
Learning, Breaking, and Securing things, Eventually
Welcome to my corner of the cybersphere, where I document the beautiful chaos of continuous learning in our ever-evolving field.
After many years navigating the minefield of cybersecurity—from consultancy war stories to OT adventures, SOC late nights to GRC frameworks that make your eyes glaze over - I've learned one undeniable truth: we're all just figuring it out as we go. This blog serves two purposes that keep me caffeinated and curious:
The Learning Lab: Follow along as I tackle new projects, chase certifications, and dive headfirst into technologies that probably didn't exist when I started my career. Expect honest accounts of what works, what spectacularly doesn't, and those "aha!" moments that make the struggle worthwhile.
The Security Spotlight: Where I unpack interesting security topics, share industry observations, and occasionally rant about why we still can't agree on password policies. I aim to make cybersecurity accessible without dumbing it down—because complexity shouldn't require a decoder ring.
Whether you're a seasoned professional or someone just starting their security journey, you'll find candid insights, practical lessons learned, and maybe a few laughs along the way. Because if we can't find humour in our daily battle against attackers, what's the point?
Who am I
With many years knee-deep in the chaotic world of cybersecurity, I've worn many hats. My experience includes roles as Incident Response Lead, fortifying critical infrastructure as a Senior Analyst in OT Security, and providing security guidance to some of the largest organisations in the world.
My professional journey is a continuous quest to outsmart tomorrow's threats and drive forward-thinking security initiatives. I specialize in incident response, vulnerability and risk management, information security, and auditing, with deep knowledge of PCI DSS, COBIT5, and ISO 27001. I thrive on process improvement, stakeholder engagement, and leading teams to enhance security postures.
My career is built on the belief that in cyber, the learning literally never stops, and staying ahead of malicious actors requires constant adaptation and a commitment to lifelong professional development.