Video Resources for CMMC Compliance
-

CMMC FAQ: If I’m NIST 800-171 compliant, am I CMMC Level 3 compliant as well? Video
Similarities and differences between NIST 800-171 and CMMC Level 3. This 2+ minute CMMC FAQ video answers the question: Is NIST 800-171 compliance synonymous with CMMC Level 3? They’re similar and even congruous, but CMMC Level 3 is more involved. Kyle discusses the differences and gives insight on what else is needed. Read More »
-

Phishing Training Video 3: The Fake Financial Report Video
This 4 1/2 minute Phishing Email Training Video-03 is the third in our FREE Phishing Email Training Video series. We review a “real world” phishing email example and show how to recognize them; so you don’t fall victim to hackers and personal identity theft. We’re going to go through another phishing email example today in… Read More »
-

Phishing Training Video 2: The bogus FRANPRIX Email
Our Phishing Training Video-02 is a 4-minute video in our FREE cybersecurity training series. It demonstrates a “real world” phishing email currently in wide circulation around the internet – The bogus FRANPRIX.Com email scam; and shows how to identify and distinguish phishing attacks from legitimate emails. Let’s look at a real Phishing scam We are… Read More »
-

Web Application and API Vulnerabilities Video
This web application and API vulnerabilities webinar was presented by Kyle Lai on 07/18/2020 at CISO Platform – a 40,000 member international community dedicated to information security (www.cisoplatform.com) 43% of all data breaches were through hacker attacks on web applications in 2019. And that’s more than twice as many as reported in the 2018 (Verizon… Read More »
-

Continuous Vulnerability Management Service Video
Continuous Vulnerability Management Service also known as Continuous Monitoring: The traditional security assessment formula has become stale and obsolete. And some companies perform vulnerability assessments or Penetration Tests (PenTest) only once each year. Once each year isn’t enough because technology advances in modern society have made us more interconnected and software reliant. New technology frequently… Read More »
-

Phishing Training Video 1: The Fake DHL (Video)
KLC Consulting’s FREE Phishing Training-01 Video. This 4+ minute video, the first in our FREE cybersecurity training series, demonstrates a “real world” phishing email currently in wide circulation around the internet, and shows how to identify and distinguish phishing attacks from legitimate emails. A Real Phishing Email Example What you are seeing is a real… Read More »
-

Current Trends in Data Breaches
Current Trends in Data Breaches Video (Episode#002). We discuss the current trends in data breaches from unsecure web application design, cloud misconfigurations and phishing email attacks; as reported in Verizon’s 2020 Data Breach Investigation Report (DBIR). And Kyle gives recommendations on how to develop strategy to mitigate those risks. Read More »
-

IDOR Vulnerabilities In Web Applications Video
IDOR Vulnerabilities in Web Applications (Insecure Direct Object Reference) Chances are they’re alive and well in your web applications. The bad news is – if you’re foregoing source code reviews by a security professional and relying on automated scanning tools to detect them, you’re out of luck; you won’t find them. But hackers do. And… Read More »
-

Hacking Web Applications and APIs Video
This Hacking Web Applications and APIs Video talks about how to prevent cybercriminals from hacking web applications and API’s: Why are they difficult to secure? And what are the risks from these attacks? How do we improve application security Read More »
Feeling Overwhelmed by CMMC?
Download our essential guide to gain a clear roadmap through every phase of a CMMC Assessment. From foundational preparation and scope definition to navigating the assessment day and understanding post-audit requirements. Don’t leave your CMMC Level 2 success to chance.


Don’t Let Your Security Posture Drift
The Phase II suspension changed the third-party assessment timeline, not the underlying obligation to protect CUI. Use this period to verify your scope, close known gaps, align documentation with implementation, and ensure your SPRS submission accurately reflects your environment.




