Topic · 8 articles
Government & Defense
Federal, defense, and state and local mission data.
Spans Federal & Defense and Threat Brief.

CJIS Security Changes for 2026 and 2027: What State and Local Agencies Need to Know
Two dates now shape CJIS planning for state and local agencies: the FIPS 140-2 sunset on September 21, 2026, and the end of the zero-cycle period on September 30, 2027. Here is what each one actually requires, and why so much of the work lands on storage.
11 min read

Valid logins, an MFA bypass, and 678,000 records: the French tax breach
France’s tax administration disclosed that an attacker used a staff account and a contractor account, plus a multi-factor bypass, to consult and extract data on 678,000 people and businesses. Nothing was encrypted. Every query looked like work.
5 min read

Harvest now, decrypt later: post-quantum encryption reaches the data layer
Two executive orders, three NIST standards, and NSA’s CNSA 2.0 have turned post-quantum cryptography from research topic into procurement requirement. What the mandates actually say, and how BrickStor SP is post-quantum ready for data at rest and data in transit.
6 min read

Sharing without surrender: NATO’s data strategy and the storage layer
NATO’s Data Strategy for the Alliance sets a 2030 target: federated data sharing across the Alliance while every ally keeps control of its own data. Sharing and sovereignty at once is not a networking problem. It is a mandate for enforcement that lives where the data lives.
6 min read

Zero Trust reaches the data pillar
What Zero Trust security is, where it came from, and how the CISA and DoD Zero Trust Maturity Models differ, who each applies to, and why both converge on the data pillar.
9 min read

CUI lives in files. Protect it there.
Controlled Unclassified Information is overwhelmingly unstructured: drawings, specs, contract documents on file shares. CMMC compliance increasingly comes down to whether you can label, control, and account for those files, which is exactly what data labeling and ABAC at the storage layer deliver.
7 min read

Understanding CMMC: A Practical Guide for Defense Contractors
What CMMC is, who must comply, the three levels, the phased enforcement timeline through 2028, and the path to certification for defense contractors handling FCI and CUI.
10 min read

A government paid $1 million to Kairos — and the blockchain shows it recovered nothing
Fresh analysis this week traces a roughly $1 million extortion payment from a U.S. government entity to the Kairos group, for data that was never encrypted, only stolen. The payment is visible on the blockchain. The files were taken anyway.
5 min read
See data-layer defense in your environment
In a 30-minute demo we’ll show Active Defense stopping an attack inline, immutable recovery, and surgical rollback — mapped to your data and your threats.
