Federal Market Frontlines
TechnoMile’s Federal Market Frontlines with Tom Temin features in‑depth interviews with public sector and industry leaders on AI, acquisition reform, regulatory change, and challenges shaping mission‑driven organizations.
Federal Market Frontlines
We Need to Talk About Defense Startups' Security
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
How can defense startups meet rigorous security compliance without slowing innovation?
In this episode of Federal Market Frontlines, host Tom Temin speaks with Isaiah Ike Rivers, Chief Security Officer at Astranis Space Technologies, about building security into a fast-moving organization from day one.
They discuss how security leaders can move beyond traditional compliance, use data and artificial intelligence to identify risks earlier, and position security as a mission enabler and business enabler. Ike also shares lessons from his four decades of experience supporting the Department of Defense, the intelligence community, and the defense industrial base.
Topics covered include:
• Cybersecurity compliance for defense startups
• Integrating security without creating barriers
• Traditional defense programs versus commercial space
• Data-driven risk management and continuous readiness
• The role of AI in cybersecurity
• Developing the next generation of security leaders
• Helping executives understand the business value of security
Subscribe for more conversations with the leaders shaping federal contracting and corporate security.
Follow Federal Market Frontlines and TechnoMile: https://technomile.com | LinkedIn YouTube Facebook
Have a guest suggestion or topic idea? Please email: marketing@technomile.com.
To an astonishing degree, the government is buying in volume from startup companies. That's good news for innovation and moving at mission speed. But how do you ensure defense-grade security compliance when you are a startup?
SPEAKER_01The key is really changing the mindset from security being a compliance requirement to security really being a mission enablement. Our role is not to really slow innovation down. It really is simply to help the organization one understand the risks, two, make informed decisions, and three, move faster with confidence. I always feel that the best security programs don't create those barriers. They create the foundation that allows innovation to happen securely.
SPEAKER_00Each month we explore timely issues affecting the ever-changing federal market for technology and services. Our topic today is security and startups. To an astonishing degree, the government is buying in volume from startup companies. That's good news for innovation and moving at mission speed, but how do you ensure defense-grade security compliance when you are a startup? To help answer that crucial question, we turn to a security director of a startup. He served for 20 years in the Air Force and another 20 years supporting DoD and intelligence community industrial security programs. Now he leads security for Astranus Space Technologies. Please welcome Isaiah Rivers. Ike, it's good to have you with us.
SPEAKER_01Oh man, thank you, Tom. It's glad to be here. You know, every day you wake up is a good day, so thanks for having us.
SPEAKER_00All right. And let's start with you, a little bit of your background, and it looks like you have some relevant experience in this whole security area. Tell us about yourself briefly.
SPEAKER_01I guess let me just go straight to my Air Force days. Um spent 20 years uh in the Air Force, retired back in 2025, and was looking to do something different and joined a contract company, great company called Sighttour Corporation. Um, spent uh about 12 years uh at that particular company, and then I had an opportunity to become a chief security officer at a phenomenal company called Institute for Defense and Analysis, better known as IDA. And then I started hanging out with a lot of different leaders in the industry, and I stumbled on a great leader, uh his name is Scott Jacobs from Astrana Space Technologies Corp. And we just started talking about the company and the things that they do. First, I was like, okay, that's not my not my forte. Um, but as we got to talking a lot more, it became very intriguing to me. And um took a visit out to San Francisco, that's where our headquarters is at. And then I got to see a company, a great company like Astranas, where they build and make the satellites from the very beginning, from the motherboard to the payloads to all the panels of the satellites right in the warehouse. And then I said to myself, I wanted to be part of this. And then um it just all came together. Uh, there was a chief security officer position available, and they asked if I wanted, and I raised my hand and said, hey, bring their board, and and I've been there ever since uh October of 2025 and loving every minute of it.
SPEAKER_00All right, and of course, the space domain is a fast growing one, a fast expanding one, and also a contested one increasingly, and I think the military and civilian sides of government are well aware of that. The security compliance frameworks that DOD and to a large extent civilian agencies operate under are kind of dated, uh a little bit rigid from time to time. And so, how do you ensure that you are secure and secure compliant in the startup phase when things are moving so quickly?
