Chris Nyhuis on Defending Critical Infrastructure Before It Makes National News

The Moment That Changes How You See Cybersecurity

Most people think of a cyberattack as a data problem. Chris Nyhuis thinks of it as a life-safety problem, and the distinction traces back to a single moment early in his career. Working at a company that warehoused frozen food across the United States, he started noticing strange traffic hitting the network. When he asked himself what an attacker would actually want there, the answer stopped him cold: access to the ammonia control system. Open that valve, and the surrounding area becomes a kill zone. That realization, he told Robin on Episode 256 of the Localization Fireside Chat, is what pulled him into cybersecurity and eventually led him to co-found Vigilant, a Cincinnati-based firm that now protects critical infrastructure clients across manufacturing, healthcare, defense, and food supply chains, and has maintained a zero-breach record across sixteen years of operation, backed by a guarantee that covers forensic costs if that record ever breaks.

What Nyhuis disagreed with, loudly, was the direction the broader industry took as private equity moved in. Defenders migrated up the OSI stack over time, chasing simpler, cheaper detection at the application layer while leaving the physical and data link layers largely unwatched. The result is that attackers can sit dormant in those lower layers for months without triggering a single alert. The industry average time to detect a threat actor is now 287 days, and in most of those cases, Nyhuis points out, detection systems did not find the intruder. The attacker simply chose to reveal themselves. Vigilant’s approach, built on what he calls forensically validated detection and response, pulls data from sources that logs and firewalls never touch, solves the big data sorting problem in real time, and has brought that detection window down to roughly four hours.

What Actually Happens When Infrastructure Goes Down

The 2021 JBS ransomware attack, carried out by the Russia-linked group REvil, temporarily shut down roughly a quarter of U.S. beef processing capacity. Nyhuis does not think that attack, or the wave of similar strikes against healthcare systems and oil pipelines that followed, represents the full ambition of the groups behind them. His read is that those incidents were dress rehearsals, experiments to measure public response, test recovery timelines, and map the cascading effects of taking down food, power, and logistics simultaneously. The United States runs on just-in-time supply chains with almost no buffer inventory, and AI has since compressed the attack timeline dramatically. Where threat actors once spent months in a network before executing, they are now moving in days.

For any CEO who has never been inside an incident response room, Nyhuis describes it plainly: chaos. Fight-or-flight shuts down clear thinking, and skilled attackers know how to manufacture exactly that pressure. He has watched executives override their own security teams in the middle of an active breach, desperate to get servers back online, and seen that decision extend a weeks-long recovery into months or end in the company closing entirely. His advice is to calm the room first, contain the threat second, and preserve forensic evidence before touching anything, because the entry point the attacker wants you to find is almost never the real one.

What Every CEO Should Do Before the Next Board Meeting

Nyhuis saved his sharpest challenge for the executives themselves. The single greatest cybersecurity risk inside most organizations, he argued, is an unengaged CEO. The hacker group targeting your company may know your business better than you do, because they have studied it with the patience and focus of a competing enterprise. Some of those groups have their own CEOs, their own strategic timelines, and their own ideologies they are defending. Respecting that reality is not optional.

His practical prescription is straightforward and almost no one does it. Go sit with your tier-one triage analyst for a week, even an hour a day, and learn how a cyber event gets triaged, not remediated, just triaged. The warrior kings who understood their armies were the ones who had fought alongside them. Compliance frameworks and checkbox audits will not save you, he said flatly, because they publish your playbook to the people trying to defeat you. Doing security well means being secretive, doing things differently, and knowing your business at every layer, not just the layer that shows up in a quarterly report.


This conversation goes places most cybersecurity discussions never reach, from the ammonia valve that reframed an entire career to the AI-powered supply chain attack that left 250 million systems with remote access trojans installed last March. If you lead an organization that depends on infrastructure you cannot afford to lose, this episode is worth your full attention. Watch on YouTube or Listen on Simplecast and choose the format that works best for you.

Leave a comment

Blog at WordPress.com.

Up ↑