Behind the Shield

InfusionPoints

 Behind the Shield is InfusionPoints’ podcast where we sit down with partners, customers, and industry leaders to talk about FedRAMP, compliance, and cybersecurity in today’s government landscape. Each episode offers laid-back, insightful conversations that blend expertise with real-world experiences. 

  1. 2h ago

    Compliance at Machine Speed with Tieu Luu: AI, Continuous Monitoring, NIST & FedRAMP 20x

    What happens when compliance starts operating at machine speed? In this episode of Behind the Shield, Gary Daemer sits down with Tieu Luu, Chief Product Officer at Qmulos, to explore the evolution of compliance automation, continuous monitoring, AI, and evidence-driven security. Tieu shares how Qmulos approaches compliance as a massive data problem, using security telemetry, automation, analytics, and Splunk to help organizations assess whether security controls are operating effectively. The conversation explores the challenges of automating NIST 800-53 controls, collecting technical evidence at scale, normalizing data across different technologies, and keeping human assessors in the loop. Gary and Tieu also discuss the growing role of AI and agentic technologies in cybersecurity and compliance, from generating documentation and SSP content to automating control assessments, analyzing large volumes of security data, and accelerating software development. They also explore one of the biggest challenges emerging alongside that speed: how organizations verify and validate what AI produces. The conversation turns to FedRAMP 20x and the broader movement toward continuous proof, machine-readable evidence, automated validation, and security outcomes that can be demonstrated continuously rather than through periodic compliance exercises. For CISOs, CIOs, cybersecurity leaders, compliance teams, cloud service providers, and anyone working with FedRAMP, NIST 800-53, GRC, or continuous monitoring, this episode offers a look at where compliance automation is heading and why security and compliance increasingly need to operate as two sides of the same coin. WHAT YOU’LL LEARN: • Why compliance automation is fundamentally a data problem • How organizations can automate evidence collection using security telemetry • Where NIST 800-53 controls can and cannot realistically be automated • How continuous monitoring can provide ongoing insight into control effectiveness • Why normalized data models matter when working across multiple security technologies • How AI and agentic technologies could transform control assessments and compliance workflows • Why human verification and validation still matter as AI accelerates development • How FedRAMP 20x is advancing continuous proof and automated security validation • Why security and compliance need to operate at the same speed • How building security correctly from the beginning can make compliance a natural byproduct CHAPTERS: 0:00 - Introduction to Tieu Luu 1:33 - Qmulos, Splunk, and Compliance Automation 6:45 - The Challenges of Automating Compliance 9:26 - Automating Evidence Collection 11:30 - Security Telemetry vs. Screenshots 14:06 - Continuous Monitoring Across Complex Environments 18:18 - Compliance as a Massive Data Problem 23:01 - Building a Common Data Model for Security Evidence 24:55 - How AI Is Changing Compliance Automation 27:21 - AI, Security Operations, and Incident Response 29:24 - Bringing SOC Speed to Compliance 31:26 - FedRAMP 20x and Continuous Proof 36:15 - Building Teams in the Age of AI 38:31 - Validating and Evaluating AI-Generated Work 40:25 - Where InfusionPoints and Qmulos Align 42:09 - Why Security and Compliance Are Two Sides of the Same Coin 43:34 - Closing Thoughts Guest Links: Tieu Luu: https://www.linkedin.com/in/tieuluu/ Qmulos: https://www.linkedin.com/company/qmulos/about/ https://qmulos.com/ InfusionPoints Links: Gary Daemer: https://www.linkedin.com/in/infusionpoints/ InfusionPoints: https://www.linkedin.com/company/infusionpoints/ Continuous Trust Platform: https://infpts.com/platform https://infusionpoints.com/ InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints helps organizations Build. Operate. Prove. Defend. secure, mission-ready environments in highly regulated markets. Our Continuous Trust Platform brings cloud, cybersecurity, compliance, and operations together to support FedRAMP, FedRAMP 20x, DoD, and other critical security requirements with greater automation, visibility, and continuous readiness.

