5 IT priorities supporting modernization in civilian agencies

New directives demand a flexible IT foundation

Federal agencies are being directed to increase efficiency, detect waste and fraud, optimize costs, deliver services across an open hybrid cloud environment, and adopt bias-free AI as described in America’s AI Action Plan.1 Reduced staffing levels, legacy IT systems, and mounting technical debt compound the challenge. 

To achieve this mission and comply with these new directives, civilian agencies are modernizing their IT infrastructure. This overview summarizes 5 IT priorities for government and explains how Red Hat® technologies can help to achieve them. 

1. Introduce AI at scale while meeting requirements for accountability and security

Citizen interactions, sensor readings, documents, and email are all sources of insights that can be used for decision-making, personalized citizen experiences, predictive maintenance, and content generation with gen AI. To turn data into useful insights, agency IT teams need the technology that can prevent data leakage, avoid application latency when large data sets are sent across the network, and maintain AI model accuracy. To introduce AI at scale, agencies also need the flexibility to train and run models in different locations, including at the edge of the network, and need standardized processes for AI application development. 

How Red Hat can help

Comply with the objective truth and bias-free mandates in the AI Action Plan. Develop and deploy transparent, open source AI models with Red Hat OpenShift® AI. Red Hat’s open approach gives government teams control over AI systems. It also provides transparency and auditability, helping to build trust in automated decision-making. 

Build in a security focus. AI applications rely on an inference server to communicate with large language models and generate a response. Red Hat AI Inference Server helps to strengthen security with real-time analysis and anomaly detection. 

Maintain data privacy. To keep up with rapid changes, some agency personnel are using commercial AI tools not approved by their IT teams. This practice exposes the agency to risks from data leakage. Take steps to prevent data leakage by using Red Hat OpenShift AI to host open source alternatives to commercial AI chatbots, hosted within your agency’s trusted agency computing environments.

Lightwell. A $5 billion joint commitment between Red Hat and IBM, Lightwell provides agencies with a security-focused enterprise clearinghouse to harden foundational software libraries and AI frameworks for security. By combining advanced agentic AI with expert human engineering, Lightwell delivers validated, production-ready patches directly into agency pipelines. This capability allows multiple IT teams to execute surgical fixes on the exact stable software versions running in production without forcing a risky system upgrade, delivering the automated resilience required to align with recent Executive Orders on AI and cybersecurity. 

Simplify the citizen experience. Red Hat specialists in AI and government can coach your teams to use Red Hat data management and AI tools to personalize the digital experience for citizens, all while keeping a focus on security. Deepen your knowledge of agency IT teams with Red Hat Training, instructor-led or self-paced, in-person or online.

Red Hat in action: NASA Marshall

“[At NASA Marshall Space Flight Center], we achieved about 40% efficiency in our cost avoidance for our operational infrastructure. We also avoided a 200-300% [price] increase from our legacy virtualization provider.”

Red Hat in action: National Nuclear Security Administration

National Nuclear Security Administration (NNSA), located at Lawrence Livermore National Laboratory (LLNL), uses Red Hat Enterprise Linux for El Capitan, a powerful supercomputer, capable of more than 2.79 exaflops per second. Red Hat Enterprise Linux is helping NNSA prepare for cloud-enabled supercomputers with AI/ML capabilities. El Capitan helps address the safety, security, and reliability of the nation’s nuclear stockpile.

Authority to Operate 

Microsoft Azure Red Hat OpenShift for Microsoft Azure Government and Red Hat OpenShift Service on AWS have achieved FedRAMP Agency Authority to Operate (ATO) at the High Impact Level. 

2. Expand automation

Automating manual activities helps agency IT groups maintain (or even increase) service levels despite a reduced workforce. Automation also avoids human-caused errors that can interrupt government services or create security vulnerabilities. 

How Red Hat can help

Automate routine tasks. Automate workflow and reduce technical debt with Red Hat Ansible® Automation Platform. Automating tasks such as continuous deployment, reboot, security patching, configuration changes, and cloud resource management reduces labor requirements. Use the time saved to automate more tasks, simplify existing service delivery, or build new digital capabilities to support the mission.

