Security should be a beneficial add-on, not an assumed part of every hosting plan. That is one of the central ideas Aaron Campbell, VP of Product at Monarx, brings to this conversation with Jesse Friedman. Aaron spent 15 years in the hosting world before moving to a company that helps hosts fight malware and bad actors, and he draws a clear line between what a host should secure and what falls to the site owner.
Jesse and Aaron work through the metaphor of hosting as a neighborhood. The host keeps the streets clean and the infrastructure secure, but there is only so much they can do when a site owner uses a weak password or hands out admin access without thinking. They talk about how the low barrier to entry in WordPress created millions of users who never learned the basics of staying safe online.
The two also look at how AI could help close that education gap. Aaron shares how Monarx uses language models to turn technical breach data into plain words that regular people can act on. Anyone running a hosting company or building WordPress products will find useful ideas here about positioning security, building customer trust, and meeting users where they are.
Links:
Chapters:
00:00 Teaser
03:50 Where should hosts draw the line on security responsibility?
05:55 How does the neighborhood metaphor apply to hosting security?
08:01 How do you educate users who aren’t interested in security?
11:13 Should security awareness be built into hosting dashboards or Word Press core?
15:12 Can AI help translate complex security language for everyday users?
19:21 How should security alerts balance urgency without creating panic?
22:15 How does Monarx work behind the scenes with hosting companies?
24:49 Should security companies build their own trusted brand alongside hosts?
Transcript
Jesse: Welcome to Impressive Hosting, a podcast about the role hosting plays in shaping the open web. I’m your host, Jesse Friedman. On this show, we go deeper than uptimes and dashboards. We talk about hosting as infrastructure, about ownership, independence, and what it takes to build ethical, high-end WordPress hosting that actually serves creators, businesses, and the internet itself. Before we dive in, head to impressive.host. That’s where you can comment on episodes, ask follow-up questions, and help shape future conversations. You’ll also find links to follow, like, and subscribe wherever you listen. Today, I’m very happy to have Aaron Campbell, VP of Product at Monarx, joining us to talk about security. We’re gonna talk about WordCamp US, a variety of different things, and a little bit about AI. Probably a lot about AI and how it’s shaping the future of security and how it’s affecting WordPress. Aaron, thanks for joining. Tell us a little about what you’re working on and where you’re from.
Aaron Campbell: Thanks for having me. I’m in the middle of nowhere in the middle of the US. I live in Oklahoma. I enjoy the technical side of work and the outdoor spaces in Oklahoma. Professionally, I’ve been through a lot of things, from running my own agency and then moving into the hosting space where I’ve pretty much found myself digging in deep over the last 15 years. Now at Monarx, where we help hosts fight malware and bad actors and keep their sites, their servers, and their users safe and secure. It’s a very interesting and fun problem to be solving in our modern AI-powered days. Keeps me on my toes and gives me fun problems to solve.
Jesse: Yeah, it’s interesting. I appreciate the fact that you went from working with a host to now supporting hosts from an outside perspective. That’s always something really interesting to me. One thing that always comes up with hosting companies is that there’s a baseline level of security that all hosts should be expected to bring to the table, and then there are added layers of security that hosts opt in to bring. Sometimes they end up charging customers for it. Most novice users think that everything is fully incorporated into every hosting plan they get. They think all the security they’re gonna need is already built in. So from your perspective as someone who used to work for a hosting company and now works for a security company, where do you draw that line? Where are hosts responsible to secure things, and where is the agency or the DIYer responsible to pick up the slack?
Aaron Campbell: Right into one of the biggest questions that hosts have been struggling with for decades.
Jesse: Right into it.
Aaron Campbell: Yeah. This is a great question, Jesse, because I think it’s shifting some in our modern day. But it’s still something hosts struggle with a lot. To be clear, I do think hosts have a responsibility to help their users, who are by nature less security-aware than the hosts themselves, stay secure online. However, not all users at any given host need the same types or level of security. People are running different kinds of sites and applications. Some are selling things, some are not. So the host doesn’t need to include the same everything bundle for everyone. What I think is most important is helping customers understand what they need and why they need it. The biggest thing hosts need to be doing is keeping their own infrastructure secure so that the neighborhood, if you will, that the customer is hosting in is generally secure and clean. Then all the detection, all the awareness, and raising that to the customer in a way that lets them know exactly what their risk is and what they can do to solve it. That may look like, “Hey, we don’t block all these potential attacks, but what we do is surface this in your dashboard. You’ve had this many failed login attempts. We could help throttle those if you’d like. If that’s not important to you, you don’t need to upgrade to that service.” You can roll that general rule of thumb out across the board.
