From Wake Island to the War Room
Nykolas Muldrow (Cyber Security Solutions Architect · US Air Force; CI Solutions Global Incorporated)
Blacks in Cyber Village @ DEF CON 33 · Day 1 · Blacks in Cyber Village
Overview
Nykolas Muldrow, a Cyber Security Solutions Architect with the US Air Force and CEO of CI Solutions Global Incorporated, delivered a compelling and deeply personal address titled "From Wake Island to the War Room: A Black Cyber Leader's Path to Purpose." This talk transcended typical technical discussions, offering a powerful exploration of identity, resilience, and service as foundational pillars for leadership in the high-stakes realm of cybersecurity. Muldrow recounted his extraordinary journey from isolated military assignments, including Wake Island and Guantanamo Bay, to his current influential roles, demonstrating how intentional action and an unwavering commitment to personal growth can transform challenging environments into springboards for significant impact.

Key moments
- 0:00 Introduction: From Wake Island to War Room
- 2:00 Speaker's background and professional roles
- 3:00 Journey begins: Janitor on isolated Wake Island
- 5:00 Introducing the 'Control the Chaos' model
- 5:50 Control your narrative: know your environment
- 7:50 Taking initiative: forming a union on Wake Island
- 8:40 Resilience in cyber: continuous learning and adaptation
- 9:40 Challenges of isolated assignments: satellite internet
From Wake Island to the War Room
Speakers: Nykolas Muldrow (Cyber Security Solutions Architect, US Air Force; CI Solutions Global Incorporated)
Conference: Blacks in Cyber Village
YouTube: https://www.youtube.com/watch?v=tWaBeES6b54
Overview
Nykolas Muldrow, a Cyber Security Solutions Architect with the US Air Force and CEO of CI Solutions Global Incorporated, delivered a compelling and deeply personal address titled "From Wake Island to the War Room: A Black Cyber Leader's Path to Purpose." This talk transcended typical technical discussions, offering a powerful exploration of identity, resilience, and service as foundational pillars for leadership in the high-stakes realm of cybersecurity. Muldrow recounted his extraordinary journey from isolated military assignments, including Wake Island and Guantanamo Bay, to his current influential roles, demonstrating how intentional action and an unwavering commitment to personal growth can transform challenging environments into springboards for significant impact.
The presentation served as both a motivational speech and a practical guide for aspiring and current cybersecurity professionals, particularly those from underrepresented backgrounds. Muldrow’s narrative underscored the critical importance of self-belief, continuous learning, and community building in a field that demands constant adaptation and strategic thinking. His framework, dubbed "Control the Chaos" (CRT), provided actionable insights into navigating professional hurdles, fostering innovation, and ultimately, shaping the future of cybersecurity leadership.
Background
▶ Watch: Introduction: From Wake Island to War Room (0:00)
The cybersecurity landscape is inherently chaotic, characterized by rapidly evolving threats, complex technical infrastructures, and a perpetual shortage of skilled professionals. Within this dynamic environment, the need for effective leadership, particularly from diverse perspectives, is more critical than ever. Nykolas Muldrow’s journey provides a unique lens through which to understand the development of such leadership. His early career was marked by assignments in geographically isolated and strategically vital locations like Wake Island – a remote military base in the middle of the Pacific, accessible only by military aircraft. This setting presented unique challenges, from logistical nightmares to acute personnel shortages and communication limitations, which Muldrow encapsulated with the term "wakish" – meaning if something could go wrong, it would.
Muldrow's path began not in a technical role, but as a janitor on Wake Island, despite his prior studies in network engineering and several IT certifications. This initial barrier to entry, where he had to interview three times for a compsac department vacancy, highlights a common hurdle faced by individuals seeking to transition into or advance within technical fields, especially when perceived through a narrow lens. His experience underscores the systemic challenges within organizations that often fail to recognize latent talent or provide opportunities based on potential rather than immediate, predefined roles. The talk implicitly addresses the broader issue of underrepresentation in cybersecurity leadership, particularly for Black professionals, by showcasing a personal journey of overcoming adversity and forging a path to influence. Muldrow's story is a testament to the power of individual agency in an environment often perceived as rigid and hierarchical, setting the stage for his "Control the Chaos" philosophy.
