-

10 Mistakes CISO’s Make in Vulnerability Management
KLC Consulting’s president, Kyle Lai, recently shared his insights in CSO Magazine about the 10 most common pitfalls CISO’s make when trying to keep their vulnerability management up to snuff. The number of unpatched vulnerabilities identified have risen anywhere from 27% to 60% over the past several years. This comes as no surprise to cyber… Read More »
-

CMMC News Flash for Defense Contractors
DOD: Failure to implement NIST 800-171 may be a material breach The Department of Defense, (DoD), takes the protection of controlled unclassified information, (CUI), on contractor information systems seriously. On June 16, 2022, the DOD warned that failure to comply with DFARS 7012 and 7020 (submission to SPRS), may result in contract termination by your contract officers. Contractors… Read More »
-

CMMC Podcast Event
Kyle Lai, President and CISO of KLC Consulting, was thrilled to be interviewed along with Carter Schoenberg, VP of Cybersecurity at SoundWay Consulting, on the cuicktrac podcast to discuss the common CMMC 2.0 Scenarios and key strategies for organizations seeking CMMC certification. Thanks to Derek White, Co-Founder and Director at cuicktrac for leading the lively… Read More »
-

DoD DFARS Clauses Explained Video
This 1m video features Kyle Lai explaining the differences between these DFARS clauses for DoD Prime and Subcontractors DFARS Clauses applicable to DoD Defense Industrial Base Companies U.S. DoD cybersecurity expert Kyle Lai presents this DoD DFARS Clauses Explained video. Some people are confused about the requirements of DFARS 252.204-7012, 7020, and 7021. Or cybersecurity… Read More »
-

DFARS Flow Down Requirements Video
This 2m video features Kyle Lai explaining DFARS flow down requirements for DoD Prime and Subcontractors DFARS Flow Down Requirements Video (Continued) Recent questions about Flow Down Requirements Let’s discuss a couple of questions related to the flow-down requirements for DFARS 252.204-7012, 7020, and 7021. Or cybersecurity maturity model certification, or CMMC. First question: Flow… Read More »
-

CMMC News Flash – Russia & Town Hall
KLC Consulting keeps you up-to-date with what’s happening on the front lines of CMMC and NIST 800-171 in our role as a CMMC-AB cleared candidate C3PAO. CISA Issues “Shields-Up Alert” CISA (Cybersecurity & Infrastructure Security Agency) issued a Shields-Up cybersecurity alert to all Defense Industrial Base (DIB) companies in response to increasing cyber threats from… Read More »
-

CMMC with Microsoft Azure
Kyle LaiPresident and CISOKLC Consulting, Inc.CISSP, CSSLP, CISA, CDPSE, CIPP/US, CIPP/G, ISO 27001 Lead Auditor CMMC with Microsoft Azure discussion points: I still receive questions about which versions of (Microsoft) Azure support CMMC, NIST 800-171, and DFARS 252.204-7012: In short – it depends: Federal Contract Information (FCI): Requires CMMC Level 1 – Azure Commercial meets… Read More »
-

Map ISO 27001 to CMMC
ISO 27001 greatly reduces effort in CMMC 2.0 Level 2 compliance KLC Consulting‘s guide to Map ISO 27001 to CMMC If you have an ISO 27001 certification, it doesn’t mean you are compliant with CMMC 2.0 Level 2. But you can map ISO 27001 to CMMC and obtain CMMC compliance in less time and with… Read More »
-

Ransomware Trends and Risks Briefing
KLC Consulting provides updates on the latest ransomware trends and risks briefing, so check back often. Trends Challenges What Should A Company Do? 1 State of Ransomware 2021 by Sophos2 NY Times3 Wall Street Journal4 Bloomberg5 Bloomberg Read More »
Feeling Overwhelmed by CMMC?
Download our essential guide to gain a clear roadmap through every phase of a CMMC Assessment. From foundational preparation and scope definition to navigating the assessment day and understanding post-audit requirements. Don’t leave your CMMC Level 2 success to chance.


Don’t Let Your Security Posture Drift
The Phase II suspension changed the third-party assessment timeline, not the underlying obligation to protect CUI. Use this period to verify your scope, close known gaps, align documentation with implementation, and ensure your SPRS submission accurately reflects your environment.



