Making Cybersecurity an Executive Focus
CIOREVIEW >> Cyber Security >> NEWS

Fairfax County Government

Michael Dent, CISO

Making Cybersecurity an Executive Focus

Michael Dent, CISO
Michael Dent, CISO, Fairfax County Government

My career has always been rooted in public service. I began in the military, where I learned discipline, accountability and how to lead under pressure— principles that have guided me ever since. As I moved into IT and ultimately cybersecurity, I was drawn to the intersection of mission-critical operations and protection. It wasn’t just about securing systems; it was about enabling continuity of service and preserving public trust.

When I joined Fairfax County nearly 25 years ago, cybersecurity in local government was often treated as a technical afterthought. I saw an opportunity to shift that perception by building not just a program, but a culture of leadership accountability around cyber risk. I’ve always believed cybersecurity is not an IT issue—it’s an executive issue. That belief has driven everything I’ve done since.

Securing funding starts with reframing the conversation. Instead of discussing firewalls and patching, I focused on continuity of government, public safety and risk exposure. Cybersecurity had to be positioned as a business enabler and a fundamental part of service delivery, not a cost center or a compliance task.

I also made it a priority to show value through real-world outcomes—whether that was a successful incident response, maintaining uninterrupted services, or preventing potential breaches. Over time, the leadership saw results, and trust grew. Eventually, the Board of Supervisors issued a public proclamation in support of cybersecurity. That moment symbolized a cultural shift: leadership owned the risk and backed the program.

Collaborating on Regional Cybersecurity

We build trust through transparency, empathy and shared language. I never assume technical leaders will automatically understand cyber risk, nor do I expect non-technical leaders to appreciate the nuances of an evolving threat landscape. I frame conversations in their terms—business disruption, reputational harm, legal liability and continuity of essential services.

I also make sure to provide options. Instead of saying “no,” I say, “Here are three secure ways to achieve what you want to do.” That shift has been powerful. It repositions cybersecurity as a partner in innovation, not a barrier. That’s when the relationship changes and trust is built.

 ​I’ve always believed cybersecurity is not an IT issue—it’s an executive issue 

Collaboration has been a cornerstone of our program. As Chair of the MWCOG NCR CISO Committee and a member of numerous regional and national boards, I’ve worked to create alignment across jurisdictions. We share threat intelligence, policy frameworks and joint initiatives like identity federation and shared forensics. Those relationships aren’t just professional—they’ve become personal. Many of my closest colleagues are also my strongest allies.

We also hold our agency leaders accountable internally. Cyber risk decisions are elevated to the County Executive, not filtered or softened through layers. That clarity of structure helps ensure leaders are informed and empowered to act. And when everyone understands their role in protecting the enterprise, accountability becomes part of the culture.

Fostering Cyber Awareness

We treat cybersecurity as integral to every business process. That means we embed security reviews in our Architecture Review Board, conduct proactive risk-based audits, and enforce vendor compliance through contractual cybersecurity requirements.

We’ve also built robust forensic capabilities and led one of the longest-running regional awareness events in the country— our annual Security Awareness Day is now in its 18th year. While we take a layered approach to defense, we also focus heavily on culture, education and governance. It’s not just about technology—it’s about creating a sustainable ecosystem that prioritizes security from the inside out.

We’ve aligned our risk management practices with the NIST Cybersecurity Framework since its inception. As the framework has evolved—especially with recent guidance around governance, supply chain security and resilience—we’ve adapted our approach accordingly. Our Zero Trust deployments, vendor risk reviews and disaster recovery alignment efforts are all mapped to national standards.

We also emphasize third-party validation through audits and continuous assessments. These aren’t check-the-box exercises— they're critical tools to maintain confidence in our strategy and ensure we’re prepared for what’s next.

Start by building the relationship. Cybersecurity must be seen not as a technical burden, but as a strategic asset. Get in the room with executive leaders, speak their language and understand their pressures. Align your message to their mission, not yours.

Second, insist on structure. CISOs must have independent reporting authority and not be buried under operational IT layers. That old-school model is outdated and threatening in today’s environment. You can’t protect what you can’t see, and you can’t influence what you can’t reach.

Finally, focus on small wins. Show how cybersecurity can enable, not impede. Whether it's simplifying compliance, supporting cloud adoption, or helping restore services quickly after a disruption, the goal is to be a trusted partner in resilience, not a cost driver or roadblock.

Looking Ahead: Continuing the Mission

As I transition into a new role as Strategic Liaison and Advisor to the Office of the CIO, I remain fully committed to championing the success of Fairfax County’s cybersecurity program and the broader efforts of our IT Department. Fairfax County is one of the topperforming counties in the country when it comes to IT innovation and cyber maturity. The new role will allow me to continue advancing that legacy while helping scale our lessons learned to the national stage.

None of this would be possible without the extraordinary people behind the scenes. The true strength of our program lies in our amazing staff, the cutting-edge technologies we’ve implemented and the leadership that—though sometimes hard-won—ultimately stood up and owned their role in securing the county.

The mission continues. And I remain as passionate as ever about helping governments nationwide evolve their cybersecurity leadership, strengthen their posture and build the cultures of trust and accountability their communities deserve.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.