Behind the Shield

InfusionPoints

 Behind the Shield is InfusionPoints’ podcast where we sit down with partners, customers, and industry leaders to talk about FedRAMP, compliance, and cybersecurity in today’s government landscape. Each episode offers laid-back, insightful conversations that blend expertise with real-world experiences. 

  1. 9h ago

    Beyond the Digital Perimeter: Drones, Radar, and the Future of Physical Security

    Behind the Shield is taking a slight detour. Most episodes focus on cloud security, cybersecurity compliance, and mission systems inside the data center. This time, Gary steps outside the digital perimeter with Logan Harris, CEO of Spotter Global, to explore threats surrounding critical infrastructure, military sites, airports, utilities, and data centers. Logan shares how his work evolved from traffic-monitoring radar into lightweight surveillance systems for military missions. Technology that once required hundreds of pounds of equipment was reduced to only a few pounds, creating new possibilities for drones, operations, and perimeter monitoring. The conversation then turns to a fast-growing security concern: drones. Gary and Logan discuss how inexpensive commercial drones, fiber-optic-guided systems, autonomous navigation, and coordinated swarms are changing the threat landscape. They explain why GPS and communication jamming may no longer be enough when drones can operate without emitting a detectable signal. They also examine how radar, remote identification, cameras, AI analysis, and common operating pictures can identify aircraft, locate operators, reduce false positives, and help teams respond. Although this episode ventures beyond our usual topics, the parallels are clear. Physical security teams face many of the same challenges as cybersecurity operations centers: collecting sensor data, identifying threats, reducing noise, maintaining human oversight, and moving from detection to response. It is a different kind of perimeter, but the question remains the same: once you detect a threat, what can you actually do about it? Chapters 00:00 - Introduction 00:12 - Welcome to Behind the Shield 00:58 - Logan Harris and Spotter Global’s origin story 02:38 - From airborne radar to ground surveillance 04:08 - Supporting special operations and village stability missions 06:48 - The Metcalf substation attack and pivot to critical infrastructure 09:01 - Miniaturizing radar with modern wireless and DSP tech 13:08 - The new threat: FPV and fiber-optic drones 16:51 - Detection, remote ID, and operator location tracking 23:21 - What drone mitigation looks like today 27:26 - The Critical Infrastructure Airspace Defense Act 29:57 - AI, autonomous drones, and the future battlefield 32:39 - Holographic 3D radar and swarm detection 33:56 - How the system distinguishes drones from birds and clutter 37:25 - Biggest adoption challenges: education and regulation 41:28 - Funding model and commercial vs. military customers 43:29 - Books, documentaries, and personal recommendations 46:07 - Compliance, integration, and future follow-up topics 50:19 - Closing thoughts on drone threats and infrastructure risk What You’ll Learn • How military radar technology evolved into commercial perimeter security • Why drones are creating new risks for critical infrastructure and data centers • How radar, remote ID, cameras, and AI work together to identify threats • Why fiber-optic and autonomous drones are difficult to detect or disrupt • The similarities between physical security operations and a cybersecurity SOC • How legal restrictions affect drone detection, mitigation, and response Connect with Logan Harris and Spotter Global: Logan Harris: https://www.linkedin.com/in/lh1937/ Spotter Global: https://www.spotterglobal.com/ Spotter Global LinkedIn: https://www.linkedin.com/company/spotterglobal/ Links Reference:  https://www.congress.gov/bill/119th-congress/senate-bill/4380/all-actions-without-amendments https://www.cotton.senate.gov/news/press-releases/cotton-introduces-bill-to-protect-critical-infrastructure-from-drones https://www.spotterglobal.com/blog/spotter-blog-3/spotter-global-s-gax500-3d-radar-wins-prestigious-sia-award-delivering-unprecedented-security-against-drone-swarms-88 Connect with InfusionPoints:  Gary Daemer: https://www.linkedin.com/in/infusionpoints/ InfusionPoints: https://www.infusionpoints.com InfusionPoints LinkedIn: https://www.linkedin.com/company/infusionpoints/ InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints helps organizations Build, Operate, Prove, and Defend secure, mission-ready environments in highly regulated markets. We combine cybersecurity, cloud engineering, compliance, and real-world operations expertise across FedRAMP, FedRAMP 20x, DoD, and enterprise frameworks. Through our Continuous Trust approach, we help customers move faster, maintain compliance, and strengthen security from authorization through ongoing operations.

