Enterprise Cybersecurity & Applied Research

An engineering and technical research publication by Joshua A. Wortz, CISSP β€” exploring Zero Trust cloud architectures, shift-left DevSecOps, active blue-team defense, and hands-on AI security.

Direct Collaboration & Engagements

“Partnering with colleges, conference organizers, and enterprise security leaders on accessible curriculum design, technical keynotes, and defensive architecture advisory.”

Navigation Guide

Start Here: Targeted Pathways

Select your role or objective to discover curated blueprints, curricula, and defensive tools.

Executive & CISO

Enterprise Leaders & CISOs

Zero Trust blueprints, NIST SP 800-207 architectures, and executive risk governance frameworks designed for healthcare, cloud systems, and highly regulated industries.

NIST SP 800-207 SABSA Framework Healthcare Compliance CISO Roadmaps
Educators & Students

Educators & Students

Universal Design for Learning (UDL) aligned AI security curriculum, zero-cost Docker and Ollama defense labs, and open teaching materials from NCyTE workshops.

UDL Pedagogy Zero-Cost Labs Docker & Ollama NCyTE Workshops
AppSec & Blue Team

Security Engineers & Builders

Production-grade AppSec toolkits (StateHunter & AuditGuard), Microsoft Sentinel KQL query packs, and shift-left CI/CD automated security quality gates.

StateHunter & AuditGuard Sentinel KQL Packs CI/CD Quality Gates Safe Harbor SOW
Featured Spotlight

Flagship Research & Tooling

Spotlight on peer-reviewed enterprise architecture blueprints and open-source defensive software.

Flagship Academic Blueprint
Healthcare & Zero Trust

Enterprise Healthcare Security Architecture

Acuity Health Blueprint & Capstone Hotwash Synthesis

The definitive synthesis uniting enterprise Zero Trust architecture, DevSecOps pipelines, active defense deception, digital forensics, and executive governance into a production-ready healthcare reference blueprint.

Author: Joshua A. Wortz, CISSP
Standards: NIST SP 800-207 • SABSA • ISO 27001
Permanent DOI: 10.5281/zenodo.22287696
Flagship Open-Source Suite
AppSec & Recon

Application Security Suite

StateHunter (DevTools SPA Recon) + AuditGuard (Safe Harbor)

A two-stage offensive reconnaissance and defensive verification pipeline pairing browser DevTools runtime inspection with terminal mathematical boundary enforcement and Disclose.io Safe Harbor proof-of-adherence certification.

Architecture: Chrome MV3 + Python 3 CLI
Capabilities: SPA Route De-obfuscation • IDOR Prober
Compliance: FIRST CVSS v3.1 • Safe Harbor SOW

Core Publication Tracks

πŸ“„

Research Papers & Blueprints

63 Blueprints, Frameworks & Technical Briefs

πŸ›‘οΈ

Acuity Health Security Architecture

Active Series β€” 8 Parts

πŸ€–

Hands-On AI Security

Active Series β€” 4 Parts

πŸ€–

NCyTE Fellowship

Completed Track β€” 2 Parts

πŸ› οΈ

Open Source & Security Tools

9 Production Tools: AuditGuard, StateHunter, Sentinel & AI

πŸ‘€

About & Philosophy

Enterprise Career, NCyTE Fellowship & Pedagogy

Latest Publications

Recent articles, research papers, and webinars
View All Articles →

Modernizing the Academic Knowledge Graph: Canvas Sync Bridge v0.4.0, Hybrid Ingestion, and Official Obsidian Compliance

πŸŽ“ The Academic Knowledge Management Dilemma Modern higher education and enterprise training institutions rely almost universally on Learning Management Systems (LMS) like Instructure Canvas to distribute course syllabi, lecture modules, assignments, student discussions, and grading rubrics. Yet for technical students, researchers, and security practitioners who build their intellectual workflows inside personal knowledge management (PKM) systems like Obsidian, Canvas represents an isolated, walled-off data silo: Ephemerality & Term Expiration: Once an academic semester concludes, student access to Canvas courses is routinely archived or revoked. Syllabi, instructor annotations, curated reading lists, and assignment rubrics vanish behind institutional access gates. Disconnected Knowledge Graphs: Course notes authored in Obsidian remain disconnected from source materials, grading criteria, and module pacing guides living inside the web browser. Administrative Token Gating: Canvas exposes an extensive REST API, but institutional administrators frequently disable personal access tokens (Account > Settings > + New Access Token) for student roles due to enterprise compliance policies. Third-Party Cloud Aggregation Risks: Traditional third-party scrapers and web integrations require routing student session credentials, course documents, and peer discussions through external SaaS servers. For students handling proprietary lab code or education records governed by FERPA and GDPR, third-party cloud aggregation is an unacceptable privacy compromise. Third-Party Cloud Scraper (High Risk): [Canvas LMS] ----(Credentials/Course Data)----> [Cloud Relay / SaaS] ----> [Obsidian Vault] β–² └── Attack Surface & Data Leakage Risk Canvas Sync Bridge v0.4.0 (Hybrid Local-First Architecture): [Canvas LMS REST API] ════(Direct Token / requestUrl)═══════════════════╗ β–Ό [Canvas LMS Web Tab] ════(Session Cookies)════> [Browser Ext] ──(127.0.0.1)──> [Obsidian Vault] To eliminate this friction while upholding strict privacy boundaries and supply-chain integrity, I architected and open-sourced Canvas Sync Bridge v0.4.0β€”a production-grade, hybrid local-first ecosystem split into two dedicated, decoupled open-source GitHub repositories and audited against official Obsidian Community guidelines. ...

