Jimmy Huber: And welcome to another episode of the Info Tech Podcast. I'm your host, Jimmy Huber. For our video users, my virtual background is broken today. So this is where I actually am. for those online that are just audio only, I'm sorry, but you won't know what I just mentioned. my guest today is a cyber expert. His company is Hire a Cyber Pro. he's a veteran, and this is gonna be a really interesting episode for those whether you're in security or not. I'm really excited about today and I want to welcome Brent Galeo. Or is it Gallo? Brent Gallo: Hey, nice nice to see you, Jimmy. It's gallo, like the wine or salami. Or I get gallo when I'm in Texas, you know? So it's okay it's all good. Jimmy Huber: excellent. Okay. I I always throw it out there and then I either fix it or I don't in post. And this one I probably won't, because you took it like a champ. So no, I'm I'm really excited for you Brent Gallo: It's all good. You're cool. Jimmy Huber: to be here today. Sometimes I do it my own intro pretty much every time for the guest. but I've sure I left a bunch of stuff out. So take some time and tell us who is Brent and a little bit about your background and your story. Brent Gallo: Thanks for having me today, Jimmy. So my background, I've been in cyber since 2014. Like I said, I got involved in the Air Force and that's really where it all started. I had the opportunity to work with the National Security Agency doing foreign intel collection. So very offensive heavy. And when I got out in 2020, I worked for the Department of Energy. So I'm in the Oak Ridge and Knoxville, Tennessee area now. And I started higher cyber pro as a side hustle in 2021 and I've taken it to full time since twenty Jimmy Huber: Nice. Brent Gallo: twenty five. So it's been a lot of learning, a lot of growth, and a lot of success this year, and hoping for more success in the future. Jimmy Huber: Yeah, no, that's great. So just curious, what made you go from, you know, the technical guy that's working for companies and and then start your own thing? Because most people, I think, in your position are just fine at a desk or in a cubicle, banging out projects, probably making a good living, lots of benefits, whatnot. You can work remotely, flexible, you know, all those things for the thousands of other security people in that industry. But you all were chuck checked all those boxes, but then said, Hey, I want to start my own thing. What was a linchpin or describe how that process worked? Brent Gallo: So there's there's a lot of factors. So I have a family, so flexibility is is key for me. I got young kids. my wife, she comes from a background of social work and therapy. So she's seen, you know, people, you know, unfortunately, right, life comes to an end. And she wants to live now. And so I I agree with that mindset, and we're living now. So we like to travel and things like that, and to be able to, Jimmy Huber: Nice. Yeah. Brent Gallo: you know, have that flexibility, afford to to travel, you know, bring our whole family along. for example, this summer we went to Crater Lake in the Redwoods and Lawson Volcanic out in southern Oregon and California there. Jimmy Huber: nice. Brent Gallo: Yeah, it was it was great, great trip. So we we wanna live now and you know work hard, play hard kinda. So yeah. Jimmy Huber: Yeah. I love that. Yeah. I mean it in my own journey at InfoTech, it's it's gotten more and more flexible as I've trained more people and hired more people. It it's all it's not Brent Gallo: Mm. Jimmy Huber: always perfect, but yeah, I got time to, you know, record podcast episodes and like that was not a thing, you know, Brent Gallo: Yeah. Jimmy Huber: a couple of years ago. So no, I I love that. And yeah, I just in the you know, short time I've gotten to know you, you seem to be a really down to earth guy that really wants to help others and and serve people in in capacity of security. And I think that comes across, which is just huge these days in in a world of fake AI bots everywhere. people want to know who they're working with. So I think I think you'll definitely do well as it sounds like you already have started. So we talked a little bit about your area where you live and there's some really cool things about the Oak Ridge and the Tennessee area there. Go into a little bit of that because you mentioned that on one of our first calls and it it kind of blew me away. No pun intended. Brent Gallo: yeah, so not very many people know about the Oak Ridge or Knoxville area, but in Oak Ridge is actually where the Manhattan Project started, you know, to develop our nuclear weapons during World War II. Oak Ridge area is called the