It’s no secret: America is under attack online every day. Organizations of all sizes get bombarded with digital threats 24/7, and the velocity and volume of the vulnerabilities, breaches and hacks just keep growing. Successful cybersecurity executives not only need the technical know-how to safeguard systems and information but to always be one step ahead of the adversaries.
The following 10 executives have proven themselves capable of doing so. These execs range from chief technologists to senior cyber leads to company vice presidents and presidents, all with the common goal of defending their organizations and customers from the ever-evolving threats.
Why Watch: These leaders play key roles in strategizing, developing and implementing cyber defenses to keep pace with emerging technologies. They continue to push the envelope on innovation, with an eye, ultimately, toward creating a culture of security and resilience, and they understand the importance of cyber education and awareness. So when — it’s not a question of if — the next cyber catastrophe strikes, these cutting-edge leaders are prepared.

Darren Death, ASRC Federal
Darren Death is vice president of information security and chief information security officer at ASRC Federal. Among other affiliations, he is a member of the invitation-only Forbes Technology Council and a member of the board of advisers of The Cyber Intelligence Initiative for The Institute for World Politics.
Why Watch: ASRC Federal recently achieved a fully compliant rating with NIST SP 800-171 and also implemented the consensus security controls from the Center for Internet Security throughout the organization. Those milestones are part of ARSC Federal’s overarching commitment to continue strengthening its cyber hygiene culture, Death said. Over the next 12 months, Death will be part of the ASRC Federal team working to implement innovative technologies.
“We will be pushing traditional data center-based security capabilities down to the user space, ensuring the security services are provided to the user regardless of geographic location or method of access,” he said.
Amid a renewed push by companies in the federal space to protect themselves and their customers from a cybersecurity standpoint, the investment commitment and buy-in required “cannot be understated,” Death said. He has made it a personal goal to contribute to making the nation more cyber secure.
“I’m proud of the leadership that ASRC Federal has exhibited in this space, and I’m excited to continue spearheading industry-leading projects in the cybersecurity and compliance space,” he said. “I currently support the American Council for Technology — Industry Advisory Council, volunteering on projects that have a direct impact on the cybersecurity of our government agencies. As the cyber threat chief for InfraGard, I serve to provide content and services to the Maryland cybersecurity community that raises awareness and provides actionable information to secure organizational information systems.”
Successful cyber resilience, Death said, begins with communication. “First, I focus on understanding the various mission requirements, risks and challenges of our organization as we work to support our customers,” he said. “I actively engage with people across ASRC Federal. This open dialogue has really boosted cybersecurity understanding and vigilance throughout the enterprise. I also co-host an internal video series for employees that discusses cybersecurity issues and how they can help keep their customers, our company and their own home networks safe. It’s changed the dynamic at ASRC Federal — gone are the days when cybersecurity was just an ‘IT issue’ — our employees all recognize our shared and collective responsibility.”
You Might Also Like: Top 10 Execs To Watch In National Security

John DeSimone, Raytheon
John DeSimone is vice president of cybersecurity and special missions at Raytheon. His expertise in cybersecurity includes network support, transformation, operations, exploitation, IT and professional services. He previously held senior leadership positions at CSRA Inc., CSC, IBM and Northrop Grumman Corp.
Why Watch: DeSimone plays a key role in Raytheon’s nearly $1 billion DOMino contract with the Homeland Security Department that delivers cyber services to more than 100 civilian agencies.
“As prime contractor for the Network Security Deployment Division, Raytheon is working to safeguard the dot-gov domain,” DeSimone said. “Defending a nation against continuous and evolving cyber threats involves securing the hardware and software within its internet domain. Our team is advancing and we’re improving the overall architecture and systems and tools that are used by DHS to improve the cybersecurity posture of the government.”
Recently, Raytheon launched a new cyber-as-a-service offering, which DeSimone said is a way to help organizations achieve faster and more relevant protection while driving down costs. Cloud-based subscription Raytheon Cyber Academy is an example of this new type of offering. DeSimone headed up Raytheon’s transformation of its cyber portfolio into nine distinct innovation areas: cyber analytics and intelligence services, cyber warfare, cyber-as-a-service, cybersecurity automation and orchestration management, cyber physical systems security, cyber resiliency, cyber systems integration, computer network operations mission support and mission services.
