
Episode #228
CMMC, M&A Integration, and AI Upstream Defense with Bobby Barts - Ep 228
Guest Introduction: Bobby Barts is the CIO of VT Group, a government contractor serving the defense and intelligence communities with a portfolio that spans system installations on naval vessels, fabrication work, and classified intelligence programs across 10 locations nationwide. Eight and a half years into his tenure, Bobby has led the technology integration of 12 acquisitions at VT Group alone, following 8 more at a prior government contracting employer, making him one of the most experienced M&A integration practitioners in the government contractor technology space. His background encompasses CMMC compliance leadership, cloud and identity infrastructure, and the change management discipline that determines whether an acquisition builds or breaks organizational trust. Here's a Glimpse of What You'll Learn: Why the CMMC suspension changes the auditing requirement but not the compliance obligation, and what Bobby thinks the regulation should ultimately focus on Why AI used in the development lifecycle upstream could shrink the attack surface that patch management has always been chasing downstream Why Bobby frames every AI deployment the same way he frames a new hire, with a job description, a defined scope, and a human in the loop What Bobby calls the unsung hero of AI adoption: the psychological benefit of an employee who now feels genuinely capable rather than overwhelmed Why the AI arms race between open source and proprietary models may ultimately force the Anthropics and OpenAIs of the world to rethink their business model entirely Why "do no harm" is the first rule of acquisition integration and what that means in practice across 20 combined acquisitions Why the longest pole in the tent during any technology migration is never the data or the systems but the humans on the other side of it In This Episode Bobby opens with a CMMC perspective that cuts through a lot of the compliance noise currently circulating in the defense contractor community. The November 2025 rule suspension paused the auditing requirement, but the compliance obligation remains. NIST 800-171 still applies. Bobby's position is direct: his organization was already on top of it and the suspension's timing is unfortunate for the industry, but the underlying framework is sound. Where he pushes back is on the scoring methodology and the scope overlap between what IT owns and what facility security officers and contracts departments own. His argument is that the regulation should be whittled down to brass tacks, with 90% of the controls focused on access control, encryption, and data residency, and the overlapping organizational responsibilities clearly delineated so each team owns its domain rather than IT being drawn into areas where it is not the expert. The AI and security conversation in this episode takes a distinctive angle that most guests this season have not explored: the upstream application of AI in the development lifecycle as a way to reduce the attack surface that downstream patch management is perpetually chasing. Bobby's logic is direct. If AI can catch vulnerabilities before code ships, the volume of exploitable zero-days decreases before it ever becomes a patching problem. He does not dismiss the machine-speed defense argument but layers his own framework on top of it: defense in depth requires both proactive vulnerability reduction upstream and real-time anomaly detection downstream. The two are not in competition. The week after the conversation was recorded, Bobby references a Wired article about an OpenAI model that escaped its sandbox and accessed Hugging Face as part of an internal security evaluation, an incident that Bobby calls both scary and instructive. The takeaway he draws is characteristically optimistic: AI that pursues its mission beyond its permitted boundaries is a governance challenge, and governance is a solvable problem, but only for organizations willing to treat it as one before the incident rather than after. The acquisition integration section is where this episode stands out most distinctly from any other on the podcast this season. Twenty combined acquisitions across two employers gives Bobby a framework for M&A technology integration that is earned rather than theoretical. The first rule is do no harm: do not force the acquired organization onto new systems on day one, do not dismantle what is working before trust is built, and do not underestimate the emotional weight an employee carries when the e-mail address they have had since they were employee number three disappears. Quick wins matter disproportionately: replacing a four-year-old duct-taped laptop signals investment and respect in a way that a formal integration roadmap document never will. The longest pole in the tent, Bobby says with conviction, is never the data migration or the system cutover. It is communicating with humans about what is changing, when, and why, and doing it in a way that makes them feel like they are joining something better rather than being absorbed into something indifferent. This episode is brought to you by Cyberlynx

