CMMC Paused But Not Forgotten If you work anywhere near the defense industrial base (or spend your days tracking federal cybersecurity mandates just for fun like I do), the recent headlines around the Cybersecurity Maturity Model Certification (CMMC) probably gave you a sudden case of deadline-induced deja vu. Just as organizations were revving their engines […]
Learning How to Build A Cybersecurity Program: Lessons from The Princess Bride
Learning How to Build A Cybersecurity Program: Lessons from The Princess Bride Everything I know, I’ve learned from The Princess Bride. It’s how I landed my first job, played a key role in my wedding proposal, and inspired me to learn how to swordfight, which led to an Olympic Gold Medal. I’ll let you figure […]
Death, and Disruption of Your Cyber Supply Chain
Two Things Are Certain in Life 1) Death, and 2) Disruption of Your Cyber Supply Chain Benjamin Franklin famously wrote that nothing in this world is certain except death and taxes. If Ben were around today managing an enterprise IT network, he’d almost certainly add a third item to that list: supply chain disruption. We […]
Second Renaissance Contract Award: Cybersecurity Services for North Carolina
Second Renaissance was awarded a State-wide IT Contract for the State of North Carolina in August 2026. The Cybersecurity Professional Services Contract (RFP DIT 500874-001) is administered by the North Carolina Department of Information Technology (NCDIT).
Why Are Cybersecurity Compliance Tools Called GRC?
If you’ve ever shopped around for cybersecurity software or sat through an IT strategy meeting, you’ve almost certainly run into the acronym GRC. And let’s be honest: Governance, Risk, and Compliance is a mouthful of corporate jargon that feels completely disconnected from the actual day-to-day reality of stopping hackers. It sounds like something invented by […]
Why Should I Care About Cyber Threats as a Small Business?
If you run a small-to-medium-sized business, it’s easy to look at major cybersecurity news like breach headlines involving fortune 500 corporations or global infrastructure and think, “That doesn’t apply to me. Why would a hacker target my business when there are bigger fish in the sea?” It’s a natural assumption, but unfortunately, it’s also one […]