“Each of these areas highlight our innovations and the services we provide,” he said. “We don’t just offer products; we offer solutions. And we will continue to adjust our business operations, develop new offerings and adapt our delivery model to support ever changing nature of cybersecurity.”
One of the biggest misconceptions around cybersecurity is a belief that machine learning and artificial intelligence will solve cyber talent shortages, he said.
“While investments in these technologies are critical to maintaining a competitive advantage against our adversaries in the cyber domain, it will not address the critical human element needed to address certain tasks,” DeSimone said.
He is also a member of the Raytheon group shaping the workforce pipeline.
“At Raytheon, we understand the challenge and the mission need for skilled cyber talent and are dedicated to finding new ways to educate and support students and educators on this issue,” he said. “We have partnered with organizations like Girl Scouts of the USA, Boys and Girls Club of America and the National Collegiate Cyber Defense Competition to further promote and develop the next generation of cyber defenders.”
You Might Also Like: Top 10 Execs To Watch In National Security

Gus Hunt, Accenture Federal Services
Gus Hunt is in his third year as managing director and cyber strategy lead at Accenture Federal Services. A former chief technology officer for the CIA from January 2009 to October 2013, Hunt graduated from Vanderbilt University in 1979 and has worked in both the public and private sector spaces. He began his career as an aerospace engineer for Rockwell International and General Research Corp., where he designed advanced manned space flight systems and satellite orbital transfer vehicles. Today, he serves as an adviser for several cybersecurity and big data startups. He is a member of the board of directors for leading technology solutions integrator ePlus.
Why Watch: Hunt drives the strategic cyber vision for Accenture’s federal business leveraging new approaches, models and technologies, including integrating new capabilities from acquisitions like that of Defense Point Security into Accenture’s already robust portfolio. Hunt was also instrumental in Accenture’s recently launched Cyber Fusion Center, which was designed to demonstrate the latest capabilities and showcase prototypes and solutions.
Hunt is the driving force behind the recent “Cyber Moonshot” white paper that maps out 11 strategies for leveraging new methodologies and technologies for advancing an organization’s cyber resilience.
“One of the key points driving our Cyber Moonshot thinking is how best to harness power of proactive cyber defense,” Hunt said. “We believe very strongly that you should constantly pressure-test everything — probe your networks, scan your software, and look for vulnerabilities, indicators of compromise, malware.”
Hunt said he also believes assuming breaches will happen is a critical mindset for approaching information and cybersecurity.
“We need to think about designing systems to make sure the data itself is very, very hardened and minimizes the opportunity for the adversary to take advantage, whether it’s an insider threat or an outsider coming in the door,” he said.
Hunt also advocates more education on the use of social media and the internet in general. “As social media has created ‘a tsunami of data,’ businesses and government alike are looking to leverage the ‘open door information’ available to them,” Hunt said. Hunt himself said he is careful about sharing information on social media, deliberately avoiding setting up some personal social media accounts.
“Teaching people to be discriminating consumers and posters of information and content while helping them understand how their information gets used is a really, really important thing that we’ve got to do for our society as a whole,” he said.
“As policies and legislation around technology change, AFS continues to build solutions that enable clients to change, adapt and grow,” he said.
“I’ve never been willing to accept the status quo,” Hunt said. “I’m a firm believer that we have within our power, as individuals, as companies, as governments and as a nation, to make things and to always change things for the better.”
You Might Also Like: Top 10 Execs To Watch In National Security

Tommy Gardner, HP Federal
Tommy Gardner is chief technology officer at HP Federal. His position serves federal agencies, higher education, K-12 education, state and local governments, and federal systems integrators.
A 27-year Navy veteran, Gardner previously commanded the USS San Juan (SSN 751) before going on to become the deputy for science and technology to the chief of naval research. He oversaw the Navy’s Deep Submergence Program and Advanced Technology Program. He has previously served as CTO for Jacobs Engineering, Scitor and ManTech International.
