<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet href="https://rss.buzzsprout.com/styles.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:podcast="https://podcastindex.org/namespace/1.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:psc="http://podlove.org/simple-chapters" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <atom:link href="https://rss.buzzsprout.com/2541472.rss" rel="self" type="application/rss+xml" />
  <atom:link href="https://pubsubhubbub.appspot.com/" rel="hub" xmlns="http://www.w3.org/2005/Atom" />
  <title>Behind the Shield</title>

  <lastBuildDate>Tue, 26 May 2026 18:41:15 -0400</lastBuildDate>
  <link>https://behindtheshield.buzzsprout.com</link>
  <language>en-us</language>
  <copyright>© 2026 Behind the Shield</copyright>
  <podcast:locked>yes</podcast:locked>
    <podcast:guid>9af0c8b0-2f2c-5a62-b976-c2aa9fa4e3b4</podcast:guid>
  <podcast:txt purpose="verify">caitlin.pitkin@infusionpoints.com</podcast:txt>
  <itunes:author>InfusionPoints</itunes:author>
  <itunes:type>episodic</itunes:type>
  <itunes:explicit>false</itunes:explicit>
  <description><![CDATA[<p>&nbsp;Behind the Shield is InfusionPoints’ podcast where we sit down with partners, customers, and industry leaders to talk about FedRAMP, compliance, and cybersecurity in today’s government landscape. Each episode offers laid-back, insightful conversations that blend expertise with real-world experiences.&nbsp;</p>]]></description>
  <generator>Buzzsprout (https://www.buzzsprout.com)</generator>
  <itunes:owner>
    <itunes:name>InfusionPoints</itunes:name>
    <itunes:email>caitlin.pitkin@infusionpoints.com</itunes:email>
  </itunes:owner>
  <image>
     <url>https://storage.buzzsprout.com/wu0jr3rkamqoifaoxvurbkgz9xtb?.jpg</url>
     <title>Behind the Shield</title>
     <link></link>
  </image>
  <itunes:image href="https://storage.buzzsprout.com/wu0jr3rkamqoifaoxvurbkgz9xtb?.jpg" />
  <itunes:category text="Technology" />
  <item>
    <itunes:title>From FedRAMP to the Future of AI: Tony Bai on Compliance, Cybersecurity, and What’s Next</itunes:title>
    <title>From FedRAMP to the Future of AI: Tony Bai on Compliance, Cybersecurity, and What’s Next</title>
    <itunes:summary><![CDATA[In this episode of Behind the Shield, Jason Shropshire sits down with Tony Bai, Chief Solutions Officer at RISCPoint, for a wide-ranging conversation on cybersecurity, compliance, emerging technology, and the future of the workforce.  Tony shares his journey from serving in the U.S. Air Force and supporting cyber operations at the Pentagon to becoming a leader in the federal cybersecurity and compliance space. Along the way, the conversation dives into the evolution of FedRAMP, RMF, CMMC, clo...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of Behind the Shield, Jason Shropshire sits down with Tony Bai, Chief Solutions Officer at RISCPoint, for a wide-ranging conversation on cybersecurity, compliance, emerging technology, and the future of the workforce.<br/><br/>Tony shares his journey from serving in the U.S. Air Force and supporting cyber operations at the Pentagon to becoming a leader in the federal cybersecurity and compliance space. Along the way, the conversation dives into the evolution of FedRAMP, RMF, CMMC, cloud security, and the realities of helping organizations navigate increasingly complex regulatory environments.<br/><br/>Jason and Tony discuss the balance between real security and “check-the-box” compliance, why over-reliance on tools and outsourced accountability can create risk, and how organizations can build sustainable security programs that actually support business operations. The episode also explores common pitfalls in FedRAMP and CMMC journeys, the importance of tailored security engineering, and why mentorship and workforce development matter now more than ever.<br/><br/>The conversation then shifts to one of the biggest topics shaping the industry today: AI. From AI-assisted coding and automation to concerns about losing foundational technical skills, Tony and Jason unpack both the opportunities and risks that come with rapid technological acceleration. They also reflect on how today’s cybersecurity leaders can help develop the next generation of engineers and practitioners in an increasingly AI-driven world.<br/><br/>The episode wraps with lighter conversation around mentorship, career growth, sci-fi fandoms, Legos, and what life after cybersecurity might look like.<br/><br/>Links to things we talked about:<br/>The 1969 Apollo guidance computer - https://www.youtube.com/watch?v=B1J2RMorJXM<br/>Running Doom on a pregnancy test - https://www.popularmechanics.com/science/a33957256/this-programmer-figured-out-how-to-play-doom-on-a-pregnancy-test/<br/><br/>What You’ll Learn<br/>Tony Bai’s path from the Air Force into cybersecurity and compliance leadership<br/>How FedRAMP, RMF, CMMC, and cloud security have evolved over time<br/>Why “real security” goes beyond compliance checklists<br/>Common mistakes organizations make when outsourcing security responsibilities<br/>The balance between automation, AI, and human expertise<br/>Why foundational technical knowledge still matters in the age of AI<br/>How companies can better mentor and grow the next generation of cybersecurity talent<br/>The importance of long-term trusted partnerships in compliance and advisory work<br/><br/>Chapters:<br/>0:11 - Introduction and Guest Welcome<br/>1:05 - Tony&apos;s Background in Cybersecurity<br/>3:45 - Jason&apos;s Path in IT<br/>7:45 - Evolution of Technology<br/>9:33 - Transition to Compliance and Advisory<br/>13:58 - Compliance, Security Engineering, and FedRAMP<br/>19:22 - Challenges in Compliance<br/>24:38 - Over and Under Investment in Security<br/>35:59 - Rapid Changes in AI and Technology<br/>49:58 - Personal Interests and Hobbies<br/><br/>Guest Links:<br/>https://www.linkedin.com/in/williamtbai/<br/>https://www.linkedin.com/company/riscpoint/<br/>https://www.riscpoint.com/<br/><br/>Learn more about InfusionPoints:<br/>https://www.linkedin.com/company/infusionpoints/<br/>Jason Shropshire: https://www.linkedin.com/in/shrop/<br/>Request a Demo: https://xbu40.com/<br/><br/>InfusionPoints &amp; AWS:<br/>InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments.<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.<br/>Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of Behind the Shield, Jason Shropshire sits down with Tony Bai, Chief Solutions Officer at RISCPoint, for a wide-ranging conversation on cybersecurity, compliance, emerging technology, and the future of the workforce.<br/><br/>Tony shares his journey from serving in the U.S. Air Force and supporting cyber operations at the Pentagon to becoming a leader in the federal cybersecurity and compliance space. Along the way, the conversation dives into the evolution of FedRAMP, RMF, CMMC, cloud security, and the realities of helping organizations navigate increasingly complex regulatory environments.<br/><br/>Jason and Tony discuss the balance between real security and “check-the-box” compliance, why over-reliance on tools and outsourced accountability can create risk, and how organizations can build sustainable security programs that actually support business operations. The episode also explores common pitfalls in FedRAMP and CMMC journeys, the importance of tailored security engineering, and why mentorship and workforce development matter now more than ever.<br/><br/>The conversation then shifts to one of the biggest topics shaping the industry today: AI. From AI-assisted coding and automation to concerns about losing foundational technical skills, Tony and Jason unpack both the opportunities and risks that come with rapid technological acceleration. They also reflect on how today’s cybersecurity leaders can help develop the next generation of engineers and practitioners in an increasingly AI-driven world.<br/><br/>The episode wraps with lighter conversation around mentorship, career growth, sci-fi fandoms, Legos, and what life after cybersecurity might look like.<br/><br/>Links to things we talked about:<br/>The 1969 Apollo guidance computer - https://www.youtube.com/watch?v=B1J2RMorJXM<br/>Running Doom on a pregnancy test - https://www.popularmechanics.com/science/a33957256/this-programmer-figured-out-how-to-play-doom-on-a-pregnancy-test/<br/><br/>What You’ll Learn<br/>Tony Bai’s path from the Air Force into cybersecurity and compliance leadership<br/>How FedRAMP, RMF, CMMC, and cloud security have evolved over time<br/>Why “real security” goes beyond compliance checklists<br/>Common mistakes organizations make when outsourcing security responsibilities<br/>The balance between automation, AI, and human expertise<br/>Why foundational technical knowledge still matters in the age of AI<br/>How companies can better mentor and grow the next generation of cybersecurity talent<br/>The importance of long-term trusted partnerships in compliance and advisory work<br/><br/>Chapters:<br/>0:11 - Introduction and Guest Welcome<br/>1:05 - Tony&apos;s Background in Cybersecurity<br/>3:45 - Jason&apos;s Path in IT<br/>7:45 - Evolution of Technology<br/>9:33 - Transition to Compliance and Advisory<br/>13:58 - Compliance, Security Engineering, and FedRAMP<br/>19:22 - Challenges in Compliance<br/>24:38 - Over and Under Investment in Security<br/>35:59 - Rapid Changes in AI and Technology<br/>49:58 - Personal Interests and Hobbies<br/><br/>Guest Links:<br/>https://www.linkedin.com/in/williamtbai/<br/>https://www.linkedin.com/company/riscpoint/<br/>https://www.riscpoint.com/<br/><br/>Learn more about InfusionPoints:<br/>https://www.linkedin.com/company/infusionpoints/<br/>Jason Shropshire: https://www.linkedin.com/in/shrop/<br/>Request a Demo: https://xbu40.com/<br/><br/>InfusionPoints &amp; AWS:<br/>InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments.<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.<br/>Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/19244293-from-fedramp-to-the-future-of-ai-tony-bai-on-compliance-cybersecurity-and-what-s-next.mp3" length="42243027" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19244293</guid>
    <pubDate>Tue, 26 May 2026 18:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19244293/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19244293/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19244293/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19244293/transcript.vtt" type="text/vtt" />
    <itunes:duration>3517</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>35</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Breaking Into Def Tech: The Top 5 Challenges Facing Modern Companies</itunes:title>
    <title>Breaking Into Def Tech: The Top 5 Challenges Facing Modern Companies</title>
    <itunes:summary><![CDATA[The Defense Tech market is full of opportunity, but getting into the space is far from simple.  In this episode of Behind the Shield, InfusionPoints COO Jason Shropshire and CEO Gary Daemer each share their perspectives on the top 5 challenges companies face when trying to break into the Defense Tech and Department of Defense market. The conversation highlights how technical, operational, and business challenges can look very different depending on where companies are in their federal journey...]]></itunes:summary>
    <description><![CDATA[<p>The Defense Tech market is full of opportunity, but getting into the space is far from simple.<br/><br/>In this episode of Behind the Shield, InfusionPoints COO Jason Shropshire and CEO Gary Daemer each share their perspectives on the top 5 challenges companies face when trying to break into the Defense Tech and Department of Defense market. The conversation highlights how technical, operational, and business challenges can look very different depending on where companies are in their federal journey.<br/><br/>From navigating FedRAMP and the DoD Cloud Computing Security Requirements Guide (DoD CC SRG) to finding sponsorship, securing IL4/IL5 authorizations, and surviving long ATO timelines, this conversation offers a candid look at the operational, technical, and business realities of entering the federal and defense markets.<br/><br/>The discussion also explores:<br/>• Why sponsorship is one of the biggest barriers to entry<br/>• The difference between FedRAMP and DoD authorization pathways<br/>• Challenges around IL4 and IL5 environments<br/>• The impact of RMF, DISA, BCAP, and eMASS processes<br/>• Why predictability and automation matter for modern compliance<br/>• Hardening requirements, STIGs, and securing cloud environments<br/>• The business realities of getting a second and third government customer<br/>• How FedRAMP 20x and automation could reshape the future of Defense Tech compliance<br/><br/>Whether you&apos;re a startup trying to break into Defense Tech, a cloud service provider pursuing federal business, or an established company navigating DoD requirements, this episode provides practical insight from a team actively helping organizations operate in regulated federal environments.<br/><br/>What You’ll Learn:<br/>• The biggest mistakes companies make entering Defense Tech<br/>• Why compliance alone does not guarantee success<br/>• The hidden complexity of IL4/IL5 authorizations<br/>• How authorization delays impact business growth<br/>• Where the Defense Tech market may be headed next<br/><br/>Learn more about InfusionPoints:<br/>https://www.linkedin.com/company/infusionpoints/<br/>Gary Daemer: https://www.linkedin.com/in/infusionpoints/<br/>Jason Shropshire: https://www.linkedin.com/in/shrop/<br/>Request a Demo: https://xbu40.com/<br/>Blogs: <br/>SWFT, cATO, 20x and the Rev. 4 Drag Still Inside DoW Cloud Authorization:<br/>https://infusionpoints.com/blogs/swft-cato-20x-and-rev-4-drag-still-inside-dow-cloud-authorization<br/>The Quiet Convergence: why DoD DevSecOps, SWFT, and FedRAMP 20x are Starting to Rhyme:<br/>https://infusionpoints.com/blogs/quiet-convergence-why-dod-devsecops-swft-and-fedramp-20x-are-starting-rhyme<br/>Subscribe for more conversations on FedRAMP, Defense Tech, cybersecurity, cloud compliance, and the future of continuous authorization.<br/><br/>InfusionPoints &amp; AWS:<br/>InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments.<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.<br/>Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.</p>]]></description>
    <content:encoded><![CDATA[<p>The Defense Tech market is full of opportunity, but getting into the space is far from simple.<br/><br/>In this episode of Behind the Shield, InfusionPoints COO Jason Shropshire and CEO Gary Daemer each share their perspectives on the top 5 challenges companies face when trying to break into the Defense Tech and Department of Defense market. The conversation highlights how technical, operational, and business challenges can look very different depending on where companies are in their federal journey.<br/><br/>From navigating FedRAMP and the DoD Cloud Computing Security Requirements Guide (DoD CC SRG) to finding sponsorship, securing IL4/IL5 authorizations, and surviving long ATO timelines, this conversation offers a candid look at the operational, technical, and business realities of entering the federal and defense markets.<br/><br/>The discussion also explores:<br/>• Why sponsorship is one of the biggest barriers to entry<br/>• The difference between FedRAMP and DoD authorization pathways<br/>• Challenges around IL4 and IL5 environments<br/>• The impact of RMF, DISA, BCAP, and eMASS processes<br/>• Why predictability and automation matter for modern compliance<br/>• Hardening requirements, STIGs, and securing cloud environments<br/>• The business realities of getting a second and third government customer<br/>• How FedRAMP 20x and automation could reshape the future of Defense Tech compliance<br/><br/>Whether you&apos;re a startup trying to break into Defense Tech, a cloud service provider pursuing federal business, or an established company navigating DoD requirements, this episode provides practical insight from a team actively helping organizations operate in regulated federal environments.<br/><br/>What You’ll Learn:<br/>• The biggest mistakes companies make entering Defense Tech<br/>• Why compliance alone does not guarantee success<br/>• The hidden complexity of IL4/IL5 authorizations<br/>• How authorization delays impact business growth<br/>• Where the Defense Tech market may be headed next<br/><br/>Learn more about InfusionPoints:<br/>https://www.linkedin.com/company/infusionpoints/<br/>Gary Daemer: https://www.linkedin.com/in/infusionpoints/<br/>Jason Shropshire: https://www.linkedin.com/in/shrop/<br/>Request a Demo: https://xbu40.com/<br/>Blogs: <br/>SWFT, cATO, 20x and the Rev. 4 Drag Still Inside DoW Cloud Authorization:<br/>https://infusionpoints.com/blogs/swft-cato-20x-and-rev-4-drag-still-inside-dow-cloud-authorization<br/>The Quiet Convergence: why DoD DevSecOps, SWFT, and FedRAMP 20x are Starting to Rhyme:<br/>https://infusionpoints.com/blogs/quiet-convergence-why-dod-devsecops-swft-and-fedramp-20x-are-starting-rhyme<br/>Subscribe for more conversations on FedRAMP, Defense Tech, cybersecurity, cloud compliance, and the future of continuous authorization.<br/><br/>InfusionPoints &amp; AWS:<br/>InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments.<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.<br/>Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/19204879-breaking-into-def-tech-the-top-5-challenges-facing-modern-companies.mp3" length="33881191" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19204879</guid>
    <pubDate>Tue, 19 May 2026 15:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19204879/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19204879/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19204879/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19204879/transcript.vtt" type="text/vtt" />
    <itunes:duration>2820</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>34</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Understanding Minimum Assessment Scope (MAS) in FedRAMP 20x</itunes:title>
    <title>Understanding Minimum Assessment Scope (MAS) in FedRAMP 20x</title>
    <itunes:summary><![CDATA[In this episode of Behind the Shield, InfusionPoints’ Chad Spears and Tanner Bailey break down one of the most important concepts shaping the future of FedRAMP 20x: the Minimum Assessment Scope (MAS).  As organizations begin preparing for the transition toward continuous validation and automated security evidence, understanding what actually belongs in scope has become critical. Chad and Tanner unpack how MAS is designed to help organizations focus on the systems, resources, and validations t...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of Behind the Shield, InfusionPoints’ Chad Spears and Tanner Bailey break down one of the most important concepts shaping the future of FedRAMP 20x: the Minimum Assessment Scope (MAS).<br/><br/>As organizations begin preparing for the transition toward continuous validation and automated security evidence, understanding what actually belongs in scope has become critical. Chad and Tanner unpack how MAS is designed to help organizations focus on the systems, resources, and validations that truly matter to the security of the environment instead of wasting time, engineering effort, and budget on unnecessary complexity.<br/><br/>The conversation explores how FedRAMP 20x is pushing organizations toward a more operational, automation-first mindset. Rather than treating compliance as a one-time documentation exercise, the discussion highlights how continuous validation, reusable checks, and machine-readable evidence are changing the way cloud providers approach authorization readiness.<br/><br/>Throughout the episode, the team connects the technical realities of Minimum Assessment Scope back to real business outcomes. From reducing engineering overhead and controlling costs to accelerating authorization timelines and improving operational maintainability, MAS is positioned as a foundational starting point for organizations pursuing a modernized FedRAMP strategy.<br/><br/>Whether you’re a security engineer, cloud architect, compliance lead, executive stakeholder, or CSP trying to understand what FedRAMP modernization actually means in practice, this episode provides practical insight into where the ecosystem is heading and how to prepare.<br/><br/>Chapters:<br/>Introduction and Overview - 0:08<br/>Understanding MAS (Minimum Assessment Scope) - 0:56<br/>Importance of MAS in FedRAMP 20X - 4:52<br/>Defining the Scope and Its Impact - 7:29<br/>Challenges and Considerations - 11:33<br/>Business Impact of MAS - 26:46<br/>Conclusion and Resources - 28:21<br/><br/>What You’ll Learn:<br/>• What Minimum Assessment Scope (MAS) actually means in FedRAMP 20x<br/>• How MAS can reduce complexity, cost, and engineering effort<br/>• Why continuous validation changes the way compliance is approached<br/>• How reusable KSI validation checks improve operational efficiency<br/>• Why automation and machine-readable evidence are central to FedRAMP modernization<br/>• The connection between MAS, speed-to-authorization, and long-term maintainability<br/>• Updates on Consolidated Rules 2026 (CR2026) and evolving FedRAMP terminology<br/>• What organizations should be doing now to prepare for the future of FedRAMP<br/><br/>InfusionPoints Links:<br/>FedRAMP 20x Quick Look Assessment: https://xbu40.com/assessment<br/>https://infusionpoints.com/<br/>LinkedIn: https://www.linkedin.com/company/infusionpoints/<br/>Chad Spears: https://www.linkedin.com/in/chad-spears007/<br/>Tanner Bailey: https://www.linkedin.com/in/tanner-b-37a50a132/<br/><br/>InfusionPoints &amp; AWS:<br/>InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments.<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.<br/>Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of Behind the Shield, InfusionPoints’ Chad Spears and Tanner Bailey break down one of the most important concepts shaping the future of FedRAMP 20x: the Minimum Assessment Scope (MAS).<br/><br/>As organizations begin preparing for the transition toward continuous validation and automated security evidence, understanding what actually belongs in scope has become critical. Chad and Tanner unpack how MAS is designed to help organizations focus on the systems, resources, and validations that truly matter to the security of the environment instead of wasting time, engineering effort, and budget on unnecessary complexity.<br/><br/>The conversation explores how FedRAMP 20x is pushing organizations toward a more operational, automation-first mindset. Rather than treating compliance as a one-time documentation exercise, the discussion highlights how continuous validation, reusable checks, and machine-readable evidence are changing the way cloud providers approach authorization readiness.<br/><br/>Throughout the episode, the team connects the technical realities of Minimum Assessment Scope back to real business outcomes. From reducing engineering overhead and controlling costs to accelerating authorization timelines and improving operational maintainability, MAS is positioned as a foundational starting point for organizations pursuing a modernized FedRAMP strategy.<br/><br/>Whether you’re a security engineer, cloud architect, compliance lead, executive stakeholder, or CSP trying to understand what FedRAMP modernization actually means in practice, this episode provides practical insight into where the ecosystem is heading and how to prepare.<br/><br/>Chapters:<br/>Introduction and Overview - 0:08<br/>Understanding MAS (Minimum Assessment Scope) - 0:56<br/>Importance of MAS in FedRAMP 20X - 4:52<br/>Defining the Scope and Its Impact - 7:29<br/>Challenges and Considerations - 11:33<br/>Business Impact of MAS - 26:46<br/>Conclusion and Resources - 28:21<br/><br/>What You’ll Learn:<br/>• What Minimum Assessment Scope (MAS) actually means in FedRAMP 20x<br/>• How MAS can reduce complexity, cost, and engineering effort<br/>• Why continuous validation changes the way compliance is approached<br/>• How reusable KSI validation checks improve operational efficiency<br/>• Why automation and machine-readable evidence are central to FedRAMP modernization<br/>• The connection between MAS, speed-to-authorization, and long-term maintainability<br/>• Updates on Consolidated Rules 2026 (CR2026) and evolving FedRAMP terminology<br/>• What organizations should be doing now to prepare for the future of FedRAMP<br/><br/>InfusionPoints Links:<br/>FedRAMP 20x Quick Look Assessment: https://xbu40.com/assessment<br/>https://infusionpoints.com/<br/>LinkedIn: https://www.linkedin.com/company/infusionpoints/<br/>Chad Spears: https://www.linkedin.com/in/chad-spears007/<br/>Tanner Bailey: https://www.linkedin.com/in/tanner-b-37a50a132/<br/><br/>InfusionPoints &amp; AWS:<br/>InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments.<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.<br/>Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/19166178-understanding-minimum-assessment-scope-mas-in-fedramp-20x.mp3" length="22653013" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19166178</guid>
    <pubDate>Tue, 12 May 2026 14:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19166178/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19166178/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19166178/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19166178/transcript.vtt" type="text/vtt" />
    <itunes:duration>1885</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>33</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>From Acceleration to ATO: Navigating Defense Tech, Divestitures, and the Future of FedRAMP</itunes:title>
