# Cyberuptive > Cyberuptive is a U.S. managed security services provider (MSSP) and MDR provider headquartered in Honolulu, Hawaii. We deliver 24/7 SOC, managed detection and response, incident response, vulnerability management, penetration testing, Microsoft 365 and Azure security, managed firewall, and CMMC 2.0 compliance support for defense contractors and regulated mid-market organizations across the United States. ## About - Website: https://www.cyberuptive.com - Phone: 833-92-CYBER (833-922-9237) - Email: info@cyberuptive.com - Headquarters: 401 Kamakee St #204, Honolulu, HI 96814 - Service area: United States (primary), with commercial delivery in Asia-Pacific and Europe - Primary buyers: defense contractors and subcontractors handling CUI, plus regulated healthcare, financial services, insurance, legal, manufacturing, and shipping organizations - About page: https://www.cyberuptive.com/about/ ## What makes Cyberuptive different - **Segregated U.S. SOC**: The U.S. SOC is physically and logically segregated from any other operation and is staffed by U.S.-based analysts. Asia-Pacific commercial clients are also served from the U.S. SOC; international operations do not access U.S. federal or CUI telemetry. - **Built for CMMC and DFARS customers**: Operating procedures, evidence collection, and reporting are designed around NIST SP 800-171, DFARS 252.204-7012, and CMMC 2.0 Level 2 expectations. - **Trellix-powered detection stack**: Trellix Helix XDR, EDR, NX, ETP, and Threat Intelligence form a single correlated detection pipeline. Cyberuptive can also operate customer-owned tools such as CrowdStrike Falcon and Microsoft Defender. - **Vendor-neutral on firewalls and identity**: Fortinet, Palo Alto Networks, Cisco Meraki, and Cloudflare on the perimeter; Microsoft 365, Entra ID, and Azure (including GCC High) on identity. - **Pacific time-zone coverage**: HST-based primary SOC. Issues raised overnight in Hawaii are worked in real time, not queued for a morning shift. ## Services - [Managed AWS Security & Monitoring, 24/7](https://www.cyberuptive.com/services/aws-security/): 24/7 managed AWS security: CloudTrail, GuardDuty, and Security Hub monitoring correlated with endpoint and identity in Trellix Helix XDR. GovCloud by US persons. - [CMMC Consultant & NIST 800-171 Compliance](https://www.cyberuptive.com/services/cmmc-compliance/): CMMC consultants for CMMC 2.0 Level 1 and Level 2. NIST 800-171 gap assessments, SSP, POA&M, SPRS scoring, GCC High and 24/7 SOC for U.S. defense contractors nationwide. - [Incident Response Retainer for Defense Contractors](https://www.cyberuptive.com/services/incident-response/): An incident response retainer built around DFARS 252.204-7012: 72-hour DIBNet reporting, 90-day evidence preservation, and US-persons responders on call 24/7. - [Managed Detection and Response Provider](https://www.cyberuptive.com/services/managed-detection-response/): A managed detection and response provider that contains, not just alerts. MDR across endpoint, identity and cloud on CrowdStrike and Trellix, monitored 24/7 by U.S. analysts. - [Managed Firewall](https://www.cyberuptive.com/services/managed-firewall/): Managed next-generation firewall, SASE, and ZTNA from a Hawaii MSSP. 24/7 policy management, threat prevention, and CMMC-aligned configuration baselines. - [Microsoft 365 & Azure Security](https://www.cyberuptive.com/services/microsoft-365-azure-security/): Managed Microsoft 365 and Azure security: identity, email, Teams, Entra ID, Defender XDR, Sentinel SIEM, and tenant hardening including GCC High for CMMC. - [NIS2 & DORA Compliance](https://www.cyberuptive.com/services/nis2-dora-compliance/): Audit-ready NIS2 and DORA readiness: scoping, gap analysis, governance, supply chain controls, and incident reporting: delivered by an EU-resident team. - [Patch Management](https://www.cyberuptive.com/services/patch-management/): Managed patch management for endpoints, servers, and third-party apps. Risk-based prioritization, maintenance windows, exceptions, and audit-ready reports. - [Penetration Testing Services](https://www.cyberuptive.com/services/penetration-testing/): Penetration testing services for defense, healthcare, finance, and regulated organizations. External, internal, web app, cloud, and M365: assessor-ready. - [SOC as a Service](https://www.cyberuptive.com/services/soc-as-a-service/): SOC as a Service from a U.S.