Behind the Shield
Behind the Shield is InfusionPoints’ podcast where we sit down with partners, customers, and industry leaders to talk about FedRAMP, compliance, and cybersecurity in today’s government landscape. Each episode offers laid-back, insightful conversations that blend expertise with real-world experiences.
Behind the Shield
FedRAMP, 20x, and the Future of Federal Cloud Security with Michael Schroeder
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
What happens when someone who helped shape FedRAMP from inside a federal agency joins the conversation from the industry side?
In this episode of Behind the Shield, Gary Daemer sits down with Michael Schroeder, Director of FedRAMP Strategy and Market Development at Excentium, to discuss the evolution of FedRAMP, the impact of FedRAMP 20x, and what the future of cloud security and compliance could look like across the federal government. Michael shares insights from his time supporting FedRAMP efforts within the Department of Veterans Affairs Digital Transformation Center, where he worked closely with OIT and OIS leadership teams, Federal business owners, and Cloud Service Providers, in close alignment to the agency authorization process, before transitioning to Excentium to focus on strategy, market development, and industry engagement.
The conversation explores the shift from traditional compliance-driven approaches toward outcome-based security, the growing role of automation and machine-readable evidence, and why increased transparency is changing how government agencies, assessors, and CSPs work together. Gary and Michael also discuss agency adoption, the relationship between FedRAMP and CMMC, the challenges of scaling assessments, and why collaboration across the cybersecurity community may be one of the most important developments in recent years.
Beyond compliance frameworks, Michael shares his perspective on leadership, continuous learning, cybersecurity for nonprofits, and the importance of building solutions that make security more accessible and effective for organizations of all sizes.
Whether you're a Cloud Service Provider, federal agency stakeholder, cybersecurity practitioner, or simply interested in where federal compliance programs are headed, this episode offers a thoughtful look at the opportunities and challenges shaping the next generation of government cloud security.
Chapters:
0:10 - Meet Michael Schroeder: Career Journey and FedRAMP Background
7:38 - Public Discourse and FedRAMP
10:17 - FedRAMP Process and Challenges
16:25 - Security vs. Compliance
22:49 - Transparency and Public Trust
28:44 - Operational Security Practices
36:36 - Monitoring and Reporting
43:15 - Adoption of 20X and Future Predictions
55:54 - Closing Thoughts, Leadership, and Community Impact
What You'll Learn
• Michael Schroeder's transition from the VA to Excentium and the lessons learned along the way
• How FedRAMP 20x is reshaping federal cloud security
• The difference between compliance and operational security
• Why Trust Centers are changing how agencies evaluate cloud services
• The impact of machine-readable evidence and continuous validation
• Common challenges CSPs face when adopting FedRAMP 20x
• Where FedRAMP and CMMC may align in the future
• How automation can help agencies improve security oversight
• Michael's predictions for FedRAMP and agency adoption
• Why collaboration is becoming a competitive advantage in cybersecurity
• How security can drive business growth, not just compliance
• Supporting nonprofits through practical cybersecurity initiatives
• Balancing speed, security, and innovation in modern cloud environments
Guest Links:
https://www.linkedin.com/in/mjschroeder1/
https://www.linkedin.com/company/excentium/
https://excentium.com/
Learn more about InfusionPoints:
https://www.linkedin.com/company/infusionpoints/
Gary Daemer: https://www.linkedin.com/in/infusionpoints/
Request a Demo: https://xbu40.com/
FedRAMP 20x Quick Look Assessment: https://xbu40.com/assessment
InfusionPoints & AWS:
InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments.
About Us:
InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.
We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.
Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.
Welcome to another episode of Behind the Shield Podcast. I'm your host, Gary Damer, and today we have a guest from the West Coast of the United States, uh uh Michael Schroeder. So, how about you uh give give me just a brief overview of who you are and and what you're about? Um, keep it to very short time periods. I know we both can talk a lot. So I'm running kidding. Yeah, as long as you as long as you want to take, man.
SPEAKER_00Yeah, thanks. Uh well, uh thanks for having me on the show. I uh definitely watch uh most of the episodes a couple of times each. Um so uh I spent the last five years working inside of uh VA in the Digital Transformation Center, which is the org that does FedRamp. And I had a really great opportunity there advising OIT leadership and CSPs, interacting with a ton of systems that were going through FedRamp Agency sponsorship. Um and then uh, you know, that was a pretty big body of work I left behind there. And I decided to look for a new adventure earlier this year. Um so I found myself with Accent, which is a fantastic company and cool uh people. We can talk a little bit about them. Um, but outside of work, I'm actually I'm a single dad. I've got uh a teenager and uh almost 22-year-old. Um and yeah, uh it's it's an adventure. That's the real adventure of life.
SPEAKER_02So, Mike, how about explaining um what your company does since you're fairly new to it? Maybe you can give us a just a brief overview of of the company as well.
SPEAKER_00Yeah, as we're recording this, I'm a couple days away from my uh my one-month anniversary with Centium. And the company turns 20 this year, right? Our founder, uh Colin Corlett, uh built company in 2006. He came from uh serving DHA, uh defense health agency. He this is an SDVOSB, a service to save a veteran-owned small business. Um, and he came from technical trenches, right? He really feels that's where our company's credibility is still anchored. Um founding and still a thread through every contract and and uh announcement we make is that our goal is that security and compliance don't need to be roadblocks to growth. And a lot of industry can see it that way, right? Why do I have to do these things? Well, it builds security, leads to growth. And um, that principle's right in the operating logic. So another key part of our company is um Rick Virill, who leads our compliance and risk area and also leads a lot on security. Um, I he's got a stack of credentials. I just a lot, and um, some that I didn't know existed and I looked into and are really, really interesting. Like he's a fellow of the Health Information Management Systems Society, deep health um uh cyber uh history in the industry. Um and so over a decade and a half credential stack was built, right? FedRamp 3 PAO, we were GovRamp 3 PAO, uh, we got four ISO accreditations, CMMI level two, CMM uh C level two certified. Uh we're in GSA Mass and uh we're across all five subcategories for hacks for the uh uh and and so we're in uh higher vets platinum awards multiple years in a row. And uh that's before uh Fatima Corlett joined as the chief growth officer and is uh our COO. And she's got 20 years in the federal uh GovCon environment working with SAIC, Light OS, HP, she was with Oracle, and her mandate is growth that's aligned with our founding thesis that um you know security is the work. Yeah when they actually came to me and I they described the role, what they were describing was a chance to put their 20 years of company credibility into the FedRAMP 20X conversation. And for me to put my knowledge into being able to expand this organization. Uh, we've got we're not the most productive three PAO in the FedRAMP marketplace, and we're currently neither will we, we we had zero, by the way. So so we've got after 20x, we've got three. Um and so creds are there, we've got the credential stack, it's incredible. The relationships are there, the work's available, it's out there, right? And so my my real role, well, I'm I'm uh director of FedRamp Strategy and Market Development. Uh thank you for the opportunity to fulfill my role here. My role is to add the voice of Acentium to the conversation. Like that's the work. And it's really um, really interesting that all of these things trace back to this overarching reducing vulnerabilities in the nation's cyber infrastructure. That's everyday goal.