Bridge automation skill gaps with gen AI. Build automation workflows with natural language prompts using the automation coding assistant, available as a Gen-AI-as-a-Service feature in Ansible Automation Platform. For instance, the assistant understands prompts like “Write an Ansible Playbook to provision a virtual machine on AWS.”

Operationalize artificial intelligence and machine learning. With Red Hat OpenShift, government data scientists and developers can access AI tools, frameworks, and built-in monitoring and logging functions from a single interface. Agencies can also automate infrastructure management with Red Hat OpenShift to gain more time for building AI models and applications. For example, OpenShift automatically adds available graphics processing unit (GPU) resources as needed during AI model training.

Foundation for a modern software factory

A software factory is the digital equivalent of an assembly line, producing consistent, reliable cloud-native applications with minimal human intervention. Red Hat technologies automate agile development, build, test, release, and delivery phases to help government teams release updates consistently and with attention to security.

3.  Strengthen cybersecurity

Targeted by more frequent and sophisticated cyber threats, governments need to fortify defenses, accelerate incident detection and response, and increase resilience. To improve operational resilience and data privacy, agencies have been directed to implement zero trust architectures2 and to use cloud technologies to prevent, detect, assess, and remediate cyber incidents. These security capabilities are mandated in the Federal Information Processing Standards (FIPS), the Federal Information Security Management Act (FISMA), and by the National Institute of Standards and Technology (NIST).

How Red Hat can help

Implement a zero trust architecture. Zero trust3 is a security model based on a policy to “never trust, always verify” users, devices, and digital transactions, even if they operate within agency walls. Use Red Hat Trusted Software Supply Chain to code, build, and monitor software using proven platforms, trusted content, and real-time security scanning and remediation. 

Adopt confidential computing. Protect data in use by creating isolated workload environments that operate independently of the host system. Red Hat OpenShift confidential virtual machines (VMs) protect workloads and data even if the underlying host is compromised. 

Shift left by performing security tests early in the software development lifecycle. The earlier vulnerabilities are detected, the less time is needed for remediation. Adopt shift-left testing using Red Hat Advanced Cluster Management for Kubernetes. Available in self-managed and fully managed cloud editions, Red Hat Advanced Cluster Management includes hundreds of built-in controls to enforce security-focused practices throughout an agency’s DevSecOps process. These practices are based on standards such as Center for Internet Security (CIS) Benchmarks and NIST guidelines. Red Hat Advanced Cluster Management integrates with existing agency DevSecOps tooling and workflow. 

Defend against quantum-computing security threats. Traditional cryptographic algorithms are vulnerable to potential attacks from quantum computers. Red Hat OpenShift supports post-quantum cryptography (PQC), based on new cryptographic algorithms that are resistant to attacks from both classical and quantum computers. Operating system (OS) images in Red Hat Enterprise Linux® 10 and later are also immutable, meaning they cannot be altered either inadvertently or maliciously. IT teams can see exactly what is in the image. 

Security throughout the software development lifecycle

Red Hat created the Secure Software Management Lifecycle (SSML) approach, which directly aligns with National Institute of Standards and Technology Secure Software Development Framework (NIST SSDF) SP-800-218, the Open Worldwide Application Security Project (OWASP), and various International Organization of Standardization (ISO) standards. By using the SSML framework, government agencies can reduce the number of vulnerabilities in released software, mitigate the potential effect of undetected or unaddressed vulnerabilities, and address the root causes of vulnerabilities to prevent future recurrences.

4. Optimize cloud use

Moving select data, applications, and citizen services to a cloud environment helps to increase agility and IT efficiency. Migrating workloads to a cloud environment can also reduce costs as a result of pay-per-use pricing, reduced infrastructure maintenance, and cloud providers’ economies of scale. 

