Cybersecurity
Security research, threat analysis, and technical writing. Articles published on my blog alongside hands-on projects.
Articles
The Google Trap Software Developers & Founders are Walking Right In, and Never Know
If an AI agent generates part or all of your code, who holds the copyright for that code?
The Truth About Cyberattacks Most Business Owners Don't Understand, and I Get Why…
The biggest cybersecurity risk in your business might not be the hacker. It might be the fact that you'd never know they were there. Most founders imagine cyberattacks as a smash-and-grab operation. Reality is different. The best attackers are patient. And that is the trap. The trap that has made you think cybersecurity is optional. I explored this idea in my latest article with OminiLock. Because you cannot protect what you cannot see, you need to see first. Have a secure read...
The Biggest Security Lie Sold To Startups
The biggest lie sold to startups is that cybersecurity can wait. Unfortunately, that threat actor lurking behind can't; your investors won't believe that, and your future self will blame you if you keep buying that lie. In this article, I outlined why every startup founder must treat cybersecurity like their startup's success or failure depends on it (because to a large extent, it does), and I gave practical steps you can begin today, not tomorrow, to secure your startup. Have a secure read.
Why YARA Rules are Better Than Hashes in Malware Detection
After Ransomware, What Next? 3 Things to do to Prevent Ransomware Reinfection
The three things every business must do after a ransomware attack is cleared.
A Clean Dashboard Doesn't Imply Security: Here's Why
Why Equating ‘No Alerts’ With ‘No Threats' is Risky For Enterprise Environments
5 POS Security Errors that can Lose you Money, & Possibly Send you to Jail
If your business uses a POS, I highlighted five security mistakes you should avoid if you don't want to lose money... or land yourself in jail. Share this with someone who needs to read it.
Enhancing Malicious IP Detection and Intelligence Using Abuse.ch API
Discover how organizations and security teams can up their detection and intelligence game by pulling IPs labeled as malicious, while using Active Response to take automated actions against these IPs when they turn up in logs.
Security by Segmentation: The 3-tiered Network Architecture
My article on Network Segmentation and how it can be used as a means of network security is out. This article was inspired by the SEC401_K01 demo course I took from SANS Institute by Bryan Simon.
How I hacked and remotely took over a Windows PC using RDP Exploit
Practical demonstration of how organizations using RDP on their laptops can be compromised remotely.
3 Affordable Cybersecurity Implementations that Cost Less Than $100
This article touches on 3 affordable cybersecurity methods you can start implementing today to save you and your business. Instead of waiting till you can afford to pay thousands of dollars (if those threat actors actually let you do so), do these 3 now!
Security Blue Team Wireshark Exam Walkthrough
Case Study: How Cyber Threat Intelligence Can Help Food & Pharmaceutical Businesses Combat Fakes
Cybersecurity isn’t just about firewalls and passwords. In my latest case study, I break down how Cyber Threat Intel is helping food & pharma businesses fight back—protecting revenue, reputation, and lives.
The NDPR Compliance Mistake That's Silently Killing Nigerian Startups: A Cybersecurity Perspective
If you own or work with a startup, chances are high that you are a data processor, and thus, this applies to you. However, are you compliant already, or waiting for an issue to fix? In this article, I highlighted some of the silent ways many startups risk themselves when it comes to data handling compliance, and offered proactive solutions to that.
A Startup Without Cybersecurity is a Waste of Time.
Why cybersecurity is essential for every startup, and how to go about it when you are just starting out
Projects
Wazuh Email Alerts Automation
This project outlines how I configured my Wazuh manager/server to automatically send in critical email alerts.
