Insights

Longer reads for people who have to make the call.

Analysis for owners and program managers deciding what to spend, what to document, and what to tell a prime. No vendor pitches disguised as thought leadership.

Snowflake Agent Identity: AI Agents as Privileged Identities

CISO Perspective Agent Identity / SERVICE_AGENT Cortex AI Gateway Preview Updated 17 Sep 2026 Insights · AI Security and Identity AI agents are becoming privileged identities Snowflake’s work on...

CMMC SPRS Affirmation: Who Can Sign and What the Affirming Official Is Certifying

Under 32 CFR § 170.22, the Affirming Official is defined by responsibility and authority, not by title. A CISO may qualify. So may an owner. A systems administrator who knows the environment best...

Is C3PAO Still Required? CMMC Phase 2 Suspension Explained?

CMMC Regulatory Brief · 01 Class Deviation 2026-O0025 Rev. 3 DFARS Part 240 · FAR Part 40 Updated 09 Sep 2026 Insights · CMMC & NIST SP 800-171 C3PAO wasn’t removed. Read the status list...

Can you put CUI into generative AI

AI Governance Brief · 02 DFARS 252.204-7012 · NIST SP 800-171 · FedRAMP CUI & Generative AI Updated 06 Sep 2026 Insights · AI Governance Can you put CUI into generative AI? The honest answer is...

AI Vendors Under CMMC: ESP, SPA, or Neither?

Vendor Brief · 01 32 CFR 170 · DFARS 252.204-7012 · NIST SP 800-171 ESP / SPA Scoping Updated 06 Sep 2026 Insights · AI Governance Are AI vendors ESPs or SPAs under CMMC? The question assumes the two...

SPRS score vs CMMC: what the Phase 2 pause did not change

what the Phase 2 pause did not change Two separate obligations that contractors routinely collapse into one. The certification milestone is suspended; the self-assessment, the posted score and the...

AI in CMMC Level 2: Innovation Without Control Is Risk

Innovation Without Control Is Risk An engineer pastes a firewall config into a chat window and solves the problem in four minutes. Why that is a control failure, and how to permit AI use without...

Data center security: What AI changes, and what it doesn’t

What AI changes, and what it doesn’t Four areas where AI workloads genuinely alter the control set — power and cooling, cluster fabric, accelerator tenancy, data disposal — and the much longer list...

AI cybersecurity threats, defined for a CUI environment

defined for a CUI environment Most threat lists mix three unrelated things: AI used against you, attacks on the AI you deploy, and risk you create yourself. Separating them is what makes the list...

AI in a CUI Environment: What Actually Changes in Each Governance Process

What Actually Changes in Each Governance Process This is not a new compliance program. Walking through inventory, access management, boundary control and classification to show which existing...

Securing the Defense AI Supply Chain: A Practical CMMC 2.0 and NIST Framework for Vendor Management

A Practical CMMC 2.0 and NIST Framework for Vendor Management Your vendors are shipping AI features you did not evaluate. A working approach to assessing AI in the supply chain against CMMC and NIST...

AI Governance by Design: Building Controls Into the Development Lifecycle

Building Controls Into the Development Lifecycle Most AI governance programs are assembled in the wrong order — after the model is in production, when someone asks what it was trained on. What it...

Reading about it is slower than measuring it

The 25-question self-check tells you where you actually stand in five minutes.

Check your readiness