An ASME Fellow and professional engineer, Gardner chairs the ASME Industrial Advisory Board and is an adjunct faculty of the Blockchain Research Institute. He holds degrees from the United States Naval Academy, Harvard University and MIT as well as a doctorate in energy economics from George Washington University.
Why Watch: Gardner is keeping a watch on all three business segments at HP Federal: personal systems, printing and 3D printing and the cybersecurity ramifications of each.
“When most people think of cyber, they think computers, and really, any endpoint on a network, whether it’s a printer, or a 3D printer or a tablet — they’re all vulnerable for attack vectors from an adversary in cyber,” he said.
HP Federal’s approach combines security for both software and hardware as well as the human factor and insider threats.
“(Many people) don’t think of addressing security for the printer in the same way that they would for the computer or the mobile device,” Gardner said. “If you look at all the 3D manufacturers, how many of them provide cyber protections for things like file integrity or the operations of the machine? I don’t know anybody other than HP Federal looking into this.”
Gardner is in a unique position to engage with federal clients on the firmware resiliency guidelines the National Institute of Standards and Technology published with support from HP Federal. The company’s line of protective technologies isolate web activity away from a device’s main operating system as a way to defend against attacks.
“(HP Federal has) a Sure Click capability in today’s computer — it’s on my computer today — that if I click a link in an email or of I go to a website, it brings it up in a virtual machine so that any malfeasance being done within coding of the site is going to be maintained within that virtual machine,” Gardner said.
You Might Also Like: Top 10 Execs To Watch In National Security

Deborah Golden, Deloitte & Touche LLP
Deborah Golden is a Deloitte risk and financial advisory principal in Cyber Risk Services at Deloitte & Touche LLP, where she has worked for more than 22 years. Her specializations include both the commercial sector (life sciences, health care and financial services industries) and the public sector (federal health, civilian, and defense, security and justice industries).
Golden’s predominant focus these days is leading cyber risk services for Deloitte’s Government and Public Services clients, as well as being the co-leader for Deloitte’s GPS wellbeing initiative — among many other roles and responsibilities serving clients and the practice in the marketplace.
Why Watch: A self-described “techie,” Golden enjoys bridging the gap between business and technology.
“I could code with the best if I wanted to dust off that skill, but it’s my ability to bring technology and innovation with business and the ability to execute on a problem — while at the same time considering risk and its impact on multiple stakeholders that makes it exciting for me,” she said.
In an age in which there are more cybersecurity considerations than ever, organizations can expect to get hacked even when they exercise leading practices, Golden said. One of the keys to cybersecurity is having a plan for recovery when breaches happen so that an organization may minimize the impact of the breach and showcase resiliency when faced with such a crisis situation, she said.
“There are many factors that play into detection and recovery — sometimes that information is reliant on operations, processes, technology and people — or all of the above, but candidly, it’s understanding the most business critical, mission critical, important factors that need to be up and running post a breach so that your organization can sustain and ultimately maintain operations,” she said. “I think some people define ‘up time’ as it has to be 100 percent operational post a breach. However, that’s certainly not a likely scenario or if it is — it could take a lengthy time to get there as opposed to phasing activities (based on risk and criticality) back into operation.”
One of Golden’s strengths, she said, is helping clients understand their business imperatives in conjunction with their supporting technology platforms in a risk-based approach to help monitor and manage those functions or operations “in much more digestible chunks.” Related to that work are efforts around leveraging artificial intelligence and pattern-based behavioral analytics to help narrow down when incidents are likely to happen so that organizations are already poised for detection and subsequent recovery efforts.
“Where I’ve been most helpful is when we’ve been able to help our clients make sense of the myriad of potential attacks on their environment — taking a strategic, long-term view while achieving short-term successes — to strategize a means to create an approach towards prioritizing and ultimately mitigating their risk of exposure to internal or external threats,” she said.
With the proliferation of cyber threats, Golden sees both risk and opportunity from open-source data as the cyber landscape continues to expand outside of an organization’s own walls.