-based managed SOC provider: 24/7 monitoring, triage and pre-authorized containment. Co-managed for Microsoft 365, Azure, Sentinel and Defender XDR. - [Managed Trellix XDR & Helix SOC Services](https://www.cyberuptive.com/services/trellix-xdr/): Managed Trellix Helix XDR from a Trellix delivery partner: 24/7 US-based SOC, detection tuning, threat hunting, and response on the Trellix stack you already own. - [Virtual CISO Services (vCISO)](https://www.cyberuptive.com/services/virtual-ciso/): Virtual CISO services for regulated mid-market organizations. A named, U.S.-based security leader who owns your roadmap, board reporting, risk register and CMMC, HIPAA or GLBA program. Fractional CISO engagements from 8 hours a month. - [Vulnerability Scanning](https://www.cyberuptive.com/services/vulnerability-scanning/): Continuous vulnerability scanning, prioritization, and remediation tracking from a Hawaii MSSP. Tenable/Qualys/Rapid7 expertise; CMMC, HIPAA, PCI reports. - [Zero Trust Security](https://www.cyberuptive.com/services/zero-trust/): Zero Trust Security for M365 and Azure: identity-centric access, least privilege, device posture, segmentation, and conditional access: audit-ready. ## Industries - [MSSP for U.S. DoW Contractors](https://www.cyberuptive.com/industries/dod-contractors/): MSSP for U.S. defense contractors handling CUI: CMMC 2.0, NIST 800-171, DFARS 252.204-7012, SPRS, SSP, POA&M, and 24/7 SOC: nationwide. - [Financial Services Cybersecurity](https://www.cyberuptive.com/industries/financial-services/): NCUA-aligned cybersecurity for credit unions, GLBA Safeguards for community banks, and FFIEC CAT alignment from a Hawaii MSSP with US analysts. - [Healthcare Cybersecurity](https://www.cyberuptive.com/industries/healthcare/): HIPAA-aligned cybersecurity for hospitals, clinics, and medical practices. EHR-aware monitoring, breach response, and OCR-ready documentation. - [Insurance Cybersecurity](https://www.cyberuptive.com/industries/insurance/): Cybersecurity for insurance carriers, MGAs, and agencies: policyholder PII, NAIC alignment, claims third-party risk, ransomware, and incident response. - [Law Firm Cybersecurity](https://www.cyberuptive.com/industries/legal/): Cybersecurity for law firms: client confidentiality, BEC defense, M365/Azure hardening, endpoint security, vulnerability management, and 24/7 IR. - [Manufacturing Cybersecurity](https://www.cyberuptive.com/industries/manufacturing/): Cybersecurity for manufacturers: ransomware containment, endpoint visibility, vulnerability management, OT/IT segmentation, and supplier requirements. - [Shipping & Logistics Cybersecurity](https://www.cyberuptive.com/industries/shipping-logistics/): Cybersecurity for shipping and logistics: site uptime, fleet and warehouse systems, BEC defense, M365/Azure hardening, MDR/SOC, and continuity. - [Mid-Market MSSP](https://www.cyberuptive.com/industries/smb/): Real cybersecurity for Hawaii and U.S. medium and large businesses: 24/7 SOC, M365 hardening, vulnerability management, and cyber-insurance support. ## Free readiness assessments Each assessment returns a branded PDF report to the visitor. - [CMMC Readiness Assessment](https://www.cyberuptive.com/industries/dod-contractors/assessment/) - [Financial Services Assessment](https://www.cyberuptive.com/industries/financial-services/assessment/) - [HIPAA Compliance Assessment](https://www.cyberuptive.com/industries/healthcare/assessment/) - [Insurance Security Assessment](https://www.cyberuptive.com/industries/insurance/assessment/) - [Law Firm Security