Behind the Shield

InfusionPoints

 Behind the Shield is InfusionPoints’ podcast where we sit down with partners, customers, and industry leaders to talk about FedRAMP, compliance, and cybersecurity in today’s government landscape. Each episode offers laid-back, insightful conversations that blend expertise with real-world experiences. 

  1. 6d ago

    The SOC That Changed Everything: 10 Years of Lessons, Growth, and Grit

    Ten years ago, InfusionPoints was faced with a challenge that went far beyond building another security tool or checking another box on a compliance checklist. While building and securing the Dell Cloud for US government, Dell needed more than an architecture, more than a FedRAMP package, and more than documented security controls. They needed people who could actively watch the environment, manage incidents, support continuous monitoring, and provide the evidence required to operate a federal cloud on US soil with US citizens. The question was simple, but the responsibility was enormous: Who’s watching now? That question became the foundation for what would become VNSOC 360. What began as a customer requirement grew into a 24/7/365 security operations capability and ultimately became a defining part of Infusion Points. Over the past decade, the SOC has evolved from a room with monitors and dashboards into a disciplined security operation built around people, processes, technology, and continuous improvement. In this special 10 year anniversary episode of Behind the Shield, we go behind the scenes with the people who have been there throughout that journey. From the early days of standing up the SOC and building operating procedures, escalation paths, response playbooks, shift schedules, ticketing, and reporting, to the sophisticated security operations environment of today, this episode is a look at what it really takes to protect customers every hour of every day. Join Chad Spears, along with Levi Church, Eric Bowles, Alex Earhart, and Jeremy Powers, as they share their experiences from inside the SOC. Speakers • Gary Daemer, CEO, InfusionPoints • Chad Spears, CISO, InfusionPoints • Levi Church, Information Security Analyst, InfusionPoints • Eric Boles, SOC Analyst Lead, InfusionPoints • Alex Earhart, Lead Security Operations Engineer, InfusionPoints • Jeremy Powers, Senior SIEM Engineer, InfusionPoints What You’ll Learn: •  The origin story of VNSOC 360 •  What it takes to operate a SOC 24/7/365 •  The people behind the alerts and incidents •  Career growth from analyst to leadership and engineering •  How cloud, automation, and AI have transformed the SOC  •  Lessons learned from a decade of cybersecurity operations  •  The CrowdStrike outage and other memorable moments  •  What the next 10 years could look like for security operations  Chapters: 00:08 — 10 years of VNSOC 360 03:44 — Chad on the anniversary episode 05:39 — Levi Church’s SOC journey and shift work 18:31 — Eric Boles on leadership, customers, and morale 31:45 — Alex Earhart on engineering, audits, and AI 46:38 — Jeremy Powers on the SOC’s history and growth 01:01:28 — The CrowdStrike event and team response 01:09:31 — 10 years of growth and what’s next InfusionPoints LinkedIn Links: https://www.linkedin.com/company/infusionpoints/  Gary Daemer, CEO, InfusionPoints - https://www.linkedin.com/in/infusionpoints/ Chad Spears, CISO, InfusionPoints - https://www.linkedin.com/in/chad-spears007/ Levi Church, Information Security Analyst, InfusionPoints - https://www.linkedin.com/in/levichurch/ Eric Boles, SOC Analyst Lead, InfusionPoints - https://www.linkedin.com/in/erik-boles-935741221/ Alex Earhart, Lead Security Operations Engineer, InfusionPoints - https://www.linkedin.com/in/charles-e-7a2b8016a/ Jeremy Powers, Senior SIEM Engineer, InfusionPoints - https://www.linkedin.com/in/jeremepowers/ InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets. We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement. Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.

