Behind the Shield

Re-Release: From Screenshots to Signals with SK Bhachech: FedRAMP Automation and What Comes Next

InfusionPoints Season 1 Episode 39

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 47:56

In this episode of Behind the Shield, host Gary Daemer is joined by new co-host Ryan Adcock from the InfusionPoints Cloud Team and special guest SK Bhachech from Riverbed Technology for a candid conversation on what it really takes to navigate federal compliance when the goalposts move mid-flight.

Together, they unpack Riverbed’s authorization journey, why FedRAMP is often customer-driven rather than chosen, and what makes FedRAMP uniquely prescriptive. From implementing hundreds of controls to sustaining month-over-month operational rigor, SK shares lessons learned from building and maturing a security program inside a regulated environment.

The conversation also looks ahead to FedRAMP 20x, Key Security Indicators, and machine-readable evidence. The group explores how automation can reduce human error, lower costs, and shift audits away from screenshot collection toward continuous validation. They also discuss where AI may help, such as summarization and review support, and why human oversight remains critical in cybersecurity.

To close, the episode gets more personal with favorite books, shows, and a discussion on service, leadership, and giving back to the community.

Topics covered include:

Why companies are pulled into FedRAMP and why it is hard to walk away

What makes FedRAMP prescriptive and operationally demanding

Staying nimble when requirements change during authorization

FedRAMP 20x, KSIs, and continuous validation

Automation and AI as accelerators with humans still in the loop

Guest Links: 
https://www.linkedin.com/in/bhachech/
https://www.riverbed.com/

InfusionPoints Links: 
LinkedIn- 
Ryan Adcock: https://www.linkedin.com/in/ryanaadcock/
Gary Daemer:   https://www.linkedin.com/in/infusionpoints/
InfusionPoints: https://www.linkedin.com/company/infusionpoints/
Request a Demo: https://xbu40.com/

InfusionPoints & AWS:
InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments.

About Us:
InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.
We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.
Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.

SPEAKER_05

Welcome to another episode of Behind the Shield Podcast. I'm your host, Gary Gamer, and today I have a new host, Ryan Adcock. Um I'd like in the very beginning of this, I'd like for Ryan just to briefly introduce who you are, what you're about, what your role here is at Infusion Points, and just you know, uh also give us a background of who you are as well. Um, you've got to be the only employee that we have that has an IMDB here. So I'm gonna leave it at that and I'll turn it back over to you.

SPEAKER_00

Yeah, thanks, Gary. Thanks for having me here. Um my name is Ryan Atcock. I work currently I'm on the cloud team here at Infusion Points. So uh working inside of environments, managing their vulnerabilities, uh submitting poams, uh, and dealing directly with customers as we uh we prepare them for authorization or and after authorization. Uh my journey to IT is very unique, as Gary said. Um, after college, I got into real estate. I was a very successful uh real estate agent for 10 years, but ultimately decided I wanted to do something new. Um I've always been interested in computers growing up as a millennial, growing up in the computer age, right? Seeing it evolve in front of our eyes. Uh I started taking some cloud classes and really got interested in the cloud infrastructure aspect of things. Um after doing some some learning and passing a few certifications, found Infusion Points, uh, applied for a position here, uh, met with Gary and the team, and Gary took a chance on me and introduced me into IT, and it's been fantastic. I started on the advice.

SPEAKER_05

I'm really happy that you uh decided to make that transfer because you've been a pleasure to work with. I'm not gonna lie.

SPEAKER_00

Thank you. It's been it's been great, and it's been such a learning opportunity for me. And that's what I really love about Infusion Points is they encourage learning. Um, and that's really helped me grow into my position. And that's that's what I I love. I love to learn. Uh and that's that's what working at Infusion Points is really all about. It's one of the the key um definers for being an employee here.

SPEAKER_05

You're also remote base too, right? You're out of out of Norfolk, right? Yeah.

SPEAKER_00

I'm in Virginia Beach, Virginia. Um, so about five and a half hours away from our home base, but it's been great to to drive out there and meet everyone out there as well. Um and going back to how I how I got into it, you know, I also, you know, after while I was doing real estate, I also did acting. Um that's Gary mentioned. Yes. Uh so did did quite a bit of that. It was a lot of fun. Uh had an opportunity to be on a few shows, which was fun. And uh and again, it was just also learning, um, learning how to be a little more confident in yourself, which is which has helped me in my career as well.

SPEAKER_05

And and and that clearly showed when when you went through the interview process, not not only did you know about cloud stuff, which is you know important to know and working in the cloud company, uh, but you also had that ability to speak to customers. And that's that's you know, you know, why we I think more than anything like to like to have you on board here. So and and today we're gonna have actually one of your customers um as as a guest. So maybe you can do like just uh an introduction of uh of SK as we bring him on.