    <title>From Acceleration to ATO: Navigating Defense Tech, Divestitures, and the Future of FedRAMP</title>
    <itunes:summary><![CDATA[In this episode of Behind the Shield, we sit down with Phil Hickson alongside InfusionPoints’ Jackson Gorman and Jason Shropshire for a deep dive into the evolving world of Defense Tech and federal compliance. Phil shares a behind-the-scenes look at navigating a complex FedRAMP ATO journey during a major divestiture, including standing up a new authorization boundary while maintaining compliance and customer continuity. The conversation explores the challenges of scaling secure cloud services...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of <em>Behind the Shield</em>, we sit down with Phil Hickson alongside InfusionPoints’ Jackson Gorman and Jason Shropshire for a deep dive into the evolving world of Defense Tech and federal compliance.</p><p>Phil shares a behind-the-scenes look at navigating a complex FedRAMP ATO journey during a major divestiture, including standing up a new authorization boundary while maintaining compliance and customer continuity. The conversation explores the challenges of scaling secure cloud services across federal and DoD environments, from BCAP connections and IL4/IL5 considerations to managing risk at scale.</p><p>We also unpack what modernization looks like today. With FedRAMP 20x gaining momentum, the group discusses how Defense Tech companies can balance legacy requirements with continuous validation and automated evidence. The result is a candid look at where compliance is headed and what it means for companies building for mission-critical environments.</p><p>If you’re working in Defense Tech, selling into federal or DoD markets, or trying to make sense of where FedRAMP is going next, this episode offers practical insight from people actively navigating the shift.</p><p><br/>Chapters:<br/>00:08 Introduction and Guest Welcome<br/>00:31 Phil&apos;s Experience with CSPs<br/>02:34 Divestiture and Omnissa&apos;s Origin<br/>05:20 Challenges with FedRAMP and DOD<br/>15:22 Navigating DOD Authorization<br/>33:45 Modernization and 20X Discussion<br/>49:18 Phil&apos;s Origin Story in Compliance<br/>55:44 Lighthearted Questions and Wrap-up<br/><br/><br/>Guest Links: <br/>Phil Hickson- https://www.linkedin.com/in/philhickson/<br/>Omnissa- https://www.linkedin.com/company/omnissa/<br/>Omnissa trust center | Cloud security &amp; compliance- https://www.omnissa.com/trust-center/<br/>Omnissa Products and Platform Services- https://www.omnissa.com/products/ <br/>https://www.omnissa.com/<br/><br/>About Omnissa: <br/>Omnissa provides an industry-leading digital workspace platform of services that simplifies the delivery, management, and security of devices, apps, and services to employees and IT teams alike.<br/>Explore Omnissa - the digital work platform leader- https://www.omnissa.com/about-us/<br/><br/><br/>InfusionPoints Links: <br/>Jason Shropshire- https://www.linkedin.com/in/shrop/<br/>Jackson Gorman- https://www.linkedin.com/in/jacksonagorman/<br/>https://www.linkedin.com/company/infusionpoints/<br/>https://infusionpoints.com/<br/>https://xbu40.com/<br/>FedRAMP 20x Quick Look Assessment for CSPs: https://xbu40.com/assessment<br/>&apos;SWFT, cATO, 20x and Rev 4 Drag Still Inside DoD Cloud Authorization&apos; Blog: https://infusionpoints.com/blogs/swft-cato-20x-and-rev-4-drag-still-inside-dow-cloud-authorization<br/><br/>InfusionPoints &amp; AWS:<br/>InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments.<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.<br/>Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of <em>Behind the Shield</em>, we sit down with Phil Hickson alongside InfusionPoints’ Jackson Gorman and Jason Shropshire for a deep dive into the evolving world of Defense Tech and federal compliance.</p><p>Phil shares a behind-the-scenes look at navigating a complex FedRAMP ATO journey during a major divestiture, including standing up a new authorization boundary while maintaining compliance and customer continuity. The conversation explores the challenges of scaling secure cloud services across federal and DoD environments, from BCAP connections and IL4/IL5 considerations to managing risk at scale.</p><p>We also unpack what modernization looks like today. With FedRAMP 20x gaining momentum, the group discusses how Defense Tech companies can balance legacy requirements with continuous validation and automated evidence. The result is a candid look at where compliance is headed and what it means for companies building for mission-critical environments.</p><p>If you’re working in Defense Tech, selling into federal or DoD markets, or trying to make sense of where FedRAMP is going next, this episode offers practical insight from people actively navigating the shift.</p><p><br/>Chapters:<br/>00:08 Introduction and Guest Welcome<br/>00:31 Phil&apos;s Experience with CSPs<br/>02:34 Divestiture and Omnissa&apos;s Origin<br/>05:20 Challenges with FedRAMP and DOD<br/>15:22 Navigating DOD Authorization<br/>33:45 Modernization and 20X Discussion<br/>49:18 Phil&apos;s Origin Story in Compliance<br/>55:44 Lighthearted Questions and Wrap-up<br/><br/><br/>Guest Links: <br/>Phil Hickson- https://www.linkedin.com/in/philhickson/<br/>Omnissa- https://www.linkedin.com/company/omnissa/<br/>Omnissa trust center | Cloud security &amp; compliance- https://www.omnissa.com/trust-center/<br/>Omnissa Products and Platform Services- https://www.omnissa.com/products/ <br/>https://www.omnissa.com/<br/><br/>About Omnissa: <br/>Omnissa provides an industry-leading digital workspace platform of services that simplifies the delivery, management, and security of devices, apps, and services to employees and IT teams alike.<br/>Explore Omnissa - the digital work platform leader- https://www.omnissa.com/about-us/<br/><br/><br/>InfusionPoints Links: <br/>Jason Shropshire- https://www.linkedin.com/in/shrop/<br/>Jackson Gorman- https://www.linkedin.com/in/jacksonagorman/<br/>https://www.linkedin.com/company/infusionpoints/<br/>https://infusionpoints.com/<br/>https://xbu40.com/<br/>FedRAMP 20x Quick Look Assessment for CSPs: https://xbu40.com/assessment<br/>&apos;SWFT, cATO, 20x and Rev 4 Drag Still Inside DoD Cloud Authorization&apos; Blog: https://infusionpoints.com/blogs/swft-cato-20x-and-rev-4-drag-still-inside-dow-cloud-authorization<br/><br/>InfusionPoints &amp; AWS:<br/>InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments.<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.<br/>Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/19131221-from-acceleration-to-ato-navigating-defense-tech-divestitures-and-the-future-of-fedramp.mp3" length="45128203" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19131221</guid>
    <pubDate>Tue, 05 May 2026 17:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19131221/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19131221/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19131221/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19131221/transcript.vtt" type="text/vtt" />
    <itunes:duration>3758</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>32</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Agentic SOC Shift: Smarter Security, Human-Led Decisions</itunes:title>
    <title>The Agentic SOC Shift: Smarter Security, Human-Led Decisions</title>
    <itunes:summary><![CDATA[What happens when your SOC doesn’t just respond to threats but actively thinks, prioritizes, and takes action?  In this episode of Behind the Shield, we break down the rise of the Agentic SOC and what it means for the future of cybersecurity operations. As organizations face an overwhelming volume of alerts, evolving threats, and increasing pressure to move faster, traditional SOC models are being pushed to their limits. Enter agentic systems. These are AI-driven, decision-capable frameworks ...]]></itunes:summary>
    <description><![CDATA[<p>What happens when your SOC doesn’t just respond to threats but actively thinks, prioritizes, and takes action?<br/><br/>In this episode of Behind the Shield, we break down the rise of the Agentic SOC and what it means for the future of cybersecurity operations. As organizations face an overwhelming volume of alerts, evolving threats, and increasing pressure to move faster, traditional SOC models are being pushed to their limits. Enter agentic systems. These are AI-driven, decision-capable frameworks designed to augment or even transform how security teams operate.<br/><br/>We explore how agentic capabilities are shifting the SOC from reactive monitoring to proactive, intelligent defense. From automated triage to adaptive response workflows, this conversation dives into the real-world impact of bringing autonomy into security operations and what teams need to consider before adopting it.<br/><br/>Whether you&apos;re leading a SOC, building security architecture, or trying to understand how AI is reshaping cyber defense, this episode offers a grounded look at where things are headed and what it takes to get there.</p><p>What You’ll Learn:<br/>• What an Agentic SOC actually is and how it differs from traditional SOC models<br/>• How AI agents can triage, prioritize, and respond to threats in real time<br/>• The role of human analysts in an increasingly autonomous environment<br/>• Key benefits and risks of adopting agentic security operations<br/>• How organizations can begin preparing their SOC for this shift<br/>• Where agentic approaches align with modern frameworks like continuous monitoring and validation</p><p>InfusionPoints Links: <br/>Alex Erhardt: https://www.linkedin.com/in/charles-e-7a2b8016a/<br/>Nicholas Whitley: https://www.linkedin.com/in/nicholas-whitley-511085213/<br/>https://www.linkedin.com/company/infusionpoints/<br/>https://infusionpoints.com/<br/>Get continuous security without building your own SOC: https://app.hatchbuck.com/OnlineForm/93633624292<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.<br/>Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.</p><p><br/></p>]]></description>
    <content:encoded><![CDATA[<p>What happens when your SOC doesn’t just respond to threats but actively thinks, prioritizes, and takes action?<br/><br/>In this episode of Behind the Shield, we break down the rise of the Agentic SOC and what it means for the future of cybersecurity operations. As organizations face an overwhelming volume of alerts, evolving threats, and increasing pressure to move faster, traditional SOC models are being pushed to their limits. Enter agentic systems. These are AI-driven, decision-capable frameworks designed to augment or even transform how security teams operate.<br/><br/>We explore how agentic capabilities are shifting the SOC from reactive monitoring to proactive, intelligent defense. From automated triage to adaptive response workflows, this conversation dives into the real-world impact of bringing autonomy into security operations and what teams need to consider before adopting it.<br/><br/>Whether you&apos;re leading a SOC, building security architecture, or trying to understand how AI is reshaping cyber defense, this episode offers a grounded look at where things are headed and what it takes to get there.</p><p>What You’ll Learn:<br/>• What an Agentic SOC actually is and how it differs from traditional SOC models<br/>• How AI agents can triage, prioritize, and respond to threats in real time<br/>• The role of human analysts in an increasingly autonomous environment<br/>• Key benefits and risks of adopting agentic security operations<br/>• How organizations can begin preparing their SOC for this shift<br/>• Where agentic approaches align with modern frameworks like continuous monitoring and validation</p><p>InfusionPoints Links: <br/>Alex Erhardt: https://www.linkedin.com/in/charles-e-7a2b8016a/<br/>Nicholas Whitley: https://www.linkedin.com/in/nicholas-whitley-511085213/<br/>https://www.linkedin.com/company/infusionpoints/<br/>https://infusionpoints.com/<br/>Get continuous security without building your own SOC: https://app.hatchbuck.com/OnlineForm/93633624292<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.<br/>Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.</p><p><br/></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/19096551-the-agentic-soc-shift-smarter-security-human-led-decisions.mp3" length="15865776" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19096551</guid>
    <pubDate>Wed, 29 Apr 2026 08:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19096551/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19096551/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19096551/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19096551/transcript.vtt" type="text/vtt" />
    <itunes:duration>1319</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>31</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>FedRAMP 20x and the Future of Compliance with Gary Guercio</itunes:title>
    <title>FedRAMP 20x and the Future of Compliance with Gary Guercio</title>
    <itunes:summary><![CDATA[In this episode of Behind the Shield, we sit down with Gary Guercio, VP of Operations at Fortreum, for a deep dive into the evolution of cybersecurity auditing and what FedRAMP 20x signals for the future of federal cloud security. From the early days of manual audits filled with printed artifacts, screenshots, and physical binders, to today’s push toward automation, APIs, and machine-readable evidence, Gary shares a firsthand perspective on how dramatically the landscape has changed.  Togethe...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of Behind the Shield, we sit down with Gary Guercio, VP of Operations at Fortreum, for a deep dive into the evolution of cybersecurity auditing and what FedRAMP 20x signals for the future of federal cloud security. From the early days of manual audits filled with printed artifacts, screenshots, and physical binders, to today’s push toward automation, APIs, and machine-readable evidence, Gary shares a firsthand perspective on how dramatically the landscape has changed.<br/><br/>Together, we explore how the industry is shifting away from point-in-time assessments toward continuous validation, and what that really means for Cloud Service Providers, assessors, and agencies. This conversation goes beyond theory and gets into the practical realities: how auditors will need to understand code, how engineering and compliance are becoming tightly integrated, and why organizations must rethink how they build, manage, and prove security from the ground up.<br/><br/>We also discuss the broader impact of FedRAMP 20x on the market, including how transparency, competition, and automation could reshape how security is measured and trusted across the ecosystem. Whether you&apos;re just starting your FedRAMP journey or actively navigating 20x, this episode offers valuable insight into where things are going and how to stay ahead.<br/><br/>Chapters:<br/>9:08 Introduction and Guest Intro<br/>9:20 Career Path and Education<br/>10:42 Early Career in Cybersecurity<br/>13:36 Auditing and IT Controls<br/>15:37 Booz Allen and Government Projects<br/>20:39 FedRAMP and Fortreum<br/>25:17 FedRAMP 20x and Automation in Auditing<br/>59:26 The Future of Auditing and AI<br/><br/>What You’ll Learn:<br/>• How cybersecurity auditing has evolved over the last 25+ years<br/>• The biggest differences between traditional audits and FedRAMP 20x<br/>• Why automation and machine-readable evidence are changing everything<br/>• How the role of assessors is shifting toward code and engineering understanding<br/>• What continuous validation actually looks like in practice<br/>• The challenges CSPs will face when adopting 20x<br/>• How competition in the marketplace could drive stronger security outcomes<br/>• Where AI and automation are headed in the auditing space<br/>• Why FedRAMP 20x is about more than compliance, it’s about changing the system<br/><br/>Guest Links:<br/>Gary Guercio- https://www.linkedin.com/in/gary-guercio-48622b5b/<br/>Fortreum- https://fortreum.com<br/><br/>InfusionPoints Links: <br/>Gary Daemer- https://www.linkedin.com/in/infusionpoints/<br/>InfusionPoints- https://www.linkedin.com/company/infusionpoints/<br/>20x Webinar Series | Session 1- https://youtu.be/EoaXjGa-vl0?si=UmnDCXY4dhTKpC6L<br/>20x Webinar Series | Session 2 Registration- https://xbu40.com/20x-cohort/april-28-26<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.<br/>Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of Behind the Shield, we sit down with Gary Guercio, VP of Operations at Fortreum, for a deep dive into the evolution of cybersecurity auditing and what FedRAMP 20x signals for the future of federal cloud security. From the early days of manual audits filled with printed artifacts, screenshots, and physical binders, to today’s push toward automation, APIs, and machine-readable evidence, Gary shares a firsthand perspective on how dramatically the landscape has changed.<br/><br/>Together, we explore how the industry is shifting away from point-in-time assessments toward continuous validation, and what that really means for Cloud Service Providers, assessors, and agencies. This conversation goes beyond theory and gets into the practical realities: how auditors will need to understand code, how engineering and compliance are becoming tightly integrated, and why organizations must rethink how they build, manage, and prove security from the ground up.<br/><br/>We also discuss the broader impact of FedRAMP 20x on the market, including how transparency, competition, and automation could reshape how security is measured and trusted across the ecosystem. Whether you&apos;re just starting your FedRAMP journey or actively navigating 20x, this episode offers valuable insight into where things are going and how to stay ahead.<br/><br/>Chapters:<br/>9:08 Introduction and Guest Intro<br/>9:20 Career Path and Education<br/>10:42 Early Career in Cybersecurity<br/>13:36 Auditing and IT Controls<br/>15:37 Booz Allen and Government Projects<br/>20:39 FedRAMP and Fortreum<br/>25:17 FedRAMP 20x and Automation in Auditing<br/>59:26 The Future of Auditing and AI<br/><br/>What You’ll Learn:<br/>• How cybersecurity auditing has evolved over the last 25+ years<br/>• The biggest differences between traditional audits and FedRAMP 20x<br/>• Why automation and machine-readable evidence are changing everything<br/>• How the role of assessors is shifting toward code and engineering understanding<br/>• What continuous validation actually looks like in practice<br/>• The challenges CSPs will face when adopting 20x<br/>• How competition in the marketplace could drive stronger security outcomes<br/>• Where AI and automation are headed in the auditing space<br/>• Why FedRAMP 20x is about more than compliance, it’s about changing the system<br/><br/>Guest Links:<br/>Gary Guercio- https://www.linkedin.com/in/gary-guercio-48622b5b/<br/>Fortreum- https://fortreum.com<br/><br/>InfusionPoints Links: <br/>Gary Daemer- https://www.linkedin.com/in/infusionpoints/<br/>InfusionPoints- https://www.linkedin.com/company/infusionpoints/<br/>20x Webinar Series | Session 1- https://youtu.be/EoaXjGa-vl0?si=UmnDCXY4dhTKpC6L<br/>20x Webinar Series | Session 2 Registration- https://xbu40.com/20x-cohort/april-28-26<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.<br/>Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/19054422-fedramp-20x-and-the-future-of-compliance-with-gary-guercio.mp3" length="51906601" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19054422</guid>
    <pubDate>Wed, 29 Apr 2026 08:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19054422/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19054422/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19054422/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19054422/transcript.vtt" type="text/vtt" />
    <itunes:duration>4322</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>30</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>InfusionPoints Achieves FedRAMP 20x Moderate (Class C): What It Means for the Future</itunes:title>
    <title>InfusionPoints Achieves FedRAMP 20x Moderate (Class C): What It Means for the Future</title>
    <itunes:summary><![CDATA[In this special announcement episode of Behind the Shield, we’re sharing a major milestone for InfusionPoints and what it signals for the future of federal cloud security. Chad Spears and Tanner Bailey break down our FedRAMP 20x Moderate (Class C) achievement, what it took to get here, and why this moment matters for cloud service providers, agencies, and the broader FedRAMP ecosystem. This isn’t just another certification, it’s proof that the shift from point-in-time compliance to continuous...]]></itunes:summary>
    <description><![CDATA[<p>In this special announcement episode of Behind the Shield, we’re sharing a major milestone for InfusionPoints and what it signals for the future of federal cloud security.</p><p>Chad Spears and Tanner Bailey break down our FedRAMP 20x Moderate (Class C) achievement, what it took to get here, and why this moment matters for cloud service providers, agencies, and the broader FedRAMP ecosystem. This isn’t just another certification, it’s proof that the shift from point-in-time compliance to continuous validation is already happening.</p><p>We unpack how FedRAMP 20x is transforming how security is demonstrated, moving away from static documentation and toward real-time, machine-readable evidence through Key Security Indicators (KSIs). We also touch on the journey behind this achievement, from early automation efforts to navigating evolving PMO expectations.</p><p>You’ll hear how this approach changes the experience for providers and assessors, creating a more collaborative and efficient path to authorization. We also explore the business impact, including faster time to market and a clearer path for organizations entering the federal space.</p><p>Whether you&apos;re pursuing FedRAMP, evaluating 20x, or trying to understand where the program is headed, this episode offers practical insights and a clear view into what comes next.</p><p>Chapters:<br/>0:10 Introduction and Special Announcement<br/>0:45 Certification Achievement<br/>1:23 Significance of 20X Certification<br/>2:45 Customer Impact and FedRAMP Framework<br/>6:07 Understanding FedRAMP Designations<br/>11:48 Journey to 20X Certification<br/>18:30 Team Effort and Continuous Validation<br/>18:47 Customer Benefits of 20X Certification<br/>19:02 Platform as a Service and FedRAMP<br/>19:29 Security Controls and KSI&apos;s<br/>20:25 Speed to Market with XB40<br/>21:53 Webinar and Education Initiatives<br/>22:48 Upcoming Webinar Details<br/>26:22 Team Recognitions and Shoutouts<br/>30:57 Closing Remarks<br/><br/>What You’ll Learn:<br/>• What achieving FedRAMP 20x Moderate (Class C) actually means<br/>• Why this milestone is important for CSPs and federal agencies<br/>• How FedRAMP 20x is shifting compliance to continuous validation<br/>• The real business impact of faster authorization timelines<br/>• How automation and KSIs replace traditional audit processes<br/>• What makes this approach different from Rev. 5 assessments<br/>• How InfusionPoints approached the 20x journey internally<br/>• What this means for customers looking to enter the federal market<br/>• Why this proves the transition from Rev. 5 to 20x is possible<br/><br/>Resource Links:<br/>https://www.fedramp.gov/rfcs/<br/>FedRAMP 20x Community Update- https://youtu.be/eU0i6c3Yk8o?si=_kbfmhax8BD154Q7<br/><br/>InfusionPoints Links: <br/>https://xbu40.com/<br/>20x Quick Look Assessment- https://xbu40.com/assessment<br/>20x Webinar Series | Session 1- https://youtu.be/EoaXjGa-vl0?si=UmnDCXY4dhTKpC6L<br/>20x Webinar Series | Session 2 Registration- https://riverside.com/webinar/registration/eyJldmVudElkIjoiNjlkZDUzZmNiNWI5MjQ2YTllY2E0YmUwIiwic2x1ZyI6Imphc29uLXNocm9wc2hpcmVzLXN0dWRpbyJ9<br/>Chad Spears-https://www.linkedin.com/in/chad-spears007/<br/>Tanner Bailey- https://www.linkedin.com/in/tanner-b-37a50a132/<br/>https://www.linkedin.com/company/infusionpoints/<br/>https://infusionpoints.com/<br/><br/>About Us:<br/>InfusionPoints is a cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure environments in highly regulated markets.</p><p>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security, supporting customers from authorization through continuous monitoring.</p><p>With a security-first approach, we deliver scalable, compliant solutions that help organizations move faster without sacrificing security.</p>]]></description>