  2. Aug 22

    FedRAMP 20x, GRC & the Future of Compliance with Michael Peters

    What does it take to build a cybersecurity company for the long haul while keeping pace with an industry that never stops changing? In this episode of Behind the Shield, we sit down with Michael Peters of Lazarus Alliance to talk about his unconventional path from playing in a rock band to building a career in cybersecurity, the evolution of Lazarus Alliance, and what he has learned from decades of navigating security, compliance, and entrepreneurship. The conversation dives into the realities of the FedRAMP process, where traditional GRC tools fall short, the growing role of OSCAL, and how AI and automation could reshape compliance engineering. Michael also shares his perspective on building an evergreen company and why sustainable growth can look very different from the traditional venture-backed model. A quick note before you watch: This episode was recorded in late May 2026, so the FedRAMP landscape has continued to evolve since this conversation, particularly around Rev. 5 and the broader transition toward FedRAMP 20x. Some of the specific timelines, requirements, and processes discussed reflect what was known at the time of recording. You may also notice our previous InfusionPoints branding throughout the episode. We’ve had a bit of a glow-up since then, but the conversation was too good not to share. What You’ll Learn -How Michael went from the music world to cybersecurity -Lessons learned from building and growing Lazarus Alliance -The challenges organizations face navigating FedRAMP -Where GRC platforms and OSCAL are headed -Why compliance engineering needs more automation -How AI could change the future of GRC -The advantages of the evergreen company model -Why cybersecurity and compliance processes need to evolve alongside  -the technology they protect Chapters 0:00 - Introduction to Cybersecurity and Compliance 3:22 - The Journey of Building a Business 7:16 - From Rock Band to Cybersecurity 11:22 - The Evolution of Lazarus Alliance 16:34 - Navigating the FedRAMP Process 23:42 - The Future of GRC Tools and OSCAL 28:14 - Revamping Processes in Compliance Engineering 31:21 - The Future of GRC: AI and Automation 42:18 - Evergreen Companies: A Sustainable Business Model 45:56 - Navigating Compliance Challenges in the Industry Guest Links: Michael Peters- https://www.linkedin.com/in/michaeldpeters Lazarus Alliance- https://www.linkedin.com/company/lazarus-alliance/ https://lazarusalliance.com/ Continuum- https://continuumgrc.com/ Connect with InfusionPoints:  Gary Daemer: https://www.linkedin.com/in/infusionpoints/ InfusionPoints: https://www.infusionpoints.com InfusionPoints LinkedIn: https://www.linkedin.com/company/infusionpoints/ InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints helps organizations Build, Operate, Prove, and Defend secure, mission-ready environments in highly regulated markets. We combine cybersecurity, cloud engineering, compliance, and real-world operations expertise across FedRAMP, FedRAMP 20x, DoD, and enterprise frameworks. Through our Continuous Trust approach, we help customers move faster, maintain compliance, and strengthen security from authorization through ongoing operations.

  3. Aug 6

    Zero Trust Is Not a Product: Building, Proving, and Automating the Architecture

    Zero Trust is everywhere in cybersecurity conversations, but it is not a single product, tool, or technology. It is a fundamentally different way of designing, securing, and operating an entire system. In this episode of Behind the Shield, Gary Daemer welcomes Michael Schroeder back to the podcast for a practical conversation about what Zero Trust really means, how it evolved from an architectural concept into federal policy, and why implementation requires more than adding MFA or replacing a VPN. They explore the five pillars of Zero Trust, the maturity models and federal guidance shaping adoption, and the identity, access, architecture, and cultural challenges agencies and cloud service providers must overcome. They also examine one of the biggest remaining questions: How do organizations continuously prove that their Zero Trust architecture is actually working? The conversation covers assessment and validation, commercial applications, just-in-time access, least privilege, observability, logging, automation, and the technologies that may shape the next phase of Zero Trust adoption. This episode also marks a new chapter for Behind the Shield as the first release featuring our new branded introduction and refreshed thumbnail. What You’ll Learn • Why Zero Trust is an architecture, not a product • What it means to operate without inherited or implicit trust • The five pillars of the CISA Zero Trust Maturity Model • How visibility, automation, and governance support every pillar • How Zero Trust evolved from industry principles into federal policy • The roles of NIST, CISA, OMB, NSA, and federal Zero Trust guidance • Why identity, MFA, least privilege, and time-limited access are foundational • How human and non-human identities create different security challenges • Why legacy architecture and standing privileges complicate implementation • How organizational culture can become a bigger obstacle than technology • What Zero Trust validation could look like beyond checklists and self-attestation • Why cost, interoperability, motivation, and assessment remain barriers to adoption • How Zero Trust principles can reduce risk for commercial organizations • How automation, logging, observability, and just-in-time access support implementation • What may come next as federal agencies and technology providers continue to mature Chapters 0:00 - Zero Trust Foundations 5:38 - Maturity Models and Federal Guidance 11:26 - How Zero Trust Became Federal Policy 15:57 - Identity, MFA, and Access Control 22:59 - Architecture and Cultural Challenges 26:58 - Validating Zero Trust Compliance 31:05 - Barriers to Adoption and Commercial Impact 36:05 - Practical Implementation and Automation 42:35 - What’s Next for Zero Trust Guest Links: https://www.linkedin.com/in/mjschroeder1/ https://www.linkedin.com/company/excentium/ https://excentium.com/ Connect with InfusionPoints:  Gary Daemer: https://www.linkedin.com/in/infusionpoints/ InfusionPoints: https://www.infusionpoints.com InfusionPoints LinkedIn: https://www.linkedin.com/company/infusionpoints/ InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints helps organizations Build, Operate, Prove, and Defend secure, mission-ready environments in highly regulated markets. We combine cybersecurity, cloud engineering, compliance, and real-world operations expertise across FedRAMP, FedRAMP 20x, DoD, and enterprise frameworks. Through our Continuous Trust approach, we help customers move faster, maintain compliance, and strengthen security from authorization through ongoing operations.