“One of the things where we’ve been able to evolve in terms or our thinking around cyber is to leverage approaches like behavioral predictive analytics,” she said. “In order to support those activities, our threat analysis leverage many different vantage points – including open source data and intelligent tools to provide valuable historical and reputational data which helps our team establish much larger fact patterns used in their analysis efforts.”
Golden and others are Deloitte are heavily engaged in public policy and keeping a view on the horizon to upcoming policy changes, she said. That goes, too, for startups and venture capital businesses that may have an impact on the innovation landscape, including potential impact on their clients and customers.
Golden is also heavily involved in STEM education outreach and promotion through her role at Deloitte and finds a personal and professional passion in the advancement of women in the fields of technology and cybersecurity. Those efforts include campus recruitment, input on course curricula, and sponsoring women in business through various university programs.
You Might Also Like: Top 10 Execs To Watch In National Security

Daniel Smith, ManTech International Corp.
Daniel Smith is vice president of the Federal Security Solutions Division at ManTech International Corp. Prior to ManTech, Smith was an executive with Knowledge Consulting Group, which was acquired in 2015.
Why Watch: Smith has worked in public sector IT for most of his 17-year career and moved to the D.C. area shortly after 9/11 to be closer to what was happening in homeland security.
“My arrival happened to coincide closely with the startup of the Department of Homeland Security, where I spent the better part of my early IT career,” he said.
He has focused specifically on cybersecurity for the last five years. ManTech’s Federal Security Solutions division was formerly Cybersecurity Solutions but changed its name to reflect ManTech’s broadening of solutions to include data analytics as well as cloud and IT operations.
“By diversifying with these other capabilities we’re putting ourselves in the best position possible to help our customers,” he said.
There is sometimes a tendency to view the idea of “cybersecurity” through the narrow lens of a specific field, he added, when in reality, successful cybersecurity is far more comprehensive.
“Cybersecurity isn’t just about installing security tools on your computers,” he said. “It’s not just making sure firewalls are configured properly. It’s not just about making sure you’ve got appropriate policies and practices in place. It’s really a soup-to-nuts approach to having an organizational focus that ensures your data is protected, available when people need to use it, and maintained at a level of integrity that people know they can trust.”
Smith plays a key role in ManTech’s projects aimed at supporting clients whether they are deliberately strengthening their cybersecurity posture or simply forging ahead with other projects that have cybersecurity as a core element. In many cases, ManTech is helping customers do things for the first time.
“We are not afraid to go after some of our customers’ most difficult challenges in the cyberspace,” Smith said. “We’ve done a lot of work on CDM, the Department of Homeland Security’s Continuous Diagnostics and Mitigation program, where we won one of the first contracts awarded in that space. We were also one of the first companies that started doing phase two for CDM, and today we are the only company that is building a shared services platform for this vital program.”
You Might Also Like: Top 10 Execs To Watch In National Security

Greg Touhill, Cyxtera Federal Group
Greg Touhill is president of Cyxtera Federal Group. A retired Air Force brigadier general, Touhill has served in several combatant commands including U.S. Transportation, Central and Strategic commands and led the creation of the Air Force’s cyberspace operations training programs. A past deputy assistant secretary for cybersecurity and communications at the Department of Homeland Security, Touhill was the first federal chief information security officer in the nation when he was named to the role in the Executive Office of the President in September 2016.
In addition to his role at Cyxtera, Touhill serves on several boards, including those of Cybersponse, Bay Dynamics, ISACA and the advisory boards of Symantec Federal and CSFI. The author of “Cybersecurity for Executives: A Practical Guide,” Touhill teaches cyber risk management at Carnegie Mellon University.
Why Watch: With more than 30 years’ experience serving the federal government in various roles, Touhill has an insider’s view of the mission and resources necessary to support it. His approach to cybersecurity is tempered with intentional caution against relying solely on technology.
“Cybersecurity is really a combination of people, process and technology, and, as a practitioner who focuses on cybersecurity, when I’m developing solutions, I’m looking to address all three of those components,” he said. “I want to make sure that I have the right technology aligned with a properly trained workforce and processes that are effective, efficient and secure.” When he joined Cyxtera in summer 2017, he touted its capabilities as among “the most innovative and effective in the marketplace.”
