Businessbusiness

Leading Federal IT: Tony Scott on the White House CIO Role

Former U.S. CIO Tony Scott on the OPM breach, the $3.1 billion modernization plan, and how the West Wing differs from VMware and Disney.
whats-it-like-to-work-in-the-white-house-tony-scott

Tony Scott served as the third Chief Information Officer of the United States, appointed by President Barack Obama from February 2015 to January 2017. His term closed with the change of administration on January 20, 2017. The role placed him inside the Office of Management and Budget, responsible for federal IT policy across the executive branch, but with no direct authority over agency CIOs. Two events bookend Scott's tenure: the Office of Personnel Management data breach, discovered months after he arrived, and the Cybersecurity National Action Plan, announced in February 2016, which proposed a $3.1 billion IT modernization fund that Congress did not approve that year. A version of the Modernizing Government Technology Act was later signed into law in December 2017, after Scott had left.

Before the White House, Scott was CIO at VMware and held senior IT leadership roles at Microsoft and The Walt Disney Company. The transition from Fortune 500 companies to the federal bureaucracy required adjusting to a different pace of decision making and a much broader set of stakeholders. What follows draws on Scott's reported observations about what the job actually entailed.

Tony Scott US Chief Information Officer
Department of Defense. American Forces Information Service. Defense Visual Information ..., Wikimedia Commons, Public domain

The Scope of the U.S. CIO Role

A coordinator, not a commander

The federal CIO does not run a single large IT department. The role sits within the Office of Management and Budget, and its authority is largely advisory and coordinating. Scott oversaw federal IT policy, set standards for procurement, and led initiatives to consolidate data centers and move bureaus to shared services. But each cabinet-level department has its own CIO who reports to the agency head, not to the U.S. CIO. This structure meant Scott had to influence without commanding, a skill he had developed in private sector matrixed organizations.

Scope of responsibility

The U.S. government spends roughly $80 billion annually on IT. Scott was responsible for the strategy behind that spending, including efforts to retire legacy systems, improve cybersecurity posture across civilian departments, and accelerate the adoption of cloud services. He also chaired the CIO Council, a forum of agency CIOs that coordinates cross-government tech policy. The role required frequent interaction with the White House chief of staff, the director of OMB, and the National Security Council, especially on cybersecurity matters.

From VMware to the West Wing

A non-political appointment

Scott was recruited for the role by the Obama team in late 2014. He was not a political appointee in the traditional sense; the U.S. CIO is a senior executive service position, not subject to Senate confirmation. Scott had spent most of his career in the private sector, most recently as CIO of VMware, a virtualization software company. Before that, he led IT at Microsoft and held senior tech roles at Disney. He had no prior federal experience.

Why the private sector background mattered

The Obama White House was looking for someone who understood modern enterprise infrastructure at scale. The federal apparatus was still running systems built in the 1960s and 1970s, and the 2013 Healthcare.gov launch failure had made legacy IT a political liability. Scott's experience with cloud infrastructure, agile development, and vendor management was directly relevant. He later described the learning curve as steep, particularly around federal procurement law and the appropriations process, which constrain what a CIO can do in ways that have no parallel in a public company.

Managing the OPM Data Breach

The largest breach of federal personnel data

In 2015, the Office of Personnel Management discovered that hackers had compromised databases containing background investigation records of federal employees and contractors. The breach affected over 21 million individuals, making it one of the largest data breaches in U.S. history. Scott's office became deeply involved in the response, which included coordinating with the FBI, the Department of Homeland Security, and the affected bureaus.

What the CIO could and could not do

Scott did not run OPM's IT systems. The agency had its own CIO and its own security team. But the breach exposed systemic weaknesses in how the federal apparatus managed identity and access controls, and it accelerated policy changes that Scott had been pushing. His team worked on improving the government's ability to detect intrusions across departments, standardizing identity management, and pushing for faster adoption of multi-factor authentication. The breach also provided political cover for the Cybersecurity National Action Plan, which the White House announced in February 2016.

The Cybersecurity National Action Plan and the $3.1 Billion Fund

A proposal that took two years to pass

The Cybersecurity National Action Plan, announced in February 2016, was the Obama administration's most comprehensive cybersecurity proposal. It included a request for $3.1 billion to create an IT modernization fund that would allow bureaus to replace legacy systems with more secure, cloud-based alternatives. The fund was designed to circumvent the normal appropriations cycle by giving departments a pool of money they could draw from for approved projects, then pay back over time from savings.