  2. 2h ago

    One Year of Behind the Shield: FedRAMP 20x, Cybersecurity and Lessons from the InfusionPoints Team

    Behind the Shield is officially one year old, and we’re looking back at how the show started, what we’ve learned along the way, and some of the moments that shaped its first year. For the first time ever, Behind the Shield producer Caitlin Pitkin steps out from behind the camera and joins the conversation. Felisha Daemer and Caitlin Pitkin reflect on Caitlin’s path to InfusionPoints, how producing nearly 50 episodes of Behind the Shield accelerated her understanding of FedRAMP, cybersecurity, cloud security, and compliance, and how the podcast has evolved alongside a rapidly changing industry. They also bring a little personality to the anniversary episode, with Caitlin repping Harry Styles and Felisha wearing Spiritbox as a subtle nod to the music they love. Throughout the episode, Chad Spears, Mike Strohecker, Jason Shropshire, and Gary Daemer share favorite moments, lessons learned, behind-the-scenes stories, and reflections on how Behind the Shield has evolved. A major part of that evolution has been FedRAMP. When Behind the Shield began, the federal cloud security landscape was already changing quickly. Over the course of the first year, the podcast became a place to break down FedRAMP updates, FedRAMP 20x, vulnerability management, continuous monitoring, automated evidence, cloud security, and the broader shift toward more continuous approaches to trust and compliance. Rather than simply reacting to new requirements, the team has used Behind the Shield to make complex FedRAMP and cybersecurity topics easier to understand, explain what changes mean in practice, and help CSPs, government teams, and security professionals keep up with a rapidly evolving environment. The episode also brings things full circle as Jason Shropshire and Gary Daemer revisit the earliest days of the show and react to our first-ever Behind the Shield recording. It has been a year of learning, experimenting, technical difficulties, great guests, plenty of laughs, and a lot of conversations about where FedRAMP, cybersecurity, and compliance are headed next. In lieu of Caitlin's Favorite non-industry podcast, Armchair Expert, Here's a quick fact check section: High flyer host count- Gary: 24 Jason: 19 Chad: 9  Mike: 9 Felisha: 5  How long it takes to upload to Youtube: In realtime, it's at 37% and has said "1 hour and 10 minutes left" for 10 minutes.  Here’s to year two. WHAT YOU’LL LEARN: • How Behind the Shield grew into a cybersecurity and FedRAMP podcast • How producing the show helped Caitlin Pitkin learn FedRAMP, cloud security, and compliance • How FedRAMP 20x, vulnerability management, automation, and continuous trust shaped the first year • How Chad Spears’ ransomware experience influenced his cybersecurity career • Favorite moments and lessons from Chad Spears, Mike Strohecker, Jason Shropshire, Gary Daemer, Felisha Daemer, and Caitlin Pitkin • How the podcast has evolved and what’s ahead for year two Chapters:  0:00 - Episode kickoff and the show’s first year  2:20 - Caitlin’s path to InfusionPoints  5:48 - Stepping in front of the camera  12:21 - Why the podcast launched  16:36 - What’s ahead in season two  24:51 - Chad's path into IT and cybersecurity  28:03 - The ransomware attack that changed everything  33:47 - Memorable moments and fun facts  43:45 - Mike Strohecker interview  57:35 - Making short-form content for a technical audience  01:05:09 - Looking back at the first episode  01:15:20 - Favorite episodes and standout guests  01:28:18 - The podcast’s impact on customers and the industry  01:32:13 - Closing thoughts Links:  Caitlin Pitkin: https://www.linkedin.com/in/caitlin-pitkin/ Felisha Daemer: https://www.linkedin.com/in/felisha-daemer/ Chad Spears: https://www.linkedin.com/in/chad-spears007/ Mike Strohecker: https://www.linkedin.com/in/michael-strohecker-238326172/ Jason Shropshire: https://www.linkedin.com/in/shrop/ Gary Daemer: https://www.linkedin.com/in/infusionpoints/ InfusionPoints: https://www.linkedin.com/company/infusionpoints/ Continuous Trust Platform: https://infpts.com/platform https://infusionpoints.com/ InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints helps organizations Build. Operate. Prove. Defend. secure, mission-ready environments in highly regulated markets. Our Continuous Trust Platform brings cloud, cybersecurity, compliance, and operations together to support FedRAMP, FedRAMP 20x, DoD, and other critical security requirements with greater automation, visibility, and continuous readiness.

