Security Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/security/ Breaking news about the market for products, systems and services for the U.S. intelligence community Thu, 02 Apr 2026 12:42:39 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg Security Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/security/ 32 32 59882712 DCSA releases MPP BAA https://intelligencecommunitynews.com/dcsa-releases-mpp-baa/?utm_source=rss&utm_medium=rss&utm_campaign=dcsa-releases-mpp-baa Thu, 02 Apr 2026 12:42:39 +0000 https://intelligencecommunitynews.com/?p=44229 On March 31, the Defense Counterintelligence and Security Agency (DCSA) released the broad agency announcement (BAA) for its mentor-protégé program...

The post DCSA releases MPP BAA appeared first on Intelligence Community News.

]]>
On March 31, the Defense Counterintelligence and Security Agency (DCSA) released the broad agency announcement (BAA) for its mentor-protégé program (MPP).

DCSA safeguards America’s trusted workforce, workspaces, and classified information. Through its mission areas of personnel vetting, industrial security, counterintelligence, insider threat, and education, DCSA plays a central role in protecting national security.

The Department of War (DOW) MPP is a premier business development initiative designed to incentivize large prime contractors to provide developmental assistance to small businesses. The primary goal is to enhance the capabilities of Protégés, enabling them to become more competitive and expand their presence in the Defense Industrial Base (DIB). Through this mutually beneficial partnership, Protégés gain valuable technical and business expertise, while the DoD cultivates a broader, more resilient supplier network to support its mission.

This is a 2-phase submission:

  1. Phase 1: White Paper submissions must be received no later than 5 p.m. Eastern Time (ET), 30 days after the announcement date.
  2. Phase 2: Final Proposal requests will only be issued to selected White Paper submissions based on the evaluation criteria. Selected submitters will receive a Request for Proposal (RFP) for their Phase 2 response.
  3. Dates: White Paper submissions must be submitted via email to the DCSA MPP Program Manager and the MPP Intermediary no later than 5:00 p.m. Eastern Time (ET), 30 calendar days from the BAA announcement date. Submissions received after this deadline will not be considered until a subsequent evaluation cycle.

 

The BAA remains open, and White Papers are accepted on a rolling basis throughout the year. However, submissions are reviewed according to a quarterly review cycle.

DCSA seeks to leverage Mentor-Protégé Agreements (MPAs) to mature Protégé firms for its critical mission spaces. By incentivizing Mentors to provide technical assistance, the agency aims to integrate high-capability small businesses into the Defense Industrial Base. This expansion directly strengthens national security by ensuring a resilient, value-added supply chain capable of safeguarding sensitive defense assets.

Review the DCSA MPP BAA.

Source: SAM

The right opportunity can be worth millions. Don’t miss out on the latest IC-focused RFI, BAA, industry day, and RFP information – subscribe to IC News today.

The post DCSA releases MPP BAA appeared first on Intelligence Community News.

]]>
44229
Nokia Federal achieves CMMC Level 2 https://intelligencecommunitynews.com/nokia-federal-achieves-cmmc-level-2/?utm_source=rss&utm_medium=rss&utm_campaign=nokia-federal-achieves-cmmc-level-2 Fri, 27 Mar 2026 11:48:50 +0000 https://intelligencecommunitynews.com/?p=44179 On March 24, Nokia Federal Solutions announced that it has successfully achieved Cybersecurity Maturity Model Certification (CMMC) Level 2. This...

The post Nokia Federal achieves CMMC Level 2 appeared first on Intelligence Community News.

]]>
On March 24, Nokia Federal Solutions announced that it has successfully achieved Cybersecurity Maturity Model Certification (CMMC) Level 2. This certification demonstrates Nokia Federal’s compliance with the U.S. Department of War (DoW) cybersecurity standards and reinforces the company’s commitment to safeguarding sensitive government information across its operations and products.

CMMC Level 2 certification signifies that Nokia Federal has fully implemented advanced cybersecurity practices aligned with NIST SP 800-171, including stringent controls for access management, incident response, configuration management, secure development, and continuous monitoring.

“Achieving CMMC Level 2 reflects the strong cybersecurity foundation we’ve built at Nokia Federal,” said Mike Loomis, CEO of Nokia Federal Solutions. “It gives our U.S. federal customers assurance that we’re operating with the level of rigor their missions require. As threats evolve, we continue to invest in the technologies, processes, and people that keep our customers secure.”

This milestone underscores the trust federal agencies place in Nokia Federal and reflects the company’s continued investment in secure, mission-ready communications, the company said.

