Practitioner writing on security operations, detection engineering, and managed private networking. Two series — one for buyers, one for builders.
What security operations actually looks like at organizations that can't staff a full team. Assessment methodology, detection gaps, and what good visibility costs versus what a breach costs.
How a home-built security operations platform became KeserNet — and what running it in production taught us about observability, incidents, self-healing automation, and where AI is actually useful.
The structural problem — why SMBs carry the full weight of enterprise-level threats with none of the enterprise-level resources to address them.
Read →Every employee is already using AI. The question isn't whether your business has AI exposure — it's whether you have any visibility into it. A practitioner's guide to what shadow AI actually looks like, what data is moving, and what to do about it.
Read →It started as a personal project to route traffic through a remote tunnel. The interesting question wasn't "can I build a VPN" — it was what comes after it works.
Most assessments tell you what tools you have. This one tells you what your monitoring would miss during an actual incident — and what to do about it.
How observability was built from zero — Netdata, a DuckDB data lake, dashboard evolution, and why choosing the right signals is harder than collecting them.
The gap between "I have a SIEM" and "I have detection." A tool that generates alerts is not the same as a system that generates signal.
Throughput looked fine. Users reported degradation. DERP routing had silently changed. A walk through the investigation — what the data showed, what it hid, and how the root cause was found.
No articles in this series yet — check back soon.