November 2025

Facebook  Linkedin  X

Welcome to the WPI Cyber Newsletter, a monthly publication from the Wisconsin Procurement Institute (WPI), Wisconsin's Apex Accelerator


If your organization needs assistance meeting Federal or Department of Defense cyber security requirements, contact Marc Violante, Director of Federal Market Strategies at marcv@wispro.org, or Matt Frost, Government Contract Specialist at mattf@wispro.org

NEWS & UPDATES

CMMC is here – are you ready?


WPI is ready to assist!


On November 10, CMMC requirements became effective. What does this mean?


“The CMMC Program does not alter any separately applicable requirements to protect FCI or CUI, including those requirements in accordance with 48 CFR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems, or covered defense information in accordance with 48 CFR 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, or any other applicable information protection requirements.”


“The CMMC Program provides a means of verifying implementation of the security requirements set forth in 48 CFR 52.204-21, NIST SP 800-171 R2, and NIST SP 800-172 Feb2021, as applicable.”


These requirements are being implemented in four phases.

  • Phase 1 - began November 10, 2025
  • Phase 2 - begins November 10, 2026
  • Phase 3 - begins November 10, 2027
  • Phase 4 - begins November 10, 2028

 

The following applies today -- “all DoD contract and subcontract awardees that will process, store, or transmit information, in performance of the DoD contract, that meets the standards for FCI or CUI on contractor information systems” will be required to comply with 32CFR §170.


Phase I requirements include:

  • POAMs are no longer authorized.
  • Companies must attest that they have met all required security controls for Level 1-self or Level 2-self.   See: 32 CFR §170.24 CMMC Scoring Methodology.
  • SPRS updates must reflect this status.
  • Affirmations are required. See: 32 CFR §170.22 Affirmation
  • CMMC requirements apply to prime contractors and subcontractors throughout the supply chain at all tiers that will process, store, or transmit any FCI or CUI .   See: 32 CFR §170.22 Application to subcontractors
  • Additionally –
  • DoD may, at its discretion, include the requirement for CMMC Status of Level 1 (Self) or Level 2 (Self) for applicable DoD solicitations and contracts as a condition to exercise an option period on a contract awarded prior to the effective date.
  • DoD may also, at its discretion, include the requirement for CMMC Status of Level 2 (C3PAO) in place of the Level 2 (Self) CMMC Status for applicable DoD solicitations and contracts.

 

References:

 

For questions concerning these requirements or assistance with implementation of these requirements, please contact WPI at 414-270-3600

The Dark side of AI –

 

Chinese hackers used Anthropic's AI agent to automate spying


Suspected Chinese operators used Anthropic's AI coding tool to target about 30 global organizations — and had success in several cases, the company said Thursday.


Why it matters: This is the first documented case of a foreign government using AI to fully automate a cyber operation, Anthropic warned.

  • Anthropic said the campaign relied on Claude's agentic capabilities, or the model's ability to take autonomous action across multiple steps with minimal human direction.


https://www.axios.com/2025/11/13/anthropic-china-claude-code-cyberattack

AI Is Supercharging Phishing: Here’s How to Fight Back


AI has given cybercriminals the ability to operate like Fortune‑500‑scale marketing departments—except their product is account takeover, data theft, and identity fraud.


Phishing continues to be one of the most widespread and effective tactics, techniques, and procedures (TTPs) in today’s cyber threat landscape. It often serves as a gateway to data breaches that can have devastating consequences for organizations and individuals alike. For example, General Dynamics, a leading aerospace and defense contractor, reported in late 2024 that a phishing attack targeting its personnel resulted in threat actors compromising dozens of employee benefits accounts.


Check out the sections titled: The New Frontier of Phishing and How Organizations Can Fight Back


https://www.securityweek.com/ai-is-supercharging-phishing-heres-how-to-fight-back/

“57% of cyberattacks in 2024 started with compromised identities.” - Varonis researchers’ conclusion


Rethinking identity for the AI era: CISOs must build trust at machine speed


Human-centered identity systems were never designed for the coming wave of autonomous AI agents. CISOs face a reckoning over how to rebuild identity systems to counter the risks.


According to Verizon’s 2025 Data Breach Investigation Report, cyber attackers have switched up their initial access vectors of choice, with stolen credentials a leading cause of data breaches, triggering 22% of all intrusions and 88% of basic web application attacks. These findings followed Varonis researchers’ conclusion that 57% of cyberattacks in 2024 started with compromised identities.


