📌 Field Notes

Guides • Runbooks • Industry News
Observations • Getting Started

Notes from my board on what's happening in the field and what I'm learning along the way: the practitioner work behind Ministry in Context.

10+
Years in cybersecurity
21
Years military service
CISM
+ 10 active certs
CTT+
Certified Technical Trainer
What this is

The board is real.
So are the notes.

I have a physical board behind my desk covered in sticky notes. Topics I'm tracking. Things that clicked. Runbooks I built for myself before I realized someone else might need them. News that mattered and my take on why.

This page is the digital version of that board. It's not a course. It's not polished for a general audience. It's practitioner-to-practitioner: the kind of notes you'd share with your colleague over Teams.

If you're maintaining certifications, staying current, or just trying to think more clearly about a problem: you're in the right place.

What's on the board

Five types of notes.

Everything falls into one of these buckets. Each one is worth a different kind of attention.

📋

Guides

Topic deep-dives written from experience, not from a textbook. Frameworks, concepts, and controls explained the way a practitioner would explain them to a colleague.

Browse guides →
📘

Runbooks

Operational, step-by-step. Built because I needed them first. Each one is something I've actually run in my homelab or tested in a real environment, not a theoretical procedure.

Browse runbooks →
📡

Industry News

Current advisories, vulnerabilities, and incidents, with context. Not a feed: a practitioner's take on what actually matters and what the implications are for your environment.

Browse industry news →
🔍

Observations

Shorter notes on patterns, lessons, and things I keep seeing in the field. The kind of thing you'd write on a sticky note and tape to your monitor so you don't forget it.

Browse observations →
🎓

Getting Started

For career changers, complete beginners, and veterans making the transition into cybersecurity. Real experience, a proven roadmap, and no shortcuts glossed over.

Browse getting started →
From the board

Recent notes

Latest guides, runbooks, and analysis: sorted by what's most useful right now.

Know When You've Been Touched: SSH Alerts + Intrusion Detection

Turn your VPS into a server that speaks up. Learn how to receive instant SSH login alerts and detect unauthorized system changes using PAM, cron, and Ntfy.

Stop the Bots: Blocking Brute Force Attacks with Fail2ban

Bots begin probing your VPS within minutes of it going online. Learn how to configure Fail2ban to automatically detect repeated SSH login failures, ban malicious IPs, and protect your server 24/7.

Policy-Based Routing in Linux

How to configure policy-based routing (PBR) in Linux so traffic from a specific IP or interface uses a separate routing table.

Credentials

The foundation came first. Every certification on this list was a deliberate step — not a collection, a path. This is the foundation the content on this site is built on. If there's one thing this site stands for, it's that there are no shortcuts to knowing what you're doing.

CISM CGRC CySA+ Security+ Network+ A+ Server+ Cloud+ Project+ CTT+ MCSA MCP MCT (formerly held) CCNA (formerly held) ITIL 4 (formerly held)

Content on this site may qualify toward CPE/CEU requirements for ISACA, CompTIA, and other certifying bodies: verify with your organization's continuing education policy.

New note on the board.

When something worth writing goes up, you'll hear about it first. Practical, peer-level cybersecurity content: no vendor spin, no course pitches.

No spam. Unsubscribe anytime.