Cybersecurity
A risk-based approach, never a fear-based one.
Cybersecurity is one of my core specialties today. It is also the field where I hear the most messaging designed to frighten rather than to inform.
Fear is a poor engine. It drives organisations to buy tools without knowing what they protect, and it exhausts teams long before the security posture improves. I work from risk: what is genuinely exposed, what losing it would cost, and what a given fix actually prevents.
An organisation does not need to protect everything. It needs to know what it protects first.
Where I work
Security governance
Who is responsible for what, which decisions escalate, and how you demonstrate the rules are followed. Without that base, tools only generate alerts nobody handles.
Risk analysis
Inventory what actually matters, estimate the impact of losing it, and rank. It is the step organisations skip most often, and the one that makes every later step worthwhile.
Zero Trust architecture
No longer assuming access from inside the network is legitimate. Systematic verification of identity, device and context on every request.
Identity and access
MFA, PIM, RBAC, conditional access. Identity has become the real perimeter: it is where most compromises now happen.
Detection and response
Microsoft Defender and Sentinel to see what is happening, tuned to produce alerts people actually read rather than continuous noise.
Privacy protection
Law 25 compliance: incident register, privacy impact assessments, retention policies, data subject rights.
How an engagement runs
Written scope
Nothing active begins without a defined perimeter and signed authorisation. An absolute rule, not paperwork.
Current state
Map what exists: identities, access, exposed systems, backups, logging. Most organisations discover things here they did not know about.
Rank by risk
Order findings by what they genuinely enable for an attacker, not by a raw score from a tool.
Remediate in stages
A phased plan with visible gains at each step. An eighteen-month security plan with no interim result never gets finished.
Incident response plan
Write down, calmly, who does what on the day it happens. A plan written during the incident is not a plan.
Awareness
Show the attack rather than describe it. A live demonstration lands harder than a mandatory annual course.
Technologies used
Microsoft
- Microsoft Defender
- Microsoft Sentinel
- Microsoft Entra ID
- Microsoft Intune
- Azure
Network and perimeter
- Fortinet
- Segmentation
- VPN
- Web application firewall
Controls
- Zero Trust
- MFA
- PIM
- RBAC
- Conditional access
Ethical framework
Every offensive engagement follows PTES and OWASP methodologies, under signed scope, with no destructive technique and timestamped logging of each active command.
A question on this?
Describe the context in a few lines. I answer with a proposed angle, not a brochure.