Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.

Aug 07 2026
Security

Zero-Trust Strategies Help CMS, VA Improve Visibility and Control

Strong access control paves the way for managing threats and protecting patient data.

To say that the Centers for Medicare & Medicaid Services handles a lot of data would be an understatement. This agency within the Department of Health and Human Services administers Medicare, Medicaid, the Children’s Health Insurance Program and the Health Insurance Marketplace. It is responsible for ensuring the health coverage of more than 160 million people — that’s nearly 1 in 2 Americans.

With so much protected health information (PHI) and personally identifiable information (PII) to manage and secure, CMS has been at the leading edge of zero-trust deployment for several years. 

“We process over a billion Medicare claims a year,” says Wade Zarriello, acting director of the Infrastructure and User Services Group at CMS. “So, access to our data needs to be secure. Maintaining public trust that we have secure data is important. Zero trust is really the system that gets us there.”

Click the banner below to read CDW's new 2026 Cybersecurity Research Report.

 

CMS’s approach to zero trust is structured around maintaining security at four layers: device, network, application and data. One of the most far-reaching zero-trust initiatives being deployed by CMS is an enterprise identity, credential and access management program that will consolidate disparate identity systems in use across the agency into a central repository.

“Being able to federate ICAM services is a big benefit of zero trust,” says Tim Morrow, situational awareness technical manager in the CERT Division of the Software Engineering Institute at Carnegie Mellon University.

“Cloud providers typically have mechanisms where you can tie in Amazon Web Services’ or Google’s version of identity and access management. You also have identity access tied into specific applications. It’s a real challenge to integrate these all together and have a consistent picture, because it gets to be very large and convoluted. But an organization’s focus on identity capabilities and services is an important step in its zero-trust journey.”

Zero Trust on Multiple Fronts

In addition to a range of identity-focused initiatives, CMS is also implementing several other zero-trust solutions, including endpoint detection and response (EDR) and network security improvements.

“We are now centralizing data logging in our security incident and event management tools,” Zarriello says. “This gives us consistent threat analysis across all ecosystems. It’s no longer a disparate, siloed approach where different organizations have different data volume tools and are each doing their own threat analysis. We’ve effectively centralized that threat analysis from a volume perspective.” 

“One thing that is often overlooked with zero trust is that it can bring a significant reduction in the volume of unexpected log and network activity that needs to be triaged and investigated,” says Jason Garbis, co-chair of the Zero Trust Working Group for the Cloud Security Alliance. “When access shifts to a ‘default deny, explicit allow’ model, this substantially reduces the amount of access that needs to be evaluated. As a result, the operations team benefits by having more time available to perform those investigations that are truly necessary.”

READ MORE: Why does agentic AI make zero trust more important than ever?

CMS’s zero-trust efforts have not been without challenges. One particularly sticky problem was how to manage network access for the numerous internal and partner developers working on projects for CMS. Zero trust does not allow the kind of wide-open network access that developers traditionally were given. A zero-trust approach means developers get access only to specific applications or specific segments. CMS turned to Zscaler to solve the problem.

“Developers can no longer spin up an environment in the cloud, assign an IP address and just have access to whatever else is within that subnet,” says Zarriello. “There have to be specific actions in order to add access or add permissions to that asset under our zero-trust networking model. This has resulted in more operational oversight and more team members required to effectuate access for developers.”

data point

 

Zero Trust Increases Visibility Into Legacy Systems

The Department of Veterans Affairs is another federal agency tasked with managing and securing vast amounts of data, including the PHI and PII of more than 9 million veterans receiving healthcare and other services through the agency.

In its efforts to meet the zero-trust goals set out in the Office of Management and Budget’s Memorandum M-22-09, the VA has implemented a number of initiatives to strengthen identity verification, improve endpoint security, modernize network infrastructure and expand monitoring to better detect and respond to emerging threats.

In addition, the department has also conducted targeted architectural reviews and implemented measures to improve system isolation and reduce attack surfaces.

“Zero trust enhances cybersecurity at the Department of Veterans Affairs by shifting from implicit trust to continuous, risk-based verification,” says VA Deputy CISO Jeffrey Spaeth. “In an environment where threats such as phishing, credential compromise and supply chain exposure are common, this approach reduces the advantage of initial access by limiting an attacker’s ability to move within the enterprise.”

EXPLORE: AI-enhanced zero trust secures hybrid networks for the future of work.

Implementing zero trust requires moving from a perimeter-based approach to security to one focused on identity verification, least-privilege access and continuous monitoring. This presents challenges to agencies such as the VA that are managing legacy systems at enterprise scale.

“Many older systems do not provide modern, identity-focused security and cannot easily support advanced authentication or continuous monitoring,” Spaeth says. “As a result, we must apply zero-trust principles around these systems, which requires clear visibility into assets, data and dependencies. Building that level of visibility requires substantial effort.”

He adds, “In large environments, teams often maintain incomplete or outdated asset inventories, requiring significant work to identify and prioritize systems before applying meaningful zero-trust policies.” 

At the VA, Microsoft Purview underpins the data pillar of zero trust by classifying and labeling sensitive information, enforcing data loss prevention policies and monitoring insider risk to ensure that access and sharing are continuously governed.

Wade Zarriello quote

 

Zero Trust and CTEM Work Together To Protect Healthcare Data

An important element of the zero-trust framework is that it embodies an ongoing, flexible approach to the threat environment. Threats change, and defensive measures need to change with them.

At both CMS and the VA, zero-trust practices are being implemented in alignment with a continuous threat exposure management framework, which is designed to continuously identify, validate and prioritize risks to the enterprise. With zero trust working in conjunction with CTEM, IT staff can tackle the same security problem from two angles.

“Zero trust is how you design and enforce, while CTEM is how you continuously discover and reduce risk,” Zarriello says. “CTEM validates if zero trust is actually working, and zero trust provides the enforcement layer for CTEM. They share continuous monitoring responsibilities, whether that’s telemetry or asset and identity monitoring. Both involve continuous validation and verification. They both shift security from static to dynamic states, where you never trust and always verify.”

CTEM’s capabilities, including continuous evaluation and reporting on threats, are well aligned with zero trust’s emphasis on dynamic access policies,” Garbis says. “Specifically, a zero-trust system views CTEM as a source of near-real-time signals about the security posture of systems and the IT environment. These signals are used by zero-trust policy enforcement points to make decisions and changes to what access is permitted for given identities and given resources.”

“Together, zero trust and CTEM move the VA away from static, compliance-driven security toward a threat-informed approach that continuously adapts and focuses on the highest risks,” Spaeth says. “This ensures that security actions align with protecting the systems and services veterans rely on each day.”

SDI Productions/Getty Images