    Beyond the Digital Perimeter: Drones, Radar, and the Future of Physical Security
  2. Jul 21

    Meet “Vader”: FedRAMP VDR & VER, PAIN Scores, and the New Era of Vulnerability Response

    Yes, this episode starts with Jason playing the Darth Vader sound. Around here, we pronounce VDR like “Vader,” so naturally, he had to commit to the bit. Once the Imperial March ends, Jason and Mike break down two of the most important pieces of the evolving FedRAMP vulnerability management model: Vulnerability Detection and Response, or VDR, and Vulnerability Evaluation and Reporting, or VER. These requirements represent a major shift away from monthly vulnerability snapshots, blanket CVSS-based remediation timelines, and compliance processes built around spreadsheets and static reporting. Instead, CSPs will need to continuously identify vulnerabilities, evaluate them within the actual context of their environments, prioritize them based on real agency risk, and share actionable information with federal customers. The conversation explores how the new PAIN scoring model changes vulnerability prioritization by considering factors such as exploitability, internet reachability, system architecture, federal data impact, and the likelihood that a vulnerability could actually be used against a specific environment. Jason and Mike also discuss why scanners alone cannot provide all the context CSPs will need. Security, engineering, architecture, DevSecOps, and SOC teams will have to work together to understand how resources connect, what vulnerabilities truly affect, and which mitigations can immediately reduce risk while permanent remediation moves through the engineering process. For some of the highest-risk vulnerabilities, remediation or risk reduction timelines may be measured in hours rather than weeks. That means vulnerability management must begin operating more like incident response, with continuous visibility, automated analysis, real-time alerting, and teams prepared to respond outside of a traditional monthly reporting cycle. The episode also examines what these changes mean for existing FedRAMP Rev. 5 CSPs, agency reporting, POA&M processes, CI/CD pipelines, 3PAO assessments, automation, AI-assisted analysis, and communication between CSPs and their agency sponsors. Ultimately, VDR and VER are about moving beyond checking the box. The goal is to give agencies better visibility into their actual risk while allowing CSPs to focus their time and resources on the vulnerabilities that matter most. What You’ll Learn • The key differences between VDR and VER • Why vulnerability management is moving beyond monthly scans and CVSS scores • How PAIN scores add real-world risk and agency context • What continuous monitoring and faster remediation timelines mean for CSPs • Why security, engineering, SOC, and DevSecOps teams must work together • How automation and AI can support vulnerability analysis at scale • What CSPs should discuss with agency sponsors and prepare for now Chapters 0:00: Understanding VDR and VER: The Basics 2:52: Vulnerability Detection Response (VDR) Explained 5:34: Vulnerability Evaluation and Reporting (VER) Insights 8:25: The Importance of VDR and VER for CSPs 11:27: Challenges and Transitioning to New Standards 14:08: Contextualizing Vulnerabilities in Modern Environments 15:49: Challenges in Vulnerability Management 20:42: The Role of AI in Vulnerability Analysis 26:23: Understanding Remediation Timeframes 32:02: Accountability and Flexibility in Vulnerability Management 34:13: Key Questions for CSP Success Links:  Blog- https://infusionpoints.com/blogs/fedramp-vdr-and-ver-monthly-scans-continuous-trust Jason Shropshire- https://www.linkedin.com/in/shrop/ Mike Strohecker- https://www.linkedin.com/in/michael-strohecker-238326172/ Https://www.InfusionPoints.com  LinkedIn: https://www.linkedin.com/company/infusionpoints/ InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets. We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement. Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.

