A story we hear too often
The 40-person machine shop that is one link in a national supply chain
the owner of a precision machine shop that makes parts for a prime’s missile program
Frank’s shop in Rockford makes forty-one parts. Nobody outside the program knows what they go into, and Frank likes it that way. Forty people, three shifts when the prime is busy, and a drawing package marked CUI that arrives by email because that is how the prime sends it.
A Tuesday in September. The prime’s supplier-security team calls: a leak site is advertising files from ‘a Midwest defense machine shop,’ and the sample includes a drawing with the program number on it. Frank does not know yet whether it is his.
In the version that becomes a national-security story, it is his. The drawings sat on a shared drive with the office email, the CAM vendor’s remote-access box was never patched, and the 72-hour DFARS 7012 clock started three days ago without anyone knowing. The prime suspends the supplier, and the SPRS score Frank posted is now a false statement.
In Frank’s version, the CUI never touched the shared drive. It lives in the enclave, the remote-access box was patched the week the vulnerability was published, and the engineer on watch can show the prime, that afternoon, which files left. None did. The sample belongs to another shop. Frank sends the prime his SSP and his incident log by five.
A leak site is advertising files from ‘a Midwest defense machine shop,’ and the sample includes a drawing with the program number on it.
What changes the ending
- CUI contained in an enclave, away from the office email and the shared drive (NIST 800-171 3.1 and 3.13; CIS Control 3, Data Protection)
- Remote-access and vendor connections inventoried and patched against the CISA Known Exploited Vulnerabilities list (CIS Controls 7 and 15)
- A 72-hour incident reporting procedure rehearsed, with logs that show what left and what did not (NIST 800-171 3.6; CIS Controls 8 and 17)