cybersecurity Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/cybersecurity/ Breaking news about the market for products, systems and services for the U.S. intelligence community Fri, 22 May 2026 11:56:42 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg cybersecurity Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/cybersecurity/ 32 32 59882712 NSA releases security design considerations for AI-driven automation https://intelligencecommunitynews.com/nsa-releases-security-design-considerations-for-ai-driven-automation/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-releases-security-design-considerations-for-ai-driven-automation Fri, 22 May 2026 11:56:42 +0000 https://intelligencecommunitynews.com/?p=44638 On May 20, the National Security Agency’s Artificial Intelligence Security Center (AISC) released a Cybersecurity Information Sheet (CSI), “Model Context...

The post NSA releases security design considerations for AI-driven automation appeared first on Intelligence Community News.

]]>
On May 20, the National Security Agency’s Artificial Intelligence Security Center (AISC) released a Cybersecurity Information Sheet (CSI), “Model Context Protocol (MCP): Security Design Considerations for AI-Driven Automation.”

MCP is an application-level protocol that provides a simple and agreed upon messaging pattern and transport format currently used by many AI-enabled systems for managing interactions between services. The guidance aims to reduce risk while supporting safe innovation in AI-augmented systems.

Real-world adoption of MCP has accelerated. It is increasingly found in AI deployments across products used in business, finance, legal, software development, and other industries, including for sensitive tasks like querying personally identifiable information.

While MCP simplifies the integration of diverse capabilities into powerful agent workflows, the current protocol specification requires careful and cautious implementation for security. Gaps in MCP design, implementation, and operational posture have created significant and evolving security concerns including serialization risks, trust boundaries, and agent misuse, to name a few, according to the CSI.

Although traditional cybersecurity principles such as authentication, authorization, and input validation remain necessary protective measures, agentic AI systems — especially those featuring MCP — introduce novel and systemic risks like dynamic tool invocation, implicit trust relationships, and context sharing. Established cyber defense strategies unfortunately do not adequately address these new risks.
These are not isolated problems that can be patched at the interface or endpoint level. Securing MCP systems requires treating the agentic environment as a continuum. Misaligned assumptions or subtle inconsistencies at any stage can propagate and compound into exploitable conditions.

This report examines these security concerns, outlines gaps that must be addressed before MCP can be used securely and confidently. It offers practical recommendations for organizations adopting MCP in high-stakes or production environments. The guidance is designed to remain relevant as the MCP protocol, implementations, and operations continue to evolve.

Adopters are advised to proceed with caution, drawing on lessons from prior distributed and plugin-based ecosystems while applying heightened scrutiny to MCP’s novel integration and automation patterns. Continued collaborative work among implementers, security researchers, and standards organizations will be essential to establish more robust and trustworthy foundations for AI infrastructure, particularly for national security and other high assurance environments.

Read the full report.

Source: NSA

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post NSA releases security design considerations for AI-driven automation appeared first on Intelligence Community News.

]]>
44638
REDLattice names James Mingus to board https://intelligencecommunitynews.com/redlattice-names-james-mingus-to-board/?utm_source=rss&utm_medium=rss&utm_campaign=redlattice-names-james-mingus-to-board Wed, 20 May 2026 14:06:25 +0000 https://intelligencecommunitynews.com/?p=44606 On May 19, REDLattice announced the appointment of General James Mingus, United States Army (Retired), to its board of directors....

The post REDLattice names James Mingus to board appeared first on Intelligence Community News.

]]>
On May 19, REDLattice announced the appointment of General James Mingus, United States Army (Retired), to its board of directors. A distinguished career officer and former senior commander within the Department of the Army, General Mingus brings decades of operational leadership, national security expertise, and high-level institutional experience to the board at a critical moment in the company’s growth, according to the company.

General Mingus retired from the United States Army at the rank of General following an exceptional career spanning 44 years of service. His tenure included senior command and staff assignments at the highest levels of the Army, including Vice Chief of Staff, Director of the Joint Staff, Chief of the Joint Planning Group for Joint Special Operations Command, Commander 82nd Airborne Division and 75th Ranger Regiment. Throughout his career, General Mingus was instrumental in shaping U.S. defense strategy, modernization priorities, and joint force readiness.

