Unauthorized Opinions 01: What's the Deal with CMMC? https://codykretsinger.com/episode?show=unauthorized-opinions&ep=1 Narrator: This is Unauthorized Opinions, part of the Threat Aware Podcast Network, where the Galactic Security Team says exactly what's on their minds. Unfiltered takes on the cybersecurity threats, trends, and stories that matter most to the people defending real organizations. Now, here's your host, Max Kurek. Max Kurek: Welcome in. We are glad you're here. I'm Max Kurek. This is Unauthorized Opinions, where we give you a completely unfiltered view of the most notable happenings in the world of cybersecurity, threats that are making headlines, industry decisions that deserve some extra scrutiny, conventional wisdom that needs to be challenged. We are covering it all and having some fun along the way. And I am absolutely thrilled to be joined by some folks who have a lot to say on these kinds of matters. Seth Loe, Galactic's President and Chief Security Officer. Cody Kretsinger is here, Director of Security Research, and Aidan Brown, security analyst from Galactic's Security Research Division. Guys, how are we feeling? Seth Loe: Feelings. Cody Kretsinger: Excited. Max Kurek: Excited, spicy. Spicy is good because this is supposed to be kind of a spicy hot takes type of show. And yeah, gotta have that excitement. So really happy to be joined by all of you guys. And even though this is episode one, we have a ton to cover today. You guys may or may not have heard nod wink, but the Pentagon dropped some pretty big news yesterday related to everyone's favorite compliance framework. So we'll get at into that here in just a bit. We're also going to have a little fun with a feature that we'll bring back from time to time, highlighting some security heroes and some security zeros. But before we do any of that, precisely because this is episode one of Unauthorized Opinions, let's spend a few minutes hearing a bit about your own security stories that people are eager to know. They want to hear about you. So, Without making commentary on anybody's age, I know there have been some long and diverse and filled with ups and downs, journeys and stories. So I feel like I'm gonna kick it off with little question for you guys here. I wanna know in your career, what was your welcome to cybersecurity moment? And if there's any, if there's any sports fans out there, this is like when you're seeing an interview with like a rookie in the NFL or something like that and they're asking like what was your welcome to the NFL moment or what was your welcome to the NBA moment where you got dunked on or you got hit super hard or something like that. So let's do the cyber security version of what was your like welcome to the pros moment. And whoever wants to start, kick it off because I'm sure we're gonna have ample time to make fun of and laugh at you. So who's gonna stick who's gonna start us today? Aidan Brown: Yeah. Max Kurek: It was not directed at you to be clear. Seth Loe: Requisite. So I don't want to give the timeline because obviously I need to tell a story about a cybersecurity incident. Don't want anybody digging in my LinkedIn and discovering what which organization this was involved in. But I had been pretty solid on the IT service side, you know, exchange administrator, server administrator, Microsoft certificates up and down my arm. And company that I worked for had an intranet page. I don't know if anybody remembers what these things were, but it was an internally hosted website that was only available on the LAN or within the VPN. And the company did all their business out of this intranet site. And they did all kinds of stuff to kind of make it interesting and spruce it up a little bit. Well, one of the things that they did was they brought in the area weather forecast. Radar map from a local news station. So this was a local news provider, big main market. Think ABC, NBC, CBS back in the broadcast TV days for anybody who ever still has cable. But they brought in this feed and it sat up in the upper corner and you could see like the, you know, if the rain was going across the area when it was touching. And that weather feed got hit by a drive by. And we were pumping it straight into the intranet. Now, to credit, we had thorough MDR implementation at that point. We always just called it antivirus or whatever, but it was reporting in those agents on those devices reporting into a central monitoring and alerting server. But sitting here on a regular Tuesday afternoon, and all of a sudden the alerts start lighting up all over the organization. Because you just think about everybody in the company opens up their browser and Active Directory. Took them immediately to that intranet page as their homepage, drive-by after drive-by after drive-by. The A V solution was lighting it up. It was quarantining their browsers, but also that means that executable couldn't run and people trying to do business in that browser are calling in on the phone. And I had done the administration on the new rollout of the central admin server for that. And it was in a precipice where, like previously, you would have thought. God, we have to go touch hundreds of devices to clean these things up. We have to sit down at them. And you remember the McAfee days? You'd have to do a scan manually on the device and then go into the quarantine and have it rip it out. And we were sitting here looking at the immense task that was ahead of us. And I got to say, well, no, actually, with the central management server, I can go in and kick off all these quarantine cleanups. And get rid of all these JavaScript files that were dropping in everybody's temporary internet files. I think this was in the Internet Explorer days, if that doesn't date it for you a little bit. But ran a script through our RMM tool to clean up the temporary internet files while the antivirus was going and killing the stuff that was in the quarantine and restoring browser access. And then after that, the vice president of technology comes to me and says, you're my new cybersecurity guy. Cody Kretsinger: For the promotion. Max Kurek: Okay. Can I Yeah, seriously, congratulations. But can I just point out like Seth totally did all of the dated age references on his own. It didn't even he didn't even need media to intro. McAfee Antivirus. There was something else you said just at yeah, right. It was Norton. There was something else you said just at the end too that I was like, my gosh, that was Internet Explorer. Yeah, Internet Explorer. Seth Loe: Back a fee, just to my credit. Cody Kretsinger: Internet exploration. Max Kurek: So, you know, I guess we I guess we'll chalk that up to the first self owned and unauthorized opinion. Seth Loe: History. Good news there was no X fill on that whatsoever solution that we had. I think it was Viper at the time. Caught it cold. And it was a real common attack. It was a well known. I think even got hit by the thumbprint, you know, of the executables themselves. So you know, no data loss. Max Kurek: No data lo no data loss, no foul or something like that. Seth Loe: It's like before ransomware gangs did the double ransomware, right? This would have been a thing that was just meant to cause disruption. It wasn't encrypting anything. It wasn't trying to exfil anything. It was just trying to ruin your