Cyber Security, Without the Noise
I’m Tayven, and I focus on the parts of cyber security that make a practical difference: real‑world awareness, professional practice, practical defence, and clear guidance across vulnerability management, incident response, security culture, and strategic leadership. No jargon. No hype. Just experience you can use.
Featured Articles
- How to Think About the CIA Triad During Real Security Workby TayvenMost people learn the CIA Triad as a textbook definition: Confidentiality, Integrity, Availability. Three pillars. Three bullet points. Three exam terms. But the triad isn’t just something you memorise, it’s something you use. It’s a mental model you carry with you while you investigate alerts, respond to incidents, assess risks, and explain security issues to… Read more: How to Think About the CIA Triad During Real Security Work
- ATO Tax Scams: How to Spot One and What to Look Out Forby TayvenTax season is when Australians are most vulnerable to scams, and scammers know it. Every year, thousands of people receive fake ATO and myGov messages designed to steal refunds, personal information, or access to accounts. If you work, lodge, or claim anything through myGov, these scams are aimed directly at you. I write a lot… Read more: ATO Tax Scams: How to Spot One and What to Look Out For
- How to Run a Cybersecurity Tabletop Exercise: A Complete Example Scenario and Facilitation Guideby TayvenWhenever I run a tabletop exercise, the first thing I do is set the tone for the room. I tell everyone that this is not a test and it’s not about catching anyone out. It’s a safe space to walk through our policies, procedures, and decision‑making as a team. The goal is to explore how we work, not judge how anyone performs.
- How to Build an Incident Response Plan: A Complete NIST CSF 2.0 Exampleby TayvenThis article isn’t just a guide, it’s a complete, modern Incident Response Plan aligned to NIST CSF 2.0. A full, real‑world IRP you can use as a reference, benchmark, or starting point for your own organisation.
Latest Articles
- How to Create Strong Passwords Without Writing Them Downby TayvenPasswords are something most of us use every day, yet they remain one of the weakest parts of our online security. I’ve lost count of how many times I’ve heard someone say, “I use the same password everywhere because it’s easier to remember.” That approach is understandable. Most people have dozens of online accounts and… Read more: How to Create Strong Passwords Without Writing Them Down
- Why Does My Text Message Say “Unverified”? Australia’s New SMS Scam Protection Explainedby TayvenYou open your phone and see a text message from a company you’ve dealt with before. But instead of seeing their name at the top of the conversation, you see a label you’ve never noticed before: Unverified Is it a scam? Should you delete it immediately? Australia has introduced new protections designed to make text… Read more: Why Does My Text Message Say “Unverified”? Australia’s New SMS Scam Protection Explained
- Why Post‑Quantum Cryptography Matters Right Nowby TayvenA short briefing for leaders on why post‑quantum cryptography matters now. Quantum computing still sounds like science fiction to many people. But the reason to prepare isn’t that quantum computers will break the internet tomorrow. It’s that some of the cryptography organisations rely on today will eventually need replacing. The Real Problem The main concern… Read more: Why Post‑Quantum Cryptography Matters Right Now
- Why Continuous Study Shapes Your Career and Life: A Personal Journey Through IT, Burnout, and Cyber Securityby TayvenI’ve pretty much been studying my whole life. From school to TAFE to uni, learning has always been part of my life. But there was one stretch, about three years after finishing uni, where I completely burnt out and stopped studying IT. That break ended up teaching me more about the importance of continuous study… Read more: Why Continuous Study Shapes Your Career and Life: A Personal Journey Through IT, Burnout, and Cyber Security
- How to Think About the CIA Triad During Real Security Workby TayvenMost people learn the CIA Triad as a textbook definition: Confidentiality, Integrity, Availability. Three pillars. Three bullet points. Three exam terms. But the triad isn’t just something you memorise, it’s something you use. It’s a mental model you carry with you while you investigate alerts, respond to incidents, assess risks, and explain security issues to… Read more: How to Think About the CIA Triad During Real Security Work
- Incident Response Series Round‑Up: IRP, PIR, Tabletop Exercises & NIST CSF 2.0by TayvenMy interest in incident response started years ago during my first university course on the subject. It was the first time I’d seen how structured, disciplined, and genuinely powerful a well‑designed Incident Response Plan could be. That early exposure stayed with me. Later, when I began studying NIST CSF 2.0, I noticed something interesting: the… Read more: Incident Response Series Round‑Up: IRP, PIR, Tabletop Exercises & NIST CSF 2.0
