The Paramify Podcast

Paramify

The Paramify Podcast is a practical, occasionally chaotic show about GRC, risk management, and staying audit-ready without losing your mind. It’s part talking security strategy, and part group therapy. We talk with cybersecurity and GRC leaders, including CISOs, auditors, founders, and security engineers, about FedRAMP and FedRAMP 20x, SOC 2, CMMC, NIST RMF, the shift toward continuous evidence, and everything in between.  Learn about what we do at Paramify here: www.paramify.com

  1. 6d ago

    The Future of Defense Technology with SecondFront CEO Tyler Sweatt

    "If the community wins, America's going to win. If America wins, the world is going to win." That's Tyler Sweatt's mindset as CEO of Second Front. Tyler's a West Point grad and Army vet who's spent his career at the intersection of defense and tech. He's been with Second Front for six years, and in that time its Game Warden platform has powered around a hundred ISVs, from legacy primes to brand-new startups, getting mission-critical software authorized and deployed to government networks in a fraction of the usual time. Tyler joined Kenny and Mike on the Paramify Podcast to talk about it. Key moments from the podcast:  → Why old FedRAMP® is dead, and why that's a good thing  → Why entrepreneurial naivety is actually an asset in defense tech  → Why Second Front bets on self-hosted models over frontier labs for mission-critical software  → Why more competitors in this space makes everyone better  → His take on building a company right now, when the frontier labs get all the attention Learn more: Tyler Sweatt (Second Front CEO): https://www.linkedin.com/in/tylersweatt/ Kenny Scott (Paramify Founder & CEO): https://www.linkedin.com/in/kenny-g-scott/ Mike Schreiner (Paramify): https://www.linkedin.com/in/mikecschreiner/ Second Front Systems: https://www.secondfront.com Paramify: https://www.paramify.com Chapters: 0:00 Teaser: the best time in history to build a company 1:20 Welcome Tyler Sweatt from Second Front 2:04 What Second Front does and how Tyler got there 3:45 Lessons (and dark humor) from his military service 4:34 Why America struggles to think in long-term horizons 6:33 TikTok, algorithms, and a generational divide 7:09 The broken incentives behind national security spending 8:19 Why program managers aren't rewarded for efficiency 10:11 Congress, sound bites, and who ends up in office 11:17 The rise of digital natives in national security 12:00 Regulatory capture vs. building an open ecosystem 13:54 Giving credit to the FedRAMP office 15:00 The friction of selling into the Department of War 16:05 AO stovepipes and the reciprocity problem 18:00 Private capital turning defense tech into a real industry 18:35 The "defense tech cohort" and cutting your teeth at Palantir 19:07 Why having real competitors makes Second Front better 20:05 Entrepreneurial naivety as an asset 21:01 Why old FedRAMP is dead 23:06 Continuous ATO politics in the Department of War 24:43 CMMC, and why it's overdue for an overhaul 25:01 The Department's inflection point with private industry 28:16 AI access, geopolitics, and a wild few months 30:17 AI as a tailwind (or headwind) for mission software 32:17 The risk of hard-coding dependency on one frontier model 33:35 Why Second Front bet on Cohere over the big labs 35:38 What's the same and different from his Calypso AI days 39:01 AI hype vs. reality, and managing expectations 41:05 Why competition forces incumbents to get better 43:25 Paramify's early days and building trust the hard way 44:41 Living through industry-wide change 45:18 Building a company when frontier labs get all the attention 46:21 Why this is the best time in history to build 47:17 Why resisting change is a losing bet 49:27 How to learn more about Second Front