Assessment](https://www.cyberuptive.com/industries/legal/assessment/) - [Manufacturing Cybersecurity Assessment](https://www.cyberuptive.com/industries/manufacturing/assessment/) - [Shipping & Logistics Cybersecurity Assessment](https://www.cyberuptive.com/industries/shipping-logistics/assessment/) ## Resources - [CMMC 2.0 Readiness Checklist](https://www.cyberuptive.com/resources/cmmc-readiness-checklist/): A 43-point CMMC 2.0 readiness checklist for mid-market defense subcontractors, NIST 800-171 controls mapped to common gaps, with remediation guidance. - [Credit Union Exam-Readiness Checklist](https://www.cyberuptive.com/resources/credit-union-exam-readiness-checklist/): A 40-point exam-readiness checklist for credit unions and community financial institutions, organized around what NCUA and state examiners actually ask to see. - [HIPAA Security Rule Readiness Checklist](https://www.cyberuptive.com/resources/hipaa-security-rule-readiness-checklist/): A 40-point HIPAA Security Rule readiness checklist for clinics, practices, and health systems, covering Administrative, Physical, and Technical Safeguards. - [Managed SOC Pricing Guide for Mid-Market (2026)](https://www.cyberuptive.com/resources/managed-soc-pricing-guide/): A buyer's guide to managed SOC pricing for medium and large businesses in 2026, pricing models, drivers of variance, and red flags to watch. - [Shipping & Logistics Cybersecurity Checklist](https://www.cyberuptive.com/resources/shipping-logistics-cybersecurity-checklist/): A 45-point cybersecurity readiness checklist for freight, trucking, warehousing, and terminal operators, mapped to wire fraud, ransomware, and the new USCG marine cyber rule. ## Defense contractor and CMMC buyer guides - [MDR for Defense Contractors: US-Persons Managed Detection & Response](https://www.cyberuptive.com/mdr-for-defense-contractors/): Managed Detection and Response for U.S. defense contractors: US-persons SOC, CMMC/DFARS-aligned, EDR-agnostic. Provider vetting framework, cost model, deployment plan. - [MDR for Defense Contractors Handling CUI: The Buyer's Guide](https://www.cyberuptive.com/mdr-for-cui-defense-contractors/): How MDR intersects with NIST SP 800-171, CUI boundary drawing, GCC High, single-tenant vs multi-tenant analyst access, and U.S.-persons handling. What actually satisfies the CMMC Level 2 controls MDR is expected to cover. - [CMMC MSSP: How to Vet a Provider for CUI Systems](https://www.cyberuptive.com/cmmc-mssp/): A practical CMMC MSSP buyer guide for DoD contractors handling CUI: 12 vetting questions, cost anchors, provider roles, and a 90-day selection plan. - [MDR for CMMC Level 2: The 4 Disqualifiers Buyers Miss](https://www.cyberuptive.com/cmmc-mdr-comparison/): The four structural disqualifiers most MDR providers fail on CMMC Level 2: FedRAMP authorization, segregated US-persons SOC, C3PAO/RPO status, GCC High operations. Vendor-by-vendor fit table with source citations. - [CMMC Level 2 Timeline & Cost: What Defense Contractors Actually Pay](https://www.cyberuptive.com/cmmc-level-2-timeline-cost/): Realistic CMMC Level 2 timeline and cost for U.S. defense contractors: DoD official estimates, gap-to-certification phases, and small-business cost math. - [Small Defense Contractor 90-Day Cybersecurity Playbook](https://www.cyberuptive.com/small-defense-contractor-cybersecurity-playbook/): A 90-day cybersecurity playbook for small U.S. defense contractors (25-100 employees): DFARS baseline, CMMC prep, essential controls, budget, and vendor picks. - [Best CMMC MSSP for a Hawaii Defense Contractor: A Buyer's Guide](https://www.cyberuptive.com/best-cmmc-mssp-hawaii-defense-contractor/): A neutral, source-cited buyer's guide comparing the CMMC MSSP options available to a Hawaii-based defense contractor. Cyberuptive, Intech Hawaii, Cypac, Summit 7, CyberSheath. What each does well, where each may not fit, and the questions that decide the choice. ## Provider comparisons Comparisons rely on each vendor's