CLICK HERE TO DOWNLOAD THIS IMAGE & COLOR IT IN!Inside: A frost spell halts CMMC Phase II, Asa returns with four fresh threats for your scenario grimoire, and Ally adds free SSO to every user’s inventory. Plus, an invite to our first-ever AppSec-focused TTX Thursday!


CMMC Phase II was set to begin on November 10. Upon entering this new chapter, many defense contractors would be summoned before an outside assessor to prove that their cyber armor was fit for battle.
However, the Department of War has cast a spell of freezing and declared a halt on Phase II, citing that the burden was driving small and mid-sized contractors out of the defense realm. While this reasoning is rooted in truth, the plot likely goes deeper.
Too great was the number of contractors who needed outside certification, and there simply weren’t enough assessors to inspect them all. Had Phase II arrived as foretold, the DoW risked casting out suppliers its defenses still depend upon. Worse still, many companies have not yet mended the cracks in their cyber armor or mastered the technical rites required to pass inspection in the first place.
So for now, we remain in Phase I, where contractors must still inspect their own armor and declare it battle-ready. Facilitators can use this as an opportunity to continue leveling up the defense skills of kingdoms they serve through tabletop exercises.
If you need a hand with your next CMMC quest, Ally stands at the ready to assist.
Your allies in IR,
Rob & Scout


A new threat takes shape in the form of JADEPUFFER, an AI-powered raider that automates database theft and extortion...no human required. Facilitators can use this tale to challenge parties with an enemy that adapts in seconds. Examine JADEPUFFER
Microsoft’s latest patch spell cures hundreds of flaws that could let attackers gain higher privileges, execute code from afar, or uncover guarded info. Facilitators can use this trove to challenge parties as they identify and mend weak points. Survey the vulnerabilities
Brigands breached a third-party service provider and stole Lidl customer data across three countries. Facilitators can use this tale to test vendor response, delivery of warning scrolls to customers, and the phishing attacks that may follow. Review the breach chronicle
A thief claims to have plundered Accenture’s source code, cloud keys, and access tokens, offering the haul in a criminal bazaar. Facilitators can use this tale to test how a party takes command of the story while still sealing cracks in the castle walls. Inspect the stolen wares



Smithed by Stacey
This may not be the flashiest artifact in the vault, but for a security company, it’s an important one: SSO is now included with every Ally subscription at no additional cost.
It has long vexed us to see basic security protections gated behind higher-priced tiers. So, over the past several weeks, we rebuilt Ally’s identity system stone-by-stone, allowing every customer to add SSO to their inventory at no extra charge. Out of the box, Ally now supports Okta, Entra, Google, and other identity providers.
Email us to configure SSO for your Ally instance.
.webp)


We’ve uncovered the deeper tale behind CMMC’s deep freeze, added four fresh threats to the TTX arsenal, and slotted free SSO into Ally accounts. See you in the next one, fellow traveller!
About Ally Security
Ally is here to support facilitators, which in turn creates a virtuous cycle where exercises take less time, provide more value, are run more frequently, and can make every organization can be better prepared.
The unexpected wins. The client curveballs. The chaos you couldn’t have scripted if you tried. Dear Asa is your space to share the stories that don’t make it into the official post-incident report. Script, submit, and enjoy a chance to be featured or quoted in an upcoming post.
