In a World with Threats Around Every Corner - Practical Cybersecurity Architecture and AI Security
security made simple
Featured
How to Test Yourself in a Personal Cybersecurity Lab
A practical skills checklist for building a personal VM lab, testing what you know, collecting evidence, and recovering from your own mistakes.
Security Architecture in an AI and Quantum World: My Conversation with 2GuysTek
A conversation with Rich from 2GuysTek about the Cybersecurity Architect's Handbook, the fundamentals that still matter, and how architects should approach AI, zero trust, quantum readiness, and legacy systems.
Seeing Cybersecurity Architect’s Handbook in the Wild Never Gets Old
Seeing a well-read copy of Cybersecurity Architect’s Handbook, Second Edition out in the wild never gets old.
Practice at Home the Way You Preach at Work
I spend my working hours telling teams how to do security well. Segment the network. Write the change down. Model the threat before you build the control. Then I go home, and if I am honest with myself, the temptation is to cut every one of those corners because it is "just the lab."
Latest
How to Test Yourself in a Personal Cybersecurity Lab
A practical skills checklist for building a personal VM lab, testing what you know, collecting evidence, and recovering from your own mistakes.
Retiring a Security Platform Without Bringing It Back by Accident
Decommissioning is the controlled removal of authority, dependencies, identities, and startup paths, not a power-off event.
A Backup Is Not Recovery Evidence
A completed backup proves data was written somewhere. Recovery evidence proves the right service can be restored safely, within its objective, without colliding with production.
AI Guardrails Are Operating Controls, Not Prompt Instructions
A practical baseline for governing AI authority, data, tools, consequential actions, evidence, and lifecycle risk without mistaking a system prompt for a security boundary.
Security Architecture in an AI and Quantum World: My Conversation with 2GuysTek
A conversation with Rich from 2GuysTek about the Cybersecurity Architect's Handbook, the fundamentals that still matter, and how architects should approach AI, zero trust, quantum readiness, and legacy systems.
Threat Modeling the System That Actually Exists
A useful threat model tracks live trust boundaries, administration paths, transition states, recovery systems, evidence dates, and the changes that made the old model wrong.
Inspect Both Sides of the LLM Conversation
A practical policy and configuration guide for detecting prompt injection and jailbreak attempts before inference, then blocking unsafe content and sensitive-data disclosure before model output reaches a user, tool, or application.
Prompt Injection Is an Authorization Failure with Words Attached
After reading my post on AI firewalls, a friend asked for my take on prompt injection. Prompt injection becomes dangerous when untrusted content can steer a software principal into using authority that the content never possessed.