SPEAKER_01So that's a great question, Tom. The key is really changing the mindset from security being a compliance requirement to security really being a mission enabler. At Astranas, which I love, security is integrated into the business from day one, right? Because when you do not integrate security from day one, um, you're going to have some issues later on. Our role, as far as from a security perspective, our role is not to really slow innovation down. Um, it really is simply is to help the organization, one, understand the risks, two, make informed decisions, and three, move faster with confidence. I always feel that the best security programs don't create those barriers, they create the foundation that allows innovation to happen securely.
SPEAKER_00And what lessons from traditional defense programs in which you participated a while ago simply don't translate to the commercial space environment as it's moving so fast today?
SPEAKER_01So it this was this is really, really kind of cool because I've only been on the traditional uh defense program side of the house, right? I had no idea how commercial operated whatsoever, right? And when I got there, it's really a cultural thing as well. But just understand from a traditional side, defense programs often rely on lengthy timelines, extensive bureaucracy. I mean, just think about it, you know, there's a proposal that is out there. You got all of these companies bidding on this proposal, right? You gotta submit RFPs and all those different things, and it takes forever just to actually win the contracts. Well, in the commercial space sector, speed, agility, rapid decision making are really essential, requiring a security and compliance process that support innovation rather than slow slow it down. So I find this fascinating because it's like at the intersection. So I really find it fascinating because once you're in the commercial sector, you have to be chop, chop, chop. So that's the difference that doesn't translate to commercial space is really just that time, that timelines.
SPEAKER_00Sure, yeah, things move fast. And we should point out you are a spokesperson for the National Industry Security Program Policy Advisory Committee, the NISPAC. And in that role, uh you interact with security leaders throughout the industrial base. And uh so the issue of meaningful data visibility in mature secure organizations comes up there and programs have room to grow. Talk about that whole role and what you're learning there.
SPEAKER_01So in the commercial space, um plus my CEO, he's a data guy, right? So it's really data-driven, right? But I find that a mature security organization really will use the data to make decisions, not just to complete reports, because sometimes most folks want metrics just for reports. But the visibility really means means understanding like your risk, identifying those trends, and knowing where resources are needed to be focused, right? And so that data can help that out on in a big way. But the future of security is moving from that inspection ready um to continuous ready. Um, but the question is no longer are we ready for the inspection? Um, the question is really, are we ready for the mission, right? And that data will actually help you uh be prepared for that mission and succeed with that mission.
SPEAKER_00So, really, that continuous, I think, versus episodic or let's say some cynically call the theatrical readiness is really crucial, it sounds like. Yep. All right, and uh of course we have now the introduction of artificial intelligence into almost every domain for both government and industry. And how is that changing this whole security thinking, the whole national security community and how it thinks about operations and risk? What do you see there?
SPEAKER_01I really love this question because I think everybody, every listener's probably listening today at this episode has a friend named Chad, C-H-A-T, right? So Chad is kind of my good friend and everybody else's good friend from an AI perspective because um AI is really transforming security um by helping leaders analyze information faster, identifying risk earlier, and making better decisions. But we must remember though, we must remember, just because we're using this does not mean that our adversaries are not using it. Because remember, our adversaries are using the same technologies, and some of them are probably using some better technologies. So the opportunity is significant, but um there are still some risk. But let's not forget the future um is not AI replacing security professionals because that's what I hear a lot of times that AI is replacing us, right? It's not replacing security professionals. Actually, AI is empowering them to move faster, um smarter, and more effective. And when you can do that, you're gonna get some more time back in your day to actually go back out and look for more risk. So AI is definitely the wave of the future for security. And if you're not using it, shame on you, you better get to it.
SPEAKER_00Right. So the adversaries, as you point out, are using artificial intelligence against our companies and our programs here in the United States, but yet AI can also be used by us to enhance security, and so hopefully you can cancel out what the bad guys are doing.
SPEAKER_01Yes, I I I I would say that.
SPEAKER_00Good. And so what's your advice for the next generation of security leaders that are coming up?
