The July 2026 Town Hall, hosted by Adam Starnes of MAD Security and featuring Aaron Smith and Jaclyn Jones, explored how a modern Security Operations Center (SOC) helps defense contractors strengthen cybersecurity, improve threat response, and support long-term CMMC readiness. Missed the webinar? Check out the comments for the full July Town Hall recap, where you can watch the webinar replay and gain practical insights into how a 24/7 SOC combines technology, experienced analysts, and documented processes to build a stronger cybersecurity program. As discussed during the webinar, "The goal is not just to see the alerts. The goal is to understand which alerts actually matter." – Aaron Smith, MAD Security A Security Operations Center is much more than continuous monitoring. It combines skilled analysts, well-defined incident response processes, and operational evidence to help organizations detect threats, reduce alert fatigue, and build a mature cybersecurity program that supports CMMC readiness. Key Takeaways: ✅ A modern SOC combines advanced technology with experienced security analysts ✅ Customized incident response playbooks help organizations respond consistently and effectively ✅ Continuous monitoring and human investigation improve threat detection and operational resilience ✅ Strong documentation and repeatable processes help support long-term CMMC readiness Does your organization have the people, processes, and technology needed to build a mature Security Operations Center? Register for future MAD Security Town Hall webinars: https://hubs.la/Q04v8RlJ0 #MADSecurity #CMMCReadiness #SecurityOperationsCenter #SOCAsAService #TownHallWebinar
MAD Security
IT Services and IT Consulting
Huntsville, Alabama 5,511 followers
Safeguarding Business by Simplifying the Cybersecurity Challenge
About us
MAD Security is a premier Managed Security Services Provider that combines technology, services, support, and training. MAD Security has enabled clients in a wide range of verticals to manage risk, meet compliance requirements, and reduce costs. MAD Security is committed to cybersecurity excellence and has a track record of delivering quality solutions that maximize security effectiveness and operational efficiency.
- Website
-
http://www.madsecurity.com/
External link for MAD Security
- Industry
- IT Services and IT Consulting
- Company size
- 11-50 employees
- Headquarters
- Huntsville, Alabama
- Type
- Privately Held
- Specialties
- Penetration Testing, Cyber Risk Management and Governance, IT Auditing, Security Architecture Review, SIEM and Log Management, Virtual CISO & CISO Consulting, Managed Security Services, CMMC, Vulnerability Management, Cybersecurity, Cybersecurity Operations Center, Cybersecurity Consulting, Managed Endpoint Detection and Response (EDR), Managed Network Detection and Response (XDR), Incident Response, Threat Hunting, Managed Email Security, SOC as a Service, Firewall Management, Cybersecurity Technical Testing, and Cybersecurity Table Top Exercises
Locations
-
Primary
Get directions
5021 Bradford Dr NW
Suite 207
Huntsville, Alabama 35805, US
Employees at MAD Security
Updates
-
Microsoft to Make Passkeys Default in Entra ID and Retire SMS and Voice Authentication 🔗 https://hubs.la/Q04tPGqj0 Microsoft is strengthening identity security by making passkeys the default authentication experience in Microsoft Entra ID and moving away from SMS and voice-based multifactor authentication (MFA), which remain vulnerable to phishing, SIM swapping, social engineering, and interception attacks. Beginning September 1, 2026, users currently enabled for SMS or voice authentication will also be enabled for passkeys and prompted to register them. Microsoft plans to fully retire from its native SMS and voice authentication delivery on February 1, 2027, making early preparation important for organizations that rely on these authentication methods. For organizations supporting the Defense Industrial Base (DIB), government agencies, and federal supply chains, this shift reinforces the importance of strong identity and access management, phishing-resistant authentication, and proactive cybersecurity controls. At MAD Security, we help organizations strengthen their cyber resilience with: ✅ 24/7 Security Operations Center (SOC) Services ✅ CMMC, DFARS, and NIST Compliance Support ✅ GRC Gap Assessments and Virtual Compliance Management ✅ Managed Detection and Response (MDR) ✅ Vulnerability Management and Cyber Risk Assessments Contact us TODAY and partner with MAD Security to strengthen identity security, improve visibility, maintain compliance, and stay ahead of evolving cyber threats. #MADSecurity #CyberSecurity #DefenseIndustrialBase #MFA #MicrosoftEntraID
-
🚨 NEW BLOG ALERT 🚨 Does storing your CUI in the cloud put the rest of your network out of scope for CMMC? Read the blog TODAY (link in comments) to learn why moving Controlled Unclassified Information (CUI) to the cloud does not automatically remove supporting network infrastructure from your CMMC assessment scope. Many organizations use cloud environments to centralize and protect the CUI. However, even when CUI resides in the cloud, your organization may still rely on firewalls, identity platforms, endpoint security tools, and other technologies to protect access to that information. These systems may qualify as Security Protection Assets (SPAs) because of the security functions they perform, not because they store CUI. In this blog, you will learn: ✔️ How the CMMC Scoping Guide determines assessment scope ✔️ Why moving CUI to the cloud does not automatically reduce scope ✔️ How Security Protection Assets help protect cloud-hosted CUI ✔️ Common cloud scoping mistakes organizations should avoid ✔️ Best practices for maintaining an accurate CMMC assessment scope Understanding how your network protects CUI can help your organization accurately define its CMMC scope and strengthen NIST SP 800-171 implementation. #MADSecurity #CMMC #CMMCAssessment #CUI #CloudSecurity
-
-
Cybersecurity is an ever-evolving field, with new challenges arising regularly. Implementing the NIST Cybersecurity Framework’s key functions of Identify, Protect, Detect, Respond, Recover, and Govern is essential, but it is just the beginning! Ensuring your cybersecurity measures are dynamic and resilient requires continuous evaluation and adaptation to new threats and regulations. By leveraging advanced monitoring and reporting tools, MAD Security helps you track and analyze data usage, providing crucial insights that allow for swift breach detection and damage minimization. Are your security protocols keeping up with the rapidly changing landscape? Contact us NOW to ensure your cybersecurity strategy evolves with the threats it faces! 📞 #CyberDefense #DataProtection #MADSecurity #NISTFramework #SecureYourData
