Listen to this episode

Craig Petronella of PetronellaTech.com and Vincent DiCianni of AffiliatedMonitors.com discuss Monitoring and Assessments

0:0044:58

Recorded December 2020. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

Craig Petronella of Petronella Technology Group interviews Vin DiCianni, president of Affiliated Monitors, a Boston-based firm that provides independent monitoring for companies in trouble with government agencies and proactive compliance and ethics support. DiCianni explains how his years as an attorney inspired him to offer monitoring as an intermediary sanction between a slap on the wrist and license revocation.

Craig describes the Cybersecurity Maturity Model Certification for federal defense contractors, which at the time of recording replaced self-attestation with certified third-party assessment. DiCianni warns that certifying to controls a company does not have is a false claim that can bring civil, administrative, or criminal consequences, and he describes suspension and debarment. He argues that assuming the government will never audit you is a false sense of security, that pandemic-era investigation slowdowns have ended, and that prevention costs far less than fines, legal fees, and reputational damage. The conversation also covers vendor due diligence, HIPAA shortcomings, ransomware, and Craig's view of compliance as a competitive edge and investment.

Worth remembering

Key takeaways

  1. DiCianni warns that submitting a statement claiming controls a company does not have is a false claim that government agencies can pursue.
    “You submit something that says, This is who we are and what we have. And then you don't have it. You're not truthful. That is a false claim.”
  2. DiCianni argues that assuming a company will never be audited is a false sense of security, and proactive compliance protects a company's livelihood.
    “Keeping your head in the sand is just not the right approach. Being proactive and taking the steps you need to do to make sure that you're compliant is crucial because it is your livelihood.”
  3. DiCianni frames compliance spending as pay now or pay later, since investigations bring attorney fees, publicity, lost contracts, fines, and monitoring costs.
    “So if the government agency comes after you, and you didn't put that program in for, let's call it $10,000, you get caught. And now there's an investigation, and now you're going to be prosecuted.”
  4. Both speakers argue that self-assessments and self-monitoring lack objectivity, so companies should hire independent, experienced third parties to assess their programs.
    “Can you assess yourself? How good are you at assessing yourself? Don't think you give yourself an objective response.”
  5. Craig argues that under the CMMC, at the time of recording, contractors can no longer fake compliance, and companies that skip it will lose bid eligibility.
    “Those that don't do it are going to fall off the chain. They're not going to be able to bid on contracts.”
  6. DiCianni notes companies have gotten in trouble for a joint venture partner's or subcontractor's misconduct, making third-party due diligence essential.
    “And we have companies that have gotten in trouble, not for anything that they have done, but for a joint venture partner or subcontractor who has done something inappropriate, but they're working under this master contract.”
  7. Craig describes compliance as possibly the best investment an owner can make in their company, one that paves the way for new revenues and profit.
    “It's probably, the best investment you'll ever make in your own company because it paves the way for new revenues and more profit.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

Craig Petronella, CMMC RP, IT Cybersecurity and Compliance SME interviews Vincent DiCianni of AffiliatedMonitors.com on Monitoring and Assessments.

Founded in 2004, Affiliated Monitors, Inc. (“AMI”) was the first company in the United States to focus on providing top-quality, independent integrity monitoring and assessment services across a wide range of regulated industries and professions. What distinguishes our professionals from others is that monitoring is our only business; it is not a sideline to some other professional practice or service.

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.