SPEAKER_02I love it. Sounds like our companies are fairly similar in nature. We're very technical-based as as well. Um, I'm one of those guys that have about a thousand certifications as well. Um, and although I I I I've said this year that I'm gonna let most of them go and focus on continuing to grow the company as well. So we've been in business for 19 years. Uh, we are a veteran-owned business. I was very fortunate to never have been injured in the military. So we don't have the service-disabled perspective. And then we're also a Hubzone uh uh company um as well, so a small business as well. So we should talk more on that part of it as well.
SPEAKER_00So yeah, I'm I'm really uh focused on FedRamp, on process and policy, on educating folks. I like to educate in public on LinkedIn, right? And I like to learn in public as well as I'm learning new things, engaging in big conversation with whomever will join in with their expertise so I could learn more.
unknownYeah.
SPEAKER_02There you go. Yeah, I find myself I'm not very much of a written person who likes to write in public, but I do like to talk in public. Um I always like to say I have a third, third grade education on the English side. Um I'm an engineer by trade, um a bachelor's degree and master's degree. So uh very logically, uh logically thinking. So my my written word is never as good as my as my uh spoken word, I think. I can debate a lot better logically and and fast. So um I like to see that because I do see a lot of your activity, you know, in the in the in the new public forum that we have for FedRAMP as well. So what let's start off by you know the experience that you had, say, in the previous FedRAMP uh regime to where we're at today. And I would love to be able to talk about that public discourse part, right? Because I think to me that is one of the best parts that that you see um happening within the the Fed the new FedRAMP space.
SPEAKER_00So yeah, absolutely. I'm I am incredibly grateful and excited about the way that not only the FedRAMP PMO, but you know, other organizations are reaching out, uh other agencies that have authoritative control over the work we do are reaching out for input from industry. Uh and then, you know, working my all my FedRamp experience is inside of VA and working there, I really couldn't have a lot of public discourse, right? Um there's limitations to how I can communicate about what I'm doing. But when FedRamp opened up 20X, I dove right in for the contract that I worked at, um, and for my own personal edification and to make great relationships. That's uh about the time I met you, Gary. Yep. Uh directly. And uh the process of capturing input from industry was just so robust, right? Um, so that opportunity to talk about my ideas about how FedRAMP could be improved and to give just precise and sort of uh incisive insight on the proposals was really great. I know not just for me, for everybody who took part. And I know that there were a lot of uh folks who captured more than their own personal ideas to share as feedback in the RFC process. I know we borrowed a few of people's ideas, you know, I'm just saying. Yeah, certainly. Yeah, I totally captured a lot of folks that they were posting in public, and I didn't see them in uh in the forums there. And and yeah, their ideas were good. I might have included them in my own, right?
SPEAKER_02I yeah, I'm I'm I'm proud to say that we did include some of some of uh other people people's ideas. And that was the whole idea behind this, you know, um this new process uh for FedRAMP, bringing it out into the open. Stop making it non-transparent. You know, uh we've been through the you know both phases of the pilot and you know, got uh obtained uh FedRamp authorization and both sorry, FedRamp certification.
SPEAKER_00I was gonna I was going to get you there, but yeah.
SPEAKER_02Oh please do. I would I would have got a laugh out of it, you know? Right for sure. Certification is tough. It's it's a it's same syllables. Somewhat is gonna be as a change as well, right? So it makes it a little difficult difficult. So that whole new regime of how information's flowing is so much better. And we and we've been doing this for a long time, and we've been through quite a few different agencies. We've even been through the JAB process, we've been through the DOD process. And I have to say that this is the cleanest view that I've seen in a long time uh for FedRAMP, especially for commercial organizations uh trying to go through this process. You know, the old regime, you know, there was definitely some black box information going on. If if you weren't quite involved in it, we were an advisor, uh, so it was hard for us to see what all the other three POs were doing. They also had some separate meetings with the three PAOs about what they should be looking for, but didn't really meet with the advisors. So we ultimately became a three PAO just so we could sit on the inside and listen to uh what they were telling the three PAOs about what they should be doing and what they could be doing as well. And that that that did help. But I think real really helped us more than anything else is we tried each case in the in in the court of of the FedRAMP PMO each time, and every time, and that's why we we have to tell our customers, is we learned something different every single time. Um we got we got past the 11th step and they added a 12th step, or they added a 13th step, you know, e each time. So each time we went through this process, it was it was a bit difficult. But you know, we always manage that gray, and I still think there's a lot of gray requirements in this, but I think those gray requirements now are more out in the open and can be discussed uh better than that.
SPEAKER_00But I think that the gray requirements as well are on the other side of the equation right now, right? A lot of that gray was, well, we haven't seen that yet, so we can't define it. And so and the messaging there from under the old method, which is gonna stick around, ref five's not going anywhere for a while. But the messaging was always, well, they don't have a a so a solid answer. And since agencies were the sponsors and leading that process very heavily, agencies were more conservative. And so the answer was, yeah, we're not gonna do that then, if there's not a clear, stark answer. And now it's more um, yeah, we don't know. So let's try it. Let's let's see how it might work. So I think the gray still exists, probably even more vast now, while you know, class uh D is basically opaque to most people, um, and the way that certification versus authorization is aligned, uh I think that that the gray area is now an opportunity instead of a limitation, like it used to be. And being inside uh from the agency perspective, right, building a program where uh, you know, VA was the biggest contributor to the FedRant marketplace for sponsorships. And then we had another couple hundred systems that were authorized in already that were ingested and got agency ATO. Right. And there was difficulty even in that position with getting clear information and answers, often. Even from the agency side? Even from the agency side. Wow. Um, because limited resources on both ends, right? From both agencies, and often due to the structure inside of an agency, which is just the way agencies are structured, right? And I've spoken to counterparts and and tried to groupthink with folks in other agencies and similar organizations when I was there. Agencies have some strict structure. There's, you know, separation of responsibilities towards different components that build the system security plan and the ultimately the system security authorization package that some AO is going to make a decision on is all of this robust and clear enough? But along the way, there's checkpoints from the agency perspective. And often the thing that we need to know might be gate gated not only behind an organization inside of the agency, but then how that information they hold applies and is interpreted by the FedRAMP PMO. So yeah, right now, where not only is the PMO leading certification process, um, and that opens up that pathway for CSOs to be completely available to the agencies, um, everything happening in public and in the forums and being done with discussion instead of decree, I think is just fantastic. It it allows practitioners, experts, very specific SMEs to put uh insight into processes that are going to affect all of us.
unknownRight.
