SIG SAUER - Never Settle

Archive for the ‘Cyber’ Category

Independent C3PAO Assessment Provides Real-World Validation of Avatara’s Platform-Based Approach to CMMC Level 2

Wednesday, August 19th, 2026

ST. LOUIS and CHESAPEAKE, Va., Aug. 17, 2026 — Avatara, a provider of compliant IT systems-as-a-service, and AVMAC LLC (AVMAC), an aviation and maritime technical services company supporting the U.S. Department of War (DoW), today announced that AVMAC has achieved Cybersecurity Maturity Model Certification (CMMC) Level 2 using Avatara Platform for Government, receiving a maximum score of 110 with no Plan of Action and Milestones (POA&Ms).

“AVMAC is proud to achieve this important milestone,” said Bert Ortiz, Founder, President and CEO of AVMAC. “Avatara Platform for Government supports all 110 CMMC Level 2 controls, while allowing us to inherit approximately 80% of the 320 underlying assessment objectives on Day 1. Achieving this critical milestone validates our hard work and reinforces our commitment to safeguarding Controlled Unclassified Information (CUI) within the defense supply chain.”

AVMAC’s independent CMMC Level 2 assessment was conducted by a leading C3PAO assessment team, validating the company’s implementation of the security requirements necessary to protect CUI. Avatara Platform for Government served as the secure IT foundation for AVMAC’s environment.

“AVMAC’s achievement is a powerful real-world validation of the model we’ve built at Avatara,” said Rob McCormick, founder and CEO of Avatara. “We built Avatara Platform for Government so defense contractors can operate within a secure, compliant foundation and inherit a significant portion of the technical responsibility rather than assembling a compliant environment themselves. AVMAC’s success demonstrates what this model can achieve when paired with a committed, prepared and collaborative customer.”

For AVMAC, achieving CMMC Level 2 represents more than meeting a cybersecurity requirement. It gives customers, prime contractors and government contracting organizations independent verification that AVMAC has implemented the required safeguards for handling CUI.

“Independent verification creates another level of trust,” Ortiz said. “When the Department paused the transition to Phase 2 for a 60-day review, we decided to keep moving forward because these cybersecurity responsibilities aren’t going away. Other companies may be waiting to see what happens next, but we’ve already crossed the line. For us, that is a significant competitive advantage.”

From Compliance Readiness to Independent Validation

AVMAC began preparing for CMMC well before formal assessment requirements reached the company. As the longtime defense contractor grew, it needed to move beyond a decentralizedapproach to IT while keeping pace with evolving cybersecurity requirements that would increasingly determine eligibility for DoW business. For Ortiz, a 31-year U.S. Navy veteran, that meant finding a model that did not require AVMAC to build and manage complex compliant infrastructure or expand a dedicated internal IT organization.

AVMAC selected Avatara Platform for Government to consolidate its IT environment into a centralized, secure, compliant foundation for its CMMC journey. Built for organizations operating in highly regulated industries, the platform replaces fragmented tools, vendors and legacy infrastructure with one secure, all-inclusive environment designed to address cost, complexity and compliance.

“CMMC becomes significantly more manageable when security and compliance are engineered into the IT environment from the beginning,” said Brandon DiMemmo, Vice President of Product at Avatara. “Avatara Platform for Government provides customers with a centralized, standardized environment where infrastructure, security controls and operational processes are designed to work together as a system. That platform model enables customers like AVMAC to inherit much of the technical implementation required for CMMC rather than having to assemble and manage those capabilities piece by piece.”

Throughout the process, Avatara played a central role in helping AVMAC align the platform’s inherited safeguards with the company’s remaining responsibilities, updating documentation, clarifying scope and preparing for the C3PAO assessment.

Avatara Platform for Government achieved FedRAMP Moderate Equivalency in April 2026, establishing the platform foundation for organizations handling sensitive defense data. Avatara subsequently launched its Mission Ready Offering (MRO), combining compliant infrastructure, operational support, documentation acceleration and C3PAO assessment coordination to help defense contractors move toward assessment readiness faster and with greater predictability.

Owl Cyber Defense Launches XD Air 6: Portable Kiosk Catches Zero-Day Threats Signature-Based Tools Miss

Friday, August 14th, 2026

XD Air 6, a rugged kiosk built to perform where standard hardware doesn’t hold up, empowers government agencies to evaluate file safety faster, using a known-good approach.