Secret City, actually. And when I was working for the Department of Energy at the Y-12 National Security Complex, I learned a ton about the history there and the continued mission that they have. even so much interesting things like the a lot of the older buildings were made of brick and masonry, and actually it was a Of women who did those jobs at the time. And I learned you Jimmy Huber: really? Brent Gallo: could yeah, find the imperfections in the sections, and then I guess a foreman would come in and help like fix it up. So there's like you know, little tidbits like that. That's kind of cool. but you know, continuing, you know, especially with President Trump and his initiatives on nuclear energy. I got a list of companies here. nano nuclear energy, they're developing micro reactors, BWXT enrichment, you know. We're building new centrifuges, assemblies. there's tons of stuff coming through here. other micro reactor companies, Triso and X Energy, building commercial facilities for advanced small modular nuclear reactors, the Hermes nuclear reactor project. So there's there's tons Jimmy Huber: Wow. Brent Gallo: of energy and enrichment types of things coming to this area. So it's it's exciting time for for energy. Jimmy Huber: Yeah. Yeah, it it seems to be somewhat of a controversial topic when I think nuclear is by far the the best source of energy. I mean, yeah, we want to get off of coal and gas and you know, there's all the green energy movements, but f aside from a couple of bad instances that I think they've pretty much fixed around nuclear, I'm no expert, but it seems to be that's the way to go going forward. So that's really exciting to see that's right in your backyard and you can kind of see some of those things, you know, come to fruition. all right. So we're here to talk about security. Obviously, hire a cyber pro is is your bread and butter. So explain, I guess, to our audience what exactly is your niche or specialty or what's your ideal client if people want to know more about you and kind of what your sp you know, your wheelhouse. Brent Gallo: Good great question, Jimmy. So definitely my wheelhouse is CMMC right now. I'm a lead assessor. I've done over 25 assessments and mock assessments, and then I'm also helping customers, including defense industrial-based customers and and MSPs with their customers through implementing CMMC, getting ready for NIST 800-171, R2, and you know getting people ready for their assessment. So very heavy into NIST right now. Lot is happening, especially with the CMMC pause right now. The Department of War, Office of Information Security is, you know, taking a look at the assessment portion of the process. And but there's still requirements there, so don't forget that. We still gotta protect CUI, still got your contract requirements. So there's been a lot of of craze in that space right now. Jimmy Huber: Yeah, so let's back up just a little bit in case you're not in the tech world deep into cyber. CMMC is a cybersecurity maturity model certification, right? So this is a a directive, a federal law, I believe, directive for larger businesses that you know there's a defense framework that was designed to what I guess protect sensitive unclassified info. Brent Gallo: Yep. Yep. Protect our supply chain is the biggest thing. Yep. Jimmy Huber: And so yeah, there are all these rules in place. Infotech actually has a client that we discovered, they didn't even know they were required to have this. Fortunately, my Brent Gallo: no. Jimmy Huber: my ops director is is a veteran as well, so he was all into this stuff. And then yeah, recently there came out with a pause, which I thought, we don't have to do anything anymore, which is not exactly true, right? So what what is this pause and how is it different now than it was, you know, before that came out? Brent Gallo: So so the pause is only a pause on the assessment requirement. So as companies are getting ready and the Department of Defense is putting out you know contracts and bids, there's has been an increase in requirements to be CMMC level two certified. And that certification comes from a a third-party assessment organization, that's called a C3PO, and they bring in an assessment team, review your system security plan, configuration, setup, and everything to make sure you meet all a hundred. Jimmy Huber: Hundred and ten requirements? Holy smoke. Brent Gallo: Yes, and 320 assessment objectives. So it is it is very detailed. Jimmy Huber: Wow. Brent Gallo: Assessments typically take in my experience two to three days, but they can take longer depending on the complexity of the the customer. So it's Jimmy Huber: Okay. Brent