day. Cody Kretsinger: Yeah. Back when the internet was simple. Max Kurek: I was gonna say literally b in simpler times when all they wanted to do was just ruin your day and like cackle with glee in their basement knowing that they'd done that. Whatever floats your butt. Yeah, yeah. Doctor Evil with the hands or your fingers strumming each other. Okay, well, that is that's a fun one to get us going. Cody, what about you? What was your welcome to cybersecurity moment? Cody Kretsinger: You mean then the FBI knocking on my dorm room door at five o'clock in the morning? No, so Max Kurek: Yeah that's Seth Loe: Never heard this story before. Cody Kretsinger: I'm not even gonna I'm not even gonna go into it. I'm just gonna leave it out there because I have a different one. So years later, I'm doing my very first pen test breado. And I had been trusted to do a pen test for this organization. Ironically had gotten in through SQL injection and then got to domain admin on the network itself and from there was able to compromise everything because Aidan Brown: Ha. Cody Kretsinger: Had domain admin credentials. And I remember actually giving the readout to the executives at the time and one of the exec like one of the executives was openly weeping because of the information that we were able to get. And that's when I realized that this isn't just a game for, you know, a pen tester to get in and see what they can get to. We're actually like interacting with the business and there's livelihoods at here and there's business risk and there's all of this other stuff that goes along with it. Because it you know, at that time I was a young professional, and professional is debatable, to be clear. But all that being said, that's when it kind of clicked for me in terms of like what really this industry is, the security industry specifically, you know, doing penetration testing. And you know, I always go back to that story because that's when I really realized that that's my aha moment. And clearly it was impactful. And I'll always take that from kind of engagement to engagement. But that is the welcome to cybersecurity aha, holy crap moment for me. Because I would have never guessed that actually happening in an actual readout meeting. Max Kurek: Well, I also I don't think that people usually think about like actual physical tears in the context of cybersecurity, but like that is totally a real thing. You're seeing especially in some of those incident response scenarios and some of the events that you've dealt with, like you're seeing people at their rock bottom professionally in a lot of ways, right? Like this is the worst moment of their careers. And there is 100%, I think, a human side to the cybersecurity conversation and to you know, we always talk about the user and the human being the weakest link in your cybersecurity chain. But that same user has real human emotions that you're gonna see pour out, especially when they're going through a situation like that. So I think there's probably a lot of us that kind of that was a big point of realization of like, my gosh, I'm not just dealing with technology. I'm not just dealing with machines. I'm not just dealing with clicks and everything else. Like there are people on the other side of this and there's fallout from everything that we're doing and talking about. Cody Kretsinger: You know, there's one thing that I'll say real fast on that, and it's actually around the incident side. And there's one particular thing that just it brought to the front of my noggin. And I vividly remember walking into an incident that was catastrophically bad. Just i can't go into more detail than that, but it was catastrophically bad. And I remember trying to talk to the CIO of the organization, and he was in the literal definition of shell shock could not function. Couldn't put words together. I stood in his the threshold to his office, the doorway, and knocked and he couldn't even make eye contact with me. And the only thing he would do would repeat, Everything is so screwed. And that's it. He just said that over and over again. And that's when I realized like he's not the person that I need to go talk to right now. He's got to deal with that. Let me go figure out what else is going on here because clearly the situation is very bad. But that's another story for another episode. We'll I'll save that. Max Kurek: Yeah, and let me I'll unpack that. There's a lot of stories for a lot of other episodes that came out of the last five minutes of you talking, Cody. I think whether it's this or whether it's a different show that we're gonna be putting out there for you guys soon. I the autobiography of Cody, I don't know. It might be something to tease for a future podcast. Maybe, maybe not. I don't know. All right, Aidan. What was your welcome to cybersecurity moment? Seth Loe: I'm sorry to interrupt Aidan. Yeah, go ahead. Extract one more human part out of because you started and I Aidan, I totally apologize, but Cody, you said like this is the first time you're doing a big pen test, you've done a readout. The moment I need to hear is you're in your chair, you are knocking on port fourteen thirty three for the first time. You for real on a paid engagement. Max Kurek: Please. Aidan Brown: No, no, go ahead, Seth. Seth Loe: Exploit a SQL service and elevate to administrator. Didn't you just pee your pants just a little bit in that moment? I mean what this is has to be a big moment. Cody Kretsinger: So there's a much longer conversation around that. And d I didn't quite pee my pants, but the hair on the back of my neck stood up. And it was in this is a again a much, much longer conversation. That's when I realized I knew I was in the right industry. I realized I was doing the right thing in said industry, and that every time I did it, that I would always have that. And the flip side of that is. I get those same feelings when I do IR. So I naturally manage to find the two things in cybersecurity that literally make the hairs on the back of my neck stand up. And I get tingly excited when those things happen. And that engagement had a lot to it. I actually skipped over about six steps, but there's FTP servers and interpreter sessions and all of that stuff that go into it. Really old school pen test stuff that somehow still worked and still managed to get domain out of them. So Seth Loe: Thank you so much for sharing that. I appreciate that. That's I mean, I had some hair standing up on the back of my neck as you were talking about it too. And Aidan, thanks for the patience on that one. Max Kurek: Well, I'll just say too really quickly, the peeing your pants question, it made me wonder, like, are diapers an important item on the incident responder shopping list? Like, should you just have some handy? Either because you're working thirty six hours straight and can't afford a bathroom break, or because you scare the piss out of yourself with what you find or what you do. Yes. Cody Kretsinger: Be sure to feed and water your IR people. Aidan over to you, bud. Max Kurek: If there's any adult diaper companies, hit us up for a collab. You can sponsor this podcast. All right, Aidan, what was your welcome to cybersecurity moment? Aidan Brown: Yeah, I mean speaking of diapers, being the young buck on here, I will say probably so from some of what Seth was saying, I was probably