Blog
Defense & Sovereignty
-
From Sovereign Trust to Sovereign Data: How XQ Enables Resilient Defense Ecosystems
In a recent article, CGI Defense & Intelligence Global Industry Lead Torsten Bernström argues that resilience is no longer simply an operational…
-
XQ Sovereign Data Governance
How sovereign data governance changes the calculus for organizations operating across jurisdictions — and why the data layer is the only place to enforce it.
-
From Policy to Practice: Operationalizing Data Sovereignty Through Zero Trust
Data sovereignty policies are easy to write and hard to enforce. Zero Trust Data makes enforcement automatic, object-level, and auditable.
-
UAV Data Security: Zero Trust at the Tactical Edge
Unmanned systems generate and transmit ISR data in DDIL environments. XQ ensures that data is encrypted and policy-bound before it ever leaves the platform.
-
CMMC Assessment Postmortem with Chris Haigh of C3PAO Meerkat Cyber
A frank conversation with a C3PAO assessor about where DIB contractors fail CMMC Level 2 — and how data-layer controls close the gaps that perimeter tools miss.
-
Federal Cybersecurity Compliance Is Evolving — And Zero Trust Data Is the Catalyst
CISA, NSA, and OMB are aligning on a data-centric security model. Here is what that means for federal agencies and their contractors.
-
How Zero Trust Data Aligns with the NSA’s Zero Trust Implementation Guidelines
The NSA’s seven pillars of zero trust include a dedicated data pillar — and XQ is the only platform purpose-built to address it at the object level.
-
Meerkat Cyber Achieves C3PAO Certification from the DoD Using XQ Zero Trust Data Protection Platform
Integration with Microsoft Office Secures Email and File Workflows, Enhancing Meerkat Cyber’s Secure C3PAO Enclave
-
Meerkat Cyber Achieves C3PAO Certification Using XQ Zero Trust Data Protection
Meerkat Cyber becomes one of the first C3PAOs to achieve certification using XQ as its core CUI protection layer — a validation of the data-centric CMMC approach.
-
Zero Trust AI for Classified Data: The Future of Secure AI in Federal Enclaves
Federal agencies need AI that can operate on sensitive and classified data without exposing it. XQ’s data-layer approach makes that possible — at IL4, IL5, and beyond.
-
How MSPs Can Streamline CMMC Compliance with XQ Data Protection Policies
For Managed Service Providers (MSPs), supporting defense contractors on their CMMC journey is both a responsibility and an opportunity. The challenge lies…
-
Why GCC Moderate + XQ is Ideal for CMMC Compliance
Bottom Line: GCC Moderate provides the secure cloud foundation, XQ enforces Zero Trust data governance, and together they streamline achieving and…
-
GCC Moderate + XQ ITAR Compliance Implementation Plan
This implementation plan outlines how to leverage XQ’s data sovereignty, geo-fencing, and role-based access controls to make Microsoft’s Government…
-
New CMMC Rule: Treatment of Controlled Unclassified Information (CUI) in Transit
The newly introduced CMMC rule provides clarity on handling CUI during transmission . Specifically, the rule states that a common carrier’s information…
-
ITAR Compliance in the Digital Age: A Zero Trust Approach to Defense Data Security
The International Traffic in Arms Regulations (ITAR) represent one of the most stringent data protection frameworks in existence, governing how…
-
Data Sovereignty and Residency in CMMC Compliance
Under CMMC requirements, data sovereignty plays a critical role in ensuring that Controlled Unclassified Information (CUI) is stored, processed, and…
-
GCC vs. GCC High: Key Differences and CMMC Relevance
Government contractors handling Controlled Unclassified Information (CUI) must choose the right Microsoft cloud environment to meet the requirements of the…
-
CMMC: FedRAMP Requirements for Security Protection Assets
Safeguarding Controlled Unclassified Information (CUI) is a cornerstone of cybersecurity for organizations within the Defense Industrial Base (DIB). As DIB…
-
Position Paper: Why XQ Surpasses PreVeil for CMMC Level 2 Compliance
This position paper demonstrates why XQ Message provides a superior solution to PreVeil for organizations seeking CMMC Level 2 compliance. Key advantages…
-
ZTAG-I, a reference zero trust architecture for the US federal government
The federal government’s journey toward zero trust architecture represents one of the most significant cybersecurity transformations in modern history. With…
-
Data Sovereignty and Resiliency through Zero Trust Data
In today’s global digital economy, data sovereignty isn’t just a regulatory box to check—it’s a strategic imperative. Multinational corporations, government…
-
Data Sovereignty Governance for Secure Cloud Adoption
Control geographic data access everywhere
-
Zero Trust Data Compliance on AWS from Bob Gourley, Derek Doerr, and Junaid Islam
This educational video provides an overview of how #aws reduces the cost and complexity of compliance using a #zerotrust security architecture. This video…
-
Why Microsoft Data Sovereignty Falls Short
Microsoft Azure faces certain data sovereignty shortcomings that organizations need to consider.