published terms and are dated. They note who should stay with each competitor. - [Arctic Wolf Alternatives for CUI and CMMC Environments](https://www.cyberuptive.com/insights/arctic-wolf-alternatives/): Arctic Wolf alternatives for defense contractors and regulated firms. What Arctic Wolf's own terms say about CUI, GCC High, and offshore access, and what to compare. - [eSentire Alternatives and Comparison for 2026](https://www.cyberuptive.com/insights/esentire-alternatives/): Comparing eSentire MDR? What its new US SOC covers, what the announcement doesn't say about analyst citizenship, and the questions CUI buyers should ask. - [Expel Alternatives and Comparison for 2026](https://www.cyberuptive.com/insights/expel-alternatives/): Comparing Expel MDR? What its Starter, Select, and Premium packages include, what its site doesn't say about analyst location, and what CUI buyers should ask. - [CrowdStrike Falcon vs Trellix MDR: 2026 Comparison](https://www.cyberuptive.com/insights/crowdstrike-falcon-vs-trellix-mdr/): CrowdStrike Falcon vs Trellix compared for managed detection and response in 2026. Platform depth, CMMC fit, mid-market pricing, and when each EDR is the right call for your SOC. - [Trellix XDR & SIEM vs Splunk, Microsoft Sentinel & Exabeam (2026)](https://www.cyberuptive.com/insights/trellix-xdr-siem-vs-splunk-sentinel-exabeam/): How does Trellix XDR and Helix SIEM stack up against Splunk, Microsoft Sentinel, and Exabeam? A hands-on breakdown from the team that runs Trellix daily for mid-market and defense clients. - [Trellix Wise vs CrowdStrike Charlotte AI vs SentinelOne](https://www.cyberuptive.com/insights/trellix-wise-vs-crowdstrike-sentinelone/): An MSSP's hands-on comparison of Trellix Wise, CrowdStrike Charlotte AI, and SentinelOne Purple AI, and why Wise wins for the modern SOC. - [Trellix vs CrowdStrike vs Microsoft Defender: EDR Comparison for CMMC](https://www.cyberuptive.com/edr-comparison-trellix-crowdstrike-microsoft/): Vendor-neutral EDR comparison for defense contractors: Trellix, CrowdStrike Falcon, Microsoft Defender for Endpoint. Feature matrix, CMMC alignment, GCC High support, pricing model. - [Top MSSP Providers 2026 Comparison](https://www.cyberuptive.com/insights/top-mssp-providers-2026/): Opinionated 2026 comparison of top MSSPs, Arctic Wolf, eSentire, Expel, Trustwave, Critical Start, and Cyberuptive, for mid-market and regulated orgs. - [MDR vs MSSP vs SIEM: 2026 Buyer's Guide](https://www.cyberuptive.com/insights/mdr-vs-mssp-vs-siem-2026-buyers-guide/): MDR vs MSSP vs SIEM compared in plain English. What each acronym means, when you need MDR vs MSSP, how SIEM fits in, and how to pick the right model for a mid-market or regulated organization in 2026. - [MSSP Software vs MSSP Service: Which Do You Actually Need?](https://www.cyberuptive.com/insights/mssp-software-vs-mssp-service/): Searching for 'MSSP software'? You probably don't want software: you want a service. Here's the clear distinction between the two, the platforms commonly mislabeled as 'MSSP software,' and how to know which one fits. - [Co-Managed SOC vs Outsourced SOC: How to Choose](https://www.cyberuptive.com/co-managed-soc-vs-outsourced-soc/): A practical guide to co-managed SOC vs fully outsourced SOC: decision framework, cost math, staffing model, tool ownership, and 90-day pilot plan. - [Single Global SOC vs Segregated SOC MDR: Why It Matters for CMMC CUI](https://www.cyberuptive.com/single-soc-vs-segregated-soc-mdr/): A single global-SOC MDR provider cannot hold CUI under CMMC Level 2. The regulatory boundary, the ESP scoping rule, and a five-question buyer diligence framework: with primary-source citations. - [Evaluating an MSSP: Questions Your Shortlist Can't Dodge](https://www.cyberuptive.com/insights/evaluating-an-mssp-shortlist-questions/): Every MSSP finalist claims 24/7 SOC coverage and fast response. Here are the specific questions that separate a real security operations center from a reseller. ## Insights