Adalberto
Security
Know the adversary before they know you.
Risk clarity across every surface.
New York · Cyber Threat Intelligence
Applied security practice
Threat intelligence. Policy. Infrastructure security.
I'm Adalberto Trujillo. I work where enterprise IT, cyber risk, and technology policy meet, turning security findings into decisions leadership can act on.
M.S. in Global Security, Conflict, and Cybercrime, NYU. Ten years in IT and cybersecurity at CUNY.
Experience & education
Selected affiliations
Global threat surface
Actively exploited right now, in motion
Live from the CISA Known Exploited Vulnerabilities catalog · refreshed daily
Intelligence-led defense
Most security programs collect signals. Fewer turn them into a decision. I work in the gap between what the adversary is doing and what an organization does about it.
The test I care about is whether the mission still runs when something fails.
Practice areas
What I work on
Cyber Risk, Policy & Strategy
Turning technical risk into the governance, budgets, and policy decisions that determine what actually gets fixed — from national strategy to the enterprise.
- — Security strategy and multi-year planning
- — Policy analysis, standards, and program governance
- — Executive briefings and decision support
Cyber Threat Intelligence
Tracking adversary behavior and turning raw reporting into decisions defenders can act on.
- — Threat and vulnerability research mapped to adversary tradecraft
- — Strategic, operational, and tactical intelligence reporting
- — Crisis simulation and incident decision support
Enterprise IT & Security Operations
Running and hardening the systems organizations depend on — identity, network, endpoints, and cloud — as an IT specialist and cybersecurity liaison at CUNY.
- — Identity, access, and account lifecycle management
- — Network, endpoint, and cloud configuration baselines
- — Security awareness, training, and liaison with leadership
Selected work
Recent projects
Nation-State Ransomware Attacks — Policy Memo & NSC Briefing
Policy memo and briefing written for a U.S. National Security Council audience on the threat of nation-state ransomware, with response and deterrence options for senior decision-makers.
Colonial Pipeline — Cyber Risk Management & Lessons Learned
Analysis of the Colonial Pipeline incident: the risk-management failures that enabled it, the operational fallout, and the lessons critical-infrastructure operators should take from it.
Cyber Assessment — National Strategies & Digital Capabilities: Greece
Assessed Greece's national cyber capabilities, strategies, and objectives. Analyzed cyber operations and attribution of actions to actors, interpreted applicable law and policy, and made recommendations to govern future cyber activity.
Journal
Threat landscape
The threat journal is still in the works — new analysis is coming soon.