SPEAKER_00

Yeah, today uh joining us is SK from Riverbed Technology. We've been working together for almost 11, 12 months now as we prepare for authorization for Riverbed. So uh SK, welcome. Uh if you wouldn't mind, give us a little background on yourself and about Riverbed.

SPEAKER_03

Hey, uh thanks for uh inviting me to this wonderful show. Um let's see about me and Riverbed. Uh I have been in uh IT field pretty much since getting out of college, so I don't have an interesting story like you, Ryan. Um but over the last decade or so I've you know zoomed in on cybersecurity uh partly by necessity uh you know uh of the past and partly by choice. Um I joined Riverbed to take the company through its own FedRamp journey because I had some experience at my prior company going through FedRamp. And you know, it was the really exciting opportunity uh what in the middle of the pandemic, you know, starting remote, nobody's going into the office and uh uh you know, starting a new job and starting uh a new security program, really. Uh so it's been a very exciting journey, and uh we've been working on a project with you guys over the past, as you said, 11, 12 months. You guys have been fantastic, right? Uh and we've enjoyed working with uh Gary, you and Ryan and and all the countless uh members of the team that have been helping us.

SPEAKER_05

You know, for for me, you know, talk to us a little bit about how you got into FedRAMP you know, because I don't think people choose to go into FedRAMP. I think they're kind of thrusted into it. And then once they're in it, they're like, wow, there's a lot going on here. You know, and then once you get that knowledge, it's hard to walk away from it because it you got so much time and effort invested into it and so much knowledge, you know, uh invested into it. Maybe you could just talk a brief moment about how and why FedRamp uh as well for yourself.

SPEAKER_03

Yeah, uh happy to. Um I don't think there is a single company out there that decides, oh, I want to go after this compliance framework just because in almost all, if not every single case, it's their customers saying, no, you gotta do this or else we we can't do business with you. That's especially true when it comes to federal government, right? Uh, FedRAMP, as we all know, has become a law, a requirement over the last few years. But even before that, more and more agencies, more and more missions were asking for FedRamp uh authorization. And so that's how my company got pulled into doing a FedRamp authorization. And uh, as the newly appointed uh leader of security and compliance, I was named to uh shape that uh path to authorization. Of course, I didn't do it myself, right? There was a lot of help from across the company and uh you know a lot of hard work. What I've learned to appreciate about FedRAMP is you know, unlike say ISOR 27001 or or some of the other programs that are more uh descriptive, FedRamp is very prescriptive. And and that's daunting when you begin the journey. Oh, I have to do all these things, even if you just start with FedRAM modern, right? 325 controls and not just implement the controls, but keep up with the the rinse and repeat, right? The the the hygiene of it all. But once you sort of get through that initial hurdle, you're like you realize that uh you're that much better off, your customers are that much better off, your security program has evolved. And as the you know, one of my mentors used to say, you know, the rising tide lifts all boats. And and that's exactly what FedRamp does, is that it forces companies to improve their security posture, and that benefits not just the federal government, but also each and every one of these companies that's serving the federal government.

SPEAKER_05

So from a FedRAMP process perspective, you know, talk to me about like say the old process, like the process that you went in through initially, and then maybe we can talk a little bit about you know the differences that you see in say the DOD process that you're going through right now.

SPEAKER_03

Yeah, um, so when we first went through FedRAMP, we were I think 110th or 111th uh CSP to be authorized. I think the number is well north of 400 at this point, if not close to 500. Um the process was well defined. It was just a lot more manual, let's just put it that way, right? Uh the the the program management office took vested interest in reviewing the package, providing feedback, uh, and and that that that meant that there was a bit of back and forth between the CSP, the the threePal, as well as uh the PMO. Uh as I understand with the uh uh some of the recent changes with Special Lake Vedroom 20X, there's a lot more push towards automation, and that's that's that's certainly a welcome change, right? Everything, you know, not everything needs to be done manually if automation can help make things more efficient. Um we have not firsthand, I've first not seen that automation firsthand, so I can't speak so much about you know how much benefit or drawbacks it might have. Uh but as you know, we're going through a Department of Defense uh uh process today, and uh you know again the the manual touch, the the detailed review, the scrutiny is present, and and I can appreciate that, right? The Department of Defense has a lot of sensitive information that they need to protect, and um having the checks and balances is a short shot way of achieving that.