  4. Aug 3

    Beyond the Digital Perimeter: Drones, Radar, and the Future of Physical Security

    Behind the Shield is taking a slight detour. Most episodes focus on cloud security, cybersecurity compliance, and mission systems inside the data center. This time, Gary steps outside the digital perimeter with Logan Harris, CEO of Spotter Global, to explore threats surrounding critical infrastructure, military sites, airports, utilities, and data centers. Logan shares how his work evolved from traffic-monitoring radar into lightweight surveillance systems for military missions. Technology that once required hundreds of pounds of equipment was reduced to only a few pounds, creating new possibilities for drones, operations, and perimeter monitoring. The conversation then turns to a fast-growing security concern: drones. Gary and Logan discuss how inexpensive commercial drones, fiber-optic-guided systems, autonomous navigation, and coordinated swarms are changing the threat landscape. They explain why GPS and communication jamming may no longer be enough when drones can operate without emitting a detectable signal. They also examine how radar, remote identification, cameras, AI analysis, and common operating pictures can identify aircraft, locate operators, reduce false positives, and help teams respond. Although this episode ventures beyond our usual topics, the parallels are clear. Physical security teams face many of the same challenges as cybersecurity operations centers: collecting sensor data, identifying threats, reducing noise, maintaining human oversight, and moving from detection to response. It is a different kind of perimeter, but the question remains the same: once you detect a threat, what can you actually do about it? Chapters 00:00 - Introduction 00:12 - Welcome to Behind the Shield 00:58 - Logan Harris and Spotter Global’s origin story 02:38 - From airborne radar to ground surveillance 04:08 - Supporting special operations and village stability missions 06:48 - The Metcalf substation attack and pivot to critical infrastructure 09:01 - Miniaturizing radar with modern wireless and DSP tech 13:08 - The new threat: FPV and fiber-optic drones 16:51 - Detection, remote ID, and operator location tracking 23:21 - What drone mitigation looks like today 27:26 - The Critical Infrastructure Airspace Defense Act 29:57 - AI, autonomous drones, and the future battlefield 32:39 - Holographic 3D radar and swarm detection 33:56 - How the system distinguishes drones from birds and clutter 37:25 - Biggest adoption challenges: education and regulation 41:28 - Funding model and commercial vs. military customers 43:29 - Books, documentaries, and personal recommendations 46:07 - Compliance, integration, and future follow-up topics 50:19 - Closing thoughts on drone threats and infrastructure risk What You’ll Learn • How military radar technology evolved into commercial perimeter security • Why drones are creating new risks for critical infrastructure and data centers • How radar, remote ID, cameras, and AI work together to identify threats • Why fiber-optic and autonomous drones are difficult to detect or disrupt • The similarities between physical security operations and a cybersecurity SOC • How legal restrictions affect drone detection, mitigation, and response Connect with Logan Harris and Spotter Global: Logan Harris: https://www.linkedin.com/in/lh1937/ Spotter Global: https://www.spotterglobal.com/ Spotter Global LinkedIn: https://www.linkedin.com/company/spotterglobal/ Links Reference:  https://www.congress.gov/bill/119th-congress/senate-bill/4380/all-actions-without-amendments https://www.cotton.senate.gov/news/press-releases/cotton-introduces-bill-to-protect-critical-infrastructure-from-drones https://www.spotterglobal.com/blog/spotter-blog-3/spotter-global-s-gax500-3d-radar-wins-prestigious-sia-award-delivering-unprecedented-security-against-drone-swarms-88 Connect with InfusionPoints:  Gary Daemer: https://www.linkedin.com/in/infusionpoints/ InfusionPoints: https://www.infusionpoints.com InfusionPoints LinkedIn: https://www.linkedin.com/company/infusionpoints/ InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints helps organizations Build, Operate, Prove, and Defend secure, mission-ready environments in highly regulated markets. We combine cybersecurity, cloud engineering, compliance, and real-world operations expertise across FedRAMP, FedRAMP 20x, DoD, and enterprise frameworks. Through our Continuous Trust approach, we help customers move faster, maintain compliance, and strengthen security from authorization through ongoing operations.