    <content:encoded><![CDATA[<p>In this special announcement episode of Behind the Shield, we’re sharing a major milestone for InfusionPoints and what it signals for the future of federal cloud security.</p><p>Chad Spears and Tanner Bailey break down our FedRAMP 20x Moderate (Class C) achievement, what it took to get here, and why this moment matters for cloud service providers, agencies, and the broader FedRAMP ecosystem. This isn’t just another certification, it’s proof that the shift from point-in-time compliance to continuous validation is already happening.</p><p>We unpack how FedRAMP 20x is transforming how security is demonstrated, moving away from static documentation and toward real-time, machine-readable evidence through Key Security Indicators (KSIs). We also touch on the journey behind this achievement, from early automation efforts to navigating evolving PMO expectations.</p><p>You’ll hear how this approach changes the experience for providers and assessors, creating a more collaborative and efficient path to authorization. We also explore the business impact, including faster time to market and a clearer path for organizations entering the federal space.</p><p>Whether you&apos;re pursuing FedRAMP, evaluating 20x, or trying to understand where the program is headed, this episode offers practical insights and a clear view into what comes next.</p><p>Chapters:<br/>0:10 Introduction and Special Announcement<br/>0:45 Certification Achievement<br/>1:23 Significance of 20X Certification<br/>2:45 Customer Impact and FedRAMP Framework<br/>6:07 Understanding FedRAMP Designations<br/>11:48 Journey to 20X Certification<br/>18:30 Team Effort and Continuous Validation<br/>18:47 Customer Benefits of 20X Certification<br/>19:02 Platform as a Service and FedRAMP<br/>19:29 Security Controls and KSI&apos;s<br/>20:25 Speed to Market with XB40<br/>21:53 Webinar and Education Initiatives<br/>22:48 Upcoming Webinar Details<br/>26:22 Team Recognitions and Shoutouts<br/>30:57 Closing Remarks<br/><br/>What You’ll Learn:<br/>• What achieving FedRAMP 20x Moderate (Class C) actually means<br/>• Why this milestone is important for CSPs and federal agencies<br/>• How FedRAMP 20x is shifting compliance to continuous validation<br/>• The real business impact of faster authorization timelines<br/>• How automation and KSIs replace traditional audit processes<br/>• What makes this approach different from Rev. 5 assessments<br/>• How InfusionPoints approached the 20x journey internally<br/>• What this means for customers looking to enter the federal market<br/>• Why this proves the transition from Rev. 5 to 20x is possible<br/><br/>Resource Links:<br/>https://www.fedramp.gov/rfcs/<br/>FedRAMP 20x Community Update- https://youtu.be/eU0i6c3Yk8o?si=_kbfmhax8BD154Q7<br/><br/>InfusionPoints Links: <br/>https://xbu40.com/<br/>20x Quick Look Assessment- https://xbu40.com/assessment<br/>20x Webinar Series | Session 1- https://youtu.be/EoaXjGa-vl0?si=UmnDCXY4dhTKpC6L<br/>20x Webinar Series | Session 2 Registration- https://riverside.com/webinar/registration/eyJldmVudElkIjoiNjlkZDUzZmNiNWI5MjQ2YTllY2E0YmUwIiwic2x1ZyI6Imphc29uLXNocm9wc2hpcmVzLXN0dWRpbyJ9<br/>Chad Spears-https://www.linkedin.com/in/chad-spears007/<br/>Tanner Bailey- https://www.linkedin.com/in/tanner-b-37a50a132/<br/>https://www.linkedin.com/company/infusionpoints/<br/>https://infusionpoints.com/<br/><br/>About Us:<br/>InfusionPoints is a cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure environments in highly regulated markets.</p><p>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security, supporting customers from authorization through continuous monitoring.</p><p>With a security-first approach, we deliver scalable, compliant solutions that help organizations move faster without sacrificing security.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/19021264-infusionpoints-achieves-fedramp-20x-moderate-class-c-what-it-means-for-the-future.mp3" length="25379933" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19021264</guid>
    <pubDate>Wed, 15 Apr 2026 12:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19021264/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19021264/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19021264/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19021264/transcript.vtt" type="text/vtt" />
    <itunes:duration>2112</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>29</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>From SQL Injection to Compliance Automation in Cybersecurity with Andrew Plato</itunes:title>
    <title>From SQL Injection to Compliance Automation in Cybersecurity with Andrew Plato</title>
    <itunes:summary><![CDATA[In this episode of Behind the Shield, Jason Shropshire sits down with cybersecurity founder, author, and industry veteran Andrew Plato for a candid, wide-ranging conversation on what it really takes to build and scale a cybersecurity company.  Andrew shares his journey from accidentally discovering one of the earliest SQL injection vulnerabilities in the 90s to founding and growing a cybersecurity company over 26 years and ultimately exiting after building a successful compliance automation p...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of Behind the Shield, Jason Shropshire sits down with cybersecurity founder, author, and industry veteran Andrew Plato for a candid, wide-ranging conversation on what it really takes to build and scale a cybersecurity company.<br/><br/>Andrew shares his journey from accidentally discovering one of the earliest SQL injection vulnerabilities in the 90s to founding and growing a cybersecurity company over 26 years and ultimately exiting after building a successful compliance automation platform. Along the way, he breaks down the hard-earned lessons that most founders learn the hard way, covering everything from business model pivots and scaling challenges to sales strategy and the evolution of compliance in cloud environments.<br/><br/>This episode goes beyond technical security talk and dives into the mindset shifts that separate successful companies from the rest. From why “compliance is miserable” and how automation changed the game, to why customers do not buy products but instead buy pain relief, Andrew offers unfiltered insights that apply to startups, established companies, and anyone navigating today’s cybersecurity landscape.<br/><br/>Whether you are a founder, operator, or part of a growing security team, this conversation will challenge how you think about building, selling, and delivering cybersecurity solutions in a rapidly evolving market.<br/><br/>Chapters:<br/>0:09 Introduction and Welcome<br/>0:59 Andrew&apos;s Early Career and SQL Injection Discovery<br/>3:01 Starting a Security Company<br/>5:44 Compliance Automation and AWS Collaboration<br/>10:49 Managed Security and Automation Insights<br/>33:15 The Founder&apos;s Dilemma and Business Growth<br/>52:31 Sales Strategies and Credibility Selling<br/>61:21 Closing Remarks<br/><br/>What You&apos;ll Learn: <br/>•  How one of the earliest SQL injection discoveries helped spark a cybersecurity career <br/>•  The reality of building and pivoting a company over decades <br/>•  Why compliance has historically been “miserable” and how automation is changing that <br/>•  The origin and evolution of compliance automation platforms <br/>•  Why moving customers into standardized environments accelerates security and scalability <br/>•  The shift from hourly consulting to scalable, subscription-based models <br/>•  Why customers do not buy products but instead buy pain relief <br/>•  How to position cybersecurity as removing business barriers, not adding them <br/>•  The concept of opportunity barriers and how compliance impacts revenue <br/>•  Why traditional sales approaches like cold calling and product pitching no longer work <br/>•  The importance of credibility over product features in modern cybersecurity sales <br/>•  How startups can compete against larger, established players <br/>•  The biggest mistakes founders make and how to avoid them <br/>•  Why understanding your customer’s pain is the foundation of growth <br/>•  How automation and AI are accelerating the future of security and compliance<br/><br/>Guest Links: <br/>Andrew Plato- https://www.linkedin.com/in/andrewplato/<br/>The Founder&apos;s User Manual (Book)- https://www.amazon.com/dp/B0CZXP7TNF/ref=tsm_1_fb_lk<br/>Company- https://zenaciti.com/<br/><br/>InfusionPoints Links: <br/>Jason Shropshire- https://www.linkedin.com/in/shrop/<br/>https://www.linkedin.com/company/infusionpoints/<br/>https://infusionpoints.com/<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every e</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of Behind the Shield, Jason Shropshire sits down with cybersecurity founder, author, and industry veteran Andrew Plato for a candid, wide-ranging conversation on what it really takes to build and scale a cybersecurity company.<br/><br/>Andrew shares his journey from accidentally discovering one of the earliest SQL injection vulnerabilities in the 90s to founding and growing a cybersecurity company over 26 years and ultimately exiting after building a successful compliance automation platform. Along the way, he breaks down the hard-earned lessons that most founders learn the hard way, covering everything from business model pivots and scaling challenges to sales strategy and the evolution of compliance in cloud environments.<br/><br/>This episode goes beyond technical security talk and dives into the mindset shifts that separate successful companies from the rest. From why “compliance is miserable” and how automation changed the game, to why customers do not buy products but instead buy pain relief, Andrew offers unfiltered insights that apply to startups, established companies, and anyone navigating today’s cybersecurity landscape.<br/><br/>Whether you are a founder, operator, or part of a growing security team, this conversation will challenge how you think about building, selling, and delivering cybersecurity solutions in a rapidly evolving market.<br/><br/>Chapters:<br/>0:09 Introduction and Welcome<br/>0:59 Andrew&apos;s Early Career and SQL Injection Discovery<br/>3:01 Starting a Security Company<br/>5:44 Compliance Automation and AWS Collaboration<br/>10:49 Managed Security and Automation Insights<br/>33:15 The Founder&apos;s Dilemma and Business Growth<br/>52:31 Sales Strategies and Credibility Selling<br/>61:21 Closing Remarks<br/><br/>What You&apos;ll Learn: <br/>•  How one of the earliest SQL injection discoveries helped spark a cybersecurity career <br/>•  The reality of building and pivoting a company over decades <br/>•  Why compliance has historically been “miserable” and how automation is changing that <br/>•  The origin and evolution of compliance automation platforms <br/>•  Why moving customers into standardized environments accelerates security and scalability <br/>•  The shift from hourly consulting to scalable, subscription-based models <br/>•  Why customers do not buy products but instead buy pain relief <br/>•  How to position cybersecurity as removing business barriers, not adding them <br/>•  The concept of opportunity barriers and how compliance impacts revenue <br/>•  Why traditional sales approaches like cold calling and product pitching no longer work <br/>•  The importance of credibility over product features in modern cybersecurity sales <br/>•  How startups can compete against larger, established players <br/>•  The biggest mistakes founders make and how to avoid them <br/>•  Why understanding your customer’s pain is the foundation of growth <br/>•  How automation and AI are accelerating the future of security and compliance<br/><br/>Guest Links: <br/>Andrew Plato- https://www.linkedin.com/in/andrewplato/<br/>The Founder&apos;s User Manual (Book)- https://www.amazon.com/dp/B0CZXP7TNF/ref=tsm_1_fb_lk<br/>Company- https://zenaciti.com/<br/><br/>InfusionPoints Links: <br/>Jason Shropshire- https://www.linkedin.com/in/shrop/<br/>https://www.linkedin.com/company/infusionpoints/<br/>https://infusionpoints.com/<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every e</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/19016684-from-sql-injection-to-compliance-automation-in-cybersecurity-with-andrew-plato.mp3" length="45179275" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19016684</guid>
    <pubDate>Tue, 14 Apr 2026 16:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19016684/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19016684/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19016684/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/19016684/transcript.vtt" type="text/vtt" />
    <itunes:duration>3762</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>28</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>From Monthly Scans to Continuous Monitoring: Mastering FedRAMP Vulnerability Management</itunes:title>
    <title>From Monthly Scans to Continuous Monitoring: Mastering FedRAMP Vulnerability Management</title>
    <itunes:summary><![CDATA[n this episode of Behind the Shield, hosted by Mike Strohecker, the Cloud Operations team at InfusionPoints dives into the realities of vulnerability management in FedRAMP environments.  Mike is joined by Ryan Adcock and James Bolton from the Cloud Operations team, where they support customers operating in FedRAMP High and IL5 environments. Together, they break down what it really takes to maintain compliance through continuous monitoring and why strong vulnerability management practices are ...]]></itunes:summary>
    <description><![CDATA[<p>n this episode of Behind the Shield, hosted by Mike Strohecker, the Cloud Operations team at InfusionPoints dives into the realities of vulnerability management in FedRAMP environments.<br/><br/>Mike is joined by Ryan Adcock and James Bolton from the Cloud Operations team, where they support customers operating in FedRAMP High and IL5 environments. Together, they break down what it really takes to maintain compliance through continuous monitoring and why strong vulnerability management practices are critical to keeping an authorization in place.<br/><br/>This conversation goes beyond high-level compliance talk and gets into the day-to-day execution. From running scans and managing vulnerabilities to maintaining accurate inventories and communicating with engineering teams, the group shares what actually happens behind the scenes to keep systems secure and compliant.<br/><br/>They also explore how vulnerability management is evolving. What used to be a monthly exercise is shifting into a continuous, always-on process. With the introduction of Vulnerability Detection and Response, organizations are expected to move faster, respond smarter, and understand their environments at a much deeper level.<br/><br/>If you are a Cloud Service Provider, security professional, or part of a team working toward or maintaining FedRAMP authorization, this episode provides practical insight into what works, what does not, and what is coming next.<br/><br/>Chapters:<br/>0:00 Introduction and Guest Backgrounds<br/>2:35 Vulnerability Management and Compliance<br/>5:24 Continuous Monitoring and Best Practices<br/>12:01 Understanding Customer Environments<br/>17:34 VADR and Continuous Monitoring<br/>23:03 Prevention and Security Improvements<br/>27:15 Communication and Closing Remarks<br/><br/>What You’ll Learn<br/><br/>• What continuous monitoring requires in a FedRAMP environment and how it impacts your daily operations<br/>• The different types of vulnerability scans including OS, database, container, and web application scans<br/>• How Plans of Action and Milestones are used to track and report vulnerabilities<br/>• Key remediation timelines and why meeting them is essential to maintaining authorization<br/>• Why authenticated scans are necessary and where many organizations struggle<br/>• Common challenges when scanning containers and web applications<br/>• The importance of maintaining an accurate asset inventory and avoiding blind spots<br/>• How communication between security and engineering teams improves remediation timelines<br/>• What changes are coming with Vulnerability Detection and Response and continuous scanning expectations<br/>• How automation and risk-based decision making are shaping the future of FedRAMP compliance<br/><br/>InfusionPoints Links:<br/>Mike Strohecker, VP of Engineering and Operations: https://www.linkedin.com/in/michael-strohecker-238326172/<br/>Ryan Adcock, Cloud Operations / Senior Consultant:<br/>https://www.linkedin.com/in/ryanaadcock/<br/>James Bolton,  Cloud Operations / Senior Consultant:<br/>https://www.linkedin.com/in/james-bolton-cyber/<br/>https://www.linkedin.com/company/infusionpoints/<br/>https://www.InfusionPoints.com<br/>https://infusionpoints.com/contact-us<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.<br/>Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.</p>]]></description>
    <content:encoded><![CDATA[<p>n this episode of Behind the Shield, hosted by Mike Strohecker, the Cloud Operations team at InfusionPoints dives into the realities of vulnerability management in FedRAMP environments.<br/><br/>Mike is joined by Ryan Adcock and James Bolton from the Cloud Operations team, where they support customers operating in FedRAMP High and IL5 environments. Together, they break down what it really takes to maintain compliance through continuous monitoring and why strong vulnerability management practices are critical to keeping an authorization in place.<br/><br/>This conversation goes beyond high-level compliance talk and gets into the day-to-day execution. From running scans and managing vulnerabilities to maintaining accurate inventories and communicating with engineering teams, the group shares what actually happens behind the scenes to keep systems secure and compliant.<br/><br/>They also explore how vulnerability management is evolving. What used to be a monthly exercise is shifting into a continuous, always-on process. With the introduction of Vulnerability Detection and Response, organizations are expected to move faster, respond smarter, and understand their environments at a much deeper level.<br/><br/>If you are a Cloud Service Provider, security professional, or part of a team working toward or maintaining FedRAMP authorization, this episode provides practical insight into what works, what does not, and what is coming next.<br/><br/>Chapters:<br/>0:00 Introduction and Guest Backgrounds<br/>2:35 Vulnerability Management and Compliance<br/>5:24 Continuous Monitoring and Best Practices<br/>12:01 Understanding Customer Environments<br/>17:34 VADR and Continuous Monitoring<br/>23:03 Prevention and Security Improvements<br/>27:15 Communication and Closing Remarks<br/><br/>What You’ll Learn<br/><br/>• What continuous monitoring requires in a FedRAMP environment and how it impacts your daily operations<br/>• The different types of vulnerability scans including OS, database, container, and web application scans<br/>• How Plans of Action and Milestones are used to track and report vulnerabilities<br/>• Key remediation timelines and why meeting them is essential to maintaining authorization<br/>• Why authenticated scans are necessary and where many organizations struggle<br/>• Common challenges when scanning containers and web applications<br/>• The importance of maintaining an accurate asset inventory and avoiding blind spots<br/>• How communication between security and engineering teams improves remediation timelines<br/>• What changes are coming with Vulnerability Detection and Response and continuous scanning expectations<br/>• How automation and risk-based decision making are shaping the future of FedRAMP compliance<br/><br/>InfusionPoints Links:<br/>Mike Strohecker, VP of Engineering and Operations: https://www.linkedin.com/in/michael-strohecker-238326172/<br/>Ryan Adcock, Cloud Operations / Senior Consultant:<br/>https://www.linkedin.com/in/ryanaadcock/<br/>James Bolton,  Cloud Operations / Senior Consultant:<br/>https://www.linkedin.com/in/james-bolton-cyber/<br/>https://www.linkedin.com/company/infusionpoints/<br/>https://www.InfusionPoints.com<br/>https://infusionpoints.com/contact-us<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.<br/>Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18979215-from-monthly-scans-to-continuous-monitoring-mastering-fedramp-vulnerability-management.mp3" length="22464674" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18979215</guid>
    <pubDate>Tue, 07 Apr 2026 17:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2541472/18979215/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/18979215/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/18979215/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/18979215/transcript.vtt" type="text/vtt" />
    <itunes:duration>1869</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>27</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>From Interns to SOC Analysts: Real Cybersecurity Careers Start Here</itunes:title>
    <title>From Interns to SOC Analysts: Real Cybersecurity Careers Start Here</title>
    <itunes:summary><![CDATA[In this episode of Behind the Shield, we continue our internship series with a real, behind-the-scenes look at what it’s actually like to start a career in cybersecurity.  Host Felisha Daemer sits down with Levi Church and Ben Collins, two former interns turned full-time Security Operations Analysts, to talk through their journeys from local students to working hands-on in a 24/7 SOC environment.  They share how they found InfusionPoints, what surprised them most stepping into a professional ...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of Behind the Shield, we continue our internship series with a real, behind-the-scenes look at what it’s actually like to start a career in cybersecurity.<br/><br/>Host Felisha Daemer sits down with Levi Church and Ben Collins, two former interns turned full-time Security Operations Analysts, to talk through their journeys from local students to working hands-on in a 24/7 SOC environment.<br/><br/>They share how they found InfusionPoints, what surprised them most stepping into a professional environment, and how quickly things shift from theory to real-world application.<br/><br/>From navigating “acronym soup” on day one to building real solutions during live incidents, including a response to the global CrowdStrike outage, this episode highlights just how impactful hands-on experience can be.<br/><br/>You’ll also hear how InfusionPoints’ rotational internship model exposes interns to multiple teams, including security operations, engineering, advisory, cloud ops, and even marketing, helping them find where they thrive.<br/><br/>And maybe most importantly, why culture, curiosity, and being willing to figure things out matter just as much as technical knowledge.<br/><br/>Whether you’re a student exploring cybersecurity, a hiring manager building an internship program, or just curious how talent actually develops in this space, this episode gives you an unfiltered look.<br/><br/>Chapters: <br/>0:10 Introduction<br/>0:31 Levi&apos;s Introduction<br/>1:23 Ben&apos;s Introduction<br/>2:12 Inspiration to Enter the Field<br/>3:40 Internship Experiences<br/>6:50 Advice for Future Interns<br/>8:23 Certifications and Learning<br/>10:24 Culture and Work Environment<br/>15:00 Projects and Achievements<br/>21:15 Fun Questions<br/><br/>What You’ll Learn:<br/>What it’s really like transitioning from cybersecurity theory to hands-on work in a SOC<br/>How internships can shape and sometimes completely change career paths<br/>The value of rotational vs. specialized internship experiences<br/>Why “culture shock” is normal and how to push through it<br/>How small teams create faster learning opportunities and require wearing multiple hats<br/>Building an automated emergency communication system during a major outage<br/>Streamlining internal SOC documentation for faster analyst onboarding<br/>Automating employee bio updates for operational efficiency<br/>Why certifications like AWS Cloud Practitioner, CySA+, and tools like CloudQuest can give you a head start<br/>The importance of continuous learning, curiosity, and problem-solving in cybersecurity<br/>How collaboration across teams (SOC, marketing, engineering, leadership) accelerates growth<br/>What makes a strong intern and what advice current analysts would give to future applicants<br/><br/>InfusionPoints Links: <br/>Apply to the Internship- https://infusionpoints.com/careers/InfusionPoints-Internship<br/>Felisha Daemer- https://www.linkedin.com/in/felisha-daemer/<br/>Levi Church- https://www.linkedin.com/in/levichurch/<br/>Ben Collins- https://www.linkedin.com/in/benjamincollins001/<br/>https://www.linkedin.com/company/infusionpoints/<br/>https://www.InfusionPoints.com<br/>https://infusionpoints.com/contact-us<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.<br/>Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of Behind the Shield, we continue our internship series with a real, behind-the-scenes look at what it’s actually like to start a career in cybersecurity.<br/><br/>Host Felisha Daemer sits down with Levi Church and Ben Collins, two former interns turned full-time Security Operations Analysts, to talk through their journeys from local students to working hands-on in a 24/7 SOC environment.<br/><br/>They share how they found InfusionPoints, what surprised them most stepping into a professional environment, and how quickly things shift from theory to real-world application.<br/><br/>From navigating “acronym soup” on day one to building real solutions during live incidents, including a response to the global CrowdStrike outage, this episode highlights just how impactful hands-on experience can be.<br/><br/>You’ll also hear how InfusionPoints’ rotational internship model exposes interns to multiple teams, including security operations, engineering, advisory, cloud ops, and even marketing, helping them find where they thrive.<br/><br/>And maybe most importantly, why culture, curiosity, and being willing to figure things out matter just as much as technical knowledge.<br/><br/>Whether you’re a student exploring cybersecurity, a hiring manager building an internship program, or just curious how talent actually develops in this space, this episode gives you an unfiltered look.<br/><br/>Chapters: <br/>0:10 Introduction<br/>0:31 Levi&apos;s Introduction<br/>1:23 Ben&apos;s Introduction<br/>2:12 Inspiration to Enter the Field<br/>3:40 Internship Experiences<br/>6:50 Advice for Future Interns<br/>8:23 Certifications and Learning<br/>10:24 Culture and Work Environment<br/>15:00 Projects and Achievements<br/>21:15 Fun Questions<br/><br/>What You’ll Learn:<br/>What it’s really like transitioning from cybersecurity theory to hands-on work in a SOC<br/>How internships can shape and sometimes completely change career paths<br/>The value of rotational vs. specialized internship experiences<br/>Why “culture shock” is normal and how to push through it<br/>How small teams create faster learning opportunities and require wearing multiple hats<br/>Building an automated emergency communication system during a major outage<br/>Streamlining internal SOC documentation for faster analyst onboarding<br/>Automating employee bio updates for operational efficiency<br/>Why certifications like AWS Cloud Practitioner, CySA+, and tools like CloudQuest can give you a head start<br/>The importance of continuous learning, curiosity, and problem-solving in cybersecurity<br/>How collaboration across teams (SOC, marketing, engineering, leadership) accelerates growth<br/>What makes a strong intern and what advice current analysts would give to future applicants<br/><br/>InfusionPoints Links: <br/>Apply to the Internship- https://infusionpoints.com/careers/InfusionPoints-Internship<br/>Felisha Daemer- https://www.linkedin.com/in/felisha-daemer/<br/>Levi Church- https://www.linkedin.com/in/levichurch/<br/>Ben Collins- https://www.linkedin.com/in/benjamincollins001/<br/>https://www.linkedin.com/company/infusionpoints/<br/>https://www.InfusionPoints.com<br/>https://infusionpoints.com/contact-us<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.<br/>Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18940435-from-interns-to-soc-analysts-real-cybersecurity-careers-start-here.mp3" length="18868513" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18940435</guid>
