Titan of Tech

Titan of Tech I help business grow by creating the right technology strategy!

Did you the biggest threat to good cybersecurity in your business is lack of the right processes and procedures? Did you know that employee screwups by clicking the wrong email links, going to the wrong website, or keeping open "dead accounts" is MORE RISKY to your business then the threat of any actual hacker? Did you know that that IF you get "HACKED" is typically a crime of opportunity and NOT

A TARGETED ATTACK? If you want to demystify cybersecurity in a way that is sustainable, appropriate to YOUR RISK PROFILE, and also set you on a GROWTH PATH in your business..(YES I SAID THIS CAN HELP YOU GROW)...

Then visit our website and get the #1 HR Process that is missing to IMMEDIATELY make your business more secure!

14 Lessons From a CMMC Level 2 Assessment That Passed  (part 2)8. The assessor sets the schedule and picks the order of ...
08/21/2026

14 Lessons From a CMMC Level 2 Assessment That Passed (part 2)

8. The assessor sets the schedule and picks the order of control groups. You do not get to sequence this by what you feel readiest for.

9. The assessor can tell you what is deficient. They cannot tell you how to fix it. That is the independence line in their role, and the instinct when someone finds a gap is to ask them how to close it.

10. Say the words in your policy. Split tunnel DNS locked down perfectly, but no sentence stating the company does not permit it, and you may trend toward not met. A configuration is a decision an engineer made. A policy statement is the organization committing to a position.

11. Rely on your documentation, not your memory. You will be asked about something you configured eight months ago. I am pretty sure we handle that is a losing answer.

12. Keep the voices small. Five of us on the call, one main speaker. Multiple voices produce contradictions and volunteered information nobody asked for.

13. Push back, politely, and ask the lead assessor to referee if you cannot resolve it. We pushed back once on office WiFi and lost. I still think we were right on the security merits. You can be correct about risk and still lose the compliance argument, because compliance assesses conformance to a written requirement, not the quality of your reasoning. Push back anyway. Nobody wins the ones they never raise.

14. It is boring. Six days of proving you do the thing you said you do in the document where you said you do it. The tedium is not a sign something is wrong. The tedium is the process working.

Almost everything that determined how that week went was decided before the assessor showed up. How tightly we scoped the boundary. Whether the policy language matched the controls. Whether we could find our own evidence in ten seconds instead of ten minutes.

None of that is engineering work.

If a customer, regulator, or insurer is asking you to prove your cybersecurity, apply for an assessment call: https://vist.ly/5fmqf

Become a Titan of Tech

14 Lessons From a CMMC Level 2 Assessment That Passed  (part 1)The assessment was scheduled for six days.We finished in ...
08/21/2026

14 Lessons From a CMMC Level 2 Assessment That Passed (part 1)

The assessment was scheduled for six days.

We finished in four.

Four shortened days, nine to four, plus about two hours bleeding into day five. We skipped the end of day debrief after day one because there was nothing to debrief.

Here is what I took out of it.

1. Build a control cheat sheet. Excel. Every control, 3.1.1 through the end, and against each one the exact document and section that addresses it. This is the single biggest reason we finished two days early.

2. Build it late. Once the documents are stable. Build it early and you rebuild it every time a document changes.

3. Scope is the lever. You determine your CUI boundary, not the assessor. Everything inside it you document, control, monitor and pay for. Forever.

4. Buy a pre-assessment on your 3 and 5 point documentation. A few thousand dollars to find out whether you are approaching this the way an assessor expects, before you spend sixty or seventy on the real thing. You should have the same assessor and get to see them in action before the real thing and know how they will work.

5. The C3PAO is the organization. The assessor is a person. Same firm, same control, different depth of questioning depending on who you get.

6. Your assessor may be an independent contractor affiliated with the C3PAO rather than an employee of it. Ours regularly went back to the parent company on questions.

7. Expect rotating faces. Main assessor throughout, lead assessor in and out, other reps in and out. Some of them are joining cold.

(continued...)

