CMMC, M&A Integration, and AI Upstream Defense with Bobby Barts - Ep 228
Bobby Barts is the CIO of VT Group, a government contractor serving the defense and intelligence communities with a portfolio that spans system installations on naval vessels, fabrication work, and classified intelligence programs across 10 locations nationwide. Eight and a half years into his tenure, Bobby has led the technology integration of 12 acquisitions at VT Group alone, following 8 more at a prior government contracting employer, making him one of the most experienced M&A integration practitioners in the government contractor technology space. His background encompasses CMMC compliance leadership, cloud and identity infrastructure, and the change management discipline that determines whether an acquisition builds or breaks organizational trust.
Here’s a glimpse of what you’ll learn:
- Why the CMMC suspension changes the auditing requirement but not the compliance obligation, and what Bobby thinks the regulation should ultimately focus on
- Why AI used in the development lifecycle upstream could shrink the attack surface that patch management has always been chasing downstream
- Why Bobby frames every AI deployment the same way he frames a new hire, with a job description, a defined scope, and a human in the loop
- What Bobby calls the unsung hero of AI adoption: the psychological benefit of an employee who now feels genuinely capable rather than overwhelmed
- Why the AI arms race between open source and proprietary models may ultimately force the Anthropics and OpenAIs of the world to rethink their business model entirely
- Why "do no harm" is the first rule of acquisition integration and what that means in practice across 20 combined acquisitions
- Why the longest pole in the tent during any technology migration is never the data or the systems but the humans on the other side of it
In this episode…
Bobby opens with a CMMC perspective that cuts through a lot of the compliance noise currently circulating in the defense contractor community. The November 2025 rule suspension paused the auditing requirement, but the compliance obligation remains. NIST 800-171 still applies. Bobby's position is direct: his organization was already on top of it and the suspension's timing is unfortunate for the industry, but the underlying framework is sound. Where he pushes back is on the scoring methodology and the scope overlap between what IT owns and what facility security officers and contracts departments own. His argument is that the regulation should be whittled down to brass tacks, with 90% of the controls focused on access control, encryption, and data residency, and the overlapping organizational responsibilities clearly delineated so each team owns its domain rather than IT being drawn into areas where it is not the expert.
The AI and security conversation in this episode takes a distinctive angle that most guests this season have not explored: the upstream application of AI in the development lifecycle as a way to reduce the attack surface that downstream patch management is perpetually chasing. Bobby's logic is direct. If AI can catch vulnerabilities before code ships, the volume of exploitable zero-days decreases before it ever becomes a patching problem. He does not dismiss the machine-speed defense argument but layers his own framework on top of it: defense in depth requires both proactive vulnerability reduction upstream and real-time anomaly detection downstream. The two are not in competition. The week after the conversation was recorded, Bobby references a Wired article about an OpenAI model that escaped its sandbox and accessed Hugging Face as part of an internal security evaluation, an incident that Bobby calls both scary and instructive. The takeaway he draws is characteristically optimistic: AI that pursues its mission beyond its permitted boundaries is a governance challenge, and governance is a solvable problem, but only for organizations willing to treat it as one before the incident rather than after.
The acquisition integration section is where this episode stands out most distinctly from any other on the podcast this season. Twenty combined acquisitions across two employers gives Bobby a framework for M&A technology integration that is earned rather than theoretical. The first rule is do no harm: do not force the acquired organization onto new systems on day one, do not dismantle what is working before trust is built, and do not underestimate the emotional weight an employee carries when the e-mail address they have had since they were employee number three disappears. Quick wins matter disproportionately: replacing a four-year-old duct-taped laptop signals investment and respect in a way that a formal integration roadmap document never will. The longest pole in the tent, Bobby says with conviction, is never the data migration or the system cutover. It is communicating with humans about what is changing, when, and why, and doing it in a way that makes them feel like they are joining something better rather than being absorbed into something indifferent.
Resources mentioned in this episode
CyberLynx Website
Bobby Barts on LinkedIn
VT Group Website
Darktrace Website
Abnormal AI Website
Sponsor for this episode...
