Podcasts about fedramp

  • 173PODCASTS
  • 462EPISODES
  • 27mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Aug 29, 2026LATEST

POPULARITY

20192020202120222023202420252026


Best podcasts about fedramp

Latest podcast episodes about fedramp

ITSPmagazine | Technology. Cybersecurity. Society
A Secure and Compliant Business Is the Destination. Steel Patriot Partners Maps Five Routes to It. | A Brand Spotlight Recorded On Location at Black Hat USA 2026 with Michael Parisi, Chief Growth Officer at Steel Patriot Partners | Hosted by Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 29, 2026 18:27


What a company is trying to reach is rarely a certificate. Michael Parisi, Chief Growth Officer at Steel Patriot Partners, treats the destination as the opening question rather than the closing one, and the firm orders its own priorities to match. Business owners first, engineers second, compliance and security people third. What does a secure and compliant business actually look like? It looks like whatever lets that business do what it set out to do. For one company it means entering a regulated industry it has never served. For another it means proving to itself and to an auditor that it is secure enough to work with a partner that will not move without evidence. The framework follows the objective. Before a framework gets named or a control gets selected, someone has to decide whether the trip is worth taking. Michael Parisi puts more than half of that work in the category of psychology, and describes the most fulfilling part as helping someone understand where they actually stand. He comes at it from several sides of the same decision, having spent about fifteen years with the Big Four, five and a half with a cybersecurity standards organization and certification body, and two in a similar role at an audit and attestation firm. How does a company know which route it is on? Steel Patriot Partners narrowed it to five positions and put three questions in front of them under the name Find Your Path. Growth has tapped out and a new industry looks like the way to keep going. Money is already committed to a direction someone else recommended. The decision is settled and the work needs a specialist. The open question is which partners and auditors to trust. Or the team needs sustained support rather than a project with an end date. What makes the answer usable is that the firm has nothing riding on it. Steel Patriot Partners stays agnostic relative to tools, software, and auditors, which keeps the opening question plain. Who do you like, and what do you already have? Personality and culture then carry weight alongside capability. Knowing the route also means knowing where it narrows, so Michael Parisi and CEO Jason Ford both press on what a client has not considered, then on what to watch out for. Sometimes the useful answer points somewhere else entirely. Find Your Path is not a robot, an LLM, or an AI tool, and the point is to give an organization enough value to lower its guard and talk directly. One of Michael Parisi's favorite outcomes is confirming that a company may not need to do the thing it walked in asking about, and when the work sits outside what Steel Patriot Partners handles, the firm connects them with someone who does. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Michael Parisi, Chief Growth Officer, Steel Patriot Partners LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Steel Patriot Partners: https://www.steelpatriotpartners.com Find Your Path, three questions to start: https://www.steelpatriotpartners.com/find-your-path Steel Patriot Partners Insights: https://resources.steelpatriotpartners.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS michael parisi, steel patriot partners, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, find your path, secure and compliant business, business enablement, cybersecurity strategy, grc, governance risk and compliance, agnostic advisory, audit readiness, fedramp, cmmc, entering a regulated market, vendor and partner selection

ITSPmagazine | Technology. Cybersecurity. Society
Business Owners First, Engineers Second, Compliance People Third | A Brand Spotlight Conversation with Jason Ford and Michael Parisi of Steel Patriot Partners | Hosted by Marco Ciappelli

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 19, 2026 20:15


Steel Patriot Partners lists its priorities in an order much of the cybersecurity industry reverses. Business owners first, engineers second, security and compliance people third. Michael Parisi, Chief Growth Officer, says the sequence is deliberate and shapes how the firm opens a client conversation. The order tracks the path the founders took. Jason Ford, Co-Founder and CEO, started in the late 1990s as a government contractor at the FBI, met FISMA and SAS 70 early, and built a platform for the Treasury that sold savings bonds online before PCI was a standard. He started his first company in 2004, took it through FedRAMP in 2013, and was acquired in 2017 holding 35 to 36 authorizations to operate across multiple agencies. What changes when an advisor is free to answer directly? Parisi spent about 15 years in the Big Four across PwC and Deloitte before joining Steel Patriot Partners. Auditors hold independence, which means watching a decision head the wrong way without steering it. In an advisory seat, he says, telling an organization that its preferred direction falls apart as a business decision becomes part of the work. How does a company find out where it actually stands? Ford says compliance is one outcome among many, sitting alongside operational maturity, better visibility, and integrating AI into DevSecOps. The common gap is not knowing where you sit on your own maturity journey. That finding cuts both ways, and some organizations learn they are further along than they assumed. Buying more tools rarely closes the gap. Ford argues the work is holistic and that each organization is unique, so what fits one may fit another poorly. AI does not settle it either, since a model fed your own assumptions will hand them back. The name follows the same logic. Steel is Pittsburgh, Patriot is Boston, and Partners is the operating model, since Steel Patriot Partners advises, deploys and operates environments alongside the client. Parisi closes by asking anyone weighing a path to verify it as a business decision rather than as an information security purchase or a price comparison. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUESTS Jason Ford, Co-Founder and CEO, Steel Patriot Partners LinkedIn: https://www.linkedin.com/in/jason-ford-5ab206/ Michael Parisi, Chief Growth Officer, Steel Patriot Partners LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Steel Patriot Partners: https://www.steelpatriotpartners.com/ Find Your Path, the qualifier that helps you locate your starting point: https://www.steelpatriotpartners.com/find-your-path ROI Workshop: https://www.steelpatriotpartners.com/roi-workshop ITSPmagazine event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS jason ford, michael parisi, steel patriot partners, marco ciappelli, brand story, brand marketing, marketing podcast, brand spotlight, cybersecurity compliance, grc, fedramp, fisma, cmmc, maturity assessment, cybersecurity advisory, business risk, compliance strategy, security consulting, ai in devsecops, trusted advisor

Tyler Tech Podcast
Cloud Compliance in Government: FedRAMP vs. GovRAMP

Tyler Tech Podcast

Play Episode Listen Later Aug 18, 2026 30:03


In this episode of the Tyler Tech Podcast, John Smail, U.S. federal security and compliance lead at Amazon Web Services (AWS), and Clay Thomas, vice president of cloud strategy at Tyler Technologies, explore the differences between FedRAMP and GovRAMP and why the distinction matters for government organizations evaluating cloud solutions. Recorded live at Tyler Connect 2026 in Las Vegas, the conversation breaks down the purpose of each framework, who they serve, and how they relate to broader cloud security and compliance efforts. John and Clay discuss common misconceptions surrounding cloud compliance, including why FedRAMP and GovRAMP are often treated as interchangeable despite serving different levels of government and addressing different requirements. They also examine the relationship between compliance and cybersecurity, highlighting why compliance frameworks should be viewed as tools for providing assurance rather than direct measures of security. The episode concludes with practical guidance for government IT, security, and procurement leaders. From evaluating risk and data sensitivity to balancing compliance requirements with cost, innovation, and operational goals, John and Clay emphasize the importance of aligning cloud decisions with an organization's specific needs rather than defaulting to the most stringent compliance standard. This episode also highlights an upcoming webinar on cloud strategy in government, featuring research-backed insights and real-world public sector experiences. Learn more and register now: Why Private Sector Cloud Falls Short: Discover Cloud Purpose-Built for the Mission of Government This episode also highlights emerging strategies for building efficiency in the public sector, with insights into how agencies are using technology and process improvements to do more with existing resources. Download: How Governments Build Efficiency at Scale And learn more about the topics discussed in this episode with these resources: Download: AI for Impact: Proven Results for Government Download: State CIO 2026 Priorities Playbook Download: Industry Insight: AWS GovCloud (US) vs. AWS Standard (US) Download: Modern Governments Live in the Cloud Download: Building a Resilient Government Watch: Peoria County Securely Shares Data Across Agencies Read: Boosting Resilience: Cloud Solutions for Modern Government Read: Modernize in the Cloud for Innovation and Resilience Listen to other episodes of the podcast. Let us know what you think about the Tyler Tech Podcast in this survey!

MakingChips | Equipping Manufacturing Leaders
GroundControl: Turning First Articles From a Bottleneck Into an Advantage | Ep. 536

MakingChips | Equipping Manufacturing Leaders

Play Episode Listen Later Aug 17, 2026 55:23


Six jobs waiting on a first article means six spindles sitting still. That is the math Mike lives with at Hill, running around 58 jobs a day where nearly every one needs an internal or external first article before parts can ship. When inspection becomes the constraint, good parts pile up behind paperwork, and paperwork does not make chips. This week we sat down with Mehul Shah, co-founder of Ground Control, a company building what he calls mission critical software for highly regulated manufacturing. His thesis is simple. Aerospace, defense, medical, and semiconductor shops are drowning in Excel and pen-and-paper workflows, not because the people are behind the times, but because software was never really built for the shop floor or for the weight of ITAR, DFARS, and CMMC. Ground Control started with one hairy, everyday problem: first article inspection reports. We get into how their software reads decades-old, hand-drawn prints that trip up ordinary OCR, balloons the drawing, fills out the AS9102, and pushes clean data straight into ProShop with a single click. It is the kind of automation that turns a shop's worst bottleneck into a task almost anyone on the team can run. We also talk about why now is the moment for this, from reshoring and record defense budgets to the labor math that says we cannot hire our way through the coming surge. Mehul shares how a 15-person team just earned FedRAMP certification, why AI lets them do the work of a company twice their size, and what their new contract review product does to catch a buyer's price change buried in a six-figure PO before it becomes a costly mistake. If your inspectors are your constraint and your smartest people are stuck on manual data entry, this one is for you. What's Covered in this Episode (1:02) Meet Mehul Shah, co-founder of Ground Control: Why Mehul chose manufacturing (5:20) Why manufacturing runs on Excel, and the real reason software never fit the shop floor (6:04) ITAR, DFARS, CMMC, CUI, and the infrastructure tax on regulated software (9:07) Mission critical software and the three tests Ground Control uses to pick a workflow (10:43) Invest in yourself first with ProShop ERP (12:19) Finding the wedge, and why first article inspection was the obvious first product (13:49) How first article really works at Hill, and why it becomes the daily bottleneck (15:53) Why the FAI is critical, process verification before you can ship and collect (16:35) Why now, defense budgets, the SpaceX IPO, the space race, and reshoring (18:29) LLMs let manufacturers build in-house, and when it still makes sense to buy (19:30) Build on standards and a solid data heartbeat, then augment with AI (21:07) A rocket ship, 200-plus customers in two years, including five public companies (22:18) Growing into demand and the hard part of turning down the wrong work (23:39) The seven habits of highly effective work holding with SMW Autoblok (24:22) Avoiding the solution looking for a problem, and how the idea took shape (25:53) Building GroundControl from the ground up and becoming compliant (28:07) The importance of trade shows and building in-person relationships (31:55) The story behind the name Ground Control (and a nod to Major Tom) (35:20) Turn AI buzzwords into outcomes at the IMTS Industrial AI Conference (36:06) Developing out the GroundControl software and finding their MVP (39:32) The ProShop integration: One click from ballooning to master process control (42:39) AI will not replace you, but the person using AI might (46:30) Introducing contract review and catching PO errors (49:37) The visitor check-in system (ITAR sign-in without the 20-year-old paper pad) (52:16) What Mehul is most excited about, FedRAMP, and the road to IMTS Resources Mentioned Ground Control ProShop ERP SMW Autoblok IMTS Industrial AI Conference Connect with Mehul Shah Connect with Mehul on LinkedIn GroundControl Connect with MakingChips Website On Facebook On LinkedIn On Instagram On Twitter On YouTube