“The principle of a zero-trust security model as executed by a software-defined perimeter has proven itself to be extremely effective in protecting high-value assets in the private sector,” he said. “Ironically, it’s the technology that was started by the Defense Information Systems Agency and the Defense Advanced Research Projects Agency, yet it’s the commercial sector that adopted it first. I think it’s something that we’re bringing to the the federal market, and it needs to be adopted as soon as possible to buy down our risk to appropriately levels.”
Touhill advocates for federal leaders to continue to adapt and to account for the fact that data is mobile, cloud-based, on premise and in data centers.
“Continuing with the network or perimeter based approach I think is ineffective and a waste or our time and money,” he said. “We really need to shift to a zero-trust security model that recognizes that our information is everywhere.”
According to Government Accountability Office estimates, billions of dollars could be saved if the government were to close most of its 10,000-plus data centers. Commercial sector partners, including Cyxtera, are poised to step in and provide capabilities such as Cyxtera’s unique extensible data center or “data center-on-demand”, he said.
“That provides a platform that presents a much lower cost and greater security for the government and gives CIOs and operational communities the breathing space to look at whether or not they want to retool an application for hosting in the cloud, or posture into the cloud at a time and schedule that is more effective for them,” he said.
You Might Also Like: Top 10 Execs To Watch In National Security

Chris Townsend, Symantec
Chris Townsend has been vice president of federal at Symantec for two years, after the acquisition of BlueCoat. He has been in federal IT since 2003.
Why Watch: When Townsend joined Symantec, he began an approach that flipped the company’s sales focus into a customer service approach. He asked his team to meet with existing clients to educate them on better using and consolidating their current suite of tools, and to work toward building an integrated security platform to more effectively address their mission needs.
“We believe that’s how we’re maximizing our value and bringing real innovation to our federal customers,” Townsend said. “As a result of this approach over the last 18 to 24 months, we grew the Symantec federal business over 30 percent land are on pace to double the business by 2020.” Townsend sees three fast-growing segments of cyber. The first and most prominent continues to be the cloud.
“The move to cloud is forcing organizations to rethink security in a big way, and that’s really driving the shift in a lot of our customers in terms of how they’re investing, how they’re changing their security policies, and their view on security,” he said.
The second is threat analytics and leveraging data to identify and block threats while leveraging artificial intelligence and machine learning. Symantec maintains one of the largest threat databases in the world and is on “the leading edge in terms of how we incorporate that information into our platform,” he said.
The third area is web isolation.
“If we can move your web browsing out to the edge of the network, essentially do all your web browsing in the cloud and not bring that malicious content back across the network, it can eliminate a significant threat vector and really help us to start addressing the phishing problem, which has been an issue for a long time,” Townsend said. All three areas come into play in the recent trend of moving away from a reactive tools-based approach to security and shifting toward an operational approach. “Ultimately, the goal is to really drive automation across the security environment and improve operational visibility, while reducing complexity and operating costs,” he said.
You Might Also Like: Top 10 Execs To Watch In National Security

Dave Wallen, KeyW
Dave Wallen is senior vice president for KeyW’s Advanced Cyber Operations sector. He has previously worked at ManTech International, BAE Systems, Quality Systems Inc. and Price Waterhouse. From 1984 to 1990, he served as an officer in the Marines.
Why Watch: Having worked at the Pentagon and with the Joint Chiefs of Staff as well as holding leadership positions at multiple top government contractors, Wallen’s knowledge base is solid. “The defense industry is a prime target of our adversaries, and requires a heightened level of security,” he said.
“Having exposure to and expertise in what is possible helps to inform the chief security officers in industry and provide an enhanced perspective on the techniques and technology that we must guard against.”
Following National Security Agency Director Paul Nakasone’s remarks on the “weaponization of social media,” Wallen agrees it is “simply another platform to spread misinformation, sow confusion or anger people into a specific response.”
“It has been shown to influence global politics, create or intensify civil war or intimidate and squelch human rights,” he said. “Our government has the opportunity to take the lead to monitor and respond to social media attacks.”
