Security Field Notes & Technical Insights
// Authorised Incident Response · Regulatory Architecture · Defensive Engineering
Zero-Trust Document Sharing: Eliminating PII Leaks in WhatsApp & Email
Why sending national IDs and bank statements over chat channels violates KDPA/GDPR data protection laws, and how client-side AES-256-GCM ephemeral escrow eliminates permanent cloud residue.
Managed SIEM for Startups: Practical Real-Time Threat Detection Architecture
How early-stage startups and SMEs can achieve 24/7 threat visibility and KDPA breach audit compliance using lightweight Wazuh agents, Sigma detection rules, and automated containment.
OWASP Top 10 for Kenyan Web Applications
A practical walkthrough of the OWASP categories that actually show up assessing web and API applications built for the Kenyan SME, startup, and NGO market, with KDPA exposure mapping. Includes downloadable field-notes PDF.
Prompt Injection and LLM Security: What Actually Breaks
Direct vs. indirect prompt injection, why naive system-prompt defenses fail, and the practical mitigations (tool permission boundaries, human approval gates) that bound the risk in production LLM/RAG systems. Includes downloadable field-notes PDF.
Zero Trust Architecture: A Practical Starting Point
What Zero Trust actually means operationally, and a realistic staged adoption sequence for a resource-constrained Kenyan business — not an enterprise multi-year program. Includes downloadable field-notes PDF.
Extending the Network: Understanding the Security Boundary
Port forwarding, firewalls, VPNs, routers, and switches unified into one security architecture, from a TryHackMe networking fundamentals room. Includes downloadable field-notes PDF.
SOC Analyst Field Notes: Investigating & Containing the "Portal Drop" Web Shell Breach
Deep forensic walkthrough correlating Apache web access logs with EDR detections to triage brute-force ingress, Base64-obfuscated RCE, reverse shells, and config exfiltration. Includes downloadable 9-page technical PDF dossier.
The Kenya Data Protection Act (KDPA) Developer Checklist: What Engineering Teams Get Wrong
Why privacy policies alone won't prevent statutory fines. A code-level guide to automated data minimization, consent gates, column-level encryption, and 72-hour breach audit logging for Kenyan startups.
AI Governance in Kenya: What Boards and Founders Need to Know
An approval-gate framing for AI oversight, not a compliance checklist — risk tier, data lineage, and human-in-loop requirements for boards and founders deploying AI. Includes downloadable field-notes PDF.
AI Risk Assessment: A Practical Framework
A likelihood x impact scoring framework for AI-related risk, so decisions are comparable across projects instead of ad hoc. Includes downloadable field-notes PDF.
Securing n8n Workflows: A Practitioner's Checklist
Webhook authentication, credential handling, and permission boundaries — the security defaults n8n doesn't set for you. Includes downloadable field-notes PDF.
AI Threat Modeling: Adapting STRIDE for LLM Systems
Mapping Microsoft's STRIDE categories onto real LLM agent and RAG pipeline components — not an abstract exercise. Includes downloadable field-notes PDF.
AI Security Monitoring: What to Actually Log and Alert On
The security-relevant signals that actually catch abuse in production — prompt/output logging, anomaly patterns, and what deserves a real-time alert. Includes downloadable field-notes PDF.