SPEAKER_05

You know, having multiple reviews, um, and then having review boards and things like that. Um even though it does add it adds complexity and adds um you know different views, um, you know, hopefully what that ultimately does is get you uh more secure um as as you go through each each kind of layer. Because you know, you have to go through a 3PA audit. Um and um that's pretty rigorous, right? And not only do you have to go through the 3PA audit, you have to go through the readiness assessment first, and then they make sure that you're ready uh to be audited, right? That's what they want to make sure. So they're not wasting their the DOD's not wasting their time um to put you in the queue uh to to to make sure that you are you know ready for the audit. And once the audit is complete, you know, the um, which can take anywhere between eight and twelve weeks, give or give or take a day um uh for the audit. And then once that package is is is developed and submitted, you know, the the you have to go through you know an initial review uh within uh within the the the the JVT perspective, uh joint validation uh team. And then they they then take that information and can make recommendations up, but they're not the ones that actually do the approval. You have to then go through multiple layers uh beyond that. Um you know, you know, from a from a process side, it is it is definitely uh a few more layers uh and then a lot more coordination because not only are you coordinating with DISA, you're also coordinating with your customer, your end customer at the end of the day. So you also have to get them to the review it and be on board with uh you know what your what your documentation is saying, you know, what the three PO assessment is saying, and then making sure that uh they they align with what they want to have, uh your end customer wants to have uh as well. So they have to you know give their stamp of approval on it as well. And then once you make it through all that, they have to do it all over again to give you the actual authorization. So this just gives you the provisional um ATO. Um, and I think that um gets people at least started, and then being able to bring some potential customers um in into your into your environment. Because by then you're connected, you know, to the dod network. Um, all your traffic's going through the network, the dod network, and then it allows you to you know complete your your configurations.

SPEAKER_03

So but yeah, yeah, and and I think the one thing I'll add to that is one you know the rules of the game change from time to time. So guidances come out, whether it's from the PMO or or DISA or or or elsewhere, you know, it might be an executive order that comes down all the way from uh uh the precedent. And all the all that may change the goalpost for a company that might be mid flight in their authorization, right? So you speak and you speak from experience. The one thing I've learned is to be nimble, right? Things are gonna you cannot say this is the only path, right? It's right I always equate it to saying, Oh, I've decided to go from New York to LA and we're gonna take a road trip. Decide where you're gonna have pit stops and get gas or dinner and stay overnight, but then also have contingencies. If the road is closed, you might have to go around or a completely different path. That's okay. Your destination doesn't change if just because the road is closed.

SPEAKER_01

I tell you, I think that's right.

SPEAKER_05

Yeah, it is, it is that you know something that we always try to do with our customers is to say, look, this we could do we could do as much as estimates on things that we can control, right? Um, and and and everything within your control, you want to make sure you do the best job that you can do. So when you're delivering it, they're not having second second guesses about what you're delivering, right? And then that enables them when they get get the stuff, the package, right, and enables them to then make decisions and move faster, but you you have zero control over government shutdowns or or people's vacations or you know, the timelines that that that that are then experienced with this, or if a new requirement does um come in. And um, in this regard, you know, we do have a new requirement that came in, you know, during this process. And you're not the only customer that this is impacting uh as well. We have a we have like two or three others that we're going through the same exact thing with with this this whole new set of requirements that came in that we're trying to get in and and and and figure out the best way um you know to uh to enable these uh these requirements because if you don't meet those requirements, then you don't get the certification that you ultimately want to get. Um so we hoped initially that um they would grandfather folks in um uh who actually had already started the process, but uh we're finding out that uh they're not. They're gonna be pretty strict about it and drive you to where they need they need you to meet all the requirements, which if it's a requirement, we we gotta figure out how to meet it, you know. Yeah, exactly.

SPEAKER_03

Yeah. Again, you know, being nimble and and just being uh you know, expecting these kind of hurdles is is the only way to keep maintain sanity through authorization process.

SPEAKER_05

Well, you you know, you know you know you you've done this for a couple companies, right? We we've done this for 20 or 30 companies. And um trying to balance this all throughout the year is always difficult because every time we go through one of these, because we're we're I I think we're in an audit every single month with our customers because you know not only do we help you guys build and accelerate your your your uh build process, but we also manage these environments for our customers as well. So part of that management process is managing the ATOs for our customers. And we we have a service we call audit shield, which helps. And I think you've you hopefully you've seen how well that works uh uh with within your environment um uh with it with the audit. Um, but every customer that we work with, we go through that not only in the initial audit, but it's also the annual audits um and and and working with them. But every every every one we go through, we then have to figure out what new requirements are going to be um put in place. I I'll give you a really good example. I won't list which one it was and when it was, but there was a requirement that uh hit us. Uh there was an executive order, and it came out like four days before our audit started. And um the auditors are like, Well, do you meet this?

SPEAKER_06

And we're like, meet what? You know, because it had literally just come out uh and and and and dried yet.