If a customer, regulator, or insurer is asking you to prove your cybersecurity, apply for an assessment call: https://titanof.tech/

Become a Titan of Tech

One point out of 110.That's what NIST 800-171 Rev 2 assigns to control 3.1.20. Verify and control or limit connections t...
08/20/2026

One point out of 110.

That's what NIST 800-171 Rev 2 assigns to control 3.1.20. Verify and control or limit connections to and use of external systems. The lowest weight in the entire scoring model.

It's also one of six Level 2 requirements you are not permitted to put on a POA&M. 32 CFR 170.21. You can defer plenty of one-point controls. You cannot defer this one.

So it's scored like it barely matters and treated like it can't wait.

On a Level 2 assessment I worked with a client on, that control cost us more time than anything else in the framework. Not because of the technical work. That was already done. It cost us time because of one word.

External.

What counts as an external system in a company that has no internal systems? NIST does define the term. A system outside the authorization boundary you established, where you don't control how security requirements get applied.

Read that again. Outside the boundary you established.

The definition doesn't resolve until you've drawn the boundary yourself. And for a company running entirely on cloud services, there is no boundary sitting there waiting to be described.

We had our boundary, but we were still overcomplicating ourselves with what we thought an assessor would classify as an external system.

You can get this wrong in two directions. Too narrow and the assessor pushes back, because you left out systems where CUI actually moves. Too broad, the generic every website reading, and you have committed to validating every site on the internet. Nobody expects that. Nothing in the control text says so.

There is no correct answer handed to you. There is a defensible one you write.

I went looking at how other organizations handle 3.1.20. Templates, procedure documents, assessment prep guides. Same gap almost every time. Definitions covered mobile devices reaching the internal CUI environment and stopped there. Silent on the third-party portals and file transfer sites where the work actually happens.

Which means the systems most likely to carry CUI out of the business were the ones sitting outside the policy.

Deciding where CUI travels through your company is not an engineering question. If nobody owns that question, that's the gap worth closing before an assessment, not during one.

If a customer, regulator, or insurer is asking you to prove your cybersecurity, apply for an assessment call: https://vist.ly/5fhbv

Become a Titan of Tech

08/19/2026

A customer sends you a security questionnaire. 240 questions.

You forward it to your IT provider, because that is who you
call when the word "cyber" shows up in an email.

They answer most of it. Then you hit the section asking who
owns your security program, who approved your risk decisions,
and who signs the attestation.

And the honest answer is nobody.

That gap is what the market calls a fractional CISO, or vCISO.
Here is the plain version of what it is.

A CISO is not the person who configures your firewall. A CISO
is the executive who decides what risk the business carries,
what it spends to reduce the risk it will not carry, and who is
accountable when that judgment turns out to be wrong. It is a
business judgment role wearing a technology title.

A fractional CISO is that role bought in a slice. Not a hire.
A decision-making function for a defined scope.

Who it is actually for:

You are somewhere between $1M and $50M in revenue. You have a
competent IT provider handling the tactical work reasonably
well. And somebody outside your company, a customer, a carrier,
a regulator, a prime, has started requiring you to prove
something.

The problem is almost never that your IT provider is bad. It is
that there is no strategic counterpart to your IT provider, and
the absence has never been anyone's job to notice.

Who is not ready yet, and I would rather say this out loud:

If you are under $1M and nobody is requiring anything of you,
you do not need this. You need MFA everywhere, backups you have
actually tested by restoring something, and patching that
happens. That is most of your real risk and it costs a fraction
of an advisory engagement.

If you have a specific technical problem, you need an engineer
with a defined scope, not a strategist.

If you already have someone who genuinely owns risk decisions
and reports on them, you need a periodic second opinion. That is
a much smaller purchase.

And if you are buying it to make one form go away, be honest with
yourself. The form comes back next year, and every renewal after
that.

The test is simple. Look around the room and find the person whose
job it is to decide what your business should do about security.

If there is not one, that is the whole conversation.

Drop me a note If you are curious if your business situation needs a senior security leader.

Artificial Intelligence gave everyone an ocean of information.Most people are standing at the bank scooping out whatever...
07/09/2026

Artificial Intelligence gave everyone an ocean of information.

