Recent Articles
Brenda Harper • 15 Feb 2026
How Much Risk is Too Much?
Here’s the hard truth. Not all risk can be eliminated. But compliance frameworks like CMMC require you to determine how...
Brenda Harper • 8 Feb 2026
Scoping- #1 Reason for CMMC False Starts
Improper scoping. This is the number one reason that organizations have false starts for CMMC. And without proper scoping, you...
All Articles
Brenda Harper • 29 Jan 2026
The Risk Management Lifecycle
Most organizations make one critical mistake: they treat Risk Management as a single event instead of a continuous process. CMMC...
Brenda Harper • 22 Jan 2026
Understanding Risk- Threats, Vulnerabilities, Impact �...
Do you really understand risk? When assessors evaluate your risk management program, they’re looking for one key thing: Do you...
Brenda Harper • 16 Jan 2026
The Business Case: Why Risk Management Matters
Risk is fundamentally about uncertainty—and uncertainty threatens revenue. Most organizations start risk management because regulatory compliance forces them to—but the...
Brenda Harper • 9 Jan 2026
How NIST 800-30 Supports CMMC Compliance
Did you know the U.S. government has already created an excellent methodology for CMMC-compliant risk assessment? It’s called NIST Special...
Brenda Harper • 2 Jan 2026
Risk Management – Not Optional
Many companies still think that Risk Management is just a casual conversation over coffee in the break room. But in...
Brenda Harper • 20 Nov 2025
No MFA… And No Password!
I was recently on a CMMC assessment where the company had an Ubuntu machine. I asked them to log on...