
That CMMC Show · 2026-02-17 · 23 min
Key moments - from our scoring
Substance score
56 / 100
Five dimensions, 20 points each
Michael McLaughlin, co-lead of the Cybersecurity and Data Privacy Practice Group at Buchanan, Yersall & Rooney and former senior counterintelligence advisor for U.S. Cyber Command, discusses how cybersecurity compliance intersects with legal and national security obligations for defense contractors. Drawing from his book Battlefield Cyber and 15 years of Navy counterintelligence work, McLaughlin explains why CMMC (Cybersecurity Maturity Model Certification) represents a critical baseline - not a panacea - for protecting the defense industrial base. He addresses the false equivalence between compliance and security, highlighting how multi-factor authentication alone blocks ~90% of credential-based attacks, while also exposing emerging threats like North Korean IT workers using deepfakes to infiltrate Fortune 500 companies. The episode tackles practical implementation challenges including the C3PAO certification bottleneck (only ~100 assessors for 300,000 DIB companies by 2028), MSP vetting gaps, and contract protest risks when organizations self-attest false CMMC scores. McLaughlin emphasizes that defense contractors should view cybersecurity as a mission imperative tied to warfighter capability, not merely regulatory obligation.
Approximately 90% of attacks stem from simple, stolen, or leaked credentials. Multi-factor authentication can eliminate this entire threat vector, making it one of the highest-impact controls available.
Approximately 100 C3PAOs have been certified, but roughly 300,000 DIB companies must achieve CMMC certification by 2028, creating a significant bottleneck that McLaughlin notes will be "pretty tough, if not impossible" to resolve on schedule.
DPRK actors create fake LinkedIn accounts and doctor resumes, use deepfakes or accomplices for video interviews with fake IDs, gain super-user access, and disable EDR tools - a threat largely outside CMMC's current scope that requires HR vetting integration.
Yes. If a competitor discovers non-compliance indicators (such as DNS records pointing to non-FedRAM clouds when email should be in scope), they can file a GAO protest, potentially invalidating the contract award even if the competitor self-attested a perfect CMMC Level 2 score.
Because without a standardized baseline, organizations default to inaction or inadequate measures (like "locking servers in the attic"). Compliance frameworks force systematic adoption of controls - multi-factor authentication, network segmentation, encryption - that substantively reduce attack surface and risk.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode surfaces a handful of genuinely non-obvious operational points - DPRK IT worker infiltration through outsourced HR, the DNS-record protest angle, and the C3PAO-to-DIB-company ratio problem - but roughly half the runtime is spent on broad cyber-warfare framing and book promotion that delivers little actionable per-minute value for a B2B operator.
how many CISOs, how many executives are actually involved in the process of vetting that HR company from a security perspective, thinking to themselves, are we going to be giving access to North Koreans by using this HR company?
The easiest way to find out is to look up their DNS records and see if they're still pointed to non-FedRam clouds.
The framing of CMMC as a rising-tide baseline rather than a panacea is a useful reframe, and the protest-via-DNS-lookup angle is fresh, but most of the geopolitical cyber-warfare content and 'compliance is security' argument are well-worn talking points in the CMMC/DIB community.
it's more like death by a thousand cuts than it is a Pearl Harbor or a 9-11 event
Compliance is absolutely security because you're not complying with a specific framework. You are inherently going to be insecure.
McLaughlin is a genuine practitioner - 15 years Navy counterintelligence including six as senior CI advisor to US Cyber Command, now a cybersecurity attorney and published author - not a career podcast guest; his depth shows in operational specifics that only come from direct experience.
