full
Passing the Test Is Not Staying Compliant | CMMC, AI & Governance with William McBorrough
Passing the test and staying compliant are two different jobs.
A defense contractor can spend months preparing for an assessment, pass it, and begin losing ground almost immediately.
Why?
Because assessment readiness is not the same thing as operating a sustainable compliance program.
In this episode of The Briefing, Dr. Tuboise Floyd sits down with William McBorrough, CISO and Lead CMMC Assessor, MCGlobalTech for a conversation about what happens every day after assessment day.
William has seen the problem from both sides: building cybersecurity compliance programs and assessing whether organizations can actually operate what they documented.
The conversation starts with CMMC and the Defense Industrial Base, then moves into governance, evidence, executive accountability, technology procurement, and AI.
Because whether the system is a cybersecurity compliance program or an AI use case, the underlying question is remarkably similar:
Can you prove that what you say is happening is actually happening?
FULL SHOW NOTES
Passing the test is not staying compliant.
A company can spend a year preparing for an assessment, pass it, and watch the program begin coming apart afterward.
The people who built it return to their regular jobs.
The documentation stops matching the work.
The next assessor may discover an organization that was compliant once.
That is the problem at the center of this episode of The Briefing.
Dr. Tuboise Floyd sits down with William McBorrough, CISO and Lead CMMC Assessor, to examine what happens when organizations build cybersecurity compliance programs around assessment day instead of the operating capability required for every day after it.
William describes this as a sustainability problem.
Organizations frequently buy audit-readiness services, tools, consulting, and managed services designed to get them through a point-in-time assessment. But when the audit becomes the goal, organizations can immediately begin drifting once the assessment is over because the ongoing activities required by the compliance program were never built into normal operations.
That leads to one of the central arguments of the conversation:
CMMC is a governance problem.
Cybersecurity compliance requires more than a mandate. Governance is a discipline requiring people, skills, processes, accountability, and the capability to perform the work repeatedly.
And an assessor can see the difference.
If an organization's policy says access is reviewed every month, an assessor doesn't simply want to read the policy.
Where are the records?
What process was followed?
Who performed the work?
Can the organization demonstrate that the activity actually occurred?
An assessor is looking for evidence that the program is operating, not merely evidence that somebody documented one.
Then the conversation crosses into AI.
William explains why security leaders increasingly find themselves responsible for AI risk because AI is already entering organizations. Rather than serving as the traditional "voice of no," he describes the security leader's job as finding a secure path to legitimate business objectives.
That raises another governance problem:
How do you use AI without simply turning it loose?
William explains how MCGLOBALTech approaches AI inside its compliance operations.
The organization governs AI by use case, not simply by declaring a particular AI product acceptable. Different uses of the same tool can create very different risks.
There are also boundaries.
AI is not used on client data inside MCGLOBALTech's client environments. AI is instead used for specific approved operational purposes outside those prohibited uses.
And there is an important operating rule:
Do it manually first.
William's team develops the process manually, operates it, validates that the process produces the desired outcome, and only then determines how AI can accelerate or automate it.
The process is not created by AI.
AI is applied after the organization understands the process and knows what a valid outcome should look like.
That distinction matters because AI can produce something that looks convincing even when it is wrong.
As William explains in the conversation, asking AI for a heart-surgery plan may produce something that looks excellent to someone who isn't a heart surgeon.
Expertise is what allows someone to recognize whether the output is actually valid.
The same discipline required for sustainable cybersecurity compliance begins appearing again in AI:
Defined processes.
Clear boundaries.
Validated outputs.
Evidence.
Human judgment.
Accountability.
The episode also gets personal for executives.
CMMC and federal cybersecurity requirements eventually reach the people whose names stand behind what the organization says is true.
William advises CEOs operating in the federal space to examine their contracts, understand the security obligations contained in them, and determine whether their organizations actually possess the capability to meet those obligations.
He also discusses the responsibility of the senior official affirming an organization's compliance information and the importance of having evidence behind what leadership is being asked to stand behind.
The question isn't simply:
Did we pass?
It is:
Can we prove we're still doing what we said we do?
The assessment is a day.
The program is every day after.
IN THIS EPISODE
• CMMC and the compliance sustainability gap
• Passing an assessment versus sustaining compliance
• CMMC Level 2
• What CMMC assessors actually look for
• Evidence versus documentation
• Governance versus audit readiness
• NIST 800-171 requirements
• Cybersecurity inside the Defense Industrial Base
• Small-business compliance challenges
• Governance as an operating discipline
• Executive accountability and attestation
• Security obligations inside federal contracts
• AI governance
• The CISO as an AI governance leader
• Governing AI by use case
• ChatGPT, Claude and Microsoft Copilot
• Separating AI experimentation from controlled environments
• Manual validation before AI automation
• Validated outputs versus convincing outputs
• Continuous review of AI use cases
• Why technology-first procurement fails
• What CEOs should examine now
GUEST
William McBorrough
CISO, Lead CMMC Assessor
MCGLOBALTech
William McBorrough is a cybersecurity and compliance leader whose work spans building, operating, and assessing security governance programs.
He has spent more than 16 years building security compliance programs and has supported defense contractors around NIST 800-171 requirements and cybersecurity compliance.
His work has included organizations ranging from five employees to 5,000 employees, while MCGLOBALTech also serves federal government organizations.
William is also an associate professor of cybersecurity at the University of Maryland Global Campus, serves on the EC-Council Global Advisory Board, publishes the SMB CISO Insights newsletter, and is the author of Beyond Compliance, a governance roadmap focused on sustainable CMMC.
ABOUT THE BRIEFING
The Briefing with Dr. Tuboise Floyd is independent media examining the decisions underneath consequential technology.
AI. Quantum. Cyber.
The technology is only the beginning of the story.
Find the decision.
Follow the evidence.
Name who owns it.
Independent media. Real conversations. Higher stakes.
A Human Signal Production
Hosted by Dr. Tuboise Floyd
Creative Director: Jeremy Jarvis
Watch and listen:
humansignal.io/thebriefing
EDITORIAL / PARTNER DISCLOSURE
MCGLOBALTech is a paying Human Signal partner, and Dr. Tuboise Floyd has performed contract advisory work with the firm.
The partnership does not determine guest selection, questions, editorial conclusions, favorable treatment, or endorsement. Editorial questions and conclusions remain independent.
This podcast uses the following third-party services for analysis:
OP3 - https://op3.dev/privacy
