full

Passing the Test Is Not Staying Compliant | CMMC, AI & Governance with William McBorrough

Published on: 15th September, 2026

Passing the test and staying compliant are two different jobs.

A defense contractor can spend months preparing for an assessment, pass it, and begin losing ground almost immediately.

Why?

Because assessment readiness is not the same thing as operating a sustainable compliance program.

In this episode of The Briefing, Dr. Tuboise Floyd sits down with William McBorrough, CISO and Lead CMMC Assessor, MCGlobalTech for a conversation about what happens every day after assessment day.

William has seen the problem from both sides: building cybersecurity compliance programs and assessing whether organizations can actually operate what they documented.

The conversation starts with CMMC and the Defense Industrial Base, then moves into governance, evidence, executive accountability, technology procurement, and AI.

Because whether the system is a cybersecurity compliance program or an AI use case, the underlying question is remarkably similar:

Can you prove that what you say is happening is actually happening?

FULL SHOW NOTES

Passing the test is not staying compliant.

A company can spend a year preparing for an assessment, pass it, and watch the program begin coming apart afterward.

The people who built it return to their regular jobs.

The documentation stops matching the work.

The next assessor may discover an organization that was compliant once.

That is the problem at the center of this episode of The Briefing.

Dr. Tuboise Floyd sits down with William McBorrough, CISO and Lead CMMC Assessor, to examine what happens when organizations build cybersecurity compliance programs around assessment day instead of the operating capability required for every day after it.

William describes this as a sustainability problem.

Organizations frequently buy audit-readiness services, tools, consulting, and managed services designed to get them through a point-in-time assessment. But when the audit becomes the goal, organizations can immediately begin drifting once the assessment is over because the ongoing activities required by the compliance program were never built into normal operations.

That leads to one of the central arguments of the conversation:

CMMC is a governance problem.

Cybersecurity compliance requires more than a mandate. Governance is a discipline requiring people, skills, processes, accountability, and the capability to perform the work repeatedly.

And an assessor can see the difference.

If an organization's policy says access is reviewed every month, an assessor doesn't simply want to read the policy.

Where are the records?

What process was followed?

Who performed the work?

Can the organization demonstrate that the activity actually occurred?

An assessor is looking for evidence that the program is operating, not merely evidence that somebody documented one.

Then the conversation crosses into AI.

William explains why security leaders increasingly find themselves responsible for AI risk because AI is already entering organizations. Rather than serving as the traditional "voice of no," he describes the security leader's job as finding a secure path to legitimate business objectives.

That raises another governance problem:

How do you use AI without simply turning it loose?

William explains how MCGLOBALTech approaches AI inside its compliance operations.

The organization governs AI by use case, not simply by declaring a particular AI product acceptable. Different uses of the same tool can create very different risks.

There are also boundaries.

AI is not used on client data inside MCGLOBALTech's client environments. AI is instead used for specific approved operational purposes outside those prohibited uses.

And there is an important operating rule:

Do it manually first.

William's team develops the process manually, operates it, validates that the process produces the desired outcome, and only then determines how AI can accelerate or automate it.

The process is not created by AI.

AI is applied after the organization understands the process and knows what a valid outcome should look like.

That distinction matters because AI can produce something that looks convincing even when it is wrong.

As William explains in the conversation, asking AI for a heart-surgery plan may produce something that looks excellent to someone who isn't a heart surgeon.

Expertise is what allows someone to recognize whether the output is actually valid.

The same discipline required for sustainable cybersecurity compliance begins appearing again in AI:

Defined processes.

Clear boundaries.

Validated outputs.

Evidence.

Human judgment.

Accountability.

The episode also gets personal for executives.

CMMC and federal cybersecurity requirements eventually reach the people whose names stand behind what the organization says is true.

William advises CEOs operating in the federal space to examine their contracts, understand the security obligations contained in them, and determine whether their organizations actually possess the capability to meet those obligations.

He also discusses the responsibility of the senior official affirming an organization's compliance information and the importance of having evidence behind what leadership is being asked to stand behind.

The question isn't simply:

Did we pass?

It is:

Can we prove we're still doing what we said we do?

The assessment is a day.

The program is every day after.

