Access the full text logs of this transmission for compliance and review purposes.
00:00:01:06 – 00:00:07:19
Actual
Welcome to Status Secure, the weekly Cyberthreat briefing for executives who refuse to operate in the blind.
00:00:07:21 – 00:00:20:08
Actual
Hosted by the watcher six collective, uniting former Army Special Forces and Naval Special Warfare communications operators alongside an industry leading CISO nominated for cybersecurity. Woman of the world.
00:00:20:10 – 00:00:27:05
Actual
We cut through the noise and give you the operational intelligence you need for mission success in a hostile digital environment.
00:00:27:07 – 00:00:28:10
Actual
The enemy is listening.
00:00:28:13 – 00:00:32:05
Actual
Is your status secure?
00:00:32:07 – 00:00:54:06
Actual
Welcome to Santa secure. Today we’re covering the ransomware as a service economy that has turned cyber attacks into a subscription based business, hitting every sector. The AI generated phishing that has erased the warning signs we spent decades teaching people to spot. And then we’re going to get into Cmmc level three. And why those of you who are currently in Cmmc have Cmmc are working towards level two.
00:00:54:07 – 00:01:07:03
Actual
What it means for you and if you want level three next year, what you have to do to get there. So let’s start with ransomware as a service. What is it and why does it change the threat? Math for every organization listening.
00:01:07:05 – 00:01:29:13
CISO
So if we go back in time and we talked about this before, but if we go back in time, the way is, you know, you’re bad actors with some, you know, some person in a basement, right. Like looking who looks like me right sitting there, you know, trying to trying to attack and then it moved into, you know, box and mask being a single bad actor adversary.
00:01:29:14 – 00:01:53:10
CISO
You know, being able to do multiple attacks so simultaneously. And now of course, like anything else, monetization. Right. Like making it bigger, making it better. So industrializing it, making it into a business. Right. So ransomware as a service. So, you know, the attacker no longer needs to be sophisticated to hit you. They they build developers build the malware.
00:01:53:10 – 00:02:15:01
CISO
And when it ain’t so you don’t have to know. You can just you just need to know and then purchase the service ransomware as a service. So this multiplies the number of attackers by doing this skill barrier. You don’t have to be you know, you don’t have to be a excellent coder anymore, right? Excellent hacker. Anybody can can send off ransomware.
00:02:15:02 – 00:02:40:11
CISO
So, you know, this makes it really hard because they’re just attacking like the, the volume, a number of bad actors just increased exponentially. And what do they do? Right. They then, you know, back in the day, it’s even now, I think a lot of companies, they say, hey, you know, back up right. Do back up, encrypt you back up and then if something happens we’ll just recover it.
00:02:40:13 – 00:03:06:17
CISO
So if we get ransomware, it will just recover from backup. Well that doesn’t matter if they’ve already stolen your data, right? So what they do is they get in, they steal your data, and then they ransomware you. Right. So they have your data and then they, you know, they can post it, they can sell it. And when you’re paying for the encrypting your data, that’s already that’s already on the, on the market, the tech, you know, like a prime example.
00:03:06:19 – 00:03:30:09
CISO
Hey it is. You can look at we talked about colonial Pipeline last time. You know that’s the dark side model. They they ran an affiliate program a help desk. And then they negotiated ransomware like this, like a business. So this this increases I mean, we talked about it again last time, you know, OT. Right? They are observing about 44% of ransomware.
00:03:30:15 – 00:03:55:18
CISO
That’s a lot. And it hits everyone though. You know health care A which gets your patient data and operations finance right. Financial services industry payment and account data tech right. They grab your source code and customer data. Hey gov can they you know they infiltrate and get your UI and your contact data. So it’s something that every every industry has to be aware of.
00:03:55:19 – 00:04:08:23
Actual
Yeah. And then there’s the AI generated phishing sitting on top of that. Because the way an attacker gets in the door has fundamentally changed. So walk us through that through kind of what’s been different in 2026. Yeah.