  2. Jun 29

    Printer Security, FedRAMP High, and the Road to IL6 with Justin Scott

    Justin Scott didn't set out to build a security program. But after Vasion's customers started asking hard questions about cloud security, he ended up leading the company through ISO 27001, SOC 2, FedRAMP Moderate, and all the way to FedRAMP High, with IL6 on the horizon. He breaks down what actually worked, what didn't, and why automation is non-negotiable. Learn more about Vasion at https://vasion.com Learn more about Justin Scott: https://www.linkedin.com/in/jusscott/ Learn more about Paramify at https://www.paramify.com Learn more about Kenny Scott: https://www.linkedin.com/in/kenny-g-scott/ Learn more about Mike Schreiner: https://www.linkedin.com/in/mikecschreiner/ Chapters: 0:00 Intro 1:06 Meet Justin Scott and Vasion 2:24 How Justin Got Into Security 4:29 Going from On-Prem to SaaS 7:24 Owning the Full Security Program at Vasion 10:26 Starting with ISO 27001 Before FedRAMP 13:00 The Challenge of Finding a Sponsor 16:20 Choosing Stack Armor as a Partner 19:06 Why a Technical Program Manager is Non-Negotiable 19:44 Printer Security and Why It's a Blind Spot 23:00 How Vasion's Capabilities Map to Compliance Frameworks 25:00 AI, ISO 42001, and What Vasion Is Building 27:36 The Role of Simplicity in Building a Security Program 29:31 Why Automation Is the Only Way to Keep Up 31:39 FedRAMP 20X: Takes and Tradeoffs 36:51 FedRAMP High as a Growth Lever 38:27 Justin's Advice for Anyone Starting a FedRAMP Journey 39:52 Outro

  3. Jun 26

    The VDR Mandate Is Here: FedRAMP NTC-0014 and CISA BOD 26-04 Explained

    Monthly vulnerability scans and POA&M spreadsheets aren't going to cut it anymore. Kenny and Isaac break down FedRAMP NTC-0014 and CISA BOD 26-04, the two mandates reshaping how cloud service providers approach vulnerability management, and what CSPs need to do before the December 7, 2026 deadline hits. They cover why AI has fundamentally changed the threat landscape, how tools like Wiz are helping teams understand attack paths instead of just CVE lists, and what the FedRAMP VDR/VER standard actually requires in practice. Plus, why showing red in your trust center might be the best thing you can do for agency confidence. If you're a CSP still running manual scans and hoping for the best, this one's for you. Resources mentioned: - FedRAMP NTC-0014 (VDR/VER Mandate): https://www.fedramp.gov/notices/0014/ - FedRAMP VDR Technical Docs: https://www.fedramp.gov/docs/20x/vulnerability-detection-and-response/ - CISA BOD 26-04 Implementation Guidance: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk - CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog - CISA SSVC Decision Tree Methodology: https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc - FedRAMP NTC-0013 (Rev 5 Sunset): https://www.fedramp.gov/notices/0013/ - FedRAMP Marketplace: https://marketplace.fedramp.gov/ Learn more about Paramify: https://www.paramify.com/ Chapters: 0:00 - Transparency in Trust Centers: Why Agencies Want to See Red 0:13 - Episode Intro & FedRAMP NTC-0014 Explained 3:24 - CISA BOD 26-04 and the December 7, 2026 Deadline 5:46 - Why the Old FedRAMP Approach Is Broken 9:01 - How AI Changed the Vulnerability Landscape 11:35 - DARPA's AI Cyber Challenge at DEF CON 13:12 - Risk-Based Vulnerability Prioritization: The FedRAMP VDR Response 15:15 - Smart Architecture as a Security Foundation 20:14 - The FedRAMP VDR Standard: Scanning Requirements 21:27 - SSVC Decision Tree: Triage Methodology 22:14 - What "Internet Reachable" Actually Means 24:07 - Likely Exploitable: The CISA KEV List 26:58 - Agency Impact and the Pain Scale 28:25 - Pain Level Timelines by FedRAMP Class 31:00 - Ditching the POA&M Spreadsheet Mindset 32:10 - What to Stop Doing in the Old Model 34:17 - Boundary Diagrams vs. Terraform Truth 36:24 - Why Transparency Wins with Agency Customers 41:08 - Trust Centers Done Right: The OpenAI Status Page Example 43:06 - What Large Orgs Getting Ahead Are Doing 45:06 - Incident Response and Vulnerability Management: Blurring Lines 46:55 - Outro