SPEAKER_00Who may not have that sub specific like privacy stuff. There's some some CUI uh or rather uh privacy stuff that CMMC experts provided as insight on those forums and uh an attention to the RFCs. And um that may not be a hundred percent applicable, but knowing that information is critical for the PMO to make a a decision on what the rules are gonna be.
SPEAKER_02So do you do you feel this is a very crazy question, but I'll ask it anyway. Do you feel like we're doing we have more security now or less security? I mean, what how do you feel about that?
SPEAKER_00So do we define security as a very strict set of obligations and requirements and checks that can be uh marked off? Because if so, we have less now. But if security is intentional institution of practices and and methodologies that achieve the outcome of reducing vulnerabilities inside of these systems that are being used with our federal data, we're doing so much better. 20M's is a much better.
SPEAKER_02See, to me, that's exactly what it is. To me, that's exactly what it is. It's really more about you know the security of the solution and the data. And it's not so much, you know, did I write that control exactly right? Did I dot my I, did I cross my T, did I write, use the right words in there to make it past um um the reviewer, right? It's more you know, show it to me right now, show it to me right now, show it to me right now. Right. And then look at it in a total solution, too, right? You can look at it in a total solution with the with the trust centers, uh especially the public trust centers that are out there.
SPEAKER_00So that's a huge change, right? That's magnificent. You can know that the product that you're gonna try as think about bringing in as a solution, and and that's not limited to the agencies who are the ultimate real customers to FedRAMP products, it's to all the the CSPs who are building an offering that is going to incorporate FedRAMP authorizers, FedRamp certified um tool sets.
SPEAKER_02It's gonna take us a while to get there, man. It's gonna take us so long. Yeah.
SPEAKER_00Well, and also we're talking about two separate things, right? Uh they are technically still authorizations until June and the consolidated rules are coming out. Yeah. Right. Um But yeah, so that uh public-facing trust centers are outstanding. I think that's one of the greatest choices that um providers have made along the way, and that that is now institutionalized.
SPEAKER_02I tell you, when I first saw that requirement, I remember saying, there's no way in the world I'm ever going to do that. I forget this whole 20x thing. I'm not putting my security out there for everyone to see, you know, and and then after a while I thought about it, well, maybe we can if we do this, this, and this. Like we redact all our evidence out. So you you you can't tell. And you know, it's it's we that the way we do 20x is we do the validations. But on top of the validations, on on for each validation, we have between you know three uh to ten checks, right? So we we look at each of those validations and we say, okay, is this true? Is this true? Is this true? Is this true on down the line? So we took all of our checks out of our public um our public uh trusts that way people couldn't tell exactly what we were testing. You know, if you want to see that, then you can get a private view and um you know sign all the proper paperwork to to get into that environment, right? Um you know, so that that to me uh uh kind of swayed me. But I tell you what, it did take me a minute to get there. Um because my my traditional view since we've been doing Fedbread for so long was a package included all the evidence. You know, all the all the screen captures. You know. And in this case, it's not screen captures, it's script that runs that pulls JSON, you know, so we can make it into a re machine readable readable uh format. So you know, we we don't publish that on a public side, but that is on our private side. So if people want to be able to see that. So but I'm gonna uh it it did shock me for a minute. And I I talked to quite a few folks in the industry at that time, and I think everybody like took a step back. I mean, if you remember the forums when it when that first came out, it was probably how this is gonna happen.
SPEAKER_00How would you just conversation was hot and heavy? Yeah. And you know, um Accentum is a three P as a three-PAO, but it's not necessarily the primary thing we're doing, right? We're um a service provider to federal agencies, working um in a variety of ways, advisory capacity, um, but the the company being founded on a simple premise that um security leads to growth, right? Yep. Um the mission, and I I've been living this mission, uh, you have as well, it's to reduce vulnerabilities in the the nation's cyber infrastructure. Little ways that we can and building relationships and networking and organizations with fellow folks on that that mission, right? And just trying to learn from each other and capture the information. And I think that you know uh that thought process is more open now. In just the past year, consider the amount of openness with uh with people who you compete directly with for business that has occurred, right? People who are absolutely communicating about their methodologies in public. Whereas before, you know, that was locked secrets. And if anybody, you know, and there was a feeling as well, I know, early on that with companies that partner with government and commercial industry, that uh sharing the way 20x is and putting putting your pilot in public on the GitHub repos was just absolutely incredibly insert negative word here. Uh, you know, nobody wanted to do that. And I remember several negative words, by the way. Yeah, yeah. And maybe uh maybe inserted uh you know objects off of a desk. Um pretty much. And I remember explaining to uh a federal lead um what 20x really was, right? Um uh Scotty Ross, great guy. He's uh uh a a fantastic human. Um but I I I like he went into a reboot loop. They're gonna do what? And like you could just see all of it processing at once, and just it's so antithetical to the way that FedRamp has been done for so long, the way that other frameworks and governance uh and compliance um requirements have been delivered. That that openness, that transparency, a year in, uh a year in to the the concept, it looks like uh we were in the dark ages with Rev5 and the way that things were done.