  3. Sep 22

    FedRAMP CR26 Explained: VDR/VER, Key Deadlines & the Move to 20x

    FedRAMP CR26 is changing how Cloud Service Providers approach vulnerability management, continuous monitoring, compliance, and the transition to FedRAMP 20x. In the Season 1 finale of Behind the Shield, Mike Strohecker and Aidan Fratcher break down the Consolidated Rule Set 2026 (CR26), including what CSPs need to prioritize now, how VDR and VER are changing traditional vulnerability management, and how Binding Operational Directive 26-04 is accelerating key vulnerability management requirements and timelines for CSPs. They also dig into some of the biggest areas of confusion surrounding CR26, including the difference between “must” and “should” requirements, what FedRAMP means by obtain, maintain, and grace period deadlines, and how security, compliance, engineering, and operations teams will need to work together as FedRAMP continues moving toward a more automated, continuous model. What You’ll Learn • What CR26 means for Cloud Service Providers • Why VDR and VER are among the most immediate priorities for CSPs • How BOD 26-04 impacts VDR and VER implementation timelines • How vulnerability management is shifting beyond traditional 30/90/180-day remediation timelines • Why vulnerability scanning failures can become vulnerabilities themselves • How CSPs can operationalize VDR and VER across CloudOps, SOC, engineering, and compliance teams • What FedRAMP means by “must” and “should” requirements • The difference between obtain, maintain, and grace period deadlines • What upcoming CR26 deadlines mean for existing and new FedRAMP authorizations • How CR26 supports the broader transition from Rev. 5 to FedRAMP 20x • Why continuous security evidence and automation are becoming increasingly important to the FedRAMP model Chapters 0:00 Introduction and Overview of CR 26 0:05 Understanding CR 26 and Its Implications 1:19 Vulnerability Management in CR 26 3:14 Prioritizing Vulnerability Management 4:43 Operationalizing Vulnerability Management 7:26 Continuous Scanning and Security Operations 9:26 Understanding Vulnerability Management in Federal Compliance 14:14 The Importance of Incident Response Plans 19:55 Navigating Must and Should Requirements 24:02 Clarifying Obtain, Maintain, and Grace Periods 29:01 Transitioning to FedRAMP 20X 31:10 Looking Ahead: Expectations for CR 27 Links:  CR26 Whitepaper: Coming soon Mike Strohecker: https://www.linkedin.com/in/michael-strohecker-238326172/ Aidan Fratcher: https://www.linkedin.com/in/aidanfratcher/ InfusionPoints: https://www.linkedin.com/company/infusionpoints/ Continuous Trust Platform: https://infpts.com/platform https://infusionpoints.com/ InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets. We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement. Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.

