top of page
Search

Synagex was proud to once again attend and sponsor MassMEP’s Manufacturing Your Future, representing cybersecurity and CMMC alongside manufacturers and industry partners from across Massachusetts.


MYF is all about bringing the manufacturing community together to connect, learn, and explore the resources and solutions helping Massachusetts manufacturers move forward. And you know we’re always happy to be part of IT. 😎


🤝 Our Partnership with MassMEP


This event is just one piece of a relationship we’re pretty proud of. Synagex and MassMEP have worked together to help manufacturers across Massachusetts better understand cybersecurity, CMMC, and what it all actually means for their businesses.



As MassMEP’s Olivia put it, “Synagex is a true partner to MassMEP, providing cybersecurity support to manufacturers all across Massachusetts.”


We couldn’t have said IT better ourselves. And, wait... Did She Just Call Us FUN?!


Okay, we’ll take IT. Because that’s exactly what we’ve always wanted Modern IT to be. Simple. Result-focused. Human. Engaging. Great technology backed by great people, processes, tools, and strategy.


🔐 Talking CMMC with PreVeil



We also had Dan from PreVeil join us at the Synagex booth, where we were ready to talk all things CMMC, answer questions, and, perhaps equally important... hand out some pretty cool swag. Because CMMC might be serious business, but talking about IT doesn’t have to be boring!


Thanks to MassMEP, Dan, and everyone who stopped by to talk with us. We’re proud to support Massachusetts manufacturers and even prouder to apparently have official confirmation that we can make cybersecurity fun. 😎

 
 
 
Writer: Synagex Modern IT
Synagex Modern IT
May 7
2 min read

It’s World Password Day, which means it’s time to talk about one of the oldest pieces of cybersecurity advice around: use a strong password. Our own Leah is sharing some password advice in the video above. We’re adding a few tips of our own, along with some ways to make password security a little less... boring.


Simple enough, right? And yet somewhere out there, someone is still protecting their email, bank account, and half their digital life with Password123!.


First Things First: Longer Is Better


If your idea of a strong password is taking your usual password and adding an exclamation point, we have some news. 😬


Current NIST guidance puts much more emphasis on password length than complicated formulas requiring a specific combination of uppercase letters, numbers, and symbols. For a password used on its own, NIST recommends at least 15 characters.


One way to get there is with a passphrase: a longer combination of unrelated words that's easier for you to remember but difficult for someone else to guess.


Think less: Fluffy1!

And more: Something long, random, and uniquely yours.


Just don't use our examples as your actual password. That would make this a very unsuccessful cybersecurity blog.


Stop Reusing Passwords. Seriously.


We get IT. Remembering dozens of unique passwords sounds terrible.


But using the same password everywhere creates a much bigger problem. If that password is exposed in a breach, attackers can try the same credentials on your other accounts, a technique commonly called credential stuffing. NIST specifically recommends distinct passwords to help prevent this.


Think of password reuse like having one key that opens your house, car, office, safe, and everything else you own.


Convenient? Sure. Great if someone steals the key? Not so much.


Let a Password Manager Remember Them for You


So how are you supposed to remember a different long password for every account?


You aren't.


A reputable password manager can generate and securely store long, unique passwords so you don't have to keep them all in your head. NIST highly recommends password managers for accounts that still require passwords. That also means we can finally retire the sticky note under the keyboard.


And because your password-manager account holds the keys to the kingdom, protect it with a strong master passphrase and MFA.


Add MFA


A strong password is good. A strong password plus multifactor authentication? Better.


MFA adds another layer of verification so a stolen password alone may not be enough to access your account. NIST recommends setting up MFA and notes that passkeys can be an even stronger option where they're supported.


Synagex Password Hygiene Quick List:


  • Use long, unique passwords or passphrases.

  • Stop reusing passwords across accounts.

  • Use a password manager to generate and store them.

  • Turn on MFA wherever you can.

  • Replace passwords with passkeys when they're available and appropriate.


And most importantly, remember that cybersecurity doesn't have to be complicated to make a difference!


Happy World Password Day from all of us at Synagex Modern IT. Stay secure, folks, and as always, Keep IT Cool. 😎

 
 
 

What Manufacturers Should Really Be Thinking About as CMMC Certification Assessments Become Reality


CMMC certification assessments are no longer a distant “someday” problem for manufacturers in the Defense Industrial Base. They are becoming a very real part of Department of Defense contracting requirements, and organizations are starting to realize that readiness is about far more than simply “having cybersecurity.”