    <pubDate>Tue, 31 Mar 2026 15:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2541472/18940435/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/18940435/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/18940435/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/18940435/transcript.vtt" type="text/vtt" />
    <itunes:duration>1569</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>26</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>FedRAMP 20x Explained, CMMC Impact, and Real Compliance Talk with Matt Bruggeman</itunes:title>
    <title>FedRAMP 20x Explained, CMMC Impact, and Real Compliance Talk with Matt Bruggeman</title>
    <itunes:summary><![CDATA[In this episode of Behind the Shield, Jason Shropshire, InfusionPoints COO, sits down with Matt Bruggeman, Director of GTM Federal at A-LIGN, to explore one of the most unique career paths in the compliance space and how it directly shapes the way he approaches FedRAMP today. Starting in engineering, transitioning into improv comedy, and ultimately moving into sales engineering, Matt brings a perspective that blends technical depth with communication, adaptability, and real-world problem solv...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of Behind the Shield, Jason Shropshire, InfusionPoints COO, sits down with Matt Bruggeman, Director of GTM Federal at A-LIGN, to explore one of the most unique career paths in the compliance space and how it directly shapes the way he approaches FedRAMP today. Starting in engineering, transitioning into improv comedy, and ultimately moving into sales engineering, Matt brings a perspective that blends technical depth with communication, adaptability, and real-world problem solving.<br/><br/>We dive into the realities of FedRAMP, including the friction points that have challenged CSPs over the last several years, from inconsistent interpretations to long timelines and the operational burden of maintaining authorization. Matt shares firsthand insight into how these challenges have impacted both providers and assessors, and where the industry is starting to shift.<br/><br/>The conversation also unpacks FedRAMP 20x and what it actually means beyond the headlines. We talk about automation, machine-readable evidence, and what organizations need to start thinking about now if they want to keep pace with where the program is going. This isn’t just about moving faster, it’s about fundamentally changing how compliance is approached.<br/><br/>We also touch on CMMC and its growing influence across the defense ecosystem, how it compares to FedRAMP, and why organizations need to think strategically about overlapping requirements and long-term compliance investments.<br/><br/>Throughout the episode, Matt highlights the importance of clear communication, storytelling, and being able to translate complex technical requirements into something actionable, especially in a space that often leans too heavily on jargon and process.<br/><br/>Whether you&apos;re early in your FedRAMP journey, actively working toward authorization, or rethinking your approach in light of 20x, this episode offers practical insight, honest perspective, and a look at where compliance is headed next.<br/><br/>What You’ll Learn:<br/><br/>• Matt’s journey from engineering to improv and how it shaped his approach to problem-solving<br/>• The realities of FedRAMP challenges and why the process has been so difficult historically<br/>• How FedRAMP is evolving and what changes are underway<br/>• What FedRAMP 20x actually means and what it requires from organizations<br/>• The impact of CMMC on the broader compliance and defense ecosystem<br/>• Why communication, storytelling, and adaptability matter in technical roles<br/>• Key insights for navigating compliance in a rapidly changing environment<br/><br/>Chapters:<br/><br/>0:00 - Introduction to the Podcast<br/>0:29 - Meet Matt Bruggeman<br/>1:16 - Matt&apos;s Engineering Background<br/>2:13 - Transition to Improv Comedy<br/>4:04 - Sales Engineering Journey<br/>6:02 - Joining A-LIGN and FedRAMP<br/>11:01 - FedRAMP Challenges and Changes<br/>17:12 - CMMC and Industry Impact<br/>23:33 - FedRAMP 20X Discussion<br/>47:43 - Lighter Fare and Closing<br/><br/>If you’re building, managing, or defending in regulated environments, make sure to subscribe for more conversations like this.<br/>Interested in learning more about FedRAMP 20x? Join our FedRAMP 20x Explained webinar on April 2nd at 1 PM EST: https://xbu40.com/20x-cohort <br/><br/>Guest Links: <br/>Matt Bruggeman Linkedin: https://www.linkedin.com/in/matt-bruggeman/<br/>A-LIGN- https://www.a-lign.com/<br/>Mostly Compliant Podcast- https://www.youtube.com/playlist?list=PLLU5Lb_V9iSyFhftOkbrOE_y0DVAvDmO4<br/>Sooper Doods- https://www.youtube.com/@SooperDoods<br/><br/>InfusionPoints Links: <br/>Jason Shropshire, COO- https://www.linkedin.com/in/shrop/<br/>https://www.linkedin.com/company/infusionpoints/<br/>https://www.InfusionPoints.com<br/>https://infusionpoints.com/contact-us</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of Behind the Shield, Jason Shropshire, InfusionPoints COO, sits down with Matt Bruggeman, Director of GTM Federal at A-LIGN, to explore one of the most unique career paths in the compliance space and how it directly shapes the way he approaches FedRAMP today. Starting in engineering, transitioning into improv comedy, and ultimately moving into sales engineering, Matt brings a perspective that blends technical depth with communication, adaptability, and real-world problem solving.<br/><br/>We dive into the realities of FedRAMP, including the friction points that have challenged CSPs over the last several years, from inconsistent interpretations to long timelines and the operational burden of maintaining authorization. Matt shares firsthand insight into how these challenges have impacted both providers and assessors, and where the industry is starting to shift.<br/><br/>The conversation also unpacks FedRAMP 20x and what it actually means beyond the headlines. We talk about automation, machine-readable evidence, and what organizations need to start thinking about now if they want to keep pace with where the program is going. This isn’t just about moving faster, it’s about fundamentally changing how compliance is approached.<br/><br/>We also touch on CMMC and its growing influence across the defense ecosystem, how it compares to FedRAMP, and why organizations need to think strategically about overlapping requirements and long-term compliance investments.<br/><br/>Throughout the episode, Matt highlights the importance of clear communication, storytelling, and being able to translate complex technical requirements into something actionable, especially in a space that often leans too heavily on jargon and process.<br/><br/>Whether you&apos;re early in your FedRAMP journey, actively working toward authorization, or rethinking your approach in light of 20x, this episode offers practical insight, honest perspective, and a look at where compliance is headed next.<br/><br/>What You’ll Learn:<br/><br/>• Matt’s journey from engineering to improv and how it shaped his approach to problem-solving<br/>• The realities of FedRAMP challenges and why the process has been so difficult historically<br/>• How FedRAMP is evolving and what changes are underway<br/>• What FedRAMP 20x actually means and what it requires from organizations<br/>• The impact of CMMC on the broader compliance and defense ecosystem<br/>• Why communication, storytelling, and adaptability matter in technical roles<br/>• Key insights for navigating compliance in a rapidly changing environment<br/><br/>Chapters:<br/><br/>0:00 - Introduction to the Podcast<br/>0:29 - Meet Matt Bruggeman<br/>1:16 - Matt&apos;s Engineering Background<br/>2:13 - Transition to Improv Comedy<br/>4:04 - Sales Engineering Journey<br/>6:02 - Joining A-LIGN and FedRAMP<br/>11:01 - FedRAMP Challenges and Changes<br/>17:12 - CMMC and Industry Impact<br/>23:33 - FedRAMP 20X Discussion<br/>47:43 - Lighter Fare and Closing<br/><br/>If you’re building, managing, or defending in regulated environments, make sure to subscribe for more conversations like this.<br/>Interested in learning more about FedRAMP 20x? Join our FedRAMP 20x Explained webinar on April 2nd at 1 PM EST: https://xbu40.com/20x-cohort <br/><br/>Guest Links: <br/>Matt Bruggeman Linkedin: https://www.linkedin.com/in/matt-bruggeman/<br/>A-LIGN- https://www.a-lign.com/<br/>Mostly Compliant Podcast- https://www.youtube.com/playlist?list=PLLU5Lb_V9iSyFhftOkbrOE_y0DVAvDmO4<br/>Sooper Doods- https://www.youtube.com/@SooperDoods<br/><br/>InfusionPoints Links: <br/>Jason Shropshire, COO- https://www.linkedin.com/in/shrop/<br/>https://www.linkedin.com/company/infusionpoints/<br/>https://www.InfusionPoints.com<br/>https://infusionpoints.com/contact-us</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18902515-fedramp-20x-explained-cmmc-impact-and-real-compliance-talk-with-matt-bruggeman.mp3" length="41490057" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18902515</guid>
    <pubDate>Tue, 24 Mar 2026 16:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2541472/18902515/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/18902515/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/18902515/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/18902515/transcript.vtt" type="text/vtt" />
    <itunes:duration>3454</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>25</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Inside the InfusionPoints Internship Program with Rachael &amp; Aidan</itunes:title>
    <title>Inside the InfusionPoints Internship Program with Rachael &amp; Aidan</title>
    <itunes:summary><![CDATA[What does an internship at InfusionPoints actually look like, and what can it lead to?  In this episode of Behind the Shield, Tanner Bailey sits down with former interns Rachael Smith and Aidan Fratcher, who are now full-time members of the InfusionPoints team, to talk about their journey from students to professionals in cybersecurity, compliance, and cloud.  They share how they first connected with InfusionPoints, what made the internship experience stand out, and what it was like to move t...]]></itunes:summary>
    <description><![CDATA[<p>What does an internship at InfusionPoints actually look like, and what can it lead to?<br/><br/>In this episode of Behind the Shield, Tanner Bailey sits down with former interns Rachael Smith and Aidan Fratcher, who are now full-time members of the InfusionPoints team, to talk about their journey from students to professionals in cybersecurity, compliance, and cloud.<br/><br/>They share how they first connected with InfusionPoints, what made the internship experience stand out, and what it was like to move through the rotational internship program across multiple teams. From shadowing engineers and SOC analysts to learning cloud operations and advisory work, this conversation gives an inside look at how interns gain real exposure to the business, technology, and culture behind the work.<br/><br/>Rachael and Aidan also discuss the projects their internship cohorts completed, including real-world automation concepts inspired by operational needs, and reflect on how those experiences helped shape their careers. The episode also dives into advice for students, career changers, and future interns on staying curious, continuing to learn, using AI tools wisely, and standing out in a fast-changing industry.<br/><br/>Whether you are exploring cybersecurity careers, interested in the InfusionPoints internship program, or just want a candid look at how early career talent can grow into impactful team members, this episode is packed with helpful perspective.<br/><br/>Chapters: <br/><br/>00:08 Welcome and Episode Overview<br/>00:37 Interns&apos; Backgrounds and Interests<br/>02:54 Application Process and Networking Tips<br/>05:26 Infusion Points&apos; Culture and Learning Focus<br/>08:21 Day in the Life of an Intern<br/>09:58 Rotational Program and Team Exposure<br/>12:34 Real-World Projects and Automation Solutions<br/>18:30 Cross-Department Collaboration and Crisis Handling<br/>33:31 Advice for Aspiring Cybersecurity Professionals<br/>42:52 Fun Questions and Closing Thoughts<br/><br/>What You&apos;ll Learn:<br/><br/>• How Rachael and Aidan found the InfusionPoints internship program<br/>• What the application and interview process was like<br/>• What a day in the life of an InfusionPoints intern looks like<br/>• How the rotational program exposes interns to engineering, cloud operations, advisory, and security operations<br/>• Real internship project examples and how they created value for the company<br/>• Why culture, curiosity, and initiative matter in cybersecurity careers<br/>• Advice for students and early career professionals entering the field<br/>• A few fun closing questions, including favorite snacks, movies, and shows<br/><br/>InfusionPoints Links: <br/>https://infusionpoints.com/careers/InfusionPoints-Internship<br/>Tanner Bailey, Senior Consultant: https://www.linkedin.com/in/tanner-b-37a50a132/<br/>Rachael Smith, Consultant: https://www.linkedin.com/in/rachael-n-smith/<br/>Aidan Fratcher, Consultant: https://www.linkedin.com/in/aidanfratcher/<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.<br/>Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.</p>]]></description>
    <content:encoded><![CDATA[<p>What does an internship at InfusionPoints actually look like, and what can it lead to?<br/><br/>In this episode of Behind the Shield, Tanner Bailey sits down with former interns Rachael Smith and Aidan Fratcher, who are now full-time members of the InfusionPoints team, to talk about their journey from students to professionals in cybersecurity, compliance, and cloud.<br/><br/>They share how they first connected with InfusionPoints, what made the internship experience stand out, and what it was like to move through the rotational internship program across multiple teams. From shadowing engineers and SOC analysts to learning cloud operations and advisory work, this conversation gives an inside look at how interns gain real exposure to the business, technology, and culture behind the work.<br/><br/>Rachael and Aidan also discuss the projects their internship cohorts completed, including real-world automation concepts inspired by operational needs, and reflect on how those experiences helped shape their careers. The episode also dives into advice for students, career changers, and future interns on staying curious, continuing to learn, using AI tools wisely, and standing out in a fast-changing industry.<br/><br/>Whether you are exploring cybersecurity careers, interested in the InfusionPoints internship program, or just want a candid look at how early career talent can grow into impactful team members, this episode is packed with helpful perspective.<br/><br/>Chapters: <br/><br/>00:08 Welcome and Episode Overview<br/>00:37 Interns&apos; Backgrounds and Interests<br/>02:54 Application Process and Networking Tips<br/>05:26 Infusion Points&apos; Culture and Learning Focus<br/>08:21 Day in the Life of an Intern<br/>09:58 Rotational Program and Team Exposure<br/>12:34 Real-World Projects and Automation Solutions<br/>18:30 Cross-Department Collaboration and Crisis Handling<br/>33:31 Advice for Aspiring Cybersecurity Professionals<br/>42:52 Fun Questions and Closing Thoughts<br/><br/>What You&apos;ll Learn:<br/><br/>• How Rachael and Aidan found the InfusionPoints internship program<br/>• What the application and interview process was like<br/>• What a day in the life of an InfusionPoints intern looks like<br/>• How the rotational program exposes interns to engineering, cloud operations, advisory, and security operations<br/>• Real internship project examples and how they created value for the company<br/>• Why culture, curiosity, and initiative matter in cybersecurity careers<br/>• Advice for students and early career professionals entering the field<br/>• A few fun closing questions, including favorite snacks, movies, and shows<br/><br/>InfusionPoints Links: <br/>https://infusionpoints.com/careers/InfusionPoints-Internship<br/>Tanner Bailey, Senior Consultant: https://www.linkedin.com/in/tanner-b-37a50a132/<br/>Rachael Smith, Consultant: https://www.linkedin.com/in/rachael-n-smith/<br/>Aidan Fratcher, Consultant: https://www.linkedin.com/in/aidanfratcher/<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.<br/>Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18863712-inside-the-infusionpoints-internship-program-with-rachael-aidan.mp3" length="34266439" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18863712</guid>
    <pubDate>Tue, 17 Mar 2026 16:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2541472/18863712/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/18863712/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/18863712/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/18863712/transcript.vtt" type="text/vtt" />
    <itunes:duration>2852</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>24</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>FedRAMP 20x Public Notices: What CSPs and Assessors Need to Know</itunes:title>
    <title>FedRAMP 20x Public Notices: What CSPs and Assessors Need to Know</title>
    <itunes:summary><![CDATA[FedRAMP modernization is moving quickly, and one of the newest developments is the introduction of FedRAMP Public Notices. In this episode of Behind the Shield, the team explains what these notices are, why the FedRAMP PMO created them, and what they reveal about the future direction of FedRAMP 20x. Public Notices serve as a formal communication channel that provides transparency and a chronological record of key program updates. Instead of relying on blogs or scattered announcements, the Fed...]]></itunes:summary>
    <description><![CDATA[<p>FedRAMP modernization is moving quickly, and one of the newest developments is the introduction of FedRAMP Public Notices. In this episode of Behind the Shield, the team explains what these notices are, why the FedRAMP PMO created them, and what they reveal about the future direction of FedRAMP 20x.</p><p>Public Notices serve as a formal communication channel that provides transparency and a chronological record of key program updates. Instead of relying on blogs or scattered announcements, the FedRAMP Public Notices page offers a centralized place where industry stakeholders can track developments, including outcomes from Requests for Comment (RFCs), operational updates, and emergency directives.</p><p>During the conversation, the team walks through the first seven FedRAMP Public Notices and discusses what they mean for Cloud Service Providers (CSPs), assessors, and advisors navigating the evolving FedRAMP ecosystem. They highlight outcomes from recent RFCs, including updates to authorization terminology, changes to the FedRAMP Marketplace, and how the program is responding to industry feedback.</p><p>The episode also explores operational updates such as quarterly security inbox testing requirements and the role of emergency directives that may require CSPs to respond quickly to vulnerabilities.</p><p>The conversation also touches on the broader FedRAMP 20x modernization effort, including the push toward automation, machine-readable evidence, and reducing barriers to entry for cloud providers supporting federal customers.</p><p>Chapters:<br/>00:08 Understanding FedRAMP Notices and Their Importance<br/>03:09 Navigating FedRAMP Notices<br/>05:55 Understanding Security Assessments<br/>08:12 Changes in Authorization Designations<br/>10:59 Marketplace Updates and CSP Pathways<br/>13:50 Emergency Directives and Testing Procedures<br/>17:24 Leveraging External Frameworks for Certification<br/>28:35 Conclusion and Future Outlook<br/>30:09 Update: RFC-0023 Notice added<br/>34:14 Alternate Intro Outtake<br/><br/><br/>What You’ll Learn:<br/><br/>• What FedRAMP Public Notices are and why the FedRAMP PMO introduced them<br/>• Key updates and initial outcomes from RFC 19, RFC 20, RFC 21, and RFC 22<br/>• The shift toward FedRAMP Certified designations and new class-based certification levels (A–D)<br/>• New security inbox monitoring and quarterly testing expectations for Cloud Service Providers (CSPs)<br/>• How FedRAMP may begin leveraging external frameworks like SOC 2 Type II<br/>• What these changes signal about the future direction of FedRAMP 20x and cloud authorization modernization<br/><br/>Links to visit: <br/>https://www.fedramp.gov/notices/<br/><br/>InfusionPoints Links: <br/><br/>Jason Shropshire, COO- https://www.linkedin.com/in/shrop/<br/>Mike Strohecker, VP of Engineering and Operations: https://www.linkedin.com/in/michael-strohecker-238326172/<br/>Tanner Bailey, Senior Consultant/FedRAMP 20x Lead: https://www.linkedin.com/in/tanner-b-37a50a132/<br/><br/>https://www.linkedin.com/company/infusionpoints/<br/>https://www.InfusionPoints.com<br/>https://infusionpoints.com/contact-us<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.<br/>Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.</p>]]></description>
    <content:encoded><![CDATA[<p>FedRAMP modernization is moving quickly, and one of the newest developments is the introduction of FedRAMP Public Notices. In this episode of Behind the Shield, the team explains what these notices are, why the FedRAMP PMO created them, and what they reveal about the future direction of FedRAMP 20x.</p><p>Public Notices serve as a formal communication channel that provides transparency and a chronological record of key program updates. Instead of relying on blogs or scattered announcements, the FedRAMP Public Notices page offers a centralized place where industry stakeholders can track developments, including outcomes from Requests for Comment (RFCs), operational updates, and emergency directives.</p><p>During the conversation, the team walks through the first seven FedRAMP Public Notices and discusses what they mean for Cloud Service Providers (CSPs), assessors, and advisors navigating the evolving FedRAMP ecosystem. They highlight outcomes from recent RFCs, including updates to authorization terminology, changes to the FedRAMP Marketplace, and how the program is responding to industry feedback.</p><p>The episode also explores operational updates such as quarterly security inbox testing requirements and the role of emergency directives that may require CSPs to respond quickly to vulnerabilities.</p><p>The conversation also touches on the broader FedRAMP 20x modernization effort, including the push toward automation, machine-readable evidence, and reducing barriers to entry for cloud providers supporting federal customers.</p><p>Chapters:<br/>00:08 Understanding FedRAMP Notices and Their Importance<br/>03:09 Navigating FedRAMP Notices<br/>05:55 Understanding Security Assessments<br/>08:12 Changes in Authorization Designations<br/>10:59 Marketplace Updates and CSP Pathways<br/>13:50 Emergency Directives and Testing Procedures<br/>17:24 Leveraging External Frameworks for Certification<br/>28:35 Conclusion and Future Outlook<br/>30:09 Update: RFC-0023 Notice added<br/>34:14 Alternate Intro Outtake<br/><br/><br/>What You’ll Learn:<br/><br/>• What FedRAMP Public Notices are and why the FedRAMP PMO introduced them<br/>• Key updates and initial outcomes from RFC 19, RFC 20, RFC 21, and RFC 22<br/>• The shift toward FedRAMP Certified designations and new class-based certification levels (A–D)<br/>• New security inbox monitoring and quarterly testing expectations for Cloud Service Providers (CSPs)<br/>• How FedRAMP may begin leveraging external frameworks like SOC 2 Type II<br/>• What these changes signal about the future direction of FedRAMP 20x and cloud authorization modernization<br/><br/>Links to visit: <br/>https://www.fedramp.gov/notices/<br/><br/>InfusionPoints Links: <br/><br/>Jason Shropshire, COO- https://www.linkedin.com/in/shrop/<br/>Mike Strohecker, VP of Engineering and Operations: https://www.linkedin.com/in/michael-strohecker-238326172/<br/>Tanner Bailey, Senior Consultant/FedRAMP 20x Lead: https://www.linkedin.com/in/tanner-b-37a50a132/<br/><br/>https://www.linkedin.com/company/infusionpoints/<br/>https://www.InfusionPoints.com<br/>https://infusionpoints.com/contact-us<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.<br/>Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18824395-fedramp-20x-public-notices-what-csps-and-assessors-need-to-know.mp3" length="25592739" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18824395</guid>
