Trust Issues
CMMC, Whistleblowers and the Cost of Lying
September 9, 2026
Compliance is not security, and security is not compliance. In this episode of Trust Issues, Jeremy Patterson and Bruno Lecoq speak with E.J. Hilbert, Director of US Regulatory Compliance and Security Officer at Element Materials Technology, about why checkbox compliance fails, why CMMC cannot be treated like an IT-only project and why contractors need to understand the rules they are signing up to, before an auditor, whistleblower, competitor, or regulator forces the issue. The big takeaway: CMMC is not a certificate you hang on the wall. It is a program that has to live across the company.
A lot of contractors talk about compliance like it is a form to finish.

E.J. Hilbert sees it very differently.

In this episode of Trust Issues, Jeremy Patterson and Bruno Lecoq speak with E.J. Hilbert, Director of US Regulatory Compliance and Security Officer at Element Materials Technology, about the difference between compliance, security and the checkbox version of both.

What You’ll Learn: 
Episode chapters:
00:43 Welcome to Trust Issues
01:04 Meet E.J. Hilbert
03:08 EJ’s path into cybersecurity and compliance
06:11 Why compliance is not the enemy
08:07 Why NIST 800-171 is not new
08:55 Why checkbox compliance fails
09:15 The problem with assessors who never built the system
10:55 Good students, bad students, and the CMMC pause
12:43 Why government data raises the stakes
14:45 The contractor that found 35 backdoors
22:19 Why CMMC needs centralized proof
25:15 HR, U.S. person status, and compliance confusion
29:42 Why CMMC touches every department
30:02 CMMC as a program, not a project
34:04 False claims, fraud, and contract penalties
37:11 Why whistleblowers are a real compliance risk
40:10 How false claims can threaten government work
46:05 The conflict risk in the CMMC auditor model
47:15 What CMMC could look like next
49:29 Why government data marking needs to improve
52:15 EJ’s final compliance reality check
56:02 Closing thoughts from Bruno

Quotes:

  1. “Compliance is not security. Security is not compliance. Compliance is understanding the regulations that have been placed on you. It’s understanding the rules under which you are supposed to work.”
  2. “If you haven’t actually implemented the NIST 800-171s or the 800-53s or CSC or COVIT or any of the other ones out there, you coming in with a little checklist, that’s not compliance either.”
  3. “The reason the rules are in place now with the government is because the government can’t protect its own stuff.”
  4. “If I have one message to anybody out there, it's to understand the actual facts of what is being said, not the opinions of everybody else that’s being shared.”

Connect with the team: 

👉 E.J. Hilbert on LinkedIn: https://www.linkedin.com/in/ejhilbert/
👉 Bruno Lecoq on LinkedIn: https://www.linkedin.com/in/brunolecoq/
👉 Jeremy Patterson on LinkedIn: https://www.linkedin.com/in/jeremypatterson2026/ 
👉 BEMO Website: https://www.bemopro.com/ 

Trust Issues is handcrafted by our friends over at: fame.so