FedRAMP Is Hard – That Does Not Make It Unnecessary

There is a legitimate debate over the burden FedRAMP places on cloud service providers, particularly small businesses attempting to enter the federal market. Authorization can be expensive, technically demanding and difficult to navigate, and those concerns are supported by more than simple anecdotes. In 2024, the Government Accountability Office (GAO) identified six key challenges faced […]
What the DoW CMMC Review Means for Defense Contractors

By Idenhaus Consulting The Department of War’s (DoW) July 13, 2026 announcement suspending CMMC Phase II has created immediate uncertainty across the Defense Industrial Base, especially for small businesses and mid-market prime contractors that were preparing for mandatory third-party assessments. The most important point for executive leaders is straightforward: the government paused one part of […]
CMMC at the Crossroads: What DIB Contractors Should Prepare for Next

For Defense Industrial Base (DIB) contractors, CMMC is no longer something that can be kept on the “future planning” list. It’s moving from a compliance conversation to a contract requirement as it is now a major part of how DoW contracts are awarded, renewed, and managed. The biggest change is simple: contractors need to be […]
The Identiverse AI Agent Illusion

By Ron Bowron Why Agents Need Human Sponsors, Not Just App Accounts Walking the expo floor at Mandalay Bay during Identiverse 2026, it was impossible to miss the sea of “Agent Identity” banners. If you closed your eyes, you’d think the identity community had completely solved the next generation of access management. But if you […]
Invisible Walls, Real Evidence: Proving Logical and Physical Separation in CMMC Enclaves, Hybrid IT, and Multi-Site Operations

Picture your next CMMC assessment. The C3PAO assessment team is not really interested in how shiny your SIEM is or how much you have spent on the latest pentest. They want to know one thing: where your sensitive data actually goes, from a real keyboard on a real desk to a real (or virtual) SharePoint, […]
Mark It Right, Spend Less: Simple, Defensible CUI Handling

Controlled Unclassified Information is unclassified, but it is not unrestricted. It is information that the government requires to be safeguarded and disseminated in accordance with specific rules derived from law, regulation, or government-wide policy. In practice, CUI markings are not administrative clutter; they are a low-cost control that prevents high-cost mistakes. For organizations focused on immediate […]
GSA’s New CUI Security Requirements: A Turning Point for Federal Contractors

In January 2026, the U.S. General Services Administration (GSA), the federal agency that manages government contracting and procurement, released updated guidance on how Controlled Unclassified Information (CUI) must be secured when it resides in contractor systems. The new procedural guide titled “Protecting Controlled Unclassified Information (CUI) in Nonfederal Systems and Organizations Process [CIO-IT-Security-21-112-Rev-1]” introduces a […]
If Hackers Had Yelp Reviews

By Navneet Lounsberry Nobody reads the negative reviews. We scroll straight to the five stars, skim the complaints, and convince ourselves that those problems only happen to other people. It turns out, that is also exactly how most organizations approach cybersecurity. Real cyberattacks are not funny. The financial losses, reputational damage, and operational chaos […]
Non-Human Identities and AI Agents: The New Blind Spot in Your IAM Program

By Navneet Lounsberry The numbers tell a story most security leaders aren’t prepared to hear. In enterprise cloud environments, non-human identities now outnumber human users on average at a 50 to 1 ratio, and some organizations have significantly higher ratios. A recent study found that 85% of identity-related cloud breaches involve compromised non-human identities. I’ve […]
Teaching Claude to Read Designer Workspaces

By Jerry Combs If you’ve ever asked an AI assistant to help you document or untangle an Identity Manager driver, you know how the first ten minutes of every conversation go. You paste in a file, the model asks what .Driver_ means. You explain. You paste another file, it asks what Model/EdirOrphan/ is doing in a project that clearly […]