Always Forward Manufacturing LLC
A cyber guy who
went into manufacturing
and couldn't look away.
I spent 13 years at a global financial institution, 10 of them in cybersecurity. I ran access management for the applications that let people move money on the bank's behalf. Later I built and led third-party access management teams of in-house staff and contractors, and finished as a strategy lead for the systems regulators require banks to run. Every one of those roles was the same job at its core: design controls that meet a regulatory requirement, implement them, and prove they work.
Before the bank, I was infantry. Four deployments. When I interviewed for the cyber role, I told them the battlefield had changed but the principles hadn't: there is always room for improvement in your defenses, and training is paramount.
Then I moved into manufacturing, which I love, and found a shop floor full of talented people doing real work for the DoD who had no idea what CMMC was and no practical path to figure it out. The guidance that exists was written for large primes with dedicated IT teams and six-figure compliance budgets. It wasn't written for a 12-person machine shop where the owner is also the estimator, the floor supervisor, and the person who answers the phone.
A machine shop owner shouldn't need a lawyer and a CISO to figure out whether they need to turn on multi-factor authentication.
So I built Unit 1 Cyber. It takes every CMMC control and gives you what it says, what it means, what to do, and how to document that you did it. It won't replace a C3PAO assessment if your contracts require one. It will take you from "I don't know where to start" to a documented, scored, defensible position.
Unit 1 Cyber is a product of Always Forward Manufacturing, not a consulting firm. I've stood on both sides of this: the person writing the controls, and the small shop that has to comply with them.