ITSPmagazine | Technology. Cybersecurity. Society
Compliance Moves at the Speed of DevOps When Paperwork Writes Itself | A Brand Briefing at Black Hat USA 2026 with Travis Howerton, Co-Founder and CEO at RegScale | Hosted by Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 14, 2026 13:45


Why does compliance paperwork fall behind the systems it describes? Because the systems change faster than the documents. Travis Howerton points to cloud native technologies that spin up and down on demand, which makes describing infrastructure in paperwork something that goes out of date instantly. Add new regulation for third party risk, supply chain, zero trust, and privacy, and an approach that was already expensive and frustrating stops being fit for purpose. RegScale answers that with compliance as code. The company went to NIST and helped write the standard that became OSCAL, the Open Security Controls Assessment Language, then built the capability for machines to attest to their own state using it. Paperwork starts writing itself, and CISOs get risk and compliance outcomes as a byproduct of operational excellence rather than as a separate project. Is automating the evidence trail a shortcut? Travis Howerton argues the opposite. It prevents corner cutting, because the alternative is what he calls compliance theater. An old general he worked for described that as a mother-in-law visit, where you clean the house to a ridiculous standard, everybody goes through the dance, and the moment the visit ends the kids destroy the house again. Where should a security team start automating? Start with what hurts. He tells people to think like a surgeon, who opens by asking the patient what is wrong, then work backwards from the pain. There is no easy button, and the honest starting point is the truth about how fast teams will need to react. That pain usually maps to one of three business drivers. Cut cost, or shift the share of budget going to checklist compliance toward tools that buy down risk. Get real-time assurance. Or earn the reps and certs needed to sell into a market, whether that is FedRAMP for government work or PCI for card data. Compressing those timelines by 70 to 80 percent lets a company get to market faster and grow revenue. The results Travis Howerton cites are specific. One large government agency is touting over $100 million in labor savings, and a Department of War customer with a 52-week end-to-end cycle has compressed it by 36 weeks using RegScale technology alongside other integrated tools. Having tripled, doubled, and doubled again over the last three years, RegScale stays focused on the largest and most complex organizations, with international markets and the energy sector on the horizon. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Travis Howerton, Co-Founder and CEO at RegScale LinkedIn: https://www.linkedin.com/in/travishowerton/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas RegScale: https://regscale.com OSCAL, the Open Security Controls Assessment Language: https://pages.nist.gov/OSCAL/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS travis howerton, regscale, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, compliance as code, continuous controls monitoring, oscal, grc engineering, fedramp, fisma, authority to operate, ai agents, risk management, cybersecurity compliance Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

CarahCast: Podcasts on Technology in the Public Sector
FedRAMP CR26: What It Means and How to Respond

CarahCast: Podcasts on Technology in the Public Sector

Play Episode Listen Later Aug 12, 2026 42:52


As FedRAMP evolves through the consolidated rules of C26 (CR26) initiatives, Government agencies must adapt to new certification pathways, increased automation and stricter cybersecurity requirements. By preparing for emerging priorities, including post-quantum cryptography (PQC), stronger cryptographic governance and continuous compliance, agencies can modernize cybersecurity programs and support the Federal cloud ecosystem. Access the podcast to hear experts from Qanapi, SafeLogic, stackArmor and SCOOP Cyber discuss how FedRAMP CR26 is reshaping the FedRAMP certification process through automation and continuous evidence. Learn how your agency can respond and comply with these updates while strengthening security through cryptographic agility and post-quantum readiness. Fill out the form to access the FedRAMP CR26 podcast to modernize Federal cybersecurity and build a more resilient compliance strategy.

Federal Drive with Tom Temin
VA's cloud security memo more mythbuster than new policy

Federal Drive with Tom Temin

Play Episode Listen Later Aug 5, 2026 9:07


The Department of Veterans Affairs recent memo on cloud security isn't breaking new ground. It's not even changing policy. The best comparison for the memo that is reminding VA contracting officers and program managers that vendors do not have to have their FedRAMP certification before responding to or submitting proposals for solicitations or requests for information is mythbusting.See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

Jon Myer Podcast
Partner Spotlight: Ep#8 Compliance Without the Theater Cloud Advisory for Regulated Industries

Jon Myer Podcast

Play Episode Listen Later Aug 5, 2026 15:13


Eric Evans and Charlie Clayton from Hanabyte join Ingram Micro's AWS Partner Spotlight to discuss how regulated organizations can move fast in the cloud without sacrificing security or compliance. They break down Hanabyte's "cradle to grave" approach — from mock audits and knowledge transfer to blurring the line between compliance and engineering — and how their Ingram Micro partnership helps clients navigate NIST, CMMC, FedRAMP, and HIPAA requirements.Key Takeaways

Jon Myer Podcast
Partner Spotlight: Ep#8 Compliance Without the Theater Cloud Advisory for Regulated Industries

Jon Myer Podcast

Play Episode Listen Later Aug 5, 2026 15:13


Eric Evans and Charlie Clayton from Hanabyte join Ingram Micro's AWS Partner Spotlight to discuss how regulated organizations can move fast in the cloud without sacrificing security or compliance. They break down Hanabyte's "cradle to grave" approach — from mock audits and knowledge transfer to blurring the line between compliance and engineering — and how their Ingram Micro partnership helps clients navigate NIST, CMMC, FedRAMP, and HIPAA requirements.Key Takeaways

The Daily Scoop Podcast
Balancing innovation and risk across the Department of Energy

The Daily Scoop Podcast

Play Episode Listen Later Aug 4, 2026 28:31


Throughout 2026, you cast your nominations for the FedScoop 50, and the results are in. Hundreds of top executives from across the government tech landscape are now up for vote to see who will be honored among this year's FedScoop 50. Voting is open now and runs through September 25. Make your voice heard to help us select who will be recognized on this year's list. One of those nominees in the prestigious Golden Gov category for this year is Department of Energy CIO Dawn Zimmer. Zimmer joined the Daily Scoop Podcast to discuss how the agency is balancing innovation and security in the age of AI, what the Genesis Mission means for her office, how AI adoption is going across the department and much more. A senior General Services Administration technology official has been placed on administrative leave after criticizing the government's veterans' hiring preference on his personal LinkedIn page, the agency confirmed Monday. Pete Waterman, director of FedRAMP and a career GSA official, said in the July post that his office needs experienced tech professionals, but federal hiring is “terribly broken.” “Veterans preference is brutally unfair when taken to the extreme of blocking any consideration of non-veterans, but we're seeing that everywhere these days,” he wrote. “The future for FedRAMP is pretty dark if we can't hire experts from private sector who have actually worked on cloud services.” GSA Administrator Edward Forst said in a statement that “we categorically and completely disagree with a senior employee's recent remarks denigrating veterans preferences in hiring,” noting that veterans represent about 30% of GSA's workforce. “GSA has zero tolerance for comments that disparage or disrespect America's veterans,” Forst said. “The men and women who have worn and continue to wear our nation's uniforms deserve our respect and unwavering support.” Veterans' preference requires federal agencies to prioritize hiring qualified veterans before civilians. OpenAI's self-reported breach in which an agent escaped testing and autonomously hacked the open-source AI tool company Hugging Face is generating interest in a congressional investigation. In a Friday open letter, dozens of public interest groups, progressive organizations, and academics urged lawmakers to open an investigation into the incident to determine whether stronger safeguards and independent oversight of AI model development and testing is needed. They called the incident “a historic inflection point” for AI. The letter comes after OpenAI's July 21 disclosure of the breach added fuel to the fire of preexisting concerns about the capabilities of the ever-learning technology. According to the ChatGPT maker's statement, an agent driven by several of its models found a way to break free of a testing sandbox, gain internet access, and discover ways to breach Hugging Face — all in an effort to cheat on a benchmarking test. OpenAI has been working with Hugging Face and third-party organizations to investigate and analyze the incident. The organizations that wrote the letter argued the incident arose from OpenAI's own choices on system capabilities and testing design, including decisions it made on objectives for the agent and safeguards to prevent any issues. The Daily Scoop Podcast is available every Monday-Friday afternoon. If you want to hear more of the latest from Washington, subscribe to The Daily Scoop Podcast  on Apple Podcasts, Soundcloud, Spotify and YouTube.

The GovNavigators Show
Lauren Lombardo Recodes America

The GovNavigators Show

Play Episode Listen Later Aug 3, 2026 26:17 Transcription Available


This week on the GovNavigators Show, Robert and Adam welcome Lauren Lombardo, Policy Director for Recoding America, to discuss her work driving collaborative and coordinated government management policy reform. Lauren walks us through how working on campaigns at 13 years old sparked an early interest in public service, and describes her professional path working as a data scientist in the private sector before pivoting to use her technology background as a staffer in Congress. She dives into her work with the Recoding America fund, building connections with think tanks and individuals passionate about government management reform, developing the narrative surrounding these issues, and administering grants to organizations doing policy development and advocacy work in the government management sphere. Plus, learn why Lauren believes problems attributed to technology in government often stem much deeper, and why bipartisanism is necessary for real policy change.  Show Notes Allocore: allocore.com New York Times: Accept Your Fate. Don't Wear Shorts to the Office.  Congress.gov: House C.R. The Hill: House passes reconciliation framework for Pentagon boost, voting restrictions House Armed Services Committee: FY27 NDAA Resources GSA: OneGov CORUS partnership FedScoop: VA won't require existing FedRAMP certification for cloud contracts VA: FedRAMP memo Nextgov/FCW: After Hugging Face breach, FedRAMP chief tells slow-to-patch vendors to stay out of government Recoding America Fund: recodingamerica.org HSGAC: Testimony of Anthony Fauci C-SPAN: Dr. Anthony Fauci Testifies on Origins of COVID-19 Pandemic The Washington Post: Rand Paul threatens to hold Fauci in contempt after he declines to answer questions  What's on the GovNavigators' Radar? August 4th TheXchange August Workshop on NASA's SEWP VI, Reston, VA August 5th  HSGAC Business Meeting, Washington, D.C. August 5th-6th  The 14th Annual Border Security and Intelligence Summit, Washington, D.C. 

