<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Business Consulting &#8211; Closer to the Problem Closer to the Solution</title>
	<atom:link href="http://zonics.com/portfolios/advisory/feed/" rel="self" type="application/rss+xml" />
	<link>http://zonics.com</link>
	<description>Awareness, Containment, Remediation, and Training</description>
	<lastBuildDate>Fri, 16 Apr 2021 14:53:09 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>

<image>
	<url>http://zonics.com/wp-content/uploads/2021/08/Logo-round-78x78.jpg</url>
	<title>Business Consulting &#8211; Closer to the Problem Closer to the Solution</title>
	<link>http://zonics.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Dark Web Live Search &#038; Monitoring</title>
		<link>http://zonics.com/portfolio/awareness/</link>
		
		<dc:creator><![CDATA[wschadejr]]></dc:creator>
		<pubDate>Thu, 01 Apr 2021 11:04:24 +0000</pubDate>
				<guid isPermaLink="false">http://demo.prosystheme.com/business-ezone-pro/?post_type=portfolio&#038;p=121</guid>

					<description><![CDATA[WAYS YOUR EMPLOYEES’ WORK CREDENTIALS CAN LEAD TO A BREACH

When your employees use their work email on websites like the ones listed below, it makes your business vulnerable to a....]]></description>
										<content:encoded><![CDATA[<p><img fetchpriority="high" decoding="async" class="alignnone wp-image-397" src="http://zonics.com/wp-content/uploads/2021/04/TopSecurityThreats-2021-04-01_16-12-42-300x138.jpg" alt="" width="709" height="326" srcset="http://zonics.com/wp-content/uploads/2021/04/TopSecurityThreats-2021-04-01_16-12-42-300x138.jpg 300w, http://zonics.com/wp-content/uploads/2021/04/TopSecurityThreats-2021-04-01_16-12-42-600x277.jpg 600w, http://zonics.com/wp-content/uploads/2021/04/TopSecurityThreats-2021-04-01_16-12-42.jpg 860w" sizes="(max-width: 709px) 100vw, 709px" /></p>
<h3>WAYS YOUR EMPLOYEES’ WORK CREDENTIALS CAN LEAD TO A BREACH</h3>
<p>When your employees use their work email on websites like the ones listed below, it makes your business vulnerable to a breach.<br />
With our Dark Web Monitoring, we can detect if your company is at risk due to exposed credentials on 3rd party websites.</p>
<h4><b>The </b><b>Bad</b><b> News</b></h4>
<ul>
<li>NOTHING will prevent a determined hacker from getting into your network(s)</li>
<li>Even enterprise giants, government agencies and cyber security vendors can get hacked</li>
<li>Serious challenge: Your business needs nearly PERFECT security at every level, while hackers or criminal insiders only need 1 opening or weak point</li>
<li>Less of an ‘If’ and more of a ‘When’</li>
</ul>
<h4><b>The </b><b>Good</b><b> News</b></h4>
<ul>
<li>You can mitigate risks and discourage cybercriminals</li>
<li>Most security attacks or breaches are “crimes of opportunity”</li>
<li>Prioritizing IT Network &amp; Data Security is the key step to avoiding disaster</li>
<li>The best defense is a proactive offense</li>
</ul>
<h4><b>We Provide Strategies for<br />
</b></h4>
<ul>
<li>Top security threats to your business operations and data protection</li>
<li>The #1 security risk to your business most companies are not properly addressing</li>
<li>What YOU can do to effectively safeguard your business and avoid costly and devastating cyberattacks and data breaches</li>
</ul>
<p><img decoding="async" class="alignnone wp-image-454" src="http://zonics.com/wp-content/uploads/2021/04/Dark-Web-ID-Infographic-9-Ways-Credential-Breach-232x300.png" alt="" width="545" height="705" srcset="http://zonics.com/wp-content/uploads/2021/04/Dark-Web-ID-Infographic-9-Ways-Credential-Breach-232x300.png 232w, http://zonics.com/wp-content/uploads/2021/04/Dark-Web-ID-Infographic-9-Ways-Credential-Breach-791x1024.png 791w, http://zonics.com/wp-content/uploads/2021/04/Dark-Web-ID-Infographic-9-Ways-Credential-Breach-768x994.png 768w, http://zonics.com/wp-content/uploads/2021/04/Dark-Web-ID-Infographic-9-Ways-Credential-Breach-600x776.png 600w, http://zonics.com/wp-content/uploads/2021/04/Dark-Web-ID-Infographic-9-Ways-Credential-Breach.png 816w" sizes="(max-width: 545px) 100vw, 545px" /></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cybersecurity Maturity Model Certification &#8211; CMMC</title>
		<link>http://zonics.com/portfolio/cmmc/</link>
		