Newest first. Full index: https://www.cyberuptive.com/insights/ - [WSO2 and Adobe Commerce KEV Additions: CVE-2026-5430, CVE-2026-71362](https://www.cyberuptive.com/insights/wso2-adobe-commerce-cve-2026-5430-71362-kev/): CISA added a WSO2 JWT auth bypass and an Adobe Commerce session-hijack flaw to its KEV catalog Sept 24, 2026, both patched months earlier. Here's the lesson. - [How to Raise Your SPRS Score During the CMMC Pause](https://www.cyberuptive.com/insights/raise-sprs-score-cmmc-phase-2-pause/): CMMC Phase 2 is paused, but SPRS scores and affirmations still count. How scoring works, which fixes move the number most, and how to raise it honestly. - [Pen Test Cost in 2026, and Does CMMC Require One?](https://www.cyberuptive.com/insights/penetration-test-cost-cmmc/): What a penetration test costs in 2026, what drives the price, and whether CMMC requires one. Level 2 doesn't; Level 3 requires annual pen testing. - [GCC High Enclave vs. Full Migration: The Monitoring Gap](https://www.cyberuptive.com/insights/gcc-high-enclave-vs-full-migration/): GCC High enclave or full tenant migration for CMMC? How scope, cost, and 24/7 monitoring differ, including the Sentinel data gaps in GCC High. - [Does Your MSSP Need Its Own CMMC Certification?](https://www.cyberuptive.com/insights/does-your-mssp-need-cmmc-certification/): Under 32 CFR 170.19, an MSSP doesn't need its own CMMC certificate, but its services get assessed in yours. What to ask a provider before you sign. - [Do SOC Analysts Need to Be US Persons for CUI or ITAR?](https://www.cyberuptive.com/insights/do-soc-analysts-need-to-be-us-persons/): CMMC doesn't require US-person SOC analysts. ITAR and EAR can. When your SOC's access to logs becomes an export question, and what to put in the contract. - [CMMC Phase 2 Paused: What Defense Contractors Should Do Now (2026)](https://www.cyberuptive.com/insights/cmmc-phase-2-paused-keep-moving/): The Department of War suspended CMMC Phase 2 on July 13, 2026. NIST 800-171, DFARS 252.204-7012, and SPRS remain enforced. The 90-day playbook for defense contractors, with primary sources. - [NIS2 Compliance for US Suppliers With EU Customers](https://www.cyberuptive.com/insights/nis2-compliance-us-suppliers-eu-customers-2026/): NIS2 doesn't register US companies directly, but EU customers are pushing its supply-chain and reporting rules into contracts. Here's what changed in 2026. - [MSSP Contracts and Breach Notification: Is Your Clock Fast Enough?](https://www.cyberuptive.com/insights/mssp-contract-breach-notification-deadline/): Most MSSP contracts promise to notify you “promptly.” That phrase can cost you the runway you need to meet DFARS, HIPAA, or FTC Safeguards Rule deadlines. - [Check Point, Arista, F5 KEV: CISA's September 2026 Additions](https://www.cyberuptive.com/insights/checkpoint-arista-f5-kev-september-2026/): CISA added four actively exploited Check Point, Arista, and F5 flaws to its KEV catalog Sept 22, 2026, with a 3-day deadline. Here's what to check. - [USCG Cybersecurity Plan Deadline: What Shippers Must Have Ready](https://www.cyberuptive.com/insights/uscg-cybersecurity-plan-deadline-2027/): The Coast Guard's cybersecurity rule sets a July 16, 2027 deadline for a CySO, a completed assessment, and an approved Plan. Here's what's actually due. - [Law Firm Cybersecurity Requirements in 2026](https://www.cyberuptive.com/insights/law-firm-cybersecurity-bar-client-requirements-2026/): Bar ethics rules, state CLE mandates, and outside counsel guidelines now treat law firm cybersecurity as enforceable. Here's what changed and what to do. - [NIST 800-171 Rev 3 vs. CMMC Level 2 in 2026](https://www.cyberuptive.com/insights/nist-800-171-rev-3-cmmc-level-2-2026/): NIST finalized SP 800-171 Revision 3 in 2024, but CMMC Level 2 still runs on Revision 2. What changed, why the transition stalled, and what to do now. - [Post-Quantum Migration Timeline for Mid-Market Teams](https://www.cyberuptive.com/insights/post-quantum-cryptography-migration-timeline-2026/): A