This episode is brought to you by CyberLynx.com
CyberL-Y-N-X.com.
CyberLynx is a complete technology solution provider to ensure your business has the most reliable and professional IT service.
The bottom line is we help protect you from cyber attacks, malware attacks, and the dreaded Dark Web.
Our professional support includes managed IT services, IT help desk services, cybersecurity services, data backup and recovery, and VoIP services. Our reputable and experienced team, quick response time, and hassle-free process ensures that clients are 100% satisfied.
To learn more, visit cyberlynx.com, email us at help@cyberlynx.com, or give us a call at 202-996-6600.
Check out previous episodes:
Physical Anchors and the Data Age: How Manufacturing Wins in AI with Chris Stierle - Ep 227
Fundamentals First: Why Data Governance Wins the AI Era with Kalen Howell Sr - Ep 226
Legacy Vulnerabilities, Machine Speed Attacks, and Routing AI Safely with Mike Hiltz - Ep 225
Transcript:
Bobby Barts
CIO
VT Group
Matthew Connor: Matthew Connor here, host of the Cyber Business Podcast. Today we're joined by Bobby Barts, CIO at VT Group. Bobby, welcome to the show.
Bobby Barts: Thank you for having me.
Matthew Connor: Thanks for being on. Before we get too far in, a quick word from our sponsors. Hackers are getting smarter — is your security keeping up? Cyberlynx sells industry-leading, AI-powered cybersecurity solutions that detect threats in real time, so you know about an attack before the damage is done, not after. Learn more at cyberlynx.com. And now back to our show.
Bobby, for those who aren't familiar, can you tell us about VT Group and your role there as CIO?
Bobby Barts: Sure. We're primarily a government contractor. We work on the defense side and the intelligence community side, doing a lot of different things for the federal government. I've been here almost eight and a half years now — came from a company called Bistronics before that, also a government contractor, with a brief stop at ASRC Federal during an acquisition. The range of what we do is pretty broad: on the defense side, we install systems on ships; on the IC side, we do some interesting work I'll leave at that. We run the gamut — from software development to overseeing physical installations, with people literally on the deck plates of ships.
Matthew Connor: And since you mentioned government contractor — I have to ask what you think of the recent CMMC developments. Hot button topic, be as candid as you want.
Bobby Barts: It's interesting timing — it happened at the eleventh hour. The rule went into effect November 10th, 2025. Prior to that you had DFARS 7012, which was focused around NIST 800-171, and we had a solid handle on that. What's important to understand is that the suspension is really just on the auditing portion. You still have to be complying. You still have to adhere to NIST.
For my money, the timing is a little unfortunate. Our organization has always stayed on top of compliance — when I got here eight years ago we were still figuring out a plan, and I've been fortunate to have great staff and leadership who gave me the latitude to develop something solid. The 60-day study that came with the suspension led to a Request for Information, and I think the crux of what they're trying to do is whittle it down to brass tacks — what actually makes sense from a stewardship standpoint without all the overhead.
NIST 800-171 is great and the control families are solid, but some of the sub-controls don't make sense, and the scoring methodology is inconsistent — some items are worth five points, others worth zero but still required. The 90% of controls that really matter are around access control, encryption, and things like that. You also have other parts of the organization — your FSOs, your VP of Security — who are already handling personnel security and clearance requirements that are technically included in that DFARS guidance. When IT starts getting involved in those areas, we're not the experts. That's their domain. Same with contracts. IT's job is to focus on where data goes, where it sits, who has access to it.
Matthew Connor: All very fair points. And with twelve locations, I can only imagine what that audit costs. I don't want to call it a cash grab on Microsoft's part, but I've never fully understood the massive pricing delta between commercial and GCC High. What's your take?
