FAQs

Red 3D question marks on a white background.
  • Yes, Dovestech is a DoD CMMC pioneer, and it led the creation of a first in the nation CMMC compliance cyber testing and compliance cyber physical range designed to simulate manufacturing environments.  The range also tested cyber solutions for the manufacturing sector and for the Department of Defense. 

    Dovestech was the top resource as a subcontractor for a DoD CMMC training and readiness program funded by DoD and other DoD components to support DoD defense small businesses with CMMC readiness.  

    Dovestech trained NSA Centers of Academic Excellence in Cybersecurity Colleges and Universities in cybersecurity and CMMC compliance and through an internship created by a Dovestech executive advisor, leveraged the trained students to assist the DoD small businesses.  This project garnered an international innovation award for its use of the cloud, virtual hands-on cybersecurity training with a national reach, and its work in lowering the cost of compliance through automation. 

    Dovestech consultants helped to orchestrate many of the first and largest virtual and in person CMMC conferences from 2019 – 2022.

  • Dovestech currently provides NIST RMF compliance and risk assessments for a major intelligence community customer and DoD customers.  Dovestech is experienced in the use of Emass, and Xacta for cybersecurity NIST RMF workflow, and body of evidence and assessment adjudication. 

    Dovestech also conducts cyber risk and compliance assessments for major cloud data centers around the U.S. using the NIST RMF, SOC 2 (readiness), EN 5050 and other cybersecurity frameworks. 

    Dovestech has assisted the intelligence community, State and Local Government, Government Contractors and the Department of Defense with NIST RMF Compliance. 

    Tell me about cyber compliance training Dovestech has executed – Dovestech has curated training for the Defense Industrial Base, manufacturers, healthcare providers, the Department of Defense and the financial sector on cybersecurity compliance.  Examples of compliance frameworks and polices that we have provided training for include:

    • The Cybersecurity Maturity Model Certification (CMMC)

    • Cloud Cybersecurity

    • NIST RMF

    • SOC 2

    • HIPDAA 

    • PCI DSS

    • GDPR 

    • Various maritime cybersecurity 

    • Zero Trust 

    • Cybersecurity for manufacturing networks and operations 

    • Medical IoT cybersecurity 

    • Building/facilities cybersecurity

  • Yes.  Dovestech conducted continuous semi-automated pen testing for the defense industrial base companies subscribed to its continuous compliance, vulnerability management and pen testing cloud platform it developed for a DoD project. 

    Dovestech was an advisor on a recent artificial intelligence pen testing project for a FINTECH company. 

    Dovestech led the pen testing for several commercial companies across the United
    States.

  • Dovestech has bene actively reviewing existing AI cybersecurity frameworks for a government agency and making recommendations designed to enhance the cybersecurity compliance of AI cloud and other applications as part of NIST RMF compliance efforts. 

    Dovestech was the senior advisor on the pen testing of a FINTECH company. 

    Dovestech is reviewing the AI technology stack for AWS and other cloud service provider solutions for a government customer and commenting on aspects that could lead to vulnerabilities or exploitation.

  • Yes.  Most of our work has been in the intelligence and Department of Defense Community but we have developed analytic applications for mass amounts of unstructured data.  Dovestech has developed insider threat detection solutions for the U.S. Government. Dovestech staff helped to develop custom industrial control systems (ICS) drivers for mission critical ICS power and cooling systems located overseas that needed agile remote control and mean time to failure monitoring. 

  • Dovestech is conducting NIST RMF assessments for the U.S. government for AWS and as needed other cloud service providers such as Google, Microsoft and Oracle. 

    Dovestech assesses cyber risks that may be present in no fail data centers for various cloud service providers utilizing the NIST RMF and industrial control systems (ICS) cybersecurity frameworks. 

    Dovestech has led efforts to migrate companies from one cloud service provider to another. 

  • Yes.  Many of the Dovestech team hold the proper credentials to perform work at sensitive government facilities and on sensitive projects. 

    Does Dovestech have critical infrastructure systems (ICS) cybersecurity experience?  Absolutely.  Dovestech has worked with ICS solutions from Nozomi Networks, Tenable, Cisco, Claroty, Dragos and others. 

    Dovestech has tested several ICS solutions from many manufacturers and helped to design a critical infrastructure testing lab for ICS technologies for maritime, manufacturing, water plants, aviation, and facilities. 

    Dovestech continues to be a resource for manufactures seeking to secure their plant operations and comply with cybersecurity regulations. 

  • U.S. Cyber Command, the National Security Agency, the Marines, the U.S. Air Force, the U.S. Department of State, Library of Congress and many more.