00:04:08:23 – 00:04:34:14
CISO
In phishing emails we used to teach people how to identify phishing emails. And if you practice it long enough, you can like I can look at an email now and pretty much be able to tell that it’s a phishing email, right? If it has the tap, if it has the signs and which is, you know, the, you know, email address is a little, you know, replacing letters with numbers and numbers with letters.
00:04:34:15 – 00:04:59:06
CISO
So instead of Microsoft.com, it’s Microsoft with a one instead of an I mean, you’re looking at like there, you know, it’s a generic email. It’s not personalized. Ain’t bad grammar. Misspellings aren’t links that when you have it over the link, like they go, they go to the wrong, you know, like some strange URL. Those are the things that we used to teach people to look for.
00:04:59:11 – 00:05:24:05
CISO
But now with AI, those emails are no longer. They no longer have those, right? They they look. They look exactly like you would expect from your internal company. Communication. Right? It has the same style. It actually goes out. So the AI will go out and social engineer and tailor your email to you. Right. So it makes it really hard to move.
00:05:24:07 – 00:05:50:17
CISO
It makes it really hard to identify because those those signs that we teach everybody to look for aren’t there anymore. Right. And then you’re also looking at like the deepfake voices made synthetic audio. I think it said something like, the only need, only need about eight words from you. Okay. And then they can and the AI deepfake can simulate your voice almost perfectly.
00:05:50:18 – 00:06:11:04
CISO
It’s so hard that the way the way that you identify a deepfake is you listen for breathing. You’re not going to be on a call listening for somebody to breathe, right? But really, that’s kind of the only way sometimes to to know that it’s not, you know, it’s not the real person. So just imagine that if you’re just an average person, right?
00:06:11:05 – 00:06:35:16
CISO
You’re working. You’re working. You know, it’s harder. It’s a lot harder. Right. So IBM did research and they found that roughly 16% of breaches now in AI driven attacks. And that’s just increasing. Yeah. That’s just going to get more and more. So I phishing is the entry. Ransomware as a service is the payload. And then it’s cheaper. It’s more convincing right.
00:06:35:17 – 00:07:01:14
CISO
It’s easier as an entry you know. And it feeds an industrialized extortion machine. So those things together are creating this machine that just continuously is trying to get in the front door through, you know, through to human social engineering and people. And then once they’re in, aren’t they, you know, they treat this ransomware as a service and they’re just it’s over and over again.
00:07:01:15 – 00:07:21:09
CISO
What’s that thing that says, you know, repeatable process, right. They’ve created a repeatable process, and it’s faster and it’s better. And it’s and so their results are going to be faster and quicker for them. So it’s cheaper for them. It’s more convincing. And it’s, you know, it’s supercharging the ransomware.
00:07:21:11 – 00:07:33:02
Actual
Got it. Yeah. So I’m listening to this and I’m like, all right, these threats are getting better. So like, what do I do to close the gap on both the ransomware economy and the AI phishing?
00:07:33:03 – 00:07:56:00
CISO
Well, you need to do your controls right. So, you know, the first thing is because you know that people are not MFA, right? MFA verification, verification protocols like procedures, you know, you you you just can’t trust. You know, you just can’t trust your eyes and your ears that you have to verify. You can’t rely on human judgment anymore.
00:07:56:02 – 00:08:31:19
CISO
So that’s going to be key is that you’re putting in automated controls. So you have multi-factor authentication. Your YubiKey right. Yeah. You know having procedures in place that your high like your high transactions like your high high value transactions have to have multiple approvers. Right. And there needs to be a process in that approval to ensure that the approval is actually coming from authorized and valid, you know, sources making sure that, again, your backups are immutable and tested.
00:08:31:21 – 00:08:55:23
CISO
You know, it. It’s, it’s the backups an attacker can’t reach or encrypt and you can restore. I mean, it’s bad enough that they may sell your data. They’ve already taken your data. Okay. But, you know, so they could publish it. But then on top of that, you have to pay ransomware, right? So at least, you know, at least be able to restore your environment so you don’t have to pay the ransomware.
00:08:56:01 – 00:09:19:08
CISO
As far as like your data being, you know, sold on the market. Unfortunately, there’s very little you can do about that, right? But at least you can mitigate the one. The one with the one financial and operational risk and reputation too, right. Because if you get that up, the more people are going to feel, you know, comfortable that you’re doing what you’re supposed to do, you know, segment your network and make sure that blast radius is small.
