In our previous posts, we introduced the foundations of cATO and explored the pivotal role of Continuous Monitoring (ConMon) in keeping federal systems secure and compliant. Now, we’re focusing on another crucial element of cATO: Active Cyber Defense (ACD). ACD is a proactive strategy designed to help agencies like the Department of Defense (DoD) and the Army combat increasingly sophisticated cyber threats.
If you’re in the federal or defense world, you know the importance of an Authorization to Operate (ATO). It’s essentially a green light for systems to run, confirming they meet required security standards. However, the traditional ATO process is slow and rigid. You might secure approval today, but your system could face new vulnerabilities six months later. This is where cATO comes in.
cATO ensures systems maintain continuous compliance, allowing for faster deployment of technologies without sacrificing security. Unlike traditional ATOs, cATO emphasizes real-time risk assessments, continuous monitoring, and adaptive security measures, aligning with agile development practices.
ACD is a critical requirement for achieving and maintaining cATO for the DoD and its components. To qualify, organizations must demonstrate three key competencies:
Think of ACD as moving from a “set it and forget it” strategy to one that is proactive, adaptive, and predictive. It’s not just about deploying tools—it’s about staying vigilant, hunting for threats, and even countering adversaries when necessary.
ACD aligns with cATO’s focus on continuous compliance. By adopting strategies outlined in NIST SP 800-53 and leveraging methodologies like the MITRE ATT&CK Framework, agencies can build robust defenses tailored to their mission requirements and threat landscapes.
ACD relies on actionable intelligence to predict, identify, and counteract threats. To effectively implement the ACD pillar of cATO, several key components must be put in place.
Let’s break it down:
1. Threat Intelligence and Analysis
2. Automated Threat Response: When a threat is detected, speed is key. This involves having robust mechanisms for detecting and mitigating threats as they emerge rather than relying on periodic scans or updates. The DoD memo on cATO emphasizes that “systems must be able to show a real, or near real-time ability to deploy appropriate countermeasures to thwart cyber adversaries” 1,2.
3. Hunt Teams and Incident Response: Automation doesn’t replace the need for skilled personnel. Hunt teams are the boots on the ground, proactively looking for signs of malicious activity and taking action to stop it. They analyze threat data, assess risks, and respond to incidents, guided by the latest intelligence. Agencies can quickly contain and recover from breaches with a well-defined incident response plan.
4. Deception Technology: Deception technology is a fascinating piece of the ACD puzzle. It creates decoys or traps within the network, drawing attackers away from real assets. By luring attackers into a controlled environment, agencies can gather intelligence on their tactics and buy themselves extra time to respond.
5. Continuous Monitoring and Real-Time Analytics: ACD must be integrated with the Continuous Monitoring (ConMon) pillar of cATO. This integration ensures that security data collected from various environments (development, test, and production) is used to inform and power active incident response. The flow of information between these systems is crucial for making real-time risk decisions and responding to threats efficiently.

A recent SIGNAL media article by Evan Lynch highlights the U.S. Army’s implementation of the cATO framework, marking a significant shift in how the Army monitors and addresses cybersecurity risks. This initiative aligns closely with the principles of ACD we’ve been discussing and offers valuable insights for organizations implementing ACD and working towards cATO.
Key aspects of the Army’s cATO framework include:
The Army is leading by example with its adoption of cATO. Two of the key systems under this initiative include:
Leonel Garciga, the Army CIO, states this development marks a major shift in how Army officials monitor and address threats. He explained, “It’s really about understanding the risk of the software you’re delivering as opposed to our more compliance-based culture that we have today… We’re really focused on the threat-based understanding of what the environment looks like and making decisions on software we’re building based on the risks that we’re creating with that software.” 4
To earn and maintain cATO, organizations need to demonstrate they can handle threats as they emerge—not just during a biannual review.
We’re excited about the potential of Active Cyber Defense in cATO. ACD is an essential capability for achieving and maintaining cATO. It’s the linchpin of a security strategy that’s as dynamic as the threats it faces. The DoD is actively putting these principles into action, demonstrating that the concepts of ACD and cATO are not just theoretical but are actively being implemented at the highest levels of defense.
We see it as a game-changer for our clients to effectively integrate cutting-edge threat intelligence, advanced virtualization technologies, automated orchestration tools, and cloud-based security solutions within DevSecOps platforms. All of these come together to create a robust, dynamic defense system that’s always on, always learning, and always one step ahead of the bad guys.
If you’re interested in learning more about Continuous Authorization to Operate (cATO) and how to implement it effectively for your organization, contact BreakPoint Labs. Our team of experts can guide you through the process and help you develop a robust cybersecurity strategy tailored to your specific needs.
References
1 GovCIO Media & Research. (2022, February 4). DOD Releases New Continuous ATO Initiative for ‘Active’ Cybersecurity. https://govciomedia.com/dod-releases-new-continuous-ato-initiative-for-active-cybersecurity/
2 U.S. Department of Defense. (2022, February 3). Continuous Authorization To Operate (cATO). https://media.defense.gov/2022/Feb/03/2002932852/-1/-1/0/CONTINUOUS-AUTHORIZATION-TO-OPERATE.PDF
3 FedTech Magazine. (2022, September 9). ATO to cATO Cybersecurity Transition in The Federal Government. https://fedtechmagazine.com/article/2022/09/understanding-transition-authorization-operate-continuous-ato-perfcon
4. Lynch, E. (2024, May 28). U.S. Army Officials Launch New Way to Constantly Monitor Risks. SIGNAL Media. https://www.afcea.org/signal-media/cyber-edge/us-army-officials-launch-new-way-constantly-monitor-risks