# Andrew Morgan: Andrew Morgan \- Technology Transformation > Andrew Morgan delivers innovative consulting enabled by strategy, best\-practices and advanced technology solutions\. Generated by Yoast SEO v28.3, this is an llms.txt file, meant for consumption by LLMs. ## Pages - [Regulatory Risk \& Compliance](https://andrew-morgan.com/regulatory-risk/) - [Home](https://andrew-morgan.com/) - [Audit Tracking](https://andrew-morgan.com/audit-tracking/) - [AM's Financial Management Practice](https://andrew-morgan.com/financial-management/) - [Data \& Analytics at Andrew Morgan](https://andrew-morgan.com/data-and-analytics-center-of-excellence/) ## Posts - [How Artificial Intelligence Is Reshaping the Office of the CFO in Public Sector Organizations](https://andrew-morgan.com/2026/08/27/how-artificial-intelligence-is-reshaping-the-office-of-the-cfo-in-public-sector-organizations/): Repeat audit findings signal deeper systemic issues\. Learn why agencies must go beyond quick fixes and use data\-driven root cause analysis to resolve problems for good\. - [cATO – The New Frontier: Active Cyber Defense \(ACD\) \(Part 3 of 5\)](https://andrew-morgan.com/2026/08/20/cato-the-new-frontier-active-cyber-defense-acd-part-3-of-5/): Part 3 of our cATO series covers Active Cyber Defense: the CSSP engagement, penetration testing, incident response planning, and continuous detection capabilities the DoD requires once a system goes live\. - [Cost Estimation vs\. Actual Spending](https://andrew-morgan.com/2026/08/06/cost-estimation-vs-actual-spending/): Repeat audit findings signal deeper systemic issues\. Learn why agencies must go beyond quick fixes and use data\-driven root cause analysis to resolve problems for good\. - [cATO – The New Frontier: The Dilemma \(Part 1 of 5\)](https://andrew-morgan.com/2026/07/15/cato-new-frontier-part-1/): For decades, the Authorization to Operate has gated federal systems with a slow, point\-in\-time review\. Part 1 of our cATO series breaks down why that model is falling behind, and the OSD memo that introduced Continuous ATO as the fix\. - [cATO – The New Frontier: Secure Software Supply Chain \(SSSC\) \(Part 2 of 5\)](https://andrew-morgan.com/2026/07/30/cato-new-frontier-part-2/): Part 2 of our cATO series breaks down the Secure Software Supply Chain pillar, translating abstract supply chain security goals into concrete DevSecOps platform, process, and workforce requirements the DoD actually evaluates\. ## Categories - [Financial Management](https://andrew-morgan.com/category/fm/) - [Enterprise Performance Management](https://andrew-morgan.com/category/epm/) - [Technology Solutions](https://andrew-morgan.com/category/technology-solutions/) - [Regulatory Risk \& Compliance](https://andrew-morgan.com/category/regulatory-risk-compliance/) ## Categories - [Financial Management Practice](https://andrew-morgan.com/team-category/financial-management-practice/) - [Healthcare](https://andrew-morgan.com/team-category/healthcare/) - [Data \& Analytics](https://andrew-morgan.com/team-category/data-analytics/) - [EPM](https://andrew-morgan.com/team-category/epm/) ## Optional - [Sitemap index](https://andrew-morgan.com/sitemap_index.xml)