AI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News – Keith Hollender – ESW #468
Interview with Keith Hollender, CEO and Co-Founder of Arcova
Why AI Security Is Becoming an Execution Problem, Not Just a Governance ProblemAs enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introducing unmanaged risk. The challenge is no longer whether organizations should pursue AI, but how they can govern it, secure it, and operationalize it in ways that stand up to real-world business and threat conditions.In this conversation, Keith Hollender discusses what Arcova is seeing across enterprise environments as organizations work to connect cybersecurity, AI governance, resilience, and broader transformation priorities. He explores where companies are getting stuck, why traditional siloed approaches are falling short, and what it takes to move from strategy decks to secure execution.Keith also shares how Arcova’s practitioner-led, relationship-driven model helps organizations turn complexity into clarity by embedding with client teams, solving urgent problems hands-on, and building capabilities designed to last. The conversation also covers Arcova’s continued growth, including expansion into the Middle East, and what global demand signals reveal about the next phase of cybersecurity and AI consulting.Segment Resources:For more information about Arcova and how they can help your enterprise shape what's next, please visit:https://securityweekly.com/arcovaTopic: CMMC Pause creating chaos among federal contractors
This one sent some shockwaves through the CMMC community, particularly the hundreds or thousands of folks gearing up to assist with the validation that phase 2 aimed to provide. The TL;DR - defense contractors have been required to comply with CMMC controls for years, but self-attestation means that many probably haven't been meeting the requirements. Perhaps, rather than have tons of defense contractors fail the test, they just suspended the requirement for the test itself.I think Howard Holton nails it here when he says:"100,000 defense contractors needed third-party assessments. Roughly 100 authorized assessors exist. That's 1,000 assessments each, with the deadline in November."PCI already created a model that works for a scenario like this. If you're small, you self-assess. If you're big enough, an independent auditor comes to check you out once a year. I'm sure they were probably aware of this and chose not to go down that path for some reasons. I'm not aware of those reasons.What this means:- Phase II is paused
- Phase I self-assessments still in place (note, however, that phase II existed, because self-attestation didn't work)
- NIST SP 800-171 Rev 2 and DFARS 252.204-7012 compliance still required
- 60-day review aims to reform CMMC
- DoW opened an RFI for industry perspectives on what they should do
- CMMC characterized as a "compliance burden" and "red tape"
- False Claims Act and DOJ's cyber-fraud enforcement are still on the table
- CIO Davies' post on Twitter
- Administrator of the Small Business Administration, Kelly Loeffler's post
- A useful LinkedIn post that breaks down a lot of what this really means (and doesn't)
Weekly Enterprise News
Finally, in the enterprise security news,- will AI eliminate more cybersecurity jobs than it creates?
- Linus’s law, amended
- the biggest patch Tuesday ever
- AI context bombs
- AI workflows are a security disaster
- people using AI in areas they don’t understand
- ransomware crews are hitting legal firms hard
- lessons learned from CISA’s recent github leak
- demystify your USB cables!
Keith Hollender is the CEO and Co-Founder of Arcova, a leading cybersecurity advisory
and managed services firm formed from the former MorganFranklin Cyber business. With
more than two decades of experience spanning cybersecurity, strategy, and financial
services, Keith has built a distinguished career leading security transformation initiatives
for complex global organizations. In addition to his leadership at Arcova, Keith serves on
the Cybersecurity Board at Seton Hall University and has contributed thought leadership
to numerous industry publications.
Prior to co-founding Arcova, Keith held senior information security leadership roles at a
Fortune 200 financial institution, where he was responsible for cybersecurity strategy,
planning, governance, and budget management. His portfolio included oversight of
security awareness and training, communications, metrics and reporting, and the
development of a cross-functional offshore Center of Excellence (COE). Earlier in his
career, he served as Head of Strategic Planning & Analysis for Global Information
Security at a Fortune 50 Financial Services firm. He has held a variety of strategy,
planning, and analytical leadership positions at both Citi and Goldman Sachs earlier in his
career.