“We are honored to welcome General Mingus to our board,” said Andy Boyd, chief executive officer of REDLattice. “His record of leadership at the highest levels of the United States Army, combined with his deep understanding of national security requirements and defense policy, will be invaluable as we advance our mission and expand our capabilities. This appointment reflects our continued commitment to building a board of exceptional leaders who understand the unique landscape our customers operate in.”

General Mingus’s appointment strengthens REDLattice’s standing within the national security sectors. His extensive relationships across the Department of War, the intelligence community, and military establishments position the company to better serve customers navigating an increasingly complex global threat environment.

“I have spent my career in service to this nation, and I am proud to continue that commitment in this new capacity,” said General Mingus. “The threats facing this nation — and our allies — do not respect borders. They are accelerating, they are interconnected, and they demand solutions built for a world that no longer fights in isolation. REDLattice is building those solutions, and I am here to help deliver them.”

Source: REDLattice

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

The post REDLattice names James Mingus to board appeared first on Intelligence Community News.

]]>
44606
Avatara launches CMMC readiness offering https://intelligencecommunitynews.com/avatara-launches-cmmc-readiness-offering/?utm_source=rss&utm_medium=rss&utm_campaign=avatara-launches-cmmc-readiness-offering Tue, 19 May 2026 10:57:53 +0000 https://intelligencecommunitynews.com/?p=44596 On May 18, Avatara announced the launch of its Mission Ready Offering (MRO), a new offering that gives defense contractors...

The post Avatara launches CMMC readiness offering appeared first on Intelligence Community News.

]]>
On May 18, Avatara announced the launch of its Mission Ready Offering (MRO), a new offering that gives defense contractors a faster, more predictable path to CMMC Level 2 readiness.

Built on Avatara’s FedRAMP Moderate Equivalency platform foundation, MRO provides organizations with a fully managed Controlled Unclassified Information (CUI) enclave that supports all 110 CMMC Level 2 controls and enables customers to inherit 80% of the CMMC Level 2 practice objectives on Day 1, accelerating CMMC readiness timelines to as little as 60 days.

The launch comes at a critical moment for the DIB. As CMMC requirements move into active enforcement across the Department of Defense (DoD) supply chains, thousands of contractors face mounting pressure to secure compliant infrastructure, complete documentation requirements, and schedule assessments in an increasingly constrained certification market.

“Companies should be focused on growing their business and supporting their customers — not spending years navigating fragmented infrastructure, disconnected security tools, and compliance uncertainty,” said Rob McCormick, founder and CEO of Avatara. “Our mission is to help organizations thrive in regulated environments by simplifying the path to secure operations and compliance readiness, and MRO is here and now for an industry that needs trusted solutions.”

“Enterprises across the DIB understand that compliance is no longer optional — but most do not have the time, internal resources, or operational runway to spend a year rebuilding infrastructure and documentation from scratch,” said Matt Pushkin, vice president of compliance and government Sslutions at Avatara. “MRO gives contractors a deterministic path forward. We provide the compliant platform foundation, the operational support, and the documentation acceleration needed to move organizations toward assessment readiness quickly and confidently.”

Source: Avatara

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

The post Avatara launches CMMC readiness offering appeared first on Intelligence Community News.

]]>
44596
A-LIGN and Exostar partner https://intelligencecommunitynews.com/a-lign-and-exostar-partner/?utm_source=rss&utm_medium=rss&utm_campaign=a-lign-and-exostar-partner Mon, 18 May 2026 12:30:44 +0000 https://intelligencecommunitynews.com/?p=44589 On May 14, A-LIGN, a cybersecurity compliance firm and C3PAO (CMMC Third-Party Assessor Organization), and Exostar, provider of secure, compliant B2B...

The post A-LIGN and Exostar partner appeared first on Intelligence Community News.

