Facebook  Linkedin  X

Welcome to the WPI Cyber Newsletter, a monthly publication from the Wisconsin Procurement Institute (WPI), Wisconsin's Apex Accelerator


If your organization needs assistance meeting Federal or Department of Defense cyber security requirements, contact Marc Violante, Director of Federal Market Strategies at marcv@wispro.org, or Matt Frost, Government Contract Specialist at mattf@wispro.org

NEWS & UPDATES

CMMC


We are roughly a month closer to the full implementation of CMMC for DoD solicitations/contracts.


How are your preparations coming? Are you ready? Have you reviewed your self-assessment, and/or updated your SPRS score as required?


Have you visited the CYBER AB’s Marketplace and identified potential authorized resources? Please note, that only companies listed in the Cyber AB’s Marketplace can be relied upon to provide authoritative assistance. Beware of emailed offers that seem too good to be true. Only those resources listed on the

Cyber AB Marketplace hold the requisite training and credentials.


Need help in understanding these upcoming requirements and how to proceed – call WPI for assistance.

Cyber AB hosts Monthly Town Hall


The Cyber AB is the official accreditation body for DoD’s Cybersecurity Maturity Model Certification (CMMC) ecosystem. It is the sole authorized non-governmental partner of the U.S. Department of Defense (DoD) in implementing and overseeing the CMMC conformance regime. (cyberab.org)


Except for December, the Cyber AB hosts an hour-long town hall. The town hall is scheduled for the last Tuesday of the Month and runs from 5:00 pm to 6:00 pm CST.


Each town hall has a slightly different agenda. Topics typically include program updates, updates related to rules and rulemaking, terminology and requirements. Guests and subject matter experts often provide updates on regulations and related issues. Additionally, the calendar of national outreach events is reviewed. A portion of the town hall is open to address attendee questions asked during the town hall or emailed to the Cyber AB prior to the town hall.


Companies and individuals that are attempting to better understand the process, resources and requirements may benefit from attending.


Town Halls are archived and can be accessed at - https://cyberab.org/News-Events/Town-halls


To register for future town halls please send an email several days prior to support@cyberab.org

Cyber AB Announces Initial Appointees to new C3PAO Advisory Council


Scott Singer (Chair) CyberNINES LLC , a cybersecurity firm located in Central Wisconsin will chair this council.


The C3PAO Advisory Council is the recognized entity that will provide feedback and recommendations for Cyber AB consideration in improving assessment processes and clarifying guidance.


C3PAOs play a vital role in the assessment process. “ C3PAOs are organizations authorized by The Cyber AB to perform official CMMC assessments. They employ CMMC assessors and are responsible for conducting the assessments and issuing CMMC certifications to organizations that meet the requirements.”


The council is comprised of owners, executives, and CMMC business area leaders among the authorized CMMC Third-Party Assessment Organizations (C3PAOs) compose the Council, which serves as a recognized entity to provide feedback and recommendations for Cyber AB consideration in improving assessment processes and clarifying guidance.


For more information on the Cyber AB please visit: https://www.cyberab.org/

DoD User Agreements and Splash pages


Read these slowly and with purpose. If you are the account owner, DIBBS Super User, provide training to your subusers or have them read these requirements. Don’t just read them superficially. Read them as if the success of your business depends on understanding and complying with them. It does! Take time to learn about VPNs and VPN-like devices. Also learn about how to properly handle Export Controlled information.


Why are these actions important? Violation of these Terms and Conditions can impact National Security. The result of violation of DLA’s Terms and Conditions can be permanent denied access to DIBBS as a Prime Contractor. There can also be other consequences. All the terms and conditions are important. The following are two which if violated will result in DLA terminating your access to DIBBS. DLA’s letter will specify what is required to request reinstatement. If DLA agrees to reinstating the company, DLA will provide a new agreement for review and signature.


Super User Terms and Conditions for Access to the DLA Internet Bid Board (DIBBS) – effective 28 OCT 2024


Item #8: I agree that no user account will use any means to mask their internet usage/access to DIBBS (for example, a Virtual Private Network (VPN)). The cFolder splash page also provides this alert.

Does DLA/DoD actively monitor these sites. YES! There have been several businesses whose DIBBS access has been terminated for violating this requirement.


The critical idea behind item #8 is that the IP identify of the user cannot be masked. VPNs exist as software to help protect against cyber threats. To accomplish this, they mask the user’s IP address. Proxy servers and dynamic IP allocation are two other ways in which a user’s IP is cloaked. There may be other methods.


It doesn’t matter whether the use of one of these masking tools was intentional or innocent. If a DIBB’s user’s IP is masked DLA will Flag it, remove DIBB’s access and inform the user. In one instance, the user’s business installed a VPN on all machines. The user didn’t know they were using a VPN. In another case, a user accessed DIBBS from a UW-System campus and didn’t realize that the access point functioned as a Proxy Server. More recently, a business used their phone as an access point. The phone service provider utilized dynamic IP assignment.


The bottom line is that in each of the above scenarios, DLA identified a violation and acted to protect sensitive information. It is possible, that DLA will not agree with the company’s explanation. Access may not be reinstated.


Item 11 is also noteworthy. It states - If the address of this company, as registered in the U.S. Government System for Award Management (SAM), is a U.S. address, I agree that I will not access DIBBS outside the United States or U.S. territories without prior approval from DLA.


There have been at least three companies which have accessed DIBBS from outside the U.S. The foreign access was identified, and DLA took appropriate action.


These are very serious matters and accessing DIBBS is just one issue.


If your laptop contains Export Controlled information in an unencrypted form or using encryption that does not meet the requirements, that can be another issue. This is especially true if the laptop or phone contains ITAR information. In this case, there would most likely be a reportable Export violation.

