Blog · InfoSec

Notes & essays.

InfoSec3 Sept 2026 · 9 min read

Cybersecurity Frameworks: NIST CSF, ISO 27001 and CIS

NIST CSF 2.0, ISO 27001 and CIS Controls, written for auditors and decoded for founders: what each says, how they fit together, and where to start.

Read
InfoSec31 Aug 2026 · 9 min read

Incident Response Plan: Logging, Detection and Recovery

Breaches take 258 days to spot on average. What to log, the ten alerts that catch real intrusions, and an incident response plan short enough to use at 3 a.m.

Read
InfoSec27 Aug 2026 · 9 min read

Social Engineering and Phishing: Why Training Alone Fails

68% of breaches involve a person doing something a person would do. How phishing, vishing and BEC really work, why annual training barely helps, and what does.

Read
InfoSec24 Aug 2026 · 9 min read

Defence in Depth: Layered Security That Survives Failure

Colonial Pipeline fell to one password with nothing behind it. Defence in depth arranges controls so one failure never costs everything. A ten-line design.

Read
InfoSec20 Aug 2026 · 10 min read

Cryptography Basics: Hashing, Encryption and TLS

You’ll never design a cipher, but you’ll choose one every week. What to use in 2026 (Argon2id, AES-GCM, TLS 1.3) and the mistakes that make good crypto useless.

Read
InfoSec17 Aug 2026 · 9 min read

Principle of Least Privilege and Zero Trust Explained

Access accumulates until a phished receptionist can delete production. Least privilege, joiner–mover–leaver fixes, admin tiers, and what zero trust means.

Read
InfoSec13 Aug 2026 · 9 min read

Multi-Factor Authentication, Passwords and Passkeys

Most breaches still start with a password. What NIST now says (no forced rotation, no symbol rules), which MFA can be phished, and why passkeys fix the problem.

Read
InfoSec10 Aug 2026 · 9 min read

Information Security Risk Management: A Practical Guide

No system is “secure”, only carrying risks you chose. How to measure risk honestly, pick mitigate, avoid, transfer or accept, and write a register boards read.

Read
InfoSec6 Aug 2026 · 9 min read

Threat Modelling: How to Think Like an Attacker

You can’t defend against “hackers”, only specific people on specific paths. Four questions, STRIDE, attack trees, and a first threat model in 90 minutes.

Read