-

More than 87% of Pentagon Supply Chain Fails Basic Cybersecurity Minimums

First ever independent study of the Defense Industrial Base (DIB) shows that federal contractors are not properly securing military secrets

RESTON, Va.--(BUSINESS WIRE)--Defense contractors hold information that's vital to national security and will soon be required to meet Cybersecurity Maturity Model Certification (CMMC) compliance to keep those secrets safe. Nation-state hackers are actively and specifically targeting these contractors with sophisticated cyberattack campaigns.

A shocking 87% of contractors have a sub-70 Supplier Performance Risk System (SPRS) score, the metric that shows how well a contractor meets Defense Federal Acquisition Regulation Supplement (DFARS) requirements.

DFARS, which has been law since 2017, requires a score of 110 for full compliance. Critics of the system have anecdotally deemed 70 to be “good enough,” but the overwhelming majority of contractors still come up short.

The first ever comprehensive, independent study of the DIB’s cybersecurity maturity was conducted by Merrill Research and commissioned by CyberSheath, the largest CMMC managed service vendor. The survey data of 300 U.S.-based Department of Defense (DoD) contractors was tested at the 95% confidence level, meaning that there is a 95% probability that significant differences are real and are not due to sampling error. The study was completed in July and August 2022, with CMMC 2.0 on the horizon.

“The report’s findings show a clear and present danger to our national security,” said Eric Noonan, CEO of CyberSheath. “We often hear about the dangers of supply chains that are susceptible to cyberattacks. The DIB is the Pentagon’s supply chain, and we see how woefully unprepared contractors are despite being in threat actors’ crosshairs. Our military secrets are not safe and there is an urgent need to improve the state of cybersecurity for this group, which often does not meet even the most basic cybersecurity requirements.”

Roughly 80% of the DIB doesn’t monitor its systems 24/7/365 and doesn’t use U.S.-based security monitoring services. Other deficiencies were evident in the following categories that are currently required by law and will be required in the future to achieve CMMC compliance:

  • 80% lack a vulnerability management solution
  • 79% lack a comprehensive multi-factor authentication (MFA) system
  • 73% lack an endpoint detection and response (EDR) solution
  • 70% have not deployed security information and event management (SIEM)

These security controls are legally required of the DIB, and since they are not met, there is a significant risk facing the DoD and its ability to conduct armed defense. In addition to being largely non-compliant, an astounding 82% of contractors find it “moderately to extremely difficult to understand the governmental regulations on cybersecurity.”

Additional Resources 

About CyberSheath Services International, LLC
Established in 2012, CyberSheath is one of the most experienced and trusted IT security services partners for the U.S. defense industrial base. From CMMC compliance to strategic security planning to managed security services, CyberSheath offers a comprehensive suite of offerings tailored to clients’ information security and regulatory compliance needs. Learn more at www.cybersheath.com.

Contacts

CyberSheath Services International, LLC
Kristen Morales at Kristen.Morales@cybersheath.com

CyberSheath Services International, LLC


Release Versions

Contacts

CyberSheath Services International, LLC
Kristen Morales at Kristen.Morales@cybersheath.com

Social Media Profiles
More News From CyberSheath Services International, LLC

CyberSheath Helps Kampi Components Achieve CMMC Level 2 Certification in Complex, Multi-Vendor Environment

RESTON, Va.--(BUSINESS WIRE)--CyberSheath, the largest CMMC managed service vendor, partnered with Kampi Components Co., Inc., a leading military distributor, to achieve CMMC Level 2 certification after addressing complex challenges involving multiple managed service providers. The certification comes as a recent Cyber AB town hall highlighted ongoing confusion about external service provider compliance requirements across the defense industrial base. Kampi’s certification followed an unannounc...

CyberSheath Helps CIS Secure Achieve CMMC Level 2 Certification Ahead Of Schedule

RESTON, Va.--(BUSINESS WIRE)--CyberSheath, the largest CMMC managed service vendor, partnered with CIS Secure, the world leader in secure collaboration solutions, to successfully complete the Cybersecurity Maturity Model Certification (CMMC) Level 2 assessment, earning a perfect score of 110. CMMC Level 2 certification is required for U.S. Department of Defense (DOD) contracts and demonstrates compliance with NIST 800-171 standards for protecting Controlled Unclassified Information (CUI). Accor...

New Study Reveals Only 1% of Defense Contractors Fully Ready for Imminent CMMC Deadline

RESTON, Va.--(BUSINESS WIRE)--With the Cybersecurity Maturity Model Certification (CMMC) final rule set to take effect Nov. 10, a new Merrill Research study commissioned by CyberSheath reveals that just 1% of defense contractors say they are fully prepared for the upcoming assessments. The percentage dipped over the past two years despite CMMC deadlines approaching and signals a dangerous disconnect between contractor confidence and actual preparedness across the Defense Industrial Base (DIB)....
Back to Newsroom