Generated by All in One SEO v5.0.0.1, this is an llms.txt file, used by LLMs to index the site. # SecureStrux ## Sitemaps - [XML Sitemap](https://securestrux.com/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [Insights](https://securestrux.com/resources/insights/) - [NIST Updates SP 800-18: A New Era for System Security, Privacy, and C-SCRM Planning](https://securestrux.com/resources/insights/nist-updates-sp-800-18-a-new-era-for-system-security-privacy-and-c-scrm-planning/) - Learn what's new in NIST SP 800-18r2, including unified security, privacy, and C-SCRM planning, automation guidance, and updated RMF templates. - [Managing the Digital Supply Chain in Defense Networks](https://securestrux.com/resources/insights/managing-the-digital-supply-chain-in-defense-networks/) - This article will discuss why the digital supply chain is important and how to help manage it; emphasis on the Cybersecurity Maturity Model Certification (CMMC) - [Operationalizing Compliance: Turning Audits into Action](https://securestrux.com/resources/insights/operationalizing-compliance-turning-audits-into-action/) - This article discusses how PowerStrux addresses the needs and requirements of NIST 800-53 reporting and compliance. Learn how PowerStrux can benefit your team. - [CMMC 2.0 Compliance: What Defense Contractors Need to Know in 2025 and 2026](https://securestrux.com/resources/insights/cmmc-2-0-compliance-what-defense-contractors-need-to-know-in-2025-and-2026/) - In 2025 and beyond, CMMC 2.0 compliance is no longer a future requirement; it’s soon-to-be a contractual reality. Align your technology, people, and processes. - [A Year in Review: Reflecting on 2024 at SecureStrux](https://securestrux.com/resources/insights/a-year-in-review-reflecting-on-2024-at-securestrux/) - Reflecting on a remarkable 2024, SecureStrux celebrates client successes, community contributions, and team milestones. - [3 Recent Cyber Incidents and How SecureStrux Can Help](https://securestrux.com/resources/insights/3-recent-cyber-incidents-and-how-securestrux-can-help/) - Meta description: Explore how recent cyber incidents reveal vulnerabilities and the lessons learned. SecureStrux offers tailored solutions to enhance your cybersecurity posture. - [How Cybersecurity Consultants Offer Comprehensive Protection](https://securestrux.com/resources/insights/how-cybersecurity-consultants-offer-comprehensive-protection/) - Learn more about how cybersecurity consultants offer comprehensive, cradle-to-grave protection to safeguard your organization's sensitive data and systems. - [PowerStrux® Standalone Auditor User Reference](https://securestrux.com/resources/insights/powerstrux-standalone-auditor-user-reference/) - The PowerStrux® Standalone Auditor produces a report containing the following: User logon and logoff dates and times Data transfers and print jobs Failed logon attempts Account management events User status and inactivity Administrator, Backup Operator, Auditors, and Power User group membership Event Log actions, to include clearing the Event Log Windows Defender signature update and - [PowerStrux® Suite of Tools for Continuous Security Monitoring](https://securestrux.com/resources/insights/powerstrux-suite-of-tools-for-continuous-security-monitoring/) - SecureStrux is pleased to announce the launch of the PowerStrux™ Suite, cutting-edge, automated tools designed to revolutionize continuous security monitoring. - [PowerStrux® Standalone Auditor 5.0 Release and Updates](https://securestrux.com/resources/insights/powerstrux-standalone-auditor-5-0-release-and-updates/) - Introduction Event monitoring is a challenging and intimidating task. A properly configured audit policy results in an extreme number of captured events, contributing to the difficult nature of identifying unauthorized and malicious activity. Windows facilitates audit reduction capability via the Event Viewer, but this method offers little efficiency to the reviewing entity. This reality results - [Enhanced Cybersecurity Monitoring and Compliance with PowerStrux® Suite of Tools](https://securestrux.com/resources/insights/enhanced-cybersecurity-monitoring-and-compliance-with-powerstruxsuite-of-tools/) - PowerStrux™ Suite of Tools heralds a new era in cybersecurity monitoring and compliance. Simplify compliance, enhance security, and gain a strategic advantage. - [PowerStrux® ACAS Validator: Faster Compliance Validation for Mission-Critical Networks](https://securestrux.com/resources/insights/powerstrux-acas-validator-faster-compliance-validation-for-mission-critical-networks/) - PowerStrux ACAS Validator automates ACAS compliance checks, reduces manual effort, and helps validate configurations faster and accurately, TASKORD 20-0020 - [CMMC Phase II Delayed: What Defense Contractors Need to Know](https://securestrux.com/resources/insights/cmmc-phase-ii-delayed-what-defense-contractors-need-to-know/) - The DoW has announced the immediate pause of CMMC Phase II, delaying the planned November 10, 2026 rollout of third-party C3PAO assessments. - [Why Smarter Patching Beats Faster Patching: CISA's BOD 26-04](https://securestrux.com/resources/insights/why-smarter-patching-beats-faster-patching-cisas-bod-26-04/) - CISA’s BOD 26-04 introduces risk-based patching, helping organizations prioritize critical vulnerabilities and reduce cyber risk more efficiently. - [DISA J9 Directorate Pivots to Customer-Centric Hybrid Cloud Model](https://securestrux.com/resources/insights/disa-j9-directorate-pivots-to-customer-centric-hybrid-cloud-model/) - The J9 Directorate of DISA is driving a fundamental shift in how it serves the warfighter, transforming to a dynamic hybrid cloud solutions provider. - [Zero Trust Implementation Guidelines Published by NSA](https://securestrux.com/resources/insights/zero-trust-implementation-guidelines-published-by-nsa/) - NSA launched a Zero Trust Implementation Guide to provide consumable, interactive access to ZT resources, such as implementation, and technical guidance. - [DAAG vs DAAPM and The Transition to DAAG](https://securestrux.com/resources/insights/daag-vs-daapm-and-the-transition-to-daag/) - This article covers DAAPM vs DAAG - the