    Beyond the Digital Perimeter: Drones, Radar, and the Future of Physical Security
  5. Jul 21

    Meet “Vader”: FedRAMP VDR & VER, PAIN Scores, and the New Era of Vulnerability Response

    Yes, this episode starts with Jason playing the Darth Vader sound. Around here, we pronounce VDR like “Vader,” so naturally, he had to commit to the bit. Once the Imperial March ends, Jason and Mike break down two of the most important pieces of the evolving FedRAMP vulnerability management model: Vulnerability Detection and Response, or VDR, and Vulnerability Evaluation and Reporting, or VER. These requirements represent a major shift away from monthly vulnerability snapshots, blanket CVSS-based remediation timelines, and compliance processes built around spreadsheets and static reporting. Instead, CSPs will need to continuously identify vulnerabilities, evaluate them within the actual context of their environments, prioritize them based on real agency risk, and share actionable information with federal customers. The conversation explores how the new PAIN scoring model changes vulnerability prioritization by considering factors such as exploitability, internet reachability, system architecture, federal data impact, and the likelihood that a vulnerability could actually be used against a specific environment. Jason and Mike also discuss why scanners alone cannot provide all the context CSPs will need. Security, engineering, architecture, DevSecOps, and SOC teams will have to work together to understand how resources connect, what vulnerabilities truly affect, and which mitigations can immediately reduce risk while permanent remediation moves through the engineering process. For some of the highest-risk vulnerabilities, remediation or risk reduction timelines may be measured in hours rather than weeks. That means vulnerability management must begin operating more like incident response, with continuous visibility, automated analysis, real-time alerting, and teams prepared to respond outside of a traditional monthly reporting cycle. The episode also examines what these changes mean for existing FedRAMP Rev. 5 CSPs, agency reporting, POA&M processes, CI/CD pipelines, 3PAO assessments, automation, AI-assisted analysis, and communication between CSPs and their agency sponsors. Ultimately, VDR and VER are about moving beyond checking the box. The goal is to give agencies better visibility into their actual risk while allowing CSPs to focus their time and resources on the vulnerabilities that matter most. What You’ll Learn • The key differences between VDR and VER • Why vulnerability management is moving beyond monthly scans and CVSS scores • How PAIN scores add real-world risk and agency context • What continuous monitoring and faster remediation timelines mean for CSPs • Why security, engineering, SOC, and DevSecOps teams must work together • How automation and AI can support vulnerability analysis at scale • What CSPs should discuss with agency sponsors and prepare for now Chapters 0:00: Understanding VDR and VER: The Basics 2:52: Vulnerability Detection Response (VDR) Explained 5:34: Vulnerability Evaluation and Reporting (VER) Insights 8:25: The Importance of VDR and VER for CSPs 11:27: Challenges and Transitioning to New Standards 14:08: Contextualizing Vulnerabilities in Modern Environments 15:49: Challenges in Vulnerability Management 20:42: The Role of AI in Vulnerability Analysis 26:23: Understanding Remediation Timeframes 32:02: Accountability and Flexibility in Vulnerability Management 34:13: Key Questions for CSP Success Links:  Blog- https://infusionpoints.com/blogs/fedramp-vdr-and-ver-monthly-scans-continuous-trust Jason Shropshire- https://www.linkedin.com/in/shrop/ Mike Strohecker- https://www.linkedin.com/in/michael-strohecker-238326172/ Https://www.InfusionPoints.com  LinkedIn: https://www.linkedin.com/company/infusionpoints/ InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets. We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement. Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.