  4. Sep 2

    The SOC That Changed Everything: 10 Years of Lessons, Growth, and Grit

    Ten years ago, InfusionPoints was faced with a challenge that went far beyond building another security tool or checking another box on a compliance checklist. While building and securing the Dell Cloud for US government, Dell needed more than an architecture, more than a FedRAMP package, and more than documented security controls. They needed people who could actively watch the environment, manage incidents, support continuous monitoring, and provide the evidence required to operate a federal cloud on US soil with US citizens. The question was simple, but the responsibility was enormous: Who’s watching now? That question became the foundation for what would become VNSOC 360. What began as a customer requirement grew into a 24/7/365 security operations capability and ultimately became a defining part of Infusion Points. Over the past decade, the SOC has evolved from a room with monitors and dashboards into a disciplined security operation built around people, processes, technology, and continuous improvement. In this special 10 year anniversary episode of Behind the Shield, we go behind the scenes with the people who have been there throughout that journey. From the early days of standing up the SOC and building operating procedures, escalation paths, response playbooks, shift schedules, ticketing, and reporting, to the sophisticated security operations environment of today, this episode is a look at what it really takes to protect customers every hour of every day. Join Chad Spears, along with Levi Church, Eric Bowles, Alex Earhart, and Jeremy Powers, as they share their experiences from inside the SOC. Speakers • Gary Daemer, CEO, InfusionPoints • Chad Spears, CISO, InfusionPoints • Levi Church, Information Security Analyst, InfusionPoints • Eric Boles, SOC Analyst Lead, InfusionPoints • Alex Earhart, Lead Security Operations Engineer, InfusionPoints • Jeremy Powers, Senior SIEM Engineer, InfusionPoints What You’ll Learn: •  The origin story of VNSOC 360 •  What it takes to operate a SOC 24/7/365 •  The people behind the alerts and incidents •  Career growth from analyst to leadership and engineering •  How cloud, automation, and AI have transformed the SOC  •  Lessons learned from a decade of cybersecurity operations  •  The CrowdStrike outage and other memorable moments  •  What the next 10 years could look like for security operations  Chapters: 00:08 — 10 years of VNSOC 360 03:44 — Chad on the anniversary episode 05:39 — Levi Church’s SOC journey and shift work 18:31 — Eric Boles on leadership, customers, and morale 31:45 — Alex Earhart on engineering, audits, and AI 46:38 — Jeremy Powers on the SOC’s history and growth 01:01:28 — The CrowdStrike event and team response 01:09:31 — 10 years of growth and what’s next InfusionPoints LinkedIn Links: https://www.linkedin.com/company/infusionpoints/  Gary Daemer, CEO, InfusionPoints - https://www.linkedin.com/in/infusionpoints/ Chad Spears, CISO, InfusionPoints - https://www.linkedin.com/in/chad-spears007/ Levi Church, Information Security Analyst, InfusionPoints - https://www.linkedin.com/in/levichurch/ Eric Boles, SOC Analyst Lead, InfusionPoints - https://www.linkedin.com/in/erik-boles-935741221/ Alex Earhart, Lead Security Operations Engineer, InfusionPoints - https://www.linkedin.com/in/charles-e-7a2b8016a/ Jeremy Powers, Senior SIEM Engineer, InfusionPoints - https://www.linkedin.com/in/jeremepowers/ InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets. We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement. Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.

  5. Aug 22

    FedRAMP 20x, GRC & the Future of Compliance with Michael Peters

    What does it take to build a cybersecurity company for the long haul while keeping pace with an industry that never stops changing? In this episode of Behind the Shield, we sit down with Michael Peters of Lazarus Alliance to talk about his unconventional path from playing in a rock band to building a career in cybersecurity, the evolution of Lazarus Alliance, and what he has learned from decades of navigating security, compliance, and entrepreneurship. The conversation dives into the realities of the FedRAMP process, where traditional GRC tools fall short, the growing role of OSCAL, and how AI and automation could reshape compliance engineering. Michael also shares his perspective on building an evergreen company and why sustainable growth can look very different from the traditional venture-backed model. A quick note before you watch: This episode was recorded in late May 2026, so the FedRAMP landscape has continued to evolve since this conversation, particularly around Rev. 5 and the broader transition toward FedRAMP 20x. Some of the specific timelines, requirements, and processes discussed reflect what was known at the time of recording. You may also notice our previous InfusionPoints branding throughout the episode. We’ve had a bit of a glow-up since then, but the conversation was too good not to share. What You’ll Learn -How Michael went from the music world to cybersecurity -Lessons learned from building and growing Lazarus Alliance -The challenges organizations face navigating FedRAMP -Where GRC platforms and OSCAL are headed -Why compliance engineering needs more automation -How AI could change the future of GRC -The advantages of the evergreen company model -Why cybersecurity and compliance processes need to evolve alongside  -the technology they protect Chapters 0:00 - Introduction to Cybersecurity and Compliance 3:22 - The Journey of Building a Business 7:16 - From Rock Band to Cybersecurity 11:22 - The Evolution of Lazarus Alliance 16:34 - Navigating the FedRAMP Process 23:42 - The Future of GRC Tools and OSCAL 28:14 - Revamping Processes in Compliance Engineering 31:21 - The Future of GRC: AI and Automation 42:18 - Evergreen Companies: A Sustainable Business Model 45:56 - Navigating Compliance Challenges in the Industry Guest Links: Michael Peters- https://www.linkedin.com/in/michaeldpeters Lazarus Alliance- https://www.linkedin.com/company/lazarus-alliance/ https://lazarusalliance.com/ Continuum- https://continuumgrc.com/ Connect with InfusionPoints:  Gary Daemer: https://www.linkedin.com/in/infusionpoints/ InfusionPoints: https://www.infusionpoints.com InfusionPoints LinkedIn: https://www.linkedin.com/company/infusionpoints/ InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints helps organizations Build, Operate, Prove, and Defend secure, mission-ready environments in highly regulated markets. We combine cybersecurity, cloud engineering, compliance, and real-world operations expertise across FedRAMP, FedRAMP 20x, DoD, and enterprise frameworks. Through our Continuous Trust approach, we help customers move faster, maintain compliance, and strengthen security from authorization through ongoing operations.