difference between the two rulebooks, and what it means for you and your team now that DAAG has superseded DAAPM. - [New ISOO Notice 2026-01 Addresses AI and Sensitive Information Handling](https://securestrux.com/resources/insights/new-isoo-notice-2026-01-addresses-ai-and-sensitive-information-handling/) - ISOO has issued Notice 2026-01 providing guidance regarding handling of classified security information and CUI with the use of various AI systems and tools. - [CMMC 2.0 and the External Factors Problem - What Defense Contractors Need to Know](https://securestrux.com/resources/insights/cmmc-2-0-and-the-external-factors-problem-what-defense-contractors-need-to-know/) - This article covers external factors that could affect your ability to obtain CMMC 2.0 certification, including assessor bottlenecks and supply chain weak links - [The Cybersecurity Trends Poised to Transform Defense Contracting in 2026](https://securestrux.com/resources/insights/cybersecurity-trends-that-might-shape-defense-contracting-in-2026/) - 2026 will require contractors to rethink how they secure systems, operationalize compliance, and defend sensitive government data. 2026 cybersecurity trends. - [Building a SIPRNet Enclave: Lessons Learned From the Field](https://securestrux.com/resources/insights/building-a-siprnet-enclave-lessons-learned-from-the-field/) - Standing up a SIPRNet enclave is one of the most complex and high-stakes projects an organization can undertake. Here are some lessons learned from the field. - [CISA and FBI Introduce New Guidance to Address Cyber Risks in OT Environments](https://securestrux.com/resources/insights/cisa-and-fbi-introduce-new-guidance-to-address-cyber-risks-in-ot-environments/) - This articles describes CISA’s commitment to working hand-in-hand with US and international partners to provide timely, actionable cybersecurity guidance in OT. - [DISA Advances Mission Network-as-a-Service Initiative for 2026](https://securestrux.com/resources/insights/disa-advances-mission-network-as-a-service-initiative-for-2026/) - In 2026, DISA will advance a major modernization effort to consolidate combatant command networks worldwide into a single, cloud-based environment. - [What is Splunk and What Does Splunk do?](https://securestrux.com/resources/insights/what-is-splunk-transforming-your-organizations-data-management-and-cybersecurity-operations/) - Splunk is a powerful tool that simplifies the task of collecting and managing large volumes of data. In this article, we'll go over what it is & how it works. - [Corporate Account Takeover: How it Works & Tips for Prevention](https://securestrux.com/resources/insights/corporate-account-takeover-how-it-works-tips-for-prevention/) - Corporate account takeover lets attackers hijack business accounts for fraud and data theft. Learn tactics used and how to prevent attacks in this article. - [How a SecureStrux Mock CORA can Reduce the Stress and Uncertainty of Your Upcoming "Visit"](https://securestrux.com/resources/insights/how-a-securestrux-mock-cora-can-reduce-the-stress-and-uncertainty-of-your-upcoming-visit/) - The CORA program attempts to measure cyber operational readiness against compliance standards. Read this article to see how a SecureStrux Mock CORA can help you - [The DoW’s New Approach to Cybersecurity Risk Management](https://securestrux.com/resources/insights/the-dows-new-approach-to-cybersecurity-risk-management/) - Breaking Down the Department of War's New Cybersecurity Risk Management Construct (CSRMC): 5 Phases and 10 Tenets As outlined within the DoW announcement dated September 24th, 2025, DoW is looking to replace the Risk Management Framework with a “modernized” framework or “construct” that focuses more on current battlefields in both physical and cyber space. The - [Summer 2025 CORA Alert – Prepare Now](https://securestrux.com/resources/insights/summer-2025-cora-alert-prepare-now/) - At the 2025 NCMS Annual Seminar, the DCSA Mission Director and Authorizing Official provided an important update to CORA, ODP, and CCSP within the cyber space. - [Master Nessus Scans & Offline Registration in Minutes](https://securestrux.com/resources/insights/nessus-scans-offline-registration/) - This blog contains two videos that provide expert guidance on configuring and registering Nessus for comprehensive vulnerability scanning, ensuring secure, compliant systems. Nessus Offline Registration: In this first video, Justin Sylvester walks you through how to install and register Tenable's Nessus Vulnerability Scanner on a system that doesn’t have internet access. This is an important - [Compliance as a Service (CaaS): 4 Ways to Simplify Regulation](https://securestrux.com/resources/insights/compliance-as-a-service-caas-4-ways-to-simplify-regulation/) - Discover how compliance as a service simplifies regulation through automated monitoring, expert support, and improved reporting. Learn more with SecureStrux. - [Network Design and Security Services: A Comprehensive Guide](https://securestrux.com/resources/insights/network-design-and-security-services-a-comprehensive-guide/) - Learn about SecureStrux's tailored network design and security solutions to protect sensitive data and ensure compliance for DoD and high-security environments. - [SecureStrux's Comprehensive CMMC Services: Empowering Organizations to Achieve Compliance](https://securestrux.com/resources/insights/securestruxs-comprehensive-cmmc-services-empowering-organizations-to-achieve-compliance/) - Introduction At SecureStrux, we recognize the importance of achieving Cybersecurity Maturity Model Certification (CMMC) and the complexities it presents. As trusted leaders in cybersecurity solutions, our goal is to guide organizations through the compliance process, ensuring they meet the stringent standards necessary to protect sensitive federal contract information (FCI) and controlled unclassified information (CUI). Our - [Mitigating Turnover Impacts on Risk Management Framework](https://securestrux.com/resources/insights/mitigating-turnover-impacts-on-risk-management-framework/) - Discover strategies to mitigate the impact of turnover on your Risk Management Framework (RMF) process