00:09:19:08 – 00:09:39:06
CISO
If they do, if they do get it right, that networks, that one foothold become a full environment. And there’s so many there’s so many times where I see, you know, you know, networks have been architected legacy and nobody’s going back. And we viewed them to change them and make them more secure. So those are your three marching orders.
00:09:39:08 – 00:10:06:10
Actual
Got it. And so as this relates to, those in the government contracting space, those working with federal contracts or whatnot, the their answer to these threats is cmmc. And so we’ve discussed before about level two certification and how that’s mandatory. You know, if you have, CII and that’s coming and, and this year, in November, right, like that will be a mandatory thing you have to have.
00:10:06:10 – 00:10:26:15
Actual
And so what I wanted to talk about now, since we’ve already covered level two is okay, well, let’s get aware of what’s level three. Right. So level three is the thing that’s coming next year. And so for those companies like who who’s going to need level three. And what does that mean for them now. Because there’s a reason why we’re talking about it now okay.
00:10:26:17 – 00:11:19:12
CISO
So let’s let’s give let’s go get some history first okay. So CMC was actually you know and it stands for Cybersecurity Maturity Model Certification. And it came from originally from a DoD. I mean it’s you know, now I’m going to refer to it as it certification. It was actually in effect November 10th of 2025. Right. But what it meant in 20 last year was that you could self attest, you could just go ahead and, you know, say, hey, I have all these controls in place, you know, and that I am following, you know, I’m following the you know, that it’s a 110 controls and it’s based off of next, 801 71.
00:11:19:16 – 00:11:43:22
CISO
Right. And so you could self attest this year, November 10th, 2026, you have to have you can no longer self attest to level two. You have to get what’s called a certified third party assessment organization. So the C three, which is the, you know, CMM c a POW, which is your, you know, third party assessment organization. Okay.
00:11:43:23 – 00:12:05:16
CISO
And there’s only right now there’s only like a hundred of them. And it’s on the w c CIO website. And this them. So that’s just that’s one thing that you you have to use one of those, you know one of those C three O’s. They have to do they have to do the certification, the audit basically to certify you.
00:12:05:21 – 00:12:40:03
CISO
And then next year level three will be required. Right. And level three you cannot you can’t get a level three certification without already being level 2C3O certified. That’s very important. So if you push off the time to get level two, it’s just going to it’s just going to increase the timeline for you okay. And level three requires the government right there like the the the government agency Dib tech has to actually lead the assessment.
00:12:40:05 – 00:13:03:22
CISO
Who does it apply to anybody? First of all, if you’re applying. So if on it if you’re bidding on a contract and they will say it this year that they’re that they require him and I c level two certification, the one thing is that it’s not required until award. Okay. That contract. But it will stated in the you know in that RFP in the bid.
00:13:03:22 – 00:13:25:17
CISO
And so if you’re going to bid on any of those contracts, you need to be level two certified certified this year if you are a sub contractor. Okay. So you’re thinking, oh, well, you know, my plane is EMC certified, so I don’t need to be because I’m just a sub. You’re very much mistaken. It specifically says that subs subs also.
00:13:25:22 – 00:13:46:01
CISO
So you’re a subcontractor on a contract that requires EMC level two. You also must be okay. So just be aware of that. The other thing is joint ventures because you’re like, well I’m going to do a joint venture. And so my you know, so the other organization has the Ansi to certify it doesn’t matter if you’re doing a joint venture.
00:13:46:01 – 00:13:47:14
CISO
Both have to be certified.
00:13:47:19 – 00:14:13:08
Actual
Got it. And so here’s the part I want every contractor to understand because it’s the whole point of today’s episode. Level three is not a separate track that you can just jump into, right. So what I want to kind of reiterate and or have you reiterate is very specifically because it may feel like a long ways away, almost like when Star Wars or Marvel comes out with a movie and they, like, promote a trailer like two years in advance.