Key Findings
▶ Watch: Journey begins: Janitor on isolated Wake Island (3:00)
Muldrow’s central contribution is the "Control the Chaos" (CRT) framework, a personal and professional philosophy derived from his experiences in high-stakes, unpredictable environments. This framework is not about exerting brute force power, but rather about intentional actions that allow an individual to master their surroundings and drive positive outcomes. The CRT acronym breaks down into three core tenets:
- Control Your Narrative: This principle extends beyond merely telling a story to leadership; it emphasizes understanding and actively shaping one's environment. Muldrow stressed the importance of knowing "what's in your own backyard" – a deep understanding of the tools being used, the people involved, key stakeholders for communication, and the specific target threat actors that pose risks. He illustrated this with his experience on Wake Island, where a significant portion of the workforce comprised Thai nationals who, despite long tenure, faced wage disparities due to the unfavorable exchange rate. Muldrow, recognizing a systemic issue and taking initiative, organized a union with the IBW (International Brotherhood of Electrical Workers) to establish a Collective Bargaining Agreement (CBA). This act demonstrated profound control over his professional narrative and environment, transforming a perceived weakness into a strength for the entire community. He challenged the audience to abandon the mindset of waiting for someone else to act, urging them to step up and implement improvements they identify.
- Be Resilient: Muldrow highlighted that resilience is paramount in cybersecurity, a field characterized by continuous learning and an ever-changing threat landscape. He recounted the extreme challenge of internet connectivity on Wake Island, where a satellite internet connection offered a mere four megs up, four megs down. Despite this severe limitation, Muldrow demonstrated his resilience by staying up in the middle of the night, diverting bandwidth to his laptop to pursue further education and obtain additional Compsac certifications. This proactive pursuit of growth, even under arduous conditions, exemplifies the resilience required to stay ahead in a profession where stagnation means being left behind. He warned that those who do not continuously learn, experiment with new technologies like flippers, and build new skills will be surpassed by others who are dedicated to their craft.
- Trust Yourself and Your Capabilities: Addressing the pervasive issue of imposter syndrome, Muldrow asserted that self-doubt is a common experience, but it can be overcome by acknowledging the effort and hours invested. He emphasized the critical role of one's mental mindset, suggesting that a positive and confident outlook is a prerequisite for success. Muldrow shared his personal strategy of using a "theme song" to mentally prepare himself for public speaking, illustrating a tangible technique for cultivating self-assurance. Beyond individual trust, he advocated for building one's "own table" rather than waiting for an invitation, and crucially, for making room for others. This principle combats gatekeeping of opportunities and knowledge, promoting collaboration and preventing innovation from stagnating. He stressed that true leadership doesn't require a fancy title; it's about being present, engaged, communicative, and willing to take on new challenges.
Technical Deep Dive
▶ Watch: Control your narrative: know your environment (5:50)
While Muldrow's talk primarily focused on leadership and personal development, it was deeply embedded within a rich technical context derived from his extensive experience in critical infrastructure defense and solutions architecture. His professional journey underscores the strategic application of technical knowledge and leadership within complex, high-stakes environments.
As a Cyber Security Solutions Architect for the federal government, including the Department of Defense (DoD) and the Department of Energy (DOE), Muldrow is responsible for designing and implementing robust security solutions. This role demands a profound understanding of various security domains, including network architecture, data protection, access control, and compliance frameworks. His work involves conceptualizing and integrating security measures that protect vast and intricate government IT infrastructures against sophisticated threats. This isn't merely about patching vulnerabilities; it's about architecting secure systems from the ground up, ensuring mission assurance and operational continuity for critical national assets.
Furthermore, Muldrow serves as a cyber operations instructor for the Air Force, where he trains airmen, civilians, and contractors in the methodologies and practices of defending critical infrastructure. This teaching role highlights his expertise in translating complex technical concepts into practical, actionable knowledge for a diverse audience. The curriculum likely covers topics such as threat intelligence, incident response, vulnerability management, and defensive cyber operations, all vital for maintaining the integrity and resilience of national defense systems. His instruction emphasizes not just theoretical understanding but also the practical application of cyber defense techniques, preparing personnel for real-world scenarios in the war room.
A compelling illustration of his technical acumen and resourcefulness came from his time on Wake Island. Confronted with an extremely limited satellite internet connection offering only four megs up and four megs down, Muldrow strategically managed this scarce resource. To advance his career and obtain additional Compsac certifications, he made the deliberate technical decision to divert bandwidth to his laptop during off-peak hours. This act, while seemingly simple, demonstrates an understanding of network resource allocation and the ability to leverage available technical infrastructure to achieve personal and professional growth. It highlights the ingenuity often required in constrained environments where traditional solutions are unavailable.
