Enterprise Cybersecurity & Applied Research

An engineering and technical research publication by Joshua A. Wortz, CISSP — exploring Zero Trust cloud architectures, shift-left DevSecOps, active blue-team defense, and hands-on AI security.

Direct Collaboration & Engagements

“Partnering with colleges, conference organizers, and enterprise security leaders on accessible curriculum design, technical keynotes, and defensive architecture advisory.”

Core Publication Tracks

📄

Research Papers & Blueprints

63 Blueprints, Frameworks & Technical Briefs

🤖

NCyTE Fellowship

Multi-Part Engineering Track

🛡️

Acuity Health Security Architecture

Active Series — Part 1 Live

🤖

Hands-On AI Security

Active Series — Part 1 Live

👤

About & Philosophy

Enterprise Career, NCyTE Fellowship & Pedagogy

Latest Publications

Recent articles, research papers, and webinars
View All Articles →

Hands-On AI Security: Building a Zero-Cost Local LLM Lab with Docker, Ollama, and Piper

How to build a 100% free, local AI security sandbox using Docker Desktop, Ollama (llama3.2), and a custom vulnerable chatbot to test prompt injection defenses without cloud API costs.

September 10, 2026 · 7 min · 1286 words · Joshua Wortz

Triage Under Fire: The Lean Team's 48-Hour Hardening Blueprint for September 2026 Patch Tuesday

Triage Under Fire: The Lean Team’s 48-Hour Hardening Blueprint for September 2026 Patch Tuesday 🚨 The 5:00 PM Firehose It is Tuesday, September 8, 2026, at 5:00 PM. Your vulnerability management dashboard updates, and the room goes silent. Microsoft has just released patches for 973 vulnerabilities in a single monthly update cycle—including 113 rated Critical. By every metric, it is the largest Patch Tuesday in history, shattering previous records. Pagers begin chiming. The compliance team sends an automated Slack notification reminding engineering leads that Critical CVEs must be remediated within 72 hours per enterprise SLA. ...

September 9, 2026 · 6 min · 1238 words · Joshua Wortz

Acuity Health: Part 1 — Securing the 2 AM Urgent Care (Zero Trust for Distributed Clinics)

Why deploying hardware firewalls across 15 satellite clinics is an operational trap—and how to architect a cloud-native Zero Trust perimeter under NIST SP 800-207 that protects EMR databases without slowing down clinicians.

September 8, 2026 · 8 min · 1578 words · Joshua Wortz

My Teaching Philosophy: Building Accessible AI Security Education

As the father of a college student with autism, my approach to inclusive teaching is both professionally grounded and deeply personal. I see firsthand how traditional, single-mode instructional methods can create unintentional barriers for neurodivergent learners or students balancing non-traditional paths. To foster an environment where every student can succeed regardless of their starting point or learning style, I focus on building multimodal, accessible, and low-cost learning environments across three key areas. ...

August 30, 2026 · 3 min · 462 words · Joshua Wortz

Teaching AI Security: Hands-On LLM Hardening with Docker Desktop and Security Gateways

In August 2026 I delivered a webinar for the NCyTE Center on a question I kept hearing from community college faculty: how do you teach AI security when you don’t have a budget, your IT department locks down what you can install, and API costs for a live LLM are unpredictable? The answer I built — and the one this post walks through — is a zero-cost, fully local lab that any instructor can drop into their course next week. ...

August 30, 2026 · 5 min · 917 words · Joshua Wortz

Acuity Health Enterprise Security Architecture: Hotwash Synthesis

The definitive synthesis and lessons-learned hotwash uniting enterprise architecture, DevSecOps, active defense, forensics, CTI, and governance into a master healthcare security blueprint.

August 10, 2026 · 2 min · 227 words · Joshua Wortz

Healthcare Privacy Law, Regulatory Compliance & Cybersecurity Governance

A legal and governance framework navigating HIPAA Security and Privacy rules, state breach notification statutes, and executive CISO ROI leadership.

August 2, 2026 · 2 min · 253 words · Joshua Wortz

Instituting Cyber Threat Intelligence: Predictive Blue-Team Operations

An operational blueprint for establishing a Cyber Threat Intelligence (CTI) program within a cloud-hosted healthcare provider, featuring threat platform evaluations and dynamic flare response.

July 26, 2026 · 2 min · 259 words · Joshua Wortz

Healthcare Incident Response, Computer Network Forensics & Containment

A digital forensics investigation and chain-of-custody framework analyzing an unauthorized electronic health record (EHR) database breach involving VIP patient records.

July 20, 2026 · 2 min · 270 words · Joshua Wortz

Active Blue-Team Defense, Applied Cryptography & Security Operations

An active defense architecture integrating cryptographic key rotation, honeytokens, canary credentials, and proactive blue team threat hunting across clinical healthcare networks.

July 13, 2026 · 2 min · 256 words · Joshua Wortz