SPEAKER_02I tell you what, it it opened up our eyes in a way that allowed us to look at the problem set a little differently, right? And what we did is is we took a look at the way, say, SOC 2 was done or uh ISO 27,000 was done, and you know, you get your certification, right? But then there's a report that goes back behind it. Maybe you don't make that public, but you bet your certification public. So that's your public facing piece. The same thing with your SOC 2 reports, they do a public facing one, um, and then they could do a um kind of a private the private label one as well, right? So so that that's kind of how we started to look at it and from a private perspective and a public perspective. We I think we actually were probably a little bit too open in the very beginning on our on our public side, and then we then we pulled back a little bit on on that as well. But I I'm super happy, you know, that that we that we went all in on 20x and decided to go this route. You know, our engineers will even tell you half the stuff we had already developed. Um, and we had scripts that we ran, you know, to be able to prove to different uh three PAOs. Uh the the problem was is it it for us uh is and then converting those that that they could be machine readable and um in a fashion that could be reportable. If you have a whole bunch of extra scripts that you run, which that's kind of how they were, they were disjointed, you know, uh scripts or lambdas or whatever. And then so we ended up um you know kind of converting all a lot of those into our our first set for for 20x. But it was still was a was a leap of faith from a technology perspective of what else that we had to to to uh to develop. And some of the ones that we struggled with the most uh from a from a 20x perspective weren't really the technical controls. It was more the prove to me that you're doing it consistently or the word that they use persistently, right? That was the harder part. And I still I still think it's hard uh to truly show that you know if you if you have one or two incidents a year or you know whatever whatever the the mount is, it's hard to demonstrate that you're doing that persistently, that you're doing the lessons learned. You're doing all those very constructive elements for for of a very solid incident response program to be able to show that um each time in a logical way that you can test. But for us, we have a ticketing system built right directly into our solution. So all that stuff is built right directly into the platform. So it makes it easier for us. So if you don't have the other ticketing system built and you got you may figure out a different way to show that you're you're you're following the incident response, you know, persistently managing your incident response with lessons learned and all the things that you need to be doing there as well. You know what do you what do you think about some of those kind of harder non-binary one or zero kind of thing, you know?
SPEAKER_00Yeah Yeah I mean obviously great for security for improving the visibility of of work allows FedRamp to have a better understanding of what the CSO is really operating like. And uh Accent was in 20X as well we were a three PAO for uh another platform. And some of the things that we learned in that process you know you're right that demonstrating persistence is uh you know this was in a low pilot. Um demonstrating persistence is difficult when you don't actually encounter the issue if you haven't yet had a reason to mitigate something. So and we're operating across Fed space in a few different vantage points, right? We're a service provider uh to federal agencies, right? And federal agencies are actually two of our longstanding three PIO engagements are cloud services built by Gov for Gov. Oh okay and so these are just two of six that fall in that category. And federal agencies have a different viewpoint and sitting in that that that environment changes how uh security demonstration really works right and and to ensure for a federal agency that that the product that not only they're building but now they're consuming as well directly is meeting all of these requirements um it that is definitely more the checkbox style solving. And so I think the big difficulty to wrap back to your actual question is the big difficulty is going to be having consumers of the products understand what their obligation, their shared responsibility to providing the information to the CSP is because there is a little bit of that that shadowed wall and incidences happen on the customer side more often than on the provider side. And so I mean there's a complexity there that that we're still exploring right we haven't haven't really dove in entirely but I do think as an outcome right rather than the the functional pieces of how it's being delivered as an outcome those less technical things are really gonna help demonstrate more right that the security's there that people can have trust in the system that when they're building a CSO that incorporates a tool that has demonstrated their persistence towards towards the KSIs um it will overall increase security but the de how to is really vague as you said and and the way that it's done we're gonna see some innovative stuff I think there's going to be a duff uh a a bunch of different ways that this is accomplished innovative ways and sometimes you know you're gonna find ways that didn't work things that that reporting didn't apply enough.
SPEAKER_02I will tell you that the first couple tries that we tried just didn't work. They were they were they seem right on paper but then when you actually went back to uh execute them and they just didn't perform the way that you you would think you know this actually was a a big discussion that I had back and forth with the PMO on this I I I personally and I'm still trying to figure this part out um even after doing this for a year now to me there's a difference between operational security and compliance right and and and 20x is still a compliance program. I mean it's it it's it's a security program but it really is a compliance program still. And I think some things are you know operationally are different than than compliance you know and then one of the things that we talked about was let's say I I import a new a new system or a new container in and my SBOM is a is a little bit different or I have a a vulnerability or two in that but then I get it corrected like within the time limit of of you know the the Vader product right or Vader right am I am I out of compliance or am I in compliance and do I need to report that or do I need to say it's within it's within the timelines. I think that's an I personally think that's an operational security thing. And you don't need to truly report that as a violation or not meeting not meeting right um so there's there there's going to be some boundaries that are going to occur over time in my opinion that say you know this is an operational thing and it just doesn't it doesn't make your system any less secure because guess what? You're following the rules you're doing what you're supposed to be doing and um you're achieving the uh ultimately the overall outcome is by making it secure within that within the timeframe that you need to be making it.
SPEAKER_00Now granted you don't want to you know go up to the wire on on on on you know to contrast that to the way that it previously would be handled, right? You had an incident report, you had to mitigate an issue and the number of in Kanmon in in the agency side right as a as a recipient of of continuous monitoring reports, the number of incidences or or vulnerabilities that had to be documented or um in a POAM deviation request. The the times where effort was put to create a POM that was already for an issue that was solved weeks ago. Right. Because it was only on the POAM sheet for a day. Right. A few hours of a day because as soon as it's identified it's being resolved and that that hard documentation, yeah, is that operational security relevant or is it just compliance, just that that check boxes?
SPEAKER_02Right. I think we should lean into the operational security perspective. And and and you know now there are going to be some people who take advantage of that, right? But I think more often than not there are going to be folks who really want to follow the rule of operational security and really focus on what do I need to do day to day? What do I need to do week to week what do I need to do month to month what do I need to do once a quarter perspective. And you know if if it if it falls within those the the the criteria do you really need to report that you're out of compliance. That's where it becomes real-time monitoring for compliance may not be the best way to handle this. I like the way they're doing it right now. Certain things need to be done every couple days, you know, certain things need to be done every um on a weekly basis and so forth. They got a whole schedule for uh the different KSIs uh as well.