with expert consulting and staff augmentation solutions. - [The New Focuses of CORA: Key Indicators of Risk (KIORs) and Securing the Boundary](https://securestrux.com/resources/insights/the-new-focuses-of-cora-key-indicators-of-risk-kiors-and-securing-the-boundary/) - Introduction For organizations within the Department of Defense (DoD), the Cyber Operational Readiness Assessment (CORA) plays a critical role in protecting sensitive networks and maintaining operational readiness. CORA consolidates threat, vulnerability, and impact data to equip decision-makers with actionable intelligence for securing their cyberinfrastructure. A key component of this assessment is the identification of Key - [Thoughts from the Field: The Critical Role of the Defense Industrial Base in Supporting Our Military](https://securestrux.com/resources/insights/thoughts-from-the-field-the-critical-role-of-the-defense-industrial-base-in-supporting-our-military/) - As a company, we know firsthand the impact that the Defense Industrial Base (DIB) has on the lives and careers of those serving in the military. We are privileged in that many of our team members are either currently serving or have previously served in various branches of the military. Recently one of our Cybersecurity Maturity Model Certification (CMMC) team members, Matthew - [The Evolution of CCRI/CORA: The SecureStrux Journey](https://securestrux.com/resources/insights/the-evolution-of-ccri-cora-the-securestrux-journey/) - Introduction Over the past decade, SecureStrux has conducted hundreds of Command Cyber Readiness Inspections (CCRIs), serving over 75 clients. With the recent shift to Cyber Operational Readiness Assessment (CORA), SecureStrux remains a trusted partner in helping organizations navigate this evolving landscape. What is CCRI/CORA? CCRI, now known as CORA (Cyber Operational Readiness Assessment), is a From early DISA collaborations to CORA innovations, discover the SecureStrux journey in empowering cybersecurity resilience. - [Understanding TASKORD 20-0020](https://securestrux.com/resources/insights/understanding-taskord-20-0020/) - Updated Guidelines for ACAS Vulnerability Scans on DoD Networks The TASKORD 20-0020 directive covers the new operational guidance for conducting ACAS (Tenable) vulnerability scans on DoD Information Networks (DODIN). There are several important changes to the way organizations are now required to conduct vulnerability scans. Contact SecureStrux today for a consultation. Our Tenable SMEs have - [Understanding Cybersecurity Penetration Testing & Why It Matters](https://securestrux.com/resources/insights/understanding-cybersecurity-penetration-testing-why-it-matters/) - Discover vulnerabilities before attackers do. Schedule cybersecurity penetration testing with SecureStrux for proactive defense and robust security. - [Deploying Mission Ready DoD Cybersecurity Solutions with SecureStrux](https://securestrux.com/resources/insights/deploying-mission-ready-dod-cybersecurity-solutions-with-securestrux/) - Discover how SecureStrux leads the way in DoD cybersecurity with expert solutions to safeguard critical information. Explore our core capabilities today. - [What are Tenable and Assured Compliance Assessment Solution (ACAS)?](https://securestrux.com/resources/insights/what-are-tenable-and-assured-compliance-assessment-solution-acas/) - Organizations working with the DoD are probably familiar, in part, with the compliance demands for vulnerability scanning and risk assessment. The increasing sophistication of cyberattacks has led to increased attention on the Defense Industrial Base (DIB) supply chain and DoD contractors, especially on their ability to maintain effective cybersecurity postures. A critical tool for DoD - [SIPRNet vs NIPRNet: What’s the Difference?](https://securestrux.com/resources/insights/siprnet-vs-niprnet-whats-the-difference/) - SIRPNet vs NIPRNet: these networks serve as major communication channels for sensitive and non-sensitive data. But, what’s the difference? Discover more... - [SecureStrux Achieves Remarkable Growth, Recognized On Inc. 5000 List](https://securestrux.com/resources/insights/securestrux-achieves-remarkable-growth-recognized-on-inc-5000-list/) - SecureStrux, a leading provider of cybersecurity solutions in the defense sector, proudly announces its inclusion on Inc. magazine’s prestigious Inc. 5000 list for the fourth time in the last six years. The company, headquartered in Lancaster, Pennsylvania, continues to play a pivotal role in the dynamic cybersecurity services industry. While serving both commercial markets and - [Navigating the Path to CMMC Compliance: Insights From SecureStrux Experts](https://securestrux.com/resources/insights/navigating-the-path-to-cmmc-compliance-insights-from-securestrux-experts/) - The Cybersecurity Maturity Model Certification (CMMC) is becoming a critical standard for companies contracting with the U.S. Department of Defense (DoD). - [Making Sense of CMMC Certification and the Changing Goal Posts of Final Rulemaking](https://securestrux.com/resources/insights/making-sense-of-cmmc-certification-and-the-changing-goal-posts-of-final-rulemaking/) - DoD Contractors Want to Know What the Hubbub is All About While the title of this article makes a bold statement, in full transparency, we cannot assert that we can make complete sense of CMMC, nor can we with certainty provide concise information on the status of rulemaking; we can provide you with the latest - [Leveraging STIG Evaluations for Robust System Hardening](https://securestrux.com/resources/insights/leveraging-stig-evaluations-for-robust-system-hardening/) - The need for secure systems is your first line of defense against cyber threats and system hardening is crucial to ensuring and maintaining a secure network. - [CMMC 2.0 | What Are the Requirements?](https://securestrux.com/resources/insights/cmmc-2-0-what-are-the-requirements/) - CMMC 2.0: You Cannot Afford to Wait CMMC Model 2.0 was announced in November 2021 and will be implemented through the rule-making process. The Two Rules Are: Part 32 of the Code of Federal Regulations (CFR) (Federal Acquisition Rules) (FAR) Part 