  4. May 26

    FedRAMP 20x, CMMC, and the Future of GRC with Matt Bruggeman

    "For years defense contractors kept hearing CMMC's coming. And then it kept not coming. So they grew this boy who cried wolf mentality where once it finally really was coming, they were like, I've heard that before." - Matt Bruggeman Kenny and Mike sit down with Matt Bruggeman, Director of Federal GTM at A-LIGN. Matt has done it all, he's a trained electrical engineer, improv comedian, and independent filmmaker. Matt's birthday was yesterday so this episode is basically his gift. Happy birthday Matt 🎂  In this episode, they talk about where CMMC actually stands today, why the November 10th Phase 2 deadline changes everything, and what FedRAMP® 20x could mean for the future of CMMC. Chapters: 00:00 The State of CMMC in 2026 01:00 Intro and Meet Matt Bruggeman 02:52 Matt's Unconventional Path to GRC 06:11 About A-LIGN and the Ascend Platform 08:14 CMMC Today: What's Working and What Needs to Change 09:19 Phase 1 vs Phase 2 and the November 10th Deadline 11:01 NIST 171 Rev 2 vs Rev 3: What's the Plan? 15:46 FedRAMP 20X: Hype vs Reality 19:01 Why FedRAMP Was Broken from the Start 23:28 How to Think About Rev 5 vs 20X for Your Business 27:52 FedRAMP Equivalency Explained 31:36 The Technical Reality of a CMMC Assessment 35:27 Compliance Doesn't Have to Be Boring 37:30 How to Get Into the GRC Space 40:19 Where to Find Matt and A-LIGN Connect with our guest: Matt Bruggeman: https://www.linkedin.com/in/matt-bruggeman/ A-LIGN: https://www.a-lign.com A-LIGN on LinkedIn: https://www.linkedin.com/company/a-lign/ Paramify: Website: https://www.paramify.com LinkedIn: https://www.linkedin.com/company/80788473/ Hosts: Kenny Scott: https://www.linkedin.com/in/kenny-g-scott/ Mike Schreiner: https://www.linkedin.com/in/mikecschreiner/

  5. May 18

    AI, FedRAMP and the "Dark Matter" of Data with Bhanu Jagasia and Vincent Tham

    Is legacy compliance actually dead?  In this episode of the Paramify Podcast, we sit down with Bhanu Jagasia and Vincent Tham from BladeStack to talk about the massive shift happening in the GRC world. From the "dark matter of data" to the transition toward FedRAMP 20X, we’re moving away from 1,500-page "black box" documents and toward real-time, automated evidence. We also dive deep into the AI hype: Will knowledge workers be automated by 2027? Why does "vibe coding" fail in high-stakes compliance? And how can lean teams punch above their weight class using deterministic automation? Connect with BladeStack: LinkedIn: bladestack.io Bhanu Jagasia: linkedin.com/in/bhanujagasia Vincent Tham: linkedin.com/in/vincenttham Website: bladestack.io Connect with Paramify: LinkedIn: linkedin.com/company/paramify Kenny Scott: linkedin.com/in/kenny-g-scott Mike Schreiner: linkedin.com/in/mikecschreiner Website: paramify.com 0:00 Intro & Evidence Automation 1:27 Welcome to the Paramify Podcast 3:00 How Bladestack Got Started 6:29 Evidence Automation & the "Dark Matter" of Data 12:31 Why Expertise Still Matters in FedRAMP 14:37 Bladestack's Tech-First Approach to Compliance 18:40 AI Hype vs Reality in FedRAMP 22:52 Understanding What LLMs Actually Are 26:34 The Problem with Legacy SSPs 28:06 Why FedRAMP 20X Changes Everything 36:40 The Legacy FedRAMP Process Was Broken 40:32 How Bladestack Leverages AI Internally 43:19 Branding in an AI-Commoditized World 46:31 AI's Impact on the Threat Landscape 49:53 The Future of Compliance 54:00 Where to Find Bladestack