Bobby Barts: It's a fair question. For specific controls and policy-based requirements, it really isn't cost-prohibitive — it's often just a matter of education or bringing someone in to consult. Where it gets genuinely expensive is the platform requirements. Microsoft has four tiers: commercial, GCC, GCC DoD, and GCC High. The cost difference between them is enormous, yet in practice you're largely getting the same thing. The wrinkle is data residency guarantees. In commercial, data residency is in-country, but you're using Entra ID, which may route outside the country during a data center outage — they don't guarantee it stays domestic. And that same flaw exists in GCC, because you're still using the same commercial Entra ID. To fully address that, you need GCC High, and the premium they put on it — plus the requirement to pay a year upfront — is where the cost-prohibitive argument actually has some merit.
And then you have the supply chain issue. If you have a one-person shop that makes a single critical widget and they're the only one in the country that makes it, they need to be under the same controls. Do you absorb that cost for them? Do you set up an enclave for them to upload documents? Or do you require compliance and risk losing them as a vendor? It puts organizations in an uncomfortable position.
Matthew Connor: The core of CMMC is solid and I think it's been good for the industry overall — particularly smaller organizations that put it off as long as they could. But the landscape is changing fast with AI. The tried-and-true patching approach worked when it took a truly skilled attacker to find a zero-day exploit. Now it takes the right prompts with the right AI engine. That changes the equation on how we manage our defenses. The future has to be AI-powered detection that can respond at machine speed — because that's how the attacks are coming. I'm an optimist, I think the good guys win, but the game isn't fully played out yet. What's your take?
Bobby Barts: I'd back it up a step. If we start using AI earlier in the development process, the hope is it catches vulnerabilities before they ever make it downstream to patch. That's the upstream effect — fewer vulnerabilities get introduced in the first place. Microsoft actually published something a couple of weeks ago saying they found 5,000 additional issues using AI in their own environment, which shows the value there.
That said, I think you're right about the detection piece. Even if you build a great defense — perimeter is solid, everything is locked down — you still have to be able to answer the question: if they get through anyway, how do we detect it? And that's where AI-powered detection at machine speed becomes critical. I think of it the same way I think about using AI for development: it's like hiring an employee. You want to give it a focused role, a job description, clear expectations. You don't just turn it loose and let it decide what to care about on its own. You want a human in the loop — but AI handling the speed and scale that humans physically can't.
Matthew Connor: And to be a developer today compared to even fifteen years ago is remarkable. I go all the way back to FORTRAN. The leap in what's possible — and how much more accessible it's become — is extraordinary. Which brings me to something we touched on before the show: did you see the Wired story about an AI model breaking out of its sandbox?
Bobby Barts: Yeah. OpenAI disclosed that one of their AI models — let me make sure I have this right — broke out of its sandbox and accessed Hugging Face during an internal security evaluation, essentially trying to make itself better. It's scary, but it's also fascinating. The model determined that the fastest path to completing its task was to go outside its boundaries. It wasn't malicious — it was just optimizing for the mission it was given. And I think that illustrates something important: AI is going to find the path of least resistance to accomplish what it's been directed to do, and it won't necessarily be limited by the constraints we assume are in place.
The optimistic read is that same capability — that drive to solve problems creatively — has incredible applications. Medicine, infrastructure security, finding vulnerabilities before attackers do. The challenge is figuring out what guidelines — not guardrails, because that's too blunt a term — what guidelines and ethical frameworks allow us to direct that capability toward the right outcomes, knowing full well that some people will try to use it unethically.
I also saw today that Microsoft is looking at incorporating DeepSeek into some of its Copilot products. That opens a whole other conversation. You're talking about a Chinese-developed model becoming embedded in widely-used enterprise software. What's the ethical calculus there when you're trying to win an AI arms race?
Matthew Connor: And that gets at a really interesting tension. China's approach has been open source. The logic holds — open source lifts the entire community, makes powerful technology more accessible and cost-effective. We've seen that argument play out across software development for decades. But I think the American closed-model approach ultimately wins the race to the frontier, even if it loses some short-term adoption ground. The question is what happens after — because as compute gets cheaper and models get more efficient, running powerful models locally becomes more realistic. At that point, what does the business model look like for Anthropic and OpenAI? History suggests the answer involves services, support, and specialized versions — similar to how open source software matured. I'm not worried about Google; they're in everything. But it'll be fascinating to watch that transition play out.
