• SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us

Call us today! 844-OCD-TECH

Find our Location
OCD TechOCD Tech
  • SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us
OCD Tech Sponsor at NDIA New England 4th Annual Cyber Event

OCD Tech Sponsor at NDIA New England 4th Annual Cyber Event

October 16, 2019 Posted by Kate Upton DFARS

OCD Tech was pleased to have been a sponsor at the National Defense Industrial Association (NDIA) New England 4th Annual Cyber event at Northeastern University’s Innovation Campus at Burlington. The event that took place on October 10, 2019, provided a platform for industry and government officials to share information, thoughts, and concerns on the upcoming Cybersecurity Maturity Model Certification (CMMC) announced by the Pentagon earlier this year. The overarching theme of the day, exemplified by the event’s location, was the need for government, industry, and academia to come together on this single cybersecurity standard.

The CMMC is not another checklist, says Katie Arrington, Chief Information Security Officer for Acquisition. She explained that instead, this is a framework of standards and controls to secure the DoD, national security interests, and the supply chain from nation-state and non-nation-state cyber threats. Ms. Arrington spoke at length at the event to inform those in attendance that this new framework is necessary, achievable, and imminent.

The CMMC, its first form to come out in January 2020 for training purposes, introduces levels of certification based on what information the contractor, subcontractor, or supply chain provider has in their possession. For example, a major defense contractor would be a Level 5, with the most stringent hurdles for certification, where a small business that, hypothetically, sews backpacks for the Army would have a Level 1 obligation which Ms. Arrington describes as “basic cyber hygiene”.

Many of OCD Tech’s industry partners asked: “How is my small business supposed to pay for this?” Ms. Arrington addressed this concern, explaining that the cost for certification may be rolled into the bid for the DoD job. Small businesses were kept in mind during the creation of this framework with Ms. Arrington continuing to say that we cannot expect our small businesses to protect themselves against nation-state attacks. The Level 1 certification would require things like regular password changes, 2-factor authentication, and the use of anti-virus software.

Cybersecurity Leadership Panels

Although the CMMC was the hot-button issue of the day, the team from OCD Tech was pleased to participate in panels discussing cyber-related issues and observe a drone demonstration put on by Northeastern University’s Expeditionary Cyber and Unmanned Aerial System Research Development Facility.

OCD Tech’s own Scott Goodwin, Senior IT Security Analyst, sat on a panel discussing securing data from the Cloud. Mr. Goodwin spoke to an issue that many IT auditors see: clients that believe that moving their stack to the cloud will result in less regulatory obligation. He continued to caution against this and urged companies to always be aware of which regulations that they are obliged to comply with based upon the contracts they hold.

OCD Tech’s team was pleased to be a part of this information session and to not only listen and learn, but to share our own experiences and knowledge. OCD Tech looks forward to next year’s NDIA Cyber Event and to continue to grow with the exciting changes and challenges of the expanding cyber environment.

Share
0
Kate Upton

About Kate Upton

Kate Upton is the IT Government Compliance Team Lead at OCD-Tech. Kate has been with the firm since May 2019. Before joining the firm, Kate received her Bachelor’s degree in Political Science & Legal Studies from the University of Maine and went on to earn a Master’s degree from Northeastern University in Strategic Intelligence. She dedicates her time at the firm to meeting the unique compliance needs of clients in the Defense Industrial Base with projects including CMMC, NIST 800-171, NIST 800-53, and DFARS rules. Kate lives in Portland, Maine with her dog Lucy.

You also might be interested in

OCD TECH. TSA NEW CYBERSECURITY RULES

TSA new cybersecurity rules

Mar 14, 2023

OCD Tech believes stay informed is the best way to[...]

password access in will

Where do your Passwords go when you Die?

Feb 27, 2018

Where do your Passwords go when you Die? Christopher J.[...]

Kerberoasting – Mr. Smith’s Hacker Insights

Kerberoasting – Mr. Smith’s Hacker Insights

May 22, 2019

Hacker Insights is a series of blog posts meant to[...]

Find us on

Contact Us

We're not around right now. But you can send us an email and we'll get back to you, asap.

Send Message
OCD Tech logo Audit. Security. Assurance.

IT Audit | Cybersecurity | IT Assurance | IT Security Consultants – OCD Tech is a technology consulting firm serving the IT security and consulting needs of businesses in Boston (MA), Braintree (MA) and across New England. We primarily serve Fortune 500 companies including auto dealers, financial institutions, higher education, government contractors, and not-for-profit organizations with SOC 2 reporting, CMMC readiness, IT Security Audits, Penetration Testing and Vulnerability Assessments. We also provide dark web monitoring, DFARS compliance, and IT general controls review.

Contact Info

  • OCD Tech
  • 25 BHOP, Suite 407, Braintree MA, 02184
  • 844-623-8324
  • https://ocd-tech.com

Follow Us

Videos

Check Out the Latest Videos From OCD Tech!

Services

SOC Reporting Services
– SOC 2 ® Readiness Assessment
– SOC 2 ®
– SOC 3 ®
– SOC for Cybersecurity ®

IT Advisory Services
– IT Vulnerability Assessment
– Penetration Testing
– Privileged Access Management
– Social Engineering
– WISP
– General IT Controls Review

IT Government Compliance Services
– CMMC
– DFARS Compliance
– FTC Safeguards vCISO

Industries

  • Financial Services
  • Government
  • Enterprise
  • Auto Dealerships

© 2025 — OCD Tech: IT Audit - Cybersecurity - IT Assurance

  • OCD Tech
  • About Us
  • Contact Us
Prev Next