Asset visibility, M-26-14 compliance, OT/IoT security, and where to find us this quarter.
August Schell · Quarterly Newsletter
Welcome to Our Q3 2026 Newsletter
This quarter, we’re featuring our partnership with Armis, a leader in asset intelligence and cyber exposure management helping federal and defense organizations secure complex IT/OT environments.
In our employee spotlight, we’re proud to introduce George Simmons, Principal Security Consultant and Managed Services Lead — a 35-year DoD cybersecurity veteran who helps our clients turn compliance requirements into sustainable, mission-focused security programs.
Finally, scroll down for a look at where August Schell will be this quarter across the federal and defense community.
— The August Schell Team
Feature
Logging in an M-26-14 World
The Problem
Threat actors are increasingly using AI to accelerate attacks — gaining unauthorized access, moving laterally, and persisting undetected faster than legacy defenses can respond. M-26-14 has now been released to replace M-21-31 completely. The core gap M-26-14 exposes is visibility: agencies cannot log what they cannot see, and today most agencies have near-non-existent logging visibility into their IoT and OT environments. Traditional agent-based tools simply can’t reach these devices, many of which have no native logging capability at all. The memo is largely aimed at addressing this glaring blind spot to ensure adequate visibility against the latest threats.
The Solution
Meeting M-26-14 requires closing that visibility gap end-to-end, which means:
Complete asset inventory (HWAM/SWAM) across IT, IoT, and OT including unmanaged and non-communicating devices — full visibility is the prerequisite for every other requirement.
Continuous Event Monitoring (CEM): real-time behavioral monitoring across every device class, not just managed endpoints, feeding actionable alerts to the agency SOC.
THIRF-ready forensics: retained, enriched historical telemetry that lets teams reconstruct lateral movement and attack paths across IT/OT/IoT boundaries after a compromise.
Centralized, normalized telemetry feeding into SIEM, SOAR, and CDM platforms for unified visibility.
An approach that reaches OT/ICS/SCADA environments passively — without disrupting sensitive operational systems — and aligns with the Zero Trust Maturity Model’s Visibility & Analytics pillar.
A path to Level 3 (Advanced) maturity within the 320-day window, without requiring a rebuild of existing infrastructure.
Why This Matters for Your Agency
Agencies must produce searchable, retrievable logs (6 months searchable, 12 months retrievable minimum) and provide them to CISA and the FBI upon request. Without full-device visibility, that’s not achievable for IoT/OT assets.
The compressed timeline (Level 3 within 320 days of the CISA LRA publication) means agencies with existing blind spots are already behind — this isn’t a future planning item, it’s an active gap.
IoT and OT devices are where most agencies have the least visibility today — and where a security incident would be hardest to detect or reconstruct after the fact.
Interested in what this looks like for your organization? Contact August Schell to learn how you can meet M-26-14 requirements.
Partner Spotlight
See Every Asset. Secure Every Mission. August Schell + Armis.
You can’t protect what you can’t see. In today’s federal environment, agencies are managing a sprawling mix of IT workstations, OT systems, IoT sensors, and mission-critical devices — many of them unmanaged, unmonitored, and invisible to traditional security tools. That’s where Armis changes the game.
Armis Centrix™ is an AI-powered Cyber Exposure Management Platform that continuously discovers, monitors, and secures every connected asset across your environment, whether it’s managed or unmanaged, IT or OT, on-prem or cloud. And it does it agentlessly — meaning zero disruption to the very systems your mission depends on.
At August Schell, we help federal customers close the visibility gap before adversaries exploit it. By pairing Armis Centrix™ with our deep federal cybersecurity expertise, agencies gain a real-time, unified picture of their entire attack surface — with automated risk scoring, vulnerability prioritization, and threat detection built in. The result: less time chasing unknowns, more time protecting what matters.
Armis Centrix™ is FedRAMP and DISA IL authorized, and available through GSA and NASA SEWP V — contract vehicles ASE customers already know. Contact us to learn more.
Employee Spotlight
Principal Security Consultant & Managed Services Lead
George Simmons
As Principal Security Consultant & Managed Services Lead, George Simmons is dedicated to helping organizations navigate the increasingly complex world of cybersecurity compliance, cloud authorization, and operational risk management. Drawing on more than 35 years of Department of Defense cybersecurity experience, George helps organizations transform compliance requirements into practical, mission-focused security programs that enable business growth while maintaining rigorous security standards.
