It’s not just about checking off boxes; they’re helping shape long-term strategies that influence day-to-day operations, from coordinating with cybersecurity experts to ensuring that software development and change management processes meet stringent cyber standards.

John: I see. So, how is CRA-as-a-Service different from ISSO-as-a-Service? They sound critical to an agency’s security, but what sets them apart?

Khalil: They’re both important, but their focus is different. CRA-as-a-Service is more strategic—it's about evaluating risks from a high level and improving the overall security posture. The CRA is a trusted advisor to leadership, providing risk recommendations that guide big decisions. On the other side, ISSO-as-a-Service is more tactical. The ISSO is on the front lines, managing compliance and ensuring that the day-to-day security controls and processes are implemented correctly. They’re more hands-on with executing tasks, whereas the CRA thinks about the big picture and how to steer the ship.

John: That makes sense. So, when it comes to expertise, what kind of knowledge does a CRA bring to the table?

Khalil: A CRA possesses rather unique expertise with regard to cyber operations, John. They deeply understand technical and policy aspects, honed through years working in government and compliance-heavy environments. They know their way around security controls, tools, platforms, and the RMF process. But it’s more than just technical know-how—they’re troubleshooters. They can independently assess, analyze, and resolve security issues, particularly those high-risk, persistent threats. A CRA isn’t just patching problems; they’re thinking about long-term solutions engaging with system owners, stakeholders, and development teams to ensure cybersecurity operations run smoothly and comply with federal regulations. The CRA provides the transition is secure as organizations move to the cloud or adopt new technologies.

John: It sounds like the CRA is pretty central to everything. How do they use the NIST Risk Management Framework (RMF) in their role?

Khalil: RMF serves as the backbone of the CRA role. They use it to guide risk assessments and manage information systems from start to finish. The CRA moves through each step of the RMF—categorization, control selection, implementation, monitoring—to ensure that every part of the security process aligns with federal standards and agency-specific policies. They’re not just following the RMF but orchestrating the entire process. They identify sensitive data, evaluate privacy impacts, and continuously review how effective those processes are. It's a constant improvement cycle to ensure the organization’s top-notch cyber practices.

John: I can see how crucial that is. How do CRAs collaborate with other roles, like ISSOs and system stakeholders?

Khalil: Collaboration is key. The CRA works hand-in-hand with ISSOs and system stakeholders, especially throughout the RMF process. They ensure that security controls are not only implemented but optimized. This collaboration helps ensure that the system’s security posture is continuously evaluated and improved in real time based on emerging threats and evolving compliance standards. The CRA also plays a critical role in advising leadership on addressing evolving risks, ensuring the organization stays ahead of the curve.

John: When assessing a system’s security posture, what exactly does the CRA do?

Khalil: The CRA conducts in-depth risk assessments, closely examining the system’s vulnerabilities. Based on their findings, they recommend to the CIO and CISO whether the system is ready for an Authority to Operate (ATO). This is critical because it’s not just about saying “yes” or “no.” The CRA ensures that all vulnerabilities are identified, risks are mitigated, and the system is fully protected before it moves forward for certification.

John: Got it. So, let’s talk about the benefits. Why should organizations invest in CRA-as-a-Service?

Khalil: It’s all about agility and expertise. With CRA-as-a-Service, agencies don’t need full-time staff to get top-tier risk analysis and recommendations. They can tap into our expertise as needed, which is cost-effective and efficient. Plus, the CRA isn’t just reacting to security issues—they’re proactively managing risks to prevent breaches. This service helps agencies avoid threats while ensuring compliance and regulatory standards are met. It also supports POA&Ms and long-term cybersecurity strategies, making it a well-rounded solution.

John: Finally, how can an organization scope CRA-as-a-Service effectively?

Khalil: The first step is to assess where you stand—look at your security posture and identify gaps. From there, set clear objectives, whether improving RMF compliance, obtaining ATO certification, or strengthening overall risk management. It’s important to bring in key stakeholders early and ensure the CRA is integrated into the RMF process. And, of course, success can be tracked through tangible metrics like improved audit outcomes, faster incident response times, and readiness for ATO. It’s all about aligning the service with your strategic goals to get the most out of it.

About ASSYST Cybersecurity Capabilities and Solutions

ASSYST provides cyber support services that help customers with portfolios of FISMA Systems to manage risks effectively and comply with regulations. Our services include risk management, policy and compliance, vulnerabilities, knowledge management, data management, project management, and talent management for CISOs and business leaders. Our Security Data Lake Solution harmonizes data and improves holistic threat intelligence through actionable insights. Our unique ISSO-as-a-Service (ISSOaaS) and SOC-as-a-Service (SOCaaS) connect you with adaptable security professionals who follow industry best practices to support your organization's Cyber Mission Assurance. ASSYST’s ComplySync ATO solution applies AI/ML and collaborative document intelligence to help agencies acquire Continous Authority to Operate (cATO) capabilities.

Our seasoned cyber security experts adhere to industry standards and best practices such as NIST CSF/RMF, PMBOK, ISO 27001/9001, HS2P2 guidelines, and Zero-Trust frameworks. We offer a Cyber Resilience Program with various engagement, education, and training initiatives for customer cyber experts, business owners, and cyber leadership. These initiatives help them discuss evolving trends, share their best practices based on experience, and grow their knowledge base through certifications.

Pagination

  • First page « First
  • Previous page ‹ Previous
  • …
  • Page 11
  • Page 12
  • …
  • Next page Next ›
  • Last page Last »

CORPORATE

22866 Shaw Road
Sterling, VA 20166
Phone: 703-230-3100
Fax: 703-230-3100
e-mail: info@assyst.net

OTHER OFFICES

7000 Security Boulevard, Suite 120
Baltimore MD 21244
Phone: 443-200-5387

FOLLOW US

facebook linkedin twitter

TALK TO US

Image CAPTCHA
Get new captcha!
Enter the characters shown in the image.
Clicky
Footer menu
  • Terms of Use
  • Accessibility
  • Privacy Statement
CMMC 2.0 CMMI Level 3 ISO 9001 ISO 20000 ISO 27001 © All Rights Reserved.