Muldrow also emphasized the critical importance of continuous technical learning. He cited examples of individuals "in their labs," "experimenting with flippers," "building things," and "learning new codes." This reference to flippers (likely referring to devices like the Flipper Zero, a multi-tool for penetration testers and hardware hackers) speaks to the rapid pace of innovation in offensive security tools and techniques. For defenders, this necessitates an equally rapid and proactive approach to understanding emerging technologies and threat vectors. His message to "control your narrative" technically means maintaining an intimate knowledge of one's "backyard" – the specific tools deployed, the intricate protocols in use, the architecture of systems, and the evolving tactics of target threat actors. This holistic technical awareness is fundamental for effective defense and strategic planning in cybersecurity. In essence, Muldrow's talk, while inspirational, is deeply rooted in the practical, strategic, and continuous technical engagement required to excel in modern cybersecurity leadership.
Demo / Proof of Concept
▶ Watch: Taking initiative: forming a union on Wake Island (7:50)
The talk "From Wake Island to the War Room" did not feature a traditional technical demonstration or a live proof of concept of a specific exploit or tool. Instead, Nykolas Muldrow's entire presentation served as a powerful, living proof of concept for his "Control the Chaos" philosophy. His personal and professional journey, meticulously recounted, demonstrated the efficacy of his framework in real-world, high-stakes environments.
For instance, his initiative to organize a union and secure a Collective Bargaining Agreement (CBA) for the Thai nationals on Wake Island showcased the "Control your narrative" principle in action, proving that intentional, strategic engagement can reshape an environment. Similarly, his dedication to diverting bandwidth on a severely limited satellite internet connection to pursue further education and obtain Compsac certifications served as a tangible demonstration of "Resilience" and the commitment to continuous learning. Finally, his rise from a janitorial role to a Cyber Security Solutions Architect and instructor, overcoming imposter syndrome and building his own company, CI Solutions Global Incorporated, epitomized the "Trust yourself and your capabilities" tenet. Muldrow's career trajectory and the impactful decisions he made along the way collectively validated the practical applicability and transformative power of his leadership framework.
Defensive Implications
▶ Watch: Challenges of isolated assignments: satellite internet (9:40)
Nykolas Muldrow's "Control the Chaos" framework, though presented through a personal lens, offers profound and actionable defensive implications for cybersecurity professionals and organizations. His principles translate directly into strategies for building more resilient, proactive, and effective defense postures.
- Control Your Narrative (for Defenders):
- Know Your Environment: Defenders must meticulously understand their attack surface, including all assets, vulnerabilities, network configurations, and deployed tools. This means comprehensive asset inventories, regular vulnerability assessments, and deep network visibility. Muldrow's emphasis on knowing "what's in your own backyard" directly translates to a robust threat intelligence program that identifies specific target threat actors and their Tactics, Techniques, and Procedures (TTPs) relevant to the organization.
- Proactive Risk Management: Instead of passively reacting, defenders should proactively shape their security posture. This involves implementing security by design principles, performing red teaming exercises to identify weaknesses before adversaries do, and establishing clear communication protocols with all stakeholders, including non-technical leadership, to ensure security initiatives are understood and supported.
- Strategic Communication: Effective communication is a defensive tool. Muldrow highlighted the need to communicate effectively with diverse stakeholders, including those who are not technical. Defenders must translate complex technical risks into business-relevant terms, ensuring that security investments are justified and prioritized, thereby controlling the narrative around an organization's security posture.
- Be Resilient (for Defenders):
- Continuous Learning and Adaptation: The cybersecurity threat landscape is in constant flux. Defenders must embody continuous learning, staying abreast of emerging threats, new attack vectors, and innovative defensive technologies. This includes investing in training, attending conferences (like Blacks in Cyber Village), and experimenting with new tools (e.g., flippers to understand adversary capabilities). Organizations must foster a culture that encourages and rewards this continuous professional development.
- System and Team Resilience: Beyond individual learning, defense teams must build resilient systems and processes. This means implementing redundancy, failover mechanisms, robust backup and recovery strategies, and incident response plans that are regularly tested and refined. Team resilience involves fostering psychological safety, enabling teams to learn from failures without fear of retribution, and supporting each other under pressure.
