John "Lt" Sciandra vCISO, CISSP, CMMC Lead CCA/Instructor’s Post

View profile for John "Lt" Sciandra vCISO, CISSP, CMMC Lead CCA/Instructor, graphic

Ask me how to setup your cybersecurity program. Yo hablo Español. Ich spreche Deutsch.

How to lessen the impact of complying with DFARS CUI requirements (DFARS 252.204.7012) or the CMMC program assessment you may be required to meet. Yes, the costs will be high esp. for an SMB. The answer is a business answer and not a cybersecurity answer at all. When I study P&L statements and balance sheets with my financial review team (these days that means by myself :p), I see large expenses that are spread out across months and quarters. This is how to avoid that large lump payment that hurts. The same for the DFARS and CMMC preparations. Spread out your workload across 12-18 months. Pay for services as you need them in small affordable amounts. For example, make a $30k CMMC preparation a $1600/Month expense over 18 months. There is another secret benefit to this approach - most compliance experts will tell you that it takes that long anyway if you are to truly implement a proper and passable cybersecurity program. So many of the answers to managing a cybersecurity program can be found in the daily business practices you already are doing. I have been studying how to lessen the burden on SMB's to achieve compliance and have some controversial ideas that I have been slowly unwinding here. They include: 1. [Executive Leadership] CEO emotional intelligence (EQ) - no this is not an attack but a concept for executive leadership if you have read anything about it [Subtopic Executive Coaching] 2. [Team Building] Team Transparency and commitment. 3. [Project Management] Use of tools like OKR's to keep the 18-month program on track and accountable to each other (another sign of EQ). Trust is good but verification is better. 4. [IT Planning and Management] Putting together the right mix of tools (yes you might choose to buy some software for parts of this) that will help you cover a majority of the security controls and requirements without overlap. 5. [Board Room Discussion] Consideration of your IT architecture and migrations to platforms that will ease the compliance burden. 6. [HR} Find a compliance SME that your team can work with over the 18 months and beyond. Get the right consultant on the bus and get the wrong consultant off the bus. Food for thought. #CW #ceomindset #CMMC #cybersecurity #DFARS

Nancy Ho

● Helping C-Level Execs, Mid-Level Managers, & Business Owners Bridge The Gap Between 𝐏𝐫𝐨𝐟𝐞𝐬𝐬𝐢𝐨𝐧𝐚𝐥 𝐒𝐮𝐜𝐜𝐞𝐬𝐬 & 𝐏𝐞𝐫𝐬𝐨𝐧𝐚𝐥 𝐅𝐮𝐥𝐟𝐢𝐥𝐥𝐦𝐞𝐧𝐭 ● Thought Leader on "The Professional Paradox"

8mo

Strategic approach for long-term success.

To view or add a comment, sign in

Explore topics