in diapers in some of those moments. But in any case, so perfect segue. Thank you, Max. But yeah, my welcome to cybersecurity, I will say it's not as I would say flashy as those two. It's honestly quite the opposite. And it kind of give you the story and the context. So When I was studying cybersecurity in the in school, and I will say a quick side note, like one of the biggest things during that was always human safety is first and foremost when it comes to cybersecurity. So side note on the continuation of that conversation. But when I was in that cybersecurity classes, it was always showing us the big bad, the big the SQL injections, the cross-site scripting, those kinds of things. And I mean, that's what we grew up seeing in movies too, how complex and how futuristic cybersecurity can be like the whoa the big bad thing on the screen with a bunch of green text along the black screen. So that was, I mean, kind of what I was expecting coming into cybersecurity. And so when I started here at Galactic, so our partners will know this, one of the things that we tell them to do is a questionnaire at the before they run our scans, before they run the penetration test on the client or whoever it may be, the organization. And One of those questions is where do you store your passwords? I'll I could not believe, short story short, I could not believe how many was an Excel sheet on a paper in the file cabinet stored somewhere on a post-it note. Well, why I'm saying this and why I was saying it's The complex versus the simple stuff, it just made me realize that sometimes cybersecurity is about the simple stuff. It's about storing passwords in a password manager instead of an Excel spreadsheet. Guys, I could not tell you how many times Excel spreadsheet was the answer there. It just blew my mind. So again, kind of the reason I'm saying this is it made me realize how cybersecurity can be about the simple stuff a lot of the times. And honestly, you see in the news, all of these breaches, all of these incidents happening. And it is the small stuff. It is this account didn't have MFA. This account they got their passwords 'cause it was they were shoulder surfing them and got their passwords from the post it note on their computer. So like I said, it was it's not as flashy, but i when I saw that question, honestly, that was it. It was cybersecurity is not all about the whoa, whoa, the all the SQL injections and that kind of stuff. It can sometimes Max Kurek: A day there was a point in time where I was that answer on that questionnaire. Just and it may have been not long before I began my cybersecurity journey. I may have been the spreadsheet guy, but that was like six years ago. So we won't talk. Aidan Brown: My wife and I were at Barnes and Noble the other week and there was a I'm sure it's in every Barnes and Noble, you can probably go find it. It it's literally called a password storing notebook where you store you where you write down and store all your passwords at Barnes and Noble. Max Kurek: Shout out Barnes and Noble. Shout out bookstores still existing today. It's important. Love that for them. That's crazy that those I you should have asked how many they sell of those password notebooks and for a list of the people they sold them to, so you could go give them a nice kind warning about what they've gotten themselves into. Okay. Guys, those are some pretty fantastic stories. I'll just really quickly say so it even though Aidan might be the young buck here. I'm probably the newest in the cybersecurity space generally, like j at just over five years. And my kind of welcome to cybersecurity moment wasn't necessarily a moment, it was a thing. When I first started at Galactic, which was my first foray into the cybersecurity space, I used to have this legal pad, you know, like one of those big long legal pads that all the lawyers carry into court with them. And the reason I had it, it was on my desk. All the time. And I was spending most of my first year at the company in meetings and just shadowing and learning and being a sponge. And I had this legal pad. And every time I would hear a term or an acronym or just some reference that I didn't know, I would write it on this legal pad so that I could go back and look it up later and learn about it and figure out what it was. And gosh, I don't even know how many pages of stuff I filled up. In that legal pad, sitting in meetings with partners, sitting in meetings with colleagues, sitting in meetings with really high level security professionals who have been in the industry for decades and who are speaking a language that, you know, at that point in time I was completely unfamiliar with. And I filled up this notebook and a couple of years ago, when I when my wife and I moved into our new house, I was unpacking the box that had all of my work, like my office stuff in it, right? From back in the early days. I used to my office originally in the first condo we used to live in was in this basement, man. It felt like a cybersecurity office. Like it was in a basement. There was no windows. I was like drinking Mountain Dew and just chilling. But I was unpacking everything and getting all my computer stuff and everything, all the books. And at literally at the bottom of this box was the notebook, or not the legal pad with all of these things that I had written. And the f some of the first things on the list were. EDR and NIST and you know, just some really basic terminology and concepts that everybody, you know, it it's second nature to everybody in cybersecurity. But it kind of I would think that moment and just that thing, that physical notebook, which I have, I should probably like hang it on the wall or something, was kind of my like welcome to cybersecurity moment, if you will. It w but it was a thing. So thanks by the way to all of you for helping me. Populate answers in that thing because whether you know it or not, you absolutely did. So Cody Kretsinger: I was gonna ask you if you still had it and I do think that you should frame it. Max Kurek: You know, the question is, do I still know where it is around this office? But I will find it. It's here somewhere. I can't imagine I would have thrown it away. But and don't even get me started on my handwriting. Terrible. Okay. We're gonna shift gears pretty quickly here because there's some really big news that we need to talk about. We're filming this, we're recording this episode in mid-July and There is something that was just announced earlier this week, in fact. And I think I was even in a meeting with a couple of you guys when the news about this broke. And that is that the Pentagon, and this is not a political conversation, disclaimer, this is not a political conversation. So don't come at us for talking politics. This has nothing to do with politics. But the Pentagon announced just the other day the immediate suspension of CMMC phase two requirements. Which I believe had been scheduled to take of effect at some point in the next 30 to probably not like I think some point in Q4 is when they were like officially scheduled to take effect, I believe, in the early November. And just kind of to help set the stage a little bit, phase two would have required like defense contractors and vendors to pass third party assessments from a certified third party assessor, a C three PAO, not