Jesse: I really like that. When I was working with agencies in the past, I’d watch as they described the website building process as designing a house. The foundation, the framework of it, very much like the CMS of your choice. The aesthetics of the house, the colors, the fonts, equivalent to the user interface and user experience you choose for your website. But I never really thought about that metaphor extending beyond the house and into the neighborhood and into the city. That’s very much how it works. The infrastructure itself is the cul-de-sac or the city infrastructure provided by the hosting company, and there’s a layer of policing that is the responsibility of the city to enforce and make sure they’re securing the neighborhood and everyone around you. But there’s only so much they can do when you start inviting predatory people into your home. If you’re running WordPress and you have the most secure infrastructure, the most secure city, but your passcode on your digital deadbolt is 0000, or your WordPress password is adminadmin, there’s only so much a hosting company can do to protect you at that point. This actually came up in the recent Automattic documentary, Code for the People. I remember Paolo talking about this. One of the greatest things that happened is that the barrier of entry was lowered to a point where anyone at any level is able to build a website. But that also means they don’t come with an education in security. They don’t have years of experience understanding how to thwart attacks, block malicious actors, or even just the basic knowledge of what creates vulnerabilities in their space. So how do we go about educating people in security when, for the most part, people are bored by it? They’re not interested in it. They’re very focused on marketing or getting their website up and running, getting leads or sales. Security’s usually a backseat. How do we get to a place where we accept that the barrier of entry is super low, but also acknowledge that these folks don’t have that level of education and don’t necessarily want it?
Aaron Campbell: Yeah. I think this is one of the places where hosts really have to look at security as a beneficial add-on service and not as a base-level inclusion, like a server connected to the internet with a really big pipe. By viewing security as this add-on, this thing that can make your hosting package better, you position it that way in all of your customer interactions, and that’s what helps build customer awareness. For the longest time, security has been a base-level thing included in hosting. But that was when all the added security, all the extras, were done by the agency or the site owner because there was a higher level of technical understanding. Now that level of technical understanding has lowered, and the host has to become the expert to help guide even some agencies, but definitely site owners. They need to view those extra steps that were being done by the end user before as beneficial things and start bringing them in. That’s where I’m talking about the same spot in your dashboard where you say, “Hey, do X, Y, and Z or buy A, B, and C in order to reach more customers,” should also be saying, “Hey, these things have you at risk. We checked Have I Been Pwned and your password is terrible and needs to be changed. These are the risks. We’ve seen these kinds of things trying to probe your site. You should be updating some of your plugins.” Whatever it is, raising that in a way that frames it as, “We have services that can take these headaches off your plate and do them for you to keep you secure, or you can do it yourself like you’ve been doing all along.” Baking it in like that is the only way I can see us really raising awareness to the level that we need. I can go around and talk on as many stages as people will let me, but I’m only reaching a tiny fraction of what could be done if it was baked in this way.
Jesse: Yeah. So when you say baked in, are you saying that’s at the hosting level, adding some kind of must-use plugin or interface? Or are you thinking it should even go into core, that core should take on more of this?
Aaron Campbell: I think it’s at the hosting level. Core does a lot for security, but I think what core is meant to give you is a secure structure. What hosting is meant to give you is a secure online presence, and the structure needs to stay secure. Core needs to continue doing what it’s doing. Are there a few more things that could maybe land there someday? Yeah, maybe. But hosts are the biggest place at the moment where they can go above and beyond what they’ve been doing, and in the process bring awareness to their users. I think that’s where the biggest gap is right now.
Jesse: And I think that’s interesting because there are multiple ways we can talk about AI and the way it’s being used in security. One area I think is really interesting is that AI is an LLM, a language model that allows us to talk to it in the way we like to communicate, which means it can also talk back to us in the way we communicate. I think that’s something that has been missing from the software space, especially around security, for a very long time. When I worked at Brew Protect, one of the things we focused on heavily was helping people understand. And man, was it hard to find ourselves at the intersection of “you’re vulnerable and you can be attacked” but also “don’t be afraid to build a website.” You don’t wanna create fear in folks. You don’t wanna use fear tactics to get them to subscribe to something. At the same time, you want them to understand that they’re not simply behind a giant wall and fully protected, because they’re not. One of the first things we needed to solve for was helping people understand why they were even vulnerable. In talking to users, what we found is that a lot of folks just didn’t understand why they would be attacked. “I run a small mom-and-pop shop, or I have a brochure website, or it’s just my personal portfolio. Why would anyone want to attack that?” What we had to help them understand is that it’s not necessarily a targeted attack. It’s usually a blanket attack. Someone grabbing every single new domain that gets registered and seeing what they can do to penetrate it. Most of the time these botnets are looking to get to the resources behind your website, not necessarily into your actual website. So I wonder if AI could play a role in education, in being a real-time personal assistant inside the WP admin to assist you as you make decisions throughout your website. The moment you install WordPress as a core vanilla product, it’s highly secure. But then you start adding extensions, changing passwords, adding users, and there are so many little things you don’t necessarily think about. Like, something we see so commonly is, “Hey, I’d love your help fixing my website.” This happens at a WordCamp all the time. Someone sits down with me and says, “Okay, I’ll create an admin account for you.” Then they forget they’ve created that admin account. I find myself to be a trustworthy person, but that doesn’t mean everyone is, and it doesn’t mean everyone is for all time. That little action of creating a new admin user creates a vulnerability, but it’s not something they think about. So maybe having a little AI bot that’s like, “Hey, are you sure this person needs to be an admin? Maybe they just need to be an author,” might be a way to leverage AI to help secure a greater part of the internet.