Source: Nokia Federal Solutions

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

The post Nokia Federal achieves CMMC Level 2 appeared first on Intelligence Community News.

]]>
44179
Guidehouse, IP3, and Cybernetic Intelligence partner https://intelligencecommunitynews.com/guidehouse-ip3-and-cybernetic-intelligence-partner/?utm_source=rss&utm_medium=rss&utm_campaign=guidehouse-ip3-and-cybernetic-intelligence-partner Mon, 23 Mar 2026 11:55:50 +0000 https://intelligencecommunitynews.com/?p=44140 On March 18, Guidehouse, IP3 Corporation, and Cybernetic Intelligence announced that they have partnered to jointly advance a new class...

The post Guidehouse, IP3, and Cybernetic Intelligence partner appeared first on Intelligence Community News.

]]>
On March 18, Guidehouse, IP3 Corporation, and Cybernetic Intelligence announced that they have partnered to jointly advance a new class of secure, resilient, nuclear‑enabled compute infrastructure. The partnership brings together three industry leaders to deliver the power, security, and sovereignty required for the next generation of AI, data processing, and mission‑critical intelligent operations.

“Reliable, resilient compute capacity is now a national‑security imperative,” said John Saad, president of Guidehouse, a global professional services firm serving the commercial and government sectors. “By uniting our energy, grid, capital projects, regulatory, and community engagement expertise with IP3 and Cybernetic Intelligence, we are helping create a new capability for global markets—one that ensures advanced AI and data systems can operate securely, sustainably, and at scale.”

Across governments and industries, growing demand for compute power is outpacing traditional grid capacity and challenging existing data‑center models. As the owner’s integrator, Guidehouse will deliver governance, program integration, performance assurance, and cross-stakeholder coordination across projects.

“This partnership represents a significant step forward in developing nuclear‑powered, behind‑the‑meter energy systems that keep high-performance computing running independently of the commercial grid,” said Dan Hahn, partner and growth leader, communities, energy and infrastructure, Guidehouse. “Our goal is to accelerate AI readiness while reducing vulnerability to power and compute disruptions.”

By combining IP3’s nuclear development expertise, Cybernetic Intelligence’s advanced compute and systems capabilities, and Guidehouse’s proven leadership across the energy, utilities, technology, regulatory, and national security domains in both the commercial and public sectors, the partnership will deliver contractor‑owned, contractor‑operated infrastructure aligned with emerging government priorities and mission needs.

“IP3 is proud to partner with Guidehouse and Cybernetic Intelligence to deliver nuclear‑powered infrastructure capable of meeting the moment,” said RDML Michael Hewitt, USN (Ret), co-founder and CEO of IP3, a U.S. integrator for the development and operations of peaceful and secure civil nuclear power in the global marketplace. “This model brings together energy security, technological innovation, and private‑sector investment to accelerate deployment.”

These capabilities support key global priorities, including those reflected in recent U.S. federal initiatives, such as national‑security directives and efforts to ensure compute sovereignty for defense and intelligence workloads.

“Compute is the new strategic resource. Our collaboration enables a resilient architecture that is powered by advanced energy systems and ensures AI and mission‑critical workloads remain available no matter the threat environment,” said Maxim Serezhin, founder and CEO of Cybernetic Intelligence, which develops interpretable, mission-ready AI systems that combine technical excellence with ethical governance.

Source: Guidehouse

Your competitors read IC News each day. Shouldn’t you? Learn more about our subscription options, and keep up with every move in the IC contracting space.

The post Guidehouse, IP3, and Cybernetic Intelligence partner appeared first on Intelligence Community News.

]]>
44140
Lastwall and Carahsoft partner https://intelligencecommunitynews.com/lastwall-and-carahsoft-partner/?utm_source=rss&utm_medium=rss&utm_campaign=lastwall-and-carahsoft-partner Fri, 20 Mar 2026 13:29:06 +0000 https://intelligencecommunitynews.com/?p=44120 On March 18, Lastwall and Carahsoft Technology Corp. announced a partnership to deliver unified Zero Trust and quantum-ready identity protection to...

The post Lastwall and Carahsoft partner appeared first on Intelligence Community News.

]]>
On March 18, Lastwall and Carahsoft Technology Corp. announced a partnership to deliver unified Zero Trust and quantum-ready identity protection to the public sector. Under the agreement, Carahsoft will serve as Lastwall’s public sector distributor, making Lastwall’s IDCommand Suite available to the public sector through Carahsoft’s reseller partners and NASA Solutions for Enterprise-Wide Procurement (SEWP) V, Information Technology Enterprise Solutions – Software 2 (ITES-SW2), National Association of State Procurement Officials (NASPO) ValuePoint, The Interlocal Purchasing System (TIPS), OMNIA Partners, E&I Cooperative Services Contract and The Quilt contracts.

