<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://ross-sec-audio.github.io//</id><title>EvK1r0Sp3m</title><subtitle>Ross' website and blog covering Security research, music production, and art.</subtitle> <updated>2026-07-22T22:24:25+01:00</updated> <author> <name>Ross / EvK1r0Sp3M</name> <uri>https://ross-sec-audio.github.io//</uri> </author><link rel="self" type="application/atom+xml" href="https://ross-sec-audio.github.io//feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://ross-sec-audio.github.io//"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Ross / EvK1r0Sp3M </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>Concerns Regarding Digital Identity, VPN Restrictions, and Child Online Safety</title><link href="https://ross-sec-audio.github.io//posts/Concerns-Regarding-Digital-Identity,-VPN-Restrictions,-and-Child-Online-Safety/" rel="alternate" type="text/html" title="Concerns Regarding Digital Identity, VPN Restrictions, and Child Online Safety" /><published>2026-02-23T00:00:00+00:00</published> <updated>2026-04-01T21:16:24+01:00</updated> <id>https://ross-sec-audio.github.io//posts/Concerns-Regarding-Digital-Identity,-VPN-Restrictions,-and-Child-Online-Safety/</id> <content src="https://ross-sec-audio.github.io//posts/Concerns-Regarding-Digital-Identity,-VPN-Restrictions,-and-Child-Online-Safety/" /> <author> <name>Ross / EvK1r0Sp3M</name> </author> <summary> Concerning News I’m very concerned about the current implementation of the UK’s Online Safety Act and the emerging digital identity framework, particularly in relation to fairness, civil liberties, and recent proposals relating to VPN restrictions. While I fully support the goal of making the internet safer, I’m worried that the direction being taken, which may unintentionally harm the very gr... </summary> </entry> <entry><title>InfoSec Best Practice - An Unhelpful Term</title><link href="https://ross-sec-audio.github.io//posts/InfoSec-Best-Practice-An-Unhelpful-Term/" rel="alternate" type="text/html" title="InfoSec Best Practice - An Unhelpful Term" /><published>2023-10-04T00:00:00+01:00</published> <updated>2024-09-10T23:18:53+01:00</updated> <id>https://ross-sec-audio.github.io//posts/InfoSec-Best-Practice-An-Unhelpful-Term/</id> <content src="https://ross-sec-audio.github.io//posts/InfoSec-Best-Practice-An-Unhelpful-Term/" /> <author> <name>Ross / EvK1r0Sp3M</name> </author> <summary> Best Practice Throughout my career in InfoSec, I must have heard the term “Information Security best practice” thousands of times. I didn’t think too much about it until recently, waving it off as a heuristic way to describe how something is “appropriately secured”, or “secured in line with an industry’s expectations”. The term bothered me and I knew some colleagues who had a distaste for it,... </summary> </entry> <entry><title>A Rant about DevSecOps</title><link href="https://ross-sec-audio.github.io//posts/DevSecOPs-Rant/" rel="alternate" type="text/html" title="A Rant about DevSecOps" /><published>2023-02-27T00:00:00+00:00</published> <updated>2024-09-10T23:18:53+01:00</updated> <id>https://ross-sec-audio.github.io//posts/DevSecOPs-Rant/</id> <content src="https://ross-sec-audio.github.io//posts/DevSecOPs-Rant/" /> <author> <name>Ross / EvK1r0Sp3M</name> </author> <summary> Scene setting Over the last few years, I’ve witnessed many organisations express pretty negative views and misplaced ideas about DevOps and Agile, while sometimes using them as excuses to sidestep process gates and governance. In response, I’ve often tried to explain the benefits and specific uses of DevOps and Agile practices, and attempted to correct those who abuse DevOps and Agile terms t... </summary> </entry> <entry><title>Vulnerability Management in 4 Stages</title><link href="https://ross-sec-audio.github.io//posts/Vulnerability-Management-in-4-Stages/" rel="alternate" type="text/html" title="Vulnerability Management in 4 Stages" /><published>2022-06-07T00:00:00+01:00</published> <updated>2024-09-10T23:18:53+01:00</updated> <id>https://ross-sec-audio.github.io//posts/Vulnerability-Management-in-4-Stages/</id> <content src="https://ross-sec-audio.github.io//posts/Vulnerability-Management-in-4-Stages/" /> <author> <name>Ross / EvK1r0Sp3M</name> </author> <summary> What is Vulnerability Management? Well, running a periodic Nessus scan on some of your organisation’s stuff ain’t it. That’s because it’s a full lifecycle of tools, team collaboration and processes, including: Periodic/continuous scanning of all your organisation’s assets, using various tools Informed measurement and prioritisation of findings from these tools The remediation of t... </summary> </entry> <entry><title>InfoSec Risk Management - Benefits &amp; Common Pitfalls</title><link href="https://ross-sec-audio.github.io//posts/Risk-Management-Explained/" rel="alternate" type="text/html" title="InfoSec Risk Management - Benefits &amp; Common Pitfalls" /><published>2021-12-31T00:00:00+00:00</published> <updated>2026-02-23T11:08:22+00:00</updated> <id>https://ross-sec-audio.github.io//posts/Risk-Management-Explained/</id> <content src="https://ross-sec-audio.github.io//posts/Risk-Management-Explained/" /> <author> <name>Ross / EvK1r0Sp3M</name> </author> <summary> How Information Security (InfoSec) Risk Management can practically improve the security posture of your organisation if implemented correctly. Introduction The purpose of this article is to clearly describe how InfoSec Risk Management can tangibly improve the security posture of your organisation while outlining some common pitfalls and mistakes. TL;DR Risk Management provides methodolog... </summary> </entry> </feed>