  6. May 12

    GRC Engineering, FedRAMP 20x, and AI with Ethan Troy

    "Anytime someone says something is dead, that's exactly what I have to go learn." - Ethan Troy Kenny and Isaac sit down with Ethan Troy, Senior GRC Engineer at TRM Labs, Head of AI Research at GRC Engineering Club, and Hacker at hackIDLE. One of the GOATs of GRC engineering. He's been shipping GRC tools, automations, and agents nonstop. He's assessed FedRAMP packages from the 3PAO side at Coalfire and A-LIGN. He's pentested for the Department of the Treasury. He built a FedRAMP 20x assessment app before most people knew what 20x was. His job interview at TRM Labs? They made him build an AI agent. And yes, this is the first Paramify Podcast Isaac is on. We got into: → Why now is the best time to learn something new  → Why 85% of a good GRC agent is deterministic code, not AI  → How to actually build agents (dog food your own stuff, stop one-shotting)  → Why the SSP is becoming the SSDR (System Security Decision Record) and what that means for FedRAMP® 20x  → Why domain expertise is what separates good AI output from great AI output FedRAMP is changing rapidly. Want to learn more about these changes check out this webinar here: https://lnkd.in/ge9wQ2Zf Learn more about Ethan Troy: https://www.linkedin.com/in/ethantroy/?skipRedirect=true Learn more about TRM Labs:  https://www.trmlabs.com/ Learn more about Kenny Scott:  https://www.linkedin.com/in/kenny-g-scott/ Learn more about Isaac Teuscher:  https://www.linkedin.com/in/isaacteuscher/ Learn more about Paramify: https://www.paramify.com/ Chapters: 00:58 - Introductions & GRC Engineering 02:12 - From Nursing to Cybersecurity 05:18 - The Problem with Legacy GRC Tools 12:13 - FedRAMP 2.0: The End of SSPs? 16:48 - The FedRAMP Marketplace Metaphor 24:38 - Outcome-Based vs. Hourly Consulting 31:51 - Automating Evidence Collection 37:16 - AI & Real-Time Incident Response 45:10 - Secure Configuration Guides 52:43 - Building an AI-First Culture 58:51 - Principles for AI Agents in GRC 01:05:03 - The 85/15 Rule for AI Logic

  7. Mar 2

    Justin Merhoff on FedRAMP 20x, Secure AI, Trust Centers, and Modern Cybersecurity

    In this episode of The Paramify Podcast, Kenny sits down with Justin Merhoff to talk about what makes security actually work: usability, speed, adaptability, and real-world adoption. Justin shares lessons from nearly three decades in cybersecurity, from his time in the U.S. Army to leading security and compliance programs in the private sector. The conversation covers FedRAMP 20x, trust centers, secure AI, accessibility in cybersecurity, and why security should support the business instead of slowing it down. They also get into the real burden of FedRAMP and CMMC documentation, why better tooling can reduce burnout for lean security teams, and why “usable security” is often the difference between a control that works in practice and one that only looks good on paper. Note: At the time this episode was recorded, Justin was with Rhymetec. He is now Director of Compliance at DTEX.ai. Links: Justin Merhoff on LinkedIn: https://www.linkedin.com/in/justinmerhoff Kenny Scott on LinkedIn: https://www.linkedin.com/in/kenny-g-scott DTEX.ai: https://www.dtex.ai/ Paramify: https://www.paramify.com/ In this episode, you’ll hear: - Why usable security is better security - How secure AI can help small teams move faster - Why trust centers are becoming more important - How accessibility gaps can create real security risk - Why servant leadership matters in cybersecurity - Why FedRAMP 20x is shifting the focus back to risk Chapters: 0:00 Secure AI, lean teams, and why the right tools matter 1:12 Intro to Justin Merhoff 2:08 How Justin got started in cybersecurity 8:31 Army stories, leadership, and early security lessons 16:06 Moving from the military into corporate security 19:17 Why security should enable the business 20:45 The future of trust centers 25:20 Secure AI, small teams, and reducing compliance burnout 29:32 Why FedRAMP 20x is a needed change 36:31 Cyber leadership, adaptability, and how people break into security 44:13 Why accessibility is a cybersecurity issue 51:18 What Justin was doing at the time and how Rhymetec helps clients 54:35 Outro This episode is a great listen for anyone working in FedRAMP, CMMC, GRC, compliance, security leadership, or third-party trust.

Ratings & Reviews

5
out of 5
3 Ratings

About

The Paramify Podcast is a practical, occasionally chaotic show about GRC, risk management, and staying audit-ready without losing your mind. It’s part talking security strategy, and part group therapy. We talk with cybersecurity and GRC leaders, including CISOs, auditors, founders, and security engineers, about FedRAMP and FedRAMP 20x, SOC 2, CMMC, NIST RMF, the shift toward continuous evidence, and everything in between.  Learn about what we do at Paramify here: www.paramify.com