- What Seven Months of Publishing Taught Me About Security Communicationby TayvenAfter seven months of publishing consistently, I’ve learned more about communication than I did during years of simply doing the work. Writing forces clarity. You can work effectively while only partially understanding a concept. You cannot explain something clearly to someone else without understanding it properly yourself. The gap between knowing and explaining is where… Read more: What Seven Months of Publishing Taught Me About Security Communication
- How to Use Your IRP During an Incident (Aligned to NIST CSF 2.0)by TayvenMy role as an analyst is managing incidents end‑to‑end, escalating when needed, and often acting as the point of coordination during active events. So I wanted to walk through how an Incident Response Plan is actually used during a live incident, the practical, real‑time steps that matter when you’re the one guiding the response. Most… Read more: How to Use Your IRP During an Incident (Aligned to NIST CSF 2.0)
- “Hi Dad, I Dropped My Phone”: How to Spot This Scam And What To Do If You Get Oneby TayvenA late‑night buzz from an unknown number. A message that sounds exactly like your child. A believable accident, a broken phone, a new SIM card arriving at the exact moment you’re tired, distracted, and least likely to double‑check anything. That’s why the “Hi Mum / Hi Dad” scam works. It doesn’t rely on hacking. It… Read more: “Hi Dad, I Dropped My Phone”: How to Spot This Scam And What To Do If You Get One
- The Complete Guide to NIST CSF 2.0 Mappings: Functions, Categories & Outcomes (And How to Use Them)by TayvenSeries Introduction Every IRP, PIR, playbook, and tabletop in this series maps back to NIST CSF 2.0. If you want your security work to look mature, consistent, and defensible, you can’t just say “we follow NIST CSF 2.0.” You need to understand how Functions, Categories, and Outcomes actually fit together and how to use those… Read more: The Complete Guide to NIST CSF 2.0 Mappings: Functions, Categories & Outcomes (And How to Use Them)
- Known Exploited Vulnerabilities + End‑of‑Life Tracking Toolsby TayvenOne of the Github projects I started this year was a Known Exploited Vulnerabilities and End‑of‑Life tracking tools, a small engine that pulled CISA KEV entries and vendor EOL timelines, and highlighted assets that were both vulnerable and unsupported. KEV tells you what’s being exploited. EOL tells you what can’t be patched. Putting them together… Read more: Known Exploited Vulnerabilities + End‑of‑Life Tracking Tools
- ATO Tax Scams: How to Spot One and What to Look Out Forby TayvenTax season is when Australians are most vulnerable to scams, and scammers know it. Every year, thousands of people receive fake ATO and myGov messages designed to steal refunds, personal information, or access to accounts. If you work, lodge, or claim anything through myGov, these scams are aimed directly at you. I write a lot… Read more: ATO Tax Scams: How to Spot One and What to Look Out For
- Patch Management Automation Toolby TayvenOver the past few months, I’ve been experimenting with building small automation tools to support my Patch Management Series. One of those experiments was a patch ingestion and normalisation tool, a lightweight script designed to pull vendor advisories, clean the data, and present it in a consistent format for analysis. It worked surprisingly well. The… Read more: Patch Management Automation Tool
- How to Create a Participant Handout for a Cybersecurity Tabletop Exerciseby TayvenA participant handout sets the tone for the entire exercise. It gives everyone the same starting point, removes uncertainty, and helps people focus on the scenario rather than trying to remember process details. This one is designed to be read in under two minutes, just enough to orient the room without overwhelming it.
- How to Write an After Action Report (AAR) for Cyber Tabletop Exercisesby TayvenAn After‑Action Report is where a tabletop exercise turns into something real. It’s the moment where the conversation becomes clarity, and clarity becomes improvement. This AAR captures not just what happened in the scenario, but how the team thought, reacted, hesitated, and learned, because that’s where the real value sits.
- How to Run a Cybersecurity Tabletop Exercise: Facilitator Script with Discussion Promptsby TayvenA good tabletop lives or dies on facilitation. A script doesn’t remove spontaneity, it creates psychological safety. It gives the facilitator a structure to fall back on, keeps the room aligned, and ensures the exercise stays focused on process rather than personalities. This script is written so that even a first‑time facilitator can run the scenario confidently while still leaving space for natural discussion and team dynamics.