Keith earned his MBA, summa cum laude, from Rutgers University and holds a Bachelor
of Business Administration in Finance from Seton Hall University. He also maintains
several industry-recognized cybersecurity certifications, including CompTIA Security+
(DoD 8140/8570, ISO 17024), ISACA Certified Data Privacy Solutions Engineer (CDPSE)
and IMI Certified Identity & Access Manager (CIAM).
- Security leaders, your vulnerability program is overloaded. Thousands of findings, limited resources, and no clear way to prioritize what actually matters to the business.Meanwhile, regulators and boards expect measurable risk reduction, not just scan results.Join the Vulnerability Management Virtual Cybersecurity Summit on July 29th to learn how leading organizations are shifting from volume to risk-based prioritization and turning exposure into actionable strategy.Security Weekly listeners can register for free at https://securityweekly.com/vulnmanagement using the promo code: CSS26-SW
- CyberRisk TV is proud to be an official media partner of Black Hat USA 2026! We'll be broadcasting live from the Black Hat LIVEWIRE Studio with executive interviews focused on the technologies and strategies helping enterprise security teams defend modern organizations.Our Event Momentum Packages extend your reach to analysts, practitioners, and security leaders well beyond the conference. Fewer than 10 interview opportunities remain, so visit https://securityweekly.com/exec today and reserve your spot before they're gone.
Adrian Sanabria
- FUNDING/M&A, courtesy of the Security, Funded newsletter, issue #252 – Big Key Energy
VIBE CHECK
Will AI eliminate more cybersecurity jobs than it creates?
- 66% - Same jobs, just retitled
- 22% - Net job destroyer
- 11% - Net job creator
- 0% - Something different
Coincidentally, I was just a guest on Simply Cyber, and the topic was "AI is not coming for your job"
FUNDING
Slow week, everyone is probably waiting until we're a little closer to Black Hat to announce?
- Keyfactor, a United States-based private key infrastructure (PKI) management platform for human and machine identities, raised a $1.0B Private Equity from Summit Partners.
ACQUISITIONS
- Evo Security, a United States-based managed identity and access management platform for MSSPs, was acquired by Barracuda Networks for an undisclosed amount. Evo Security had previously raised $16.3M in funding.
- Kentik, a United States-based network detection and response (NDR) platform, was acquired by Infoblox for an undisclosed amount. Kentik had previously raised $40.0M in funding.
- ESSAY: The Amended Linus’s Law
- VULN MGMT: Microsoft Patch Tuesday July 2026 – The AI Acopolypse is Here
We suspected it was coming, and oh boy is it here. One Patch Tuesday. 622 patches.
Except that none of these vulnerabilities seem all that urgent, and applying them hasn't gone smoothly for everyone.
- RESEARCH: Context bombs: stopping AI attackers in their tracks
A novel way to stop an AI attack: trigger the model's guardrails on purpose.
- AI CHALLENGES: AI-Generated Workflows Are a Silent Security Disaster
- AI CHALLENGES: One of the more annoying parts of being the team that enables AI: you inherit everyone else’s nonsense
"One of the more annoying parts of being the team that enables AI: you inherit everyone else's nonsense.
I've heard from IT and corpsec teams dealing with: - a lot of rogue OpenClaw. A lot. Even after being removed and wiped, even after being reprimanded and told to stop it or else (not so much Hermes but who's looking?) - a $10k+ token bill, because someone who didn't know how to use pivot tables used a model to parse a CSV (poorly) - trying to decide what to do when someone talks to the AI in a way that would get them fired if it were a coworker
It's all the worst parts of IT and security in one: open networks, nonsense costs, having to pull in HR/legal. Pour one out for whoever owns this. (We were already installing Steam on our work laptops, sure, but... come on.)"
- BREACHES: Top-100 Law Firm Fox Rothschild Suffers Data Breach and Leak by Silent Ransom Group – DataBreaches.Net
Law firms are systematically getting hit with ransomware. There are crews that seem to find it easier to specialize in a single vertical at a time.
- BREACHES: Lessons Learned from CISA’s Recent GitHub Leak – Krebs on Security
Some very interesting details and lessons learned from CISA's infamous open GitHub repo incident.
- SQUIRREL: WhatCable: Know what your USB-C cable can really do
Deliciously nerdy.