C three PO, but Shout out to all of our C three PO fans out there. Before Seth Loe: Or jokes on my notes, thank you. Max Kurek: What was that? Did I We should have compared. We should have compared. How many Seth, you might know the answer to this question. How many languages or how many forms of communication was C three PO fluent in? You know offhand? There you go. Okay. So there's the fun fact for this episode. Seth Loe: Forms of communication. Cody Kretsinger: Can I ask how you know that? Seth Loe: It came with the tattoo. Max Kurek: There it is. What we should have asked him, what's your welcome to Star Wars moment? I have I've got a buddy who's a big Star Wars fan like Seth, and you can watch any of the movies with him and point to any character or anything. It doesn't matter. It could be the quickest monta or quickest appearance in the film, and he could tell you, that's even droids, like, that's R4 D5. Incredible. So anyways, we're not talking about C3. PO. We're talking about C three PAOs because that's what the suspension of these requirements means is you no longer are required, at least in the interim and in our current state, to go through and pass that third party assessment. The verification piece of that is now on hold. And the CIO, the chief information officer at the Pentagon made this announcement. And if you haven't seen the video of her announcing this, I would say go watch it. It's about three and a half minutes. But You might get a little bit of a good chuckle out of this, kind of like I did, because the government is so good at making non-AI videos so sterile and boring that you're convinced that they're made by the world's driest AI bots. I like looked at it, I was like, I know this is not AI, but my gosh. So that's kind of what happened the other day. They're they are standing up a CMMC reform task force with a mandate to review the program and kind of report back within 60 days. And the phase one self-assessments do remain in place. So it, you know, let me be clear. CMMC is not dead, right? CMMC is not gone. Long live CMMC. But the phase two requirements are on pause. So before I got some questions for you guys on this, but like I just want to start with immediate reactions. Like when you heard this news the other day. What was kind of the first thing that came to mind, whether it was for certifiers and assessors and that had just gone through all this work of becoming certified assessors, whether it was for MSPs who are going out and trying to help their clients with CMMC compliance? Like what was your major takeaway when you first heard this news the other day? Cody Kretsinger: I'll go first because I've got a little bit of a hot take on it. The initial reaction, at least from my part, was here we go again. Right. Anybody that's followed CMMC over the course of its life, knows that it has a history. It has a history of changes, it has a histories of starts and stops. It has a history dating all the way back to twenty twelve. Actually I up I apologize. Has a history going all the way back to two thousand and eight, which means if I'm doing my math right, it's legally old enough to drink. And here we are, drunk legally drunk. Max Kurek: And it is. Seth Loe: There's some counties down south where it was legal to drink it a few years ago. Cody Kretsinger: Yeah. It but the point being, we still haven't ratified it yet. So my initial gut reaction was this is just the latest iteration of it. And I saw the original reports where it basically said CMMC is dead, and I'm glad that that's not the case because really it's just a 60 day suspension on things just to reassess where it's at to see where it's going because I've heard From to like a ton of different places. Some of the significance of this that I'll go into a little bit later because there's some folks that I've talked to over the last couple of days where they've done some back of the ma napkin math and they're starting to calculate their losses based on this. And I think everyone here would be incredibly surprised by some of those calculations. Seth Loe: My initial reaction was just pure cynicism. But I mean, that's kind of what you get out of me at first anyway, right? I mean, that's like the very first my first take on anything is to be a little bit cynical. But you know, Max, you were talking about your notepad, and I still have my notepad from one of my very first days at Galactic Two. And it was sitting this is the first day I met Cody Kretsinger. This is the first day I met Matt Kerrick, and I wrote in on the heels of our good friend. And Marty, if you're out there, you have to mess you have to message us if you watch this. But and I I'm sitting at those round tables at that event, and I remember Leia kept getting up, and here's another Star Wars reference, but Leah kept getting up to the mic and she was saying, CMMC, CMMC, CMMC. This is 2022, and I wrote that down on my notepad and said Cody Kretsinger: Mm. Seth Loe: Boy, I better Google that during the break because people are talking about it. And it was one of those. But, you know, even during the breaks, there were discussions about, well, it's gonna get it's been stopped a couple of times, and there's another touch point in the spring, and we're not sure if they're gonna continue it, if it's really gonna be a thing. And that's kind of been the way it has been. And you know, keeping in perspective here that they're talking about. Somewhere between eighty and a hundred thousand companies that need to be CMMC certified. And what I mean, guys, you can correct me on this. I because I've heard a couple of different reports. I've heard some reports that there are currently a hundred organizations that are certified to do the audits. The highest that I've heard was two fifty-five. And I assumed that was somebody who was doing binary. But the That's a major choke point. Right. And you know, I was a little cynical too. I watched the Department of War's announcement on this. And, you know, anytime we're talking about CMMC and somebody has to go war fighters, in the middle of the discussion, I thought, okay, well, we're definitely getting we're getting the spin on this side of thing. But the truth of the matter is that this is about supply chain. And we never we can't ever forget that this is about supply chain risk and managing supply chain risk. And people saying that even and people recognizing that even the warfighters on the front lines are at risk to supply chain attacks. So, my cynicism died down a little bit. I mean, I don't want to give any I definitely don't want to ruin this with any political talk, but I think somewhere in this discussion, guys, we gotta talk about government and the role of government. 