    <pubDate>Tue, 10 Mar 2026 15:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2541472/18824395/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/18824395/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/18824395/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2541472/18824395/transcript.vtt" type="text/vtt" />
    <itunes:duration>2130</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>23</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Winning Government Work Without the Overwhelm with Nick Bernardo</itunes:title>
    <title>Winning Government Work Without the Overwhelm with Nick Bernardo</title>
    <itunes:summary><![CDATA[Government contracting can feel overwhelming, with complex regulations, countless tools, and uncertainty about where to begin. In this episode of Behind the Shield, host Felisha Daemer is joined by Jeff Bivens of InfusionPoints and Nick Bernardo, President of MyGovWatch.com, to explore how businesses can enter and succeed in the government marketplace without overcomplicating the process. Nick shares how MyGovWatch bridges the gap between low-cost but ineffective lead tools and expensive ente...]]></itunes:summary>
    <description><![CDATA[<p>Government contracting can feel overwhelming, with complex regulations, countless tools, and uncertainty about where to begin. In this episode of Behind the Shield, host Felisha Daemer is joined by Jeff Bivens of InfusionPoints and Nick Bernardo, President of MyGovWatch.com, to explore how businesses can enter and succeed in the government marketplace without overcomplicating the process.</p><p>Nick shares how MyGovWatch bridges the gap between low-cost but ineffective lead tools and expensive enterprise platforms, helping organizations identify the right opportunities without unnecessary complexity. The conversation covers how contracting works across federal, state, and local levels, how to build sustainable pipelines, and why reverse engineering your business development strategy is key.</p><p>They also discuss the real value of AI in opportunity matching, how subcontracting opens doors for new entrants, and common myths that hold companies back. Whether contracts are your primary focus or a supplemental revenue stream, this episode offers practical guidance to help you pursue opportunities strategically and confidently.</p><p>Chapters:<br/>[0:00] Introduction and Guest Introduction<br/>[0:26] How We Met and Introduction to MyGovWatch<br/>[1:42] The Goldilocks Analogy and Target Users<br/>[3:42] Comparison with Competitors and Bid Notification<br/>[6:08] Customer Success Story<br/>[7:44] Advice for Contractors<br/>[10:12] GovWatch Coverage and AI Utilization<br/>[16:16] Government Contracting Lifecycle<br/>[20:08] Subcontracting Opportunities<br/>[25:11] Common Myths in Government Contracting<br/>[28:54] Fun Questions and Closing Remarks<br/><br/><br/>What You’ll Learn:<br/><br/>• How to identify the right government opportunities without expensive enterprise tools<br/>• Why reverse engineering your BD strategy saves time and resources<br/>• The difference between federal, state, and local contracting pipelines<br/>• When subcontracting is a smarter entry point than prime contracting<br/>• How AI and smart data curation improve opportunity matching<br/>• Common government contracting myths and what is actually true<br/>• Ways to build relationships and position your company before an RFP is released<br/>• How open records requests can reveal teaming and subcontracting opportunities<br/>• Practical advice for companies adding government work as a supplemental revenue stream<br/><br/>Book Recommendations: <br/>The Millionaire Next Door -  Thomas J. Stanley, Ph.D. and William D. Danko, Ph.D.<br/>The First 90 Days - Michael D. Watkins<br/>The Grit Factor: Courage, Resilience, and Leadership in the Most Male-Dominated Organization in the World - Shannon Huffman Polson <br/>Lean In: Women, Work, and the Will to Lead -  Sheryl Sandberg<br/><br/>Guest Links: <br/>Nick Bernardo: https://www.linkedin.com/in/nickthegovconguy/<br/>https://www.mygovwatch.com/<br/><br/>InfusionPoints Links: <br/>Felisha Daemer: https://www.linkedin.com/in/felisha-daemer/<br/>Jeff Bivens: https://www.linkedin.com/in/jeffbivens/<br/>https://www.linkedin.com/company/infusionpoints/<br/>https://www.InfusionPoints.com<br/>https://infusionpoints.com/contact-us<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.<br/>Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.</p>]]></description>
    <content:encoded><![CDATA[<p>Government contracting can feel overwhelming, with complex regulations, countless tools, and uncertainty about where to begin. In this episode of Behind the Shield, host Felisha Daemer is joined by Jeff Bivens of InfusionPoints and Nick Bernardo, President of MyGovWatch.com, to explore how businesses can enter and succeed in the government marketplace without overcomplicating the process.</p><p>Nick shares how MyGovWatch bridges the gap between low-cost but ineffective lead tools and expensive enterprise platforms, helping organizations identify the right opportunities without unnecessary complexity. The conversation covers how contracting works across federal, state, and local levels, how to build sustainable pipelines, and why reverse engineering your business development strategy is key.</p><p>They also discuss the real value of AI in opportunity matching, how subcontracting opens doors for new entrants, and common myths that hold companies back. Whether contracts are your primary focus or a supplemental revenue stream, this episode offers practical guidance to help you pursue opportunities strategically and confidently.</p><p>Chapters:<br/>[0:00] Introduction and Guest Introduction<br/>[0:26] How We Met and Introduction to MyGovWatch<br/>[1:42] The Goldilocks Analogy and Target Users<br/>[3:42] Comparison with Competitors and Bid Notification<br/>[6:08] Customer Success Story<br/>[7:44] Advice for Contractors<br/>[10:12] GovWatch Coverage and AI Utilization<br/>[16:16] Government Contracting Lifecycle<br/>[20:08] Subcontracting Opportunities<br/>[25:11] Common Myths in Government Contracting<br/>[28:54] Fun Questions and Closing Remarks<br/><br/><br/>What You’ll Learn:<br/><br/>• How to identify the right government opportunities without expensive enterprise tools<br/>• Why reverse engineering your BD strategy saves time and resources<br/>• The difference between federal, state, and local contracting pipelines<br/>• When subcontracting is a smarter entry point than prime contracting<br/>• How AI and smart data curation improve opportunity matching<br/>• Common government contracting myths and what is actually true<br/>• Ways to build relationships and position your company before an RFP is released<br/>• How open records requests can reveal teaming and subcontracting opportunities<br/>• Practical advice for companies adding government work as a supplemental revenue stream<br/><br/>Book Recommendations: <br/>The Millionaire Next Door -  Thomas J. Stanley, Ph.D. and William D. Danko, Ph.D.<br/>The First 90 Days - Michael D. Watkins<br/>The Grit Factor: Courage, Resilience, and Leadership in the Most Male-Dominated Organization in the World - Shannon Huffman Polson <br/>Lean In: Women, Work, and the Will to Lead -  Sheryl Sandberg<br/><br/>Guest Links: <br/>Nick Bernardo: https://www.linkedin.com/in/nickthegovconguy/<br/>https://www.mygovwatch.com/<br/><br/>InfusionPoints Links: <br/>Felisha Daemer: https://www.linkedin.com/in/felisha-daemer/<br/>Jeff Bivens: https://www.linkedin.com/in/jeffbivens/<br/>https://www.linkedin.com/company/infusionpoints/<br/>https://www.InfusionPoints.com<br/>https://infusionpoints.com/contact-us<br/><br/>About Us:<br/>InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.<br/>We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.<br/>Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18783722-winning-government-work-without-the-overwhelm-with-nick-bernardo.mp3" length="24606878" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18783722</guid>
    <pubDate>Tue, 03 Mar 2026 14:00:00 -0500</pubDate>
    <itunes:duration>2047</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>22</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Protecting Community Colleges from Cyber Threats with Michael Wingler, CIO- Wilkes Community College</itunes:title>
    <title>Protecting Community Colleges from Cyber Threats with Michael Wingler, CIO- Wilkes Community College</title>
    <itunes:summary><![CDATA[In this episode of Behind the Shield, Chad Spears (Director of Security Operations at InfusionPoints) sits down with Michael Wingler, VP of IT &amp; Operations / CIO at Wilkes Community College, to talk about a reality more schools are facing: community colleges are targets now.  Michael shares what’s changed in the threat landscape, why attacks love nights, weekends, and holidays, and how limited budgets and staffing make higher-ed security uniquely challenging. They dig into real-world less...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of Behind the Shield, Chad Spears (Director of Security Operations at InfusionPoints) sits down with Michael Wingler, VP of IT &amp; Operations / CIO at Wilkes Community College, to talk about a reality more schools are facing: community colleges are targets now.<br/><br/>Michael shares what’s changed in the threat landscape, why attacks love nights, weekends, and holidays, and how limited budgets and staffing make higher-ed security uniquely challenging. They dig into real-world lessons learned from close calls, vendor/partner risk, and why you can’t rely on “8–5 security” when threat actors work 24/7.<br/><br/>You’ll also hear what’s working: building a strategic IT program that earns a seat at the leadership table, leveraging security awareness training (including measurable phishing-rate improvements), and partnering locally for 24/7 monitoring and response.<br/><br/>If you work in higher ed, SLED, or IT/security leadership, this one hits home.<br/><br/>🔔 Subscribe for more conversations on cybersecurity, leadership, and real-world security operations.<br/><br/>Links / resources<br/><br/>InfusionPoints: www.InfusionPoints.com<br/><br/>Wilkes Community College: www.WilkesCC.edu<br/><br/>#Cybersecurity #HigherEd #HigherEdIT #SLED #ITLeadership #SecurityAwareness #Phishing #SOC #MDR #BehindTheShield #InfusionPoints #WilkesCommunityCollege</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of Behind the Shield, Chad Spears (Director of Security Operations at InfusionPoints) sits down with Michael Wingler, VP of IT &amp; Operations / CIO at Wilkes Community College, to talk about a reality more schools are facing: community colleges are targets now.<br/><br/>Michael shares what’s changed in the threat landscape, why attacks love nights, weekends, and holidays, and how limited budgets and staffing make higher-ed security uniquely challenging. They dig into real-world lessons learned from close calls, vendor/partner risk, and why you can’t rely on “8–5 security” when threat actors work 24/7.<br/><br/>You’ll also hear what’s working: building a strategic IT program that earns a seat at the leadership table, leveraging security awareness training (including measurable phishing-rate improvements), and partnering locally for 24/7 monitoring and response.<br/><br/>If you work in higher ed, SLED, or IT/security leadership, this one hits home.<br/><br/>🔔 Subscribe for more conversations on cybersecurity, leadership, and real-world security operations.<br/><br/>Links / resources<br/><br/>InfusionPoints: www.InfusionPoints.com<br/><br/>Wilkes Community College: www.WilkesCC.edu<br/><br/>#Cybersecurity #HigherEd #HigherEdIT #SLED #ITLeadership #SecurityAwareness #Phishing #SOC #MDR #BehindTheShield #InfusionPoints #WilkesCommunityCollege</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18741980-protecting-community-colleges-from-cyber-threats-with-michael-wingler-cio-wilkes-community-college.mp3" length="46156716" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18741980</guid>
    <pubDate>Tue, 24 Feb 2026 15:00:00 -0500</pubDate>
    <itunes:duration>3843</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>21</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Inside InfusionPoints Development: Command Center, FedRAMP 20x &amp; Hackathon Builds</itunes:title>
    <title>Inside InfusionPoints Development: Command Center, FedRAMP 20x &amp; Hackathon Builds</title>
    <itunes:summary><![CDATA[Go Behind the Shield with a special 3-segment episode, hosted by Jason Shropshire, featuring members of the InfusionPoints engineering team as they break down what they’re building, how they’re building it, and the lessons learned along the way. Recorded after hours during Hackathon week, this one’s a little less buttoned-up in the best way. Expect real talk, real lessons, and a few laughs as the engineers unwind.  Segment 1: Meet Chris Eaves and Gavin Blankenship from R&amp;D as they share h...]]></itunes:summary>
    <description><![CDATA[<p>Go Behind the Shield with a special 3-segment episode, hosted by Jason Shropshire, featuring members of the InfusionPoints engineering team as they break down what they’re building, how they’re building it, and the lessons learned along the way. Recorded after hours during Hackathon week, this one’s a little less buttoned-up in the best way. Expect real talk, real lessons, and a few laughs as the engineers unwind.<br/><br/>Segment 1: Meet Chris Eaves and Gavin Blankenship from R&amp;D as they share how they found InfusionPoints, what it’s like building in a “jack-of-all-trades” environment, and how Command Center became a purpose-built, opinionated GRC platform designed to make complex compliance (FedRAMP, DoD, and more)- manageable without relying on someone else’s roadmap.<br/>They also talk roadmap highlights like automated user onboarding, incident response tracking, and a behind-the-scenes look at building a deployment pipeline to scale Command Center across environments.<br/><br/>Segment 2: Kay and Mike Strohecker join to talk life on the dev team, what Kay’s working on now (vulnerability + asset management), and what it’s like ramping up in the world of acronym soup—especially in the era of FedRAMP 20x. Plus: Hackathon reality check (no sleeping bags required).<br/><br/>Segment 3: Caleb Brinkley (backend) and Matthew Melang (frontend) share what they focus on day-to-day in Command Center, how cross-functional hackathon teams spark better ideas, and how automation (including tools like Power Automate + Teams workflows) can eliminate repetitive work across the business.<br/><br/>And yes… there’s a legendary story about AWS Bedrock, throttling, and an accidental “stress test” you don’t want to recreate.<br/><br/>🎧 Topics covered:<br/><br/>Command Center as a “one pane of glass” for compliance + security operations<br/><br/>FedRAMP 20x and the growing importance of KSIs<br/><br/>Continuous monitoring automation + customer feedback loops<br/><br/>Infrastructure + serverless architecture (Python, AWS services, Terraform)<br/><br/>Hackathon builds: onboarding automation, back-office workflows, and more<br/><br/>Lightning round essentials: dark mode, tabs vs spaces, and dev playlists<br/><br/>👍 Like, subscribe, and follow along for more real-world engineering + security conversations from the InfusionPoints team.<br/><br/>#BehindTheShield #InfusionPoints #Cybersecurity #Engineering #FedRAMP #FedRAMP20x #GRC #CloudSecurity #DevOps #AWS</p>]]></description>
    <content:encoded><![CDATA[<p>Go Behind the Shield with a special 3-segment episode, hosted by Jason Shropshire, featuring members of the InfusionPoints engineering team as they break down what they’re building, how they’re building it, and the lessons learned along the way. Recorded after hours during Hackathon week, this one’s a little less buttoned-up in the best way. Expect real talk, real lessons, and a few laughs as the engineers unwind.<br/><br/>Segment 1: Meet Chris Eaves and Gavin Blankenship from R&amp;D as they share how they found InfusionPoints, what it’s like building in a “jack-of-all-trades” environment, and how Command Center became a purpose-built, opinionated GRC platform designed to make complex compliance (FedRAMP, DoD, and more)- manageable without relying on someone else’s roadmap.<br/>They also talk roadmap highlights like automated user onboarding, incident response tracking, and a behind-the-scenes look at building a deployment pipeline to scale Command Center across environments.<br/><br/>Segment 2: Kay and Mike Strohecker join to talk life on the dev team, what Kay’s working on now (vulnerability + asset management), and what it’s like ramping up in the world of acronym soup—especially in the era of FedRAMP 20x. Plus: Hackathon reality check (no sleeping bags required).<br/><br/>Segment 3: Caleb Brinkley (backend) and Matthew Melang (frontend) share what they focus on day-to-day in Command Center, how cross-functional hackathon teams spark better ideas, and how automation (including tools like Power Automate + Teams workflows) can eliminate repetitive work across the business.<br/><br/>And yes… there’s a legendary story about AWS Bedrock, throttling, and an accidental “stress test” you don’t want to recreate.<br/><br/>🎧 Topics covered:<br/><br/>Command Center as a “one pane of glass” for compliance + security operations<br/><br/>FedRAMP 20x and the growing importance of KSIs<br/><br/>Continuous monitoring automation + customer feedback loops<br/><br/>Infrastructure + serverless architecture (Python, AWS services, Terraform)<br/><br/>Hackathon builds: onboarding automation, back-office workflows, and more<br/><br/>Lightning round essentials: dark mode, tabs vs spaces, and dev playlists<br/><br/>👍 Like, subscribe, and follow along for more real-world engineering + security conversations from the InfusionPoints team.<br/><br/>#BehindTheShield #InfusionPoints #Cybersecurity #Engineering #FedRAMP #FedRAMP20x #GRC #CloudSecurity #DevOps #AWS</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18702383-inside-infusionpoints-development-command-center-fedramp-20x-hackathon-builds.mp3" length="47579831" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18702383</guid>
    <pubDate>Tue, 17 Feb 2026 17:00:00 -0500</pubDate>
    <itunes:duration>3962</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>20</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Selling in AWS Marketplace Without Guessing: Analytics, Private Offers, and Co-Sell with Trés Vance</itunes:title>
    <title>Selling in AWS Marketplace Without Guessing: Analytics, Private Offers, and Co-Sell with Trés Vance</title>
    <itunes:summary><![CDATA[What happens when you treat AWS Marketplace like real commerce, not a static listing page?  In this episode of Behind the Shield, Gary Daemer and Jason Shropshire sit down in North Wilkesboro with Trés “Trey” Vance, Executive Chairman of CloudSmart, to talk about the business mechanics behind modern cloud go-to-market: marketplace analytics, private offers, channel partner private offers, and why co-sell is the difference between “we built something” and “we built a business.”  Trey shares th...]]></itunes:summary>
    <description><![CDATA[<p>What happens when you treat AWS Marketplace like real commerce, not a static listing page?<br/><br/>In this episode of Behind the Shield, Gary Daemer and Jason Shropshire sit down in North Wilkesboro with Trés “Trey” Vance, Executive Chairman of CloudSmart, to talk about the business mechanics behind modern cloud go-to-market: marketplace analytics, private offers, channel partner private offers, and why co-sell is the difference between “we built something” and “we built a business.”<br/><br/>Trey shares the origin story behind CloudSmart (starting with AMIs and “steak dinner money”), why marketplace reporting has historically been harder than it should be, and how CloudSmart Insights helps sellers understand who’s buying, why they’re buying, and what’s actually working. The conversation also dives into newer marketplace realities, including multi-product solutions and bundles, marketplace APIs, CRM integrations (Salesforce and HubSpot), and the coming wave of AI listings that may force everyone to rely on smarter search and better data.<br/><br/>You’ll also hear how InfusionPoints and Trey first connected through the early ATO on AWS days, why focus versus “we do every cloud” matters, and how rural North Carolina tech teams can absolutely compete with the biggest hubs without inheriting the traffic.<br/><br/>Topics covered:<br/><br/>Marketplace intelligence: payouts, customers, intent, trends<br/><br/>Public offers vs. private offers and why 95%+ of transactions are private offers<br/><br/>Co-sell vs. go-to-market and why it changes customer acquisition cost<br/><br/>Marketplace APIs and CRM connectors to eliminate swivel chair operations<br/><br/>Multi-product solutions: bundling software, services, and security tools<br/><br/>Usage-based pricing and making buying frictionless<br/><br/>Building tech talent pipelines in rural communities<br/><br/>🎧 Watch and listen to the full episode and drop your questions in the comments.</p>]]></description>
    <content:encoded><![CDATA[<p>What happens when you treat AWS Marketplace like real commerce, not a static listing page?<br/><br/>In this episode of Behind the Shield, Gary Daemer and Jason Shropshire sit down in North Wilkesboro with Trés “Trey” Vance, Executive Chairman of CloudSmart, to talk about the business mechanics behind modern cloud go-to-market: marketplace analytics, private offers, channel partner private offers, and why co-sell is the difference between “we built something” and “we built a business.”<br/><br/>Trey shares the origin story behind CloudSmart (starting with AMIs and “steak dinner money”), why marketplace reporting has historically been harder than it should be, and how CloudSmart Insights helps sellers understand who’s buying, why they’re buying, and what’s actually working. The conversation also dives into newer marketplace realities, including multi-product solutions and bundles, marketplace APIs, CRM integrations (Salesforce and HubSpot), and the coming wave of AI listings that may force everyone to rely on smarter search and better data.<br/><br/>You’ll also hear how InfusionPoints and Trey first connected through the early ATO on AWS days, why focus versus “we do every cloud” matters, and how rural North Carolina tech teams can absolutely compete with the biggest hubs without inheriting the traffic.<br/><br/>Topics covered:<br/><br/>Marketplace intelligence: payouts, customers, intent, trends<br/><br/>Public offers vs. private offers and why 95%+ of transactions are private offers<br/><br/>Co-sell vs. go-to-market and why it changes customer acquisition cost<br/><br/>Marketplace APIs and CRM connectors to eliminate swivel chair operations<br/><br/>Multi-product solutions: bundling software, services, and security tools<br/><br/>Usage-based pricing and making buying frictionless<br/><br/>Building tech talent pipelines in rural communities<br/><br/>🎧 Watch and listen to the full episode and drop your questions in the comments.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18657210-selling-in-aws-marketplace-without-guessing-analytics-private-offers-and-co-sell-with-tres-vance.mp3" length="53105705" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18657210</guid>
    <pubDate>Tue, 10 Feb 2026 11:00:00 -0500</pubDate>
    <itunes:duration>4422</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>19</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title> FedRAMP 20x: From 12–18 Months to Weeks? Reality Check with Andrea Livero-Scott</itunes:title>
    <title> FedRAMP 20x: From 12–18 Months to Weeks? Reality Check with Andrea Livero-Scott</title>