SPEAKER_05

Oh my god, the ink wasn't even dry yet, but they were asking us about it, and uh we quickly had to you know figure out how our solution met that requirement because it did. It it actually did meet the requirement, but we just had to you know figure out how to get it documented properly and um you know how to be able to tell the story, you know, on on that. And and I I mean it almost everyone we go through with there's always something we learn something new every time.

SPEAKER_00

So and that's that's the benefit for us being in audits so often, right? One, we see how different three Paos view things, right? That you know, there is some interpretation there, so it allows us to be able to have a better understanding of the requirements, how a three pao may may view those. Um so it just sharpens our team even more when we when we do see these new requirements come down the pipe.

SPEAKER_03

And and um the other thing I'll say is you know, uh having worked with you, Ryan, right, you're you're great at navigating, you know, helping us navigate through these surprise requirements, right? Sometimes uh one might be able to say, look, we understand it's a requirement, but not having it implemented presents a risk. Why don't we just take on the hit, add it to our plan of, you know, take the risk at the as part of your findings, miss, you know, Miss or Mr. 3PAL, and then we'll add it to our plan of actions and milestones and track it to completion by time that way, as opposed to it becoming a roadblock. I should I'm not saying that every single requirement can be mitigated like that, but some of them, which may not be like that stringent or that risky, uh can be treated like that. And I appreciate you guys you know helping us navigate through some of those hurdles.

SPEAKER_05

Well, that's part of what we do here again, knowing the all the all the different questions that we get um uh with different auditors and then understanding the requirements um as as they're laid out, it it does get to be quite difficult um, you know, to try to address all the new stuff um as you're also all trying to implement all the old stuff. You know, it's like, well, yeah, by the way, these three things changed and uh we're gonna have to figure out how to get them integrated in, or we're gonna figure out how to figure out how we do some risk adjustments uh to accept some of that risk as well. And and to be honest with you, uh SK, you you've done that very well yourself. You've been able to, you know, um kind of talk your team, you know, because yeah, we build we build a good infrastructure, but you know, you are really focused on helping your team, um, your developers um and your support people to be able to support this as well. So you're constantly, you know, talking them up to them about what is acceptable, was it what isn't acceptable, and really translating, you know, the FedRamp language to the language of your company, and which has really been helpful as well, which is a crucial part of being successful here.

SPEAKER_03

So what you're saying is that every company needs a champion uh that is sort of bridging the business and the security worlds.

SPEAKER_05

Yes, absolutely. There's no doubt. Um we struggle when when there's not somebody like you on the other side, right? Um it it really is very difficult if we're trying to explain it to somebody who has no security experience for one, no government experience, number two, and and and then not understand the rigor that that's really required. And you know, I've been to an ISO audit, I've been to a sock tool audit. You know, why is it any harder than that? Well, you know, you know as well as I do that it's not just even the technical controls or the or the manual controls, it's those operational controls, that rigor, that month over month over month that you gotta continue to to hammer in with vulnerabilities and and you know, different various checks, you know, that you gotta do, you know. So I know I know you just met our our new VP of customer success, uh Jeff Bivins. Um I I've often and you've probably heard me say this before, but I'm gonna say it again, you know, it's something that he said that I've borrowed um um to try to talk to many of our customers about. FedRamp, as an example, is not something you do, it is something that you become. And I know you've probably heard me say that before. Now you actually know who actually said it. Um you got you got to meet the guy. And I think it was our second or third ATO we were working on with him. Um that he, you know, he he he's he said, you know, Gary, this is this is you've got to become this. You you do, you've got to be able to feel it out and and and really be able to explain it to the staff because a lot of people know why. Why is this so hard? Why do I gotta do this? Why do I gotta do that? Why do I have to do this? You know, and uh you've been able to do a really good job with your with your team. You know, um, from from the very from the very beginning of uh from the day we started with the gap assessments, even, you know, uh all the way through, all the way through to we had the on-site, you know, at your facility here in North Carolina. So yeah.

SPEAKER_03

It's uh I I often come up with uh very risque analogies.

SPEAKER_06

And so I think you know, for that you do I always look forward to them though. They're great every time.

SPEAKER_03

You know, all these compliances are like religion, you know. You know, look, doesn't matter which which religion you pick, right? Whether you know you're Catholic and you you gotta go to confessional, you gotta go to confessional, right? You you gotta go to church every Sunday, you gotta go to church, or you're you know, like you go to temple, you go to mosque, doesn't matter, right? Once you adopt religion, you've got to go through with uh certain level of uh rituals, yes, and you gotta keep up with it, and I think that's what it is with these compliance regimes as well.