- Adaptation to Constraints: Muldrow's experience with four megs up, four megs down satellite internet demonstrates adapting to severe resource constraints. Defenders often face similar limitations (budget, personnel, legacy systems). Resilience here means finding creative, efficient solutions within these constraints, prioritizing effectively, and advocating for necessary resources based on clear risk assessments.
- Trust Yourself and Your Capabilities (for Defenders):
- Empowering Expertise: Organizations must trust their security professionals' expertise. This means empowering technical teams to make informed decisions, providing them with the necessary authority and resources, and valuing their input. It also involves fostering a culture where junior analysts feel confident speaking up about potential weaknesses or innovative solutions.
- Overcoming Imposter Syndrome: Cybersecurity professionals, regardless of experience, can suffer from imposter syndrome. Leaders must create environments where this is acknowledged and addressed, perhaps through mentorship programs, peer support, and celebrating small wins. Trusting one's own capabilities is crucial for confident decision-making during security incidents.
- Building a Diverse and Inclusive "Table": Muldrow's call to "build your own table" and "make room for others" directly impacts defense. Diverse teams bring varied perspectives, which are invaluable for identifying blind spots, anticipating novel attacks, and developing creative defensive strategies. Gatekeeping knowledge or opportunities stunts innovation and weakens the collective defense. Leaders must actively champion diversity, equity, and inclusion within their security teams and the broader industry.
Ultimately, Muldrow's framework provides a blueprint for developing not just technically proficient defenders, but also strong, adaptable, and visionary leaders capable of navigating the inherent chaos of cybersecurity and building truly resilient organizations.
Key Takeaways
- Embrace the "Control the Chaos" (CRT) Framework: Actively control your professional narrative by understanding your environment, being resilient under pressure, and trusting your capabilities to drive intentional positive change.
- Prioritize Continuous Learning: The cybersecurity landscape demands perpetual growth; dedicate yourself to ongoing education, experimentation with new technologies, and skill development to avoid stagnation and remain relevant.
- Overcome Imposter Syndrome: Acknowledge your efforts and expertise, cultivate a positive mental mindset, and develop personal strategies to build confidence in your professional abilities.
- Build Your Own Table and Invite Others: Do not wait for opportunities; create them. Actively network, foster collaboration, and champion the growth of others to build a stronger, more innovative cybersecurity community, especially for underrepresented groups.
- Master Your Mental Game and Set SMART Goals: Utilize strategies like SMART goals (Specific, Measurable, Achievable, Relevant, Time-bound) to break down large objectives into manageable steps, celebrate small wins, and maintain a positive, focused outlook.
- Be a Proactive Leader, Regardless of Title: True leadership involves showing up, being present, communicating effectively with diverse stakeholders (technical and non-technical), taking on new challenges, and empowering your team, thereby leaving a lasting legacy.
About the Speaker(s)
Nykolas Muldrow is a distinguished Cyber Security Solutions Architect at the US Air Force and also serves as a Cyber Operations Instructor. With over 15 years of experience in federal contracting and critical architecture infrastructure defense, Muldrow brings a wealth of practical knowledge to the field. He is the CEO of CI Solutions Global Incorporated, a company specializing in compliance, leadership development, and mission assurance. His career has seen him work at the intersection of national security, compliance, and leadership development, including challenging assignments in isolated locations such as Wake Island and Guantanamo Bay. Muldrow is passionate about fostering greater diversity in cybersecurity leadership roles and is dedicated to sharing his insights and mentoring the next generation of cyber professionals.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A genuine, well-delivered personal narrative from someone who clearly did hard things in hard places. The 'Control the Chaos' framework is serviceable and the Wake Island union story is unexpectedly compelling, but this is a motivational keynote for an underrepresented-community track — judge it as that, not as research. Within its lane it delivers real value; it just doesn't say anything a determined listener couldn't piece together from a handful of similar talks.
Heather Calloway (CISO) — SOLID
Muldrow delivers a sincere, well-grounded leadership narrative aimed squarely at aspiring Black cybersecurity professionals — and for that audience, it works. The CRT framework is coherent, the personal stakes are real, and the institutional insight about who gets overlooked and why is worth hearing. But this is a motivational address, not a security leadership talk, and the gap between inspiration and operational consequence is never closed.