Unfortunately — and I take the blame for this — a lot of folks thought my posts on the recent CMMC “pause” and mental health crises by those affected were jokes or sarcastic snark. I tried to make it clear in those posts that I was not joking, but many just didn’t believe it. That is, as I said, partly my fault for peppering the CMMC debate with so much humor and sarcasm. People know where I stand on the scheme — CMMC is a grift — so they struggled to recognize I had shifted gears and appeared, all of a sudden, genuinely concerned for the folks in the scheme.

But two things can be true at once. I can believe CMMC is a grift and work hard to stop people from becoming victims. But I can also recognize when it’s time to stop joking and reach out to help victims, even if they are some of the folks who were previously grifting everyone else.

That is the situation we have here. CMMC was rolled out in a cultish fashion, with a biased commercial cybersecurity press machine dutifully pushing Katie Arrington and her scams in order to sell subscriptions and gain promotions. (As I chronicled in this video.) Voices in opposition of Arrington and her small but vocal cult were shunned and banned, and an echo chamber of grifters, scammers, and fraudsters rose to power.

From the outside, it is clear that Arrington failed at every single thing she tried to accomplish. (I’ll have more on that later.) But for those inside the CMMC scheme, all you were given was blind praise and full-on lies about her and her Frankensteinian creation.

Now the bill has come due. It never made a lot of sense that under Trump 1.0, which was ostensibly a pro-business, anti-tax administration, they would create a massive billion-dollar de facto tax on American businesses including — worst of all — the huge defense contractors who can literally sway elections. Biden’s weak administration did nothing to course correct, of course, and Trump 2.0 launched with more vigor. It was a matter of time before someone in the administration noticed that CMMC ran entirely against everything Trump stood for, even if it had been created by a second-place, lower-run Trump supporter.

(Arrington’s political opponent, Nancy Mace, had the President’s ear. Arrington herself did not. That left a lot of room for Mace to trash Katie.)

We will know, eventually, whether the departure of Stacy Bostjanick, just a few ticks before the “CMMC Reform Task Force” was convened, was a coincidence. I do not think it was. Kirsten Davies saw CMMC for what it was and, perhaps, even mentioned it to Trump, who had never been paying attention to it before. It was doomed.

It’s never a good look when the government forms a “Reform Task Force” to manage the thing you created.

Now we have a temporary pause as the DoW considers what to do with Arrington’s misguided, rogue monster. But for the people who were sucked into that echo chamber and saw gold in them thar hills, they have become the victims now. And they deserve some compassion even if some of them were grifting just a few weeks ago.

The crisis is real, although there obviously won’t be hard data to support this statement. I have only anecdotes but when it comes to mental health crises, anecdotes must be taken seriously.

Here is one message I received from an anonymous CMMC actor (who used a Protonmail account, so I legitimately don’t know who sent it):

In 2021 I left my job at a large cybersecurity firm to try this CMMC thing. I thought I could build a consulting practice and C3PAO. I bought all the credentials. Went to seminars. Traveled to a few of the trade shows to pass around my business card. Paid for retraining when they went with 2.0. All my money was going out, nothing coming in. Took out loans that I have to pay back now. I might still be able to get consulting work but my dream of doing audits as a C3PAO are over. Read your post and said to myself, this is me. Stand to lose everything because I made stupid decisions.

Another one:

This is the first time in my life I thought of calling that [mental health crisis] hotline number. I am 56 years old and divorced but still never felt as bad as I do now.

I have a few more, but their details are a bit too specific and I don’t want to accidentally doxx them. But you get the picture.

Real people were affected by this rug-pull. That’s not to say the DoW and Davies were wrong to yank the carpet. It needed to be done. But for anyone drawn into a cult — or even just a pipe dream — yanking it away from them in one, swift, unannounced move can be devastating.

If you’re reading this and see yourself in this story, get help. There is no shame in contacting someone for support. A family member, a friend, someone in your church, or that hotline. (Dial 988 in USA.)

Also, understand that help may be on the way. Oxebridge is working with a major international training org to offer free transition training from CMMC assessor credentials (CCA and LCCA) to ISO 27001 Lead Auditor, so that you may be able to get work in the faster-growing (and more lucrative) ISO 27001 certification scheme. I actually got the CEO of the training org to agree to offer this for free to anyone affected by the CMMC pause, so should have a more formal announcemtn shortly.

While the remaining grifters are still pushing their scams, there are folks working hard behind the scenes, on their own dime, to help. We’ll get no credit for this. No reporters from cybersecurity websites will interview us. We don’t get invited to any seminars or town halls. We’re burning up our own money, too. But it’s worth it because we are supposed to be living in a civilization, not a set of warring tribes. So, you’re not alone.

Meanwhile, if you want to just chat to me, reach out. You can use Signal if you want to remain anonymous.

 

 

Advertisements

ISO 17000 Series Consulting