Cyber Insights From SecureNM™ Leaders

Our members possess diverse expertise and experiences that bring tremendous value to the entire community. They contribute to this blog, they head industry-specific peer groups, education programs, and critical member services.

The CMMC Phase II Pause Is Not a Cybersecurity Pause


by Justin Kreinbrink, VP of Assessments & Lead CCA @ DTC, LLC | SecureNM™ Founding Sponsor - Outreach & Education Program | August 10, 2026


EDITOR'S NOTE: This is a summation of the full article - additional important details are linked here.


The Department of War’s decision to pause the CMMC Phase II rollout has generated understandable questions across the Defense Industrial Base. Many organizations are asking whether certification is still necessary or whether cybersecurity requirements have been relaxed.

The implementation timeline has changed, but applicable cybersecurity responsibilities have not disappeared.

Contractors and subcontractors must still meet applicable DFARS and NIST SP 800-171 requirements where required by contract. Phase I self-assessment requirements remain in place, existing CMMC certificates remain valid, and authorized C3PAOs continue conducting Level 2 certification assessments.

For New Mexico businesses supporting military installations, national laboratories, aerospace, manufacturing, engineering, and other federal missions, this distinction is significant. Cybersecurity obligations may flow through prime contractors and subcontract agreements even when an organization does not contract directly with DoW.

The current pause creates uncertainty around when and how certification requirements may appear in future contracts. It does not mean organizations should stop strengthening their cybersecurity posture. Business leaders should use this period to confirm which contracts contain cybersecurity requirements, understand what FCI or CUI their organization handles, verify that system documentation reflects the actual environment, address known gaps, and confirm expectations with prime contractors and customers.

Independent assessments continue to provide value beyond satisfying a single contract requirement. They can help validate that security requirements are implemented and operating as intended, while providing objective support for representations made to customers and government agencies.

Those representations matter. Knowingly inaccurate cybersecurity claims may carry legal and financial consequences under the False Claims Act, regardless of changes to the CMMC implementation schedule.

The path to certification may change. The responsibility to protect sensitive government information has not..


Read the full article for a detailed explanation of what the Phase II pause changes, what remains in effect, how existing certifications are affected, and the questions defense contractors should be asking while the federal review continues.

Effective Cybersecurity Requires Independent Oversight


by Thomas Sipf, CTO/CSO of Erisa Administrative Services, Inc. (EASI Gov) | Founding Sponsor - Education & Outreach | May 18, 2026

Thomas Sipf, CTO/CSO

Cybersecurity is not an IT function. It is a leadership responsibility that requires independent oversight. Many small and midsize organizations combine IT and cybersecurity for efficiency. In practice, this creates a critical gap: the same team builds systems and validates its own controls. That is not efficiency. In fact, it creates a serious lack of accountability.

Where Risk Emerges

Looking at my job title, you may find this assertion to be inconsistent. How can someone who is both the Chief Technology Officer and the Chief Security Officer preach about separate duties and third-party reviews? The answer is simple: I approach the management of diverse resources and processes as an executive responsibility. Regardless the “hands-on” work that I do within our frameworks, I rely upon additional experts to evaluate every corner of our systems.

Our company is in constant third-party review of its information technology and cybersecurity standards for several regulatory or contract regimes. Some are specific to our industry and the products or services that we administer. Some involve proprietary processes and standards. Regardless the oversight modalities in force, I can’t conduct the reviews. In fact, I and our executive team rely on additional levels of independent oversight, including peer review available through SecureNM™, to stay on top of an ever-evolving threat environment.

Three Problems Arise

When IT and cybersecurity operate as one function, three issues appear:

Self-Policing - Systems are configured and reviewed by the same individuals, allowing misconfigurations and excessive access to persist.

Standards Drift Toward Convenience - Without independent oversight, decisions often prioritize speed and usability over risk.

Limited Visibility - If one group controls system logs and monitoring, detection and response become less reliable.

Three Principles That Restore Accountability

Small organizations do not need large teams to improve control. They need structure and discipline:

Separation of Duties - Ensure the person who implements systems is not the only one reviewing them. Independent review introduces objectivity.

Security Defines Rules, IT Executes - Security sets policies and acceptable risk levels. IT implements and maintains systems within those boundaries.

Verification Requires Independent Visibility - Access to logs, system activity, and control validation must be shared and reviewed beyond a single function.

Why This Matters To You

Small businesses and nonprofits across New Mexico operate with lean teams and high trust environments. That trust can be a strength—but without verification, it becomes vulnerability.

One practical action you can take this week is to assign a second person—internal or external—to review access permissions for one critical system such as email or accounting. Even a simple review like this introduces meaningful oversight to your security environment.

Cybersecurity maturity begins when oversight becomes independent. SecureNM™ helps organizations apply practical governance that separates responsibility, strengthens verification, and improves resilience without adding unnecessary complexity. That is why my company supports this association’s education mission and the peer review process.

Why Every Business Deserves Practical, Scalable Cybersecurity


by Joel Long, CEO of Rook Advisors | Founding Sponsor - Peer Review Program | April 27, 2026

In today’s rapidly shifting digital economy, cybersecurity has become as essential to business operations as payroll, bookkeeping, or insurance. Yet many small and mid-size organizations feel overwhelmed by the complexity of cybersecurity standards and the high cost of enterprise-level solutions.

I’ve spent my career helping organizations navigate growth, change, and technology modernization. At Rook Advisors, we oversee mergers and acquisitions, business transitions, and large-scale IT integrations. Through that work, one truth has become unmistakable: every organization (no matter its size) deserves comprehensive protection against cyber threats. And that protection must be accessible, scalable, and grounded in practical business principles.

That belief is what led me to support SecureNM™. The organization fills a critical gap in New Mexico’s cybersecurity landscape by giving small businesses and nonprofits a realistic place to begin. Through free self-assessment tools, community workshops, and peer review programs, SecureNM™ empowers organizations to understand their vulnerabilities and build effective, sustainable cybersecurity practices.

Supporting Best Business Practices in Cybersecurity

Just as important, SecureNM™ encourages something I believe is fundamental to good governance: seeking objective, third-party assessments. No matter how trusted your IT provider or internal team may be, outside review helps ensure that your business is genuinely protected - not just assuming it is.

Rook Advisors is proud to sponsor SecureNM™ because cybersecurity readiness strengthens our entire business community. When organizations are safer, they operate with greater confidence, protect their customers, and contribute to a stronger statewide economy.

I look forward to continuing this work with SecureNM™ and helping bring practical cybersecurity leadership to all New Mexico organizations.