Topics
All Categories
25 topics across security domains, operations, governance and tooling.
Domains
Cybersecurity
Foundational cybersecurity concepts, defensive strategy and the principles behind resilient security programmes.
Cloud Security
Securing AWS, Azure and GCP workloads — IAM, configuration, workload isolation and cloud-native threat models.
Application Security
Secure development practices, vulnerability classes, code review and application-layer defensive controls.
Network Security
Segmentation, traffic control, perimeter design and the network-layer controls that limit attacker movement.
Linux Security
Hardening Linux systems — kernel controls, permissions, auditing, SELinux and server-side defensive configuration.
Windows Security
Windows and Active Directory hardening, Group Policy, credential protection and endpoint defensive configuration.
Cloud
Cloud platform architecture, infrastructure design decisions and the operational context security sits inside.
AI Security
Securing AI systems — prompt injection, model supply chain, agentic tool risk and controls for LLM applications.
Operations
DevSecOps
Embedding security into CI/CD — pipeline controls, automated scanning, policy as code and developer workflow design.
Ethical Hacking
Authorised offensive security — penetration testing methodology, red teaming and adversary simulation for defenders.
Threat Intelligence
Adversary tracking, indicator analysis, the intelligence lifecycle and turning threat data into working detections.
Malware
Malware families, analysis methodology, evasion techniques and the detection engineering that catches them.
Ransomware
Ransomware operations, extortion economics, the attack lifecycle and the controls that break it at each stage.
SOC
Security operations centre design — triage workflow, analyst tiering, runbooks and the metrics that actually matter.
SIEM
Log management and detection engineering — source prioritisation, parsing, retention economics and rule lifecycle.
Governance
Zero Trust
Zero Trust architecture — policy enforcement, identity-driven access, microsegmentation and realistic migration paths.
Identity Management
Authentication and authorisation architecture — MFA, passkeys, federation, session design and privilege management.
Compliance
Security compliance programmes — control mapping, evidence collection, audit readiness and continuous assurance.
GDPR
GDPR obligations for engineering teams — lawful basis, data minimisation, breach notification and privacy by design.
NIST
NIST frameworks in practice — the Cybersecurity Framework, SP 800 series guidance and how to apply them properly.
ISO 27001
ISO 27001 certification — ISMS scoping, Annex A controls, risk treatment and surviving the certification audit.
Tooling
Security Tools
Independent evaluation of security tooling — what each category is genuinely good at and where it falls down.
VPN
VPN protocols, architecture and the shift toward Zero Trust Network Access for remote connectivity.
Firewalls
Firewall architecture and policy design — next-generation features, rule hygiene and traffic inspection trade-offs.
Password Managers
Password and secrets management — encryption architecture, deployment models and enterprise evaluation criteria.