Posts

Most Recent Article

Best Practices for Locating Data Centers in Communities

  "The Horst Community-First Data Center Framework" Data centers are large, secure buildings packed with computers (servers) that store, process, and deliver the information we all rely on — from cloud photos and streaming videos to banking apps and online shopping. They are the “engine rooms” of the modern digital world. First it was colos, then the cloud. Now, AI and quantum computing — all of which need data centers.  This evolution has been happening for decades. Colocation (“colo”) facilities in the 1990s–2000s allowed companies to rent secure space for their own servers. The Cloud (Amazon AWS, Microsoft Azure, Google, etc.) in the 2010s made it possible to rent computing power over the internet instead of owning expensive hardware. Today, artificial intelligence (like ChatGPT and advanced tools) and the emerging field of quantum computing require even more powerful facilities.  The current boom is driven by real, growing demand, not conspiracy or sudden greed. While...

Kentucky Manufacturing Security: A CISO Intelligence Perspective

Image
  Kentucky’s manufacturing sector, anchored by major automotive operations including Toyota in Georgetown, Ford’s Louisville plants, and GM’s Bowling Green Assembly Plant (exclusive home of the Chevrolet Corvette), employs over 250,000 people and drives record exports. As designated Critical Manufacturing sector facilities under DHS/CISA, these facilities are high-value targets for nation-state espionage, ransomware, and supply chain attacks. From a CISO viewpoint, IT/OT convergence, legacy equipment on the plant floor, and rapid digital transformation have expanded the attack surface, while tight production schedules limit remediation windows.

Securing the Heart of Manufacturing: My Perspective on OT Security

Image
  As someone deeply involved in OT security for manufacturing environments, I've seen firsthand how critical this field has become. With Industry 4.0 driving tighter connections between legacy machinery, IoT sensors, SCADA systems, PLCs, and robotics to IT networks and the cloud, the risks have skyrocketed. In my experience, a single breach doesn't just steal data; it can stop production lines cold, endanger workers, create enormous financial losses, and disrupt entire supply chains. Unlike pure IT incidents, OT attacks often carry physical consequences that go far beyond data loss.  In this article, I'll share my insights from years of securing factory floors: starting with a high-level overview of OT security, moving into key threats and vulnerabilities, exploring practical use cases I've helped implement, and examining real-world breaches that show the devastating impact on organizations. I'll finish with actionable strategies that actually work in real manufactu...

When Cybersecurity Hiring Breaks Down, Look at the Boardroom

Image
  A Warning Sign That Leaders Can’t Afford to Ignore Imagine this: a breach occurs at a competitor. Regulators are asking questions. Your board wants to know: Are we protected? Your answer depends entirely on whether you have the right cybersecurity leadership in place. And if your organization has been struggling to hire or retain that leader, the problem may not be the talent market. It may be you. Across industries, a troubling pattern is emerging. Companies post senior cybersecurity roles with ambitious language about strategy, resilience, and program leadership. Interviews happen. Then the roles quietly disappear, get downgraded to tactical positions, or sit unfilled for months. Candidates are left in silence. This isn’t bad luck. It’s a symptom, and the disease is organizational.

Mythos AI: Another Zero-Day Threat in a Long Line of Hype Cycles

Image
The cybersecurity world loves a good scare story. This week, headlines exploded around Anthropic’s new Claude Mythos Preview, a frontier AI model so “dangerous” the company won’t release it publicly. Instead, they’re sharing it defensively with big partners through Project Glasswing to hunt vulnerabilities in critical software before bad actors can. Anthropic claims Mythos autonomously discovered thousands of high-severity zero-days across every major operating system, every major browser, and even long-forgotten bugs in projects like OpenBSD and FFmpeg. Some allegedly survived decades of scrutiny. It can chain exploits with minimal human guidance and turn findings into working proofs of concept at an impressive rate. Sounds terrifying, right? The media ran with “0-day apocalypse” framing. CEOs started asking their security teams the predictable question: “What are we doing about this?” Here’s the calmer reality: Mythos is a significant capability jump in AI-assisted vulnerability disc...