Duffy Compliance 2023 Logo
  • Home
  • About
  • Services
    • Assessments
    • CMMC Compliance
    • Fractional CISO
    • Fractional Compliance Officer
  • MSPs
  • Free Resources
    • Case Studies
    • Cybersecurity Self-assessment
    • FTC Safeguards Rule Checklist
    • Incident Response Checklist
  • Blog
  • Contact
Schedule A Call

Careers

The Security Gap MSPs Are Being Asked to Fill

The Security Gap MSPs Are Being Asked to Fill

by Shawn Duffy | May 20, 2026 | Blog, Cybersecurity, MSP, Risk Management, vCISO

There’s a pattern emerging across MSP practices of all sizes. Clients who have relied on their managed service provider for IT operations are now bringing a different category of question to the table: questions about security programs, compliance frameworks,...
The Top 6 Cybersecurity Mistakes Small Businesses Make

The Top 6 Cybersecurity Mistakes Small Businesses Make

by Shawn Duffy | Mar 18, 2026 | Cybersecurity, Blog, Risk Management, Security, Vulnerability

Last month I wrote about “Quiet Warning Signs Most Organizations Miss.” I want to continue that topic by covering some of the mistakes we make as well, even with the best intentions. Many small businesses believe cybersecurity problems happen to larger...
Quiet Warning Signs Most Organizations Miss

Quiet Warning Signs Most Organizations Miss

by Shawn Duffy | Feb 11, 2026 | Cybersecurity, Blog, CMMC, DFARS, MSP, Penetration Testing, Risk assessment, Risk Management, Security, Security Awareness Training, Vulnerability

When people think about cybersecurity breaches, they usually picture a sudden, dramatic moment where the screen goes dark, the ransom note appears, and the phones light up, amplifying the disaster. More times than not, most breaches don’t start that way.  They begin...
Why Ransomware Isn’t Slowing Down and What Businesses Can Do About It

Why Ransomware Isn’t Slowing Down and What Businesses Can Do About It

by Shawn Duffy | Jan 21, 2026 | Cybersecurity, Blog, Incidence Response, Risk Management

If it feels like ransomware should be on the decline by now, you’re not alone. We all see the headlines: law enforcement takedowns of major operations, new regulations, advanced security tools. However, what we actually see is ransomware incidents continuing to rise....
That Newest & Greatest Pen Test Tool? Here’s What You Need to Know.

That Newest & Greatest Pen Test Tool? Here’s What You Need to Know.

by Shawn Duffy | Nov 19, 2025 | Blog, Artificial Intelligence AI, Cybersecurity, Penetration Testing, Risk assessment, Risk Management

Artificial intelligence has officially arrived in the world of penetration testing. It seems that every month, a new “AI-powered” security tool hits the market, promising to find vulnerabilities faster, smarter, and cheaper than traditional methods. Yet another AI pen...
Why Your MSP Shouldn’t Be Your Only Line of Defense: The Value of Independent Cybersecurity Expertise

Why Your MSP Shouldn’t Be Your Only Line of Defense: The Value of Independent Cybersecurity Expertise

by Shawn Duffy | Sep 17, 2025 | Cybersecurity, Blog, Compliance, MSP, Risk assessment, Risk Management

Most organizations today rely on a Managed Service Provider (MSP) to handle their IT needs. From setting up infrastructure to monitoring systems and ensuring business continuity, MSPs are vital to keeping operations running smoothly. Many MSPs also advertise...
« Older Entries

Recent Articles

  • AI vs. Human Support: What Small Defense Contractors Really Need 
  • 5 Reasons Why Going Cheap with CMMC May Not Be the Cheapest Solution
  • The Cyber Risk Hidden Inside GovCon M&A Deals
  • The Security Gap MSPs Are Being Asked to Fill
  • Why GovCon Companies Can’t Afford to Skip a Fractional CISO During CMMC Readiness

Featured Articles

  • Interview on WBAL-TV: Hackers Steal Sensitive Info From Baltimore SAO
  • Why Experts Hire Fractional CISOs
  • Shawn Duffy Featured in Discover Frederick: Leading Cybersecurity with National Impact
  • How to spot check where you are with DFARS / CMMC
  • How to Reduce Risk
  • Prepare for Compliance

Categories

Archives

  • About
  • Services
  • Fractional CISO
  • Fractional Compliance Officer
  • MSPs
  • Blog
  • In the News
  • Careers
  • Contact

What We Do

IT GovCons can’t compete when they struggle to meet government cybersecurity requirements.

Duffy Compliance makes it easy for them to exceed requirements and stand out in the market.

Schedule A Call
Duffy Compliance Logo

Duffy Compliance Services, LLC
New Market, MD 21774-6266
Info@duffycompliance.com
www.DuffyCompliance.com
301-865-0345

  • Follow
  • Follow

From the Blog

  • AI vs. Human Support: What Small Defense Contractors Really Need 
  • 5 Reasons Why Going Cheap with CMMC May Not Be the Cheapest Solution
  • The Cyber Risk Hidden Inside GovCon M&A Deals
  • The Security Gap MSPs Are Being Asked to Fill
  • Why GovCon Companies Can’t Afford to Skip a Fractional CISO During CMMC Readiness

© 2026 Duffy Compliance Services | All Rights Reserved | Privacy Policy | Accessibility Statement | Web Development by Design Formare Inc.