The Centers for Medicare and Medicaid Services is moving beyond mere compliance to risk-based cybersecurity, with a focus on continuous monitoring and attack surface management. CMS Chief Information Security Officer Keith Busby said that transition is aimed at linking compliance with “threat-informed, risk-based defense.” But Busby said CMS is now leaning into a “protect first, visibility second” mindset. “We need to be very intentional in the use cases for AI,” Busby said. As the technologies and approaches behind cybersecurity quickly evolve, CMS earlier this year announced plans to hire roughly 100 people into its Office of Information Technology.