Writeups // Series

Blog

A practitioner's series on cyber-governance, security operations, and digital resilience — written from the SOC chair, the founder's seat, and lived experience of isolation. Read in sequence, or jump to what you need.

  1. No. 01Governance & Policy

    Why Isolated States Build Cyber Resilience Differently

    Isolation does not just limit a state's cyber options — it rewrites what resilience means, and Iran and North Korea show two very different answers.

  2. No. 02Practitioner

    Building a Vulnerability Management Program from Zero

    How I built a working vulnerability management program at my own startup with no security budget, and the sequence any small organization can copy.

  3. No. 03Educator

    Cybersecurity in Plain Language: A Policymaker's Glossary

    The fifteen security terms a policymaker actually needs, each defined in plain sentences with a policy-relevant example.

  4. No. 04Educator

    Teaching Cybersecurity to People Who Will Never Write Code

    Why security literacy for non-coders matters more than another certification for engineers, and the teaching method I use to build it.

  5. No. 05Educator

    What Is a CSIRT, and Why Should a Government Care?

    A plain-language explainer of what an incident response team actually does day to day, and why a country without one is structurally blind.

  6. No. 06Governance & Policy

    CSIRT Capacity Building: The Missing Governance Layer

    A national CSIRT is not a room full of screens — it is a governance institution, and Ghana's decade-long build-out shows what getting the sequence right looks like.

  7. No. 07Practitioner

    Incident Response Playbooks That Actually Get Used

    What separates a playbook that survives a real incident from one that dies in a wiki, drawn from telecom SOC work and building IR processes from scratch.

  8. No. 08Educator

    Phishing Explained Without the Jargon

    How phishing really works, psychologically and technically, with a realistic walkthrough and practical checklists for individuals and small-org leaders.

  9. No. 09Practitioner

    SOC Analyst Diary: What Detection Engineering Really Looks Like

    A generalized, honest account of SOC shift work — alert fatigue, tuning, and the distance between vendor promises and the queue at 3am.

  10. No. 10Educator

    Explaining Zero Trust to Non-Technical Executives

    What zero trust actually means, why it is not a product you can buy, and the three questions every executive should ask a vendor.

  11. No. 11Governance & Policy

    Minimum Viable Cyber Governance

    Before OECD- or EU-style cyber regulation can transfer to a state, four basic things must exist — an accountable agency, a short strategy, recurring money, and a legal basis.

  12. No. 12Practitioner

    OWASP Top 10, Five Years Later

    The web-security failures that never leave the list, why they persist, and what startups should actually do with the OWASP Top 10.

  13. No. 13Practitioner

    Secure Coding for Teams Without a Security Hire

    The small set of secure-development habits that prevents most common failures, learned running a startup dev team with no security budget.

  14. No. 14Educator

    How Encryption Actually Protects — and Doesn't Protect — You

    Sealed envelopes, locked safes, and the honest limits of encryption — what it defends against, what it cannot, and why that matters for the backdoor debate.

  15. No. 15Governance & Policy

    Comparing Global CIIP Frameworks: What Each One Assumes About You

    The OECD Recommendation, EU NIS2, and the AU Malabo Convention protect critical infrastructure in very different ways — and each silently assumes a different kind of state.

  16. No. 16Educator

    A Non-Technical Guide to Reading a Security Incident Report

    The anatomy of an incident report — timeline, scope, root cause, impact, remediation — plus the questions to ask and the red flags of a bad one.

  17. No. 17Practitioner

    SIEM Deployment Lessons from Two Very Different Organizations

    What running a SIEM alone at a mid-sized trade company taught me that a mature telecom SOC could not — and vice versa.

  18. No. 18Practitioner

    Threat Intelligence for Small Teams

    How a team with no TI function can separate the intelligence that changes decisions from the feed noise that only changes moods.

  19. No. 19Governance & Policy

    Digital Sovereignty vs. Digital Isolation

    Self-reliance and disconnection get discussed as if they were one thing — a working taxonomy of who chose the constraint, what it constrains, and why the difference matters.

  20. No. 20Governance & Policy

    When the Internet Goes Dark: Governance Lessons from National-Scale Shutdowns

    What national-scale connectivity loss actually does to work, families, and the economy — and what any government should learn from it, written from lived experience.

  21. No. 21Region

    Digital Infrastructure Under Sanctions: The Iranian Case

    How sanctions reshape a country's digital infrastructure across hardware, software, cloud, and payments — and why the bill lands on defenders.

  22. No. 22Region

    Rebuilding Digital Trust After a National Shutdown

    Connectivity comes back in days; trust comes back in years — what banks, businesses, and public services must actually do to earn it back.

  23. No. 23Region

    Freelancing Through a Blackout: A Firsthand Account

    What it takes to keep an independent consulting practice alive when the internet disappears for months — a professional survival playbook, told firsthand.

  24. No. 24Governance & Policy

    Cyber Resilience Without a Seat at the Table

    What resilience looks like for states shut out of Western-aligned frameworks, vendor markets, and information-sharing bodies — and why their exclusion costs everyone.

  25. No. 25Region

    What Regional Cyber Cooperation Could Look Like

    A realistic blueprint for cyber cooperation across the Middle East and West and Central Asia — technical channels that can work even where political trust cannot.