by Shawn Duffy | Feb 11, 2026 | Cybersecurity, Blog, CMMC, DFARS, MSP, Penetration Testing, Risk assessment, Risk Management, Security, Security Awareness Training, Vulnerability
When people think about cybersecurity breaches, they usually picture a sudden, dramatic moment where the screen goes dark, the ransom note appears, and the phones light up, amplifying the disaster. More times than not, most breaches don’t start that way. They begin...
by Shawn Duffy | Oct 16, 2024 | CMMC, Blog, CMMC 2.0, DFARS
Now that the final rule for CMMC 2.0 was released last Friday and hit the federal register yesterday, understanding CMMC is more important than ever, especially if you’re a government contractor bidding on contracts. 3 years ago, I wrote an article about CMMC Acronym...
by Shawn Duffy | Jun 19, 2023 | Blog, CMMC, Compliance, Continuous Monitoring, DFARS, Featured, Security Awareness Training, SPRS
If you are a prime or subcontractor to the DOD, the DFARS compliance requirement is something you already know. We have been discussing “adequate security” from clause 7012 for some time now. Your service provider may not be able to assess how close you...
by Shawn Duffy | Nov 9, 2021 | CMMC, Assessments, Blog, CMMC 2.0, Department of Defense, DFARS, DOD, News, POA&M, SPRS, Vulnerability
As you may have seen last week, the new CMMC 2.0 has been released, which reverts us back to the NIST 800-171 set of security controls and families. It also allows for both a Plan of Actions & Milestones (POA&M) and self-assessments. This is great news for...