00:00:14 --> 00:00:27
Stratom, a defense-focused robotics firm, just earned CMMC Level Two certification in September 2026, a milestone that signals a shift in how the defense industrial base secures its data.
00:00:27 --> 00:00:38
That certification means Stratom now meets a set of protective measures that go beyond basic hygiene, and it can manage and protect Controlled Unclassified Information.
00:00:38 --> 00:00:42
Can you explain why Level Two is a big deal for companies that work with the Department of Defense?
00:00:43 --> 00:00:55
Level Two sits between Level One, which focuses on basic hygiene, and Level Three, which demands more rigorous controls. It requires a formal security program and documented procedures.
00:00:56 --> 00:01:02
What does a formal security program look like in practice, especially for a company that builds autonomous robots?
00:01:02 --> 00:01:14
It starts with a written incident response plan, a system security plan that documents architecture and controls, and the use of continuous monitoring tools to track real-time telemetry.
00:01:14 --> 00:01:20
That sounds like a lot of paperwork. How does Stratom manage to keep that manageable while still innovating?
00:01:20 --> 00:01:35
Stratom layered security into every phase of development. They enforce least privilege with role-based access, secure their firmware with hardware security modules, and run automated static and dynamic analysis before shipping.
00:01:35 --> 00:01:40
What about the unique risks that come with robotic platforms, like sensor tampering or model poisoning?
00:01:40 --> 00:01:56
Autonomous systems rely on sensors, machine learning models, and real-time communication. Hardware tampering can corrupt sensor data, software supply chain issues can inject malicious code, and model poisoning can alter decision logic.
00:01:57 --> 00:02:00
How did Stratom's certification demonstrate that they addressed those threats?
00:02:01 --> 00:02:13
During the assessment, auditors reviewed their access control logs, verified that all communication channels were encrypted, and tested their incident response plan against simulated attacks on the robot’s firmware.
00:02:14 --> 00:02:19
So the certification isn't just a checkbox; it requires real evidence of controls in action.
00:02:19 --> 00:02:31
Exactly. Level Two also mandates continuous monitoring, which means collecting telemetry from endpoints, networks, and cloud services to detect anomalies in near real time.
00:02:31 --> 00:02:37
That sounds like a lot of data to sift through. How do organizations make sense of it?
00:02:37 --> 00:02:50
They aggregate logs, normalize traffic patterns, and feed the data into a managed XDR platform that correlates events across the stack. The platform then generates actionable insights and automated playbooks.
00:02:51 --> 00:02:55
I see. So continuous monitoring also provides evidence for compliance audits?
00:02:56 --> 00:03:06
Yes. The recorded telemetry and alert history become part of the audit evidence that the organization is actively managing risk, not just claiming to do so.
00:03:06 --> 00:03:11
What happens after a company like Stratom gets Level Two? Are there ongoing risks they need to watch for?
00:03:12 --> 00:03:25
Even after certification, the threat landscape evolves. Insider threats, supply chain incidents, zero-day vulnerabilities, and operational disruptions can erode compliance if not continuously monitored.
00:03:25 --> 00:03:29
That suggests compliance is a journey, not a destination.
00:03:29 --> 00:03:43
Correct. To sustain Level Two, organizations must adopt a risk-based approach that prioritizes high-impact controls, maintains continuous monitoring, and regularly tests incident response plans.
00:03:43 --> 00:03:47
What specific steps would you recommend to a company that is just starting its Level Two journey?
00:03:48 --> 00:04:00
First, conduct a gap analysis against the CMMC Level Two requirements using a trusted assessment tool. Next, prioritize controls that address the most critical vulnerabilities identified.
00:04:01 --> 00:04:01
And after that?
00:04:02 --> 00:04:15
Establish a security governance committee that brings together IT, legal, and business stakeholders. Deploy a continuous monitoring platform that aggregates logs, network traffic, and endpoint telemetry.