What happened to the proposal

Congress did not approve the $3.1 billion fund in 2016. The proposal was reworked and eventually passed as part of the Modernizing Government Technology Act in December 2017, after Scott had left office. The final version created a much smaller central fund and allowed bureaus to set up their own working capital funds. Scott's office had spent much of 2016 and early 2017 building the case for the fund, testifying before Congress and briefing staff on both sides of the aisle.

White House Eisenhower Executive Office Building
The White House, Wikimedia Commons, Public domain

Culture Shock: West Wing vs. Silicon Valley

Slower decisions, more stakeholders

Scott has described the biggest difference between leading IT at VMware and at the White House as the decision-making velocity. In a public company, a CIO can make a tech acquisition or change a vendor relationship in weeks. In the federal sphere, procurement cycles run for months or years, and every decision involves legal review, congressional oversight, and interagency coordination. The West Wing itself operates on a rhythm driven by the president's schedule and the news cycle, which means IT projects can be deprioritized or accelerated based on events outside the CIO's control.

What worked in government

Some private sector practices transferred directly. Scott brought agile development methodologies to federal IT projects, pushing departments to break large contracts into smaller pieces and deliver software incrementally rather than in multi-year waterfall cycles. He also emphasized the importance of user experience, arguing that federal websites and services should be as easy to use as commercial equivalents. The U.S. Digital Service and 18F, both created before Scott arrived, had already started this work, and his office helped institutionalize it.

The Legacy of Scott's Tenure

Structural changes that outlasted the administration

Scott's office made several structural changes that survived the transition to the Trump White House. The Cybersecurity National Action Plan's emphasis on identity management led to the creation of a federal identity and credential management office. The push for shared services reduced the number of federal data centers. And the IT modernization fund concept, though delayed, eventually became law. Scott also established a formal process for agency CIOs to report cybersecurity metrics to OMB, creating a baseline that later administrations used to track progress.

What the role became after 2017

Scott was the third person to hold the U.S. CIO title, following Vivek Kundra and Steven VanRoekel. The role has continued under subsequent presidents, though its influence has varied depending on the priority the White House assigns to tech policy. Scott's term ended on January 20, 2017, with the inauguration of President Donald Trump. He did not remain in the government. The position since then is not established here, as of mid-2024.

Key Facts

  • Title: Chief Information Officer of the United States
  • Tenure: February 2015 to January 2017
  • Appointed by: President Barack Obama
  • Predecessors: Vivek Kundra and Steven VanRoekel
  • Previous roles: CIO at VMware, senior IT roles at Microsoft and Disney
  • Key incident: OPM data breach affecting over 21 million individuals (2015)
  • Major policy: Cybersecurity National Action Plan, proposed $3.1 billion IT modernization fund (February 2016)
  • Outcome of fund: Not approved in 2016; MGT Act signed into law in December 2017

Frequently Asked Questions

What was Tony Scott's role as U.S. CIO?

He was responsible for federal IT policy, cybersecurity strategy, and tech modernization across the executive branch, working from within the Office of Management and Budget.

How did the OPM breach affect Scott's tenure?

The breach exposed systemic weaknesses and accelerated policy changes, including the push for the Cybersecurity National Action Plan and stronger identity management standards.

Did the $3.1 billion IT modernization fund pass?

No, not in 2016. A version of the MGT Act passed in December 2017, after Scott had left office.

How was the White House different from VMware?

Scott reported that decision-making was much slower due to procurement laws, congressional oversight, and interagency coordination, with no single authority over agency CIOs.

About the author

, Editor

Kenneth Ma is the editor of LeadMonitor.ai, covering the companies, deals and policy decisions shaping business and technology markets.

View all 427 articles by Kenneth Ma  ·  Our editorial policy

Recent Stories

How to make money selling Canva templates

How to highlight text in Canva

How to print from Canva without quality loss

How to check if Canva is down right now

How to group and ungroup elements in Canva

How to stretch an image in Canva

How to make a QR code in Canva

Convert Canva to PowerPoint and Google Slides