		<dc:creator><![CDATA[wschadejr]]></dc:creator>
		<pubDate>Wed, 24 Mar 2021 10:56:00 +0000</pubDate>
				<guid isPermaLink="false">http://demo.prosystheme.com/business-ezone-pro/?post_type=portfolio&#038;p=116</guid>

					<description><![CDATA[Our Compliance Manager Tool delivers for you. Companies that work with the US Department of Defense will soon need to meet CMMC requirements to bid on contracts.]]></description>
										<content:encoded><![CDATA[<h1><img decoding="async" class="wp-image-382 aligncenter" src="http://zonics.com/wp-content/uploads/2018/02/Compliance_Social-Graphic_CMMC-DFARS-NIST_APR-21_Ad-6-300x157.png" alt="" width="696" height="364" srcset="http://zonics.com/wp-content/uploads/2018/02/Compliance_Social-Graphic_CMMC-DFARS-NIST_APR-21_Ad-6-300x157.png 300w, http://zonics.com/wp-content/uploads/2018/02/Compliance_Social-Graphic_CMMC-DFARS-NIST_APR-21_Ad-6-1024x536.png 1024w, http://zonics.com/wp-content/uploads/2018/02/Compliance_Social-Graphic_CMMC-DFARS-NIST_APR-21_Ad-6-768x402.png 768w, http://zonics.com/wp-content/uploads/2018/02/Compliance_Social-Graphic_CMMC-DFARS-NIST_APR-21_Ad-6-600x314.png 600w, http://zonics.com/wp-content/uploads/2018/02/Compliance_Social-Graphic_CMMC-DFARS-NIST_APR-21_Ad-6.png 1200w" sizes="(max-width: 696px) 100vw, 696px" /></h1>
<h2>Explained: What defense contractors need to know.</h2>
<p>Our Compliance Manager Tool delivers for you. Companies that work with the US Department of Defense will soon need to meet CMMC requirements to bid on contracts.</p>
<section class="deck viewability">
<h3>What is the CMMC?</h3>
<p>The Cybersecurity Maturity Model Certification (CMMC) is a unified standard for implementing cybersecurity across the defense industrial base (DIB), which includes over 300,000 companies in the supply chain. The CMMC is the DoD&#8217;s response to significant compromises of sensitive defense information located on contractors&#8217; information systems.</p>
<p>The US Department of Defense (DoD) released the much-anticipated Cybersecurity Maturity Model Certification (CMMC) version 1.0 on January 31, 2020. It was drafted with significant input from University Affiliated Research Centers, Federally Funded Research and Development Centers, and industry.</p>
<p>Previously, contractors were responsible for implementing, monitoring and certifying the security of their information technology systems and any sensitive DoD information stored on or transmitted by those systems. Contractors remain responsible for implementing critical cybersecurity requirements, but the CMMC changes this paradigm by requiring third-party assessments of contractors&#8217; compliance with certain mandatory practices, procedures and capabilities that can adapt to new and evolving cyber threats from adversaries.</p>
<h3>What actions should DoD contractors take now?</h3>
<p>DoD contractors should immediately learn the CMMC&#8217;s technical requirements and prepare not only for certification, but long-term cybersecurity agility. Details on how the CMMC assessments will be conducted, and how to challenge those assessments, are anticipated soon. DoD contractors that have already started to evaluate their practices, procedures and gaps when the details are finalized will be well-positioned to navigate the process and meet the mandatory CMMC contract requirements for upcoming projects.</p>
<p>The Office of the Under Secretary of Defense for Acquisition &amp; Sustainment maintains a <a href="https://www.acq.osd.mil/cmmc/faq.html">CMMC FAQ</a> where contractors can keep up to date on the certification process.</p>
<h3>The CMMC framework</h3>
<p>The CMMC establishes five certification levels that reflect the maturity and reliability of a company&#8217;s cybersecurity infrastructure to safeguard sensitive government information on contractors&#8217; information systems. The five levels are tiered and build upon each other&#8217;s technical requirements. Each level requires compliance with the lower-level requirements and institutionalization of additional processes to implement specific cybersecurity-based practices.</p>
<ul>
<li><strong>Level 1:</strong> A company must perform &#8220;basic cyber hygiene&#8221; practices, such as using antivirus software or ensuring employees change passwords regularly to protect Federal Contract Information (FCI). FCI is &#8220;information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government.&#8221; It does not include public information or certain transactional information.</li>
<li><strong>Level 2:</strong> a company must document certain &#8220;intermediate cyber hygiene&#8221; practices to begin to protect any Controlled Unclassified Information (CUI) through implementation of some of the US Department of Commerce National Institute of Standards and Technology&#8217;s (NIST’s) Special Publication 800-171 Revision 2 (NIST 800-171 r2) security requirements. CUI is &#8220;any information that law, regulation, or government-wide policy requires to have safeguarding or disseminating controls,&#8221; but does not include certain classified information.</li>
<li><strong>Level 3:</strong> A company must have an institutionalized management plan to implement &#8220;good cyber hygiene&#8221; practices to safeguard CUI, including all the NIST 800-171 r2 security requirements as well as additional standards.</li>