COLUMBIA, MD, August 12, 2026 – Owl Cyber Defense®, a global market leader in hardware-enforced cross domain and data diode network security solutions, today announced the launch of XD Air™ 6, an all-in-one portable kiosk built to inspect and sanitize files transported via portable media and stop threats that conventional antivirus cannot catch. XD Air 6 evaluates an extensive number of file types and media using a known-good approach to catch zero-day exploits and targeted attacks before they ever reach a network, giving security teams confidence in every file that crosses the boundary.
 
“XD Air 6 answers a simple question: how do you know a file is safe before it ever gets inside,” said Tim Fahl, CTO of Owl Cyber Defense. “Most security tools only catch what they’ve already seen before. XD Air 6 is purpose-built to take a different approach, checking each file meets our expectations, so zero-day exploits and targeted attacks get caught before they ever reach a sensitive environment. For the defense and high-assurance mission we support, that’s the difference between hoping a file is safe and knowing it is.”
 
XD Air has already proven itself across an extensive range of government and critical infrastructure applications worldwide; XD Air 6 builds on that trusted foundation with a new generation of file inspection and sanitization capabilities. It pairs multiple antivirus scanners with dual Content Disarm and Reconstruction (CDR) engines, powered by industry-leading providers including Glasswall and PuriFile®. Each engine is individually licensable, so organizations can match protection to their own mission needs and budget. XD Air 6 runs on a hardened operating system and is powered by Panasonic’s rugged Toughbook 40, bringing full protection to secure facilities, forward operating locations, and tactical environments without asking teams to sacrifice reliability for portability. Together, these capabilities give security teams a single, repeatable checkpoint that keeps malicious and mobile content out of the world’s most sensitive networks, without slowing operators down or adding new training burden.
 
To learn more about XD Air 6, reach out to our team today.

President Trump Issues National Security Memorandum Authorizing Private Sector to Combat Cyber Crime

Thursday, August 13th, 2026

With the issuance of the National Security Presidential Memorandum for Expanding Capabilities To Combat Transnational Cyber-Enabled Crime, dated 12 August, cyber privateering seems to be on the table.

This new action expands on Executive Order 14390 of March 6, 2026 (Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens), from the Federal Government taking no various actions to combat cyber-enabled crime harming American citizens to incorporating the ingenuity of the private sector. 

The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States.  Yet, American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace.  Thus, it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime.  By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens.

The program will authorize Participating Companies to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs), under the control and oversight of the Federal Government.

The NSPM also establishes a framework where private sector companies that willingly participate in the program are encouraged to enter into agreements with other private entities as well Federal, State, Local, Tribal, and Territorial agencies to gather TCO threat information and propose cyber operations that address those threats.

In a fact sheet issued by the White House several sobering statistics were offered to explain why this course of action is being taken:

  • The most vulnerable among us—seniors, children, and low-income families—are disproportionately targeted, with scammers draining life savings, stealing the benefits of years of work, and destroying lives.
  • In 2025, American consumers reported losing more than $20.8 billion to cyber-enabled crime.
  • 73% of U.S. adults have experienced some kind of online scam or attack and 98% of Americans believe scams pose a threat to individuals in the U.S., with two-thirds saying it is a “major” threat.
  • One in seven young people who experienced sextortion as a minor reported harming themselves in response to the abuse. Until now, outdated frameworks, gaps in coordination, and the absence of meaningful consequences have allowed these networks to thrive.

Implementing details to follow as they become available.

Cyber Soldiers Collaborate on Drone Dominance

Saturday, July 18th, 2026

FORT GORDON, Ga. – Developers from the Hardware Section of Cyber Solutions Development-Maryland, 780th Military Intelligence Brigade (Cyber), recently collaborated with developers from the 11th Cyber Warfare Battalion’s CSD-Tactical on a project to increase the Army’s drone warfare capabilities.

The project, which spanned more than a year, aligns with the Army’s “Transforming in Contact” initiative, which aims to modernize the battlefield by rapidly delivering new technology into the hands of Soldiers. Drone warfare has become one of the most significant battlefield innovations in recent years, with several countries scrambling to develop increasingly advanced drone technology following the outbreak of the war in Ukraine.

