Why I’m Creating This
I’m not a professional with years of experience, I’m not a CISO that has the answer to every cybersecurity question. Until recently, I didn't even know what NIST was.
What I am is a software engineering student who looked at where the industry was heading and made a deliberate pivot toward cybersecurity, specifically toward the intersection of Governance Risk and Compliance (GRC), and cloud security. This newsletter is part of that journey. It exists because writing seriously about something is one of the most effective ways I know to actually understand it.
The Honest Version of My Background
I started in software engineering because it made sense. I was good at it, the career prospects were clear, and building things felt meaningful. But the longer I spent in it, the more I kept circling back to a different problem: the systems being built were increasingly complex, increasingly critical, and increasingly exposed. With the growing popularity of vibe-coding, this notion became ever more prevalent. Security wasn’t an afterthought in theory. In practice, it almost always was.
That gap bothered me enough to want to fix it.
I’m currently completing my engineering degree while I look to transition into cybersecurity. It’s not the most direct pathway, but it’s taught me more about how real infrastructure functions, so that I know exactly what attackers will want to exploit. I’m studying toward GRC and cloud security certifications, building a portfolio of independent security assessments, and trying to develop a genuine point of view on where the field is going.
This newsletter is where I work that out in public.
Why AI Specifically Keeps Me Up at Night
I want to be honest about this because I think a lot of people in tech feel it but don’t say it directly: I find AI capabilities unsettling from a security perspective, and I think that’s a reasonable position to hold.
Not in a doomer way. Not because I think the robots are coming. But because the same capabilities that make large language models useful for automating workflows also make them useful for automating attacks, phishing at scale, social engineering that’s actually convincing, and vulnerability research that used to require deep expertise. The asymmetry between offensive capability and defensive readiness is widening, and it’s widening fast.
I don’t think the right response to that is to look away from it. My instinct is the opposite: understand the threat surface as clearly as possible, no matter how fast it’s growing, because that’s the only honest starting point for building defenses that actually work. So you’ll see a lot of coverage here on AI-enabled threats, AI governance frameworks, and what organisations are actually doing (or failing to do) to manage this risk.
What I’ll Be Covering
This won’t be a headlines compilation, nor will it be a look into the “Top Cybersecurity Trends of 2027”. There are plenty of those. What I’m trying to build here is analysis with a point of view, written by someone with a technical background who’s also genuinely trying to understand the governance and compliance side of security.
In practice that means:
Breach analysis. When significant incidents happen, I’ll go beyond the headlines to look at what the technical timeline reveals, where the controls failed, and what a functioning security program should have caught.
Framework and regulatory breakdowns. The NIST AI RMF, the Essential Eight, Australia’s Privacy Act reforms, ISO 27001. These matter enormously to how organisations actually manage risk, and most coverage of them is either too shallow or written by vendors with something to sell. I’ll try to give you something more honest than that.
Cloud security specifics. Misconfiguration, IAM failures, shared responsibility misunderstandings - The technical realities that sit underneath the governance frameworks.
AI and security governance. How organisations should be thinking about AI risk, what the emerging frameworks actually require, and where the gap between policy and practice currently sits.
I’ll also write occasionally about the career side of this, more specifically what the transition into cybersecurity actually looks like from the inside, what’s working, what isn’t. Not as a content strategy, but because I think there’s a shortage of honest accounts from people mid-journey rather than looking back with the benefit of hindsight.
Who This Is For
Practitioners who want analysis, not just news. People making the same kind of career transition I’m navigating. Security-adjacent professionals (developers, IT managers, compliance people) who want a clearer picture of what’s happening at the edges of the field they work in.
If you’re looking for confident takes from someone who has it all figured out, this probably isn’t it. If you’re interested in someone working through it carefully and in public, stick around.

