The Defense Industrial Base is under pressure—and the data proves it. Chris Petersen breaks down the findings from our 2025 DIB Cybersecurity Maturity Report, revealing the real-world gaps in detection, response, and compliance across SMBs serving the DIB. This isn’t just about compliance—it’s about resilience. As Chris says, “check-the-box” security won’t cut it against threats like APT31 and APT28. The HOW matters. At RADICL, we’re here to help DIB companies build defense-in-depth strategies that go beyond minimum requirements and actually protect what matters most. Explore the full report: https://lnkd.in/ges_sRE7 #DIBCyberReport #Cybersecurity #DefenseIndustrialBase #CMMC #RADICL #NationalDefense
This is not good. - 54% would take 2+ days to respond to an incident. - 38% would take a week+ to detect a threat in their environment - 47% had 4+ accounts or endpoints compromised in the past year - 17% are CMMC Level 2 ready This is the state of cybersecurity maturity in the Defense Industrial Base (DIB) per our new 2025 DIB Cybersecurity Maturity Report. We produce this report to shed light on the cyberthreat readiness and resiliency of companies serving America's defense supply chain - companies being actively targeted for industrial espionage. This year's report again shows help is desperately needed. Fortunately, we had some good news last week. CFR 48 was amended and on November 10th, DoD contracts can begin to require CMMC per the addition of DFARS clause 252.204-7021. CMMC has become very real. Why is this good news? Because until all DIB CEOs have the same economic incentive to invest in improved security, they will choose price competitiveness and margins over robust, defense-in-depth. Why would they do otherwise if it puts their competitive survival at risk? While I'm happy to see CMMC progress, I also know that "check-the-box" compliance won't move the needle to where it needs to rest - especially for companies facing threats like APT31 (Judgement Panda) and APT28 (Fancy Bear) known for targeting the defense sector. This is why RADICL lives, to help companies achieve CMMC readiness, and more importantly, see them realize STRONG, defense-in-depth measures that can actually withstand the persistent advancements of highly motivated threats. As those in the industry know, compliance doesn't equate to protection. The HOW matters! If you are DIB CEO, ensure your internal team or MSP raises the expectation bar on the how front. The cost between being compliant and actually better defended may be negligible. Care about the how, care about the intended outcome - which is not just being compliant - it is about reducing the risk of operational disruption and theft of sensitive data. It is about protecting America's defense supply chain. https://lnkd.in/gXCcENg8 #DIB, #DefenseIndustrialBase, #Cybersecurity, #CMMC, #NIST800171, #CFR48