    <itunes:summary><![CDATA[In this episode of Behind the Shield, host Gary Daemer sits down with Andrea Livero-Scott, Director for Cybersecurity at Kratos Defense &amp; Security Solutions, to unpack what is changing across FedRAMP and why the shift to FedRAMP 20x is more than a process update.  We cover:  The biggest FedRAMP pain points from the last 4–5 years (timelines, reviewer interpretation, package churn)  The real differences between civilian and DoD authorization paths  FedRAMP 20x: automation readiness, KSIs, ...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of Behind the Shield, host Gary Daemer sits down with Andrea Livero-Scott, Director for Cybersecurity at Kratos Defense &amp; Security Solutions, to unpack what is changing across FedRAMP and why the shift to FedRAMP 20x is more than a process update.<br/><br/>We cover:<br/><br/>The biggest FedRAMP pain points from the last 4–5 years (timelines, reviewer interpretation, package churn)<br/><br/>The real differences between civilian and DoD authorization paths<br/><br/>FedRAMP 20x: automation readiness, KSIs, and what “faster” really requires<br/><br/>Machine-readable evidence and the questions agencies and assessors still need answered<br/><br/>The sponsorless pathway and what it could unlock for commercial providers<br/><br/>Where AI fits, including why agentic AI starts to look like an insider threat<br/><br/>Subscribe for more conversations on compliance, cloud security, automation, and what it takes to build, manage, and defend in regulated environments.<br/><br/>www.InfusionPoints.com</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of Behind the Shield, host Gary Daemer sits down with Andrea Livero-Scott, Director for Cybersecurity at Kratos Defense &amp; Security Solutions, to unpack what is changing across FedRAMP and why the shift to FedRAMP 20x is more than a process update.<br/><br/>We cover:<br/><br/>The biggest FedRAMP pain points from the last 4–5 years (timelines, reviewer interpretation, package churn)<br/><br/>The real differences between civilian and DoD authorization paths<br/><br/>FedRAMP 20x: automation readiness, KSIs, and what “faster” really requires<br/><br/>Machine-readable evidence and the questions agencies and assessors still need answered<br/><br/>The sponsorless pathway and what it could unlock for commercial providers<br/><br/>Where AI fits, including why agentic AI starts to look like an insider threat<br/><br/>Subscribe for more conversations on compliance, cloud security, automation, and what it takes to build, manage, and defend in regulated environments.<br/><br/>www.InfusionPoints.com</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18620601-fedramp-20x-from-12-18-months-to-weeks-reality-check-with-andrea-livero-scott.mp3" length="37069201" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18620601</guid>
    <pubDate>Tue, 03 Feb 2026 16:00:00 -0500</pubDate>
    <itunes:duration>3086</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>18</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>FedRAMP 20x Phase 2: Building Trust, Transparency, and ATO Monitoring at Scale</itunes:title>
    <title>FedRAMP 20x Phase 2: Building Trust, Transparency, and ATO Monitoring at Scale</title>
    <itunes:summary><![CDATA[FedRAMP 20x is moving fast and in this episode of Behind the Shield, host Gary Daemer  and co-host Chad Spears break down what it actually looks like to go from Phase 1 pilot to Phase 2 production-ready thinking. We cover the real shift happening right now from “is the thing there?” to “is the control effective?” plus how KSIs, continuous and persistent validation, and machine-readable evidence are changing the game for CSPs, 3PAOs, and agencies. In this episode, we discuss: What FedRAMP...]]></itunes:summary>
    <description><![CDATA[<p>FedRAMP 20x is moving fast and in this episode of Behind the Shield, host Gary Daemer  and co-host Chad Spears break down what it actually looks like to go from Phase 1 pilot to Phase 2 production-ready thinking.<br/>We cover the real shift happening right now from “is the thing there?” to “is the control effective?” plus how KSIs, continuous and persistent validation, and machine-readable evidence are changing the game for CSPs, 3PAOs, and agencies.<br/>In this episode, we discuss:<br/>What FedRAMP 20x Phase 2 changes and why it feels like crawl, walk, run<br/>How trust is built by showing how evidence is pulled, not just what it is<br/>Why continuous and persistent checking matters and how it prevents configuration drift<br/>Machine-readable evidence, faster audits, and faster time to market<br/>Transparency through Trust Centers and public-facing security status<br/>What CSPs should do next including cloud-native readiness and API integration<br/>The evolving role of 3PAOs and verifying automated compliance<br/>How a Build | Manage | Defend mindset supports the future of FedRAMP<br/>If you are navigating FedRAMP, modern compliance automation, or want a clearer picture of where 20x is headed, this episode is for you.<br/>Links and Resources<br/>Learn more about InfusionPoints: www.InfusionPoints.com<br/>FedRAMP 20x resources: https://www.fedramp.gov<br/>Contact us: https://app.hatchbuck.com/OnlineForm/53273431050<br/> <br/>#FedRAMP #FedRAMP20x #ComplianceAutomation #ContinuousMonitoring #CloudSecurity #GRC #ATO #3PAO #GovCloud</p>]]></description>
    <content:encoded><![CDATA[<p>FedRAMP 20x is moving fast and in this episode of Behind the Shield, host Gary Daemer  and co-host Chad Spears break down what it actually looks like to go from Phase 1 pilot to Phase 2 production-ready thinking.<br/>We cover the real shift happening right now from “is the thing there?” to “is the control effective?” plus how KSIs, continuous and persistent validation, and machine-readable evidence are changing the game for CSPs, 3PAOs, and agencies.<br/>In this episode, we discuss:<br/>What FedRAMP 20x Phase 2 changes and why it feels like crawl, walk, run<br/>How trust is built by showing how evidence is pulled, not just what it is<br/>Why continuous and persistent checking matters and how it prevents configuration drift<br/>Machine-readable evidence, faster audits, and faster time to market<br/>Transparency through Trust Centers and public-facing security status<br/>What CSPs should do next including cloud-native readiness and API integration<br/>The evolving role of 3PAOs and verifying automated compliance<br/>How a Build | Manage | Defend mindset supports the future of FedRAMP<br/>If you are navigating FedRAMP, modern compliance automation, or want a clearer picture of where 20x is headed, this episode is for you.<br/>Links and Resources<br/>Learn more about InfusionPoints: www.InfusionPoints.com<br/>FedRAMP 20x resources: https://www.fedramp.gov<br/>Contact us: https://app.hatchbuck.com/OnlineForm/53273431050<br/> <br/>#FedRAMP #FedRAMP20x #ComplianceAutomation #ContinuousMonitoring #CloudSecurity #GRC #ATO #3PAO #GovCloud</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18579933-fedramp-20x-phase-2-building-trust-transparency-and-ato-monitoring-at-scale.mp3" length="39274454" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18579933</guid>
    <pubDate>Tue, 27 Jan 2026 15:00:00 -0500</pubDate>
    <itunes:duration>3270</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>17</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Inside our Cyber and Cloud Talent Pipeline - Part 1</itunes:title>
    <title>Inside our Cyber and Cloud Talent Pipeline - Part 1</title>
    <itunes:summary><![CDATA[Building talent is part of building secure systems. In Episode 1 of our 3-part Internship Series, host Felisha Daemer sits down with Tanner Bailey (former InfusionPoints intern turned Internship Coordinator) to unpack how we develop the next generation of cybersecurity and cloud professionals through a rotational program across Advisory, Cloud Ops/Engineering, and a 24x7 SOC. If you are not looking for an internship, this episode is still for you. You will hear: How we scale delivery without ...]]></itunes:summary>
    <description><![CDATA[<p>Building talent is part of building secure systems.<br/>In Episode 1 of our 3-part Internship Series, host Felisha Daemer sits down with Tanner Bailey (former InfusionPoints intern turned Internship Coordinator) to unpack how we develop the next generation of cybersecurity and cloud professionals through a rotational program across Advisory, Cloud Ops/Engineering, and a 24x7 SOC.<br/>If you are not looking for an internship, this episode is still for you. You will hear:<br/>How we scale delivery without sacrificing quality or customer outcomes<br/>Why fresh eyes and repeatable processes improve security and operations<br/>What it takes to cross-train teams in a real-world cloud security services org<br/>How we assess “Hungry, Humble, Smart” and why that matters in high-trust environments<br/>Lessons learned from turning interns into contributors who ship meaningful work<br/>You will also learn:<br/>How the rotational program is structured and what interns do day to day<br/>The certification and training paths we support (AWS Cloud Practitioner, Solutions Architect, Security Ops)<br/>How evaluations work and what the path to full-time can look like<br/>Interested in applying or sharing with someone who should?<br/>Website: InfusionPoints.com/careers (internships link at the bottom)<br/>Email: internships@infusionpoints.com<br/>Meet us in person:<br/>App State Career Fair: January 28, 2026<br/>App State Cyber Summit: April 9 to 10, 2026 (booth + sponsoring the social hour)<br/>Subscribe for Part 2 and Part 3, where we hear directly from past interns about what they built, learned, and how they leveled up.<br/>#CloudSecurity #Cybersecurity #SOC #AWS #GovCloud #FedRAMP20X #Leadership #TalentDevelopment #BehindTheShield #InfusionPoints</p>]]></description>
    <content:encoded><![CDATA[<p>Building talent is part of building secure systems.<br/>In Episode 1 of our 3-part Internship Series, host Felisha Daemer sits down with Tanner Bailey (former InfusionPoints intern turned Internship Coordinator) to unpack how we develop the next generation of cybersecurity and cloud professionals through a rotational program across Advisory, Cloud Ops/Engineering, and a 24x7 SOC.<br/>If you are not looking for an internship, this episode is still for you. You will hear:<br/>How we scale delivery without sacrificing quality or customer outcomes<br/>Why fresh eyes and repeatable processes improve security and operations<br/>What it takes to cross-train teams in a real-world cloud security services org<br/>How we assess “Hungry, Humble, Smart” and why that matters in high-trust environments<br/>Lessons learned from turning interns into contributors who ship meaningful work<br/>You will also learn:<br/>How the rotational program is structured and what interns do day to day<br/>The certification and training paths we support (AWS Cloud Practitioner, Solutions Architect, Security Ops)<br/>How evaluations work and what the path to full-time can look like<br/>Interested in applying or sharing with someone who should?<br/>Website: InfusionPoints.com/careers (internships link at the bottom)<br/>Email: internships@infusionpoints.com<br/>Meet us in person:<br/>App State Career Fair: January 28, 2026<br/>App State Cyber Summit: April 9 to 10, 2026 (booth + sponsoring the social hour)<br/>Subscribe for Part 2 and Part 3, where we hear directly from past interns about what they built, learned, and how they leveled up.<br/>#CloudSecurity #Cybersecurity #SOC #AWS #GovCloud #FedRAMP20X #Leadership #TalentDevelopment #BehindTheShield #InfusionPoints</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18542885-inside-our-cyber-and-cloud-talent-pipeline-part-1.mp3" length="26585786" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18542885</guid>
    <pubDate>Tue, 20 Jan 2026 16:00:00 -0500</pubDate>
    <itunes:duration>2212</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>16</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>From Tokens to Passwordless: RSA CISO, Rob Hughes, On FedRAMP REV 5 and AI Risk</itunes:title>
    <title>From Tokens to Passwordless: RSA CISO, Rob Hughes, On FedRAMP REV 5 and AI Risk</title>
    <itunes:summary><![CDATA[In this episode, hosts Mike Strohecker and Jason Shropshire sit down with Rob Hughes, CISO of RSA, for a deep dive into identity security, FedRAMP Rev 5, and emerging AI risk.  Rob shares his journey into the CISO role and how RSA has evolved from its early days of hardware tokens into a modern, cloud focused identity provider. The conversation covers real world lessons from RSA’s FedRAMP authorization experience, including navigating the JAB process, operating during the shift to remote work...]]></itunes:summary>
    <description><![CDATA[<p>In this episode, hosts Mike Strohecker and Jason Shropshire sit down with Rob Hughes, CISO of RSA, for a deep dive into identity security, FedRAMP Rev 5, and emerging AI risk.<br/><br/>Rob shares his journey into the CISO role and how RSA has evolved from its early days of hardware tokens into a modern, cloud focused identity provider. The conversation covers real world lessons from RSA’s FedRAMP authorization experience, including navigating the JAB process, operating during the shift to remote work, and balancing compliance requirements with meaningful security outcomes.<br/><br/>The group also explores what FedRAMP Rev 5 changes actually mean for identity, phishing resistant authentication, and passwordless approaches, as well as how FedRAMP is moving toward more outcome driven security models. Rob offers candid insight into how these changes affect both federal and commercial environments.<br/><br/>The discussion wraps with a practical look at AI risk, including data leakage, shadow AI usage, and why identity and zero trust principles are becoming even more critical as AI tools become part of everyday workflows. A lightning round at the end adds a lighter close to the conversation.<br/><br/>Topics covered include:<br/><br/>Rob Hughes’ path to CISO and RSA’s identity evolution<br/><br/>FedRAMP Rev 5 and phishing resistant authentication<br/><br/>Lessons learned from the FedRAMP JAB process<br/><br/>Identity as the modern security perimeter<br/><br/>AI risk, data exposure, and shadow AI concerns<br/><br/>Lightning round questions<br/><br/>Subscribe for more conversations on cloud security, compliance, and the people behind the programs shaping federal and enterprise cybersecurity.<br/><br/>#FedRAMP  #CloudSecurity #FedRAMPRev5 #identitysecurity</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode, hosts Mike Strohecker and Jason Shropshire sit down with Rob Hughes, CISO of RSA, for a deep dive into identity security, FedRAMP Rev 5, and emerging AI risk.<br/><br/>Rob shares his journey into the CISO role and how RSA has evolved from its early days of hardware tokens into a modern, cloud focused identity provider. The conversation covers real world lessons from RSA’s FedRAMP authorization experience, including navigating the JAB process, operating during the shift to remote work, and balancing compliance requirements with meaningful security outcomes.<br/><br/>The group also explores what FedRAMP Rev 5 changes actually mean for identity, phishing resistant authentication, and passwordless approaches, as well as how FedRAMP is moving toward more outcome driven security models. Rob offers candid insight into how these changes affect both federal and commercial environments.<br/><br/>The discussion wraps with a practical look at AI risk, including data leakage, shadow AI usage, and why identity and zero trust principles are becoming even more critical as AI tools become part of everyday workflows. A lightning round at the end adds a lighter close to the conversation.<br/><br/>Topics covered include:<br/><br/>Rob Hughes’ path to CISO and RSA’s identity evolution<br/><br/>FedRAMP Rev 5 and phishing resistant authentication<br/><br/>Lessons learned from the FedRAMP JAB process<br/><br/>Identity as the modern security perimeter<br/><br/>AI risk, data exposure, and shadow AI concerns<br/><br/>Lightning round questions<br/><br/>Subscribe for more conversations on cloud security, compliance, and the people behind the programs shaping federal and enterprise cybersecurity.<br/><br/>#FedRAMP  #CloudSecurity #FedRAMPRev5 #identitysecurity</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18503805-from-tokens-to-passwordless-rsa-ciso-rob-hughes-on-fedramp-rev-5-and-ai-risk.mp3" length="36904000" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18503805</guid>
    <pubDate>Wed, 14 Jan 2026 16:00:00 -0500</pubDate>
    <itunes:duration>3072</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>15</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>“Wild West FedRAMP” to 20x: Lessons Learned with Sam Aydlette</itunes:title>
    <title>“Wild West FedRAMP” to 20x: Lessons Learned with Sam Aydlette</title>
    <itunes:summary><![CDATA[Behind the Shield- Episode 14  In this episode of Behind the Shield, host Jason Shropshire is joined by guest host Jason Redding (InfusionPoints Advisory) and special guest Sam Aydlette, a longtime FedRAMP leader who’s seen the program from nearly every seat: government, industry, and consulting.  Sam takes us back to the early “Wild West” days of FedRAMP, why cloud changed everything about traditional FISMA thinking, and what today’s shift toward transparency and measurable secure outcomes m...]]></itunes:summary>
    <description><![CDATA[<p>Behind the Shield- Episode 14<br/><br/>In this episode of Behind the Shield, host Jason Shropshire is joined by guest host Jason Redding (InfusionPoints Advisory) and special guest Sam Aydlette, a longtime FedRAMP leader who’s seen the program from nearly every seat: government, industry, and consulting.<br/><br/>Sam takes us back to the early “Wild West” days of FedRAMP, why cloud changed everything about traditional FISMA thinking, and what today’s shift toward transparency and measurable secure outcomes means for agencies and CSPs. We dig into why not every system needs to be Moderate, how tailoring should work in practice, and where standards like SBOM and OSCAL can help (and why adoption is complicated).<br/><br/>We also touch on the DoD side of the house, the challenge of scaling compliance and security across large enterprises, and why check-the-box compliance doesn’t build trust.<br/>Topics we cover:<br/>How FedRAMP evolved from early JAB days to today<br/>Transparency, collaboration, and the move toward secure outcomes<br/>Control tailoring, mission assurance vs. trustworthiness<br/>Inventory, SBOM, OSCAL, and what objective measurement should look like<br/>What’s different (and still hard) about the DoD authorization landscape<br/>Lightning round: drums, van-life YouTube, and favorite philosophers<br/><br/>👍 If you enjoyed this episode, like, subscribe, and drop your biggest FedRAMP 20x question in the comments.<br/><br/>*Sam Aydlette&apos;s views are his own and do not represent the views of any organization or employer.<br/>Follow Sam on LinkedIn: https://www.linkedin.com/in/sa2/<br/>Sam&apos;s Website: https://samaydlette.com/<br/><br/>Learn more about InfusionPoints:<br/>LinkedIn: https://www.linkedin.com/company/infusionpoints/<br/>Website: www.InfusionPoints.com<br/><br/><br/>#FedRAMP #FedRAMP20x #Cybersecurity #Compliance #FISMA #CloudSecurity #ContinuousMonitoring #OSCAL #SBOM #InfusionPoints #BehindTheShield</p>]]></description>
    <content:encoded><![CDATA[<p>Behind the Shield- Episode 14<br/><br/>In this episode of Behind the Shield, host Jason Shropshire is joined by guest host Jason Redding (InfusionPoints Advisory) and special guest Sam Aydlette, a longtime FedRAMP leader who’s seen the program from nearly every seat: government, industry, and consulting.<br/><br/>Sam takes us back to the early “Wild West” days of FedRAMP, why cloud changed everything about traditional FISMA thinking, and what today’s shift toward transparency and measurable secure outcomes means for agencies and CSPs. We dig into why not every system needs to be Moderate, how tailoring should work in practice, and where standards like SBOM and OSCAL can help (and why adoption is complicated).<br/><br/>We also touch on the DoD side of the house, the challenge of scaling compliance and security across large enterprises, and why check-the-box compliance doesn’t build trust.<br/>Topics we cover:<br/>How FedRAMP evolved from early JAB days to today<br/>Transparency, collaboration, and the move toward secure outcomes<br/>Control tailoring, mission assurance vs. trustworthiness<br/>Inventory, SBOM, OSCAL, and what objective measurement should look like<br/>What’s different (and still hard) about the DoD authorization landscape<br/>Lightning round: drums, van-life YouTube, and favorite philosophers<br/><br/>👍 If you enjoyed this episode, like, subscribe, and drop your biggest FedRAMP 20x question in the comments.<br/><br/>*Sam Aydlette&apos;s views are his own and do not represent the views of any organization or employer.<br/>Follow Sam on LinkedIn: https://www.linkedin.com/in/sa2/<br/>Sam&apos;s Website: https://samaydlette.com/<br/><br/>Learn more about InfusionPoints:<br/>LinkedIn: https://www.linkedin.com/company/infusionpoints/<br/>Website: www.InfusionPoints.com<br/><br/><br/>#FedRAMP #FedRAMP20x #Cybersecurity #Compliance #FISMA #CloudSecurity #ContinuousMonitoring #OSCAL #SBOM #InfusionPoints #BehindTheShield</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18464860-wild-west-fedramp-to-20x-lessons-learned-with-sam-aydlette.mp3" length="37562250" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18464860</guid>
    <pubDate>Tue, 06 Jan 2026 16:00:00 -0500</pubDate>
    <itunes:duration>3127</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>14</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>From Screenshots to Signals with SK Bhachech: FedRAMP Automation and What Comes Next</itunes:title>
    <title>From Screenshots to Signals with SK Bhachech: FedRAMP Automation and What Comes Next</title>
    <itunes:summary><![CDATA[In this episode of Behind the Shield, host Gary Daemer is joined by new co-host Ryan Adcock from the InfusionPoints Cloud Team and special guest SK Bhachech from Riverbed Technology for a candid conversation on what it really takes to navigate federal compliance when the goalposts move mid-flight.  Together, they unpack Riverbed’s authorization journey, why FedRAMP is often customer-driven rather than chosen, and what makes FedRAMP uniquely prescriptive. From implementing hundreds of controls...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of Behind the Shield, host Gary Daemer is joined by new co-host Ryan Adcock from the InfusionPoints Cloud Team and special guest SK Bhachech from Riverbed Technology for a candid conversation on what it really takes to navigate federal compliance when the goalposts move mid-flight.<br/><br/>Together, they unpack Riverbed’s authorization journey, why FedRAMP is often customer-driven rather than chosen, and what makes FedRAMP uniquely prescriptive. From implementing hundreds of controls to sustaining month-over-month operational rigor, SK shares lessons learned from building and maturing a security program inside a regulated environment.<br/><br/>The conversation also looks ahead to FedRAMP 20x, Key Security Indicators, and machine-readable evidence. The group explores how automation can reduce human error, lower costs, and shift audits away from screenshot collection toward continuous validation. They also discuss where AI may help, such as summarization and review support, and why human oversight remains critical in cybersecurity.<br/><br/>To close, the episode gets more personal with favorite books, shows, and a discussion on service, leadership, and giving back to the community.<br/><br/>Topics covered include:<br/><br/>Why companies are pulled into FedRAMP and why it is hard to walk away<br/><br/>What makes FedRAMP prescriptive and operationally demanding<br/><br/>Staying nimble when requirements change during authorization<br/><br/>FedRAMP 20x, KSIs, and continuous validation<br/><br/>Automation and AI as accelerators with humans still in the loop</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of Behind the Shield, host Gary Daemer is joined by new co-host Ryan Adcock from the InfusionPoints Cloud Team and special guest SK Bhachech from Riverbed Technology for a candid conversation on what it really takes to navigate federal compliance when the goalposts move mid-flight.<br/><br/>Together, they unpack Riverbed’s authorization journey, why FedRAMP is often customer-driven rather than chosen, and what makes FedRAMP uniquely prescriptive. From implementing hundreds of controls to sustaining month-over-month operational rigor, SK shares lessons learned from building and maturing a security program inside a regulated environment.<br/><br/>The conversation also looks ahead to FedRAMP 20x, Key Security Indicators, and machine-readable evidence. The group explores how automation can reduce human error, lower costs, and shift audits away from screenshot collection toward continuous validation. They also discuss where AI may help, such as summarization and review support, and why human oversight remains critical in cybersecurity.<br/><br/>To close, the episode gets more personal with favorite books, shows, and a discussion on service, leadership, and giving back to the community.<br/><br/>Topics covered include:<br/><br/>Why companies are pulled into FedRAMP and why it is hard to walk away<br/><br/>What makes FedRAMP prescriptive and operationally demanding<br/><br/>Staying nimble when requirements change during authorization<br/><br/>FedRAMP 20x, KSIs, and continuous validation<br/><br/>Automation and AI as accelerators with humans still in the loop</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18407350-from-screenshots-to-signals-with-sk-bhachech-fedramp-automation-and-what-comes-next.mp3" length="34552990" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18407350</guid>
    <pubDate>Tue, 23 Dec 2025 13:00:00 -0500</pubDate>
    <itunes:duration>2876</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>13</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>One Pane, Zero Panic: Command Center on XBU40, FedRAMP 20x Phase 2 Moderate &amp; ATO Monitoring</itunes:title>
    <title>One Pane, Zero Panic: Command Center on XBU40, FedRAMP 20x Phase 2 Moderate &amp; ATO Monitoring</title>
