I run security at Ingram, not as a side task, as the actual job. Wrote the guidelines everyone gets onboarded with, picked NIST CSF + Belgium’s CCB Cyfun as the practical starting point instead of jumping straight to ISO 27001, and I’m building the asset inventory and controls we’d need if we go for certification later.
On the hands-on side: pentesting our own product (AI-assisted recon, manual follow-up), setting up SSO/MFA with the dev team, picking vulnerability scanning and supply chain tooling, and mentoring our security intern.
Old scratch notes this grew out of:
Iso27001
Nist2
Certifications nism csnp
IA
Passion
Cyber what is it
Headmind research
Cloud sec
Read book wim
Rtc internationale
Aspect culturel secu
H4 crak quick w gpu on window
Xss sql
Firewall out reverse
Site find vuln: openvas
Dirbuster
Metasploite
Sqlmap
Greenbone security as
Cia tools
Corelight at home