48 of the CFR (Defense Federal Acquisition Regulation Supplement) (DFAR) DoD contractors will be - [CMMC 2.0: Waiting on the Final Rule Can Have Consequences](https://securestrux.com/resources/insights/cmmc-2-0-waiting-on-the-final-rule-can-have-consequences/) - Waiting on the Final Rule Can Have Consequences for DoD Contractors CMMC Model 2.0 was announced in 2021 and will be implemented very soon. The Rules: Part 32 of the Code of Federal Regulations (CFR) (Federal Acquisition Rules) (FAR) Part 48 of the CFR (Defense Federal Acquisition Regulation Supplement) (DFARS) All DoD contractors will be - [CMMC 2.0 | Are You Stuck on Your CMMC Certification Journey?](https://securestrux.com/resources/insights/cmmc-2-0-are-you-stuck-on-your-cmmc-certification-journey/) - Whether you are required to have a CMMC Level 2 certification and are not sure where to start, or you already have a good start and need an independent review, SecureStrux can help you. SecureStrux is a Small Business Cybersecurity Firm established in 2013 with ISO 9001:2015-certified processes providing specialized services in cybersecurity, vulnerability management, - [A Streamlined Process for DoD Risk Management Framework](https://securestrux.com/resources/insights/a-streamlined-process-for-dod-risk-management-framework/) - The DoD risk management framework is a cornerstone of the DoD's cybersecurity strategy and is instrumental in supporting its defense priorities. Learn more... - [5 Tips to Navigate CMMC Compliance](https://securestrux.com/resources/insights/5-tips-to-navigate-cmmc-compliance/) - Staying abreast of the latest regulatory updates for CMMC compliance is crucial. This article offers an overview of the proposed rule, an analysis of changes... - [NIPRNet vs SIPRNet: All Your Questions About Access Answered](https://securestrux.com/resources/insights/niprnet-vs-siprnet-all-your-questions-about-access-answered/) - NIPRNet vs SIPRNet: Learn to navigate access protocols for contractors within the Department of Defense (DoD) in this comprehensive guide. - [Mastering Endpoint Security: A Fireside Chat](https://securestrux.com/resources/insights/mastering-endpoint-security-a-fireside-chat/) - What is Endpoint Security? I consider an endpoint to be an Operating System Instance on a network. Providing Endpoint Security is the next level of defense in depth after Network Security. There are some protections provided by the network for endpoints and some protections provided by endpoints for the network. But most endpoint security is Explore the future of endpoint security with industry veteran Roy "Mac" Kincaid. Join the conversation and master your defense strategies. - [What is SIPRNet? A Brief Introduction to the Secret Internet Protocol Router Network](https://securestrux.com/resources/insights/what-is-siprnet-a-brief-introduction-to-the-secret-internet-protocol-router-network/) - Modern military and defense threats call for data and intelligence, and both need to be readily communicable and available to U.S. interests around the world. Fortunately, we already have a model for an information network that fits this need: the Internet. Unfortunately, the Internet is public and unsecured, and unfit for the demands of military - [A Guide to Achieving SIPRNet Connectivity](https://securestrux.com/resources/insights/a-guide-to-achieving-siprnet-connectivity/) - In an era where data security is paramount, SecureStrux leads the way in navigating SIPRNet integration for defense contractors and organizations. - [Critical Infrastructure Part 3: OT Security](https://securestrux.com/resources/insights/critical-infrastructure-part-3-ot-security/) - In Part I of the Critical Infrastructure Series, we covered the importance of protecting the nation’s critical infrastructure (CI) Sectors, why they’re targeted, and how to defend against attack. In Part II, we described the Operational Technology (OT) ecosystem and the importance of its components. In Part III, we cover the threats, common vulnerabilities, and - [Emphasizing Continuous Compliance Monitoring](https://securestrux.com/resources/insights/emphasizing-continuous-compliance-monitoring/) - The concept of continuous monitoring has always existed. Everything that requires a periodic assessment by default requires continuous monitoring. The concept of continuous monitoring is a proactive measure that should be taken by every organization regardless of size to ensure information system (IS) configurations meet requirements and perform effectively and efficiently. The Purpose of Continuous - [NIST Releases Concept Paper to Guide Development of CSF 2.0](https://securestrux.com/resources/insights/nist-releases-concept-paper-to-guide-development-of-csf-2-0/) - NIST Releases Concept Paper to Guide Development of CSF 2.0 The National Institute of Standards and Technology (NIST) has posted a concept paper titled, "Potential Significant Updates to the Cybersecurity Framework,” providing an update on the cybersecurity framework (CSF). NIST has also announced its plan for scheduling virtual and in-resident workshops starting in February. The - [The Cybersecurity Threat Landscape: Is Anywhere Safe?](https://securestrux.com/resources/insights/the-cybersecurity-threat-landscape-is-anywhere-safe/) - Is Your Sensitive Data Safe? The Short Answer is, No. Cybersecurity is an increasingly critical issue as the digital landscape constantly changes, and hackers seek ways to penetrate networks and systems. To ensure safety and security for all, defense contractors must know about emerging threats or vulnerabilities, including what malicious actors are targeting and how - [SecureStrux Celebrates 10th Anniversary And New Office Space With Ribbon Cutting](https://securestrux.com/resources/insights/securestrux-celebrates-10th-anniversary-and-new-office-space-with-ribbon-cutting/) - On Thursday, May 18, SecureStrux invited friends, family, staff, local businesses, and clients to celebrate its 10th anniversary and the ribbon cutting of their new office space. Approximately 70 guests attended the event, which was held in the heart of Lancaster City. The celebration started with an open house at