AI has made the security arms race move faster than ever. Jesse Friedman sits down with Aaron Campbell, VP of Product at Monarx, to discuss how bad actors now use the same tools as the people defending against them. They explain how AI compresses the time between a vulnerability being disclosed and being exploited in the real world.
The conversation covers why layered security remains the gold standard. Aaron shares how Monarx blocked 8.7 trillion attacks last year, with more than half caught at the runtime layer based on behavior rather than known signatures. This matters because AI systems are finding brand new vulnerabilities and exploiting them immediately.
Jesse and Aaron also talk about WordCamp US in Phoenix and why it still delivers real value for agencies and hosting companies. From building connections to solving hard problems, they make the case for why sharing knowledge in the WordPress community continues to pay off. This episode is a practical look at security, AI, and the future of hosting.
Links:
- Monarx
- WordCamp US
- WordCamp TV
- Review Signal Web Hosting Benchmarks
- Secure Hosting Alliance
- i2 Coalition
- BruteProtect
- Jetpack Backups
- ThreatShield
Transcript
Jesse: Welcome to Impressive Hosting, a podcast about the role hosting plays in shaping the open web. I’m your host, Jesse Friedman. On this show, we go deeper than uptime and dashboards. We talk about hosting as infrastructure, about ownership, independence, and what it takes to build ethical, high-end WordPress hosting that actually serves creators, businesses, and the internet itself. Before we dive in, head to impressive.host. That’s where you can comment on episodes, ask follow-up questions, and help shape future conversations. You’ll also find links to follow, like, and subscribe wherever you listen. We are back with Aaron Campbell, VP of Product at Monarx. We were talking about security and the narrative that hosting companies and security companies need to build to help educate users on the threats and vulnerabilities they face without having to leverage fear tactics. We talked a little bit about AI. We talked about WordCamp US, and that’s where I wanna pick up because I’m very excited about WordCamp US. It’s gonna be in Phoenix, Arizona. It’s coming up in just a few weeks, and I think it’s an opportunity for us to come together as a community and ecosystem to learn from each other, to benefit from insider knowledge around certain things, and to talk about trends. That’s where I usually spend most of my time. I get to spend a lot of time with folks in meetings, going to booths, hearing about what they’re building and what tools they’re utilizing. And then I watch a lot of the sessions when I get back. WordCamp TV is constantly playing in the background. It’s a nice resource for all those videos that get published later. But Aaron, where are you spending most of your time at the conference?
Aaron Campbell: Pretty similar to you. I wanna go around to all the booths, all the sponsors, see what it is that they’re doing, what’s the exciting new thing, what are they building. You mentioned coming together and sharing knowledge being one of the things you appreciate about the event, and that really sums up what I see in WordCamp US every year. I’ve been to every single WordCamp US and most of the predecessor WordCamp San Francisco, because of that very reason. Sharing knowledge and learning from each other in that kind of space is so great for being aware of what’s going on, but also just learning new things and finding out things you could try, learning how to help steer your business or your business ideas. There’s so much valuable knowledge there, and I love the sharing of knowledge. I’m a person that likes to know everything. I’m an information addict, so it’s a happy place for me.
Jesse: Yeah, for sure. I feel the same way. Plus it’s always great to shake hands, give hugs, see friends, and learn about what they’re working on and what’s going on in their lives.
Aaron Campbell: And make new ones if you don’t have existing ones there, you know? It’s a good spot.
Jesse: Yeah. And I think if you’re thinking about building a website, that’s where a lot of us who’ve been veterans in this space for a long time got our start. We went to a WordCamp and got help from a stranger who raised their hand and said, “I’ll give you a hand with something.” And ever since, we’ve all been giving back to the community in the same way that we got it. I think it’s really great for people to think about it from that perspective, that it is an opportunity to go get some help, to go see somebody about what you’re struggling with. DIYers who don’t necessarily know what they’re doing can go and get an extra hand. But for agencies too, it’s an opportunity to drive business, meet new clients, bring on a whole new book of business, and develop relationships that will help sustain them for a really long time.
