Listen to this episode

CMMC Cybersecurity and Compliance - November 2020

0:0051:16

Recorded November 2020. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

In this episode of the Petronella Technology Group podcast, host Craig Petronella welcomes Sam Brown, Vice President of the human services group at Rancho Mesa Insurance Services, to discuss cybersecurity insurance and compliance. Craig describes the DFARS Interim Rule and the CMMC framework, noting that at the time of recording federal contractors needed to upload self-assessments to the SPRS database by November 30, with only limited exceptions such as commercial off-the-shelf products.

He argues the CMMC's third-party verification requirement is a positive development because companies can no longer fake compliance. Sam explains what cyber liability insurance covers, including defense costs, settlements, administrative penalties such as HIPAA fines, ransomware response, breach notification, and cybercrime coverage like computer fraud, funds transfer fraud, and social engineering. The two discuss the legal risks of paying ransoms to sanctioned groups, ransomware attacks on hospitals, and the vulnerabilities created by employees working from home on unpatched personal devices. Craig recommends password managers with long passphrases, hardware tokens, and multi-factor authentication, while Sam advises keeping cyber insurance applications accurate, training remote employees, and confirming workers' compensation coverage for staff who relocate out of state.

Worth remembering

Key takeaways

  1. At the time of recording, Craig says pretty much all federal contractors needed to upload a DFARS self-assessment to the SPRS database by November 30.
    “Some folks thought they did not need to upload their self-assessment to the SPRS database by November 30. And she said that pretty much everyone needs to upload it.”
  2. Craig argues that even companies outside the controlled unclassified information bucket should complete the free self-assessment because it will only strengthen their organization.
    “And I think that even if folks don't fall into the controlled unclassified information bucket, they should still do the self-assessment process. It's freely available to everyone.”
  3. Sam explains that cyber liability insurance can cover attorney defense costs and any settlement or judgment when a breached company faces a lawsuit.
    “You would have coverage for the defense costs for the attorneys who will defend you against those allegations, and then any settlement or judgment that does come to pass, you'd have coverage for that as well.”
  4. Sam explains that cyber typically refers to stolen data while cybercrime refers to stolen money under a cyber liability policy.
    “So that cyber typically means stolen data, but the cybercrime will reference stolen money and security.”
  5. Craig relays a data privacy attorney's warning that paying ransoms to criminals in sanctioned areas could lead to prosecution for money laundering.
    “If they're in a sanctioned area of Russia or China, for example, they're on that list or a terrorist list, and you're found to send them the ransom payment, the three Bitcoin, you can get prosecuted for money laundering.”
  6. Craig recommends using a password manager with a long 22 character passphrase plus a hardware token, so a stolen password alone will not get hackers in.
    “So if I got a keylogger on my system, somehow, they could capture my long 22 character password, but they won't get in because they need my hardware key too.”
  7. Sam's final tips are to keep the cyber insurance application accurate and up to date and to double down on training the workforce.
    “Just make sure that your insurance application is up to date and accurate. And then make sure you double down on training your workforce.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

CMMC Cybersecurity and Compliance - November 2020 - In this episode, Craig Petronella of Petronella Cybersecurity and Digital Forensics and Sam Brown of Rancho Mesa Insurance Services answers questions about Cybersecurity CMMC, NIST, DFARS and how these standards may influence Cybersecurity Requirements.

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.