
Hosted by Charles Denyer · ENGLISH

In this episode of The Brief, Charles Denyer continues his 8-part CMMC series with Step 4: CUI Storage — where Controlled Unclassified Information lives at rest in your environment, and why this is where compliance scope explodes most unexpectedly. Building on the processing framework from Episode 28, Charles explains that CUI does not disappear once work is finished. It persists — in primary repositories, collaboration platforms, application databases, endpoint profiles, backup vaults, archives, and email tenants — often long after the people who put it there have stopped thinking about it. He walks through a structured, workbook-driven methodology covering three matrices and a supporting gaps log designed to make every CUI storage location visible, classified, evidenced, and defensible. The Brief is a Charles Denyer Productions podcast hosted by Charles Denyer. Learn more at charlesdenyer.com | Instagram: @denyer.charles | Facebook: @charles.denyerQuestions/Topics/Advertising: info@charlesdenyer.comDisclaimer: The Brief is a podcast produced by Charles Denyer Productions. The views and opinions expressed by the host and any guests are their own and do not constitute legal advice.

In this episode of The Brief, Charles Denyer continues his 8-part CMMC series with Step 3: CUI Processing and Transformation — what actually happens to Controlled Unclassified Information after it enters your environment, and why this is where risk concentrates and assessors probe hardest. Building on the ingestion framework established in Episode 27, Charles explains that CUI rarely stays static after arrival. It gets viewed, edited, analyzed, exported, annotated, and transformed through the normal course of engineering, proposals, testing, and program execution — and every one of those activities creates artifacts. Drafts, working files, autosave copies, intermediate outputs, cached downloads, and derivative reports are where CUI quietly spreads, where scope silently expands, and where compliance programs that looked solid on paper begin to break down under real assessment conditions. He walks through a structured, workbook-driven methodology covering three matrices and two supporting logs designed to make CUI processing visible, mapped, and defensibleThe Brief is a Charles Denyer Productions podcast hosted by Charles Denyer. Learn more at charlesdenyer.com | Instagram: @denyer.charles | Facebook: @charles.denyerQuestions/Topics/Advertising: info@charlesdenyer.comDisclaimer: The Brief is a podcast produced by Charles Denyer Productions. The views and opinions expressed by the host and any guests are their own and do not constitute legal advice.

In this episode of The Brief, Charles Denyer continues his 8-part CMMC series by breaking down Step 2: CUI Ingestion—how Controlled Unclassified Information actually enters your environment and why this is where most organizations lose control of their compliance scope. Building on the foundation established in Episode 26, Charles explains that defining CUI is only the beginning. The real challenge lies in controlling how that data flows into your systems through contracts, vendors, email, file transfers, and internal processes. He walks through a structured, workbook-driven methodology for identifying ingestion points, validating incoming data, restricting approved channels, and aligning all entry points to your system boundary. This episode makes one thing clear: if you cannot control how CUI enters your environment, your scope is already compromised. And if your scope is not controlled, your compliance program will not withstand assessment.The Brief is a Charles Denyer Productions podcast hosted by Charles Denyer. Learn more at charlesdenyer.com | Instagram: @denyer.charles | Facebook: @charles.denyerQuestions/Topics/Advertising: info@charlesdenyer.comDisclaimer: The Brief is a podcast produced by Charles Denyer Productions. The views and opinions expressed by the host and any guests are their own and do not constitute legal advice.

In this episode of The Brief, Charles Denyer shifts from foundational concepts to real-world execution by breaking down the most critical step in any CMMC program: defining and identifying Controlled Unclassified Information (CUI) with precision and authority. Drawing directly from his CUI Definition Workbook, Charles walks through a structured, contract-driven methodology for determining what actually qualifies as CUI within your environment—and just as importantly, why. This is not a theoretical discussion. It is a step-by-step operational approach that forces organizations to move beyond assumptions and establish traceability between contract requirements, CUI categories, and the actual data flowing through their systems.He explains how CUI enters and is created within an organization, how derivative data expands risk, and why failing to properly define CUI leads to uncontrolled scope, misaligned controls, and failed assessments. The episode also highlights the importance of documenting what is not CUI, preventing scope creep that can significantly increase compliance cost and complexity.If your CUI cannot be mapped, categorized, and defended with evidence, then your compliance program is already unstable. This episode establishes the foundation required to build a truly controlled, defensible, and audit-ready CMMC environment.The Brief is a Charles Denyer Productions podcast hosted by Charles Denyer. Learn more at:• charlesdenyer.com• Instagram: @denyer.charles• Facebook: @charles.denyerQuestions/Topics/Advertising: Have a topic you'd like Charles to cover on the podcast? Interested in advertising opportunities or something else? Reach out anytime at info@charlesdenyer.com Disclaimer: The Brief is a podcast produced by Charles Denyer Productions. The views and opinions expressed by the host and any guests are their own and do not constitute legal advice.