Read the article: https://www.csoonline.com/article/4089732/rethinking-identity-for-the-ai-era-cisos-must-build-trust-at-machine-speed.html

Ransomware recovery perils: 40% of paying victims still lose their data


Paying the ransom is no guarantee of a smooth or even successful recovery of data. But that isn’t even the only issue security leaders will face under fire. Preparation is key.


Two in five companies that pay cybercriminals for ransomware decryption fail to recover data as a result, according to a survey of 1,000s SMEs by insurance provider Hiscox.


The survey also revealed that ransomware remains a major threat, with 27% of businesses surveyed reporting an attack in the past year. Of those affected, 80% — which includes both insured and uninsured businesses — paid a ransom in an attempt to recover or protect critical data.


See: https://www.csoonline.com/article/4077484/ransomware-recovery-perils-40-of-paying-victims-still-lose-their-data.html


There are several excellent take-away ideas in the following article. The “ransomware economy” continues to evolve. Accordingly, tactics are also changing. Companies have prepared better but attackers have countered with new approaches and new goals.

The last paragraph captures a key element of cybersecurity and it echoes a thought expressed in this newsletter and others ---


“Cybersecurity can't be an afterthought. It is now more important than ever that organizations -- especially mid-market size and larger -- invest in and implement robust security practices, strategies, and post-incident procedures. Businesses should also consider penetration testing to resolve cybersecurity vulnerabilities before they can be exploited.”


No one pays ransomware demands anymore - so attackers have a new goal

Ransomware payments were made in around 85% of attacks in 2019. But things have changed dramatically since then. Here's why.


https://www.zdnet.com/article/no-one-pays-ransomware-demands-anymore-so-attackers-have-a-new-goal/


Looking down the road


Quantum computing is predicted to be the future. It will solve an amazing array of problems. Unfortunately, some of the problems quantum computing will be able to solve will impact just about all aspects of daily life. This article explores what may happen and the impacts.

Quantum Computing Is Coming for Your Digital Secrets


When Q-Day arrives, anything encrypted—emails, banking info, classified materials—will be up for grabs


https://thewalrus.ca/quantum-computing/

 

NIST announces Post-Quantum Encryption Standards; encourages companies to start using them


Luckily quantum computing and its potential power to solve the encryption that secures today’s information flows has been known for some time. One of the organizations studying quantum computing and its potential effect has been NIST – the National Institute for Standards and Technology. On August 13, 2024, NIST posted an article announcing its Release of the First 3


Finalized Post-Quantum Encryption Standards


One of the statements made at the end of the article was - “Go ahead and start using these three. We need to be prepared in case of an attack that defeats the algorithms in these three standards, and we will continue working on backup plans to keep our data safe. But for most applications, these new standards are the main event.” 


https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards

The books shaping today’s cybersecurity leaders


Cybersecurity leaders reveal the books that have influenced how they lead, think, and manage security in the enterprise — and their own lives.

 

https://www.csoonline.com/article/4027000/the-books-shaping-todays-cybersecurity-leaders.html

What different USB icons actually mean

Decoding the symbols you’ve seen a thousand times

 

There's a reason why manufacturers put those tiny symbols next to USB ports. And once you start paying attention, you’ll see the symbols around your USB ports in a completely different way.

 

https://www.makeuseof.com/usb-ports-symbols-icons-meaning

If your organization needs assistance meeting Federal or Department of Defense cyber security requirements, contact Marc Violante, Director of Federal Market Strategies at marcv@wispro.org, or Matt Frost, Government Contract Specialist at mattf@wispro.org

OTHER NEWS

Announcing New Sessions

Previously Cyber Fridays, Now Thursdays


If you are currently, or are planning to be, a contractor or subcontractor supporting the Defense Industrial Base (DIB) you are required to comply with the newly finalized CMMC requirements. 





Registration and more information can be found at wispro.org/wpi-events/featured-webinars

January 28, 2026


NDIA CMMC Academy

Milwaukee, WI


Registration & More Information

January 29, 2026


18th Annual End of Year Federal Contractor Update

Pewaukee, WI


Registration & More Information

  • Be sure to follow WPI on social media (Facebook, LinkedIn, X) for regular updates on events, news and opportunities.
WPI 10437 Innovation Dr. Suite 320, Milwaukee, WI 53226 414-270-3600
Newsletter Editor: Doug Clemons, dougc@wispro.org 
Facebook  Linkedin  X

Not currently a subscriber to WPI's Newsletters?

Click Here to Subscribe