Thirty years of thinking in public.
White papers, research, and articles from the intersection of cybersecurity operations, civic leadership, and institutional resilience.
Articles & Commentary
You Don't Have to Be a Big Target to Be the Next Victim
Ninety-four percent of small and mid-sized businesses have experienced at least one cyberattack, because attackers scan for accessible vulnerability rather than evaluating organizational size. This piece lays out a four-phase incident response framework — preparation, detection and analysis, containment and recovery, and post-incident review — and argues that preparation, not sophisticated technology, is what determines whether a small organization recovers.
Read ↗No Longer a Small Fish: Why AI and Quantum Computing Make Every Business a Target
AI-enabled tooling can now scan thousands of small business networks simultaneously, which makes the assumption that small size confers protection structurally obsolete, while quantum computing accelerates the ability to break the encryption those organizations rely on. This piece argues that cybersecurity is an operation rather than a product, and that an organization's security profile has to scale with its business maturity rather than lag behind it.
Read ↗The Human Element: Why Your People Are Your Biggest Cybersecurity Risk — and What to Do About It
The human element is a factor in roughly sixty percent of all data breaches, and it is a permanent variable rather than a gap that can be closed. This piece separates training, which addresses knowledge, from culture, which addresses behaviour, and argues that the most dangerous moment in a breach is the interval between an employee realising something went wrong and being willing to report it.
Read ↗Demystifying Cybersecurity for Small Businesses and Non-Profit Organizations
Introduces the Cybersecurity Maturity Pyramid, a five-layer model that maps security requirements to an organization's stage of growth: protective countermeasures at launch, operational processes at stability, human capital at growth, then risk management and governance at scale and optimizing. The argument is that organizations do not need everything at once — they need the right controls at the right stage.
Read ↗Compartmentalization: The Enterprise-Level Strategy That Protects Your Digital Life
Adapts a defensive principle from critical infrastructure work for personal use: separate your digital life into functional buckets — finance, travel, retail, health — each with its own email and password pair, so one compromised credential cannot cascade into total exposure. The argument is that the goal is not perfection but reducing the threat vector so a single breach stays contained.
Read ↗AI Is Lowering the Cost of Attacking the Communities That Can't Afford to Defend Themselves
Artificial intelligence has removed the resource constraint that once limited how often under-defended organizations were attacked, and it has done so across three categories at once: automated scanning of municipal infrastructure, social engineering at volume, and identity and access manipulation. The piece argues that the coming failure of pre-quantum encryption compounds this exposure, and that closing the gap is a governance obligation for civic leaders rather than an IT problem.
Read ↗Who Really Pays the Price When a Cyberattack Hits?
The named target in a breach is the institution, but the cost is absorbed by the residents, patients, and families who depend on it and have no substitute when it goes offline. The piece argues that state-sponsored actors select civic infrastructure precisely because the damage is immediate and the recovery is slow, and that cybersecurity has always been a social policy question.
Read ↗White Papers
"City of Aurora, IL: A Cybersecurity Case Study"
Documents the City of Aurora's journey from a reactive posture to a lifecycle-driven cybersecurity operation — proving the MCOP model at scale. Aurora's in-house program left critical infrastructure severely exposed. Data Defenders deployed DataShield Cybersecurity 360°® and DataShield Analytics® at 77% lower cost than an in-house SOC. Results: 35,331 threats mitigated, 351 high-severity threats eliminated, zero major incidents declared.
Download Case Study ↗"Incident Response: A Practical Guide for Organizations"
A practitioner's guide to building and executing an effective cybersecurity incident response capability. Covers the full incident response lifecycle — preparation, detection, containment, eradication, recovery, and post-incident analysis — with emphasis on the organizational and operational decisions that determine whether a response succeeds or fails. Written for leadership and operations teams who need to move from having an incident response plan to having an incident response capability.
Download White Paper ↗"Managing Your Digital Life: A Consumer's Guide to Cybersecurity"
A practical consumer guide to understanding and reducing cybersecurity risk in everyday life. Introduces the concept of "digital life etiquette" — behavior-based practices for managing mobile devices, online accounts, and software. Covers account compartmentalization, credential management, and multifactor authentication as accessible strategies for locking down a digital footprint without disrupting daily habits.
Download White Paper ↗"Information Security for Small Businesses"
An operational guide addressing the unique cybersecurity vulnerabilities of small businesses operating in an increasingly connected environment. Covers behavior and awareness, technology strategies, event monitoring, incident response planning, and the distinction between internal and external threats. Designed to help non-technical business owners build a defensible security posture without enterprise-level resources.
Download White Paper ↗"Internet Voting System Security Auditing from System Development through Implementation: Best Practices for Electronic Voting Deployments"
Presented at the Fifth International Conference on Electronic Voting, this paper makes the case that any Internet voting deployment must be supported by continuous security auditing from the development stage through active field use. Draws on real-time election forensics methodology to demonstrate how the same approach mitigates risk and detects intrusions in Internet-based voting solutions. Co-authored with Edwin B. Smith III, Michelle M. Shafer, and L. Jay Aceto.
Read Publication ↗"A Case Study of Real-Time Election Forensics"
A practitioner's examination of how digital forensics can be applied in real time to maintain the integrity of electronic voting systems throughout an election cycle — not just after the fact. Covers vote capture devices, Election Management System software, and how forensic monitoring enables jurisdictions to detect anomalies and respond to system threats before they affect outcomes. Co-authored with Edwin B. Smith III and Michelle M. Shafer.
Download Case Study ↗"Forensics: The Vital Link in Election Integrity — A Case Study of Cook County, IL"
Documents Data Defenders' pioneering application of Applied Computer Forensics™ to Cook County's electronic voting system, from the 2006 General Election through the 2008 Presidential cycle. Details the Election Integrity Forensics Analysis (EIFA™) process and demonstrates how real-time monitoring of over six million files produced verified assurance that no evidence of malicious code or tampering was found. Endorsed by Cook County Clerk David Orr.
Download Case Study ↗"AND — ATM Network Design System"
Published in the IEEE journal at the Fifth International Workshop on Modeling, Analysis, and Simulation of Computer and Telecommunications Systems (MASCOTS'97). Presents the ATM Network Design System developed to support the architecture and design of high-speed broadband networks — foundational work in a career that led Cyrus Walker to build the nation's first coast-to-coast broadband network, recognized by President Bill Clinton. Co-authored with Charles Brooks, Hong Li, and Shuyue Wei.
View on IEEE Xplore ↗