ITSPmagazine | Technology. Cybersecurity. Society
The Business Decision Hiding Inside FedRAMP's Consolidated Rules for 2026 | A Brand Story Conversation with Jason Ford and Michael Parisi of Steel Patriot Partners | Hosted by Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jul 30, 2026 44:13


FedRAMP has changed before. What makes the Consolidated Rules for 2026 different is that the dates are on the calendar and the fence sitters have run out of runway. Jason Ford, Co-Founder and CEO of Steel Patriot Partners, has been inside the program since Rev 3 in 2013. Michael Parisi, Chief Growth Officer, comes at it from the business side. Together they map what changes and, more usefully, what it means for the decision in front of a provider right now. So what actually changes? The program consolidates into two paths, 20X and Rev 5. FedRAMP Ready moves to legacy status. Class A, B, and C pipelines open across a thirty to sixty day window, mandatory adoption arrives January 1, and new Rev 5 certifications close on June 11, 2027. Authorized becomes certified. Jason Ford also points out where the rules live: fedramp.gov, hosted in GitHub, which means they move with a commit. Reading them once is not tracking them. Why did FedRAMP need to change at all? Michael Parisi frames it as a supply problem. Agencies and primes have been working from a limited and aging set of technologies while better tools sat outside a process that was slow, rudimentary, and expensive. The action was warranted. His follow-up question gets less airtime: if the process moved faster, did responsibility move with it, and does the stakeholder now holding that due diligence know it yet? The engineering shift is real and it is the part most teams see coming. Jason Ford describes RMF thinking giving way to continuous DevSecOps, proving compliance in real time rather than at a point in time. Vulnerability remediation is where the compression bites. CISA's updated guidance drops severity score as the driver in favor of stepped prioritization, and windows that used to run 30, 60, and 90 days now land closer to three to twenty-one. What does this cost a business past the budget line? Time and capacity. 20X is faster than a Rev 5 process that once ran eighteen months, but faster is not instant. Retraining a couple hundred users inside a thousand-person organization is not a small endeavor, and if the transition eats half of the organization's capacity for a year, that is half as much capacity aimed at the business paying for it. Jason Ford is not arguing against the move. He is arguing that disruption belongs inside the decision. Then there is the internal work almost nobody has started. Mapping an existing Rev 5 ATO scope into a new certification level is not clear-cut, and past the mapping, marketing and sales both need re-education. Michael Parisi describes building a translation layer for customers: here is what we provided before, here is what it is now, and this change came from the program rather than from any reduction in assurance. Roughly half the time, Steel Patriot Partners tells organizations not to pursue certification at all. Michael Parisi treats that as one of the more valuable things the firm does. The opposite failure shows up just as often, with companies preparing to spend heavily on 20X because it sounds quicker and cheaper, when the agency or prime they are chasing expects a certification level. A lower bar only helps if the buyer accepts it. Where should a business start? With the business conversation. Michael Parisi notes the answer does not have to be yes or no today; it can be a maybe with defined trigger points. Jason Ford closes on posture: come with an open mind, and do not hand a multi-year commitment to a language model whose guardrails and training are not built for that call. Or, shorter: don't wait, and don't go it alone. Steel Patriot Partners built a three-question starting point for that first conversation at https://www.steelpatriotpartners.com/find-your-path. This is a Brand Story. A Brand Story is a ~35-40 minute in-depth conversation designed to tell the complete story of the guest, their company, and their vision. Learn more: https://www.studioc60.com/creation#full GUESTS Jason Ford, Co-Founder and Chief Executive Officer, Steel Patriot Partners On LinkedIn: https://www.linkedin.com/in/jason-ford-5ab206/ Michael Parisi, Chief Growth Officer, Steel Patriot Partners On LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Learn more about Steel Patriot Partners: https://www.steelpatriotpartners.com/ FedRAMP's Consolidated Rules for 2026: What It Means for Cloud Providers: https://resources.steelpatriotpartners.com/fedramps-consolidated-rules-for-2026 Find Your Path, a three-question starting point for ISO, CMMC, and FedRAMP decisions: https://www.steelpatriotpartners.com/find-your-path Complimentary ROI Workshop: https://www.steelpatriotpartners.com/roi-workshop Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS jason ford, michael parisi, steel patriot partners, sean martin, brand story, brand marketing, marketing podcast, fedramp, fedramp consolidated rules for 2026, fedramp 20x, rev 5, fedramp certification classes, cloud service provider compliance, federal compliance, cisa vulnerability remediation, continuous monitoring, devsecops, ato, 3pao, govramp, cmmc, grc, federal marketplace, compliance roi Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

The Daily Scoop Podcast
The Department of Veterans Affairs relaxes FedRAMP requirements for cloud contracts

The Daily Scoop Podcast

Play Episode Listen Later Jul 30, 2026 6:27


Existing FedRAMP certification is no longer required for Department of Veterans Affairs contractors to win bids, a top agency IT official said Tuesday in a memo obtained by FedScoop. Any acquisition documents, including requests for information, proposals or quotations, should not state or imply that a cloud company must have already completed the governmentwide security check, Zack Schwartz, principal deputy assistant secretary in the VA's Office of Information and Technology, said in the memo. Schwartz wrote that the “memo supports VA's ability to sustain momentum with mission needs to provide secure technology solutions in a dynamic cyber risk environment, while avoiding unnecessary delays in the procurement of critical systems and services.” He added that the “distinction is intended to preserve acquisition flexibility while maintaining VA's risk management and operational security standards.” Instead, cloud systems, services and solutions companies must fully comply with other security requirements — including those from the National Institute of Standards and Technology, VA directives and handbooks — and receive a VA Authorization to Operate, which could be granted in 60 days. The Department of Homeland Security is expanding its AI use for FOIA processing in response to a sizable backlog and increasing number of requests, per the agency's annual report. In fiscal 2025, DHS started with 221,068 pending FOIA requests. After receiving more than 1 million requests and processing nearly the same amount, the agency ended the year with 245,572 pending requests. Despite the uptick, DHS said it maintained its backlog — defined as the number of requests or administrative appeals at the end of the fiscal year that are beyond the statutory time for a response — at just 16% of total requests received. Technology could help the agency make a bigger dent in the years to come. “The DHS Office of Privacy continues to invest, develop, implement, and deploy new technological advances in FOIA processing,” the agency said in its 2025 FOIA report, published Thursday. “It expects to launch additional automation tools this coming year to further improve efficiency and reduce administrative redundancies. The Daily Scoop Podcast is available every Monday-Friday afternoon. If you want to hear more of the latest from Washington, subscribe to The Daily Scoop Podcast  on Apple Podcasts, Soundcloud, Spotify and YouTube.

Jon Myer Podcast
Partner Spotlight: Ep#3 Accelerating GovernmentGrowth for ISVs

Jon Myer Podcast

Play Episode Listen Later Jul 29, 2026 14:12


Ray from Project Host joins Ingram Micro's AWS Partner Spotlight to discuss how their 20+ years supporting government and regulated cloud workloads has evolved into a fast, flexible path to FedRAMP and DoD authorization for ISVs. Ray shares how Project Host recently helped clients achieve full FedRAMP authorization in under four months — and what their growing AWS and Ingram Micro partnership unlocks for software vendors trying to break into the federal market.Key Takeaways

Jon Myer Podcast
Partner Spotlight: Ep#3 Accelerating GovernmentGrowth for ISVs

Jon Myer Podcast

Play Episode Listen Later Jul 29, 2026 14:12


Ray from Project Host joins Ingram Micro's AWS Partner Spotlight to discuss how their 20+ years supporting government and regulated cloud workloads has evolved into a fast, flexible path to FedRAMP and DoD authorization for ISVs. Ray shares how Project Host recently helped clients achieve full FedRAMP authorization in under four months — and what their growing AWS and Ingram Micro partnership unlocks for software vendors trying to break into the federal market.Key Takeaways

ITSPmagazine | Technology. Cybersecurity. Society
FedRAMP First: Modernizing the Defense Supply Chain Without Cutting Corners | A Brand Feature Conversation with Michael Parisi of Steel Patriot Partners and Jason LaPointe of Exostar

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jul 28, 2026 37:47


For companies in the defense industrial base, a compliance deadline is not paperwork. It is the difference between winning contracts and watching them stall. In this Brand Feature, Jason LaPointe, Chief Technology Officer at Exostar, and Michael Parisi, Chief Growth Officer at Steel Patriot Partners, walk through what it takes to get FedRAMP ready without cutting corners. Exostar was born out of a consortium that included Boeing and Lockheed Martin, and its FedRAMP-moderate posture lets smaller suppliers keep working on Department of War contracts. How does that work? Instead of moving every server and mailbox into a secure boundary, a supplier inherits roughly 80% of the controls from Exostar, which shrinks the scope of its own CMMC audit considerably. The clock was real. At the time, a November transition date loomed, after which many suppliers could no longer self-attest. That specific timeline has since been paused, but the pressure to prove readiness has not gone away. Exostar needed to show it was FedRAMP-moderate and ready for an audit, and working with Steel Patriot Partners, the team pulled a January target in by nearly three months, not by skipping steps, but by moving with confidence. Why build a new platform instead of retrofitting the old one? Jason LaPointe describes a platform first initiative: build the new compliant home, then migrate customers into it. Trying to modernize inside a live production environment would have been disruptive, so the team built alongside rather than on top, which freed them to re-architect and retool without breaking customers. Michael Parisi frames the engagement as embedding, not staff augmentation. Steel Patriot Partners plugged directly into the product team through daily standups and leadership calls, delivered infrastructure as code and deployment pipelines, and kept the work with US citizens, a requirement once controlled unclassified information is in play. What makes an audit go smoothly? Preparation that extends to how questions get answered. Jason LaPointe compares the audit to a deposition, where an unsolicited comment hands an assessor somewhere new to go. Michael Parisi, who spent years in the assessor's seat and ran the practice for a large C3PAO, explains why knowing the auditors and presenting information cleanly protects the outcome. The business math is unforgiving. Miss the audit window and millions in direct contracts can be exposed, while auditors book out six to eight months. Exostar cleared it with a clean, no POA&M result, and the business is now seeing tailwinds through initiatives like Golden Dome. The lesson Jason LaPointe offers other technology and security leaders is about temperament. Every part of the organization gets touched, from R&D to HR to finance, and the willingness to change quickly becomes the governor on success. Having a clear voice at the table for what good looks like, as Steel Patriot Partners provided, is what accelerates the decisions. This is a Brand Feature. A Brand Feature is a ~30 minute in-depth conversation designed to go deep on a company's story, solutions, and customer success. Learn more: https://www.studioc60.com/creation#feature GUESTS Jason LaPointe, Chief Technology Officer, Exostar Website: https://www.exostar.com/ LinkedIn: https://www.linkedin.com/in/jasonlapointe Michael Parisi, Chief Growth Officer, Steel Patriot Partners Website: https://www.steelpatriotpartners.com/ LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Learn more about Exostar: https://www.exostar.com/ Aerospace and Defense solutions from Exostar: https://www.exostar.com/industries/aerospace-defense/ Learn more about Steel Patriot Partners: https://www.steelpatriotpartners.com/ Find Your Path with Steel Patriot Partners: https://steelpatriotpartners.com/find-your-path/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Jason LaPointe, Michael Parisi, Exostar, Steel Patriot Partners, Sean Martin, brand story, brand marketing, marketing podcast, brand feature, FedRAMP, FedRAMP-moderate, CMMC, CMMC 2.0, defense industrial base, DIB, controlled unclassified information, CUI, compliance inheritance, C3PAO, FedRAMP audit, platform modernization, GCC High, Department of War, defense supply chain, cybersecurity compliance Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

