Cyber Compliance & Beyond Podcast Por Kratos arte de portada

Cyber Compliance & Beyond

Cyber Compliance & Beyond

De: Kratos
Escúchala gratis

Welcome to "Cyber Compliance and Beyond," a Kratos podcast that will bring clarity to compliance, helping put you in control of cybersecurity compliance in your organization. Kratos is a leading cybersecurity compliance advisory and assessment organization, providing services to both government and commercial clients across varying sectors including defense, space, satellite, financial services, and health care. Through "Cyber Compliance and Beyond," our cyber team of experts will share their insights on the latest compliance issues. We want to hear from you! What unanswered question would you like us to tackle? Is there a topic you'd like us to discuss? Or do you just have some feedback for us? Let us know on Linked and Twitter at Kratos Defense or by email at ccbeyond@kratosdefense.com.Kratos Defense & Security Solutions Ciencia Política Política y Gobierno
Episodios
  • 22 - Preparing for CMMC the Right Way: A Q&A Deep Dive
    Feb 3 2026

    In this Q&A-style episode, we revisit the CMMC landscape following the implementation of the rule and the finalization of the Title 48 procurement rule. We break down what's changed, how CMMC requirements are phased into contracts and most importantly, the types of CMMC services available to help you take your next best step.

    We dive into boundary identification and definition, gap analysis/assessment, documentation support, readiness assessments, and formal Level 2 C3PAO assessments, along with key questions you should ask service providers to avoid confusion and unnecessary costs.

    Whether you're just starting out or preparing for assessment, this episode is designed to help you better navigate CMMC confidently and with clarity.

    References

    • Episode 11 – CMMC Rollout Q&A
    • Phased Implementation of CMMC (each one year in length)
      • Phase 1: Level 1 and Level 2 self-assessments; possibility of Level 2 C3PAO
      • Phase 2: Level 2 C3PAO for initial contract award; possibility of Level 3 and Level 2 C3PAO for option year awards
      • Phase 3: Level 2 C3PAO for option year awards; Level 3
      • Phase 4: Level 3 and full implementation across all contracts
    • Key questions to ask CMMC service providers
      • Does the assessment allow me to still leverage you as a C3PAO?
      • Does the assessment mimic a full formal assessment, including all evidence collection? This is important, as some only include interviews and live demonstrations, but do not include formal evidence gathering.
      • Can I use evidence collected in one of these preparatory assessments during my formal assessment? Generally, the answer is yes, but a good rule of thumb is that the evidence shouldn't be more than 90 days old during a formal assessment.
      • Do you offer a scoped preparatory assessment? Alternatively, you may want to only cover the controls for which a POA&M is not allowed. Ask if these are a possibility. They'll save you money, time, and give you the peace of mind you're looking for.
    • Contact the Kratos CMMC team
    • Cape Endeavors
    Más Menos
    18 m
  • 21 - Managing Cyber Risk: The Insurance Component Leaders Shouldn't Overlook
    Jan 6 2026

    In this episode, we take a practical look at how cyber insurance fits into the broader world of organizational risk. While we often talk about risk from a security and compliance perspective, insurance brings its own lens, which has become increasingly important as threats evolve, and claims grow more complex.

    Today's guest, Mark Westcott, President & CEO of ACNB Insurance, breaks down the types of risks insurers care about most, how cyber policies are shaped and the key factors that influence underwriting decisions. We also explore how compliance frameworks and certifications play into premium pricing, risk scoring, and eligibility.

    Learn about:

    • The types of risks insurers prioritize—and why
    • How insurers approach cyber insurance
    • The connection between compliance standards, certifications and insurance rates
    • Core benefits of cyber insurance beyond financial protection
    • Whether regulations mandate cyber insurance and what drives adoption
    • Key questions organizations should ask when evaluating cyber coverage
    Más Menos
    40 m
  • 20 - Red Teamers and Pen Testers: Technical, Cloud and Soft Skills
    Dec 2 2025

    There's no shortage of cybersecurity tools, but most compromises don't happen because of technology failures, they happen because of a failure in organizational processes. In today's episode, we explore how penetration testing and red teaming expose the people, processes and operational weaknesses that technology alone cannot.

    We discuss why security is ultimately a people problem, why organizations struggle to identify their own blind spots and how offensive testing reveals hidden vulnerabilities that technologies alone miss.

    In today's broad ranging episode, we cover the following:

    • Penetration testing vs. red team engagements
    • What a real red team assessment looks like
    • Attack vectors that still work surprisingly well
    • Interesting "ins" from the real-world
    • The ongoing role of social engineering
    • Custom tooling vs. off-the-shelf frameworks
    • Staying current with attacker techniques
    • Finding business-logic flaws automated tools miss
    • The hardest parts of offensive security work
    • Common organizational mistakes that create risk
    • Making findings actionable for engineering teams
    • Skills the next generation of operators should build
    • Soft skills that matter in offensive security
    • How AI and cloud are changing modern red teaming
    • Underestimated attack surfaces
    • Whether offense will always outpace defense
    Más Menos
    51 m
Todavía no hay opiniones