Ctrl-Alt-Security

> cybersecurity for all

ctrlaltsecurity

Control. Adapt. Protect.

Security guidance written for people, not just for enterprise teams. Plain language, current threats, and steps you can actually take today.

> about

Fifteen years of defending, explained without the jargon

Who is behind this

I am Mark Blair, a cybersecurity professional with more than fifteen years spent on the defending side. My day to day has covered vulnerability management, incident response, threat detection, risk assessment, governance and compliance, and running security awareness programs for people who never asked to think about security.

CTRL-ALT-Security is my personal project. It exists because most security advice is either written for large security teams or watered down until it stops being useful. This site sits in the middle: real threats, current sources, and specific things you can do.

Why it matters outside work

The attacks that hit families, small businesses and volunteers are usually the same techniques that hit large organizations, minus the budget to respond. Phishing, reused passwords, unpatched devices and account takeover do not care how big you are.

Sharing what works, in language people actually use, is the highest leverage security work I know of.

> news

Global information security news

Headlines pulled from public feeds run by government agencies, research teams and independent reporters. Each one links straight to the source.

> awareness

Security awareness you can use today

Short, practical habits that block most of what actually happens to normal people.

Start here

Stop reusing passwords

Password managers and passkeys

One breached site becomes ten breached accounts when passwords repeat. Use a password manager to generate a different password everywhere, and switch to passkeys wherever a site offers them.

High impact

Turn on multifactor everywhere

App codes and security keys beat SMS

Multifactor authentication stops most account takeover attempts outright. An authenticator app or a hardware security key is far stronger than text message codes, which can be intercepted or redirected.

Slow down on urgent messages

Recognizing phishing and smishing

Urgency is the tell. A message that pressures you to act right now, pay immediately, or confirm your account is worth a pause. Go to the site or app directly rather than tapping the link you were sent.

Let your devices update

Patching is the quiet win

Most successful attacks use vulnerabilities that were already fixed. Turn on automatic updates for your phone, computer, browser and router, and replace hardware once it stops receiving security updates.

Back up like you will need it

Three copies, two formats, one offsite

Ransomware and dead hard drives both end the same way without backups. Keep at least one copy that is not permanently connected to the machine it protects, and test a restore once in a while.

Have the scam conversation early

Protecting relatives and kids

Grandparent scams, fake job offers, romance scams and gift card requests all rely on isolation and embarrassment. Agree in advance that anyone can call you to sanity check a strange request, no judgment.

> projects

Things I am building

Side projects that came out of real security problems.

CTRL-ALT-Security newsletter

Substack

Regular writing on current threats, breach lessons and practical defenses, aimed at readers who are not full time security professionals.

Read on Substack

Self hosted app suite

PHP, MySQL, no frameworks

A growing set of personal web applications built and hosted from scratch, with a shared security pattern across all of them: passwords hashed with bcrypt, signed cookies, CSRF protection, rate limiting, and sensitive files stored outside the web root.

In progress

Continuous scanning pipeline

Static and dynamic analysis, one dashboard

A vulnerability scanning setup for my own applications, combining static analysis, secret scanning, dependency checks, TLS testing and dynamic scanning, with results collected in one dashboard.

> training

Training and free resources

Where to start, and where to go next. Everything listed here is free or has a free tier.

  • CISA free cybersecurity services

    Government resources for individuals and small organizations

    Advisories, guidance and no cost tools published by the United States Cybersecurity and Infrastructure Security Agency.

  • STOP. THINK. CONNECT.

    National Cybersecurity Alliance

    Awareness campaign materials you can hand to family, a classroom or a small team without editing anything.

  • Hands on labs

    Learn by doing

    Guided browser based labs that teach attacking and defending concepts. Good next step once the basics feel comfortable.

    Free tier Open TryHackMe
  • NIST Cybersecurity Framework

    Structure for organizations

    The reference most security programs are measured against. Useful even for a small business trying to decide what to do first.

  • Check your exposure

    Have I Been Pwned

    Find out which breaches included your email address, then change those passwords and enable multifactor on the accounts involved.

  • KnowBe4 Home Security Awareness Training

    Password is "homecourse"

    It’s very important to keep your whole family safe on the internet. That is why we created this training just for you.

> contact

Get in touch

Questions, speaking requests, or a topic you want covered. Messages come straight to me.

  • No trackers and no third party scripts on this page.
  • Reply usually within a few days.
  • Do not send confidential or client data.