I did about 15 years in the Navy as a counterintelligence officer, about six of which I was senior counterintelligence advisor for U.S. Cyber Command
I'm the co-lead of the Cybersecurity and Data Privacy Practice Group at the law firm of Buchanan, Yersall & Rooney
There are real specific data points - approximately 100 C3PAOs vs. 300,000 DIB companies by 2028, negative 203 SPRS scores winning contracts, a 20-slide PowerPoint submitted as an SSP - but key figures are hedged ('I could be wrong about that number') and there are no dollar amounts, named breach cases, or sourced statistics, which limits the evidential weight.
there are only, I think about a hundred, and I could be wrong about that number, but about a hundred C3 PAOs that have actually been certified for somewhere in that ballpark, but for 300,000 dib companies that need certified by 2028
somebody delivered a 20 slide PowerPoint deck and said, this is my SSP to an assessor
The host occasionally adds substantive color (SPRS negative 203 anecdote, server-in-the-attic story) and asks a reasonably structured question about organizational risk, but there is no meaningful pushback on any claim, the 90% credentials statistic goes completely unchallenged, and the closing prompt degrades into asking about favorite food and restaurants.
what organizational risks should they be aware of when it comes to cmmc or better yet maybe legacy dfar 7012 and false claims acts
Any bits of wisdom, your favorite food, best restaurants, whatever your closing remark wants to be, the floor is yours, my friend.
Computed from the transcript - who did the talking, and the words that came up most.
Sit down with Daniel Akridge, CMMC CCP, Summit 7, while he talks with Michael McLaughlin, Shareholder | Co-Lead, Cybersecurity and Data Privacy | Cyber Policy Advisor | Co-Author, Battlefield Cyber: How China and Russia are Undermining our Democracy and National Security In episode 17 of That CMMC Show Daniel & Michael discuss organizational risks with CMMC, DFARS 7012, & FCA, Michael's book Battlefield Cyber, and more!
Transcribed and scored by The B2B Podcast Index.
Hello, everybody, and welcome back to That CMMC Show. Today, we have a longtime friend, Michael McLaughlin, legal lawyer extraordinaire when it comes to cybersecurity and compliance. He's got so many fun stories to share and just an incredible life experience. Just got promoted.
Congratulations, by the way, on that. But I'm not going to steal all your thunder. I'm going to go ahead and cue it over to you. So, Michael, tell the crew a little bit about yourself.
I appreciate that. So my name is Mike McLaughlin. I'm the co-lead of the Cybersecurity and Data Privacy Practice Group at the law firm of Buchanan, Yersall & Rooney. And as Daniel just said, I was recently promoted to shareholder, which I'm excited about.
I assist clients in a whole array of things dealing with cybersecurity, data privacy, of course, artificial intelligence, and government contracting. And so my foray into government contracting started actually many, many years ago. I did about 15 years in the Navy as a counterintelligence officer, about six of which I was senior counterintelligence advisor for U.S.
Cyber Command and worked really, really closely with a lot of government contractors, as well as federal agencies in dealing with threats from China, from Russia, and North Korea, Iran, and then non-state actors, ransomware groups, and others. So I really cut my teeth on the cybersecurity side, working for the government, and now as his clients doing the same thing. That's awesome. And what's so interesting about it is that you know so much, you actually wrote a book that I read.
I don't read a ton of books, but I read Battlefield Cyber that you wrote, and it is a modern day wake up call for people not taking cybersecurity seriously. Like the example you gave in there about somebody 10 layers deep in the supply chain, compromising one core component, and then a missile potentially unable to fire. Right. I mean, you start going through these narratives here.
So if you have a few moments, maybe share a little bit about your book and then tell us some, maybe some more modern stories about what you're seeing kind of out there in the space. Yeah, absolutely. And so the book itself was very much a labor of love. When I was getting out of active duty, I was seeing very clearly that there were a lot of people in the private sector that didn't view cybersecurity, cyber operations in the same way as we did in the military.
In the military, we viewed it as a standalone domain in the same way as air, land, and sea are a domain of warfare. In the private sector, it was really something that had been relegated just to the IT personnel, as opposed to being a primary focus of business concern and really the way it should be. And it was not being invested improperly. To me, that was really a direct result of executives and people just generally not understanding the overall battle space and really getting so focused on the trees that they miss the forest around them and really miss the geopolitical drivers of what are cyber operations?
