Protect your data, ensure compliance, and strengthen your security posture...
The loss of sensitive data can cost a business millions of dollars and severely ...
Many organizations do not want to pay for a full-time CISO or do not know if they are ready...
The Cybersecurity Risk & Maturity Assessment (CSMA) is a gap analysis and risk assessment...
A vulnerability assessment systematically reviews security weaknesses in IT ecosystems...
A penetration test, or pen test, actively identifies, tests, and highlights your organization’s...
With the growing threat of cyberattacks and data breaches—and the potential costs...
At any time, your organization might be running hundreds of security controls...
With rapidly changing regulations, maintaining compliance isn’t just a box to check—it’s essential...
Move beyond one-time assessments. Our coaching program provides continuous...
Is your manufacturing business prepared for CMMC compliance? Learn what CMMC compliance is...
At Right Hand, we understand what it takes for companies doing work within a defense industry ...
Is your medical practice HIPAA compliant...
The National Institute of Standards and Technology (NIST), a division of the U.S. Department...
SOC is a suite of reports from the American Institute of Certified Public Accountants (AICPA)...
PCI DSS designs a set of security standards to ensure that all companies accepting...
ISO 27001 is a set of standards and requirements for an information security management...
Is your IT team stretched to the breaking point supporting your business? Have you had...
Is your in-house IT staff overworked and overburdened managing routine tasks? Do you have...
Cloud computing is transforming the way organizations buy and consume software...
Is your current IT strategy prepared for the threats that your organization faces every day? From human...
Protect your data, ensure compliance, and strengthen your security posture...
Manufacturing operations face intense competitive pressures, increasingly complex supply chains, and strict compliance requirements like CMMC and ITAR...
Healthcare providers face mounting pressures from ever-evolving technology...
Accounting firms handle sensitive financial data—from tax filings to audit...
Law firms operate under strict confidentiality obligations and face evolving...
Auto dealerships handle a wealth of customer information, from financing details...
In Oil & Gas, uptime, safety, and data integrity are paramount. Whether you’re managing offshore rigs,...
Financial institutions bear a heavy responsibility: they hold sensitive client information and manage...
In the insurance sector, safeguarding sensitive policyholder information is essential—not just to meet...
Auto dealerships handle a wealth of customer information, from financing details...
Small and medium-sized businesses are the backbone of our economy, but they often face...
Protect your data, ensure compliance, and strengthen your security posture...
The loss of sensitive data can cost a business millions of dollars and severely ...
Many organizations do not want to pay for a full-time CISO or do not know if they are ready...
The Cybersecurity Risk & Maturity Assessment (CSMA) is a gap analysis and risk assessment...
A vulnerability assessment systematically reviews security weaknesses in IT ecosystems...
A penetration test, or pen test, actively identifies, tests, and highlights your organization’s...
With the growing threat of cyberattacks and data breaches—and the potential costs...
At any time, your organization might be running hundreds of security controls...
With rapidly changing regulations, maintaining compliance isn’t just a box to check—it’s essential...
Move beyond one-time assessments. Our coaching program provides continuous...
Is your manufacturing business prepared for CMMC compliance? Learn what CMMC compliance is...
At Right Hand, we understand what it takes for companies doing work within a defense industry ...
Is your medical practice HIPAA compliant...
The National Institute of Standards and Technology (NIST), a division of the U.S. Department...
SOC is a suite of reports from the American Institute of Certified Public Accountants (AICPA)...
PCI DSS designs a set of security standards to ensure that all companies accepting...
ISO 27001 is a set of standards and requirements for an information security management...
Is your IT team stretched to the breaking point supporting your business? Have you had...
Is your in-house IT staff overworked and overburdened managing routine tasks? Do you have...
Cloud computing is transforming the way organizations buy and consume software...
Is your current IT strategy prepared for the threats that your organization faces every day? From human...
Protect your data, ensure compliance, and strengthen your security posture...
Manufacturing operations face intense competitive pressures, increasingly complex supply chains, and strict compliance requirements like CMMC and ITAR...
Healthcare providers face mounting pressures from ever-evolving technology...
Accounting firms handle sensitive financial data—from tax filings to audit...
Law firms operate under strict confidentiality obligations and face evolving...
Auto dealerships handle a wealth of customer information, from financing details...