  3. Jul 8

    Identity, AI, and the Future of FedRAMP 20x with Matt Topper

    In this episode of Behind the Shield, Gary Daemer sits down with Matt Topper, President of UberEther, to discuss identity, FedRAMP, FedRAMP 20x, DoD cloud authorization, AI, and what it takes to build secure platforms for highly regulated environments. Matt shares UberEther’s approach to helping agencies and SaaS providers solve identity and access management challenges while accelerating authorization through inherited controls, private tenant environments, and secure platform design. Gary and Matt dig into the realities of FedRAMP, FedRAMP 20x, and DoD Impact Level 5, including the “easier button” approach to authorization, the ongoing complexity of audit logging, FIPS validation, cryptography, access control, POA&Ms, and application-level security. The conversation also explores how AI is being used in compliance and security workflows, from crypto discovery and audit control review to POA&M analysis, vulnerability noise reduction, log correlation, and security operations. They also discuss change management, sponsor requirements, SCNs, agency expectations, and how FedRAMP 20x is shifting the conversation around certification, authorization, inherited controls, automation, and faster paths to assurance. Later in the episode, Matt shares the story behind UberEther, his approach to company culture, growing without outside funding, and building a people-first business focused on long-term value. What You'll Learn:  • How identity and access management shape FedRAMP and DoD cloud security • Why DoD IL5 and FedRAMP 20x require both technical depth and process discipline • How inherited controls can help accelerate authorization • Why audit logging, FIPS, crypto, POA&Ms, and access controls remain major challenges • How AI agents are being used to support compliance and security workflows • Why change management can slow innovation in regulated environments • How sponsorship impacts the federal authorization process • Why non-person identities and AI-connected systems create new governance challenges • How Matt thinks about company culture, long-term growth, and building without outside funding Chapters:  00:09 Intro 01:19 Platform overview 02:58 Building for government needs 08:27 AI, audit, and FIPS 20:28 FedRAMP 20x and sponsor blocking points 20:56 Virtual ISO services 32:25 Future of the company 46:37 Big services company Books & Podcasts Referenced: • Traction by Gino Wickman • Another Way by Dave Whorton • The Ideal Team Player by Patrick Lencioni • Multipliers by Liz Wiseman • The Identity Jedi Podcast with David Lee Guest Links:  Matt Topper: https://www.linkedin.com/in/matttopper/ UberEther: https://www.linkedin.com/company/uberether/ https://uberether.com/ Learn more about InfusionPoints: https://www.linkedin.com/company/infusionpoints/ Gary Daemer: https://www.linkedin.com/in/infusionpoints/ Request a Demo: https://xbu40.com/ FedRAMP 20x Quick Look Assessment: https://xbu40.com/assessment InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets. We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement. Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.

  4. Jul 8

    FedRAMP CR26 Explained: What the 2026 Consolidated Rules Mean for CSPs

    In this bonus episode of Behind the Shield, we’re breaking down one of the biggest FedRAMP updates of the year: the release of the FedRAMP Consolidated Rules for 2026, also known as CR26. FedRAMP has been moving quickly, and for cloud service providers, agencies, assessors, advisors, and anyone working in the federal cloud ecosystem, CR26 marks an important shift toward a more unified, structured, and transparent approach to FedRAMP certification. Instead of navigating scattered updates, public notices, RFCs, legacy documentation, and evolving pilot language, the Consolidated Rules for 2026 are designed to bring the program’s expectations together into one clearer reference point. In this timely bonus conversation, the InfusionPoints team walks through what CR26 means in practical terms, why it matters now, and how organizations should begin thinking about the transition. The discussion covers how the rules impact FedRAMP 20x, Rev5, certification classes, the Marketplace, machine-readable requirements, and the broader move away from static, narrative-heavy compliance toward structured, automation-friendly security evidence. This episode is especially relevant for cloud service providers evaluating their FedRAMP strategy, teams preparing for Class A, B, C, or D certification paths, organizations currently working through Rev5, and stakeholders trying to understand where FedRAMP 20x fits into the future of the program. Chapters:  00:00 — Consolidated Rules Overview 01:08 — Rule Automation and Management 05:46 — Initial Implementation Phase 08:09 — Key Dates and Deadlines 14:10 — Certification Paths and Timelines 19:48 — AI, Documentation, and Resources What You’ll Learn: • What the FedRAMP Consolidated Rules for 2026 are and why they matter • Why CR26 is more than just another policy update • How FedRAMP is organizing rules, definitions, timelines, and responsibilities • What the shift to FedRAMP Certification language means for CSPs and agencies • How certification classes are changing the way stakeholders talk about FedRAMP baselines • What CR26 signals about the future of FedRAMP 20x and Rev5 • Why machine-readable requirements and structured evidence are becoming increasingly important • How cloud service providers should think about transition planning • Key dates and milestones organizations need to keep on their radar • The importance of understanding applicability, responsibilities, and timing before making major program decisions Resources:  Consolidated Rules- https://www.fedramp.gov/2026/ Important Dates Table- https://preview.fedramp.gov/2026/timeline/ https://infusionpoints.com/blogs/fedramp-consolidated-rules-2026-cr26-released Learn more about InfusionPoints: https://www.linkedin.com/company/infusionpoints/ Jason Shropshire: https://www.linkedin.com/in/shrop/ Chad Spears: https://www.linkedin.com/in/chad-spears007/ Tanner Bailey: https://www.linkedin.com/in/tanner-b-37a50a132/ Request a Demo: https://xbu40.com/ FedRAMP 20x Quick Look Assessment: https://xbu40.com/assessment InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets. We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement. Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.