What is cybersecurity? How is it something that is occurring in China, occurring in Russia, and is directly impacting our national security, even in companies or universities that may not realize it? And so the book itself was drawing on my experience within Cyber Command, as well as my experience as a counterintelligence officer and taking that mindset, working really closely with my co-author, Bill Holstein, who's a fantastic journalist and has been covering Chinese and the rise of China for decades.
We combined to put forth this book that really discussed these are the threats in a way that we thought was going to be palatable for executives and for everyday Americans. And we started with the idea that the definition of cyber warfare was just wholly inadequate. And as an attorney, I love my words. I love my definitions.
And I fall back on semantics. But it's important. And if we look at the traditional definitions of cyber warfare, they generally deal with nation states attacking other nation states and their government assets or potentially their critical infrastructure. But the way in which our adversaries wage cyber warfare, it's not in the same way as we wage kinetic warfare.
And if we're waiting for that, if we're waiting for the equivalent of a missile strike from Russia to occur in cyberspace or a missile strike from China to take out our entire electric grid, we're going to be waiting for a very long time. That's simply not how they do it. Our adversaries are using cyber operations in cyberspace more broadly to undermine our political system, to steal intellectual property, to advance their capabilities, to make us question the things that we are doing or to divide us.
That's how they wage cyber warfare. And it's more like death by a thousand cuts than it is a Pearl Harbor or a 9-11 event. And so the point behind the book was to really detail what is cyber warfare? What is the full spectrum of it?
Well, it's everything from, yes, what you would expect to be a traditional kinetic strike or a lights out event in downtown Manhattan. But it's also things like intellectual property theft and stealing from the defense innovation base or the defense industrial base. It's things like ransomware, and it's leveraging criminal groups as proxies to destabilize us. It's things like corporate espionage and stealing intellectual property through insiders or malicious insiders.
It's utilizing North Korean IT workers and having them fake being just regular IT workers from the U.S. and infiltrating Fortune 500 companies. All of these different aspects, while we look at them as individual, maybe criminal activity or either criminal activity or otherwise, our adversaries look at this as just another cog in their machine or along that spectrum of warfare And our executives our private sector really needs to prepare itself because U Cybercom is not going to be swooping in with a SWAT team Neither is the FBI And if again, if you're waiting for that to happen, you're going to be waiting for a very long time.
Companies, universities, they need to be preparing themselves for a full onslaught by nation state adversaries. Whew, man, that is a pill to swallow. But you're not wrong. We see it in our base all the time.
People will come to us after the fact, right, of like, hey, you know, like we had kind of cybersecurity, but then North Korea or China or Iran deployed a ransomware. And now they took, you know, information that the defense industrial base really wants to keep, you know, private, we'll say, controlled and classified information. They're like, what do we do? You know, which is why you see CMMC becoming such a big deal as one of the U.
S.'s like firmest stance on cybersecurity regulations is like, hey, like, no, you really, really have to do this because we really need to protect that data. So on your side, I'm curious, Michael, have you seen any like more practical, like frontline examples that you've seen in the work you've done over the years? I've seen innumerable.
And ultimately, I think I just want to clear something up because a lot of people come to me and when we talk about CMMC, a lot of people say, well, it's not going to stop China. I mean, if China wants to get in your network, they're going to get in your network. They are a nation state with unlimited resources. They've got incredible cyber actors, really, really great folks who are going to be operating, developing software, developing exploits.
And while all that's true, if you're targeted by China or really any nation state, there is very little you can do because you are limited in your resources as a company or as an organization. You're going against a nation state that is designed to do this. That's not what CMMC is for. CMMC is more of a rising tide lifts all ships mentality where we can't just do nothing.
And so we have to have a baseline. And when people argue, it's like, well, compliance is not security. I would disagree. Compliance is absolutely security because you're not complying with a specific framework.
You are inherently going to be insecure. And that's essentially what CMMC is. So I don't want to throw the baby out with the bathwater. It's not a panacea of security, but it's certainly better than doing nothing.
thing. And at this point, we're in this space where CMMC is going to increase security broadly. And that's something that defense industrial-based companies really need to embrace and really need to get on board with because their industry is one that supports national security. You're not supporting a library down the street.