  6. Jul 8

    Identity, AI, and the Future of FedRAMP 20x with Matt Topper

    In this episode of Behind the Shield, Gary Daemer sits down with Matt Topper, President of UberEther, to discuss identity, FedRAMP, FedRAMP 20x, DoD cloud authorization, AI, and what it takes to build secure platforms for highly regulated environments. Matt shares UberEther’s approach to helping agencies and SaaS providers solve identity and access management challenges while accelerating authorization through inherited controls, private tenant environments, and secure platform design. Gary and Matt dig into the realities of FedRAMP, FedRAMP 20x, and DoD Impact Level 5, including the “easier button” approach to authorization, the ongoing complexity of audit logging, FIPS validation, cryptography, access control, POA&Ms, and application-level security. The conversation also explores how AI is being used in compliance and security workflows, from crypto discovery and audit control review to POA&M analysis, vulnerability noise reduction, log correlation, and security operations. They also discuss change management, sponsor requirements, SCNs, agency expectations, and how FedRAMP 20x is shifting the conversation around certification, authorization, inherited controls, automation, and faster paths to assurance. Later in the episode, Matt shares the story behind UberEther, his approach to company culture, growing without outside funding, and building a people-first business focused on long-term value. What You'll Learn:  • How identity and access management shape FedRAMP and DoD cloud security • Why DoD IL5 and FedRAMP 20x require both technical depth and process discipline • How inherited controls can help accelerate authorization • Why audit logging, FIPS, crypto, POA&Ms, and access controls remain major challenges • How AI agents are being used to support compliance and security workflows • Why change management can slow innovation in regulated environments • How sponsorship impacts the federal authorization process • Why non-person identities and AI-connected systems create new governance challenges • How Matt thinks about company culture, long-term growth, and building without outside funding Chapters:  00:09 Intro 01:19 Platform overview 02:58 Building for government needs 08:27 AI, audit, and FIPS 20:28 FedRAMP 20x and sponsor blocking points 20:56 Virtual ISO services 32:25 Future of the company 46:37 Big services company Books & Podcasts Referenced: • Traction by Gino Wickman • Another Way by Dave Whorton • The Ideal Team Player by Patrick Lencioni • Multipliers by Liz Wiseman • The Identity Jedi Podcast with David Lee Guest Links:  Matt Topper: https://www.linkedin.com/in/matttopper/ UberEther: https://www.linkedin.com/company/uberether/ https://uberether.com/ Learn more about InfusionPoints: https://www.linkedin.com/company/infusionpoints/ Gary Daemer: https://www.linkedin.com/in/infusionpoints/ Request a Demo: https://xbu40.com/ FedRAMP 20x Quick Look Assessment: https://xbu40.com/assessment InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets. We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement. Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.

  7. Jul 8

    FedRAMP CR26 Explained: What the 2026 Consolidated Rules Mean for CSPs

    In this bonus episode of Behind the Shield, we’re breaking down one of the biggest FedRAMP updates of the year: the release of the FedRAMP Consolidated Rules for 2026, also known as CR26. FedRAMP has been moving quickly, and for cloud service providers, agencies, assessors, advisors, and anyone working in the federal cloud ecosystem, CR26 marks an important shift toward a more unified, structured, and transparent approach to FedRAMP certification. Instead of navigating scattered updates, public notices, RFCs, legacy documentation, and evolving pilot language, the Consolidated Rules for 2026 are designed to bring the program’s expectations together into one clearer reference point. In this timely bonus conversation, the InfusionPoints team walks through what CR26 means in practical terms, why it matters now, and how organizations should begin thinking about the transition. The discussion covers how the rules impact FedRAMP 20x, Rev5, certification classes, the Marketplace, machine-readable requirements, and the broader move away from static, narrative-heavy compliance toward structured, automation-friendly security evidence. This episode is especially relevant for cloud service providers evaluating their FedRAMP strategy, teams preparing for Class A, B, C, or D certification paths, organizations currently working through Rev5, and stakeholders trying to understand where FedRAMP 20x fits into the future of the program. Chapters:  00:00 — Consolidated Rules Overview 01:08 — Rule Automation and Management 05:46 — Initial Implementation Phase 08:09 — Key Dates and Deadlines 14:10 — Certification Paths and Timelines 19:48 — AI, Documentation, and Resources What You’ll Learn: • What the FedRAMP Consolidated Rules for 2026 are and why they matter • Why CR26 is more than just another policy update • How FedRAMP is organizing rules, definitions, timelines, and responsibilities • What the shift to FedRAMP Certification language means for CSPs and agencies • How certification classes are changing the way stakeholders talk about FedRAMP baselines • What CR26 signals about the future of FedRAMP 20x and Rev5 • Why machine-readable requirements and structured evidence are becoming increasingly important • How cloud service providers should think about transition planning • Key dates and milestones organizations need to keep on their radar • The importance of understanding applicability, responsibilities, and timing before making major program decisions Resources:  Consolidated Rules- https://www.fedramp.gov/2026/ Important Dates Table- https://preview.fedramp.gov/2026/timeline/ https://infusionpoints.com/blogs/fedramp-consolidated-rules-2026-cr26-released Learn more about InfusionPoints: https://www.linkedin.com/company/infusionpoints/ Jason Shropshire: https://www.linkedin.com/in/shrop/ Chad Spears: https://www.linkedin.com/in/chad-spears007/ Tanner Bailey: https://www.linkedin.com/in/tanner-b-37a50a132/ Request a Demo: https://xbu40.com/ FedRAMP 20x Quick Look Assessment: https://xbu40.com/assessment InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets. We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement. Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.