SPEAKER_00I I like that I think it'll be interesting once they're talking more thoroughly about a class D, right? Yep. Um how how aggressive the intention will be to um those timelines and mitigation uh obligations. And that I think is when we're really going to see the the impact of the persistence, the the consistent and um uh monitoring the the use of those um trust centers and the reporting dashboards are going to be really important over time um because there are a lot of systems right now that are FedRamp authorized that the agencies utilizing them in ways that are you know high, high high on the s on CIA triad triad that we don't know for two months currently right that's basically because that's the reporting mechanism, right? Right. Right. And so while real-time reporting of of the uh the system security and the adherence feels like it could be onerous right because yeah you know like you just said the concept we're talking about do we have to report something that was out of compliance for a day if we mitigated it and solved it but in some systems yes that knowing in an hour is going to be critical to to the agencies who are responsible to those systems. Yep. And it seems as though overall the federal agencies that the federal agencies report to right and the organizations there are much more attentive and intentional about mitigating vulnerabilities not just in FedRAMP right um you know point my big uh finger at CMMC these all align really well in the seriousness with which they're being taken is while onerous in ways I think it's overall good for increasing security, right? And the improving the security posture overall of our of our interconnected systems that are delivering like you know on federal information. It's pretty important to keep those in real time. And that is one of the biggest uh changes that has the most impact I think the most positive impact on actually being security instead of just compliance that 20x is is delivering.
SPEAKER_02Yeah and you know something that I I like to talk about a lot as well you know sometimes we when you report on everything, right, you get inundated uh with the alerts right and if you get inundated with alerts after a while they you become numb to them and and you don't see them. So if you're trying to do too much from a let me just say a in a larger perspective like say you're an agency and you're trying to view what's going on overall, you know, if you try to watch all the vulnerabilities from every single system at all times, then you're you as a an agency in that in that monitoring capability, you're not gonna be able to keep up, right? It's just not possible to keep up with all that. But now if you re if you report it on I'm gonna I'm gonna monitor these 200 systems, but what I'm really gonna monitor is whether or not they're staying within tolerance of that that check that's much easier to monitor. And then if you see them go out of tolerance how quickly can they bring it back into tolerance? That's that that's the true true um uh um I think mission of you know managed service providers or managed security service providers is to provide you know that tolerance how can we get that tolerance down in more in a more automated fashion um but I think I think if if people try to monitor every level of detail then then the alarms and knobs are going to be too hard for them to to maintain. So focus on the things that are important and I hear that from Pete all the time is focus on the things that are important, you know, which is true um you know and sometimes things might be more important to me you know than they are the PML office because I've been I've lived in this space for 40 years. So it's a day a day or two, right? So the cybersecurity space is is is is definitely a passion uh for me and um trying to figure out how do you get the right amount of data in in front of the right people at the right time. And that's the pizza I think we ultimately need to think about. So if you still continue to go back to the individual systems this is great. I think 286 would be going to be really good for that. What I truly think it's gonna be great for is managing the 200 pieces as well, right? So if you can look at all you know the red green um yellow indicators it's gonna be a lot easier to manage that.
SPEAKER_00You know so does that make sense? Oh that totally does and agencies will end up ingesting um the their own dashboard or you building their own dashboards to be able to ingest this information and highlight it to the right people because part of what you were saying what's important to uh 3PAO to see uh an IAS independent assessment service uh if we're gonna move forward with the right language right that one's gonna be tough that's the that's the the tough exactly IAS no people are gonna be like what's that um but space shuttle what's important even to the customer our customer is going to be different to the the CSP that is uh is going to be different to the agency customer but there's gonna be differences there too because there's some ISO who is assigned you know 47 systems to make sure Kanmon is being done appropriately and the things that they're gonna be looking out for that are critical and relevant to them so much different than the privacy specialist who's also assigned to an uh you know I see that in the future where where they'll break down those um those different roles and the different foci to individuals to monitor across lots of systems instead of it all being one you know one giant job of spending seven days in a row reviewing the CIS CRM against the SSP and making sure that every single security control is documented in their system of record in a different verbiage. Right. So the focus is going to be able to change from that compliance.
SPEAKER_02Do you think that's gonna happen in our lifetime or in our in our I I foresee it happening.
SPEAKER_00There's a lot of change in leadership in in the agencies, right? That's definitely true. Yeah. Right. And there's there's different mentalities that really strongly align with some of the the speed and um you know operationalization of information systems that are you know are prevalent right now in the federal government. So I do think that these people who are coming into roles that are you know just delivering on a uh their career with the perspective that we need to move fast but do it right, that they're going to see agencies that are high consumers of FedRAMP systems really treating it the way that we are right now, the way that the the you know the industry is uh there's there's so much value to it. Right. Like if they can automate 70% of their tasking and really align to the important vulnerability criteria, the things that matter for the use case that they have it in I think that there's going to be changes like that. It's gonna take a couple of years, but I also feel maybe slightly pessimistically that it's gonna take a couple of years for there to be uptake of 20x by agencies. That said, I mean the PMO and there's agency leadership that's talking in public about being ready to do this, ready to ingest 20x, ready to dive in and see the automated validation, the the cons persistent uh uh validation of security controls. I know that um a couple of agencies have built internal systems that do things like uh rely on other than FedRAMP certification to demonstrate security posture for authorization. Right. Now those agencies are still you know beholden to adhere to the FedRAMP Authorization Act and use FedRamp for cloud systems but it's good to know that there's innovation in multiple agencies. Another reason why we're going to see that is the if you go on the FedRAM marketplace and look at who sponsored or or authorized what systems, a lot of smaller agencies just don't have the manpower simple as that to be able to ingest a traditional FedRAMP package. It's a lot of work. Agency in kind spending on a FedRamp ATO even just a moderate not even as the sponsor is big as a sponsor agency it's kind of astronomical. Right. Yeah and so when we have these smaller agencies who are going to see the advantage of automation see the advantage of machine readable evidence and real-time Kanmon, um they're they're definitely going to start consuming it. So I do think we'll see real, real uptake on this in a in a short period of time, especially from the smaller consumer aid consuming agencies on the FedRAM marketplace.
SPEAKER_02You know, you you said something that that that I I live and breathe by for sure here at diffusion points and it's you can do it fast and you can do it right at the same time. Right. Matter of fact I think you can do it fast and right easier today than you ever could, especially in cloud native systems, because cloud native I mean there's so many the ability to pull the right logs out or be to be able to check the metadata you know on systems it's just it's just so much easier. Everything comes with APIs nowadays. So all you gotta do is be able to talk to that API, get the right authorization to to get in and pull that information and then you could pull that information back in a lot faster than you ever could today. And it's right, it's more right than it ever was when I transferred it here and I wrote about it there. And then I took about a diagram over here and then I and I and I and I adjusted it based off of the vulnerabilities that were in the system a week ago. Right.
SPEAKER_00So you could definitely do it for the Bob's got the new uh A B D, but he's out for two days.
