Insights

What we know.
How we know it.

Practitioner writing on security operations, detection engineering, and managed private networking. Two series — one for buyers, one for builders.


Keser SecOps Series

For the people responsible for security

What security operations actually looks like at organizations that can't staff a full team. Assessment methodology, detection gaps, and what good visibility costs versus what a breach costs.

KeserNet Series

For the people who build the infrastructure

How a home-built security operations platform became KeserNet — and what running it in production taught us about observability, incidents, self-healing automation, and where AI is actually useful.

Keser Jul 28, 2026

The Security Operations Gap: Why Small Organizations Are Underserved

The structural problem — why SMBs carry the full weight of enterprise-level threats with none of the enterprise-level resources to address them.

Read →
Keser Jul 28, 2026

What You Don't Know About Your AI Exposure Is the Risk

Every employee is already using AI. The question isn't whether your business has AI exposure — it's whether you have any visibility into it. A practitioner's guide to what shadow AI actually looks like, what data is moving, and what to do about it.

Read →
KeserNet Coming Soon

What Happens When a Home Lab Grows Up: The Origins of KeserNet

It started as a personal project to route traffic through a remote tunnel. The interesting question wasn't "can I build a VPN" — it was what comes after it works.

Keser Coming Soon

Building a Security Monitoring Assessment from First Principles

Most assessments tell you what tools you have. This one tells you what your monitoring would miss during an actual incident — and what to do about it.

KeserNet Coming Soon

You Cannot Operate What You Cannot Observe: Building Visibility into KeserNet

How observability was built from zero — Netdata, a DuckDB data lake, dashboard evolution, and why choosing the right signals is harder than collecting them.

Keser Coming Soon

What Most SMBs Get Wrong About Detection Engineering

The gap between "I have a SIEM" and "I have detection." A tool that generates alerts is not the same as a system that generates signal.

KeserNet Coming Soon

When the Metrics Lied: The DERP Incident

Throughput looked fine. Users reported degradation. DERP routing had silently changed. A walk through the investigation — what the data showed, what it hid, and how the root cause was found.

No articles in this series yet — check back soon.