    <itunes:summary><![CDATA[Disclaimer:  This conversation includes a live demo of Command Center on XBU40. To see the dashboards, workflows, and visuals discussed, watch the full episode on YouTube: https://youtu.be/2db13PnF62s  In this episode of Behind the Shield, host Gary Daemer is joined by co-host Chad Spears (Director, Security Operations) and special guest Alex Earhart (Lead SecOps Engineer and 20x pilot engineer) for a live walkthrough of Command Center on XBU40.  We go hands-on with the platform and...]]></itunes:summary>
    <description><![CDATA[<p>Disclaimer:  This conversation includes a live demo of Command Center on XBU40. To see the dashboards, workflows, and visuals discussed, watch the full episode on YouTube: <a href='https://youtu.be/2db13PnF62s'>https://youtu.be/2db13PnF62s</a> </p><p>In this episode of Behind the Shield, host Gary Daemer is joined by co-host Chad Spears (Director, Security Operations) and special guest Alex Earhart (Lead SecOps Engineer and 20x pilot engineer) for a live walkthrough of Command Center on XBU40.<br/><br/>We go hands-on with the platform and the tooling that helps teams operate, manage, and prove security across FedRAMP and DoD environments, while also showing what we are taking forward into our FedRAMP 20x Phase 2 Moderate approach.<br/><br/>In the demo, you will see how Command Center brings everything into one place, including:<br/><br/>Built-in ticketing designed for FedRAMP workflows, evidence collection, and KSI-aligned tracking (including significant change support)<br/><br/>Continuous monitoring and vulnerability management, including POA&amp;M support and the shift to VDR (Vulnerability Detection &amp; Response)<br/><br/>Alert management with integrations, automated ticket creation, and SOC metrics like mean time to respond and close<br/><br/>SSP management as a living system, structured as data (not a static document) with the ability to import existing SSPs and generate outputs<br/><br/>AuditShield for FedRAMP 20x, including automated KSI validations, machine-readable evidence, and the ability to run checks on a schedule or live<br/><br/>Trust Center views that publish scorecards and trends, plus secure sharing through the document repository<br/><br/>A look at ATO Monitoring, built around machine-readable outputs to help agencies and teams track security posture across multiple ATOs in a single view<br/><br/>If you are navigating FedRAMP Rev 5, exploring 20x, supporting DoD IL workloads, or just tired of chasing screenshots, this one is for you.<br/><br/>Explore the Trust Center: XB40.com</p>]]></description>
    <content:encoded><![CDATA[<p>Disclaimer:  This conversation includes a live demo of Command Center on XBU40. To see the dashboards, workflows, and visuals discussed, watch the full episode on YouTube: <a href='https://youtu.be/2db13PnF62s'>https://youtu.be/2db13PnF62s</a> </p><p>In this episode of Behind the Shield, host Gary Daemer is joined by co-host Chad Spears (Director, Security Operations) and special guest Alex Earhart (Lead SecOps Engineer and 20x pilot engineer) for a live walkthrough of Command Center on XBU40.<br/><br/>We go hands-on with the platform and the tooling that helps teams operate, manage, and prove security across FedRAMP and DoD environments, while also showing what we are taking forward into our FedRAMP 20x Phase 2 Moderate approach.<br/><br/>In the demo, you will see how Command Center brings everything into one place, including:<br/><br/>Built-in ticketing designed for FedRAMP workflows, evidence collection, and KSI-aligned tracking (including significant change support)<br/><br/>Continuous monitoring and vulnerability management, including POA&amp;M support and the shift to VDR (Vulnerability Detection &amp; Response)<br/><br/>Alert management with integrations, automated ticket creation, and SOC metrics like mean time to respond and close<br/><br/>SSP management as a living system, structured as data (not a static document) with the ability to import existing SSPs and generate outputs<br/><br/>AuditShield for FedRAMP 20x, including automated KSI validations, machine-readable evidence, and the ability to run checks on a schedule or live<br/><br/>Trust Center views that publish scorecards and trends, plus secure sharing through the document repository<br/><br/>A look at ATO Monitoring, built around machine-readable outputs to help agencies and teams track security posture across multiple ATOs in a single view<br/><br/>If you are navigating FedRAMP Rev 5, exploring 20x, supporting DoD IL workloads, or just tired of chasing screenshots, this one is for you.<br/><br/>Explore the Trust Center: XB40.com</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18364280-one-pane-zero-panic-command-center-on-xbu40-fedramp-20x-phase-2-moderate-ato-monitoring.mp3" length="49148140" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18364280</guid>
    <pubDate>Tue, 16 Dec 2025 11:00:00 -0500</pubDate>
    <itunes:duration>4093</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>12</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>From the Assessment Side: FedRAMP 20X, Automation &amp; Continuous Validation with Christian Baer</itunes:title>
    <title>From the Assessment Side: FedRAMP 20X, Automation &amp; Continuous Validation with Christian Baer</title>
    <itunes:summary><![CDATA[Behind the Shield- Episode 11 What does FedRAMP look like from the assessor’s seat? In this episode of Behind the Shield, host Gary Daemer sits down with Christian Baer, Technical Fellow at Schellman, to unpack what FedRAMP 20X really means from the inside of the assessment process. Christian shares first-hand insight into:  • How automation is reshaping federal security assessments  • The shift from point-in-time audits to continuous validation  • Why KSIs and real-time visibility matter mor...]]></itunes:summary>
    <description><![CDATA[<p>Behind the Shield- Episode 11<br/><b>What does FedRAMP look like from the assessor’s seat?</b><br/>In this episode of Behind the Shield, host Gary Daemer sits down with Christian Baer, Technical Fellow at Schellman, to unpack what FedRAMP 20X really means from the inside of the assessment process.<br/>Christian shares first-hand insight into:<br/> • How automation is reshaping federal security assessments<br/> • The shift from point-in-time audits to continuous validation<br/> • Why KSIs and real-time visibility matter more than endless screenshots<br/> • The balance between risk, context, and compliance in modern cloud environments<br/> • What CSPs should expect as FedRAMP, Rev 5, and 20X continue to evolve<br/>From exceptions and vulnerability prioritization to red-yellow-green security posture views, this conversation explores how assessors, CSPs, and agencies can move faster without sacrificing security.<br/>If you work in federal cloud, compliance, cybersecurity, or GRC, this is an episode you don’t want to miss.<br/>🔐 Learn how InfusionPoints is helping CSPs prepare for FedRAMP 20X with automation, transparency, and continuous assurance.<br/>👉 Subscribe for more real-world compliance and cybersecurity conversations.<br/>👉 Visit InfusionPoints.com to learn more.<br/>#FedRAMP #FedRAMP20X #Cybersecurity #GRC #CloudSecurity #ContinuousMonitoring #FederalCompliance #KSIs #ATO #CyberRisk #BehindTheShield</p>]]></description>
    <content:encoded><![CDATA[<p>Behind the Shield- Episode 11<br/><b>What does FedRAMP look like from the assessor’s seat?</b><br/>In this episode of Behind the Shield, host Gary Daemer sits down with Christian Baer, Technical Fellow at Schellman, to unpack what FedRAMP 20X really means from the inside of the assessment process.<br/>Christian shares first-hand insight into:<br/> • How automation is reshaping federal security assessments<br/> • The shift from point-in-time audits to continuous validation<br/> • Why KSIs and real-time visibility matter more than endless screenshots<br/> • The balance between risk, context, and compliance in modern cloud environments<br/> • What CSPs should expect as FedRAMP, Rev 5, and 20X continue to evolve<br/>From exceptions and vulnerability prioritization to red-yellow-green security posture views, this conversation explores how assessors, CSPs, and agencies can move faster without sacrificing security.<br/>If you work in federal cloud, compliance, cybersecurity, or GRC, this is an episode you don’t want to miss.<br/>🔐 Learn how InfusionPoints is helping CSPs prepare for FedRAMP 20X with automation, transparency, and continuous assurance.<br/>👉 Subscribe for more real-world compliance and cybersecurity conversations.<br/>👉 Visit InfusionPoints.com to learn more.<br/>#FedRAMP #FedRAMP20X #Cybersecurity #GRC #CloudSecurity #ContinuousMonitoring #FederalCompliance #KSIs #ATO #CyberRisk #BehindTheShield</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18325157-from-the-assessment-side-fedramp-20x-automation-continuous-validation-with-christian-baer.mp3" length="42512309" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18325157</guid>
    <pubDate>Tue, 09 Dec 2025 11:00:00 -0500</pubDate>
    <itunes:duration>3540</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>11</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Meet Mike Strohecker: Turning Real-World Experience into Cloud Ops Success</itunes:title>
    <title>Meet Mike Strohecker: Turning Real-World Experience into Cloud Ops Success</title>
    <itunes:summary><![CDATA[Behind the Shield- Episode 10   In this introductory episode of Behind the Shield, host Jason Shropshire sits down with Mike Strohecker, Director of Cloud Operations at InfusionPoints, to highlight Mike’s professional journey, leadership role, and perspective on the future of cloud security and FedRAMP 20x.  As part of our series, we periodically introduce members of InfusionPoints’ leadership team, many of whom will also appear as hosts in future episodes. These leadership spotlights al...]]></itunes:summary>
    <description><![CDATA[<p>Behind the Shield- Episode 10 <br/><br/>In this introductory episode of Behind the Shield, host Jason Shropshire sits down with Mike Strohecker, Director of Cloud Operations at InfusionPoints, to highlight Mike’s professional journey, leadership role, and perspective on the future of cloud security and FedRAMP 20x.<br/><br/>As part of our series, we periodically introduce members of InfusionPoints’ leadership team, many of whom will also appear as hosts in future episodes. These leadership spotlights allow our audience to get to know the people shaping our mission and guiding our work between our guest-focused interviews.<br/><br/>In this episode, Mike discusses how he:<br/><br/>Transitioned from a 14-year law enforcement career in Maryland to earning a cybersecurity degree and starting a new chapter in North Carolina<br/><br/>Entered the world of digital forensics and chain-of-custody processes through crash reconstruction and vehicle data analysis<br/><br/>Joined InfusionPoints through a timely LinkedIn connection and a CEO willing to support a career pivot<br/><br/>Grew from advisory work into leading Cloud Operations, overseeing complex customer environments and advancing how we secure cloud solutions<br/><br/>Views FedRAMP 20x, VADER, and the shift from traditional control documentation to Key Security Indicators (KSIs) and real security outcomes<br/><br/>Advises aspiring cybersecurity professionals on the value of cloud expertise, certifications, and embracing AI<br/><br/>This episode also offers a personal look at Mike, including:<br/><br/>Life as a father of three<br/><br/>His passion for tinkering and hands-on projects<br/><br/>A recent family trip to Dollywood<br/><br/>Why Abraham Lincoln would be his ideal historical dinner guest<br/><br/>For those interested in career transitions into cybersecurity, cloud operations, or the evolution of FedRAMP 20x and vulnerability management, this conversation provides meaningful insight and perspective.</p>]]></description>
    <content:encoded><![CDATA[<p>Behind the Shield- Episode 10 <br/><br/>In this introductory episode of Behind the Shield, host Jason Shropshire sits down with Mike Strohecker, Director of Cloud Operations at InfusionPoints, to highlight Mike’s professional journey, leadership role, and perspective on the future of cloud security and FedRAMP 20x.<br/><br/>As part of our series, we periodically introduce members of InfusionPoints’ leadership team, many of whom will also appear as hosts in future episodes. These leadership spotlights allow our audience to get to know the people shaping our mission and guiding our work between our guest-focused interviews.<br/><br/>In this episode, Mike discusses how he:<br/><br/>Transitioned from a 14-year law enforcement career in Maryland to earning a cybersecurity degree and starting a new chapter in North Carolina<br/><br/>Entered the world of digital forensics and chain-of-custody processes through crash reconstruction and vehicle data analysis<br/><br/>Joined InfusionPoints through a timely LinkedIn connection and a CEO willing to support a career pivot<br/><br/>Grew from advisory work into leading Cloud Operations, overseeing complex customer environments and advancing how we secure cloud solutions<br/><br/>Views FedRAMP 20x, VADER, and the shift from traditional control documentation to Key Security Indicators (KSIs) and real security outcomes<br/><br/>Advises aspiring cybersecurity professionals on the value of cloud expertise, certifications, and embracing AI<br/><br/>This episode also offers a personal look at Mike, including:<br/><br/>Life as a father of three<br/><br/>His passion for tinkering and hands-on projects<br/><br/>A recent family trip to Dollywood<br/><br/>Why Abraham Lincoln would be his ideal historical dinner guest<br/><br/>For those interested in career transitions into cybersecurity, cloud operations, or the evolution of FedRAMP 20x and vulnerability management, this conversation provides meaningful insight and perspective.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18288614-meet-mike-strohecker-turning-real-world-experience-into-cloud-ops-success.mp3" length="21855265" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18288614</guid>
    <pubDate>Tue, 02 Dec 2025 16:00:00 -0500</pubDate>
    <itunes:duration>1818</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>10</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Small SaaS to ATO: Teo Balbach on Government Compliance for Small Businesses</itunes:title>
    <title>Small SaaS to ATO: Teo Balbach on Government Compliance for Small Businesses</title>
    <itunes:summary><![CDATA[Behind the Shield- Episode 9  Getting a government Authority to Operate (ATO) can feel impossible for small businesses- but it doesn’t have to be.  In this episode of Behind the Shield, CoachMePlus CEO Teo Balbach shares how a five-person sports technology startup turned its athlete-management platform into a DoD-authorized SaaS used by Army and Air Force programs. Joined by InfusionPoints’ Jackson Gorman and Gary Daemer, Teo explains what it really takes to move from “commercial-ready” to cy...]]></itunes:summary>
    <description><![CDATA[<p>Behind the Shield- Episode 9<br/><br/>Getting a government Authority to Operate (ATO) can feel impossible for small businesses- but it doesn’t have to be.<br/><br/>In this episode of Behind the Shield, CoachMePlus CEO Teo Balbach shares how a five-person sports technology startup turned its athlete-management platform into a DoD-authorized SaaS used by Army and Air Force programs. Joined by InfusionPoints’ Jackson Gorman and Gary Daemer, Teo explains what it really takes to move from “commercial-ready” to cyber-compliant in government environments.<br/><br/>What you’ll learn:<br/><br/>How CoachMePlus built trust and sponsorship inside DoD programs<br/><br/>The value of early gap assessments and knowing your system boundary<br/><br/>Surviving documentation and continuous monitoring without derailing your roadmap<br/><br/>Translating strong cybersecurity into audit-ready evidence<br/><br/>How partnerships accelerate ATOs for small SaaS teams<br/><br/>Real lessons on cost, timing, and scaling across Army, Navy, and Air Force<br/><br/>Who should watch:<br/>Founders, CTOs, engineers, and compliance leaders at small SaaS or tech companies hoping to serve the federal or defense market—without losing focus on innovation and delivery.<br/><br/>Keywords: small business cybersecurity, DoD ATO, Authority to Operate, DISA provisional authorization, FedRAMP 20x, SBIR grants, SaaS compliance, AWS GovCloud, continuous monitoring, audit readiness, government software, CoachMePlus, InfusionPoints<br/><br/>Featuring:<br/>🎙️ Teo Balbach, CEO of CoachMePlus<br/>🎙️ Jackson Gorman, Advisory Consultant, InfusionPoints<br/>🎙️ Gary Daemer, CEO, InfusionPoints<br/><br/><br/></p>]]></description>
    <content:encoded><![CDATA[<p>Behind the Shield- Episode 9<br/><br/>Getting a government Authority to Operate (ATO) can feel impossible for small businesses- but it doesn’t have to be.<br/><br/>In this episode of Behind the Shield, CoachMePlus CEO Teo Balbach shares how a five-person sports technology startup turned its athlete-management platform into a DoD-authorized SaaS used by Army and Air Force programs. Joined by InfusionPoints’ Jackson Gorman and Gary Daemer, Teo explains what it really takes to move from “commercial-ready” to cyber-compliant in government environments.<br/><br/>What you’ll learn:<br/><br/>How CoachMePlus built trust and sponsorship inside DoD programs<br/><br/>The value of early gap assessments and knowing your system boundary<br/><br/>Surviving documentation and continuous monitoring without derailing your roadmap<br/><br/>Translating strong cybersecurity into audit-ready evidence<br/><br/>How partnerships accelerate ATOs for small SaaS teams<br/><br/>Real lessons on cost, timing, and scaling across Army, Navy, and Air Force<br/><br/>Who should watch:<br/>Founders, CTOs, engineers, and compliance leaders at small SaaS or tech companies hoping to serve the federal or defense market—without losing focus on innovation and delivery.<br/><br/>Keywords: small business cybersecurity, DoD ATO, Authority to Operate, DISA provisional authorization, FedRAMP 20x, SBIR grants, SaaS compliance, AWS GovCloud, continuous monitoring, audit readiness, government software, CoachMePlus, InfusionPoints<br/><br/>Featuring:<br/>🎙️ Teo Balbach, CEO of CoachMePlus<br/>🎙️ Jackson Gorman, Advisory Consultant, InfusionPoints<br/>🎙️ Gary Daemer, CEO, InfusionPoints<br/><br/><br/></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18252981-small-saas-to-ato-teo-balbach-on-government-compliance-for-small-businesses.mp3" length="44394972" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18252981</guid>
    <pubDate>Tue, 25 Nov 2025 13:00:00 -0500</pubDate>
    <itunes:duration>3696</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>9</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>From Intern to VP: Felisha Daemer on Building Culture and Leading Public Sector Growth</itunes:title>
    <title>From Intern to VP: Felisha Daemer on Building Culture and Leading Public Sector Growth</title>
    <itunes:summary><![CDATA[Behind the Shield- Episode 9  In this episode of Behind the Shield, host Gary Daemer, CEO of InfusionPoints, sits down with Felisha Daemer, VP of Public Sector and one of the driving forces behind the company’s culture and growth.  Felisha shares her personal journey from college intern to executive leadership — and how being “humble, hungry, and smart” became the foundation of InfusionPoints’ hiring philosophy and team success. Together, Gary and Felisha reflect on what it means to stay scra...]]></itunes:summary>
    <description><![CDATA[<p>Behind the Shield- Episode 9<br/><br/>In this episode of Behind the Shield, host Gary Daemer, CEO of InfusionPoints, sits down with Felisha Daemer, VP of Public Sector and one of the driving forces behind the company’s culture and growth.<br/><br/>Felisha shares her personal journey from college intern to executive leadership — and how being “humble, hungry, and smart” became the foundation of InfusionPoints’ hiring philosophy and team success. Together, Gary and Felisha reflect on what it means to stay scrappy and authentic in the cybersecurity world, how InfusionPoints built its culture of grit and continuous learning, and what makes their internship program a true pipeline for future leaders.<br/><br/>They also discuss current trends in federal cybersecurity and FedRAMP 20x, from “doing it live” compliance to solving agencies’ “hair-on-fire” problems through automation and trust-center visibility.<br/><br/>🎧 Topics Covered:<br/><br/>Felisha’s journey from intern to VP of Public Sector<br/><br/>The father–daughter dynamic in leadership<br/><br/>The “Ideal Team Player” philosophy: humble, hungry, and smart<br/><br/>InfusionPoints’ internship pipeline and culture of growth<br/><br/>What “scrappy” means in cybersecurity and compliance<br/><br/>How FedRAMP 20x and automation are reshaping public sector security<br/><br/>➡️ Subscribe for more Behind the Shield episodes featuring stories, strategies, and insights from the people building, managing, and defending secure cloud environments.</p>]]></description>
    <content:encoded><![CDATA[<p>Behind the Shield- Episode 9<br/><br/>In this episode of Behind the Shield, host Gary Daemer, CEO of InfusionPoints, sits down with Felisha Daemer, VP of Public Sector and one of the driving forces behind the company’s culture and growth.<br/><br/>Felisha shares her personal journey from college intern to executive leadership — and how being “humble, hungry, and smart” became the foundation of InfusionPoints’ hiring philosophy and team success. Together, Gary and Felisha reflect on what it means to stay scrappy and authentic in the cybersecurity world, how InfusionPoints built its culture of grit and continuous learning, and what makes their internship program a true pipeline for future leaders.<br/><br/>They also discuss current trends in federal cybersecurity and FedRAMP 20x, from “doing it live” compliance to solving agencies’ “hair-on-fire” problems through automation and trust-center visibility.<br/><br/>🎧 Topics Covered:<br/><br/>Felisha’s journey from intern to VP of Public Sector<br/><br/>The father–daughter dynamic in leadership<br/><br/>The “Ideal Team Player” philosophy: humble, hungry, and smart<br/><br/>InfusionPoints’ internship pipeline and culture of growth<br/><br/>What “scrappy” means in cybersecurity and compliance<br/><br/>How FedRAMP 20x and automation are reshaping public sector security<br/><br/>➡️ Subscribe for more Behind the Shield episodes featuring stories, strategies, and insights from the people building, managing, and defending secure cloud environments.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18210913-from-intern-to-vp-felisha-daemer-on-building-culture-and-leading-public-sector-growth.mp3" length="19554424" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18210913</guid>
    <pubDate>Tue, 18 Nov 2025 08:00:00 -0500</pubDate>
    <itunes:duration>1626</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>8</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Automation, Trust, and the Next Era of Compliance with Tim Sandage (AWS)</itunes:title>
    <title>Automation, Trust, and the Next Era of Compliance with Tim Sandage (AWS)</title>
    <itunes:summary><![CDATA[Behind the Shield- Episode 7  In this episode of Behind the Shield, we’re joined by Tim Sandage, Head of AWS Global Security &amp; Compliance Acceleration, to explore how automation, AI, and platform-driven design are reshaping the future of cloud compliance.  Tim sits down with Gary Daemer and Jason Shropshire of InfusionPoints to discuss the evolution from static audits to continuous validation—and what it really takes to build trust in an automated world.  🔹 How FedRAMP 20x is changing the...]]></itunes:summary>
    <description><![CDATA[<p>Behind the Shield- Episode 7<br/><br/>In this episode of Behind the Shield, we’re joined by Tim Sandage, Head of AWS Global Security &amp; Compliance Acceleration, to explore how automation, AI, and platform-driven design are reshaping the future of cloud compliance.<br/><br/>Tim sits down with Gary Daemer and Jason Shropshire of InfusionPoints to discuss the evolution from static audits to continuous validation—and what it really takes to build trust in an automated world.<br/><br/>🔹 How FedRAMP 20x is changing the path to authorization<br/>🔹 Why “Security by Design” remains essential in the AI era<br/>🔹 Continuous audit vs. annual audit panic<br/>🔹 Platform-driven compliance and opinionated architectures<br/>🔹 Balancing automation with human oversight and trust<br/><br/>If you’re navigating FedRAMP, CMMC, or enterprise-grade security frameworks, this episode highlights the real-world strategies AWS and InfusionPoints use to accelerate compliance without compromising assurance.<br/><br/>🎧 Listen now to see how automation and AI are transforming the next era of security and compliance.<br/><br/>#BehindTheShield #FedRAMP20x #AWS #CloudSecurity #ContinuousCompliance #Automation #AI #Cybersecurity #InfusionPoints #SecurityByDesign</p>]]></description>