SPEAKER_02So wait until Friday we've got to make some adjustments to that diagram because you know and we can't we'll be we're being audited so we're not allowed to touch the system for another couple of weeks. But yet now this I I this the fast but a couple months you know I think fast but right I think is is is is key and actually and and and more secure you know I I I what I'd like to do is shift the conversation a little bit now to all right this is great. I love this right this whole I um everybody knows who's listened to us to me once or twice knows I'm a big fan of of 20x and what it's been able to produce. How do we now get other organizations to be able to see this as well? I mean can we can we start to see maybe CMMS E adopts something like this as well? Can we see, can we get the DOD to start looking at 20x or something like 20x to to push you know that through as well um I I think that um you know um we do probably half of our work is in the Department of Defense um helping customers through the the IL four and IL5 um um impact level four and impact level five uh perspective uh and the requirements uh that they need to meet to get there. Uh the requirements to be honest with you are fairly similar to what they are in Fedbrand um yeah there's some changes here and there's some software that you have to use uh versus what you can use. But to be honest with you, it's really about the time it takes to get somebody through that process. And we can help people get the technology right we can help them get the processes right we get the management pieces right but it's been going through that process to demonstrate that you have met uh you know the requirements for the DOD side do we do we do we see or can we see you know them guys taking on this kind of effort? I think CMMC might be a little harder because of the nature of the customer base. So let's hold that one to the second the second part of the conversation if that's okay with you.
SPEAKER_00So yeah so other organizations I think that smart cloud native companies are building in ways even if they have no intention right now of becoming FedRAM certified they're building systems in ways that like you pointed out cloud native systems make it so easy right an API call through their whole supply chain allows you to have outcome of of the the data flow and and where the security is I think you know the the choice there are going to be companies that are not cloud native that are just going to be like well we're going Revive and this is what we're gonna do. And I think in 28 we're gonna see Rev 5 continuing to 30 as well right yeah I'd there with you that that engineering muscle answers both the the Fed ramp and CMMC especially if you're talking about level two right um question. You've got the obligation to uh uh NIST 800 171 when 72 just came out yesterday. Uh R3 came out. Um, you've got these obligations to FedRAMP from these companies or for these companies to be CMMC, right? We like let's talk about that. You have to be FedRAMP moderate equivalent, but you can't have any vulnerabilities that are and any unassessed controls, and you can't have or unimplemented controls, and you can't have POAMs to attain FedRAMP moderate, and it's in a time box. You only have a certain amount of time to be able to deliver any remediation you need when a three PAO assesses you for FedRamp moderate equivalent. So, in ways right now, CMMC is more difficult to become FedRamp moderate equivalent than getting a FedRamp high. Right. Right. Um so I think that DOD has demonstrated with CMMC that there is some openness to hear from industry. Not necessarily responsiveness to what they're hearing, but they've had they've heard. Um NIST as well is moving along with a lot of input from industry. Again, not responsiveness to that input, essentially. They're not saying, yes, we heard you and here's why, the way that FedRAMP is. But I do think that, again, a lot of different leadership inside of a lot of different organizations and agencies is going to lead to that faster, better the first time outcomes. And if they're looking to achieve those goals, then they're gonna have to redirect their agencies and the programs that um they manage and direct to be responsive to machine readability, to persistent validation. Um again, it's it's gonna be a journey. I mean, the FedRAMP journey so far has been 15 years, uh, right?
SPEAKER_02I was like, I was like, I was saying to somebody the other day that uh when FedRAMP first started, there was one, then there were two, yeah, then there were three certified systems, and there were four certified systems, and then five, six, seven, so forth and so on down the line. And then finally, next thing you know, there were fifty, right? And then next thing you know was that there were a hundred, and then it was two hundred, and now there's how many? I mean, there's gotta be close to getting six hundred close uh down. It's like five, fifteen somewhere in there right now? So low low five. Yep. Yep. And then uh we got more.
SPEAKER_00Some have no ingestion currently, some have no federal use cases that they're applied to, but the vast majority do. And if they're revive, they're no longer listed if they don't have the sponsored use case. That's a difficulty. And this changes that too, right? I think we're at a really great crossroads with the way that AI consumption in federal government spaces is increasing and being done in a moderately secure way, right? Right. Um, there's uh CMMC phase two is uh a big deal too. CMMC's been out for nine years, 10 years. Right, right, right. And it's always been an obligation under DFARS. I think 2016, I'm I'm still learning about CMMC. Uh it's relatively very much.
SPEAKER_022016, 2017 was the year uh that I had to turn my inbound marketing off because I had so many DFARS customers coming in to meet the deadlines. I think it was December 17th, uh 20 uh uh December uh 31st, I think that everybody had to be.
SPEAKER_00Yeah, and that was just for the the level one self-attestation, making sure that things are right, right? But so now that there's uh there's this big end date for 300,000 businesses, 80,000 of which are expected to require level two assessment. Um, there's a this again, this rapid increased consumption of AI and FedRAMP20X changes. Like this is the backbone of information system security for the federal government and its most uh high and widespread use cases. We've got GSA making sounds about wanting to have CMMC equivalency. We've seen that, right? Um HHS is also uh talking a little bit about trying to bring either a Fed FedRAMP-like program to life. It is not just a DOD problem, right? So And it is really important for the average person, right? I mean, DOD C UI, yes, that that is national security, but that's an abstract for us. But when it's health and human services, when it's DSHS, um uh there's there's a real personalness to it that I think average people can feel. And the more people that are learning about these k these requirements, these capabilities, I think that we're going to see a response that's positive from federal government.