The SaaS CFO
From Army Special Forces to AI Finance: A CFO's Unconventional Path

The SaaS CFO

Play Episode Listen Later Jul 23, 2026 23:53


Welcome to The SaaS CFO Podcast, where we dive deep into the financial and operational strategies shaping the future of SaaS companies. In this episode, Ben sits down with Brian Mongeau, CFO at Cav—a company revolutionizing compliance and assurance for high-reliability organizations in both the government and commercial enterprise space. With a career spanning Army Special Forces, stints at Goldman Sachs and CrowdStrike, and extensive experience in early-stage security tech investing, Brian Mongeau offers a unique perspective at the intersection of finance, product, and go-to-market strategy. Together, they explore Cav's evolution from legacy SaaS to the development of its AI-driven ComplianceOS platform, the challenges of pricing and margins in an era powered by tokens, the intricacies of fundraising in a capital-efficient environment, and the lessons learned from driving enterprise growth and retention. Whether you're a SaaS founder, operator, or fellow CFO, this episode is packed with actionable insights for navigating today's rapidly changing landscape. Show Notes: 00:00 Early career experiences and learnings 04:21 Scaling and operationalizing the business 06:52 Developing ComplianceOS and Fundraising 09:55 Importance of cross-department communication 15:18 Importance of Customer Referrals 18:13 Discussing efficiency metrics in federal space 21:21 Investment in Compliance and FedRAMP 23:16 Exploring the CAVHQ website Links: Brian Mongeau's LinkedIn: https://www.linkedin.com/in/brian-mongeau/ Cav's LinkedIn: https://www.linkedin.com/company/caveonix Cav's Website: https://cavhq.ai/ To learn more about Ben check out the links below: Subscribe to Ben's daily metrics newsletter: https://saasmetricsschool.beehiiv.com/subscribe Subscribe to Ben's SaaS newsletter: https://mailchi.mp/df1db6bf8bca/the-saas-cfo-sign-up-landing-page SaaS Metrics courses here: https://www.thesaasacademy.com/ Join Ben's SaaS community here: https://www.thesaasacademy.com/offers/ivNjwYDx/checkout Follow Ben on LinkedIn: https://www.linkedin.com/in/benrmurray

ScanNetSecurity 最新セキュリティ情報
Tenable One Cloud Exposure が米政府認証「FedRAMP High」と「IL5」を取得

ScanNetSecurity 最新セキュリティ情報

Play Episode Listen Later Jul 23, 2026 0:18


Tenable Network Security Japan株式会社は6月29日、「Tenable One Cloud Exposure」が米国政府の最も厳格なセキュリティ認証の一つであるFedRAMP High および Impact Level(IL)5の承認を取得したと発表した。

The GovNavigators Show
Improving Performance with Dana Fowler

The GovNavigators Show

Play Episode Listen Later Jul 20, 2026 27:43 Transcription Available


This week on the GovNavigators Show, Robert and Adam welcome Dana Fowler, member of the GovNavigators Network, to walk us through her career path and offer insights on government performance reform. Dana details her interesting start in the federal government as “basically a deckhand on a fishing boat,” before moving onto the Substance Abuse and Mental Health Services Administration, the CDC, the Performance Improvement Council within GSA, and the Department of the Interior, in a performance management field she never expected to be a part of. The show raises the importance of leveraging data for decision-making, measuring the right things for the right reasons, and the value of an outside perspective. Plus, Dana gives us a peek into her new projects that work on government reform from the outside, using the knowledge she's collected as a “practitioner” within. Show Notes: House Budget Committee: Press Release on Reconciliation 3.0 The Hill: Key House committee advances framework for reconciliation 3.0 Congress.gov: Budget Impoundment and Control Act of 1974 The Washington Post: Wildfire smoke in DC FedRAMP: FedRAMP 20x DOW: Department of War Suspends CMMC Phase II Requirements Federal News Network: Pentagon suspends CMMC phase two requirements NOTUS: The Social Security Chief Keeps Sending Staff His Daughter's Pretzels Performance.gov: GPRA IBM: IBM Center for the Business of Government We the Doers: We the Doers website House Oversight: Emerging Fraud Threats and the Evolving Fraud Landscape hearing IMDB: Movie reference What's on the GovNavigators' radar? July 21-23rd: AGA Professional Development Training (PDT) 2026, Washington, DC July 21st: ACT-IAC Supply Chain Innovation Forum, Reston, VA July 23rd: GovForward's 8th Annual Carahsoft Summit on FedRAMP, Washington, DC 

Security Visionaries
The AI Public-Private Divide

Security Visionaries

Play Episode Listen Later Jul 14, 2026 34:46


On the latest episode of Security Visionaries, host Bailey Popp sits down with Teresa Carlson, Global Head of Public Sector at Anthropic and former CEO of the General Catalyst Institute, for a wide-ranging conversation on the intersection of AI, cybersecurity, and public-private collaboration. Teresa draws on nearly three decades in technology to share what it truly takes to work with government. From navigating compliance frameworks like FedRAMP to building sponsor networks that accelerate the path to authority to operate. The discussion explores how security leaders can shift from a checklist culture to an outcomes-based mindset, and why going in as a partner, not a vendor, is the defining factor for success. Teresa and Bailey also tackle the fragmented global AI regulatory landscape, the challenge of data sovereignty, and why startups bear a disproportionate burden in a world of conflicting mandates. This episode's bottom line? AI is minting a new generation of citizen developers and the opportunity has never been bigger.

Security. Cryptography. Whatever.
Trump's Golden Post-Quantum EO(s)

Security. Cryptography. Whatever.

Play Episode Listen Later Jul 2, 2026 56:37 Transcription Available


The dear leader has actually bleated out some not-dumb executive orders (EOs) to accelerate adoption of post-quantum crypto for the US government! This looks to be in response to a flurry of advancements in quantum computing and quantum attack algorithms a few months ago. We cram legalize into our eyeballs— plus, ECDSA.fail!Watch on YouTube: https://www.youtube.com/watch?v=7ZwQpN_F6P8Transcript: https://securitycryptographywhatever.com/2026/07/02/trumps-golden-post-quantum-eosLinks:- The EO https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/- CNSA2 https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF- https://media.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF- https://www.ecdsa.fail/- https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/- https://blog.cloudflare.com/post-quantum-roadmap/- https://blog.google/innovation-and-ai/technology/research/neutral-atom-quantum-computers/- https://en.wikipedia.org/wiki/FedRAMP- https://www.whitehouse.gov/presidential-actions/2026/06/ushering-in-the-next-frontier-of-quantum-innovation/- https://blog.trailofbits.com/2026/04/17/we-beat-googles-zero-knowledge-proof-of-quantum-cryptanalysis/- https://scottaaronson.blog/?p=9861"Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

Govcon Giants Podcast
Three Ways to Turn Your Existing Skills Into Real Income Right Now | EP: 331

Govcon Giants Podcast

Play Episode Listen Later Jul 1, 2026 32:28


Making your first 10000 dollars doesn't require an LLC, a business plan, or any startup capital — just skills you already have and the willingness to use them differently. In this episode, Eric Coffie breaks down three real strategies he's personally used to help people generate $5,000 to $10,000 quickly, even with zero business infrastructure in place. If you've ever felt like you don't have enough resources to get started, this episode will show you exactly what's already in your hands. Learn how to package and sell a skill you already have, the same way Eric turned free YouTube content into a $397,000 course launch Discover how documenting a repetitive process, like a government compliance report, can save hundreds of hours and become a sellable asset Watch a live demo of vibe coding an app from scratch using Base44, built in real time during the call Understand why partnering with people who already have customers is the fastest way to generate revenue without building an audience first Get a breakdown of Y Combinator's Fall 2025 "Request for Startups," including AI-powered vocational training and FedRAMP approval automation EPISODE CHAPTERS: 0:00 - Welcome to the GovCon Giants podcast intro 1:22 - Why this episode is for people starting from zero 3:44 - Selling a skill you already know how to do 6:39 - Turning a LinkedIn following into a sellable course 9:31 - Documenting repetitive processes to save companies time 11:57 - Introducing vibe coding with the Base44 platform 15:18 - Partnering with people who already have paying customers 21:33 - Live demo building a late invoice tracking app 26:46 - Reveal of the finished vibe coded invoice app 27:45 - Y Combinator Fall 2025 request for startups breakdown 31:12 - Closing thoughts on using skills to buy back time Mindy gives you the federal opportunities, agency signals, recompete intel, and pursuit briefs that tell you not just what contracts exist, but which ones to chase and how to win them. Sign up for free Daily Alerts and get opportunities delivered to your inbox before the day starts.

FedBiz'5
AI, Cybersecurity, and Federal Buying: Where Small Contractors Can Still Break In

FedBiz'5

Play Episode Listen Later Jun 23, 2026 12:18 Transcription Available


Send us Fan MailAI is moving fast in federal contracting, but the real opportunity for small businesses may not be where everyone thinks it is.In this episode of FedBiz'5, we break down how AI, cybersecurity, and federal buying are converging, and why that creates both pressure and possibility for small business contractors. Agencies want AI-enabled solutions, but they also need security, governance, data protection, compliance, human oversight, and practical implementation support.That is where small contractors can still break in.You'll learn how AI is showing up in RFIs and RFPs, what “AI security layers” really mean in procurement terms, why CMMC, FedRAMP, CUI, and data governance matter more than ever, and which AI-adjacent lanes may be most realistic for small businesses heading into 2026.If you support cybersecurity, data modernization, compliance, cloud, training, governance, analytics, or mission-focused IT services, this episode will help you see where federal AI demand is headed and how to position before the market gets even more crowded.Visit us: FedBizAccess.comStay Connected: Follow Us on FacebookFollow Us on LinkedInNeed help in the government marketplace? Call a FedBiz Specialist today: 844-628-8914Or, schedule a complimentary consultation at your convenience. 

GREY Journal Daily News Podcast
What Does Twenty's Unicorn Status Signal for Defense Tech?