Aaron Campbell: I ran an agency for 15 years before I got into hosting, and the connections that you build at these events, I would not have succeeded in my agency if not for WordCamps. And I think that even if you are succeeding in your agency, WordCamps, especially WordCamp US, can really help accelerate that, help you solve problems you’re struggling with, identify new opportunities. I cannot overstate how useful that is to agencies.
Jesse: Yeah, that’s a great point. And it’s a cheap conference too. You think about these big tech conferences where you’re usually spending hundreds if not thousands of dollars for a ticket. WordCamp is incredibly inexpensive to go to. I think that’s interesting because as someone who ran WordCamps in the past, I often felt like you had to help explain why the value is there even though the price tag is so low. Typically people evaluate it that way. “Oh, it’s so cheap, it must be a cheap conference,” but it’s not. There’s so much value in getting to hear from some of the smartest minds in the industry and learn about the most innovative stuff. On that note, a nice segue, innovative stuff. What are you guys innovating on, and where are you spending your time? What’s your focus right now around security threats and the other things you’re seeing the ecosystem facing?
Aaron Campbell: Oh, man, Jesse, it’s 2026, so it’s AI stuff, right? We are in such an interesting space. Since AI released to more of the public, which it’s only been a few years since ChatGPT entered the scene and everybody started experiencing AI in a much more usable way, it’s being used by the bad actors, and it’s being used by us and others in our space to continue the fight we’ve always fought. Can I break in and use your server resources for my own gain? Can I protect those server resources and keep you out? But with AI, the scale has changed dramatically. AI really compresses the time between vulnerability disclosure and real-world exploitation. It’s really about figuring out how we best leverage those tools to protect against those same tools. It has been all-consuming over the last little bit. It’s a lot, but it’s exciting and we’re making great progress.
Jesse: That’s good to hear. So when you think about the fact that these bad actors are leveraging these tools and moving at breakneck speed, how does that feel on a day-to-day? Are you nervous? Do you feel like we, the good actors, the white hats, have the necessary things to combat those threats?
Aaron Campbell: Yes. I think that we do have the necessary things to combat those threats. The biggest thing I think about a lot is, are we all leveraging them as much as the bad actors are? You’ve known me for a long time, Jesse, mostly from the WordPress space, because I’m an extreme advocate of open-source software. I have always said that open-source software is not less secure. All these eyes on it can help it be more secure. Part of the benefit was that you had lots of people working on the software, so even though it also exposes the code to the bad actors, you’ve got so many good actors trying to help shepherd and improve it that it’s still a net positive. I think that’s still the case, but we have to purposefully keep it that way. If the bad actors are using the latest models to look at source code and try to break into it, we need to be doing the same, finding those same things, and fixing them before they can be exploited. And I think that trickles down through so many things. Companies like ours need to be using AI to monitor the actions of bad actors on tens of thousands, hundreds of thousands of servers across the world, to see what they’re doing and build ways to protect against it. The only way to do that at that scale is using these AI models, which is what we do to make that possible.
Jesse: Yeah. It feels a little bit like an arms race. The faster they deploy something or come up with a new way of using something, we have to deploy the same thing, get our hands on the same technology, and use it as a way to protect. But it makes me wonder, is it going to be a situation where we all have to be at DEFCON 1 constantly? Or do you think it’ll start to level out and calm down a little bit?
