Michael Gruden on CUI Protection, Legal Exposure, and Executive Responsibility

Mission: Cyber — Episode 5

PODCAST

Mission: Cyber Ep. 5 | Michael Gruden on CUI Protection, Legal Exposure, and Executive Responsibility

Listen on Apple Podcasts Listen on Spotify

In this episode of Mission: Cyber, host Emil Sayegh sits down with Michael Gruden, Partner at Steptoe and a leading cybersecurity and incident-response attorney. With a career spanning the Pentagon, DHS, and private practice, Michael brings a mission-focused perspective to the legal, regulatory, and operational challenges facing defense contractors today. 

Michael breaks down the confusion surrounding the Department of Defense’s Phase 2 CMMC pause — clarifying what has actually changed, what hasn’t, and why the obligation to protect Controlled Unclassified Information (CUI) remains firmly in place. He also explains how DOJ enforcement, inaccurate attestations, and unprivileged assessments can expose contractors to significant legal risk amid increased scrutiny across the Defense Industrial Base. 

Most importantly, Michael offers practical guidance for leaders on how to use this pause as a strategic opportunity, why governance and data-flow mapping matter more than ever, and how conducting assessments under legal privilege can help organizations identify and address cybersecurity gaps with greater confidence. 

In this episode: 

  • What the CMMC Phase 2 pause really means for contractors
  • Why protecting CUI remains a critical legal and contractual obligation
  • How internal assessments, SPRS scores, and attestations can become evidence
  • DOJ enforcement trends impacting prime contractors and small businesses
  • Why now is the time to strengthen governance, documentation, and data mapping
  • How legal privilege can reduce exposure during cybersecurity assessments 

Whether you’re a CEO, CIO, CISO, or compliance leader navigating the shifting CMMC landscape, this conversation delivers clarity, perspective, and actionable advice on what it takes to protect your mission — and your organization — in today’s evolving regulatory environment.