SPEAKER_00

You can pick and choose which ones you want to follow, yeah. Exactly.

SPEAKER_05

So where do you what do you think? You know, um, you've been in the industry for a long time. Where do you think this federal compliance, you know, space is headed? I mean, if if you could just imagine just for a moment, you know, where do you what do you see? Where do you you think it's gonna go? And you and you can divide it up because I think we're starting to see a little bit of a division between the way DOD is doing it and the way the civil sector is doing it. But so however, you want to you know kind of maybe pull together, maybe you have a bit uh a pure view of say, hey, you know, they're gonna come back together and they're gonna get married again.

SPEAKER_03

So no, I think um I don't know whether they will or not, but I do see the value in the two sides of the government trusting each other's work to some extent, right? And trusting each other's programs to some extent. Uh um because that benefits them, they don't have to do double reviews of the same thing, for example, right? Just because, oh, we trust that our counterparts have done their due diligence. We're gonna skim over and you know look at the uh the the cliff notes, if you will, and authorize this you know, CSP. It also benefits the industry because then they're able to bring their products to market, especially government space, more efficiently with less overhead, and it most certainly benefits and what does less overhead mean to the customer? Yeah, it's well again, right? You know, like imagine you you know, you having to go to two different churches versus just having to go to one church, yeah.

SPEAKER_05

Spending time in the morning in one church and spending the time in the afternoon in another. Uh exactly, yeah, right.

SPEAKER_03

Um so you know, I mean, if you can say, look, you know, my confession here at this church is good enough, but you know, it's just the same God, right? At the end of the day, right? Okay, I'm stretching it a little bit. There you go.

SPEAKER_05

But time, time, time is uh is is is a is a resource that you can't get back, right? It's the yeah, the one resource that keeps going on no matter what what happens.

SPEAKER_03

So yeah, and and the the the biggest beneficiary is actually the agencies themselves because they can start using products quickly, right?

SPEAKER_05

Quickly and less and for less, right? Exactly. So that's that's the whole idea here, right? You know, they want to be able to do this for less. Um, because at the end of the day, we don't want to pay twice the amount of money for a specific uh set of services. If you have to go through this twice, you know, then you're gonna have to start you know adjusting your prices appropriately, right? Yeah. Just imagine, imagine if you have to um manage two different environments, um, you know, for the DOD and and and for the civil space, but it's also not just the build, it's the operations pieces. And you know as well as I do the operation pieces is really what what cost you right for for the over the long over the long haul. So right Ryan, what do you what do you think, you know, the the the the kind of industry is going and and you know, what do you where would you like to see it go to?

SPEAKER_00

I think you know what's happening with uh FedRAM 20X it sounds like the wave of the future, right? This continually being able to audit your system for compliance, right? Instead of a snapshot in time, you know, that you do once a year with an auditor uh to prove that that you're compliant. Well, what about the other 364 days of the year? Are you compliant? I mean, there's we don't know, right? So I think that's where that continuous ability to audit systems is gonna be very important because these systems, you know, they're on secure areas of our government. So we want to make sure that they are secure, right? And that's that's why I appreciate the thoroughness of these reviews we're going through, because it's our government, it needs to be secure, we need to be able to prove it, right? There should be no questions around that. So I think that that continual audit is is a great way to more secure, you know, the applications that our government uses. And I think that if they can also get more applications available to the government, then that will you know lower costs, right? Uh and provide more competition for those applications as well. And I think that all is a benefit across the board.

