Uncategorized

Strengthening Critical Infrastructure: Our Commitment and Partnership with Dragos, Inc.

Posted on Jul 17, 2024

Strengthening Critical Infrastructure: Our Commitment and Partnership with Dragos, Inc.

The security of our nation’s critical infrastructure has never been more imperative. As partners to our clients in the Defense Industrial Base (DIB) and critical infrastructure, we understand the critical role we play in national security. Our commitment extends beyond compliance; we are dedicated to proactive collaboration and advanced cybersecurity measures. In line with this commitment, we are proud to announce our partnership with Dragos, Inc., a leader in industrial cybersecurity.

Partnership with Dragos, Inc.

Through our partnership with Dragos, Inc., we aim to leverage their expertise in industrial control systems (ICS) and operational technology (OT) cybersecurity. Dragos brings unparalleled capabilities in threat detection, incident response, and vulnerability management tailored for critical infrastructure. This collaboration enhances our ability to provide our clients with the most advanced security solutions, ensuring that their operations remain secure and resilient against emerging threats.

The Dragos Platform received the 2023 SC Award for Best Industrial Security Solution for its ability to help organizations identify their OT assets, manage vulnerabilities, and detect and respond to threats that target industrial control systems. In June, Dragos was named Best Incident Response Solution by SC Awards Europe. 

Through this partnership, MNS Group gains the benefits of the Dragos Global Partner Program, the only channel program to comprise OT cybersecurity technology, services, and threat intelligence supported by training that prepares partners as OT cybersecurity experts. The program helps develop and advance resellers as ICS/OT cybersecurity experts and advisors with the full spectrum of OT cybersecurity offerings in their portfolios

MITRE’s Call to Action

Recent insights from MITRE highlight the escalating threats posed by cyberattacks, particularly from nation-state actors such as the Chinese Communist Party (CCP), targeting essential services like energy, transportation, communications, and water systems. This environment necessitates robust measures and innovative solutions to ensure resilience and operational continuity.

MITRE ​ has been vocal about the need for the U.S. government to intensify efforts to safeguard critical infrastructure. A recent MITRE-Harris poll underscores the public’s concern, with 81% of respondents expressing worry over the security of vital services, and 78% believing that the federal government bears full or partial responsibility for fortifying these infrastructures. MITRE’s leadership emphasizes that the threat landscape has evolved significantly, requiring a shift from incremental improvements to comprehensive, coordinated responses involving both public and private sectors​.

Proactive Measures and Client Support

We are dedicated to supporting our clients by:

Implementing Advanced Security Protocols: Utilizing the latest technologies and best practices in cybersecurity to protect against sophisticated attacks.

Continuous Monitoring and Threat Intelligence: Providing real-time monitoring and actionable intelligence to preemptively address potential threats.

Training and Awareness Programs: Educating our clients on the latest cyber threats and best practices to maintain robust security postures.

Incident Response and Recovery: Ensuring swift and effective response to any cyber incidents, minimizing downtime and operational impact.

Looking Ahead

As threats to critical infrastructure continue to evolve, so must our strategies and partnerships. We remain committed to collaborating with industry leaders like Dragos, Inc., and aligning with MITRE’s recommendations to enhance our collective resilience. By fostering a culture of security and innovation, we aim to protect the vital services that underpin our nation’s security and prosperity.

For more insights into how we are working to secure critical infrastructure and our strategic partnerships, stay tuned to our updates and reach out to our team for more information.

Read More »

Forecasting Beyond the Clouds: How GovCons Can Plan for a Bright Future by Tracking the Right Metrics

Posted on Apr 30, 2024

Forecasting Beyond the Clouds: How GovCons Can Plan for a Bright Future by Tracking the Right Metrics

Small and medium businesses (SMBs), defined as those with under $25 million in annual revenue, are the economic backbone on which our nation depends. Every state in the union and members of every community have a vested interest in and depend on the success of small and medium businesses. To plan for success, businesses utilize forecasting. Forecasting employs past data to make educated predictions about future trends. Companies use this method to decide on budget allocation or prepare for expected costs in upcoming periods, usually influenced by the anticipated demand for their products and services.

How important is forecasting for SMBs to our nation’s overall economic health and security? Very. This is emphasized further when the focus is narrowed to GovCon SMBs. Their success- or failure- is shared and felt among our nation’s citizens. 