Aaron Campbell: Possibly something that helps convey what those risks are in very normal words. “Hey, an admin can do absolutely anything on your site. This person will continue to have access until you remove this account.” Maybe, “Would you like me to remind you tomorrow to remove this account?” Those kinds of things could be very helpful because there is good maintenance health that end users should be doing, and it’s not that they won’t do it. They just don’t understand that they need to or why. I do think there’s a barrier, and I’ve seen it in almost every company I’ve ever worked in, between the way that super technical people who build and really understand this stuff speak and the way that your average person using this at the end of the day speaks. There can be a translation error there. I think AI might be able to help with that. We’ve certainly been playing with that some at Monarx recently. A good example is in our dark web monitoring product. When we surface a breach, the jargon around what’s included in it tends to be very technical, and we use AI to summarize that in a way that a normal person can understand. What does this mean to you, and what was in this data? I think that’s potentially one of the more exciting ways AI can be used, even if people aren’t super excited about it at the moment, since everybody’s looking at AI for coding and these other big tasks. But this translation could be massively useful going forward.
Jesse: Yeah, I think so. Something that speaks at your level, translating not from two different languages but from two different levels of language. It’s funny because you just talked about dark web monitoring. I’d love to dive into that because when I sit down with folks who get a notice like that, I’ll give you an example. My father-in-law is in his 70s. He’s a smart guy. He used to work at a major publishing company. But this technological stuff is a little hard to digest. When he gets a notice that says, “Hey, you’ve been pwned,” first of all, that’s language not everyone immediately understands, and second, you can feel the tension. Immediately there’s a little bit of adrenaline, a little bit of nervousness. When that happens, your brain starts to constrict, the scope of what you understand gets narrower, and you have a harder time digesting what’s actually happening. It’s really interesting when you start to help people understand that their username and password are now public and they should go change it. But it’s not always, “Wait, did I use that same username and password in six other places?” And how would they even know to start doing that? I think one thing they don’t understand is the broad sweeping ability of hackers to test things a trillion times, to attack 100 million times until they get in, just continually cycling usernames and passwords over and over again. Or if there is a targeted attack, to go and search for your username somewhere else. I think in that moment, being able to help them understand this actually relates to your website is important. It’s tough too because the language has to be designed in a way that helps them understand it, but it doesn’t have full access to everything. It wouldn’t necessarily know if your current password, the one that’s hashed and stored, is vulnerable or not. So it’s kind of a guessing game, and you don’t always give them exact details like, “You have to change your username and password.” It’s more like, “You may need to change your username and password.” So how do you balance that level of urgency with sometimes vaguer statements?
Aaron Campbell: First, you dig in as deep as you can to clarify as much of that vagueness as possible. “May need to change your password” maybe instead becomes an alert on login where you’ve actually checked the password and said, “This is in fact one of those vulnerable passwords,” because you checked it in flight, not just against your database hash. And you do need to change your password because of X, Y, Z. Maybe that’s not possible and “may” is all you can do. Maybe you do know what breach it was tied to and you can say, “Hey, your password from your Nike account was compromised. If you used the same password here, you should change it.” The way we’re doing it in our dark web monitoring is giving roughly three to-dos for every breach someone’s seeing. Trying to give them actionable things that help them think through what’s next. Sometimes the data isn’t even a password. Maybe it was my address and phone number, and what I need to do is set up some credit monitoring because someone’s probably trying to take my identity. Or maybe it’s, “Go everywhere you use this password and change it.” Or, “Make sure to cycle the password on your email account because that’s at risk.” Whatever it is, give them concrete steps. If you have to be vague with the message, make sure the steps are concrete. Maybe your password was compromised, but to make sure you’re safe, click here to change your password. Once that’s done, you’re good to go. Don’t use a password you’ve used somewhere else. Those simple, solid, exact steps can help, to your point, reduce that stress you were talking about. They can just say, “Okay, there’s a scary thing, but if I do this and that, the scary thing’s taken care of. Done.”