SPEAKER_02Something else that that that they really need to focus on, in my opinion, right, is um some of the requirements for certifiers, right? You have to have a certified person to do the assessment. So you have to have a senior FedRAMP specialist. And then you have to have a certified um uh um auditor for a C uh C3PAO. Well, what happens if my auditor has one each of those, right? And he audits me on FedRAMP and all the evidence they collect on FedRAMP, they can't use now in the um CMMC audit because the CMMC audit has to be audited by a CMMC auditor, right? Right. So certified. So they can't take that evidence, so they have to go back and recollect all that evidence. So now we're really are running people through two audits, and you can't do those combined audits. So somehow or another, they could they have to do some reciprocity as well through that um auditor space um as well, not only just in the hit meeting the requirements, but it's demonstrating that you're meeting those requirements. You know, so you have to they're making they're making firms do that twice if they're on the on the FedRAMP side. If they do the FedRAMP requirements, and then you also then have the CMMC uh uh requirements that you have to meet. Um so somehow know that that has to be brought out a little bit, and hopefully they'll make some some adjustments to to allow maybe both of those uh to occur. Because they keep saying they're they're having troubles you know with with uh getting people registered, you know. Well, maybe what they need to do is look at the other other third party um auditing um capabilities and say, you know what, we'll accept FedRAMP auditors uh as well. Now, some people, well, it's totally different. No, it's not different, right? The requirements are the requirements, and how you interpret them are not gonna be any different, whether I'm a FedRAMP auditor or I'm a CMMC auditor. Uh same way when we deploy them. I don't care if it's a CMMC requirement or it's a FedRAMP requirement. If if it's tells me I got to do X, I'm deploying X and I'm configuring it in a way that meets those requirements. I I don't need a special hat.
SPEAKER_00Right, right. Well, and especially when when, as we're discussing, you need that FedRAMP moderate equivalency to be assessed by a three PAO, a FedRAMP 3PAO for CMMC. And that has to be a to my understanding, I could be wrong on this, but that has to be a separate party as well. It can't be it Yeah. Yeah, it can't be the same uh individual that's doing the the CMMC.
SPEAKER_02It could be if they were if they had if they it could be if they had both both individual certification. So if say I was an individual that I had um the capability of being a senior auditor, you know, inside a FedRAMP, and then I also have the uh C three PAO um widget, you know, uh certain certification, then I could do both audits. But but they're already struggling to have just the C three PAOs. How are you gonna get people that spend the time? Because the the education requirements are slightly different, the the testing is different. You know, one you have to do the bar cybersecurity thing, the other thing you have to do the the event um uh and training and testing, you know, for the the CP uh C three PAO. Somehow another they gotta come together, in my opinion, in that uh as well. So not just from a requirements perspective, but also from an auditing perspective. So I think there's just starting to see some of those crashes.
SPEAKER_00So yeah, definitely. Nobody's gonna be able to deliver to these 80,000 companies that need to be CMMC level two by November. Just not gonna happen. And so the waiver system exists in in DOD, so they can, you know prov allow service providers to continue doing so until capacity opens up far far enough. Right. Um similarly, and I think here's a key component to what you were saying, Gary, is that uh A2LA and FedRAMP were able to provide waivers for some of the requirements for three PAOs and uh during the pilot processes. It's still to be seen if those are going to continue for 20x, but it's it's lowering the bar for again, is it security or compliance? Lowering the bar for compliance for an auditor to deliver these audits as opposed to lowering the the security of it by taking away their skill sets, right? Or the skill requirements. It's more just the the credentialing and that that for CMMC is tough, right? Like that is a difficult thing because it is that's administered by um CPAs, right? And CPAs are definitely looking at what compliance looks like differently than uh a senior security engineer is. Yep. Yep. Yeah.
SPEAKER_02So um as we get close to wrapping this up, um how about some predictions from you? Um what do you what do you see? You know, if you had a crystal ball, you know, what do you see this thing three years from now? You know, your hopes, dreams, and and aspirations, you know, keep it that way as opposed to the thing.
SPEAKER_00Yeah, totally. So I foresee, let's say let's call it three years, right? Let's call it three years by 29. I foresee that um the vast majority of agency use of systems will be through 20 acts, that there will be a short uptake in the next 18 months. And about that point, they'll have had time to really build systems that work right to be able to ingest and trust the systems that they're that are certified. I would say I think that um this single community-based rule set, right, is going to continue. We'll have a lot of lessons learned, but I don't think it's going to look very different than it does now. The persistent validation, the uh automation and and machine readability is going to be more pervasive in industry than just inside of this framework, because it's a smart way to do it. And often where the federal government requirements lead, industry will follow and adjust. Especially in the security space, right. Especially in the security space. Because hey, maybe we're not doing business there now, but geez, it's smart. And look at all the effort and resources that have been put into developing these processes and these pathways. Who wouldn't take advantage of somebody else putting that kind of time frame and and effort into building what works? Um I do think that there will be a lot more alignment over the course of the next two years between CMMC and FedRAMP to some of the things that you're calling out as a wish list. I do think that the bars will align a little closer and that there will be crossover between the C3PAO and the the FedRAMP 3PAO. Um I also foresee a really large increase in the systems that are on the marketplace, right? The FedRamp PMO has said that they're expecting maybe 50 certifications by end of this calendar year. Um unless unless, you know, when Pete stated that at some point he meant the fiscal year, in which case, hey, cool. That's October, right? Yeah, right. That's soon. That's real close, real soon. Um the rules will have been out for a season, a single course. Yeah. Um I think then we're gonna see probably a doubling next year. If if the the PMO has the ability to handle that throughput.
SPEAKER_02We actually did that same exercise uh here at the office, and uh that was that was what that was kind of like the common theme was doubling in size uh of the marketplace. So I I hope to see it. Um make it a really robust marketplace and then be able to, you know, the agencies be able to find what they want and have some competition to to be able to leverage you know across the board. You know, if company X doesn't satisfy them, it's very easy to go to company company Z. Indeed. You know, so that that's pretty cool.
SPEAKER_00So and I also think that, you know, three PAOs are gonna have to make some shifts too. The people who are auditing on both both of these. Um I mean, uh one shift that we already talked about is an increase in in politeness and and co-working and sharing of knowledge. That's not gonna change, I don't think. Um there is a large enough market, I think, where that risk of being good friends with your competitors isn't going to be as much of a challenge as it might have once been. And, you know, we're all concerned about conflict of interest. That's really important as well, um, to have those good relationships to manage that and serve the customer needs. Because if the market's going to double, then we have a lot of throughput to be able to manage. There's a lot of customers that are going to need to be served that are have CSOs. And ultimately, it is, you know, our our customers, our our federal customers, the whole industry's total customer. Um I'm really thinking, I I've said it, I do think that the federal customer is going to have a strong opinion shift. About 18 months from now, everyone will be seeing the value of the new methodologies and these increase in turnaround times, the increase of availability for them to deliver on their missions. Yep. Um they will will certainly jump in. Yeah. We can we can visit it at the uh the tail of 29 to see how close we are. We'll come back then and we'll double check, right? So hopefully we come back before then, too. There you go. You know, the the work ahead is meth methodological, right? You've got to change the methodology by which we're delivering work. But it's not very different from what everybody's been doing so far. It's just in fact uh easier in some ways, once you have the systems and the engineering in place. Um, and then uh yeah, there's more availability for everybody.