“Above all, the forecaster’s task is to map uncertainty, for in a world where our actions in the present influence the future, uncertainty is opportunity.” Paul Saffo 

Events over the last several years have allowed ample opportunity for business managers and executives to navigate uncertainty. Indeed, even the concept of certainty seems quaint among GovCons when the US has lost 30% of its defense industrial base (DIB) over the last 10 years, as shared by Isabella Guzman, administrator for the U.S. Small Business Administration (SBA). Forecasting for non-GovCons may include Sales Revenue, Cost of Goods Sold (COGS), Gross Margin, Operating Expenses, Interest and Tax Expenses, Capital Expenditures, Inventory Levels, Accounts Receivable and Payable, Cash Flow, Market Trends and Economic Conditions, Workforce Needs, New Projects and Investments, Break-even and Risk Analysis.

There are abundant challenges for GovCons to consider when forecasting in addition to the lengthy list above that are unique to them due to specific operational, regulatory, and financial environments:

Regulatory Compliance and Changes: GovCons must anticipate and plan for changes in government regulations, which can affect everything from contract bidding to execution. 

Budget Cycles and Funding Fluctuations: Government budgets are subject to political processes and fiscal cycles, leading to fluctuations in funding availability. They must have an understanding of the government’s budgeting process, the timing of appropriations and the (frustrating) potential for shutdowns.

Contract Types and Payment Schedules: GovCons deal with a variety of contract types (e.g., fixed-price, cost-reimbursement, time-and-materials) each with its own financial and performance risks. Forecasting must account for the specifics of these contracts, including payment schedules, performance milestones, and risk of adjustments.

Bid and Proposal Efforts: Forecasting in GovCons must include the costs and timelines associated with preparing bids and proposals, as well as the probability of winning contracts. 

Long-term Contracts and Lifecycle Management: Many government contracts are for long-term projects that can span several years. Forecasting needs to account for the lifecycle management of these contracts, including potential modifications, maintenance, and operational support.

Security Clearances and Classified Work: Projects requiring security clearances or involving classified information add layers of complexity to forecasting. This includes considerations for personnel clearances, secure facilities, and IT infrastructure.

Public-Private Partnerships and Joint Ventures: GovCons often engage in public-private partnerships or form joint ventures to pursue contracts. Forecasting must consider the dynamics and obligations of these partnerships, including shared risks and revenues.

Market and Political Environment: The demand for government contracting services can be influenced by political priorities, geopolitical events, and changes in policy. Forecasting in this sector requires a deep understanding of these external factors and their potential impact on contract opportunities.

Technology Adoption and Innovation Cycles: Government contracts may involve cutting-edge technology or require adherence to specific technical standards. Forecasting must factor in the costs and timelines for research and development, technology adoption, and potential innovation cycles.

Don’t Miss the Shifts 

Are there additional critical areas that GovCon’s should track into the future for their businesses to succeed in a climate of such uncertainty for sake of national security? Yes. As a business that provides compliance, information technology, and business consulting, we have insight into some areas that should be tracked now by GovCons that are often missed.

Survey Says: GovCons are Up at Night

In truth, executives are kept up at night by several issues regarding their companies that are unique to GovCon businesses. The GAUGE 2023 Report, by Unanet and CohnReznick, gathers information from 1,180 survey responses from a variety of government contracting professionals. 60% of respondents were in a C-Suite or Controller role, and more than half of the respondents were small and mid-sized businesses.

Read More »

Where do I start with CMMC compliance?

Posted on Dec 22, 2023

At long last, the CMMC proposed rule will be released on December 26, 2023! 

If you have not prepared to pass the CMMC Assessment, there is no time like the present! (And if we may be so bold, we suggest preparing for the journey with some music to get you in the right frame of mind!)

Where does a contractor in the Defense Industrial Base start?

Rally the troops, and choose a leader: CMMC compliance is a team effort. A common misconception of the CMMC program is that it contains all technical controls and requires little coordination with staff not directly involved with IT. However, the CMMC program controls involve much more than technical configurations: human resources, building security, administration and operations, accounting, and even external service and cloud providers may be inscope. 

Leadership starts at the top. Management must make clear that conforming to the requirements of CMMC is a priority. Kick off an all-hands meeting to align and educate the entire organization and include goals, defined roles and responsibilities, and communication channels. It is key to have one person designated to serve as the lead to coordinate your team’s efforts. In one company that MNS Group works with, the head of business development led the compliance implementation for the company. Why that role to lead the effort? Lost opportunity. This individual had a lot to lose if the company did not become compliant in time to win the contracts that provided the bulk of his department’s income, and he possessed the skills to educate, encourage, and track the various departments to contributions. Whoever in your organization secures the honor, they will require the support of the management team.

The good news is that if you are working with MNS Group, we are able to assist your team with our CMMC Certified Professionals and Assessors (CCPs and CCAs), with implementation and support toward compliance.

