The Military Chapter Nobody Puts on Their Resume
Michael Farnum is quick to correct the record: he was not a tank commander. He loaded, drove, and gunned on an M1A1 Abrams, but commanding it is a specialized role he never held. That small distinction matters to him, and it tells you something about how he operates. What the military did give him, he says, was discipline he frankly lacked as a kid from a small town in backwoods Mississippi, where most of his graduating class of eighty-six people never left. He joined the army to get out, to get college money, and because a tank jumping off a hill in a recruitment commercial looked genuinely cool. Then Saddam Hussein invaded Kuwait in August of 1990, one month after Michael enlisted, and the plan changed considerably. Desert Shield and Desert Storm shaped a combat mentality that still shows up in how he thinks about defense, community accountability, and the difference between instilling discipline through authority versus earning it through trust. That last part is the civilian translation, and he has spent thirty years working it out.
Building the Community You Wished Existed
Michael founded what was then called HOU.SEC.CON in 2010 as a nonprofit conference in Houston, and it grew steadily to more than three thousand practitioners before he restructured the whole operation into Cybersec Community, a for-profit entity, with Cybersec Careers remaining as the nonprofit workforce development arm. The reasoning was flexibility. Nonprofits carry more government scrutiny and operational constraints, and he needed room to move. The flagship event CybersecCon runs September 15th and 16th in Houston, tickets are $150, and he makes no apologies for pricing it far below the $1,500 entry points that dominate the conference circuit. Two other events round out the portfolio: OTSecCon, focused on critical infrastructure security in energy and manufacturing, and CyberHackCon up in the Dallas-Fort Worth area, built around the hands-on, curiosity-driven culture that the word hacker actually implies when it is not being used as a synonym for criminal. What Robin noticed during the conversation, and what Michael confirmed, is that this whole structure was built to solve a visibility problem. Cybersecurity in Houston had practitioners but no real gathering place, no shared stage, no mechanism for the radical transparency that makes the industry function. He built the thing because it did not exist, and that origin story is a direct echo of the community-building impulse Robin has watched drive the best work in localization as well.
The Workforce Problem Is More Complicated Than the Numbers Suggest
The cybersecurity industry loves to cite millions of unfilled jobs, and Michael is skeptical of that figure in the way someone is skeptical when they know who funded the study. Certification bodies and universities have a vested interest in overstating demand, and that matters when you are advising a young person on how to spend several years of their life. What he does believe is that the entry-level tier is genuinely shrinking, because AI handles exactly the kind of data gathering, evidence aggregation, and report generation that analyst roles used to require. His honest advice is that cybersecurity has entry-level jobs but is not an entry-level career, and that getting IT experience first before moving into security is the path that worked for his generation and is quietly coming back into fashion. Cybersec Careers addresses this through mentorship, a scholarship program named in memory of a young man who died while trying to break into the industry, and a youth event called Youth SecCon that brought seventy-five high school students through the door in its first year and is targeting one hundred and fifty this year. The through-line from Mississippi to Houston to a room full of ninth-graders learning to pick locks is not subtle once you see it: if you do not give people exposure, they never know the path exists.
Why Transparency Is the Actual Security Model
The moment in this conversation that lands hardest is when Michael pushes back on the instinct to protect information about how cybersecurity defenses work. The industry has historically held its cards close, reasoning that telling people how you defend yourself tells adversaries how to attack you. He thinks that calculus is wrong, or at least incomplete. The more visibility practitioners share with each other, the faster the whole field adapts. He made the same point about critical infrastructure, specifically water systems, which are often operated by small, underfunded, understaffed local organizations with no dedicated security personnel. Attacks on those systems are already happening. The defense is not more secrecy. It is more community, more shared knowledge, and more citizens showing up to municipal utility board meetings to ask hard questions. That argument maps cleanly onto what Robin has been saying about the localization industry for years: trust is the foundational asset, and the sectors that figure that out earliest are the ones that build something durable.
This is one of those conversations where the guest’s background keeps revealing new layers the longer you stay with it. If you want the full exchange, including Michael’s take on AI shrinking entry-level roles, the blind spots he sees across healthcare and critical infrastructure, and the practical advice for non-security leaders navigating vendor risk in enterprise deals, the whole episode is available in both formats. Watch on YouTube or Listen on Simplecast and choose whichever works best for how you consume this kind of conversation.
Leave a comment