Katie Arrington: CMMC Seeks to Protect Companies Against Negligence

Katie Arrington, chief information security officer at the office of the assistant secretary of Defense for Acquisition and Sustainment and a 2020 Wash100 Award recipient, said the Cybersecurity Maturity Model Certification (CMMC) framework does not aim to punish companies for failing to anticipate cyber breaches like the SolarWinds hack but to protect them from negligence, Breaking Defense reported Friday.

“SolarWinds wasn’t normal. No one is going to take that against you and take your certification away against a nation-state actor penetrating in a way that has never been done before — absolutely not,” Arrington said at an AFCEA event.

In mid-December, the Cybersecurity and Infrastructure Security Agency released an emergency directive directing all federal civilian agencies to mitigate a compromise that threat actors are exploiting in SolarWinds’ Orion Network Management products. The breach was believed to be carried out by hackers from Russia.

CMMC seeks to help companies build a security baseline to compete for contracts with the Department of Defense and incentivize them for meeting expectations.

“If you get hit by something like SolarWinds, which everybody is going through right now, you’re not going to lose it over that. That’s something that the TTP was new. Nobody had planned for that,” said Arrington. “But if you come in, and there’s a cyber incident at your company and it happened because you weren’t deploying your multi-factor authentication, then you do run a risk.”

Share the Post:

Related Posts

Key Takeaways From Baird’s 2025 Defense & Government Conference

Co-authored with Pat Host For eight years, investment banking firm Baird has brought the government contracting community a sterling conference every November to take the pulse on the industry’s current...

Saluting First-Time 2025 Wash100 Winners From Government

The annual Wash100 Award represents the apex of an executive’s career. Issued by Executive Mosaic, the GovCon industry’s leading events, media and membership organization, the first-time winners from the class...

The Five Foundational Values of the Wash100 Award

The Wash100 Award is the ultimate achievement in a GovCon executive’s career. The award, created by Executive Mosaic in 2014, is the yearly recognition of GovCon leaders who demonstrate excellence...