SPEAKER_05

And and for me, what I'd like to see um from a vision standpoint, you know, I I've never thought the audits were horrible. You know, I've always thought they were tough. Um, and then yes, they asked some redundant questions depending on depending on the auditor. Some are you know better than others. Um and um it really has been the review process on the government side, which uh hasn't been as as consistent or as fast as I would like I've liked to have seen. That's why I really love this this concept of the machine readable perspective. So if you can get a machine readable piece of it in there, maybe it can do 80%, 70%, 50% of the review, and it can still cut out a big chunk of time. Uh if it can take out just uh any bit of uh of that review process and just kind of move a little bit faster, I think that would enable customers, you're you know, the CSPs, you know, to be able to get out there and um sell their services a lot faster. I to me that that that that's a hurdle that we got to continually figure out. Um I had an auditor on last last week that's not been published yet, but it'll be published soon, I think. Um and we were talking about like CDM and them wanting to know every vulnerability on every system in the federal government. And that's just you know when you when you're when you're looking at that much stuff, I I just there's no way, there's no tools available, you know, that can that can look at all that information. So when you're looking at that much, you're to me you're looking at nothing, right? Because, you know, it's just way too much to review. So somehow or another, we gotta have some kind of hierarchy of review and then some kind of hierarchy thing to flag it, you know, to be an extra set of eyes put on that. And so I don't know, I don't know exactly how that's gonna come into play. I'm hoping that that 20x and this automation pieces that were putting into it. I I'm hoping that that really can lead to machine readable um uh functions that will enable us to make faster decisions on things that we can make faster decisions on, you know, encryption on an EC2. Let me tell you, I I I I know when it's on or when it's off, right? And in our systems that we develop, we have alarms and alerts that go off if we if somebody launches a an EC2 that doesn't have encryption on. There's no way and in them in our accounts that you can that you can run a um system that isn't encrypted, right? And so building those those features and functions into you know the the the designs will help the auditing pieces tremendously um as well. So that's where we really need to get to, um in my opinion, right? We've really got to get to that piece of it. But in some cases, I think it might even take some laws to be changed, right? Because an AO, the way they interpret the law, um it may be that they have to look at every single vulnerability, and they might have to look at every single finding and every everything all along the path. But if there's something that we could they could put in place to say, well, maybe that AO doesn't need to look at everything, they only need to look at the things that need that they really need to look at. And and I think that's where we we we where we've got to get to. Um and then you they they got to put trust in the automations, they gotta put trust in the auditors, and they gotta put trust in the CSPs, but that trust is earned right over time with consistent audits, consistent automations, um, that people then can um look at the red, yellow, green, you know, as an example, right? And then you don't really go look at it until it's yellow as an example. Um I'm uh I'm oversimplifying the problem. I know I am, but there's got to be something that we could do better. Um and it to me it has to be it has to start with automation and maybe we even mix some AI in there as well as a supplemental tool, you know. So how do how do you guys feel about that from a from an overall perspective, the automation perspective? Um, Ryan, I don't know how close you have been, because I know you've been very much involved with with SK and his team and getting um uh their their package all the way through, but I don't know how close you've been involved in the rest of our team that's working on 20x or not. But maybe both you guys could spend some time just thinking and amusing about you know the automation perspective and what you think it could help us do, especially in this part, this auditing part, this review piece, um, and then going back to that not doing this thing from a point-in-time perspective, but doing this continuously every single day, you know.

SPEAKER_00

Right. Well, you know, yeah, correct, Gary. I've been, you know, really focused on Riverbed, but I'd like to, you know, keep up with what our company's doing through our blogs and just you know reading some of the messages that go back and forth around the 20x effort. Um, I like the idea of these key security indicators or KSIs as FedRAM's calling them, right? And being able to, you know, with what we're building, able to look at those and say, you know, this is what it's checking, right? And this is the result, right? So instead of having to prove that through screenshots and an audit, we can we can pull those records and in live time show that we meet these key security indicators, which cuts down on the number of checks that have to be done because it's more or less, you know, grouping them all together, right? And showing it all in one that it's it's meeting these requirements. Uh, but I think with automation, I think you you start to eliminate the risk, the risk of human error, right? And something that's not checked, right? Oh, I I thought we checked that, but we didn't, right? We don't have a piece of evidence for it. So I think you start to remove that human error. So I think automation is uh the the efficiency tool coming into this as well. I think that's important to cut down on uh the cost, right, and the resourcing needed for these for these efforts.

SPEAKER_03

I I agree 100%. I think uh I can't wait for the Department of Defense to start benefiting and start implementing uh some of this uh automation uh as well, because uh again, going back to the previous narrative, right? That if if if there is uniformity, if there's homogeneity in the the two sides of the uh government you know doing the assessment, it becomes that much easier for the industry as well to comply and provide uh provide assurances to the government, right? Uh and who who likes to go and get a bunch of screenshots, right? Whoever said that today is the perfect day for me to get a bunch of screenshots because that's what I live for. Nobody nobody thinks that. Right. Nope, there's no um fulfillment in that, right? Um you're doing it automatically, right? You're pulling the KSIs, you're you're pushing them up to the government, and that way the government itself can say, Oh, yeah, you know, these are the things that are missing, and we need to focus on those. I think AI can help, uh, as you said, Gary, perhaps to the point that, or at least maybe today, right? SSP reviews, package reuse.

SPEAKER_02

Yeah.

SPEAKER_03

Maybe that's you know, AI, maybe FedRamp and DOD are thinking about this, but no, and you know, throwing an AI agent saying, hey, summarize this SSP and you know, you know, give us some of the highlights might be a good way to say, you know, where the gaps might exist. Um in the same way, right? AI agent can be applied to the automation that's been ingested by uh the agency. But again, you still need that human oversight. You can't trust AI just yet, right? Especially when it comes to security, I don't think one can trust AI. You can use it as another tool in your tool set, right? As your Swiss Army knot, if you will. But it won't replace the screwdriver, it won't replace the hammer.