GREY Journal Daily News Podcast

Play Episode Listen Later Jun 17, 2026 1:06


Axios reported that Twenty, a cyber warfare startup, reached a $1 billion valuation. The development highlights investor interest in defense cyber markets that depend on compliance, accreditation, and long government sales cycles. Companies in this space often pursue FedRAMP, Authority to Operate, and DoD impact level requirements to handle sensitive data. Startups typically progress from SBIR awards and DIU or AFWERX prototypes to production contracts through OTA or traditional procurement. Export controls such as EAR, ITAR, and Wassenaar shape market access and allied sales strategies. Founders will watch for signs that Twenty secures accredited deployments and converts pilots into multi-year agreements.Learn more on this news by visiting us at: https://greyjournal.net/news/ Hosted on Acast. See acast.com/privacy for more information.

GREY Journal Daily News Podcast
How Is DHS Cyber Modernization Changing Federal Procurement?

GREY Journal Daily News Podcast

Play Episode Listen Later Jun 12, 2026 1:44


The Department of Homeland Security is pushing cyber modernization across civilian agencies through CISA programs such as zero trust implementation, Continuous Diagnostics and Mitigation, and Trusted Internet Connections 3.0. Budget requests have kept CISA funding near $3 billion, supporting multi-year investments in detection, response, and workforce. Leadership from Secretary Alejandro Mayorkas, CISA Director Jen Easterly, and DHS CIO Eric Hysen emphasizes joint defense, binding directives, and cross-component coordination. Workforce constraints persist despite the Cyber Talent Management System, prompting greater use of training and managed services. Acquisition relies on vehicles like FirstSource III, PACTS III, GSA MAS, NASA SEWP, and CDM DEFEND task orders. Compliance requirements now center on OMB secure software guidance, NIST control baselines, FIPS 140-3, and FedRAMP. Vendors that map capabilities to CISA's Zero Trust Maturity Model and prepare attestations and authorizations can better align to agency buying priorities.Learn more on this news by visiting us at: https://greyjournal.net/news/ Hosted on Acast. See acast.com/privacy for more information.

Business of Tech
Vendor Outcomes, Warranties, and the Shift from Risk Manager to Delivery Arm for MSPs

Business of Tech

Play Episode Listen Later Jun 3, 2026 13:03


Outcome-based managed security and attached vendor warranties are driving a new form of coverage-based vendor lock-in for MSPs and IT service providers. Vendors such as Intezer and SPECTRA are introducing performance guarantees, SLAs, and cyber resilience warranties that require MSPs to fully standardize on their architectures. This evolving model shifts accountability for enforcement and risk management from the individual MSP to the vendor's operating model, thereby altering the independent role of the MSP within client environments. A notable example is Intezer's Amplify Partner program, which asserts that its platform can process 100% of security alerts while escalating fewer than 2% for human review—claims the company frames as outcomes rather than product specifications. SPECTRA's use of certification-linked warranties, distributed via Ingram Micro, establishes channel-distributable assurance products with explicit conditions attached at every level. According to a Check Point report, while 77% of organizations report having adopted AI for cloud security, only 26% feel capable of enforcing those strategies, revealing a gap between security intent and operational ability. This structural shift is further illustrated by Merlin Cyber's FedRAMP managed service offering, Lumen's MDR enhancements targeting mid-market MSPs, and Trustlogix's addition of intent-based authorization controls. The FBI's announcement regarding Microsoft 365 OAuth token hijacking and recent vulnerabilities in widely used platforms like ConnectWise Automate underscore the real-world risks of automation platforms being targeted. These developments collectively point to growing operational complexity, rising compliance burdens, and the need for MSPs to separate their commitments from upstream vendor claims. For operators, the trend demands increased scrutiny of warranty terms, claim denial conditions, and SLA language before making any client-facing assurances. MSPs risk absorbing liability if they repeat vendor marketing claims without contractual clarity or operational control. Effective governance now requires independently produced, audit-ready evidence that documents compliance and enforcement separate from vendor portals. As assurance sales proliferate, the operational gap between acting as an underwriter versus a reseller will drive market differentiation, affecting both pricing structures and eligibility for vendor-backed coverage. 00:00 Channel-Ready Security 03:41 Policy vs. Reality 05:59 MFA Isn't Enough 09:12 Why Do We Care?    Supported by:  ScalePad Moovila   

Federal Drive with Tom Temin
"FedRAMP certified" vs. "FedRAMP authorized"

Federal Drive with Tom Temin

Play Episode Listen Later May 27, 2026 7:13


The Federal Risk Authorization and Management Program is making a simple word change that will hopefully put to rest some long-standing confusion about the cloud security program. Under the new rules, cloud services the program has approved will be dubbed “FedRAMP certified” instead of “FedRAMP authorized.” Nicole Thompson is the security director for FedRAMP at the General Services Administration. She talked about the latest changes with Federal News Network's Jason Miller. See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

Business of Tech
AI Governance Hurdles in Defense: Jason Tierney Examines CMMC Barriers for MSPs

Business of Tech

Play Episode Listen Later May 26, 2026 26:33


The episode details a tightening regulatory environment driven by new enforcement timelines for Cybersecurity Maturity Model Certification (CMMC), altering how MSPs and IT service providers are expected to deliver both compliance and operational services for U.S. defense contractors. Structural pressure stems from the Department of Defense making CMMC Level 2 compliance a contractual mandate for approximately 300,000 defense contractors, shifting risk and accountability towards providers who manage compliance workflows, technical environments, and client behaviors. C3 Integrated Solutions and their dual CMMC Level 2 certifications exemplify this transition, with clear implications for co-ownership of compliance outcomes and increased scrutiny on provider practices. The most consequential development is the substantial gap between compliance requirements and the current readiness of the defense contractor base. As of early 2026, only around 8% of contractors have obtained CMMC Level 2 certification, despite enforcement being implemented in contracts starting in November of the same year, according to Dave and Jason. Challenges arise from cost, organizational bandwidth, and complexity, with MSPs serving as pivotal partners to small subcontractors lacking in-house resources for process documentation and change management. Assessment scheduling bottlenecks and insufficient documentation are delaying certifications, increasing risk that many contractors and their service partners will miss the rapidly approaching deadlines. Related developments reinforce the central issue of operational risk and governance complexity. Jason Tierney illustrates the difference between technical compliance and true assessment readiness, citing real-world examples where insufficient evidence and poor understanding of process details lead to significant assessment delays. The rise of compliance-as-a-service offerings, enclave computing environments, and specialized governance tooling are attempts to address those gaps, but also introduce new layers of pricing, platform selection, and accountability concerns, especially when third-party tools fail to meet strict requirements such as FedRAMP moderate for handling sensitive data. For MSPs and IT leaders, the shift imposes higher barriers to entry, increased legal and contractual exposure, more rigorous documentation and process controls, and the need for customized delivery models that support both technical defenses and organizational behavior change. Providers must navigate conflicting requirements between specialized regulatory environments and multi-tenant tooling, manage escalating costs for both themselves and clients, and clarify responsibility boundaries in shared compliance scenarios. The requirement for human oversight—particularly in automated or AI-assisted compliance tooling—remains non-negotiable, reflecting the ongoing gap between technical implementation and credible assessment outcomes. Supported by:CometBackupMoovilaHaloPSA

@BEERISAC: CPS/ICS Security Podcast Playlist
AI Agents & Cybersecurity: Identity, Compliance, and the New Risks Facing IT and OT

@BEERISAC: CPS/ICS Security Podcast Playlist

Play Episode Listen Later May 13, 2026 66:44


Podcast: PrOTect It All (LS 27 · TOP 10% what is this?)Episode: AI Agents & Cybersecurity: Identity, Compliance, and the New Risks Facing IT and OTPub date: 2026-05-11Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarization AI agents are changing cybersecurity faster than most organizations can adapt. In this episode of Protect It All, host Aaron Crow welcomes back cybersecurity veteran Ken Foster for a deep dive into how AI is reshaping risk, identity, and resilience across IT and OT environments. With more than 30 years of experience spanning the Navy, manufacturing, fintech, government programs, and startups, Ken brings a grounded, real-world perspective on what organizations are getting right and dangerously wrong about AI adoption. Together, Aaron and Ken explore the growing challenges around AI agents, identity governance, shadow AI, compliance, and attribution in highly regulated industries. As AI tools become embedded into workflows and decision-making, organizations must rethink how they manage access, monitor activity, and maintain resilience against rapidly evolving threats. You'll learn: Why AI agents introduce new identity and governance risks The dangers of shadow AI inside enterprise environments How AI impacts compliance, attribution, and accountability Why foundational practices like patching, segmentation, and documentation still matter The role of continuous monitoring in AI-driven environments How organizations can balance innovation with resilience and control Whether you're leading cybersecurity strategy, managing critical infrastructure, or navigating AI adoption inside regulated environments, this episode delivers practical insights for securing the next generation of digital operations. Tune in to learn how AI is transforming cybersecurity - and what leaders must do to stay ahead - only on Protect It All. Key Moments:  07:47 AI guardrails discussion 12:02 Patching and network segmentation 20:44 AI changing job roles 24:24 FISMA and FedRAMP concerns 29:18 Emergency response planning 35:36 Choosing the right tech team 37:14 Discussing accountability and risk 46:31 Developer access problems 51:50 AI Dependence Risks 57:36 AI in pen testing 58:55 AI in risk prevention About the guest : Ken Foster is a veteran cybersecurity leader with 25+ years of experience in enterprise security, risk governance, and global infrastructure strategy. Currently Head of Global Architecture at Adient, Ken has previously led cybersecurity and compliance programs at Fleetcor and Fiserv, specializing in IAM, cloud security, regulatory compliance, and risk-based cybersecurity strategy. He is known for helping organizations balance innovation, resilience, and operational execution in highly regulated environments. How to connect Ken: http://linkedin.com/in/kennethfoster/ Connect With Aaron Crow: Website: www.corvosec.com  LinkedIn: https://www.linkedin.com/in/aaronccrow Learn more about PrOTect IT All: Email: info@protectitall.co  Website: https://protectitall.co/  X: https://twitter.com/protectitall  YouTube: https://www.youtube.com/@PrOTectITAll  FaceBook:  https://facebook.com/protectitallpodcast   To be a guest or suggest a guest/episode, please email us at info@protectitall.co Please leave us a review on Apple/Spotify Podcasts: Apple   - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124 Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4The podcast and artwork embedded on this page are from Aaron Crow, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.

