
Sign up to save your podcasts
Or


🔥 "I Could Have Saved $300K on CMMC!" 🔥
Miguel is the founder of Villa-Tech, a small but powerful tech company that is breaking into the defense contracting space.
Miguel shares a raw and honest look at the costly missteps, lessons learned, and strategies that could save small businesses hundreds of thousands of dollars preparing for CMMC certification!
👉 Here are some highlights:
Villa-Tech has built a CUI enclave environment that other defense contractors can leverage! They also have an amazing set of capabilities and just achieved CMMC level 2 certification, so be sure to check out their capabilities statement below.
Small businesses CAN succeed in CMMC, but the path is filled with pitfalls that can drain your budget.
Don’t make the same mistakes - learn from someone who’s been through it!
What were your biggest takeaways? Let me know in the comments!
Follow Miguel on LinkedIn: https://www.linkedin.com/in/miguel-villarreal-0231286/
Villa-Tech Website: https://www.villa-tech.com
Villa-Tech Capabilities: https://villa-tech.com/government/capabilities-statement/
Structura.io Website: https://structura.io/
-----------
Thanks to our sponsor Vanta!
Need continuous visibility into the state of your security controls?
Discover the new way to GRC here: https://vanta.com/grcacademy
-----------
Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!
Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s2-e2&utm_campaign=courses
#cmmc #nist #cybersecurity
CMMC and DFARS compliance is hard - especially in the cloud.
Got AWS? They've given you tools that make compliance much easier!
In this episode, I sit down with Travis Goldbach from Amazon Web Services (AWS) to break down the solutions AWS has created to simplify CMMC and DFARS compliance.
👉 Here are some highlights:
I didn't know that AWS was so mature when it came to CMMC and DFARS compliance!
It was really awesome to learn how they are making compliance easier!
What were your biggest takeaways? Let me know in the comments!
Follow Travis on LinkedIn: https://www.linkedin.com/in/travis-goldbach-b446a223/
AWS CMMC website: https://aws.amazon.com/compliance/cmmc/
-----------
Thanks to our sponsor Vanta!
Need continuous visibility into the state of your security controls?
Discover the new way to GRC here: https://vanta.com/grcacademy
-----------
Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!
Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s2-e1&utm_campaign=courses
#cmmc #nist #cybersecurity #aws
It’s been a long and wild ride on this #cmmc ship! ⛵
In this episode, I speak with Stacy Bostjanick who is the Director of the CMMC program at DoD CIO!
Here are some highlights from the episode:
First mentioned in 2019, CMMC 1.0 was released in 2020 under the Trump administration.
CMMC 1.0 was reviewed during the Biden administration, they released CMMC 2.0 in late 2021, and then… There was a great silence.
If you threw a small rock, you’d hit ten people who thought CMMC was going away.
All this time though, the DoD was quietly marching on.
They released the proposed CMMC program rule in December 2023 and released the final CMMC program rule in October 2024 - which is now EFFECTIVE.
After all of that, CMMC will FINALLY begin to phase into DoD solicitations and contracts by this summer.
CMMC has been a LONG time coming, and it was an honor to hear the back story and why certain decisions were made!
What were your biggest takeaways? Let me know in the comments!
Follow Stacy on LinkedIn: https://www.linkedin.com/in/stacy-bostjanick-a3b67173/
DoD CIO CMMC website: https://dodcio.defense.gov/CMMC/
-----------
Thanks to our sponsor Vanta!
Want to save time filling out security questionnaires?
Experience questionnaire automation here: https://vanta.com/grcacademy
-----------
Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!
Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e43&utm_campaign=courses
#cmmc #nist #cybersecurity
Your MSP could be a CMMC disaster. 💥💣💥
I wish I was joking.
In this episode I speak with Joy Beland about the critical role IT Managed Service Providers (MSPs) play in the CMMC space and why so many of them will cause their clients to fail their CMMC assessments.
Here are some of the highlights:
Joy is the Vice President of Cybersecurity Compliance at Summit 7 and brings over 20 years of experience as a former MSP owner. Summit 7 is a specialized MSP exclusively supporting defense contractors.
