As featured on MassMEPâs Manufacturing Podcast â Episode 109
If youâve ever wondered how cybersecurity, government contracts, and strawberry ice cream intersectâyouâre in luck. Our own John and Pete were recently welcomed back by Hayley and Kevin at MassMEP to talk all things CMMC, cybersecurity, smishing scams, and how to build a better risk posture for 2025 (with a few laughs along the way).
You can listen to the full episode here:đ§ Ep. 109 â New Episode, Same Certification Process
đŚ Cyber Ice Cream Flavors of the Day
The crew kicked off the episode with a fun questionâ What ice cream flavor sums up your day?
Here's how the team answered:
- Peteâ Coffee Coffee BuzzBuzzBuzz â, acknowledging his well-caffeinated state.
- Johnâ Strawberry đ because it was simply all he could think about (and yes, he went to get some right after the call)...
- Kevinâ Rocky Road, it was looking like a tough day.
- Hayleyâ Tutti Fruttiâbecause you just never know what you're going to get.
đą Smishing, Phishing, and "USPS" Texts That Steal Your Life
A big topic in the first half of the episode: Smishing, or phishing attacks via text message.
John shared a real story from the holidays, where a friend-of-a-friend fell for a fake USPS text. Her phone number was hijacked, her MFA codes were intercepted, and 15+ accounts were compromised.
âYou really do have to stay vigilant. These phishing emails look more real than everâalways double check where itâs coming from.â âPete
The takeaway? Slow down. Be skeptical. And no, the Post Office didnât magically get your cell number.
đ CMMC in 2025: Whatâs New?
The second half of the episode dove into CMMC (Cybersecurity Maturity Model Certification) and whatâs changing:
- CMMC is back to three levels instead of five.
- Level 1 covers Federal Contract Info (self-assessed).
- Level 2 covers Controlled Unclassified Info (CUI) and requires a third-party audit.
- Level 3 is the highest tierâreserved for prime contractors and R&Dâaudited by the DoD directly.
And while your MSP doesnât need to be certified under CMMC, John made the case for why they should:
âYou can buy 150 different security tools, but only a few meet the right compliance requirements. Itâs hard for manufacturers to know who to trust if the MSPs arenât fluent in this.â
đ ď¸ Compliance â Plug-and-Play
One of the biggest myths in cybersecurity? That you can just buy a tool and be compliant.
âYou canât just plug something in because the white paper says itâs good. .. You need a trusted partnershipâsomeone who doesnât just throw a menu of tools at you, but guides you through what actually meets compliance.â
Pete added a solid tip: When in doubt, look for FedRAMP-certified tools. The FedRAMP Marketplace is a great place to start when evaluating providers or platforms.
As threats grow more complexâespecially with the rise of AIâthe mindset around cybersecurity must shift too. For businesses, this means budgeting for cybersecurity like any other strategic priorityâmeasuring ROI not just in tools, but in resilience and readiness.
âThereâs no âfence in a box.â Youâre never done. Itâs about ongoing investment and growing smarter each year.â â John
đ¸ How Synagex + MassMEP Can Help
CMMC compliance isnât easy, and manufacturers shouldnât go it alone.
Thatâs why Synagex and MassMEP partner to deliver value-packed gap assessmentsânot just to check a box, but to clarify the path forward, cost it out, and help you get started. And in Massachusetts, state funds and assistance programs make this more attainable than ever.
âWeâve done this work in other states, and we can confidently say Massachusetts is one of the best. When you combine our cybersecurity focus with MassMEPâs deep manufacturing network, itâs powerful stuff.â âJohn
đ§ Final Thoughts: Be Paranoid. Ask Questions.
The group closed with a reminder: You donât need a ton of sensitive data to be a target. Even basic informationânames, birthdays, email accessâcan be leveraged by attackers.
âAny business collecting data, in any industry, needs to take security seriously. You might think youâre small or simple, but youâre still a risk if the wrong person gets in.ââHayley
Ready to understand your riskâand do something about it?
Letâs talk. Synagex and MassMEP are here to help guide you through the chaos and toward calm, compliant, modern IT.
đ Listen to the full episode
đŠ Reach out to Synagex
CMMC is HereâAre You Ready? Synagex Joins MassMEP for Another Readiness Webinar