top of page

If Entrusted to Lead: My First 100 Days as Chief Information Officer (CIO) of the U.S. Environmental Protection Agency

Writer: DEW Diligence
DEW Diligence
3 days ago
12 min read

Updated: 1 day ago

A mission-first agenda for technology leadership, cybersecurity, Super Intelligence (SI), and

measurable public value. By David E. Williams, CISM, GSTRT, GSLC | October 2026


David Williams is not an EPA employee or representative; this is independent commentary.


When an American family turns on the kitchen faucet, when a scientist evaluates environmental data, when an emergency responder investigates a hazardous release, or when a business submits an environmental permit application, information technology may not be the first thing that comes to mind. Yet behind these activities lies an essential network of information systems, scientific data, digital services, cybersecurity capabilities, and institutional expertise. These systems help the U.S. Environmental Protection Agency (EPA) carry out its mission to protect human health and the environment.


That mission is consequential. Its execution demands more than modern technology. It requires trusted information, disciplined leadership, operational resilience, responsible innovation, and careful stewardship of public resources.


If entrusted with the responsibility of serving as EPA's Chief Information Officer (CIO) and Chief Artificial Intelligence Officer (CAIO) under M-25-21, I would approach the position with a clear understanding that the CIO's responsibility is more than leading technology; it is to make technology an effective instrument of public service. It is also more than just leading people, but leading ~300 federal employees, 400+ contractors, a 12,000+ workforce, and being a leader representing the United States. My first 100 days would establish that foundation through listening, disciplined assessment, informed decisions, and measurable progress. Because in federal service, leadership is ultimately judged by the integrity of its decisions and the results delivered to the American people. The CIO should demonstrate and champion commitment to the rule of law and American founding principles, driving efficiency, merit, and competence, leading people, and achieving results.



If Entrusted to Lead the EPA as CIO/CAIO
If I were entrusted to lead the EPA as CIO & CAIO | My first 100 days

The Mission Comes First. Technology Must Follow.


The U.S. Environmental Protection Agency's FY 2026–2030 Strategic Plan establishes five strategic goals: Provide Clean Air, Land, and Water for Every American; Restore American Energy Dominance; Advance Permitting Reform, Cooperative Federalism, and Cross-Agency Partnership; Make America the Super Intelligence (SI) Capital of the World; and Bring Back and Protect American Auto Jobs.


Supported by 14 strategic objectives, these goals establish the agency's direction for fulfilling its statutory responsibilities, improving government performance, encouraging innovation, and responsibly managing public resources.


The plan further establishes two FY 2026–2027 Agency Priority Goals, both targeted for September 30, 2027. These goals are advancing investment and job creation through permitting reform, and reducing public risks associated with per- and polyfluoroalkyl substances (PFAS) by strengthening science, fulfilling statutory obligations, enhancing communication, and building partnerships.


For a CIO, these priorities carry direct operational significance. EPA's stated objectives include modernizing permitting and other public-facing operations, improving financial systems and data availability, strengthening organizational efficiency, and leveraging automation and SI to enhance agency processes and capabilities. The plan also recognizes cybersecurity preparedness for water infrastructure and responsible management of the environmental impacts associated with expanding data-center infrastructure. These are opportunities to strengthen existing agency capabilities, protect critical information, improve services, support sound scientific and regulatory decisions, and make more effective use of taxpayer resources.


As CIO, the task is to translate these priorities into an integrated, secure, financially disciplined, and measurable technology strategy building upon work already underway and partnering with EPA's program offices, regional leadership, and federal, state, and Tribal stakeholders. That responsibility requires a clear understanding of institutional authority. The CIO enables scientific, regulatory, administrative, and enforcement functions through trustworthy information and resilient technology; the CIO does not independently establish environmental standards or substitute technological judgment for the responsibilities assigned by law to EPA's authorized officials.


My guiding principle would be to modernize where it advances the mission, innovate where measurable value can be demonstrated, safeguard what Americans depend upon, and ensure every significant technology decision respects the law, the public trust, and the resources entrusted to the agency.


Days 1–30: Listen, Understand, and Establish the Baseline


The first month emphasizes listening before restructuring, verification before judgment, and mission understanding before prescribing solutions. EPA possesses substantial institutional knowledge accumulated through decades of scientific research, environmental administration, technical operations, and public service. That expertise deserves respect. That means engaging senior leadership, program and regional offices, mission professionals, the cybersecurity and data leadership teams, financial and acquisition officials, privacy and legal professionals, and the workforce responsible for operating essential services. The aim is to understand where technology is already performing well, where mission dependencies create operational risk, and where existing improvement initiatives may need additional executive support.


