Listen to this episode

From Zero-Trust to Zero-Day: An Interview with PreVeil's Compliance Wizard, Noël Vestal

0:0046:55

Recorded April 2022. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

Craig, Erin, BJ, and Blake of Petronella Technology Group interview Noël, compliance manager at PreVeil, about recent zero-day vulnerabilities in Apple iOS and Chrome and what they signal about the threat landscape. Craig suggests companies often rush products out and address security later, while BJ notes that heightened awareness is affecting companies across the industry.

Noël describes PreVeil's zero trust, encrypted email and file storage platform and his own path from high school English teacher through DC government and Department of Defense contracting to PreVeil, where he was a customer before joining the team. He explains how NIST 800-171 and CMMC, which at the time of recording was roughly a year from official rulemaking, aim to verify that contractors actually protect controlled unclassified information. The group discusses the False Claims Act, scoping down data, the people, process, and technology trifecta, tabletop exercises, executive buy-in, the gap between IT and cybersecurity, vendor risk scoring, and Noël's claim that PreVeil can help lift a system security plan score to a positive 40.

Worth remembering

Key takeaways

  1. Craig suggests software makers often rush products out and handle security later, which may contribute to the recent zero-day vulnerabilities in Apple iOS and Chrome.
    “I think it's always a rush. We talked about this before, push it out and then do security or backups later.”
  2. Noël notes that at the time of recording official CMMC rulemaking was about a year away, prompting more contractors to begin preparing.
    “since we're about a year out from official rulemaking on CMMC, so people are starting to go, oh, I only have a year to do this now.”
  3. Noël advises defense contractors to isolate controlled unclassified information in an enclave and give access only to the people who need it.
    “Scope it down as much as humanly possible. That is going to be the saving grace.”
  4. Noël explains that assessors examine documentation, check procedures, and interview employees, including HR staff, so security awareness must extend beyond the IT team.
    “They're going to interview people who work at the company and it's not just going to be it people”
  5. Noël warns that at the time of recording the False Claims Act let the Department of Defense sue contractors lacking CUI protections for twice the contract value.
    “If you did not have those NIS controls in place, they can Sue you for twice the, of your contract.”
  6. Noël cautions that a managed service provider may lack cybersecurity and compliance expertise, so businesses should not assume their IT provider keeps them secure.
    “However, that person at that MSP does not necessarily have any understanding of cybersecurity.”
  7. Noël argues that no vendor can promise full compliance, and Blake recommends checking the CMMC AP database before working with any provider.
    “that's impossible. No one can promise you full compliance.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

In today's podcast, PreVeil's compliance manager, Noël Vestal, discusses how using Zero-Trust end-to-end encryption helps fight the Zero-Day attacks that are all the rage today, and why having trusted vendors is crucial when implementing compliance standards, especially when a government contract is on the line.

Compliance takes hard work - even with vendors there to help - but knowing who to trust makes all the difference.

Google Chrome Bug Actively Exploited as Zero-Day

Apple Rushes Out Patches for 0-Days in MacOS, iOS

Special Guest: Noël Vestal, Compliance Manager at PreVeil Host: Craig Petronella Co-Hosts: Blake (we didn't forget you this time!), Erin, & BJ

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.