Aaron Campbell: I don’t wanna underplay the urgency here because you’re right, it is a bit of an arms race. And to be clear, as someone who has been in the security space for a long time, it has always been an arms race. It just used to move slower and be easier to keep up with. Now it’s moving much faster and the arms being built are improving significantly day over day, not just year over year. We know we don’t always wanna be at DEFCON 1, and to do that, we have to try to step outside of it just being an arms race. Yes, if they’re using the latest AI model to assess data, we’re gonna need to be doing that as well. There’s definitely some arms racing there. They’re building tools that attack in a certain way and we need to block those attacks. But I think we also need to go back to our roots a little bit in security, which is that the best security approach has always been a layered security approach, blocking at every layer with its own level of intelligence. That has always been the gold standard. Now it’s really the only way to do it. And in doing so, we can work to stay a little ahead of that arms race in different ways. Simple example: last year we blocked 8.7 trillion attacks. More than half of those were blocked at the runtime layer. The interesting thing there is that essentially all these AI systems are coming up with vulnerabilities that no one’s ever seen before. It just finds them and immediately starts exploiting them, but we’re catching it based on behavior in the runtime layer. We didn’t already learn about the exact attack and write a WAF rule to protect against it. We caught it by seeing what they were doing while they were doing it. If you apply that at every layer along the way, that’s really our best protection. Lay out the nets at every layer to catch the attacks rather than just try to shoot down each individual one after you fully understand it.
Jesse: Yeah, that makes a lot of sense. But you’re explaining it in a way that makes total sense in this moment, with all this context around it. If you’re an agency at home trying to decide on a hosting company for your next client, you don’t always know what you need to know to do a good job evaluating one. There are third-party resources that help you take an unbiased approach to looking at a hosting company. Kevin Ohashi’s web hosting benchmarks, for example. I absolutely love it because I know Kevin personally. I know his level of integrity and how he runs those things. And, shameless plug aside, WP Cloud came out incredibly well in those benchmarks. It’s a very nice thing to see that it’s not just another list where hosting companies are ranked based on the size of their affiliate payouts or whatever gets a marketing company to write the blog post. Instead, it’s actual data showing 100% uptime, fastest response times, all those things. When I think about that for security, it’s a little bit more of a black box. It’s harder to understand. WP Cloud is a member of the Secure Hosting Alliance, i2 Coalition’s effort to bring together hosting companies who are naturally competitors, around governance, security, and ethically good hosting. That’s something I can point to and say, “Hey, make sure you’re using a hosting company that has that Secure Hosting Alliance badge.” But that still doesn’t help explain all the things agencies should be considering. You have an opportunity right now. You’re talking to hosting companies to help them understand how they should educate people around security. You’re also talking to agencies at home who might be making that decision. What would you tell them to look for when evaluating a hosting company?
Aaron Campbell: This is a tough one, Jesse. When you’re looking for performance and uptime, that kind of stuff, it’s much easier to find the information you’re looking for, and Kevin does a fantastic job with his unbiased assessment of hosts. What the i2 Coalition and the Secure Hosting Alliance are trying to do is an important part of this. They’re trying to establish some sort of standards that hosts can adhere to, to show that they have good security practices. But that still ends up being a bit of a checkbox situation, to your point. Do they have the Secure Hosting Alliance checkmark or not? And it doesn’t give a lot of insight into how they’re meeting the various things the Secure Hosting Alliance has laid out. This goes back to what we were talking about in the other episode, about how hosts really need to start bringing security into the way that they talk to and interact with their customers. Instead of just saying “we have secure hosting,” it would be great for them to be putting out the kinds of things that I would tell an agency to check for. If a host put that out there, agencies could actually check it. Are you blocking things at the network layer, and how? Do you protect against distributed attacks? Because for my individual site, I don’t have enough of a picture to block against distributed attacks. Even if I have a whole server with several sites, that’s not really enough. But a host looking at thousands of servers can see those patterns of attack and block them. So are you doing something there, and what is it? Are you doing something at the server network interface, and what is it? Are you giving me runtime protection, and what is it? Are you running malware cleanup? Are you just scanning and alerting me, or are you automatically cleaning? Are you quarantining? These are all things that hosts frankly do. They do them in different ways and to different degrees, but then they just don’t talk about them or put that information anywhere where an agency can say, “Hey, I have my checklist of these five things, and my hosting company actually meets that.” We need to get that out there so that when I tell an agency what to look for, they can actually check that stuff.