June 2026 executive order set 2030-2031 federal PQC deadlines. Here's a realistic migration timeline for mid-market and defense-contractor security teams. - [Cisco FMC CVE-2026-20079: CVSS 10.0 KEV, Actively Exploited](https://www.cyberuptive.com/insights/cisco-fmc-cve-2026-20079-kev/): CISA's federal deadline for Cisco FMC CVE-2026-20079 was today. Three distinct threat clusters, one tied to Sandworm, are already inside unpatched boxes. - [DORA Compliance for US Vendors With EU Financial Clients](https://www.cyberuptive.com/insights/dora-compliance-us-vendors-eu-financial-clients-2026/): DORA doesn't regulate US companies directly, but it forces EU financial clients to flow requirements into your contract. Here's exactly what changes in 2026. - [SonicWall SMA1000 CVE-2026-83548: Critical SSRF KEV](https://www.cyberuptive.com/insights/sonicwall-sma1000-cve-2026-83548-kev/): CISA gave a 3-day deadline for CVE-2026-83548/83549 on SonicWall SMA1000. This is the second SSRF-to-RCE pair in seven weeks. Here's what to patch and check. - [Cyber Insurance Underwriting Requirements 2026](https://www.cyberuptive.com/insights/cyber-insurance-underwriting-2026-carrier-requirements/): Cyber insurers now check specific controls, not general posture. See exactly what Beazley, Travelers, and CISA guidance require before you bind or renew. - [DFARS 252.204-7012 Flow-Down for Subcontractors](https://www.cyberuptive.com/insights/dfars-7012-flow-down-subcontractors-2026/): CMMC Phase 2 is suspended, but DFARS 252.204-7012 is not. Here is exactly what subcontractors still owe primes on NIST 800-171 and 72-hour reporting. - [AI Security in Regulated Industries: Pre-Deployment Checklist](https://www.cyberuptive.com/insights/ai-security-regulated-industries-2026/): Federal bank regulators exempted generative AI from their 2026 model risk rules. Here's the governance, logging, and access controls to require anyway. - [Citrix NetScaler CVE-2026-8452: DoS Label, Root RCE Risk](https://www.cyberuptive.com/insights/citrix-netscaler-cve-2026-8452-kev/): Citrix calls CVE-2026-8452 a denial-of-service bug. watchTowr Labs proved unauthenticated root RCE. Patch, hunt, and report before CISA's deadline. - [Introducing the Cyberuptive Command Center](https://www.cyberuptive.com/insights/cyberuptive-command-center/): Bring your own SIEM or XDR. The Cyberuptive Command Center sits above Trellix, CrowdStrike Falcon, Microsoft Sentinel, Rapid7, and more, unifying detection, triage, and response across whatever platform you already run. - [PIPEDA Safeguards: What a Canada MSSP Must Prove](https://www.cyberuptive.com/insights/pipeda-canada-mssp-safeguards/): PIPEDA still requires safeguards, RROSH breach reports, and records of every incident. What Toronto and Canada mid-market teams should demand from an MSSP. - [Hawaii MDR and 24/7 SOC: What Local Coverage Changes](https://www.cyberuptive.com/insights/hawaii-mdr-24-7-soc/): Hawaii MDR and 24/7 SOC coverage explained: HST never shifts, CMMC Phase I still applies after the July 2026 pause, and CUI handling still requires U.S. persons. - [FedRAMP Program Certification: What Changes in 2026](https://www.cyberuptive.com/insights/fedramp-program-certification-2026/): FedRAMP's 2026 updates reshape Ready, Certification Classes, and sponsorless paths. Learn what cloud providers should prepare before CR26. - [CISA KEV: Linux CVE-2022-0492 Container Risk](https://www.cyberuptive.com/insights/cisa-kev-linux-cve-2022-0492-container-risk/): CISA added Linux CVE-2022-0492 to KEV. Learn how cloud and container teams should patch kernels, limit cgroups v1 risk, and verify hosts. - [Cisco Secure Workload CVE-2026-20223: What to Fix](https://www.cyberuptive.com/insights/cisco-secure-workload-cve-2026-20223/): Cisco Secure Workload CVE-2026-20223 affects internal REST APIs. Learn how to patch, verify exposure, and govern workload segmentation risk. - [NIST IR 8320E: Confidential Computing