Technical writing and field notes.

Latest Updates (31 articles)

Deepfakes

8 min read

Deepfakes: Cyber Risks and Practical Controls

An analysis of the key cyber risks associated with deepfakes across biometric authentication, social engineering, and disinformation, along with practical mitigation controls.

Data Loss Prevention

11 min read

Stop Screen Leaks: Dynamic Watermarks

Most data protection tools focus on files, emails, uploads, and network transfers. That is necessary, but it does not cover every leakage path.

AI Security

6 min read

Is Your LLM Pipeline Leaking PII?

Core strategies, patterns, and best practices for Personable Identifiable Information (PII) protection, least-privilege agent design, and secure cross-region inference.

Third Party Risk Management

8 min read

Outsource the Work, Not the Blame: Practical Principles of TPRM

A practical guide to modern Third-Party Risk Management (TPRM) focusing on dependency classification, evidence-based due diligence, subcontractor management, concentration risk, and exit planning.

Cybersecurity

7 min read

MAS Notice on Cyber Hygiene Requirements

An analysis of MAS Notice FSM-N06 cyber hygiene requirements, its legally binding controls, scope challenges, and practical implementation for FIs in Singapore.

Cybersecurity

3 min read

Modernize Your SOC: The Cloud-Native Shift

An overview of a strategic initiative to modernize security operations by migrating from legacy on-premises infrastructure to a high-performance, AI-driven SaaS SIEM platform.

Cybersecurity

5 min read

Threat Model Your Life

A compact framework for mapping trust boundaries across identity, devices, cloud services, and automation.

Cybersecurity

2 min read

Secure Logging on a Shoestring Budget

What to log, what not to log, and how to keep observability useful without creating a second data problem.

Cybersecurity

3 min read

Cybercrime Is Becoming a Professional Industry

An analysis of modern threat landscape trends, highlighting the shift toward stealth tactics, extortion-only ransomware, edge device targeting, and AI-enabled social engineering.

Cybersecurity

4 min read

Kerberos Simplified: A Beginner's Guide

Kerberos is a network authentication protocol based on tickets. It provides clients and servers a reliable way to verify each other before establishing a connection.

Mental Models

3 min read

Teach It to a Child: The Feynman Method

Discover the power of the Feynman Technique—a simple, four-step learning framework to master complex concepts and explain them simply.

Cybersecurity

2 min read

OAuth, OIDC, SAML Explained in Plain English

An introductory guide explaining the differences between OAuth, OIDC, and SAML, and their roles in authentication and authorization.

Data Science

1 min read

How K-Means Clustering Groups Your Data

A beginner-friendly introduction to K-Means clustering, explaining how this unsupervised machine learning technique works and its real-world use cases.

Data Science

2 min read

Big Data 101: Understanding the 4 Vs

A beginner roadmap explaining the four core characteristics of big data—volume, velocity, variety, and veracity—using simple, relatable analogies.

Mental Models

3 min read

First Principles: Build from Scratch

With first principles thinking, we can break out of herd mentality, think creatively, and create some unique solutions to very common problems.

Architecture

3 min read

The 7 Golden Rules of System Architecture

A structured set of ideas and general guidelines that collectively define and guide IT solution architecture, focusing on scalability, security, and resiliency.

Data Science

3 min read

The Art of Exploratory Data Analysis

In this article, I'll try to explain Exploratory Data Analysis (EDA) in a five-part series. This part 1 is about overview of statistics and scales of measurement.

Cybersecurity

2 min read

Is Microsoft 365 Leaking Data?

How a CASB-based SSPM capability helped bring visibility, control, and assurance to Microsoft 365 security posture.