Cybersecurity Blog


Subscribe

Category: Compliance

GAO Report Flags Duplicative Cyber Reporting Requirements

GAO Report Flags Duplicative Cyber Reporting Requirements


Posted July 28, 2026 in Compliance, HIPAA, Cybersecurity, CMMC, NIST

A GAO analysis finds potentially duplicative cyber incident reporting requirements as the U.S. standardizes reporting...

DevMan RaaS Portal Centralizes Payload Builds and Payouts

DevMan RaaS Portal Centralizes Payload Builds and Payouts


Posted July 25, 2026 in Compliance, Ransomware, NIST, Cybersecurity

The DevMan ransomware-as-a-service portal consolidates payload builds, victim management, and affiliate payouts into...

Patient Data Exposed at Ohio Revenue Cycle Management Firm

Patient Data Exposed at Ohio Revenue Cycle Management Firm


Posted July 24, 2026 in Compliance, HIPAA, CMMC, Ransomware, Penetration Testing

Patient data exposure at an Ohio revenue cycle management company shows why healthcare vendors need HIPAA-aligned...

CMMC Level 3 Is the Quietest Land Grab in Defense Contracting

CMMC Level 3 Is the Quietest Land Grab in Defense Contracting


Posted July 24, 2026 in Ransomware, Cybersecurity, Compliance

CMMC Level 3 adds 24 NIST SP 800-172 requirements to Level 2. See the DoD cost estimates, why early movers win, and...

Clover Health Assessing Impact of Social Engineering Incident

Clover Health Assessing Impact of Social Engineering Incident


Posted July 24, 2026 in Compliance, HIPAA, CMMC, NIST, Cybersecurity

Clover Health disclosed a social engineering cybersecurity incident to the SEC. See what happened and how healthcare...

Major Healthcare Software Vendor Investigating Cyberattack

Major Healthcare Software Vendor Investigating Cyberattack


Posted July 22, 2026 in Compliance, HIPAA, CMMC, NIST, Ransomware

A major healthcare software vendor is investigating a cyberattack affecting protected health information. What...

ISMG Editors: AI Phishing Kits Go Mainstream

ISMG Editors: AI Phishing Kits Go Mainstream


Posted July 18, 2026 in AI, Compliance, HIPAA, CMMC, Cybersecurity

AI phishing kits have gone mainstream, letting low-skill attackers run convincing campaigns. Key takeaways from...

CMMC Phase II Suspended: What Defense Contractors Should Do Now

CMMC Phase II Suspended: What Defense Contractors Should Do Now


Posted July 15, 2026 in CMMC, NIST, Compliance, Cybersecurity, AI

The Department of War suspended CMMC Phase II requirements set for November 10, 2026. What the pause means and what...

How We Scored 110 on Our Own CMMC Self-Assessment

How We Scored 110 on Our Own CMMC Self-Assessment


Posted July 1, 2026 in CMMC, Compliance, NIST

Petronella Technology Group earned a perfect 110 SPRS score on its own CMMC Level 2 self-assessment. Five lessons for...

False SPRS Score Costs a Defense Contractor $507,144

False SPRS Score Costs a Defense Contractor $507,144


Posted June 26, 2026 in Compliance, Cybersecurity

LOGZONE self-reported a perfect 110 SPRS score; DIBCAC found negative 170. Inside the $507,144 False Claims Act...

Why CMMC SSPs and POA&Ms Fail at Assessment and How to Pass

Why CMMC SSPs and POA&Ms Fail at Assessment and How to Pass


Posted June 23, 2026 in CMMC, Compliance, NIST, AI, Cybersecurity

Most CMMC System Security Plans fail before the assessor opens them. See exactly what C3PAOs check in your SSP and...

CMMC vs NIST 800-171: Complete Comparison 2026

CMMC vs NIST 800-171: Complete Comparison 2026


Posted May 21, 2026

NIST 800-171 vs CMMC explained: 110 controls, 3 levels, C3PAO assessments, DFARS 7021 enforcement. Plain-English...