Episodes

  • What's Next for GRC Academy and Jacob Hill
    Sep 4 2025

    I have an incredible announcement to share! 👀

    Before that though, let me share some of my history with you.

    Back in 2016, I started a side-business called TEKFused LLC focused on web design/hosting.

    Fast forward to 2022, I launched GRC Academy, and since then I’ve released 3 CMMC courses, released 50+ podcast episodes, and partnered with some amazing companies.

    Earlier this year, life threw me a curveball when I was laid off from my full-time role.

    Thanks to the incredible support of my AMAZING LinkedIn network, I had new opportunities on the table immediately!

    Within a week, I accepted a role with Summit 7 as Director of Cybersecurity - a company I’ve admired since 2019.

    And here’s the part I NEVER expected:

    👉 Summit 7 has officially acquired GRC Academy!! 🎉🥳🎉

    And guess what?!? I've already completely updated and rerecorded my CMMC training!! And it's even better than it was before!!

    GRC Academy students with active enrollments to my CMMC training will receive access to the new training on Summit 7's platform. It will take some time to get this all together, so keep your eyes open for that announcement.

    I'll be contributing to Summit 7's YouTube channel in the future as well, so subscribe if you haven't already: https://youtube.com/@summit7

    I will still be reselling PECB training at my TEKFused LLC website! If you need to get certified in ISO 27001/42001 (and more), be sure to keep me on your list: https://tekfused.com/courses/?utm_source=podcast&utm_medium=s2-11&utm_campaign=s7-acquisition-announcement

    On a personal note, I’m very thankful that this transition allows me to spend way more time with my family - while continuing my mission of educating the Defense Industrial Base!

    I learned so much during this chapter of my life. I want to thank all of you for your support - it truly made this possible.

    #cmmc #nist #cybersecurity

    Show More Show Less
    4 mins
  • The Business Case for CMMC - Surviving DOGE
    Jun 19 2025

    CMMC certification could be the key to surviving DOGE cuts! 👀

    In this episode, I’m joined by Derek Kernus of Aethon Security to discuss the business case for CMMC!

    This episode was really refreshing to me. Yes, our discussions about deep CMMC topics are important, but learning how to convince your company leadership to make the CMMC investment is even more critical.

    Here are some takeaways:

    • How CMMC early adopters can shape contracts and limit competition
    • How to frame the CMMC investment to internal leadership
    • The impending CMMC bottleneck of doom 👻
    • What mock assessments are and how they can help you prepare
    • Why choosing the wrong MSP could actually kill your chances at certification

    After being impacted by DOGE myself, I've put a lot of thought into how small businesses will be impacted by DOGE + CMMC.

    Most of my concern is for SMBs that haven't started preparing for CMMC. That costs a lot of money, and if SMBs lose revenue due to DOGE cuts before they prepare for CMMC, I'm not sure they'll be able to survive in the defense contracting space.

    But there is great opportunity for CMMC early adopters to be part a small cadre of CMMC certified companies and operate in a much smaller competitive space.

    It turns out CMMC actually could be your business's savior. Who knew!?!

    I really enjoyed this conversation! What were your biggest takeaways? Let me know in the comments.

    Follow Derek on LinkedIn: https://www.linkedin.com/in/derekkernus/

    Aethon Security Website: https://www.aethonsecurity.com/

    -----------

    Thanks to our sponsor Vanta!

    Get back time to focus on strengthening security and scaling your business.

    Discover the new way to GRC here: https://vanta.com/grcacademy

    -----------

    Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!

    Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s2-10&utm_campaign=courses

    #cmmc

    Show More Show Less
    53 mins
  • The Compliance Playbook to Cybersecurity
    Jun 5 2025

    "Compliance is the security referee - frameworks are the playbooks."

    In this episode, I’m joined by Tim Golden, Founder of Compliance Scorecard, to unpack the misunderstood, and mission-critical world of cyber GRC.

    Tim shares what he’s learned from decades of hands-on work - from implementing NIST frameworks before “GRC” was even a term, to helping teams understand why writing policies is just as important as patching vulnerabilities.

    Here are some highlights from the episode:

    • What GRC actually means - and why governance is the most misunderstood part
    • Why people who say "compliance isn't security" are missing the point
    • How explaining the "why" of cybersecurity controls aids in acceptance
    • Why data retention policies can protect you from major legal headaches
    • And yes… a story about how Tim accidentally ransomwared himself 🙃

    This is a must-listen for anyone navigating compliance, cybersecurity, or just trying to understand how it all fits together!

