Integrating physical and digital services makes government more efficient, secure, and trusted. In this article, learn key takeaways from a panel discussion with Matthew Percival, Security Engineering Officer with the U.S. Department of State's Bureau of Diplomatic Security, Office of Technology, Innovation and Engineering; Craig Veith, Solutions Expert at GDIT; and Melissa Frye, VP of Programs at GDIT.

The Mission Doesn't Wait for the Briefing

Picture this: surveillance teams at a U.S. embassy are reporting unusual activity around the perimeter. At the same time, cybersecurity systems inside the building are registering a spike in targeted intrusions against the mission's networks.

Two different teams, each doing their jobs well, but neither have full visibility into what the other is seeing. By the time both threads reach a decisionmaker with the authority to act, the adversary may already have moved to the next phase.

This is not a hypothetical scenario. These are the conditions that the U.S. Department of State's Diplomatic Security Service operates under every day, in 190 countries worldwide. And it reflects a structural vulnerability that adversaries have long understood and exploited: when defenders think in silos, they fight at a disadvantage.

"Our adversaries don't think in silos. They have a unified response. They are very well tuned and they don't care what the defense looks like." — Craig Veith, GDIT

Faster Threats, Slower Defenses

Threat activity has accelerated, and the overlap between physical and digital attack vectors is no longer an edge case — it is routine. A surveillance operation and a phishing campaign targeting the same facility in the same week are not a coincidence. They are a coordinated tactic.

At the same time, the volume of available threat data has grown enormously. Intelligence streams, physical sensor systems, open-source data and cybersecurity telemetry are all generating signals that could paint a coherent operational picture — but only if they can be brought into a shared environment. Today, in most organizations, those signals still arrive through separate pipes, reach separate teams, and surface to leadership on separate timelines. The technology to change this now exists. The harder questions are organizational: who owns the unified risk picture, and how does it reach the right decision-makers in time to matter?

Four Insights from the Field

1. Unified risk requires shared architecture — not just shared meetings.

The instinct when confronting siloed risk is often organizational: more coordination, more cross-functional briefings. These steps have value, but they do not solve the core problem. Data about physical and digital threats still lives in separate systems on separate timelines. You cannot coordinate your way to a unified risk picture if the underlying data remains fragmented.

At the Diplomatic Security Service, the work began with a classified data lake — built to ingest, normalize, and correlate risk data from all 190 countries of operational exposure and integrate it with intelligence streams arriving in Washington. The goal was not to replace expert analyst judgment. It was to give analysts something they had never had: a single environment where physical security data, cyber threat intelligence, and other risk streams could be seen together and acted on from a common picture.

Building this required a Commercial Solutions for Classified (CSfC) architecture and collaboration across government and industry partners — with security-first design embedded from the start, not treated as a constraint to manage later.

That foundation is now enabling the next evolution: from "what happened across our global footprint?" to "what patterns are emerging and what does leadership need right now to get ahead of it?"

"How do we make this generative? How do we make this predictive? How do we bring all these teams doing great work together and deliver the risk information they need to make decisions?" — Matthew Percival, Department of State

2. The adversary's advantage is organizational, not just technological.

State-sponsored actors and espionage networks plan across physical and digital domains in concert. They do not run separate directorates that brief separately and compete for resources. They have a mission, and they deploy every capability toward it in coordination. As long as defenders organize the opposite way, the structure of the defense itself creates exploitable seams. An attacker who can trigger a physical security response while simultaneously conducting a cyber intrusion wins not by superior capability, but by superior coordination. Closing that gap requires organizational decisions — about who owns the integrated risk picture, how analysts across functions access each other's data and how threat information flows to decision-makers without being filtered through the silo that generated it.

3. Honest assessment must come before new investment.

A common failure mode in modernization: a new capability lands on top of an environment that has never been rationalized. The result is not integration — it is additional complexity. In one program, a frank audit of the existing software landscape turned up 73 separate contracts for tools performing overlapping security functions. Together, they produced an environment that was simultaneously over-resourced and under-integrated.

The work of integration begins with that kind of honesty. Before laying new architecture on top of an existing environment, the question must be: what do we actually have, what is it doing and where are the real gaps versus the redundancies? The most durable partnerships in this space have been ones where the integrator's first obligation was to understand the legacy environment — its investments, its constraints, its embedded expertise — before proposing what to change.

4. The hardest variable is human — and leadership determines the outcome.

Every practitioner who has worked through a major security integration effort will say the same thing: the technology is the easier part. The data architectures, the AI models — these are hard but tractable. The human factors are harder and more consequential.

People who have built genuine expertise over years or decades do not shed their professional identity because a new system arrives. They need to understand why the change matters, have a meaningful role in shaping it and feel that leadership will stay the course when the process gets difficult. The leaders who navigate this most effectively don't treat it as a change management problem to solve. They treat it as a collaboration to sustain.

"Innovation often is the opposite of tranquility. A lot of people like tranquility — and when you're trying to change that landscape, you have to work through that." Craig Veith

What Integration Actually Delivers

The goal of this work is not a more sophisticated security program. It is better decisions, made by the right people, at the speed the mission demands.

In practice, that means a leadership team receiving a real-time, correlated view of threats across every country of operation — not a compiled overnight report, but a living picture. It means an analyst working a developing situation overseas who can see physical indicators, cyber activity, and intelligence context in one environment, without waiting for information to move through separate channels. And it means building a posture that, over time, spends less of its capacity reacting to events that have already happened and more anticipating them before they mature.

Getting this right doesn't require a revolution. It requires discipline, leadership and the willingness to build toward a unified defense — one decision at a time.