00:04:15 --> 00:04:22
You mentioned earlier that Stratom also used red-team exercises. How do those fit into the overall strategy?
00:04:22 --> 00:04:34
Red-team exercises simulate adversarial scenarios, especially targeting machine learning models and network segmentation. They uncover blind spots before an attacker can exploit them.
00:04:35 --> 00:04:37
So it's like a rehearsal for real attacks?
00:04:37 --> 00:04:45
Exactly. It validates your incident response plan, tests your monitoring alerts, and ensures your controls hold up under pressure.
00:04:45 --> 00:04:49
What about the people side? Training and awareness are mentioned as part of Level Two.
00:04:49 --> 00:05:01
Security awareness training keeps staff informed about emerging threats and reinforces the importance of following policies. It also helps identify insider threats early.
00:05:01 --> 00:05:05
You also talk about a system security plan. How detailed does that need to be?
00:05:06 --> 00:05:16
It documents your architecture, identifies roles and responsibilities, lists all controls in place, and outlines how you monitor and maintain them over time.
00:05:16 --> 00:05:19
And continuous monitoring feeds into that plan?
00:05:19 --> 00:05:29
Yes. Continuous monitoring provides the real-time data that validates whether the controls described in the system security plan are functioning as intended.
00:05:29 --> 00:05:34
It seems like a lot of moving parts. How does a company keep all of this in sync?
00:05:34 --> 00:05:45
By embedding security into the development lifecycle, automating controls, and using a single platform for telemetry and alerts. That reduces manual coordination.
00:05:45 --> 00:05:51
What about scaling? If a company expands its product line, can it maintain Level Two compliance?
00:05:51 --> 00:06:03
Continuous monitoring and adaptive controls allow organizations to scale security posture in tandem with product growth. Regular reassessment ensures new assets are integrated.
00:06:03 --> 00:06:10
You mentioned a Virtual CISO service earlier. How does that fit into a small organization that lacks in-house expertise?
00:06:10 --> 00:06:23
The Virtual CISO provides seasoned leadership, governance oversight, and policy development for organizations that cannot afford a full-time executive. It bridges the gap between policy and practice.
00:06:24 --> 00:06:29
Petronella Technology Group also offers Managed XDR. What does that bring to the table?
00:06:29 --> 00:06:44
Managed XDR unifies visibility across endpoints, networks, and cloud environments, delivering real-time threat intelligence, automated playbooks, and forensic capabilities that help detect and respond to emerging threats.
00:06:44 --> 00:06:47
So the idea is to have a single platform that covers everything?
00:06:48 --> 00:06:56
Yes, but it also requires integration with existing security tools and continuous tuning to keep alerts relevant and reduce noise.
00:06:57 --> 00:07:04
Petronella’s services also mention compliance documentation and audit support. How does that help during an assessment?
00:07:04 --> 00:07:16
They assist in creating system security plans, incident response plans, and other required artifacts. They also help compile evidence that auditors need to verify compliance.
00:07:16 --> 00:07:23
It seems that continuous monitoring is a recurring theme. Could you elaborate on how it ties into the evidence for a Level Two audit?
00:07:24 --> 00:07:38
Auditors review alert logs, monitoring reports, and incident response evidence. Continuous monitoring provides the data stream that proves the organization is actively managing risk, which is a Level Two requirement.
00:07:38 --> 00:07:43
That makes sense. But is there a risk that continuous monitoring could become a compliance burden itself?
00:07:44 --> 00:07:49
Continuing from where we left off, let's dig deeper into what Level Two really means for day-to-day operations.
00:07:50 --> 00:07:59
Level Two isn't just a checkbox; it's a framework that demands documented processes, continuous monitoring, and a clear incident response plan.
00:07:59 --> 00:08:05
So the organization has to prove that it's actively managing risk, not just putting up firewalls.
