Weekly Column
Welcome to the Column
I didn't come into cybersecurity through a computer science degree. I came into it through journalism and education — two fields built around the same basic habit: ask enough hard questions, and eventually you understand how something actually works, not just how it's supposed to work.
That habit turned out to translate almost directly. A network, like a story, is a set of claims about how things are connected and what's supposed to happen when they interact. Security work is mostly the process of testing those claims against reality — finding the gap between the diagram on the whiteboard and what's actually reachable, exposed, or misconfigured.
Since 2018 I've spent close to seven years doing that work inside managed service providers, across a wide range of environments and client maturity levels. I've seen the same mistakes repeat across organizations that never talk to each other, and I've seen the same fixes work again and again once someone finally asks the right question.
This column is where I'll write that up — weekly notes on security risk, how networks actually behave under pressure, what I'm seeing in assessments and audits, and the occasional plain-language breakdown of a concept that gets more jargon than it deserves.
No fear-mongering, no vendor pitches disguised as thought leadership — just what I'd tell a client if they asked me straight. Thanks for reading. New post every week.
— Daniel