Cuick 10 Podcast

The Cuick 10 Podcast, hosted by Cuick Trac, covers all things cybersecurity, from all different perspectives and personalities across the FedCon and Cyber Defense industry. All in 10 (ish) minutes. 

Listen on these platforms:

Sign up for alerts on new podcasts:

Episodes:

Identifying CUI in the Supply Chain

In this episode of the Cuick 10 Podcast, Derek White, Chief Operating Officer of Cuick Trac, is joined by Alex Major, Partner & Co-Leader of the Government Contracts and Global Trade Group at McCarter & English, to discuss the challenges organizations face when identifying Controlled Unclassified Information (CUI).

Alex explains why CUI identification has become one of the most critical components of CMMC compliance and how confusion across government agencies, prime contractors, and suppliers creates risk throughout the Defense Industrial Base. The conversation explores how contractors should approach CUI policies, what role supply chain partners play in CUI flowdown, and why organizations must clearly understand what information they are required to protect.

Tune in for practical insights on navigating CUI identification and strengthening compliance across the supply chain.

What Makes a Great CMMC Consultant

To kick off Season 3, Derek White, COO of Cuick Trac, sits down with Kyle Lai, President & CISO at KLC Consulting, to discuss what makes someone truly effective in the CMMC consulting space. Kyle brings unique perspective as both an experienced assessor and a trusted advisor to organizations navigating DFARS, NIST 800-171, and CMMC compliance.

In this episode, they explore what separates technical know-how from true client impact—from soft skills like listening and empathy to real-life stories of consulting gone wrong (and right).

FIPS Encryption, Governance & Growth Strategy

In this episode of the Cuick 10 Podcast, Derek White, Chief Operating Officer of Cuick Trac, is joined by James Harper, CEO at Quatronics, to break down FIPS encryption, validated crypto modules, and how governance underpins both CMMC compliance and long-term company growth.

James shares real-world examples of where small businesses stumble—from improper data mapping to lack of documented roles—and explains how CMMC can be a catalyst for sustainable scaling. If you’ve ever asked, “Do I really need FIPS validated equipment?” or struggled to track CUI across your team, this one’s for you.

CMMC as a Value Multiplier

In this episode of the Cuick 10 Podcast, Derek White, Chief Operating Officer of Cuick Trac, sits down with Jeff Smedley, retired CIO and CMMC strategy consultant, to explore how CMMC can go beyond compliance to drive organizational value.

Jeff shares how his company achieved a perfect assessment score and leveraged CMMC to unlock board alignment, private equity support, and a billion-dollar exit. From cultural transformation to financial metrics, this conversation reframes CMMC as a growth opportunity—not just a mandate.

What CMMC Assessors Want You to Know

In this episode of the Cuick 10 Podcast, Derek White, Chief Operating Officer of Cuick Trac, is joined by Brad Taylor, Senior Information Security Consultant at Foregenix, to explore what goes into a successful CMMC assessment from the assessor’s perspective. Brad shares insights from a recent real-world engagement, including how strong inheritance documentation, pre-assessment reviews, and clear traceability helped one OSC complete their assessment in under two days.

This episode is full of practical tips for preparing your environment, aligning your SSP and policies, and ensuring your team is ready to show up informed and confident.

Can We Standardize Cybersecurity Across Agencies?

In this episode of the Cuick 10 Podcast, Derek White, Chief Operating Officer of Cuick Trac, is joined by Heather Siemens, CEO of iFortress, to explore the growing call for standardization across federal cybersecurity frameworks — particularly for contractors serving both defense and energy sectors.

Heather shares lessons from her background in NERC compliance, the challenge of overlapping frameworks like NIST SP 800-171 and NIST 800-161, and what needs to happen for agencies like DoD, DOE, and DHS to speak a common cybersecurity language.

🍪 We Use Cookies

To enhance your experience and analyze site usage, we use cookies. By continuing to use our site, you agree to our use of cookies in accordance with our Privacy Policy.