In this episode of The Brief, Charles Denyer takes a deep dive into one of the most critical—and most consistently misunderstood—foundations of CMMC compliance: the relationship between Controlled Unclassified Information (CUI) and your true audit scope. Most defense contractors believe they understand where their CUI resides and how it’s controlled. But when that assumption is tested under real assessment conditions, it almost always breaks down. What appears to be progress on paper often reveals gaps in definition, visibility, and control that expand risk in ways organizations don’t fully recognize.In this episode, Charles introduces the first two steps of his structured 8-step framework for building a defensible CMMC program: precisely defining CUI and controlling how it enters your environment. He explains why scope is not defined by policy or intent—but by where CUI actually exists—and how uncontrolled data flows silently and continuously expand that scope.This is not theoretical compliance. This is operational reality.If you cannot clearly define CUI, trace it, and prove how it is controlled, then you are not prepared for a CMMC assessment—you are exposed.This episode sets the foundation for everything that follows.The Brief is a Charles Denyer Productions podcast hosted by Charles Denyer. Learn more at:• charlesdenyer.com• Instagram: @denyer.charles• Facebook: @charles.denyerQuestions/Topics/Advertising: Have a topic you'd like Charles to cover on the podcast? Interested in advertising opportunities or something else? Reach out anytime at info@charlesdenyer.com Disclaimer: The Brief is a podcast produced by Charles Denyer Productions. The views and opinions expressed by the host and any guests are their own and do not constitute legal advice.

In this episode of The Brief, Charles Denyer breaks down Controlled Unclassified Information (CUI)—one of the most critical and misunderstood requirements facing today’s defense contractors. Using real-world examples from machining firms, aerospace suppliers, and IT service providers, Denyer explains how CUI actually shows up in everyday operations and why many organizations are handling it without realizing the compliance obligations it triggers. He walks through how CUI flows across the defense supply chain, why it activates requirements under NIST 800-171 and CMMC, and how seemingly small operational decisions—like sharing files or granting access—can create serious risk. This episode makes it clear that CUI is not just a labeling requirement, but a fundamental shift in accountability. For organizations working with the Department of Defense, understanding where CUI exists and proving it is protected is no longer optional—it is essential to maintaining contracts, passing audits, and staying competitive.The Brief is a Charles Denyer Productions podcast hosted by Charles Denyer. Learn more at:• charlesdenyer.com• Instagram: @denyer.charles• Facebook: @charles.denyerQuestions/Topics/Advertising: Have a topic you'd like Charles to cover on the podcast? Interested in advertising opportunities or something else? Reach out anytime at info@charlesdenyer.com Disclaimer: The Brief is a podcast produced by Charles Denyer Productions. The views and opinions expressed by the host and any guests are their own and do not constitute legal advice.

In this episode of The Brief, Charles Denyer explores why most information security policies fail—not because organizations lack documentation, but because that documentation becomes static, outdated, and disconnected from reality. What starts as a structured, well-intentioned effort—complete with approved policies across access control, incident response, and vendor risk—often fades into irrelevance when it’s not actively maintained. Denyer explains how rapid shifts in technology, from cloud adoption to AI integration, outpace traditional governance models, creating hidden gaps and “risk debt.” He emphasizes that policies alone don’t protect organizations—people do, and only when those policies are clear, actionable, and embedded into daily operations. Through a practical “living policy” framework, he outlines how organizations can create accountability, integrate policies into workflows, and continuously refine them through real-world feedback. The core message: security is not a one-time exercise—it’s a dynamic, ongoing discipline.. The Brief is a Charles Denyer Productions podcast hosted by Charles Denyer. Learn more at:• charlesdenyer.com• Instagram: @denyer.charles• Facebook: @charles.denyerQuestions/Topics/Advertising: Have a topic you'd like Charles to cover on the podcast? Interested in advertising opportunities or something else? Reach out anytime at info@charlesdenyer.com Disclaimer: The Brief is a podcast produced by Charles Denyer Productions. The views and opinions expressed by the host and any guests are their own and do not constitute legal advice.