SecureStrux's new office space at - [CMMC Compliance is Not All Technical—Technically Speaking](https://securestrux.com/resources/insights/cmmc-compliance-is-not-all-technical-technically-speaking/) - Preparing for Cybersecurity Maturity Model Certification As we continue to consult with Organizations Seeking Certification (OSC) that are preparing for the CMMC Level 2 assessment for certification, we find that the non-technical CMMC practices (a.k.a., NIST SP 800-171 security controls) tend to be glossed over. It’s easier to focus on technical controls with tangible solutions - [Critical Infrastructure Part 2: Cyber Attacks on Critical Infrastructure](https://securestrux.com/resources/insights/critical-infrastructure-part-2-cyber-attacks-on-critical-infrastructure/) - In Part I of the Critical Infrastructure Series, we covered the importance of protecting the nation’s critical infrastructure (CI) Sectors, why they’re targeted, and how to defend against attack. In Part II, we go a little deeper into the Operational Technology (OT) ecosystem and describe how its components interplay to provide critical services within the - [Critical Infrastructure Part 1: What is Critical Infrastructure?](https://securestrux.com/resources/insights/critical-infrastructure-part-1-what-is-critical-infrastructure/) - What is So Critical About Critical Infrastructure? Over the next several weeks we will be diving deeper and talking more extensively about the importance of protecting the nation’s critical infrastructure (CI), why it’s targeted, and how to defend against attacks. Hardly a day passes by without critical infrastructure attacks making headline news, whether on the - [CMMC and the HIPAA Privacy Rule: What is the Connection?](https://securestrux.com/resources/insights/cmmc-and-the-hipaa-privacy-rule-what-is-the-connection/) - HIPAA Privacy and Security Rules Consider this scenario; you are a Chief Information Security Officer (CISO) for a major university hospital system, with over 10 years of experience working with protected health information (PHI) under the following: HIPAA Privacy Rule (“protecting the type of data while communicated”) HIPAA Security Rule (“protecting the security of the ## Pages - [Home](https://securestrux.com/) - Comprehensive end-to-end cybersecurity compliance services for defense, infrastructure, and commercial sectors. Fortify your network now. - [Our Team](https://securestrux.com/who-we-are/our-team/) - [RMF](https://securestrux.com/rmf-compliance/) - SecureStrux simplifies RMF compliance for federal agencies with tailored solutions, from preparation to ATO achievement and continuous monitoring. - [FISMA](https://securestrux.com/fisma/) - SecureStrux excels in FISMA compliance solutions, ensuring ATO success for federal agencies with a 100% success rate and comprehensive support. - [Products](https://securestrux.com/what-we-do/continuous-monitoring-tools-and-products/) - Discover PowerStrux®, SecureStrux's continuous monitoring tools to safeguard your digital landscape with real-time threat detection and security insights. - [PowerStrux Webinar Q1 2026](https://securestrux.com/powerstrux-webinar-q1-2026/) - Watch our Q1 2026 PowerStrux® webinar. See updates, and an active demonstration of the PowerStrux® suite, including Windows Auditor and more. - [Opt-out preferences](https://securestrux.com/opt-out-preferences/) - [Disclaimer](https://securestrux.com/disclaimer/) - [Imprint](https://securestrux.com/imprint/) - [DoW Cybersecurity Services in Dayton](https://securestrux.com/cybersecurity-dayton/) - [DoW Cybersecurity Services in Los Angeles](https://securestrux.com/cybersecurity-los-angeles/) - [DoW Cybersecurity Services in Augusta](https://securestrux.com/cybersecurity-augusta/) - [DoW Cybersecurity Services in Aberdeen](https://securestrux.com/cybersecurity-aberdeen/) - [DoW Cybersecurity Services in Miami](https://securestrux.com/cybersecurity-miami/) - [DoW Cybersecurity Services in Austin](https://securestrux.com/cybersecurity-austin/) - [DoW Cybersecurity Services in Columbia](https://securestrux.com/cybersecurity-columbia/) - [DoW Cybersecurity Services in Alexandria](https://securestrux.com/cybersecurity-alexandria/) - [DoW Cybersecurity Services in Boston](https://securestrux.com/cybersecurity-boston/) - [DoW Cybersecurity Services in San Diego](https://securestrux.com/cybersecurity-san-diego/) - [DoW Cybersecurity Services in Washington DC](https://securestrux.com/cybersecurity-washington-dc/) - [DoW Cybersecurity Services in Colorado Springs](https://securestrux.com/cybersecurity-colorado-springs/) - [DoW Cybersecurity Services in Denver](https://securestrux.com/cybersecurity-denver/) - [DoW Cybersecurity Services in Huntsville](https://securestrux.com/cybersecurity-huntsville/) - [Government Agencies](https://securestrux.com/who-we-serve/dod-cybersecurity-service-provider/) - SecureStrux is a leading DoD cybersecurity service provider for government agencies, ensuring advanced security and compliance with expert services. - [Our Culture](https://securestrux.com/who-we-are/our-culture/) - [Schedule Meeting](https://securestrux.com/schedule-meeting/) - [Engineering Solutions](https://securestrux.com/what-we-do/engineering-solutions/) - [CORA](https://securestrux.com/cyber-operational-readiness-assessment/) - SecureStrux offers expert Cyber Operational Readiness Assessment (CORA) services for network security and compliance. Achieve CORA success with our guidance. - [Careers](https://securestrux.com/careers/) - [About Us](https://securestrux.com/who-we-are/about-us/) - [Cybersecurity Maturity Model Certification (CMMC)](https://securestrux.com/cybersecurity-maturity-model-certification-cmmc-services/) - SecureStrux's CMMC services guide you through certification with expert consulting and C3PAO assessments for defense contractors. Start your compliance journey. - [Jobs](https://securestrux.com/job-openings/) - [SIPRNet](https://securestrux.com/siprnet/) - Streamline your SIPRNet integration and compliance with SecureStrux's expert services for secure DoD network connections and risk management. - [Compliance & Inspections](https://securestrux.com/what-we-do/cybersecurity-compliance-solutions/) - SecureStrux ensures compliance with in-depth cybersecurity compliance solutions, guiding through CCRI, CMMC, RMF, and more for secure infrastructures. - [Defense Industrial Base](https://securestrux.com/who-we-serve/dib-cybersecurity-service-provider/) - SecureStrux serves the Defense Industrial Base with expert DoD Cybersecurity Service Provider solutions for secure and compliant network environments. - [PowerStrux.wa](https://securestrux.com/powerstrux-trial/) - [Higher Education / R&D](https://securestrux.com/who-we-serve/higher-ed-cybersecurity/) - SecureStrux enhances higher ed cybersecurity, providing expert support for unique challenges in education and research. Partner with us for security excellence. - [DFARS](https://securestrux.com/dfars-compliance/) - Navigate DFARS compliance confidently with SecureStrux. Our comprehensive services ensure DoD contractors meet essential cybersecurity requirements. - [Other Critical Infrastructure](https://securestrux.com/who-we-serve/ot-cybersecurity/) - Our dedicated OT cybersecurity experts safeguard critical infrastructure with cutting-edge strategies and technologies for operational technology protection. - [Staffing Solutions](https://securestrux.com/what-we-do/cybersecurity-staffing-agency/) - SecureStrux is your go-to cybersecurity staffing agency, providing top talent with industry expertise to meet your cyber staffing needs efficiently. - [Endpoint Security](https://securestrux.com/endpoint-security-solutions/) - SecureStrux delivers endpoint security solutions to protect against diverse threats with advanced software, ensuring compliance and robust defense." - [Security Event Information and Event Management (SIEM)](https://securestrux.com/siem-as-a-service/) - SecureStrux provides advanced SIEM as a service, offering rapid threat detection, compliance, and tailored security solutions for your organization. - [Vulnerability Assessment & Management](https://securestrux.com/vulnerability-assessment-services/) - Maximize security with SecureStrux's vulnerability assessment services, offering management, detailed scans, prioritization, and expert mitigation strategies. - [Systems Administration](https://securestrux.com/system-administrative-services/) - SecureStrux's system administrative services ensure top-notch security system deployment and configuration for optimal digital asset protection. - [Network Security](https://securestrux.com/network-security-service-providers/) - Choose SecureStrux as your network security service providers to protect digital assets with advanced solutions and expert implementation. - [Penetration Testing](https://securestrux.com/advanced-penetration-testing/) - Unlock robust security with SecureStrux's advanced penetration testing, uncovering and mitigating vulnerabilities for superior protection. - [Specialized Network Design](https://securestrux.com/specialized-network-design/) - [Federal Contracting](https://securestrux.com/federal-contracting/) - [Virtualization](https://securestrux.com/virtualization/) - [Privacy](https://securestrux.com/privacy/) ## Job Openings - [Network Engineer SME](https://securestrux.com/jobs/network-engineer-sme/) - About the Job The Network Engineer will support SecureStrux clients by designing, implementing, securely configuring, and maintaining their network infrastructure, with a focus on Cisco switches, Cisco routers, Cisco ASA, Cisco ISE, Forescout, and Palo Alto firewalls. Job Details Full Time, Exempt, Salaried Remote home office with approx. 60% travel (overnight) to - [Staff Accountant](https://securestrux.com/jobs/staff-accountant/) - About the Job The Staff Accountant serves as a key member of the SecureStrux finance team and is responsible for executing the organization's day-to-day accounting functions with a high degree of accuracy, organization, and ownership. This role supports the monthly close process, maintains the integrity of the general ledger, prepares - [PowerStrux Software Account Executive](https://securestrux.com/jobs/powerstrux-software-account-executive/) - About the Job SecureStrux is a cybersecurity and compliance solutions company supporting the Department of War (DoW), Defense Counterintelligence and Security Agency (DCSA), and the Defense Industrial Base (DIB). Our proprietary PowerStrux suite delivers automated cybersecurity compliance, continuous monitoring, auditing, assessment, and reporting capabilities designed specifically for highly regulated and - [SE&V Performance Assessment Engineer (26-241)](https://securestrux.com/jobs/sev-performance-assessment-engineer-26-240-26-241/) - About the Job The SE&V Performance Assessment Engineer will support the C2BMC program and will be responsible for the following tasks. Location Huntsville, AL The Work You'll Do The selected applicant will perform the following: Software development of ad-hoc post processing analysis tools and plots to assess and analyze C2BMC - [System Tester (26-236)](https://securestrux.com/jobs/system-tester-26-236/) - About the Job The System Tester will support the C2BMC program and will be responsible for assisting with the organization and participation in Flight and Ground Tests. Location Colorado Springs, CO The work associated with this position will be performed onsite at a designated Lockheed Martin facility 4X10 hour day, 3 - [Global Integration Engineer (26-229 & 26-232)](https://securestrux.com/jobs/global-integration-engineer-26-229/) - About the Job The Global Integration Engineer will support the C2BMC program and will be responsible for the following tasks. Location Colorado Springs, CO The Work You'll Do In this role, the selected applicant will be responsible for: Integrating JEMINI Lab test suites in our development lab Assisting software development personnel ## Timeline Stories - [October 15, 2024](https://securestrux.com/resources/insights/cool_timeline/cmmc-anticipated-timeline/) - The Department of Defense (DoD) issues the Final CMMC Rule, officially establishing the Cybersecurity Maturity Model Certification (CMMC) program. - [Phase 1: Early to Mid-2025](https://securestrux.com/resources/insights/cool_timeline/early-to-mid-2025/) - DoD