- How to Run a Cybersecurity Tabletop Exercise: A Complete Example Scenario and Facilitation Guideby TayvenWhenever I run a tabletop exercise, the first thing I do is set the tone for the room. I tell everyone that this is not a test and it’s not about catching anyone out. It’s a safe space to walk through our policies, procedures, and decision‑making as a team. The goal is to explore how we work, not judge how anyone performs.
- How to Write a Post-Incident Review (PIR) Report (With Real-World Example)by TayvenA PIR isn’t just paperwork. It’s where the real learning happens. It’s the document that turns an incident into improvement. To show you what a mature, well‑structured PIR looks like in practice, here’s a full example based on a realistic MFA fatigue and OAuth compromise scenario.
- How to Remove Old Wi‑Fi Networks (and Why Your Devices Keep Reconnecting to Them)by TayvenTayven Tech – Practical Device Tips Old Wi‑Fi networks cause all kinds of annoying problems: your phone auto‑joins a weak café hotspot, your laptop clings to a neighbour’s guest network, or your Mac keeps trying to connect to a router you replaced years ago. The fix is simple, remove the old networks. But to stop… Read more: How to Remove Old Wi‑Fi Networks (and Why Your Devices Keep Reconnecting to Them)
- How I Got Into Cyber, Got Uni for Free, and Passed the SC‑900by TayvenTayven Cyber Security Edition #1: The Education Arc Inside: Uni for Free, Getting Into Cyber, Passing the SC‑900, and the HTB Web Exploitation Pathway You step into the digital frontier, not a void, but a living expanse of systems, signals, and unseen architecture. The paths ahead aren’t labeled; they shift and shimmer with possibility. Cloud,… Read more: How I Got Into Cyber, Got Uni for Free, and Passed the SC‑900
- How I Passed the SC-900 on My First Attempt (Using 4 Free Tools + 2 Paid)by TayvenI’ve been working with Microsoft systems for years, but this year I finally decided to take the Microsoft certification pathway seriously. Everywhere I looked, job ads, cyber roles, cloud positions, Microsoft certifications were becoming a baseline expectation. They’re affordable, the learning material is free, and they map directly to real‑world work. It just made sense… Read more: How I Passed the SC-900 on My First Attempt (Using 4 Free Tools + 2 Paid)
- June 2026 SECURITY PATCH ROUNDUP – Windows, iOS, macOS, Android, Linuxby TayvenJune’s Patch Tuesday delivers a heavy month across all major platforms, with critical kernel vulnerabilities, remote code execution risks, and multiple privilege‑escalation vectors affecting Windows, Apple, Android, and Ubuntu systems. This month’s updates include several container‑escape paths, Secure Boot certificate changes, and high‑impact vendor component fixes across mobile ecosystems. Below is the full breakdown for… Read more: June 2026 SECURITY PATCH ROUNDUP – Windows, iOS, macOS, Android, Linux
- How to Build an Incident Response Plan: A Complete NIST CSF 2.0 Exampleby TayvenThis article isn’t just a guide, it’s a complete, modern Incident Response Plan aligned to NIST CSF 2.0. A full, real‑world IRP you can use as a reference, benchmark, or starting point for your own organisation.
- How to Write a Modern Incident Response Plan (IRP) Using NIST CSF 2.0by TayvenMost organisations have an IRP. Most discover it doesn’t work the moment they actually need it. Not because the document is wrong, but because it was written for the organisation they used to be, not the one responding to an incident today. Incidents in 2026 are cloud‑distributed, identity‑driven, SaaS‑entangled, and business‑impacting. Modern incident response is… Read more: How to Write a Modern Incident Response Plan (IRP) Using NIST CSF 2.0
- The Evolution of Incident Response: Updating the Classic NIST IRP to the 2026 Frameworkby TayvenFor years, cybersecurity teams followed the traditional NIST Incident Response Process: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned. This model shaped how organisations built response capabilities and how students learned incident handling. The threat landscape has shifted dramatically, with cloud‑identity attacks defying linear phases, ransomware spreading before containment can begin, and supply‑chain compromises blurring… Read more: The Evolution of Incident Response: Updating the Classic NIST IRP to the 2026 Framework
More to Explore
Explore more of the ideas, stories, and themes shaping my work.




















