|
Welcome to the WPI Cyber Newsletter, a monthly publication from the Wisconsin Procurement Institute (WPI), Wisconsin's Apex Accelerator
If your organization needs assistance meeting Federal or Department of Defense cyber security requirements, contact Marc Violante, Director of Federal Market Strategies at marcv@wispro.org, or Matt Frost, Government Contract Specialist at mattf@wispro.org
| | |
DoD Cybersecurity Resources for Small Business
The Department of the Air Force (DAF) Chief Information Security Officer’s (CISO) Blue Cyber Education Series for Small Businesses provides free and open-to-the-public cybersecurity information and support. More information can be found at - https://www.dafcio.af.mil/CISO/Small-Business-Cybersecurity-Information/
The Defense Acquisition University (DAU) hosts the DAU Cyber Solutions program with weekly small business cybersecurity acquisition webinars on topics such as CMMC, Cyber Incident Reporting and Cybersecurity for Contracts. More information can be found at – www.dau.edu/events
| | |
DIBBS users – Important Reminder about the presence of CUI
The inclusion of the following STOS – standard text objects provides notice that the solicitation will result in a contract, task order, or delivery order that involves CUI. If STO RD002 - covered defense information applies, or RD003 – covered defense information potentially applies, or RQ032 - export control of technical data is included, the requirements in DFARS 252.204-7012, 252.204-7019 and 252.204-7020 must be met. Failure to comply may result in cancellation of automated purchase orders.
See page 2 in the Master Solicitation: https://www.dla.mil/Portals/104/Documents/J7Acquisition/MasterSolicitation4ASAcqRev-100_April_24_2025.pdf
| | |
Don’t Get Hooked!
NSA's no-cost DIB cybersecurity services can help protect against targeted phishing attempts.
Available to any company with an active DOD contract or access to non-public DOD information.
GET STARTED TODAY!
https://nsa.gov/ccc
| | |
Dept. of Transportation: Wisconsin DMV warns consumers of latest phishing scam
The Wisconsin Department of Transportation (WisDOT) Division of Motor Vehicles (DMV) is warning consumers of another phishing scam where scammers are texting and pretending to be from WisDOT DMV to get individuals to click on fraudulent links or reveal personal information.
This recent wave warns of a “final notice” or of an unspecified “unpaid traffic violation.” Some scams duplicate the look of official WisDOT content. These are not from WisDOT or DMV.
https://www.wispolitics.com/2025/dept-of-transportation-wisconsin-dmv-warns-consumers-of-latest-phishing-scam/
| | |
FORBES C-Suite CIO
Take note of the statistics concerning scam emails
“While you may be conducting trainings on email safety and continually testing employees with fake scam emails, the scammers are still successful. By monitoring activity in 1,400 organizations’ email accounts, Abnormal found a 44.2% engagement rate with these fake emails. They were some of the most often replied and forwarded emails throughout company inboxes, with large companies’ employees responding and forwarding them 72% of the time. And the vast majority of these incidents—98.5%—were not reported to the IT department.”
Of note: Research conducted by Abnormal found – “It’s a difficult problem to solve. Abnormal found that most of the engagement with scam emails came from more entry-level employees, who are likely unaware of the extent of phishing emails and company processes.”
Forbes C-Suite CIO, June 12, 2025
| | |
How to conduct an effective post-incident review
Mitigation and remediation aren’t the endpoints of incident response. Having a structured process to analyze and learn from a cybersecurity incident once it has been resolved is paramount to improving security operations.
The following article addresses topics such as – capture information while details are fresh; establish a timeline; ask what happened and why it happened – root cause analysis; evaluate team performance and identify training gaps; identify business impacts.
These reviews are important tools for capturing data essential to strengthening cybersecurity programs.
https://www.csoonline.com/article/4009438/how-to-conduct-an-effective-post-incident-review.html
| | |
You can’t protect it if you don’t know what assets you have!