Gallo: it's a it is a process. Jimmy Huber: Yeah. Well it makes sense now because our client is a a trucking logistics company, right? So that's Brent Gallo: Mm-hmm. Jimmy Huber: supply chain for sure, which is why they would fall under this this bracket. So Brent Gallo: Yeah. Jimmy Huber: are you working then with internal IT teams? Are you working directly with C suite? What how do you fit in for a company that maybe is looking to, I guess you get certified and then it renews, I assume? You're doing project work to make sure one of those those objectives is hit, or how do you fit in? Brent Gallo: So I typically come into small IT teams because a lot of these companies don't have you know the the background or expertise to meet these compliance requirements. So I've worked with you know one man, two, three man shops and really bring the compliance portion to the table and then I work with them to get everything configured. I also work with companies who have no IT team at all. And I bring in engineers to set up their Microsoft GCC high environments, for example, and Jimmy Huber: Okay. Brent Gallo: also work Work together with MSPs, right? So the MSP is running the technical side and I'll run the compliance side to get the client ready. Jimmy Huber: Yeah, that's a great one two punch because obviously infotech's an MSP, so we're kind of jacks of all trades, but we're Brent Gallo: Mm-hmm. Jimmy Huber: we have the client trust, right? So we'll find something like this like, hey, you guys need to certify and get a thing. In this case, they don't even know what it was, like they had no idea. And so we get to come in and look like the hero by bringing in Brent, right? And so, Brent Gallo: Exactly. Jimmy Huber: what's that look like? I mean, break it down for us. Is this like a six week, six month? I mean, is this a four figure project, five plus figure? I mean, what's it look like? I guess it it probably depends on where they're at, but Brent Gallo: Yeah. It it de yeah depends on the customer and where they're at, but a lot of folks are are really just starting from the beginning. So there is a lot of work to do. typically a six-month project or longer, you know, it depends on how fast the customer needs to move. this is not something that you can get done in 60 days, where you know you submit for a contract, right? You have that 60 day window where you need to be, you know, certified by the time that contract is awarded. That's definitely not happening. so So if anyone says they get you certified in 60 days, I wish you good luck. so it is a process. Yeah, maybe a red flag. Yeah, yeah. Jimmy Huber: Maybe a red flag if somebody leads with that in a yeah. Brent Gallo: So definitely if it's something you need to pursue, you want to separate yourself from other companies, you know, strategic advantage, things like that. It does take time to implement and do right, and there's there's no shortcuts around it. So it's yeah, it's it's work. Jimmy Huber: Yeah. Yeah, no, I I believe it. I mean, we've seen I mean anything with the federal government's gonna be a ton of of check boxes, right? but I think the goal around it is something that, you know, these companies should be doing a lot of this already, right? It's not like they should be moving Brent Gallo: Yes. Jimmy Huber: heavy and earth to make changes. You're just certifying what should already be in place. And if it's not, coming out of this, I would think they would be in a way better position regardless of whether they have to do it or not, right? Brent Gallo: Definitely, yeah. So these requirements have been in place since 2017. And the whole reason we have CMMC is you know bringing in the checkers, right? Because a very small percentage of companies were actually meeting all all 110 requirements. And we've had several you know, intelligence leaks, right? you look at or sorry, not intelligence leaks, but you know, supply chain issues. look at China's, you know, J20 aircraft, right? It looks very similar to our you know F-22. Right, and the the J30. So, right, suspiciously, right? So Jimmy Huber: Yeah. Suspiciously similar. Brent Gallo: it's about you know tinying up our supply chain and you know making sure contractors actually do what they say they're you know supposed to do per contract. And Jimmy Huber: Yeah. Brent Gallo: it's a lot of the pain right now is really technical debt that should have been you know implemented over time. Jimmy Huber: Yeah. Brent Gallo: So you know it's it's a big number to implement right now. You know, some companies between you know the 50k, 150k for most products. probably, you know, plus the assessment cost. so it's it's a