Events
Blog
Client Dashboard

- January 2025 -

Facebook  Linkedin  X

Welcome to the WPI Cyber Newsletter, a monthly publication from the Wisconsin Procurement Institute (WPI), Wisconsin's Apex Accelerator


If your organization needs assistance meeting Federal or Department of Defense cyber security requirements, contact Marc Violante, Director of Federal Market Strategies at marcv@wispro.org, or Matt Frost, Government Contract Specialist at mattf@wispro.org

NEWS & UPDATES

CMMC is here!

It’s official, on December 16, 2024, the federal rule that authorizes the CMMC program took effect.


From a regulatory perspective, CMMC requirements are covered by two Parts of the Code of Federal Regulations (CFR). Part 32 authorizes and implements the program; this is the rule that went into effect on December 16th. In addition to the Part 32 rule there is a Part 48 rule. Part 48 may be better known as the Federal Acquisition Regulations (FAR). The Part 48 rule addresses how CMMC will be incorporated into Department of Defense Contracts. The Part 48 rule is expected to go into effect early in 2025.


What does the Part 32 Final Rule do?


This final rule published in the federal register at Federal Register :: Cybersecurity Maturity Model Certification (CMMC) Program allows the DOD to verify contractors have implemented required security measures necessary to safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).

Additionally, the mechanisms discussed in the rule allow the Department to confirm a defense contractor or subcontractor has implemented the security requirements for a specified CMMC level and is maintaining that status (meaning level and assessment type) across the contract period of performance.


CMMC Level - Assessment type and information type covered.

  • Level 1 (Assessment type: Self) required for FCI*
  • Level 2 (Assessment type: Self or C3PAO) required for CUI *
  • Level 3 (C3PAO and DIBCAC) required for highly sensitive CUI*
  • *Assessment results are uploaded to the SPRS database.


Arguably, in today’s world, cybersecurity should be an active part of every business’ culture and operations. Cybersecurity should begin with senior staff acting as champions and supporting needed initiatives. Cybersecurity should be seen as a valuable business process rather than viewed as a necessary evil.


Unfortunately, general cybersecurity efforts have shown that they are not sufficient to provide adequate protection for DoD information such as FCI and CUI. CMMC applies to primes subcontractors and suppliers at any tier when either FCI or CUI information is generated, used or stored. Therefore, companies that are either actively part of the Defense Industrial Base (DIB) or considering entering the DIB must understand their responsibilities under the CMMC program and implement and maintain the required security measures. 

FBI and CISA encourage the use of encryption apps – Really?


Typically, these government agencies would argue against the use of end-to-end encryption. Today’s encryption is strong and does what it’s supposed to do – prevent others, including government agencies from intercepting phone calls or reading texts and emails. So, when these organizations recommend the use of apps such as WhatsApp or Signal, or FaceTime on iPhones that is something to heed.


Many in business use their phones extensively not only for phone conversations but also to receive and send project information. These devices should be covered in the business’ System Security Plan (SSP) and there should be policies and procedures that address their use and what information can be stored, transmitted and/or discussed.


Companies should review the following articles and determine what changes are required to maintain the proper level of security.


FBI Warns iPhone And Android Users—Stop Sending Texts

FBI Phone Hacking Warning—You Need To Change Your iPhone Settings

We can learn from cybersecurity articles.


All articles can be informative. There are lessons to be learned, issues to ponder, questions to ask and trends to notice. For example, the following story about Starbucks highlights that – Ransomware attacks are on the rise, companies place to much trust in their supply chain partners and open source software may be convenient but convenience doesn’t equate to it being secure.


The second article asks the question what happens if your company has a cyber incident? What do you do? How do you respond? Are you prepared? Unfortunately, there are many other questions and actions that will need to be addressed.


The last article addresses a new variant of ransomware criminals who don’t hold data for ransom. They delete the data. If data is your company’s lifeblood and all the data has been destroyed, what do you do?


The article also mentions the percentage of companies that pay the ransom again both federal advice and having no-pay policies.


Strong cybersecurity doesn’t guarantee that a company can’t or won’t be affected. Needless to say, the better a company’s cyber defenses, the less likely it is to be impacted by a cyber incident.


Starbucks operations hit after ransomware attack on supply chain software vendor


Securing our world: how businesses can prepare for and recover from cyber attacks


Data deletion enters the ransomware chat; New cyber gangs are increasingly using ransomware to delete data rather than encrypt it.

If your organization needs assistance meeting Federal or Department of Defense cyber security requirements, contact Marc Violante, Director of Federal Market Strategies at marcv@wispro.org, or Matt Frost, Government Contract Specialist at mattf@wispro.org

FEATURED EVENTS

January 15


17th Annual End of Year Federal Contractor Update

In-Person | Appleton, WI

 

Join Wisconsin’s Federal contractors and subcontractors for this annual event. Briefings during the event will provide an overview of the current Federal contracting environment as well as highlight up and coming trends for future business opportunities.

Registration & More Information

January 16


Wisconsin Federal Contractor Forum

In-Person | Oshkosh, WI

 

Additional information will be posted here and at www.wifedforum.org

The focus on this year’s series is Building a CMMC Ready Program.


Registration now available at

https://www.wispro.org/wpi-events/featured-webinars/cyber-fridays/

New Sessions Added


Presented by the National Contract Management Association (NCMA) Wisconsin Chapter, this webinar series covers a range of topics from market entry, sales growth, small business certifications, compliance, and more. Attendees receive 1 CPE credit for attending.

 

  • January 22 – Federal Acquisition Regulations (FAR) Overview
  • January 28 – Service Contracts with Federal Agencies
  • January 31 – CMMC Update – January 2024
  • February 18 – Federal Contracting: Contract Methods and Types of Contracts
  • February 19 – Mastering Federal Construction Contract Performance
  • February 26 – Understanding the US SBA and DOD Mentor Protégé Programs (MPP)


Registration now available at

https://www.wispro.org/wpi-events/featured-webinars/acquisition-hour/

OTHER NEWS
  • Be sure to follow WPI on social media (Facebook, LinkedIn, X) for regular updates on events, news and opportunities.
WPI 10437 Innovation Dr. Suite 320, Milwaukee, WI 53226 414-270-3600
Newsletter Editor: Doug Clemons, dougc@wispro.org 
Facebook  Linkedin  X

Not currently a subscriber to WPI's Newsletters?

Click Here to Subscribe