For defense suppliers, one convincing email can become a contract-threatening incident.
Attackers do not need to defeat every firewall, exploit every server, or compromise every endpoint. They need one employee to trust the wrong message, open the wrong attachment, visit a fake subcontractor portal, or approve a fraudulent payment request. From there, stolen credentials can become a direct path toward Controlled Unclassified Information (CUI).
For many defense contractors, phishing remains the primary human entry point into a CUI environment. The answer is not to blame employees. The answer is to equip them with practical training, and surround them with an enclave engineered to limit damage when a mistake occurs.
That is the purpose of CPE Level 2.
The Real Fear: A Single Click Could Cost You a Contract
Defense industry personnel are targeted because their access has value.
An attacker may research your company, identify your program managers, imitate a prime contractor, and create a message that looks completely normal. The message may reference:
- A current contract or solicitation
- A real executive’s name
- A known subcontractor
- A legitimate delivery deadline
- A project number or purchase order
- A shared document requiring immediate review
- A security or Microsoft 365 notification
The goal is often not immediate malware execution. It may be credential harvesting: capturing a username, password, session token, or multifactor authentication approval.
Once credentials are abused, attackers can attempt to:
- Access email and collaboration tools.
- Search for CUI-related terms and files.
- Impersonate executives or contract personnel.
- Move laterally toward systems holding CUI.
- Establish persistence for future access.
- Exfiltrate information without obvious disruption.
The risk is operational, contractual, and reputational. A defense supplier cannot treat phishing as merely an IT inconvenience.

How CMMC 2.0 Level 2 Addresses the Human Attack Surface
CMMC 2.0 Level 2 addresses the protection of CUI through 110 security requirements and 320 assessment objectives aligned with NIST SP 800-171 Revision 2.
Three Awareness and Training requirements are directly relevant to phishing defense:
AT.L2-3.2.1 , Role-Based Risk Awareness
Managers, system administrators, and users must understand:
- The security risks associated with their activities
- Applicable security policies and procedures
- Their responsibilities when handling CUI
- How to recognize and report suspicious activity
The official CMMC Assessment Guide specifically identifies awareness techniques such as simulated phishing emails, security reminders, email advisories, and recurring awareness activities.
AT.L2-3.2.2 , Role-Based Training
Security responsibilities must be assigned and personnel must be trained to perform them.
This is especially important for:
- System administrators
- Security personnel
- Program managers
- Help desk staff
- Personnel managing privileged accounts
- Employees responsible for incident reporting
- Personnel who administer CUI systems
A system administrator who clicks a phishing link presents a different risk from a general user. Training must reflect the role, the permissions, and the potential impact.
AT.L2-3.2.3 , Insider Threat Awareness
CMMC requires training on recognizing and reporting potential indicators of insider threat. This includes unusual access, suspicious behavior, policy violations, and misuse of legitimate credentials.
A compromised account may look like an insider threat because the attacker is operating through valid access. Employees must know how to report:
- Unexpected multifactor authentication prompts
- Unusual login notifications
- Requests for access outside normal job duties
- Large or unusual file transfers
- Suspicious contacts or instructions
- Repeated attempts to bypass procedures
Training is not complete when a video ends. Assessors expect evidence that awareness exists, is delivered to the right personnel, and is reinforced over time.
Three Realistic Phishing Scenarios Defense Suppliers Face
1. CEO Fraud and Executive Impersonation
A finance employee receives an urgent message that appears to come from the company president:
“I am in a meeting with the customer. Please process this wire transfer immediately and keep this confidential.”
The email uses the correct signature, familiar language, and a spoofed or lookalike domain.
The objective may be financial fraud, but the same method can be used to request:
- CUI attachments
- Contract documents
- Employee account information
- Vendor credentials
- Access to a shared drive
The defense: Require independent verification for sensitive requests. A phone call to a known number: not a number included in the email: can stop the attack.
2. Fake Subcontractor Portals
A project manager receives an email from a supposed subcontractor stating that updated drawings, specifications, or compliance forms are available in a new portal.
The link leads to a convincing login page. The portal may imitate Microsoft, a prime contractor, or a real supplier.
The attacker captures the user’s credentials and may immediately attempt access to email, remote services, or file repositories.
The defense: Users should access portals through known bookmarks or approved applications: not unsolicited links. CPE Level 2 also supports controlled information flows, managed remote access, and monitoring of suspicious authentication activity.
3. Credential Harvesting Through “Security Alerts”
An employee receives a message warning that their account will be disabled unless they “verify identity” within 30 minutes.
The page requests:
- Username and password
- Multifactor authentication approval
- Recovery codes
- Security questions
- A phone number or alternate email address
The defense: Teach employees that urgency is a warning sign. CPE Level 2 adds technical controls such as multifactor authentication, access restrictions, session controls, and monitoring to reduce the impact of stolen credentials.