You're developing innovations to advance our warfighting capabilities. We should want to secure those against our adversaries. So off my soapbox. um hey some of the things i add a little bit of color to that here's another reason we have people come into our door that say we were protecting our security i was like oh fantastic i was like how are you doing it's like we're locking our server in the attic that's a real story and it's like to your point like compliance doesn't always equal security but you have to have a standard playbook that that people can adopt or else people end up doing nothing and and it becomes very problematic so i also have a soapbox with that jacob horn has the biggest soapbox of anyone I know, but back to you and kind of some stories from the front there.
Yeah. And so some of the things that we're seeing are non-traditional, right? And so as we get through, I mean, CMMC in reality, it goes all the way back to what EO 13566, this is what CUI is. And then the implementation of NIST 800-171, the DFARS-7012 clause, the GAO report that said, this is wholly insufficient because everybody's lying about their attestation.
And then finally, we have CMMC as a result, kind of a knee-jerk reaction to failure on the part of the Dib to actually secure these cover defense networks. Well, what we're starting to see is though, as people implement these things and they go through all of the various controls and multi-factor authentication is the easiest one we can point to because credentials are by and large the easiest way for bad actors or threat actors, as we call them, for threat actors to get into an environment.
And it's simply, you're reusing passwords. It gets hit. You get hit on another breach, totally unrelated. And that email address and that password are then connected and used to access another network.
And we see it time and time again. And all you have to do if you have multi-factor authentication in place, that takes out that entire threat stream. Now that's not going to prevent like, you know, spear phishing. It's not going to prevent somebody doing a man in the middle of attack or SIM swapping or anything else.
But at the very least, you're stopping that front end. And I mean, I'm going to throw a percentage out there. 90% of attacks, I think, truly do come from simple credentials and stolen credentials or leaked credentials. So if you can take away that vector, that's huge in just securing our defense supply chain.
And so we see that all the time. But now we're also seeing other things come into play and things that may not actually be covered by CMMC, quite frankly, and things that we need to be taking, taking a look at? DPRK, right? So the IT workers that we are starting to see that are masquerading as US persons and trying to apply for jobs with doctor resumes, fake LinkedIn accounts, they get on video with deep fakes or they have somebody else get on video on their behalf with a fake ID.
They gain access to these systems as super users. They'll get sysadmin credentials And it's not until you see that they've turned off the EDR on their devices or their devices are pinging from an IP address somewhere they shouldn be that you actually starting to pay attention to this Well it shouldn get to the point that you seeing an IP address pinged from the wrong place or you get notification that your EDR has been turned off on this new employee device HR should be involved in the process.
But a lot of cases, HR is a third party that's outsourced to help with recruiting. How many CISOs, how many executives are actually involved in the process of vetting that HR company from a security perspective, thinking to themselves, are we going to be giving access to North Koreans by using this HR company? None of that's really covered by CMMC. And so CMMC, when we say it's a baseline, it's absolutely a baseline for compliance for a specific purpose.
We really need to be looking at cybersecurity from a holistic perspective. And that's not even getting into like the harvest now, decrypt later issues that we get to when we talk about quantum or the threats from AI that we're starting to see come on more and more by threat actors, just simple things that we need to take a more holistic look at cybersecurity. But CMMC is absolutely that baseline. Man.
All right. It's crazy to see CMMC is now old in the sense of protecting its modern attacks, right? In a lot of ways. It's still something good to build off of, but a lot of people are like, oh, it's not enough.
It's like, you're right. It's not enough. You have to do more. And it expands outside of just IT environments, to your point, right?
HR is a big piece of it, right? Operational security, manufacturing and OT cyber, like that's a place where IT doesn't really have a lot of domain, right? And so you start looking at the critical infrastructure and everything and it becomes problematic. But the thing to get someone to do something, I found out over all of these years, DFAR-7012, it didn't do it, right?