-
Free CMMC Scoring Tool
Free and Easy CMMC Scoring Calculator
-
AWS Zero Trust for Government
XQ has been included in #AWS’s Zero Trust for Government Partnership. AWS Partner solutions align with the five functional components of the NIST Zero Trust Framework. XQ fulfills this framework’s Zero Trust Data component, and we’re excited to work with government interests to meet their Zero Trust compliance objectives.
-
Learn about AWS Zero Trust for DoD at the DC Summit
XQ has been included in #AWS’s Zero Trust for Government Partnership. AWS Partner solutions align with the five functional components of the NIST Zero Trust Framework. XQ fulfills this framework’s Zero Trust Data component, and we’re excited to work with government interests to meet their Zero Trust compliance objectives.
-
Preparing For CMMC 2.1 Workshop and Guidance
Unlocking CMMC 2.1 Mastery: A Workshop and Guidance Session with Ingram Micro feat.
-
Navigating the Pentagon’s CMMC 2.0 Announcement: Your Path with XQ
In a recent and significant development, the Pentagon has unveiled a pivotal announcement that carries profound implications for the cybersecurity landscape…
-
XQ Message for DFARS 7012 on Single and Multi-Tenant Storage
Organizations handling Controlled Unclassified Information (CUI) are subject to DFARS 252.204-7012 (AKA DFARS 7012). This clause addresses specific (c)-(g) requirements for cyber incident reporting, NIST SP 800-171 security controls, and stipulates the FedRAMP Baseline Moderate or equivalent standard for organizations using cloud services. XQ and DFARS 7012 Requirements In addition to supporting organizations in meeting CMMC 2.0 technology solutions – 77 of Level 2’s 110 NIST SP 800-171 requirements – XQ accepts and, where applicable, can support users in meeting DFARS 7012 requirements.
-
Strengthening your CMMC 2.0 Go-To-Market with Microsoft
Are you a defense contractor preparing for the Cyber Maturity Model Certification 2.0 (CMMC 2.0)? This webinar will ensure you meet the new standards set by the Department of Defense (DoD) and protect sensitive data throughout the supply chain. Our experts discuss the consequences of non-compliance and provide practical solutions to help you achieve compliance. Learn the ins and outs of CMMC 2.0, including the different levels of certification and the specific requirements. Discover our exclusive XQ solution for CMMC 2.0 compliance using Microsoft 365 Business Premium.
-
CMMC For Healthcare: Boost Immunity Against HIPAA Penalties with Recognized Security Practices
Thanks to never before seen levels of PHI data and advanced cyber threats, covered entities and business associates are increasingly vulnerable to data loss incidents and HIPAA penalties. The Safe Harbor Bill (H.R.7898) can help insulate organizations from HIPAA penalties if they adopt recognized security practices like CMMC.
-
The SMB’s Survival Guide to CMMC 2.0
While CMMC 2.0 is a welcome improvement over CMMC 1.0, the CMMC landscape remains a challenge for many smaller businesses. CMMC non-compliance threatens a business’s survival, but its requirements may still feel impossible for many SMBs. Talk about being stuck between a rock and a hard place!
-
The System Security Plan: What It Is, Why It Matters for CMMC, and How to Get Started on Yours
The rollout of the Cybersecurity Maturity Model Certification (CMMC, or CMMC 2.0) means it is now more important than ever for defense contractors to ensure that they have a comprehensive cybersecurity program in place. One crucial component of a good cybersecurity program is a System Security Plan (SSP). In this blog post, we’ll explain what an SSP is, why it’s important for CMMC, and provide tips on developing an SSP.
-
XQ vs. GCC High
Comparing XQ with GCC High reveals some important truths for Defense Industrial Base (DIB) (sub)contractors and vendors. XQ is less expensive, faster to deploy, easier to use, and better adapted to today’s risk landscape. For many DIB members, XQ is the smarter choice.
-
Five Benefits to Achieving CMMC 2.0 Compliance Now
CMMC compliance provides numerous benefits for defense contractors and suppliers. By achieving CMMC certification, your organization can gain a competitive advantage, build relationships with prime contractors, improve its cybersecurity posture, increase trust with customers and partners, reduce liability, and simplify compliance efforts. As the DoD ramps up NIST 800-171 audits and certification requirements for DoD contract eligibility become increasingly imminent, there’s no better time to start your organization’s CMMC journey.
