Topic · 9 articles
Compliance
CMMC, CJIS, CUI, and the control frameworks that land on storage.
Spans Federal & Defense, Sector Spotlight and Executive Briefing.

CJIS Security Changes for 2026 and 2027: What State and Local Agencies Need to Know
Two dates now shape CJIS planning for state and local agencies: the FIPS 140-2 sunset on September 21, 2026, and the end of the zero-cycle period on September 30, 2027. Here is what each one actually requires, and why so much of the work lands on storage.
11 min read

Harvest now, decrypt later: post-quantum encryption reaches the data layer
Two executive orders, three NIST standards, and NSA’s CNSA 2.0 have turned post-quantum cryptography from research topic into procurement requirement. What the mandates actually say, and how BrickStor SP is post-quantum ready for data at rest and data in transit.
6 min read

Sharing without surrender: NATO’s data strategy and the storage layer
NATO’s Data Strategy for the Alliance sets a 2030 target: federated data sharing across the Alliance while every ally keeps control of its own data. Sharing and sovereignty at once is not a networking problem. It is a mandate for enforcement that lives where the data lives.
6 min read

Zero Trust reaches the data pillar
What Zero Trust security is, where it came from, and how the CISA and DoD Zero Trust Maturity Models differ, who each applies to, and why both converge on the data pillar.
9 min read

Why healthcare keeps paying the highest breach costs
Healthcare has carried the highest average breach cost of any industry for more than a decade. The five reasons why trace back to the data itself: sensitive, regulated, sprawling, and largely unstructured.
6 min read

CUI lives in files. Protect it there.
Controlled Unclassified Information is overwhelmingly unstructured: drawings, specs, contract documents on file shares. CMMC compliance increasingly comes down to whether you can label, control, and account for those files, which is exactly what data labeling and ABAC at the storage layer deliver.
7 min read

Understanding CMMC: A Practical Guide for Defense Contractors
What CMMC is, who must comply, the three levels, the phased enforcement timeline through 2028, and the path to certification for defense contractors handling FCI and CUI.
10 min read

Recovery time is now a disclosure question
Regulators, insurers, and customers increasingly ask the same two questions after an incident: how fast were you back, and what exactly was taken? Both answers are determined at the data layer, before the incident ever happens.
2 min read

A board-level view of unstructured data risk
Most of an organization’s data is unstructured files, and most of its risk concentrates there. A short briefing for executives on why the storage layer belongs on the risk register.
2 min read
See data-layer defense in your environment
In a 30-minute demo we’ll show Active Defense stopping an attack inline, immutable recovery, and surgical rollback — mapped to your data and your threats.