]]>
On May 14, A-LIGN, a cybersecurity compliance firm and C3PAO (CMMC Third-Party Assessor Organization), and Exostar, provider of secure, compliant B2B collaboration solutions for the defense industry, announced a strategic partnership. A-LIGN and Exostar will help defense contractors get certified under the Department of War’s Cybersecurity Maturity Model Certification (CMMC) program and to help prime contractors manage flow down compliance risk across their global, multi-tier supply chains, providing a scalable solution to the market to meet the urgent demand accompanying the rollout of CMMC.

With CMMC requirements now embedded in DoW contract solicitations and renewals, primes face growing risk due to limited visibility into supplier compliance readiness, putting key programs at risk when suppliers fail to achieve CMMC accreditation on time.  A single uncertified supplier can mean disqualification from contract award. Together, A-LIGN and Exostar make the path to certification for primes and their suppliers faster and more straightforward, while giving primes unprecedented confidence in the security and compliance of their supply chains.

“The defense supply chain is only as strong as its weakest link,” said Scott Price, CEO of A-LIGN. “By pairing Exostar’s supply chain visibility capabilities with A-LIGN’s experienced CMMC teams that conduct rigorous assessments at scale, we’re giving prime contractors the confidence that every supplier in their network gets certified and compliant before affecting DoW revenue streams. The partnership will help contractors drive readiness, strengthen security at scale, and position themselves for success.”

“Our community has trusted us to deliver supply chain visibility and management and secure, compliant collaboration for over two decades. We’ve understood the importance of CMMC to the DoW and the DIB since the framework was first proposed in 2019, leading us to invest in the development of our innovative CMMC Ready Suite of products and managed services,” said Richard Addi, CEO at Exostar. “Partnering with A-LIGN complements our CMMC Ready Suite with the resources necessary to give our customers the direct, trusted accreditation assessment pathway imperative for primes and suppliers to protect and enhance their DoW revenue streams.”

Source: Exostar

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post A-LIGN and Exostar partner appeared first on Intelligence Community News.

]]>
44589
Summit 7 reaches 100 CMMC Level 2 certified client milestone https://intelligencecommunitynews.com/summit-7-reaches-100-cmmc-level-2-certified-client-milestone/?utm_source=rss&utm_medium=rss&utm_campaign=summit-7-reaches-100-cmmc-level-2-certified-client-milestone Wed, 13 May 2026 11:22:55 +0000 https://intelligencecommunitynews.com/?p=44553 On May 8, Summit 7 announced a milestone. The company has helped over 100 clients receive their Cybersecurity Maturity Model...

The post Summit 7 reaches 100 CMMC Level 2 certified client milestone appeared first on Intelligence Community News.

]]>
On May 8, Summit 7 announced a milestone. The company has helped over 100 clients receive their Cybersecurity Maturity Model Certification (CMMC) Level 2 assessment certification. This achievement represents a momentous step forward for the protection of American defense intellectual property and further establishes Summit 7’s leadership as the trusted cybersecurity partner for the Defense Industrial Base (DIB), the company said.

“We are incredibly proud of the work we have done since 2016 to implement secure infrastructure and ultimately prepare our clients for CMMC certification,” said Scott Edwards, CEO of Summit 7. “I would like to congratulate these organizations and their hardworking teams on fortifying themselves and our nation against critical cyber threats. I would also like to thank Microsoft for their partnership and commitment to quality platforms and services, both of which have heavily contributed to the DIB’s certification success.”

In response to ever growing cyber threats from adversarial nations, the Department of War (DoW) is holding defense contractors to a higher standard than ever.

“Organizations with CMMC certifications show the DoW and prime contractors that they take their contractual obligations and security of the data they hold seriously,” Joy Beland, VP of cybersecurity compliance for Summit 7 said. “Cybersecurity is one of the greatest threats to our generation, and each organization that gets CMMC certified in the Defense Industrial Base is doing their part in securing the supply chain which ultimately protects the American dream.”