System Security Plans need to identify and include all assets. Identifying all assets is also critical for determining the Scope of required DoD assessments.
| | |
73% of CISOs admit security incidents due to unknown or unmanaged assets
“As IT infrastructures become increasingly complex, so do the attack surfaces. Many companies are doing too little to contain the risks.
Only those who know their attack surfaces can defend against them effectively. What seems like a truism, however, appears to be causing problems for many companies.”
See: https://www.csoonline.com/article/3980431/more-assets-more-attack-surface-more-risk.html
| | |
Understanding Identity & Access Management
Many organizations still rely primarily on firewalls, antivirus software, and network security measures. However, the real battleground for cybersecurity has shifted from the perimeter to the identity layer.
Cyber attackers now increasingly target individuals through tactics like phishing, social engineering, credential stuffing, and insider threats. Once they gain access to a person’s identity, they can cause significant damage across an organisation’s data and systems.
This makes Identity & Access Management (IAM) a crucial component of modern cybersecurity. It acts as the organisation’s digital front door, controlling who has access to what, and when.
https://www.cybersecurityintelligence.com/blog/understanding-identity-and-access-management-8460.html
| | |
Fake resumes targeting HR managers now come with updated backdoor
"The recruiters and hiring managers who work in HR departments are often considered to be the weak point in an organization by attackers, as the very nature of their job means that they must regularly open email attachments (such as resumés and cover letters) emailed to them from external and unknown sources, including job candidates and hiring agencies," said the report.
Typically, a malicious message in this campaign contains a link, supposedly to allow the manager to download the job seeker's resumé from an external site. If the manager clicks the link, they are taken to an actor-controlled website from which the recruiter can download a (decoy) resumé. On this site, the user must check a CAPTCHA box, a precaution that helps the site bypass automatic scanners.
https://www.csoonline.com/article/3977803/fake-resumes-targeting-hr-managers-now-come-with-updated-backdoor.html
| | |
FBI Warns of Deepfake Messages Impersonating Senior Officials
“The FBI on Thursday issued a warning to the public after investigating a malicious campaign targeting former senior US federal or state government officials with deepfakes.
The campaign, the agency says, relies on text messages and AI-generated voice messages impersonating senior US officials, two techniques known as smishing and vishing.
After establishing communication with the victims, threat actors send malicious links allegedly transitioning the conversation to a different messaging platform, but aimed at serving malware or harvesting credentials to gain access to the victims’ personal accounts.”
There are three suggestions in this article.
1.“If you receive a message claiming to be from a senior US official, do not assume it is authentic,”
2. “also verify the email address, contact information, and spelling in correspondence, find small imperfections in images and videos, carefully listen to the tone and word choice to identify voice cloning”
3. “Create a secret word or phrase with your family members to verify their identities,”
https://www.securityweek.com/fbi-warns-of-deepfake-messages-impersonating-senior-officials/
https://www.ic3.gov/PSA/2025/PSA250515
| | |
DLA MIGRATION TO THE DOD365 INTEGRATED PHONE SYSTEM DIPS
DLA is in the process of migrating to the DoD365 Integrated Phone System (DIPS). Therefore, the phone numbers for most DLA employees are changing due to this transition. In the interim, please utilize email for contacting POCs at DLA in lieu of phone numbers on solicitations, orders, websites, etc. as most phone numbers have changed due to the new phone system.
Posted: 06-02-2025
| | If your organization needs assistance meeting Federal or Department of Defense cyber security requirements, contact Marc Violante, Director of Federal Market Strategies at marcv@wispro.org, or Matt Frost, Government Contract Specialist at mattf@wispro.org | | |
Announcing New Sessions
Previously Cyber Fridays, Now Thursdays
If you are currently, or are planning to be, a contractor or subcontractor supporting the Defense Industrial Base (DIB) you are required to comply with the newly finalized CMMC requirements.
Registration and more information can be found at wispro.org/wpi-events/featured-webinars
| | -
Be sure to follow WPI on social media (Facebook, LinkedIn, X) for regular updates on events, news and opportunities.
| |
WPI 10437 Innovation Dr. Suite 320, Milwaukee, WI 53226 414-270-3600
| | | | |