Most people are standing at the bank scooping out whatever floats by first.

The problem was never access to data.

It was always knowing which data actually matters for your business, your risk profile, and your decisions.

Tools don't know your priorities. They know patterns. And they will confidently hand you the wrong answer if you let them.

More information is not the same as better judgment. Never was.

Know what you're looking for before you ask the tool to look for it.

4 times in 2 months.Never been this sick, this many times.And its like a box of old, unused cables.  I just can't get ri...
07/07/2026

4 times in 2 months.

Never been this sick, this many times.

And its like a box of old, unused cables. I just can't get rid of it once I get it.

The clock is back to zero. See how long I can go this time.

Time to get back into the groove!

06/26/2026

One question tells you whether you're talking to an advisor or a vendor.

It costs you nothing to ask. The answer tells you whose interests the advice is really serving.

Try it this week. Then watch how they answer.

The graphic is the part that never makes it into the proposal.When the same company sells you the tools and also tells y...
06/25/2026

The graphic is the part that never makes it into the proposal.

When the same company sells you the tools and also tells you whether you need them, that's not a second opinion.

It's a sales call with better vocabulary.

A good IT company should want an independent voice in the room. It takes the conflicted hat off their head and lets them focus on the ex*****on they're actually good at.

Independence isn't anti-IT. It's the thing that makes the whole relationship honest.

06/24/2026

A company emailed me last week asking me to resell their security tools to my clients for a cut of the sale.

My profile says, in plain words, that I sell no tools and take no commissions.

They pitched me anyway.

I'm not annoyed at them. They were doing exactly what the industry trains everyone to do. The working assumption in small-business cybersecurity is that everyone has something to sell, and most of the time that assumption is correct. They had no reason to think I'd be the exception.

I ignored it. Not because selling software is wrong. People build good businesses doing it.

I ignored it because the minute I take a cut of what you buy, I lose the only thing that actually matters to you.

I can't tell you you're overspending. I can't tell you that you don't need the thing.

I can't tell you that the problem you should actually fix has no product attached to it.

The independence isn't a personality trait. It's the product.

If your IT company also provides your security advisor, ask one question.Who are they actually working for?Last week a c...
06/22/2026

If your IT company also provides your security advisor, ask one question.

Who are they actually working for?

Last week a company emailed me asking if I'd resell their security tools to my clients for a cut of the sale. My profile says, in plain words, that I sell no tools and take no commissions.

They asked anyway.

That message isn't strange. It's the industry working exactly the way it was built to work. In most small-business cybersecurity, the person advising you on what you need and the person who profits when you buy it is the same person.

Most owners never notice, because that person is wearing a strategist title.

Here's the part that rarely makes it into the proposal. When your advisor works inside the same IT company that sells you the tools, the strategy and the sales quota are the same job.

This isn't about dishonest people. Most of them are genuinely good at the work. It's about how the role is designed. When the job is built around revenue, the advice bends toward revenue, whether anyone means it to or not.

So you end up with a security stack that grows every year, and a real vulnerability that never gets fixed. Not because anyone was careless. Because the real vulnerability didn't have a product attached to it.

Nobody made money solving that one, so it stayed on the list.

If you like your IT company, I'm not telling you to fire anyone. A good IT company is genuinely good at ex*****on. The problem is asking one company to both sell you the tools and be the independent voice on whether you need them. Those two jobs fight each other inside the same building.

Here's something that costs you nothing this week. Ask whoever advises you on cybersecurity one plain question: do you make more money off the tools if I buy more? Then watch how they answer.

If the honest answer is yes, you don't have an advisor.

You have a vendor with a strategist title.

I broke the whole thing down in a new video, linked in the comments.

Be a titan over your tech.

Address

Fredericksburg, VA
22406

Opening Hours

Monday 9am - 5pm
Tuesday 9am - 5pm
Wednesday 9am - 5pm
Thursday 9am - 5pm
Friday 9am - 5pm

Alerts

Be the first to know and let us send you an email when Titan of Tech posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Titan of Tech:

Shortcuts

Share