Skip to content

Security Compliance Checklists vs. Commander's Intent

  • Season 1
  • Episode 18
  • Guest Ian Kelly, Senior Director of Solutions Engineering, Cloudflare Public Sector
September 14, 2026

The government is great at security governance — but that isn't the same as being secure. In Episode 18 of The GIST of Govt IT, Brian and Sean sit down with Ian Kelly of Cloudflare, a self-described liberal arts major turned 15-year Google veteran turned public-sector technologist, to talk about closing the gap between the checkbox and the outcome. The conversation digs into why the exploit window has collapsed from weeks to roughly five minutes, the pivot from point-in-time compliance to continuous, risk-based security, and AI governance before the horse leaves the barn. Sean and Ian also get into edge compute, the CBP conversational video bot built for the FIFA games, infrastructure as code for repeatable accreditation, and the emerging discipline of AEO — optimizing content so agents, not just humans, can use it. Plus, Cloudflare's FedRAMP High authorization and IL4 intentions, a wall of lava lamps as a cryptographic entropy source, and three Monday-morning takeaways, not to mention KatEye makes an appearance.

Resources Mentioned in This Episode

Featured Guest

Ian Kelly, Senior Director of Solutions Engineering, Cloudflare Public Sector

Cloudflare Public Sector

Cloudflare FedRAMP High authorization announcement

Cloudflare Capabilities Discussed

Cloudflare Edge Compute

Cloudflare AI Gateway (visibility, governance, cost control)

Cloudflare SASE / Zero Trust

Cloudflare's LavaRand entropy wall (true randomness)

Compliance, Standards & Frameworks

FIPS 140-3 validated cryptography

FIPS 203 and NIST post-quantum cryptography

Also Mentioned

KATSEYE

Military Grade Metal Podcast

Related Content

GIST360 Webinar: Rethinking Command and Control Resiliency at the Edge

The Hosts & Show

Swish

GIST 360