Navy’s Aaron Weis on Use of Automated Red-Teaming in Addressing Cyber Vulnerabilities

Aaron Weis, chief information of the Department of the Navy and a 2022 Wash100 Award winner, said conducting regular automated red-teaming is far more effective than adopting a “checklist” approach when it comes to detecting and addressing cyber vulnerabilities, Defense One reported Tuesday.

It's a very compliance-driven mentality, like an audit… and it's wrong,” Weis told the publication of the checklist approach. “Cybersecurity is not a compliance problem.”

The Navy conducted an experiment using a tool called Nova from software startup Rebellion to perform automated red-teaming on networks and found that the process revealed which cyber vulnerabilities allow threat actors to gain wider access to networks and those that were the easiest to exploit.

“It can identify the system, understand its patch level, catalog its vulnerabilities according to what’s generally available, and then try to run an automated exploit against it, based on what it knows,” Weis said of the tool.

Share the Post:

Related Posts

Booz Allen, SAIC, Leidos Lead Wash100 Pack

It’s a tremendous achievement to receive a prestigious and highly competitive Wash100 Award as it recognizes leadership, superior performance and impact in federal contracting. So it’s no small feat for...

Wash100 Award Popular Vote Week 9: Booz Allen Trio Holds Strong as Gray, Mengucci & Ramirez Climb Ranks

The Wash100 Popular Vote contest has entered its ninth week with familiar names dominating the leaderboard—but not without a few notable shake-ups. Andrea Inserra, Horacio Rozanski, and Steve Escaravage, all...

Wash100 Award Popular Vote Week 8: Booz Allen Retains Lead as Industry Leaders Dominate Top 10

The Wash100 Popular Vote contest enters Week 8 with Andrea Inserra of Booz Allen maintaining her stronghold at the top. With 1,123 votes, Inserra continues to set the pace, while...