Events
Blog
Client Dashboard

- February 2025 -

Facebook  Linkedin  X

Welcome to the WPI Cyber Newsletter, a monthly publication from the Wisconsin Procurement Institute (WPI), Wisconsin's Apex Accelerator


If your organization needs assistance meeting Federal or Department of Defense cyber security requirements, contact Marc Violante, Director of Federal Market Strategies at marcv@wispro.org, or Matt Frost, Government Contract Specialist at mattf@wispro.org

NEWS & UPDATES

Controlled Unclassified Information (CUI) associated with the Department of Defense (DoD) is well-known due to the DoD’s cybersecurity requirements and the soon-to-be fully implemented Cybersecurity Maturity Model Certification (CMMC) program. However, many agencies besides the DoD create, use, and share information that qualifies as CUI. The scope of information qualifying as CUI is extremely broad. A list of the categories of CUI can be viewed at: CUI Registry Category List.


See: https://www.archives.gov/cui/registry/category-list


Cybersecurity requirements apply to both agencies and contractors that handle and store CUI. However, implementation requirements are not uniform across all agencies. On January 15, 2025, a proposed rule was published in the Federal Register. This rule addresses the handling of CUI by both Federal agencies and contractors.


This proposed rule will likely impact a larger number of federal contractors than the DoD rule does. The resulting requirements may affect costs, compliance requirements, and other business activities. As with all proposed rules, companies are offered the opportunity to review the rule and submit comments. All comments are read and can alter the final rule.


Actions to Take:

  • Companies should review the above link to see if the type or expected types of information they may handle qualify as CUI and determine if this new rule will affect them.
  • Companies that handle or may handle CUI should then review the Proposed Rule. See: Federal Acquisition Regulation: Controlled Unclassified Information.


See: https://www.federalregister.gov/documents/2025/01/15/2024-30437/federal-acquisition-regulation-controlled-unclassified-information


  • Comments are welcome but need to be submitted by March 17, 2025, to be considered for the final rule.


To discuss this proposed rule or the comment submission process, please contact WPI at 414-270-3600 or email: APEXAccelerator@wispro.org.


A summary of the proposed rule can be viewed at: FAR Council Publishes Proposed Rule Imposing New Security Requirements on Contractors Handling CUI.


See: FAR Council Publishes Proposed Rule Imposing New Security Requirements on Contractors Handling CUI | Woods Rogers - JDSupra


The following article is from December 2024.


Just because we turned the page on the calendar doesn’t mean that hackers discarded their old book of cyber-hacks and are using a new playbook. The article mentions two weaknesses: outdated systems that do not receive security updates and systems that increase the attack surface. Note that in 2025, Microsoft will stop supporting Windows 10 on October 14, 2025. See: see: https://www.microsoft.com/en-us/windows/end-of-support. This includes providing both system and security updates. As the saying goes – Wait! There is more. Take a few minutes to review the following article. It is short but addresses several items that deserve both mention and attention. Below the article are questions that apply and links that help to answer the questions. One such question is – How do industrial control systems increase the attack surface for cybercriminals?


See: https://www.csoonline.com/article/3618133/8-biggest-cybersecurity-threats-manufacturers-face.html

A second article also addresses Attack Surface Management.


Attack Surface Management – identifying and managing the Attack Surface is an important idea. Defining the Attack Surface without taking any action may not be beneficial. The following is a longer article that addresses this important concept/issue.


For members of the Defense Industrial Base (DIB), the ideas related to Attack Surface Management (ASM) may be important as there is a relationship between Scope, which is a NIST 800-171 r2 term, and ASM.


See: https://www.securityweek.com/cyber-insights-2025-attack-surface-management/

Catch up on Malware Directions for 2025.


Cyber Insights 2025 examines expert opinions on the expected evolution of more than a dozen areas of cybersecurity interest over the next 12 months. We spoke to hundreds of individual experts to gain their insights. Here we discuss what to expect with Malware Directions.


See: https://www.securityweek.com/cyber-insights-2025-malware-directions/

Another report worth skimming is Microsoft’s SMB Trends report.


Microsoft published this report in late October 2024. The report provides good information and many sobering statistics. Here are three:

  • One in three SMBs were affected by a cyberattack.
  • Cyberattacks cost SMBs $250,000 on average and up to $7,000,000.


The following is a link to the summary:

https://www.microsoft.com/en-us/security/blog/2024/10/31/7-cybersecurity-trends-and-tips-for-small-and-medium-businesses-to-stay-protected/


Additional information can be found at the following links

  • Read the full report to learn more about how security is continuing to play an important role for SMBs.
  • Get theBe Cybersmart Kit to help educate everyone in your organization with cybersecurity awareness resources.

Cybersecurity Marketing Predictions for 2025 Business Growth


Brand awareness is vital in cybersecurity because buyers—often risk-averse professionals like CISOs, IT managers, and procurement teams—rely on trusted brands when researching tools to protect their organizations.


See: Cybersecurity Marketing Predictions for 2025 Business Growth - SecurityWeek

If your organization needs assistance meeting Federal or Department of Defense cyber security requirements, contact Marc Violante, Director of Federal Market Strategies at marcv@wispro.org, or Matt Frost, Government Contract Specialist at mattf@wispro.org

FEATURED EVENTS

SCHEDULE UPDATED – focus on CMMC – deadlines are coming up very quickly

 

 

Registration now available at

https://www.wispro.org/wpi-events/featured-webinars/cyber-fridays/

New Sessions Added


Presented by the National Contract Management Association (NCMA) Wisconsin Chapter, this webinar series covers a range of topics from market entry, sales growth, small business certifications, compliance, and more. Attendees receive 1 CPE credit for attending.

 

  • January 31 – CMMC Update – January 2024
  • February 18 – Federal Contracting: Contract Methods and Types of Contracts
  • February 19 – Mastering Federal Construction Contract Performance
  • February 26 – Understanding the US SBA and DOD Mentor Protégé Programs (MPP)


Registration now available at

https://www.wispro.org/wpi-events/featured-webinars/acquisition-hour/

OTHER NEWS
  • Be sure to follow WPI on social media (Facebook, LinkedIn, X) for regular updates on events, news and opportunities.
WPI 10437 Innovation Dr. Suite 320, Milwaukee, WI 53226 414-270-3600
Newsletter Editor: Doug Clemons, dougc@wispro.org 
Facebook  Linkedin  X

Not currently a subscriber to WPI's Newsletters?

Click Here to Subscribe