<li><strong>Level 4:</strong> A company must have implemented processes for reviewing and measuring the effectiveness of practices as well as established additional enhanced practices detect and respond to changing tactics, techniques and procedures of advanced persistent threats (APTs). An APT is defined as an adversary that possesses sophisticated levels of expertise and significant resources that allow it to create opportunities to achieve its objectives by using multiple attack vectors.</li>
<li><strong>Level 5:</strong> A company must have standardized and optimized processes in place across the organization and additional enhanced practices that provide more sophisticated capabilities to detect and respond to APTs.</li>
</ul>
<h3>Who must comply with the CMMC?</h3>
<p>All DoD contractors will eventually be required to obtain a CMMC certification. This includes all suppliers at all tiers along the supply chain, small businesses, commercial item contractors and foreign suppliers. The CMMC Accreditation Body (CMMC-AB) will coordinate directly with DoD to develop procedures to certify independent Third-Party Assessment Organizations (CP3AOs) and assessors that will evaluate companies&#8217; CMMC levels.</p>
<aside id="" class="nativo-promo nativo-promo-1 tablet desktop"></aside>
<h3>When will CMMC compliance be required?</h3>
<p>The DoD predicts that it will begin to include minimum certification requirements in requests for information (RFIs) as early as June 2020 and in select requests for proposals (RFPs) in September 2020. DoD has also indicated that a prime-level certification requirement will not necessarily be the same certification level required throughout its entire supply chain for a given contract. Differing certification levels on a single contract have the potential to raise complex implementation challenges for primes and subcontractors alike.</p>
<h3>CMMC legal implications and takeaways</h3>
<p><strong>Certification preparation starts now.</strong> Accreditation procedures and accreditors have not yet been established, but we expect details soon. The DoD estimates that the DIB includes more than 300,000 contractors that will all need certification to continue to compete for DoD contracts.<br />
Early preparation could result in a more efficient assessment with positive end results. Contractors should begin taking immediate steps to:</p>
<ul>
<li>Clearly document practices and procedures with those requirements that already comply with CMMC practices or processes.</li>
<li>Plan for and implement further procedures and practices to obtain the highest certification level possible.</li>
</ul>
<p>Prime contractors also should begin (or continue) working with subcontractors throughout the supply chain to assist in developing compliance programs where necessary or reviewing programs already in place.</p>
<p><strong>Engage with agencies.</strong> Offerors should closely review RFIs and RFPs that include minimum certification requirements to ensure the assessed level is not unnecessarily burdensome and that it provides enough clarity for the certification level required throughout the supply chain. Offerors should consider providing feedback to DoD during the market research stage and during an RFP&#8217;s question and answer process.</p>
<aside id="" class="nativo-promo nativo-promo-2 tablet desktop smartphone"></aside>
<p>If the issue is not resolved to the offeror&#8217;s satisfaction, the offeror could consider bringing a pre-award protest—although, as a general matter, the US Government Accountability Office and the Court of Federal Claims likely will be deferential to DoD on questions related to national security and technical requirements.</p>
<p><strong>Follow the development of assessment challenges.</strong> One of the most significant concerns for contractors of all sizes is what type of due process will be available if a certification level or audit result is erroneous. The CMMC assessments could have a significant impact on contractors&#8217; ability to meet minimum contract requirements, and a low rating could limit a contractor&#8217;s ability to meaningfully compete for work.</p>
<p>Currently, the CMMC does not establish a contractor&#8217;s right of appeal, although DoD indicates it is coming. This is an important development to follow. Where possible, contractors should provide DoD detailed feedback on any proposed due process procedures to ensure it is adequate.</p>
<p><strong>Prepare to be agile.</strong> CMMC certification will soon be a minimum requirement to be eligible for DoD contract awards, but this does not mean that contractors should view their cyber-compliance as “complete” once certification is achieved. DoD has emphasized that the CMMC is a starting point for transforming contractors’ internal cybersecurity culture and that industry must focus on preparing for evolving threats, not simply achieving CMMC certification. Contractors that foster a culture of cyber resiliency and flexibility within their organizations, in addition to obtaining CMMC certification, will be best positioned to compete in a marketplace that is and will continue to be less tolerant of accepting cyber-related risks.</p>
</section>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cybersecurity Awareness Training</title>
		<link>http://zonics.com/portfolio/security-awareness-training/</link>
		
