 Hello everyone, we are live and welcome to Protected Trust live. We are doing kind of a special one today We have three guests on the panel Ingram Levy, how everyone knows and loves CEO of Protected Trust, fan favorite And joining us for the first time on the panel, but not the first time on video, is Cindy, one of our Solutions Consultants Hello And so today's topic is You know, we've been doing the pillars, the five pillars, the six pillars And we've been focused on business You know, private businesses and how they can make themselves more productive, more secure But we haven't really talked about the government And today I thought it would be a good time to talk about the government cloud community, also known as GCC You know, we, I just don't know where to start, Cindy, do you want to kind of give us a little The question is what is it, right? Or why are we talking about it? Yeah, why are we talking about it? There are many governmental agencies, not only just in the state of Florida but nationwide that are either thinking about moving to the Office 365 platform or are planning to A lot of them are basically hosting their email internally or through another provider They're ready to make that move to the cloud, but they're not quite sure how to get started This is, you know, not necessarily a simple process, although we make it easy But there are steps that need to be taken in order to move, you know, from an internal platform to the cloud A lot of the government agencies are familiar with purchasing their office licenses directly through either an enterprise vendor or from Microsoft directly And they can still do that, however, they really need assistance in order to ensure that as they move to the cloud, you know, governments have different compliance regulations And even different government entities have different government regulations that they need to follow as well And so really to make that move in a compliant and secure way, they really are kind of wondering how to get started And so today we wanted to talk a little bit about that so that we can maybe address some questions and show them, you know, give them more information on how to get started with that process You know, we did a survey, you know, we worked with government clients for about 15 or more years And we just recently did a survey last fall of just inventorying the state of Florida government clients And we found that about a third of them have already made a move to Office 365 or to Office 365 government And that's a very important distinction is that Microsoft has created these special versions of Microsoft 365 that are isolated from the normal public version of 365 That are designed just for government and the reason why is because government has special regulations, special compliance needs And they need to be like different than what the public cloud gets So that's what we want to talk a little bit more about So even from the licensing is different, but also the data centers where the information is stored are also separate And Microsoft has come out with the GCC Yeah You want to talk a little bit about that? Yeah, I can do that. On the screen here is a map of, you know, Microsoft has data centers all across the country But they have these very special data centers that are dedicated just for government cloud And they call it GCC government community cloud to signify that it's different And they also have a GCC high which is designed to be a cloud that's for even higher levels of government Which are probably more federal government or contractors that are working with federal agencies and things like that And then they have DOD regulations as well which are related to like say the FBI for example is moving to 365 And so they would go to like a level of DOD or something like that But in general Microsoft has several compliance regulations standards in the normal public version But in the United States they have very specific, you know, we're familiar with HIPAA and things like that But in the GCC they have things called FedRAMP or like CEGIS for criminal justice information systems Which is the department of the FBI And it may be interesting to kind of say why CEGIS is such a big deal, right? Because something like two thirds, or more than two thirds of all government entities have some sort of law enforcement inside them If you're a city, you have a police department, or if you're a county you have a sheriff's department Even the court systems deal with certain kind of law enforcement data And so I think it's important to maybe say what is this data that they're trying to protect Basically criminal background information, any information involving someone's criminal background, personal information Is to be considered CEGIS, you know, criminal justice information And then CEGIS is a criminal justice information system Which is really a department of the FBI, it's the largest department of the FBI And the FBI has like terrorist activity or criminal behavior or organized crime And they submit this information to the states through a state agency And in the case in Florida we have the Florida Department of Law Enforcement at the elite It disseminates it to the county sheriffs, and the county sheriffs may disseminate it again to the local police departments And so that information, not only does the federal government provide information But even the state, like the state of Florida may have criminal information They may want to disseminate that maybe the federal government doesn't have And so there may be extra stuff inside the data that's being sent around the state So anyway, while this data has to be protected and it's very important that when you're dealing with a government agency They're making sure that this information is being kept secure Exactly And it's also important as the government agencies are working with providers or vendors Assisting them with this particular project That they are working with someone that has the authority to assist them That has the proper background to security If you are a vendor that is working with a government agency And there's any CG information that would be involved It's important that they actually have security background checks We actually went through that process here at Protected Trust So all of our employees have gone through the CG criminal background check, fingerprinting And also their security training that must be taken in order to be able to assist with these types of projects That's right Yeah, every single person in the organization From the top down all the way to the bottom So every single one of us has gone through it You're taking it right, Steven? Yeah, what? But yeah, it's... When you think about not knowing anything about Office 365 in your private business And what you have to do to get it done It seems overwhelming But to do it for GCC Microsoft has taken a lot of steps To make sure that every one of their servers and all the people who are involved with those servers Have the correct credentials I think that's happening in Florida right now Yeah, there's a little wrinkle in Florida There's 38 something states that have been