Skip to main content
search
CybersecurityPodcastPodcasts

Cybersecurity Best Practices for Manufacturers: Stay Sharp Episode 57

By November 11, 2024December 17th, 2025No Comments

In Episode 57 of Razorleaf’s Stay Sharp podcast, Understanding the Cybersecurity Maturity Model, co-hosts Jen Ferello and Jonathan Scott are joined by the Vice President of Razorleaf Government Solutions, Steve Nichols. The trio tackle cybersecurity, which is a hot topic, particularly for the Defense Industrial Base (DIB)—the worldwide network of organizations, facilities, and resources that provides the U.S. military with everything it needs to operate. Together, Steve, Jen, and Jonathan discuss why securing your digital information is so important, what kind of regulations exist, and how to get started with cybersecurity in your own organization.

Eyeing the Cybersecurity Landscape

While cybersecurity is an everyday concern for the Department of Defense (DOD) and the DIB, its value also extends to commercial organizations. “The fact is that the more data that is digital, the easier it is to actually steal,” Jen points out. “Commercial data is every bit as important. It’s every bit as important to protect that data as it is that our country protect our defense data.”

For obvious reasons, the DOD has taken the lead on creating guidance for private industry processes and programs “to have more of a digital framework, but a digital framework which drives efficiency and collaboration and some of the other things they’re really trying to get to—speed-to-fleet, speed-to-resource, those kinds of things,” Steve explains. The DOD is focused on the DIB, which has far ranging implications, since it involves defense contractors and every manufacturer throughout the supply chain, down to the smallest businesses.

To assist all of those manufacturers, the DOD developed the Cybersecurity Capability Maturity Model (C2M2) and the Cybersecurity Maturity Model Certificate (CMMC), which reference a “common framework and common foundation for supplying information and having access to that information to do their jobs,” says Steve. The model now has a number of different levels, from basics, to low, to high. “Some of these things we can meet ourselves,” Steve notes,” while for some of them we need an outside assessor to certify that a company has met certain requirements.”

Who Needs C2M2/CMMC?

While the DOD requires some maturity from its entire ecosystem of suppliers, the regulations they developed are becoming important to the commercial industry as well, because they provide a structure for the kinds of internal discussions companies need to have about securing their data and intellectual property.

What’s so broadly useful about the C2M2, Steve says, is that “it gives you IT security in bite-sized chunks that smaller or mid-sized groups can actually start to tackle. And it drives that conversation.” Plus, it’s free, and its available in a variety of formats, from 8 bullet points up to dozens of pages, to make it easy for everyone to consume. He explains, “This is a great foundational piece for your IT discussion—internal, external, whatever that happens to be—to say, are we meeting basic requirements here?”

How to Get Started

The trio want to make it clear that though the cybersecurity maturity model can be long, involved, and pretty complex, companies “shouldn’t put all of this in one big, scary bucket of, oh my goodness, I can’t tackle it. Everything here is approachable, but it’s understanding what applies to you,” Jonathan says. “This doesn’t have to be overwhelming,” Steve agrees. “Don’t try and boil the ocean at once. Let’s just start with a couple steps moving forward and then take a couple more.”

Jonathan adds a caution about anyone you might be working with to address some of these cybersecurity questions, saying, “The folks that you’re having that conversation with should be knowledgeable enough to give it to you in a way you can consume and understand—even if you’re not an IT expert—why that’s valuable.” If they can’t talk with you about steps and processes for improving your cybersecurity, whether they’re using unintelligible language or making you think you need to tackle the entire project at once, you might be talking with the wrong people.

Ultimately, Jen says, the value of exposure to and some understanding of the cybersecurity maturity model is “being more intentional and aware about the data that you have and how to protect it. The DOD is certainly leading in this area, and there’s a lot to be learned from them.”

Learn More About How Cybersecurity Might Affect You

The full podcast contains more discussion and details on a variety of topics, including how the maturity model might impact how you look at or choose the digital tools you use, how its requirements complement ITAR and EAR requirements (p8), how to balance your organizations need for collaboration and the sharing of ideas with your need to protect your data and IP, and more.

Check out the full conversation in Stay Sharp Episode 57: Understanding the Cybersecurity Maturity Model, and join us each week for a new podcast.

Follow the Razorleaf Podcast, Stay Sharp in Digital Engineering on:

Close Menu