  5. Jul 2

    Rob Hughes Returns: What AI Means for Identity, Security, and FedRAMP 20x

    Rob Hughes returns to Behind the Shield for his second appearance, making him the show’s first returning guest. This episode picks up in the middle of a year defined by rapid change, especially across AI, cybersecurity, identity, and federal compliance. Rob joins the InfusionPoints team for a wide-ranging conversation about how security leaders are thinking through the speed, scale, and uncertainty being introduced by AI, and what that means for organizations trying to keep pace without losing control. The discussion explores how AI is reshaping vulnerability management, identity security, social engineering, data governance, and security culture. Rob shares perspective on how security teams are evaluating AI’s impact in real environments, including how AI can help prioritize vulnerabilities, assess risk faster, and surface issues that may have previously taken much longer to identify. At the same time, the group digs into the challenges AI introduces, including AI agents, non-human identities, permission creep, unclear data retention, model transparency, and the rise of shadow AI. A major theme throughout the episode is that AI may be new, but many of the security fundamentals still matter more than ever. Strong identity controls, clean data, least privilege, layered defense, human accountability, and clear governance all become even more important when AI can move quickly, access large amounts of information, and operate across systems. Rob also discusses what good security culture looks like inside a company built around security, and why organizations need to educate employees on responsible AI use without stifling innovation. The conversation also turns toward FedRAMP 20x and the broader federal authorization landscape. Rob and the team discuss how trust, automation, 3PAO expectations, agency adoption, and ATO challenges are evolving as the federal market looks for faster, more scalable ways to evaluate cloud security. From AI risk to FedRAMP 20x, this episode looks at what is changing, what still needs to be solved, and how security leaders can prepare for what comes next. What You’ll Learn: • Why AI is accelerating the pace of change across cybersecurity • How AI is changing vulnerability discovery, analysis, and prioritization • What security teams should consider when evaluating AI agents in the enterprise • Why identity, permissions, and non-human identities are becoming even more critical • How shadow AI creates new risks around data visibility, retention, and control • Why security culture still depends on people, not just tools • How organizations can encourage AI adoption without ignoring risk • What good security culture looks like inside a company built around security • Why FedRAMP 20x is forcing new conversations about trust, automation, and accountability • Where agencies, vendors, and 3PAOs may still be struggling with authorization expectations • What needs to improve to make ATOs more accessible, repeatable, and scalable Chapters: 0:09 - AI Overview 1:55 - Rapid Change 10:14 - Identity Management 12:54 - Social Engineering 20:45 - Government Security 28:17 - Data Transparency 32:19 - AI Ethics 36:56 - Robotics 41:57 - Human Trust 49:49 - Authorization Process 55:41 - Shadow AI Guest Links: https://www.linkedin.com/in/robert-hughes-816067a4/ https://www.linkedin.com/company/rsasecurity/ https://www.rsa.com/ Learn more about InfusionPoints: https://www.linkedin.com/company/infusionpoints/ Jason Shropshire: https://www.linkedin.com/in/shrop/ Mike Strohecker: https://www.linkedin.com/in/michael-strohecker-238326172/ Request a Demo: https://xbu40.com/ FedRAMP 20x Quick Look Assessment: https://xbu40.com/assessment InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets. We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement. Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.