Doing so, he said, requires a close partnership between major social networks and the intelligence community in which collaboration “allows us to identify and disable social media accounts used by trolls, fake accounts and ‘bot’ accounts.” One way to do this is to develop tools based on machine learning and artificial intelligence that use the cloud to help identify these threats in real time, he said.
Wallen has faith in KeyW’s ability to bring its multidisciplinary cyber approach to federal customers.
“One example includes data scientists who develop statistical models and algorithms used in machine learning and artificial intelligence,” he said. “Another example involves working with KeyW’s robust Intelligence, Surveillance and Reconnaissance products integrated with full spectrum cyber tool suites to accelerate cyber capabilities to defend and operate in this rapidly evolving battlespace. This process produces new technologies and products used by our customers, including government and commercial entities, to better protect our networks, help identify and counter cyber threats and do so in real time.”
This year, much of Wallen’s focus has been on aligning KeyW’s teams to better produce integrated solutions, tools and technologies.
“This means attracting, hiring and retaining top-level cyber experts with the experience to bring together resources and people into teams capable of addressing our nation’s most critical cyber challenges,” he said, “and doing so in a way that is financially and socially responsible.”
Wallen sees opportunity over the next year or so for KeyW to help shape the landscape in next-generation solutions for cyber operations.
“This includes applying machine learning and data analytics to the volume of data and speed of decision-making, particularly as the internet of things expands,” he said. “This will enable United States government and intelligence community partners to transition from reactionary postures to a proactive stance with respect to cybersecurity, cyber defense and information assurance.”
You Might Also Like: Top 10 Execs To Watch In National Security

Andy Zembower, General Dynamics Mission Systems
Andy Zembower is vice president of encryption products for General Dynamics Mission Systems, where he has worked in various capacities since 1994. Over the course of his 39-year career, he has, among other accomplishments, led hardware, software and engineering development efforts and product development teams. He currently directs GD’s encryption product business within the cyber and electronic warfare systems line of business.
Why Watch: As cybersecurity continues pressing to the forefront of enterprise IT concerns, Zembower brings both experience and passion to the table.
“This is not just a job for me,” he said. “My tenure at General Dynamics has afforded me the opportunity to get to know our wide base of customers and learn exactly what we can offer to our customers and how we contribute to protecting their most valuable data. My relationships go beyond the daily operational execution — they extend to listening, understanding and anticipating what my customers need.”
Zembower said GD is extending its reach beyond legacy customers into the broader military, intelligence and federal civilian markets, as well as possibly delving more into the commercial sector.
“I want to understand the problems that keep them awake at night,” he said. “I’m their advocate — I will fight for the products and capabilities they need. I will build what they need. I will find what they need. I also see the goodness in this ecosystem we are building — customers, partners, suppliers, employees and academia. Together, we will successfully secure cyber.”
Zembower believes successful cybersecurity can be achieved when people and technology converge. He aims to drive that convergence.
On the technology side, Zembower sees the importance of bringing capabilities to customers before an urgent need arises. That’s especially important as clients’ top secret and sensitive compartmented information becomes increasingly mobile.
“This past year, we introduced our TACLANE-FLEX product that provides a modern, highly secure and flexible encryption platform for delivering new software capabilities to help customers respond to emerging cybersecurity threats,” he said. “We’re also bringing the smallest, lightest and lowest power High Assurance IP Encryptor device available today to market in the TACLANE-Nano. And in direct response to how encryptors are being remotely managed, we introduced GEM One to provide better visualization for increased efficiency when configuring connections and helping operators detect and respond to issues immediately.”
While continuing to work with long-time customers, Zembower is poised to play a role in fulfilling needs around the rise of emerging technologies, including mobile devices and small satellites. “We plan to continue to challenge the status quo so that we can build the right products faster to help our customers thrive in this fast-becoming ubiquitous environment,” he said.
“This focus and direct customer feedback informs and prioritizes our technology investments, a number of which are already under evaluation to include wireless, layer 2, high-speed, secure mobile, encryption technologies and products to secure military platforms.”
You Might Also Like: Top 10 Execs To Watch In National Security