This project required developers to work across several technical domains, including embedded systems, radio-frequency engineering, 3D printing, networking systems and more. Developers from CSD-Maryland collaborated with CSD-Tactical through shared code repositories, hundreds of remote meetings and numerous TDY trips.

The project culminated with a visit to U.S. Army Cyber Command by the Secretary of the Army, Honorable Daniel P. Driscoll, on March 26. CSD-Maryland’s Hardware Section traveled to Fort Gordon, Georgia, to demonstrate the numerous capabilities developed over the previous year.

The drone demonstration was conducted alongside the 11th CWB’s Expeditionary Cyber and Electromagnetic Activities Teams which showcased their ability to provide battlefield lethality through cyberspace operations. Developers from CSD-Maryland demonstrated to the Secretary Driscoll; ARYCYBER Commanding General Lt. Gen. Christopher L. Eubank and other senior leaders their ability to simultaneously deploy three autonomous 3D printed vertical take-off and landing drone systems and corresponding software solutions developed entirely in-house.

This project, which originated at CSD-Maryland, was fully transitioned to the 11th CWB shortly after the demonstration, enabling the battalion to continue developing and employing the capability. The impact of this effort extends beyond cyber units. The project was designed not only for use by electromagnetic activities teams within the 11th CWB, but also for potential employment by Army brigade combat teams. This demonstrates how the gap between cyber operations and more traditional combat roles continues to narrow as battlefield technology becomes increasingly advanced.

This evolving battlefield environment makes the task of building combat-ready formations more important than ever, whether through the development of new battlefield capabilities by organizations such as CSD-Maryland and CSD-Tactical or through training in cyber warfare tactics by electromagnetic activities teams. By remaining at the forefront of emerging wartime strategies, including drone warfare and expeditionary cyber operations, the Army’s cyber forces are helping ensure that Soldiers remain prepared to face any adversary in an increasingly complex and dynamic operational environment.

By SPC William Perez, 780th Military Intelligence Brigade (Cyber)

Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements

Wednesday, July 15th, 2026

The Department of War today announces the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which were originally scheduled to come into effect on November 10, 2026. All Phase I self-assessment requirements remain firmly in place. Additionally, the Department will begin a comprehensive review of CMMC aimed at aligning with Secretary of War Pete Hegseth’s Acquisition Transformation System (ATS) directives prioritizing speed to capability, lowering barriers for small, medium, and non-traditional businesses, and replacing bureaucratic compliance with scalable, resilient cybersecurity measures.

Ensuring access to leading-edge commercial capabilities is a critical driver powering the Secretary of War’s operational execution for the “Arsenal of Freedom”. While the current CMMC program was designed to enhance DIB cybersecurity, instead it has created prohibitive compliance costs and bureaucratic burdens. Recent data, including reports from the Small Business Administration (SBA), confirmed that CMMC compliance is forcing innovative companies out of the Defense Industrial Base (DIB) which will delay the delivery of critical capabilities to the warfighters.

“In support of Secretary Pete Hegseth’s directive to reduce compliance barriers for small and medium sized businesses, we are today suspending the CMMC Phase II requirements and initiating a 60-day study of the future of this program,” said DoW Chief Information Officer Kirsten A. Davies. “Robust cybersecurity and operational resilience remain critical to protecting American innovation and supporting warfighter readiness. We believe the DIB can achieve both, while we reduce unnecessary government red tape.”

Effective immediately, the Department will suspend the transition to Phase II requirements of CMMC, as well as pending and future CMMC implementation milestones across the Department of War solicitations and contracts.

“We have a strategic imperative to reduce bureaucracy as we build the world’s strongest Arsenal of Freedom. The CIO’s decision ensures we maintain a strict security baseline while removing paralyzing costs and keeping innovators and competition growing in the defense supply chain,” said Hon. Michael Duffey, Under Secretary of War for Acquisition and Sustainment.

To realign our cybersecurity posture with the principles of the ATS, the Department CIO is establishing a CMMC Reform Task Force to conduct a comprehensive top-to-bottom review of the certification program. This task force will serve as the central hub for synthesizing industry feedback from our public Request for Information (RFI) regarding compliance challenges. Using these insights, the team will recommend realistic, scalable security measures that prioritize speed to capability and lower barriers for small and non-traditional businesses, delivering their final report to the DoW CIO within 60 days.