00:08:05 --> 00:08:14
Exactly. Auditors will look for evidence of ongoing assessment, like log reviews, vulnerability scans, and real-time alerts.
00:08:14 --> 00:08:18
Speaking of evidence, how does continuous monitoring feed into that audit trail?
00:08:19 --> 00:08:28
Continuous monitoring streams telemetry from endpoints, networks, and cloud services, which auditors review as proof that controls are operational.
00:08:28 --> 00:08:33
But if monitoring creates a lot of data, could that become a compliance burden itself?
00:08:33 --> 00:08:40
That risk exists if alerts aren't tuned. You need to filter noise so that only actionable events reach the security team.
00:08:41 --> 00:08:44
What are the most common mistakes organizations make when setting up monitoring?
00:08:45 --> 00:08:50
First, they deploy tools without a clear mapping to controls, so evidence is scattered.
00:08:50 --> 00:08:56
Second, they rely on static thresholds that don't adapt to new threat patterns, leading to missed anomalies.
00:08:57 --> 00:08:59
So the key is alignment and adaptability.
00:08:59 --> 00:09:04
Yes, and that ties back to the adaptive controls requirement in Level Two.
00:09:04 --> 00:09:09
Moving on, what immediate steps should a company take after deciding to pursue Level Two?
00:09:10 --> 00:09:15
Start with a gap analysis against the Level Two requirements using a trusted assessment tool.
00:09:15 --> 00:09:21
Prioritize high-impact controls that address the most critical vulnerabilities identified.
00:09:21 --> 00:09:24
That sounds methodical. What about governance?
00:09:24 --> 00:09:31
Form a security governance committee that includes IT, legal, and business stakeholders to oversee the program.
00:09:31 --> 00:09:37
This committee will review policies, risk assessments, and incident response plans on a regular basis.
00:09:38 --> 00:09:41
And the technical side-what core controls must be in place?
00:09:41 --> 00:09:46
Access control mechanisms enforcing least privilege and role-based access.
00:09:46 --> 00:09:51
System and communications protection to secure data in transit and at rest.
00:09:51 --> 00:09:56
Audit and accountability mechanisms that log events for forensic analysis.
00:09:56 --> 00:10:01
Configuration management processes tracking hardware and software changes.
00:10:01 --> 00:10:07
Incident response procedures defining roles, responsibilities, and communication paths.
00:10:07 --> 00:10:12
Those are the pillars. How do you integrate them into an autonomous system, like Stratom's robots?
00:10:12 --> 00:10:21
Embed security early in the development lifecycle-secure coding guidelines, hardware security modules, and automated analysis tools.
00:10:21 --> 00:10:28
Conduct red-team exercises to simulate attacks on machine learning models and sensor integrity.
00:10:28 --> 00:10:32
Red-team sounds intense. Does that fit into a small budget?
00:10:32 --> 00:10:39
You can scale the exercises; even tabletop scenarios provide valuable insights without high cost.
00:10:39 --> 00:10:42
What about the role of a Virtual CISO in this context?
00:10:42 --> 00:10:51
A Virtual CISO provides strategic guidance, policy development, and governance oversight without the overhead of a full-time executive.
00:10:51 --> 00:10:57
They help align security initiatives with business objectives and keep the program on track.
00:10:57 --> 00:11:00
And Managed XDR-how does it complement the Virtual CISO?
00:11:00 --> 00:11:12
Managed XDR unifies visibility across all environments, delivering real-time threat intelligence and automated playbooks that the Virtual CISO can leverage.
00:11:12 --> 00:11:15
So together they form a bridge between policy and practice.
00:11:15 --> 00:11:22
Precisely. The Virtual CISO sets the strategy; Managed XDR implements the tactics.
00:11:22 --> 00:11:25
What about documentation? How do you avoid drowning in paperwork?
00:11:26 --> 00:11:32
Focus on essential artifacts: system security plan, incident response plan, and evidence logs.