-
-
Are your applications ready for today’s cyber threats? Click the link in the comments to learn how to defend your organization. MAD Security’s Application Security Testing helps defense, maritime, and government contractors protect applications handling Controlled Unclassified Information (CUI), strengthen security, and support compliance objectives. Our testing helps you: 🔍 Identify misconfigurations and vulnerabilities before attackers exploit them 🔍 Uncover hidden attack vectors through multi-layer testing 🔍 Prioritize remediation with clear, actionable guidance 🔍 Protect sensitive data and application integrity 🔍 Strengthen alignment with NIST and cybersecurity requirements Application security is mission critical. Find weaknesses before attackers do and build more resilient applications with MAD Security. Visit our website to learn more! #MADSecurity #CMM #Cybersecurity #NISTCompliance #TechnicalTesting
-
Assessors will expect clear proof that cybersecurity responsibilities are assigned, implemented, and supported by evidence. It is not enough to mention them in a document once a year. Read the blog NOW (link in comments) to learn what defense contractors must do to operationalize shared responsibilities and how a Shared Responsibility Matrix helps prove it before, during, and after the assessment. You will need to demonstrate that your organization has mapped every NIST SP 800-171 control to the correct internal owner or external service provider. This includes showing who is responsible, how enforcement is tracked, and where supporting evidence is stored, whether in your SSP, contracts, or monitoring tools. #MADSecurity #CMMCCompliance #CyberCompliance #DefenseContractors #SharedResponsibilityMatrix
-
-
Preparing for a CMMC Level 2 certification assessment? Read the full blog in the comments to learn why understanding the difference between a gap assessment and a mock assessment can improve your certification readiness. One of the most common mistakes organizations make is treating a gap assessment and a mock assessment as the same thing. They are not. Our blog explains how each assessment serves a different purpose and why both are critical for certification readiness. Key takeaways: 🔍 How gap assessments identify weaknesses before they become certification findings 🔍️ Why remediation guidance helps organizations address gaps more effectively 🔍 How mock assessments validate readiness under realistic assessment conditions 🔍 Why staff preparation is critical for interviews and evidence reviews Understanding when to use each assessment can help reduce risk, improve preparation, and increase confidence before engaging a C3PAO. #MADSecurity #CMMC #CMMCAssessments #CybersecurityCompliance #DefenseContractors
-
-
Clear documentation is one of the most important factors in a successful CMMC Level 2 assessment. Read the blog to learn how assessment ready documentation supports a smoother CMMC Level 2 assessment! Assessors expect documentation that accurately reflects how your environment operates at the time of the assessment. When documentation is outdated or incomplete, even well implemented controls can result in NOT MET findings or assessment delays. You must be able to clearly show how your environment protects Controlled Unclassified Information and how controls are implemented in practice. This includes clear documentation of: 🛡️ System Security Plan details 🛡️ Asset inventories and system boundaries 🛡️ Network architecture and data flows 🛡️ Roles and responsibilities for internal teams and service providers Do not assume assessors will connect the dots for you. #MADSecurity #AssessmentReady #CMMCCompliance #CMMCLevel2 #DoDContractors
-
-
In the complex world of data security, knowing what to protect is as critical as how to protect it. Identifying your “crown jewels,” the most critical data assets like CRM databases, business-critical documents, regulated information, intellectual property, and personal employee details, is the first step in fortifying your defenses. It’s not just about locking every door; it’s about knowing which doors to lock to protect your most valuable assets without hampering accessibility. Do you know where your digital crown jewels are? 🔍 Understanding the specifics of what you hold and the risks associated with these assets is key to effective data protection. Let MAD Security help you build a solid foundation of knowledge and implement targeted protections where they matter most. From strategic planning to compliance with regulations, ensure your essential data is secure against evolving threats. 🛡️ Contact us TODAY for a comprehensive data security strategy tailored to your unique needs! 📞 #CrownJewels #CyberProtection #DataSecurity #MADSecurity #SecureYourData
-
-
Suspected China-Nexus Actor Exploits VMware vCenter Flaw and Deploys Babuk-Derived Ransomware 🔗 https://hubs.la/Q04tMBL80 A suspected China-linked advanced persistent threat (APT) actor has been observed exploiting a critical VMware vCenter vulnerability, CVE-2026-59310, to gain remote code execution and establish persistent access inside victim environments. Once inside targeted environments, the threat actor deployed backdoors, created administrative accounts, established reverse SSH access, harvested credentials, and moved toward ESXi hosts. In at least one investigated case, the intrusion ultimately resulted in the deployment of Babuk-derived ransomware that encrypted files with the “.babyk” extension. This campaign demonstrates how quickly threat actors can weaponize newly disclosed vulnerabilities and why organizations cannot rely on patching alone. Continuous monitoring, vulnerability management, rapid remediation, threat detection, and incident response are essential to reducing exposure before attackers establish persistence. Contact us NOW and partner with MAD Security to identify vulnerabilities, detect threats faster, strengthen defenses, maintain compliance, and stay ahead of sophisticated cyber adversaries. #MADSecurity #Cybersecurity #CyberResilience #DefenseIndustrialBase #ManagedDetectionAndResponse