“Identity is no longer just an access point. It’s the new frontline in an era where quantum decryption and AI-driven impersonation converge to break what was once unbreakable,” said Karl Holmqvist, founder and CEO of Lastwall. “Most organizations still treat identity as a checkbox, but the clock is ticking faster than they realize. This partnership with Carahsoft gives government and defense leaders a direct, trusted path to accelerate adoption of Zero Trust principles at the foundational identity layer, before today’s encryption becomes tomorrow’s open book.”

Credential compromise remains the leading cyberattack vector in the public sector, making identity the front line of defense. The Department of War (DoW) requires all Components to achieve Target-Level Zero Trust compliance by 2027, while Executive Order 14306 directs all federal agencies to support post-quantum cryptography (PQC) by 2030, creating a growing urgency to modernize authentication and ensure long-term resilience against evolving threats. Trusted by the U.S. DoW’s Defense Innovation Unit (DIU) and the Government of Canada, Lastwall’s IDCommand Suite meets this need by replacing outdated and fragmented access systems with a unified Zero Trust identity framework that secures cloud, hybrid and disconnected environments, with quantum resilience built in.

“Our partnership with Lastwall will help us deliver secure, quantum-resilient identity solutions to our government customers,” said Brian O’Donnell, vice president of cybersecurity solutions at Carahsoft. “Together with our reseller partners, we look forward to helping agencies modernize authentication, reduce credential risk and advance Zero Trust initiatives in line with new security mandates.”

Source: Carahsoft

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post Lastwall and Carahsoft partner appeared first on Intelligence Community News.

]]>
44120
AccuKnox and Carahsoft collaborate https://intelligencecommunitynews.com/accuknox-and-carahsoft-collaborate/?utm_source=rss&utm_medium=rss&utm_campaign=accuknox-and-carahsoft-collaborate Wed, 26 Nov 2025 15:04:02 +0000 https://intelligencecommunitynews.com/?p=43268 On November 20, AccuKnox and Carahsoft Technology Corp. announced a strategic partnership. Under the agreement, Carahsoft will serve as AccuKnox’s Master...

The post AccuKnox and Carahsoft collaborate appeared first on Intelligence Community News.

]]>
On November 20, AccuKnox and Carahsoft Technology Corp. announced a strategic partnership. Under the agreement, Carahsoft will serve as AccuKnox’s Master Public Sector Reseller and Aggregator, making the company’s comprehensive Zero Trust Application, DevSecOps, Cloud and AI Security offerings for IT, OT, 5G, drones, satellites, Internet of Things (IoT) and tactical edge available to the public sector through Carahsoft’s reseller partners and NASA Solutions for Enterprise-Wide Procurement (SEWP) V, Information Technology Enterprise Solutions – Software 2 (ITES-SW2) and National Association of State Procurement Officials (NASPO) ValuePoint contracts.

“Zero Trust Security for Application, Cloud and AI is increasingly becoming imperative. AccuKnox provides government agencies with a platform that delivers Zero Trust Security by design,” said Bryan Maizlish, federal business leader at AccuKnox. “Our partnership with Carahsoft significantly expands our reach, enabling federal, state and local agencies and education entities to procure and deploy relevant, secure and mission-critical digital assets. We are pleased to jointly accelerate AccuKnox’s capabilities into our customer’s operational environments.”

AccuKnox is a Gen-AI powered Zero Trust Cloud Native Application Protection Platform (CNAPP) that provides comprehensive multicloud and on-premise security. The CNAPP platform secures modern, comprehensive, multilayer and system-of-system workloads and devices (Kubernetes, Containers, API, AI/LLM, Agentic AI, IoT/Edge, OT, satellite, drone and 5G) and traditional assets (Virtual Machines) across all public, private and air-gapped clouds.

Focusing on the support of critical Zero Trust and cybersecurity protection for the Golden Dome, AccuKnox unifies relevant cybersecurity compliance, Zero Trust and runtime security protection across space, land, air and sea. The platform provides a comprehensive and multilayered system of systems that is interoperable, integrated and multi-level security compliant, identifying non-compliance, areas of vulnerability and risk and observability of real-time attacks. AccuKnox isolates and shuts down areas compromised by a cybersecurity breach, while protecting the integrity of the Golden Dome through an on-premise, air-gapped solution.