for Cloud](https://www.cyberuptive.com/insights/nist-ir-8320e-confidential-computing-cloud/): NIST's draft IR 8320E explains confidential computing for cloud workloads. How regulated teams evaluate TEEs, key governance, attestation, and AI data risk. - [PAN-OS CVE-2026-0257: GlobalProtect KEV Guide](https://www.cyberuptive.com/insights/pan-os-cve-2026-0257-globalprotect-kev/): CISA added PAN-OS CVE-2026-0257 to KEV. How to verify GlobalProtect exposure, check authentication override config, patch fast, and review VPN evidence. - [NIST SP 800-172r3: What CUI Teams Should Do Now](https://www.cyberuptive.com/insights/nist-sp-800-172r3-cui-readiness/): NIST finalized SP 800-172r3 and 172Ar3 in May 2026. How CUI teams map enhanced requirements, design assessment evidence, and prepare cyber resilience plans. - [CISA KEV: Nx and TanStack Supply-Chain Response](https://www.cyberuptive.com/insights/cisa-kev-nx-tanstack-supply-chain-response/): CISA added Nx Console (CVE-2026-48027) and TanStack (CVE-2026-45321) to KEV May 27. How to verify exposure, rotate credentials, and harden dev tooling. - [Exchange OWA CVE-2026-42897 Mitigation Guide](https://www.cyberuptive.com/insights/exchange-owa-cve-2026-42897-mitigation/): On-prem Exchange OWA is exposed to CVE-2026-42897. How to validate EEMS coverage, run EOMT in disconnected environments, and cut residual risk. - [CVE-2026-8153: PolyScope 5 RCE Risk in Manufacturing](https://www.cyberuptive.com/insights/polyscope-cve-2026-8153-manufacturing/): Universal Robots patched CVE-2026-8153 in PolyScope 5.25.1. What manufacturing and OT teams should upgrade, disable, and segment - and how to validate safely. - [Oracle CSPU May 2026: What Security Teams Should Do Now](https://www.cyberuptive.com/insights/oracle-cspu-may-2026-security-teams/): Oracle's first Critical Security Patch Update lands May 28, 2026. How security teams should adjust patch governance, SLAs, and the CSPU operating calendar. - [Cisco SD-WAN KEV: Patch First, Then Hunt](https://www.cyberuptive.com/insights/cisco-sd-wan-kev-cve-2026-20182/): CISA added Cisco Catalyst SD-WAN CVE-2026-20182 to the KEV catalog with a May 17, 2026 federal due date. Why upgrade comes before forensics, and the operational checklist for control components, TAC engagement, and cloud-hosted SD-WAN. - [Exchange CVE-2026-42897: What to Verify Now](https://www.cyberuptive.com/insights/exchange-cve-2026-42897-kev/): CISA added Exchange CVE-2026-42897 to the KEV catalog with a May 29, 2026 due date. How to verify mitigation, capture evidence, and prepare for the permanent patch. - [Oracle Monthly CSPUs: What Changes for Patch Governance](https://www.cyberuptive.com/insights/oracle-monthly-cspu-patch-governance/): Oracle monthly Critical Security Patch Updates begin May 28, 2026. Update patch governance, SLAs, testing, and audit evidence before the cadence changes. - [FedRAMP 2026 Rules Preview: What CSPs Should Do Now](https://www.cyberuptive.com/insights/fedramp-2026-rules-preview/): FedRAMP's 2026 consolidated rules preview signals structured evidence, clearer MUST requirements, and July 2026 changes. What CSPs should do now. - [NIST SP 800-70r5: Secure Configuration Checklist Guide](https://www.cyberuptive.com/insights/nist-sp-800-70r5-secure-configuration-checklists/): NIST SP 800-70r5 updates secure configuration checklist guidance. Operationalize baselines, evidence, and audit readiness for FedRAMP and CMMC. - [Credit Unions in the Crosshairs: 2024–2026 Breach Wave](https://www.cyberuptive.com/insights/credit-unions-in-the-crosshairs/): Patelco, MemberSource, Marquis, Ongoing Operations: the last 24 months show credit unions are hit through vendors as often as their own networks. - [OpenSearch npm compromise: who’s affected and what to do](https://www.cyberuptive.com/insights/opensearch-npm-compromise-may-2026/): OpenSearch disclosed compromised npm dev packages. Learn who’s affected, what to check, and how to harden CI/CD supply chains. - [Mini