Behind the Shield

From Screenshots to Signals with SK Bhachech: FedRAMP Automation and What Comes Next

InfusionPoints Season 1 Episode 13

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 47:56

In this episode of Behind the Shield, host Gary Daemer is joined by new co-host Ryan Adcock from the InfusionPoints Cloud Team and special guest SK Bhachech from Riverbed Technology for a candid conversation on what it really takes to navigate federal compliance when the goalposts move mid-flight.

Together, they unpack Riverbed’s authorization journey, why FedRAMP is often customer-driven rather than chosen, and what makes FedRAMP uniquely prescriptive. From implementing hundreds of controls to sustaining month-over-month operational rigor, SK shares lessons learned from building and maturing a security program inside a regulated environment.

The conversation also looks ahead to FedRAMP 20x, Key Security Indicators, and machine-readable evidence. The group explores how automation can reduce human error, lower costs, and shift audits away from screenshot collection toward continuous validation. They also discuss where AI may help, such as summarization and review support, and why human oversight remains critical in cybersecurity.

To close, the episode gets more personal with favorite books, shows, and a discussion on service, leadership, and giving back to the community.

Topics covered include:

Why companies are pulled into FedRAMP and why it is hard to walk away

What makes FedRAMP prescriptive and operationally demanding

Staying nimble when requirements change during authorization

FedRAMP 20x, KSIs, and continuous validation

Automation and AI as accelerators with humans still in the loop