Priorities for the CBP Office of Information & Technology Part 1
27m 21s
The discussion highlights CBP’s technology priorities amid a transformative year, led by CIO Sunny Bagualia and CTO Sonil Madagiri. Bagualia outlines three pillars: strategic transformation, tactical operational excellence, and innovation at mission speed. Strategic transformation involves adopting generative AI, quantum, edge computing, and OT-IT integration, with a focus on delivering real-time answers to agents and officers while maintaining security. Tactical excellence ensures systems operate at high reliability, reducing firefighting and enabling focus on innovation. CBP has deployed Chat CBP, a secure AI tool for all employees, and is exploring AI code assist for efficiency gains. Madagiri details an architectural approach divided into efficiency, application development, and operational technology, with security woven throughout. The Technical Reference Model governs all technology, minimizing tool sprawl. Edge computing is emphasized, as most data is generated there, supported by SATCOM and mobile wireless for remote operations. Data sharing and zero trust are priorities, with CBP handling massive data volumes and facing 2.2 billion cyberattacks monthly. The team stresses collaboration with industry, supply chain security, and preparing for future needs like biometrics and AI energy consumption, ensuring technology meets mission demands securely and swiftly.
Welcome to HSDF the podcast, a collection of policy discussions on government technology and homeland security brought to you by the Homeland Security and Defense Forum. Our panel pulls back the curtain on a playbook that blends five Sigma reliability with bold bets on generative AI, edge computing, and zero trust, so agents get real answers in real time while security stays tight. This is a story about turning policy into operations, reducing toolsprall with a strong technical reference model, and building an architecture that meets the mission where it lives, at the edge, featuring Sunny Bagualia, Assistant Commissioner and Chief Information Officer CBP, Sonil Madagiri, Chief Technology Officer CBP, Dr. Barry West, former DHS Acting Deputy CIO moderator. This discussion took place December 12, 2025, at the 8th Annual Homeland Security and Defense Forum, Border Security Symposium. Good afternoon, everybody. Well, it was really great to have the secretary here this afternoon, and also to be able to take questions, which I think is very rare. She laid out, I thought, and did a good job with the administration's priorities, strategic plan, and also did the same for the department. I'm going to start with you first, Sunny, because I know each year we try to work as a CIO towards our goals and objectives in the strategic plan. Obviously that evolves because of technology, because of business needs, and we've had quite a bit of change in 2025. Maybe you can talk to what are some of your key technology priorities and the goals and the objectives it goes with those. Thank you, Barry. Well, first of all, I think as the secretary and everyone else knows, this has been one heck of a year, would everyone agree with that? We've really worked hard, and I'm exhausted, and I'm going to take leave starting next Monday after a thousand hours of leave. So I can only carry over 720. But anyhow, did I just say that this outside voice? I don't know, anyway. I think much better now. I just want to just say I've done this for now. This is my 41st year working. This is the most amazing terms of just sheer work that our entire workforce and contractors and vendors, everyone together, to a common mission and common goal. To answer your question, Dr. West, I think the key is that administration policy, they set the policy, which drives the mission stakeholders, which are agents and officers, then supported by technology, implemented through technology. That's really what's been going on. We have really three things that we do, strategic transformation, which is really setting up for newer technologies. Sunil, we'll talk about that. Some of the things as an engineer here and I have set up the technology direction as to go forward. I don't want to steal all this thunder otherwise, it really starts coming back and asking the questions. We think there's obviously that strategic transformation is very key. We're going to be investing in a lot of new things. You'll hear about generative AI, quantum, you'll be hearing about PTC, you'll be hearing about edge computing. You'll hear about certain things that we're doing with OT, IT integration and all of that stuff is going to be very, very key in terms of how we go forward. The second thing we use, tactical ops excellence, we're really focused on the fact that our stuff needs to be 5, 6 sigma operational so the lights stay on so that that is not the thing that we are distracted by. We're not just firefighting all the time. That is something that we've really improved on. We've set up measures, we've set up all these sort of things. Everyone is really focused on that. My entire organization, I was there at the Homeland Security Homeland Heroes thing yesterday. Dak May is one, the sort of executive of the year. I've got Nile Samhaw, one also for mission. That Tyson Walker, the deputy CTO one as well, Sheila Patel, one for OT, IT. This is something I was taking