|
Welcome to the WPI Cyber Newsletter, a monthly publication from the Wisconsin Procurement Institute (WPI), Wisconsin's Apex Accelerator
If your organization needs assistance meeting Federal or Department of Defense cyber security requirements, contact Marc Violante, Director of Federal Market Strategies at marcv@wispro.org, or Matt Frost, Government Contract Specialist at mattf@wispro.org
| | |
October has been formally designated Cyber Security month what about November?
For those in the DIB or seeking to enter the DIB it seems that November 2025 should be known as CMMC month. Why? – CMMC requirements will formally begin to be entered into selected DOW contracts on November 10, 2025. CMMC requirements will continue to be rolled out over the next several years.
The most immediate impact will be on primes. However, CMMC is a flow-down clause. As such it will impact many if not all subcontractors and suppliers. On November 10, when CMMC is required by the solicitation the prime and all subcontractors/suppliers that will “use” CUI will be required to hold a formal Level 2 assessment. For contractors that will handle FCI, they will need to obtain Level 1 status.
For many contractors, there is time. For others, not being certified equates to not eligible for awards as either a Prime or sub-tier. Needless to say, the clock is ticking. Developing a cybersecurity program that satisfies the requirements takes time, takes effort, and takes support both in the forms of senior leadership and adequate budget.
This effort is not a weekend project!
If you have questions on how to get started or needed guidance moving forward reach out to WPI at 414-270-3600.
| | |
CMMC for JCP – the time to start is now!
On September 10, 2025, the Department of War (DoW) published the Cybersecurity Maturity Model Certification (CMMC) Acquisition Rule, mandating that companies handling sensitive unclassified DoW information progressively advanced cybersecurity standards based on data type and sensitivity. Under this rule, the Joint Certification Program (JCP) will gradually implement CMMC requirements from November 10, 2025, to November 10, 2028, after which contractors seeking new or renewed JCP Certification must obtain a CMMC Level 2 Certification from a Certified Third-Party Assessment Organization (C3PAO) and ensure it is uploaded to the Supplier Performance Risk System (SPRS). This certification is essential for protecting export-controlled information in line with U.S. law and the DoW Controlled Unclassified Information (CUI) Program. Resources for locating a C3PAO and learning more about CMMC are available at SPRS, DoD CUI, CMMC Marketplace, DoD CIO, and the DLA Cybersecurity Resource Center.
https://www.dla.mil/Logistics-Operations/Services/JCP/#cmmc-for-jcp
| | |
Recent developments in FCA cybersecurity enforcement for government contractors
The U.S. Department of Justice (“DOJ”) has kept busy in pursuing cybersecurity-related fraud in government contracts resulting in seven settlements. These settlements illustrate the continuing need for contractors to familiarize themselves with applicable regulations and maintain ongoing compliance.
Issues highlighted include improper reporting of SPRS scores, failure to update (maintain) SPRS scores, the critical role that the SSP plays and others such as what happens when a company is acquired.
This is an interesting article with seven short but pertinent reviews.
https://www.lexology.com/r/V0Tr5IB/00fb46f2b6
Need assistance with your cybersecurity efforts? Give WPI a call at 414-270-3600.
| | |
2025 Cyber Incident Trends What Your Business Needs to Know
Mayer Brown LLP
In this Legal Update, we highlight key trends shaping the cybersecurity landscape and offer practical recommendations to help mitigate the associated risks.
Key Developments in the Cyber Threat Landscape
You can access the article for free using this link: https://www.lexology.com/r/V0OfgfW/1f7ba7949d
| | |
Alert - Microsoft 10 Users
Microsoft 10 users, Microsoft has curtailed support for Microsoft 10 on Tuesday, October 14.
This means the software will no longer receive automatic technical and security updates.
Users will need to identify other methods of support or quickly shift to a software platform – Microsoft or other which is being supported.
Users which are DoD contactors, should note this change and update their System Security Plan and appropriate policies and procedures.
https://www.msn.com/en-us/news/technology/warning-to-microsoft-users-ahead-of-major-software-change/ss-AA1OnqZP
| | |
Alert - Businesses
Windows 10 Still on Over 40% of Devices as It Reaches End of Support
Users can continue receiving important security updates for Windows 10 by enrolling in the ESU program.
PCs running Windows 10 will continue to work, but they will become increasingly vulnerable to malware and other cyberattacks as new threats emerge and no patches are released.
For users who cannot immediately upgrade to Windows 11, Microsoft has launched the Extended Security Updates (ESU) program.
In order to enroll into the ESU program and get important security updates until October 13, 2026, consumers will be charged $30, while commercial organizations will have to pay $61 per device. The price will double each year for organizations that want ESU for up to three years.
