Kenneth Ingham Consulting, LLC

About

Kenneth Ingham has worked in computer security since the early 1980s and has run Kenneth Ingham Consulting since 1991. The practice serves small and medium-sized organizations that carry serious security obligations without a serious security budget.

It is based in Albuquerque and registered in New Mexico, but has never been a New Mexico practice. Clients have been spread across the United States for decades, and much of the work—policy review, readiness, risk assessment—does not depend on being in the room.

Portrait of Kenneth Ingham
Photograph by Liz Blasingame, used with permission.

How this started

Kenneth's introduction to security was breaking it, for the most ordinary of reasons. As an undergraduate in the early 1980s he was writing his own Unix shell and could not get pipes to work. The operating system source would have shown him how the existing shells did it—so he set about getting to the source, and succeeded.

That led to a job administering the systems he had just defeated, one small part of which was keeping out people like him.

Most of that work was ordinary academic computing: keeping DEC VAX systems running for the university's users. But learning the defensive side from the attacking side first left a permanent habit—asking how a control actually fails, rather than whether a document says it exists.

He does not recommend this as a way into the field today.

Research

Part of Kenneth's income before graduate school came from configuring customers' systems to run securely. That work led to an uncomfortable conclusion: however well it was done, it had a shelf life. The next published vulnerability would undo it.

Then a 1997 Communications of the ACM article—"Computer Immunology," by Stephanie Forrest, Steven Hofmeyr, and Anil Somayaji—proposed the immune system as a model for computer security: adaptive defense rather than a fixed configuration, which was precisely the gap he had run into. The group turned out to be at the University of New Mexico. Kenneth visited the professor running the lab; Forrest became his dissertation advisor, and Somayaji later served on his committee and became a frequent co-author. He completed the Ph.D. in 2007.

His research applied adaptive computing to security, specifically to deciding which requests reaching a running web application are not normal. Comparing that approach against existing detection algorithms started as a necessary step and became the more useful result: most published techniques, he found, had been evaluated against simple test data rather than traffic representative of real systems, and their reported accuracies did not survive more realistic measurement.

That question—what was this actually tested against?—is still the first one this practice asks of any security claim.

Teaching

For many years Kenneth developed and taught cybersecurity courses for SkillBridge Training, a corporate training company. Until the 2008–2009 financial crisis he spent one or two weeks a month, usually in Manhattan, teaching secure coding and related subjects to financial services firms—organizations with real regulatory exposure and no patience for theory that did not survive contact with their codebase.

SkillBridge did not survive the crash, and Kenneth returned to consulting full time. He has also taught at the University of New Mexico—first as an undergraduate, later as a teaching associate while completing his Ph.D.—and at Central New Mexico Community College, where he was lead faculty for the cybersecurity curriculum and its NSA Center of Academic Excellence designation for two-year colleges. He still teaches there, often a class a semester, including Digital Forensics and Incident Response.

Teaching remains a demanding test of understanding: a control that cannot be explained clearly to someone who does not already know the subject is usually a control that will not survive contact with a real organization. Clients get the same plain explanations that students do.

CMMC

Kenneth is a Certified CMMC Assessor (CCA), certified in August 2023, and is listed in the Cyber AB Marketplace. The practice also works with Dyan Edington, a Lead Certified CMMC Assessor (LCCA).

Clients have completed CMMC certification assessments with this practice's support, achieving full certification rather than a conditional status carrying open remediation items.

The focus here is readiness: the preparation, evidence, and remediation that determine how a certification assessment goes long before the assessor arrives.

That focus comes from having done it from the inside. As a company's senior cybersecurity employee, Kenneth led it through DoD DIBCAC medium and high assessments, ran repeated NIST SP 800-171 self-assessments, wrote its security policy and incident response plans, and grew its security function into a team of three engineers.

He has met these requirements from the side that has to implement them and keep them running, not only from the side that evaluates them.

AI governance and risk

Organizations are adopting AI considerably faster than they are governing it, which is a familiar shape of problem: capability arriving ahead of the controls. Kenneth performs AI risk assessments and helps organizations write AI policy that reflects how their people are actually using these tools.

Kenneth served on the City of Albuquerque's Artificial Intelligence Policy Working Group, which completed its work and produced the city's policy, and has taken part in NIST's NCCoE Cyber AI Profile working sessions. He spoke on chatbot hallucinations and cybersecurity at BSides Albuquerque in 2024, and wrote the large language model module for his Digital Forensics and Incident Response course.

He was also one of 272 international experts in a three-round Delphi study prioritizing risks from artificial intelligence, led from MIT FutureTech and the University of Queensland, and is a named author of the resulting report. MIT publishes an overview of the study and an interactive presentation of its findings. The work rated 24 AI risk domains on severity, on who is most exposed, and on who bears responsibility for addressing them—the same three questions any organization has to answer about its own AI use, asked at a larger scale.

How the work goes

Every engagement starts by clarifying scope, obligations, decision owners, and the evidence that will show the work is complete. Recommendations are grounded in what an organization can actually operate, not in a generic checklist. When the honest answer to "are we ready?" is "not yet," clients hear that first, while there is still time to do something about it.

Selected publications

Kenneth's ORCID record is 0009-0004-4593-7806.

Kenneth is a member of the IEEE and IEEE Computer Society, the Association for Computing Machinery, the Usenix Association, and ISACA.