    I really enjoyed this conversation! What were your biggest takeaways? Let me know in the comments.

    Follow Tim on LinkedIn: https://www.linkedin.com/in/timothygolden/

    Compliance Scorecard Website: https://compliancescorecard.com/

    -----------

    Thanks to our sponsor Vanta!

    Get back time to focus on strengthening security and scaling your business.

    Discover the new way to GRC here: https://vanta.com/grcacademy

    -----------

    Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!

    Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s2-e9&utm_campaign=courses

    #cybersecurity

    Show More Show Less
    32 mins
  • How HITRUST Fixes What’s Broken in Cybersecurity Compliance
    May 27 2025

    Cybersecurity frameworks can learn a lot from HITRUST.

    In this episode, Ryan Patrick of HITRUST explains how HITRUST approaches the assurance problem, from centralizing the certification process to frequent updates to the control sets based on threat data.

    I barely knew anything about HITRUST going in, but it’s clear they’re tackling the cybersecurity assurance problem in a radically different way.

    Here’s what stood out to me:

    • HITRUST reviews its security controls quarterly based on threat intel and control effectiveness
    • There are three distinct assessment levels (like CMMC)
    • HITRUST itself issues a certification after the 3rd party assessment and running the assessment results through two stages of QA
    • Every 3rd assessment gets reviewed. Every. Single. One.

    The centralized approach of HITRUST allows them to provide feedback to its assessment community after each and every assessment which results in assessments that are more consistent and higher quality.

    HITRUST certified organizations are contractually required to report incidents which then allows them to evaluate the effectiveness of their controls.

    I personally think that commercial cybersecurity frameworks should take a look at HITRUST.

    What were your biggest takeaways? Let me know in the comments.

    Follow Ryan on LinkedIn: https://www.linkedin.com/in/ryan-patrick-3699117a/

    HITRUST Website: https://hitrustalliance.net/

    -----------

    Thanks to our sponsor Vanta!

    Get back time to focus on strengthening security and scaling your business.

    Discover the new way to GRC here: https://vanta.com/grcacademy

    -----------

    Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!

    Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s2-e8&utm_campaign=courses

    #hitrust

    Show More Show Less
    56 mins
  • CUI Masterclass with Ryan Bonner
    May 9 2025

    "Outread the others" - that's how Ryan Bonner mastered CUI.

    If you're confused about Controlled Unclassified Information (CUI) - you're not alone. Many defense contractors (not to mention DoD themselves) misunderstand what is CUI, where it comes from, and how to handle it.

    In this episode, Ryan Bonner, CEO of DEFCERT, gives a masterclass in understanding CUI from the actual laws and regulations - not just hearsay.

    👉 Here are the highlights:

    • What CUI really is - and what it’s not
    • How to use the NARA and DoD CUI registries
    • The proprietary paradox
    • How to decontrol CUI
    • The difference between FCI and CUI
    • DoD memo on determining CMMC levels

    This is essential listening for anyone working with the defense industrial base - primes, subs, and especially DoD program managers who want to avoid missteps.

    What were your biggest takeaways? Let me know in the comments.

    Follow Ryan on LinkedIn: https://www.linkedin.com/in/rybonner/

    DEFCERT Website: https://defcert.com/

    -----------

    Thanks to our sponsor Vanta!

    Get back time to focus on strengthening security and scaling your business.

    Discover the new way to GRC here: https://vanta.com/grcacademy

    -----------

    Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!

    Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s2-e7&utm_campaign=courses

    #cui #cmmc

    Show More Show Less
    51 mins
  • Small Business Achieves CMMC Level 2 Certification: Reynolds Construction's DIY Success Story
    Apr 24 2025

    HR guy leads his company to CMMC level 2 certification! 👀

    In this episode I’m joined by Eric Fields of Reynolds Construction to learn how he led his business to CMMC level 2 certification!

    I call him "Eric the Great" - you'll see why in a moment.

    Eric's background was in HR and business operations. He had no background in IT or cybersecurity.

    They did it in-house - with just two people and smart choices.

    👉 Here’s how they did it:

    • CMMC training from GRC Academy
    • Resources and advisory services from Kieri Solutions
    • CCP & CCA training
    • Meticulous documentation

    This episode is very special to me - Eric's intro to CMMC was through GRC Academy more than 2 years ago, and he was actually the second person to leave a 5-star review on my CMMC training for defense contractors: https://grcacademy.io/course-reviews/cmmc-overview-training-eric-f-20230127/

    This episode is a great reminder that small businesses can achieve CMMC certification without breaking the bank.

