Cyber Defense Advisors

Year: 2026

The CMMC Pause Didn’t Let MSPs Off the Hook

The CMMC Pause Didn’t Let MSPs Off the Hook Why “We Don’t Touch CUI” Is Still One of the Most Dangerous Assumptions in the Defense Industrial Base When the Pentagon paused CMMC Phase II in July, many Managed Service Providers breathed a sigh of relief. They shouldn’t have. Yes, the Department of Defense temporarily suspended […]

Cyber Thoughts

The Smartest CMMC Strategy for Small Businesses May Be Scope Reduction

The Smartest CMMC Strategy for Small Businesses May Be Scope Reduction The DoD’s recent CMMC reset isn’t changing the goal of protecting CUI. It’s reinforcing an approach many organizations were already beginning to embrace: build smaller, smarter, and more defensible environments. The Department of Defense’s recent decision to pause the rollout of CMMC Phase II […]

Cyber Thoughts

More Small Defense Contractors Are Reconsidering Full GCC High Migrations

More Small Defense Contractors Are Reconsidering Full GCC High Migrations The DoD’s recent CMMC reset is reinforcing a question many organizations were already beginning to ask: Are we solving the actual problem, or are we reacting to fear? Something interesting is happening inside the Defense Industrial Base. Long before the Department of Defense announced its […]

Cyber Thoughts

CMMC Phase II Pause: What Defense Contractors Need to Know 

CMMC Phase II Pause: What Defense Contractors Need to Know The Department of Defense Has Announced It Is Pausing Implementation of CMMC On July 13, 2026, the Department of Defense announced that it is pausing implementation of CMMC Phase II while it conducts a 60-day review of the program.  Watch the live announcement here: DVIDS – Video […]

Cyber Thoughts

New Book Challenges Decades of Conventional Cybersecurity Thinking

New Book Challenges Decades of Conventional Cybersecurity Thinking Cyber Defense Advisors CEO Francis Schmuff Says the Industry’s Biggest Problem Isn’t Technology—It’s Contradictory Advice What if two cybersecurity experts could give completely opposite recommendations… and both be right? That’s the provocative question posed in The Dirty Little Contradictions of Cybersecurity, the newly released book by Francis […]

Cyber Thoughts

As AI Becomes Business-Critical, Hidden Security & Governance Risks Are Emerging

As AI Becomes Business-Critical, Hidden Security & Governance Risks Are Emerging Organizations are rapidly adopting generative AI to boost productivity. But many have yet to answer a more fundamental question: Is their AI platform secure, governable, and aligned with their long-term strategy? One employee uses AI to summarize reports. Another drafts customer emails. Engineers rely […]

Cyber Thoughts

Monitoring AI Systems: The Missing Piece of Responsible AI

Monitoring AI Systems: The Missing Piece of Responsible AI Many organizations focus heavily on deploying AI systems but spend far less time monitoring them after implementation. Yet ongoing monitoring is essential for maintaining security, compliance, performance, and trust. AI Control Implementation should always include monitoring and oversight mechanisms. Why AI Monitoring Matters AI systems can […]

AI Control Implementation

Preparing for AI Regulations Through Control Implementation

Preparing for AI Regulations Through Control Implementation AI regulations are evolving rapidly across industries and jurisdictions. Organizations that wait until regulations become mandatory may find themselves scrambling to implement controls under significant time pressure. Implementing AI controls today helps organizations prepare for future compliance requirements. Regulatory Focus Areas Emerging AI regulations often emphasize: Transparency Accountability […]

AI Control Implementation

AI Access Controls: Protecting Sensitive Data and Systems

AI Access Controls: Protecting Sensitive Data and Systems As AI systems gain access to enterprise data, controlling who can use those systems and what information they can access becomes increasingly important. AI Access Controls serve as one of the most fundamental safeguards within an AI governance program. Why Access Controls Matter AI systems often aggregate […]

AI Control Implementation