AI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - Keith Hollender - ESW #468

AI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - Keith Hollender - ESW #468

Author: Security Weekly Productions July 20, 2026 Duration: 1:42:29

Interview with Keith Hollender, CEO and Co-Founder of Arcova

Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem

As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introducing unmanaged risk. The challenge is no longer whether organizations should pursue AI, but how they can govern it, secure it, and operationalize it in ways that stand up to real-world business and threat conditions.

In this conversation, Keith Hollender discusses what Arcova is seeing across enterprise environments as organizations work to connect cybersecurity, AI governance, resilience, and broader transformation priorities. He explores where companies are getting stuck, why traditional siloed approaches are falling short, and what it takes to move from strategy decks to secure execution.

Keith also shares how Arcova's practitioner-led, relationship-driven model helps organizations turn complexity into clarity by embedding with client teams, solving urgent problems hands-on, and building capabilities designed to last. The conversation also covers Arcova's continued growth, including expansion into the Middle East, and what global demand signals reveal about the next phase of cybersecurity and AI consulting.

Segment Resources:

For more information about Arcova and how they can help your enterprise shape what's next, please visit:

https://securityweekly.com/arcova

Topic: CMMC Pause creating chaos among federal contractors

This one sent some shockwaves through the CMMC community, particularly the hundreds or thousands of folks gearing up to assist with the validation that phase 2 aimed to provide. The TL;DR - defense contractors have been required to comply with CMMC controls for years, but self-attestation means that many probably haven't been meeting the requirements. Perhaps, rather than have tons of defense contractors fail the test, they just suspended the requirement for the test itself.

I think Howard Holton nails it here when he says:

"100,000 defense contractors needed third-party assessments. Roughly 100 authorized assessors exist. That's 1,000 assessments each, with the deadline in November."

PCI already created a model that works for a scenario like this. If you're small, you self-assess. If you're big enough, an independent auditor comes to check you out once a year. I'm sure they were probably aware of this and chose not to go down that path for some reasons. I'm not aware of those reasons.

What this means:

  • Phase II is paused
  • Phase I self-assessments still in place (note, however, that phase II existed, because self-attestation didn't work)
  • NIST SP 800-171 Rev 2 and DFARS 252.204-7012 compliance still required
  • 60-day review aims to reform CMMC
  • DoW opened an RFI for industry perspectives on what they should do
  • CMMC characterized as a "compliance burden" and "red tape"
  • False Claims Act and DOJ's cyber-fraud enforcement are still on the table

More resources:

  • CIO Davies' post on Twitter
  • Administrator of the Small Business Administration, Kelly Loeffler's post
  • A useful LinkedIn post that breaks down a lot of what this really means (and doesn't)

Weekly Enterprise News

Finally, in the enterprise security news,

  1. will AI eliminate more cybersecurity jobs than it creates?
  2. Linus's law, amended
  3. the biggest patch Tuesday ever
  4. AI context bombs
  5. AI workflows are a security disaster
  6. people using AI in areas they don't understand
  7. ransomware crews are hitting legal firms hard
  8. lessons learned from CISA's recent github leak
  9. demystify your USB cables!

All that and more, on this episode of Enterprise Security Weekly.

Show Notes: https://securityweekly.com/esw-468


Dive into the ever-evolving world of digital defense with the Security Weekly Podcast Network (Video). Produced by Security Weekly Productions, this network isn't a single perspective but a comprehensive hub where different facets of cybersecurity come into focus through distinct, dedicated shows. You'll find episodes from series like Application Security Weekly, Business Security Weekly, Paul's Security Weekly, Enterprise Security Weekly, and Security Weekly News, all curated in one feed. This structure means that whether you're analyzing code, shaping corporate policy, or managing infrastructure, there's relevant content for you. The discussions move beyond headlines, offering practical analysis and expert insights that help make sense of complex threats and solutions. By blending technology deep dives with timely news commentary, this video podcast provides a multi-dimensional view of the field, suitable for professionals who need to stay informed and enthusiasts curious about how security shapes our digital lives. It’s a consistent resource for anyone looking to understand not just what is happening in cybersecurity, but why it matters and how to respond.
Author: Language: English Episodes: 50

Security Weekly Podcast Network (Video)
Podcast Episodes
Hacking All The Devices, with AI? - Rob Allen - PSW #941 [not-audio_url] [/not-audio_url]

Duration: 2:06:01
Rob Allen from ThreatLocker joins us to discuss securing agentic AI with zero-trust controls, least privilege, and access controls to limit what agents can access and do. This segment is sponsored by ThreatLocker. Visit…
Applying Zero Trust Principles to Agents - Kieran Human - ASW #397 [not-audio_url] [/not-audio_url]

Duration: 1:06:40
Sandboxing, least privilege, and monitoring are well-established controls in terms of the defenses they provide against unexpected and unauthorized actions. But being well-established in theory doesn't always translate t…
Rejoice In The Nostalgia - PSW #940 [not-audio_url] [/not-audio_url]

Duration: 2:08:22
In the security news this week: Cursor opens your repo, the repo opens you If you want the good model I'm going to need to see your ID Flock's a Flocking mess Defender was supposed to be the chosen one Side stepping Secu…