Skip to content
Core specialty

Cybersecurity

A risk-based approach, never a fear-based one.

Cybersecurity is one of my core specialties today. It is also the field where I hear the most messaging designed to frighten rather than to inform.

Fear is a poor engine. It drives organisations to buy tools without knowing what they protect, and it exhausts teams long before the security posture improves. I work from risk: what is genuinely exposed, what losing it would cost, and what a given fix actually prevents.

An organisation does not need to protect everything. It needs to know what it protects first.

Where I work

Security governance

Who is responsible for what, which decisions escalate, and how you demonstrate the rules are followed. Without that base, tools only generate alerts nobody handles.

Risk analysis

Inventory what actually matters, estimate the impact of losing it, and rank. It is the step organisations skip most often, and the one that makes every later step worthwhile.

Zero Trust architecture

No longer assuming access from inside the network is legitimate. Systematic verification of identity, device and context on every request.

Identity and access

MFA, PIM, RBAC, conditional access. Identity has become the real perimeter: it is where most compromises now happen.

Detection and response

Microsoft Defender and Sentinel to see what is happening, tuned to produce alerts people actually read rather than continuous noise.

Privacy protection

Law 25 compliance: incident register, privacy impact assessments, retention policies, data subject rights.

How an engagement runs

    01

    Written scope

    Nothing active begins without a defined perimeter and signed authorisation. An absolute rule, not paperwork.

    02

    Current state

    Map what exists: identities, access, exposed systems, backups, logging. Most organisations discover things here they did not know about.

    03

    Rank by risk

    Order findings by what they genuinely enable for an attacker, not by a raw score from a tool.

    04

    Remediate in stages

    A phased plan with visible gains at each step. An eighteen-month security plan with no interim result never gets finished.

    05

    Incident response plan

    Write down, calmly, who does what on the day it happens. A plan written during the incident is not a plan.

    06

    Awareness

    Show the attack rather than describe it. A live demonstration lands harder than a mandatory annual course.

Technologies used

Microsoft

  • Microsoft Defender
  • Microsoft Sentinel
  • Microsoft Entra ID
  • Microsoft Intune
  • Azure

Network and perimeter

  • Fortinet
  • Segmentation
  • VPN
  • Web application firewall

Controls

  • Zero Trust
  • MFA
  • PIM
  • RBAC
  • Conditional access

Ethical framework

Every offensive engagement follows PTES and OWASP methodologies, under signed scope, with no destructive technique and timestamped logging of each active command.

A question on this?

Describe the context in a few lines. I answer with a proposed angle, not a brochure.