'Cause you can't separate CMMC from you know, our way the way we have chosen to structure our you know, three bicameral legislature and you know, three branch system that we're operating here that implemented this to begin with. But yeah. Max Kurek: Aidan, what about you? Aidan Brown: Yeah, I mean, I just kinda wanna I honestly kinda want to continue what Seth was just saying because what I found interesting specifically about the official statement they released, that document that I'm sure everybody has seen, I feel like a lot of the focus was on like the warfighters, but also talking about hey, the we're lowering the barrier of entry for small businesses that are part of the defense industry, the DIB, So we're doing this to because we want to lower the bar to entry, which don't get me wrong, I'm all for America's built on small businesses, local businesses. I love that. Lowering that barrier of entry. Like shout out my local Korean restaurant here in Cincinnati. Always supporting them. But what I'm trying to get at is that supply chain risk because sure, I love small businesses getting involved in this, but that also doesn't mean they shouldn't Pi The same controls, the same things shouldn't apply to them as well because especially in this industry, these the sensitivity of the information, of the data that they are holding, I still want them to be secure. I still want them to be assessed by third parties as well to make sure they are following the rules, following the regulations. Again, I know there's it's a bigger discussion when it comes to CMMC when it's the large, medium, small size businesses, but again I just kinda that thought came to my mind when Seth you mentioned supply chain risk. I mean, that also includes the small businesses in that supply chain when it comes to this. Max Kurek: What's one of the first one of the first myths that I we always talk about when it comes to being the victim of a cyber incident is I'm too small to get hacked, right? Like that's such a common excuse. And so I think that's a really good point, Aidan. Like, let's think of the small businesses. Let's think of giving everyone an opportunity to play here and like we can still do that while also doing our due diligence on the vetting and on the framework alignment side. So I think that's a really good call out. Let me just really quickly ask you guys, because there's a lot of there's a lot of MSPs serving clients. There's a lot of IT professionals and risk management professionals and security leaders that are serving the defense supply chain and who are we're building toward this framework. How does this suspension Change the conversation that an MSP needs to be having with their client, that a risk management professional needs to be having with their executive team, that a, that a cybersecurity leader needs to be having with their team. Like there's obviously a shift in it. This isn't going away, but there's obviously a shift in how we approach and how we think about the strategic roadmap moving forward. Like, how does the conversation change? And what is some folks, what do those folks need to think about when they're talking to decision makers about. What comes next? Cody Kretsinger: I want to jump in here because I don't think the conversation changes at all. This is bear with me for a moment because I think like I might actually get a little soapboxy here. The level one hasn't changed. Level two still has the same requirements. It's still NIST 800-171. There's a DFARS component to it. There's a si civil cyber fraud initiative that still goes along with level two. But the only thing that changed there was self-attestation, which basically means that you have to attest that you are doing these things, that you don't need to have somebody come in and actually certify that you're doing it. So the bottom line is you still have to do the thing. There's also a component of that where And I want to highlight this. There's a component of that where there are going to be some organizations out there that do the trust me, bro, I'm totally doing it and not doing it. Those organizations inevitably will be caught and dealt with. And it ultimately it boils back down to that organization's risk appetite and whether or not they want to bid on those contracts and all of that. But the thing that I want to point out specifically a around this is all of those businesses that did already invest in this. So I've got some stuff th that I did a little bit of digging on real fast. The DOD pretty much states that a level two assessment is anywhere between a hundred and five to a hundred and eighteen thousand dollars. That's the actual assessment and two annual affirmations. So that's a hundred thousand dollars just to get certified. The pre assessment and readiness review is anywhere between three and twenty thousand dollars. So we're Close to 150 at this point. The cost to l reach level two, according to the DOD, is anywhere between one hundred to three hundred thousand dollars. So let's just take it right in the middle. So we're at a quarter million dollars. The organizations that set up the enclave and put up all the policies and procedures and all of these things took on at minimum around a quarter million dollar investment into something and got the rug pulled out from them because now there's organizations that won't do it until this actually goes all the way through in hopes that they don't get caught. And they have to the organizations that did it. That were responsible, that followed the rules, that played by the rules, that were you know, were thought ahead, have to realize that cost, that quarter million dollars that they just sank into something. Whereas you've got other organizations that don't have to realize that cost when they actually do the bidding. And that's the part about this that frankly pisses me off, because there's there are going to be businesses that don't follow the rules. And the ones that did are ultimately kind of getting punished here. And I just I think that's such a shame because we had so much good momentum and there was the possibility of this thing actually going through. I truly believe it will eventually. I just man, it puts a sour taste in my mouth just to see another stumble like this. That's all. Max Kurek: Ask a follow-up question on that because like of the timing and the pattern that's kind of developing here with CMMC, right? Like we talked about earlier. I think Cody mentioned 2008 and Seth talking about listening to somebody talking in 2022 about CMMC, CMMC, CMMC. But really quickly, like not to be like police procedural cliche here, but the follow-the-money point is an interesting one, and I don't want to delve this conversation into a conspiracy theory. But the other side of that coin, right? All of these people are the investment that they're making. Like, what does the other side of that coin look like? And is there a monetary reason, maybe, that the decisions are being made in the other direction? So it's a mystery. And I know I don't want to get I don't want to get Seth up on that soapbox but Seth Loe: Muted out of respect for you. I do have a cynical take on this though. So first of all, there are plenty of legitimate reasons why I think this pause needed to take place. And I think that as a professional community we should focus on those. But I gotta say, I think the small business line is BS for the masses. It's trying to pull at your heartstrings. Folks, there was a massive multi-billion dollar company Max Kurek: Okay. Seth Loe: That was not going to be able to make the grade in time. And they were gonna lose their government contract because of it. And they probably bought curtain rods for a ballroom somewhere. And they had the influence to say we need you to hit the brakes on this. But that doesn't mean that all that stuff that Cody just said wasn't right. Because Kakody is right about this. And I mean, if you look at the fact that even the