IN THIS EPISODE

• CMMC and the compliance sustainability gap

• Passing an assessment versus sustaining compliance

• CMMC Level 2

• What CMMC assessors actually look for

• Evidence versus documentation

• Governance versus audit readiness

• NIST 800-171 requirements

• Cybersecurity inside the Defense Industrial Base

• Small-business compliance challenges

• Governance as an operating discipline

• Executive accountability and attestation

• Security obligations inside federal contracts

• AI governance

• The CISO as an AI governance leader

• Governing AI by use case

• ChatGPT, Claude and Microsoft Copilot

• Separating AI experimentation from controlled environments

• Manual validation before AI automation

• Validated outputs versus convincing outputs

• Continuous review of AI use cases

• Why technology-first procurement fails

• What CEOs should examine now

GUEST

William McBorrough

CISO, Lead CMMC Assessor

MCGLOBALTech

William McBorrough is a cybersecurity and compliance leader whose work spans building, operating, and assessing security governance programs.

He has spent more than 16 years building security compliance programs and has supported defense contractors around NIST 800-171 requirements and cybersecurity compliance.

His work has included organizations ranging from five employees to 5,000 employees, while MCGLOBALTech also serves federal government organizations.

William is also an associate professor of cybersecurity at the University of Maryland Global Campus, serves on the EC-Council Global Advisory Board, publishes the SMB CISO Insights newsletter, and is the author of Beyond Compliance, a governance roadmap focused on sustainable CMMC.

ABOUT THE BRIEFING

The Briefing with Dr. Tuboise Floyd is independent media examining the decisions underneath consequential technology.

AI. Quantum. Cyber.

The technology is only the beginning of the story.

Find the decision.

Follow the evidence.

Name who owns it.

Independent media. Real conversations. Higher stakes.

A Human Signal Production

Hosted by Dr. Tuboise Floyd

Creative Director: Jeremy Jarvis

Watch and listen:

humansignal.io/thebriefing

EDITORIAL / PARTNER DISCLOSURE

MCGLOBALTech is a paying Human Signal partner, and Dr. Tuboise Floyd has performed contract advisory work with the firm.

The partnership does not determine guest selection, questions, editorial conclusions, favorable treatment, or endorsement. Editorial questions and conclusions remain independent.



This podcast uses the following third-party services for analysis:

OP3 - https://op3.dev/privacy
Next Episode All Episodes Previous Episode
Show artwork for The Briefing with Dr. Tuboise Floyd

About the Podcast

The Briefing with Dr. Tuboise Floyd
AI · Quantum · Cyber · Decision Assurance · Human Signal
ABOUT THE PODCAST

The Briefing with Dr. Tuboise Floyd

The Briefing is for leaders who build, approve, procure, govern, or certify consequential technology.

Hosted by Dr. Tuboise Floyd, Founder and Principal, Decision Assurance at Human Signal, the show examines the operating reality beneath technology strategy: decision authority, accountability, controls, evidence, critical infrastructure, and the conditions that produce institutional failure.

The market is crowded with technology noise, checklists, and compliance theater. The Briefing focuses on the harder question:

What governance infrastructure must exist before autonomous and emerging systems create exposure that leadership cannot explain, defend, or control?

Episodes use Human Signal’s TAIMScore™, GASP™ Diagnostic, L.E.A.C. Protocol™, and Failure Files™ approaches to examine real-world failures, identify structural risk, and surface the decisions leaders must make before scrutiny arrives.

Produced with Creative Director Jeremy Jarvis, The Briefing covers AI governance, cyber risk, post-quantum readiness, critical infrastructure, government contracting, and the builder economy.

New episodes, visual briefings, and practical playbooks:

https://humansignal.io/thebriefing

The Briefing is a Human Signal production. Human Signal is an independent decision-assurance advisory and research platform.

DISCLOSURE

All episode content, including analysis, case studies, and framework applications, is provided for educational and informational purposes only. Nothing in this podcast constitutes legal, regulatory, compliance, financial, or professional advice. Listening to or engaging with this content does not create an advisory or consulting relationship.

Guest opinions are their own and do not necessarily represent the views of Human Signal or Dr. Tuboise Floyd. Case studies and institutional-failure analyses use publicly available information and are presented as educational tools, not legal findings or regulatory determinations.

This podcast uses OP3 for privacy-friendly audience measurement:

https://op3.dev/privacy

© 2026 Dr. Tuboise Floyd. All rights reserved.
Support This Show