Episode

Misunderstood ATOs Are Costing Agencies Time and Money | CyberCast

Podcast
GovCIO Media & Research Podcasts
Published
Jun 25, 2026
Duration seconds
497
Processing state
not_requested
Canonical source
https://govciomedia.com/podcasts/
Audio
https://traffic.libsyn.com/secure/governmentcio-media-govcast/CyberCast_Dave_Raley_Audiomp3.mp3?dest-id=785468
JSON
/v1/public/podcasts/govcio-media-research-podcasts-236090/episodes/misunderstood-atos-are-costing-agencies-time-and-money-cybercast
Markdown
/podcast/govcio-media-research-podcasts-236090/misunderstood-atos-are-costing-agencies-time-and-money-cybercast.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/govcio-media-research-podcasts-236090/episodes/misunderstood-atos-are-costing-agencies-time-and-money-cybercast/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/govcio-media-research-podcasts-236090/misunderstood-atos-are-costing-agencies-time-and-money-cybercast.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Misunderstandings about the Authority to Operate (ATO) process are slowing federal technology modernization efforts and driving up costs, according to David Raley, chief digital business officer for Operation StormBreaker in the Marine Corps. Speaking at GovCIO Media & Research's Federal IT Efficiency Summit, Raley argued that many delays stem from a fundamental misconception about what receives an authorization. Rather than granting ATOs to individual software applications, agencies authorize integrated systems operating within specific environments, taking into account mission context, infrastructure, users and data. Raley said this misunderstanding often leads to unnecessary delays for both government teams and industry partners. To accelerate software delivery, Raley highlighted the Marine Corps' Operation StormBreaker initiative, which leverages modern DevSecOps practices and continuous integration and continuous deployment (CI/CD) pipelines. By building applications on preauthorized platforms, teams can inherit the majority of required security controls, reducing compliance burdens and enabling faster, more efficient delivery of mission capabilities.