top of page

All Posts


How CMMC Workforce Compliance Training Delivered via eLearning Creates Attestable Artifacts of Completion and Compliance
Ensuring your workforce meets cybersecurity standards is no longer optional. The Cybersecurity Maturity Model Certification (CMMC) sets clear expectations for organizations working with the Department of Defense (DoD). But how do you effectively train your team and prove they’ve completed the required compliance training and annual refreshers? That’s where CMMC workforce compliance training delivered through eLearning shines. It offers a flexible, scalable way to educate empl
Brian McCarthy
Jun 104 min read


Why NIST Essentials Matter for Your Staff
When it comes to protecting sensitive information and maintaining a secure organizational environment, NIST essentials are not just a checkbox on a to-do list. They are a critical foundation for building trust, safeguarding assets, and ensuring smooth operations. But here’s the thing: compliance isn’t just about policies and paperwork. It’s about people. Your staff is the frontline defenders in this ongoing battle against cyber threats and data breaches. So, why does NIST tra
Brian McCarthy
Jun 23 min read


The Importance of NIST Staff Training for Organizational Success
When it comes to safeguarding sensitive information and maintaining robust cybersecurity, organizations cannot afford to overlook the value of proper training. I’ve seen firsthand how investing in NIST staff training can transform a company’s security posture and overall operational efficiency. It’s not just about ticking a compliance box; it’s about empowering your team to understand, implement, and maintain critical security standards that protect your business and your cli
Brian McCarthy
May 113 min read


Smart devices are making cybersecurity choices on your behalf. Are you asking the right questions?
Think about the refrigerator in your break room, the badge reader at your front door, the industrial sensor on your production floor, and the camera watching your parking lot. These devices don’t fit the usual IT asset profiles. Most vulnerability scanners overlook them, and they are rarely mentioned in insurance applications or board risk briefings. Still, these devices are connected to your network. They store and transmit data and can be compromised. When that happens, whe
Brian McCarthy
Apr 208 min read


The Evolving Regulatory Landscape in Industrial Automation: What Oil and Gas Executives Must Know
Most oil and gas executives have heard of NIS2, but many do not realize it holds them personally accountable for compliance, not just their IT or OT teams. This is not a simple compliance checkbox. In several EU jurisdictions, non-compliance may result in temporary suspension from management roles and significant fines. This is only one regulation among many that have expanded significantly in the past 18 months. Here is what oil and gas boards and senior executives need to k
Brian McCarthy
Apr 17 min read


From Assumption to Evidence: How the IIA's Competency Framework Is Changing What Good Internal Audit Looks Like
What It Is, Why It Matters, and What You Need to Do About It Ask most organizations if their internal audit function has the right capabilities. Most say, "Yes, they're experienced, they deliver, and we haven't had any problems." That isn't enough anymore. The IIA released the updated Internal Auditing Competency Framework™ in June 2025, changing how internal audit capability is assessed, demonstrated, and reported — for individual auditors, chief audit executives (CAEs), and
Brian McCarthy
Mar 317 min read
The Importance of CMMC Awareness Training for Defense Contractors to Safeguard Data and National Security
Cybercriminals are increasingly targeting the Defense Industrial Base (DIB) with sophisticated attacks. Even one vulnerability can compromise your personnel, intellectual property, and business operations. The Cybersecurity Maturity Model Certification (CMMC) is more than a DoD requirement; it is a framework designed to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The Awareness and Training (AT) domain is central to CMMC 2.0. Techn
Brian McCarthy
Mar 274 min read
How Generative AI Is Revolutionizing Instructional Design in 2026
Instructional design has always balanced art and science building experiences that foster real behavior change while conforming to pedagogical principles. In 2026, generative AI (GenAI) is transforming that balance, not by replacing instructional designers, but by fundamentally evolving their role. GenAI rapidly accelerates workflows and allows personalized learning at scale, positioning designers as strategists who drive impact and inclusivity. GenAI tools quickly draft obj
Brian McCarthy
Mar 275 min read
The Compliance Landscape Every Organization Must Know in 2026 | 10 min read
Cyber & Risk Governance | March 2026 | 10 min read Compliance is a top concern for auditors, risk officers, and board members. Organizations recognize that the regulatory landscape for cybersecurity, data protection, and governance is changing rapidly. In 2025 and 2026, new global regulations are pushing accountability upward to executives, directors, and governance bodies while enlarging the scope of compliance. Cybersecurity is now a boardroom obligation, an audit priority,
Brian McCarthy
Mar 267 min read
bottom of page