pictures like a fan, you know, just like, you know, and there. So they took a picture of the CIO, taking a picture of the team. They said, you look like a proud papa. I'm really proud of the team, you know. But I think what that means is that the technical ops excellence, we really worked and made that so successful that right now that is working so we can focus on strategic transformation. But the third one is innovation at the speed of mission. Everybody bringing out new technology so that the Sunil talk about running generative AI that we've done our first chat to all of the organization and all 67,000 people now are using a very, very, very safe and secure tool. So we're not just going after shiny objects. We're making sure that these models are very, very carefully thought through and cybersecurity is sort of woven into the process. Our new thing is zero trust, which is, you know, never trust always verified. And so we really kind of making a lot of effort into this area. The supply chain and data security is a key challenge for us. So I just put that out there and we're very interested in industry focusing on that and OTIT integration. So you'll see the whole world change where operational technology and information technology will merge at some point so that the planes, boats, drones, vehicles, wall, IoT, all these things that you will have sort of a thing where voice prompt through voice prompt and agent and officer out in the field will be able to integrate launch a prompt, get an answer, make things happen, search across, you know, with an edge device that will be more not going back to a tier four data center or we'll have the cloud and we're going to be the first agency going to the cloud into years fully all done at a large agency. But all that process out at the edge. So these are the sort of things that we are doing is really, really important. We're also looking at SATCOM so that we can now, we have the first agency to be 18 months ahead of schedule on AIS completely done. And now we're ready for the next generation of 6G and we just saw the thing that China is a little bit ahead of the United States in this area. Well, we can't let that happen. We got to get going. So leveraging those contracts and also getting SATCOM directly to across all the border elements. So we have tested that out by the way. There are two or three constellations. I think you know what they are. I know you all know that. We are looking at all three so that we can have not only the starling and now I think I've saw one of the equations so you can solve the other two. Someone got the joke here. Good. So those all available so an agent and officer never has to worry. We've got another device called mobile wireless where multicellular coverage. So my point is that infrastructure and our DAC maze and our doctor maize can really work anywhere anytime at the speed of mission. The software under DAC J can start delivering. We're also doing AI code assist where now AI is going to do some code generation and we're checking that. So nail started this effort. It's been very, very successful. We realized a couple of million dollars already avoidance and savings. So I can go on and on. I think I may have gone on my script a little bit but this was more fun. I just want to let you know I'm very excited. The reason I bring this passion is because I'm really proud of the team. I'm also proud of all of you how you've supported us but I think now we're ready to go to the next generation. There is a tremendous amount of funding coming in and we are all set to kind of you know with equity and process really start developing and deploying anything with the from the towers to bringing stuff in with OTI integration and to a mobile device and to more devices where even with hopefully some glasses by the way we haven't decided on that yet so we're going to we're still working on that issue but we're going to make sure that from voice video text translation all this stuff is made available to an agent and officer where AI is the assist and the human is in charge. So I think with that those are some of the things they're going in. So again applications infrastructure, cyber security, OTI integration better spend on the money. Clearly the White House I've talked to the DHSCIO I talked to him all the time. He's talked to the federal CIO. There's I've just talked to the GSA CFO just had another event right before this with Namesh Agarwal but I think the key thing is that there's going to be a lot of effort where savings across so that there's common solutions and those sort of things are deployed out and making more affordable and more automation I believe that's going to be the order of the day but other than that nothing much to do. That's a great opening, Sonny. Similarly taking that a step further and drilling down how are we really adopting a lot of these new technologies into the actual CV vision space. I know a lot of organizations get involved probably enterprise architecture, infrastructure, obviously business. How are we governing that and how's that coming along? Sure. Thank you Dr. West. My boss, just to make sure I've only one penny he has three. He's the boss. So make sure that that's what people understand that. I just had my review yesterday so I need to be in the best behavior. And he did well yesterday so it's still been great. So thank you AC. So first of all thank you for having us. I really appreciate it. These forums are very critical for us. Like AC said it's 24 by 7 for us as to what we do on a daily basis at CVP. I came from the tech industry myself. I tell you there is no other job like CVP job. I tell you that nothing not even close. I work with the tech industry for 30 years and this is the most fulfilling and I would say