Synagex's own Cathy and John recently joined MassMEP for a Webinar to dive deep into the details—read on for the highlights!



The ultimate question is no longer “What is CMMC?”

It’s: Are. You. Ready?


Readiness Starts with Asking the Right Questions. The reality is, this is not something organizations can simply flip a switch and suddenly become prepared for—The devil is all in the details. Here's some important readiness questions organizations should be thinking about right now:

  • Do you clearly understand your assessment scope?

  • Can you document how CUI and FCI move through your environment?

  • Can you define your internal and external boundaries?

  • Has leadership been involved in the process?

  • Are your External Service Providers (ESPs) assessment-ready too?


At first glance, those questions sound straightforward. But as Cathy explained throughout the webinar, confidently answering them often requires organizations to dig much deeper into their environment, documentation, operations, and processes than they initially expect.


CMMC Is Becoming Operational


Another takeaway from the webinar was that CMMC is moving from theory into operational reality. Organizations may initially complete self-assessments, but certification assessments are increasingly becoming the long-term expectation for many defense contractors. And unlike a one-time project, compliance must be maintained over time through:

  • Ongoing documentation

  • Annual reviews

  • Risk assessments

  • Incident response testing

  • Awareness training

  • Provider management

  • Continuous readiness activities


Organizations should stop viewing CMMC as a temporary initiative and start treating it as an ongoing business process.


Documentation Is Where Many Organizations Struggle


As Cathy explained, every time a control objective says “define” or “identify,” assessors will expect organizations to provide evidence supporting it. That includes much more than a few security policies sitting in a folder. Organizations should be prepared to maintain:

  • Network diagrams

  • CUI data flow diagrams

  • Asset inventories

  • User inventories

  • Shared responsibility matrices

  • Policies and procedures

  • Risk registers

  • Boundary documentation



Good documentation helps organizations clearly explain their environment to assessors rather than forcing assessors to piece the story together themselves.

And during a certification assessment, clarity matters.


Scope Is Bigger Than Most Organizations Think


Another important point discussed during the webinar was scope.

Many organizations assume CMMC only applies to the systems directly storing Controlled Unclassified Information (CUI). But assessments often involve much more than that. Assessors may also evaluate:

  • Facilities

  • Employees

  • External Service Providers

  • Security systems

  • Cloud providers

  • Operational technology

  • Specialized assets like IoT devices and manufacturing systems



This becomes especially important for manufacturers with industrial systems, smart devices, and segmented operational environments. Understanding how those systems fit into your assessment scope is a critical part of readiness.


Mock Assessments Are Becoming Increasingly Valuable

Many organizations have already completed initial gap assessments and are now looking for help preparing for what a real certification assessment will actually feel like.

Mock assessments can help organizations:

  • Practice interviews

  • Validate documentation

  • Test evidence collection

  • Identify remaining gaps

  • Better understand assessor expectations


In many cases, readiness preparation can significantly reduce surprises during the actual assessment process.


So… Are You Ready?

That question is becoming more important by the day!

Folks, organizations that prepare early will have options, confidence, and a much smoother path forward. Organizations that wait until requirements suddenly appear in contracts may find themselves scrambling to understand concepts they should have started addressing months...or years earlier.


The good news? You do not have to figure this all out alone. As a Registered Practitioner Organization (RPO), Synagex Modern IT works with manufacturers and defense contractors to help simplify the CMMC journey through:

  • Gap assessments

  • Readiness planning

  • Documentation guidance

  • Compliance strategy

  • Ongoing cybersecurity support


Watch the Webinar



We recommend checking out the full session for deeper guidance from Cathy and John. And if you need help preparing your organization for what comes next… Synagex is here if you need IT. 😎

 
 
 

Headquarters

703 West Housatonic St

Suite 108

Pittsfield, MA 01201

Colorado Service Branch

143 Union Blvd 

Suite 900 

Lakewood, CO 80228

Innovation Office

Berkshire Innovation Center

45 Woodlawn Ave

Pittsfield, MA 01201

What is Synagex?

Synagex Modern IT is a simple IT and cybersecurity solution for businesses. Synagex delivers the entire IT ecosystem and cybersecurity protection that every business needs and combines that with strategy to enable business growth. Synagex is also a Registered Provider Organization (RPO) providing CMMC assessments and extensive cybersecurity services. All Synagex services have the same guiding principle simplifying concept to service delivery.

RPO CYBER AB BADGE.png

Follow Us On:

  • LinkedIn
  • Facebook
  • Instagram

© 2023 by Synagex

bottom of page