“AccuKnox’s Zero Trust security platform is a critical addition to our technology portfolio,” said Natalie Gregory, vice president for enterprise open source and DevSecOps solutions at Carahsoft. “The comprehensive platform allows public sector agencies and entities to protect themselves against current and emerging threats, and zero-day attacks. AccuKnox provides continuous compliance, a mandatory capability in the current world of AI-powered attacks. We look forward to working with AccuKnox and our reseller partners to expand agencies’ access to this platform, including the Golden Dome, and help them implement Zero Trust Security for applications, cloud and AI, while maintaining operational efficiency and mission readiness.”

Source: Carahsoft

Don’t miss out — become a paid subscriber to IC News, and lock in subscription rates at 2025 prices. You’ll get full access to breaking news from across the IC contracting space, with new articles each weekday.

The post AccuKnox and Carahsoft collaborate appeared first on Intelligence Community News.

]]>
43268
Rite-Solutions achieves CMMC Level 2 https://intelligencecommunitynews.com/rite-solutions-achieves-cmmc-level-2/?utm_source=rss&utm_medium=rss&utm_campaign=rite-solutions-achieves-cmmc-level-2 Wed, 12 Nov 2025 23:25:03 +0000 https://intelligencecommunitynews.com/?p=43167 Rite-Solutions announced on November 10 that it has achieved Level 2 Cybersecurity Maturity Model Certification (CMMC) v2.0 through a Certified...

The post Rite-Solutions achieves CMMC Level 2 appeared first on Intelligence Community News.

]]>
Rite-Solutions announced on November 10 that it has achieved Level 2 Cybersecurity Maturity Model Certification (CMMC) v2.0 through a Certified Third-Party Assessment Organization (C3PAO).

Non-government companies, facilities, and organizations that provide the DoW with products and services are targets for increasingly complex cyberattacks. CMMC 2.0 was created to verify that government contractors have implemented the required security measures necessary to safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).

The company is one of the first few hundred contractors in the nation to receive certification. The requirements are rigorous. Organizations must implement all 110 practices from NIST SP 800-171, develop a System Security Plan (SSP), create a Plan of Action and Milestones (POA&M), and fulfill other requirements, including training personnel, establishing a risk assessment process, and having an incident response plan in place.

“This goes beyond simply checking a compliance box,” says Kaitlin Nagy, information security manager at Rite-Solutions. “CMMC certification affirms that we operate with a mature, disciplined approach to information security and risk management. It’s yet another reason why Rite-Solutions continues to be recognized as one of the most trusted vendors in the DoW contractor space.”

“This CMMC certification demonstrates that we take our role in national security seriously and that we’re ready to meet the demands of today’s cybersecurity landscape,” adds Joe Marino, Rite-Solutions CEO and co-founder. “It reinforces the trust our customers have placed in us and why they continue to choose us.”

Source: Rite-Solutions

Time is running out — become a paid subscriber to IC News today, and lock in subscription rates at 2025 prices. You’ll get full access to breaking news from across the IC contracting space, with new articles each weekday.

The post Rite-Solutions achieves CMMC Level 2 appeared first on Intelligence Community News.

]]>
43167
Rubrik partners with AWS https://intelligencecommunitynews.com/rubrik-partners-with-aws/?utm_source=rss&utm_medium=rss&utm_campaign=rubrik-partners-with-aws Wed, 12 Nov 2025 13:06:32 +0000 https://intelligencecommunitynews.com/?p=43147 On November 10, Rubrik announced that it has signed a strategic collaboration agreement (SCA) with Amazon Web Services (AWS). The...

The post Rubrik partners with AWS appeared first on Intelligence Community News.

]]>
On November 10, Rubrik announced that it has signed a strategic collaboration agreement (SCA) with Amazon Web Services (AWS). The SCA validates Rubrik’s commitment to delivering cybersecurity solutions that meet the highest standards of availability, recovery, and operational continuity. Rubrik aims to support how organizations achieve cyber resilience in their AWS environments, while unlocking the full potential of enterprise AI.

Rubrik offers the world’s only Preemptive Recovery Engine, which begins recovery before a cyberattack occurs. It proactively identifies clean recovery points, enabling the fastest recovery time objective (RTO) after an attack.

“By deepening our collaboration with AWS, Rubrik helps organizations keep data and systems running before, during, and after cyber threats,” said Mike Tornincasa, chief business officer at Rubrik. “Combining Rubrik’s Preemptive Recovery Engine with the built-in security of AWS enables customers to adopt proactive cyber resilience, scale AI safely, automatically find sensitive data, and identify clean recovery points during attacks. With these capabilities, customers can restore operations in minutes, not weeks.”