governing body that was supposed to certify the C three PAOs failed to achieve the ISO cert that they were supposed to get. That's like finding out the guard down at the local swimming pool doesn't even know how to dog paddle, right? I mean he can't much less C PR, forget that. I mean he hasn't even been certified as a swimmer yet. Right? So there were good reasons, I think to pull the plug and to pause and say, hey, let's move forward. I think that bottleneck has got to be one. If you look at let's look at the low end of the estimates of 80,000 companies that still needed to get certified to be able to continue to provide services to the government. And the high end of 255 certifiers. I mean that's like deep water horizon numbers there. I mean if you guys remember the deep water horizon back in was it twenty twelve or whatever. The stuff that came out of that investigation was like they didn't even have enough people to inspect all of the wells in the Gulf of Mexico. The number of people they dedicated to it would have had to have inspected like three wells a day to keep up with the pace, which is just physically impossible to do. Right? It just was going to be another figurative oil blowout in the bottom of the Gulf of Mexico. Let's just speak in twenty twelve terms here. Yeah, yeah. Another blowout preventer exploding in the basin of the Gulf of Mexico in twenty twelve, all but of cybersecurity proportions. Max Kurek: It's gonna Yeah. Yeah. And the small business line, just to go back to what Aidan was talking about, what you said, that is the ultimate like think of the children aspect to this entire thing, right? Think just think of the children, the poor, poor children. Aidan Brown: Yeah, don't get me wrong. I was bringing it up because I was like, Why are we talking about this in this kind of announcement? So Max Kurek: Smoke in mirrors, bro. Smoking Seth Loe: The mic for just a moment though. Go ahead. About like government, not politics, not the current administration, previous administration, all that. I think one of the things that's affecting this is that we are talking about cybersecurity decisions, cybersecurity audit processes, cybersecurity requirements that span multiple administrations, right? So most of this standard is You know, I mean the standards being driven and monitored by the executive branch of government. And one of the things that this is I think we're looking at a difference between what's in the constitution versus what has been traditions that were upheld, right? And one of the traditions that have been upheld over decades and over a hundred years is that the actual workers at the federal level are not elected people. They are professionals that are hired to cover their jobs. And you notice that and well one of that is to provide continuity. You don't want every single person who works in the highway department to get fired and all the federal roadways to go under unrepaired while there's an administration shift and they get some new people in there that learn how to drive a truck. You know, you can't do that. We want continuity of those services. And that is really one of the upheld traditions that we've seen sort of fall off in the in recent years, I don't think we're going to see that get any better. So I think you're going to see this ebb and flow when it comes to these federal standards. But I don't want to lose sight of the fact that, you know, you know, Cody mentioned was that the these organizations that do not comply with this, if they do not continue to stay faithful, invest in cybersecurity, follow the advice of the these cybersecurity advisors that are helping them build these protections. And be compliant, I think you're gonna see natural selection pick these companies off as one by one. They've got breaches, there's holes in their security, there's scandals around their organizations. But every single time that happens and every single time they get lazy with their pennies and say, we don't have to do this now, it's gonna be the people that suffer for it, and it's gonna be the war fighters. I know they brought it in. But it's gonna be the warfighters, it's gonna be the medical professionals, it's gonna be the Coast Guard and places like this. So Max Kurek: So in that vein, I want to kind of wrap this topic with one last question for you guys. So the reform task force, they've got 60 days. Whether you think this is just going through the motions, whether you think this is truly necessary and there's going to be like tangible positive outcomes that come from this, right? They've got 60 days to report back to the Pentagon, make their recommendations. So my question is, like What do you think is going to happen next? And I know that sounds like a futile question with CMMC in general and it how unpredictable it's been. But in 60 days, when the reform task force comes out of the comes out of conclave, and there's white smoke billowing out of the chimney, like what do we expect to happen if you had to take your best guess, where do you think we're gonna stand sixty days from now when that reform task force has done their completed their work. Seth Loe: Well, they were just formed three days ago, so I think the first thing I would ask them is, have you found your parking space yet? But I think, you know, from the places that I sit in the conversations that I have with the people that we advise along the way, I you know, I'm gonna wonder, are you going to give us something that keeps the teeth in protecting the cybersecurity measures that are meant to protect us all? And they're you know, they're keeping the doors and the windows locked, they're keeping the borders safe, they're keeping the lights on, they're protecting national infrastructure, things that we rely on every day. Can they at least keep us moving forward? And I wonder if that's gonna hopefully they will come up with something sixty days from now that says, Okay, we gonna need to be reasonable about this and we need to throttle it, but let's keep it moving forward. Aidan Brown: Yeah, on that note, I was I mean My perception of the government, without getting political, is the government's always slow. So my reaction was to this, like the sixty day review, the suspension, I was not surprised. I mean and I hate to say it, but I wouldn't be surprised if it gets even further delayed after these sixty days. Just because kinda going on set's note, I really hope this lowering barrier lowering the barrier of entry doesn't mean Less and less controls that impact the safety of the warfighters, of the people. But yeah, my answer to that is I honestly wouldn't be surprised if it gets delayed even further. Max Kurek: That would certainly be in keeping with the historical pattern here. Cody, any final thoughts on this from your perspective? Cody Kretsinger: Yeah, I mean I think everybody can acknowledge to some point that CMMC has some bloat to it. I think what we're finding is, especially if there's only one hundred auditors that can actually do the audits, right? And so many of these organizations that need audits. I think we've established that maybe this is a little complex. Is it complex for the right reason? I'm I listen. Compliance is the last lane that I'll ever swim in, to be clear, and I don't have an opinion on it. But from a casual observer from the outside, I