Cyber Security, Without the Noise
I’m Tayven, and I focus on the parts of cyber security that actually matter: real‑world awareness, practical defence, and clear guidance across vulnerability management, patching, blue‑team operations, and strategic leadership. No jargon. No hype. Just experience you can use.
Featured Articles
- How to Think About the CIA Triad During Real Security Workby TayvenMost people learn the CIA Triad as a textbook definition: Confidentiality, Integrity, Availability. Three pillars. Three bullet points. Three exam terms. But the triad isn’t just something you memorise, it’s something you use. It’s a mental model you carry with you while you investigate alerts, respond to incidents, assess risks, and explain security issues to… Read more: How to Think About the CIA Triad During Real Security Work
- ATO Tax Scams: How to Spot One and What to Look Out Forby TayvenTax season is when Australians are most vulnerable to scams, and scammers know it. Every year, thousands of people receive fake ATO and myGov messages designed to steal refunds, personal information, or access to accounts. If you work, lodge, or claim anything through myGov, these scams are aimed directly at you. I write a lot… Read more: ATO Tax Scams: How to Spot One and What to Look Out For
- How to Run a Cybersecurity Tabletop Exercise: A Complete Example Scenario and Facilitation Guideby TayvenWhenever I run a tabletop exercise, the first thing I do is set the tone for the room. I tell everyone that this is not a test and it’s not about catching anyone out. It’s a safe space to walk through our policies, procedures, and decision‑making as a team. The goal is to explore how we work, not judge how anyone performs.
- How to Build an Incident Response Plan: A Complete NIST CSF 2.0 Exampleby TayvenThis article isn’t just a guide, it’s a complete, modern Incident Response Plan aligned to NIST CSF 2.0. A full, real‑world IRP you can use as a reference, benchmark, or starting point for your own organisation.
Latest Articles
- Why Post‑Quantum Cryptography Matters Right Nowby TayvenA short briefing for leaders on why post‑quantum cryptography matters now. Quantum computing still sounds like science fiction to many people. But the reason to prepare isn’t that quantum computers will break the internet tomorrow. It’s that some of the cryptography organisations rely on today will eventually need replacing. The Real Problem The main concern… Read more: Why Post‑Quantum Cryptography Matters Right Now
- Why Continuous Study Shapes Your Career and Life: A Personal Journey Through IT, Burnout, and Cyber Securityby TayvenI’ve pretty much been studying my whole life. From school to TAFE to uni, learning has always been part of my life. But there was one stretch, about three years after finishing uni, where I completely burnt out and stopped studying IT. That break ended up teaching me more about the importance of continuous study… Read more: Why Continuous Study Shapes Your Career and Life: A Personal Journey Through IT, Burnout, and Cyber Security
- How to Think About the CIA Triad During Real Security Workby TayvenMost people learn the CIA Triad as a textbook definition: Confidentiality, Integrity, Availability. Three pillars. Three bullet points. Three exam terms. But the triad isn’t just something you memorise, it’s something you use. It’s a mental model you carry with you while you investigate alerts, respond to incidents, assess risks, and explain security issues to… Read more: How to Think About the CIA Triad During Real Security Work
- Incident Response Series Round‑Up: IRP, PIR, Tabletop Exercises & NIST CSF 2.0by TayvenMy interest in incident response started years ago during my first university course on the subject. It was the first time I’d seen how structured, disciplined, and genuinely powerful a well‑designed Incident Response Plan could be. That early exposure stayed with me. Later, when I began studying NIST CSF 2.0, I noticed something interesting: the… Read more: Incident Response Series Round‑Up: IRP, PIR, Tabletop Exercises & NIST CSF 2.0
- Writing Every Week Made Me a Better Writer (Seven Months In)by TayvenOver the last few months, I’ve felt a real evolution in my writing. Something clicked, not in a dramatic, overnight way, but in the slow, steady way that only happens when you show up week after week. I started analysing some of my favourite writers, and because I was actively writing, I finally understood why… Read more: Writing Every Week Made Me a Better Writer (Seven Months In)
- How to Use Your IRP During an Incident (Aligned to NIST CSF 2.0)by TayvenMy role as an analyst is managing incidents end‑to‑end, escalating when needed, and often acting as the point of coordination during active events. So I wanted to walk through how an Incident Response Plan is actually used during a live incident, the practical, real‑time steps that matter when you’re the one guiding the response. Most… Read more: How to Use Your IRP During an Incident (Aligned to NIST CSF 2.0)
- “Hi Dad, I Dropped My Phone”: How to Spot This Scam And What To Do If You Get Oneby TayvenA late‑night buzz from an unknown number. A message that sounds exactly like your child. A believable accident, a broken phone, a new SIM card arriving at the exact moment you’re tired, distracted, and least likely to double‑check anything. That’s why the “Hi Mum / Hi Dad” scam works. It doesn’t rely on hacking. It… Read more: “Hi Dad, I Dropped My Phone”: How to Spot This Scam And What To Do If You Get One
- The Complete Guide to NIST CSF 2.0 Mappings: Functions, Categories & Outcomes (And How to Use Them)by TayvenSeries Introduction Every IRP, PIR, playbook, and tabletop in this series maps back to NIST CSF 2.0. If you want your security work to look mature, consistent, and defensible, you can’t just say “we follow NIST CSF 2.0.” You need to understand how Functions, Categories, and Outcomes actually fit together and how to use those… Read more: The Complete Guide to NIST CSF 2.0 Mappings: Functions, Categories & Outcomes (And How to Use Them)
- KEV + End‑of‑Life Tracking Toolby TayvenOne of the Github projects I started this year was a KEV and End‑of‑Life tracking tool, a small engine that pulled CISA KEV entries and vendor EOL timelines, and highlighted assets that were both vulnerable and unsupported. It was a powerful idea. KEV tells you what’s being exploited. EOL tells you what can’t be patched.… Read more: KEV + End‑of‑Life Tracking Tool
- ATO Tax Scams: How to Spot One and What to Look Out Forby TayvenTax season is when Australians are most vulnerable to scams, and scammers know it. Every year, thousands of people receive fake ATO and myGov messages designed to steal refunds, personal information, or access to accounts. If you work, lodge, or claim anything through myGov, these scams are aimed directly at you. I write a lot… Read more: ATO Tax Scams: How to Spot One and What to Look Out For
More to Explore
Explore more of the ideas, stories, and themes shaping my work.