00:14:13:08 – 00:14:32:05
Actual
It’s almost like exhausting because I’m excited, but I’m going to forget about it, right? But this is important to think about now. And I just reiterate kind of break it down. If I’m doing like, what am I doing today, for example, that makes me a an entity that needs level three or that would need it next year. Right?
00:14:32:09 – 00:14:45:22
Actual
And so if I’m thinking ahead and I will need this next year, then what do I need to do now. Because it takes process, right? So what do I need to do now? Start doing today to prepare for next year when the requirement comes out. Yeah.
00:14:46:00 – 00:15:09:05
CISO
So so you have to be very careful because people are always like, you know, everybody has to be level three next year. That’s not true okay. So so level three, the DoD has very specific criteria about whether or not you’re required to do level three. Everybody’s required level two. Let’s let’s just start with that okay. Everybody’s required the prime the sub everyone okay.
00:15:09:07 – 00:15:29:02
CISO
If you’re if you are touching the UI, if you store it, if you process it, if you transmit it. Okay. For level three, that’s a little bit different. Level three because because again, you know, you have to go through you, you have to go through Jim Carrey, which is the defense industrial base, cyber security assessment center.
00:15:29:04 – 00:15:52:11
CISO
This is a government body. Oh, so you have to meet certain criteria in order to be required to do level three. But again, these are big contracts making a lot of money on the table. And they you know, there’s criteria you have to there’s we can talk about this in more detail. But if you if if you bid on any of those they will tell you that level three is required.
00:15:52:12 – 00:16:15:07
CISO
Right. And so based and then they it in there and you can ask them. So don’t you know if you see a requirement come out. You know from an agency it says level three CMC, CMC is required. Ask them what the criteria for, you know, being level three is because because those are for larger like larger contractors, government contractors.
00:16:15:09 – 00:16:37:02
CISO
If you are sub on that contract, you only need level two. I know it’s a little confusing. Everybody gets confused because the government loves to make it complicated, you know, complicated and have different tiers and have different like requirements. So just be aware of that. The DoD estimates that fewer than a thousand contractors will need level three. You know, they you know, give or take.
00:16:37:02 – 00:16:57:07
CISO
Right. So that’s why you have to be there. Like you have to understand, first of all, everybody has to be level two. And it doesn’t matter who you are. And that is that’s required this year. Next year level three is required. You need to deter, you need to figure out if you are going to be required to be level three, because that’s a lot harder.
00:16:57:08 – 00:17:04:21
CISO
I mean, again, you know, you’re not going through a private third party assessor, you’re going through a government agency to get that.
00:17:04:21 – 00:17:26:13
Actual
Got it. Yeah. That helps clarify it. Maybe. So don’t get so scared thinking that you may need level three. You may not. Right. So let’s talk about the calendar. All right. Because this is maybe where the urgency comes from for those who do need it. So what’s the the roll out. And maybe what do they need to start doing today to prepare for level three next year?
00:17:26:14 – 00:17:58:05
CISO
You should already have. I mean, if you have, you should have already done. You know, the level one and level two self-assessment because that was required as of last year. Yeah. This year what you need is to get your C3po certification for level two. And that’s you know, and so make sure like, I will say this, a lot of them the reason the reason they’re doing this is to give time to roll it out, but also because self attestation okay.
00:17:58:07 – 00:18:18:10
CISO
So out of station they want they want the people who have self-satisfied and self attested right to actually prove that they have those controls in place that I mean, if you wanted to bid, I had to do is attest that you would level two. I mean, come on. Right. You know, you know, so everybody’s like, sure, I’m level two, I’m on this.
00:18:18:10 – 00:18:47:11
CISO
Right. But now it’s like, no, no, no, no, no, no. You know, that’s not good enough with the government where we have a lot of things going on in the world, there’s a lot of, you know, it’s a lot of threats happening. We cannot just trust. Right. We have to validate. Okay. So you know, this year, if you if you haven’t already, you need to be getting getting eight, three a C3po contract in place.
00:18:47:13 – 00:19:06:06
CISO
It may be because I’m going to tell you it’s only like 100 of them. And they are getting so busy they are getting backed up. You may not, you may say, you may think you’re ready, but you may not be able to get a C3po for like six months to eight months on their calendar. And then there’s a whole audit period right before you can get it.