“At Accelya, data protection is mission critical. Rubrik was the clear choice for our strategic cyber resilience partner to protect our customers’ data,” said Richard Kettlewell, director of technology at Accelya. “With Rubrik’s air-gapped backups and sensitive data discovery, we are confident that our critical data hosted on AWS is fully protected. We look forward to the innovations this collaboration between Rubrik and AWS will deliver to Accelya.”

The SCA aims to accelerate secure AI adoption through Rubrik’s expanding AI portfolio and Amazon Bedrock. Customers will be able to move from reactive crisis management when an attack or outage occurs, to proactive cyber resilience – all while safely scaling their AI initiatives from pilot to production.

“Our customers are racing to adopt AI, but data protection can’t be an afterthought,” said Chris Grusz, managing director, technology partnerships at AWS. “This collaboration brings Rubrik’s Preemptive Recovery Engine and cyber resilience expertise to AWS’s secure foundation, giving customers breakthrough capabilities—clean recovery points, sensitive data discovery, and AI-powered threat detection. Together, we’re enabling organizations to recover critical operations in minutes while confidently scaling their AI initiatives in our trusted cloud.”

Source: Rubrik

Time is running out — become a paid subscriber to IC News today, and lock in subscription rates at 2025 prices. You’ll get full access to breaking news from across the IC contracting space, with new articles each weekday.

The post Rubrik partners with AWS appeared first on Intelligence Community News.

]]>
43147
Understanding Data Security Posture Management: Five Questions to Get You on Your Way https://intelligencecommunitynews.com/ic-insiders-understanding-data-security-posture-management/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-understanding-data-security-posture-management Mon, 03 Nov 2025 15:08:16 +0000 https://intelligencecommunitynews.com/?p=43089 From IC Insider Thales Trusted Cyber Technologies By: Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies Data Security Posture Management...

The post Understanding Data Security Posture Management: Five Questions to Get You on Your Way appeared first on Intelligence Community News.

]]>
From IC Insider Thales Trusted Cyber Technologies

By: Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies

Data Security Posture Management (DSPM) is emerging as a better way to get visibility into where your sensitive data is located, who has access to it, how it has been used and how stored data and applications are secured. It’s a shift from perimeter-based defenses to data-centric approaches, and it’s important to understand because, in today’s hybrid multi-cloud environments, and with quantum computing just around the corner, dynamically managing data security postures is essential.

In the article that follows, we’ll take a deeper dive into what DSPM is, and what you need to know to implement this strategy effectively.

DPSM and today’s security challenges

In general, DPSM refers to tools and practices organizations can use to protect sensitive data across their infrastructure. These tools identify vulnerabilities, generate alerts, and provide remediation guidance to address data security risks. When integrated into other security systems, DSPM helps organizations maintain a strong data security posture and meet regulatory requirements.

There are several challenges and risks that have emerged in recent years that make DPSM strategies essential for any organization:

Poor visibility into data security across the information lifecycle. Accurately identifying and classifying data is harder than ever as data now spreads across clouds, data lakes, and on-premises systems. Understanding the location and interaction of structured and unstructured data is, of course, essential. But today, data can be easily moved and shared. When users share data without proper security measures in place, that sensitive information may end up in unknown or external locations, which makes it more vulnerable to data exfiltration attacks.

Credential sprawl. Cloud computing has led to organizations storing sensitive data online. Because of the adoption of cloud services, containers, and DevOps; keys and secrets are now scattered across platforms, repositories, and codebases. This in turn increases the attack surface, and exposes your data to problems arising from mismanaged credentials. In fact, according to the 2024 Verizon Data Breach Investigation Report, 80% of data breaches involved stolen credentials. Securing sensitive credentials and preventing unauthorized access are one direct benefit of implementing a DSPM strategy.

The AI threat to credential security. In a report from Sapios research and Deep Instinct, a significant uptick in attacks over the past year was traced back by survey respondents to bad actors using generative AI. With AI, attacks like phishing are more convincing, scalable, and harder to detect, which increases the risk of credentials being compromised. Multi-factor authentication is not enough to counter this threat; it must be supplemented with behavioral monitoring, such as tracking unusual access times, login locations, and unexpected data downloads. An effective DSPM strategy can help safeguard organizational data across all environments.