good chunk, right? Not nothing you know we can just slide under the table, but it's what has to happen, it's what needs to happen to to continue to keep our warfighters number one on the battlefield. Jimmy Huber: Yeah. No, I think it's a worthy cause and it should be across the board accepted. But if you're a smaller business on the lower end of that spectrum and you got to come up with a hundred and fifty large, that could be that that isn't a small thing, right? So how are businesses dealing with this? Is are there grants available? Is there financial assistance for the smaller companies? Or is this just, hey, we have these dates, this is just another cost of doing business, we factor it into our budget and you know it's like anything else. Brent Gallo: So right now it's just like any other expense. you can, you know, kind of put it into your contract, right? What you expect to get out of it in return to you know meet the requirement. But there have been some proposal about grants, some proposals about providing dedicated environments for folks to, you know, stand up and work in that are provided by the government instead of having to stand up your own environment, you know, for each business. So there are Jimmy Huber: Okay. Brent Gallo: proposals like that. But you know, that all does take you know time and money and and Congress, you know, to really move on that. And so it's it's a it's a mess. Yeah, yeah. If I can go wrong, Jimmy Huber: Yeah. What could go wrong? Brent Gallo: yeah. So it's not an easy problem to solve. And you know, we have a pause now. This isn't the first pause there, you know, that there's been in CMMC. So as demands change, right, the adversary, the threat changes, these pauses are you know expected in my in my view, but we'll we'll come out with whatever they decide and hopefully the best thing is to you know keep protecting our our classified or sorry our our controlled and classified information well. Jimmy Huber: Yeah. Yeah, it makes sense. So would you say these pauses are moving the goalpost, or is it just, you know, giving people more time or both? Because obviously that they aren't random, right? There's some Brent Gallo: Mm-hmm. Jimmy Huber: reasoning behind it. Brent Gallo: So I think it's a little bit of both. So we were expecting a surge of assessments come November, right? The end of the fiscal year, and when phase two is supposed to roll in. So this pause is a gift, in in my opinion, right? We've got 60 days to you know get our stuff together and see what happens next. I think that you know there could be some meaningful changes on the assessment side after the pause, but we'll we'll see what that looks like. I think also as an assessor myself. the C3POs and assessors, we are doing our job. We're not to blame for for the madness. We're just, you know, one cog in the machine. There's a lot of Jimmy Huber: Yeah. Brent Gallo: crap, you know, even before you get to the assessment. That's that's messy. But we'll we'll see what happens. So yeah. Jimmy Huber: Yeah. Yeah, you're just the messenger, but you're the face of it. So I could see where you could be the brunt of some frustration. Yeah. How how Brent Gallo: We are the face. Yeah. Yeah. Jimmy Huber: do you deal with that? Because I mean, you're you're not just coming in for a weekend. This is a multi month thing with, you know, you're the new guy, but the probably the the cog of all of this which I think some C suite people would probably see 150 grand to do what? We don't need any of this stuff. Who's this Brent guy? And like you could be put in some some sticky situations. So have have you seen that already, or how are you dealing with that? Brent Gallo: So there's definitely growing pains with some customers, more or less, right? some, you know, don't wanna spend the money, but you gotta see that the risk is huge, right? Like if you're not following this this protocol, especially if you've been supposed to be following it since 2017, there's what's called the False Claims Act. And that's basically the the f the DIPCAT can come in, the DOD, and they can do an assessment. And if you aren't even close to your you know 110 controls, like you've you know, testify that you have been for X number of years, you can get a significant fine and you know, kind of blacklisted, right? So you probably wouldn't Jimmy Huber: Well yeah. Brent Gallo: be doing business for a good while so and and have a fine. one company recently in the Huntsville area, I forget the name, but they had a a five hundred K fine against them. That's that's what they s that's what they settled on, right? So I'm sure I'm sure Jimmy Huber: my. my goodness. Brent