About
I’m Joe. I work in cybersecurity, and most of the problems I see aren’t technical, they’re human.
People are juggling too much. Training gets forgotten. Systems don’t behave the way people expect them to. When things break, “user error” becomes the default explanation.
That feels like a cop-out to me.
This blog is my space to explore how security can be calmer, clearer, and more human, and how that shift alone could prevent a lot of incidents.
What you’ll find here
This isn’t a place for fear-driven security advice or finger-pointing. It is a place for:
- Practical insights from real-world experience
- Reflections on behaviour, culture, and training
- Lessons learned from things that didn’t work
- Experiments, observations, and patterns from the field
Sometimes that means sharing things I got wrong.
Sometimes it means questioning accepted “best practice”.
Who this is for
If you:
- Work in cybersecurity, risk, or IT
- Train or support staff on security topics
- Care about security culture, not just compliance
- Have ever thought “we’ve done the training, so why is this still happening?”
…then you’re in the right place