an exciting job I've had in my career. It's very excited to be here, work for the AC here. And the thing which is, AC gave you like a whole kind of list of things and kind of vision of what he thinks where we are going and what we need to do. And so I'm one of his direct reports along with both the DAX and the CISO. And what we are trying to do is to figure out what's the best way. You see, I think is what generally happens, especially some of the agencies or some other companies, we try and boil the ocean. When trying to boil the ocean, kind of the concept of really what it means is things don't work the way it's supposed to. It doesn't work. But what is happening now is I think we are at a transformational age. Every conference that we talk to, we talk about transformation. But we truly are at the space right now within our lifetime. I wish about a little younger because there's a very exciting times, especially in technology space. And I came from Silicon Valley, so I worked there for a while. And some of the folks who work there, they are working on some stuff, which is going to transform what we are doing every day. We met a CEO of very large company six, eight months ago. And that gentleman, I asked, I told him, so what do you think where we are? We had the.com. And.com was a bubble and a bus people thought. But it gave us a whole new technologies to work on from 2000, on late '90s to 2000 onwards. Because all the foundation is built on that right now. So we are, he said, no, we're not transformation. This is industrial revolution, kind of changes we are going through right now. So the partners here were sitting here. I think you heard me speak before, right? It is, we have to change how we do business. We really, really do. Things are no longer like Secretary Noam said, right? It's no longer delivering stuff on a slow-based. Everything is due yesterday. It's really a fact. It's no longer, so we talked about code assist. I'll talk a little bit more about some of those things. So what we are doing is we dividing the whole architecture in like, I would say like two or three areas. Let's say three areas. One is the traditional, making thing very, very efficient for our, for our, for our, for all of our law enforcement and all the employees and the contractors who work for us. That's one area. Make it more efficient. How do you get your job done faster? So you'll be hearing a thing called chat, CBP. That's really helping. We are getting a lot of information out. It's a, it's kind of an interactive LLM-based chat. We do stuff in there and we support various type forms. Like, you know, text, audio, video and that and, and, and, full motion kind of video also. It supports that. So that's becoming, becoming, making people very, very efficient. That's one area we're working on. The second area I would say is, is the application developed in, DAGJ, absolutely amazing DAG, deputy CIOB have and his team. Some of the folks will talk, talk to you guys after us here. They are doing amazing job, taking these technologies, incorporating within these applications. Right? It's no longer building the application the old way anymore. So that's other area to adapt very quickly and we can go a little bit more in, in depth with that as to where, where that is going. The third area I have with AC mentioned, I think, massive, massive, massive work is going on in this area with the operation technology area, which is operational. That means you're looking at for us, how our whole border is operational for us, right? Not only that, you, you have global entry, right? You guys come in, you go to a device and something happened to device. It says green check mark and you go. That's an edge for you. That's an edge device you can say, right? That work also is going on, especially how to make it more efficient from that perspective. Those are three silos I would say we are concentrating on. Then on top layer, you can put some of the areas we talked about, AC mentioned security is everywhere. Horizontal and vertical security for every stack what we have. Our system we work very closely with, there's a critical part and if he says no, it ain't happening. So whatever architecture, whatever products or services you're bringing to us, please keep that in mind. It is critical. We are very flexible. We do have SaaS offerings when some certain areas you want to keep it closer to our network as you can imagine why, right? There's most sprawl we have, the more issues we have. So just keep that in mind. The second area I would say is from operational technology component is that 70% of all the data getting generated is the fact is getting generated on the edge. You will hear about NII, I'm sure this morning, actually Jori Harden talked about not into some inspection. All the technology that is being headed by XT Devakota and our team in doing a phenomenal job there. So all the technologies what we're working on, so my job is working on the architecture