|
Welcome to the WPI Cyber Newsletter, a monthly publication from the Wisconsin Procurement Institute (WPI), Wisconsin's Apex Accelerator
If your organization needs assistance meeting Federal or Department of Defense cyber security requirements, contact Marc Violante, Director of Federal Market Strategies at marcv@wispro.org, or Matt Frost, Government Contract Specialist at mattf@wispro.org
| | |
Cybersecurity Resources for Suppliers
To enhance DLA's cybersecurity and better protect DoW information, the Cybersecurity Maturity Model Certification (CMMC) Program was created to empower Vendors to align with DoW cybersecurity requirements in order to work with the Government.
The links on this page lead to resources outside of DLA's Office of Small Business Programs.
The content is informational only and should not be interpreted as being definitive, all-inclusive or an endorsement, sanction, approval, or authorization by DLA.
Updated Last: 12/12/2025
| | |
What makes a STRONG password?
If you cringe or mumble “what?” when the password you entered is rejected, you are on the right path. Passwords are not supposed to be easy to remember or construct. They also should not be easy to guess, be a word in the dictionary or a commonly used phrase such as a trademark line. Password – Admin – 123456 and others are easy to remember but are also easy to guess. These types of Passwords are viewed as being WEAK. WEAK passwords provide little protection. WEAK passwords might allow a stranger to sit at your desk, make a few guesses and voila access your system.
Remember WEAK passwords may be convenient and easy to remember but they also reduce the security of a system by creating a less secure entry point.
Passwords should be complex. The complexity of a password is defined by the number of unique characters used to create the password and its length. The more character sets that are used, the more options for each password character. Numbers (0 - 9) are a character set as are Lower case letters (a – z), Upper case letters (A – Z) and special characters ( !, @, #, etc), this varies by system but generally there are 32 options..
It would be one thing to guess a single number (0 – 9). There are only 10 choices. However, if password character can be selected from multiple character groups, the number of options increases.
Numbers ( 0 – 9 ) – 10
Lower case letters ( a-z) – 26
Upper case letters (A-Z) – 26
Special characters (eg. !,%,^, …) – 32 Note: 32 is a common number; each system may have its own requirements.
Using these four-character groups increases the number of options to 94 (– 10 + 26 + 26 + 32) for each password character.
Many systems establish a minimum number of characters for a password. Some may require eight characters and others may require more, maybe – 15. Does the number of characters make a real difference?
Password length: character sets ( numbers, lowercase, uppercase, special characters) Calculation and table created using MS Copilot.
| | |
It’s easy to see that password length works for us and against us. Password length makes for a stronger password which is more secure and more difficult to guess (crack). Longer passwords are also more difficult to remember. It’s one thing to remember your dog’s name Sparky or $parkee. It’s another issue to remember - a7G!kP (AI generated) which includes lower case, upper case, number and special characters. What about a passphrase such as Sparky runs like a bow-legged turtle!?
When asked about Password strength, here is MS Copilot’s response which is just stating the obvious.
Strength Factors:
-
Length: It’s over 30 characters long, which massively increases the number of possible combinations. The complexity could be further increased by using more Upper Case letters, or replacing the S with the $ or including quotes for “bow-legged”
- Character Variety:
- Uppercase: S
- Lowercase: most of the phrase
- Special character: !
- Spaces: add complexity (if allowed by the system)
-
Unpredictability: It’s a unique phrase, not a common quote or dictionary phrase, making it hard to guess.
Also, if allowed by your system, such a Password - Passphrase is more easily remembered than - a7G!kP
So let’s make 2026 the year of the STRONG password!!!!
| | |
Five Cybersecurity Predictions for 2026: Identity, AI, and the Collapse of Perimeter Thinking
The perimeter is gone. Credentials are no longer sufficient. And security can no longer rely on static controls in a dynamic threat environment.
The following are two thoughts from this article.
“By 2026, deepfake technology will be good enough—and cheap enough—to convincingly impersonate executives, IT administrators, and even trusted vendors. Video and voice will no longer be considered reliable proof of identity.”