The initial assessment would examine five dimensions. They are mission-critical services, enterprise technology architecture, cybersecurity and resilience, information and SI governance, and financial and workforce capacity. The first month asks the question of which technology-related risks or constraints, if addressed appropriately, would produce the greatest measurable benefit for EPA's mission?


The work starts by checking existing inventories against evidence, then examining documented system dependencies, mission continuity requirements, outstanding risks, modernization plans, technology contracts, and available performance data. This would be an evidence-based assessment of current conditions and opportunities. By Day 30, the target is an initial enterprise decision framework that identifies priority mission services, accountable owners, significant dependencies, and issues requiring executive attention. The immediate deliverable would be a credible, shared understanding of where leadership attention and resources are most justified.


This assessment also aligns with EPA's FY 2026–2030 Learning Agenda and FY 2027 Evidence Plan, giving attention to permitting efficiency, grants effectiveness, and the measurable results of automation and SI initiatives already underway.


Days 31–60: Prioritize Mission Outcomes and Strengthen Resilience


During the second phase, assessment would begin transitioning into execution. Working with program leaders, the priority is selecting a limited number of improvements capable of delivering demonstrable benefits without creating unnecessary procurement, operational, or compliance burdens, building on the guardrails and reuse-first posture already in place. Two potential opportunities deserve consideration.


  1. Digital permitting and administrative efficiency. Permitting activities often depend on information exchange, document management, workflow coordination, and communication across multiple stakeholders. With the responsible program offices, the question is whether improvements to application intake, document routing, data validation, or case-status visibility could reduce avoidable administrative effort. The objective would be to support timely and accurate processing. This work would directly support EPA's Objective 3.1 by advancing reliable, increasingly paperless permitting processes, improving public visibility into permitting actions, and identifying opportunities to reduce processing time, uncertainty, and administrative costs.


  2. Environmental information integrity and interoperability. Reliable information supports scientific assessments, compliance activities, emergency response, and public communication. Priorities include strengthening data quality, provenance, secure exchange, and accessibility, including possible support for EPA's PFAS-related objectives. These opportunities would be evaluated alongside existing initiatives rather than presumed to require new platforms.


Cybersecurity would remain a parallel executive priority. Working closely with EPA's security leadership and appropriate federal partners, the review covers the protection and recovery capabilities associated with high-value mission services. This would include identity and access management, vulnerability exposure, third-party dependencies, monitoring, incident readiness, and continuity planning. The current federal direction is particularly relevant. OMB Memorandum M-26-14, issued in May 2026, establishes a more risk-based approach to agency logging and network visibility, replacing the earlier M-21-31 requirements.


My responsibility would be to ensure that EPA's implementation of applicable requirements is grounded in mission risk, measurable effectiveness, and efficient use of resources. The Day 60 milestone is agreement on a small, prioritized delivery portfolio with named business owners, clear dependencies, preliminary costs, risk treatments, and measurable success criteria.


Days 61–100: Demonstrate Progress and Establish Accountability


The third phase would focus on translating leadership decisions into observable progress. Selected initiatives move into short delivery cycles, executive review checkpoints, and explicit criteria for continuation, adjustment, or termination. Where feasible, early pilots would demonstrate improvements to a defined workflow, data exchange, or internal service. Where production deployment would require more time, the measurable accomplishment would be a validated baseline, tested solution, documented risk decision, and approved implementation path. I would not represent an unfinished pilot as a delivered public benefit. Equally important is a practical governance rhythm across technology, cybersecurity, SI, acquisition, and mission stakeholders.


The CIO should have clear visibility into the technology investment portfolio and the information needed to advise leadership about continuing, modifying, consolidating, or retiring investments. The Federal Information Technology Acquisition Reform Act (FITARA) and M-26-10, Reinforcing Transparency, Accountability, and Oversight of Federal Technology (Mar 31, 2026) reinforce this responsibility.


Technology approvals should connect to utilization, lifecycle costs, cybersecurity considerations, mission benefit, and evidence of performance. That work is done jointly with acquisition and financial leadership. By the conclusion of the first 100 days, the executive deliverables are:


  1. A validated mission-and-technology baseline, aligning mission, technology, and security strategies, including prioritized risks, dependencies, and accountable owners.

  2. An evidence-based improvement portfolio, with selected initiatives, measurable objectives, resource assumptions, and decision checkpoints.

  3. A 12-month execution and performance framework, with quarterly review checkpoints, connecting technology delivery to operational results, financial stewardship, and risk reduction.