CISSP Cyber Training Podcast - CISSP Training Program
AI Poisoning the Quiet Enterprise Threats and CISSP Questions (Domain 1)

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later May 7, 2026 28:05 Transcription Available


Send us Fan MailQuiet failures are the ones that scare me most, and enterprise AI creates a brand-new way for them to spread. If a chatbot becomes the “trusted employee” everyone relies on, a slow drip of bad documents, outdated procedures, or deliberately manipulated data can poison decisions for months without a single red flag. We break down what that looks like in real organizations, why it differs from the Hollywood version of a hack, and how the business impact shows up as confident misinformation rather than obvious outages.We also dig into the difference between data poisoning (deliberate manipulation) and data pollution (accidental garbage at scale), then connect it to retrieval augmented generation (RAG). RAG is powerful because it answers from your internal knowledge base, but that same knowledge base becomes the attack surface and the “source of truth” the model won't question. I share practical steps you can take right now: audit what your AI actually trusts, map the full AI contact surface across workflows and repositories, treat the AI pipeline like an untrusted vendor, and assign a named owner for accuracy and security.Then we shift into CISSP Domain 1 practice with exam-style questions that force real trade-offs: using annual loss expectancy (ALE) to recommend a risk treatment to the board, applying NIST RMF guidance even when controls are inherited through FedRAMP, handling an ethics dilemma under the ISC2 Code of Ethics, spotting the biggest BCP gap when RTO and RPO targets collide with backup frequency, and explaining why HIPAA compliance does not automatically equal GDPR compliance for EU citizen data.If you're studying for the CISSP or you're building security controls around AI and cloud systems, this one is built to sharpen both your judgement and your test readiness. Subscribe, share this with a friend who's deploying AI internally, and leave a quick review so more CISSP candidates can find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

AWS for Software Companies Podcast
Ep205: AI Teammates Are Here - Asana's Multiplayer Approach to an Agentic Future

AWS for Software Companies Podcast

Play Episode Listen Later May 5, 2026 21:32


Asana CPO Arnab Bose breaks down how AI agents are transforming collaborative work management with multiplayer AI teammates that any team member can coach and correct.Topics Include:Asana is a collaborative work management platform used by 170,000+ companies worldwide.The "Pyramid of Clarity" connects individual tasks all the way up to company strategy.Asana's "work graph" maps tasks, teams, projects, and portfolios in one connected system.Generative AI now converts unstructured data like emails into structured project plans.Asana integrates directly with AWS, Gemini, and Claude to automate that conversion.AI Teammates are first-party agents that take on and complete tasks inside Asana.These agents work in multiplayer mode — visible, collaborative, and team-correctable.A third AI unlock is coming: letting any external agent builder plug into Asana's interface.Asana runs entirely on AWS, including a new FedRAMP moderate GovCloud deployment.AWS Marketplace listings help customers transact faster using existing AWS credits.Arnab advises startups to bet on AWS long-term rather than chasing short-term LLM trends.His 2026 prediction: multi-agent orchestration standards will be the enterprise AI battleground.Participants:Arnab Bose – Chief Product Officer, AsanaSee how Amazon Web Services gives you the freedom to migrate, innovate, and scale your software company at https://aws.amazon.com/isv/

Govcon Giants Podcast
How to Build a Cyber Defense Strategy That Meets CMMC Without Overspending | EP: 321

Govcon Giants Podcast

Play Episode Listen Later Apr 22, 2026 43:35


Cybersecurity is no longer a nice-to-have for government contractors — CMMC compliance is now a pre-award requirement, and if you haven't addressed it, your proposal may be dead before anyone reads it. In this episode, Eric sits down with a 15-year MIT Lincoln Laboratory veteran whose company now trains US Cyber Command to break down exactly what small and mid-size contractors need to know about cyber readiness in a rapidly shifting AI-driven threat landscape. Here's what you'll learn in this episode: Why CMMC and FedRAMP exist — and why meeting the minimum standard is just the floor, not the finish line, for contractors serious about winning DoD business How AI is accelerating cyberattacks on small businesses — attackers are using the same tools you use to run your business, and they're moving faster than ever What a cyber range actually is and how it works — the fire drill analogy that explains why buying tools without training your team is money wasted The right cybersecurity stack for small contractors — endpoint detection and response (EDR), firewalls, and SIEMs explained in plain language with practical starting points How to stop overspending on tools you don't use — why most CISOs only fully utilize a third of their security tools and how to build a lean, effective stack instead What AI adoption inside your company is actually exposing — prompt injection, data leakage, and the governance controls that protect your sensitive contract data   EPISODE CHAPTERS: 0:00 - Sponsor message and why cybersecurity just became mandatory 0:53 - Introducing a 15-year MIT Lincoln Lab cyber expert  6:01 - How the guest built cyber infrastructure for national defense 7:25 - What cyber ranges are and how they work for DoD training  9:16 - The fire drill analogy for understanding cyber readiness 11:07 - Why buying tools without training your team is not enough  13:28 - How the threat landscape has evolved from servers to cloud to AI 16:17 - CMMC and FedRAMP explained as a minimum bar for contractors  19:38 - The real-world financial losses that finally force action on cyber 25:21 - Building a practical cyber stack for small business contractors  31:17 - How AI is changing team size, efficiency, and detection capability 33:36 - Where AI adoption inside your business is creating new vulnerabilities  37:00 - How cyber range assessments work and how long they take  42:14 - What the next five years looks like for cybersecurity in govcon   If you want to learn more about the community and to join the webinars go to: https://federalhelpcenter.com/ Website: https://govcongiants.org/ Connect with Encore Funding: http://govcongiants.org/funding Connect with Lee Rossey: https://www.linkedin.com/in/lee-rossey-0873881/  

ITSPmagazine | Technology. Cybersecurity. Society
Cutting Through the Fog of More | A Brand Highlight Conversation with Michael Parisi, Chief Growth Officer of Steel Patriot Partners

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Apr 21, 2026 7:29


RSAC Conference 2026 is in the books, and the post-event read is familiar. More vendors, more AI-driven marketing, more noise, and a buyer-side audience that increasingly cannot tell who to trust. Michael Parisi, Chief Growth Officer at Steel Patriot Partners, joins ITSPmagazine for a quick post-event catch-up on what he walked away with, and what is quietly shifting underneath all that volume. The headline takeaway is what Michael Parisi calls the "fog of more." Marketing has done its job too well. CISOs and business leaders facing real decisions cannot tell competing solutions apart, do not know where to start, and are not sure their current stack is even the right one. Too much information has become its own information problem. What is shifting, according to Michael Parisi, is where the meaningful conversations actually happen. Closed-door, hallway, and dinner conversations have always existed at RSAC Conference, but more people are now openly recognizing that this is where the real industry decisions get made. That recognition is changing how teams plan to engage with future conferences and industry events. For Steel Patriot Partners, which describes itself as business owners first, engineers second, and security and compliance practitioners third, that is exactly the conversation they want to be in. This is a Brand Highlight. A Brand Highlight is a ~5 minute introductory conversation designed to put a spotlight on the guest and their company. Learn more: https://www.studioc60.com/creation#highlight GUEST Michael Parisi, Chief Growth Officer, Steel Patriot Partners | https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Learn more about Steel Patriot Partners: https://www.steelpatriotpartners.com Steel Patriot Partners Assistance Center: https://www.steelpatriotpartners.com View all of our RSAC Conference 2026 coverage: https://www.itspmagazine.com/rsac26 Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Michael Parisi, Steel Patriot Partners, Marco Ciappelli, Sean Martin, brand story, brand marketing, marketing podcast, brand highlight, RSAC Conference 2026, RSAC, cybersecurity compliance, fog of more, vendor noise, CISO, GRC, cybersecurity advisory, FedRAMP, CMMC, HITRUST, AI security marketing, hallway conversations, post RSAC Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Gov Tech Today
E72: RSA Conference Takeaways – Governing AI Agents and Securing Public Infrastructure

Gov Tech Today

Play Episode Listen Later Apr 14, 2026 18:34


Gov Tech Today hosts Russell Lowery and Jennifer Saha recap this year's RSA cybersecurity conference in San Francisco, noting the event's commercial scale and a smaller, dedicated public-sector track. Key takeaways include how “agentic AI” is moving from buzzword to reality, with public agencies urged to treat AI agents like users—requiring identity and access controls, least-privilege permissions, logging, and auditing—within existing governance frameworks such as FedRAMP, StateRAMP, and NIST. They discuss governance as a primary security control, growing attention to critical infrastructure and physical access as cybersecurity issues, and the challenge of tiny local utilities lacking staff and budgets, suggesting collaboration and shared services. The conversation also flags procurement and tool sprawl concerns, and explores what outcome-based security might mean for measuring automation, effectiveness, and ROI in government contracts.   00:00 Welcome to Gov Tech Today 00:15 What is RSA Conference 00:53 San Francisco Cleanup Talk 01:52 Public Sector at RSA 04:42 AI Everywhere at RSA 05:34 Agentic AI as Users 07:42 Governance as Security Control 09:25 Critical Infrastructure Cyber Shift 10:57 Small Districts Big Risk 12:38 Shared Services and Support 14:20 Procurement Must Catch Up 16:31 Outcome Based Security Metrics 18:09 Wrap Up and Next Year

Texas Talks
AI and Public Policy: Transforming Government w/Tanner Jones & Chris Minge

Texas Talks

Play Episode Listen Later Apr 9, 2026 46:01


This episode kicks off the Texas Talks Special Series: AI and Public Policy, a multi-part series exploring how artificial intelligence will reshape governance at every level in the years ahead. Artificial intelligence is advancing at an unprecedented pace — but can government keep up? In this episode of Texas Talks, host Brad Swail is joined by Tanner Jones and Chris Minge, cofounders of Vulcan Technologies, to launch the series with a deep dive into how AI is already transforming the private sector — and why government risks falling dangerously behind if it fails to adapt. Jones and Minge explain how their company is working to bring “frontier AI” into state and federal government, giving policymakers the tools to better understand laws, budgets, and regulatory systems in real time. They argue that without modernization, the gap between private-sector innovation and government capability could grow so wide that it undermines effective governance. The discussion also dives into the structural problems holding government back — from outdated procurement systems to legacy vendors delivering obsolete technology — and how those inefficiencies impact everything from permitting to policymaking. The conversation also covers: • Why government technology often lags years behind the private sector • How outdated procurement systems slow innovation and increase costs • The risks of governments relying on outdated AI models • Why AI should serve as a tool for policymakers — not replace them • How Vulcan's platform helps navigate massive legal and regulatory datasets • The challenge of building clean, usable government data from fragmented systems • How AI can reduce months-long processes (like permitting) down to days • The dangers of a fragmented, state-by-state regulatory patchwork • Why startups — not just legacy vendors — are critical to innovation in government • How Texas is positioning itself as a national leader in AI-driven governance • The broader economic and policy implications of AI adoption Jones and Minge also highlight real-world results, including dramatic reductions in time spent on routine government tasks and the ability for public servants to focus more on high-level policy work instead of clerical processes. Looking ahead, they argue that states like Texas that successfully integrate AI into governance will see faster economic growth, more efficient public services, and a stronger competitive advantage — while those that fail to adapt risk falling further behind. 00:00 — Introduction to AI and public policy series 00:27 — Tanner Jones and Chris Minge introduce Vulcan Technologies 01:10 — Founders' background and company origin story 02:28 — The growing gap between private sector and government tech 03:55 — Why outdated government tech threatens the “Republic” 05:10 — Procurement failures and legacy vendors explained 06:59 — Why citizens often have better AI tools than government 07:47 — Are government buyers equipped to evaluate tech? 09:08 — How AI models rapidly become outdated 10:38 — Concerns about AI accuracy, hallucinations, and control 11:49 — AI as a tool vs decision-maker in government 13:13 — What happens if government falls too far behind 14:38 — Procurement bottlenecks and adoption challenges 16:10 — Vendor lock-in and inflated government tech costs 17:54 — Why Vulcan ships updates differently 18:58 — Real-world use cases: governors and policymaking tools 20:15 — Navigating legal, budget, and regulatory systems with AI 21:26 — Why generic AI tools fail for government use 22:42 — Building massive legal datasets from scratch 24:06 — The challenge of unusable government data (PDFs, scans) 26:17 — Texas innovation and the Regulatory Efficiency Office 27:47 — The risks of a fragmented AI regulatory patchwork 29:20 — Balancing AI innovation with necessary guardrails 31:16 — Compliance challenges and FedRAMP 33:02 — Real-world example: fixing permitting bottlenecks 35:23 — What becomes possible with AI in government 37:08 — Cleaning up contradictory laws and regulations 38:43 — Real results: time savings and productivity gains 41:21 — The future of AI-driven governance in Texas 44:06 — Economic growth and competitive advantage from AI adoption 45:03 — Closing thoughts and where to learn more Watch Full-Length Interviews: https://www.youtube.com/@TexasTalks

GREY Journal Daily News Podcast
Is AI Adoption by the Federal Government a Double-Edged Sword?