  6. Jun 26

    Re-Release: From Screenshots to Signals with SK Bhachech: FedRAMP Automation and What Comes Next

    In this episode of Behind the Shield, host Gary Daemer is joined by new co-host Ryan Adcock from the InfusionPoints Cloud Team and special guest SK Bhachech from Riverbed Technology for a candid conversation on what it really takes to navigate federal compliance when the goalposts move mid-flight. Together, they unpack Riverbed’s authorization journey, why FedRAMP is often customer-driven rather than chosen, and what makes FedRAMP uniquely prescriptive. From implementing hundreds of controls to sustaining month-over-month operational rigor, SK shares lessons learned from building and maturing a security program inside a regulated environment. The conversation also looks ahead to FedRAMP 20x, Key Security Indicators, and machine-readable evidence. The group explores how automation can reduce human error, lower costs, and shift audits away from screenshot collection toward continuous validation. They also discuss where AI may help, such as summarization and review support, and why human oversight remains critical in cybersecurity. To close, the episode gets more personal with favorite books, shows, and a discussion on service, leadership, and giving back to the community. Topics covered include: Why companies are pulled into FedRAMP and why it is hard to walk away What makes FedRAMP prescriptive and operationally demanding Staying nimble when requirements change during authorization FedRAMP 20x, KSIs, and continuous validation Automation and AI as accelerators with humans still in the loop Guest Links:  https://www.linkedin.com/in/bhachech/ https://www.riverbed.com/ InfusionPoints Links:  LinkedIn-  Ryan Adcock: https://www.linkedin.com/in/ryanaadcock/ Gary Daemer:   https://www.linkedin.com/in/infusionpoints/ InfusionPoints: https://www.linkedin.com/company/infusionpoints/ Request a Demo: https://xbu40.com/ InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets. We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement. Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.

  7. Jun 16

    FedRAMP, 20x, and the Future of Federal Cloud Security with Michael Schroeder

    What happens when someone who helped shape FedRAMP from inside a federal agency joins the conversation from the industry side? In this episode of Behind the Shield, Gary Daemer sits down with Michael Schroeder, Director of FedRAMP Strategy and Market Development at Excentium, to discuss the evolution of FedRAMP, the impact of FedRAMP 20x, and what the future of cloud security and compliance could look like across the federal government. Michael shares insights from his time supporting FedRAMP efforts within the Department of Veterans Affairs Digital Transformation Center, where he worked closely with OIT and OIS leadership teams, Federal business owners, and Cloud Service Providers, in close alignment to the agency authorization process, before transitioning to Excentium to focus on strategy, market development, and industry engagement. The conversation explores the shift from traditional compliance-driven approaches toward outcome-based security, the growing role of automation and machine-readable evidence, and why increased transparency is changing how government agencies, assessors, and CSPs work together. Gary and Michael also discuss agency adoption, the relationship between FedRAMP and CMMC, the challenges of scaling assessments, and why collaboration across the cybersecurity community may be one of the most important developments in recent years. Beyond compliance frameworks, Michael shares his perspective on leadership, continuous learning, cybersecurity for nonprofits, and the importance of building solutions that make security more accessible and effective for organizations of all sizes. Whether you're a Cloud Service Provider, federal agency stakeholder, cybersecurity practitioner, or simply interested in where federal compliance programs are headed, this episode offers a thoughtful look at the opportunities and challenges shaping the next generation of government cloud security. Chapters:  0:10 - Meet Michael Schroeder: Career Journey and FedRAMP Background 7:38 - Public Discourse and FedRAMP 10:17 - FedRAMP Process and Challenges 16:25 - Security vs. Compliance 22:49 - Transparency and Public Trust 28:44 - Operational Security Practices 36:36 - Monitoring and Reporting 43:15 - Adoption of 20X and Future Predictions 55:54 - Closing Thoughts, Leadership, and Community Impact What You'll Learn • Michael Schroeder's transition from the VA to Excentium and the lessons learned along the way • How FedRAMP 20x is reshaping federal cloud security • The difference between compliance and operational security • Why Trust Centers are changing how agencies evaluate cloud services • The impact of machine-readable evidence and continuous validation • Common challenges CSPs face when adopting FedRAMP 20x • Where FedRAMP and CMMC may align in the future • How automation can help agencies improve security oversight • Michael's predictions for FedRAMP and agency adoption • Why collaboration is becoming a competitive advantage in cybersecurity • How security can drive business growth, not just compliance • Supporting nonprofits through practical cybersecurity initiatives • Balancing speed, security, and innovation in modern cloud environments Guest Links: https://www.linkedin.com/in/mjschroeder1/ https://www.linkedin.com/company/excentium/ https://excentium.com/ Learn more about InfusionPoints: https://www.linkedin.com/company/infusionpoints/ Gary Daemer: https://www.linkedin.com/in/infusionpoints/ Request a Demo: https://xbu40.com/ FedRAMP 20x Quick Look Assessment: https://xbu40.com/assessment InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets. We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement. Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.