Gallo: the number was higher. And so and they're Jimmy Huber: So they were fraudulently reporting things that weren't accurate, it sounds like. Yeah, well you're gonna get yeah, that that goes across the board. I think that's a bad idea, bad business practice, especially Brent Gallo: Exactly. Exactly. So Jimmy Huber: with the federal government. Brent Gallo: Yeah, so there's big risk there, right? there are some growing pains, right? And it's not that people, you know, want to do the wrong thing. It's just they're just not trained or educated in the space yet, right? Like what are the Jimmy Huber: Sure. Yeah. Brent Gallo: requirements, right? I told you there's 110, 320 objectives. Like there's Jimmy Huber: Sure. Brent Gallo: there's a lot to that. And so it's really just education, explaining you know, why you need the requirement, how it increases your security. And like you said before, all these companies they are better off and more secure because we've implemented implemented these controls to protect our supply chain. Jimmy Huber: Yeah. I completely agree. And yeah, I mean, it's unfortunate that companies have to rely on, you know, the stick versus the carrot. but you see that in other things too. you mentioned NIST. I mean, InfoTech comes across PCI and HIPAA a lot. not to pick on the medical industry, but no one cares about HIPAA because it's not really enforced, right? And it's things that should Brent Gallo: Mm-hmm. Jimmy Huber: be happening, and our our customers are HIPAA compliant. But if there's no stick, it's like, well, you know, it's hard to build the value and understand the cost of staying compliant when, you know, if you haven't been burned. So what are I guess the implications? Obviously you can get a huge fine here, but I mean, is it enough so that you can kind of thread the needle between motivating people to understand the reasoning why and get on board versus just doing it 'cause they have to and it's always like an uphill battle. Brent Gallo: So the the carrot in this sense is also contract eligibility, right? So the phase two was also rolling in that CMMC level two requirement. So you you know you have to have that certification to even be able to bid on said contract. So that there is a carrot out there that will separate you from other contractors, but it is it is a step up to meet that requirement. Jimmy Huber: Sure, sure. Well, I would think that this job for you is gonna be a lot of education and the technical wherewithal, you know. So yeah, I could see those. I mean, and I assume you're not doing a bunch of them at a time. You probably have a a limit on how many you take on at the same time. What what do you see the runway for this being? I mean, there's a pause now, but is this just gonna be an ongoing thing that will always have companies that need to be compliant? Like is this kind of the future for higher cyber pro? As as your one thing, or do you see branching out tangentially into other things too? Brent Gallo: So definitely a a future here, as it's you know, definitely not going away. The requirements to handle control of classified information, those aren't going away for sure. Companies are gonna need to implement, regulations are gonna change. There's already NIST 800171 R3, that's been out for a little while, and Isaka, who's in charge of the training for assessors. They're already training to R3. there's been some complaints that R2 is outdated. Yes, it is a little outdated. So, you know, companies are preparing for ar revision two right now. There's gonna be a point where they need to prepare for revision three. And so that's, you know, another opportunity to mean the arcade cover. No, no, it's Jimmy Huber: Ongoing. Yeah. Which makes sense. I mean the bad guys aren't getting dumber. So you're you're always reacting and and trying to get ahead. Brent Gallo: Yeah, yeah, it's it's and it's getting more complex with AI and and current requirements are to recertify every three years through a C through pre O and you have to self-attest at least once a year. So there's Jimmy Huber: Okay. Brent Gallo: a whole you know continuous monitoring, whole security assessment protocol to maintaining your security program. So it's it's something that we can't just you know do our check boxes and put on the back burner. It's something that has to be, you know, maintained on a on a monthly basis. Jimmy Huber: Yeah. No, I think that's great. And you mentioned a couple of things there. So NIST and the the sanctioning body, I think that puts it on. Are those just kind of all the same conversation or how are those connected? Because we see other small businesses that want to be