In Oil & Gas, uptime, safety, and data integrity are paramount. Whether you’re managing offshore rigs,...
Financial institutions bear a heavy responsibility: they hold sensitive client information and manage...
In the insurance sector, safeguarding sensitive policyholder information is essential—not just to meet...
Auto dealerships handle a wealth of customer information, from financing details...
Small and medium-sized businesses are the backbone of our economy, but they often face...
On September 12th, 2024, Right Hand Technology Group hosted another insightful Office Hours session featuring Matt Gilbert, a CMMC Assessor from Baker Tilly. This session provided clients with valuable information on navigating the Cybersecurity Maturity Model Certification (CMMC) process, including updates, practical tips, and real-world scenarios. Here’s a recap for those who couldn’t attend.
Matt Gilbert highlighted the recently proposed CMMC rules that aim to clarify contract requirements for different CMMC levels. However, there is concern about the lack of flexibility these rules provide to contracting officers. Matt discussed how contracts involving both high-risk CUI (Controlled Unclassified Information) and low-risk tasks like janitorial services might end up requiring all subcontractors, even those handling low-risk tasks, to obtain Level 2 certification. He suggested that this could increase the burden on small contractors and limit participation, especially in services unrelated to CUI.
A new feature mentioned in the proposed rule is the introduction of a Unique Identifier (UID) for certified systems. This UID will be linked to the systems that handle CUI and must be provided during contract bidding. Matt explained that once an organization registers and gets certified, that UID becomes essential for tracking compliance throughout the contract’s lifecycle. However, he noted concerns over what constitutes a “significant” system change, such as moving from one cloud provider to another, and whether such changes would necessitate recertification.
When discussing companies with shared IT systems between a parent and subsidiary, Matt explained that if a parent company handles any CUI or security protection data on behalf of the subsidiary, they would be considered an External Service Provider (ESP) and
must be CMMC certified. He warned of potential timing challenges if certifications need to be obtained in sequence, creating a “domino effect” where the parent must be certified before the subsidiary can begin its own certification process.
A frequent question in the session was whether outsourced IT providers need to be CMMC certified. Matt clarified that if an IT provider takes possession of CUI or security protection data, they qualify as an ESP and must be certified. However, if the IT provider is simply managing on-premise systems without accessing CUI directly, they may not need certification. He emphasized that each scenario should be carefully scrutinized to ensure compliance.
One of the pressing concerns raised was the potential burden the CMMC requirements could place on small businesses. With certification costs possibly exceeding profits for certain contracts, some small businesses may opt out of bidding on DoD contracts altogether. Matt pointed out that this could result in less competition and might favor larger defense contractors. Despite the cost burden, he emphasized the importance of protecting critical information and that proper compensation should be provided for ensuring compliance.
When asked about VoIP (Voice over IP) and virtual meetings like those conducted via Teams, Matt noted that discussions involving CUI must be protected with appropriate encryption. He recommended ensuring that VoIP systems are segmented from networks handling CUI and that users follow acceptable use policies (AUPs) to avoid sharing sensitive data over non-secure channels. Additionally, any tools that interact with meetings, such as AI note-takers, should be vetted to ensure they meet compliance standards.
Start Early with Certifications: If you share systems with a parent or external provider, ensure those parties are certified first to avoid delays.
Regular Affirmations: Even though certifications last three years, consider reassessing annually, especially after major system changes, to avoid unnecessary compliance risks.
Scrutinize ESP Agreements: If using third-party IT services, ensure they meet the definition of an ESP and understand what qualifies them as in-scope for CMMC.
Keep Data Boundaries Clear: If making changes to your information systems, document them thoroughly to defend whether or not they necessitate recertification.
As CMMC continues to evolve, it’s important to stay informed about updates and best practices. Right Hand Technology Group is committed to helping organizations navigate this complex landscape.
Join us for our next Office Hours session!
We host these sessions every month to keep you informed and answer your questions directly. Don’t miss the opportunity to gain valuable insights and guidance from industry experts.
Explore comprehensive strategies for manufacturers to combat Business Email Compromise (BEC) scams, including email…
Ever Search for Managed Services Providers Near Me? Why Location Matters Searching for managed…
Explore how Microsoft 365 Copilot can revolutionize small business productivity. Learn about integration, setup,…