The Department of Defense (DoD) has one of the largest supply chains in the world, scaling to hundreds of thousands of different vendors and partners. Yet, these vital partners in our nation’s defense infrastructure pose a huge cyber risk.
Indeed, Bloomberg has published a laundry list of cybersecurity lapses among contractors that give bad actors and hostile nations a “leg up on countering the Pentagon’s weapons of tomorrow.”
Unfortunately, the DoD has lacked an effective way to monitor cybersecurity risk in its supply chain; thus, attacks continue unabated. Only last week, Nextgov reported that a supplier to several major defense contractors — including Lockheed Martin, Boeing, General Dynamics, and SpaceX — was the target of a ransomware attack. Documents were stolen from Denver-based aerospace contractor Visser Precision Manufacturing and are already showing up online. The ransomware used in the alleged attack, DoppelPaymer, steals data before encrypting the victim’s computer and then exposes the files, which can include classified or sensitive information.
The attack is a textbook example of the kind of cyber incident the Pentagon is trying to prevent through its new Cybersecurity Maturity Model Certification (CMMC) framework. But CMMC only goes so far. Let’s take a look at what CMMC requires and how the defense community can augment its cyber risk reduction efforts.
What is the Cybersecurity Maturity Model Certification?
CMMC is a new security DoD framework that holds suppliers accountable for their security postures before they engage in government business.
Finalized on January 31, 2020, the model articulates several requirements that contractors must meet to qualify for various cybersecurity maturity certifications. Those certifications range from Level 1, “Basic cybersecurity,” to Level 5, “Highly advanced cybersecurity practices.” These certifications are likely to be mandated in RFPs beginning as early as September this year.
How do contractors get CMMC certified?
To achieve certification, contractors must partner with an independent third-party agency, which will schedule an assessment. Contractors can select the level of certification they’re applying for. They will be required to demonstrate their cybersecurity maturity to the assessor; there is no self-certification allowed.
Once the assessment is complete, the certification level (though not specific results) will be made available to the DoD and the public.
Here is a comprehensive list of CMMC FAQ’s to help you get started.
The need for the CMMC in today’s security climate
No one wants more regulations, but as the DopplePaymer breach and other attacks highlight, it’s critically important that defense contractors find ways to strengthen and validate their security postures. Not doing so compromises their ability to do business with the government and heightens their own cyber risk postures. With the average cost of a data breach reaching up to $4.6 million per incident, these companies can’t afford the risk exposure. Furthermore, a breach would likely jeopardize national security — potentially exposing intellectual property pertaining to weapons, materials, and R&D that could compromise military and defense readiness.