During this interim period, the Department will enforce cybersecurity compliance with the NIST SP 800-171 Rev 2 standard through self-assessments and select government-led assessments, focusing on tangible cyber hygiene rather than administrative overhead.

It is critical to note that this action does not eliminate the requirement for companies to protect federal data. All defense contractors and subcontractors remain contractually obligated to safeguard covered defense information in accordance with DFARS clause 252.204-7012.

The Department of War remains steadfast in its commitment to securing its digital domain while empowering the DIB to rapidly provide the most advanced capabilities to the warfighter. More information can be found here: dowcio.war.gov/brilliantbasics

Department of War Establishes Cyber Mastery Incentive Pay

Friday, June 12th, 2026

The Department of War (DoW) is launching the Cyber Mastery Incentive Pay (C-MIP) program, a key effort in the Secretary of War’s Project Patriot Pipeline initiative, and an important step toward hardening our cyber defenses and strengthening our Defense Industrial Base capacity to compete in the cyber domain.

C-MIP fundamentally modernizes how the Department incentivizes its Cyberspace Operations Forces (COF) assigned to U.S. Cyber Command. The C-MIP Framework provides DoW a powerful tool to build and drive an elite corps of cyber warfighters ready to dominate in the digital battlespace. As part of the broader Secretary of War-approved CYBERCOM 2.0 effort, C-MIP is a forward-looking, multi-layered incentive framework that promotes domain mastery within our most critical cyber work roles.

“Cyber domain capabilities are high-demand, low-density skill sets critical to our daily warfighting operations. To incentivize our cyber forces and meet both Department of War and Defense Industrial Base needs, we need to shed legacy incentive models and invest directly in our people serving on the digital front lines. C-MIP does this,” said Anthony J. Tata, Under Secretary of War for Personnel and Readiness. “It is a strategic initiative to attract, develop, and retain the specialized workforce needed to counter threats, deter aggression, and dominate the cyber domain.” The C-MIP program moves beyond one-size-fits-all incentive models to a flexible and cumulative system that directly links pay to certified skill mastery and the performance of exceptionally demanding duties.

“C-MIP fundamentally changes our approach by incentivizing the pursuit of deep, technical, and career-long expertise,” said Katie Sutton, Assistant Secretary of War for Cyber Policy. “By breaking down the bureaucratic norms of government incentives, this framework enables increased lethality by driving the skills, roles, and duties most vital to mission success. New incentive frameworks normally take years to develop, but the CYBERCOM 2.0 team has driven this outcome in 60 days. This framework ultimately sends a clear signal to our cyber warriors that the Department values the skills necessary to outpace and prevail against our Nation’s adversaries by incentivizing Service Members’ commitment to cyber domain mastery.”

The C-MIP program features two distinct and cumulative layers:

Skill Incentive Pay (SIP): The foundational layer that directly rewards an individual’s demonstrated work role skill level — Basic, Senior, or Master — established by U.S. Cyber Command (USCYBERCOM). This layer creates a clear and compelling path for our cyber warriors to pursue continuous technical growth.

Special Duty Pay (SDAP): A monthly incentive for members performing duties that USCYBERCOM designates as exceptionally demanding. This pay recognizes the specialists who scale their skills across the force by serving as instructors, certified work role trainers, and in advanced cyber duties.

The Assistant Secretary of War for Cyber Policy (ASW-CP) will oversee the execution of the C-MIP framework. The ASW-CP will closely partner with the Office of the Under Secretary of War for Personnel and Readiness (USW(P&R)), U.S. Cyber Command (USCYBERCOM), and the Military Departments to ensure the framework remains agile to warfighter requirements. General Joshua M. Rudd, Commander of USCYBERCOM, stated, “I’m excited about what C-MIP represents. Our warfighters take on complex missions that demand extraordinary commitment and technical expertise. We need to ensure that commitment is being recognized, especially when our operators step into our most demanding roles.”

Taking effect October 1, 2026, the C-MIP program launches a new era of cyber talent management. By aligning a competitive incentive model with Secretary Hegseth’s strategic vision, the Department of War begins to unleash our Nation’s potential to build and sustain world-class cyber forces for years to come.