Post-Quantum Cryptography risk. As many news reports indicate, it’s only a matter of a decade or less before quantum computing breaks asymmetric algorithms like RSA and ECC, exposing sensitive data. The damage this could cause may not be apparent for years. The 2025 Thales Data Threat Report shows “Harvest now, decrypt later” attacks are the leading interest in post-quantum computing. Cybercriminals are collecting encrypted data today to decrypt when a Cryptographically Relevant Quantum Computer (CRQC) exists. Organizations’ need to prepare now by adopting the National Institute of Standards and Technology (NIST) FIPS post-quantum cryptography standard  algorithms (ML-KEM, ML-DSA and SLH-DSA) and embracing crypto agility.

Difficulty detecting insider threats. Insider threats, including leaks and sabotage, are becoming increasingly sophisticated and challenging to detect. Traditional perimeter security is insufficient to prevent breaches. What’s really required is effective risk management through robust monitoring.

The growing importance of data governance. Global data protection regulations impose severe penalties for non-compliance. US Federal Government guidelines for achieving Zero Trust maturity models by 2026 contain requirements for data governance. This makes it more important than ever to recognize behavioral changes and identify threats before they compromise sensitive data. DSPM as a security strategy can help address emerging vulnerabilities and attack vectors.

To implement a comprehensive and successful DSPM strategy, you will need to have answers to these five questions. Let’s look at each one.

DPSM Question One: Where is my sensitive data?

Many organizations don’t fully understand where their sensitive data is. In the 2025 Thales Data Threat Report, 24% of respondents indicated that they had little or no confidence in identifying where their data is stored. This creates security risks that can create opportunities for attackers – often through hidden vulnerabilities or misconfigured databases you may not even know exist.

To secure sensitive data, you have to know its specific location. That applies to both structured data (from databases and spreadsheets, for example) and unstructured data (like emails, documents, and multimedia files).

Unfortunately, data types are often spread across various storage environments, including on-premises servers and multiple cloud platforms (like AWS, Azure, or Google Cloud). What’s more, data within an organization is often moved, processed, and accessed by various applications and users. This dispersal of sensitive data across locations complicates comprehensive tracking and management without advanced monitoring tools.

Data protection regulations (GDPR,  HIPAA, Zero Trust etc.) require detailed knowledge of where specific types of data are stored. Consequently, it is critical to leverage data discovery and classification to automatically discover all data stores in your data estate – from structured to unstructured – across on-premises, cloud, multi-cloud, and hybrid environments.

Automated discovery and classification is the only way to routinely and consistently discover and classify new or modified data stores.

DPSM Question Two: Who has access to my sensitive data?

Controlling and monitoring who has access to sensitive data is essential for preventing unauthorized use and potential data breaches. Many organizations, however, lack the comprehensive tools required for full visibility and oversight of data access. Without a way to aggregate and analyze access to data across various systems and platforms, it’s hard to know who has access to sensitive information.

Many modern enterprises employ complex and layered access structures, including role-based access control (RBAC), attribute-based access control (ABAC), and other models. These intricate systems make it difficult to understand exactly who has access to what data and under which conditions.

Additionally, in large organizations, different departments or divisions often manage their own IT resources independently. This can lead to inconsistent access controls and policies. Decentralization makes it harder to track data access throughout the organization.

Scanning your data store locations for granted user rights and displaying various details regarding user rights is critical to understanding your data posture by mapping users and privileges to database objects across all databases.

DPSM Question Three: How well are credentials protected?

It’s important to have safeguards over metadata and credentials – such as encryption keys and secrets – that can unlock encrypted data to make it readable and usable. This includes using cryptography that supports protecting data today and tomorrow, because cryptographically relevant quantum computers will only accelerate malicious decryption techniques.

The problem in protecting credentials is that many organizations rely on multiple cloud providers to house data, so that key creation, management, and rotation processes may vary across CSPs. With an ever-increasing number of encryption solutions, it’s difficult to manage policies protection levels – to say nothing of escalating costs.

The best way through this maze is to transition into a centralized encryption key management system. Centralizing keys and secrets management for key life-cycle  generation, storage, rotation, backup, recovery, revocation, and termination effectively delivers separation of duties. This ensures that the same person creating and managing the keys cannot access protected data.

Limiting access to sensitive data to only those who need it for their work can reduce the risk of insider threats and external attacks. And monitoring who has access to data can help in auditing and tracking usage patterns, which can be vital for security and operational efficiency.

DSPM Question Four: How has my sensitive data been used?

Tracking how data is accessed and used over time is vital for security and compliance. This includes understanding the context of data access and modifications, and detecting unusual patterns that could indicate a security threat.