No one actually implemented the controls of NIST-800-171 because no one else did it and the DOD didn't really care in the sense of they didn't check the math, right? Right. SPRS scores. I've known organizations that have won contracts with negative 203, which is the lowest you can go.
And if the DoD really cared, they would have kind of stepped this up until CMMC was live. But now it is. November 10th of last year, we've started the phase rollout. But question over to you on a couple of fronts, Michael, is from a if people aren't doing the right thing, but being forced to do something, which is really what a lot of people are in.
what organizational risks should they be aware of when it comes to cmmc or better yet maybe legacy dfar 7012 and false claims acts like any kind of insight on that side yeah i mean that that's a very loaded question so we'll try to unpack that piece by piece um first and foremost when you say the things that people should be aware of with cmmc it's i mean for a government contractor that's a law of the land now if you're if you've operated covered defense system if you're handling CUI, you have to be in compliance.
Understand what the CMMC level that you are at. And it's either going to be level one, you're just dealing with contract information, or it's level two, and you're actually dealing with CUI. If you're in level three, you know you're in level three, because the type of data that you're handling is so sensitive that the government's coming in saying, we are going to go into do the attestation. We're not even going to leave it to a C3PAO.
But it's the point that we can't, and I think companies, especially dip companies, are coming to this realization that burying your head in the sand is just not a solution. So now we get to the challenge of a bottleneck, right? Because there are only, I think about a hundred, and I could be wrong about that number, but about a hundred C3 PAOs that have actually been certified for somewhere in that ballpark, but for 300,000 dib companies that need certified by 2028, the numbers there just don't add up.
Like we are going to have a significant problem. So those companies that have been waiting and waiting to get in compliance and to get certified, they're going to run into a real issue. And so then it's going to be, well, how do we ensure that we're, and we are still achieving the same innovation. We're still attracting the same good small businesses that should be involved in the Dib and make sure that they're also compliant from cybersecurity perspective.
Ultimately, the answer there is going to be managed service providers because companies themselves are not going to be able to do it. And we need to have managed service providers that are already certified, that are able to just move the ball forward. And basically you get a check in the box because you're using a certified managed service provider versus one that's not. And the challenge you run into there, and I'm going to get to my soapbox.
Yeah. And the challenge you run into there is, Daniel, if you and I wanted to go out and start an MSP today, we could, we could go hang out our shingle and we could be Mike and Daniel's MSP. And that would be that. And we could go offer services and no one would be able to tell the difference between you and me or a very high end MSP that's extremely expensive, but very efficient, very good at what they do because there's no certification process, right?
There's no underwriter's laboratory that's putting their stamp of approval on an MSP as to whether or not they are certified. There's no American Bar Association saying you are a certified MSP. So really, you know, Billy the IT guy from down the street is just as good as Microsoft in the eyes of any sort of certifying authority because it just doesn't exist. So that's a problem.
Being able to vet MSPs that are going to be able to do this on the one hand is important, but also those that are going to be able to get you CMMC certified because if you are just starting right now, you are way behind the eight ball. And realistically, in order to be in compliance by 2028 with the number of C3 PAOs we have right now is going to be pretty tough, if not impossible. So that's kind of the tricky part. So the DOD and 32 CFR said, hey we going to revise this a little bit We think 118 companies have to be certified for level two It like okay let take that number back 100 so C3 PAOs So big bottleneck problem or so we thought So when this started happening and this is the interesting part, it's a bottleneck, but in a place that people don't assume.
And it's to your second point, C3 PAOs are continuing to suspend assessments because of they couldn't provide the SSP. Well, that's kind of step one of the actual assessment. We're seeing the bottleneck actually happened with the managed service providers being able to onboard people in a compliance state before their certification. And so what's crazy about that is like, so there's that bottleneck, but then ultimately there's also going to be the C2PO's that they have to schedule, right?