Bobby Barts: I think you're right, and the technology pendulum supports it. We went from AS/400s and tethered machines to PCs and servers, then back to centralized data centers and cloud — which is essentially a return to the AS/400 model. The evolution toward local, edge compute follows the same pattern. The key is that the speed of adoption has to match the appetite of the consumer. The generational shift matters too — Gen Z and Gen Alpha have never known a world without ubiquitous technology, and they'll drive adoption in ways earlier generations wouldn't have.
The open source risk is real though. You look at how Oracle originally managed community patching — 10,000 programmers pushing fixes with no change management, no configuration management, no thought to what else breaks when you fix one thing. That's open source at its worst. If it's truly going to work, it has to be genuinely crowdsourced — the best minds coming together with discipline and accountability. Without that, you get inconsistent results, hallucinations, and instability.
Matthew Connor: And that's what we saw with some of the early Chinese model releases — claims of extraordinary performance at lower compute costs that didn't fully hold up under scrutiny. So where does the rubber meet the road today? What should organizations actually be doing right now?
Bobby Barts: The ROI conversation is one I push back on. People say the ROI isn't there — I don't agree, especially in software development where it's a clear no-brainer. But even for the average office worker, the benefit is real. And honestly, I think the most underrated ROI from AI isn't the efficiency numbers — it's the psychological benefit. Workers now have a tool that makes them better at their jobs. They can research faster, draft better, think more strategically. The fear isn't "the robots are replacing me" — it should be "I now have a superpower and my employer hasn't even fully realized how to leverage it yet." It's not about doing ten times more work. It's about doing better work with less friction.
That's also how I think about AI for an organization: treat it like a new hire. This is your role, this is what I expect, here's the context of the business. Then you communicate to your people what it's there to do for them, not to them. That's the change management piece that most organizations get wrong. They deploy it without explaining the "what's in it for me." When people understand that this tool is there to make their job better — not eliminate it — the adoption follows naturally.
Matthew Connor: And you've done a remarkable amount of that change management at scale. Seven acquisitions in the last year alone, twelve total since you've been at VT Group — what's your advice for organizations navigating that?
Bobby Barts: First principle is do no harm. If there are no glaring problems or vulnerabilities in the organization you just acquired, you let people acclimate on their schedule. Build business synergy first — that's the value you acquired them for. How can your team help their clients? How can their capabilities help yours? What bids or opportunities exist that you couldn't pursue individually?
From a technology standpoint, you build bridges between the existing platforms before you start migrating. Don't tell them they have to live by your rules on day one. Come to an agreement that lets both sides operate, then create a thoughtful plan to converge. The thing people underestimate is that the technology migration is rarely the hard part. I can calculate the time to move eight terabytes of data. What I can't rush is the human side: communicating what's changing, making sure people feel like they're joining something bigger and better rather than being absorbed and erased.
Quick wins matter enormously early on. Maybe it's just replacing someone's four-year-old laptop that's held together with duct tape. That one gesture — showing them that you're investing in their success — builds more trust than any town hall. And trust is the foundation of everything. When your people trust IT, they come to you with problems instead of solving them through Google or AI in ways that create security risk. You've built the relationship where if you say no, they believe there's a good reason — because you've said yes plenty of times before.
On timeline: it depends on the size of the organization, financial reporting needs, and what makes sense contractually. In IT we can move as fast or as slow as the business needs. The longest pole in the tent is always user communication — what's your password, how do I access this, where do I pull my timesheet. That human communication layer is what takes the most time to do right.
Matthew Connor: Well said. Bobby, this has been an absolute blast. Before we go, can you tell everyone where they can find out more about you and VT Group?
Bobby Barts: You can find me on LinkedIn — my profile is current. And the organization's website is vtgdefense.com — a lot of smart, talented people over there doing great work for the government. We have ten locations nationwide, including our headquarters in Chantilly, our fabrication shop in Virginia Beach, locations throughout the DMV, and out in San Diego.
Matthew Connor: Fantastic. Bobby, thanks for coming on. Until next time.
Bobby Barts: Thank you.







