Translating cyber to the board · and back

Cybersecurity for the people who build it
and the people who fund it.

We don't dumb things down. We translate them. Leadership gets business impact. Practitioners get real implementation. Both get respect.

What security says
"We have critical CVEs in our external attack surface with no compensating controls."
What the board hears
"Three internet-facing systems carry a roughly 15% annual chance of a $2M loss event. Fixing them costs $80K. Fund, accept, or transfer?"
Subscribe free
The map

Twelve pillars, five personal domains.

The publication covers twelve technical and leadership pillars. The personal writing draws from five domains. Every post lives somewhere on this map.

Where the stories come from: building programs from nothing, the translation act itself, the human side of leading, compliance as trust, and a path that ran Air Force → teaching → IT → consultancy → MSSP leadership.

The newsletter

Latest from Security Translated.

Pulled live from the Substack feed. Every issue serves both altitudes: leadership framing on top, implementation underneath.

Never miss an issue

One translation per week, free

Subscribers get the templates and frameworks the day each issue ships. No filler, no vendor spin.

Subscribe free →
The catalog

Free finds the gap. Paid closes it.

Every product line follows the same funnel: a free asset that finds your gaps, a weekly newsletter that keeps you sharp, and a paid playbook that closes them.

Buy once, keep forever. Every purchase lives in your Lemon Squeezy library: lose the file, switch laptops, or want the updated edition, and you log back in and re-download. Updates to anything you've bought are free.

Every pillar gets the same treatment: a free asset that finds the gap, and a paid product that closes it. Two are shipping now; the rest are in production, in this order of demand.

Pillar
Free asset
Paid product
Domain
Free asset
Paid product
Not sure where to start?

Take the free asset first

Both flagship products upgrade a free checklist or template. Run the free version. If it finds gaps, the paid version is how you close them. If it doesn't, you just saved money.

Free downloads

Free to share. Built to use.

Every freebie is a complete, standalone asset. Subscribing (free) unlocks the download; that's the whole price. Free to share with attribution; not for resale.

The honest pitch

The free stuff finds problems. The paid stuff fixes them.

If a free checklist tells you everything's fine, believe it and move on. If it doesn't, the matching playbook is the fastest path from gap to done.

Ciber Cazadora · The person behind the newsletter

I don't inherit security programs. I build them.

Then I translate them so the people who fund security understand what they bought. Director of Information Security. USAF veteran. CISSP. Founder of Security Translated.

0
Major audit findings (SOC 2, HIPAA, NIST 800-171)
13+
Years in IT & security
300+
Global clients trusting the program
253%
Company growth while a 2-person team held the line

Six years active duty in the U.S. Air Force taught me that security is operational; there's no room for "good enough." Since then: built security programs from scratch more than once, taught ethical hacking and digital forensics at three universities for a decade, founded a consultancy in Hawai'i, and now run security end-to-end at an MSSP through 253% growth with a two-person team and no outside consultants. "Ciber Cazadora" means cyber huntress. I don't wait for threats to find me.

Identity & Access Management

Entra IDSAML / OIDC / SCIMSSO & MFAPAMRBAC & JITIdentity lifecycle

Security Operations

Microsoft SentinelDefender XDRKQLPurview DLPIncident responseTenable VM

Compliance & Frameworks

SOC 2 Type 2NIST 800-171HIPAACMMC L2GDPR / FERPA / COPPACIS Controls

Cloud, Zero Trust & Endpoints

Azure & AWSIntune / JamfCloudflareTailscale ZTNAConditional access

Offense & Automation

Kali / MetasploitBurp SuiteNmap / NessusPython / Bash / PowerShellCI/CD

Certifications & Education

CISSPGCPNGFACTCHFICEHNetwork+MSc InfoSec & AssuranceBSc Computer IT
2023 – Present

Director of Information Security

Lumifi Cyber

Own the program end-to-end across hybrid AWS/Azure serving 300+ global clients. Built SOC 2 Type 2, HIPAA, and NIST 800-171 compliance from zero with zero major findings. Cut unnecessary privileged access by 96%. Two people, no consultants, 253% company growth.

2023 – 2024

Sr. IT Security Engineer

Lumifi Cyber

Promoted to Director within a year. Built the first vulnerability management program, authored 37 policies mapped to SOC 2/NIST/HIPAA, embedded SAST/DAST into CI/CD, and cut critical production vulnerabilities by 38%.

2013 – 2023

Cybersecurity Professor

Three universities, concurrent

Taught ethical hacking, digital forensics, Python, and CCNA for ten years. Built hands-on labs on AWS Workspaces and VMware. 2015 Instructor Excellence Award; led NSF grant-funded cyber cohorts.

2018 – 2023

Computer Systems Engineer

Education sector

Owned IT strategy and security for 750 users. Azure migration, 70% uptime improvement, malware incidents cut in half, compliance across HIPAA, PCI, GDPR, and COPPA.

2019 – 2021

Founding Owner

Lana'i Computer LLC

Built a consultancy from the ground up. Pen tests for healthcare, legal, and retail clients; HIPAA-compliant infrastructure for a nonprofit healthcare org. Clients across the Hawaiian Islands and nationwide.

2000 – 2006

Staff Sergeant (E-5)

U.S. Air Force, Active Duty

Six years with Secret clearance. Directed 30+ complex operations with zero safety failures. Two Air Force Achievement Medals, an Outstanding Unit Award, and a Humanitarian Service Medal.

Let's build something

I'd rather build with you than talk at you.

Open to security leadership, CISO advisory, engineering consulting, mentoring, and speaking. Not open to unsolicited vendor pitches.

Booking & links LinkedIn Full portfolio site