Because those are schedules months out in a lot of cases. Sometimes you'll get like a, you know, out of the blue moon, you'll get like a random assessment, they become available if you're ready. But like those are being scheduled multi-months out. But a lot of people think, oh, I can just go, this is a real story.
Somebody delivered a 20 slide PowerPoint deck and said, this is my SSP to an assessor. Right. So like the, and then they're having to be said, no, that's actually not. And you need to actually go find help.
Oh, well helps four months away, three months away from me getting to help. And then I have to come back in line to get certified. So again, to your point, there's multiple bottlenecks here. And I think a lot of people are overlooking the complexity of CMMC audits versus like ISO or other frameworks in general.
Well, in all the while, you've got the business and the operational side of the house trying to live through the valley of death, especially for small businesses that are just starting to do business with the federal government. If you can survive that valley of death, good on you. But now you're having to fight a battle on multiple fronts where you're also trying to get in compliance with CMMC, address this bottleneck. And then let's say for the sake of argument, you win the contract, but you were unsuccessful in the CMMC certification, now your contract is subject to a protest.
Because if I'm competing against you, if I'm representing a company that competed against you and I didn't get the contract and I get wind that you're not CMMC certified, the first thing I'm doing is going to the GAO and filing a protest immediately. It's funny. I was talking with somebody the other day. They're like, how would you actually do that?
I kind of sat back and I'm like, how would I find out? Oh, the easiest way to find out is to look up their DNS records and see if they're still pointed to non-FedRam clouds. Right. And then you have an idea of, okay, they would potentially be in a noncompliant environment because email is typically in scope.
And then I can go protest. And it's like it only takes a little bit of information that's publicly available to potentially protest for you self-attesting to a perfect 110 CMMC L2 score. Only in reality is like you're not actually meeting the full requirements, right? Becomes very, very problematic.
Well, hey, Michael, this has been fantastic. I always love to leave the guest with one last thing. That's closing remarks. Any bits of wisdom, your favorite food, best restaurants, whatever your closing remark wants to be, the floor is yours, my friend.
So I'm going to try to be a little bit philosophical here, my closing remarks. So my favorite color is red and favorite restaurant. I love ethnic food. There is a little place on 9th Street in D.
C. that has the best Ethiopian restaurant right by the convention center. Fantastic. Called Family Ethiopian, in case you're wondering.
Anyway, what I'm going to leave you guys with is when we are talking about CMMC, and this is the part that really, it always kind of chafes me a little bit when we have government contractors that are complaining about CMMC. And I understand that challenge. What you have to understand, though, is when you get into the defense industrial base, you're essentially in a walled garden. You have unlimited opportunity to do business with, essentially, do business with an organization with what will soon be a $1.
5 trillion budget. That is an incredible opportunity for any contractor. That aside, when you're dealing with the federal government, particularly with the Department of War, your business is national security. You should be focusing on delivering capabilities, delivering tools to warfighters so that they can have an edge against our adversaries, or at the very least, so that that tool, that capability, that equipment functions as it's supposed to function when they're in a firefight.
And if that's not the mindset of defense contractors, you should not be in the defense industrial base. CMMC plays a critical role in that process in ensuring that we are delivering capabilities that have the lethality that we want that are defensible to our warfighters. That's the mindset we need to have. Man, what a closing remark.
And you're not wrong. How many defense contractors have integrity and mission and all of that in their in their mantra, right? In their in their mission statement. It's like, hey, this applies to all aspects, right?
This is how you run your organization from a cyber perspective all the way to the materials and equipment that you're delivering to the warfighter, right? And we need to make sure that that stream continues from the back office all the way through the front lines, right? And so, man, what incredible closing remarks, Michael. Thank you so much for your time.
Hopefully we'll have you back here again to maybe review your second book, Battlefield Cyber 2, The Reckoning, right? I'm just throwing out some names for you. You don't have to take any of them, but I really do appreciate your time. I'll know where to send the royalty checks, though.
Don't worry, Daniel. There you go. That's what I'm talking. I really appreciate you having me.
Absolutely. Thanks for watching, everybody, and stay tuned for the next one.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.