Prior to joining the private sector, George served as Chief of the Cloud Assessments and Authorization Division at DISA, where he led the assessment and authorization of commercial cloud service offerings seeking DoD Provisional Authorization at Impact Levels 4, 5, and 6. He also represented the DoD CIO and CISO communities as a technical lead within the FedRAMP authorization process.
With the recent addition of his Certified CMMC Professional (CCP) and Certified CMMC Assessor (CCA) credentials, George further strengthens our ability to guide organizations through the evolving CMMC landscape. His expertise spans CMMC, NIST SP 800-171, RMF, FedRAMP, DoD Cloud Computing SRG, continuous monitoring, and executive-level risk management.
Events & Engagements
Where You Can Find Us in Q3 2026
From Los Alamos to Chicago — here’s where August Schell will be this quarter.
Jul 21 2026
Los Alamos National Lab Cyber Day
Los Alamos, NM
August Schell and Ivanti on-site at LANL for live demos and cybersecurity discussions with lab personnel. One of the premier tech events of the year at this national security research institution.
August Schell and Ivanti exhibiting at Sandia National Laboratories tech expo with live demos for SNL staff. An exclusive industry showcase connecting solution providers with key members of the Sandia community.
San Antonio, TX · Grand Hyatt San Antonio River Walk
Annual conference connecting IT professionals across Texas state agencies and higher education. Featuring keynote speakers, interactive workshops, and networking opportunities focused on the latest technology trends in public sector IT.
Reston, VA · Carahsoft Conference & Collaboration Center
Complimentary half-day forum for federal, defense, SLED, and education leaders on modernizing endpoint security and IT service delivery. Up to 3 CPE credits.
A two-day tech and innovation expo series at USDA Headquarters. August Schell will be in attendance — connect with our team on modernizing federal IT and cybersecurity operations.
Augusta, GA · Augusta Marriott at the Convention Center · Booth #114
AFCEA’s Army and joint warfighting conference focused on C2, cyber, and emerging technologies. Themed around “C2/Counter C2 in Support of Army and Joint Warfighting.” August Schell will be on the exhibit floor — stop by and connect with our team.
Montgomery, AL · Renaissance Montgomery Hotel & Spa at the Convention Center
The Department of the Air Force’s largest annual IT and cyberpower event. This year’s theme: “Accelerating the Digital Edge: From Enterprise to Orbit.” Featuring 140+ breakout sessions, 200+ vendor booths, and 4,000+ attendees. August Schell will be on the exhibit floor — stop by and connect with our team.
Qlik Webinar: Faster Insights, Greater Trust, and Cost-Efficient AI Operations with Qlik’s Agentic AI
Online · 2:00 PM ET · 60 minutes · 1 CPE Credit
Join August Schell’s Chief Data & AI Officer, Caroline Kuharske, alongside Qlik’s Andrew Churchill (VP Public Sector) and Ryan Welsh (Field CTO, Generative AI) to learn how Qlik and August Schell are helping defense and federal organizations move from experimentation to operational, ROI-positive AI grounded in trusted, governed, mission-ready data. Hosted in partnership with Carahsoft.
Washington, DC · Walter E. Washington Convention Center
The 17th Annual Billington Summit brings together 3,000+ senior government, military, and industry leaders across nine content tracks — AI, Zero Trust, supply chain, workforce, and more. August Schell will be on the exhibit floor.
Join August Schell for an evening reception at Yardbird in Washington, DC, held alongside the Billington Cybersecurity Summit. Connect with federal cyber leaders over food and drinks. Sponsored by LeapXpert and others.
Registration coming soon
Sep 14–17 2026
Splunk .conf26
Denver, CO · Colorado Convention Center
The premier Splunk community event covering security, observability, and AI-driven analytics. Hundreds of hands-on sessions, certifications, and networking with thousands of Splunk practitioners. August Schell is attending as a Splunk Elite Partner.
Chicago, IL · Chicago Marriott Downtown Magnificent Mile
Cribl’s annual conference focused on AI-ready telemetry, data pipeline management, and observability. This year’s theme: “Magic in the Making.” August Schell will be there connecting with practitioners tackling federal data challenges.