-
Why use XQ for CMMC Compliance?
Incorporating XQ means you get incredibly safe, secure, and compliant customization on the infrastructure you control. Wherever and however you already work, simplify your sharing, upgrade your security, and achieve compliance quickly, cheaply, and effectively. If you’re still not ready for the May 2023 onset of CMMC, we can help. Book a time to talk, email us, or subscribe to our CMMC newsletter now!
-
Scoping for CMMC Level 2
Scoping is a key part of the CMMC assessment process. Per CMMC Assessment Guide Level 2, “The CMMC Assessment Scope informs which assets within the contractor’s environment will be assessed and the details of the assessment.” In other words, scope determines which organizational assets are relevant when conducting CMMC assessment and certification. Scoping can be confusing, so we’ve dedicated this post to simplifying things for our readers.
-
Preparing for CMMC Assessment, Part Two
Are you interested in learning more about preparing for CMMC assessment, including gap analysis, gap closure, and documentation? Read on! If you missed the first post, see Preparing For CMMC Assessment, Part One !
-
Preparing for CMMC Assessment, Part One
This blog is part one of a two-part series outlining the steps contractors can take, regardless of their unique conditions or approaches, to begin ‘doing’ CMMC. Following these blog posts will be individual posts outlining how to accomplish the listed steps in even greater detail. Today’s blog outlines steps one through three.
-
Introduction to CMMC Level 2
Unlike CMMC Level 1, compliance with Level 2 practices cannot be self-assessed. The formal Level 2 CMMC Assessment Process (CAP) can take months to complete! Understand the CMMC Level 2 Assessment Process and begin preparations for CMMC before requirements appear in DoD contracts in May 2023! This blog introduces CMMC Level 2 Requirements The formal CMMC Assessment Process (CAP)
-
Understanding CMMC: Domain Groups
CMMC practices are organized into 14 domains, which are categories that reflect the areas of security that the practices cover. These include Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity. Each domain contains a different amount of practices, and with each level of certification, more practices are needed.
-
Zero Trust Data: A New Capability From The DoD To Enable Secure Information Sharing
XQ ZTD Based CMMC Level 2 Compliance For Microsoft 365 Business Premium Email and Files is the primary operational mode for many small businesses and Microsoft 365 Business Premium is already the market leader. XQ’s Zero Trust Data (ZTD) can be added to a small business account within an hour to provide 94 of the 110 requirements to meet Level 2 CMMC compliance.
-
Introduction to CMMC Level 1
While contractors can use outside support (like a Certified CMMC Professional or even C3PAO), CMMC Level 1 compliance is ultimately self-assessed and the contractor’s responsibility. Contractors scope and evaluate their compliance using the CMMC Level 1 Assessment Guide, based on the assessment guidelines described in NIST Special Publication (SP) 800-171A Section 2.1 and whose practices align with FAR Clause 52.204-21.
-
Announcing XQ’s CMMC Series
Malicious cyber actors are increasingly targeting the Defense Industrial Base (DIB) sector and the Department of Defense (DoD) supply chain. By exploiting vulnerabilities in cyber security, bad actors can steal valuable intellectual property and sensitive information, undercutting technical advantages, impairing innovation, and increasing risks to national security. The Cybersecurity Maturity Model Certification (CMMC) is a product of the Department of Defense’s (DoD’s) need to protect American interests against this growing threat. CMMC improves, standardizes, and verifies cyber hygiene practices across the DIB. It outlines the required cyber security measures DIB members must take to protect non-classified, sensitive information across three maturity levels. Each level prescribes security practices commensurate with the sensitivity and risk of a specific category of information or data.
-
New DoD Zero Trust Data Guidelines
The DoD published an update to its Zero Trust Strategy (attached). The most important item is data’s increased role in their Zero Trust strategy. In the past, the DoD defined Zero Trust primarily from a network, device, and identity perspective (the data component was not prominent). Two changes drive the evolution of the DoD’s Zero Trust Strategy; 1/ the growth of sensor/imaging data and ensuring that it is available to front-line personnel and 2/real-world experience from Ukraine in which wireless networks are continuously jammed. These two factors have resulted in a new warfighting model in which mission-critical data is stored at the edge along with authorization policies. In fact, the only example of Zero Trust in action on Page 6 is about moving away from the older approach to locking down data in one place to allowing any authorized user to access data WHENEVER and WHEREVER they are (they actually capitalize those words).