  6. Aug 6

    Zero Trust Is Not a Product: Building, Proving, and Automating the Architecture

    Zero Trust is everywhere in cybersecurity conversations, but it is not a single product, tool, or technology. It is a fundamentally different way of designing, securing, and operating an entire system. In this episode of Behind the Shield, Gary Daemer welcomes Michael Schroeder back to the podcast for a practical conversation about what Zero Trust really means, how it evolved from an architectural concept into federal policy, and why implementation requires more than adding MFA or replacing a VPN. They explore the five pillars of Zero Trust, the maturity models and federal guidance shaping adoption, and the identity, access, architecture, and cultural challenges agencies and cloud service providers must overcome. They also examine one of the biggest remaining questions: How do organizations continuously prove that their Zero Trust architecture is actually working? The conversation covers assessment and validation, commercial applications, just-in-time access, least privilege, observability, logging, automation, and the technologies that may shape the next phase of Zero Trust adoption. This episode also marks a new chapter for Behind the Shield as the first release featuring our new branded introduction and refreshed thumbnail. What You’ll Learn • Why Zero Trust is an architecture, not a product • What it means to operate without inherited or implicit trust • The five pillars of the CISA Zero Trust Maturity Model • How visibility, automation, and governance support every pillar • How Zero Trust evolved from industry principles into federal policy • The roles of NIST, CISA, OMB, NSA, and federal Zero Trust guidance • Why identity, MFA, least privilege, and time-limited access are foundational • How human and non-human identities create different security challenges • Why legacy architecture and standing privileges complicate implementation • How organizational culture can become a bigger obstacle than technology • What Zero Trust validation could look like beyond checklists and self-attestation • Why cost, interoperability, motivation, and assessment remain barriers to adoption • How Zero Trust principles can reduce risk for commercial organizations • How automation, logging, observability, and just-in-time access support implementation • What may come next as federal agencies and technology providers continue to mature Chapters 0:00 - Zero Trust Foundations 5:38 - Maturity Models and Federal Guidance 11:26 - How Zero Trust Became Federal Policy 15:57 - Identity, MFA, and Access Control 22:59 - Architecture and Cultural Challenges 26:58 - Validating Zero Trust Compliance 31:05 - Barriers to Adoption and Commercial Impact 36:05 - Practical Implementation and Automation 42:35 - What’s Next for Zero Trust Guest Links: https://www.linkedin.com/in/mjschroeder1/ https://www.linkedin.com/company/excentium/ https://excentium.com/ Connect with InfusionPoints:  Gary Daemer: https://www.linkedin.com/in/infusionpoints/ InfusionPoints: https://www.infusionpoints.com InfusionPoints LinkedIn: https://www.linkedin.com/company/infusionpoints/ InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints helps organizations Build, Operate, Prove, and Defend secure, mission-ready environments in highly regulated markets. We combine cybersecurity, cloud engineering, compliance, and real-world operations expertise across FedRAMP, FedRAMP 20x, DoD, and enterprise frameworks. Through our Continuous Trust approach, we help customers move faster, maintain compliance, and strengthen security from authorization through ongoing operations.