finalizes the second part of its CMMC rule under 48 C.F.R. Part 204. New DoD solicitations require self-assessments for CMMC Level 1 and Level 2 compliance. Prime contractors 'may' require downstream (subcontractor) DIB companies CMMC Level 2 C3PAO certifications in lieu of self-assessment. - [Phase 2: Early to Mid-2026](https://securestrux.com/resources/insights/cool_timeline/early-to-mid-2026/) - DoD includes CMMC Level 2 certifications in applicable solicitations. Contractors bidding on these opportunities must achieve Level 2 certification by this time. - [Phase 3: Early to Mid-2027](https://securestrux.com/resources/insights/cool_timeline/early-to-mid-2027/) - CMMC Level 2 certifications become mandatory to exercise option periods on applicable contracts awarded post-rule. DoD introduces CMMC Level 3 certification requirements in select solicitations. - [Phase 4: Early to Mid-2028](https://securestrux.com/resources/insights/cool_timeline/early-to-mid-2028/) - CMMC requirements apply to all applicable solicitations and contract option periods, regardless of award date. ## Advisory Center - [Webinar - PowerStrux Introduction and Update 2026 Q1](https://securestrux.com/resources/cyber-advisory-center/webinar-powerstrux-introduction-and-update-2026-q1/) - Recorded in March 2026, attendees learned how PowerStrux delivers actionable insights while reducing the time and effort required to maintain compliance. - [Active Directory Module for Windows PowerShell | Basic Auditing for Security Professionals](https://securestrux.com/resources/cyber-advisory-center/active-directory-module-for-windows-powershell-basic-auditing-for-security-professionals/) - [How to Use Windows PowerShell for Advanced Auditing](https://securestrux.com/resources/cyber-advisory-center/how-to-use-windows-powershell-for-advanced-auditing/) - [A Quick Guide: Creating a Tenable Nessus Scanning Account for VSCA](https://securestrux.com/resources/cyber-advisory-center/a-quick-guide-creating-a-tenable-nessus-scanning-account-for-vsca/) - [The State of Cybersecurity in Higher Education](https://securestrux.com/resources/cyber-advisory-center/the-state-of-cybersecurity-in-higher-education/) - [Addressing Cybersecurity Challenges in Higher Education](https://securestrux.com/resources/cyber-advisory-center/addressing-cybersecurity-challenges-in-higher-education/) - [Impact of GLBA on Higher Education](https://securestrux.com/resources/cyber-advisory-center/impact-of-glba-on-higher-education/) - [Apply Configuration With Microsoft's LGPO Utility](https://securestrux.com/resources/cyber-advisory-center/apply-configuration-with-microsofts-lgpo-utility/) - [Empowering Efficient System Auditing with the PowerStrux Windows Auditor](https://securestrux.com/resources/cyber-advisory-center/empowering-efficient-system-auditing-with-the-powerstrux-windows-auditor/) - [Overcoming Hurdles: Navigating Challenges in Risk Management Framework](https://securestrux.com/resources/cyber-advisory-center/overcoming-hurdles-navigating-challenges-in-risk-management-framework/) - Learn how to navigate RMF challenges and overcome hurdles efficiently with SecureStrux's expert strategies. - [Demystifying CMMC - A Comprehensive Introduction](https://securestrux.com/resources/cyber-advisory-center/demystifying-cmmc-a-comprehensive-introduction/) - [Understanding and Implementing NIST SP 800-53 AU-2 Logging Requirements for Defense Industrial Base Systems](https://securestrux.com/resources/cyber-advisory-center/understanding-and-implementing-nist-sp-800-53-au-2-logging-requirements-for-defense-industrial-base-systems/) - [Securing the Defense Industrial Base: Comprehensive CMMC Compliance with SecureStrux](https://securestrux.com/resources/cyber-advisory-center/securing-the-defense-industrial-base-comprehensive-cmmc-compliance-with-securestrux/) - [Taking the Secret Out of Obtaining SIPRNet - A Video Webinar](https://securestrux.com/resources/cyber-advisory-center/taking-the-secret-out-of-obtaining-siprnet/) - [Configuring Splunk Enterprise for Common Access Card (CAC) Authentication](https://securestrux.com/resources/cyber-advisory-center/configuring-splunk-enterprise-for-common-access-card-cac-authentication/) ## Team - [Nate Swartz](https://securestrux.com/who-we-are/team/nate-swartz/) - [Lauren Eshelman](https://securestrux.com/who-we-are/team/lauren-eshelman/) - [James Hayward](https://securestrux.com/who-we-are/team/james-hayward/) - [Rachel Krall](https://securestrux.com/who-we-are/team/rachel-krall/) - Rachel Krall is SecureStrux's Director of Business Development, DoW. - [Nathan Shea](https://securestrux.com/who-we-are/team/nathan-shea/) - [Roy "Mac" Kincaid](https://securestrux.com/who-we-are/team/roy-mac-kinkaid/) - [Shane Cairns](https://securestrux.com/who-we-are/team/shane-cairns/) - [Maranda McElheny](https://securestrux.com/who-we-are/team/maranda-mcelheny/) - [Asher Fogie](https://securestrux.com/who-we-are/team/asher-fogie/) - [Lisa Weir](https://securestrux.com/who-we-are/team/lisa-weir/) - [Jeff Parker](https://securestrux.com/who-we-are/team/jeff-parker/) - [Jen Cottle](https://securestrux.com/who-we-are/team/jen-cottle/) - [Patrick Badra](https://securestrux.com/who-we-are/team/patrick-badra/) - [Jeri Harvey](https://securestrux.com/who-we-are/team/jeri-harvey/) - [Wayne Maw](https://securestrux.com/who-we-are/team/wayne-maw/) - [Katie Shelly](https://securestrux.com/who-we-are/team/katie-shelly/) - [Jeffrey Keyser](https://securestrux.com/who-we-are/team/jeffrey-keyser/) - [Sherie King LTC (Ret.)](https://securestrux.com/who-we-are/team/sherie-king/) - [Kevin Patton](https://securestrux.com/who-we-are/team/kevin-patton/) - [MG (RET) Joe Brendler](https://securestrux.com/who-we-are/team/joe-brendler/) - [Rick Pena](https://securestrux.com/who-we-are/team/rick-pena/) - [Katie Saldarriaga](https://securestrux.com/who-we-are/team/katie-saldarriaga/) - [Michael Lux](https://securestrux.com/who-we-are/team/michael-lux/) - [Steven Ricker](https://securestrux.com/who-we-are/team/steven-ricker/) - [Justin Sylvester](https://securestrux.com/who-we-are/team/justin-sylvester/) - [Harry