Determine the level you need to comply with.

Your contract and the type of information your company handles determines the level and number of controls your organization must meet. Every defense contractor will need to meet at minimum Level 1. The CMMC 2.0 model consists of three distinct levels, each representing a different set of cybersecurity practices and processes:

Level 1 – Foundational: This level is focused on the protection of Federal Contract Information (FCI) and encompasses the basic safeguarding requirements for this information as outlined in Federal Acquisition Regulation (FAR) 52.204-21. It includes 17 practices that are fundamental to cybersecurity, largely aligning with basic cyber hygiene practices. At this level, companies are required to perform annual self-assessments.

Level 2 – Advanced: Level 2 aligns with the protection of Controlled Unclassified Information (CUI) and is based on a subset of the security requirements specified in NIST SP 800-171. Level 2 applies to you if your company handles CUI; you are already subject to DFARS 252.204-7012 requirements and have been since late 2017. This level includes a total of 110 practices and focuses on the implementation of intermediate cyber hygiene practices to protect CUI. Level 2 requires companies to undergo an independent third-party assessment every three years to ensure compliance.

Level 3 – Expert: This level is intended for companies that are part of the defense industrial base and are handling critical national security information. Level 3 is based on a subset of the security requirements from NIST SP 800-172, along with additional practices and processes from other sources to protect CUI and reduce the risk from Advanced Persistent Threats (APTs). Compliance with Level 3 requires a government-led assessment every three years. The final rule is expected to have greater detail on this level.

Target your efforts based on the level at which your organization must comply. 

Scoping

If your company handles, creates, stores, or transmits CUI- who handles it? Where is it accessed, processed, or stored? The environment where CUI exists helps determine your scope. A System Security Plan (SSP) documents what controls are in place. The smaller the environment, the less expensive compliance efforts will be. Some companies find that an enclave for the CUI is a smart solution.

An enclave is a way for organizations to limit the endpoints that need to be secured, making compliance efforts more streamlined, resulting in less expensive and sometimes faster compliance. All contractors to the DoD will have Level 1 controls in-scope applied organization-wide, even if your CUI is confined to an enclave.

Read More »

COMPLY> The Journey

Posted on Dec 22, 2023

COMPLY> The Journey

There was never a task that was not enhanced by a great playlist! Achieving CMMC compliance is quite a journey! With 2024 on the horizon, it is a great time to rock out (with some humor) while making strides toward a stronger and more cyber-resilient company! Our team created a playlist to stream in the background. GO AHEAD- you deserve a little...

Read More »

Bracing for Impact: The Finalization of CMMC Rules and What It Means for DoD Contractors

Posted on Dec 4, 2023

As the finalization of the Cybersecurity Maturity Model Certification (CMMC) rule looms near, DoD contractors are on high alert. With CMMC 2.0, the Department of Defense (DoD) aims to streamline and strengthen cybersecurity requirements. This shift to a three-level model demands a strategic approach from contractors to ensure compliance and safeguard sensitive information.
Although the final CMMC rule has not been officially released yet, recent developments have brought significant updates. As of November 21, 2023, the Office of Information and Regulatory Affairs (OIRA) website shows an important change in the status of the eight components and the overarching Framework of the Cybersecurity Maturity Model Certification Program (CMMC). Previously marked as “Pending Review,” these elements have now been updated to “Consistent with Change.” This shift suggests that the CMMC program, along with its eight foundational policy elements, is advancing towards publication.

Read More »

Travel, Temps, and Tempests, OH MY! Take Steps to Keep Tech Tip Top

Posted on Jun 21, 2023

Travel, Temps, and Tempests, OH MY! Take Steps to Keep Tech Tip Top

Hurricanes, thunderstorms, and a reliance on air conditioning that taxes the power grids can cause outages and increase the risk of power surges. To prevent any potential damage from power surges, it’s essential that all your PCs or servers are connected to UPS devices. That’s the battery backup that kicks in during power outages. Check the integrity of your Uninterruptible Power Supply (UPS); make sure the light on the UPS is working properly. You can also unplug the UPS from the power source to see if it will still power your computer without external electricity.

Did you test and find the UPS is not working? Plan to replace the UPS as soon as possible. Simply power down and unplug your device before leaving for the day, especially if bad weather is expected. If you are one of our clients and need advice regarding a new UPS, just open a ticket via your portal or email and we will happily help you choose one!

Keep Connected with Your Hot Spot
Power outages often interrupt internet connectivity, even after the power returns! As a stopgap until service can be restored, consider using your phone as a hotspot to get connected and be able to work again.

Speaking of Heat….

Read More »