  7. Aug 3

    Beyond the Digital Perimeter: Drones, Radar, and the Future of Physical Security

    Behind the Shield is taking a slight detour. Most episodes focus on cloud security, cybersecurity compliance, and mission systems inside the data center. This time, Gary steps outside the digital perimeter with Logan Harris, CEO of Spotter Global, to explore threats surrounding critical infrastructure, military sites, airports, utilities, and data centers. Logan shares how his work evolved from traffic-monitoring radar into lightweight surveillance systems for military missions. Technology that once required hundreds of pounds of equipment was reduced to only a few pounds, creating new possibilities for drones, operations, and perimeter monitoring. The conversation then turns to a fast-growing security concern: drones. Gary and Logan discuss how inexpensive commercial drones, fiber-optic-guided systems, autonomous navigation, and coordinated swarms are changing the threat landscape. They explain why GPS and communication jamming may no longer be enough when drones can operate without emitting a detectable signal. They also examine how radar, remote identification, cameras, AI analysis, and common operating pictures can identify aircraft, locate operators, reduce false positives, and help teams respond. Although this episode ventures beyond our usual topics, the parallels are clear. Physical security teams face many of the same challenges as cybersecurity operations centers: collecting sensor data, identifying threats, reducing noise, maintaining human oversight, and moving from detection to response. It is a different kind of perimeter, but the question remains the same: once you detect a threat, what can you actually do about it? Chapters 00:00 - Introduction 00:12 - Welcome to Behind the Shield 00:58 - Logan Harris and Spotter Global’s origin story 02:38 - From airborne radar to ground surveillance 04:08 - Supporting special operations and village stability missions 06:48 - The Metcalf substation attack and pivot to critical infrastructure 09:01 - Miniaturizing radar with modern wireless and DSP tech 13:08 - The new threat: FPV and fiber-optic drones 16:51 - Detection, remote ID, and operator location tracking 23:21 - What drone mitigation looks like today 27:26 - The Critical Infrastructure Airspace Defense Act 29:57 - AI, autonomous drones, and the future battlefield 32:39 - Holographic 3D radar and swarm detection 33:56 - How the system distinguishes drones from birds and clutter 37:25 - Biggest adoption challenges: education and regulation 41:28 - Funding model and commercial vs. military customers 43:29 - Books, documentaries, and personal recommendations 46:07 - Compliance, integration, and future follow-up topics 50:19 - Closing thoughts on drone threats and infrastructure risk What You’ll Learn • How military radar technology evolved into commercial perimeter security • Why drones are creating new risks for critical infrastructure and data centers • How radar, remote ID, cameras, and AI work together to identify threats • Why fiber-optic and autonomous drones are difficult to detect or disrupt • The similarities between physical security operations and a cybersecurity SOC • How legal restrictions affect drone detection, mitigation, and response Connect with Logan Harris and Spotter Global: Logan Harris: https://www.linkedin.com/in/lh1937/ Spotter Global: https://www.spotterglobal.com/ Spotter Global LinkedIn: https://www.linkedin.com/company/spotterglobal/ Links Reference:  https://www.congress.gov/bill/119th-congress/senate-bill/4380/all-actions-without-amendments https://www.cotton.senate.gov/news/press-releases/cotton-introduces-bill-to-protect-critical-infrastructure-from-drones https://www.spotterglobal.com/blog/spotter-blog-3/spotter-global-s-gax500-3d-radar-wins-prestigious-sia-award-delivering-unprecedented-security-against-drone-swarms-88 Connect with InfusionPoints:  Gary Daemer: https://www.linkedin.com/in/infusionpoints/ InfusionPoints: https://www.infusionpoints.com InfusionPoints LinkedIn: https://www.linkedin.com/company/infusionpoints/ InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints helps organizations Build, Operate, Prove, and Defend secure, mission-ready environments in highly regulated markets. We combine cybersecurity, cloud engineering, compliance, and real-world operations expertise across FedRAMP, FedRAMP 20x, DoD, and enterprise frameworks. Through our Continuous Trust approach, we help customers move faster, maintain compliance, and strengthen security from authorization through ongoing operations.

