How federal cybersecurity teams can adapt to a post-DOGE environment COMMENTARY | The long-lasting impact of DOGE has been to accelerate a broader shift toward more disciplined, efficient and operationally resilient security strategies. The actions of DOGE may have faded from the news cycle, but for government chief information security officers the cuts that were made last year still feel fresh. Most are facing rising cyber threats with leaner teams and smaller budgets, including increased risks tied to the Iran conflict. There is a silver lining, however. Many security teams are using this moment to modernize and operate more efficiently. They’re not necessarily trying to do more with less. Instead, they’re prioritizing, automating and simplifying. What’s more, CISOs are concerned but not panicking. A new Forrester Consulting report found only 38% of public sector cybersecurity decision-makers are confident in their agency’s cybersecurity posture in the wake of headcount reductions. But those same decision-makers are proactively — and successfully — adapting their risk management approach to accommodate the current reality. Here are the operational shifts they’re adopting to meet the demands of a post-DOGE world. A renewed focus on high-priority vulnerabilities and critical infrastructure Agencies simply do not have the resources to try to protect everything equally. According to OPM workforce data published in March, the federal government had experienced a net workforce reduction of more than 278,000 employees since January 2025. As a result, security teams are under pressure to move faster while managing increasingly complex environments with fewer people. That reality is forcing CISOs to become far more disciplined about how risk is prioritized and managed. Instead of spreading limited resources across every possible vulnerability or compliance requirement, agencies are increasingly concentrating on the systems, networks and data sets most critical to mission continuity and public services. According to