Jesse: Yeah. You know, it’s funny because prior to working at BruteProtect, a company I co-founded and ended up selling to Automattic, I was working with hosting companies as a customer. That was the first time I started working with hosting companies from a different perspective. Very similar to what you just said, at a per-site level you have a very narrow scope of what’s happening out there, where attack vectors are coming from. At the hosting level you can see far more across their entire infrastructure. What we actually did with BruteProtect was build a communal blacklist of information we learned from all the hosting companies that were installing the product, and then redistributing that blacklist in real time back to those hosting companies. So if a DDoS or brute-force attack was hitting host A, we could channel those attack vectors and blacklist them before they even got to host B. And of course it would go the other way around too. It was providing real-time protection because we could see a larger landscape at that moment. It makes me think about the fact that there’s this opportunity for us to do so much more in real time on behalf of the user. And I think what you’re getting at is that one of the things we can do better is, even if we handle things automatically, educating the user on what actually happened and occurred. It’s this idea of taking action, and then annotating that action and reporting on it. It’s a double-sided approach because it’s not only educating the customer on what happened so they have a better understanding of their vulnerability and what’s their responsibility, but it also reinforces that you are protecting them, which gives them peace of mind and makes them feel a little bit better. There’s a commercial interest there too, in that you’re improving your brand awareness and the effectiveness of what you’re working on. I like that idea of taking automated action and then telling people about it. One of the things we have at WP Cloud is defender mode, which is this opportunity to automatically test whether the person or system requesting the website is making a legitimate request or if it’s a botnet or something like that. It’s an option users can turn on themselves, but we can also decide to take that action on their behalf. I think one of the things that’s really good is giving people the options to make their own decisions. But it’s a lot like watching your kid. You wanna give them the freedom to make their own decisions, and hopefully they’re making smart ones. Maybe they’re climbing the smaller rock at the playground and you don’t need to interfere. But when you see them starting to climb the bigger rock with a sheer face, you can step in at that exact moment and say, “Hey, I’m gonna hold your hand and help you through this.” I think there’s something there about balancing automation with giving them the tools to take action on their own, and supplementing that with awareness, education, and reporting on what we solved for them.
Aaron Campbell: I completely agree with all those points. The biggest thing that stood out first is your assertion that when a host is doing something in an automated way and blocking things automatically, you should let your customer know that you did that because it does two things. It raises their awareness that stuff is happening out there and will probably make them more aware of the fact that they really are being attacked, even though they aren’t a very big target. And it also builds trust. “I was being attacked, but my host stopped it and kept my site safe.” I think a lot of that comes in with making sure our dashboards can show customers what happened, but it starts with a green banner that says, “You’re all clear. Everything has been cleaned up or blocked, and here are the details around what happened.” Those numbers, even for relatively small sites, can grow pretty quickly. Without that friendly green banner saying “everything’s already been taken care of,” it can be a little scary to see “my site was probed 100 times in the last 24 hours looking for vulnerabilities.” Yeah, that’s normal. That’s the everyday work we do to keep you safe. And then to your point about when something is going wrong and the end user hasn’t opted in to some of these features, like defender mode at WP Cloud, we have all these different layers that Monarx offers as tools, and therefore the hosts that run Monarx offer them too. Some of those layers are optional or run in detect-only mode unless you turn them on to block mode. But one of the things we very much encourage our hosts to do is, if you’ve got a user that’s under attack, turn ThreatShield, our runtime monitoring, into block mode for them, even though they didn’t do that themselves. Protect them, tell them that you did that, and take the credit for it. And if you want to continue gating something like that as an upsell, which depending on what it is can make sense, you can still enable it and say, “Hey, we enabled a free one-month trial of this to keep you safe because you were under attack, but for two bucks a month you can keep this going,” or whatever it is. It still builds trust and keeps your customer safe all in one go. It feels like the easy path forward for getting customers to appreciate security.
