Stop Defending the Perimeter. Start Controlling the Blast Radius.
Participants build an operational OpenBSD Packet Conditioning Gateway, create segmented network zones, implement traffic-control policies, and validate how segmentation, packet conditioning, visibility, and deception establish the first technical foundation of the Cardwell Doctrine.
Kevin developed the Cardwell Doctrine from decades of hands-on network architecture and penetration testing work, applying mission-assurance and compartmentalization principles from military doctrine to enterprise network design. He has trained security teams across government, defense, and critical infrastructure worldwide, and leads Cyber2Lab and CybastionTech.
Traditional cybersecurity architecture design continues to focus on an increasingly unattainable objective — preventing every attack. Organizations invest heavily in perimeter defenses, yet attackers continue to compromise networks, move laterally, and disrupt critical operations.
The Cardwell Doctrine introduces a different paradigm. Rather than assuming perfect prevention, the doctrine applies the enduring principles of mission assurance, compartmentalization, and active defense to modern network architectures. The first phase begins with the Packet Conditioning Gateway (PCG) — a purpose-built architectural component designed to condition, validate, observe, and shape network traffic before it enters the operational environment.
In this workshop, participants will learn how the PCG serves as the foundation for digital bulkheads, network mines, active deception, segmentation, and resilient network design. Through practical demonstrations and hands-on implementation guidance, attendees will acquire the architectural blueprints required to deploy these concepts immediately within enterprise, government, and critical infrastructure environments.
This session establishes the foundational layer for the complete Cardwell Doctrine framework, equipping practitioners with actionable techniques that can be implemented upon returning to the workplace.
This is a technical, hands-on workshop. Deep OpenBSD expertise is not required — the workshop builds the Packet Conditioning Gateway from the ground up. Participants should have:
Previous experience with OpenBSD, pf, network security appliances, packet analysis, virtualization, intrusion detection, deception technologies, or enterprise network architecture will be beneficial but is not required.
Participants do not need to be OpenBSD experts — the objective is to understand and implement the architectural principles of the Cardwell Doctrine through a working Packet Conditioning Gateway.
This workshop is designed for technical practitioners, architects, and operational leaders responsible for building, securing, or assuring resilient network environments — particularly organizations seeking to move beyond perimeter-centric security toward segmentation, controlled communication paths, visibility, deception, containment, and blast-radius reduction.
For organizations sending a team, this is the strongest combination — it lets the team leave not only understanding the Cardwell Doctrine, but with a shared technical model for translating the Packet Conditioning Gateway, Digital Bulkheads, and Network Mines into their operational environment.