00:11:32 --> 00:11:37
Use templates and automation to generate documentation from monitoring data.
00:11:37 --> 00:11:39
That helps maintain evidence for auditors.
00:11:40 --> 00:11:44
Yes, and it keeps the documentation current as the environment evolves.
00:11:44 --> 00:11:49
Now, regarding continuous improvement-what does that look like post-certification?
00:11:50 --> 00:11:56
Regular reassessment of risks, updating controls, and incorporating lessons learned from incidents.
00:11:56 --> 00:12:01
Also, integrate new assets into the compliance framework as they come online.
00:12:01 --> 00:12:05
How do you handle vendor risk, especially with supply chain components?
00:12:05 --> 00:12:13
Implement a rigorous vendor risk management program that screens suppliers for security compliance before integration.
00:12:13 --> 00:12:17
Maintain a registry of approved components and monitor for any changes.
00:12:17 --> 00:12:20
What about insider threats? They're often overlooked.
00:12:21 --> 00:12:29
Insider threats are a top risk vector; enforce least privilege, monitor privileged activity, and conduct regular training.
00:12:29 --> 00:12:30
Training-how often should that happen?
00:12:31 --> 00:12:35
At least quarterly, with updates on emerging threats and policy changes.
00:12:35 --> 00:12:38
Let's talk about common questions we hear from listeners.
00:12:38 --> 00:12:43
Sure, one question is how long it typically takes to achieve Level Two compliance.
00:12:43 --> 00:12:51
The timeline varies, but a focused, phased approach that prioritizes high-impact controls can accelerate certification.
00:12:51 --> 00:12:56
Another question is whether Level Two can be maintained while expanding product lines.
00:12:56 --> 00:13:03
Continuous monitoring and adaptive controls enable scaling security posture alongside product growth.
00:13:04 --> 00:13:07
What about the role of continuous monitoring in sustaining compliance?
00:13:07 --> 00:13:17
It provides real-time visibility, enabling rapid detection of anomalies and timely incident response, which auditors view as ongoing compliance.
00:13:17 --> 00:13:22
Do you see any pitfalls when organizations try to maintain Level Two during rapid growth?
00:13:22 --> 00:13:26
They often defer documentation updates, leading to gaps in evidence.
00:13:27 --> 00:13:31
They also may overload the monitoring system, creating alert fatigue.
00:13:31 --> 00:13:32
How can they avoid that?
00:13:32 --> 00:13:38
Automate log collection, enforce strict alert thresholds, and regularly review alert relevance.
00:13:39 --> 00:13:41
What about the cost implications for small firms?
00:13:42 --> 00:13:50
Leverage managed services like Virtual CISO and Managed XDR to reduce internal overhead while meeting controls.
00:13:50 --> 00:13:55
And for those with limited staff, what are the essential controls they must focus on first?
00:13:55 --> 00:14:02
Start with access control, system and communications protection, and incident response documentation.
00:14:02 --> 00:14:04
Anything else you'd add as a final recommendation?
00:14:05 --> 00:14:14
Treat compliance as a continuous journey, not a one-time event; integrate security into every phase of product development and operations.
00:14:14 --> 00:14:21
Remember that every new asset-whether a device, cloud service, or partner-must be assessed against the Level Two controls.
00:14:22 --> 00:14:28
Document its configuration, access permissions, and monitoring coverage to maintain a complete audit trail.
00:14:29 --> 00:14:31
How do you ensure that the audit trail stays up to date?
00:14:32 --> 00:14:38
Automate configuration management tools to capture changes and feed them into the monitoring platform.
00:14:38 --> 00:14:41
And what about the human factor-how do you keep staff engaged?
00:14:42 --> 00:14:49
Involve them in security drills, recognize compliance milestones, and tie security metrics to business outcomes.
00:14:49 --> 00:14:53
That wraps up our discussion. Thanks again for your expertise.