How Red Hat can help 

Standardize technology across the hybrid cloud environments. Simplify IT operations with a consistent technology architecture. Red Hat Enterprise Linux and Red Hat OpenShift can run across environments, including the agency datacenter, public cloud environments, and at the edge of the network. IT teams can manage all environments using the same tools, increasing efficiency.

Modernize applications. Many of today’s government applications are large, monolithic systems written in the early 2000s. Few people know how to maintain them. A change to a single line of code could potentially break the entire application, and application components cannot be distributed across different locations. In contrast, modern microservices-based applications consist of independent services that communicate via application programming interfaces (APIs), making them more efficient to build, test, deploy, and update. Simplify the shift to microservices-based applications by using Red Hat OpenShift and Red Hat Service Interconnect. 

Boost AI performance by running applications closer to data and users. Transmitting data to the datacenter or cloud for model training and analytics adds latency. Reduce latency by hosting workloads closer to data and users. Red Hat OpenShift can be deployed in cloud environments, the agency datacenter, and many edge environments.

Proactively identify risk. Red Hat subscriptions include Red Hat Lightspeed, an AI-powered cloud service that provides visibility into operating environments so that staff can identify and address risks before they spread. Red Hat Lightspeed has received FedRAMP ATO at the High Impact Level, certifying it for the government’s sensitive unclassified data in cloud computing environments.

U.S.-based support

Red Hat Confirmed Stateside Support gives Red Hat government customers the appropriate support resources and data handling to meet federally mandated security requirements. For example, support staff are U.S. citizens working on U.S. soil.

5. Modernize open hybrid cloud and edge infrastructure

Aging government software platforms and applications are costly to maintain. Many cannot interoperate, leading to duplicate data sets. Modern platforms increase efficiency. For example, automated DevSecOps workflows help developer teams more quickly introduce new citizen services and experiences. Interoperable applications allow departments to share data, avoiding the costs of duplicate data sets and simplifying the citizen experience. Another aspect of modernization is breaking up monolithic applications into smaller microservices that are simpler to update and can be distributed across different environments, including at the edge. 

How Red Hat can help

Support workloads and run them in the optimum location. Red Hat OpenShift supports container and VM workloads across data centers, public cloud environments (e.g., Amazon AWS, Microsoft Azure, Google Cloud Platform (GCP), Open Container Initiative (OCI)), and remote locations. Applications behave the same way everywhere. Freely move workloads in response to new performance requirements, changes to cloud providers’ pricing and tools, and other factors.

Maintain a consistent OS across open hybrid cloud environments. Use Red Hat Enterprise Linux 10 or later in image mode to build, deploy, and manage the OS as a container. Teams use the same tools and processes for application containers and OS containers, which both move through the agency’s continuous integration and continuous delivery (CI/CD) pipeline. Containerizing the OS also prevents configuration drift that can cause security vulnerabilities and performance issues. 

Increase efficiency with fleet management. Manage edge devices (remote servers, cameras, sensors, etc.) at scale with Red Hat Edge Manager4

Extend OS lifetime. Red Hat Enterprise Linux has a 10-year lifecycle. When it comes time to upgrade, minimize service interruption by using the Leapp utility, which makes it possible to install a new version of Red Hat Enterprise Linux without removing an earlier version that is already in place. If an upgrade is not feasible for a particular application, Red Hat provides extended lifecycle support.

Simplify container adoption. Ease the transition to containers with Podman, an open source tool for developing, managing, and running containers on Red Hat Enterprise Linux. Add orchestration and automate Day 2 operations by migrating workloads to Red Hat OpenShift.

Learn more

Read about how Red Hat is helping civilian agencies achieve mission success.

  1. White House. “White House Unveils America’s AI Action Plan.” 23 July 2025.

  2. Cyber Security and Infrastructure Defense Agency. “Executive Order on Improving the Nation's Cybersecurity.” Accessed 17 Nov. 2025.

  3. Red Hat e-book. “Zero trust security for government agencies.” 18 Oct. 2024.

  4. Red Hat datasheet. “Red Hat Edge Manager.” 15 April 2026.