		<dc:creator><![CDATA[wschadejr]]></dc:creator>
		<pubDate>Fri, 26 Feb 2021 11:01:20 +0000</pubDate>
				<guid isPermaLink="false">http://demo.prosystheme.com/business-ezone-pro/?post_type=portfolio&#038;p=120</guid>

					<description><![CDATA[The biggest, most damaging and most widespread threat facing small businesses are phishing attacks. Phishing accounts for 90% of all breaches that organizations face, they've grown 65% over the last year, and they account for over $12 billion in business losses.]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="wp-image-428 alignnone" src="http://zonics.com/wp-content/uploads/2021/04/SAT-528x408-1-300x232.jpg" alt="" width="979" height="758" srcset="http://zonics.com/wp-content/uploads/2021/04/SAT-528x408-1-300x232.jpg 300w, http://zonics.com/wp-content/uploads/2021/04/SAT-528x408-1.jpg 528w" sizes="auto, (max-width: 979px) 100vw, 979px" /></p>
<p>&nbsp;</p>
<div id="hs_cos_wrapper_module_158083985570054" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_module" data-hs-cos-general-type="widget" data-hs-cos-type="module">
<div id="featured_snippet_wrapper">
<div id="featured_snippet_area">
<h3>Top Reasons Your Employees are Your Biggest Cybersecurity Threat</h3>
<hr />
<ol>
<li>Falling for phishing attacks and scams</li>
<li>Becoming a victim of social engineering</li>
<li>Unrestrained web browsing</li>
<li>Bad password habits</li>
<li>Vulnerable document processes</li>
</ol>
</div>
</div>
</div>
<h3>Our preventative solution has three components</h3>
<ol>
<li>interactive security training,</li>
<li>simulated phishing campaigns,</li>
<li>reporting.</li>
</ol>
<p>All of these features are included to provide the very best experience possible.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cybersecurity Assessments</title>
		<link>http://zonics.com/portfolio/cybersecurity-assessments/</link>
		
		<dc:creator><![CDATA[wschadejr]]></dc:creator>
		<pubDate>Wed, 24 Feb 2021 11:05:19 +0000</pubDate>
				<guid isPermaLink="false">http://demo.prosystheme.com/business-ezone-pro/?post_type=portfolio&#038;p=122</guid>

					<description><![CDATA[Our Philosophy
Understanding our client is critical – what you do, what you want, and what you are afraid of. Our assessment isn’t about your cybersecurity – it is about your business, your wealth, and your reputation......]]></description>
										<content:encoded><![CDATA[<h1></h1>
<p><img loading="lazy" decoding="async" class="wp-image-432 aligncenter" src="http://zonics.com/wp-content/uploads/2021/04/Security-Risk-Assessment-OIP-300x124.jpg" alt="" width="641" height="265" srcset="http://zonics.com/wp-content/uploads/2021/04/Security-Risk-Assessment-OIP-300x124.jpg 300w, http://zonics.com/wp-content/uploads/2021/04/Security-Risk-Assessment-OIP.jpg 487w" sizes="auto, (max-width: 641px) 100vw, 641px" /><span id="more-251"></span></p>
<div style="width: 1170px;" class="wp-video"><!--[if lt IE 9]><script>document.createElement('video');</script><![endif]-->
<video class="wp-video-shortcode" id="video-251-1" width="1170" height="658" preload="auto" controls="controls"><source type="video/mp4" src="http://zonics.com/wp-content/uploads/2021/04/PS_Video_SecurityV2-Assessment.mp4?_=1" /><a href="http://zonics.com/wp-content/uploads/2021/04/PS_Video_SecurityV2-Assessment.mp4">http://zonics.com/wp-content/uploads/2021/04/PS_Video_SecurityV2-Assessment.mp4</a></video></div>
<h3>Our Philosophy</h3>
<div class="entry">
<p>Understanding our client is critical – what you do, what you want, and what you are afraid of. Our assessment isn’t about your cybersecurity – it is about your business, your wealth, and your reputation.  We are not in the Business of Cybersecurity. Instead, we are in the Cybersecurity of Business – YOUR BUSINESS.  YOU don’t care about what WE do. YOU don’t want Managed Services. YOU don’t want cybersecurity or compliance services.  YOU want Peace-of-Mind and the ability to focus on your business and life goals. We will show YOU that we can do that and YOU will win!</p>
<p>Our Industry Cheat Sheets identify YOUR challenges and how we are critical to YOUR success.</p>
<p><strong>Focused Industry:</strong></p>
<ul>
<li><strong>Industry Cheat Sheet- Government Contractor Subcontractor</strong></li>
<li><strong>Industry Cheat Sheet- Healthcare</strong></li>
<li><strong>Industry Cheat Sheet- K-12 Education</strong></li>
<li><strong>Industry Cheat Sheet- Law Firms</strong></li>
<li><strong>Industry Cheat Sheet- Local Government</strong></li>
<li><strong>Industry Cheat Sheet- Manufac</strong><strong>t</strong><strong>uring</strong></li>
</ul>
</div>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