Beyond 100 Days: A Practical 12-Month Execution Agenda


The first 100 days should establish direction. The following months must demonstrate whether that direction produces sustainable results.


Months 4–6: Validate and expand what works. Priority goes to completing carefully selected improvements, subject to required security, privacy, accessibility, acquisition, and operational reviews. Activities could include strengthening high-value service resilience, improving digital permitting workflows, supporting financial-system modernization, enhancing the accessibility and interoperability of agency information, and introducing appropriate automation into administrative processes. Grants and acquisition oversight are natural next candidates, pursued with the responsible program, financial, and acquisition leadership


Months 7–9: Institutionalize improvements and develop workforce capabilities. Successful initiatives would progress through controlled expansion based on documented value, operational readiness, and available resources. Workforce investment follows: technical competencies, succession planning, cross-functional collaboration, and knowledge transfer, all developed with agency leadership. SI and emerging technologies would receive focused workforce development, including training in responsible use, information protection, model limitations, and human accountability.


Months 10–12: Evaluate results and refine the investment portfolio. At the end of the first year, the organization should be able to explain which investments produced measurable benefits, which risks were reduced, which initiatives should continue, and which require reconsideration. Financial and operational reviews would inform the next planning and budget cycle. This would remain an adaptive roadmap. Priorities and milestones would be reviewed as evidence develops and adjusted for mission needs, statutory obligations, appropriations, procurement realities, and emerging threats.


Cybersecurity, SI, and the Rule of Law: Governance That Enables Results


A federal CIO must operate within a framework of constitutional responsibility, congressional authority, executive direction, established policy, and public accountability.


My approach is grounded in respect for the Constitution, faithful execution of applicable law, sound administrative processes, protection of sensitive information, and impartial service to the American people. That commitment must be reflected in leadership statements and in operational decisions. The following would provide an initial governance alignment, subject to legal and agency-specific review.


Governing authority or framework

Executive leadership application

Environmental statutes, including the Clean Air Act, Clean Water Act, Safe Drinking Water Act, RCRA, CERCLA, and TSCA

Protect the integrity, availability, traceability, and appropriate use of information supporting statutory programs.

FITARA, FISMA, the GPRA Modernization Act, the Evidence Act, and OMB Circular A-130

Connect technology investments, security, resource oversight, performance reporting, and evidence-based decisions.

NIST Cybersecurity Framework 2.0, applicable NIST SP 800-53 controls, and OMB M-26-14/M-26-15

Strengthen cybersecurity governance, prioritized monitoring, resilience, and post-quantum migration planning.

Executive Order 14179; OMB M-25-21, M-25-22, and M-26-04; and NIST AI RMF 1.0

Enable risk-proportionate SI adoption, trustworthy outputs, effective procurement, transparency, and appropriate human oversight.

Executive Order 14318 and EPA Strategic Plan Objectives 3.1 and 4.1

Support lawful and efficient data-center permitting and related infrastructure initiatives through reliable information systems, secure data exchange, and coordination with EPA's authorized program, and regional offices.

NIST's AI Risk Management Framework 1.0 is voluntary guidance and NIST has announced a revision. Applicable federal policies, rather than the framework alone, establish binding agency requirements.


Governance should never become a substitute for leadership. Its purpose is to make informed decisions faster, clarify accountability, protect the public, and demonstrate that technology is being used lawfully and effectively.


Responsible SI: Moving From Possibility to Demonstrable Public Value


EPA's FY 2026–2030 Strategic Plan establishes Super Intelligence (SI) as a strategic priority, including Objective 4.2, which focuses on leveraging SI to improve agency processes and capabilities.


This direction builds upon existing agency initiatives. EPA identifies the Resource Conservation and Recovery Act (RCRA) Model for Large Quantity Generators, which uses machine learning to help predict where inspectors are more likely to find severe violations. The agency also intends to pilot similar models in other statutory programs and further develop governance, workforce capabilities, and practical applications of SI.


As CIO and CAIO, my role is to build on these efforts through a disciplined, mission-driven approach by strengthening data governance, security, system integration, operational accountability, and evidence-based evaluation while identifying opportunities to responsibly expand successful capabilities.


Potential applications could include assisted document classification, information retrieval, administrative workflow support, and data-quality analysis. However, successful SI adoption requires more than acquiring models or deploying software. It requires executive support, authoritative data, secure architectures, privacy controls, supply chain risk management, vendor due diligence, accountable and responsible governance, meaningful evaluation, appropriate access controls, and continuous monitoring.


