Coffee & Conversation with Cheri Benedict

August 18, 2026 9:00 AM to 9:45 AM

Registration Fees

On Tuesday, August 18, INSA hosted a virtual Coffee & Conversation with Cheri Benedict, Senior Cyber Supply Chain Advisor, Office of the Federal CIO, Executive Office of the President.

Recording courtesy of session sponsor, ManTech

Moderated by INSA President Suzanne Wilson Heckenberg, the discussion focused on the cyber supply chain risk management (C-SCRM) landscape and efforts to strengthen visibility, integrate cybersecurity and acquisition practices, address emerging AI risks, and improve government-industry collaboration.

Drawing on her experience across cybersecurity, IT management, and acquisition, Ms. Benedict emphasized that one of the biggest challenges is gaining visibility into the full vendor ecosystem. Organizations often lack insight beyond their first-tier vendors, making it difficult to identify vulnerabilities deeper in the supply chain. At the same time, adversaries are increasingly exploiting vendors and suppliers rather than targeting an organization through its traditional “front door.”

Benedict stressed the importance of getting “left of boom” by addressing supply chain risk during the acquisition process, before products or services enter federal environments. Doing so requires closer coordination among IT, cybersecurity, and acquisition teams and, where possible, supply chain reviews before contract awards for high-priority assets.

She also discussed the foundation the federal government has built through the SECURE Technology Act, which established the Federal Acquisition Security Council (FASC) and required agencies to maintain supply chain risk management programs. Ms. Benedict emphasized the importance of shared risk, information sharing, and continued coordination across government as agencies strengthen their cyber supply chain risk management practices.

The conversation also addressed Software Bills of Materials (SBOMs) and the need for greater visibility into second- and third-tier suppliers. Ms. Benedict noted that agencies are still determining how best to operationalize SBOM data, but the goal remains better understanding what technologies organizations have, what vendors are providing, and where risks may exist.

Looking ahead, Ms. Benedict identified AI and autonomous AI agents as an expanding source of supply chain risk. She emphasized knowing where AI is being used, maintaining strong cyber hygiene, and applying “ruthless prioritization” to critical assets so organizations can quickly act on new threat information.

Ms. Benedict closed by emphasizing that supply chain security is a shared risk. As threats evolve, stronger partnerships, information sharing, and coordination across government and industry will be critical to securing national security systems.

Speakers

All Speakers

Moderator

Sponsors

  • Host