GREY Journal Daily News Podcast

Play Episode Listen Later Apr 6, 2026 2:40


The federal government is rapidly adopting artificial intelligence to enhance efficiency and security, but faces challenges including hidden costs from tech companies like Microsoft and Google, which offer AI tools at reduced prices that may lead to increased long-term expenses. Historical transitions, such as the shift to cloud computing, highlight similar issues with oversight programs like FedRAMP, which struggle with limited resources, potentially compromising security. The reliance on third-party assessors, paid by the companies they evaluate, introduces conflicts of interest, complicating the government's ability to ensure secure AI adoption. Addressing these challenges involves strengthening oversight programs, ensuring assessor independence, and evaluating long-term AI tool costs.Learn more on this news by visiting us at: https://greyjournal.net/news/ Hosted on Acast. See acast.com/privacy for more information.

GovCast
CDC's AI Strategy Embraces Speed, Flexibility | HealthCast

GovCast

Play Episode Listen Later Apr 3, 2026 13:10


The CDC is taking a major step forward in its approach to artificial intelligence with the release of a new four-year AI strategy, aimed at strengthening public health capabilities and modernizing data use across the agency. Outgoing acting Chief AI Officer Travis Hoppe discussed how years of foundational work have positioned the CDC to responsibly adopt and scale AI technologies. He underscored the importance of balancing innovation with federal compliance requirements, including FedRAMP authorization and rigorous cybersecurity standards, while maintaining strong partnerships with industry and state and local partners. As AI capabilities evolve, Hoppe underscores the importance of agility across federal IT leadership — continuously reassessing tools, guidance and workforce readiness to keep pace with a rapidly changing landscape.

ITSPmagazine | Technology. Cybersecurity. Society
Cutting Through the Fog: Trust, Outcomes, and What Real Consulting Looks Like | A Brand Spotlight at RSAC Conference 2026 with Michael Parisi, Chief Growth Officer of Steel Patriot Partners

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Mar 31, 2026 22:16


At RSAC Conference 2026, the noise is relentless. Vendor booths, AI pitches, and breathless marketing compete for attention at every turn. Michael Parisi, Chief Growth Officer at Steel Patriot Partners, joins Sean Martin and Marco Ciappelli on the ground in San Francisco to name what too few are willing to say out loud: most of the conversation happening on the show floor does not reflect the conversations that actually matter. The real exchanges, Parisi says, are happening backstage -- in the hallways, over coffee, between practitioners who trust each other enough to ask: does this vendor actually do what they say? That shift back to peer-driven trust is not a trend. It is a correction. Security leaders are exhausted and fragile, operating under intense pressure, and they are returning to the relationships they know rather than the research tools and AI-generated answers they do not trust. Steel Patriot Partners was built around exactly that dynamic. Their operating principle -- business owners first, engineers second, compliance and security people third -- runs counter to how most consulting firms approach an engagement. Rather than leading with frameworks or certifications, the team starts by asking what outcome the client is actually trying to achieve. Parisi is candid about how often that conversation leads them to steer a client away from the path they came in convinced they needed. That willingness to say no -- and mean it -- is what sets a trusted advisor apart from a vendor. The outcome-first philosophy shapes every engagement. As founder Jason Ford says, 80% of what Steel Patriot Partners does is a therapy session. Organizations coming in with complex compliance challenges -- FedRAMP, CMMC, HITRUST, DoD IL -- need more than a checklist. They need a partner who has lived those journeys themselves, made the mistakes, and can speak honestly about what is worth pursuing and what is not. Parisi's advice to anyone evaluating a consulting partner is pointed: ask the question up and down the team, not just of the founder. The firms that have genuinely lived what they sell -- and can talk about the failures as clearly as the successes -- are the ones worth trusting when the stakes are high. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Michael Parisi, Chief Growth Officer, Steel Patriot Partners LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Steel Patriot Partners: https://www.steelpatriotpartners.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Michael Parisi, Steel Patriot Partners, Sean Martin, brand spotlight, brand story, brand marketing, marketing podcast, cybersecurity consulting, compliance advisory, FedRAMP, CMMC, HITRUST, DoD IL, trusted advisor, outcome-based consulting, vendor trust, cybersecurity noise, RSAC Conference 2026, security leadership, GRC, business risk, human in the loop Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

The GovNavigators Show
Rewriting FedRAMP: Inside the Push to Modernize Federal Cloud Security

The GovNavigators Show

Play Episode Listen Later Mar 30, 2026 29:25 Transcription Available


This week on the GovNavigators Show, Adam and Robert sit down with Ryan Hoesing, Chief of Staff for FedRAMP, and Nicole Thompson, Security Director, for a deep dive into one of the most consequential federal IT programs undergoing transformation today.Ryan and Nicole walk through the sweeping changes to the FedRAMP program and explain what the new “FedRAMP 20x” approach means for agencies and industry. They unpack the shift from authorization to certification, the move toward continuous and machine-readable security data, and why redefining FedRAMP's role is critical to making cloud adoption actually work across government.Show Notes:Continued DHS appropriations uncertaintyLaunch of VP Vance's anti-fraud taskforceNew DEI EOWhat's on the GovNavigators' Radar:Mar 31: Oracle Federal ForumApr 8: ACT-IAC Contact Center Summit

The Information's 411
Crypto's Nasty Downturn Worsens, SpaceX IPO Hype Halo Effect, Selling AI in Regulated Industries

The Information's 411

Play Episode Listen Later Mar 30, 2026 44:24


The Information's Yueqi Yang talks with TITV Host Akash Pasricha about crypto's "crisis of faith" and why Bitcoin's value has halved since October. We also talk with Elon Musk Reporter Theo Wayt about how the SpaceX IPO hype is boosting—and threatening—the space ecosystem, and Haystack Partner Aashay Sanghvi about the "Big Token" thesis for AI startup exits and making it onto The Information's Next General Partners list. Lastly, we get into the complex world of FedRAMP and regulated AI with M12 Partner Cheryl Cheng.Articles discussed on this episode: https://www.theinformation.com/articles/cryptos-nasty-downturn-getting-worsehttps://www.theinformation.com/articles/spacex-hype-boosts-stocks-crosshairsSubscribe: YouTube: https://www.youtube.com/@theinformation The Information: https://www.theinformation.com/subscribe_hSign up for the AI Agenda newsletter: https://www.theinformation.com/features/ai-agendaTITV airs weekdays on YouTube, X and LinkedIn at 10AM PT / 1PM ET. Or check us out wherever you get your podcasts.Follow us:X: https://x.com/theinformationIG: https://www.instagram.com/theinformation/TikTok: https://www.tiktok.com/@titv.theinformationLinkedIn: https://www.linkedin.com/company/theinformation/

Govcon Giants Podcast
Decode Million-Dollar Proposals in 3 Minutes Using AI Tools

Govcon Giants Podcast

Play Episode Listen Later Mar 27, 2026 7:45


Federal contract proposals don't have to take days to decode — AI tools are changing the game for small business owners competing for government work. In this episode of the Federal Help Center Podcast, Eric Coffey walks through his exact process for using AI-powered platforms to analyze solicitations, identify compliance gaps, and determine whether a contract is even worth pursuing — all in under three minutes.

Business of Tech
Government Policy Moves Vendor Choice from Preference to Proof for MSPs

Business of Tech

Play Episode Listen Later Mar 24, 2026 11:42


The structural mechanism highlighted in this episode is the shift of government policy from serving as a regulatory guardrail to acting as a direct steering function in technology selection, shifting liability boundaries and procurement decisions onto MSPs and their contracts. Federal agencies, including the FCC and the White House, are no longer just prescribing security outcomes but are increasingly specifying acceptable inputs such as specific routers, AI contract terms, and cloud platforms, converting technology choices into explicit compliance obligations. A consequential development supporting this shift is the FCC's move to ban imports of consumer-grade routers manufactured outside the United States, a policy change that directly impacts not only residential but also business environments such as home offices and smaller hybrid setups. Additionally, the White House's push for a unified national AI governance framework, rather than a patchwork of state-based rules, further codifies what vendors and MSPs must document and justify in both procurement and ongoing service delivery. Contractual requirements—such as the GSA's draft AI clause—are moving compliance from best practice guidance to enforceable terms, influencing which vendors can bid for federal contracts and what they must attest to regarding AI-enabled services. Related stories underscore the tightening of enforcement through procurement and certification gates. The transcript cites the FedRAMP system as an example, where conditional approvals and review backlogs highlight operational challenges and reinforce how authorization is less about technical sufficiency and more about meeting buyer and audit expectations. The trend toward requiring supply chain and AI attestations by default in master service agreements is consolidating vendor choice around those that can produce defensible documentation, while increasing burdens for those unable to do so. For MSPs and IT providers, the practical implications are increased operational complexity and contract risk. Vendor selection now carries liability exposure that extends beyond technical performance to proving decisions in audits, insurance reviews, and contract disputes. Maintaining evidence-ready reports for backup, recovery, and AI governance is no longer optional, as the inability to produce such proof can result in being excluded from regulated verticals. The expected tradeoff is a consolidation of vendors and solutions, weighted toward those who offer prepackaged compliance and attestation capabilities, but with an accompanying risk of over-dependence and concentration. 00:00 Contract Conditions 02:53 Gates, Not Laws 04:34 Compliance Consolidates 07:30 Why Do We Care?  Supported by:  ScalePad  Nerdio 

Security Conversations
The greatest APT hunter of all time, Apple's exploit kit problem, Microsoft FedRAMP mess

Security Conversations

Play Episode Listen Later Mar 20, 2026 147:20


(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 90: We remember GReAT teammate Sergey Mineev, the legendary malware hunter behind discoveries like Equation Group and Project Sauron (Remsec), including stories about his methods and why he was the best to ever do it. Plus, another in-the-wild iOS exploit kit discovery and a long overdue conversation about Apple's responsibility to hundreds of millions of users on older iOS versions; the ProPublica Microsoft/FedRAMP bombshell, Interlock ransomware sitting on a Cisco zero-day, the White House AI policy framework, and Supermicro co-founder $2.5 billion AI chip smuggling bust. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.