ABS Acquires RMC Global to Strengthen Cyber, Risk and Resilience Capabilities

Friday, May 8th, 2026

Acquisition to Deliver Stronger More Integrated Solutions for Clients


Photo Caption (L to R): Vince Kuchar, President, RMC Global, and David Wechsler, President and CEO, ABS Group

(HOUSTON) ABS, through its affiliate ABSG Consulting Inc. (ABS Consulting), has today announced the acquisition of?RMC Global (RMC), a leading provider of industrial cybersecurity, risk management?and resiliency solutions.

The acquisition strengthens ABS Consulting’s capabilities and market position, bringing together two organizations with complementary expertise, shared values and a common mission. Combining RMC’s capabilities with ABS Consulting’s scale, technical depth and global resources, unlocks more integrated solutions for clients operating in increasingly complex risk environments.

ABS Chairman and CEO John McDonald said: “Clients are facing increasing operational risk, cyber threats, and regulatory pressure. Bringing together the expertise of RMC and ABS Consulting strengthens our ability to deliver even greater value and support for our clients through comprehensive, integrated solutions.”

He highlighted that the acquisition is both a strategic and cultural fit. RMC’s strong culture of critical infrastructure protection and industrial cybersecurity aligns closely with ABS Consulting’s focus on protecting people, assets and critical operations around the world.

He said: “ABS and RMC make a strong fit in mission and culture. Both organizations are focused on work with real-world impact. Both value expertise, practical problem solving, and long-term trust. And both are committed to helping protect critical systems, support resilience, and solve complex challenges in environments where the stakes are high.”

ABS Consulting CEO David Wechsler said: “This acquisition builds on priority areas where we see sustained client demand and long-term growth opportunity. The combination strengthens our ability to support our customers’ evolving operational risk, cyber threats, and regulatory demands, while giving us a broader platform to deliver increasingly innovative solutions.”

RMC President Vince Kuchar said: “What brought our organizations together is a shared culture, mission, and purpose: delivering practical, trusted solutions that protect critical infrastructure and critical missions, enabling resilience in the face of growing risk. By joining ABS with its 164-year mission, we are better positioned to support our clients today and to adapt alongside them in the years ahead.”

More information about ABS Consulting is available here. More information about RMC is available here

D-Fend Solutions Named in 2025 Gartner Emerging Tech: Top-funded Startups for Cyber Electronic Defense (CED)

Thursday, February 12th, 2026

RA’ANANA, Israel and MCLEAN, Va., February 12th — D-Fend Solutions, the leader in field-proven radio frequency (RF) cyber-based, non-kinetic, non-jamming counter-drone takeover technology, has been named in the Gartner Emerging Tech: Top-funded Startups for Cyber Electronic Defense (CED).

According to Gartner, in a Key Finding of the report, “commercial counter-drone success hinges on nonkinetic, high-precision counter-unmanned aircraft system (C-UAS) technology. Solutions that can neutralize threats without causing collateral damage or disrupting legitimate civilian communications are favored.”

In a related Recommendation, Gartner advises organizations to “Secure commercial market leadership by prioritizing scalable, nonkinetic mitigation systems that guarantee low collateral damage. Do this by implementing AI-driven sensor fusion to precisely distinguish alien assets from legitimate communication signals and demonstrating practical efficacy.”

According to the report, “the drone detection and mitigation category received significant commercial investment, driven by the reality that inexpensive, widely accessible drones pose threats to private enterprises, energy grids, and public venues. Consequently, investment is heavily focused on companies providing scalable, nonkinetic solutions that can operate within urban and regulatory-sensitive environments without causing collateral damage.”  D-Fend Solutions is an example of one such company.

Regarding Near-term Implications and Actions, Gartner states that “To protect against widely accessible, inexpensive drones in civilian settings, leaders must focus on solutions that are scalable, effective, and nondestructive. Product leaders should prioritize the development of modular, open-architecture C-UAS systems that leverage easily deployable detection sensors.”

Gartner subscribers can access the report here.

Gartner, Emerging Tech: Top-funded Startups for Cyber Electronic Defense (CED), 8 December 2025. GARTNER is a trademark of Gartner, Inc. and/or its affiliates. Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.