December 2025 Site Notes
A short update on the site, privacy language, and the kind of work I am taking on.
By Kevin O'Connor
Last reviewed
These are my December 2025 site notes. I have kept the timing explicit because a personal update should not become an undated statement about current services.
Location
I moved from Philadelphia to Alexandria, Virginia. That puts me closer to the DC security and federal community, but it does not really change how most work happens. Remote calls, document review, research, and advisory work continue the same way.
Defensive Device Review
I am keeping the site language narrow around executive and high-risk individual support. The work I am comfortable describing publicly is defensive:
- checking phones, laptops, and network gear for obvious tampering or suspicious configuration
- reviewing account and device hardening
- triaging malware or targeted-surveillance concerns
- preparing clean travel devices
All of this requires explicit written authorization. The scope is the authorized person's own accounts and equipment. Requests concerning someone else's private activity are outside that scope.
Privacy And Security Pages
I cleaned up the privacy policy and added a clearer security page. The main things I wanted to make explicit:
- what the contact form collects
- what is logged by security tooling
- how browser-local tools behave
- how to report a vulnerability
Focus At The Time
Most of my public writing will stay close to the work I actually do: threat research, detection engineering, ransomware economics, AI safety boundaries, and small security tools that are useful without pretending to be a platform.
The useful thread through those topics is understanding a system well enough to explain where a claim holds and where it stops. That is the direction I want the writing here to take.
Email updates
Get new research by email
In-depth notes on AI security, threat research, and practical defensive work.