Might Small Contractors pose greater than average cyber risks?


A joint keynote featuring Bailey Bickley, the NSA Cybersecurity Collaboration Center’s chief of industrial base defense, and AI-powered cybersecurity company Horizon3.ai CEO and cofounder Snehal Antani spotlights one of the biggest threats to large companies: the use of smaller contractors with less rigorous cybersecurity that could provide backdoor access to the bigger company’s system, Bradley writes. This means that there needs to be more attention paid to cybersecurity throughout the ecosystem that companies work with—either through automated tests of a full environment, like Horizon3.ai runs, or at the very least by extending the top-security mindset to all contractors a company works with.

Do Not Reset Your Password — FBI Issues Critical New Warning


https://www.forbes.com/sites/daveywinder/2025/08/02/do-not-reset-your-password---fbi-issues-critical-new-warning

Google Issues 3 New Security Warnings — Fast Action Needed


https://www.forbes.com/sites/daveywinder/2025/08/02/google-issues-3-gmail-security-warnings---fast-action-needed/

Landline Identify Theft


Landline identity theft is an emerging threat that gives scammers backdoor access to your accounts. 

An outdated phone number, especially a forgotten landline, can help them bypass security and drain your savings. 


Here's how it happens and how to stop it.


Link to the story: https://www.msn.com/en-us/money/personalfinance/landline-identity-theft-leads-to-major-bank-fraud/ar-AA1IIAAy

‘Quishing’ scams dupe millions of Americans as cybercriminals turn the QR code bad


  • Almost three-quarters of Americans (73%) scan QR codes without verification, and more than 26 million have already been directed to malicious sites, according to NordVPN. 
  • The FTC warned earlier this year about scanning QR codes on unexpected packages. 
  • New York City’s Department of Transportation issued a warning that scammers are posting QR codes on parking meters that are not legitimate payment links.


Note: QR codes are being widely used. While email links can be visually verified, the link associated with a QR code is often not visible. QR codes are convenient, especially for those individuals who are in a hurry. The need for speed plus the offer of convenience can create complacency and a false sense of security. QR code users Beware!


“A study this year from cybersecurity platform KeepNet Labs found that 26 percent of all malicious links are now sent via QR code. According to cybersecurity company, NordVPN, 73% of Americans scan QR codes without verification, and more than 26 million have already been directed to malicious sites.”


Read the complete article at: https://www.cnbc.com/2025/07/27/cybersecurity-scams-quishing-qr-code-consumer-risks-hackers.html

The TSA Warns Against 'Juice Jacking' at the Airport—Here's How to Protect Yourself


Your at the airport waiting for your flight. There is a call you need to make but your phone battery is low.


The urge to plug-in is overwhelming. The question is should you. Read the following article to understand what is at stake and how to protect yourself.


https://www.travelandleisure.com/what-is-juice-jacking-11756622

State of Wisconsin – Department of Transportation


Recognizing scams


Wisconsin DMV is warning consumers of common phishing scam attempts. Scammers are increasingly texting and emailing consumers, posing as Wisconsin DMV and demanding payment or personal information. These messages are not from Wisconsin DMV. Wisconsin DMV will never text you to demand payment for a service.


What to watch for:

  • Demands for money.
  • Urgency.
  • Requests for personal information.


Read more: https://wisconsindot.gov/Pages/about-wisdot/newsroom/statistics/scams.aspx


NIST Digital Identity Guidelines Evolve With Threat Landscape


The US National Institute of Standards and Technology updated its Digital Identity Guidelines to match current threats. The document detailed technical recommendations as well as suggestions for organizations.


“NIST's document highlights anti-fraud measures, "updated authentication risk and threat models to account for new attacks," and new phishing-resistant authentication options like FIDO passkeys, the agency believes will help organizations contend with the current threat landscape.”


This is the first update since 2017. Some feel that the update is overdue as threats and the threat environment have evolved over the years. In addition, AI poses a new level of threats. The main issue is how important establishing a user’s identity is.


Read more: https://www.darkreading.com/identity-access-management-security/nist-digital-identity-guidelines-evolve-with-threat-landscape


Clickjacking – what you can’t see can create security issues


Clickjacking is an attack technique in which the attacker tricks the targeted user into clicking on hidden elements on a web page. The attacker sets up a website that contains malicious buttons or other elements that are transparent and placed on top of harmless-looking elements on the page. When the victim visits the attacker’s site and interacts with these harmless-looking elements, they are actually clicking on the malicious element, unknowingly carrying out dangerous actions. 


A researcher has tested nearly a dozen password managers and found that they were all vulnerable to clickjacking attacks that could lead to the theft of highly sensitive data.


Read the article: https://www.securityweek.com/password-managers-vulnerable-to-data-theft-via-clickjacking/

If your organization needs assistance meeting Federal or Department of Defense cyber security requirements, contact Marc Violante, Director of Federal Market Strategies at marcv@wispro.org, or Matt Frost, Government Contract Specialist at mattf@wispro.org

OTHER NEWS

Announcing New Sessions

Previously Cyber Fridays, Now Thursdays


If you are currently, or are planning to be, a contractor or subcontractor supporting the Defense Industrial Base (DIB) you are required to comply with the newly finalized CMMC requirements. 





Registration and more information can be found at wispro.org/wpi-events/featured-webinars

  • Be sure to follow WPI on social media (Facebook, LinkedIn, X) for regular updates on events, news and opportunities.
WPI 10437 Innovation Dr. Suite 320, Milwaukee, WI 53226 414-270-3600
Newsletter Editor: Doug Clemons, dougc@wispro.org 
Facebook  Linkedin  X

Not currently a subscriber to WPI's Newsletters?

Click Here to Subscribe