WriteupsFitnessBlogAbout LinkedIn
/blog

Blog

Security research, network engineering, and the journey from defender to attacker.

Aug 27
2026

GRC in Plain English : Governance, Risk and Compliance Explained

Most engineers know how to secure a network. Far fewer understand the framework that decides what to secure, how much to spend on it, and who's accountable when something goes wrong. That framework is GRC.

grcgovernancerisk-managementcompliance
->
Aug 11
2026

Security Awareness Training That Actually Works

Most security awareness training is a checkbox exercise that changes nothing. Here's what actually moves the needle — and what I've seen work in real enterprise environments across the UAE.

security-awarenessphishingcybersecurityhuman-factor
->
Jul 23
2026

Your Firewall Is Not Your Biggest Security Risk

After 12 years securing enterprise networks, the threats that concern me most have nothing to do with misconfigured rules or unpatched systems. They start with a person.

cybersecuritysecurity-awarenesshuman-factorphishing
->
Jul 19
2026

Implementing Zero Trust on Palo Alto NGFW — A Practical Guide

Zero Trust gets thrown around a lot. Most implementations I see are just VLANs with a new name. Here's what it actually looks like to build it properly on Palo Alto.

zero-trustpalo-altopanoramangfw
->
Jul 13
2026

5 Red Flags in Enterprise Firewall Audits

After years of reviewing enterprise firewall estates across the UAE, these are the red flags I find almost every single time. If your network has any of these, fix them before someone else finds them for you.

firewallpalo-altopanoramasecurity-audit
->
Jul 09
2026

From Network Engineer to Pentester — Why I Started TryHackMe

I have a CCIE and a CISSP. I've been building and securing networks for over 10 years. So why did I go back to basics and start TryHackMe's Junior Pentester path? Here's the honest answer.

tryhackmepentestingnetworkingcareer
->