NIST certified or just, you know, gain something. I mean, there's what ISO twenty seven thousand one. I mean, there's all kinds of things that you can go after. but I would assume that these are more connected to C C than others. Brent Gallo: Yeah, so So NIST 800171 is the designated level of protection required for control and classified information. That's that's per per the government. but yeah, if you want to go for different industries, right? Like you said, you're medical folks, then you're gonna wanna be HIPAA compliant. there is a revision came out, I think it's twenty twenty four for HIPAA. So if you haven't updated in twenty years, there's a new revision there. take a look at it. you know, Jimmy Huber: Yep, sure. Sure. Brent Gallo: for PCI, right? Payment card industry, that If you get into the financial space, there's a folks require the SOC 2 certification very often. So it is Jimmy Huber: Yep. Sure. Brent Gallo: are also in universities. I've had a few university customers. They require GLBA requirements, the Graham Bleach and sorry, Graham Leach and Bliley Act. That's always a mouthful. So Jimmy Huber: Yeah, yeah. Brent Gallo: yeah, and these requirements, right, these have been identified and put together by national level organizations, global organizations. For ISO, right? And so they're they're good Jimmy Huber: Yeah, yeah. Brent Gallo: standards. may, you know, their language may be a little bit different, maybe a little bit more strict than others, but they all kind of well they all do have the same goal, right? To raise our security, make sure we don't have any blind spots, and to protect our data and financial information from from the bad guys. Jimmy Huber: Yeah, I couldn't agree more. And fortunately, the insurance companies I think are getting on board with this. It used to be Brent Gallo: Mm-hmm. Jimmy Huber: infotech or the MSP would come in as the bad Brent Gallo: Yeah. Jimmy Huber: guy and require it, but now it's like, my agent just said that too. And instead of three questions, it's now 40 and five pages. And what is all this stuff? Brent Gallo: Yes. Mm-hmm. Jimmy Huber: And you can connect the dots a lot easier for a a CFO or somebody who's got these questions and isn't technical, right? So it seems like the industries of the world are finally catching up to the point where like not only is security kind of a nice to have, but it's just a baseline, a cost of running business, right? Brent Gallo: Exactly. And yeah and Speaking of the insurance agency, that's really changed in the last couple of years, right? In Jimmy Huber: yeah. Brent Gallo: early 2020s, everybody's getting hit by ransomware and really getting wiped out. And therefore those insurance companies are getting wiped out because they they don't have they're not making any money. Yeah. Jimmy Huber: Yeah, it's reactive. Yeah, sure. Sure. Brent Gallo: So so those increased questionnaires, increased requirements, typically start at insurance. And and for me and I'm sure you and your business, Jimmy, starting with, you know, what are your insurance requirements? How can we reduce your bill? you know, your yearly bill by increasing your security, right? reduce your risk of a cyber attack in general. And another conversation you should probably have with your folks is do you have enough insurance right for your risk? Because a lot of people, Jimmy Huber: yeah. Yeah. Brent Gallo: hey, I get a blanket, you know, million dollar, five million dollar policy, but doing the analysis to really figure out do I have enough? Do I have too much? Where am I not covered? That's really a next step that very few people take. Jimmy Huber: Yeah, I I read another interesting article that said something like forty some percent, I don't remember the exact number, of claims don't get paid out. Even though they have Brent Gallo: Mm-hmm. Jimmy Huber: cyber, there's something that wasn't covered or it wasn't good enough. And so Brent Gallo: Yeah. Jimmy Huber: it's not just having the policy, but it's proving that you have enough documentation and compliance to actually get paid, right? And I think that's where our industry is definitely heavy into that. which was not a thing five years ago. I mean maybe Brent Gallo: Mm mm. Jimmy Huber: a little bit, but now it's all about compliance, even selling it as a service, right? So in your world, coming in from from doing these CMMC projects, do you get drawn into some of those other conversations? Because I feel like it's all just different cogs on the same or different spokes on the same wheel, right? it's all pushing people to be more cyber intensive, security minded, and you know, the same outcome