“Our clients have so much dedication to their respective crafts, and it’s been an honor to guide them through implementation and the certification process,” said Caleb Leidy, director of compliance for Summit 7. “CMMC Level 2 Certifications are hard-earned and will serve these 100 organizations well. We look forward to continuing our support in maintaining those certifications.”

Source: Summit 7

Like IC News? Then please consider subscribing. You’ll get full access to our searchable library of 10,000+ articles, plus new articles each weekday.

The post Summit 7 reaches 100 CMMC Level 2 certified client milestone appeared first on Intelligence Community News.

]]>
44553
Intelligent Waves earns CMMC Level 2 https://intelligencecommunitynews.com/intelligent-waves-earns-cmmc-level-2/?utm_source=rss&utm_medium=rss&utm_campaign=intelligent-waves-earns-cmmc-level-2 Wed, 13 May 2026 11:09:07 +0000 https://intelligencecommunitynews.com/?p=44551 On May 12, Intelligent Waves, announced that it has successfully achieved Cybersecurity Maturity Model Certification (CMMC) Level 2. This milestone reinforces...

The post Intelligent Waves earns CMMC Level 2 appeared first on Intelligence Community News.

]]>
On May 12, Intelligent Waves, announced that it has successfully achieved Cybersecurity Maturity Model Certification (CMMC) Level 2. This milestone reinforces Intelligent Waves’ commitment to safeguarding Controlled Unclassified Information (CUI) and positions it among a select group of organizations authorized to support critical Department of War (DoW) programs.

CMMC Level 2 certification represents a rigorous, independently assessed validation of an organization’s ability to implement and sustain 110 security practices aligned with National Institute of Standards and Technology SP 800-171. The process requires significant investment in cybersecurity architecture, policy development, continuous monitoring, and workforce training, often taking months to years to operationalize fully.

“This certification is more than a compliance milestone, it is a strategic inflection point and business enabler,” said James Howell, chief information officer at Intelligent Waves. “It validates our operational maturity, strengthens trust with our partners, and demonstrates our commitment to protecting sensitive national security information.”

An estimated 80,000 companies across the Defense Industrial Base (DIB) are expected to require CMMC Level 2 certification to remain eligible for DoW contracts. However, only a small percentage have achieved certification to date, creating a significant competitive divide between compliant and non-compliant organizations, the company said.

A cornerstone of Intelligent Waves’ cybersecurity strategy is adopting Hypori to enable secure Bring Your Own Device (BYOD) access and eliminate CUI exposure on endpoint devices.

Source: Intelligent Waves

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

The post Intelligent Waves earns CMMC Level 2 appeared first on Intelligence Community News.

]]>
44551
Greystones achieves CMMC Level 2 https://intelligencecommunitynews.com/greystones-achieves-cmmc-level-2/?utm_source=rss&utm_medium=rss&utm_campaign=greystones-achieves-cmmc-level-2 Tue, 12 May 2026 11:54:08 +0000 https://intelligencecommunitynews.com/?p=44542 On May 11, Greystones Group, a certified Women-Owned Small Business (WOSB) delivering innovative digital solutions to the United States military...

The post Greystones achieves CMMC Level 2 appeared first on Intelligence Community News.

]]>
On May 11, Greystones Group, a certified Women-Owned Small Business (WOSB) delivering innovative digital solutions to the United States military and civilian federal government, announced it has successfully achieved Cybersecurity Maturity Model Certification (CMMC) Level 2 (Expert) following an independent assessment conducted by an accredited Certified Third-Party Assessment Organization.

“Achieving CMMC Level 2 was a deliberate investment and a core part of our 2026 strategy,” said Julie Lofreddo, director at Greystones Group and head of total quality management. “We made the decision early to build the infrastructure, processes, and culture required to operate at the highest levels of cybersecurity maturity. This certification validates that commitment and strengthens our ability to support the most demanding defense missions.”

CMMC Level 2 represents the Department of War’s most advanced cybersecurity certification for contractors, requiring enhanced protections against sophisticated threats and the institutionalization of mature security practices across the enterprise.

