Behind the Shield
Introducing Ctrl-Alt-Security: security lessons for anyone, not just the enterprise
I’ve spent more than 15 years in information security. In that time I’ve built vulnerability management programs from nothing, run incident response when things went sideways at 2 a.m., stood in front of executive teams to explain risk in language that actually lands, and mentored newer cyber talent as they grow into their own careers on teams. I’ve built security functions almost entirely from scratch: no playbook, no predecessor to copy, just a problem and a mandate to fix it.
I’m writing this because I want to do more of that work outside the walls of any one company.
What I actually do
Strip away the job titles and the acronyms, and the work comes down to this: protect data, protect systems, protect people, and do it in a way that doesn’t grind the business to a halt. That means:
Finding and fixing vulnerabilities before someone else finds them first
Building governance and risk programs that hold up under audit and under pressure
Running security awareness efforts that people actually remember, not just click through
Sitting across the table from a machine operator one hour and a CFO the next, translating risk both ways
Evaluating vendors and frameworks (things like CMMC and FedRAMP) and turning compliance requirements into something a business can actually operate under
I also work internationally, collaborating with security teams overseas, speaking at industry conferences, and bringing back ideas that make programs stronger. Security is a global problem. The best fixes rarely come from one country, one company, or one person.
I’m also a member of InfraGard, the FBI’s public-private partnership for protecting critical infrastructure, and I’m affiliated with the National Cybersecurity Alliance’s STOP. THINK. CONNECT. program, which focuses on helping everyday people stay safer online. Both of those communities shape a lot of how I think about this newsletter: security isn’t just an enterprise problem, it’s a public one.
Why Substack, why now
I’ve been doing this work inside organizations for a long time, and I’m proud of it. But most of what I learn stays inside those walls. Meanwhile, plenty of people (security professionals early in their careers, IT generalists who got handed “security” as an extra duty, small business owners, or just people trying to keep their own data safe) don’t have easy access to any of it.
That’s the gap I want to close. Not by rehashing headlines, but by writing the way I’d explain something to a colleague: plainly, with the reasoning shown, and without pretending things are simpler than they are.
What you can expect here
This will not be a compliance-checklist newsletter. Expect a mix of:
Practical security: the kind of thing you can actually apply, whether you’re defending a Fortune 500 or your own home network
Career guidance: how to break into this field, how to grow in it, and what I wish someone had told me at year two instead of year twelve
Program-building lessons: what it actually takes to stand up a security function, told through real (anonymized) scars
Tools and tech I use myself: I care a lot about privacy and practical security tooling, and I test a lot of it firsthand
Home lab and testing: I run my own infrastructure at home, and I'll write about what I learn from testing tools and setups firsthand instead of just reading about them.
Where this goes
I don’t have a five-year content calendar. What I have is 15+ years of experience, a habit of mentoring people who ask good questions, and a genuine belief that security knowledge shouldn’t be locked behind a badge. If that’s useful to you, subscribe, and let’s build it out together.
You can also find me as @ctrlaltsecurity on Instagram, X, Bluesky, and Mastodon.
Thanks for being here early.
-Mark