Jesse: I think it goes back to empowerment. You wanna leverage that urgency they’re feeling into something they can take action on so they feel empowered to actually fix the problem and address it. So how does someone actually interact with Monarx? Is it an interface that end users interact with directly? Is it passing through the hosting company? Do customers have a direct relationship with Monarx, or is it all through their host?
Aaron Campbell: We power the security solutions at hosts. At many of the big hosts, you are using Monarx whether you realize it or not, to help keep your site clear of malware, et cetera. At some registrars you might be using us for dark web monitoring if you’ve opted into that. We do have some direct interaction with end users in that we supply those hosts with a customer portal that lets a customer see the malware that was found, cleaned, and remediated on their site, the attacks that were blocked, the monitoring that’s in place, those kinds of things. In some cases it gives them the ability to find more details, take action on those things, et cetera. Everything we do is fully API-first, so some hosts have chosen to build that dashboard themselves into their own dashboard, which is great as well. As long as the end user is able to see, know, and understand, that’s great.
Jesse: Yeah. It’s funny because with WP Cloud, we operate the same way. It’s 100% API-based. The hosting company is outsourcing their infrastructure to us for fully managed WordPress, and we handle performance and security for them as well. That puts the host brand up front, which is great for the most part. But there’s an added complexity, especially around security. I think the security company’s brand is important in developing trust with the end user because they don’t only host with one company. It’s ignorant, I think, to assume that an agency or someone else is using only one hosting company. So if these messages are coming through multiple brands, or some hosting companies aren’t taking advantage of the full security solutions that are out there, I wonder if that diffuses the message. Whether it would actually be better for the ecosystem if there was a larger trusted voice across the entire industry that was educating folks. Maybe there’s an opportunity for Monarx to live kind of behind the scenes but also take a larger part in WordPress ecosystem education and community, and maybe other security companies should be doing that as well.
Aaron Campbell: I do think we’re trying to move that way. It is an interesting balance. To your point about agencies, I think you’re 100% right. An agency probably hosts at a number of different hosts. Being able to know that this host or that host is using Monarx and we trust Monarx, that’s great. So building the Monarx brand to those people as a trusted security expert is important. But you also look at the huge number of end users who are hosting directly with a host, who just go to Bluehost and buy hosting. They only know the Bluehost name. That’s the only thing they’ve interacted with. That’s the only thing they’ve built trust with, and they’re not aware of any security companies in the space and probably don’t want to be. They’re a leather worker selling their leather goods online who decided they wanna own their own space instead of sit on Etsy. Since they trust Bluehost with that, they should be able to buy Bluehost Complete Security, and that can come with Monarx, and they never have to know. But they can still be safe with the brand they do trust. So I do think there’s a balance there. There are a number of customers that are only ever gonna know the host as the brand they trust. And for those that make sense, I think it’s important for us to get out there and be talking to agencies, hosts, et cetera, putting out white papers and such, which we’ve been doing recently, to help build trust in our brand.
Jesse: Yeah. I think that kind of leans on the fact that part of the responsibility of a security company like Monarx or WP Cloud, or others, is building the narrative around security so we can help shape the way we’re educating folks and helping them understand things. We’re almost at time, and I wanna continue this conversation. We’ve barely scratched the surface of AI. But before we part on this episode, quick question: are you going to WordCamp US? And if so, what are you excited about?
Aaron Campbell: Going to WordCamp US. And I’m excited about the same thing I’m always excited about at WordCamp US, which is getting together with people and getting the chance to talk about everything happening in our industry at the moment. Everything from what’s affecting hosting, what people are building with the product, what new things are out there, what exciting new projects people have going on. That’s always been my favorite part, and it’s what I’m looking forward to again.
Jesse: Yeah. Very much the same.
Aaron Campbell: What about you? Are you gonna be there?
Jesse: Gonna be there. Very excited to go. I think the energy’s gonna be great. I think we’re gonna see a lot of people hanging out inside the expo because it’s gonna be sweltering outside, but they know how to keep the room cool in there. I think we’re even gonna see people with sweatshirts. What that means is there’s gonna be less of that typical venturing out and taking a break, and more of, “Hey, I’m gonna hang out in the expo area, hang out with others.” I think it’s gonna make for a really great, intimate but large WordCamp. On that note, we’re gonna take a break, and we’ll come back with Aaron for another episode in the future. Thanks, Aaron.
Aaron Campbell: Thanks for having me.





Leave a Reply