Tayven

Circular NIST CSF 2.0 diagram with a dark‑navy “Govern” center and five equal outer segments labeled Identify, Protect, Detect, Respond, and Recover, each with its own color and icon on a cyber‑themed background.

Incident Response Series Round‑Up: IRP, PIR, Tabletop Exercises & NIST CSF 2.0

My interest in incident response started years ago during my first university course on the subject. It was the first time I’d seen how structured, disciplined, and genuinely powerful a well‑designed Incident Response Plan could be. That early exposure stayed with me. Later, when I began studying NIST CSF 2.0, I noticed something interesting: the […]

Incident Response Series Round‑Up: IRP, PIR, Tabletop Exercises & NIST CSF 2.0 Read More »

A metallic cyber‑themed “The Build Log” logo featuring a chrome gear, glowing circuit lines, and a digital progress bar.

Writing Every Week Made Me a Better Writer (Seven Months In)

Over the last few months, I’ve felt a real evolution in my writing. Something clicked, not in a dramatic, overnight way, but in the slow, steady way that only happens when you show up week after week. I started analysing some of my favourite writers, and because I was actively writing, I finally understood why

Writing Every Week Made Me a Better Writer (Seven Months In) Read More »

Circular NIST CSF 2.0 diagram with a dark‑navy “Govern” center and five equal outer segments labeled Identify, Protect, Detect, Respond, and Recover, each with its own color and icon on a cyber‑themed background.

How to Use Your IRP During an Incident (Aligned to NIST CSF 2.0)

My role as an analyst is managing incidents end‑to‑end, escalating when needed, and often acting as the point of coordination during active events. So I wanted to walk through how an Incident Response Plan is actually used during a live incident, the practical, real‑time steps that matter when you’re the one guiding the response. Most

How to Use Your IRP During an Incident (Aligned to NIST CSF 2.0) Read More »

Cracked smartphone on a dark table at night displaying a text message notification that says “Hi Dad,” symbolising the start of a scam.

“Hi Dad, I Dropped My Phone”: How to Spot This Scam And What To Do If You Get One

A late‑night buzz from an unknown number. A message that sounds exactly like your child. A believable accident, a broken phone, a new SIM card arriving at the exact moment you’re tired, distracted, and least likely to double‑check anything. That’s why the “Hi Mum / Hi Dad” scam works. It doesn’t rely on hacking. It

“Hi Dad, I Dropped My Phone”: How to Spot This Scam And What To Do If You Get One Read More »

A printed document titled “NIST CSF 2.0 Explained: Functions, Categories & Outcomes (Complete Mapping Guide)” lies on a modern corporate desk beside a MacBook Pro. The Tayven Cyber Security logo is stamped on the top page, and the document is neatly stapled in the top‑left corner, ready to be read.

The Complete Guide to NIST CSF 2.0 Mappings: Functions, Categories & Outcomes (And How to Use Them)

Series Introduction Every IRP, PIR, playbook, and tabletop in this series maps back to NIST CSF 2.0. If you want your security work to look mature, consistent, and defensible, you can’t just say “we follow NIST CSF 2.0.” You need to understand how Functions, Categories, and Outcomes actually fit together and how to use those

The Complete Guide to NIST CSF 2.0 Mappings: Functions, Categories & Outcomes (And How to Use Them) Read More »

Patch Management Series logo featuring a metallic shield with two interlocking gears and a digital circuit background.

KEV + End‑of‑Life Tracking Tool

One of the Github projects I started this year was a KEV and End‑of‑Life tracking tool, a small engine that pulled CISA KEV entries and vendor EOL timelines, and highlighted assets that were both vulnerable and unsupported. It was a powerful idea. KEV tells you what’s being exploited. EOL tells you what can’t be patched.

KEV + End‑of‑Life Tracking Tool Read More »

A hand‑drawn, softly coloured illustration showing a person holding a smartphone displaying a fake ATO tax refund SMS message. The banner at the top reads “ATO Tax Scams: How to Spot One and What to Look Out For.”

ATO Tax Scams: How to Spot One and What to Look Out For

Tax season is when Australians are most vulnerable to scams, and scammers know it. Every year, thousands of people receive fake ATO and myGov messages designed to steal refunds, personal information, or access to accounts. If you work, lodge, or claim anything through myGov, these scams are aimed directly at you. I write a lot

ATO Tax Scams: How to Spot One and What to Look Out For Read More »

Patch Management Series logo featuring a metallic shield with two interlocking gears and a digital circuit background.

Patch Management Automation Tool

Over the past few months, I’ve been experimenting with building small automation tools to support my Patch Management Series. One of those experiments was a patch ingestion and normalisation tool, a lightweight script designed to pull vendor advisories, clean the data, and present it in a consistent format for analysis. It worked surprisingly well. It

Patch Management Automation Tool Read More »

A cybersecurity team sits around a conference table while a facilitator leads a tabletop exercise. The screen behind them displays the Tayven Cyber Security logo and the words “Tabletop Exercise: Cyber Security Team.”

How to Create a Participant Handout for a Cybersecurity Tabletop Exercise

A participant handout sets the tone for the entire exercise. It gives everyone the same starting point, removes uncertainty, and helps people focus on the scenario rather than trying to remember process details. This one is designed to be read in under two minutes, just enough to orient the room without overwhelming it.

How to Create a Participant Handout for a Cybersecurity Tabletop Exercise Read More »

A cybersecurity team sits around a conference table while a facilitator leads a tabletop exercise. The screen behind them displays the Tayven Cyber Security logo and the words “Tabletop Exercise: Cyber Security Team.”

How to Write an After Action Report (AAR) for Cyber Tabletop Exercises

An After‑Action Report is where a tabletop exercise turns into something real. It’s the moment where the conversation becomes clarity, and clarity becomes improvement. This AAR captures not just what happened in the scenario, but how the team thought, reacted, hesitated, and learned, because that’s where the real value sits.

How to Write an After Action Report (AAR) for Cyber Tabletop Exercises Read More »