Greystones’ secure delivery model supports its portfolio of AI-enabled platforms, including Soleite and Fleet Edge, which are designed for deployment in regulated and mission-critical environments. The company’s architecture emphasizes Zero Trust alignment, IL5/IL6 readiness, and integration with existing government systems without disruption.

“Achieving Level 2 required demonstrating technical controls, and repeatable, auditable processes under independent review,” said John Mark Suhy, chief technology officer of Greystones Group. “It ensures we can deliver advanced AI capabilities with the security, traceability, and resilience expected by the Department of War.”

With this certification, Greystones is positioned to support current and future DoW programs requiring advanced cybersecurity compliance, reducing risk and accelerating acquisition for government partners, according to the company.

Source: Greystones

Your competitors read IC News each day. Shouldn’t you? Learn more about our subscription options, and keep up with every move in the IC contracting space.

The post Greystones achieves CMMC Level 2 appeared first on Intelligence Community News.

]]>
44542
C Speed achieves CMMC Level 2 https://intelligencecommunitynews.com/c-speed-achieves-cmmc-level-2/?utm_source=rss&utm_medium=rss&utm_campaign=c-speed-achieves-cmmc-level-2 Fri, 08 May 2026 14:18:11 +0000 https://intelligencecommunitynews.com/?p=44516 On May 6, C Speed, a provider of advanced, American-made radar and surveillance solutions, and a NewSpring Holdings platform company,...

The post C Speed achieves CMMC Level 2 appeared first on Intelligence Community News.

]]>
On May 6, C Speed, a provider of advanced, American-made radar and surveillance solutions, and a NewSpring Holdings platform company, announced it has achieved Cybersecurity Maturity Model Certification (CMMC) Level 2 with a perfect score of 110. C Speed is among the first companies to meet the Department of Defense’s full cybersecurity standard for protecting Controlled Unclassified Information (CUI).

CMMC Level 2 is the standard required for defense contractors that store, process and/or transmit CUI on behalf of the U.S. Government. C Speed completed its assessment with Redspin, a leading CMMC 3rd Party Assessment Organization (C3PAO). The certification covers the systems, people, and processes that support C Speed’s defense programs. A perfect score of 110 means C Speed met all 110 security requirements and 320 assessment objectives without exception.

“The warfighter cannot afford a supply chain that falls short. CMMC Level 2 is the bar the Department of Defense set for protecting the information our customers trust us with, and our team cleared it without a single deduction. We pursued this certification early and earned it cleanly because that is the standard a defense company should hold itself to,” said Andy Maner, executive chairman, C Speed.

C Speed designs, builds, and delivers high-power radar systems engineered and manufactured in the United States. The company’s LightWave Radar platform supports homeland defense, multi-domain awareness, and defense missions for the U.S. Government and its partner nation customers. CMMC Level 2 certification reinforces C Speed’s ability to support these missions across the full program lifecycle.

Source: C Speed

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

The post C Speed achieves CMMC Level 2 appeared first on Intelligence Community News.

]]>
44516
ABS acquires RMC Global https://intelligencecommunitynews.com/abs-acquires-rmc-global/?utm_source=rss&utm_medium=rss&utm_campaign=abs-acquires-rmc-global Tue, 05 May 2026 11:45:00 +0000 https://intelligencecommunitynews.com/?p=44490 On April 29, ABS, through its affiliate ABSG Consulting Inc., announced the acquisition of RMC Global (RMC), a leading provider...

The post ABS acquires RMC Global appeared first on Intelligence Community News.

]]>
On April 29, ABS, through its affiliate ABSG Consulting Inc., announced the acquisition of RMC Global (RMC), a leading provider of industrial cybersecurity, risk management and resiliency solutions.

The acquisition strengthens ABS Consulting’s capabilities and market position, bringing together two organizations with complementary expertise, shared values and a common mission. Combining RMC’s capabilities with ABS Consulting’s scale, technical depth and global resources, unlocks more integrated solutions for clients operating in increasingly complex risk environments.