component. I tell you I have to give a lot of props to both the DAX. One DAX is not here. DAX may be, but DAXJ, he says, if it ain't approved by the CTO office, it ain't happening. We also own what is called the technical reference model. That means all technologies, software, hardware, from plain drones, you just name it across the board, which hits the network has to be approved in the TRM, which makes sense, right? You want everything to be secure. So that some of the areas we're looking at that, how exactly we make this work, we're not slowing anything down from that perspective. We have to make sure it's secure. We don't want any external components. We are leaked from somewhere else, which can create a problem. That includes data sharing also. We may be very secure with sharing with somebody else. If there is a bottle like a semi-shoot there, guess what? We are also compromised, right? So when we're looking in the holistic architecture, we have to make sure from across the board that we are looking at everything else. And data sharing is phenomenal. We're doing it as you know. You must have heard of UIP, which runs from the XT Devakota team. Those are all great examples at what's really working in a secure way. So we are very excited. Please talk to us. We'll talk about a business connection moving forward. Is it portal? And if you don't get back to you, my boss gets mad at me. But I'm just telling you that because we get thousands of requests, right? I'm trying my best to respond to folks. So, that's fine. If I could just add one thing. I think the key thing is data. We've, in a lot of the technology or architectures, we already had. So what industry, when Silicon Valley, does it come to us? They were kind of shocked that this is a government agency. It's already implemented some of the capabilities that we're looking at. What we're interested in is there's still an opportunity for data mesh, data sharing, which is a clear priority of the administration. So there's tremendous amount of data sharing and everything delivered to a mobile device, where, for example, once we do all the national security targeting information, that package is delivered to an agent and officer. And with geospatial coordinates, they can get down to a building, to a room, to an apartment, whatever. They define some one weekend through biographics and two levels, and maybe even three levels of biometrics, face, touchless fingerprints, and maybe others may come down the line with FIFA 26 coming up and LA28 coming up. All that ability to basically correlate and corroborate and make sure that is the right person. So we get the right person that needs to leave because they're a threat to the country. That sort of stuff is happening. I believe there'll be additional biometrics and additional need to link all that data together. So I feel like that's really key. Just to give you a mindset of where we are, we are a couple of Fortune 20 companies that I keep on saying this all the time, but I have some metrics to prove this. You know, we're talking about 40 to 50 billion data exchanges a day. You know, we've got 10 billion transactions a day. We've got 50 petabytes of information that we're dealing with on a continual basis. So we think in some of the areas, we need to do a little bit of better data classification tagging. The main key is we've done our inventory first now. That is very key to enabling of AI. Don't forget that we need to also generate some energy for AI because it's going to be a big consumer of that. So working with the energy department and others, how do we kind of make sure that computing is made available? And so I think some of those things are really, really, really, really key. We're also the number of attacks on us, 2.2 billion a month, are growing. So we're seeing quite a lot of threats. You saw the latest ontropic, the Chinese government, I guess. We're attributed to that and they tried. We have not, we've touched word, are still good, but every day is hand-to-hand combat pretty much. So I think just that vigilance where that whole data lifecycle, what are they really interested in? Getting those analytics and seeing how that's really happening. The supply chain, if they can't get to us and they can't so far, they're trying to get to supply chain where are the weaklings? And then make that happen. That's another weakness that I think we should all take a look at together. So I think those are kind of things that are part of also the strategy. Excellent. So I mean, he talked about zero trust here at the beginning. How is OIT addressing some of the other OMB, federal and departmental policies and priorities to really still achieve your goals? Yeah, that's a very good question because I think at some point, certain times, again, I've been a department CEO twice in previous roles. And when you look at it from that perspective, it's really sort of, I look at the five principles, policy, process, technology, people, hand governance, so it's easy to set up policy, but it's very hard to then implement real operations. So when I'm sitting on this side as a competency, obviously, we're really, I mean, we're talking like massive operations, like I said, a couple of fortune-twenties in one every day, transacting. I mean, you know, we're talking what 1.2 million travelers a day, we're talking millions of cargo elements.