    Beyond the Digital Perimeter: Drones, Radar, and the Future of Physical Security
  8. Jul 21

    Meet “Vader”: FedRAMP VDR & VER, PAIN Scores, and the New Era of Vulnerability Response

    Yes, this episode starts with Jason playing the Darth Vader sound. Around here, we pronounce VDR like “Vader,” so naturally, he had to commit to the bit. Once the Imperial March ends, Jason and Mike break down two of the most important pieces of the evolving FedRAMP vulnerability management model: Vulnerability Detection and Response, or VDR, and Vulnerability Evaluation and Reporting, or VER. These requirements represent a major shift away from monthly vulnerability snapshots, blanket CVSS-based remediation timelines, and compliance processes built around spreadsheets and static reporting. Instead, CSPs will need to continuously identify vulnerabilities, evaluate them within the actual context of their environments, prioritize them based on real agency risk, and share actionable information with federal customers. The conversation explores how the new PAIN scoring model changes vulnerability prioritization by considering factors such as exploitability, internet reachability, system architecture, federal data impact, and the likelihood that a vulnerability could actually be used against a specific environment. Jason and Mike also discuss why scanners alone cannot provide all the context CSPs will need. Security, engineering, architecture, DevSecOps, and SOC teams will have to work together to understand how resources connect, what vulnerabilities truly affect, and which mitigations can immediately reduce risk while permanent remediation moves through the engineering process. For some of the highest-risk vulnerabilities, remediation or risk reduction timelines may be measured in hours rather than weeks. That means vulnerability management must begin operating more like incident response, with continuous visibility, automated analysis, real-time alerting, and teams prepared to respond outside of a traditional monthly reporting cycle. The episode also examines what these changes mean for existing FedRAMP Rev. 5 CSPs, agency reporting, POA&M processes, CI/CD pipelines, 3PAO assessments, automation, AI-assisted analysis, and communication between CSPs and their agency sponsors. Ultimately, VDR and VER are about moving beyond checking the box. The goal is to give agencies better visibility into their actual risk while allowing CSPs to focus their time and resources on the vulnerabilities that matter most. What You’ll Learn • The key differences between VDR and VER • Why vulnerability management is moving beyond monthly scans and CVSS scores • How PAIN scores add real-world risk and agency context • What continuous monitoring and faster remediation timelines mean for CSPs • Why security, engineering, SOC, and DevSecOps teams must work together • How automation and AI can support vulnerability analysis at scale • What CSPs should discuss with agency sponsors and prepare for now Chapters 0:00: Understanding VDR and VER: The Basics 2:52: Vulnerability Detection Response (VDR) Explained 5:34: Vulnerability Evaluation and Reporting (VER) Insights 8:25: The Importance of VDR and VER for CSPs 11:27: Challenges and Transitioning to New Standards 14:08: Contextualizing Vulnerabilities in Modern Environments 15:49: Challenges in Vulnerability Management 20:42: The Role of AI in Vulnerability Analysis 26:23: Understanding Remediation Timeframes 32:02: Accountability and Flexibility in Vulnerability Management 34:13: Key Questions for CSP Success Links:  Blog- https://infusionpoints.com/blogs/fedramp-vdr-and-ver-monthly-scans-continuous-trust Jason Shropshire- https://www.linkedin.com/in/shrop/ Mike Strohecker- https://www.linkedin.com/in/michael-strohecker-238326172/ Https://www.InfusionPoints.com  LinkedIn: https://www.linkedin.com/company/infusionpoints/ InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets. We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement. Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.

Ratings & Reviews

5
out of 5
2 Ratings

About

 Behind the Shield is InfusionPoints’ podcast where we sit down with partners, customers, and industry leaders to talk about FedRAMP, compliance, and cybersecurity in today’s government landscape. Each episode offers laid-back, insightful conversations that blend expertise with real-world experiences.