← All transmissions

Tagged: #cybersecurity

Defending an AI Email Tool Against Prompt Injection: Three Layers
Three defence-in-depth layers I built into Sift, my AI email triage tool, and what a real prompt-injection attack against it did and didn't prove.
Cybersecurity Capstone — VIP Events (Stage 5: Policy Implementation)
The final stage of the VIP Events cybersecurity proposal — user authentication policy via Conditional Access, network configuration policy for the web app via Azure Policy, and why both are tested in non-production first.
Cybersecurity Capstone — VIP Events (Stage 4: Testing and Validation)
Stage 4 of the VIP Events cybersecurity proposal — a test plan validating authentication, role-based access (including negative tests), MFA enforcement, and logging in the live Entra ID tenant.
Cybersecurity Capstone — VIP Events (Stage 3: Roles and Access)
Stage 3 of the VIP Events cybersecurity proposal — integrating the VIP Foods application into Entra ID, defining eight least-privilege app roles, and mapping the security groups to them.
Cybersecurity Capstone — VIP Events (Stage 2: Entra ID Setup)
Stage 2 of the VIP Events cybersecurity proposal — building the identity and access foundation in a live Microsoft Entra ID tenant: tenant configuration, user accounts, and role-based security groups.
Cybersecurity Capstone — VIP Events (Stage 1: Company Requirements)
Stage 1 of a cybersecurity proposal for a fictional catering company moving to a new three-storey building — network segmentation, wireless design, access control, user roles, and physical security.
Little Did I Know: Catching My First Brute-Force
I brute-forced my own homelab server to see what was behind an open SSH port — and found out my Wazuh setup had already caught me in the act.