today, we're talking about 5.5, whatever, 7 trillion latest numbers came out of imports exports. Collections are almost at one quarter of a trillion dollars so far on and on and on, right? So some of these systems are really massive. So I think the answer to the question is, we have looked at the policy and we're having a dialogue with the DHSCIO has been very good and to unrecord and just telling me and certain things, you know, like for example, on certain areas of credential access management, you know, understand the policy, give us a little time because I've got two or three iterations of things that are security embedded in application logic. There are certain systems, there are two or three systems embedded. Some of these are national security systems, border security systems or what I call economic security systems. You can't just take an A system and then suddenly, you know, because there's a lot of custom code also in there. My goal obviously is to get to, you know, 80 to 85% cuts and 10% configuration that are in a many 5% custom, but that's not the case. I would say that it's at least 25% custom. And so how do we look at that whole code base? The AI code assist was a really interesting thing where the policy was, so the policy also, the administration is setting some things up from the federal CIO. So I think the policy seemed to be generally speaking as follows. One is automate more. So get more automation so that and then that's one thing. I think and get the government folks to do more with what they have and be more involved with actual maybe implementation as opposed to just oversight. Also expecting more from the contractors, better deals. So licensing and all that and products. I've got the TRM that I asked Sunil to create. I'm a chief architect and chief engineer from before. So obviously he and I can we can talk in technical terms with the team and we have a very technical team. I think that's one of the secret sources of OIT success is that everyone is first to all very driven. You know, Sunil give a big salary to come over here, you know, for one low price, right? 80 hour weeks, you know, you're enjoying government so far. He's loving it. Here you go. It's not about the money. It's all about it. So so by bottom line is all my team. We love the mission and when we see things successful, that really energizes us. So but for example, so that whole thing with the code assist is another policy that they're implementing. More AI. Now there's a lot of concern. There's some people saying may take away jobs, you know, but we are trying to train on workforce that AI is the assist. The human is in charge. But what that means is you also have to change processes. Yeah. You got to change the processes. You know, IIT only automates that inefficient process faster. So you got it. So I think that's another key that we're seeing. I think the other policy that seemed to be coming out is CVP's been left alone. I've said this before when doge came in and they were reporting to Mr. Musk regularly and a couple of those gentlemen were billionaires themselves. We came to the meeting, but they're techies. These are folks who form Tesla and SpaceX and they said they've never seen a team this good and they thought we're as good as SpaceX and Tesla employees and took that as a compliment. But we met them at 10 o'clock at night. We met them at 11 o'clock at night. We met them at 1 o'clock at night. We got the thing done by 4 o'clock and we were still there. And I told my team, you got to stay the course right now and fight the good fight to show that we're right there with them and can hang with them blow by blow. And it worked. And you know, we've not had any issues here so far. But I think that's because all of our folks with relational database experts, you know, the contractors as well, everyone working together. I think the other policy is security first with a very, very focused on on real world, not just dashboards where FISMA scorecards are all green and suddenly are compromised over here. So what are the metric that they're they're asking. So we had good conversation with Antoine. Now the thing that I'm also telling the DHSC is to look at from my standpoint, I'm in the battlefield every day and there's a lot of complexity in this environment. And I got to tell him, hey, I need some relief over here. You know, you just can give me a score which makes me look bad in front of somebody. You know, that for example, you know, when I was an engineering student, you know, I mean, if you got a 35% in my double E class in electrical engineering, that was a C in the class, right? And nowadays, I said, you can make it 95 and 95 is a passing grade. So let's just, you know, make sure there's a context for these questions. So I think those are the things that are, I think, are really important. I think he's listening and he's a really good CIO. So I think those are the kind of things that are going to be very, very important for our success. I think the biggest thing that's happening is information sharing. We've been told there should be nobody blocking us from sharing information to protecting the safeguard this country. So protect the American people, safeguard our borders and hence the nation's economic prosperity. No one should come in the way. In fact, sometimes they ask for names and we just say, no, no, no, we got it. And we're working there. So I think to me, there is a certain, I'll just say zest and a certain focus that really is energizing the team. So, you know, those 250 agile teams is not growing even more. And now they want, you know, maybe sort of 100 story points, 1000 story points, and maybe 10,000. So we can