Federal Tech Podcast: Listen and learn how successful companies get federal contracts
How Ethical Hackers Help Federal Agencies Find Hidden Cyber Vulnerabilities

Federal Tech Podcast: Listen and learn how successful companies get federal contracts

Play Episode Listen Later Mar 17, 2026 22:01


Today, we sat down with Trey Ford from Bugcrowd to talk about ethical hacking. One of the most memorable phrases from ancient Rome is Quis custodiet custodes? (Who Watches the Watchman?). This ancient admonition has direct application to federal cybersecurity. We know federal agencies spend millions of dollars to protect data. How does one ensure the contracted companies are doing their jobs? Traditionally, an organization would use penetration testers, contractors, or basic scanning methods. However, today's attack surfaces are expanding, and malicious actors are innovating so rapidly that we are being forced to consider more creative options. In other words, an annual penetration test against an AI-inspired attack is too focused to be effective. The innovation Bugcrowd brings to the table is a community of researchers who can attack a system from many perspectives. During the discussion, you will learn about federal vulnerability disclosure programs, how to overcome talent shortages, and how Bugcrown vets its research community. Trey Ford also touches on the FedRAMP journey, AI integration, and the evolving cybersecurity landscape, stressing the need for human creativity and dynamic responses to threats. Connect to John Gilroy on LinkedIn   https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com

Federal Drive with Tom Temin
Two December cases show DOJ is shifting its cyber enforcement into higher gear

Federal Drive with Tom Temin

Play Episode Listen Later Mar 4, 2026 13:08


Two very different cyber cases — a DFARS‑driven settlement and a criminal indictment involving FedRAMP misrepresentations; are giving contractors a preview of DOJ's posture for 2026. Both point to a more aggressive and more varied enforcement landscape. We're talking through what that means with Andrew Liebler and Lance Taubin of Alston & Bird.See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

Federal Tech Podcast: Listen and learn how successful companies get federal contracts
Fed up with FedRAMP? How Knox Delivers Authorization in 90 Days

Federal Tech Podcast: Listen and learn how successful companies get federal contracts

Play Episode Listen Later Feb 24, 2026 26:44


Connect to John Gilroy on LinkedIn   https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com When people look back on 2025 they will see many changes in the FedRAMP process.  It looks like a new administration examined the process, got feedback from companies, and launched new initiatives to speed up the process. During today's interview, Irina Denisenko (Knox CEO) details FedRAMP's challenges and something called "FedRAMP 20x." Knox runs the largest FedRAMP-managed cloud, enabling 90-day authorizations by hosting customers' production environments. Denisenko explains the story of the origin of Knox Systems:   she was running a training company and the Air Force wanted to use her product.  It would have taken so long to complete the FedRAMP requirements that she just bought a company that was FedRAMP compliant. It is hard to believe that the process is so frustrating that fewer than 500 apps are authorized at moderate/high FedRAMP The initiative from the GSA is called FedRAMP 20x  It shifts to continuous monitoring and continuous authorization, moving from annual audits (sampled every 3 years) and monthly CVE spreadsheets to real-time, machine-readable data. What Knox offers is a tried-and-true platform that has reduced time for compliance in order to better serve federal needs. 

Federal Tech Podcast: Listen and learn how successful companies get federal contracts
Fixing FedRAMP: How Automation Cuts ATO Time by 36 Weeks

Federal Tech Podcast: Listen and learn how successful companies get federal contracts

Play Episode Listen Later Feb 17, 2026 23:28


Connect to John Gilroy on LinkedIn   https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com Way back in 2011, one of the goals of FedRAMP was to eliminate software redundancy. The federal government had evolved to the point where one agency would spend millions of dollars on the same application program that the agency in the same zip code had just invested heavily in. The theory proposed by luminaries like Vivek Kundra was to move to the cloud to share services. Reducing cost and improving resilience. FedRAMP was the initiative that established a safe environment for federal cloud use. Companies can comply with regulations outlined in an Authorization to Operate (ATO). Well, fifteen years later, and we are seeing the same duplication not in the application programs, but in the process to get the ATO itself. For example, FedRAMP, RMF, and agency internal policies may require specific artifacts to satisfy one or the other. During the interview, Travis Howerton paints the legacy model—static documentation, annual/3-year audits, spreadsheets. His solution is to have AI assist with documentation, which will drastically reduce compliance time; he cites an example of reducing a process from 52 weeks to 356 weeks. RegScale uses OSCAL (XML/YAML/JSON) to auto-generate RMF artifacts and integrate with SIEMs (Splunk, Elastic), Axonius, ServiceNow, and APIs. Howerton understands the limitations of many automated systems and suggests that a human is a key component after the machine language has assembled the data to make the decision.    

ITSPmagazine | Technology. Cybersecurity. Society
Rethinking Public Health Workflows Through Automation and Governance: Why Data Modernization May Be The Key | A Conversation with Jim St. Clair | Redefining CyberSecurity with Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Dec 9, 2025 44:06


⬥EPISODE NOTES⬥Artificial intelligence is reshaping how public health organizations manage data, interpret trends, and support decision-making. In this episode, Sean Martin talks with Jim St. Clair, Vice President of Public Health Systems at a major public health research institute, Altarum, about what AI adoption really looks like across federal, state, and local agencies.Public health continues to face pressure from shifting budgets, aging infrastructure, and growing expectations around timely reporting. Jim highlights how initiatives launched after the pandemic pushed agencies toward modernized systems, new interoperability standards, and a stronger foundation for automated reporting. Interoperability and data accessibility remain central themes, especially as agencies work to retire manual processes and unify fragmented registries, surveillance systems, and reporting pipelines.AI enters the picture as a multiplier rather than a replacement. Jim outlines practical use cases that public health agencies can act on now, from community health communication tools and emergency response coordination to predictive analytics for population health. These approaches support faster interpretation of data, targeted outreach to communities, and improved visibility into ongoing health activity.At the same time, CISOs and security leaders are navigating a new risk environment as agencies explore generative AI, open models, and multi-agent systems. Sean and Jim discuss the importance of applying disciplined data governance, aligning AI with FedRAMP and state-level controls, and ensuring that any model running inside an organization's environment is treated with the same rigor as traditional systems.The conversation closes with a look at where AI is headed. Jim notes that multi-agent frameworks and smaller, purpose-built models will shape the next wave of public health technology. These systems introduce new opportunities for automation and decision support, but also require thoughtful implementation to ensure trust, reliability, and safety.This episode presents a realistic, forward-looking view of how AI can strengthen the future of public health and the cybersecurity responsibilities that follow.⬥GUEST⬥Jim St. Clair, Vice President, Public Health Systems, Altarum  | On LinkedIn: https://www.linkedin.com/in/jimstclair/⬥HOST⬥Sean Martin, Co-Founder at ITSPmagazine and Host of Redefining CyberSecurity Podcast | On LinkedIn: https://www.linkedin.com/in/imsmartin/ | Website: https://www.seanmartin.com⬥RESOURCES⬥N/A⬥ADDITIONAL INFORMATION⬥✨ More Redefining CyberSecurity Podcast: 

WBSRocks: Business Growth with ERP and Digital Transformation
WBSP788: Grow Your Business by Learning from Enterprise Software Stories - Jul 2025, Ep 25, an Objective Panel Discussion

WBSRocks: Business Growth with ERP and Digital Transformation

Play Episode Listen Later Nov 18, 2025 61:34


Send us a textThis week's customer experience and marketing technology updates highlight a clear shift toward deeper intelligence, tighter collaboration, and more secure enterprise-grade platforms. CallMiner strengthened its conversational analytics footprint with the acquisition of VOCALLS, while Contentstack expanded its composable ecosystem by launching the new Data and Insights solution. Mosaicx introduced the next generation of its Engage platform, and Salesforce continued its march toward unified workflows by embedding Slack directly into CRM collaboration. In the government and regulated markets, Talkdesk achieved FedRAMP authorization for its CX Cloud Government Edition, signaling a major milestone for secure cloud CX. Meanwhile, Treasure Data rolled out five new AI suites aimed at enhancing customer experiences, Uniphore unveiled a new suite of AI marketing agents, and Zeta Global provided fresh details on its new Zeta Answers offering—collectively reflecting increased innovation and maturity across the CX and martech landscape.In today's episode, we invited a panel of industry analysts for a live discussion on LinkedIn to analyze current enterprise software stories. We covered many grounds including the direction and roadmaps of each enterprise software vendors. Finally, we analyzed future trends and how they might shape the enterprise software industry.Video: https://www.youtube.com/watch?v=85vq3s9786EQuestions for Panelists?

WBSRocks: Business Growth with ERP and Digital Transformation
WBSP786: Grow Your Business by Learning from Enterprise Software Stories - Jul 2025, Ep 24, an Objective Panel Discussion

WBSRocks: Business Growth with ERP and Digital Transformation

Play Episode Listen Later Nov 11, 2025 61:14


Send us a textThe enterprise tech landscape saw a wave of AI-driven advancements this week, with major vendors pushing deeper into intelligent automation and unified customer experiences. Sage introduced its AI-powered Copilot to Sage X3, while Storyblok rolled out two new integrations to strengthen content operations. Workday expanded its ecosystem with a new AI Agent Partner Network and Gateway, and AdDaptive Intelligence broadened its AI-powered advertising platform. In the CX space, CallMiner acquired VOCALLS and Mosaicx launched the next generation of its Engage platform. Contentstack unveiled a new Data and Insights solution, Salesforce embedded Slack for tighter CRM collaboration, and Talkdesk secured FedRAMP authorization for its CX Cloud Government Edition. Rounding out the announcements, Treasure Data released five new AI suites focused on customer experience, Uniphore introduced a suite of AI marketing agents, and Zeta Global shared details on its new Zeta Answers offering—collectively signaling an accelerating shift toward more intelligent, integrated, and automated digital ecosystems.In today's episode, we invited a panel of industry analysts for a live discussion on LinkedIn to analyze current enterprise software stories. We covered many grounds including the direction and roadmaps of each enterprise software vendors. Finally, we analyzed future trends and how they might shape the enterprise software industry.Video: https://www.youtube.com/watch?v=iplWl80n90YZhdGlxBackground Soundtrack: Away From You – Mauro SommQuestions for Panelists?