  8. Jun 9

    Built to Last: Christian Hyatt on Entrepreneurship, AI, and the Future of Cybersecurity

    In this episode of Behind the Shield, Gary Daemer sits down with Christian Hyatt, Founder and CEO of risk3sixty, for a conversation that goes far beyond cybersecurity. Together, they explore what it means to build an evergreen company in an industry often driven by venture capital, rapid growth expectations, and short-term outcomes. Christian shares the story behind risk3sixty's culture-first philosophy, lessons learned from more than a decade of entrepreneurship, and why focusing on customers, team members, and craftsmanship can create a lasting competitive advantage. The conversation also dives into the evolving cybersecurity and compliance landscape, including AI governance, GRC engineering, automation, workforce transformation, and the changing skills security leaders need to succeed. As organizations navigate unprecedented technological change, Gary and Christian discuss how business leaders can balance innovation, risk management, and long-term sustainability. Whether you're a cybersecurity practitioner, business leader, entrepreneur, or simply interested in how great companies are built, this episode offers practical insights on leadership, growth, and building something designed to last. Chapters: 0:09 - Introduction and Guest Introduction 0:38 - Building a Lasting Company 1:10 - Unique Approach to Business 2:26 - Personal Business Journey 3:35 - Evergreen Company Concept 7:31 - Team Building and Culture 10:17 - Customer and Market Insights 22:16 - AI and Compliance Challenges 39:20 - Future Skills and Industry Trends 51:55 - Conclusion and Final Thoughts What You'll Learn:  • Why some founders choose to build evergreen companies instead of pursuing outside investment • How culture and customer focus become long-term competitive advantages • The lessons Christian learned while growing risk3sixty from a startup into a thriving cybersecurity business • Why many CISOs are being asked to do more with fewer resources • How AI is transforming governance, risk, and compliance programs • What organizations are getting wrong about AI governance and adoption • The shift from traditional GRC work to GRC engineering and systems thinking • How automation is changing the future of compliance and security operations • Why business acumen is becoming just as important as technical expertise • What the next generation of cybersecurity professionals can teach us about AI adoption • Emerging trends shaping the future of cybersecurity, compliance, and technology • The books, experiences, and philosophies that have influenced both Christian and Gary as leaders Book Links:  Another Way by Dave Whorton with Bo Burlingham: https://www.tugboatinstitute.com/anotherway/ The EOS Life by Gino Wickman:  https://www.amazon.com/EOS-Life-Live-Ideal-Entrepreneurial/dp/1637740131/ref=tmm_hrd_swatch_0?_encoding=UTF8&qid=1632761524&sr=8-1-spons Guest Links:  Christian Hyatt: https://www.linkedin.com/in/christianhyatt/ https://risk3sixty.com/ Guest's Books: Security Team Operating System: How to Run an Unstoppable Team The Good Business: How to Bootstrap a Business to $10m and Beyond For the kiddos (or adults!)- Chief Information Security Officer: CISO the Dog Saves Secure City  What Is a Good Business Made Out Of (The Good Business) Find Christian's Books Here: https://www.amazon.com/stores/author/B0D7D6HKS9?ccs_id=75ab130f-9913-4b4e-b057-dd798be408dc Learn more about InfusionPoints: https://www.linkedin.com/company/infusionpoints/ Gary Daemer: https://www.linkedin.com/in/infusionpoints/ Request a Demo: https://xbu40.com/ FedRAMP 20x Quick Look Assessment: https://xbu40.com/assessment InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets. We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement. Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.

Ratings & Reviews

5
out of 5
2 Ratings

About

 Behind the Shield is InfusionPoints’ podcast where we sit down with partners, customers, and industry leaders to talk about FedRAMP, compliance, and cybersecurity in today’s government landscape. Each episode offers laid-back, insightful conversations that blend expertise with real-world experiences.