Jesse: Yeah. I like that. When you sell security products, you’re kind of always in this weird spot where you have to keep the lights on, invest in research and development and the tools you need to defend these sites. You do need to take money. We are in a commercial society after all. But at the same time you feel for these website owners who are struggling or having an issue. I really do like that idea of being generous, saying we identified an attack happening, it’s not good for anybody, and we can just give you this for free as a limited solution. Let them feel the benefits of it and then give them the option to continue paying for it. Or at the very least, they know it’s something they can enable themselves next time and pay for it that way. But it’s always a balance. It’s the same thing with backups. We have Jetpack backups, real-time backups, with an activity log that shows every change on your site. It’s basically an undo button. There are times where people think that just because they’re using the free version of Jetpack there’s some kind of restore point that exists. It breaks my heart when I get a support ticket from someone saying, “Hey, can you help me? Can you bring back my site?” And I have to say, “Well, you never activated the backup solution, so there’s nothing there for me to restore for you.” Usually in those moments we’re giving away a license for a short period of time or a free trial to try and help them feel a bit more confident. But storage is incredibly expensive. Running backups on every site we wanna run them on is not necessarily feasible. So it kind of circles back to that education idea, and the fact that you’re making yourself more aware of what it is you’re doing, and being comfortable from a brand perspective saying, “We’re doing this for you. We’re helping you through this moment.” But it still needs to have that little bit of optimism so they’re not sitting around feeling scared that something’s wrong or that they made a mistake.
Aaron Campbell: Yeah. I’m not a fan of scare tactics to get people to buy. But I do think a little more transparency and a little bit of that aggrandizing you’re talking about, claiming the things that you’re doing, are both really important here. With physical products, when there’s an add-on or an extra package, like a sunroof when you’re buying a car, we understand that all those things have associated costs, which is why the price of what I’m buying goes up. When it comes to digital things like hosting, the security built on top of that, and the backups built around that, a lot of times people don’t make the connection to the added expense and actual real costs around those things. Part of that I think is because we don’t talk about them as separate things that had to be built and that have things powering them separate from what we’re doing. There’s been a lot of “everything’s bundled into this one hosting package, buy it and get everything.” That mentality has been around for years, but it’s trained our users to not appreciate some of the things that cost us. I think we need to get out of that with the way we talk about things, and claim those benefits that we’re building so that the end user learns to appreciate them and value them.
Jesse: It’s funny because with BruteProtect, one of the reasons we grew as fast as we did is because we did something very simple. When you arrived in your WP admin, there was a dashboard widget that showed how many attacks we had thwarted for you. That counter just kept going up and up and up. It created this passive awareness of what was going on. We weren’t hounding you with notifications or pinging your phone every single time somebody tried to get into your site. But there was this counter that kept incrementing a little bit every time you went into your site, and I think that helped make people more aware of the fact that this is constantly working to protect you. Then we created a little share button, and people ended up sharing on Twitter and Facebook and other places, saying “BruteProtect has protected my site from 10,000 attacks this month,” or something like that. It was a really nice way to crowdsource awareness around the security vulnerabilities that exist. The interesting juxtaposition to that with social media is that no one ever thinks to themselves, “I need to figure out a way to back up my Facebook page or my TikTok profile,” or “I don’t have to worry about security with those things.” Because so many folks think of the internet as these platforms they live on, not just social media but also e-commerce platforms like eBay and Amazon, we’ve siloed and shrunk the internet down to these large islands. Those islands exist in a very different way than your individual website does on a hosting company. I don’t know that people necessarily think about that. Their exposure to this type of internet usage is limited. It goes back to that barrier-to-entry thing we talked about in the first episode. But anyways, really great having you on, Aaron. Always awesome hearing your perspective on what’s going on in the security world and the hosting world. Thank you so much for joining. If there’s anything else you wanna share, now’s the time. Otherwise, thank you so much for being on the show.
Aaron Campbell: Thank you for having me. I think the only thing is, the open web is worth defending. Let’s all keep working together to do that very thing. I’m proud to be a part of Monarx and making that happen. That’s my biggest call-out.
Jesse: Couldn’t have said it better myself. Defend the open web. That’s it. Thanks again, Aaron.
Aaron Campbell: Thanks for having me.





Leave a Reply