that sounds like a little bit of a struggle. And maybe in the back of my head, maybe there is someone going, Well, wait a minute, there might be a better way to approach this. I th no in government that actually happening is probably very small. But That being said, maybe out there, there's somebody that goes, wait a minute, there could be a better approach to this that is that makes sense. The flip side of that is the last thing that we need to do with the industrial base is make it easier for the adversaries to be adversaries. These should be hardened targets because these are the companies that are doing work for the government through contracts. And that information needs to be secure. It does. There's no you can't get around that fact. And I really hope, as Seth mentioned, and honestly, Aidan, you too, man. I hope the teeth doesn't come out of this too much because by and large, organizations in the United States need to catch up with the rest of the world when it comes to protecting not only critical infrastructure, that's a whole different conversation. But also the industrial base that is supplying defense. So where do I think this is going? Who knows? I d I wish I had a crystal ball on this. I could I'd put a bet down on it. Aidan, I think you're probably the most right on this, that we're gonna see the can get kicked down the road. And I just I hate the fact that we've lost momentum on this because there finally was something. And now it's just in this holding pattern. And that's just so frustrating. Max Kurek: So Aidan Brown: One last thing I'll add to it, and it's actually something I Cody, you reposted something on LinkedIn from I think his name was Wes. Yeah, Wes. I watched the whole thing, but one of the things kind of on this losing its teeth idea here, one thing that he mentioned near the end that kind of stuck with me is we need to learn from things like HIPAA. Because with HIPAA Seth Loe: Yeah well. Aidan Brown: You see these because the teeth are kind of it's kind of in question. It's along the same lines, that self-assessment, the honor system. So you see these smaller organizations that for some reason they called out here, but these smaller organizations, so like for example, I can give it perfect. My wife is a nurse and she had a job where they were still doing paper charting. They were still doing all of these things. She would come back and tell me they did, and I was like, That doesn't sound very secure, like the way they got the medications out of the med bay. She was like, I it was my first day and I was allowed to go get the medications out of there. Because it was these smaller organizations that the HIPAA police probably isn't gonna come around and they'll be like, Well, just pay the fine. It's whatever. We don't need these controls. We don't want to spend the money on cybersecurity. Again, kind of to Wes's point, CMMC needs to learn from that. We can have these smaller organizations if these smaller organizations that they called out be in a boat where they feel like, All right, we we'll just pay the fine. It's okay. We don't need these controls. Let's just go about our business and that's it. So I just wanted to call that out. It was a great point. Seth Loe: Can I say what I hope for the companies that are being affected by this over the next sixty days? I know we're talking about the r the committee and all that, is that I hope that the companies some of them are gonna have like buyer's remorse, right? They invite they invested all this money in this and they they're gonna panic and say this was a sign that we should fire that compliance guy because he gave us bad advice and all that. I'm sure while we're doing this podcast. There are boards that are sitting around contemplating whether to fire cybersecurity professionals. But what I hope they do is that they treat this like in the ND500 when there's like debris on the track and they put out a warning flag and the pace car comes out and everybody keeps their tires warm because they know it's time to race again here in a little bit. I hope they use this time to keep things moving forward. I hope they use this time to catch up if they thought they were behind. And use this as the opportunity it is to say, you know what, we were afraid we weren't gonna hit that deadline. And we're gonna make sure when the next deadline drops, we're there for all of our sakes. Max Kurek: Leave it to the guy from Indiana to drop an Indy five hundred reference instead of like Formu Formula One or something like that. Aidan Brown: Call out for our audience analogies like that from Seth Loe. If you tune in for anything, tune in for those analogies. He's so good at them. Cody Kretsinger: Plus. Max Kurek: All right. So needless to say, nobody's going to be rushing over to Polymarket or CalShi to make any bets on what's going to happen with CMMC. But check back to unauthorized opinions in about 60 days. Maybe we'll have an updated episode for you if the reform task force emerges with anything interesting. I want to wrap this episode with something a little bit fun, recurring feature that we're gonna try. And we're gonna identify some security heroes and some security zeros. Let's do some hall inductions. All right, guys. So I'm looking for nominations for the security hall of fame and the security hall of shame. This could be an organization, a group, it could be an individual, anybody or anything or any group that has done something particularly noteworthy that we want to recognize, or on the flip side of that coin, maybe made a pretty big blunder, got some egg on their face, want to take some nominations for someone we should induct into the Security Hall of Fame, one that we should induct into the Hall of Shame. We'll kind of decide. And then we'll build our little Hall of Fames and Hall of Shames as we go here, because there are people doing things every day. That warrant induction into one of these two places. So does anybody have any let's start with the good stuff. Let's start with the good. Does anybody have any hall of fame, security hall of fame nominees for this week? Aidan Brown: I don't want to play both sides here. I got two two to two items, but I kinda I want to get the audience opinion and I want to get your guys' opinion because I don't know whether the I think they could fit in both Hall of Fame and the Hall of Shame. The first one is so again the we're recording this mid July. Microsoft Patch Tuesday just released and it was the biggest one ever. I saw different numbers. It was like 570 vulnerabilities. I think it was 60 critical, three zero days in the patch Tuesday. And the reason I'm saying I don't know if this is a wall of fame or wall of shame. All right, Microsoft, good job. You patched six what five hundred almost six hundred vulnerabilities. That's great. But you had six hundred vulnerabilities. So I don't know what whether to which one to put it in. And the other one I had was a group that's been researchers, I should say, really, that have been making headlines is chaotic eclipse because or nightmare eclipse. Because speaking of Patch Tuesday, it was hours after that released, they released yet another proof of concept for a vulnerability. It was called where am I not legacy hive. It was targeting the Windows user profile service. But for anyone who doesn't know, this