SPEAKER_02And the more times you do it, the better, better it feels. The more times you do it, the b the the easier it gets, the more recognizable it gets, the the easier it is for people to understand, right? And then accept it. That's where we need to get to. So um I've got two or three other additional questions for you if you want to take them on. Um is they're a little more personal in nature in some ways, but uh Oh, yeah, for sure. Yeah, there you go. What uh tell tell me uh like one of your favorite books, uh or one of the big the biggest biggest book that you recommend here lately.
SPEAKER_00All right. So um Xentium uh uh leadership pointed me towards a couple of great books. Um one is Traction. Um by Hyatt, I believe. Um awesome book. I'm about uh a quarter of the way through. Uh that's the the nonfiction, the work-related stuff. Uh fiction-wise, uh one of my all-time favorite books is a book I don't know the author, but the title is As the Crow Flies. Okay. And it is a uh early 18th century fruit merchant with a cart uh who ends up uh owning a uh conglomerate of department stores across the world. His journey is just really cool. It's a really great, great story of perseverance and and climbing a lot of tough hills and approaching challenges.
SPEAKER_02One of our core values here is this grit, be gritty, right? So you gotta hang in there and and and and you know show that you can get something done. Perseverance. I used to say patience, person perfect perseverance and uh patience. So uh hang in there and and you can get it done. So and I changed it over to the case.
SPEAKER_00I try to practice patience every day. Um I'm I I have this thing, right? Since we're doing personal stuff, one of my favorite things is if I'm in the grocery store, and again, I'm a single dad, I'm I'm there a lot. It's just the way it goes. Uh and if I have to have teenagers, right? Yeah, yeah. Uh if I have just a couple or if I have a lot of groceries, I like to let the next person go ahead of me. And uh especially if they've only got a couple of things, right? I hate being the I hate having two things standing behind somebody with a cart full of groceries.
SPEAKER_02Um right there with you.
SPEAKER_00So uh when I do, I let them know, hey, look, I promise it's a good thing for me. I'm practicing patience here. I'm just you know making sure that I can do this. I can be in a situation that maybe at another point in my life might have made me impatient. And that spreads throughout all the aspects of my life.
SPEAKER_02There you go. There you go. How about a TV show or a um um movie uh that you've recently watched that you'd recommend?
SPEAKER_00Um I'm not a really uh a TV and movies kind of guy, but I I will say that the Dune movies are pretty phenomenal visually. Um not fully true to the books. But uh, you know. Uh even uh Frank Herbert's son isn't uh as true to the books as as he could be.
SPEAKER_02Um my wife and I watched um uh a movie called Apex on Netflix the other night. Fast paced, action-packed, just make your knees wobble. Um if you like those kind of movies.
SPEAKER_00Yeah, I like to go for uh you know, the the content that I I have some love for, like Dune, right? But uh generally I find myself if I'm watching TV, I'm like, oh, I could be writing something. I could be studying something right now. There's you know I could be able to do that. Well, I do both at the same time. So Yeah, there's that too. Trevor Burrus, Jr.
SPEAKER_02It's the reason why I mentioned my writing page up front, you know, it's the third grade level. It's because I'm so inundated with watching movies like Apex.
SPEAKER_00So Yeah, but you have the verbal communication. It's uh you know you get capturing that verbal communication mechanism. That's it.
SPEAKER_02That's it. I'm a visual kind of guy. So um so the last the last one is is along the lines of we're we're a services-based kind of company, and uh we help a lot of nonprofits around. I don't know if you do any of that. If you do and you want to you know give a shout out to what you do, that would be awesome.
SPEAKER_00Yeah, I am uh recently engaging quite a bit in understanding how nonprofits serve my local community. Um I'm here in Olympia, Washington, and um some of the concerns here uh for a lot of folks that nonprofits that I've encountered serve are um cybersecurity for nonprofits. So I do have this goal of being able to serve my local community with providing insight guidance tools at low or no cost to the nonprofits in my community, right? So that they can uh there's so many nonprofits that, you know, they take down people's names that need assistance on a piece of paper and then they throw it into a Google Doc and then they share it out later on to some other organization and print it out lists of names of folks and and orgs that can help. Um, it's they're doing good work, right? For the vast majority of times. If you keep up with, you know, nonprofits, there's there's challenges all over the place. But um this is a challenge for massive corporations that have large pockets of resources. It's certainly a challenge for some organization that's trying to pay somebody a full-time wage, maybe a couple people, on $250,000 worth of grants a year. Right. Right. Right, exactly. It is, it is. Um I don't want to call out any particular ones, but that's my goal is to be able to be in a position to do that.
SPEAKER_02I think that's awesome because I I know um we support several uh nonprofits around here, and and I'm the um Ung Sung hero. And I just never thought about the cybersecurity stuff that I always do as well. Uh or even the IT stuff uh that I do um as well as as being a a good service for them because they definitely need it. Um most of the time they don't understand the problems we're even getting into.
SPEAKER_00So well, here's the next conversation for us, Gary. Figure out uh an easy packageable tool set that we can get into the hands of the nonprofits we need.
SPEAKER_02I actually know another another guy who um um uh James Leach from Fortrium. Um does something very similar, uh, but he does it in a very organized way for the for the less fortunate, less fortunate, not just nonprofits, but for the less fortunate as well. So I think uh maybe we can several of us can get our heads together and maybe we can come up with some good charity around um you know helping cybersecurity for nonprofits or less fortunate as well. Maybe I'll ping him up.
SPEAKER_00There's a lot of education out there. Information's easy to get, right? Oh, it is that's easy to get. But implementing tool sets, that's tar hard. Implementing and finding the right tool that's gonna help easily, that's difficult. And again, outside of the purview of that poor, you know, that person who's stuck with uh a challenging opportunity to deliver services to their community. And that's the focus. So they're putting all their time, attention, and effort and energy into that.
SPEAKER_02Well, I thoroughly enjoyed our conversation, and I truly appreciate you attending um an episode uh on an episode of Behind the Shield. I I really do appreciate it. And um that's all we have for today. Um I may not always be the one on Behind the Shield, uh, but there will be somebody from Infusion Points behind the shield in these types of conversations. Thank you very much for your time. Appreciate it. Thanks, Gary. Thanks.
SPEAKER_01Yep, thank you.