“Regulatory pressure will continue to increase, but by 2026 it will be clear that compliance does not equal resilience. Many organizations that “checked the boxes” on frameworks and audits will still suffer material breaches due to identity-based attacks that fall outside traditional controls.”
https://www.securityweek.com/five-cybersecurity-predictions-for-2026-identity-ai-and-the-collapse-of-perimeter-thinking/
| | |
CBP Moves Toward Quantum Readiness in 2026 Push
The U.S. Customs and Border Protection (CBP) has big plans for quantum technology next year, with a top agency official saying Tuesday that the agency is “hitting that sweet spot” in its progress toward quantum readiness.
In the new year, the agency tasked with securing the nation’s borders will be moving forward with a post-quantum cryptography (PQC) project, Ed Mays, deputy assistant commissioner for infrastructure and support services and chief enterprise infrastructure officer, said while speaking at the SAP Public Sector Summit in Washington.
See: https://meritalk.com/articles/cbp-moves-toward-quantum-readiness-in-2026-push/
| | |
Why is post quantum computing – “a thing?”
Quantum computing is real and in the near future, it will exit the labs and become the next source of computing. However, quantum computing isn’t just a little bit better, or a little bit faster than our current fastest computing platforms. It is lightning fast. Quantum computers will be able to solve what have been previously unsolvable problems or problems that would take thousands of years.
Online transactions – email and online shopping rely upon cryptography. It is the math of current cryptography that to date has made breaking the codes that drive business all but impossible; even when using the current fastest supercomputers.
Quantum computing will provide the tools to break these codes. When this happens, emails will not be secure, web connections will not be secure and financial transactions will no longer be secure. It’s easy to see that quantum computing will create a problem.
When quantum computing hits the market, current transactions will be at risk. This is a given.
What about prior transactions and communications? They can also be at risk under the concept of harvest now and decrypt later. This could be an issue for individuals, businesses and governments.
NIST has published post-quantum algorithms. See: https://csrc.nist.gov/projects/post-quantum-cryptography
| | |
Senators want US construction firms to detail use of DJI drones in government contracts
WASHINGTON, Dec 18 (Reuters) - Two U.S senators on Thursday asked several U.S. construction companies to detail the use of Chinese-made DJI drones in government contracts and at sensitive national security facilities, saying the issue raised national security concerns.
Democratic senators Maggie Hassan and Gary Peters in letters to Hensel Phelps, Brasfield & Gorrie, and the Bechtel Corporation sought answers on the companies' relationships with DJI, citing reports about DJI drone use by the government contractors.
https://www.reuters.com/world/us/senators-want-us-construction-firms-detail-use-dji-drones-government-contracts-2025-12-18/
Note: The concern of information security around DJI drones is similar to the issues covered by FAR 52.204-24, 52.204-25 and 52.204-26 . In essence the concern is that these drones which are manufactured by a Chinese company may be able to transmit or disclose sensitive data to other than the user.
| | If your organization needs assistance meeting Federal or Department of Defense cyber security requirements, contact Marc Violante, Director of Federal Market Strategies at marcv@wispro.org, or Matt Frost, Government Contract Specialist at mattf@wispro.org | | |
Announcing New Sessions
Previously Cyber Fridays, Now Thursdays
If you are currently, or are planning to be, a contractor or subcontractor supporting the Defense Industrial Base (DIB) you are required to comply with the newly finalized CMMC requirements.
Registration and more information can be found at wispro.org/wpi-events/featured-webinars
| | |
NDIA CMMC Academy
January 28, 2026
Pewaukee, WI
The NDIA CMMC Academy is your roadmap to staying eligible for federal and Department of War (DoW) contracts. Phase 1 implementation is underway, and new clauses are moving into prime and subcontractor agreements. If you touch federal work in any part of the supply chain, now is the moment to act.
Join NDIA’s Cybersecurity Division and the Great Lakes’ Chapter for a practical briefing on what the regulation includes and what you must do to bid, win, and perform under DoW solicitations.
Registration & More Information
| | |
18th Annual
End of Year Federal Contractor Update
January 29, 2026
Pewaukee, WI
Join Wisconsin’s Federal Government contractors and subcontractors for this annual event. Briefings during the event will provide an overview of the current Federal contracting environment as well as highlight up and coming trends for future business opportunities.
Registration & More Information
| | -
Be sure to follow WPI on social media (Facebook, LinkedIn, X) for regular updates on events, news and opportunities.
| |
WPI 10437 Innovation Dr. Suite 320, Milwaukee, WI 53226 414-270-3600
| | | | |