SPEAKER_05

Not anytime soon, right?

SPEAKER_03

Not anytime soon.

SPEAKER_05

Yeah, yeah. Yeah, and to me, to me, also with this is you you you have a um history uh easier in an automation perspective as well, right? You have that history of met this control, met this control. So you can look at that over over history so you can see all the trend of how people are doing as well. And then and then you think about this from the you know, we're we're and have been working on doing an uh SSP ingest. We we can pet ingest SSPs um with no problem today, but where we're we're where we're not at yet is what is the quality of that SSP, right? Does that SSP meet all of the checks? Now we we can do all the mechanical stuff, you can look and see all the check boxes and all that, but to me that's that's low-hanging fruit, right? But can it really interpret AC2A that says XYZ and does it meet the spirit of of the control, right? Yeah, we're still in the midst of trying to train some models um uh to do that. And I'm hoping, I'm hoping that uh we have a hackathon sometime in December. And I'm hoping that that that rises to the top of one of the challenges that the teams take on because uh they're gonna choose uh which what what which and what they're gonna do at the at the hackathon. So you know that should be interesting to see what they choose.

SPEAKER_02

And another AI agent to review it and then go through.

SPEAKER_05

Well, you know, we we've seen a lot um of traction in the the writing side, right? Um there's several companies out there that um you know can help you write uh an SSP, and that's something that that we can do as well. Um, but I think that's that's that's something like one-tenth the problem, right? Right. Um writing an SSP is not as not as easy as reviewing an SSP, you know.

SPEAKER_03

And and I will say, you know, I was being facetious, of course. Uh you know, you don't want no what's gonna happen is just writing up, you know, a bunch of gobbledygoo in in something so important as an SSP, right? Right. Um I'm sure somebody will do it just just so that they can check the box and you know, they'll stumble through the the authorization process.

SPEAKER_05

Maybe they'll get rejected and they'll have to rethink, but you know, one of the things that FedM20X is also doing is it's it's kind of removing the requirement for an SSP uh as well. Uh not that you can get rid of the narrative, you still have to have a narrative, you know, like uh um the the first section of of uh the description of your of your service, right? That that part won't ever go away, but the actual description of the um how you're meeting the the requirements, uh they're not asking us for that right now. So what they're asking us for is inside the KSIs to be able to explain how those KSIs are meeting the requirement. So in as an example, in each one of our KSIs, um, we describe uh what we're doing, right? Make sure you encrypt all S3 buckets, right? And uh we say, well, the way we're gonna do this is by checking these flags inside of AWS as an example, right? And then then we have to say, how do we know when we're done? So what are we doing, right? So in order for us to say we're we're we're looking at everything, we got to describe not only you know what we're doing, but what's the criteria of for success. So that's really what they're looking for. They're not looking for so much as how did you implement this thing, right? They're looking more of how do you know what you do it, what you're doing is accurate and and fully inclusive, right?

SPEAKER_03

Right, right. So that's that's necessarily uh the right direction that they're going in, then okay, cool.

SPEAKER_05

Yeah, I I like I like I would like to really see that um come come to fruition. I think that's very gonna be very helpful uh for us as well. So but well, um SK, I tell you, it's been an absolute pleasure uh to have you and Ryan on here today. It's always great talking to you anyway. I always learn a good analogy uh when I talk to you. So this is a completely new one for me.

SPEAKER_03

So one of these days they're gonna one of them's gonna come and bite me in the back.

SPEAKER_06

I've got one or two of them. I'm like, ooh, I don't know if I'd go down that road now. No, they're all they're all pretty good.

SPEAKER_05

I I I appreciate them because I I tell you, we always talk about storylines, and you gotta be able to tell a story, you gotta be able to pull that storyline all the way through. So but uh hey, thanks for having me.

SPEAKER_03

Is this uh I always love chatting with you guys about okay, good.

SPEAKER_05

I do have a few extra questions if you got time to to to ask my to answer my three questions. He's like, I'm I thought I thought I was gonna get out of here, man. Let's go. Let's go. So I like to I like to ask that. I'm gonna ask both you guys this. So if you know, real uh if you think about it, what is your favorite book, you know, of all time, uh that that you've read? I'll tell you mine real quick. Mine's the stand. It's like one of my favorite books of all time. But uh pick any book that you want to pick, you know. So and then why is it your favorite book?

SPEAKER_03

Ryan, you want to go next?

SPEAKER_00

I mean, you know, I would say favorite book. Uh I would see book that maybe invokes the most memory for me is uh Charlie and the Chocolate Factory.

SPEAKER_04

Remember growing up on my how about you, SK?