Effective data usage tracking requires advanced monitoring and logging tools that provide detailed and accurate records of all data interactions. Many enterprises lack these tools or do not have them fully integrated across all systems. This can lead to gaps in data usage visibility.

Complicating matters is that enterprises employ on-premises systems, multiple cloud platforms, and a variety of end-user devices. Each of these environments can process and store data differently, which makes it challenging to track exactly how data is accessed and used across the entire organization.

Understanding specifically how data is used makes it easier to detect anomalies, because unusual access patterns or unexpected data modifications can be early indicators of a data breach. Then, by optimizing data access controls, organizations can better match actual business needs and security requirements.

With the digital economy driving exponential data growth, organizations must have data-centric compliance and security solutions to reduce risks of non-compliance and breaches. That includes comprehensive logs of data usage, which are not only crucial for audits, but can be invaluable during forensic investigations after a security incident.

DSPM Question Five: What is the security posture of our data stores?

Assessing the security posture of data stores involves evaluating the effectiveness of implemented security measures, identifying vulnerabilities, and understanding the impact of potential threats. This knowledge can help strengthen defenses, enabling proactive improvements to data security and aiding in the prevention of breaches.

Therefore, it’s important to manage security resources effectively. By knowing where security is weakest, organizations can allocate resources more effectively to where they are most needed.

Regular assessments of your security posture ensure that defenses keep up with evolving threats and changing business practices.

Effective posture management requires the latest regularly updated vulnerability definitions, leveraged through scans to assess resources, search for vulnerabilities and determine risk. By scanning databases with predefined vulnerability tests, organizations can be aware of databases susceptible to the latest threats.

These scans, using CVSS, assign a risk score to the vulnerabilities discovered in your network and data. CVSS is “an open framework for communicating the characteristics and impact of IT vulnerabilities.” It is maintained by NIST as part of the Security Content Automation Protocol (SCAP) framework. Scoring vulnerabilities using CVSS provides an accurate model for measuring the risk inherent in discovered vulnerabilities and prioritizing them for mitigation.

Beyond scanning, it’s also important to employ monitoring across the data management lifecycle. Monitoring delivers real-time information, such as system events, alerts, violations, blocked sources and more. Monitoring events, alerts, and violations is a multi-faceted pursuit. Depending on your specific implementation, there may be several types of users with varying roles and associated security policies. You will need to fine-tune for yourselves how events are interpreted to determine if an alert is a false positive, an attack, or something else.

These are the important things to know about DSPM, and the state of your data, to establish a strategy that will gain you greater visibility into where your sensitive data is located, who has access to it, how it has been used and how stored data and applications are secured.

Quantum computing is becoming more of a reality every day, and multi-cloud environments are only complicating matters further still, so perimeter-based defenses are no longer enough. Dynamically managing your data security postures – ideally from a single platform – is essential to keeping data secure today and into the foreseeable future.

Keeping Your Data Safe with a Single Platform for DPSM

Across all businesses, public sector and private industry, data is an organization’s most valuable resource, driving economies of scale. As more businesses and even federal agencies are adopting AI, more data than ever before will be generated, leading to more data depositories, more data blind spots and more potential to leave data exposed and vulnerable to bad actors.

To protect this data, every security professional knows that they need an effective way to identify sensitive data and to keep it secure for their organization’s own sake and for compliance with local and international cybersecurity guidelines.

This can lead to a complicated and scattershot collection of solutions and tools. There are, however, some vendors that can support your Data Security Posture Management (DPSM) efforts with a single platform to help you understand the state of your data.

To take one example, CipherTrust DSPM automates the discovery and classification of both structured and unstructured data. This platform is applicable across a wide range of data stores, including on-premises, cloud, multicloud, and hybrid-cloud environments.

If you are ready to look for an all-in-one data platform for DPSM, here are the feature and benefits you need to look for from a solution vendor:

Scanning and Identifying Data: Make sure your DSPM platform can systematically scan data environments—whether on-premises or in the cloud—to discover data repositories. This must include databases, big data platforms, cloud storage, and file systems.

Classifying Data: After data repositories are discovered, a DSPM platform must be able to classify data based on its type and sensitivity. This automated classification helps organizations to understand the data they hold, and to prioritize their security accordingly.

Understand User Access: To identify excessive, inappropriate, or unused privileges, an effective DSPM platform must provide user rights management, monitoring data access, and activities of privileged users. It must also give security and IT teams full visibility into how data is accessed, used, and moved around the organization.

