The Hugging Face Breach and the Case for AI Failover
An autonomous AI agent breached Hugging Face, and its responders couldn't use OpenAI or other frontier models to investigate. Why you need an AI failover plan.
Founder & Principal Consultant
Mike started his career in 2006 in systems administration, progressing through network engineering before building a passion for code, automation, and security. He began penetration testing in 2010 and hasn't looked back. Over 20 years he's managed enterprise security environments at organizations like Computer Sciences Corporation and Comcast, served as Director of Cybersecurity at a regional VAR/MSP, and worked at boutique cybersecurity firms. He co-founded Breach Craft with colleagues built over that career, to deliver the level of service they always wished they'd received. Mike sits on the board of the Lehigh Valley Chapter of the Cloud Security Alliance and regularly participates in local, regional, and national cybersecurity events.
22 articles published
An autonomous AI agent breached Hugging Face, and its responders couldn't use OpenAI or other frontier models to investigate. Why you need an AI failover plan.
Does a pentest lower your cyber insurance premium? Usually not as a discount. Here's how testing actually affects eligibility, sub-limits, and renewal.
MSPs, MSSPs, VARs, and systems integrators can refer or resell penetration testing, vCISO, and compliance work with Breach Craft through the partner portal.
How security consultants, vCISO contractors, and practitioners refer clients to Breach Craft and earn transparent commissions through our partner portal.
Breach Craft's new partner portal opens the door to MSPs, MSSPs, VARs, individual practitioners, and consultants who refer clients or co-sell our services.
A tabletop exercise stress-tests your incident response plan without real consequences. Learn how they work, who attends, what you get, how often to run.
Vulnerability assessments find known issues. Penetration tests prove what an attacker can actually do. Here's how to decide which one your organization needs.
Penetration testing costs range from $5,000 to $100,000+. What drives the price, what to watch for in proposals, and how to scope an assessment that fits your budget.
DoD suspended CMMC Phase 2 on July 13, 2026. The C3PAO deadline is gone, but DFARS clauses and your SPRS affirmation still bind. Here is what changed.
Only 1 in 4 cyber insurance claims paid out in 2024. Learn what carriers like Coalition and Travelers require in 2026 before your renewal.
Enterprise AI evolved from chatbots to agents with system access. Shadow AI breaches now cost $4.63M. Here's how to assess what you're actually exposed to.
After hundreds of gap assessments, the same 5 security program gaps keep showing up. Here's what they are, why they persist, and how to actually fix them.
How school districts can build incident response plans, protect student data under FERPA, and meet state cybersecurity mandates. Practical steps for IT leaders.
Learn how wireless penetration testing evaluates your wireless infrastructure security using the same techniques employed by malicious attackers.
Full-time CISO pay now runs well past $400K in the mid-market. Here is how to tell whether you need one, and when fractional leadership is the better call.
What a fractional CISO handles day to day, the work it will never cover, and why we staff vCISO engagements with a full team behind one point of contact.
Learn what web application penetration testing is, why your organization needs it, and what to expect from a thorough security assessment.
Learn how gap assessments compare your current security practices against established frameworks like NIST, CIS, and ISO 27001 to identify improvement opportunities.
Learn what penetration testing is, why your organization needs it, how to choose the right provider, and what to expect from the assessment process.
Learn how CIS Controls v8 gap assessments help organizations evaluate and systematically improve their cybersecurity posture through Implementation Groups.
Compliance certifications don't equal security. 2026 DBIR data, SEC enforcement, and what to test beyond audit scope to actually reduce real risk.
The CrowdStrike outage affecting 8.5 million computers offers critical lessons for incident response and business continuity planning.