SPEAKER_03

Um I don't get to read as much as I'd like, and uh audiobooks just don't cut it for me, but uh you know, some of the favorites are you know the The Brave New World, The Animal Farm, uh 1984, you know, uh those at uh and then we should talk more. Yeah. Uh then Stranger in Strangeland uh is another, you know, rather very interesting read uh that uh I enjoyed, you know, just recently again.

SPEAKER_05

Cool, cool. I I I I listen to probably one book to almost two books a week.

SPEAKER_01

Oh wow, okay.

SPEAKER_05

Yeah. I I walk a lot. I walk probably about 20 miles a week, and when I walk, I listen.

SPEAKER_01

Okay.

SPEAKER_05

Uh so 20 miles is a is a long time. You figure three miles an hour because I'm slow. I'm not running. So it adds up pretty quickly. Um the amount of time. And I really look forward to kind of losing my mind a little bit as I as I walk, find myself in another space. I listen to fiction and nonfiction uh when I walk. Um it's it's it's very, very fun.

SPEAKER_04

So how about your favorite TV show or movie?

SPEAKER_03

Oh, anything that Ryan's in.

SPEAKER_04

So, Ryan, which movies and TV shows were you in?

SPEAKER_00

Oh my gosh. No, I don't want to get into those. I mean, so you know, I started my career with a lot of the you know investigation discovery uh channel shows. Those were filmed locally. Um, so those were easy for me to get into starting out. Um so I I really enjoyed that. Um you know, I I'm most known, especially in my town, uh being a military and a navy town, for some training videos I did for the Navy. And those will probably be shown to the entire Navy many times a year for the next 20 years. Um so that was fun to not tell my friends who are in the Navy. Uh so when they experienced having to watch it, they you know, they they really got pulled out of the training because they they started laughing because they knew who I was, right? You know, and they're like, Why are you laughing? This is a serious training. And they're like, Well, I I grew up with that guy. Like, I know him. Um But for me, my favorite uh favorite movie is probably The Matrix. Um and then favorite TV show uh has changed over time, but I think it's the office. I I just it's just my my my go-to always. That's that's why our sense of humor is uh aligned fairly well. That's right.

SPEAKER_05

Well, cool. So last question I have is um, you know, we're we're uh very big on service uh here at Infusion Point. So I always like to ask the question, you know, what what have you done in the past year, you know, um that um has had a big impact uh on other people uh within um say society or any any organization to be anything?

SPEAKER_03

Um in my case, you know, all the credit goes to my wife. She uh takes the initiative to help out uh a handful of families and and uh you know I wouldn't call them in need, but certainly they you know they don't have all the means. And so um helping fund their children's education or uh you know address a chronic uh or or an acute health situation is where um you know she ends up helping out, right? Um and and she actually does it rather anonymously. So perhaps the recipient knows, but nobody else knows outside in our friend circle, family, nobody does. That's cool. That's cool. So I I earned earned the I earned the the blessings through her work.

SPEAKER_05

Yeah, we we do the same thing. Um, you know, my wife is a big uh uh proponent here in town, and um I I follow her lead wherever she tells me I need to go. And then we have a and you may know that you may know this, you may not, but we have a son that has uh Down syndrome, so we were very big into Special Olympics and anything to do with any of the group homes here in in town as well.

SPEAKER_03

So but I remember you sharing that last December, I think, when we met.

SPEAKER_04

Okay, yeah.

SPEAKER_05

Great kid. I say kid, he's 27 years old.

SPEAKER_03

Young man. It always gonna be kids too. It's like uh I'm gonna be 80 and my daughter's gonna be 55. She's still gonna be a kid to me.

SPEAKER_06

Yeah, still my baby.

SPEAKER_03

Yeah, exactly.

SPEAKER_00

Right? Yeah, for me, um, you know, I I'm able to support, you know, local charities and um youth, you know, sports activities and foundations through uh charitable golf tournaments. I really enjoy doing that. Um, it's a great way uh to kind of blend two passions, right? Of you know, supporting the next generation for some of these um youth sports organizations that I was a part of as a kid, right? And they they supply um college scholarships as you get down the road. So it really helps helps them and it really, you know, they're they're built on shaping, you know, uh young kids into you know successful adults more than being focused on sports, you know, solely. It's more about growing that individual. And I really support that, my community.

SPEAKER_05

Cool, cool. Well, uh guys, I appreciate uh you two being on here. Uh I truly do. Thank you very much for your time today. And uh thank you, audience, for listening in all the way uh to the end. And as always, uh I may not always be the host uh behind the shield, uh, but somebody will always be here trying to uh shepherd you through this process. Thank you very much and peace out. Take care. See you guys.