nightmare eclipse, chaotic eclipse, they're the same researchers, they're same group. They've released things like Rogue Planet, Yellow Key, Blue Hammer, Mini Plasma, Green Plasma. And the reason why I'm on the kind of the wall here on whether to fame or shame them is because one, they're finding this. This is good. Good job. You're finding these vulnerabilities and releasing them. But they're also releasing them in the not I don't know the I don't know the perfect word ethically. They're not disclosing these ethically because apparently Microsoft pissed them off when they were disclosing these ethically. Microsoft pissed them off. I forget the backstory there. But now they're just releasing them themselves out in the wild without disclosing them to Microsoft to patch it. Like with the rogue planet, I think it took two, three weeks for Microsoft to release that patch while that proof of concept was out there the entire time. So again, two two ones that I wanted to bring that I just I didn't know where to put them. I think they can fit in both. Max Kurek: All right, we got two nominations on the board. Cody, what do you got? Cody Kretsinger: I wanna know how many of those vulnerabilities were vibe coded and then also how many of those vulnerabilities were found while vibe coding as in like the use of AI to find them. Max Kurek: Isn't that gonna be the new that's gonna be the new way. They're all found that way. Cody Kretsinger: Yeah, because I've got a sneaking suspicion that there might be a lot on both sides on that one, Aidan. So I've just got a fame nomination. And for the this is something that doesn't happen very often, but I'm gonna say the feds did a good job with working with Google and Mandia. Specifically there was a botnet called the Popa. Botnet P O P A. And that botnet is what created net nut. And what that was Yeah, mind you. It's a strawberry, net nut, and chocolate, right? Yeah. Yeah, and the imported ones just aren't as good as the one here locally either. Max Kurek: Locally grown. Cody Kretsinger: The whole premise to this is the Papa or the Popa botnet was a bunch of budget smart TVs and streaming boxes that had a proxy enabled in them by default. There was no actual consent that was given to the user when they purchased this stuff. And when pressed against it, the organization with that sold all of these said, No, we Pinky Promise we made sure to ask all of the people that purchase these things whether or not we could use their devices for this network. It just ends up being that the bad guys leveraged it quite a bit as well. So there's a whole slew of threat actors, both nation state threat actors outside the United States, as well as just like your run of the mill your unks, if you want to call that, that were leveraging this bot net in order to do password spraying and basically look like they're from the United States. So the FBI and Google took them down here recently. I think that's deserving of some accolades. There will be unfortunately there's gonna be another one that pops up. Sorry, another one that poppas up. Max Kurek: There you go. There you go. All right. Well, I'll round it out, and then maybe the I have a proposition after I do. I just wanna I've got one fame and one shame nominee, and on the fame side, another thr another group of threat researchers, this one at Sysdig. And this was something that Aidan talked about last week in Threat Thursday, which If you're not subscribed to the Galactic Advisors LinkedIn page, go follow the Galactic Advisors LinkedIn page, Galactic Advisors.com slash research. Threat Thursday, every single week, Aidan is providing a threat intelligence roundup and not just what happened, but what the impact on your organization is and what you need to do about it. It's gonna save you a ton of time and it's going to give you a ton of useful information to go protect your organization against some of the emerging threats that are making headlines every single week. So go check out Threat Thursday. And if you saw Threat Thursday last week, you saw Jade Puffer, which is the first fully documented case of agentic ransomware. Like from start to finish, no human pushing any buttons. And the folks over at Systig, their threat research team discovered and publicly disclosed this, did all the attack chain reconnaissance and analyzed it. Put the findings in front of the community. And I just wanted to call that out because this is I mean, this is a big, big deal. It's something we're gonna see a ton more of, I would expect. And to kind of have that one fully fleshed out and fully documented and fully investigated, I thought was a big, a big notable win for their threat research team and worthy of consideration into the Hall of Fame. And then on the Hall of Shame side, Again, not a political commentary, but I'm gonna shame the Pentagon not for the suspension specifically of the CMMC phase two stuff, but for years of building requirements, setting deadlines, pressuring contractors to invest in compliance, and then reversing course four months before enforcement. And also the acknowledgement that the math never worked for smaller companies, like that is shameful, I think, in a lot of ways. And I think that whole process of how we got here deserves scrutiny. We scrutinized it today. I think everyone will have their own opinions and thoughts on this. But I'm nominating the Pentagon for the Hall of Shame, not because of anything political, but because of the process and the way they went about this CMMC suspension. So what do you guys think? We need to pick one. Seth, you're kind of the impartial arbiter here. What's your feedback? Seth Loe: Well, I have a an alternate wall of shame nomination and that is that the people in the comments right now are roasting me because C three PO was fluent in over six million forms of communication. I said sixty-three. I it played it back in my head after I said it and it's look it up. I'm pretty sure it's over six million forms of communication. I gave him a 10x bump in his abilities. Max Kurek: He deserves it, man. Seth Loe: So there's a wall of shame nomination too. I think though the real winner though I agree with you with just administration and administration after our government of not scoping the requirements properly and not really thinking through well what it was going to take to provide security and offering a whole lot of unfunded mandates on both small and large businesses. Max Kurek: I'm gonna propose so that we can be equally balanced that we induct Cody's nomination, the FBI, into the Hall of Fame for the re for the reasons that he mentioned, along alongside their partners at Google. And we induct the Pentagon into the Hall of Shame. There's no, you know, no preference here. No we don't we're not showing favor to one one side or the other, equally balanced here at unauthorized opinion. So I'm gonna propose that's who we induct. What do you guys think? Seth Loe: Here, here. Max Kurek: All those in favor say aye. Cody Kretsinger: Yeah, I but I think the feds staying at a flat zero is perfect. Max Kurek: Just how it should be. All right, guys. Let's wrap it there. Thank you everybody for joining us for episode one of Unauthorized Opinions for Cody Kretsinger, Seth Loe, Aidan Brown. I'm Max Kurek, reminding you to stay threat aware. We will see you next time. Thanks, guys.