EPISODE · Oct 6, 2024 · 20 MIN
CMMC, HIPAA, Insurance, and the Future of Security Standards with Craig Petronella
from Business of Tech: Daily 10-Minute IT Services Insights · host Dave Sobel
Host Dave Sobel welcomes Craig Petronella, founder of Petronella Technology Group, to discuss the evolving landscape of technology compliance and cybersecurity. With a focus on the Cybersecurity Maturity Model Certification (CMMC), Craig highlights its significance for defense industrial base contractors and its potential to streamline compliance across various industries. He emphasizes that while regulations like HIPAA and FTC compliance exist, they often lack a consistent framework, leading to confusion and non-compliance among businesses.Craig shares his insights on the current state of compliance, noting that many organizations, including those in healthcare, are not adequately meeting regulatory standards. He points out that the CMMC introduces a more rigorous approach, requiring third-party validation for compliance, which could help address the shortcomings of existing frameworks. This shift towards a proof-based model aims to ensure that businesses cannot simply check boxes to claim compliance but must provide evidence of their adherence to security controls.The conversation also delves into the challenges of enforcement and accountability in compliance. Craig argues that without significant consequences for non-compliance, such as losing the ability to operate in certain sectors, many organizations will continue to neglect their security responsibilities. He draws parallels to the driving test analogy, suggesting that just as individuals must demonstrate their driving skills to obtain a license, businesses should be held to similar standards in cybersecurity.Finally, Craig discusses the role of cybersecurity insurance in driving compliance. He explains how insurance companies are increasingly requiring businesses to implement basic security measures, such as multi-factor authentication, to qualify for coverage. This trend reflects a broader movement towards a "don't trust, verify" model, where organizations must take proactive steps to secure their systems. The episode concludes with Craig advocating for a future where AI and third-party validation play crucial roles in ensuring software security and compliance across industries. Supported by: https://www.huntress.com/mspradio/ 💼 All Our SponsorsSupport the vendors who support the show:👉 https://businessof.tech/sponsors/ 🚀 Join Business of Tech PlusGet exclusive access to investigative reports, vendor analysis, leadership briefings, and more.👉 https://businessof.tech/plus 🎧 Subscribe to the Business of TechWant the show on your favorite podcast app or prefer the written versions of each story?📲 https://www.businessof.tech/subscribe 📰 Story Links & SourcesLooking for the links from today’s stories?Every episode script — with full source links — is posted at:🌐 https://www.businessof.tech 🎙 Want to Be a Guest?Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:💬 https://www.podmatch.com/hostdetailpreview/businessoftech 🔗 Follow Business of Tech LinkedIn: https://www.linkedin.com/company/28908079YouTube: https://youtube.com/mspradioBluesky: https://bsky.app/profile/businessof.techInstagram: https://www.instagram.com/mspradioTikTok: https://www.tiktok.com/@businessoftechFacebook: https://www.facebook.com/mspradionews Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Embed this episode
NOW PLAYING
CMMC, HIPAA, Insurance, and the Future of Security Standards with Craig Petronella
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.