00:19:06:11 – 00:19:37:01
CISO
So you need to really like sit down and look at the timeline, the, you know, the the other thing, I mean, we can talk about it, but you, you can get a conditional level two. And what does that mean. Because there’s a timeline for that too. Because if you get conditional, I will tell you that if you get conditional and you do not meet the requirements at the end of your conditional, you know, level two, I’m going to tell you that the government doesn’t like that they will put you on a list, and you will never be able to bid on a contract with them again.
00:19:37:02 – 00:19:58:13
CISO
Okay. So you have to be aware of that. You know, you have to understand that for phase three, you know, that’s again, because you know that you have the impact during the assessment. You have to you have to understand their process and how to get on on their schedule. It’s not your schedule. It’s their schedule. Okay. So the sooner the sooner.
00:19:58:13 – 00:20:08:23
CISO
So you can see already, right. Like you know what what this timeline and what I’m saying July of 2026. So November of 2027. It’s right around the corner.
00:20:09:01 – 00:20:33:16
Actual
Okay. Got it. Yeah, yeah. You know, no, this kind of makes me think, I don’t know, maybe I’m the only one thinking this, but it’s sort of like, man, you know, this just, just just one other thing that we got to do, right? And it’s kind of like, well, the government may actually be a little behind because, you know, if you look at some of the other private sector things that are like this, you look at soc2, you know, for, let’s call it a tech startup, it’s very similar.
00:20:33:16 – 00:20:51:04
Actual
And they’ve already been doing that. Right. Like Soc2 type one is a self attestation of this is what we’re doing. But then what’s actually required of them is type two. And that’s kind of what this cmmc level two is, which is you have someone come in and say, oh, you’re actually doing it. It’s one thing to say you’re doing.
00:20:51:05 – 00:21:07:06
Actual
It’s another thing for for a third party to say, no, no, no. You’re they’re actually doing the thing they said they were doing. So if anything, the government is kind of behind them and they’re allotting and affording quite a bit of time for people to sort of get, get caught up really to the private sector in terms of security.
00:21:07:10 – 00:21:28:01
Actual
So, and this connects directly to the thing we’ve hammered on this show, the, executive whose name is on the document, you know, we covered it in the cmmc, the part one and two that we did with, where we talked about the power school ruling, I mean, health care and finance. And so walk us through, I guess this would be like, maybe the last thing we talk about.
00:21:28:02 – 00:21:36:12
Actual
Let’s let’s talk about sort of the leadership, right? Who’s, who’s the people that are attesting saying, yeah, we’re good. What’s the liability there?
00:21:36:14 – 00:21:55:16
CISO
Well, first I want to I want to make sure it’s clear. So for the for the soc2 type one, it’s you still need a third party, but you’re just saying that, hey, these are these are the controls that I have in place, and I can show you, you know, like they’re here. Not that they’re operating effectively, just that they’re they’re they’re in place.
00:21:55:16 – 00:22:14:23
CISO
Right. And then the type two is you have to operate them across a period of time. And that’s what’s being added by the third party. So for the I see them see you know they because they allowed the self attestation. Right. And this is that’s more like HIPAA. You can’t get a HIPAA certification like you can’t get by certified.
00:22:15:01 – 00:22:38:09
CISO
Right. You just have to do the controls and say I I’m compliant with Hipa. Right. Okay. So the government, you know, it’s similar to that. And HIPAA comes from, you know, the government as well. So they allowed that. But what they really want to do is what is this part second part where you have to get the third party and then you have to have the, you know, the agency is they’re looking for false claims.
00:22:38:13 – 00:23:01:11
CISO
Right. So they so this false claims, the False Claims Act. So let’s say for instance you last year and I mentioned it right, a lot of companies to say hey I’m level two. I’m attesting to it so I can bid on this contract. Well now if you can’t get level two certified, what does that mean about your attestation last year?
00:23:01:13 – 00:23:31:01
CISO
Right. So now it’s, you know, you you know, you you just submitted an inaccurate CMC out of station to a government contract, right? So you have false claims act liability. Now the DOJ civil cyber fraud Initiative is going to actively pursue I would think that they would pursue, you know, like if you were on a contract and used attested that you were level two and now you can’t get level two certified.