    That said, time is no longer a luxury. With CMMC phasing in this summer, small businesses need to move fast - and partnering with a CMMC-focused MSP can help accelerate the process.

    What were your biggest takeaways? Feel free to celebrate with "Eric the Great" in the comments!

    Follow Eric on LinkedIn: https://www.linkedin.com/in/ericfields6/

    Reynolds Construction Website: https://www.reynoldscon.com/

    -----------

    Thanks to our sponsor Vanta!

    Get back time to focus on strengthening security and scaling your business.

    Discover the new way to GRC here: https://vanta.com/grcacademy

    -----------

    Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!

    Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s2-e6&utm_campaign=courses

    #cmmc #nist #cybersecurity

    Show More Show Less
    36 mins
  • The FASTEST Way to CMMC Compliance - CUI Enclaves
    Apr 10 2025

    CMMC rolls out in a few months and there are STILL companies who are JUST getting started!

    In this episode I’m joined by Daniel Akridge of Summit 7 to talk about the real challenges facing the Defense Industrial Base - and the FASTEST path to CMMC certification.

    To CUI Enclave, or not to CUI enclave - that is the question!

    👉 Here are some of the highlights:

    • What the big primes are saying about their subs and CMMC
    • The biggest CMMC hurdles for defense contractors
    • Why MOST DoD contracts could require CMMC Level 2 certification - not just self-attestation
    • Deep dive into CUI enclaves and their pros and cons

    I personally like CUI enclaves because it keeps government cybersecurity regulations and incident reporting requirements out of my corporate IT environment...

    However if you are a small business that primarily supports the DoD, CUI enclaves begin to make less sense - even as I try to reason otherwise!

    What were your biggest takeaways? Do you LUV CUI enclaves?? Let me know in the comments!

    Follow Daniel on LinkedIn: https://www.linkedin.com/in/danielakridge/

    Summit 7 Website: https://www.summit7.us/

    -----------

    Thanks to our sponsor Vanta!

    Need continuous visibility into the state of your security controls?

    Discover the new way to GRC here: https://vanta.com/grcacademy

    -----------

    Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!

    Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s2-e5&utm_campaign=courses

    #cmmc #nist #cybersecurity

    Show More Show Less
    58 mins
  • CMMC Will BREAK Your MSP - Axiom's CMMC Level 2 Journey
    Mar 25 2025

    “We built a second company from scratch…”

    Is that what it takes for MSPs to get CMMC'd!?! 👀

    In this episode I’m joined by Bobby Guerra and Kaleigh Floyd from Axiom, an IT Managed Service Provider (MSP). They explain exactly what it took to achieve CMMC level 2 certification - after 4 years of effort.

    Most MSPs aren’t ready for CMMC. Many believe it's just another checkbox, but it’s a complete operational shift that requires rethinking your tools, processes, and client relationships!

    Here are some of the highlights:

    • How much money they allocated for CMMC (it’s more than you think)
    • How to build scalable and repeatable processes to support compliance
    • The tools, contracts, and agreements you MUST have in place
    • How to prepare for the assessment (and avoid sleepless nights!)

    Bobby Guerra is the CEO of Axiom and has led the MSP for over 22 years. Under his leadership, Axiom became one of the first MSPs in the U.S. to achieve CMMC Level 2 Certification. Bobby now helps guide clients through their own CMMC journeys, focusing on sustainable security and compliance.

    Kaleigh Floyd is the Marketing Director at Axiom and Co-Host of the Climbing Mount CMMC podcast. Raised in the MSP world, she now educates others through Microsoft 365 training and cybersecurity content. Her passion lies in simplifying tech and making a lasting impact in the industry.

    This is a true CMMC for MSPs masterclass! So much great advice packed into this episode!

    What were your biggest takeaways? Let me know in the comments!

    Follow Bobby on LinkedIn: https://www.linkedin.com/in/bobbyguerra/

    Follow Kaleigh on LinkedIn: https://www.linkedin.com/in/kaleigh-floyd-079a52190/

    Axiom's Website: https://www.axiom.tech/

    Climbing Mount CMMC Podcast: https://www.axiom.tech/climbing-mount-cmmc-the-podcast/

    -----------

    Thanks to our sponsor Vanta!

    Need continuous visibility into the state of your security controls?

    Discover the new way to GRC here: https://vanta.com/grcacademy

    -----------

    Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!

    Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s2-e4&utm_campaign=courses

    #cmmc #nist #cybersecurity

    Show More Show Less
    1 hr and 32 mins