I’ve spent more than a decade on the defensive side of cybersecurity. Over the years I’ve worked incidents, built programs, and watched how security plays out in the real world.

Everyone likes to pretend that the demos are close to real environments. That the theory holds up to everyday functionality. But the real world is where systems break, people make mistakes, and small things matter more than anyone wants to admit.

What I care about most isn’t just the technology. It’s the people. The employee who notices something is off. The busy executive who hesitates before clicking that link. The analyst staring at an alert at 2am trying to decide if it matters.

Security starts with awareness. The tools are the backup plan.

All over this site, you’ll see me compare security to defending a castle. If you stop to picture it that way, a lot of things start to make more sense. I can talk about defense in depth or zero trust all day long, but they’re just technical terms. No one wants to think in jargon. So I prefer to talk about walls and the guards on them.

Before you ask:

What is this site?

This is where I write about cybersecurity the way it actually works. Not the way we all wish it did.

Who is this for?

You. If you found your way here, you will find something on this site for you. This is for analysts just starting out, or who have 10+ years experience. This is for CEOs, nurses, office assistants and everyone who works for a company. This is also for parents of the kids that read Sparklancers. And for the future Sparklancers.

Why the castle metaphor?

Because it works. If you want to see it in action, check out the tab above for the Sparklancers.

What kind of content will I find here?

Oh so much! For my analysts, you’ll find the kind of lessons that don’t show up in the training manuals. For leaders, you’ll find new ways to think about risk, decisions, and the reality of what your security team is dealing with every day. For someone just trying to do your job, you’ll find breakdowns of what the usual security messaging really means and tips for how to recognize when something feels off. For the parents and the future Sparklancers, you’ll find stories to make this world a little less confusing and a lot more understandable.
Most of all, you’ ll find a way to think about security that doesn’t rely on jargon and holds up with things get real.