Brian Scott

Security researcher and threat intelligence practitioner. Former Security Research Engineer at Cisco ASIG. Founder of Southwest Valley Research Group. CVE co-author. GXPN · GCPN · CRTO · OSCP.

Designing a Segmented Security Research Lab

Running security research, data analysis, and tooling development in one flat environment creates problems that compound quietly. A mistake in one workflow can reach another. There’s no visibility into what’s actually talking to what. And when everything shares a trust boundary, “assume breach” stops being a threat model and becomes wishful thinking. This post walks through a segmented lab design that treats each type of work as its own security context, and the reasoning behind each boundary. ...

September 24, 2026 · 4 min · Brian Scott

Active Cyber Defense Comes of Age

Two Chinese state-sponsored hacking groups have confirmed persistent access inside US power grids, water systems, and telecommunications infrastructure. Their presence spans years. Their activity does not resemble bulk data exfiltration or the kind of disruption typically associated with criminal ransomware. According to a CISA advisory published in February 2026, the characterization from the intelligence community is pre-conflict positioning: establishing persistent footholds that can be activated during a future military or geopolitical crisis. ...

August 13, 2026 · 12 min · Brian Scott