A comprehensive data protection strategy is crucial for DSPM. That means establishing a solid foundation for data protection through encryption and effective credential management.

Platforms like CipherTrust DSPM identify sensitive data and protect it with industry-leading technologies. The right platform ensures the security of your credentials and metadata, preventing unauthorized access by users and applications, and reinforcing your overall data security and compliance framework.

About Thales TCT

Thales Trusted Cyber Technologies, a business area of Thales Defense & Security, Inc., protects the most vital data from the core to the cloud to the field. We serve as a trusted, U.S. based source for cyber security solutions for the U.S. Federal Government. Our solutions enable agencies to deploy a holistic data protection ecosystem where data and cryptographic keys are secured and managed, and access and distribution are controlled.

For more information, visit www.thalestct.com

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

The post Understanding Data Security Posture Management: Five Questions to Get You on Your Way appeared first on Intelligence Community News.

]]>
43089
Ontic and Vertosoft partner https://intelligencecommunitynews.com/ontic-and-vertosoft-partner/?utm_source=rss&utm_medium=rss&utm_campaign=ontic-and-vertosoft-partner Mon, 27 Oct 2025 12:20:22 +0000 https://intelligencecommunitynews.com/?p=43031 On October 23, Vertosoft announced a strategic partnership with Ontic, a leading software platform for connected security intelligence. This collaboration...

The post Ontic and Vertosoft partner appeared first on Intelligence Community News.

]]>
On October 23, Vertosoft announced a strategic partnership with Ontic, a leading software platform for connected security intelligence. This collaboration allows Ontic to leverage Vertosoft’s robust portfolio of government contract vehicles, simplifying procurement and accelerating deployment of the Ontic Platform in the public sector.

“Vertosoft is committed to bringing innovative and mission-critical technologies to the public sector,” said Josh Slattery, VP of tech sales at Vertosoft. “This partnership ultimately strengthens public sector access to connected, proactive security technologies and ensures agencies have the tools required for today’s modern threat landscape.”

“The Ontic Platform enables federal security teams to uncover and investigate emerging threats, connect and assess threat actors, triage incidents faster, and standardize reporting – all within a single, modern system,” said Zach Kebetz, director, federal at Ontic. “By partnering with Vertosoft, we’re expanding access to this connected, proactive intelligence so federal agencies can strengthen how they protect our nation’s people and operations.”

The Ontic Platform provides a centralized database to maintain high-value assets and known threats, always-on monitoring of OSINT, public records, social media, dark web, and more – all integrated with intuitive case management and investigation workflows. With Ontic, security leaders gain a 360-degree view of their threat landscape and the tools to act with confidence, the company said.

Source: Vertosoft

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post Ontic and Vertosoft partner appeared first on Intelligence Community News.

]]>
43031
NIST engages Electrosoft to develop CSF 2.0 https://intelligencecommunitynews.com/nist-engages-electrosoft-to-develop-csf-2-0/?utm_source=rss&utm_medium=rss&utm_campaign=nist-engages-electrosoft-to-develop-csf-2-0 Fri, 19 Sep 2025 11:48:41 +0000 https://intelligencecommunitynews.com/?p=42746 On September 16, Electrosoft announced it has been awarded a prime task order under the National Institute of Standards and Technology...

The post NIST engages Electrosoft to develop CSF 2.0 appeared first on Intelligence Community News.

]]>
On September 16, Electrosoft announced it has been awarded a prime task order under the National Institute of Standards and Technology (NIST) CAPSS IDIQ to deliver technical services in support of NIST’s Cybersecurity Framework (CSF) and Risk Management Program.

“NIST continues to lead the way in helping organizations navigate complex cybersecurity challenges,” said Dr. Sarbari Gupta, CEO of Electrosoft. “Electrosoft is proud to support this mission by delivering expert guidance and innovative resources for stakeholders to manage risk more effectively and confidently.”

The contract expands Electrosoft’s long-standing partnership with NIST and comes as current efforts around CSF 2.0 focus on providing resources to help organizations implement the framework. Recent initiatives include community profiles, quick start guides (QSGs) and mappings as well as public comment periods on various NIST publications.

These services will help NIST streamline stakeholder engagement, strengthen the integration of cybersecurity and privacy, and help ensure the CSF remains flexible and effective across government and industry organizations. By simplifying how risks are communicated and managed, the program enables better decision-making and risk awareness for both technical and non-technical users.

Source: Electrosoft

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post NIST engages Electrosoft to develop CSF 2.0 appeared first on Intelligence Community News.

]]>
42746