  8. Jul 2

    Rob Hughes Returns: What AI Means for Identity, Security, and FedRAMP 20x

    Rob Hughes returns to Behind the Shield for his second appearance, making him the show’s first returning guest. This episode picks up in the middle of a year defined by rapid change, especially across AI, cybersecurity, identity, and federal compliance. Rob joins the InfusionPoints team for a wide-ranging conversation about how security leaders are thinking through the speed, scale, and uncertainty being introduced by AI, and what that means for organizations trying to keep pace without losing control. The discussion explores how AI is reshaping vulnerability management, identity security, social engineering, data governance, and security culture. Rob shares perspective on how security teams are evaluating AI’s impact in real environments, including how AI can help prioritize vulnerabilities, assess risk faster, and surface issues that may have previously taken much longer to identify. At the same time, the group digs into the challenges AI introduces, including AI agents, non-human identities, permission creep, unclear data retention, model transparency, and the rise of shadow AI. A major theme throughout the episode is that AI may be new, but many of the security fundamentals still matter more than ever. Strong identity controls, clean data, least privilege, layered defense, human accountability, and clear governance all become even more important when AI can move quickly, access large amounts of information, and operate across systems. Rob also discusses what good security culture looks like inside a company built around security, and why organizations need to educate employees on responsible AI use without stifling innovation. The conversation also turns toward FedRAMP 20x and the broader federal authorization landscape. Rob and the team discuss how trust, automation, 3PAO expectations, agency adoption, and ATO challenges are evolving as the federal market looks for faster, more scalable ways to evaluate cloud security. From AI risk to FedRAMP 20x, this episode looks at what is changing, what still needs to be solved, and how security leaders can prepare for what comes next. What You’ll Learn: • Why AI is accelerating the pace of change across cybersecurity • How AI is changing vulnerability discovery, analysis, and prioritization • What security teams should consider when evaluating AI agents in the enterprise • Why identity, permissions, and non-human identities are becoming even more critical • How shadow AI creates new risks around data visibility, retention, and control • Why security culture still depends on people, not just tools • How organizations can encourage AI adoption without ignoring risk • What good security culture looks like inside a company built around security • Why FedRAMP 20x is forcing new conversations about trust, automation, and accountability • Where agencies, vendors, and 3PAOs may still be struggling with authorization expectations • What needs to improve to make ATOs more accessible, repeatable, and scalable Chapters: 0:09 - AI Overview 1:55 - Rapid Change 10:14 - Identity Management 12:54 - Social Engineering 20:45 - Government Security 28:17 - Data Transparency 32:19 - AI Ethics 36:56 - Robotics 41:57 - Human Trust 49:49 - Authorization Process 55:41 - Shadow AI Guest Links: https://www.linkedin.com/in/robert-hughes-816067a4/ https://www.linkedin.com/company/rsasecurity/ https://www.rsa.com/ Learn more about InfusionPoints: https://www.linkedin.com/company/infusionpoints/ Jason Shropshire: https://www.linkedin.com/in/shrop/ Mike Strohecker: https://www.linkedin.com/in/michael-strohecker-238326172/ Request a Demo: https://xbu40.com/ FedRAMP 20x Quick Look Assessment: https://xbu40.com/assessment InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets. We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement. Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.

Ratings & Reviews

5
out of 5
2 Ratings

About

 Behind the Shield is InfusionPoints’ podcast where we sit down with partners, customers, and industry leaders to talk about FedRAMP, compliance, and cybersecurity in today’s government landscape. Each episode offers laid-back, insightful conversations that blend expertise with real-world experiences.