basically. Brent Gallo: Yes, yeah, we we definitely do get I wouldn't say dragged in, but you know, asked to help with with other things Jimmy Huber: Yeah. Sure. Brent Gallo: like insurance, other frameworks. Hey, we're going after this business, or somebody has a a third party requirement. for example, I was helping a customer, they're working with a large national bank and they're actually having an AI policy pushed down to them, and there were security and program requirements from this bank to make sure they were. using AI safely, make sure their data was protected safely. So it's not just on the government side that's increasing requirements. It's it's all over. Jimmy Huber: Yeah, yeah. It's a it's a wild world we live in. And with so much noise out there, especially you mentioned AI earlier. I mean, that's a whole other podcast just to talk about how AI is making, Brent Gallo: Mm-hmm. Jimmy Huber: you know, if you have a process, it seems like it's making it way better with less people. If you don't though, it's almost like it exacerbates the problem. And in your world, I would think that would be exponentially worse because the bad guys are all using AI already, right? And so do you see some AI requirements, say, or maybe a framework around the best use cases for that inside this context? Because it's so new that I don't think there's any rules yet, which is a huge problem. it's kind of the wild west. Brent Gallo: Yes, it's it's definitely the Wild West. CMMC itself doesn't have like and well and NISTANHER 171 doesn't have AI specific rules. So as long as you're using AI within a federal you know FedRAMP approved space, you can use it, right? You're managing that government data correctly, documenting it correctly. Those are you know some guardrails, but you know, outside of a FedRAMP environment, it is kind of the Wild West, right? What are the use cases, how is you know this company using my data you know securely you know just thinking the business process right you talked about some things are worse with AI some things are better with AI it's a lot of discovery experimentation right now but I think it's overall good if you are implementing it correctly and safely right there's a whole new ISO ISO certification on AI there's also the NIST AI Jimmy Huber: nice. Brent Gallo: playbook Which kind of is a governance framework for companies to incorporate and manage AI. And then there's also a NIST RMF for companies to develop AI safely. So there are some Jimmy Huber: nice. Brent Gallo: compliance and guidelines out there, but very seldom used right now. Like I'm sure there's a lot of companies, hey, use our AI product, right? And then Jimmy Huber: Imagine that. Yeah. Brent Gallo: I'm knocking on the door. I have another guy, he's kind of specializes more in AI than I do. But he goes to these companies and said, Hey, I see you're using AI. What do you have for security on the back end? And there's nothing there, right? So he's working with his companies. Yeah, he's work Jimmy Huber: yeah. It's awful. Yeah. Brent Gallo: he's working with these companies to give them, you know, put in place security and governance programs so you know that company can go to their customers and say, Hey, here's our AI product. Yes, it's you know safe and this is you know how we've protected it. So as you know a differentiator for for their product. Jimmy Huber: Yeah. I love that. Yeah, we'll we'll pull links to all that what you just mentioned there, and we'll have that in the show notes. Cause I think it's good for people to at least have somewhere to start, right? everybody's Brent Gallo: Exactly. Mm-hmm. Jimmy Huber: got an opinion on AI, it's super easy. People have Chat GPT, they think it's the new Google, and that's about it. And it's not even a paid version. Like there's so Brent Gallo: Yeah. Jimmy Huber: many easy ways to get really in trouble. it's not malicious, but people don't know what they don't know. So yeah, I would love to add those resources and and that's that's a great thing to note. Now you've got a promotion coming up that I want to make sure there's a readiness assessment here in September. so we're Brent Gallo: Yes. Jimmy Huber: timing this. so this if you're listening to this and it's a new podcast release, you're we're about a week away. So tell us what that means and and what what our listeners can do about that. Brent Gallo: Awesome. So we're providing an OSC, so organization seeking certification for CMMC readiness workshop. So right now during the pause, this is a gift. So we don't, you know, the pressure is eased off a little bit. And so this workshop is to help you reflect upon your system security