Why CPE Level 2 Turns Employees Into a Strength
A training program helps employees make better decisions. An enclave ensures one bad decision does not automatically become an enterprise-wide compromise.
CPE Level 2 provides a purpose-built, managed environment designed to protect CUI through layered safeguards, including:
- Network segmentation that limits unauthorized movement
- Least-privilege access so users receive only the access required for their roles
- Separation of user and system-management functionality
- Controlled CUI flow between approved sources and destinations
- Deny-by-default network communications
- Multifactor authentication
- Managed remote access
- Malicious-code protection and file scanning
- Centralized audit logging and correlation
- Security alerting and incident response support
- Backups and protected recovery processes
- Ongoing maintenance, patching, and compliance monitoring
- 900+ targeted hardening steps
- Security awareness and role-based training
- vCISO-level guidance and audit support
If a user clicks a malicious link, these controls can help prevent the user from reaching privileged functions, moving freely across the environment, or transferring CUI to an unauthorized destination.
The goal is not to pretend people never make mistakes. The goal is to make the environment resilient when mistakes occur.

Continuous Monitoring Detects Credential Abuse
Phishing defense does not end after a user reports a suspicious email.
CPE Level 2 supports continuous monitoring for indicators such as:
- Login attempts from unusual locations
- Abnormal access times
- Repeated failed authentication attempts
- New or unapproved devices
- Suspicious remote sessions
- Unusual use of privileged functions
- Unexpected access to CUI repositories
- Abnormal file downloads or transfers
- Communications with high-risk external systems
CMMC requirements such as AU.L2-3.3.1, AU.L2-3.3.2, AU.L2-3.3.5, CA.L2-3.12.3, SI.L2-3.14.6, and SI.L2-3.14.7 reinforce the need for logging, accountability, audit correlation, continuous control monitoring, attack detection, and identification of unauthorized use.
Training catches the human warning signs. Monitoring catches the technical warning signs. Together, they create a far stronger defense.
Planet Security also applies AI-obfuscated data in AI-enabled workflows. Generic AI tools cannot be trusted with client data, CUI, or sensitive operational details. AI-assisted security operations must protect the information being analyzed: not create a new exposure point through a Big-Tech workflow.
A Practical Phishing Response Process
Every employee with access to the CUI environment should know what to do immediately:
- Stop. Do not continue interacting with the message or website.
- Do not enter credentials.
- Do not approve unexpected MFA prompts.
- Report the message through the approved channel.
- If credentials were entered, report the event immediately.
- Do not delete evidence unless instructed by security personnel.
- Follow incident-response instructions without delay.
Early reporting is a security control. Employees should never fear punishment for reporting a suspected click. A fast report can prevent a small event from becoming a contract-level incident.
FAQ
Is annual security awareness training enough for CMMC 2.0 Level 2?
Annual training is a baseline, not a complete mature program. Organizations should provide onboarding training, recurring awareness communications, role-based training, and periodic phishing exercises. Results should be documented and used to improve the program.
Does CMMC require phishing simulations?
The CMMC Assessment Guide identifies simulated phishing emails as an awareness technique. Organizations should be prepared to demonstrate that training is effective through records, exercises, reporting procedures, and documented remediation.
What if an employee clicks a phishing link?
Report it immediately. Do not hide the event. Security personnel can investigate authentication records, isolate an affected device, revoke sessions, reset credentials, and determine whether CUI was accessed or transferred.
Can multifactor authentication stop phishing?
MFA significantly reduces the value of stolen passwords, but it does not eliminate every risk. Attackers may attempt MFA fatigue, session theft, or social engineering. MFA must be combined with monitoring, access controls, user training, and incident response.
Does an enclave eliminate phishing risk?
No environment eliminates all risk. CPE Level 2 reduces exposure and contains impact through layered controls, segmentation, least privilege, monitoring, and managed operations. It gives employees a safer system in which to work and gives security personnel better visibility when suspicious activity occurs.
Protect CUI Before the Next Message Arrives
Your people are not your weakest link. Untrained people operating in an uncontained environment are the weakness. Trained employees operating inside a segmented, continuously monitored, CMMC-focused enclave become a powerful defensive layer.
CPE Level 2 combines awareness, technical enforcement, monitoring, and managed security operations to help defense suppliers protect CUI and maintain confidence in their compliance posture.
We welcome a discussion on how we may assist in your CMMC success story!
Sources
- CMMC Assessment Guide : Level 2, Version 2.13
- CMMC Assessment Guide : Level 2, Version 2.0
- Planet Security CPE Level 2 Product Page
- Planet Security CPE Technical Details
| planetsecurity.net | 702.634.7233 | ![]() |
|---|