September 18, 2026 Β· 10 min Β· 2077 words Β· Joshua Wortz

Hands-On AI Security: Red Teaming Piper with 5 Prompt Injection Vectors

How to probe and break local LLMs using Direct Injection, Roleplay, Obfuscation, and Authority Claims, demonstrating why system instructions fail as security boundaries.

September 17, 2026 Β· 3 min Β· 566 words Β· Joshua Wortz

Acuity Health: Part 2 β€” Zero Trust DevSecOps & NIST SSDF

How to build an isolated, Zero Trust development architecture using ephemeral runners, proxy-scanned package caches, and NIST SP 800-218 practices without slowing engineering velocity.

September 15, 2026 Β· 6 min Β· 1263 words Β· Joshua Wortz

Bridging the Browser-to-Boundary Gap: From Client-Side SPA State Reconnaissance to Safe Harbor Verification

πŸ” The Modern SPA Testing Paradox For more than two decades, the standard operating procedure for web application security assessments has centered around the interception proxy. Tools like Burp Suite, OWASP ZAP, and Caido position themselves between the browser and the target origin, capturing every HTTP request and response traversing the network socket. In traditional server-rendered architectures (PHP, ASP.NET, Rails), this model was nearly exhaustive: every routing decision, session transition, and authorization challenge occurred strictly across the wire. ...

September 12, 2026 Β· 11 min Β· 2293 words Β· Joshua Wortz

Hands-On AI Security: Building a Zero-Cost Local LLM Lab with Docker, Ollama, and Piper

How to build a 100% free, local AI security sandbox using Docker Desktop, Ollama (llama3.2), and a custom vulnerable chatbot to test prompt injection defenses without cloud API costs.

September 10, 2026 Β· 7 min Β· 1286 words Β· Joshua Wortz

Triage Under Fire: The Lean Team's 48-Hour Hardening Blueprint for September 2026 Patch Tuesday

🚨 The 5:00 PM Firehose It is Tuesday, September 8, 2026, at 5:00 PM. Your vulnerability management dashboard updates, and the room goes silent. Microsoft has just released patches for 973 vulnerabilities in a single monthly update cycleβ€”including 113 rated Critical. By every metric, it is the largest Patch Tuesday in history, shattering previous records. Pagers begin chiming. The compliance team sends an automated Slack notification reminding engineering leads that Critical CVEs must be remediated within 72 hours per enterprise SLA. ...

September 9, 2026 Β· 6 min Β· 1220 words Β· Joshua Wortz

Acuity Health: Part 1 β€” Securing the 2 AM Urgent Care (Zero Trust for Distributed Clinics)

Why deploying hardware firewalls across 15 satellite clinics is an operational trapβ€”and how to architect a cloud-native Zero Trust perimeter under NIST SP 800-207 that protects EMR databases without slowing down clinicians.

September 8, 2026 Β· 8 min Β· 1578 words Β· Joshua Wortz

My Teaching Philosophy: Building Accessible AI Security Education

As the father of a college student with autism, my approach to inclusive teaching is both professionally grounded and deeply personal. I see firsthand how traditional, single-mode instructional methods can create unintentional barriers for neurodivergent learners or students balancing non-traditional paths. To foster an environment where every student can succeed regardless of their starting point or learning style, I focus on building multimodal, accessible, and low-cost learning environments across three key areas. ...

August 30, 2026 Β· 3 min Β· 462 words Β· Joshua Wortz

Teaching AI Security: Hands-On LLM Hardening with Docker Desktop and Security Gateways

In August 2026 I delivered a webinar for the NCyTE Center on a question I kept hearing from community college faculty: how do you teach AI security when you don’t have a budget, your IT department locks down what you can install, and API costs for a live LLM are unpredictable? The answer I built β€” and the one this post walks through β€” is a zero-cost, fully local lab that any instructor can drop into their course next week. ...

August 30, 2026 Β· 5 min Β· 917 words Β· Joshua Wortz

Acuity Health Enterprise Security Architecture: Hotwash Synthesis

The definitive synthesis and lessons-learned hotwash uniting enterprise architecture, DevSecOps, active defense, forensics, CTI, and governance into a master healthcare security blueprint.

August 10, 2026 Β· 1 min Β· 114 words Β· Joshua Wortz