Welcome to my Blog: Bridging the Gap Between Risk and Root
Welcome to the blog.
Let me be direct. Cybersecurity is often treated as two separate worlds. On one side you have risk and compliance, which covers frameworks, policies, and governance. On the other side you have the technical sector, which means homelabs, reverse engineering, and exploiting vulnerabilities and much much more.
My name is Nehaal, and I work in cybersecurity. I spend a lot of time helping organizations lock down their security posture and navigate complex governance landscapes. But I have never been content to just stay on the policy side of the fence. Whether I am experimenting with security vulnerabilities or rebuilding my own homelab, I believe the best compliance strategies are informed by practical technical experience. That is exactly what this newsletter is about.
This space is where I will document my projects, break down technical concepts, and bridge the gap between high level risk management and technical execution.
What You Can Expect
You can expect a focus on practical implementation and the realities of modern security. I will be writing about the trials and triumphs of building and securing my own homelab infrastructure. I will also break down recent Common Vulnerabilities and Exposures, cutting through the vendor noise to explain how these vulnerabilities actually work and how to mitigate them.
Alongside that, I will share walkthroughs of my thought processes as I tackle various Capture The Flag challenges. You will also see my thoughts on translating governance requirements into actionable security postures, general industry trends, authentication, and the tools I actually trust.
The Friday Schedule
Every other Friday I will publish a comprehensive wrap up of what I have been working on. These regular dispatches could either be a high level summary of my projects, detailed notes for recently completed CTF rooms, or updates on what new tools I am testing.
A Quick Note on How I Write
My expertise is in cybersecurity, not prose. I am not a professional writer. Because of that, I use AI as an editing and structuring tool to help translate my messy technical notes into readable posts. The ideas, configurations, and opinions are entirely mine. The AI just helps with the polish so I can spend less time editing and more time in the lab.
The transition from theory to practice is where the real security work happens. I am excited to start putting these thoughts to screen. Hit the subscribe button below so you do not miss the first official post, and feel free to leave a comment introducing yourself.
