GRC Academy

Penn State Cybersecurity False Claims Scandal: Meet the Whistleblower


Listen Later

Introducing the Penn State Whistleblower.

In this episode, the whistleblower explains how he tried to stop Penn State from misrepresenting their NIST 800-171 compliance to the DoD and what he has faced since he blew the whistle!

Whistleblower attorney Julie Bracker also shares what the media got wrong in this case and the latest on the Georgia Tech FCA case!

Here are a few highlights from this episode:

- Hear directly from the whistleblower in this False Claims Act case

- What the media got wrong

- Recommendations to universities

- Advice for other whistleblowers

Matthew Decker was the Chief Information Officer at the Applied Research Laboratory at Penn State from 2015 until 2023 and the interim Vice Provost and CIO responsible for all of Penn State from January 2016 until September 2016. Matthew currently serves as the Chief Data and Information Officer at NASA’s Jet Propulsion Laboratory since 2023.

It was fascinating to learn that the university assumed compliance with their own AD95 security policy meant they were automatically compliant (at least to some measure) with NIST 800-171. This is a great reminder that the details always matter!

Special thanks to Matt for sharing his story with us, and to Julie Bracker for coordinating this interview!

Follow Julie on LinkedIn: https://www.linkedin.com/in/juliekeetonbracker/

Bracker & Marcus LLC Website: https://www.fcacounsel.com/

Connect with Matt on LinkedIn: https://www.linkedin.com/in/matt-decker-cio/

Whistleblower's Handbook: https://www.amazon.com/New-Whistleblowers-Handbook-Step-Step/dp/1493028812/

-----------

Thanks to our sponsor Vanta!

Want to save time filling out security questionnaires?

Experience questionnaire automation here: https://vanta.com/grcacademy

-----------

Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!

Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e37&utm_campaign=courses

#whistleblower #cmmc #cybersecurity

...more
View all episodesView all episodes
Download on the App Store

GRC AcademyBy Jacob Hill

  • 5
  • 5
  • 5
  • 5
  • 5

5

4 ratings


More shows like GRC Academy

View all
Security Now (Audio) by TWiT

Security Now (Audio)

2,003 Listeners

Intelligent Machines (Audio) by TWiT

Intelligent Machines (Audio)

777 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

638 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,001 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

175 Listeners

Hacking Humans by N2K Networks

Hacking Humans

313 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

188 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

73 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

134 Listeners

Cyberspin by Redspin

Cyberspin

2 Listeners

Sum IT Up: CMMC News Roundup by Summit 7

Sum IT Up: CMMC News Roundup

14 Listeners

GRC & Cyber Security Podcast by SureCloud

GRC & Cyber Security Podcast

3 Listeners

Climbing Mount CMMC by Bobby Guerra

Climbing Mount CMMC

2 Listeners

CMMC Compliance Guide by CMMC Compliance Guide

CMMC Compliance Guide

0 Listeners

CUI Hotline: Live CMMC Q&A by Summit 7

CUI Hotline: Live CMMC Q&A

0 Listeners