Field Notes

Compliance and secure infrastructure, without the markup.

The Requirement Never Moved. Only the Markup Did

The DoW suspended CMMC Phase 2, but NIST 800-171 and DFARS 7012 obligations remain. What changed, what did not, and the five things defense contractors should do before the August 14 RFI deadline

Hector Velez

What does CMMC Level 2 actually require for cloud-hosted CUI?

A direct, sourced answer to the question defense contractors keep asking: what CMMC Level 2 requires when your Controlled Unclassified Information lives in the cloud.

Hector Velez

Open Letter: To Government Contractors Navigating the Microsoft Crisis

An open letter to the government contracting community from Hermathena Labs You Weren’t Wrong. You Were Misled. To every government contractor currently facing questions about your Microsoft GCC-High cloud decisions: You made the right choice with the information you had. It’s time someone said...

Hector Velez

6 Essential Microsoft 365 Tools for Your Insider Threat Program

​In today’s digital workplace, the risk from insider threats continues to grow. Whether it’s an employee accidentally leaking sensitive information or a malicious actor deliberately stealing company data, organizations need robust monitoring systems to detect and respond to these threats...

Hector Velez

CMMC Compliance Checklist: How to Get More From Secure Cloud Enclaves

Security is on everyone’s mind, what with the upcoming Q2 CMMC compliance requirements for businesses working with the government about to drop. However, the world’s digital landscape is already facing a significant threat as machine learning (ML) continues to empower malicious actors to be more...

Hector Velez

Data Security Tools and Best Practices for Sensitive Research and Development

In the world of R&D, data security challenges can be extremely costly. For example, fines for a single HIPAA violation can cost up to $71,162, which means that you may find maintaining data security to be more of a priority than otherwise. So, how can you ensure that you have the right data...

Hector Velez

Changing Digital Threats: How Has Generative AI Affected Security?

According to training firm SoSafe, one in five people clicks on AI-generated phishing emails. This stat alone emphasizes the importance of leveraging digital systems to empower people to detect phishing attempts themselves. However, generative AI has also simultaneously advanced the power of...

Hector Velez

How Can a Cloud Security Framework Help You Reach Compliance Goals?

There’s no shortage of criminals looking to procure sensitive business data. They’ll take any opportunity they can to steal information and cause disruption.As a result, the cybercrime industry is estimated to cost the world over $10 trillion USD annually by the end of 2025. Adhering to industry...

Hector Velez

NIST 800-171 Compliance Checklist: Who Needs to Follow It?

Millions of pieces of controlled unclassified information (CUI) are stored in the system you use for the US Department of Defense (DoD). The thought of a security breach exposing this information sends a chill down your spine. Research shows that cyber-attacks occur every 39 seconds. Data...

Hector Velez

Machine Learning in Cybersecurity: Ways to Build Stronger Protections

We cannot avoid the increase of machine learning (ML) and AI, which will boost every aspect of our digital lives, both good and bad. It is already occurring, with GovTech estimating that 17% of all cyberattacks will involve generative AI by 2027. However, cybersecurity is growing to meet this...

Hector Velez

Guide: Enabling Multi-Factor Authentication on MS365 for Small Businesses

Enhancing the security of your business’s digital assets should be non-negotiable, especially as cyber threats continue to proliferate. Multi-Factor Authentication (MFA) stands as a potent defense mechanism, one that significantly fortifies access to your most critical systems. This guide,...

Hector Velez

The Importance of Multi-Factor Authentication in MS365: Best Practices for Small Businesses

In the digital age, where data is a prime commodity, safeguarding your business against cyber threats is paramount. One of the most effective methods to protect your business’s sensitive data is through Multi-Factor Authentication (MFA). This blog post will delve into the importance of MFA in a...

Hector Velez

The Top 3 Cybersecurity Risks for Small Businesses in the Defense Industrial Base

As we navigate through 2023, small businesses within the Defense Industrial Base (DIB) face an ever-evolving landscape of cybersecurity threats. It is imperative to understand and mitigate these risks to protect sensitive data and maintain business continuity. This article will highlight the top...

Hector Velez

4 Ways to Prevent Insider Threats and Attacks

Online protection is nothing to take lightly. Prepare yourself and learn several ways to prevent insider threats and attacks.

Hector Velez

How to Leverage Online Behavior for Insider Threat Detection

Protect yourself by detecting insider threats before they happen. Continue reading to learn how to leverage online behavior to detect insider threats.

Hector Velez

The Role of Machine Learning in Cyber Security: A Beginner’s Guide

Understanding the role machine learning plays in cyber security can keep your assets and information safer. Learn more in our beginner’s guide.

Hector Velez

The Ultimate Guide to Phishing Prevention

Phishing prevention requires a two-part strategy involving both machines and the human factor. Learn everything you need to know in our ultimate guide now.

Hector Velez

What Are the Different Types of Insider Threats?

Did you know there is more than one type of insider threat? Learn about the different types of insider threats and prevent them from happening.

Hector Velez

Trends of Insider Threats and Attacks

One way to fight back against insider threats and attacks is to spot them ahead of time. To learn more read about insider threat and attack trends.

Hector Velez
EDUCAUSE 2026Booth C3 · Sep 29 to Oct 2