Jurisson](https://securestrux.com/who-we-are/team/harry-jurisson/) - [Michael Kelley](https://securestrux.com/who-we-are/team/michael-kelly/) - [Angie Gabrielson](https://securestrux.com/who-we-are/team/angie-gabrielson/) - [Eric White](https://securestrux.com/who-we-are/team/eric-white/) ## Categories - [Uncategorized](https://securestrux.com/resources/insights/category/uncategorized/) - Uncategorized insights to empower and inform your organization on the latest trends, compliance strategies, and best practices in cybersecurity. - [News](https://securestrux.com/resources/insights/category/news/) - News insights to empower and inform your organization on the latest trends, compliance strategies, and best practices in cybersecurity. - [CMMC](https://securestrux.com/resources/insights/category/cmmc/) - CMMC insights to empower and inform your organization on the latest trends, compliance strategies, and best practices in cybersecurity. - [RMF](https://securestrux.com/resources/insights/category/rmf/) - RMF insights to empower and inform your organization on the latest trends, compliance strategies, and best practices in cybersecurity. - [Compliance](https://securestrux.com/resources/insights/category/compliance/) - Compliance insights to empower and inform your organization on the latest trends, compliance strategies, and best practices in cybersecurity. - [SIPRNet](https://securestrux.com/resources/insights/category/siprnet/) - SIPRNet insights to empower and inform your organization on the latest trends, compliance strategies, and best practices in cybersecurity. - [CCRI](https://securestrux.com/resources/insights/category/ccri/) - CCRI insights to empower and inform your organization on the latest trends, compliance strategies, and best practices in cybersecurity. - [Cybersecurity](https://securestrux.com/resources/insights/category/cybersecurity/) - Cybersecurity insights to empower and inform your organization on the latest trends, compliance strategies, and best practices in cybersecurity. - [Critical Infrastructure](https://securestrux.com/resources/insights/category/critical-infrastructure/) - Critical Infrastructure insights to empower and inform your organization on the latest trends, compliance strategies, and best practices in cybersecurity. - [Endpoint Security](https://securestrux.com/resources/insights/category/endpoint-security/) - Endpoint Security insights to empower and inform your organization on the latest trends, compliance strategies, and best practices in cybersecurity. - [Splunk](https://securestrux.com/resources/insights/category/splunk/) - Splunk insights to empower and inform your organization on the latest trends, compliance strategies, and best practices in cybersecurity. - [SIEM](https://securestrux.com/resources/insights/category/siem/) - SIEM insights to empower and inform your organization on the latest trends, compliance strategies, and best practices in cybersecurity. - [CORA](https://securestrux.com/resources/insights/category/cora/) - CORA insights to empower and inform your organization on the latest trends, compliance strategies, and best practices in cybersecurity. - [PowerStrux](https://securestrux.com/resources/insights/category/powerstrux/) - PowerStrux insights to empower and inform your organization on the latest trends, compliance strategies, and best practices in cybersecurity. ## Tags - [CCRI](https://securestrux.com/resources/insights/tag/ccri/) - [CORA](https://securestrux.com/resources/insights/tag/cora/) - [Cybersecurity](https://securestrux.com/resources/insights/tag/cybersecurity/) - [Splunk](https://securestrux.com/resources/insights/tag/splunk/) - [SIEM](https://securestrux.com/resources/insights/tag/siem/) - [CMMC](https://securestrux.com/resources/insights/tag/cmmc/) - [Compliance](https://securestrux.com/resources/insights/tag/compliance/) - [Mock CORA](https://securestrux.com/resources/insights/tag/mock-cora/) - [PowerStrux](https://securestrux.com/resources/insights/tag/powerstrux/) - [CMMC 2.0](https://securestrux.com/resources/insights/tag/cmmc-2-0/) ## Employment Types - [Full-time](https://securestrux.com/resources/insights/job-type/full-time/) ## Work Arrangements - [Remote](https://securestrux.com/resources/insights/job-location/remote/) - [Hybrid](https://securestrux.com/resources/insights/job-location/hybrid/) - [On-site](https://securestrux.com/resources/insights/job-location/on-site/) ## Locations - [Maryland](https://securestrux.com/resources/insights/location/maryland/) - [Colorado](https://securestrux.com/resources/insights/location/colorado/) - [Alabama](https://securestrux.com/resources/insights/location/alabama/) - [Pennsylvania](https://securestrux.com/resources/insights/location/pennsylvania/) - [Virginia](https://securestrux.com/resources/insights/location/virginia/) ## Category - [Compliance & Inspections](https://securestrux.com/resources/cyber-advisory-center/category/compliance-inspections/) - Compliance & Inspections resources from the Cyber Advisory Center. - [Cybersecurity](https://securestrux.com/resources/cyber-advisory-center/category/cybersecurity/) - Cybersecurity resources from the Cyber Advisory Center. - [CMMC](https://securestrux.com/resources/cyber-advisory-center/category/cmmc/) - CMMC resources from the Cyber Advisory Center. - [PowerStrux™](https://securestrux.com/resources/cyber-advisory-center/category/powerstrux/) - PowerStrux™ resources from the Cyber Advisory Center. - [Higher Education](https://securestrux.com/resources/cyber-advisory-center/category/higher-education/) - Higher Education resources from the Cyber Advisory Center. - [Auditing](https://securestrux.com/resources/cyber-advisory-center/category/auditing/) - Auditing resources from the Cyber Advisory Center. - [RMF](https://securestrux.com/resources/cyber-advisory-center/category/rmf/) - RMF resources from the Cyber Advisory Center. - [Splunk](https://securestrux.com/resources/cyber-advisory-center/category/splunk/) - Splunk resources from the Cyber Advisory Center. - [SIPRNet / NIPRNet](https://securestrux.com/resources/cyber-advisory-center/category/siprnet-niprnet/) - SIPRNet / NIPRNet resources from the Cyber Advisory Center.