Lore & Order Vol. 16: Why Was CMMC Phase II Frozen in Place?

Cyber Trends, Threats, Guides, and News
Lore & Order Newsletters
CLICK HERE TO DOWNLOAD THIS IMAGE & COLOR IT IN!

Welcome to This Month’s Dispatch from Ally Security

Inside: A frost spell halts CMMC Phase II, Asa returns with four fresh threats for your scenario grimoire, and Ally adds free SSO to every user’s inventory. Plus, an invite to our first-ever AppSec-focused TTX Thursday!

Table Talk: Why CMMC Phase II Was Frozen in Place

CMMC Phase II was set to begin on November 10. Upon entering this new chapter, many defense contractors would be summoned before an outside assessor to prove that their cyber armor was fit for battle.

However, the Department of War has cast a spell of freezing and declared a halt on Phase II, citing that the burden was driving small and mid-sized contractors out of the defense realm. While this reasoning is rooted in truth, the plot likely goes deeper.

Too great was the number of contractors who needed outside certification, and there simply weren’t enough assessors to inspect them all. Had Phase II arrived as foretold, the DoW risked casting out suppliers its defenses still depend upon. Worse still, many companies have not yet mended the cracks in their cyber armor or mastered the technical rites required to pass inspection in the first place.

So for now, we remain in Phase I, where contractors must still inspect their own armor and declare it battle-ready. Facilitators can use this as an opportunity to continue leveling up the defense skills of kingdoms they serve through tabletop exercises.

If you need a hand with your next CMMC quest, Ally stands at the ready to assist.

Your allies in IR,

Rob & Scout

Asa's Field Intel: Inspiration for Your Next TTX

1. Sysdig: JADEPUFFER — Agentic Ransomware for Automated Database Extortion

A new threat takes shape in the form of JADEPUFFER, an AI-powered raider that automates database theft and extortion...no human required. Facilitators can use this tale to challenge parties with an enemy that adapts in seconds. Examine JADEPUFFER

2. CrowdStrike: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days

Microsoft’s latest patch spell cures hundreds of flaws that could let attackers gain higher privileges, execute code from afar, or uncover guarded info. Facilitators can use this trove to challenge parties as they identify and mend weak points. Survey the vulnerabilities

3. The Record: Hackers Steal Lidl Customer Data from External Service Provider

Brigands breached a third-party service provider and stole Lidl customer data across three countries. Facilitators can use this tale to test vendor response, delivery of warning scrolls to customers, and the phishing attacks that may follow. Review the breach chronicle

4. BleepingComputer: Accenture Confirms Breach After Hacker Offers Stolen Data for Sale

A thief claims to have plundered Accenture’s source code, cloud keys, and access tokens, offering the haul in a criminal bazaar. Facilitators can use this tale to test how a party takes command of the story while still sealing cracks in the castle walls. Inspect the stolen wares

Ally's Build Chronicle: A Free SSO Upgrade for the Entire Realm

Smithed by Stacey

This may not be the flashiest artifact in the vault, but for a security company, it’s an important one: SSO is now included with every Ally subscription at no additional cost.

It has long vexed us to see basic security protections gated behind higher-priced tiers. So, over the past several weeks, we rebuilt Ally’s identity system stone-by-stone, allowing every customer to add SSO to their inventory at no extra charge. Out of the box, Ally now supports Okta, Entra, Google, and other identity providers.

Email us to configure SSO for your Ally instance.

End of Turn

We’ve uncovered the deeper tale behind CMMC’s deep freeze, added four fresh threats to the TTX arsenal, and slotted free SSO into Ally accounts. See you in the next one, fellow traveller!

About Ally Security

Ally is here to support facilitators, which in turn creates a virtuous cycle where exercises take less time, provide more value, are run more frequently, and can make every organization can be better prepared.

Book a demo!
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Have a great IR story? Tell Asa!

The unexpected wins. The client curveballs. The chaos you couldn’t have scripted if you tried. Dear Asa is your space to share the stories that don’t make it into the official post-incident report. Script, submit, and enjoy a chance to be featured or quoted in an upcoming post.

Share my story