Where systems influence consequential decisions, human responsibility and applicable legal safeguards must remain clear, transparent, and explainable. Every proposed SI initiative should answer five questions at the outset: What problem are we solving? How will we evaluate accuracy and precision? Who is accountable and responsible? What are the potential consequences of failure? How will value and the public benefit be measured?


SI adoption must also account for infrastructure demands. Advanced computing creates real energy, water, equipment, and lifecycle considerations. EPA's role in supporting responsible infrastructure development presents an opportunity to advance reliable information and efficient agency operations while respecting the distinct responsibilities of program offices and industry. Innovation and environmental stewardship need not be competing objectives when decisions are supported by sound engineering, accurate information, statutory compliance, and measurable results.


Measuring What Matters As CIO: Outcomes, Not Activity


A credible technology strategy requires a performance scorecard that executive leadership can understand and use. Performance is organized around three principal objectives.


  1. Objective One: Improve mission service delivery. Key results would include documented processing-time baselines, service reliability, error rates, accessibility, and demonstrable improvements in selected workflows. Targets would be established after validating initial conditions.


  2. Objective Two: Reduce material technology and cybersecurity risk. Results would track ownership and treatment of prioritized risks, coverage of critical services, incident readiness, recovery performance, and closure of significant control gaps.


  3. Objective Three: Increase the value of technology investments. Measures would include validated utilization, avoidable expenditure, lifecycle cost, delivery performance, user experience, and benefits realized against approved investment objectives.


These measures align directly with EPA’s FY 2026–2027 Agency Priority Goals, including the September 30, 2027 targets for permitting reform and PFAS risk reduction. Technology performance would be evaluated through its demonstrable contribution to those priorities, while recognizing that responsibility for environmental, regulatory, and programmatic outcomes remains with the appropriate agency leadership.


Each measure would require a baseline, accountable owner, defined reporting frequency, and clear explanation of its connection to agency performance. Leading indicators must be kept distinct from realized benefits. Completing training, conducting a test, or deploying software can demonstrate progress, but these activities alone do not prove that mission performance improved. The intended result is a management culture that can answer a few questions. Are we delivering better services? Are we reducing meaningful risk? Are we making responsible use of taxpayer resources?


Leadership Is Ultimately About People and Public Trust


Technology transformation succeeds when people understand the mission, trust their leadership, and have the skills and authority necessary to perform. EPA's scientists, engineers, cybersecurity professionals, analysts, administrators, and regional personnel bring expertise that cannot simply be replaced by a new platform or an external consulting engagement. The job is to build on that expertise, not replace it.


My leadership philosophy emphasizes merit, technical competence, ethical conduct, accountability, responsibility, collaboration, and continuous improvement. It also recognizes that federal employees deserve clarity about expectations and genuine opportunities to contribute to organizational progress.


External contractors and technology partners should complement the government's essential ability to exercise informed oversight and maintain institutional knowledge. The relationship between federal leadership, employees, industry, states, Tribes, and other partners should be defined by shared objectives, appropriate boundaries, and mutual accountability.


This partnership is important for cybersecurity affecting water and wastewater infrastructure. EPA's coordination with the Cybersecurity and Infrastructure Security Agency (CISA) and other partners can help operators strengthen resilience, while recognizing that individual utilities retain their own operational responsibilities.



The Commitment: Serve the Mission, Earn the Trust, Deliver the Results


My perspective on executive technology leadership has been shaped by the intersection of business strategy, information technology, cybersecurity, enterprise risk management, and responsible innovation. —David E. Williams, CISM, GSTRT, GSLC

I believe these disciplines are most effective when they operate together and not as competing priorities, but as coordinated capabilities supporting organizational objectives. That integrated perspective is what I bring to EPA as CIO. I would not arrive with every answer. I would arrive prepared to ask informed questions, listen carefully, make defensible decisions, support capable professionals, accept accountability, and pursue meaningful results


The opportunity to serve the United States through an agency whose work reaches American homes, communities, industries, and critical infrastructure is one I regard with genuine seriousness and enthusiasm. One hundred days alone cannot complete the modernization of a complex federal enterprise, but 100 days can establish the standards of leadership, governance, execution, and trust that shape everything that follows.


If entrusted with that responsibility, my goal would be to ensure that EPA's technology organization continues advancing as a secure, innovative, fiscally responsible, and mission-centered enterprise, capable of supporting the agency's statutory obligations and serving the American people with distinction. Public service is not about the technology possessed; it is about the responsibility accepted, the trust earned, and the lasting value delivered.


Selected Authoritative References


Comments


Get actionable insights—subscribe

Enter your email address here to join the newsletter for practical insights.

bottom of page