In episode 22 of The Brief with Charles Denyer, we tackle one of the most misunderstood — and dangerous — gaps in cybersecurity and compliance: the difference between policies and procedures.Charles exposes why so many companies think they’re secure because they have documentation — when in reality, most of it is just “shelfware.” He breaks down how policies define the what, while procedures define the how, and why both are essential for surviving audits, breaches, and today’s evolving threat landscape.Through real-world stories, hard-hitting examples, and field-tested advice, you’ll learn how to transform your documentation from static PDFs into living, operational tools that actually protect your business. From backups to access control, Charles shows how small details — like who verifies, when, and how — make the difference between passing an audit and failing a crisis.If you’ve ever wondered why your compliance program feels like paperwork instead of protection, this episode will change how you think about documentation forever.The Brief is a Charles Denyer Productions podcast hosted by Charles Denyer. Learn more at:• charlesdenyer.com• Instagram: @denyer.charles• Facebook: @charles.denyerQuestions/Topics/Advertising: Have a topic you'd like Charles to cover on the podcast? Interested in advertising opportunities or something else? Reach out anytime at info@charlesdenyer.com Disclaimer: The Brief is a podcast produced by Charles Denyer Productions. The views and opinions expressed by the host and any guests are their own and do not constitute legal advice.

In episode 21 of The Brief with Charles Denyer, we uncover the hidden truth behind most security failures — not weak firewalls or fancy zero-days, but neglected policies and forgotten procedures. Charles takes you inside the boardrooms and breach investigations where “policy shelfware” — beautifully written, rarely followed — has cost companies millions in damages and trust.Through riveting storytelling and hard-earned lessons from over 2,000 security and compliance engagements, Charles reveals why information security documentation is far more than an audit requirement — it’s the backbone of every resilient organization. You’ll learn how to distinguish between a policy’s intent and a procedure’s execution, why customization is critical in today’s evolving threat landscape, and how to bring your documentation to life through ownership, training, and testing.This isn’t another lecture on compliance — it’s a reality check on leadership, accountability, and the price of complacency.The Brief is a Charles Denyer Productions podcast hosted by Charles Denyer. Learn more at:• charlesdenyer.com• Instagram: @denyer.charles• Facebook: @charles.denyerQuestions/Topics/Advertising: Have a topic you'd like Charles to cover on the podcast? Interested in advertising opportunities or something else? Reach out anytime at info@charlesdenyer.com Disclaimer: The Brief is a podcast produced by Charles Denyer Productions. The views and opinions expressed by the host and any guests are their own and do not constitute legal advice.

Every year, companies spend billions on security awareness training — yet the breaches keep coming. Why? Because most of it doesn’t work.In The Brief with Charles Denyer, Episode 20: “The Great Security Awareness Training Scam: How a Billion-Dollar Industry Is Failing to Protect You,” Charles exposes the truth behind the glossy videos, generic PowerPoints, and annual compliance courses that give executives comfort but leave organizations defenseless.You’ll hear why the once-a-year “click next to continue” model is a dangerous illusion — and how attackers exploit the exact human behaviors these programs fail to change. Through real-world stories, psychological insights, and hard-hitting analysis, Charles reveals how to replace outdated, performative training with continuous, micro-based, real-world learning that actually works.This isn’t just another cybersecurity talk — it’s a wake-up call for every organization still treating awareness as an obligation instead of a weapon.Because the next breach won’t come from a firewall failure — it’ll come from a click, a habit, or a moment of misplaced trust that your training didn’t fix.The Brief is a Charles Denyer Productions podcast hosted by Charles Denyer. Learn more at:• charlesdenyer.com• Instagram: @denyer.charles• Facebook: @charles.denyerQuestions/Topics/Advertising: Have a topic you'd like Charles to cover on the podcast? Interested in advertising opportunities or something else? Reach out anytime at info@charlesdenyer.com Disclaimer: The Brief is a podcast produced by Charles Denyer Productions. The views and opinions expressed by the host and any guests are their own and do not constitute legal advice.