plan, your configuration, your evidence, and see if, hey, am I ready? Right, to really to help you develop a good self-assessment. So that's that's all day one. You know how to write a good implementation statement, how I'm making sure my scoping is correct, how is my my FedRAMP and shared responsibilities matrix? Those are all big details you need to have figured out before you go into an assessment. And the the second day of the workshop is more around what's it like to be on the assessment, right? Assessment week, what are the expectations from the C3O, the assessors, how can you prepare? You know, mentally, physically, have lots of coffee. It's a long day, it's a long day for everybody, a long couple days. You know, what do you expect in the assessment room as you're going through the assessment? So there's no surprises and things like that. So it's really all about Jimmy Huber: Okay. That sounds great. Brent Gallo: readiness. Yep. It's September 2nd and 3rd. we have just 15 seats, so it's very personal. Folks can ask questions, Jimmy Huber: Nice. Brent Gallo: and we're actually providing a full mock OSC material for folks to review. So you Jimmy Huber: legit. Brent Gallo: have evidence, you have a full system security plan and associated policies. So you can see what ready looks like. Jimmy Huber: Yeah, that's great. And is this in person then in Tennessee near you or is it online or w how does it work? Okay. So like a webinar series kind of? Okay. Brent Gallo: All all remote. All remote. Join me remotely. Yep. Yep. So in, yep. Online, remote training, two full days. not not Jimmy Huber: And it's free to attend, or you're buying tickets, or how does it work? Brent Gallo: free. There are some seats. so there's a standard seat for the training and a premium seat for additional consulting after the the workshop. Jimmy Huber: Got it. perfect. Yeah. If it's free, I think people kind of get put up a red flag. So I'm glad that it is, you know, you're you're providing a ton of value. So yeah. But and the goal here, Brent Gallo: Exactly. Yeah, you're gonna learn a lot. Jimmy Huber: yeah. So if if they become engaged and they're like, crap, like we have a ton of work to do, you're making an easy on-ramp then to work with you and your team, right? Like it's not just about, you know, getting the word out there, but if they do discover things, they don't have to go now find a vendor and figure it all out. You've got some options there that you've already done some of the legwork and make that even easier. Brent Gallo: Exactly, exactly. Yep, lots of information, great time to reflect upon, hey, are we ready or not? Do we need to make some changes? And if you do, we'll help you build a roadmap for what that looks like. Jimmy Huber: Yeah. Awesome. Yeah, well this has been fantastic, Brent. I mean, I've really enjoyed getting to know you and talking through some of these things. you know, my role at InfoTech is more just to talk about things and not do them. That's what my team does now that we've we've grown a little bit. And the compliance around CMMC is just one of those things that I don't have a good grasp on yet. And yet we now are seeing it so much more prevalent everywhere that yeah, we our industry relies on on companies and guys like you to you know lead us down the path correctly. and it just helps us add a ton of value, you know, to our customers and and our listeners today, too. So yeah, we'll definitely add that to our show notes. this will be a lot of notes today because you you've brought Brent Gallo: Yeah. Jimmy Huber: up so many good resources and hopefully just if people are listening and maybe they already are CME C CMMC certified. Or they're going through the pause and it's just a good reminder, you know, at at at the baseline of what they're doing and why. All the way to if they're not, hey, here's a lot of good places to start. if they do want to engage, Brent, what's the best way to get a hold of you or hire a cyber pro and maybe just have a conversation about what that could look like? Brent Gallo: So the best way to get in touch, shoot me an email at Brent Gallo at hiresyberpro.com. You can also go to our website at hiresyberpro dot com, you know, submit a contact form and get in touch with myself and the rest of our team. Jimmy Huber: Awesome. Thank you so much for your time today. it's been great. And everyone, hopefully you've gotten some tidbits and some stuff from Brent that you can implement in your own business and at least be more cyber aware in the crazy world that we're all living in. so yeah, it's been fun. We'll see you next time. Brent Gallo: Thank you, Jimmy. Have a good day.