Shai-Hulud: When SLSA-Signed Packages Carry Malware](https://www.cyberuptive.com/insights/mini-shai-hulud-npm-supply-chain/): TanStack npm compromise (CVE-2026-45321) abused GitHub OIDC to ship malware with valid SLSA L3 provenance. What mid-market teams should do this week. - [Are Hardware Firewalls Still Relevant in Zero Trust?](https://www.cyberuptive.com/insights/hardware-firewalls-zero-trust/): Zero trust did not kill hardware firewalls. It changed their job from perimeter gatekeeper to segmentation, telemetry, and resilience control. - [Anthropic Mythos & AI-Driven Offense: What It Means](https://www.cyberuptive.com/insights/anthropic-mythos-ai-vulnerability-discovery/): Anthropic's Mythos AI finds vulnerabilities at machine scale, and unauthorized users have already used it. What this changes for mid-market and DoW subs. - [Why Honolulu Defense Contractors Need a Pacific MSSP](https://www.cyberuptive.com/insights/why-honolulu-defense-contractors-need-mssp/): Time zone, US-persons handling, and INDOPACOM-AOR awareness aren't optional. Why Hawaii defense subs should be skeptical of mainland MSSPs. ## Regions - [Asia-Pacific Managed Security Services](https://www.cyberuptive.com/regions/asia-pacific/) - [EU MSSP](https://www.cyberuptive.com/regions/europe/) - [Hawaii Cybersecurity Services](https://www.cyberuptive.com/regions/hawaii/) - [Philippines Cybersecurity Services](https://www.cyberuptive.com/regions/philippines/) - [U.S. MSSP](https://www.cyberuptive.com/regions/usa/) ## Key CMMC dates - **CMMC 2.0 program rule (32 CFR Part 170) published**: October 15, 2024 - **CMMC acquisition rule (48 CFR) effective, Phase I began**: November 10, 2025. Self-assessments required in applicable awards. - **CMMC Phase II suspended**: July 13, 2026. The Department of War suspended Phase II requirements pending a CMMC Reform Task Force review. Source: https://dodcio.defense.gov/CMMC/ - **Originally scheduled Phase II date**: November 10, 2026 (suspended) **Still in force during the suspension:** - NIST SP 800-171 Rev. 2 for organizations handling CUI - DFARS 252.204-7012 safeguarding and 72-hour cyber incident reporting - Phase I self-assessment requirements and SPRS score submission - Government-led assessments such as DIBCAC ## Frequently asked, briefly answered - **Is Cyberuptive's SOC U.S.-based?** Yes. The U.S. SOC is physically and logically segregated and staffed by U.S.-based analysts on 24/7 shifts. - **Do you support CMMC Level 2?** Yes. We help defense contractors scope CUI, close NIST SP 800-171 gaps, build the SSP and POA&M, and prepare evidence for assessment. - **Is Cyberuptive a CMMC Registered Practitioner Organization?** Yes. Cyberuptive is a CMMC Registered Practitioner Organization (RPO). Verify current listings in the Cyber AB catalog: https://cyberab.org/Catalog - **Do you support GCC High?** Yes. We support Microsoft 365 GCC High and Azure Government environments, including enclave designs. - **What SIEM/XDR platform do you use?** Trellix Helix XDR is the core platform. We also support customer-owned EDR such as CrowdStrike Falcon and Microsoft Defender. - **Where are you located?** 401 Kamakee St #204, Honolulu, HI 96814. We serve customers across the United States. - **Who leads Cyberuptive?** Chuck Lerch, a cybersecurity executive with experience in CMMC Level 2, FedRAMP, SIEM operations, and federal compliance. - **Do you work with smaller organizations?** Yes. Our co-managed SOC extends an in-house IT team rather than replacing it, and we support cyber-insurance attestation needs. ## How to cite Cyberuptive > Cyberuptive: U.S. MSSP and MDR provider headquartered in Honolulu, 24/7 segregated U.S. SOC, CMMC 2.0 Level 2 aligned. https://www.cyberuptive.com ## AI crawler policy AI answer-engine and search crawlers are welcome on www.cyberuptive.com. SEO and competitive-intelligence crawlers (for example AhrefsBot, SemrushBot, MJ12bot, DotBot) are blocked. Full policy: https://www.cyberuptive.com/robots.txt