See following article for more information. Windows 10 Still on Over 40% of Devices as It Reaches End of Support - SecurityWeek
| | |
Security Settings in Windows You’re Not Using (and Hackers Hope You Don’t Find)
These security settings are sitting right there, unused. More importantly, cybercriminals are counting on you not to find them.
This article addresses:
- Windows Sanbox – Keep suspicious files away from your system
- Core Isolation – Stops Advanced Malware in its tracks
- APP and Browser Control – Prevent Dangerous Downloads
- Controlled Folder Access – Block Ransomeware
Security Settings in Windows You’re Not Using (and Hackers Hope You Don’t Find)
| | |
NIST Publishes Guide for Protecting ICS Against USB-Borne Threats
NIST Special Publication 1334 focuses on reducing cybersecurity risks associated with the use of removable media devices in OT environments
NIST Special Publication (SP) 1334 was authored by the National Cybersecurity Center of Excellence (NCCoE) and it focuses on the use of USB flash drives, but also mentions other types of removable media such as external hard drives and CD/DVD drives.
USB flash drives are often used in OT environments to conduct firmware updates or to retrieve data for diagnostics purposes, but such devices are also often a source of malware infections.
https://www.securityweek.com/nist-publishes-guide-for-protecting-ics-against-usb-borne-threats/
| | |
Water Treatment Plants face Unique Cybersecurity Challenges
According to one EPA official, many water utilities remain unaware their systems are open to the internet. “What I have found in this year of discovery … is there is a general lack of asset awareness across the water sector,” Cole Dutton, a cybersecurity analyst within the EPA’s Office of Water, said on Tuesday during a webinar hosted by Censys. “Many of the times when we’ve performed outreach notifications, the systems just did not know that they had those devices internet-exposed,” Dutton said.
This means anyone with an internet connection can “turn off valves, turn on valves, change set points, change chemical levels,” etc., Dutton warned.
To assist with these challenges and efforts EPA published the following Checklist –
https://www.epa.gov/system/files/documents/2025-10/epa-cybersecurity-procurement-evaluation-checklist.xlsx
For more EPA cyber resources see: https://www.epa.gov/cyberwater/cybersecurity-planning
| | |
Why You Should Think Twice Before Leaving Your Porch Lights On At Night
Porch lights add a warm, welcoming ambiance to any entry way and can serve as a beacon for guests looking for your home for the first time. For weary travelers arriving home late, they are a welcome sight and light the path to the front door. Many people also believe porch lighting adds to a home's security. Authorities have long recommended lighting doorways and windows to prevent break-ins, but very few burglaries are actually deterred by outdoor lighting. In fact, according to ADT, the average burglary takes place during the day between 10 a.m. and 3 p.m. and is committed by someone who lives within a two-mile radius.
Why You Should Think Twice Before Leaving Your Porch Lights On At Night
| | |
Extortion Group Leaks Millions of Records From Salesforce Hacks
The data allegedly pertains to Albertsons, Engie Resources, Fujifilm, GAP, Qantas, and Vietnam Airlines.
The leak occurred days after the group, an offshoot of the notorious Lapsus$, Scattered Spider, and ShinyHunters hackers, claimed the theft of data from 39 Salesforce customers, threatening to leak it unless the CRM provider pays a ransom.
Salesforce, which stated that the extortion attempt is related to “past or unsubstantiated incidents”, refused to pay, and the hackers have published on their Tor-based leak site data allegedly pertaining to Albertsons, Engie Resources, Fujifilm, GAP, Qantas, and Vietnam Airlines.
The threat actors also provided links to the leaked data to paying users on a surface-web forum, and then published the data for free on another clear-net website.
https://www.securityweek.com/extortion-group-leaks-millions-of-records-from-salesforce-hacks/
| | |
If you are a company, you are a target
Fencing and Pet Company Jewett-Cameron Hit by Ransomware
Oregon-based fencing and pet solutions provider Jewett-Cameron Company was recently targeted in a cyberattack that resulted in disruption and the theft of sensitive information.
Jewett-Cameron Company says hackers stole sensitive information and are threatening to release it unless a ransom is paid.
Fencing and Pet Company Jewett-Cameron Hit by Ransomware - SecurityWeek
| | If your organization needs assistance meeting Federal or Department of Defense cyber security requirements, contact Marc Violante, Director of Federal Market Strategies at marcv@wispro.org, or Matt Frost, Government Contract Specialist at mattf@wispro.org | | |
Announcing New Sessions
Previously Cyber Fridays, Now Thursdays
If you are currently, or are planning to be, a contractor or subcontractor supporting the Defense Industrial Base (DIB) you are required to comply with the newly finalized CMMC requirements.
Registration and more information can be found at wispro.org/wpi-events/featured-webinars
| | -
Be sure to follow WPI on social media (Facebook, LinkedIn, X) for regular updates on events, news and opportunities.
| |
WPI 10437 Innovation Dr. Suite 320, Milwaukee, WI 53226 414-270-3600
| | | | |