00:23:31:03 – 00:24:02:10
CISO
Hey, there’s there’s there there’s a potential for a case there. Right? So, you know, you’re the senior official who signs off, right. And like we we talk about like you mentioned, we talk about all the time. Your name is on that affirmation. You own that name. If nothing if nothing else, you you know, you need you need to make sure that your organization, it’s actually level two, you know, and operating those controls because that’s self attesting level to compliance.
00:24:02:10 – 00:24:15:03
CISO
You don’t actually have it isn’t just a lost contract. It’s a potential fraud claim. Now okay. So the verified C-3po assessment is what protects the executive from signing something they can’t back up.
00:24:15:08 – 00:24:32:17
Actual
Got it. Yeah. And so let’s get into the marching orders. And as we’re, you know, getting to the end of this episode, we covered ransomware as a service and I phishing at the top. We just covered cmmc the level two to level three dependency. And I guess we can call it saying that the 2027 clock has started for that.
00:24:32:21 – 00:24:38:03
Actual
So what are three things every defense contractor should execute to get ahead of this?
00:24:38:05 – 00:25:00:17
CISO
Yeah I mean we always talk about it’s a basic security right. You can’t protect what you don’t know. So the first thing is you need to scope you see why. Like you need to, you know, identify your key. You need to do cmmc. It’s based on 871. Right. So do that gap assessment. There’s 110 controls you know. No, no.
00:25:00:19 – 00:25:20:13
CISO
You know know what controls you have in place. Which ones are operating effectively that way. You know what the gaps are right. Because you can do a poem. That’s the other thing. The conditional CRC MC says you can do a poem. I think it’s like 18. Right? You know, remediations that you can have as long as they’re not critical.
00:25:20:15 – 00:25:40:21
CISO
And based on that, then you can, you know, then you can book like book your C3po like, right away. Like once you have your gap assessment, once you have a strategy or remediate whatever that looks like, you know, make sure you have the seat info already booked because they’re, they’re not going to they’re not going to be available if you wait.
00:25:40:23 – 00:26:10:01
CISO
Hey everybody. Every contractor now who wants to do that? You know, I go a government contract is looking at this and then decide now whether level three is in your future. Right. Because level two is required by everybody. But it’s the prerequisite for level one, level three. And you need to know that because it takes time. And I think I think the Dio w estimated like they estimated.
00:26:10:06 – 00:26:18:23
CISO
So they estimate that it’s going to cost roughly like 500,000.
00:26:19:01 – 00:26:33:06
CISO
Or more over three years depending on the size of your organization. That’s a lot. You need to plan that, and you can’t plan it in six months or a year. You need to be looking at it now if you haven’t already got it.
00:26:33:12 – 00:26:56:11
Actual
Well, ransomware as a service and I phishing those are prominent threats right now. Cheaper to launch, harder to spot and industrialize, to scale, to sell. So for the defense industrial base, Cmmc is the government’s answer, right? The calendar’s no longer theoretical. Level two is becoming mandatory. Level three arrives in 2027, of which there is no level three without getting level two first.
00:26:56:14 – 00:27:20:18
Actual
Right. So mission success starts with closing the gap between the threat in the framework and between the affirmation you sign and the controls that are actually running on your network. So trust but verify your own posture. Scope your key, run the gap assessment, book your C-3po path before the Q and the deadlines close on you, and let’s execute the standard and we’ll see you next week.
00:27:20:20 – 00:27:24:13
Actual
Mission. Success isn’t about luck. It’s about preparation.
00:27:24:15 – 00:27:27:14
Actual
You’ve heard the Intel. Now go put it to use.
00:27:27:16 – 00:27:35:00
Actual
If you need to verify your security posture. I’ve established a secure line at watcher 6.com/secure.
00:27:35:02 – 00:27:38:02
Actual
Go there to get the briefing the enemy doesn’t want you to have.
00:27:38:04 – 00:27:41:10
Actual
We’ll see you next week. Until then, keep your head on a swivel.