approved To work with Microsoft on the GCC cloud with CGIS information And that represents about 80% of law enforcement in the United States Are able to get on to 365 With Florida, the FDLE is still auditing everything with Microsoft They've gone through the data centers to complete the audits there But there's some extra security background checks that have to be done on Microsoft employees That the city of Miami police department has taken on Is the lead agency to criminally background check Microsoft employees And then set up a program where once they have the system in place That all other agencies in Florida could like hop onto But it doesn't mean that you can't get on 365 today If you're a government agency, especially if you deal with CGIS information Or a sheriff or a police department Is that they're handling this information already today Is that they have a really strong email policy Or email or a CGIS policy That says what's the proper use to how to handle this information And they already have systems in place And the FDLE has provided some of these systems That allow them to communicate this CG information around And they don't have to use the public health But once all this stuff has been certified, regulated and all that stuff They'll be able to use more benefits out of 365 If they want to use file sharing or email collaboration And these tools where it'll help protect that information as well So other states have already adopted it The state of Florida is pretty close to it But it doesn't mean that if you're a state agency in Florida That you can't do it, you can go ahead and do it Just that you have to have a little more policy in place You know, we actually got a question before this live stream saying Is this something that I can do today? And the answer is we've been doing it Yes, yes, so of course Yeah, and especially that figure of client that wrote in today Is a government contractor In fact they're one of, it's very involved with all the federal level But yes, and they'd be considered a contractor to government And even contractors can get on GCC as well In fact we're working with several contractors right now To help them get them vetted and authorized There's a vetting process we'll take them through So that they can get authorized and sponsored to get into these systems And likewise we've done the same thing We've been vetted and sponsored by certain agencies To allow us to have access to from the Microsoft side And from the government side Makes sense? Makes sense to me I think the overall theme is if you've got a question about GCC Don't talk to me Talk to Cindy And Cindy, your contact information is on our website So I don't think anyone would have trouble getting it Steve, there is a slide right here if you want to pull this up But just to give you an idea is that There are the three versions of GCC And most of the clients are going to fall within this area This is the government community cloud And CGS is what we've been talking mainly about But there are other regulations that are available in GCC There may be reasons to certain IRSs Or something like that And FedRAMP, a lot of federal agencies need to be FedRAMP moderate And then we do have some contractors that we work with That are at this level And these are typically federal contractors That are working with certain branches of government That need to have this like the DFARS certification And DFARS is something that if you're dealing with I don't know, there's these regulations that say If you're working with the government, you have a contract with them You must be DFARS certified as of January And so as long as the organization has a plan They can go ahead and get on GCC high And then say they're working to get the DFARS certification So not just GCC But a totally separate set of servers With regulations called GCC high Yes, and I don't know if I have a slide Yeah, this slide here is a little bit more Kind of like how it's designed But government cloud is this area here And GCC is a subset or a separate instance of 365 But then they even have this whole other segment Which is completely isolated There are still some sharing of the actor directory And the public version But all of this has been vetted through different channels And the different like state agencies The federal agencies The compliance agency regulations That make sure that Microsoft has done All these different things correctly And there's things that need to be done on the back end In order for the agency Just because they acquire the licensing for GCC Doesn't mean that they're going to automatically be authorized To allow their data to be stored in the cloud Within the GCC And it has to be approved by Microsoft So that's why it's really important For the agencies to work with someone That has experience in this area Otherwise their licenses might end up in the public And that's not really where they want them to be We've seen that before We've seen clients that think they have the right licensing And they may have been sold the right licensing But you go to check it It's actually still not provisioned in the right spot So we've got that experience to do that Additionally is that even though You settle the stuff and you have the right license Doesn't mean that you've set it up correctly Or you're following the proper guidelines Of how to set these up Or set the correct policies And so in setting these controls in place We have a very experience of guidelines That we've gone through To how the best practices are ways to set these things up So to further help the security aspects Of setting all the government up Yeah, and I've seen it And there's a ton of options to choose from So unless you're being guided by someone Who's done it before I can see where it could be very overwhelming It's going back to climbing the mountain, right? Right, you need that guru You need the guru to get you there Well, was there anything else on the slide deck? If you want to pop on this one really quick This is a more technical slide But to me it was helpful for me to understand Whether the different silos of GCC And all these are basically Inside of each of the commercial cloud Is all the different services Like you have OneDrive and you have Skype And Exchange And so what these columns are showing Is what is available in each of the versions Of Microsoft 365 So in the 365 GCC Which is what we've been talking about Most of the services that they have In their normal 365 are all available In the GCC version In fact every day there's new things That are happening And you can see how teams Is not necessarily something that's actually In GCC yet And it's expected to be here Well actually this quarter And I think even now it may already be there now But they're continually adding More and more services that have been vetted And likewise with high There's still some things that are still missing But like teams for example But they're moving very quickly To get these in the system as quickly as possible Yeah, it looks so complicated When you look through all these things But again it's being filtered through Someone like Cindy and of course you Who know