do that. And we can do that through some automation, but we got to do it smart. So I think a little bit of planning and this is where we're asking them to consider the fact that even with vendors and industry, we need a little bit of management governance as well in addition to hands-on keyboards. But I think that seems to be some of the things that are going on and I think we're making a lot of progress in there and obviously buying good American technology is a key aspect as well. And I think you'll see a lot more in this area where savings and reduction on the TRM model because we've got 10,000 products. We can't have that many. I think you'll see some of that coming in. A lot of efficiencies and effect. I think efficiencies and effectiveness is the order of the day. And a certain urgency to national security. I mean, I'll just say that yesterday, for example, one of the agents from ICE was awarded for, you know, he prevented sexual exploitation of children. And so who amongst us is not touched by that. You know, when we see that, that immediately connected, right? But some of that, some of the information that are sharing with our people from other state national security to even other things and found that person who was also a criminal potential security threat to United States, but also potentially a pedophile. Well, that's great. You found that and they're out of here. So to me, that kind of thing is, and I'm not saying just all external, I'm saying there's some also here also. But to me, that's the kind of thing that is really resonating amongst our team and we're working really well. Thank you for tuning in to HSDF the podcast. Follow HSDF the podcast and never miss the latest insider talk on government technology, innovation and security. Visit the HSDF YouTube channel to view hours of insightful policy discussion. For more information about the Homeland Security and Defense Forum, HSDF, visit hstf.org. (upbeat music)
Podcast Summary
Key Points:
CBP is prioritizing strategic transformation with investments in generative AI, quantum computing, edge computing, and OT-IT integration, alongside tactical operational excellence focused on reliability.
The agency has deployed a secure internal AI chatbot (Chat CBP) to all 67,000 employees, emphasizing cybersecurity and human oversight.
CBP is advancing zero trust architecture, supply chain security, and data sharing, handling 40-50 billion data exchanges and 10 billion transactions daily.
A Technical Reference Model (TRM) governs all technology approvals, reducing tool sprawl and ensuring security across hardware and software.
Edge computing is critical, as 70% of data is generated at the edge, with devices like Global Entry kiosks and SATCOM connectivity for remote operations.
CBP is using AI code assist to generate code, achieving cost savings, and partnering with industry to address data mesh, biometrics, and energy needs for AI.
Summary:
The discussion highlights CBP’s technology priorities amid a transformative year, led by CIO Sunny Bagualia and CTO Sonil Madagiri. Bagualia outlines three pillars: strategic transformation, tactical operational excellence, and innovation at mission speed. Strategic transformation involves adopting generative AI, quantum, edge computing, and OT-IT integration, with a focus on delivering real-time answers to agents and officers while maintaining security.
Tactical excellence ensures systems operate at high reliability, reducing firefighting and enabling focus on innovation. CBP has deployed Chat CBP, a secure AI tool for all employees, and is exploring AI code assist for efficiency gains. Madagiri details an architectural approach divided into efficiency, application development, and operational technology, with security woven throughout.
The Technical Reference Model governs all technology, minimizing tool sprawl. Edge computing is emphasized, as most data is generated there, supported by SATCOM and mobile wireless for remote operations. 2 billion cyberattacks monthly.
The team stresses collaboration with industry, supply chain security, and preparing for future needs like biometrics and AI energy consumption, ensuring technology meets mission demands securely and swiftly.
FAQs
CBP's priorities include strategic transformation with generative AI, edge computing, and quantum tech, tactical ops excellence for 5-6 sigma reliability, and innovation at mission speed. They also focus on zero trust, OT/IT integration, and secure data sharing.
CBP launched a safe and secure generative AI chat tool called 'Chat CBP' for all 67,000 employees, supporting text, audio, and video. It's designed to make employees more efficient while ensuring cybersecurity is woven into the process.
The TRM is CBP's architecture governance framework that requires all technologies, from software to drones, to be approved before hitting the network. It ensures security and reduces tool sprawl by preventing unvetted external components.
CBP focuses on edge computing since 70% of data is generated at the edge, like Global Entry devices. They're merging operational technology and IT so agents can use voice prompts and edge devices for real-time responses without relying on data centers.
CBP faces 2.2 billion attacks monthly, with threats targeting data and supply chains. They emphasize zero trust, vigilant data lifecycle management, and secure data sharing to prevent compromises through external partners.
CBP uses secure data sharing systems like UIP, ensuring that if a partner is compromised, CBP isn't. They focus on holistic architecture, data classification, and tagging to enable safe AI and analytics use.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.