Security
Password Manager vs Browser Passwords
Browser password storage is convenient. A dedicated password manager gives better cross-platform control, sharing, and recovery planning.
A Practical Post-Quantum Readiness Checklist for Network Teams
A practical checklist for network teams preparing for post-quantum cryptography: inventory, risk ranking, platform support, certificates, VPNs, secure boot, and refresh planning.
Resilience Planning for Cisco Networks: Patch, Shield, Replace, or Segment
A practical resilience model for Cisco networks should classify each exposure into patch, shield, replace, or segment, with owners, deadlines, and evidence.
Reverse Proxy for Media Apps: Nginx Proxy Manager, SSL, Access Lists, and Security
Keep Sonarr, Radarr, Prowlarr, SABnzbd, Tdarr, NAS administration, and the Nginx Proxy Manager dashboard private. Use LAN or VPN access by default. Add a reverse proxy only for a hostname that has a real remote-user requirement, and keep application authentication, patching, isolation, backups, and logging behind it. Rights and lawful use: This reverse-proxy workflow assumes […]
Homelab Reverse Proxy Guide: HTTPS Without Unsafe Exposure
A security-first reverse proxy guide for homelabs, covering DNS, TLS, app exposure, internal-only services, authentication, logging, and validation.
Post-Quantum Networking: What Cisco’s Quantum-Ready Push Means
Post-quantum networking is about inventory, crypto-agility, long-lived data risk, secure boot, VPNs, certificates, and refresh planning before the emergency arrives.
Designing Networks With DoD IL5 in Mind: Campus, Data Center, IT, and OT Security
A network is not "Department of Defense (DoD) Impact Level 5 (IL5) compliant" by itself. A network can, however, be designed to support a mission system categorized at IL5 or pursuing a DoD IL5 authorization. That distinction matters. IL5 is about the mission system, the authorization boundary, the data being protected, the controls that are […]
Live Protect and Runtime Vulnerability Shielding for Network Infrastructure
Live Protect is Cisco’s runtime shielding approach for reducing exposure while teams plan upgrades. It should complement patching, segmentation, and lifecycle management, not replace them.
Cisco Secure Access: Where SSE, ZTNA, SD-WAN, and AI Security Meet
A practical look at Cisco Secure Access, SSE, ZTNA, Meraki SD-WAN integration, AI application control, and how to design a migration away from legacy VPN assumptions.
