SEC Draws Line in the Sand With Latest Suit
Over the years, organizations dealing with sensitive data from the government have flouted cybersecurity risk regulations from Department of Defense (DoD) contracts and other federal contracts by simply entering perfect scores, knowing that no true audit would be conducted. However, as the SEC has shown with the recent lawsuit against SolarWinds for the exact thing many are guilty of, they have shown that the government is coordinating to enforce cybersecurity regulations and hold those organizations accountable.
The self attestation that the DoD has required for prime and subcontractors are rooted in the lucrative contracts these organizations sign, but as of last year, only 36% of those contractors were reporting scores to the federal database, according to a study conducted by Merrill Research. These guidelines are due to get an overhaul in the new Cybersecurity Maturity Model Certification (CMMC) 2.0 regulation that is pending.
The CMMC will institute a new program that will enforce and audit the contractors, holding them truly accountable for the first time, as cybersecurity becomes more and more of a concern for the United State’s government. In a worst case scenario, if the contractor is found to not be in compliance, the organization will be subject to action by SEC and the cancellation of current and future contracts with the DoD and United State’s government.
Cyber Defense is available to discuss and to help implement these updated regulations to avoid any negative consequences from not being in compliance. Please reach out, if you require assistance!