SPEAKER_01You know, when I saw this question, uh I found it fascinating because I come from the old school era, in the old school eras that you know we had to learn the hard way. Um, but in today's because we're so techie and you can get things by just typing in a word and you can you can learn so much. But what I would say is never stop learning, never stop building relationships in the security world, right? Relationships are a must, right? Because if you do not have that networking and you're sitting by yourself, okay, you're going to be pigeonholed and you're not going to be able to expand your knowledge, or you're not going to be able to help uh assist your company to grow from a compliance perspective and from a risk management perspective. I think security leaders must understand technology, we must understand business, and we must understand the mission. The next generation cannot just be compliance experts. See, back in the days, we were just compliant experts. They cannot just be compliance experts. They must be a strategic advisor who can influence decisions and enable organizations to succeed. That is what the C-suite is looking for. Those individuals who can influence those decisions.
SPEAKER_00Now, you could say IT costs as a relative part of the pie of costs is lower now relatively than it was 30 years ago because of cloud and software as a service and so forth. Nobody's buying an IT hardware infrastructure anymore. Security, you have to be on top of. So, what's your way of making sure that security is seen as that business enabler for the startup and not simply a cost?
SPEAKER_01So, for me, it's very, very important to understand the business side of the house. It goes back to what we were talking about before, where uh security was in old days compliance experts, right? Security leaders have to speak the language of the business. Executives need to really understand that security protects the mission, the workforce, the customer, and the future of the organizations. I personally think the best leaders don't just identify the risk, right? Because we can identify, but a CEO is going to want to know, okay, well, you identified it. What is your solution? So we actually have to be a better business person to bring that solution and help the business move forward in a confident way.
SPEAKER_00And as we've discussed, you wear a lot of hats these days and have worn a lot of hats. There's one more, and you have recently joined Technomile's Security Information Management Advisory Board. What are people talking about in that context and what are you bringing to that?
SPEAKER_01This, I'm not gonna say this fell in my lap, but this was really intriguing. So ever since I uh got out of the military and um I joined the became an industry individual, I used to utilize the Sims product. So I've been utilizing the Sims product for over 20 years, and I have become extremely close to Sims and the leadership of Sims, uh, Mr. Mike Strutman. And then when they merged with Technomiles, I met um the phenomenal uh CEO for Technomile, and we just started to talk about that merger and what it could do for industry. And because I am still in the game, I have practitioners that work for me, and I used to be a practitioner. So I know exactly what the practitioners need. The practitioners need a voice in how security solutions are developed. The practitioners think that the best technologies come from understanding real-world challenges, and uh security leaders need tools that improve that visibility, reduce the complexity, and help them make better decisions faster. And so now that I have this avenue, I talked to both of them about that role and what I could bring to the table. And they said, hey, yes, I agree we would love to have your board. And so now I get to be that voice that industry really does not have. And so that's what really drew me to um joining the Techno Mile Advisory Board. Not so much for myself, but to give back to the community who does not have that voice.
SPEAKER_00And you've been working for 40 plus years. Sounds like you're just getting started.
SPEAKER_01I actually am, and you know, I'm actually having a good time, Tom, right? You know, um, it is nothing like waking up every day and saying, one, you know, I was blessed to see another day, but two, to do something that you like to do and that's meaningful. One is giving back to the community, right? The Dib is such a great, phenomenal place to work. The industrial security base is just phenomenal, right? And protecting the warfighter and knowing that you're protecting the warfighter and knowing that the things that you're doing on a day-to-day basis are helping protect that warfighter is really a self-accomplishment to anybody, right? And so um just what I just really wanted to just say to folks is just that keep doing what you're doing. Um, doesn't matter if you're a practitioner or you're a chief security officer, everything that we do makes a difference.
SPEAKER_00And that's a good note to end on. Ike Rivers is the Chief Security Officer at Astranas Space Technologies and industry spokesperson for the National Industrial Security Program Policy Advisory Committee. Great to have you with us.
SPEAKER_01Thank you, Tom. It's been a pleasure.
SPEAKER_00And that's it for this edition of Federal Market Frontlines, brought to you by Technomile. I'm Tom Temmon.