ABS Chairman and CEO John McDonald said, “Clients are facing increasing operational risk, cyber threats, and regulatory pressure. Bringing together the expertise of RMC and ABS Consulting strengthens our ability to deliver even greater value and support for our clients through comprehensive, integrated solutions.”

He highlighted that the acquisition is both a strategic and cultural fit. RMC’s strong culture of critical infrastructure protection and industrial cybersecurity aligns closely with ABS Consulting’s focus on protecting people, assets and critical operations around the world.

McDonald continued, “ABS and RMC make a strong fit in mission and culture. Both organizations are focused on work with real-world impact. Both value expertise, practical problem solving, and long-term trust. And both are committed to helping protect critical systems, support resilience, and solve complex challenges in environments where the stakes are high.”

ABS Consulting CEO David Wechsler said, “This acquisition builds on priority areas where we see sustained client demand and long-term growth opportunity. The combination strengthens our ability to support our customers’ evolving operational risk, cyber threats, and regulatory demands, while giving us a broader platform to deliver increasingly innovative solutions.”

RMC President Vince Kuchar said, “What brought our organizations together is a shared culture, mission, and purpose: delivering practical, trusted solutions that protect critical infrastructure and critical missions, enabling resilience in the face of growing risk. By joining ABS with its 164-year mission, we are better positioned to support our clients today and to adapt alongside them in the years ahead.”

Source: ABS

Help IC News continue to bring you breaking news from across the IC and IC contracting landscape. Join our paid subscribers today.

The post ABS acquires RMC Global appeared first on Intelligence Community News.

]]>
44490
Owl launches incident response data diode https://intelligencecommunitynews.com/owl-launches-incident-response-data-diode/?utm_source=rss&utm_medium=rss&utm_campaign=owl-launches-incident-response-data-diode Mon, 04 May 2026 22:03:10 +0000 https://intelligencecommunitynews.com/?p=44485 On May 4, Owl Cyber Defense announced the launch of its Incident Response Diode (IRD), the industry’s first pocket-sized protocol...

The post Owl launches incident response data diode appeared first on Intelligence Community News.

]]>
On May 4, Owl Cyber Defense announced the launch of its Incident Response Diode (IRD), the industry’s first pocket-sized protocol filtering diode (PFD) for incident response and forensics teams. The Owl IRD was developed to help users securely move evidence from compromised endpoints into trusted analysis environments without adding risk. Owl IRD will be made available to select customers for field testing.

When an endpoint is compromised, responders must race against the clock to pull critical data before systems are wiped, reimaged or attacked again. But risky connections and legacy technology may spread malware, break chain of custody, and trigger costly enclave rebuilds. The Owl IRD solves this with hardware-enforced, protocol-aware one-way transfer per U.S. Government PFD requirements. As a PFD, the Owl IRD enhances the unidirectional nature of a simple diode with protocol filtering at the FPGA level — delivering a secure, repeatable evidence path that reduces reinfection risk and preserves forensic integrity. The Owl IRD extends Owl’s PFD suite to the endpoint, complementing Owl Talon’s always-on network flows with purpose-built incident response capabilities, from endpoint triage to evidence intake and one-way mission data collection. High-stakes collections become a consistent, defensible workflow.

“Every incident responder knows the uncomfortable tradeoffs they face when collecting evidence from a live, compromised system,” said Tim Fahl, chief technology officer at Owl Cyber Defense. “Their options are to rush ahead with tools that put their clean environments at risk, or slow everything down trying to engineer safer workarounds in the middle of a crisis. The Owl IRD eliminates that tradeoff by putting protocol-aware, hardware-enforced, one-way protection directly into the responder’s go-bag, so teams can confidently collect what they need without opening new paths for the adversary.”

Source: Owl

Your competitors read IC News each day. Shouldn’t you? Learn more about our subscription options, and keep up with every move in the IC contracting space.

The post Owl launches incident response data diode appeared first on Intelligence Community News.

]]>
44485