If you use an MSP, don't just assume that everything is OK and your MSP has it all covered.
It's highly likely that they do NOT and you'll FAIL your CMMC assessment because of them.
There are some great CMMC-focused MSPs out there, but the majority of MSPs have NO BUSINESS supporting defense contractors.
Choose wisely!
What stood out most to you? Whatever your thoughts are, feel free to let me know in the comments!
Follow Joy on LinkedIn: https://www.linkedin.com/in/joy-belinda-beland/
Summit 7 website: https://www.summit7.us/
-----------
Thanks to our sponsor Vanta!
Want to save time filling out security questionnaires?
Experience questionnaire automation here: https://vanta.com/grcacademy
-----------
Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!
Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e42&utm_campaign=courses
Should you NEVER pay after a ransomware attack?
In this episode I speak with Frank Riccardi about cybersecurity in healthcare and the event that triggered much more cyber accountability for the C-suite.
Here are some of the highlights:
Frank is a former C-level executive with 25 years of experience developing compliance and privacy programs for large healthcare systems comprised of hospitals, physician practice groups, urgent care centers, and other healthcare organizations.
I really enjoyed Frank's description of shadow IT! I always thought of an employee who is using an unauthorized application, but I never thought of it from the standpoint of an acquisition/merger.
What stood out most to you? Whatever your thoughts are, feel free to let me know in the comments!
Follow Frank on LinkedIn: https://www.linkedin.com/in/frank-riccardi-261831b1/
Frank's Book (Mobilizing the C-Suite: Waging War Against Cyberattacks): https://www.amazon.com/Mobilizing-C-Suite-Waging-Against-Cyberattacks/dp/1637424248/
-----------
Thanks to our sponsor Vanta!
Want to save time filling out security questionnaires?
Experience questionnaire automation here: https://vanta.com/grcacademy
-----------
Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!
Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e41&utm_campaign=courses
#cybersecurity #healthcare #hospital #informationtechnology
Should you fire your MSP?!? 🔥🔥🔥
In this episode, I speak with cybersecurity attorney Sarah Anderson about how to evaluate IT Managed Service Providers and how businesses can protect themselves when relying on them.
Here are some of the highlights:
Sarah is the owner of SWA Law LLC and also serves in U.S. Army Reserves as a Lieutenant Colonel.
She has been involved in more than 100 cyber incident responses throughout her career and also represents public and private entities in regulatory compliance, cybersecurity practices, and technology contract negotiations.
If you are relying on an MSP to manage your IT and security, you won’t want to miss this!
As Sarah said, not all MSPs are created equally. Many MSPs have such poor security practices they WILL get you hacked.
Encourage your MSP to join MSPCyberX! It's a nonprofit focused on elevating the security of MSPs: https://www.mspcyberx.com/
Follow Sarah on LinkedIn: https://www.linkedin.com/in/sarah-anderson-lacyberlawblog123/
Legally Cyber website: https://www.legallycyber.com/
Sarah's cybersecurity course for lawyers: https://courses.sprouteducation.com/item/cybersecurity-basics-lawyers-653403
-----------
Thanks to our sponsor Vanta!
Want to save time filling out security questionnaires?
Experience questionnaire automation here: https://vanta.com/grcacademy
-----------
Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!
Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e40&utm_campaign=courses
#msp #informationtechnology #cybersecurity #cmmc
SOC 2 isn't the only SOC out there! 🧦
In this episode Cera Adams breaks down these SOC reports and what to expect in a SOC audit!
Here are a few highlights from this episode:
Cera is the Director of IT Assurance Services and leads OCD Tech's SOC 2 and IT Audit Practices. She has more than 20 years of experience in information security!
I've spent most of my career working in the NIST cybersecurity space, so this was very interesting to me!
I thought that the SOC 3 report was interesting, especially since many other frameworks don't have an equivalent.
What were your takeaways? What is your best SOC pun? Let me know in the comments!
Follow Cera on LinkedIn: https://www.linkedin.com/in/ceraadams/
OCD Tech Website: https://ocd-tech.com/
-----------
Thanks to our sponsor Vanta!
Want to save time filling out security questionnaires?
Experience questionnaire automation here: https://vanta.com/grcacademy
-----------
Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!
Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e39&utm_campaign=courses
#soc2 #cybersecurity #informationsecurity
Do you use Android at work, but don't really understand it?
In this episode Hahna Kane Latonick teaches an Android cybersecurity masterclass for cyber GRC teams:
Here are a few highlights from this episode:
Hahna is the Director of Security Research at Dark Wolf Solutions. Some of her focuses include Android reverse engineering and exploit development. She has been featured on national media outlets including Fox Business News, ABC News, and many others!
Too often companies integrate mobile devices at work without truly understanding how they work and the risks involved.
Hahna explained these concepts so well! And of course, we had some back and forth on what is more secure, Android or Apple.
I really enjoyed this episode and learned more about Android myself! What were your takeaways?
Follow Hahna on LinkedIn: https://www.linkedin.com/in/hahnakane/
Dark Wolf Solutions Website: https://darkwolfsolutions.com/
Android Security Research Playbook: https://asrp.darkwolf.io/
-----------
Thanks to our sponsor Vanta!
Want to save time filling out security questionnaires?
Experience questionnaire automation here: https://vanta.com/grcacademy
-----------
Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!
Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e38&utm_campaign=courses
#android #cybersecurity #informationsecurity
Introducing the Penn State Whistleblower.
In this episode, the whistleblower explains how he tried to stop Penn State from misrepresenting their NIST 800-171 compliance to the DoD and what he has faced since he blew the whistle!
Whistleblower attorney Julie Bracker also shares what the media got wrong in this case and the latest on the Georgia Tech FCA case!
Here are a few highlights from this episode:
- Hear directly from the whistleblower in this False Claims Act case
- What the media got wrong
- Recommendations to universities
- Advice for other whistleblowers
Matthew Decker was the Chief Information Officer at the Applied Research Laboratory at Penn State from 2015 until 2023 and the interim Vice Provost and CIO responsible for all of Penn State from January 2016 until September 2016. Matthew currently serves as the Chief Data and Information Officer at NASA’s Jet Propulsion Laboratory since 2023.
It was fascinating to learn that the university assumed compliance with their own AD95 security policy meant they were automatically compliant (at least to some measure) with NIST 800-171. This is a great reminder that the details always matter!
Special thanks to Matt for sharing his story with us, and to Julie Bracker for coordinating this interview!
Follow Julie on LinkedIn: https://www.linkedin.com/in/juliekeetonbracker/
Bracker & Marcus LLC Website: https://www.fcacounsel.com/
Connect with Matt on LinkedIn: https://www.linkedin.com/in/matt-decker-cio/
Whistleblower's Handbook: https://www.amazon.com/New-Whistleblowers-Handbook-Step-Step/dp/1493028812/
-----------
Thanks to our sponsor Vanta!
Want to save time filling out security questionnaires?
Experience questionnaire automation here: https://vanta.com/grcacademy
-----------
Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!
Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e37&utm_campaign=courses
#whistleblower #cmmc #cybersecurity
Confused about Microsoft 365 and DFARS/CMMC compliance?
In this episode, I speak with Richard Wakeman, Chief Architect for cybersecurity of Aerospace & Defense @ Microsoft!
We discuss the history of the government clouds, the need behind GCC and GCC High, and much more!
Here are some highlights:
Richard is a wealth of knowledge, and I have personally benefited from his compliance blog articles since at least 2020!
If you are currently operating in the Microsoft cloud or are trying to decide which Microsoft cloud to buy, you won't want to miss this!
Were you aware that GCC High isn't FedRAMP authorized yet? What about Microsoft 365 commercial not being compliant with DFARS 7012?
Whatever your thoughts are, let me know!
Follow Richard on LinkedIn: https://www.linkedin.com/in/wakeman/
Microsoft Cloud compliance article: https://aka.ms/MSGovCompliance
Microsoft 365 Roadmap: https://www.microsoft.com/en-us/microsoft-365/roadmap
-----------
Thanks to our sponsor Vanta!
Want to save time filling out security questionnaires?
Experience questionnaire automation here: https://vanta.com/grcacademy
-----------
Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!
Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e36&utm_campaign=courses
From the publisher's feed