exactly what it means And can get people who Basically the sticklers are like Well have they thought about this thing? It's like oh yeah of course they have So I can hear how they handle it So Microsoft's done a great job of Working with the government Or previous governments And getting it configured So that there's no gotchas Because that's the last thing we want Is for one little thing to be missing Any additional security that Microsoft's added Just even over the last few years Really is beneficial to the agencies With the advanced threat protection That's available now to scan the messages Before they're delivered to the mailboxes Really helps protect the organizations If they click on links you know Within messages You know it can protect the system If it is you know a bad site So and then there's additional security That can be added There's data loss prevention policies If they are an agency that deals with CG They can establish policies there Within data loss prevention To help avoid any data loss With CG information being sent via email So there's just a lot of things That Microsoft has put into place That the agencies really don't need to wait They can start planning their move now And you know just make sure you work with Someone that is experienced in that area Yeah right if they're budgeting right now They have time to start looking at the stuff now If they're budgeting start in the fall It's good to start looking and now Kind of figure out what's going to take to get them up there You know how long it would take to migrate it We're really good at the migrations too We can migrate a client that It can even tell they're being migrated That's like it just is so seamless But all that there's a lot of prep work That goes in to get that stuff in that way So it's just done simply like that You know government agencies are also usually On a very tight budget What Microsoft too is the packages are so comprehensive There's so many different applications That come with Office 365 now That what they're finding Is they can eliminate applications That they're paying separately for Because it's included in their Office 365 license The spam filter The anti-threat detection Now they have Skype for business So they can get rid of You know go-to meeting applications And things like that that they may not need any longer Teams, planner There's so many different Applications that come with The Office 365 That it really is great to do an assessment And look at all of the applications That you have in place now And then take a look at what can be replaced Whenever you do move to Office 365 Because I think you'll find that there's a lot of things That you can save in the long run with That's a very good point And it makes me think about A lot of this is email focused At least in my mind On all the bases So if you're worried about someone Data loss prevention with SharePoint Or OneDrive even They set it up so that it covers those tracks And I think teams is even We're emailing less Because we have teams I love teams, it's changed the way we work here We only use Outlook For external messages So much easier People actually read your messages now So Any final thoughts? You can do this now You can do this today, start it now Start planning it now In the state of Florida You don't have to wait You can get moving now If you already have 365 We can take a look at it And make sure you're doing the best practices Making sure you're doing the right checklists We can remediate the current tenants They may have That's a good point too So 365 licenses I have the office suite You as If you were looking to seek our services We can become Partner of record and upgrade existing licenses You're not paying above and beyond The licenses you have currently We can simply modify what you have To add email and any other Applications that you need If I could circle back I want to remember this When you talked about Seamlessly migrating people Because the worst Is when you have to stop an entire day You have to have Assign your tech team to go around To different computers And making sure everyone has the right things installed But with us Restart your computer It makes us look bad Because it makes it look like we did nothing It's so easy for them to do They're like what did you do Or you didn't do anything You restart But all that work is done By our amazing team We've had years of experience of doing this All the way from the project management To the engineers who actually Flip the switches Just a great experience And I think If any of our clients talk to each other We're very committed on this Compliance and security is our Top of the pyramid for us One of the most important things for us Such as some sort of compliance Regulation And to have that expertise around it Is we're really committed Of getting all of our employees Seed to certified Seed to aware Seed to training HIPAA There's other certifications we've done It's like all those things are so important to us Because when we come to a client That has these questions we understand it Any final thoughts Since the beginning of the company Starting with Have you talked about that before On the live streams? So kind of how we got started In this whole business In my prior life I had an internet provider But when we started doing hosting Email for companies One of the first clients that we received Was I got a call during the second Gulf War Evasion to set up the email system For the provisional government of Iraq And so I got a call from the Pentagon And the Pentagon asked if we could do this And set up for 38 ministries In the government of Iraq So the Pentagon was my client For a few months And then it was handed over To the Bank of Iraq And the new provisional government And they became our client And we helped get them all in their feet And we ran that all from our facilities here Been a Microsoft partner for almost 20 years or more And they helped build it and set it all up And that really got us into government contractors And then they got us into Like the other government agencies State, sheriffs, law enforcement And really We got an expertise around encryption Around all the compliance regulations So we have a long history Of understanding their needs And when you're dealing with a government Especially like a city or a court We've had our hands In some of the More nuances of their law enforcement Which is, they're typically always handling Something with law enforcement Yeah Well, thank you both for joining us today For joining me today This has been very enlightening Just for my sake And I just touched my mic What did you take the CGS testing What did you think about it? I think that there's a lot of things That People do Is a violation And so, taking that exam Well, first of all, going through the training Makes you realize and then finalizing it Makes you realize that you need to be more secure Than you actually are 100% Good job So, thank you all for watching If you like our content, please click the Like button and click Subscribe If you'd like to be notified the next time We do a live stream or a video And thank you to our clients Thank you