    <content:encoded><![CDATA[<p>Behind the Shield- Episode 7<br/><br/>In this episode of Behind the Shield, we’re joined by Tim Sandage, Head of AWS Global Security &amp; Compliance Acceleration, to explore how automation, AI, and platform-driven design are reshaping the future of cloud compliance.<br/><br/>Tim sits down with Gary Daemer and Jason Shropshire of InfusionPoints to discuss the evolution from static audits to continuous validation—and what it really takes to build trust in an automated world.<br/><br/>🔹 How FedRAMP 20x is changing the path to authorization<br/>🔹 Why “Security by Design” remains essential in the AI era<br/>🔹 Continuous audit vs. annual audit panic<br/>🔹 Platform-driven compliance and opinionated architectures<br/>🔹 Balancing automation with human oversight and trust<br/><br/>If you’re navigating FedRAMP, CMMC, or enterprise-grade security frameworks, this episode highlights the real-world strategies AWS and InfusionPoints use to accelerate compliance without compromising assurance.<br/><br/>🎧 Listen now to see how automation and AI are transforming the next era of security and compliance.<br/><br/>#BehindTheShield #FedRAMP20x #AWS #CloudSecurity #ContinuousCompliance #Automation #AI #Cybersecurity #InfusionPoints #SecurityByDesign</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18171215-automation-trust-and-the-next-era-of-compliance-with-tim-sandage-aws.mp3" length="58722982" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-18171215</guid>
    <pubDate>Tue, 11 Nov 2025 10:00:00 -0500</pubDate>
    <itunes:duration>4890</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>7</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Leverage Compliance Pipelines to Bust Down Walls</itunes:title>
    <title>Leverage Compliance Pipelines to Bust Down Walls</title>
    <itunes:summary><![CDATA[Behind the Shield- Episode 6  In this episode of Behind the Shield, Jason Shropshire and Gary Daemer connect history, innovation, and compliance. What can the fall of Constantinople teach us about modern cybersecurity and FedRAMP 20x?  They explore why traditional “walls and moats” thinking no longer works in today’s cloud world, how compliance pipelines are changing the game, and why automation—not screenshots—is the future of assurance.  You’ll hear how InfusionPoints’ platforms like XBU40,...]]></itunes:summary>
    <description><![CDATA[<p>Behind the Shield- Episode 6<br/><br/>In this episode of Behind the Shield, Jason Shropshire and Gary Daemer connect history, innovation, and compliance. What can the fall of Constantinople teach us about modern cybersecurity and FedRAMP 20x?<br/><br/>They explore why traditional “walls and moats” thinking no longer works in today’s cloud world, how compliance pipelines are changing the game, and why automation—not screenshots—is the future of assurance.<br/><br/>You’ll hear how InfusionPoints’ platforms like XBU40, XccelerATOr, and AuditShield are helping customers move from static audits to continuous validation—and how FedRAMP 20x is leading that transformation.<br/><br/>Topics include:<br/><br/>What “walls and moats” have to do with compliance<br/><br/>Why continuous validation beats point-in-time audits<br/><br/>The rise of compliance pipelines under FedRAMP 20x<br/><br/>Platform vs. GRC approaches in federal cybersecurity<br/><br/>Hosted by: Jason Shropshire &amp; Gary Daemer<br/>🎧 Subscribe for more Behind the Shield episodes on FedRAMP 20x, cloud security, and compliance innovation.<br/><br/>Click here to read the blogs: <br/>https://infusionpoints.com/blogs/rethinking-walls-and-moats-cybersecurity-and-compliance<br/>https://infusionpoints.com/blogs/opinionated-design-why-platform-plus-grc-wins-fedramp20x<br/><br/>#fedramp20x #compliance #grc</p>]]></description>
    <content:encoded><![CDATA[<p>Behind the Shield- Episode 6<br/><br/>In this episode of Behind the Shield, Jason Shropshire and Gary Daemer connect history, innovation, and compliance. What can the fall of Constantinople teach us about modern cybersecurity and FedRAMP 20x?<br/><br/>They explore why traditional “walls and moats” thinking no longer works in today’s cloud world, how compliance pipelines are changing the game, and why automation—not screenshots—is the future of assurance.<br/><br/>You’ll hear how InfusionPoints’ platforms like XBU40, XccelerATOr, and AuditShield are helping customers move from static audits to continuous validation—and how FedRAMP 20x is leading that transformation.<br/><br/>Topics include:<br/><br/>What “walls and moats” have to do with compliance<br/><br/>Why continuous validation beats point-in-time audits<br/><br/>The rise of compliance pipelines under FedRAMP 20x<br/><br/>Platform vs. GRC approaches in federal cybersecurity<br/><br/>Hosted by: Jason Shropshire &amp; Gary Daemer<br/>🎧 Subscribe for more Behind the Shield episodes on FedRAMP 20x, cloud security, and compliance innovation.<br/><br/>Click here to read the blogs: <br/>https://infusionpoints.com/blogs/rethinking-walls-and-moats-cybersecurity-and-compliance<br/>https://infusionpoints.com/blogs/opinionated-design-why-platform-plus-grc-wins-fedramp20x<br/><br/>#fedramp20x #compliance #grc</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18131086-leverage-compliance-pipelines-to-bust-down-walls.mp3" length="21809760" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18131086</guid>
    <pubDate>Tue, 04 Nov 2025 09:00:00 -0500</pubDate>
    <itunes:duration>1814</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>6</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>From SaaS to FedRAMP 20x: Meet Jeff Bivens, VP of Customer Success</itunes:title>
    <title>From SaaS to FedRAMP 20x: Meet Jeff Bivens, VP of Customer Success</title>
    <itunes:summary><![CDATA[Behind the Shield- Episode 5   Meet our new VP of Customer Success, Jeff Bivens. Jeff shares his path from late-90s client-server to SaaS, through a Dell acquisition and multiple ATOs, to why he joined InfusionPoints now. We dig into how strong program management turns compliance into momentum, how FedRAMP 20x can lower barriers without lowering security, and why “customer success” in public sector means repeatable outcomes, faster audits, and durable trust. We also touch on AI’s role in...]]></itunes:summary>
    <description><![CDATA[<p>Behind the Shield- Episode 5 <br/><br/>Meet our new VP of Customer Success, Jeff Bivens. Jeff shares his path from late-90s client-server to SaaS, through a Dell acquisition and multiple ATOs, to why he joined InfusionPoints now. We dig into how strong program management turns compliance into momentum, how FedRAMP 20x can lower barriers without lowering security, and why “customer success” in public sector means repeatable outcomes, faster audits, and durable trust. We also touch on AI’s role in detection and operations, evergreen company values, and what changes when a services firm becomes a true cloud service provider.<br/><br/>What you’ll learn:<br/><br/>How SaaS delivery, faster releases, and customer feedback loops shaped Jeff’s approach<br/><br/>Lessons from taking platforms through Low and Moderate ATOs with speed and cost control<br/><br/>Why FedRAMP 20x matters for automation, machine-readable controls, and audit reuse<br/><br/>The program management skills that keep complex portfolios on track<br/><br/>How Customer Success aligns security outcomes, business value, and long-term relationships<br/><br/>Highlights<br/><br/>From support queues to SaaS startup life in Austin<br/><br/>Dell and the pivot to cloud offerings<br/><br/>Two ATOs in two years and what changed<br/><br/>Using compliance to improve engineering hygiene and costs<br/><br/>Evergreen culture, coaching, and building teams that last<br/><br/>Subscribe for more Behind the Shield conversations on building, managing, and defending in the federal cloud.</p>]]></description>
    <content:encoded><![CDATA[<p>Behind the Shield- Episode 5 <br/><br/>Meet our new VP of Customer Success, Jeff Bivens. Jeff shares his path from late-90s client-server to SaaS, through a Dell acquisition and multiple ATOs, to why he joined InfusionPoints now. We dig into how strong program management turns compliance into momentum, how FedRAMP 20x can lower barriers without lowering security, and why “customer success” in public sector means repeatable outcomes, faster audits, and durable trust. We also touch on AI’s role in detection and operations, evergreen company values, and what changes when a services firm becomes a true cloud service provider.<br/><br/>What you’ll learn:<br/><br/>How SaaS delivery, faster releases, and customer feedback loops shaped Jeff’s approach<br/><br/>Lessons from taking platforms through Low and Moderate ATOs with speed and cost control<br/><br/>Why FedRAMP 20x matters for automation, machine-readable controls, and audit reuse<br/><br/>The program management skills that keep complex portfolios on track<br/><br/>How Customer Success aligns security outcomes, business value, and long-term relationships<br/><br/>Highlights<br/><br/>From support queues to SaaS startup life in Austin<br/><br/>Dell and the pivot to cloud offerings<br/><br/>Two ATOs in two years and what changed<br/><br/>Using compliance to improve engineering hygiene and costs<br/><br/>Evergreen culture, coaching, and building teams that last<br/><br/>Subscribe for more Behind the Shield conversations on building, managing, and defending in the federal cloud.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18089566-from-saas-to-fedramp-20x-meet-jeff-bivens-vp-of-customer-success.mp3" length="42085310" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18089566</guid>
    <pubDate>Tue, 28 Oct 2025 11:00:00 -0400</pubDate>
    <itunes:duration>3504</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>5</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Abolish Screenshots and Ship Security: FedRAMP 20x with Ethan Troy</itunes:title>
    <title>Abolish Screenshots and Ship Security: FedRAMP 20x with Ethan Troy</title>
    <itunes:summary><![CDATA[Behind the Shield- Episode 4: FedRAMP 20x, KSIs, and the End of Screenshots (with Fortreum’s Ethan Troy &amp; InfusionPoints’ Tanner Bailey)  In this episode we explore how FedRAMP 20x is changing audits. Instead of relying on screenshots, auditors now focus on scripts, APIs, and code logic. Host Gary Daemer sits down with InfusionPoints’ Tanner Bailey and Fortreum’s Ethan Troy to talk about KSIs, Trust Centers, and the skills auditors need for the future.  What you’ll learn:  Why screenshots...]]></itunes:summary>
    <description><![CDATA[<p><b>Behind the Shield- Episode 4:</b><br/>FedRAMP 20x, KSIs, and the End of Screenshots (with Fortreum’s Ethan Troy &amp; InfusionPoints’ Tanner Bailey)<br/><br/>In this episode we explore how FedRAMP 20x is changing audits. Instead of relying on screenshots, auditors now focus on scripts, APIs, and code logic. Host Gary Daemer sits down with InfusionPoints’ Tanner Bailey and Fortreum’s Ethan Troy to talk about KSIs, Trust Centers, and the skills auditors need for the future.<br/><br/>What you’ll learn:<br/><br/>Why screenshots are being replaced with automated, repeatable checks<br/><br/>How KSIs and themes make audits clearer and faster<br/><br/>Trust Centers built on JSON and Markdown instead of PDFs<br/><br/>Why auditors must understand Python, Linux, networking, and infrastructure as code<br/><br/>How InfusionPoints is building AuditShield and Command Center to support FedRAMP 20x<br/><br/>Host: <br/>Gary Daemer – CEO and Founder of InfusionPoints<br/>Guests:<br/>Ethan Troy – Assessor at Fortreum, focused on technical audits and code review<br/>Tanner Bailey – Advisory team lead at InfusionPoints and coordinator for the 20x project<br/><br/>Subscribe for more conversations on FedRAMP, audit automation, and the future of cloud security.<br/><br/>#FedRAMP #FedRAMP20x #AuditAutomation #CloudSecurity #InfusionPoints #Fortreum</p>]]></description>
    <content:encoded><![CDATA[<p><b>Behind the Shield- Episode 4:</b><br/>FedRAMP 20x, KSIs, and the End of Screenshots (with Fortreum’s Ethan Troy &amp; InfusionPoints’ Tanner Bailey)<br/><br/>In this episode we explore how FedRAMP 20x is changing audits. Instead of relying on screenshots, auditors now focus on scripts, APIs, and code logic. Host Gary Daemer sits down with InfusionPoints’ Tanner Bailey and Fortreum’s Ethan Troy to talk about KSIs, Trust Centers, and the skills auditors need for the future.<br/><br/>What you’ll learn:<br/><br/>Why screenshots are being replaced with automated, repeatable checks<br/><br/>How KSIs and themes make audits clearer and faster<br/><br/>Trust Centers built on JSON and Markdown instead of PDFs<br/><br/>Why auditors must understand Python, Linux, networking, and infrastructure as code<br/><br/>How InfusionPoints is building AuditShield and Command Center to support FedRAMP 20x<br/><br/>Host: <br/>Gary Daemer – CEO and Founder of InfusionPoints<br/>Guests:<br/>Ethan Troy – Assessor at Fortreum, focused on technical audits and code review<br/>Tanner Bailey – Advisory team lead at InfusionPoints and coordinator for the 20x project<br/><br/>Subscribe for more conversations on FedRAMP, audit automation, and the future of cloud security.<br/><br/>#FedRAMP #FedRAMP20x #AuditAutomation #CloudSecurity #InfusionPoints #Fortreum</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18049348-abolish-screenshots-and-ship-security-fedramp-20x-with-ethan-troy.mp3" length="27543465" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18049348</guid>
    <pubDate>Tue, 21 Oct 2025 11:00:00 -0400</pubDate>
    <itunes:duration>2292</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>4</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Introducing Chad Spears &amp; A Deep Dive into FedRAMP 20x</itunes:title>
    <title>Introducing Chad Spears &amp; A Deep Dive into FedRAMP 20x</title>
    <itunes:summary><![CDATA[ Behind the Shield - Episode 3:  Meet one of our hosts, Chad Spears (Director of Security Operations at InfusionPoints), as he sits down with Gary Daemer to talk about the journey from hands-on IT to leading a modern SOC, the power of automation, and how FedRAMP 20x is reshaping audits, evidence, and continuous monitoring.  What you’ll learn  How a major ransomware event shaped Chad’s approach to defense and incident response  Why we split Security Operations and Security Engineerin...]]></itunes:summary>
    <description><![CDATA[<p> Behind the Shield - Episode 3: <br/>Meet one of our hosts, Chad Spears (Director of Security Operations at InfusionPoints), as he sits down with Gary Daemer to talk about the journey from hands-on IT to leading a modern SOC, the power of automation, and how FedRAMP 20x is reshaping audits, evidence, and continuous monitoring.<br/><br/>What you’ll learn<br/><br/>How a major ransomware event shaped Chad’s approach to defense and incident response<br/><br/>Why we split Security Operations and Security Engineering to scale outcomes<br/><br/>The origin of AuditShield and what “automated evidence collection” looks like in practice<br/><br/>The core goals of FedRAMP 20x: automation, inheritance, continuous monitoring, trust, and faster innovation<br/><br/>Phase 1 lessons and our path into Phase 2 (Moderate), including KSI validation, self-healing remediations, and significant change notifications<br/><br/>How Command Center, Trust Center, and VDR (“Vader”) tie into faster ATOs and better agency confidence<br/><br/>Subscribe for more conversations on FedRAMP, automation, and security engineering.<br/>Watch, comment, and tell us what you want covered next.<br/><br/><br/></p>]]></description>
    <content:encoded><![CDATA[<p> Behind the Shield - Episode 3: <br/>Meet one of our hosts, Chad Spears (Director of Security Operations at InfusionPoints), as he sits down with Gary Daemer to talk about the journey from hands-on IT to leading a modern SOC, the power of automation, and how FedRAMP 20x is reshaping audits, evidence, and continuous monitoring.<br/><br/>What you’ll learn<br/><br/>How a major ransomware event shaped Chad’s approach to defense and incident response<br/><br/>Why we split Security Operations and Security Engineering to scale outcomes<br/><br/>The origin of AuditShield and what “automated evidence collection” looks like in practice<br/><br/>The core goals of FedRAMP 20x: automation, inheritance, continuous monitoring, trust, and faster innovation<br/><br/>Phase 1 lessons and our path into Phase 2 (Moderate), including KSI validation, self-healing remediations, and significant change notifications<br/><br/>How Command Center, Trust Center, and VDR (“Vader”) tie into faster ATOs and better agency confidence<br/><br/>Subscribe for more conversations on FedRAMP, automation, and security engineering.<br/>Watch, comment, and tell us what you want covered next.<br/><br/><br/></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/18008965-introducing-chad-spears-a-deep-dive-into-fedramp-20x.mp3" length="33083072" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18008965</guid>
    <pubDate>Tue, 14 Oct 2025 09:00:00 -0400</pubDate>
    <itunes:duration>2754</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>3</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>From Rev4 to FedRAMP 20x: Faster ATOs &amp; AI — with Said Syed (Snyk)</itunes:title>
    <title>From Rev4 to FedRAMP 20x: Faster ATOs &amp; AI — with Said Syed (Snyk)</title>
    <itunes:summary><![CDATA[Behind the Shield – Episode 2:  In our first episode featuring a guest, hosts Jason Shropshire and Jason Redding sit down with a public-sector security leader, Said Syed, CISO Snyk for Government, to unpack the real story behind FedRAMP—from the messy early days and the shared-responsibility model, to today’s accelerated authorizations and the 20x roadmap. We cover hard-won lessons, how process (not just tech) slows teams down, what RC-12 means for vulnerability reality checks, and where...]]></itunes:summary>
    <description><![CDATA[<p>Behind the Shield – Episode 2: <br/>In our first episode featuring a guest, hosts Jason Shropshire and Jason Redding sit down with a public-sector security leader, Said Syed, CISO Snyk for Government, to unpack the real story behind FedRAMP—from the messy early days and the shared-responsibility model, to today’s accelerated authorizations and the 20x roadmap. We cover hard-won lessons, how process (not just tech) slows teams down, what RC-12 means for vulnerability reality checks, and where AI, KSIs, and agency expectations are heading next.<br/><br/>What you’ll learn:<br/><br/>How early cloud providers navigated FedRAMP before inheritable controls were common<br/><br/>Why the process—and acceptance criteria—trips up most teams more than technology<br/><br/>The shift from Rev4 → Rev5 and how to plan upgrades without derailing product roadmaps<br/><br/>20x Phase 1 outcomes, the move to Moderate (Phase 2), and what faster ATOs mean for SaaS<br/><br/>RC-12, “reachable ≠ accessible,” and pushing back on non-applicable vulns with evidence<br/><br/>Practical ways to use opinionated architectures, automation, and live evidence collection<br/><br/>Sensible guardrails for AI features in regulated environments<br/><br/>Mentioned:<br/><br/>Snyk Government: security in modern DevSecOps pipelines<br/><br/>InfusionPoints XBU40 + Command Center + AuditShield: “audit-ready, always-on” compliance<br/><br/>FedRAMP Day at GSA and growing marketplace velocity<br/><br/><br/>Subscribe for new episodes on FedRAMP 20x, ATO strategy, and real-world build/manage/defend tactics coming out every Tuesday.<br/><br/>Have a FedRAMP question? Drop it in the comments or reach out to InfusionPoints. <br/><br/>#fedramp #fedramp20x #govcloud #ATO #GRC #cybersecurity #devsecops #snyk #infusionpoints<br/><br/>Links:<br/>• Learn more about InfusionPoints: https://infusionpoints.com/<br/>• Learn more about Snyk: https://snyk.io/<br/>• Connect with us on LinkedIn: https://www.linkedin.com/company/infusionpoints</p>]]></description>
    <content:encoded><![CDATA[<p>Behind the Shield – Episode 2: <br/>In our first episode featuring a guest, hosts Jason Shropshire and Jason Redding sit down with a public-sector security leader, Said Syed, CISO Snyk for Government, to unpack the real story behind FedRAMP—from the messy early days and the shared-responsibility model, to today’s accelerated authorizations and the 20x roadmap. We cover hard-won lessons, how process (not just tech) slows teams down, what RC-12 means for vulnerability reality checks, and where AI, KSIs, and agency expectations are heading next.<br/><br/>What you’ll learn:<br/><br/>How early cloud providers navigated FedRAMP before inheritable controls were common<br/><br/>Why the process—and acceptance criteria—trips up most teams more than technology<br/><br/>The shift from Rev4 → Rev5 and how to plan upgrades without derailing product roadmaps<br/><br/>20x Phase 1 outcomes, the move to Moderate (Phase 2), and what faster ATOs mean for SaaS<br/><br/>RC-12, “reachable ≠ accessible,” and pushing back on non-applicable vulns with evidence<br/><br/>Practical ways to use opinionated architectures, automation, and live evidence collection<br/><br/>Sensible guardrails for AI features in regulated environments<br/><br/>Mentioned:<br/><br/>Snyk Government: security in modern DevSecOps pipelines<br/><br/>InfusionPoints XBU40 + Command Center + AuditShield: “audit-ready, always-on” compliance<br/><br/>FedRAMP Day at GSA and growing marketplace velocity<br/><br/><br/>Subscribe for new episodes on FedRAMP 20x, ATO strategy, and real-world build/manage/defend tactics coming out every Tuesday.<br/><br/>Have a FedRAMP question? Drop it in the comments or reach out to InfusionPoints. <br/><br/>#fedramp #fedramp20x #govcloud #ATO #GRC #cybersecurity #devsecops #snyk #infusionpoints<br/><br/>Links:<br/>• Learn more about InfusionPoints: https://infusionpoints.com/<br/>• Learn more about Snyk: https://snyk.io/<br/>• Connect with us on LinkedIn: https://www.linkedin.com/company/infusionpoints</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/17971745-from-rev4-to-fedramp-20x-faster-atos-ai-with-said-syed-snyk.mp3" length="30991001" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17971745</guid>
    <pubDate>Tue, 07 Oct 2025 13:00:00 -0400</pubDate>
    <itunes:duration>2579</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>2</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Origins of InfusionPoints &amp; the Future of FedRAMP</itunes:title>
    <title>The Origins of InfusionPoints &amp; the Future of FedRAMP</title>
    <itunes:summary><![CDATA[Behind the Shield- Episode 1:  In the premiere episode of Behind the Shield, hosts Gary Daemer (CEO of InfusionPoints) and Jason Shropshire (COO) share the story of InfusionPoints’ journey from its early federal and commercial projects to becoming a leader in cloud compliance and security engineering. They discuss how the rise of FedRAMP in 2012 pushed the team to pioneer automation, compliance-as-code, and platform engineering long before it became industry standard. Listeners will hear...]]></itunes:summary>
    <description><![CDATA[<p>Behind the Shield- Episode 1: <br/>In the premiere episode of Behind the Shield, hosts Gary Daemer (CEO of InfusionPoints) and Jason Shropshire (COO) share the story of InfusionPoints’ journey from its early federal and commercial projects to becoming a leader in cloud compliance and security engineering. They discuss how the rise of FedRAMP in 2012 pushed the team to pioneer automation, compliance-as-code, and platform engineering long before it became industry standard.<br/>Listeners will hear candid stories about the “hardware days” of building compliant systems, the painful lessons learned from InfusionPoints’ first customers, and how those experiences fueled the creation of the XccelerATOr platform—a solution that helps SaaS providers accelerate their ATO journey. The conversation also dives into the evolution of platform engineering, opinionated architectures, and the Command Center, InfusionPoints’ “crown jewel” for managing compliance, risk, vulnerabilities, and evidence in a single pane of glass.<br/>This episode sets the stage for the Behind the Shield series: authentic conversations about the challenges, innovations, and future of federal cloud security and compliance—with insights drawn from real-world engineering, not just theory.</p>]]></description>
    <content:encoded><![CDATA[<p>Behind the Shield- Episode 1: <br/>In the premiere episode of Behind the Shield, hosts Gary Daemer (CEO of InfusionPoints) and Jason Shropshire (COO) share the story of InfusionPoints’ journey from its early federal and commercial projects to becoming a leader in cloud compliance and security engineering. They discuss how the rise of FedRAMP in 2012 pushed the team to pioneer automation, compliance-as-code, and platform engineering long before it became industry standard.<br/>Listeners will hear candid stories about the “hardware days” of building compliant systems, the painful lessons learned from InfusionPoints’ first customers, and how those experiences fueled the creation of the XccelerATOr platform—a solution that helps SaaS providers accelerate their ATO journey. The conversation also dives into the evolution of platform engineering, opinionated architectures, and the Command Center, InfusionPoints’ “crown jewel” for managing compliance, risk, vulnerabilities, and evidence in a single pane of glass.<br/>This episode sets the stage for the Behind the Shield series: authentic conversations about the challenges, innovations, and future of federal cloud security and compliance—with insights drawn from real-world engineering, not just theory.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2541472/episodes/17933154-the-origins-of-infusionpoints-the-future-of-fedramp.mp3" length="23071798" type="audio/mpeg" />
    <itunes:author>InfusionPoints</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17933154</guid>
    <pubDate>Tue, 30 Sep 2025 12:00:00 -0400</pubDate>
    <itunes:duration>1920</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>1</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
</channel>
</rss>
